目录
虚拟机环境:centos 7
临时: setenforce 0 永久: vi /etc/sysconfig/selinux selinux=enforcing 改为 selinux=disabled 重启服务reboot systemctl stop firewalld.service systemctl disable firewalld.service
yum install -y openldap-servers openldap-clients migrationtools
slappasswd 然后根据提示输入密码: new password: 123456 re-enter new password: 123456 会返回加密的密码字符串,保存好这个字符串 {ssha}ycugpzbszt3chctkpwr5wxgqhvugxcnv
###### 查看安装了哪些文件
rpm -ql openldap rpm -ql openldap-servers
###### 修改配置
vim /etc/openldap/slapd.d/cn\=config\/olcdatabase\={2}hdb.ldif 找到olcsuffix,修改为你的dc,如: dc=mypaas,dc=com 下一行olcrootdn, 修改为你的用户名,如: cn=manager,dc=mypaas,dc=com 在文件末尾添加一行,设置刚才的密码: olcrootpw: {ssha}ycugpzbszt3chctkpwr5wxgqhvugxcnv
vi /etc/openldap/slapd.d/cn\=config\/olcdatabase\={1}monitor.ldif 修改 olcaccess 中的dn.base=”cn=xxxxxxx”这行为刚才设置的用户名,如: dn.base=”cn=manager,dc=mypaas,dc=com”
cp /usr/share/openldap-servers/db_config.example /var/lib/ldap/db_config chown -r ldap:ldap /var/lib/ldap/
slaptest -u 末尾出现configfile testing successed 说明成功了
systemctl start slapd.service systemctl enable slapd.service # 查看运行状态 systemctl status slapd.service
ls /etc/openldap/schema/*.ldif | xargs -i {} sudo ldapadd -y external -h ldapi:/// -f {}
yum install httpd -y
vim /etc/httpd/conf/httpd.conf 找到allowoverride一行,修改none为all 如果想修改端口号,修改listen 80一行
systemctl start httpd.service systemctl enable httpd.service curl http://127.0.0.1/
yum install phpldapadmin(如果找不到软件包,重新设置一下yum源) yum localinstall http://rpms.famillecollet.com/enterprise/remi-release-7.rpm
vim /etc/phpldapadmin/config.php 找到并取消下面几行的注释: $servers->setvalue(‘server’,’host’,’127.0.0.1’); $servers->setvalue(‘server’,’port’,389); $servers->setvalue(‘server’,’base’,array(‘dc=mypaas,dc=com’)); (array里加上openldap配置文件中设置的olcsuffix) $servers->setvalue(‘login’,’auth_type’,’session’); $servers->setvalue(‘login’,’attr’,’dn’); 把它的下一行注释掉 #$servers->setvalue(‘login’,’attr’,’uid’);
vim /etc/httpd/conf.d/phpldapadmin.conf 改为下图所示 <ifmodule mod_authz_core.c> # apache 2.4 require local require ip 172.16.31 </ifmodule> <ifmodule !mod_authz_core.c> # apache 2.2 order deny,allow deny from all allow from all allow from ::1 </ifmodule>
cd /etc/openldap/ vim base.ldif
dn: dc=mypaas,dc=com o: ldap objectclass: dcobject objectclass: organization dc: mypaas
systemctl restart httpd.service
访问 http://ip/phpldapadmin 登陆用户名:cn=manager,dc=mypaas,dc=com
如对本文有疑问, 点击进行留言回复!!
linux下文本编辑器vim的使用方法(复制、粘贴、替换、行号、撤销、多文件操作)
网友评论