亚洲av成人无遮挡网站在线观看,少妇性bbb搡bbb爽爽爽,亚洲av日韩精品久久久久久,兔费看少妇性l交大片免费,无码少妇一区二区三区

  免費(fèi)注冊 查看新帖 |

Chinaunix

  平臺 論壇 博客 文庫
最近訪問板塊 發(fā)新帖
查看: 3791 | 回復(fù): 3
打印 上一主題 下一主題

[ldap] kerberos+ldap配置問題求解! [復(fù)制鏈接]

論壇徽章:
0
跳轉(zhuǎn)到指定樓層
1 [收藏(0)] [報(bào)告]
發(fā)表于 2012-11-12 00:33 |只看該作者 |倒序?yàn)g覽
各位大牛,小弟剛接觸ldap,想存儲(chǔ)kerberos用戶,配置好后用kerberos無法寫入數(shù)據(jù)到ldap,求解!!部分配置如下

sldap.conf:

database        bdb
suffix          "dc=example,dc=com"
rootdn          "cn=admin,dc=example,dc=com"
rootpw          123456
directory       /var/lib/ldap
index krbPrincipalName                  eq,pres,sub



krb5.conf:

[logging]
default = FILE:/var/log/krb5libs.log
kdc = FILE:/var/log/krb5kdc.log
admin_server = FILE:/var/log/kadmind.log

[libdefaults]
default_realm = EXAMPLE.COM
dns_lookup_realm = false
dns_lookup_kdc = false
ticket_lifetime = 24h
forwardable = yes

[realms]
EXAMPLE.COM = {
  kdc = kerberos.example.com:88
  admin_server = kerberos.example.com:749
  default_domain = example.com
  database_module = openldap_ldapconf
}

[domain_realm]
.example.com = EXAMPLE.COM
example.com = EXAMPLE.COM

[appdefaults]
pam = {
   debug = false
   ticket_lifetime = 36000
   renew_lifetime = 36000
   forwardable = true
   krb4_convert = false
}

[dbdefaults]
ldap_kerberos_container_dn = ou=krb5,dc=example,dc=com

[dbmodules]
openldap_ldapconf = {
  db_library = kldap
  ldap_kerberos_container_dn = ou=krb5,dc=example,dc=com
  ldap_kdc_dn = "cn=admin,ou=krb5,dc=example,dc=com"
  ldap_kadmind_dn = "cn=admin,ou=krb5,dc=example,dc=com"
  ldap_service_password_file = /etc/kerberos/service.keyfile
  ldap_servers = ldap://test2.example.com
  ldap_conns_per_server = 5
}


啟動(dòng)都是正常的,kdc上也能看數(shù)據(jù):
kadmin.local      
Authenticating as principal root/admin@EXAMPLE.COM with password.
kadmin.local:  listprincs
K/M@EXAMPLE.COM
krbtgt/EXAMPLE.COM@EXAMPLE.COM
kadmin/admin@EXAMPLE.COM
kadmin/changepw@EXAMPLE.COM
kadmin/history@EXAMPLE.COM
kadmin/kerberos.example.com@EXAMPLE.COM
對應(yīng)ldap數(shù)據(jù):
# K/M@EXAMPLE.COM, EXAMPLE.COM, krb5, example.com
dn: krbPrincipalName=K/M@EXAMPLE.COM,cn=EXAMPLE.COM,ou=krb5,dc=example,dc=com
krbMaxTicketLife: 86400
krbMaxRenewableAge: 0
krbTicketFlags: 64
krbPrincipalName: K/M@EXAMPLE.COM
krbPrincipalExpiration: 19700101000000Z
krbPrincipalKey:: MF2gAwIBAaEDAgEBogMCAQGjAwIBAKRHMEUwQ6FBMD+gAwIBEKE4BDYYANNu
hVzHQ9szgEljpeeKj/uJR/pQncr1+ecYAtfAjfG7BCJG4+XGsyWLwscMORIfyHwc54g=
krbLastPwdChange: 19700101000000Z
krbExtraData:: AAJAFp9QZGJfY3JlYXRpb25ARVhBTVBMRS5DT00A
krbExtraData:: AAcBAAIAAisAAAAAAAA=
objectClass: krbPrincipal
objectClass: krbPrincipalAux
objectClass: krbTicketPolicyAux

# krbtgt/EXAMPLE.COM@EXAMPLE.COM, EXAMPLE.COM, krb5, example.com
dn: krbPrincipalName=krbtgt/EXAMPLE.COM@EXAMPLE.COM,cn=EXAMPLE.COM,ou=krb5,dc=
example,dc=com
krbMaxTicketLife: 86400
krbMaxRenewableAge: 0
krbTicketFlags: 0
krbPrincipalName: krbtgt/EXAMPLE.COM@EXAMPLE.COM
krbPrincipalExpiration: 19700101000000Z
krbPrincipalKey:: MIIBx6ADAgEBoQMCAQGiAwIBAaMDAgEApIIBrzCCAaswS6FJMEegAwIBEqFA
BD4gAEvL5fU71+daL5Lch4dlM9CeTi4iX0M42CQ6UI26ATmD+EnYyTXKaZFZYWWBrEN5kFPG+2Q+a
vD2TCZF6DA7oTkwN6ADAgERoTAELhAA/ua/8YOisdYlNOE6cdqWowJRo2Nd7poQDea7HaqbV4Fgta
86GVJbxCkVLzMwQ6FBMD+gAwIBEKE4BDYYAMN9uik6+ZNyT9pWgfunaCrpMlyH90Rm6VN0QxypoCe
+oYq0hHrQOizv0f6bvSu9vKVHnDUwO6E5MDegAwIBF6EwBC4QAMwVy0xujDDjpEQ1SbpDi0e6IqIr
jeTjlNm5ENC/uFuZKB/IxB6iKjf83nIdMDOhMTAvoAMCAQihKAQmCACfVSm2pdmQKZ7DqFgsPiBPK
YxWwk/K6S0LkuqRxXYncUpjdv8wM6ExMC+gAwIBA6EoBCYIAEP2dr89phY1mfD41nvHvUkDD8UFrK
QbMpOjkd99IhTfPeKK6DAzoTEwL6ADAgEBoSgEJggA0P7N6jKvlbMAzdjon4viOTH1cnwb7LlrMMY
M1DLnat39h+zS
krbLastPwdChange: 19700101000000Z
krbExtraData:: AAJAFp9QZGJfY3JlYXRpb25ARVhBTVBMRS5DT00A
krbExtraData:: AAcBAAIAAisAAAAAAAA=
objectClass: krbPrincipal
objectClass: krbPrincipalAux
objectClass: krbTicketPolicyAux

# kadmin/admin@EXAMPLE.COM, EXAMPLE.COM, krb5, example.com
dn: krbPrincipalName=kadmin/admin@EXAMPLE.COM,cn=EXAMPLE.COM,ou=krb5,dc=exampl
e,dc=com
krbMaxTicketLife: 10800
krbMaxRenewableAge: 0
krbTicketFlags: 4
krbPrincipalName: kadmin/admin@EXAMPLE.COM
krbPrincipalExpiration: 19700101000000Z
krbPrincipalKey:: MIIBx6ADAgEBoQMCAQGiAwIBAaMDAgEApIIBrzCCAaswS6FJMEegAwIBEqFA
BD4gAIBpXDcdZTiqatH7GYZ2mcYgKZsthhJpRVT2YaToRYXrTghzQH4LQBqWvYIWjXFtIJ+9KyPxo
yLL6k2dbTA7oTkwN6ADAgERoTAELhAAQ1R0GyYTM4zI0SxUMLNFFR4Ta6TKurAW7Owhi6N4x8msri
PJdGhvKHTpwbQwQ6FBMD+gAwIBEKE4BDYYAM3ngcn+OrlZk06fu6C5+/H+qyV5wASEo7f3EvAlMw4
wmB50p0iaMqpxW8adNOdWAEbInDAwO6E5MDegAwIBF6EwBC4QAPrQmtoN1uv/4VHSEiZueoAuH+9c
msJqtfRItb8uqMffu+hNrNjIt+3rwVFOMDOhMTAvoAMCAQihKAQmCAASoK0k9SSvHrBcEOMmvhZLu
ZllweiksfqcKlmqsczl3HmsWO0wM6ExMC+gAwIBA6EoBCYIAFWvQ8LXP4Rq/71mjo4XNbEVIrgiEn
8EH1Yrb1AiJGVKQ3Fp/TAzoTEwL6ADAgEBoSgEJggAk7RGY+GrgvcOj1o4O5854CZhnL/eCte4I/s
m4XWNXN0xeVWX
krbLastPwdChange: 19700101000000Z
krbExtraData:: AAJAFp9QZGJfY3JlYXRpb25ARVhBTVBMRS5DT00A
krbExtraData:: AAcBAAIAAisAAGlvbkA=
objectClass: krbPrincipal
objectClass: krbPrincipalAux
objectClass: krbTicketPolicyAux
...

但就是不能添加:
kadmin.local:  addprinc -x dn="uid=aaa,cn=EXAMPLE.COM,ou=krb5,dc=example,dc=com" aaa         
WARNING: no policy specified for aaa@EXAMPLE.COM; defaulting to no policy
Enter password for principal "aaa@EXAMPLE.COM":
Re-enter password for principal "aaa@EXAMPLE.COM":
add_principal: No such entry in the database while creating "aaa@EXAMPLE.COM".

報(bào)以上錯(cuò)誤,求各位不吝賜教

論壇徽章:
0
2 [報(bào)告]
發(fā)表于 2012-11-12 10:11 |只看該作者
自己頂~~~~

論壇徽章:
33
榮譽(yù)會(huì)員
日期:2011-11-23 16:44:17天秤座
日期:2014-08-26 16:18:20天秤座
日期:2014-08-29 10:12:18丑牛
日期:2014-08-29 16:06:45丑牛
日期:2014-09-03 10:28:58射手座
日期:2014-09-03 16:01:17寅虎
日期:2014-09-11 14:24:21天蝎座
日期:2014-09-17 08:33:55IT運(yùn)維版塊每日發(fā)帖之星
日期:2016-04-17 06:23:27操作系統(tǒng)版塊每日發(fā)帖之星
日期:2016-04-18 06:20:00IT運(yùn)維版塊每日發(fā)帖之星
日期:2016-04-24 06:20:0015-16賽季CBA聯(lián)賽之天津
日期:2016-05-06 12:46:59
3 [報(bào)告]
發(fā)表于 2012-11-12 11:24 |只看該作者
為啥要配置成 kerberos + ldap 呢?

你這個(gè)樣子的話, 直接搞一臺 Windows的 AD 不就行了?

論壇徽章:
0
4 [報(bào)告]
發(fā)表于 2012-11-12 11:48 |只看該作者
環(huán)境都是linux,木辦法
有哪位能解決不
您需要登錄后才可以回帖 登錄 | 注冊

本版積分規(guī)則 發(fā)表回復(fù)

  

北京盛拓優(yōu)訊信息技術(shù)有限公司. 版權(quán)所有 京ICP備16024965號-6 北京市公安局海淀分局網(wǎng)監(jiān)中心備案編號:11010802020122 niuxiaotong@pcpop.com 17352615567
未成年舉報(bào)專區(qū)
中國互聯(lián)網(wǎng)協(xié)會(huì)會(huì)員  聯(lián)系我們:huangweiwei@itpub.net
感謝所有關(guān)心和支持過ChinaUnix的朋友們 轉(zhuǎn)載本站內(nèi)容請注明原作者名及出處

清除 Cookies - ChinaUnix - Archiver - WAP - TOP