MacLdapAuth: Difference between revisions
AlainKnaff (talk | contribs) |
m (Reverted edits by Yxawyjo (Talk) to last version by AlainKnaff) |
||
(3 intermediate revisions by 2 users not shown) | |||
Line 70: | Line 70: | ||
N.B. It is normal that the template setting automatically changes from <code>RFC 2307</code> to <code>Custom</code> as soon as you change one of the setting. | N.B. It is normal that the template setting automatically changes from <code>RFC 2307</code> to <code>Custom</code> as soon as you change one of the setting. | ||
== Add new LDAPv3 server entry as an authentication provider == | |||
In the ''Directory access'' window, click the ''Authentication'' tab. | |||
Then, click the ''add'' button to add service /LDAPv3/ldap.lgl.lu (you can pick it from a list). | |||
On some newer version of MacOS, you may need to proceed as follows instead: click on the "Search Policy" Icon at the top of the "Directory Utility" (only clickable if currently no service is being edited: click Ok or Cancel to dismiss if you are editing a service), and then add the newly defined service to the list. | |||
== Testing == | == Testing == |
Latest revision as of 19:48, 26 November 2010
(This Howto is based on the instructions at http://www.spack.org/wiki/AppleOsxIntegrationWithOpenLdap)
Setting up LDAP access to LLL server on a Macintosh client[edit]
This page describes how to set up LDAP authentication with SSL on Mac OSX 4.
Open Directory access[edit]
- Doubleclick on hard disk icon (red circle 1)
- In the filebrowser window, chose application on the left (2)
- click on the "3 pane view" icon (3)
- Open /Application/Utilities/DirectoryAccess (by first single-clicking on Utilities in left pane, then doubleclick "Directory Access" in middle pane)
On some versions of MacOS, you may instead need to do the following:
- go into Apple->SystemSettings->Accounts instead
- click on Login Options (lower left)
- add a "Network Account Server"
- Open Directory Utility
Enable and configure LDAPv3 plugin[edit]
- Doubleclick on the padlock (lower left of directory acess window) and enter admin user and password until padlock is open
- Select "LDAPv3" in list
- Click "Configure"
Create a new directory server entry[edit]
- Click "New"
- Enter LDAP server's host name (in this example,
ldap.lgl.lu
- Check "Encrypt using SSL"
- Click "Manual"
- Pick "RFC 2307 (Unix)" template
- Enter
dc=lgl,dc=lu
as search base - Click ok
Configure LDAPv3 server entry[edit]
- If you want, assign a meaningful Configuration Name to entry by entering it in place of
Untitled 0
- Select configuration (
Untitled 0
or whatever name you gave it) - Click Edit
- Click "Search and Mappings" in tab bar
- Click Users in left hand pane
- Enter
ou=People,dc=lgl,dc=lu
as a search base - Check check "first level only"
- Click Groups in left hand pane
- Enter
ou=Groups,dc=lgl,dc=lu
as a search base - Check check "first level only"
- Click Mounts in left hand pane
- Enter
ou=Mounts,dc=lgl,dc=lu
as a search base - Check check "first level only"
- Click ok
N.B. It is normal that the template setting automatically changes from RFC 2307
to Custom
as soon as you change one of the setting.
Add new LDAPv3 server entry as an authentication provider[edit]
In the Directory access window, click the Authentication tab.
Then, click the add button to add service /LDAPv3/ldap.lgl.lu (you can pick it from a list).
On some newer version of MacOS, you may need to proceed as follows instead: click on the "Search Policy" Icon at the top of the "Directory Utility" (only clickable if currently no service is being edited: click Ok or Cancel to dismiss if you are editing a service), and then add the newly defined service to the list.
Testing[edit]
Now is time for testing.
- Open a terminal by calling Applications/Utilities/Terminal in file manager
- In terminal, enter
dscl localhost list /Search/Users
. This displays a list of all users known by the macintosh. If everything worked, it should include all users from the server's LDAP database.
- If all users are included, log out, and log back in as one of the server users (you need to click "Other users" at the login window, then enter its name). It's expected that the login process is slow, as we have not yet set up mounting of
/home
. - If login was successful, clean away its temporary home directory (if the system created one)