Slack00
(usa Slackware)
Enviado em 03/03/2015 - 10:53h
Bom Dia Galera estou com um problema ao migrar o meu ldap para outro servidor [SO Slackware 14.1].
acontece que ele funciona [eu consigo inicializa-lo], executo o comando ldapsearch -xLL ele me trás todos usuários, no meu SO ja configurei o nss_ldap porem quando executo o comando id usuario_cadastrado_no_ldap ele demora e me retona um erro e no log do ldap ele joga essa mensagem .:
=> ldap_bv2dn(cn=nssuser,dc=tntedu,dc=com,dc=br,0)
<= ldap_bv2dn(cn=nssuser,dc=tntedu,dc=com,dc=br)=0
=> ldap_dn2bv(272)
<= ldap_dn2bv(cn=nssuser,dc=tntedu,dc=com,dc=br)=0
=> ldap_dn2bv(272)
<= ldap_dn2bv(cn=nssuser,dc=tntedu,dc=com,dc=br)=0
54f5d5c0 send_ldap_result: err=53 matched="" text="unauthenticated bind (DN with no password) disallowed"
segue abaixo a configuração do meu slapd.conf.:
#
# Definicoes de ObjectClass e Attributes
#
include /etc/openldap/schema/core.schema
include /etc/openldap/schema/cosine.schema
include /etc/openldap/schema/inetorgperson.schema
include /etc/openldap/schema/nis.schema
include /etc/openldap/schema/openldap.schema
include /etc/openldap/schema/samba.schema
#include /etc/openldap/schema/qmail.schema
#
# Local de armazenamento dos dados de PID e afins
#
pidfile /var/run/slapd.pid
argsfile /var/run/slapd.args
#
# Parametros para fazer o ldappasswd gerar hashes no formato Crypt/MD5
#
password-hash {CRYPT}
password-crypt-salt-format "$1$%.8s"
#
# Permitir que clients mais antigos consigam se conectar ao servidor
#
#allow bind_v2
access to attrs=userPassword
by self write
by dn="cn=nssuser,dc=tntedu,dc=com,dc=br" read
by anonymous auth
access to attrs=sambaLMPassword,sambaNTPassword
by self write
by anonymous auth
access to *
by * read
#
# Tipo de backend que o OpenLDAP vai usar. Por padrao, eh bdb (Berkeley DB) no OpenLDAP 2.1.x
#
database bdb
suffix "dc=tntedu,dc=com,dc=br"
rootdn "cn=Manager,dc=tntedu,dc=com,dc=br"
rootpw {SSHA}SHEaO7FG7Z5TE/JhvAnhGAFL70vhEWBF
directory /home/openldap-data
#
# Indices pra agilizar a pesquisa
#
#index objectClass eq
#index uid eq
#index gidNumber eq
#index uidNumber eq
# para samba e qmail
index objectClass,uidNumber,gidNumber eq
index cn,sn,uid,displayName pres,sub,eq
#index memberUid,mail,mailAlternateAddress,givenname,accountStatus,mailHost,deliveryMode eq
#index memberUid,mail,givenname eq
index memberUid eq
index sambaSID,sambaPrimaryGroupSID,sambaDomainName eq
index default sub
Alguêm poderia ajudar?