Sign inSign up

circutor/ldapserver-iberdrola

By circutor

•Updated over 2 years ago

Image
0

342

circutor/ldapserver-iberdrola repository overview

⁠USE OF THIS DOCKER

This docker launches a LDAP Server that emulates Iberdrola LDAP Server.

  • To launch a container of it:
sudo docker run -d -it --name=ldapServerContainer -h iberdrola.es -p 389:389 -p 636:636 --restart unless-stopped circutor/ldapserver-iberdrola

where the LDAP Server port #389 is mapped to the one of the computer where the container is being executed. This will be used for plain-text LDAP connections and for those upgraded to encryption by calling StartTLS() method. Port #636 for LDAPs using SSL is mapped too, although not used in our case.

  • Get inside the container and load the default groups and users configured in internal files groupsCncIberdrola.ldif and usersCncIberdrola.ldif.
sudo docker exec -it ldapServerContainer /bin/bash
ldapadd -x -D cn=admin,dc=iberdrola,dc=es -w Adm1n -f groupsCncIberdrola.ldif
ldapadd -x -D cn=admin,dc=iberdrola,dc=es -w Adm1n -f usersCncIberdrola.ldif
  • Apply certificates to the server to enable LDAPs functionality (TLS on port #389):
cd ~
ldapmodify -H ldapi:// -Y EXTERNAL -f addcerts.ldif
  • If needed, new users can be added using ldapadd. To reconfigure a user, search it (ldapsearch), delete it (ldapdelete) and send (ldapadd) its new configuration in a .ldif file.
ldapsearch -x -b "uid=U000001,ou=usuarios,dc=iberdrola,dc=es" -s sub "objectclass=*"
ldapdelete -v -c -D "cn=admin,dc=iberdrola,dc=es" -w Adm1n "uid=U000001,ou=usuarios,dc=iberdrola,dc=es"
ldapadd -x -D cn=admin,dc=iberdrola,dc=es -w Adm1n -f newConfigUser01.ldif

⁠CREATION OF THIS DOCKER

The steps followed to create this docker are listed below.

  1. Download ubuntu docker image:
sudo docker pull ubuntu
  1. Run a container of it in background and interactive mode, so as to be able to get inside it during its execution:
sudo docker run -d -it --name=ldapServer -h iberdrola.es -p 389:389 -p 636:636 ubuntu

If conflict using any of these ports arises, it's because there is another slapd server using it. Show list of processes, kill those using the affected port and re-execute run command:

sudo lsof -i -P -n | grep #Port NumberInConflict# 
kill -9 #ID_Process#
  1. Disable policy against executions inside the container; otherwise, the next instructions to launch the LDAP Server will not launch it:
sudo docker exec -it ldapServer /bin/bash
printf '#!/bin/sh\nexit 0' > /usr/sbin/policy-rc.d
chmod +x /usr/sbin/policy-rc.d
exit
  1. Install slapd utilities in the container (this must be done from outside it). Use password Adm1n when requested:
sudo docker exec -it ldapServer bash -c "apt-get update && apt-get install ldap-utils slapd"
  1. Get inside the container:
sudo docker exec -it ldapServer /bin/bash
  1. Once inside it, configure the LDAP Server inside the container following the steps listed in here⁠ (sections Installing OpenLDAP on Linux and Configuring the root user).
  • Configure the LDAP Server administrator:
dpkg-reconfigure slapd
	--> In the Console that pops-up, select:
		- Omit OpneLDAP server configuration? --> No
		- DNS domain name: iberdrola.es
		- Organization name: Iberdrola
		- Administrator pwd: Adm1n
		- Do you want the database to be removed when slapd is purged? --> Yes 
		- ... move the old database files out of the way before creating a new database? --> Yes
  • Encrypt password "Adm1n" for root user. A SSHA is generated, e.g: {SSHA}7r2LpWe3Eg3n3X8YcU49Yb6tx93rd8nz :
slappasswd
  • Install nano editor and set the server basic configuration: the BASE DN (Distinguished name), which is the base for the Server Active Directory, and the URI, which is the IP address used to connect to the server.
apt-get install nano
nano /etc/ldap/ldap.conf

BASE    dc=iberdrola,dc=es
URI     ldap://iberdrola.es
  • Create file rootpw.ldif with the content below and apply it to the LDAP Server to modify the root password.
nano rootpw.ldif

dn: olcDatabase={0}config,cn=config
changetype: modify
add: olcRootPW
olcRootPW: {SSHA}7r2LpWe3Eg3n3X8YcU49Yb6tx93rd8nz
ldapadd -Y EXTERNAL -H ldapi:/// -f rootpw.ldif
  • Import the basic general LDAP schemas:
ldapadd -Y EXTERNAL -H ldapi:/// -f /etc/ldap/schema/cosine.ldif
ldapadd -Y EXTERNAL -H ldapi:/// -f /etc/ldap/schema/nis.ldif
ldapadd -Y EXTERNAL -H ldapi:/// -f /etc/ldap/schema/inetorgperson.ldif
ldapadd -Y EXTERNAL -H ldapi:/// -f /etc/ldap/schema/openldap.ldif
ldapadd -Y EXTERNAL -H ldapi:/// -f /etc/ldap/schema/dyngroup.ldif
  • Check name of mdb.ldif file in the server (should be olcDatabase={1}mdb.ldif or olcDatabase={2}mdb.ldif):
ls /etc/ldap/slapd.d/cn\=config/ 
  • Create and apply file manager.ldif to set the IBERDROLA domain (dc=iberdrola.es) and configure its administrator credentials: username=admin and pwd=Adm1n (use mdb.ldif filename found previously). Here is where the Binding credentials are configured (LdapBindUser: "cn=admin,dc=iberdrola,dc=es", LdapBindPass: "Adm1n"):
nano manager.ldif

dn: olcDatabase={1}mdb,cn=config
changetype: modify
replace: olcSuffix
olcSuffix: dc=iberdrola,dc=es

dn: olcDatabase={1}mdb,cn=config
changetype: modify
replace: olcRootDN
olcRootDN: cn=admin,dc=iberdrola,dc=es

dn: olcDatabase={1}mdb,cn=config
changetype: modify
replace: olcRootPW
olcRootPW: {SSHA}7r2LpWe3Eg3n3X8YcU49Yb6tx93rd8nz
ldapmodify -Y EXTERNAL -H ldapi:/// -f manager.ldif
  • Create IBERDROLA schema and apply it to the LDAP Server. Caution!: Be sure not to let unnecessary spaces or tabs in the content of this file; otherwise the file transfer will fail.
nano schemaCncIberdrola.ldif

dn: cn=iberdrola,cn=schema,cn=config
objectClass: olcSchemaConfig
cn: iberdrola
olcAttributeTypes: ( 1.3.6.1.4.1.6863.2.3.110
  NAME 'apellidos'
  SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{256}
  )
olcAttributeTypes: ( 1.3.6.1.4.1.6863.2.3.112
  NAME 'perfil-fw'
  SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{256}
  )
olcAttributeTypes: ( 1.3.6.1.4.1.6863.2.3.113
  NAME 'bloqueo-clave'
  SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{256}
  )
olcAttributeTypes: ( 1.3.6.1.4.1.6863.2.3.114
  NAME 'fech-modif-clave'
  SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{256}
  )
olcAttributeTypes: ( 1.3.6.1.4.1.6863.2.3.115
  NAME 'correo'
  SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{256}
  )
olcAttributeTypes: ( 1.3.6.1.4.1.6863.2.3.118
  NAME 'nombre'
  SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{256}
  )
olcAttributeTypes: ( 1.3.6.1.4.1.6863.2.3.119
  NAME 'perfil-usu'
  SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{256}
  )
olcAttributeTypes: ( 1.3.6.1.4.1.6863.2.3.120
  NAME 'perfil-cat1'
  SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{256}
  )
olcAttributeTypes: ( 1.3.6.1.4.1.6863.2.3.121
  NAME 'perfil-cat2'
  SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{256}
  )
olcAttributeTypes: ( 1.3.6.1.4.1.6863.2.3.122
  NAME 'perfil-cat3'
  SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{256}
  )
olcAttributeTypes: ( 1.3.6.1.4.1.6863.2.3.123
  NAME 'perfil-cat4'
  SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{256}
  )
olcAttributeTypes: ( 1.3.6.1.4.1.6863.2.3.124
  NAME 'perfil-cat5'
  SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{256}
  )
olcAttributeTypes: ( 1.3.6.1.4.1.6863.2.3.125
  NAME 'perfil-cat6'
  SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{256}
  )	
olcAttributeTypes: ( 1.3.6.1.4.1.6863.2.3.126
  NAME 'perfil-cat7'
  SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{256}
  )
olcAttributeTypes: ( 1.3.6.1.4.1.6863.2.3.127
  NAME 'perfil-cat8'
  SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{256}
  )
olcObjectClasses: ( 1.3.6.1.4.1.6863.2.4.59 NAME 'equiposCTstar'
  DESC 'Equipos CT Star'
  SUP top AUXILIARY 
  MUST ( perfil-usu $ perfil-cat1 $ perfil-cat2 $ perfil-cat3 $ perfil-cat4 $ perfil-cat5 $ perfil-cat6 $ perfil-cat7 $ perfil-cat8 )
  )
olcObjectClasses: ( 1.3.6.1.4.1.6863.2.4.57 NAME 'usuarioIberdrola'
  DESC 'Usuario Iberdrola'
  SUP top AUXILIARY
  MUST ( apellidos $ userPassword $ uid $ bloqueo-clave $ fech-modif-clave $ correo $ nombre )
  MAY perfil-fw
  )
ldapadd -Y EXTERNAL -H ldapi:/// -f schemaCncIberdrola.ldif
  • If after applying the schema, new attributes or objectClasses need to be added, add them one by one, e.g.:
nano addObjectClassToschema.ldif

dn: cn=iberdrola,cn=schema,cn=config
objectClass: olcSchemaConfig
cn: iberdrola
olcObjectClasses: ( 1.3.6.1.4.1.6863.2.4.57 NAME 'usuarioIberdrola'
  DESC 'Usuario Iberdrola'
  SUP top AUXILIARY
  MUST ( apellidos $ userPassword $ uid $ bloqueo-clave $ fech-modif-clave $ correo $ nombre )
  MAY perfil-fw
  )
ldapadd -Y EXTERNAL -H ldapi:/// -f addObjectClassToschema.ldif
  • Create Server Domain and Administrator Roles and apply it to the server:
nano iberdrolaAdminRoles.ldif
                                                                                
dn: dc=iberdrola,dc=es
objectClass: domain
objectClass: top
dc: iberdrola

dn: cn=admin,dc=iberdrola,dc=es
objectClass: organizationalRole
cn: admin
description: Iberdrola LDAP server administrator
ldapadd -x -D cn=admin,dc=iberdrola,dc=es -w Adm1n -f iberdrolaAdminRoles.ldif
  • Create file with IBERDROLA groups configuration. Don't apply it yet to the LDAP Server:
nano groupsCncIberdrola.ldif

dn: ou=usuarios,dc=iberdrola,dc=es
objectclass: top
objectclass: organizationalUnit
ou: usuarios
description: Container for user entries

dn: ou=grupos,dc=iberdrola,dc=es
objectclass: top
objectclass: organizationalUnit
ou: grupos
description: Container for user entries
  • Create file with default IBERDROLA users. Don't apply it yet to the LDAP Server. NOTE: In this file, user U000001 has pwd = Adm1n01 and U000002 has pwd = Adm1n02:
nano usersCncIberdrola.ldif

dn: uid=U000001,ou=usuarios,dc=iberdrola,dc=es
objectClass: organizationalRole
objectClass: usuarioIberdrola
objectClass: equiposCTstar
cn: U000001
apellidos: Apellido1 Apellido2
userPassword: {SSHA}Odu01lI+PpiF4mPKWw6cov7618ujVVbx
uid: U000001
bloqueo-clave: N
fech-modif-clave: 20090529
correo: [email protected]
nombre: Nombre1
perfil-usu: ADMINISTRACION
perfil-cat1: NORTE
perfil-cat2: FABRICANTE1
perfil-cat3: EXPLOTACION
perfil-cat4: INTEGRADOR1
perfil-cat5: CONCENTRADOR
perfil-cat6: ALL
perfil-cat7: ALL
perfil-cat8: ALL

dn: uid=U000002,ou=usuarios,dc=iberdrola,dc=es
objectClass: organizationalRole
objectClass: usuarioIberdrola
objectClass: equiposCTstar
cn: U000002
apellidos: Apellido1 Apellido2
userPassword: {SSHA}Vd3kvUtjRnSj3raKKARVqRsozZq9f632
uid: U000002
bloqueo-clave: N
fech-modif-clave: 20090529
correo: [email protected]
nombre: Nombre2
perfil-usu: VISUALIZACION
perfil-cat1: ALL
perfil-cat1: NORTE
perfil-cat1: NOROESTE
perfil-cat1: MADRID
perfil-cat1: CENTRO
perfil-cat1: ESTE_NORTE
perfil-cat1: ESTE_SUR
perfil-cat2: ALL
perfil-cat2: FABRICANTE1
perfil-cat2: FABRICANTE2
perfil-cat2: FABRICANTE3
perfil-cat3: ALL
perfil-cat3: EXPLOTACION
perfil-cat3: PST_SERVICIO
perfil-cat4: ALL
perfil-cat4: INTEGRADOR1
perfil-cat4: INTEGRADOR2
perfil-cat4: INTEGRADOR3
perfil-cat5: ALL
perfil-cat5: REMOTA
perfil-cat5: CONCENTRADOR
perfil-cat5: CARGADOR
perfil-cat6: ALL
perfil-cat7: ALL
perfil-cat8: ALL

  1. Add encryption tools and create certificates needed to enable StartTLS over port #389, following steps in here⁠ (sections Install the SSL Components to Configure OpenLDAP to Use the Certificate and Keys).
  • Install SSL Components:
apt-get install gnutls-bin ssl-cert
  • Create the Certificate Templates to configure the certificate authority CA (and use it to sign keys) and the certificate for the server.
mkdir /etc/ssl/templates
nano /etc/ssl/templates/ca_server.conf

cn = LDAP Server CA
ca
cert_signing_key
nano /etc/ssl/templates/ldap_server.conf

organization = "Iberdrola"
cn = iberdrola.es
tls_www_server
encryption_key
signing_key
expiration_days = 18250
  • Create the Certificate Authority CA Key and Certificate.
certtool -p --outfile /etc/ssl/private/ca_server.key
certtool -s --load-privkey /etc/ssl/private/ca_server.key --template /etc/ssl/templates/ca_server.conf --outfile /etc/ssl/certs/ca_server.pem
  • Create LDAP Server Key and Certificate.
certtool -p --sec-param high --outfile /etc/ssl/private/ldap_server.key
certtool -c --load-privkey /etc/ssl/private/ldap_server.key --load-ca-certificate /etc/ssl/certs/ca_server.pem --load-ca-privkey /etc/ssl/private/ca_server.key --template /etc/ssl/templates/ldap_server.conf --outfile /etc/ssl/certs/ldap_server.pem
  • We now have all of the certificates and keys we need. However, our OpenLDAP process is unable to access its own key. Solve it by adding the user our OpenLDAP process runs under (openldap) to the already existing group "ssl-cert", which is the group-owner of the "/etc/ssl/private directory":
usermod -aG ssl-cert openldap
chown :ssl-cert /etc/ssl/private/ldap_server.key
chmod 640 /etc/ssl/private/ldap_server.key
  • Create file to configure the OpenLDAP to use the Certificate and Keys:
cd ~
nano addcerts.ldif

dn: cn=config
changetype: modify
add: olcTLSCACertificateFile
olcTLSCACertificateFile: /etc/ssl/certs/ca_server.pem
-
add: olcTLSCertificateFile
olcTLSCertificateFile: /etc/ssl/certs/ldap_server.pem
-
add: olcTLSCertificateKeyFile
olcTLSCertificateKeyFile: /etc/ssl/private/ldap_server.key
  • Once everything is configured in the container ldapServer, get out of it:
exit
  1. Create a new docker image (ldapserver-iberdrola) from the ubuntu-based container (ldapServer) that has just been configured as Iberdrola LDAP Server:
sudo docker container commit -a "Circutor" -m "Ldap Server emulating Iberdrola's one" ldapServer ldapserver-iberdrola
--> where:  
	- "Circutor": the author
	- "ldapServer": the container we want to export as a new docker image
	- "ldapserver-iberdrola": the name of the docker image we want to create

9. Image ldapserver-iberdrola holds the whole IBERDROLA LDAP Server configuration, but their containers DON'T launch the LDAP Server AUTOMATICALLY! An auto-executable docker image (circutor/ldapserver-iberdrola) derived from image ldapserver-iberdrola must be created. To do so, follow these steps:

  • Create a folder, e.g. imageFolder
  • Being inside this folder, create a Dockerfile that will invoke script.sh as soon as a container of image circutor/ldapserver-iberdrola is started. The container will have the whole configuration and files created in steps #6 and #7, but needs this script to launch the LDAP Server automatically:
nano script.sh

#!/bin/bash
# start-ldap.sh
service slapd start
# Wait for slapd to fully start
sleep 10
# Keep the container running
tail -f /dev/null
nano Dockerfile

FROM ldapserver-iberdrola
COPY script.sh /script.sh
RUN chmod +x /script.sh
ENTRYPOINT ["/script.sh"]
  • Being still inside folder imageFolder, create image circutor/ldapserver-iberdrola:
sudo docker build . -t circutor/ldapserver-iberdrola
  • Launch a container ldapServerContainer of it to start an auto-executable Iberdrola LDAP Server:
sudo docker stop ldapServer
sudo docker run -d -it --name=ldapServerContainer -h iberdrola.es -p 389:389 -p 636:636 --restart unless-stopped circutor/ldapserver-iberdrola
  • Get inside ldapServerContainer and apply the IBERDROLA Groups and the Users configured previously in groupsCncIberdrola.ldif and usersCncIberdrola.ldif:
sudo docker exec -it ldapServerContainer /bin/bash 
ldapadd -x -D cn=admin,dc=iberdrola,dc=es -w Adm1n -f groupsCncIberdrola.ldif
ldapadd -x -D cn=admin,dc=iberdrola,dc=es -w Adm1n -f usersCncIberdrola.ldif
  • Apply certificates to the server to enable LDAPs functionality (TLS on port #389):
cd ~
ldapmodify -H ldapi:// -Y EXTERNAL -f addcerts.ldif

The IBERDROLA LDAP Server is now RUNNING!!

Tag summary

Content type

Image

Digest

sha256:619aa4194…

Size

78.2 MB

Last updated

over 2 years ago

docker pull circutor/ldapserver-iberdrola