Linux Note 2-8 LDAP Network Service

Source: Internet
Author: User
Tags ldap

LDAP Network SERVICE *******************
What is 1.LDAP?
LADAP Directory service authentication, similar to Windows Active Directory, is a way to record data


2.LADAP client required software
SSSD         //The service can be used to access a variety of authentication servers, such as LDAP, Kerberos, and so on,
                and provide authorization. is a process between a local user and a data store, and the client
                 Connects SSSD first, and then SSSD contacts external resource providers.
krb5-workstation         //network authentication
650) this.width=650 , "src=" Http://s2.51cto.com/wyfs02/M02/8A/2E/wKiom1gpwviA7TQxAAAca4EHCcw398.png "style=" Float:none; "title=" capture. PNG "alt=" wkiom1gpwvia7tqxaaaca4ehccw398.png "/>

3. How to turn on LDAP user authentication
Authconfig-tui
Obtain the CA's Certificate 650) this.width=650 before starting the authentication; "Src=" http://s1.51cto.com/wyfs02/M01/8A/2A/ Wkiol1gpw47xp-h6aaddi7dcgzc803.png "title=" Capture 6. PNG "alt=" Wkiol1gpw47xp-h6aaddi7dcgzc803.png "/>

Go to Settings page

650) this.width=650; "src=" Http://s4.51cto.com/wyfs02/M01/8A/2E/wKiom1gpwy-TXFmsAAAUxZW6tJI734.png "title=" Capture 1. PNG "alt=" Wkiom1gpwy-txfmsaaauxzw6tji734.png "/>

650) this.width=650; "src=" Http://s4.51cto.com/wyfs02/M00/8A/2E/wKiom1gpwvnyGSWuAACevR-hLvg699.png "title=" Capture 2. PNG "style=" Float:none; "alt=" Wkiom1gpwvnygswuaacevr-hlvg699.png "/>

650) this.width=650; "src=" Http://s1.51cto.com/wyfs02/M02/8A/2A/wKioL1gpwvrSJJ3mAAA7P1XJPLE965.png "style=" float: none; "Title=" Captures 3. PNG "alt=" Wkiol1gpwvrsjj3maaa7p1xjple965.png "/>

650) this.width=650; "src=" Http://s1.51cto.com/wyfs02/M00/8A/2E/wKiom1gpwvviZqx7AABkZupPKJk872.png "style=" float: none; "Title=" Captures 4png.png "alt=" Wkiom1gpwvvizqx7aabkzuppkjk872.png "/>


Test
Getent passwd Ldapuser1
If the user information is displayed properly, prove that the client authentication is successful

650) this.width=650; "src=" Http://s2.51cto.com/wyfs02/M02/8A/2E/wKiom1gpxBDQr3GAAABK6XxBKFs059.png "style=" float: none; "Title=" Captures 7. PNG "alt=" Wkiom1gpxbdqr3gaaabk6xxbkfs059.png "/>


Example out of all users
Vim/etc/sssd/sssd.conf
Enumerate = True
Systemctl Restart SSSD
Getent passwd

650) this.width=650; "src=" Http://s4.51cto.com/wyfs02/M02/8A/2A/wKioL1gpxECCV4EFAAAzOnkVbe8022.png "title=" capture. PNG "alt=" Wkiol1gpxeccv4efaaazonkvbe8022.png "/>

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M02/8A/2A/wKioL1gpxBLD7R0YAAEE2vEB3oU697.png "title=" Capture 8. PNG "style=" Float:none; "alt=" Wkiol1gpxbld7r0yaaee2veb3ou697.png "/>

650) this.width=650; "src=" Http://s2.51cto.com/wyfs02/M00/8A/2A/wKioL1gpxF-iGkdZAALAHhVIeEY236.png "title=" capture. PNG "alt=" Wkiol1gpxf-igkdzaalahhvieey236.png "/>

4. Auto-mount User home directory
Required plug-in AutoFS

650) this.width=650; "src=" Http://s2.51cto.com/wyfs02/M01/8A/2E/wKiom1gpxO_DuQj0AAAXYiRrOqo697.png "style=" float: none; "title=" capture. PNG "alt=" Wkiom1gpxo_duqj0aaaxyirroqo697.png "/>
Modifying a configuration file
Vim/etc/auto.master
/HOME/GUESTS/ETC/AUTO.LADP650) this.width=650; "Src=" http://s1.51cto.com/wyfs02/M01/8A/2A/ Wkiol1gpxvcwclg-aaaycjqerko932.png "style=" Float:none; "title=" 2.PNG "alt=" wkiol1gpxvcwclg-aaaycjqerko932.png "/ >

650) this.width=650; "src=" Http://s1.51cto.com/wyfs02/M02/8A/2E/wKiom1gpxPChsXTaAABBWLEaxE8601.png "title=" Capture 2. PNG "style=" Float:none; "alt=" Wkiom1gpxpchsxtaaabbwleaxe8601.png "/>

Vim/etc/auto.ldap
Ldapuser1 172.25.254.254:/home/guests/ldapuser1//Set up a user

* 172.25.254.254:/home/guests/&//Set All Users

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M02/8A/2A/wKioL1gpxbOzbpsxAAAXx_S3nA8263.png "style=" float: none; "title=" 1.PNG "alt=" Wkiol1gpxbozbpsxaaaxx_s3na8263.png "/>

650) this.width=650; "src=" Http://s4.51cto.com/wyfs02/M02/8A/2A/wKioL1gpxPHSTPqjAAAZ_3FBMwU289.png "style=" float: none; "Title=" Captures 3. PNG "alt=" Wkiol1gpxphstpqjaaaz_3fbmwu289.png "/>

650) this.width=650; "src=" Http://s4.51cto.com/wyfs02/M00/8A/2E/wKiom1gpxPLwSCJ4AAAXIYobcS8322.png "style=" float: none; "Title=" captures 5. PNG "alt=" Wkiom1gpxplwscj4aaaxiyobcs8322.png "/>
Systemctl Restart AutoFS
Systemctl enable AutoFS//Auto mount need to start AutoFS service 650) this.width=650; src= HTTP://S5.51CTO.COM/WYFS02/M00/8 A/2e/wkiom1gpxbssdp-qaaabs6dr_0m782.png "title=" 2.PNG "style=" Float:none; "alt=" wkiom1gpxbssdp-qaaabs6dr_ 0m782.png "/>

Test

650) this.width=650; "src=" Http://s4.51cto.com/wyfs02/M00/8A/2E/wKiom1gpxPHxCOFbAAAj-1dgbds303.png "style=" float: none; "Title=" Captures 4. PNG "alt=" Wkiom1gpxphxcofbaaaj-1dgbds303.png "/>

5. Scripts to implement the above settings

650) this.width=650; "src=" Http://s1.51cto.com/wyfs02/M01/8A/2E/wKiom1gpxlfTEKgQAAGFHCmZ2-4557.png "style=" float: none; "title=" 1.PNG "alt=" Wkiom1gpxlftekgqaagfhcmz2-4557.png "/>

Test:

650) this.width=650; "src=" Http://s1.51cto.com/wyfs02/M00/8A/2E/wKiom1gpxlixgv9TAACekGqT43A522.png "style=" float: none; "title=" 2.PNG "alt=" Wkiom1gpxlixgv9taacekgqt43a522.png "/>



Linux Note 2-8 LDAP Network Service

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.