13.07.2015 Views

Naming and Directory Services (DNS, NIS, and LDAP)

Naming and Directory Services (DNS, NIS, and LDAP)

Naming and Directory Services (DNS, NIS, and LDAP)

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

System successfully configuredThe -a proxyDN <strong>and</strong> -a proxyPassword are required if the profile to be used is setup for proxy. As the credentials are not stored in the profile saved on the server,you must supply the information when you initialize the client. This method ismore secure than the older method of storing the proxy credentials on the server.The proxy information is used to create /var/ldap/ldap_client_cred. Therest of the information is put in /var/ldap/ldap_client_file.Initializing a Client ManuallySuperusers. or administrators with an equivalent role, can perform manual clientconfigurations. However, many of the checks are bypassed during the process, so it isrelatively easy to misconfigure your system. In addition, you must change settings onevery machine, instead of in one central place, as is done when using profiles.▼How to Initialize a Client Manually1. Become superuser or assume an equivalent role.Roles contain authorizations <strong>and</strong> privileged comm<strong>and</strong>s. For more informationabout roles, see “Using Role-Based Access Control (Tasks)” in System AdministrationGuide: Security <strong>Services</strong>.2. Use ldapclient manual to initialize the client.# ldapclient manual \-a domainName=dc=west.example.com \-a credentialLevel=proxy \-a defaultSearchBase=dc=west,dc=example,dc=com \-a proxyDN=cn=proxyagent,ou=profile,dc=west,dc=example,dc=com \-a proxyPassword=testtest 192.168.0.13. Use ldapclient list to verify.NS_<strong>LDAP</strong>_FILE_VERSION= 2.0NS_<strong>LDAP</strong>_BINDDN= cn=proxyagent,ou=profile,dc=west,dc=example,dc=comNS_<strong>LDAP</strong>_BINDPASSWD= {NS1}4a3788e8c053424fNS_<strong>LDAP</strong>_SERVERS= 192.168.0.1NS_<strong>LDAP</strong>_SEARCH_BASEDN= dc=west,dc=example,dc=comNS_<strong>LDAP</strong>_CREDENTIAL_LEVEL= proxyModifying a Manual Client Configuration▼How to Modify a Manual Configuration1. Become superuser or assume an equivalent role.Chapter 12 • Setting Up <strong>LDAP</strong> Clients (Tasks) 181

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!