Changes between Version 22 and Version 23 of ldap


Ignore:
Timestamp:
Nov 30, 2016, 7:40:13 AM (8 years ago)
Author:
admin
Comment:

--

Legend:

Unmodified
Added
Removed
Modified
  • ldap

    v22 v23  
    358358{{{
    359359# group, 'your domain'.ws.learn.ac.lk
    360 dn: ou=group,dc='your domain'dc=ws,dc=learn,dc=ac,dc=lk
    361 description: learn groups
    362 objectClass: top
    363 objectClass: organizationalUnit
    364 ou: group
     360dn:ou=group,dc='your domain'dc=ws,dc=learn,dc=ac,dc=lk
     361description:learn groups
     362objectClass:top
     363objectClass:organizationalUnit
     364ou:group
    365365# adm staf, group, 'your domain'.ws.learn.ac.lk
    366 dn: cn=adm,ou=group,dc='your domain'dc=ws,dc=learn,dc=ac,dc=lk
    367 cn: adm
    368 description: System Admin Staff
    369 gidNumber: 1000
    370 objectClass: posixGroup
    371 objectClass: top
     366dn:cn=adm,ou=group,dc='your domain'dc=ws,dc=learn,dc=ac,dc=lk
     367cn:adm
     368description:System Admin Staff
     369gidNumber:1000
     370objectClass:posixGroup
     371objectClass:top
    372372
    373373# acadamic staf, group, 'your domain'.ws.learn.ac.lk
    374 dn: cn=acd,ou=group,dc='your domain'dc=ws,dc=learn,dc=ac,dc=lk
    375 cn: acd
    376 description: Acadamic Staff
    377 gidNumber: 2000
    378 objectClass: posixGroup
    379 objectClass: top
     374dn:cn=acd,ou=group,dc='your domain'dc=ws,dc=learn,dc=ac,dc=lk
     375cn:acd
     376description:Acadamic Staff
     377gidNumber:2000
     378objectClass:posixGroup
     379objectClass:top
    380380
    381381# students, group, 'your domain'.ws.learn.ac.lk
    382 dn: cn=std,ou=group,dc='your domain'dc=ws,dc=learn,dc=ac,dc=lk
    383 cn: std
    384 description: Students
    385 gidNumber: 5000
    386 objectClass: posixGroup
    387 objectClass: top
     382dn:cn=std,ou=group,dc='your domain'dc=ws,dc=learn,dc=ac,dc=lk
     383cn:std
     384description:Students
     385gidNumber:5000
     386objectClass:posixGroup
     387objectClass:top
    388388
    389389# servers, 'your domain'.ws.learn.ac.lk
    390 dn: ou=servers,dc='your domain'dc=ws,dc=learn,dc=ac,dc=lk
    391 description: servers
    392 objectClass: top
    393 objectClass: organizationalUnit
    394 ou: servers
     390dn:ou=servers,dc='your domain'dc=ws,dc=learn,dc=ac,dc=lk
     391description:servers
     392objectClass:top
     393objectClass:organizationalUnit
     394ou:servers
    395395
    396396# idp, servers, 'your domain'.ws.learn.ac.lk
    397 dn: cn=idp,ou=servers,dc='your domain'dc=ws,dc=learn,dc=ac,dc=lk
    398 cn: idp
    399 description: Identity Server
    400 ipHostNumber: 192.248.6.XX
    401 objectClass: top
    402 objectClass: device
    403 objectClass: ipHost
    404 objectClass: simpleSecurityObject
    405 userPassword: {crypt}idpldap
    406 
    407 # www, servers, 'your domain'.ws.learn.ac.lk
    408 dn: cn=www,ou=servers,dc='your domain'dc=ws,dc=learn,dc=ac,dc=lk
    409 cn: irs
    410 description: IRS Server
    411 ipHostNumber: 192.248.6.XX
    412 objectClass: top
    413 objectClass: device
    414 objectClass: ipHost
    415 objectClass: simpleSecurityObject
    416 userPassword: {crypt}wwwsvr
     397dn:cn=idp,ou=servers,dc='your domain'dc=ws,dc=learn,dc=ac,dc=lk
     398cn:idp
     399description:Identity Server
     400ipHostNumber:192.248.6.XX
     401objectClass:top
     402objectClass:device
     403objectClass:ipHost
     404objectClass:simpleSecurityObject
     405userPassword:{crypt}idpldap
    417406
    418407# people, 'your domain'.ws.learnac.lk
    419 dn: ou=people,dc='your domain'dc=ws,dc=learn,dc=ac,dc=lk
    420 description: inst users
    421 objectClass: top
    422 objectClass: organizationalUnit
    423 ou: people
     408dn:ou=people,dc='your domain'dc=ws,dc=learn,dc=ac,dc=lk
     409description:inst users
     410objectClass:top
     411objectClass:organizationalUnit
     412ou:people
    424413
    425414# testme, people, 'your domain'.ws.learn.ac.lk
    426 dn: uid=testme,ou=people,dc='your domain'dc=ws,dc=learn,dc=ac,dc=lk
    427 cn: Test Me
    428 departmentNumber: LEARN
    429 employeeNumber: 02
    430 employeeType: Test Account
    431 facsimileTelephoneNumber: 081 2003032
    432 gecos: Test Me
    433 gidNumber: 1000
    434 givenName: Test Me
    435 homeDirectory: /home/testme
    436 homePhone: none
    437 homePostalAddress: none
    438 initials: T M
    439 jpegPhoto: none
    440 labeledURI: none
    441 loginShell: /usr/local/bin/bash
    442 mobile: none
    443 objectClass: person
    444 objectClass: organizationalPerson
    445 objectClass: inetOrgPerson
    446 objectClass: posixAccount
    447 objectClass: top
    448 objectClass: shadowAccount
    449 shadowExpire: 14940
    450 shadowFlag: 134538484
    451 shadowInactive: 0
    452 shadowLastChange: 14483
    453 shadowMax: 13100
    454 shadowMin: 0
    455 shadowWarning: 7
    456 sn: Test
    457 telephoneNumber: 3032
    458 uid: testme
    459 uidNumber: 1001
    460 userPassword: testme
     415dn:uid=testme,ou=people,dc='your domain'dc=ws,dc=learn,dc=ac,dc=lk
     416cn:Test Me
     417departmentNumber:LEARN
     418employeeNumber:02
     419employeeType:Test Account
     420facsimileTelephoneNumber:081 2003032
     421gecos:Test Me
     422gidNumber:1000
     423givenName:Test Me
     424homeDirectory:/home/testme
     425homePhone:none
     426homePostalAddress:none
     427initials:T M
     428jpegPhoto:none
     429labeledURI:none
     430loginShell:/usr/local/bin/bash
     431mobile:none
     432objectClass:person
     433objectClass:organizationalPerson
     434objectClass:inetOrgPerson
     435objectClass:posixAccount
     436objectClass:top
     437objectClass:shadowAccount
     438shadowExpire:14940
     439shadowFlag:134538484
     440shadowInactive:0
     441shadowLastChange:14483
     442shadowMax:13100
     443shadowMin:0
     444shadowWarning:7
     445sn:Test
     446telephoneNumber:3032
     447uid:testme
     448uidNumber:1001
     449userPassword:testme
    461450}}}
    462451Note that user passwords are not encrypted (in clear text format).
     
    490479Create new file named acc1.ldif with following modification to ACLs. This will provide your irs to read users passwords.
    491480{{{
    492 dn: olcDatabase={1}hdb,cn=config
    493 changetype: modify
    494 replace: olcAccess
    495 olcAccess: {0}to attrs=userPassword by self write by anonymous auth by dn.children="ou=servers,dc='your domain'dc=ws,dc=learn,dc=ac,dc=lk" read by * none
    496 olcAccess: {1}to attrs=shadowLastChange by self write by * read
    497 olcAccess: {2}to * by * read
     481dn:olcDatabase={1}hdb,cn=config
     482changetype:modify
     483replace:olcAccess
     484olcAccess:{0}to attrs=userPassword by self write by anonymous auth by dn.children="ou=servers,dc='your domain'dc=ws,dc=learn,dc=ac,dc=lk" read by * none
     485olcAccess:{1}to attrs=shadowLastChange by self write by * read
     486olcAccess:{2}to * by * read
    498487}}}
    499488