unknown
2008-04-02 14:22:25 UTC
ðÒÉÎÏÛÕ Ó×ÏÉ ÉÚ×ÉÎÅÎÉÑ, ÎÏ ÐÅÒ×ÏÎÁÞÁÌØÎÏ ÜÔÏÔ ÔÅËÓÔ ÐÏ ÏÛÉÂËÅ ÕÛÅÌ ×
sisyphus. ðÒÏÛÕ ÏÔ×ÅÞÁÔØ × ÒÁÓÓÙÌËÕ office-server.
+++
äÏÂÒÏÇÏ ×ÒÅÍÅÎÉ ÓÕÔÏË, ËÏÌÌÅÇÉ.
é ÔÁË, ÞÔÏ ÎÕÖÎÏ ÄÏÄÅÌÁÔØ, ÎÁ ÍÏÊ ×ÚÇÌÑÄ, ÄÌÑ ÔÏÇÏ, ÞÔÏÂÙ ÕÐÒÁ×ÌÅÎÉÅ
ÐÏÌØÚÏ×ÁÔÅÌÑÍÉ × LDAP ÒÁÂÏÔÁÌÏ ÔÁË, ËÁË ÈÏÞÅÔÓÑ.
1) óÏÚÄÁ×ÁÔØ ÎÏ×ÕÀ ÂÁÚÕ Á×ÔÏÍÁÔÉÞÅÓËÉ, ÏÓÎÏ×Ù×ÁÑÓØ ÎÁ ÎÁ hostname, Á
ÎÁ domainname. (õ ÍÅÎÑ, ÐÒÉ ÕÓÔÁÎÏ×ËÅ, ÂÙÌÁ ÓÏÚÄÁÎÁ ÂÁÚÁ, ÏÓÎÏ×ÁÎÁÑ
ÎÁ hostname). ÷ ÓÏÚÄÁ×ÁÅÍÏÊ ÐÏ ÕÍÏÌÞÁÎÉÀ ÂÁÚÅ, ÓÏÚÄÁ×ÁÔØ ÄÅÒÅ×Ï
ËÏÎÔÅÊÎÅÒÏ×.
2) ðÒÏ×ÅÒÑÔØ ÂÁÚÕ ÎÁ ÎÁÌÉÞÉÅ ÓÔÒÕËÔÕÒÙ ËÏÎÔÅÊÎÅÒÏ×, É ÅÓÌÉ ÉÈ ÎÅÔ, ÔÏ ÓÏÚÄÁ×ÁÔØ.
ou=People,dc...
ou=Group,dc...
ou=Computers,dc...
3) äÌÑ ÒÅÄÁËÔÉÒÏ×ÁÎÉÑ ËÏÎÔÅÊÎÅÒÏ× ÐÒÅÄÕÓÍÏÔÒÅÔØ ÐÏÌÑ × ÄÉÁÌÏÇÅ
https://localhost:8080/index.scm/nsswitch/:
ðÏÉÓË ÐÏÌØÚÏ×ÁÔÅÌÅÊ:
ðÏÉÓË ÇÒÕÐÐ:
ðÏÉÓ ÐÁÒÏÌÅÊ:
é ËÏÎÔÅÊÎÅÒÙ, ÓÏÏÔ×ÅÔÓÔ×ÅÎÎ:
ou=People,dc...
ou=Group,dc...
ou=People,dc...
4) òÁÓËÏÍÅÎÔÉÒÏ×ÁÔØ ÓÏÏÔ×ÅÔÓÔ×ÕÀÝÉÅ ÓÔÒÏËÉ × pam_ldap.conf
É ldap.conf (ÅÓÌÉ ÏÎÉ ÎÅ ÓÉÍÌÉÎËÉ)
nss_base_passwd ou=People,?one
nss_base_shadow ou=People,?one
nss_base_group ou=Groups,?one
nss_base_hosts ou=Computers,?one
5) îÅ ÈÒÁÎÉÔØ ÐÁÒÏÌØ cn=admin × ÏÔËÒÙÔÏÍ ×ÉÄÅ × /etc/openldap/slapd.conf,
Á ×
/etc/ldap.conf
/etc/nss_ldap.conf
/etc/pam_ldap.conf
ÎÅ ÈÒÁÎÉÔØ ÅÇÏ ×ÏÏÂÝÅ, ÔÁË ËÁË ÁÎÏÎÉÍÎÏ ×ÓÅ ÂÕÄÅÔ ÒÁÂÏÔÁÔØ.
6) ôÁË ËÁË × ÏÄÎÏÊ ÚÁÐÉÓÉ uid=èèè,ou=People,dc=... ÍÏÖÎÏ ÈÒÁÎÉÔØ
ÉÎÆÏÒÍÁÃÉÀ ÄÌÑ ÒÁÚÌÉÞÎÙÈ ÓÅÒ×ÉÓÏ×, ÔÏ ÐÒÅÄÕÓÍÏÔÒÅÔØ ÎÅÏÂÈÏÄÉÍÙÅ ÐÏÌÑ ×
ÄÉÁÌÏÇÅ ÄÏÂÁ×ÌÅÎÉÑ/ÒÅÄÁËÔÉÒÏ×ÁÎÉÑ.
7) ðÒÅÄÕÓÍÏÔÒÅÔØ ÓÏÏÔ×ÅÔÓÔ×ÕÀÝÉÅ ÐÏÌÑ É ÎÁÓÔÒÏÊËÉ × ÓÅÒ×ÉÓÁÈ, ËÏÔÏÒÙÅ
ÍÏÇÕÔ/ÂÕÄÕÔ ÉÓËÁÔØ ÚÁÐÉÓÉ × LDAP. ñ ÄÅÌÁÌ ÄÌÑ SAMBA, Postfix,
Cyrus-IMAP.
ðÒÉÍÅÒ ÚÁÐÉÓÉ, ËÏÔÏÒÁÑ ÐÒÏ×ÅÒÅÎÁ ÍÎÏÊ, ÍÏÇÕ ÐÒÅÄÏÓÔÁ×ÉÔØ × ÆÏÒÍÁÔÅ
ldif, ×ÍÅÓÔÅ Ó ×ÓÅÊ ÏÓÔÁÌØÎÏÊ ÓÔÒÕËÔÕÒÏÊ ËÏÎÔÅÊÎÅÒÏ×.
ðÏÌÉÇÏÎ ÄÌÑ ÉÓÐÙÔÁÎÉÊ ÇÏÔÏ×, ÒÕËÉ ÁÖ ÞÅÛÕÔÓÑ...
P.S. òÕËÉ ÍÙÌ...
+++
sisyphus. ðÒÏÛÕ ÏÔ×ÅÞÁÔØ × ÒÁÓÓÙÌËÕ office-server.
+++
äÏÂÒÏÇÏ ×ÒÅÍÅÎÉ ÓÕÔÏË, ËÏÌÌÅÇÉ.
é ÔÁË, ÞÔÏ ÎÕÖÎÏ ÄÏÄÅÌÁÔØ, ÎÁ ÍÏÊ ×ÚÇÌÑÄ, ÄÌÑ ÔÏÇÏ, ÞÔÏÂÙ ÕÐÒÁ×ÌÅÎÉÅ
ÐÏÌØÚÏ×ÁÔÅÌÑÍÉ × LDAP ÒÁÂÏÔÁÌÏ ÔÁË, ËÁË ÈÏÞÅÔÓÑ.
1) óÏÚÄÁ×ÁÔØ ÎÏ×ÕÀ ÂÁÚÕ Á×ÔÏÍÁÔÉÞÅÓËÉ, ÏÓÎÏ×Ù×ÁÑÓØ ÎÁ ÎÁ hostname, Á
ÎÁ domainname. (õ ÍÅÎÑ, ÐÒÉ ÕÓÔÁÎÏ×ËÅ, ÂÙÌÁ ÓÏÚÄÁÎÁ ÂÁÚÁ, ÏÓÎÏ×ÁÎÁÑ
ÎÁ hostname). ÷ ÓÏÚÄÁ×ÁÅÍÏÊ ÐÏ ÕÍÏÌÞÁÎÉÀ ÂÁÚÅ, ÓÏÚÄÁ×ÁÔØ ÄÅÒÅ×Ï
ËÏÎÔÅÊÎÅÒÏ×.
2) ðÒÏ×ÅÒÑÔØ ÂÁÚÕ ÎÁ ÎÁÌÉÞÉÅ ÓÔÒÕËÔÕÒÙ ËÏÎÔÅÊÎÅÒÏ×, É ÅÓÌÉ ÉÈ ÎÅÔ, ÔÏ ÓÏÚÄÁ×ÁÔØ.
ou=People,dc...
ou=Group,dc...
ou=Computers,dc...
3) äÌÑ ÒÅÄÁËÔÉÒÏ×ÁÎÉÑ ËÏÎÔÅÊÎÅÒÏ× ÐÒÅÄÕÓÍÏÔÒÅÔØ ÐÏÌÑ × ÄÉÁÌÏÇÅ
https://localhost:8080/index.scm/nsswitch/:
ðÏÉÓË ÐÏÌØÚÏ×ÁÔÅÌÅÊ:
ðÏÉÓË ÇÒÕÐÐ:
ðÏÉÓ ÐÁÒÏÌÅÊ:
é ËÏÎÔÅÊÎÅÒÙ, ÓÏÏÔ×ÅÔÓÔ×ÅÎÎ:
ou=People,dc...
ou=Group,dc...
ou=People,dc...
4) òÁÓËÏÍÅÎÔÉÒÏ×ÁÔØ ÓÏÏÔ×ÅÔÓÔ×ÕÀÝÉÅ ÓÔÒÏËÉ × pam_ldap.conf
É ldap.conf (ÅÓÌÉ ÏÎÉ ÎÅ ÓÉÍÌÉÎËÉ)
nss_base_passwd ou=People,?one
nss_base_shadow ou=People,?one
nss_base_group ou=Groups,?one
nss_base_hosts ou=Computers,?one
5) îÅ ÈÒÁÎÉÔØ ÐÁÒÏÌØ cn=admin × ÏÔËÒÙÔÏÍ ×ÉÄÅ × /etc/openldap/slapd.conf,
Á ×
/etc/ldap.conf
/etc/nss_ldap.conf
/etc/pam_ldap.conf
ÎÅ ÈÒÁÎÉÔØ ÅÇÏ ×ÏÏÂÝÅ, ÔÁË ËÁË ÁÎÏÎÉÍÎÏ ×ÓÅ ÂÕÄÅÔ ÒÁÂÏÔÁÔØ.
6) ôÁË ËÁË × ÏÄÎÏÊ ÚÁÐÉÓÉ uid=èèè,ou=People,dc=... ÍÏÖÎÏ ÈÒÁÎÉÔØ
ÉÎÆÏÒÍÁÃÉÀ ÄÌÑ ÒÁÚÌÉÞÎÙÈ ÓÅÒ×ÉÓÏ×, ÔÏ ÐÒÅÄÕÓÍÏÔÒÅÔØ ÎÅÏÂÈÏÄÉÍÙÅ ÐÏÌÑ ×
ÄÉÁÌÏÇÅ ÄÏÂÁ×ÌÅÎÉÑ/ÒÅÄÁËÔÉÒÏ×ÁÎÉÑ.
7) ðÒÅÄÕÓÍÏÔÒÅÔØ ÓÏÏÔ×ÅÔÓÔ×ÕÀÝÉÅ ÐÏÌÑ É ÎÁÓÔÒÏÊËÉ × ÓÅÒ×ÉÓÁÈ, ËÏÔÏÒÙÅ
ÍÏÇÕÔ/ÂÕÄÕÔ ÉÓËÁÔØ ÚÁÐÉÓÉ × LDAP. ñ ÄÅÌÁÌ ÄÌÑ SAMBA, Postfix,
Cyrus-IMAP.
ðÒÉÍÅÒ ÚÁÐÉÓÉ, ËÏÔÏÒÁÑ ÐÒÏ×ÅÒÅÎÁ ÍÎÏÊ, ÍÏÇÕ ÐÒÅÄÏÓÔÁ×ÉÔØ × ÆÏÒÍÁÔÅ
ldif, ×ÍÅÓÔÅ Ó ×ÓÅÊ ÏÓÔÁÌØÎÏÊ ÓÔÒÕËÔÕÒÏÊ ËÏÎÔÅÊÎÅÒÏ×.
ðÏÌÉÇÏÎ ÄÌÑ ÉÓÐÙÔÁÎÉÊ ÇÏÔÏ×, ÒÕËÉ ÁÖ ÞÅÛÕÔÓÑ...
P.S. òÕËÉ ÍÙÌ...
+++
--
Best regards,
Dmitriy L. Kruglikov
Dmitriy.Kruglikov_at_gmail_dot_com
DKR6-RIPE
DKR6-UANIC
XMPP: Dmitriy.Kruglikov_at_gmail_dot_com
Best regards,
Dmitriy L. Kruglikov
Dmitriy.Kruglikov_at_gmail_dot_com
DKR6-RIPE
DKR6-UANIC
XMPP: Dmitriy.Kruglikov_at_gmail_dot_com