Autentisering via LDAP och Kerberos i CentOS 7: Difference between revisions
Jump to navigation
Jump to search
m →SSSD |
m →SSSD |
||
Line 22: | Line 22: | ||
{{RootCmd|<nowiki>authconfig --savebackup=original</nowiki>}} | {{RootCmd|<nowiki>authconfig --savebackup=original</nowiki>}} | ||
Enable:a autentisering via Kerberos: | |||
{{RootCmd|<nowiki>authconfig --enablekrb5 --krb5kdc="ns.example.com" --krb5adminserver="ns.example.com" --krb5realm="EXAMPLE.COM" --update</nowiki>}} | {{RootCmd|<nowiki>authconfig --enablekrb5 --krb5kdc="ns.example.com" --krb5adminserver="ns.example.com" --krb5realm="EXAMPLE.COM" --update</nowiki>}} | ||
Testa att du kan skaffa en Kerberos ticket. Editera /etc/sssd/sssd.conf: | Testa att du kan skaffa en Kerberos ticket. | ||
=== SSSD === | |||
Editera /etc/sssd/sssd.conf: | |||
{{bc|1= | {{bc|1= | ||
[sssd] | [sssd] | ||
Line 66: | Line 70: | ||
{{RootCmd|cacertdir_rehash /etc/openldap/cacerts}} | {{RootCmd|cacertdir_rehash /etc/openldap/cacerts}} | ||
Enable:a SSSD: | Enable:a användarinformation via SSSD: | ||
{{RootCmd|authconfig --enablesssd --update}} | {{RootCmd|authconfig --enablesssd --update}} | ||
Revision as of 12:43, 25 October 2015
Denna guide är under utveckling.
Installera följande:
Spara undan befintlig settings:
Kopiera CA cert till /etc/openldap/cacerts.
Om certifikatet adderas till cacerts mappen efter authconfig kommandot måste följande kommandon köras:
SSSD
Installera följande:
Spara undan befintlig settings:
Enable:a autentisering via Kerberos:
Testa att du kan skaffa en Kerberos ticket.
SSSD
Editera /etc/sssd/sssd.conf:
[sssd] config_file_version = 2 services = nss domains = LOCAL, example.com [nss] filter_groups = root filter_users = root reconnection_retries = 3 entry_cache_timeout = 300 entry_cache_nowait_percentage = 75 [domain/LOCAL] id_provider = local auth_provider = local access_provider = permit [domain/kerwien.se] enumerate = true auth_provider = krb5 krb5_server = ns.example.com krb5_realm = EXAMPLE.COM cache_credentials = true access_provider = simple chpass_provider = krb5 id_provider = ldap ldap_uri = ldap://ns.example.com ldap_search_base = dc=example,dc=com ldap_id_use_start_tls = true ldap_tls_cacert = /etc/openldap/cacerts/example.com-ca.crt sudo_provider = none
Kopiera ditt CA certifikat till filen /etc/openldap/cacerts/example.com-ca.crt, kör sedan kommandot:
Enable:a användarinformation via SSSD:
Start sssd:
Kontrollera med: