Browse Docs

๐Ÿ“– LDAP & Kerberos

Kerberos

1kinit <user>   # obtain a ticket.
2klist          # list the tickets in the cache.

Services

1systemctl status slapd   # OpenLDAP server.
2systemctl status sssd    # System Security Services Daemon.
1ldapsearch -x -h <ldap-host> -b "ou=People,dc=example,dc=com" uid=<user>

DN components:

  • cn : common name
  • ou : organizational unit
  • o : organization
  • c : country
  • dc : domain component

LDAP - add / modify

 1# LDIF = the commands between EOF
 2# -W prompts for the LDAP admin password
 3# -w passes the password (put it in a variable)
 4# bind_dn : the DN that acts as the LDAP bind user
 5
 6export bind_dn="CN=directory manager,DC=example,DC=org"
 7
 8# Modify an entry
 9ldapadd -W -D "$bind_dn" -h $ldap_server -p 389 <<EOT
10dn: cn=user,ou=wiki,dc=example,dc=com
11changetype: modify
12add: memberUid
13memberUid: $login
14EOT
15
16# Create a new entry
17ldapadd -w $LDAPpwd -D "$bind_dn" -h $ldap_server -p 389 <<EOT
18dn: uid=${login},ou=People,dc=example,dc=org
19uid: ${login}
20loginShell: /bin/bash
21uidNumber: ${uid}
22gidNumber: 47110
23homeDirectory: /home/${login}
24shadowLastChange: 0
25shadowMax: -1
26objectClass: account
27objectClass: posixaccount
28objectClass: shadowaccount
29objectClass: top
30gecos: ${gecos}
31cn: ${gecos}
32userPassword: {CRYPT}`perl -e 'print crypt("${login}", "${login}")'`
33EOT
Sunday, October 4, 2026 Tuesday, August 15, 2023