Re: OGo and openldap
baptiste daroussin <[email protected]>
| Newsgroups | gmane.comp.cms.opengroupware.discuss.general |
|---|---|
| Message-ID | <1063983712.2088.1.camel@localhost> |
Thanks, it helps me a lot. Now it work for postfix+courier-imap+OGo+ldap, but not for samba (I'm using the "standard" samba system for the moment. Le jeu 18/09/2003 à 00:28, Jonathon Sim a écrit : > On Thursday 18 September 2003 05:21, Benjamin Long wrote: > > I also want to have ogo use openLDAP for auth. To be honest, I've not been > > able to completely wrap my brain around LDAP. The Samba server at the > > office here use LDAP for auth, but as far as I can tell the passwords are > > held in a different attribute (ntPassword) from the system level passwords > > (userPassword). I'm really not sure how ogo would be able to look into > > ntPassword to auth. If anyone can enlighten me (us?) about this, it would > > be most appreciated. > > > Samba is something of a special case : Samba/Windows passwords are different > (and incompatible) with most other Unix password schemes, so Samba stores > them in a different attribute. FYI Ogo uses userPassword > > Anyway, here at least is what I have done to get Ogo and Ldap working > together: > 1/ Download http://www.iit.edu/~gawojar/ldap/ : its a graphical LDAP > browser/editor (Java based) and although I love the command-line as much as > the next Linux geek, sometimes you really need to see what you are doing. > 2/ Add some people. Ogo seems to use something like the fairly standard > InetOrgPerson schema (or somesuch thing : I don't think Ogo obsesses over > schemas: so long as there is a userPassword, Ogo seems to handle it). But > since the whole point of LDAP is integration, what schema you use depends on > what else your integrating with. > > FYI: this works for me (try editing it and importing it as LDIF (then changing > the password) using eg the LDAP browser/editor above) and it integrates with > Unix accounts, which lots of other stuff also integrates with: > > dn: uid=user,ou=People,o=YourOrganisation,dc=yourdomain,dc=com > objectClass: inetOrgPerson > objectClass: posixAccount > objectClass: shadowAccount > uid: user > givenName: Some Random > sn: User > loginShell: /bin/bash > uidNumber: 1001 > gidNumber: 100 > mail: [email protected] > homeDirectory: /home/randomuser > userPassword: aa0y959N2nSV6 > cn: Some Random User > > NB: Ogo seems able to populate some of the account properties from LDAP: eg > it seems to find the email above : I wonder what other properties it can get > from LDAP?? > > NNB: its a good idea to either to create an LDAP record for "root" (and then > NOT use that as the system's root user): or even better to change the uid of > "root" before switching over to LDAP to that of one of your ordinary users. > Otherwise you won't be able to log in as the administrator. > > 3/ Set the appropriate Ogo defaults (in NSGlobalDomain ) / > LSAuthLDAPServer = ldap1.yourdomain.com; > LSAuthLDAPServerRoot="ou=People,o=YourOrganisation,dc=yourdomain,dc=com"; > > Restart ogo, and log in using your LDAP users and passwords! > -- > Jonathon Sim <[email protected]> Developer/Network Administrator@Zeald Ltd > JabberID: [email protected] > -- -- baptiste daroussin <[email protected]> -- OpenGroupware.org Discussion [email protected] http://mail.opengroupware.org/mailman/listinfo/discuss