此环境为centos7.4
安装LDAP服务端
yum install -y openldap openldap-clients openldap-servers
关闭filewarlld
systemctl stop firewalld
systemctl disable firewalld
cp /usr/share/openldap-servers/DB_CONFIG.example /var/lib/ldap/DB_CONFIG
chown -R ldap. /var/lib/ldap/DB_CONFIG
systemctl start slapd
systemctl enable slapd
[root@LDAP-server ~]# slappasswd -s 123456 #记住生成的密文后面要用到
{SSHA}0aBzGgviIvv5sgZFs7XpD5MMa19xWQ/6
[root@LDAP-server ~]# cd /root/
[root@LDAP-server ~]# vim changepwd.ldif
dn: olcDatabase={0}config,cn=config
changetype: modify
add: olcRootPW
olcRootPW: {SSHA}0aBzGgviIvv5sgZFs7XpD5MMa19xWQ/6
[root@LDAP-server ~]# ldapadd -Y EXTERNAL -H ldapi:/// -f changepwd.ldif
[root@LDAP-server ~]# ldapadd -Y EXTERNAL -H ldapi:/// -f /etc/openldap/schema/cosine.ldif
[root@LDAP-server ~]# ldapadd -Y EXTERNAL -H ldapi:/// -f /etc/openldap/schema/nis.ldif
[root@LDAP-server ~]# ldapadd -Y EXTERNAL -H ldapi:/// -f /etc/openldap/schema/inetorgperson.ldif
[root@LDAP-server ~]# ldapadd -Y EXTERNAL -H ldapi:/// -f /etc/openldap/schema/collective.ldif
[root@LDAP-server ~]# ldapadd -Y EXTERNAL -H ldapi:/// -f /etc/openldap/schema/corba.ldif
[root@LDAP-server ~]# ldapadd -Y EXTERNAL -H ldapi:/// -f /etc/openldap/schema/duaconf.ldif
[root@LDAP-server ~]# ldapadd -Y EXTERNAL -H ldapi:/// -f /etc/openldap/schema/dyngroup.ldif
[root@LDAP-server ~]# ldapadd -Y EXTERNAL -H ldapi:/// -f /etc/openldap/schema/java.ldif
[root@LDAP-server ~]# ldapadd -Y EXTERNAL -H ldapi:/// -f /etc/openldap/schema/misc.ldif
[root@LDAP-server ~]# ldapadd -Y EXTERNAL -H ldapi:/// -f /etc/openldap/schema/openldap.ldif
[root@LDAP-server ~]# ldapadd -Y EXTERNAL -H ldapi:/// -f /etc/openldap/schema/pmi.ldif
[root@LDAP-server ~]# ldapadd -Y EXTERNAL -H ldapi:/// -f /etc/openldap/schema/ppolicy.ldif
[root@LDAP-server ~]# vim changedomain.ldif
dn: olcDatabase={1}monitor,cn=config
changetype: modify
replace: olcAccess
olcAccess: {0}to * by dn.base="gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth" read by dn.base="cn=admin,dc=ehaofang,dc=com" read by * none
dn: olcDatabase={2}hdb,cn=config
changetype: modify
replace: olcSuffix
olcSuffix: dc=ehaofang,dc=com
dn: olcDatabase={2}hdb,cn=config
changetype: modify
replace: olcRootDN
olcRootDN: cn=admin,dc=ehaofang,dc=com
dn: olcDatabase={2}hdb,cn=config
changetype: modify
replace: olcRootPW
olcRootPW: {SSHA}0aBzGgviIvv5sgZFs7XpD5MMa19xWQ/6
dn: olcDatabase={2}hdb,cn=config
changetype: modify
add: olcAccess
olcAccess: {0}to attrs=userPassword,shadowLastChange by dn="cn=admin,dc=ehaofang,dc=com" write by anonymous auth by self write by * none
olcAccess: {1}to dn.base="" by * read
olcAccess: {2}to * by dn="cn=admin,dc=ehaofang,dc=com" write by * read
[root@LDAP-server ~]# ldapmodify -Y EXTERNAL -H ldapi:/// -f changedomain.ldif
[root@LDAP-server ~]# vim add-memberof.ldif
dn: cn=module{0},cn=config
cn: modulle{0}
objectClass: olcModuleList
objectclass: top
olcModuleload: memberof.la
olcModulePath: /usr/lib64/openldap
dn: olcOverlay={0}memberof,olcDatabase={2}hdb,cn=config
objectClass: olcConfig
objectClass: olcMemberOf
objectClass: olcOverlayConfig
objectClass: top
olcOverlay: memberof
olcMemberOfDangling: ignore
olcMemberOfRefInt: TRUE
olcMemberOfGroupOC: groupOfUniqueNames
olcMemberOfMemberAD: uniqueMember
olcMemberOfMemberOfAD: memberOf
[root@LDAP-server ~]# vim refint1.ldif
dn: cn=module{0},cn=config
add: olcmoduleload
olcmoduleload: refint
[root@LDAP-server ~]# vim refint2.ldif
dn: olcOverlay=refint,olcDatabase={2}hdb,cn=config
objectClass: olcConfig
objectClass: olcOverlayConfig
objectClass: olcRefintConfig
objectClass: top
olcOverlay: refint
olcRefintAttribute: memberof uniqueMember manager owner
[root@LDAP-server ~]# ldapadd -Q -Y EXTERNAL -H ldapi:/// -f add-memberof.ldif
[root@LDAP-server ~]# ldapmodify -Q -Y EXTERNAL -H ldapi:/// -f refint1.ldif
[root@LDAP-server ~]# ldapadd -Q -Y EXTERNAL -H ldapi:/// -f refint2.ldif
[root@LDAP-server ~]# vim base.ldif
dn: dc=ehaofang,dc=com
objectClass: top
objectClass: dcObject
objectClass: organization
o: ehaofang Company
dc: ehaofang
dn: cn=admin,dc=ehaofang,dc=com
objectClass: organizationalRole
cn: admin
dn: ou=Dev,dc=ehaofang,dc=com
objectClass: organizationalUnit
ou: Dev
dn: ou=QA,dc=ehaofang,dc=com
objectClass: organizationalRole
cn: QA
[root@LDAP-server ~]# ldapadd -x -D cn=admin,dc=ehaofang,dc=com -W -f base.ldif
参考 https://blog.csdn.net/weixin_41004350/article/details/89521170