首页 > 其他分享 >ldap

ldap

时间:2022-11-24 08:11:06浏览次数:141  
标签:computingforgeeks server openldap LDAP ldap com

https://www.zhangqiongjie.com/5658.html

1.Reference

https://www.golinuxcloud.com/configure-ldap-client-auth-ldap-server/

https://computingforgeeks.com/run-openldap-server-in-docker-containers/

https://github.com/osixia/docker-phpLDAPadmin

https://github.com/osixia/docker-openldap

SSSD · wbwangk/wbwangk.github.io Wiki · GitHub

https://aws.amazon.com/cn/blogs/china/amazon-emr-authentication-scheme-based-on-openldap-and-kerberos-ii-synchronize-ldap-accounts-based-on-sssd/

 

LDAP in Containers - The Rubyist Blog

sssd.conf参考:

[sssd]
services = nss, pam, autofs
domains = computingforgeeks.com
debug_level = 9

[domain/computingforgeeks.com]
autofs_provider = ldap
ldap_schema = rfc2307
ldap_search_base = dc=computingforgeeks,dc=com
id_provider = ldap
auth_provider = ldap
chpass_provider = ldap
ldap_uri = ldap://127.0.0.1
ldap_id_use_start_tls = false
cache_credentials = True
ldap_tls_reqcert = demand
ldap_tls_cacertdir = /etc/openldap/cacerts
ldap_default_bind_dn = cn=admin,dc=computingforgeeks,dc=com
ldap_default_authtok_type = password
ldap_default_authtok = StrongAdminPassw0rd
override_homedir = /home/%u
default_shell = /bin/bash

[nss]
homedir_substring = /home
debug_level = 9

[pam]
debug_level = 9

[autofs]
debug_level = 9


docker-compose.yaml分别启动ldap-client, ldap-server, phpldapadmin

version: '3'
services:
  openldap-server:
    image: osixia/openldap:latest
    container_name: openldap-server
    environment:
      LDAP_LOG_LEVEL: "256"
      LDAP_ORGANISATION: "My Company"
      LDAP_DOMAIN: "computingforgeeks.com"
      LDAP_ADMIN_PASSWORD: "StrongAdminPassw0rd"
      LDAP_BASE_DN: "dc=computingforgeeks,dc=com"
    ports:
      - "389:389"
      - "636:636"
    volumes:
      - /home/ec2-user/environment/kevin/config/ldap-test/data:/var/lib/ldap
      - /home/ec2-user/environment/kevin/config/ldap-test/data:/etc/ldap/slapd.d
      - /home/ec2-user/environment/kevin/config/ldap-test/data:/container/service/slapd/assets/certs/
    # For replication to work correctly, domainname and hostname must be
    # set correctly so that "hostname"."domainname" equates to the
    # fully-qualified domain name for the host.
    hostname: "ldap.computingforgeeks.com"
  phpldapadmin:
    image: osixia/phpldapadmin:latest
    container_name: phpldapadmin
    environment:
      PHPLDAPADMIN_HTTPS: "false"
      PHPLDAPADMIN_LDAP_HOSTS: "ldap.computingforgeeks.com"
    hostname: phpldapadmin-service
    ports:
      - "8080:80"
      - "6443:443"
    depends_on:
      - openldap-server
    links:
      - openldap-server:ldap-host
  ldapclient:
    image: zhangqiongjie/ldap-client:0.0.5
    container_name: ldap-client
    hostname: ldap-client
    depends_on:
      - openldap-server
    links:
    - openldap-server:openldap

 

 

标签:computingforgeeks,server,openldap,LDAP,ldap,com
From: https://www.cnblogs.com/sinsenliu/p/16920733.html

相关文章

  • 基于飞书通讯录搭建本地LDAP服务(钉钉、企业微信配置后续更新)
    目前飞书社交办公应用成为公司日常沟通办公的协作工具,以及作为各种流程的审批处理系统,HR 也会在飞书上去管理所有员工的状态及组织架构。随着公司内新部署的业务系统越来越......
  • Spring Data(数据) LDAP
    版本3.0.0SpringDataLDAP使构建使用轻量级目录访问协议(LDAP)的基于Spring的应用程序变得更加容易。本文档是Spring数据的参考指南-文档支持。它解释了文档模块的概念......
  • Kubernetes部署ldap
    目录docldapinitpvldapinituse查看状态dochttps://hub.kubeapps.com/charts/geek-cookbook/openldapldap389tcp636tcpinitpvkubectlapply-f/free_cicd......
  • AD域/OpenLDAP账号密码被修改或过期,802.1x认证自动重连导致账户被锁定,无法上网怎么办?
    搭建了微软ActiveDirectory(AD)或OpenLDAP的企业,通常会让员工使用AD域账号或OpenLDAP账号密码登录电脑终端、OA、VPN、VDI或进行网络接入802.1x认证。AD域/OpenLDAP......
  • 使用python 接入LDAP验证系统实践记录
    LDAP简介LDAP(LightDirectoryAccessPortocol)是轻量目录访问协议,基于X.500标准,支持TCP/IP。LDAP基本概念LDAP的目的是为各种软件提供统一标准的认证机制,所有软件就可......
  • centos7 部署0penvpn+openldap
    全程远程帮忙部署,给个辛苦费就行,外加送文档骑娥8_3_6_8_8_5_5_7_4【说明来意】jumpserver、gitlab、confluence(wiki)、confluence(jira)、yapi、jenkins、nginx、zabbi......
  • java连接ranger+ldap认证的hive
        使用java连接ranger+ldap认证的hive,通过jdbc加上用户名密码即可,代码示例如下:importjava.sql.*;publicclassJdbcHiveLdap{privatestaticString......
  • Nginx集成LDAP统一认证
    编译安装nginxgitclonehttps://github.com/kvspb/nginx-auth-ldap.gitwgethttp://nginx.org/download/nginx-1.18.0.tar.gzyum-yinstallopenldap-develpcre-develop......
  • kubesphere集群ldap集成
    kubesphere集群版本v3.1.1kubectleditconfigmaps-nkubesphere-systemkubesphere-configapiVersion:v1data:kubesphere.yaml:|authentication:au......
  • k8s中kibana集成ldap和安装饼图插件
    集成ldap和添加饼图插件都需要重启容器1、创建configmapapiVersion:v1kind:ConfigMapmetadata:name:ldap-confignamespace:monitoringdata:ldap.toml:|......