Skip to content
GitLab
Explore
Sign in
Primary navigation
Search or go to…
Project
G
GoikLectures
Manage
Activity
Members
Labels
Plan
Issues
Issue boards
Milestones
Wiki
Requirements
Code
Merge requests
Repository
Branches
Commits
Tags
Repository graph
Compare revisions
Locked files
Deploy
Releases
Container Registry
Model registry
Monitor
Incidents
Analyze
Value stream analytics
Contributor analytics
Repository analytics
Code review analytics
Issue analytics
Insights
Model experiments
Help
Help
Support
GitLab documentation
Compare GitLab plans
Community forum
Contribute to GitLab
Provide feedback
Terms and privacy
Keyboard shortcuts
?
Snippets
Groups
Projects
Show more breadcrumbs
Goik Martin
GoikLectures
Commits
b4f93fdc
Commit
b4f93fdc
authored
8 years ago
by
Goik Martin
Browse files
Options
Downloads
Patches
Plain Diff
Correcting LDAP replication.
parent
19cdfbd4
No related branches found
Branches containing commit
No related tags found
No related merge requests found
Changes
2
Hide whitespace changes
Inline
Side-by-side
Showing
2 changed files
Doc/Sdi/ldap.xml
+43
-32
43 additions, 32 deletions
Doc/Sdi/ldap.xml
ws/Docbook/Config/xxe6/spell/dict_en.txt
+1
-0
1 addition, 0 deletions
ws/Docbook/Config/xxe6/spell/dict_en.txt
with
44 additions
and
32 deletions
Doc/Sdi/ldap.xml
+
43
−
32
View file @
b4f93fdc
...
...
@@ -83,12 +83,12 @@
<listitem>
<para>
What does the term
<quote>
bind to an
<acronym>
LDAP
</acronym></quote>
server mean? Which two types of bind
operations are
generally
being distinguished?
</para>
operations are being distinguished?
</para>
</listitem>
<listitem>
<para>
Do
<acronym>
LDAP
</acronym>
servers in general support database
features like transactions, ACID semantic etc.
?
</para>
features like transactions, ACID semantic etc.?
</para>
</listitem>
<listitem>
...
...
@@ -134,13 +134,13 @@
<itemizedlist>
<listitem>
<para>
What does the term database backend refer to with respect to
<productname>
OpenLDAP
</productname>
server implementation?
</para>
<para>
What does the term
<quote>
database backend
</quote>
refer to
with respect to
<productname>
OpenLDAP
</productname>
server
implementation?
</para>
</listitem>
<listitem>
<para>
Which two ways of
<acronym>
LDAP
</acronym>
replication to
slave servers are on offer? Why is replication important?
</para>
<para>
Why is
<acronym>
LDAP
</acronym>
replication important?
</para>
</listitem>
<listitem>
...
...
@@ -665,51 +665,62 @@ modifying entry "olcDatabase={0}config,cn=config"</programlisting>
<section
xml:id=
"ldapReplication"
>
<title>
Replication
</title>
<para>
Depending on your database backend choice you may have to alter
the
<link
xlink:href=
"https://wiki.debian.org/LDAP/OpenLDAPSetup#with_cn.3Dconfig-1"
>
installation
procedure
</link>
by replacing
<quote>
hdb
</quote>
with
<quote>
mdb
</quote>
accordingly both on the provider and the consumer side. For (yet)
unknown reasons the
<property>
olcSyncProvConfig
</property>
<acronym>
objectclass
</acronym>
is absent on our systems. You may safely
omit configuring the related parameters
<property>
olcSyncProvConfig
</property>
and
<property>
olcSyncProvConfig
</property>
.
</para>
<para>
Using Apache Directory Studio may be used in favour of
<command>
ldapmodify
</command>
and friends.
</para>
<para><link
xlink:href=
"???https://wiki.debian.org/LDAP/OpenLDAPSetup#with_cn.3Dconfig-1"
>
Setting
up an LDAP server with OpenLDAP
</link>
provides a replication
configuration recipe. We advise using Apache Directory Studio in favour
of
<command>
ldapmodify
</command>
and friends.
</para>
<para>
Hints:
</para>
<orderedlist>
<listitem>
<para>
Depending on your database backend choice during server
installation you may have to alter the
<link
xlink:href=
"https://wiki.debian.org/LDAP/OpenLDAPSetup#with_cn.3Dconfig-1"
>
installation
procedure
</link>
by replacing
<quote>
hdb
</quote>
with
<quote>
mdb
</quote>
accordingly both on the provider and the consumer
side.
</para>
</listitem>
<listitem>
<para>
You may want to add the value
<code>
sync
</code>
to the
<property>
olcLogLevel
</property>
attribute. This will create related
messages in
<filename>
/var/log/syslog
</filename>
.
</para>
</listitem>
<listitem>
<para>
Activating the
<code>
syncprov
</code>
overlay requires an
additional
<property>
olcModuleLoad
</property>
value:
</para>
additional
<property>
olcModuleLoad
</property>
<coref
linkend=
"sdiLdapCoSyncprov"
/>
value:
</para>
<programlisting
language=
"none"
>
dn: cn=module{0},cn=config
objectClass: olcModuleList
cn: module{0}
olcModuleLoad: {0}back_mdb
<emphasis
role=
"bold"
>
olcModuleLoad: {1}syncprov
</emphasis>
<emphasis
role=
"bold"
>
olcModuleLoad: {1}syncprov
</emphasis>
<co
xml:id=
"sdiLdapCoSyncprov"
/>
olcModulePath: /usr/lib/ldap
</programlisting>
</listitem>
<listitem>
<para>
You may want to add the value
<code>
sync
</code>
to the
<
property
>
olcLogLevel
</property>
attribute. This will crea
te
rel
ated
messages in
<filename>
/var/log/syslog
</filename>
.
</para>
<para>
Adding the
<property>
olcSyncProvConfig
</property>
objectclass
property
requires hitting the
<quo
te
>
rel
oad
</quote>
icon in Apache
Directory Studio
.
</para>
</listitem>
</orderedlist>
<para>
Check for provider changes being propagated to the
consumer
.
</para>
<para>
Check for provider changes being propagated to the
consumer by
e.g. creating an
<code>
organisationalUnit
</code>
entry
.
</para>
<para>
The current configuration contains a serious security flaw: The
credentials are being sent in clear text and are thus subject to network
sniffing (e.g. by using
<link
xlink:href=
"https://www.wireshark.org"
>
.Wireshark
</link>
). In a
professional setup you will have to configure
<xref
linkend=
"glo_TLS"
/>
for encrypting your communication channel.
</para>
<note>
<para>
The current configuration contains a serious security flaw: The
credentials are being sent in clear text and are thus subject to
network sniffing (e.g. by using
<link
xlink:href=
"https://www.wireshark.org"
>
.Wireshark
</link>
) attacks. In
a professional setup you will have to configure
<xref
linkend=
"glo_TLS"
/>
for encrypting your communication channel.
</para>
</note>
</section>
<section
xml:id=
"sdiSectLdapByJava"
>
...
...
This diff is collapsed.
Click to expand it.
ws/Docbook/Config/xxe6/spell/dict_en.txt
+
1
−
0
View file @
b4f93fdc
...
...
@@ -15,6 +15,7 @@ namespace
namespaces
no-brainer
nullable
objectclass
passphrases
plugin
plugins
...
...
This diff is collapsed.
Click to expand it.
Preview
0%
Loading
Try again
or
attach a new file
.
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Save comment
Cancel
Please
register
or
sign in
to comment