LDAP¶
Note
ldap01.example.com is just an example throughout this page.
Install the required packages:
Certificate Authority (CA)¶
On the server, display and copy the content:
On the client, create the file and paste the content there:
Update your certificates with:
SSSD Configuration¶
Create /etc/sssd/sssd.conf, with permissions 0600 and ownership root:root:
[sssd]
config_file_version = 2
domains = example.com
[domain/example.com]
id_provider = ldap
auth_provider = ldap
ldap_uri = ldap://ldap01.example.com
cache_credentials = True
ldap_search_base = dc=example,dc=com
ldap_id_use_start_tls = true
Note
If you encounter the error Could not start TLS encryption. (unknown error code), you may need to add this to your domain configuration:
Start the sssd service:
Testing¶
Check that you can connect to the LDAP server using verified SSL connections:
And for ldaps (if enabled):
Check that the system finds the ID of one of the users created in LDAP Account Manager (e.g. sslurm):
If it's not working and everything looks correct, a restart will usually fix it: