{"id":42,"date":"2011-02-14T16:09:35","date_gmt":"2011-02-14T16:09:35","guid":{"rendered":"http:\/\/www.salsaunited.net\/blog\/?p=42"},"modified":"2012-06-14T08:22:50","modified_gmt":"2012-06-14T12:22:50","slug":"rhel6-as-ldap-client","status":"publish","type":"post","link":"https:\/\/blog.domb.net\/?p=42","title":{"rendered":"RHEL6 as LDAP client with ldap authentication"},"content":{"rendered":"<p>Edit the file \/etc\/openldap\/ldap.conf<\/p>\n<p>URI ldap:\/\/$FQDN_OF_SERVER\/ (has to be the same fqdn as in the certificate)<br \/>\nBASE dc=mydomain,dc=com<br \/>\nTLS_CACERTDIR \/etc\/openldap\/cacerts<\/p>\n<p>now edit the \/etc\/nsswitch.conf file to tell linux where to get the login information from:<\/p>\n<p>passwd:\u00a0\u00a0\u00a0\u00a0 files sss <strong>ldap<\/strong><br \/>\nshadow:\u00a0\u00a0\u00a0\u00a0 files sss <strong>ldap<\/strong><br \/>\ngroup:\u00a0\u00a0\u00a0\u00a0\u00a0 files sss<strong> ldap<\/strong><\/p>\n<p>After that run the command authconfig-gtk<\/p>\n<p>Select:<\/p>\n<p>User Account Database: ldap<br \/>\nLdap base search DN: dc=domain,dc=com<br \/>\nldap server: FQDN of ldap Server<br \/>\nCheck the Box use TLS encryption<br \/>\nAdd the correct url\u00a0 which points to the ladpcertificate.pem file. Normally this file is located on a webserver (https:\/\/internal.webserver.com\/ladpcertificate.pem<br \/>\nAuthentication configuration: ldap<\/p>\n<p>If you want to create directly a new home directory for the new user you can go to the advanced tab and check the box &#8220;Create Home directories on first login&#8221;<\/p>\n<p>reboot<\/p>\n<p>Now you are done with the authentication part.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Edit the file \/etc\/openldap\/ldap.conf URI ldap:\/\/$FQDN_OF_SERVER\/ (has to be the same fqdn as in the certificate) BASE dc=mydomain,dc=com TLS_CACERTDIR \/etc\/openldap\/cacerts now edit the \/etc\/nsswitch.conf file to tell linux where to get the login information from: passwd:\u00a0\u00a0\u00a0\u00a0 files sss ldap shadow:\u00a0\u00a0\u00a0\u00a0 files sss ldap group:\u00a0\u00a0\u00a0\u00a0\u00a0 files sss ldap After that run the command authconfig-gtk Select: User&#8230;<\/p>\n","protected":false},"author":2,"featured_media":162,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_themeisle_gutenberg_block_has_review":false,"footnotes":""},"categories":[3],"tags":[],"class_list":["post-42","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-linux"],"_links":{"self":[{"href":"https:\/\/blog.domb.net\/index.php?rest_route=\/wp\/v2\/posts\/42","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.domb.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.domb.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.domb.net\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.domb.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=42"}],"version-history":[{"count":2,"href":"https:\/\/blog.domb.net\/index.php?rest_route=\/wp\/v2\/posts\/42\/revisions"}],"predecessor-version":[{"id":251,"href":"https:\/\/blog.domb.net\/index.php?rest_route=\/wp\/v2\/posts\/42\/revisions\/251"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.domb.net\/index.php?rest_route=\/wp\/v2\/media\/162"}],"wp:attachment":[{"href":"https:\/\/blog.domb.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=42"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.domb.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=42"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.domb.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=42"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}