Skip to content

LDAP

Note

ldap01.example.com is just an example throughout this page.

Install the required packages:

sudo apt install sssd-ldap ldap-utils

Certificate Authority (CA)

On the server, display and copy the content:

cat /usr/local/share/ca-certificates/mycacert.crt

On the client, create the file and paste the content there:

sudo nano /usr/local/share/ca-certificates/mycacert.crt

Update your certificates with:

sudo update-ca-certificates

SSSD Configuration

Create /etc/sssd/sssd.conf, with permissions 0600 and ownership root:root:

sudo nano /etc/sssd/sssd.conf
[sssd]
config_file_version = 2
domains = example.com

[domain/example.com]
id_provider = ldap
auth_provider = ldap
ldap_uri = ldap://ldap01.example.com
cache_credentials = True
ldap_search_base = dc=example,dc=com
ldap_id_use_start_tls = true

Note

If you encounter the error Could not start TLS encryption. (unknown error code), you may need to add this to your domain configuration:

ldap_tls_cacert = /etc/ssl/certs/ca-certificates.crt
sudo chown root:root /etc/sssd/sssd.conf
sudo chmod 600 /etc/sssd/sssd.conf

Start the sssd service:

sudo systemctl start sssd.service
sudo systemctl status sssd.service
sudo systemctl restart sssd.service
sudo sssctl config-check

Testing

Check that you can connect to the LDAP server using verified SSL connections:

ldapwhoami -x -ZZ -H ldap://ldap01.example.com
# -> anonymous

And for ldaps (if enabled):

ldapwhoami -x -H ldaps://ldap01.example.com
# -> anonymous

Check that the system finds the ID of one of the users created in LDAP Account Manager (e.g. sslurm):

id sslurm
# uid=10000(sslurm) gid=10000(slurmUsers) groups=10000(slurmUsers)

If it's not working and everything looks correct, a restart will usually fix it:

sudo systemctl restart sssd