Server LDAP Setup

From James Dooley's Wiki
Jump to: navigation, search


/etc/ldap.conf

base dc=infusedsites,dc=com
nss_base_passwd ou=People,dc=infusedsites,dc=com
uri ldap://10.0.123.9:389/
ssl no
tls_cacertdir /etc/openldap/cacerts
pam_password md5
sudoers_base ou=sudoers,dc=infusedsites,dc=com

/etc/nsswitch.conf

passwd:     files ldap
shadow:     files ldap
group:      files ldap
sudoers:    files ldap

/etc/pam.d/system-auth

#%PAM-1.0
# This file is auto-generated.
# User changes will be destroyed the next time authconfig is run.
auth        required      pam_env.so
auth    required        pam_hulk.so
auth        sufficient    pam_unix.so nullok try_first_pass
auth        sufficient    pam_ldap.so use_first_pass
auth        requisite     pam_succeed_if.so uid >= 500 quiet
auth        required      pam_deny.so

account     required      pam_unix.so
account     sufficient    pam_ldap.so
account     sufficient    pam_succeed_if.so uid < 500 quiet
account     required      pam_permit.so

password    requisite     pam_cracklib.so try_first_pass retry=3
password    sufficient    pam_unix.so md5 shadow nullok try_first_pass use_authtok
password    sufficient    pam_ldap.so use_first_pass
password    required      pam_deny.so

session     optional      pam_keyinit.so revoke
session     required      pam_limits.so
session     [success=1 default=ignore] pam_succeed_if.so service in crond quiet use_uid
session     optional      pam_ldap.so
session     optional      pam_mkhomedir.so skel=/etc/skel umask=0022
session     required      pam_unix.so

/etc/fstab

10.0.123.9:/home/ldap           /home/ldap              nfs     rsize=8192,wsize=8192,noatime,timeo=5,intr       0 0

Install nfs-utils

yum -y install nfs-utils
chkconfig nfs on
chkconfig portmap on
service portmap start
mkdir /home/ldap
mount /home/ldap