AIX 5L LDAP Óû§¹ÜÀí
11/27/06 15:33:55 11/28/06 01:33:28 krbtgt/ADDOMAIN.ABC.COM@ADDOMAIN.ABC.COM Renew until 11/28/06 15:33:55 #
ÅäÖà AIX 5L LDAP ÒÔʹÓà Active Directory¡£
ҪʹÓà mksecldap ÃüÁî¶Ô AIX 5L LDAP ½øÐÐÅäÖÃÒÔʹÓà Active Directory£¬Çë°´ÕÕÇ°ÃæµÄ¡°ÅäÖà AIX 5L ÒÔʹÓà unix_auth ģʽÓë Active Directory Ðͬ¹¤×÷¡±²¿·ÖÖеÄ˵Ã÷½øÐвÙ×÷¡£²»ÒªÎªÓû§ÉèÖà SYSTEM ºÍ registry ÊôÐÔ£¬²»ÒªÐÞ¸Ä /etc/security/user ÎļþµÄ default ½Ú¡£ ´´½¨ KRB5ALDAP ¸´ºÏ¼ÓÔØÄ£¿é¡£
Ïò /usr/lib/security/methods.cfg ÎļþÖÐÊÖ¶¯×·¼ÓÏÂÁÐÄÚÈÝ¡£ KRB5A: program = /usr/lib/security/KRB5A options = authonly KRB5ALDAP: options = db=LDAP,auth=KRB5A
»òÕߣ¬Èç¹û²»ÐèÒª TGT ÑéÖ¤£¬¿ÉÒÔ°´ÕÕÈçÏÂËùʾÉèÖø´ºÏ¼ÓÔØÄ£¿é¡£ÔÚÕâЩÇé¿öÏ£¬Äú¿ÉÒÔÊ¡ÂÔ²½Öè 5 ºÍ 6£¬Ö±½Óתµ½²½Öè 7¡£ KRB5A: program = /usr/lib/security/KRB5A options = tgt_verify=no KRB5ALDAP: options = db=LDAP,auth=KRB5A
ÔÚ Windows ·þÎñÆ÷ÉÏ´´½¨ AIX 5L Ö÷Ìå¡£ ÔÚ Windows ·þÎñÆ÷ÉÏ´´½¨Ò»¸öÓû§ÕÊ»§¡£Ê¹Óà AIX 5L Ö÷»úÃû×÷ΪÓû§Ãû£¬ÀýÈç aixhost¡£ ͨ¹ýÔÚ Windows ·þÎñÆ÷ÉÏÔËÐÐ ktpass ÃüÁ½«¸ÃÕÊ»§Ó³ÉäΪ AIX 5L Ö÷»úÖ÷Ì壬²¢½« ktpass ÃüÁîµÄ keytab Êä³öµ½Ò»¸öÎļþ¡£ ktpass ¨C princ host/aixhost.ibmabc.com@ADDOMAIN.ABC.COM ¨Cmapuser aixhost ¨Cpass password ¨Cout aixhost.keytab
½« aixhost.keytab Îļþ¸´ÖƵ½ AIX ϵͳ£¬²¢Ê¹Óà ktutil ¹¤¾ß½«ÃÜÔ¿Ìí¼Óµ½ AIX keytab¡£ # /usr/krb5/sbin/ktutil ktutil: rkt aixhost.keytab ktutil: wkt /etc/krb5/krb5.keytab ktutil: q
ÔÊÐí Windows Óû§µÇ¼µ½ AIX 5L ²Ù×÷ϵͳ¡£
ÒªÔÊÐí Windows Óû§Ê¹Óà KRB5ALDAP »úÖƵǼµ½ AIX 5L ²Ù×÷ϵͳ£¬¹ÜÀíÔ±ÐèÒªÔÚ AIX 5L ²Ù×÷ϵͳÖÐÔËÐÐÏÂÃæµÄÃüÁ # chuser -R KRB5ALDAP SYSTEM=KRB5ALDAP registry=KRB5ALDAP foo
ÆäÖУ¬foo ÊÇÒ»¸öʾÀýÓû§¡£
ÔÚ½øÐÐÁ˸ü¸ÄÖ®ºó£¬Windows Óû§¿ÉÒÔʹÓÃËûÃÇµÄ Windows ÃÜÂëµÇ¼µ½ AIX 5L ²Ù×÷ϵͳ¡£²»ÐèÒªÔÚ AIX 5L ²Ù×÷ϵͳÖд´½¨ÏàÓ¦µÄÓû§¡£Óû§µÄ±êʶÐÅÏ¢À´×ÔÓÚ Windows Active Directory¡£
Èç¹ûÒªÈÃËùÓÐµÄ Windows Óû§¶¼Äܹ»µÇ¼µ½ AIX 5L ²Ù×÷ϵͳ£¬ÎªÃ¿¸öÓû§½øÐÐÉÏÊöµÄ²Ù×÷¿ÉÄܷdz£Âé·³¡£ÔÚÕâЩÇé¿öÏ£¬¹ÜÀíÔ±¿ÉÒÔÊÖ¶¯±à¼ /etc/security/user Îļþ£¬²¢½« default ½ÚµÄ SYSTEM ºÍ registry ÊôÐÔÉèÖÃΪ KRB5ALDAP¡£Èç¹û default ½ÚÖв»°üº¬ÕâЩÊôÐÔ£¬ÄÇôÐèÒªÌí¼ÓËüÃÇ¡£default ½ÚÓ¦¸ÃÓëÏÂÃæËùʾÀàËÆ£º default: ... SYSTEM = KRB5ALDAP registry = KRB5ALDAP ...
Èç¹ûÒѽ« default ½Ú¸ü¸ÄΪ KRB5ALDAP£¬ÕâЩ±¾µØ¶¨ÒåµÄÓû§¿ÉÄÜÎÞ·¨µÇ¼µ½ AIX 5L ²Ù×÷ϵͳ£¬³ý·Ç½«ËûÃÇµÄ SYSTEM ÉèÖÃΪ compat£¬registry ÉèÖÃΪ files¡£¹ÜÀíÔ±ÐèÒªÕÒ³öÕâЩÕÊ»§£¬²¢ÎªÃ¿¸öÓû§ÔËÐÐÏÂÃæµÄÃüÁîÒÔ½øÐÐÏàÓ¦µÄ¸ü¸Ä¡£ # chuser SYSTEM=compat registry=files <local user> |