LDAP Network SERVICE *******************
What is 1.LDAP?
LADAP Directory service authentication, similar to Windows Active Directory, is a way to record data
2.LADAP client required software
SSSD //The service can be used to access a variety of authentication servers, such as LDAP, Kerberos, and so on,
and provide authorization. is a process between a local user and a data store, and the client
Connects SSSD first, and then SSSD contacts external resource providers.
krb5-workstation //network authentication
650) this.width=650 , "src=" Http://s2.51cto.com/wyfs02/M02/8A/2E/wKiom1gpwviA7TQxAAAca4EHCcw398.png "style=" Float:none; "title=" capture. PNG "alt=" wkiom1gpwvia7tqxaaaca4ehccw398.png "/>
3. How to turn on LDAP user authentication
Authconfig-tui
Obtain the CA's Certificate 650) this.width=650 before starting the authentication; "Src=" http://s1.51cto.com/wyfs02/M01/8A/2A/ Wkiol1gpw47xp-h6aaddi7dcgzc803.png "title=" Capture 6. PNG "alt=" Wkiol1gpw47xp-h6aaddi7dcgzc803.png "/>
Go to Settings page
650) this.width=650; "src=" Http://s4.51cto.com/wyfs02/M01/8A/2E/wKiom1gpwy-TXFmsAAAUxZW6tJI734.png "title=" Capture 1. PNG "alt=" Wkiom1gpwy-txfmsaaauxzw6tji734.png "/>
650) this.width=650; "src=" Http://s4.51cto.com/wyfs02/M00/8A/2E/wKiom1gpwvnyGSWuAACevR-hLvg699.png "title=" Capture 2. PNG "style=" Float:none; "alt=" Wkiom1gpwvnygswuaacevr-hlvg699.png "/>
650) this.width=650; "src=" Http://s1.51cto.com/wyfs02/M02/8A/2A/wKioL1gpwvrSJJ3mAAA7P1XJPLE965.png "style=" float: none; "Title=" Captures 3. PNG "alt=" Wkiol1gpwvrsjj3maaa7p1xjple965.png "/>
650) this.width=650; "src=" Http://s1.51cto.com/wyfs02/M00/8A/2E/wKiom1gpwvviZqx7AABkZupPKJk872.png "style=" float: none; "Title=" Captures 4png.png "alt=" Wkiom1gpwvvizqx7aabkzuppkjk872.png "/>
Test
Getent passwd Ldapuser1
If the user information is displayed properly, prove that the client authentication is successful
650) this.width=650; "src=" Http://s2.51cto.com/wyfs02/M02/8A/2E/wKiom1gpxBDQr3GAAABK6XxBKFs059.png "style=" float: none; "Title=" Captures 7. PNG "alt=" Wkiom1gpxbdqr3gaaabk6xxbkfs059.png "/>
Example out of all users
Vim/etc/sssd/sssd.conf
Enumerate = True
Systemctl Restart SSSD
Getent passwd
650) this.width=650; "src=" Http://s4.51cto.com/wyfs02/M02/8A/2A/wKioL1gpxECCV4EFAAAzOnkVbe8022.png "title=" capture. PNG "alt=" Wkiol1gpxeccv4efaaazonkvbe8022.png "/>
650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M02/8A/2A/wKioL1gpxBLD7R0YAAEE2vEB3oU697.png "title=" Capture 8. PNG "style=" Float:none; "alt=" Wkiol1gpxbld7r0yaaee2veb3ou697.png "/>
650) this.width=650; "src=" Http://s2.51cto.com/wyfs02/M00/8A/2A/wKioL1gpxF-iGkdZAALAHhVIeEY236.png "title=" capture. PNG "alt=" Wkiol1gpxf-igkdzaalahhvieey236.png "/>
4. Auto-mount User home directory
Required plug-in AutoFS
650) this.width=650; "src=" Http://s2.51cto.com/wyfs02/M01/8A/2E/wKiom1gpxO_DuQj0AAAXYiRrOqo697.png "style=" float: none; "title=" capture. PNG "alt=" Wkiom1gpxo_duqj0aaaxyirroqo697.png "/>
Modifying a configuration file
Vim/etc/auto.master
/HOME/GUESTS/ETC/AUTO.LADP650) this.width=650; "Src=" http://s1.51cto.com/wyfs02/M01/8A/2A/ Wkiol1gpxvcwclg-aaaycjqerko932.png "style=" Float:none; "title=" 2.PNG "alt=" wkiol1gpxvcwclg-aaaycjqerko932.png "/ >
650) this.width=650; "src=" Http://s1.51cto.com/wyfs02/M02/8A/2E/wKiom1gpxPChsXTaAABBWLEaxE8601.png "title=" Capture 2. PNG "style=" Float:none; "alt=" Wkiom1gpxpchsxtaaabbwleaxe8601.png "/>
Vim/etc/auto.ldap
Ldapuser1 172.25.254.254:/home/guests/ldapuser1//Set up a user
* 172.25.254.254:/home/guests/&//Set All Users
650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M02/8A/2A/wKioL1gpxbOzbpsxAAAXx_S3nA8263.png "style=" float: none; "title=" 1.PNG "alt=" Wkiol1gpxbozbpsxaaaxx_s3na8263.png "/>
650) this.width=650; "src=" Http://s4.51cto.com/wyfs02/M02/8A/2A/wKioL1gpxPHSTPqjAAAZ_3FBMwU289.png "style=" float: none; "Title=" Captures 3. PNG "alt=" Wkiol1gpxphstpqjaaaz_3fbmwu289.png "/>
650) this.width=650; "src=" Http://s4.51cto.com/wyfs02/M00/8A/2E/wKiom1gpxPLwSCJ4AAAXIYobcS8322.png "style=" float: none; "Title=" captures 5. PNG "alt=" Wkiom1gpxplwscj4aaaxiyobcs8322.png "/>
Systemctl Restart AutoFS
Systemctl enable AutoFS//Auto mount need to start AutoFS service 650) this.width=650; src= HTTP://S5.51CTO.COM/WYFS02/M00/8 A/2e/wkiom1gpxbssdp-qaaabs6dr_0m782.png "title=" 2.PNG "style=" Float:none; "alt=" wkiom1gpxbssdp-qaaabs6dr_ 0m782.png "/>
Test
650) this.width=650; "src=" Http://s4.51cto.com/wyfs02/M00/8A/2E/wKiom1gpxPHxCOFbAAAj-1dgbds303.png "style=" float: none; "Title=" Captures 4. PNG "alt=" Wkiom1gpxphxcofbaaaj-1dgbds303.png "/>
5. Scripts to implement the above settings
650) this.width=650; "src=" Http://s1.51cto.com/wyfs02/M01/8A/2E/wKiom1gpxlfTEKgQAAGFHCmZ2-4557.png "style=" float: none; "title=" 1.PNG "alt=" Wkiom1gpxlftekgqaagfhcmz2-4557.png "/>
Test:
650) this.width=650; "src=" Http://s1.51cto.com/wyfs02/M00/8A/2E/wKiom1gpxlixgv9TAACekGqT43A522.png "style=" float: none; "title=" 2.PNG "alt=" Wkiom1gpxlixgv9taacekgqt43a522.png "/>
Linux Note 2-8 LDAP Network Service