Using the LDAP plugin available for PAM, it’s possible to do LDAP authentication without joining the domain. Note however that this requires installing Identity Management for Unix on your domain controllers.
Before we proceed, it’s a good idea to take a snapshot.
Now edit /etc/nslcd.conf. # nslcd configuration file.
In /etc/pam.d/common-session, add the following at the bottom of the file. This will make home directories for users that have never logged in before. Be careful - mis-editing PAM configuration could permanently lock you out of your system!
This umask will prevent users from reading each others’ home directories. You can test this out by restarting sshd (service ssh restart) or by rebooting.
OpenLDAP is an implementation of the LDAP protocol; in other words, it is a special-purpose database designed for storing directories.
In the most common use case, using an LDAP server allows centralizing management of user accounts and the related permissions.
Moreover, an LDAP database is easily replicated, which allows setting up multiple synchronized LDAP servers.
LDAP data is structured and hierarchical.
The structure is defined by “schemas” which describe the kind of objects that the database can store, with a list of all their possible attributes.
11.7.1. The slapd package contains the OpenLDAP server.
Installing slapd usually asks only for the administrator's password and the resulting database is unlikely to suit your needs.
Omit OpenLDAP server configuration? Do you want the database to be removed when slapd is purged? No.
Move old database? This question is only asked when the configuration is attempted while a database already exists.
11.7.2. The migrate_all_online.sh asks a few questions about the LDAP database into which the data is to be migrated.
Tabela 11.1.
You might notice that we extend the PERL5LIB variable.
This is due to Debian bug report #982666.
Also note the use of the -c option to the ldapadd command; this option requests that processing doesn't stop in case of error.
11.7.3. Now the LDAP database contains some useful information, the time has come to make use of this data.
11.7.3.1. The NSS system (Name Service Switch, see sidebar GOING FURTHER NSS and system databases) is a modular system designed to define or fetch information for system directories.
Using LDAP as a source of data for NSS requires installing the libnss-ldap package.
Tabela 11.2. Configuring the libnss-ldap package:
| Question | Answer |
|---|---|
| LDAP server URI (Uniform Resource Identifier) | ldapi://ldap.falcot.com |
| Distinguished name of the search base | dc=falcot,dc=com |
| LDAP version to use | 3 |
| LDAP account for root | cn=admin,dc=falcot,dc=com |
| LDAP root account password | the administrative password |
| Allow LDAP admin account behave like local root? |
The /etc/nsswitch.conf file then needs to be modified, so as to configure NSS to use the freshly-installed ldap module.
Przykład 11.23.
# consult DNS first, we will need it to resolve the LDAP host.
# gethostbyname().
# here, so we can't do much here.
The ldap module is usually inserted before others, and it will therefore be queried first.
The notable exception is the hosts service since contacting the LDAP server requires consulting DNS first (to resolve ldap.falcot.com).
U mnie jest taka, działająca konfiguracja.
Jeśli chodzi o nsswitch.conf, to dla każdej bazy (passwd, group itp.), powinieneś mieć wyłącznie po jednym wierszu który może zawierać kila źródeł (np. compat ldap).
Z konfiguracją PAM, to już musisz wg własnych potrzeb (np. że przy logowaniu najpierw odpytuje kerberosem o użytkoniwka, a jeśli nie ma takiego użytkownika to sprawdza w passwd) - instalując dodatkowe moduły PAM, przeważnie instalator dodaje wpisy dla nich w systemie.
Jeśli chodzi o graficzne narzędzia, to nie wiem, nie korzystałem.
Czy Samba jest potrzebana?
Służy ona do zarządzania kontem komputera, tzn. Ok to może po koleji.
11.7.3.2. The LDAP module for PAM is provided by the libpam-ldap package.
Installing this package asks a few questions very similar to those in libnss-ldap; some configuration parameters (such as the URI for the LDAP server) are even actually shared with the libnss-ldap package.
Tabela 11.3. Configuration of libpam-ldap
| Question | Answer |
|---|---|
| Allow LDAP admin account to behave like local root? | Yes. |
Installing libpam-ldap automatically adapts the default PAM configuration defined in the /etc/pam.d/common-auth, /etc/pam.d/common-password and /etc/pam.d/common-account files.
This mechanism uses the dedicated pam-auth-update tool (provided by the libpam-runtime package).
pam_ldap.conf file.
provides.
the configuration file semantics of OpenLDAP.
space and any arguments.
connect to.
can be resolved without using LDAP.
specified, each separated by a space.
the LDAP server(s) to connect to.
respectively.
port number for the selected protocol is used if omitted.
Specifies the version of the LDAP protocol to use.
version must be 2 or 3.
server(s).
Specifies the cleartext credentials with which to bind.
only applicable when used with binddn above.
credential (anonymous bind).
above, except it applies when the effective user ID is zero.
Specifies the search scope (subtree, one level or base object).
Specifies the policy for dereferencing aliases.
Specifies the time limit (in seconds) to use when performing searches.
directory server.
timelimit and affects the initial server connection only.
have the underlying functionality necessary to support this option.
Specifies whether automatic referral chasing should be enabled.
select(2) system call when interrupted.
library.
library.
Specifies whether to use SSL/TLS or not (the default is not to).
over SSL.
when using SSL/TLS with the OpenLDAP client library.
it is "no", for OpenLDAP 2.1 and later it is "yes".
Specifies the ciphers to use for TLS.
assertion for retrieving a directory entry for a user's login name.
Specifies a filter to use when retrieving user information.
Specifies whether to search the root DSE for password policy.
logon authorization ("account" in the PAM stack).
not to.
The default is not to.
for logon authorization to succeed.
specifies the attribute containing the user's actual login name.
Specifies the password change protocol to use.
the userPassword value with the new cleartext password.
changed.
Specifies the SASL mechanism to use for PAM authentication.
SASL libraries be installed.
not present in LDAP.
pam_ldap module.
"required" for all accounts in the directory.
option.
contact the LDAP server.
11.7.3.3. By default, the LDAP protocol transits on the network as cleartext; this includes the (encrypted) passwords.
Since the encrypted passwords can be extracted from the network, they can be vulnerable to dictionary-type attacks.
11.7.3.3.1. The first step is to create a key pair (comprising a public key and a private key) for the LDAP server.
The Falcot administrators reuse easy-rsa to generate it (see Sekcja 10.2.2, „Public Key Infrastructure: easy-rsa”).
Running ./easyrsa build-server-full ldap.falcot.com nopass will ask you about the “common name”.
The slapd daemon also needs to be told to use these keys for encryption.
The LDAP server configuration is managed dynamically: the configuration can be updated with normal LDAP operations on the cn=config object hierarchy, and the server updates /etc/ldap/slapd.d in real time to make the configuration persistent.
Przykład 11.24.
The last step for enabling encryption involves changing the SLAPD_SERVICES variable in the /etc/default/slapd file.
Przykład 11.25.
The /etc/default/slapd file# Default location of the slapd.conf file or slapd.d cn=config directory.
# System account to run the slapd server under.
# System group to run the slapd server under.
# Path to the pid file of the slapd server.
# slapd normally serves ldap only on all TCP-ports 389.
# slapd (but stop will still work).
# work).
# keytab file (/etc/krb5.keytab).
11.7.3.3.2. LDAP clients also need to be able to authenticate the server.
In an X.509 public key infrastructure, public certificates are signed by the key of a certificate authority (CA).
With easy-rsa, the Falcot administrators have created their own CA and they now need to configure the system to trust the signatures of Falcot's CA.
Last but not least, the default LDAP URI and default base DN used by the various command line tools can be modified in /etc/ldap/ldap.conf.

This will make home directories for users that have never logged in before.
Be careful - mis-editing PAM configuration could permanently lock you out of your system!
This umask will prevent users from reading each others’ home directories.
You can test this out by restarting sshd (service ssh restart) or by rebooting.
Przykład 11.23.
# consult DNS first, we will need it to resolve the LDAP host.
# gethostbyname().
# here, so we can't do much here.
The ldap module is usually inserted before others, and it will therefore be queried first.
The notable exception is the hosts service since contacting the LDAP server requires consulting DNS first (to resolve ldap.falcot.com).
U mnie jest taka, działająca konfiguracja.
Jeśli chodzi o nsswitch.conf, to dla każdej bazy (passwd, group itp.), powinieneś mieć wyłącznie po jednym wierszu który może zawierać kila źródeł (np. compat ldap).
Z konfiguracją PAM, to już musisz wg własnych potrzeb (np. że przy logowaniu najpierw odpytuje kerberosem o użytkoniwka, a jeśli nie ma takiego użytkownika to sprawdza w passwd) - instalując dodatkowe moduły PAM, przeważnie instalator dodaje wpisy dla nich w systemie.
Ok to może po koleji.
tags: #ldap #pam #dla #poczatkujacych #debian
About the author