OpenLDAP com PHP LDAP Admin
Instalancao a partir do docker da imagem
docker pull wfp2002/openldap:latest
docker run -itd -p 8088:80 -p 389:389 --hostname server.ldap.com --name phpldapadmin
--env PHPLDAPADMIN_LDAP_HOSTS=localhost
--detach wfp2002/openldap:latest /bin/bash
Entrar no docker e digitar: service slapd start service apache2 start
acessar http://localhost:8088/phpldapadmin
FIMMMM
#######################################################
Instalacao passo a passo do zero
docker run -itd -p 8088:80 -p 389:389 --hostname server.ldap.com --name phpldapadmin
--env PHPLDAPADMIN_LDAP_HOSTS=localhost
--detach ubuntu:16.04 /bin/bash
apt-get update apt-get install -y slapd ldap-utils nano phpldapadmin apt-get clean
Editar arquivo nano /etc/ldap/ldap.conf
BASE dc=ldap,dc=com URI ldap://localhost:389
#SIZELIMIT 12 #TIMELIMIT 15 #DEREF never
TLS_CACERT /etc/ssl/certs/ca-certificates.crt
Salvar e sair
dpkg-reconfigure slapd
Omit OpenLDAP server configuration? [yes/no] no DNS domain name: ldap.com Organization name: ldap.com Database backend to use: 2 (HDB) Do you want the database to be removed when slapd is purged? [yes/no] yes Move old database? [yes/no] no Allow v2: yes
nano /etc/phpldapadmin/config.php
Colar o seguinte arquivo
############################################################
custom->debug['level'] = 0; $config->custom->debug['syslog'] = true; # $config->custom->debug['file'] = '/tmp/pla_debug.log'; /** * The phpLDAPadmin config file * See: http://phpldapadmin.sourceforge.net/wiki/index.php/Config.php */ /* The temporary storage directory where we will put jpegPhoto data This directory must be readable and writable by your web server. */ $config->custom->jpeg['tmpdir'] = '/var/www/tmp'; /* phpLDAPadmin can encrypt the content of sensitive cookies if you set this to a big random string. */ /* * Autogenerated value will be automatically added by phpldapadmin/startup.sh */ $config->custom->session['blowfish'] = 'TiVdfQH[Y%S]d0Ig X%ki+H8t?(]cs6XavhE]xpqaoFto8)ka}vvFl Yy8._sC:l'; /********************************************* * Appearance * *********************************************/ /* Hide the warnings for invalid objectClasses/attributes in templates. */ $config->custom->appearance['hide_template_warning'] = true; /********************************************* * User-friendly attribute translation * *********************************************/ /* Use this array to map attribute names to user friendly names. For example, if you don't want to see "facsimileTelephoneNumber" but rather "Fax". */ // $config->custom->appearance['friendly_attrs'] = array(); $config->custom->appearance['friendly_attrs'] = array( 'facsimileTelephoneNumber' => 'Fax', 'gid' => 'Group', 'mail' => 'Email', 'telephoneNumber' => 'Telephone', 'uid' => 'User Name', 'userPassword' => 'Password' ); /********************************************* * Define your LDAP servers in this section * *********************************************/ $servers = new Datastore(); /* * Autogenerated servers variables will come here */ $servers->newServer('ldap_pla'); $servers->setValue('server','name','WFP LDAP'); $servers->setValue('server','host','localhost'); $servers->setValue('server','base',array('dc=ldap,dc=com')); $servers->setValue('login','bind_id','cn=admin,dc=ldap,dc=com'); ?>############################################################
Sair e Salvar
service slapd restart service apache2 restart
** Apos restartar ou desligar o container é necessario subir o servico do SLAD service slapd start
Criando usuario no LDAP
create ne entry Generic Organization Unit (Sales) Commit
Sales Create new child Generic posix group (sales-group) Commit
Sales
Configurando AD LDAP no nextCloud Entrar em APPS bunlde... E ativar o LDAP/AD pois nao vem como padrao.
Apos ativar ir em settings / LDAP AD Preencher as seguintes infos:
Server: ldap://192.168.6.181 (IP DA LAN DO HOST)
DN: cn=admin,dc=ldap,dc=com Pass: 16 so (SAVE CREDENTIALS)
Detect Base DN: cn=sales-group,ou=sales,dc=ldap,dc=com *** Nome sales-group criado acima no LDAP.
TESTAR e dar NEXT
Only these object classes: InetOrgPerson, posixAccount, top Ldap Filter (|(objectclass=inetOrgPerson)(objectclass=posixAccount)(objectclass=top))
NEXT
Selecionar todas opcoes LDAP Query (&(|(objectclass=inetOrgPerson)(objectclass=posixAccount)(objectclass=top))(|(cn=%uid)(|(mailPrimaryAddress=%uid)(mail=%uid))(|(cn=%uid)(gidNumber=%uid)(objectClass=%uid))))
NEXT -> Groups
Only these object classes: posxixGroup , top Only from these groups: sales-group
Ldap Query (&(|(objectclass=posixGroup)(objectclass=top))(|(cn=sales-group)))
Para acessar o nextcloud agora pode-se usar o cn, uid ou email criado no LDAP. No phpldapadmin, pode entrar no usuario e adcionar mais campos como email, ou mesmo dar um "add value" no nome e criar um alias, como uma abreviacao, que servira pra entrar tambem.
Para ver os dados pode digitar: ldapsearch -x no servidor ldap e ver os nomes.
Content type
Image
Digest
Size
111.1 MB
Last updated
over 8 years ago
docker pull wfp2002/openldap