<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://systems.nic.uoregon.edu/internal-wiki/index.php?action=history&amp;feed=atom&amp;title=Procedure%3ANew_LDAP_Client</id>
	<title>Procedure:New LDAP Client - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://systems.nic.uoregon.edu/internal-wiki/index.php?action=history&amp;feed=atom&amp;title=Procedure%3ANew_LDAP_Client"/>
	<link rel="alternate" type="text/html" href="https://systems.nic.uoregon.edu/internal-wiki/index.php?title=Procedure:New_LDAP_Client&amp;action=history"/>
	<updated>2026-08-19T03:16:11Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.39.12</generator>
	<entry>
		<id>https://systems.nic.uoregon.edu/internal-wiki/index.php?title=Procedure:New_LDAP_Client&amp;diff=3344&amp;oldid=prev</id>
		<title>Nic-wiki: /* Replace /etc/ldap.conf */</title>
		<link rel="alternate" type="text/html" href="https://systems.nic.uoregon.edu/internal-wiki/index.php?title=Procedure:New_LDAP_Client&amp;diff=3344&amp;oldid=prev"/>
		<updated>2022-02-04T23:23:51Z</updated>

		<summary type="html">&lt;p&gt;&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;Replace /etc/ldap.conf&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 23:23, 4 February 2022&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l28&quot;&gt;Line 28:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 28:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;cat &amp;lt;&amp;lt;EOF &amp;gt;/etc/ldap.conf&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;cat &amp;lt;&amp;lt;EOF &amp;gt;/etc/ldap.conf&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;binddn cn=anonymous,dc=nic,dc=uoregon,dc=edu&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;binddn cn=anonymous,dc=nic,dc=uoregon,dc=edu&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;bindpw &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;cVx75!#L&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;bindpw &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;________&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;pam_check_host_attr yes&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;pam_check_host_attr yes&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;scope sub&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;scope sub&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Nic-wiki</name></author>
	</entry>
	<entry>
		<id>https://systems.nic.uoregon.edu/internal-wiki/index.php?title=Procedure:New_LDAP_Client&amp;diff=2726&amp;oldid=prev</id>
		<title>Brandond at 20:01, 13 April 2009</title>
		<link rel="alternate" type="text/html" href="https://systems.nic.uoregon.edu/internal-wiki/index.php?title=Procedure:New_LDAP_Client&amp;diff=2726&amp;oldid=prev"/>
		<updated>2009-04-13T20:01:45Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;This page documents the steps necessary to add a new client that will use LDAP accounts and mount the shared home directories over NFS.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Host Setup Steps ==&lt;br /&gt;
&lt;br /&gt;
These steps are valid for Red Hat 4.x and 5.x systems, Red Hat and derivatives such as CentOS, Scientific Linux, and Rocks.&lt;br /&gt;
* For other Linux distributions, follow the AutoFS sections of this page, as well as the [[Procedures:New_LDAP_Client/Manual_Setup|Manual Setup steps]].&lt;br /&gt;
* For Solaris , see [[Procedures:New_LDAP_Client/Solaris_10_Setup|Solaris 10 steps]].&lt;br /&gt;
* For AIX 5.3, see [[Procedures:New_LDAP_Client/AIX_5.3_Setup|AIX 5.3 Setup steps]].&lt;br /&gt;
* AIX 5.2 and earlier hosts do not support OpenLDAP, but can still mount NFS. See the [[Procedures:New_LDAP_Client/AIX_5.2_Setup|AIX 5.2 Setup steps]], and the [[Procedures:New_User/AIX|AIX User Creation Proceedure]] for user synchronization steps.&lt;br /&gt;
&lt;br /&gt;
== Prerequisites ==&lt;br /&gt;
&lt;br /&gt;
Make sure the following requirements are met on the new system:&lt;br /&gt;
&lt;br /&gt;
* Packages&lt;br /&gt;
** autofs&lt;br /&gt;
** pam_ldap&lt;br /&gt;
** nss_ldap&lt;br /&gt;
** authconfig&lt;br /&gt;
** openldap-clients&lt;br /&gt;
* Network&lt;br /&gt;
** On Storage Network (172.17.x.x IP address)&lt;br /&gt;
** 9000 byte MTU Jumbo frames (for best performance; [[Procedures:New_LDAP_Client#Create_Netapp_AutoFS_map_file|see note below]])&lt;br /&gt;
&lt;br /&gt;
=== Replace /etc/ldap.conf ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
cat &amp;lt;&amp;lt;EOF &amp;gt;/etc/ldap.conf&lt;br /&gt;
binddn cn=anonymous,dc=nic,dc=uoregon,dc=edu&lt;br /&gt;
bindpw cVx75!#L&lt;br /&gt;
pam_check_host_attr yes&lt;br /&gt;
scope sub&lt;br /&gt;
nss_base_passwd ou=people,dc=nic,dc=uoregon,dc=edu?one&lt;br /&gt;
nss_base_shadow ou=people,dc=nic,dc=uoregon,dc=edu?one&lt;br /&gt;
nss_base_group  ou=group,dc=nic,dc=uoregon,dc=edu?one&lt;br /&gt;
tls_checkpeer no&lt;br /&gt;
EOF&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Replace /etc/openldap/ldap.conf ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
cat &amp;lt;&amp;lt;EOF &amp;gt;/etc/openldap/ldap.conf&lt;br /&gt;
TLS_CHECKPEER no&lt;br /&gt;
EOF&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Netapp AutoFS map file ===&lt;br /&gt;
''' Note:''' If your host does not support jumbo frames, replace 'udp' in these lines with 'tcp', or filesystem operations on NFS paths may fail.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
cat &amp;lt;&amp;lt;EOF &amp;gt;/etc/auto.netapp&lt;br /&gt;
home       -fstype=nfs,hard,intr,async,rsize=32768,wsize=32768,nfsvers=3,udp     172.17.8.63:/vol/home&lt;br /&gt;
home1      -fstype=nfs,hard,intr,async,rsize=32768,wsize=32768,nfsvers=3,udp     172.17.8.63:/vol/home1&lt;br /&gt;
home2      -fstype=nfs,hard,intr,async,rsize=32768,wsize=32768,nfsvers=3,udp     172.17.8.64:/vol/home2&lt;br /&gt;
research   -fstype=nfs,hard,intr,async,rsize=32768,wsize=32768,nfsvers=3,udp     172.17.8.64:/vol/research&lt;br /&gt;
packages   -fstype=nfs,hard,intr,async,rsize=32768,wsize=32768,nfsvers=3,udp     172.17.8.64:/vol/packages/ARCH&lt;br /&gt;
EOF&lt;br /&gt;
sed -i -e &amp;quot;s/ARCH/`uname -i`/&amp;quot; /etc/auto.netapp&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Append Netapp maps to AutoFS master map ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
cat &amp;lt;&amp;lt;EOF &amp;gt;&amp;gt;/etc/auto.master&lt;br /&gt;
/mnt/netapp     /etc/auto.netapp        --timeout=1200 --ghost&lt;br /&gt;
EOF&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable Netapp mounts and add path links ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service autofs reload&lt;br /&gt;
ln -sf /mnt/netapp/packages/ /usr/local/packages&lt;br /&gt;
ln -sf /mnt/netapp/home/users/ /home/users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable LDAP authentication ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
authconfig --update --enablecache --enablepamaccess \&lt;br /&gt;
           --enableldap --enableldapauth --enableldapssl \&lt;br /&gt;
           --ldapbasedn=dc=nic,dc=uoregon,dc=edu \&lt;br /&gt;
           --ldaploadcacert=http://systems.nic.uoregon.edu/ca/NIC-cacert.pem \&lt;br /&gt;
           --ldapserver=172.17.202.25,172.17.8.66&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Test Configuration ===&lt;br /&gt;
If everything is set up right, you should be able to run the following commands, and see some output without any errors or hanging:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
getent passwd chemadmin&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ls -la /mnt/netapp/home&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== LDAP Setup Steps ==&lt;br /&gt;
In order to enable granular host access control, you must also log into the [https://systems.nic.uoregon.edu/slam/ NIC user control panel], go to the 'Manage Hosts' section, and add an entry for the new system.&lt;br /&gt;
&lt;br /&gt;
The 'Host FQDN' field should match the results of the 'hostname' command when run on the new host. The 'Display Name' field is optional, and is only used when informing the user what hosts they are allowed to log in to, in place of the FQDN. After the host has been added, you may select the entry, click the 'Edit Selected' button, and select which users are allowed to log into the host.&lt;br /&gt;
&lt;br /&gt;
'''Note:''' The functionality of this feature depends on the host's LDAP libraries honoring the 'pam_check_host_attr' option. If it does not, any user with an LDAP account will be able to log in. &lt;br /&gt;
&lt;br /&gt;
[[Category:Proceedure]]&lt;/div&gt;</summary>
		<author><name>Brandond</name></author>
	</entry>
</feed>