Here, how i proceed exactly to set up my ldap/autofs conf :
# rm -Rf /usr/local # ln -s /net/local /usr/local # apt-get install libpam-ldapd libnss-ldapd auth-client-config autofs5-ldap nfs-kernel-server
Editer /etc/ldap/ldap.conf ____________________________________________________________________________________________ BASE dc=dc1,dc=dc2,dc=dc3 URI ldaps:/1.1.1.1/ # TLS certificates (needed for GnuTLS) TLS_CACERT /etc/ssl/certs/ca-certificates.crt ____________________________________________________________________________________________
# service nscd restart
Editer /etc/nslcd.conf ____________________________________________________________________________________________ uid nslcd gid nslcd uri ldaps://1.1.1.1 base dc=dc1,dc=dc2,dc=dc3 ldap_version 3 ssl on tls_reqcert allow tls_cacertfile /etc/ssl/ldap-cacert.pem nss_initgroups_ignoreusers avahi,avahi-autoipd,backup,bin,colord,daemon,games,gnats,hplip,irc,kernoops,libuuid,lightdm,list,lp,mail,man,messagebus,news,proxy,pulse,root,rtkit,saned,speech-dispatcher,sshd,sync,sys,syslog,usbmux,uucp,whoopsie,www-data ____________________________________________________________________________________________
Creer /etc/ssl/ldap-cacert.pem ____________________________________________________________________________________________ -----BEGIN CERTIFICATE----- xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx -----END CERTIFICATE----- ____________________________________________________________________________________________
Editer /etc/nsswitch.conf ____________________________________________________________________________________________ passwd: compat ldap group: compat ldap shadow: compat ldap
hosts: files mdns4_minimal [NOTFOUND=return] dns networks: files
protocols: db files services: db files ethers: db files rpc: db files
netgroup: files ldap automount: files ldap ____________________________________________________________________________________________
Autofs
# mkdir /etc/auto.master.d # echo "+auto.home" > /etc/auto.master.d/home # echo "local -fstype=nfs4,ro,proto=tcp,port=2049 serveur_nfs1:/bin" > /etc/auto.master.d/net # echo "commun -fstype=nfs4,rw,soft,intr server_nfs2:/home/commun" >> /etc/auto.master.d/net # echo "/auto_home /etc/auto.master.d/home --timeout=10" > /etc/auto.master.d/home.autofs # echo "/net /etc/auto.master.d/net --timeout=10"> /etc/auto.master.d/net.autofs
Editer /etc/default/autofs ____________________________________________________________________________________________ MASTER_MAP_NAME="/etc/auto.master" TIMEOUT=300 BROWSE_MODE="no" LOGGING="none" LDAP_URI="ldap://10.6.200.209" SEARCH_BASE="dc=info-ufr,dc=univ-montp2,dc=fr" MAP_OBJECT_CLASS="nisMap" ENTRY_OBJECT_CLASS="nisObject" MAP_ATTRIBUTE="nisMapName" ENTRY_ATTRIBUTE="cn" VALUE_ATTRIBUTE="nisMapEntry" ____________________________________________________________________________________________
Editer /etc/default/nfs-common ____________________________________________________________________________________________ NEED_STATD= STATDOPTS= NEED_GSSD=no NEED_IDMAPD=yes ____________________________________________________________________________________________
Editer /etc/idmapd.conf ____________________________________________________________________________________________ [General] Verbosity = 0 Pipefs-Directory = /run/rpc_pipefs
Domain = rien
[Mapping] Nobody-User = nobody Nobody-Group = nogroup ____________________________________________________________________________________________
# echo "blacklist rpcsec_gss_krb5" >> /etc/modprobe.d/blacklist.conf
Here, how i proceed exactly to set up my ldap/autofs conf :
# rm -Rf /usr/local
# ln -s /net/local /usr/local
# apt-get install libpam-ldapd libnss-ldapd auth-client-config autofs5-ldap nfs-kernel-server
Editer /etc/ldap/ldap.conf _______ _______ _______ _______ _______ _______ _______ _______ _______ _______ _______ _______ _____ dc=dc2, dc=dc3 certs/ca- certificates. crt _______ _______ _______ _______ _______ _______ _______ _______ _______ _______ _______ _______ _____
___
BASE dc=dc1,
URI ldaps:/1.1.1.1/
# TLS certificates (needed for GnuTLS)
TLS_CACERT /etc/ssl/
___
# service nscd restart
Editer /etc/nslcd.conf _______ _______ _______ _______ _______ _______ _______ _______ _______ _______ _______ _______ _____ dc=dc2, dc=dc3 ldap-cacert. pem initgroups_ ignoreusers avahi,avahi- autoipd, backup, bin,colord, daemon, games,gnats, hplip,irc, kernoops, libuuid, lightdm, list,lp, mail,man, messagebus, news,proxy, pulse,root, rtkit,saned, speech- dispatcher, sshd,sync, sys,syslog, usbmux, uucp,whoopsie, www-data _______ _______ _______ _______ _______ _______ _______ _______ _______ _______ _______ _______ _____
___
uid nslcd
gid nslcd
uri ldaps://1.1.1.1
base dc=dc1,
ldap_version 3
ssl on
tls_reqcert allow
tls_cacertfile /etc/ssl/
nss_
___
Creer /etc/ssl/ ldap-cacert. pem _______ _______ _______ _______ _______ _______ _______ _______ _______ _______ _______ _______ _____ xxxxxxxxxxxxxxx xxxxxxxxxxxxxxx xxxxxxxx xxxxxxxxxxxxxxx xxxxxxxxxxxxxxx xxxxxxxx xxxxxxxxxxxxxxx xxxxxxxxxxxxxxx xxxxxxxx xxxxxxxxxxxxxxx xxxxxxxxxxxxxxx xxxxxxxx xxxxxxxxxxxxxxx xxxxxxxxxxxxxxx xxxxxxxx xxxxxxxxxxxxxxx xxxxxxxxxxxxxxx xxxxxxxx xxxxxxxxxxxxxxx xxxxxxxxxxxxxxx xxxxxxxx xxxxxxxxxxxxxxx xxxxxxxxxxxxxxx xxxxxxxx xxxxxxxxxxxxxxx xxxxxxxxxxxxxxx xxxxxxxx xxxxxxxxxxxxxxx xxxxxxxxxxxxxxx xxxxxxxx xxxxxxxxxxxxxxx xxxxxxxxxxxxxxx xxxxxxxx xxxxxxxxxxxxxxx xxxxxxxxxxxxxxx xxxxxxxx xxxxxxxxxxxxxxx xxxxxxxxxxxxxxx xxxxxxxx xxxxxxxxxxxxxxx xxxxxxxxxxxxxxx xxxxxxxx xxxxxxxxxxxxxxx xxxxxxxxxxxxxxx xxxxxxxx _______ _______ _______ _______ _______ _______ _______ _______ _______ _______ _______ _______ _____
___
-----BEGIN CERTIFICATE-----
xxxxxxxxxxx
xxxxxxxxxxx
xxxxxxxxxxx
xxxxxxxxxxx
xxxxxxxxxxx
xxxxxxxxxxx
xxxxxxxxxxx
xxxxxxxxxxx
xxxxxxxxxxx
xxxxxxxxxxx
xxxxxxxxxxx
xxxxxxxxxxx
xxxxxxxxxxx
xxxxxxxxxxx
xxxxxxxxxxx
-----END CERTIFICATE-----
___
Editer /etc/nsswitch.conf _______ _______ _______ _______ _______ _______ _______ _______ _______ _______ _______ _______ _____
___
passwd: compat ldap
group: compat ldap
shadow: compat ldap
hosts: files mdns4_minimal [NOTFOUND=return] dns
networks: files
protocols: db files
services: db files
ethers: db files
rpc: db files
netgroup: files ldap _______ _______ _______ _______ _______ _______ _______ _______ _______ _______ _______ _______ _____
automount: files ldap
___
Autofs
# mkdir /etc/auto.master.d master. d/home nfs4,ro, proto=tcp, port=2049 serveur_nfs1:/bin" > /etc/auto. master. d/net nfs4,rw, soft,intr server_ nfs2:/home/ commun" >> /etc/auto. master. d/net master. d/home --timeout=10" > /etc/auto. master. d/home. autofs master. d/net --timeout=10"> /etc/auto. master. d/net.autofs
# echo "+auto.home" > /etc/auto.
# echo "local -fstype=
# echo "commun -fstype=
# echo "/auto_home /etc/auto.
# echo "/net /etc/auto.
Editer /etc/default/autofs _______ _______ _______ _______ _______ _______ _______ _______ _______ _______ _______ _______ _____ MAP_NAME= "/etc/auto. master" MODE="no" URI="ldap: //10.6. 200.209" BASE="dc= info-ufr, dc=univ- montp2, dc=fr" OBJECT_ CLASS=" nisMap" OBJECT_ CLASS=" nisObject" ATTRIBUTE= "nisMapName" ATTRIBUTE= "cn" ATTRIBUTE= "nisMapEntry" _______ _______ _______ _______ _______ _______ _______ _______ _______ _______ _______ _______ _____
___
MASTER_
TIMEOUT=300
BROWSE_
LOGGING="none"
LDAP_
SEARCH_
MAP_
ENTRY_
MAP_
ENTRY_
VALUE_
___
Editer /etc/default/ nfs-common _______ _______ _______ _______ _______ _______ _______ _______ _______ _______ _______ _______ _____ _______ _______ _______ _______ _______ _______ _______ _______ _______ _______ _______ _______ _____
___
NEED_STATD=
STATDOPTS=
NEED_GSSD=no
NEED_IDMAPD=yes
___
Editer /etc/idmapd.conf _______ _______ _______ _______ _______ _______ _______ _______ _______ _______ _______ _______ _____ Directory = /run/rpc_pipefs
___
[General]
Verbosity = 0
Pipefs-
Domain = rien
[Mapping] _______ _______ _______ _______ _______ _______ _______ _______ _______ _______ _______ _______ _____
Nobody-User = nobody
Nobody-Group = nogroup
___
# echo "blacklist rpcsec_gss_krb5" >> /etc/modprobe. d/blacklist. conf