AIX 5L LDAP Óû§¹ÜÀí
ÆäÖУ¬foo ÊÇ Active Directory Öж¨ÒåµÄÒ»¸öʾÀýÓû§¡£ ÔÚÍê³É¸Ã¸ü¸ÄÖ®ºó£¬Óû§ foo ¾Í¿ÉÒԵǼµ½ AIX 5L ²Ù×÷ϵͳ¡£
Çë×¢Ò⣬µ±Óû§µÄ Windows ÃÜÂë¸ü¸Äʱ£¬Windows 2000 ºÍ 2003 ·þÎñÆ÷»áΪÕâЩ֧³Ö UNIX µÄÓû§ÉèÖà UNIX ÃÜÂë¡£¸ÃÓû§¿ÉÒÔʹÓÃÕâ¸öÃÜÂëµÇ¼µ½ AIX 5L ²Ù×÷ϵͳ£¬Ö±µ½ AIX 5L ²Ù×÷ϵͳ¶ÔÕâ¸öÃÜÂë½øÐÐÁ˸ü¸Ä¡£ÔÚ׫д±¾ÎÄʱ£¬µ±Óû§µÄ Windows ÃÜÂë¸ü¸Äʱ£¬Window 2003 R2 ²»»áÉèÖà UNIX ÃÜÂë¡£ÔÚÕâЩÇé¿öÏ£¬root Óû§±ØÐëÔÚ AIX 5L ²Ù×÷ϵͳÖÐÔËÐÐ passwd ÃüÁÒÔ±ãΪ Windows Óû§ÉèÖà UNIX ÃÜÂ룬´Ó¶øʹËûÃÇÄܹ»µÇ¼µ½ AIX¡£
Èç¹ûÒªÈÃËùÓÐµÄ Windows Óû§¶¼Äܹ»µÇ¼µ½ AIX 5L ²Ù×÷ϵͳ£¬¶Ôÿ¸öÓû§½øÐÐÕâÑùµÄ²Ù×÷¿ÉÄܷdz£Âé·³¡£ÔÚÕâЩÇé¿öÏ£¬¹ÜÀíÔ±¿ÉÒÔÊÖ¶¯±à¼ /etc/security/user Îļþ£¬²¢½« default ½ÚµÄ SYSTEM ºÍ registry ÊôÐÔÉèÖÃΪ LDAP¡£Èç¹û default ½ÚÖв»°üº¬ÕâЩÊôÐÔ£¬ÄÇôÐèÒªÌí¼ÓËüÃÇ¡£Ð޸ĺóµÄ default ½ÚÓ¦¸ÃÓëÏÂÃæËùʾÀàËÆ£º default: ... SYSTEM = "LDAP" registry = LDAP ...
Èç¹ûÒѽ« default ½Ú¸ü¸ÄΪ LDAP£¬ÕâЩ±¾µØ¶¨ÒåµÄÓû§¿ÉÄÜÎÞ·¨µÇ¼µ½ AIX 5L ²Ù×÷ϵͳ£¬³ý·Ç½«ËûÃÇµÄ SYSTEM ÉèÖÃΪ compat£¬registry ÉèÖÃΪ files¡£¹ÜÀíÔ±±ØÐëÕÒ³öÕâЩÕÊ»§£¬²¢ÎªÃ¿¸öÓû§ÔËÐÐÏÂÃæµÄÃüÁîÒÔ½øÐÐÏàÓ¦µÄ¸ü¸Ä¡£ # chuser SYSTEM=compat registry=files <local user>
ÅäÖà AIX 5L ÒÔʹÓà ldap_auth Éí·ÝÑé֤ģʽÓë Active Directory Ðͬ¹¤×÷ # mksecldap -c -h <Active Directory hostname> -a <cn=binduser,cn=users,dc=ADdomain,dc=abc,dc=com> -p <password> -A ldap_auth
ÆäÖУº Active Directory hostname ÊÇÄúµÄ Windows Active Directory ·þÎñÆ÷¡£ cn=binduser,cn=users,dc=ADdomain,dc=abc,dc=com ÊÇÒ»¸öʾÀý°ó¶¨Æ¾¾Ý¡£Ëü¿ÉÒÔÊÇ Active Directory Öж¨ÒåµÄÒ»¸öÓû§ÕÊ»§¡£ ÃÜÂë Ö¸µÄÊÇÉÏÃæµÄ binduser ÕÊ»§µÄÃÜÂë¡£
ÒªÑéÖ¤ÊÇ·ñÕýÈ·ÅäÖÃÁË AIX 5L ²Ù×÷ϵͳ£¬¿ÉÒÔÔËÐÐ lsuser ÃüÁîÒÔÁгö Active Directory Öж¨ÒåµÄÓû§£º # lsuser -R LDAP <username>
ÆäÖÐ username Ó¦¸ÃÊÇ Active Directory Öж¨ÒåµÄÓÐЧÓû§¡£
×¢Ò⣺Èç¹ûÄúÉÐδ°²×° APAR IY91514£¨Çë²Î¼û Microsoft Active Directory ²¿·Ö£¬ÒÔÁ˽âÈçºÎ²é¿´ÊÇ·ñ°²×°Á˸à APAR£©£¬ÄÇô¿ÉÄÜÎÞ·¨ ½« AIX 5L spassword ÊôÐÔÓ³ÉäΪÕýÈ·µÄ Active Directory ÃÜÂëÊôÐÔ¡£Õâ¿ÉÄܵ¼ÖÂÉí·ÝÑé֤ʧ°Ü£¬¼´Ê¹ÄúʹÓÃÁËÕýÈ·µÄÃÜÂë¡£Çë°´ÕÕÏÂÃæµÄ²½Öè¶ÔÓ³Éä½øÐиüÕý£º ±à¼ /etc/security/ldap/sfu30user.map Îļþ£¬ÕÒµ½ÒÔµ¥´Ê spassword ¿ªÍ·µÄÐУ¬ÀýÈç spassword SEC_CHAR msSFU30Password s
£¬½« msSFU30Password Ì滻Ϊ unicodePwd¡£ËäÈ»ÉÏÃæµÄʾÀýÖÐÏÔʾµÄÊÇ msSFU30Password£¬µ«Ò²¿ÉÄÜÊÇÆäËûµÄÄÚÈÝ¡£
ÕâÒ»Ðбä³ÉÁË£º spassword SEC_CHAR unicodePwd s
±£´æ¸ÃÎļþ¡£ ÖØÐÂÆô¶¯ secldapclntd ÊØ»¤½ø³ÌÒÔʹÉÏÃæµÄ¸ü¸ÄÉúЧ£º # restart-secldapclntd
ÒªÔÊÐí Windows Óû§µÇ¼µ½ AIX 5L ²Ù×÷ϵͳ£¬¹ÜÀíÔ±ÐèҪͨ¹ýÔÚ AIX 5L ²Ù×÷ϵͳÖÐÔËÐÐÏÂÁÐÃüÁ¶ÔÓû§µÄ SYSTEM ºÍ registry ÊôÐÔ½øÐÐÕýÈ·ÉèÖ㺠# chuser -R LDAP SYSTEM=LDAP registry=LDAP foo
ÆäÖУ¬foo ÊÇ Active Directory Öж¨ÒåµÄÒ»¸öʾÀýÓû§¡£
ÔÚÍê³É¸Ã¸ü¸ÄÖ®ºó£¬Óû§ foo ¾Í¿ÉÒÔʹÓÃÆä Windows ÃÜÂëµÇ¼µ½ AIX 5L ²Ù×÷ϵͳ¡£
Èç¹ûÒªÈÃËùÓÐµÄ Windows Óû§¶¼Äܹ»µÇ¼µ½ AIX 5L ²Ù×÷ϵͳ£¬ÎªÃ¿¸öÓû§½øÐÐÉÏÊöµÄ²Ù×÷¿ÉÄܷdz£Âé·³¡£ÔÚÕâЩÇé¿öÏ£¬¹ÜÀíÔ±¿ÉÒÔÊÖ¶¯±à¼ /etc/security/user Îļþ£¬²¢½« default ½ÚµÄ SYSTEM ºÍ registry ÊôÐÔÉèÖÃΪ LDAP¡£Èç¹û default ½ÚÖв»°üº¬ÕâЩÊôÐÔ£¬ÄÇôÐèÒªÌí¼ÓËüÃÇ¡£default ½ÚÓ¦¸ÃÓëÏÂÃæËùʾÀàËÆ£º |