13.07.2015 Views

Naming and Directory Services (DNS, NIS, and LDAP)

Naming and Directory Services (DNS, NIS, and LDAP)

Naming and Directory Services (DNS, NIS, and LDAP)

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

11. Add the -m option to the /lib/svc/method/nisplus file. Also add the -Y or-B options as needed. See “<strong>NIS</strong>+ to <strong>LDAP</strong> Tools <strong>and</strong> the Service ManagementFacility” on page 253 for more information.12. Start the <strong>NIS</strong>+ service.# svcadm enable network/rpc/nisplus:defaultStoring Configuration Information in<strong>LDAP</strong>In addition to keeping <strong>NIS</strong>+/<strong>LDAP</strong> configuration information in the configurationfiles <strong>and</strong> on the comm<strong>and</strong> line, configuration attributes can also be stored in <strong>LDAP</strong>.This is useful if the configuration information is shared by many <strong>NIS</strong>+ servers, <strong>and</strong> isexpected to change on a regular basis.To enable storing of configuration attributes in <strong>LDAP</strong>, consult your <strong>LDAP</strong> serverdocumentation <strong>and</strong> create the following new attributes <strong>and</strong> object class. Theconfiguration information is expected to reside at the location specified by thenisplus<strong>LDAP</strong>configDN value (from the rpc.nisd comm<strong>and</strong> line, or from/lib/svc/method/nisplus), with a cn equal to the nisplus<strong>LDAP</strong>baseDomainvalue (as it is known to the rpc.nisd daemon before reading any configurationinformation from <strong>LDAP</strong>).LDIF data is suitable for ldapadd(1) (attribute <strong>and</strong> object class OIDs are examplesonly).The defaultSearchBase, preferredServerList, <strong>and</strong> authenticationMethodattributes derive from a draft “DUA config” schema, which is intended to become anIETF st<strong>and</strong>ard. In any case, the following definitions are sufficient for the purposes of<strong>NIS</strong>+<strong>LDAP</strong>mapping(4).dn: cn=schemachangetype: modifyadd: attributetypesattributetypes: ( 1.3.6.1.4.1.11.1.3.1.1.1 NAME ’defaultSearchBase’ \DESC ’Default <strong>LDAP</strong> base DN used by a DUA’ \EQUALITY distinguishedNameMatch \SYNTAX 1.3.6.1.4.1.1466.115.121.1.12 SINGLE-VALUE )attributetypes: ( 1.3.6.1.4.1.11.1.3.1.1.2 NAME ’preferredServerList’ \DESC ’Preferred <strong>LDAP</strong> server host addresses to be used by a DUA’ \EQUALITY caseIgnoreMatch \SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 SINGLE-VALUE )attributetypes: ( 1.3.6.1.4.1.11.1.3.1.1.6 NAME ’authenticationMethod’ \DESC ’Identifies the authentication method used to connect to the DSA’\EQUALITY caseIgnoreMatch \SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 SINGLE-VALUE )288 System Administration Guide: <strong>Naming</strong> <strong>and</strong> <strong>Directory</strong> <strong>Services</strong> (<strong>DNS</strong>, <strong>NIS</strong>, <strong>and</strong> <strong>LDAP</strong>) • January 2005

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!