system engineer: openldap and samba server

105
NETWORK ADMINISTRATION OpenLDAP+ Samba 2013-2014

Upload: tola-leng

Post on 07-Jan-2017

126 views

Category:

Technology


1 download

TRANSCRIPT

Page 1: System Engineer: OpenLDAP and Samba Server

NETWORK ADMINISTRATION OpenLDAP+ Samba

2013-2014

Page 2: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Table of Content

1. Create Openldap server GUI .......................................................................................................................... 2

a. Changed Hostname and Assigned IP Address ........................................................................................... 2

b. Install the services packet of LDAP there are: ............................................................................................... 4

c. Go to yast for create and configure the ldap server ..................................................................................... 6

d. LDAP Client ................................................................................................................................................... 10

e. Create a sh file for configure the multi restart the services. ....................................................................... 13

2. Create Users With GUI ................................................................................................................................. 15

3. Take another client (suse) join domain with LDAP server+login (GUI) ........................................................ 18

4. Configuration Samba ................................................................................................................................... 25

a. Combine Samba with OpenLDAP ............................................................................................................ 25

b. Allowed Windows Client Join Domain ..................................................................................................... 31

Configuration file ......................................................................................................................................... 37

1. Configure openldap(slapd.conf) .................................................................................................................. 37

2. Create and Insert with *.ldif (file): .................................................................................................................... 38

4. Take another Client (SUSE) Join domain with LDAP server + Login ............................................................. 46

5. Configure SAMBA vai Configuration file ...................................................................................................... 50

A. Combid Samba with OpenLDAP by confuration file ................................................................................ 50

B. Allow Windows Client join domain + Login ............................................................................................. 57

1. Create Folders in /srv with: .......................................................................................................................... 64

A. SNA2014 .................................................................................................................................................. 66

a. SNA-A ....................................................................................................................................................... 66

b. SNA-B ....................................................................................................................................................... 66

2. Create user in OpenLDAP (file) .................................................................................................................... 66

A. Created User: ................................................................................................................................................ 67

4. Take windows Client test ................................................................................................................................. 76

-Let user in class SNA-A test ............................................................................................................................ 76

-Let user SNA2014(sopheak.ros) logon ........................................................................................................... 80

5. Install and Configure ........................................................................................................................................ 81

- Install Openfire package on Openldap server for allow user charting......................................................... 92

- Configure Openfire by remote from client ................................................................................................... 93

Let users admin login to openfire ........................................................................................................... 97

- Using Spark software for charting with each other ...................................................................................... 98

Add contact friends ............................................................................................................................... 100

Page 3: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

1. Create Openldap server GUI

a. Changed Hostname and Assigned IP Address

-Go to yast lan to assigned IP and hostname

Page 4: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 5: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

b. Install the services packet of LDAP there are: - Openldap2

- Openldap2-client

- Pam_ldap

- Nss_ldap

Page 6: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 7: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

c. Go to yast for create and configure the ldap server

Page 8: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

+To configure LDAP server by GUI

Page 9: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 10: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 11: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

d. LDAP Client

+Configure the LDAP client

Page 12: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 13: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 14: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

e. Create a sh file for configure the multi restart the services.

-rcsmb restart

-rcldap restart

-rcnmb restart

-rcnscd restart

Page 15: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 16: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

2. Create Users With GUI

+ Go to yast => Security and Users => next tap to user and

group management

+ types Alt+S =>LDAP Server => Add…..

Page 17: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 18: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 19: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

3. Take another client (suse) join domain with LDAP server+login

(GUI)

A. Assigned IP for client

Page 20: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 21: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 22: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 23: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 24: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 25: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

b. Let user logon after join domain

Page 26: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

4. Configuration Samba

a. Combine Samba with OpenLDAP

Page 27: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 28: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 29: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 30: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 31: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 32: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

b. Allowed Windows Client Join Domain

Page 33: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 34: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 35: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 36: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 37: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

+ add users to samba for allowed user logon on windows by samba

Page 38: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Configuration file

1. Configure openldap(slapd.conf)

Page 39: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

2. Create and Insert with *.ldif (file):

A. Domain

Page 40: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

OU.

Page 41: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 42: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 43: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

3. Configure LDAP Client File or LDAP client (GUI)

Page 44: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 45: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 46: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 47: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

4. Take another Client (SUSE) Join domain with LDAP

server + Login

Page 48: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 49: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 50: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Let user logon

Page 51: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

5. Configure SAMBA vai Configuration file

A. Combid Samba with OpenLDAP by confuration file

First vi /etc/samba/smb.conf

Page 52: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 53: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 54: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Combine samba with ldap by GUI

Page 55: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 56: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 57: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 58: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

B. Allow Windows Client join domain + Login

Page 59: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 60: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 61: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 62: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 63: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Let User logon

Page 64: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 65: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

1. Create Folders in /srv with:

A. SNA2015

Page 66: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

c. SNA-B

Page 67: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

A. SNA2014

a. SNA-A

b. SNA-B

2. Create user in OpenLDAP (file)

I can add users Samba in local but before I create users I just create the group

and then Users.

Page 68: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

A. CREATED USER:

-Users Class SNA –A

Page 69: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 70: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

-Users Class SNA-B

And then save the job by types Esc+:x!

B. sopheak.ros

Page 71: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

And then save the job by types Esc+:x!

Add users to LDAP by command line

Add users sopheak.ros to LDAP server.

Add user to Samba

Page 72: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Created and add users to each group

Page 73: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

3. Make sure:

A. you and your friends: Access only SNA2015, but you can only access your owner

folder(Folder Permission)

SNA-A( -Folder Saray.RONG,Folder Phirak.PHUN)

3

Page 74: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 75: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 76: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

SNA-B (Tola,Savy)

B. User: sopheak.ros : Access only SNA2014

Page 77: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

4. TAKE WINDOWS CLIENT TEST

-LET USER IN CLASS SNA-A TEST

Page 78: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 79: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 80: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 81: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

-LET USER SNA2014(SOPHEAK.ROS) LOGON

Page 82: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

5. INSTALL AND CONFIGURE

- LDAP Admin software to create user, group, reset password, computer account on Openldap server

Page 83: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 84: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 85: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Connection name = any name Host = we put the IP server host of Suse Base = the base of DN of server username = Admin ldap configure password = password DN

Page 86: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Then test connection.

Page 87: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Reset password for user in LDAP Admin

Create a user in LDAP admin

Page 88: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 89: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 90: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Create the Computer Account

Page 91: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Create Organization Unit (OU)

Page 92: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Last Result

Page 93: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

- INSTALL OPENFIRE PACKAGE ON OPENLDAP SERVER FOR ALLOW USER

CHARTING

Page 94: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

- CONFIGURE OPENFIRE BY REMOTE FROM CLIENT

Page 95: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 96: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 97: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Choose the user and group system to use with the server choose Directory Server

(LDAP)

Page 98: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Choose one or more user from LDAP to be administrator

Let users admin login to openfire

Page 99: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

This is the all user and computer account on LDAP Server

- USING SPARK SOFTWARE FOR CHARTING WITH EACH OTHER

Page 100: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

The first we need to have a software Spark So this I will let user savy.vuth to logon this PC1

Page 101: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Add contact friends

Page 102: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 103: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 104: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

Page 105: System Engineer: OpenLDAP and Samba Server

Prepared by: LENG Tola [email protected] www.itolaleng.wordpress.com

The End!