小实验:
Server端:
1 yuminstall openldap-servers openldap openldap-clients migrationtools
2 >=6.2 cp /usr/share/openldap-servers/slap*/etc/openldap/slapd.conf
rootpw string(slappasswd)
password-hash{CRYPT}
3 cp/usr/share/openldap-servers/DB_CONFIG.example /var/lib/ldap/DB_CONFIG
slaptest-u -f /etc/openldap/slapd.conf -F /etc/openldap/slapd.d
useradd ldapuser1
passwd ldapuser1
useraddldapuser2
passwd ldapuser2
4 vim/usr/share/migrationtools/migrate_common.ph
$DEFAULT_MAIL_DOMAIN= "my-domain.com";
$DEFAULT_BASE= "dc=my-domain,dc=com";
5 /usr/share/migrationtools/migrate_passwd.pl/etc/passwd > /etc/openldap/user.ldif
/usr/share/migrationtools/migrate_group.pl/etc/group > /etc/openldap/group.ldif
vim/etc/openldap/base.ldif
dn:dc=my-domain,dc=com
dc:my-domain
objectClass:top
objectClass:domain
dn:ou=People,dc=my-domain,dc=com
ou:People
objectClass:top
objectClass:organizationalUnit
dn:ou=Group,dc=my-domain,dc=com
ou:Group
objectClass:top
objectClass:organizationalUnit
6 slapadd-vl base.ldif
slapadd-vl user.ldif
slapadd-vl group.ldif
7 chown-R ldap:ldap /var/lib/ldap
8 serviceslapd start
9 tcp389 iptables
ldap client
1 yuminstall openldap openldap-clients nss-pam-ldapd nscd pam_ldap
2 vim/etc/nslcd.conf
uri ldap://192.168.1.3/
base dc=my-domain,dc=com
servicenslcd start
chkconfig
3
/etc/nsswitch.conf
passwd: files ldap
shadow: files ldap
group: files ldap
测试:su – ldapuser1
NfS 自动挂载:
1. vim /etc/exports
/home 192.168.0.0/24(rw,no_root_squash)
vim /etc/sysconfig/nfs
MOUNTD_PORT=892
STATD_PORT=662
LOCKD_TCPPORT=32803
LOCKD_UDPPORT=32769
2. 启动服务 nfs nfslock
3. Iptables 增添10个端口 : tcp/udp 111、2049、892、662
tcp 32803 udp:32769
4、 vim /etc/auto.mister
/home /etc/auto.home
vim/etc/auto.home
* -rw,soft,initr 192.168.0.250:/home/&
service autofsstop
service autofsstart
测试:
su –ldapuser1
pwd
df