Skip to content

LDAP

Central authentication server setup. From this guide: Install and configure LDAP | Ubuntu

Install slapd

Install the server and the main command-line utilities:

sudo apt install slapd ldap-utils

It defaults to your hostname and FQDN:

sudo slapcat

Changing the instance suffix (optional)

If you've set up your hostname and FQDN correctly, you shouldn't need to change this. If you do want to change your Directory Information Tree (DIT) suffix, now's the time — changing it later discards your existing one:

sudo dpkg-reconfigure slapd

Check and Query LDAP

Here's what the dc=example,dc=com DIT looks like:

ldapsearch -x -LLL -H ldap:/// -b dc=example,dc=com dn

Screenshot needed

The original doc had a screenshot here (query results) that didn't survive the migration from Notion.

In both cases you only get the results that the server's access-control lists (ACLs) allow you to see, based on who you are. A handy tool to verify authentication is ldapwhoami:

ldapwhoami -x
# -> anonymous
ldapwhoami -x -D cn=admin,dc=jrcai,dc=lan -W
# -> dn:cn=admin,dc=jrcai,dc=lan

SASL EXTERNAL examples:

ldapwhoami -Y EXTERNAL -H ldapi:/// -Q
# -> dn:gidNumber=1000+uidNumber=1000,cn=peercred,cn=external,cn=auth
sudo ldapwhoami -Y EXTERNAL -H ldapi:/// -Q
# -> dn:gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth

TLS / CA Certificates

Enabling encrypted login against the LDAP server.

Certificate Authority (CA)

Install the gnutls-bin and ssl-cert packages:

sudo apt install gnutls-bin ssl-cert

Create a private key for the Certificate Authority:

sudo certtool --generate-privkey --bits 4096 --outfile /etc/ssl/private/mycakey.pem

Create the template file /etc/ssl/ca.info to define the CA:

sudo nano /etc/ssl/ca.info

Change Example Company to your own:

cn = Example Company
ca
cert_signing_key
expiration_days = 3650

Create the self-signed CA certificate — the root of trust that signs other certificates:

sudo certtool --generate-self-signed \
--load-privkey /etc/ssl/private/mycakey.pem \
--template /etc/ssl/ca.info \
--outfile /usr/local/share/ca-certificates/mycacert.crt

Run update-ca-certificates to add the new CA certificate to the list of trusted CAs:

sudo update-ca-certificates

Server's Private Key

A unique secret key that identifies the server:

sudo certtool --generate-privkey \
--bits 2048 \
--outfile /etc/ldap/ldap01_slapd_key.pem

Adjust permissions and ownership:

sudo chgrp openldap /etc/ldap/ldap01_slapd_key.pem
sudo chmod 0640 /etc/ldap/ldap01_slapd_key.pem

Server's Public Identity

Create the /etc/ssl/ldap01.info info file — this template provides metadata for the certificate request:

sudo nano /etc/ssl/ldap01.info

Change organization and cn accordingly (e.g. JRCAI Server1, server02.jrcai.lan):

organization = Example Company
cn = ldap01.example.com
tls_www_server
encryption_key
signing_key
expiration_days = 365

The above certificate is good for 1 year, and valid only for the ldap01.example.com hostname. Adjust as needed.

Create the server's certificate:

sudo certtool --generate-certificate \
--load-privkey /etc/ldap/ldap01_slapd_key.pem \
--load-ca-certificate /etc/ssl/certs/mycacert.pem \
--load-ca-privkey /etc/ssl/private/mycakey.pem \
--template /etc/ssl/ldap01.info \
--outfile /etc/ldap/ldap01_slapd_cert.pem

LDAP Config

Create certinfo.ldif (adjust paths and filenames accordingly):

sudo nano certinfo.ldif
dn: cn=config
add: olcTLSCACertificateFile
olcTLSCACertificateFile: /etc/ssl/certs/mycacert.pem
-
add: olcTLSCertificateFile
olcTLSCertificateFile: /etc/ldap/ldap01_slapd_cert.pem
-
add: olcTLSCertificateKeyFile
olcTLSCertificateKeyFile: /etc/ldap/ldap01_slapd_key.pem

Use ldapmodify to tell slapd about the TLS setup via the slapd-config database:

sudo ldapmodify -Y EXTERNAL -H ldapi:/// -f certinfo.ldif

If you need access to LDAPS (LDAP over SSL), edit /etc/default/slapd and include ldaps:/// in SLAPD_SERVICES:

sudo nano /etc/default/slapd
SLAPD_SERVICES="ldap:/// ldapi:/// ldaps:///"

Restart slapd:

sudo systemctl restart slapd

Testing

Test StartTLS:

ldapwhoami -x -ZZ -H ldap://ldap01.example.com

Screenshot needed

The original doc had a screenshot here (successful StartTLS test) that didn't survive the migration from Notion.

Test LDAPS:

ldapwhoami -x -H ldaps://ldap01.example.com

Screenshot needed

The original doc had a screenshot here (successful LDAPS test) that didn't survive the migration from Notion.

Note

  • StartTLS uses port 389.
  • LDAPS uses port 636.

LDAP Account Manager (LAM)

sudo apt -y install ldap-account-manager

It should use port 80:

sudo systemctl restart apache2
sudo systemctl status apache2

Check the LDAP admin portal at IP-Address/lam, e.g.:

10.22.188.89/lam

You can complete the setup from the referenced video for LAM.

Tip

Account expiration can also be extended directly from here — see Manual Extension.