Académique Documents
Professionnel Documents
Culture Documents
www.emacs.com.ve
Pagina 1 de 17
2." Configuracion de Li!pa# ldap LDAP Server host * orinoco.emacs.com.ve < veri+icar :etc:hosts= D) * dc*emacs5dc*com 6ersion de LDAP a utili,ar * 7 9a&e local root Data#ase admin* ;es Data#ase require lo in in8 * )o >oot lo in account * cn*9ana er5dc*emacs5dc*com >oot lo in pass-ord * admin Local cr(pt to use -hen chan in pass-ords * ?cr(pt@ Paso ": A$ustes de per#isos % arc&ivos del siste#a LDAP ".1. Colocar per#isos de los arc&ivos A :etc:init.d:slapd stop A adduser ""s(stem "" roup ldap A vi :etc:de+ault:sdapd <asi nar los parametros SLAPDBCS'> ( SLAPDBD>OCP a EldapE= A cho-n "> ldap!ldap :var:li#:ldap A ch rp ldap :etc:ldap:sldapd.con+ A chmod 13%1 :etc:ldap:slapd.con+ A :etc:init.d:slapd start A ps "auF+- G rep ldap ".2. 'odificar el arc&ivo (etc(ldap(sldap.conf Se de#en a re ar o modi+icar los si uientes parametros
www.emacs.com.ve
Pagina 2 de 17
Para la clave de 9ana er es necesario eLecutar el si uiente comando! A sldappass-d "v "s admin "h ?C>;PM@
Paso ): Creacin de arc&ivos LDI*. 'n necesario modi+icar los parametros del archivo :etc:mi rateBcommon.ph de la si uiente manera! JD'NACLMB9AOLBDO9AO)* Eemacs.comEP JD'NACLMBQAS' * Edc*emacs5dc*comEP JD'NACLMB9AOLB.OSM* Eorinoco.emacs.com.veEP J'IM')D'DBSC.'9A */P A continuacin ha( que crear el o#Leto que a su ve, contendr el resto de los datos en el directorio. Denere un archivo #ase.ldi+ del si uiente modo! www.emacs.com.ve Pagina 3 de 17
Cna ve, entendido lo anterior5 se procede a insertar la in+ormacin enerada en el directorio utili,ando lo si uiente! ldapadd - . D /cn0'anager1 dc0e#acs1 dc0co#/ f !ase.ldif Cna ve, hecho lo anterior5 se podr comen,ar a po#lar el directorio con datos. Lo primero ser importar los rupos ( usuarios eFistentes en el sistema. >ealice la importacin de usuarios utili,ando los uiones correspondientes del si uiente modo! :usr:share:mi rationtools:mi rateB roup.pl :etc: roup roup.ldi+ :usr:share:mi rationtools:mi rateBpass-d.pl :etc:pass-d pass-d.ldi+ Lo anterior crear los +icheros roup.ldi+ ( pass-d.ldi+5 los cuales incluirn la in+ormacin de los rupos ( cuentas en el sistema5 inclu(endo las claves de acceso. Los datos se podrn insertar en el directorio LDAP utili,ando lo si uiente! ldapadd "F "R "D Scn*9ana er5 dc*emacs5 dc*comS "+ roup.ldi+ ldapadd "F "R "D Scn*9ana er5 dc*emacs5 dc*comS "+ pass-d.ldi+ Para los hosts de la red es! :usr:share:mi rationtools:mi rateBhosts.pl :etc:hosts hosts.ldi+ ldapadd "F "R "D Scn*9ana er5 dc*emacs5 dc*comS "+ hosts.ldi+
www.emacs.com.ve
Pagina 4 de 17
www.emacs.com.ve
Pagina de 17
Pro#ar con el comando! +in er EscastellanosE 0.$" 9odi+icar el archivo :etc:pam.d:common"account Aaccount account account required required su++icient pamBuniF.so pamBuniF.so tr(B+irstBpass pamBldap.so
0.7" 9odi+icar el archivo :etc:pam.d:common"auth Aauth required auth required auth su++icient pamBuniF.so nullo&Bsecure pamBuniF.so nullo&Bsecure useB+irstBpass pamBldap.so
0.%" 9odi+icar el archivo :etc:pam.d:common"pass-ord Apass-ord required pamBuniF.so nullo& o#scure min*% maF*4 mdH pass-ord required pamBuniF.so nullo& o#scure min*% maF*4 mdH useB+irstBpass www.emacs.com.ve Pagina ! de 17
3.8. 'odificar el arc&ivo (etc(pa#+ldap.conf host orinoco.emacs.com #ase dc*emacs5dc*com ldapBversion 7 root#inddn cn*mana er5dc*emacs5dc*ve port 742 3.2. 'odificar el arc&ivo (etc(li!nss ldap.conf host orinoco.emacs.com #ase dc*emacs5dc*com ldapBversion 7 root#inddn cn*mana er5dc*emacs5dc*ve port 742
Paso 9: Pro!ar autenticacin OpenLDAP. : su scastellanos Sin directorio5 entrando .O9'*: scastellanos@orinoco.emacsc.comJ pass-d 'nter lo in <LDAP= pass-ord! )e- pass-ord! >e"enter ne- pass-ord! Otra prue!a: Aapt" et install li#pam"dot+ile Jpamtest pass-d scastellanos Jpamtest ssh scastellanos www.emacs.com.ve Pagina 7 de 17
; reinicie slapd! A :etc:init.d:slapd restart 1.". Configuracin de Sa#!a A#rir el :etc:sam#a:sm#.con+ ( #uscar la linea! passd# #ac&end * td#sam uest 'sto de#e ser reempla,ado por las si uientes lineas! passd# #ac&end * ldapsam!ldap!::orinoco.emacs.com ldap su++iF * dc*emacs5dc*com www.emacs.com.ve Pagina " de 17
www.emacs.com.ve
Pagina # de 17
www.emacs.com.ve
Pagina 1$ de 17
# # # # # # # # # # # # # # # # # #
Sample configuration file for the Samba suite for Debian GNU/Linux. This is the main Samba configuration file. You should read the smb.conf !" manual page in order to understand the options listed here. Samba has a huge number of configurable options most of #hich are not sho#n in this example $n% line #hich starts #ith a & semi'colon" or a # hash" is a comment and is ignored. (n this example #e #ill use a # for commentar% and a & for parts of the config file that %ou ma% #ish to enable N)T*+ ,hene-er %ou modif% this file %ou should run the command .testparm. to chec/ that %ou ha-e not man% an% basic s%ntactic errors.
#00000000000000000000000 Global Settings 00000000000000000000000 # 1 1global2 ## 3ro#sing/(dentification ### # # 4hange this to the #or/group/NT'domain name %our Samba ser-er #ill part of workgroup = EMACS w # Netbios Name netbios name = ORINOCO n # ser-er string is the e5ui-alent of the NT Description field ser-er string 0 Samba'LD$6 # ,indo#s (nternet Name Ser-ing Support Section+ # ,(NS Support ' Tells the N73D component of Samba to enable its ,(NS Ser-er #ins support 0 no # ,(NS Ser-er ' Tells the N73D components of Samba to be a ,(NS 4lient # Note+ Samba can be either a ,(NS Ser-er8 or a ,(NS 4lient8 but N)T both
www.emacs.com.ve
Pagina 12 de 17
# This #ill pre-ent nmbd to search for Net3()S names through DNS. dns prox% 0 no # ,hat naming ser-ice and in #hat order should #e use to resol-e host names # to (6 addresses name resol-e order 0 lmhosts host #ins bcast #### Debugging/$ccounting #### # # This tells Samba to use a separate log file for each machine # that connects log file 0 /-ar/log/samba/log.:m # 6ut a capping on the si9e of the log files max log si9e 0 <=== in ;b".
# (f %ou #ant Samba to onl% log through s%slog then set the follo#ing # parameter to >%es>. s%slog onl% 0 no # ,e #ant Samba to log a minimum amount of information to s%slog. *-er%thing # should go to /-ar/log/samba/log.?smbd8nmbd@ instead. (f %ou #ant to log # through s%slog %ou should set the follo#ing parameter to something higher. s%slog 0 = # Do something sensible #hen Samba crashes+ mail the admin a bac/trace panic action 0 /usr/share/samba/panic'action :d ####### Authentication ####### # # # # # .securit% 0 user. is al#a%s a good idea. This #ill re5uire a Unix account in this ser-er for e-er% user accessing the ser-er. See /usr/share/doc/samba'doc/htmldocs/Ser-erT%pe.html in the samba'doc pac/age for details. security = user s
# You ma% #ish to use pass#ord encr%ption. See the section on # >encr%pt pass#ords> in the smb.conf !" manpage before enabling. encr%pt pass#ords 0 true # (f %ou are using encr%pted pass#ords8 Samba #ill need to /no# #hat # pass#ord database t%pe %ou are using. passdb backend = p dapsam! dap!""#$%&'&'&#
www.emacs.com.ve
Pagina 13 de 17
###### CON(I)*RACION +E +OMINIO ###### # os le-el 0 I= preferred master 0 %es domain master 0 %es oca master = yes domain ogons = yes d admin users 0 administrator8acastillo &enable pri-ileges 0 %es & logon path 0 FF:LFprofilesF:u logon dri-e 0 J+ logon home 0 FF:LFF:uF.profile logon script 0 template shell 0/bin/bash add user script 0 /usr/sbin/smbldap'useradd.pl '# :u a
www.emacs.com.ve
Pagina 14 de 17
# The follo#ing parameter is useful onl% if %ou ha-e the linpopup pac/age # installed. The samba maintainer and the linpopup maintainer are # #or/ing to ease installation and configuration of linpopup and samba. & message command 0 /bin/sh 'c >/usr/bin/linpopup .:f. .:m. :s& rm :s> P # Domain 7aster specifies Samba to be the Domain 7aster 3ro#ser. (f this # machine #ill be configured as a 3D4 a secondar% logon ser-er"8 %ou
www.emacs.com.ve
Pagina 1 de 17
www.emacs.com.ve
Pagina 1! de 17
www.emacs.com.ve
Pagina 17 de 17