Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ################################## MASTER OPENLDAP ####################
- #######################################################################
- # slapd.conf
- #######################################################################
- include /etc/openldap/schema/core.schema
- include /etc/openldap/schema/cosine.schema
- include /etc/openldap/schema/nis.schema
- include /etc/openldap/schema/inetorgperson.schema
- include /etc/openldap/slapd.acl
- modulepath /usr/lib/openldap
- moduleload back_hdb.la
- moduleload syncprov.la
- moduleload back_monitor.la
- moduleload back_ldap.la
- pidfile /var/run/openldap/slapd.pid
- argsfile /var/run/openldap/slapd.args
- loglevel sync stats
- database hdb
- suffix "dc=mydomain,dc=org"
- directory /var/lib/ldap
- checkpoint 1024 5
- cachesize 10000
- idlcachesize 10000
- index objectClass eq
- # rest of indexes
- index default sub
- rootdn "cn=admin,dc=mydomain,dc=org"
- rootpw mydomain
- # syncprov specific indexing
- index entryCSN eq
- index entryUUID eq
- # syncrepl Provider for primary db
- overlay syncprov
- syncprov-checkpoint 1000 60
- # Let the replica DN have limitless searches
- limits dn.exact="cn=replicator,dc=mydomain,dc=org" time.soft=unlimited time.hard=unlimited size.soft=unlimited size.hard=unlimited
- database monitor
- database config
- rootpw mydomain
- database ldap
- # ignore conflicts with other databases, as we need to push out to same suffix
- hidden on
- suffix "dc=mydomain,dc=org"
- rootdn "cn=slapd-ldap"
- uri ldap://192.168.2.28:389/
- lastmod on
- # We don't need any access to this DSA
- restrict all
- acl-bind bindmethod=simple
- binddn="cn=replicator,dc=mydomain,dc=org"
- credentials=testing
- syncrepl rid=001
- provider=ldap://localhost:389/
- binddn="cn=replicator,dc=mydomain,dc=org"
- bindmethod=simple
- credentials=testing
- searchbase="dc=mydomain,dc=org"
- type=refreshAndPersist
- retry="5 5 300 5"
- overlay syncprov
- ###########################################################
- ## slapd.acl ###
- ###########################################################
- access to * by dn.base="cn=replicator,dc=mydomain,dc=org" write by * break
- access to dn.base="" by * read
- access to dn.base="cn=Subschema" by * read
- access to dn.subtree="cn=Monitor" by dn.exact="uid=admin,dc=mydomain,dc=org" write by users read by * none
- access to * by self write by * read
- ###########################################################
- ## file.ldif ###
- ###########################################################
- dn: dc=mydomain,dc=org
- objectClass: dcObject
- objectClass: organization
- dc: mydomain
- o : mydomain
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement