LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 07-02-2009, 06:51 AM   #1
dave9191
LQ Newbie
 
Registered: Aug 2005
Location: London, UK
Distribution: Kubuntu
Posts: 3

Rep: Reputation: 0
LDAP Beginner


Hey guys,

First of all if this has already been heavily discussed and I havent found it, I apologise.

I've been given the fun task of sorting out LDAP. If there is something easier, then please point me in the right direction. There are 20 servers and 5 developers who need a login and password for each. So from what I have read, we need an LDAP server and we need to configure PAM for the login on each machine.

So I've tried that and failed.

I have a LDAP server with some logins in place, and I have configured a single machine with PAM to fetch those logins. And if you do 'getent passwd' the logins are fetched from the LDAP server and listed, but it wont let those users login. When I tried to configure PAM on another machine its not even getting the users from the LDAP server.

So clearly I have done something stupid somewhere. And I dont really know what to do next. I have read through many guides and they haven't really helped.


1) Is the information protected in the LDAP server with a username and password, or can anyone query it as long as they know where the server is?

2) How can I check that the admin password I set work? typing ldapsearch on the machine with the ldap server asks for a password, but the admin password never works.

3) How can I check that the passwords for the users work that I created using slappasswd? I guess that it sort of threw me of balance when I noticed that generating the same password with this command gave different resulting strings. But I guess they are being salted as they are hashed.

I am using Ubuntu 8.04 LTS Server install on all the machines.

I guess if you can help me with these few questions at first, it might help me to get somewhere.

Many thanks,

--
Dave
 
Old 07-02-2009, 07:02 AM   #2
nowonmai
Member
 
Registered: Jun 2003
Posts: 481

Rep: Reputation: 48
You shouldn't require a password to search the ldap, otherwise how would anyone log in?
You can limit the extent of the tree that is accessible anonymously to just the users.

You should get your hands on an ldap browser... it's much handier than commandline access, and seeing the ldap database visually really helps your understanding of the structure. JXplorer is pretty good. Do apt-cache search jxplorer to see if it's un the Ubuntu repos.
 
Old 07-03-2009, 08:30 AM   #3
kenneho
Member
 
Registered: May 2003
Location: Oslo, Norway
Distribution: Ubuntu, Red Hat Enterprise Linux
Posts: 657

Rep: Reputation: 40
If "getent password" works, it seem to me like PAM is not configured correctly. What does /var/log/secure when you try to log in? What does SSH say when it don't let you in?


Btw, I'm definately not an expert on this, so don't trust my ldap debugging skills to be of any help.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Ubuntu Hardy (php-ldap):Can't contact LDAP server eantoranz Programming 7 12-02-2008 06:40 PM
SMBLDAP-TOOLS SAMBA LDAP . Problem when filling ldap. jcdole Linux - Server 0 06-07-2008 11:41 AM
authenticating through one ldap server that uses other ldap servers & active director dreamm Linux - Server 1 02-21-2007 08:22 AM
LXer: LDAP Series Part IV - Installing OpenLDAP on Debian Plus Some LDAP Commentary LXer Syndicated Linux News 0 10-31-2006 06:54 PM
ldap-abook unable to get street name in ldap-entry Jingle Linux - Software 1 06-06-2004 07:13 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 01:08 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration