LDAP¶
Central authentication server setup. From this guide: Install and configure LDAP | Ubuntu
Install slapd¶
Install the server and the main command-line utilities:
It defaults to your hostname and FQDN:
Changing the instance suffix (optional)
If you've set up your hostname and FQDN correctly, you shouldn't need to change this. If you do want to change your Directory Information Tree (DIT) suffix, now's the time — changing it later discards your existing one:
Check and Query LDAP¶
Here's what the dc=example,dc=com DIT looks like:
Screenshot needed
The original doc had a screenshot here (query results) that didn't survive the migration from Notion.
In both cases you only get the results that the server's access-control lists (ACLs) allow you to see, based on who you are. A handy tool to verify authentication is ldapwhoami:
SASL EXTERNAL examples:
ldapwhoami -Y EXTERNAL -H ldapi:/// -Q
# -> dn:gidNumber=1000+uidNumber=1000,cn=peercred,cn=external,cn=auth
sudo ldapwhoami -Y EXTERNAL -H ldapi:/// -Q
# -> dn:gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth
TLS / CA Certificates¶
Enabling encrypted login against the LDAP server.
Certificate Authority (CA)¶
Install the gnutls-bin and ssl-cert packages:
Create a private key for the Certificate Authority:
Create the template file /etc/ssl/ca.info to define the CA:
Change Example Company to your own:
Create the self-signed CA certificate — the root of trust that signs other certificates:
sudo certtool --generate-self-signed \
--load-privkey /etc/ssl/private/mycakey.pem \
--template /etc/ssl/ca.info \
--outfile /usr/local/share/ca-certificates/mycacert.crt
Run update-ca-certificates to add the new CA certificate to the list of trusted CAs:
Server's Private Key¶
A unique secret key that identifies the server:
Adjust permissions and ownership:
Server's Public Identity¶
Create the /etc/ssl/ldap01.info info file — this template provides metadata for the certificate request:
Change organization and cn accordingly (e.g. JRCAI Server1, server02.jrcai.lan):
organization = Example Company
cn = ldap01.example.com
tls_www_server
encryption_key
signing_key
expiration_days = 365
The above certificate is good for 1 year, and valid only for the ldap01.example.com hostname. Adjust as needed.
Create the server's certificate:
sudo certtool --generate-certificate \
--load-privkey /etc/ldap/ldap01_slapd_key.pem \
--load-ca-certificate /etc/ssl/certs/mycacert.pem \
--load-ca-privkey /etc/ssl/private/mycakey.pem \
--template /etc/ssl/ldap01.info \
--outfile /etc/ldap/ldap01_slapd_cert.pem
LDAP Config¶
Create certinfo.ldif (adjust paths and filenames accordingly):
dn: cn=config
add: olcTLSCACertificateFile
olcTLSCACertificateFile: /etc/ssl/certs/mycacert.pem
-
add: olcTLSCertificateFile
olcTLSCertificateFile: /etc/ldap/ldap01_slapd_cert.pem
-
add: olcTLSCertificateKeyFile
olcTLSCertificateKeyFile: /etc/ldap/ldap01_slapd_key.pem
Use ldapmodify to tell slapd about the TLS setup via the slapd-config database:
If you need access to LDAPS (LDAP over SSL), edit /etc/default/slapd and include ldaps:/// in SLAPD_SERVICES:
Restart slapd:
Testing¶
Test StartTLS:
Screenshot needed
The original doc had a screenshot here (successful StartTLS test) that didn't survive the migration from Notion.
Test LDAPS:
Screenshot needed
The original doc had a screenshot here (successful LDAPS test) that didn't survive the migration from Notion.
Note
- StartTLS uses port 389.
- LDAPS uses port 636.
LDAP Account Manager (LAM)¶
It should use port 80:
Check the LDAP admin portal at IP-Address/lam, e.g.:
You can complete the setup from the referenced video for LAM.
Tip
Account expiration can also be extended directly from here — see Manual Extension.