Différences
Ci-dessous, les différences entre deux révisions de la page.
| Les deux révisions précédentes Révision précédente Prochaine révision | Révision précédente | ||
| reserves:serveurs [2019/10/09 08:37] – [Installation avec montage NFS] chabrol | reserves:serveurs [2019/10/09 08:44] (Version actuelle) – [Installation avec montage NFS] chabrol | ||
|---|---|---|---|
| Ligne 3: | Ligne 3: | ||
| ===== Installation avec montage NFS ===== | ===== Installation avec montage NFS ===== | ||
| Permet de montage automatique de homedir depuis olympe, sous ubuntu 18 | Permet de montage automatique de homedir depuis olympe, sous ubuntu 18 | ||
| - | <code> | + | <Code> |
| sudo apt install ldap-utils autofs-ldap ldap-auth-client nscd libnss-ldapd libpam-ldapd libpam-mount | sudo apt install ldap-utils autofs-ldap ldap-auth-client nscd libnss-ldapd libpam-ldapd libpam-mount | ||
| - | </code> | + | </Code> |
| lors de la configuration de nslcd répondre : | lors de la configuration de nslcd répondre : | ||
| Ligne 32: | Ligne 32: | ||
| Puis configurer le LDAP pour NSS en lancant la commande suivante : | Puis configurer le LDAP pour NSS en lancant la commande suivante : | ||
| - | <code> | + | <Code> |
| sudo auth-client-config -t nss -p lac_ldap | sudo auth-client-config -t nss -p lac_ldap | ||
| - | </code> | + | </Code> |
| Configurer le LDAP pour l' | Configurer le LDAP pour l' | ||
| - | <code> | + | <Code> |
| sudo pam-auth-update | sudo pam-auth-update | ||
| - | </code> | + | </Code> |
| lors de la configuration de PAM | lors de la configuration de PAM | ||
| Profils PAM à activer : '' | Profils PAM à activer : '' | ||
| Mettre à jour le fichier ''/ | Mettre à jour le fichier ''/ | ||
| - | <code> | + | <Code> |
| # | # | ||
| # LDAP Defaults | # LDAP Defaults | ||
| Ligne 74: | Ligne 74: | ||
| nss_initgroups_ignoreusers avahi, | nss_initgroups_ignoreusers avahi, | ||
| - | </code> | + | </Code> |
| Mettre à jour le fichier ''/ | Mettre à jour le fichier ''/ | ||
| - | <code> | + | <Code> |
| # Init syatem options | # Init syatem options | ||
| # | # | ||
| Ligne 104: | Ligne 104: | ||
| # | # | ||
| # | # | ||
| - | </code> | + | </Code> |
| - | Mettre à jour le fichier / | + | Mettre à jour le fichier |
| - | <code> | + | <Code> |
| # | # | ||
| # Sample auto.master file | # Sample auto.master file | ||
| Ligne 136: | Ligne 136: | ||
| # | # | ||
| /home | /home | ||
| - | </ | + | </Code> |
| + | |||
| + | Modification du fichier ''/ | ||
| + | < | ||
| + | <?xml version=" | ||
| + | <!-- | ||
| + | This files contains a single entry with multiple attributes tied to it. | ||
| + | See autofs_ldap_auth.conf(5) for more information. | ||
| + | --> | ||
| + | |||
| + | < | ||
| + | usetls=" | ||
| + | tlsrequired=" | ||
| + | authrequired=" | ||
| + | /> | ||
| + | </ | ||
| + | |||
| + | Modification du fichier ''/ | ||
| + | < | ||
| + | #/ | ||
| + | # | ||
| + | # Example configuration of GNU Name Service Switch functionality. | ||
| + | # If you have the `glibc-doc-reference' | ||
| + | # `info libc "Name Service Switch"' | ||
| + | |||
| + | # pre_auth-client-config # passwd: | ||
| + | passwd: files ldap | ||
| + | # pre_auth-client-config # group: | ||
| + | group: files ldap | ||
| + | # pre_auth-client-config # shadow: | ||
| + | shadow: files ldap | ||
| + | gshadow: | ||
| + | |||
| + | hosts: | ||
| + | networks: | ||
| + | |||
| + | protocols: | ||
| + | services: | ||
| + | ethers: | ||
| + | rpc: db files | ||
| + | |||
| + | # pre_auth-client-config # netgroup: | ||
| + | netgroup: nis | ||
| + | |||
| + | automount: | ||
| + | </ | ||
| + | |||
| + | On exécute la commande '' | ||
| + | |||
| + | Modification du fichier ''/ | ||
| + | < | ||
| + | # / | ||
| + | # nslcd configuration file. See nslcd.conf(5) | ||
| + | # for details. | ||
| + | |||
| + | # The user and group nslcd should run as. | ||
| + | uid nslcd | ||
| + | gid nslcd | ||
| + | |||
| + | # The location at which the LDAP server(s) should be reachable. | ||
| + | uri ldap:// | ||
| + | |||
| + | # The search base that will be used for all queries. | ||
| + | base dc=i2m, | ||
| + | |||
| + | # The LDAP protocol version to use. | ||
| + | ldap_version 3 | ||
| + | |||
| + | # The DN to bind with for normal lookups. | ||
| + | #binddn cn=annonymous, | ||
| + | #bindpw secret | ||
| + | |||
| + | # The DN used for password modifications by root. | ||
| + | # | ||
| + | |||
| + | # SSL options | ||
| + | ssl start_tls | ||
| + | tls_reqcert allow | ||
| + | tls_cacertfile / | ||
| + | |||
| + | # The search scope. | ||
| + | #scope sub | ||
| + | </ | ||
| + | |||
| + | On redémarre les services nslcd et nscd : '' | ||
| + | |||
| + | On lance la commande '' | ||
| + | |||
| + | On modifie le fichier ''/ | ||
| + | < | ||
| + | # | ||
| + | # / | ||
| + | # | ||
| + | # This file is included from other service-specific PAM config files, | ||
| + | # and should contain a list of modules that define tasks to be performed | ||
| + | # at the start and end of sessions of *any* kind (both interactive and | ||
| + | # non-interactive). | ||
| + | # | ||
| + | # As of pam 1.0.1-6, this file is managed by pam-auth-update by default. | ||
| + | # To take advantage of this, it is recommended that you configure any | ||
| + | # local modules either before or after the default block, and use | ||
| + | # pam-auth-update to manage selection of other modules. | ||
| + | # pam-auth-update(8) for details. | ||
| + | |||
| + | # here are the per-package modules (the " | ||
| + | session [default=1] | ||
| + | # here's the fallback if no module succeeds | ||
| + | session requisite | ||
| + | # prime the stack with a positive return value if there isn't one already; | ||
| + | # this avoids us returning an error just because nothing sets a success | ||
| + | # since the modules above will each just jump around | ||
| + | session required | ||
| + | # The pam_umask module will set the umask according to the system default in | ||
| + | # / | ||
| + | # umask settings with different shells, display managers, remote sessions etc. | ||
| + | # See "man pam_umask" | ||
| + | session optional | ||
| + | # and here are more per-package modules (the " | ||
| + | session required | ||
| + | session optional | ||
| + | session [success=ok default=ignore] | ||
| + | session optional | ||
| + | # end of pam-auth-update config | ||
| + | </Code> | ||