Networking :: Setting Single Sign On Using OpenLDAP?
Jan 24, 2011configuring single signon using ldap
View 1 Repliesconfiguring single signon using ldap
View 1 RepliesSetting up a single signon using ldap server ?
View 1 Replies View RelatedDoes anyone know of a good tutorial for setting up single sign-on/login sync over a pure Linux network without any AD boxes in it? I have read this can be achieved through LDAP+Kerberos+PAM...I have these installed on a server...the users and groups on the server is configured to use them and a client has been pointed toward the LDAP server and has Kerberos enabled and users and Groups set to use the LDAP server as a backend.
I expected to see the users and groups list from the server show up on my client, or at least be able to login on the client as one such user. Am I misunderstanding what I read or am I just probably misconfiguring everything? My ultimate goal is for my clients to authenticate against my server and not have to sign in again when using server resources (Samba shares etc.).
I have read that NFS and NIS are old technologies that are going by the wayside and that Samba, LDAP authentication and such are overall better and more secure...What are everyone's thoughts on this? My network is just a home network so security isnt really a big problem...im just trying to set it up like a corporation with my limited resources would for the practice and education of doing it.
I've been surfing and googling for a while trying to figure out how to set up my PC running Fedora 13 to connect to Windows AD using Single Sign On services. I couldn't find any guide or tutorial or anything. I believe I'm not the only case when the company is running Windows AD for authentication.
View 2 Replies View RelatedI have just installed openldap on my Red Hat server and it is running:
[code]...
However when I try to add my first ldif file base.ldif, no matter how many time I enter in the correct password I get invalid credentials [root@server init.d]# ldapadd -D "cn=Manager,dc=mathcs.duq,dc=edu" -W -f /home/oberlanderm/base.ldif Enter LDAP Password: ldap_bind: Invalid credentials (49) I have to be forgetting someting simple,
[code]....
I'm trying to set up an OpenLDAP server on a clean install of 10.04 server (AMD64). Following the server guide [URL] I get down to the "Setting up ACL" step:
$ ldapsearch -xLLL -b cn=config -D cn=admin,cn=config -W oldDatabase=hdb oldAccess
This command fails with "ldap_bind: Invalid credentials (49)"
When I replace the dn with what it seems like it should be:
$ ldapsearch -xLLL -b cn=config -D cn=admin,dc=example,dc=com -W oldDatabase=hdb oldAccess
I get "No such object (32)"
I have a feeling this is because 10.04 no longer asks you for the admin username and password during the initial debconf (nor does dpkg-reconfigure).
I can continue through the guide using this form of the commands (which were used earlier in the Guide):
$ sudo ldapsearch -Y EXTERNAL -H ldapi:/// -b cn=config olcDatabase=hdb olcAccess
But I'm a little concerned that I'm not able to properly use the admin user to make LDAP changes to the configuration. It also seems like the Server Guide ought to use the 'sudo ... -Y EXTERNAL' form of the commands throughout if cn=admin,cn=config isn't going to work.
I'm following the tutorial at [URL] to set up openldap on maverick. However, when I try to do
[Code]....
Does anybody have any documentation or can assist with any sort of steps on how to install a SSO server on Centos 5.4.We have just over 150 Centos servers country wide and we would like to implement an SSO server to manage the users and their login credentials locally and centrally.
View 1 Replies View RelatedI have a problem my ubuntu is the latest distro but the shiftkeys are not working like when i whant an @ sign i cant make that sign the keybaord layout has been changed i even have done most of the solutions found on the site and no use.
View 1 Replies View Relatedwhen ever i try to sign in to my messaging system it gives me this message and wont let me sign in,< Received unexpected response from [URL] useTLS=1 is not allowed for non secure requests.>
View 3 Replies View RelatedCode:
$ su -c 'yum install wine'
this forum won't let me put all the text in Transaction Check Error: package openldap-2.4.21-6.fc13.x86_64 (which is newer than openldap-2.4.21-4.fc13.i686) is already installed package nss-softokn-freebl-3.12.4-19.fc13.x86_64 (which is newer than nss-softokn-freebl-3.12.4-17.fc13.i686) is already installed
I installed 10.10 this morning from the live CD. Everything working perfectly whilst at home, but now I'm on the move I'm having troubles.At my parents' house trying to connect to their wifi. Wifi is on, their network is detected, I can go in and enter the WAP key and I get the strobing wifi icon in the top panel as though it's signing in, but after about 4 seconds I get a black screen and everything freezes. All that remains on the screen is the mouse pointer in its last position and a non-flashing cursor in the top left.
View 1 Replies View RelatedI am systems administator of the university CS lab. I have a Mac here and I'm trying to extend the directory to our OpenLDAP server. We use NFS as well. I know nothing of Macs in this respect except for the fact that they already have LDAP on them, which seems to be convenient.
View 3 Replies View RelatedIs it possible to monitor WiFi connections and identify who are connected through OpenLDAP? If so, how will authentication be possible? By the way, I'm open if OpenLDAP is inappropriate for such authentication purposes and scenario.
View 2 Replies View RelatedI've just installed my first OpenLdap + TLS + Samba + Webmin box.Everything seems to work but when i try to open the Ldap User and group module from Webmin, it takes about 3 minutes but it works.When i use $ getent passwd or$ getent group.to see if everything works okay, it also takes ages but does not show my ldap users...Here's my spec
$ cat /proc/version
Quote:Linux version 2.6.18-128.2.1.el5 (mockbuild@builder10.centos.org) (gcc version 4.1.2 20080704 (Red Hat 4.1.2-44)) #1 SMP Tue Jul 14 06:36:37 EDT 2009
I have setuped OpenLDAP+Samba PDC. When I create user and group -> Errors.
smbldap-group -a admin
No such object at /usr/sbin/smbldap_tools.pm line 457
smbldap-useradd -am -g admin admin
Could not find base dn, to get next uidNumber at /usr/sbin/smbldap_tools.pm line 1192
Ubuntu boots fine with wireless turned off via the laptop wireless button on the case, and fine with wireless on but no networks remembered, but as soon as I try to connect to a network, I get the strobing wireless icon in the top panel and then the whole system freezes. It switches to a black screen with a non-flashing terminal cursor in the top left corner of the screen plus a frozen mouse pointer in the last position from when Ubuntu was working. If I force a power-off after this, which I have to, then unless I manually turn off wifi using the laptop button then Ubuntu never boots and I just get a black screen after the BIOS screen. I can connect to the internet via wired connection.
View 5 Replies View RelatedDM9, 2GB RAM, 32GB SSD, Ubuntu 10.04 UNR.At Panera and at my local library there is a page that comes up when I try to connect to the Internet that is an agreement page. It comes up with my iPod Touch and with my MacBook. Using my DM9 that page does not come up for me to sign in so I can't get on the Internet.I have had Firefox and Chromium running at different times with the same results. When there is a WEP password or no password it connects. What do I need to do to get connected to the Internet at Panera and the like?
View 8 Replies View RelatedDell Mini 9, 2GB RAM, 32 GB SSD, Ubuntu 10.04 UNR . At Panera, and other places that have free Internet access but require signing in on a page they load, I cannot get on to the Internet. Their sign-in page comes up on my iPod Touch but does not come up on my DM9. This happens no matter which browser I have running on my DM9 (I have Firefox and Chromium). And since I can't sign in, I don't get onto the Internet. Initially I am connected to their router and the signal is strong but because I don't sign in (I'm assuming here), I am disconnected. What do I need to do to see their sign-in page so I can get connected. At locations that have no sign-in pages I have no problems whether or not a password is required.
View 3 Replies View RelatedCurrently I have a single openldap server version 2.3.32 preforming authentication on our databases as well as e-mail and other assorted programs. When we get a high volume of users, sometimes the users can not be authenticated for new e-mail sessions and what not. We have traced it back to being that our current single ldap server can not authenticate them all in a timely manner. We decided that we would put up a new ldap server and replicate the changes to it, then upgrade the older server version and replicate back to it so that both would have a current up to date copy of our configuration, and we would do a master/slave type setup.
Trying to replicate between the old server and the new server is not currently working. Here is the issue: when we try to import the schema's from the older server we get this error: slapadd: dn="cn=Domain Users,ou=Groups,dc=mydomain,dc=com" (line=247): (65) no structural object class provided I can not seem to find any information on google that shows this exact error? if this isn't detailed enough let me know what else I should post.
I have an LG R-450 laptop with Ubuntu 10.04 installed in it. When I connect him to a network (either LAN or Wireless) it stays connected for a few minutes and then Just disconnects (without showing any sign of disconnection except no internet/skype/dropbox). Only way to renew connection is after startup. The network controller is SIS 191 Gigabit Ethernet adapter.
View 9 Replies View RelatedI have question about the UNIX sockets. my goal is to connect multiple sockets from a single client to a single server and keep them open...I'm not sure if that is possible to create or not. Do you have any suggestion or an example of code?
View 1 Replies View RelatedMy machine has ONE ethernet card and is on a LAN.IP address is assigned to hosts using DHCP.I can have more than one MAC address on LAN by running Virtual Machine and setting network to bridged. This way, my virtual machine simply acts like there is one more machine in the network.Running VMWare for this job is a a bit heavy on resources. Is there a way so that I can I can have 2 or more ip addresses with different MAC address on the same machine without having to run VirtualBox.
By googling, I think its related to bridging and tap. And, I am sure thatts NOT IP-ALIASING because in ip-aliasing both the ip addresses have the same MAC address.Basically, I want my system to have interfaces like:-eth0 - which was originally presentlo- thats always present :|newint0 - New interface with new MAC address and IP addresses which can access my LAN directly. Its like if I bind, let us suppose curl to this interface, its like a different connection
Here is my network setup:
Internet <-> [public IP] Router [192.168.x.x] <-> Local
Local <-> DMZ
Local <-> HostB
Local <-> HostC
I have a system set up as a DMZ which works great for accessing SSH and other various services. I have a dyndns account that points to my public IP and allows me to access my DMZ box from around the world. I would like to make a subdomain of my current dyndns account and point it to HostB so that it can host a webserver on it, and have another subdomain point to HostC with a separate webserver on it. each would have SSH, FTP, Etc and have to not conflict with one another behind one IP. I don't even know if it is possible, but it seems like if there is a request for dev.host.homelinux.com that packet would have to hit [URL]and could be iptable'd to be routed to the appropriate local machine somehow.
I've been trying to set multiple IP my Fedora 14 but nothing seems to work. Upon browsing the net, I found there are two ways for it. One is eth0:0~eth0:n nd another is eth0-range0. All are configs under network-scripts. But neither of them worked for me. Even grabbing a working example from my live server doesn't do the trick (though the server is a CentOS 5.5).
Currently using eth0-range0
ONBOOT=yes
IPADDR_START=192.168.1.127
[code]...
I've been trying to create a simple htb qdisc on my computer for learning purposes, but it does not seem to be working as I want it to. Ive made this script that creates a simple qdisc scheme and assigns filters to it:
tc qdisc add dev $ETH root handle 1:0 htb default 1
tc class add dev $ETH parent 1:0 classid 1:1 htb rate 20kbps ceil 0kbps
tc class add dev $ETH parent 1:0 classid 1:2 htb rate 30kbps ceil 100kbps
tc class add dev $ETH parent 1:0 classid 1:3 htb rate 10kbps ceil 100kbps
[code]....
I want it to simply shape packets on my single machine so that when I go to view web pages it will limit the download rate, same thing for p21 ftp and 443 https. I just want to try out how it works and use these trial to get a hang of it, but I noticed so far that its not limiting port 80 at all.
trying to configure a transparent proxy with squid (and filter content with dansguardian) in Debian/Ubuntu. If i configure firefox to use it, it runs ok. I had seen a lot of iptables rules to use fowarding proxy to a lan, but i would like to use squid and dansguardin in a single pc that run them and filter web content.
View 5 Replies View RelatedI have a good question. I have a friend that lives in an area where he cannot receive DSL or Cable internet. He has a phone line, and physically able to get DSL, but the company won't give him service. He has Verizon wireless, but the reception is bad and his service gets dropped too much.
I however, have DSL 3.0Mbps and want to know how I could get him a DSL modem to dial up to my server at my house and receive internet. I know that I would probably need two phone lines to do this, but apart from that.
I have been using ubuntu for more than 3 months now . I was wondering if could use LAN and Internet simultaneously in windows, why that should not work in ubuntu? I tried as much as I could, searched different forum and thought there is no way I can get around with it until recently I found a solution in a forum. For your information I use ppoe for connecting to Internet.
The solution was as simple as running this simple command sudo ifconfig eth0 192.168.x.x netmask 255.x.x.xI have replaced those x with my desired number. It worked like a charm! Now I could browse LAN shares and Internet simultaneously! How to do it and forget it? I mean I don't want to do it every time I dial my connection.
Can I have two ubuntu desktop in a single installed ubuntu9.10 such that two desktop has different ipaddress?
View 5 Replies View Related