I went ahead and modified /etc/security/ldap/ldap.cfg directly *Note* Any passwords you use, MUST BE HASHED using mksecldap or some obscure command like that There is /var/lib/security/method.cfg which defines LDAP, make sure your module is in there, you can create your own modules if you want to, i.e. AUTH against KRB and find your user base in LDAP… but unlike nsswitch it does not determine a priority it just says modules are here. Lastly /etc/security/user, you need to change two args, SYSTEM (auth if you are familiar with pam) and registry (account) and point to the method in methods.cfg If you are using SSL which you should, you need to create the cert db using some obscure gui command. I essentially followed the IPA instructions and omitted the krb5 settings. Hope this helps. On May 23, 2013, at 6:54 AM, Dan Lavu <dan@xxxxxxxx> wrote:
|
-- 389 users mailing list 389-users@xxxxxxxxxxxxxxxxxxxxxxx https://admin.fedoraproject.org/mailman/listinfo/389-users