dockerhub_bitnami/openldap
github_wheelybird/ldap-user-manager
้ฒๅ
ฅlocalhost:8080/setup
OpenLDAPๅพ2.3็้ๅงๆน็จdynamic runtime configuration engine
้่ฆไปฅldapmodify
, ldapdelete
, ldapadd
็ๆนๅผไพไฟฎๆน๏ผ็ดๆฅไปฅๆๅไฟฎๆน็่ฉฑ๏ผๅฐฑ่ฆ็จslapadd
ๅslapmodify
่ๅฒๅญ็ๆชๆกๆๅจ/slapd.d
๏ผไธ่ฝ็ดๆฅไฟฎๆน้ๅ่ณๆๅคพๅ
ง็ๆชๆก๏ผๅฆๅcheckSumๆไธ็ธ็ฌฆ่ๅฐ่ด้ฏ่ชค
้ๅๆนๅไน่ฎๆๅๅฏไปฅไธ็จ้ๅslapdไพApplyๆดๅ็Config๏ผๆนๆๅ ๅฎ็พฉไธๅLDIFๆชๆก๏ผๅจ้้ๆไปค่ฎๆดLDAPไธ็Config
Slapd็configurationๆๅๅฎ็พฉๅฅฝ็ๆถๆงๅDIT(Dictionary Information Tree)
LDAP็configuration root ๅซๅcn=config
๏ผๅ
ๅซ่global configuration
LDAP Databaseๆฏ็กๅบ็๏ผๅ ๆญคๅจConfigๆๆๅ{n}๏ผ็จไพไปฃ่กจ่จญๅฎDatabase็้ ๅบ๏ผ้ๅ้ ๅบๆฏ่ชๅ็ข็็
ๅคง้จๅ็ attributes and objectClasses ้ฝๆๆolc
็prefix
ๆฏๅargument็จ็ฉบ็ฝๅ้๏ผๅฆๆๆargumentๆฏๆ็ฉบๆ ผ็๏ผ้ฃ่ฆไฝฟ็จ้ๅผ่ๅ
่ตทไพ๏ผ"like this"
้ฆๅ
่ฆๅ
ๆพๅฐ่ชฐๆๆฌ้ๅฏไปฅไฟฎๆน๏ผ็ฑๆผๆๆฏไฝฟ็จbitnami/openldap๏ผไป็configไฝๆผ/bitnami/openldap/slapd.d/cn=config
cat olcDatabase\=\{0\}config.ldif
ๅฏไปฅ็ๅฐๅชๆuid=1001ๅฏไปฅ็ทจ่ผฏ๏ผไฝๆฏgid=0๏ผ้ไปฃ่กจไป็Groupๆฏroot
ไธ่ฌ็Openldap้ฝๆฏๅ
่จฑuid=0,gid=0็userๅฏไปฅไฟฎๆน๏ผไฝๆฏๅ ็บ้ๆฏbitnami/openldap๏ผ่docker exec -it openldap bash
ๅพ๏ผๆ็ผ็พ็ฌฆๅไธ่ฟฐ็้ๆฑ
้ๆๅๅท่กldapmodify -Y EXTERNAL -H ldapi:///
ๅฐฑๅฏไปฅ่ผธๅ
ฅๆณไฟฎๆน็ldif
ๅ
งๅฎน
ldapsearch -Y EXTERNAL -H ldapi:/// -b "dc=google,dc=org" "(uid=*)"
ๆๅฐๆๆไฝฟ็จ่
ldapdelete -x -D "cn=admin,dc=google,dc=org" -W -H ldapi:/// "cn=user02,ou=users,dc=google,dc=org"
ๅช้คไฝฟ็จ่
#
้้ ญๆ่ขซ่พจ่ญ็บ่จป่งฃ
้้ ญ่ฅๆ็ฉบๆ ผๆ่ขซ่พจ่ญ็บไธไธ่ก
ๆฏๅEntityไฝฟ็จ็ฉบ็ฝ่กไพๅๅ
ๅ ไธ%admins ALL=(ALL) ALL
admins
็บๅจLdapๆๅฎ็็พค็ตๅ็จฑ
ๅฐๆService
nscd.service
้ๆฐไปฅui่จญๅฎ
dpkg-reconfigure libnss-ldapd
/etc/nsswitch.conf
ๅฐๆService
nslcd.service
้ๆฐไปฅui่จญๅฎ
dpkg-reconfigure nslcd
/etc/nslcd.conf
LDAP Debugๅทฅๅ
ท
ldap.conf /etc/ldap/ldap.conf
่ฎUserไฝฟ็จssh็ปๅ ฅๆ๏ผ็ขบ่ชๆฏๅฆ็ฌฆๅๆๅฎ็Group๏ผ็ฌฆๅๅพ็ตฆไบ้ๅUser docker group
addDocker.sh
ๅ
ๆๆพๅฐไปปๆๆๅฎไฝ็ฝฎ๏ผ้้ๆฏๆพๅจ/etc/security
ๅจ/etc/pam.d/sshd
ๅขๅ auth [default=ignore] pam_exec.so seteuid /etc/security/smmsDocker.sh
ๅฆๆญคไธไพๆฏๆฌกssh็ปๅ
ฅๆ้ฝๆ่ทaddDocker.sh
๏ผไพๆชขๆฅๆฏๅฆ็ตฆไบdocker group