Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # This an example of a config file:
- # See slapd.conf(5)
- # Global Directives:
- # Schema and objectClass definitions
- include /etc/ldap/schema/core.schema
- include /etc/ldap/schema/cosine.schema
- include /etc/ldap/schema/nis.schema
- include /etc/ldap/schema/inetorgperson.schema
- include /etc/ldap/schema/misc.schema
- # Where the pid file is put. The init.d script
- # will not stop the server if you change this.
- pidfile /var/run/slapd/slapd.pid
- # List of arguments that were passed to the server
- argsfile /var/run/slapd/slapd.args
- # Read slapd.conf(5) for possible values
- # Change loglevel to "any" if you want to see everything.
- loglevel none
- # Where the dynamically loaded modules are stored
- modulepath /usr/lib/ldap
- # Here are the recommended modules:
- # module for meta-database
- moduleload back_meta.la
- # module for the target ldap-server
- moduleload back_ldap.la
- # module for your local database
- moduleload back_hdb.la
- # module for rewriting attributes
- moduleload rwm
- # caching module
- moduleload pcache.la
- # module to enable memberof in ldap
- moduleload memberof.la
- # The maximum number of entries that is returned for a search operation
- sizelimit unlimited
- timelimit 5
- # The tool-threads parameter sets the actual amount of cpu's that is used
- # for indexing.
- tool-threads 1
- # See slapd-meta
- # database type, for multiple ADS "meta" is required
- database meta
- network-timeout 3
- timeout 3
- # now we create a local ldap tree
- # in our tree we put the multiple ADS on different branches
- # we need a suffix, an admin, and a password
- suffix "dc=domain"
- rootdn "cn=Administrator,cn=Users,dc=domain"
- rootpw {SSHA}xxx
- overlay rwm
- rwm-map attribute samaccountname *
- rwm-map attribute cn *
- rwm-map attribute uid *
- rwm-map attribute l l
- rwm-map attribute telephoneNumber *
- rwm-map attribute name *
- rwm-map attribute mail *
- rwm-map attribute mailNickname *
- rwm-map attribute objectCategory *
- rwm-map attribute sn *
- rwm-map attribute givenName *
- rwm-map attribute entryuuid *
- rwm-map attribute nsuniqueid *
- rwm-map attribute objectguid *
- rwm-map attribute objectsid *
- rwm-map attribute guid *
- rwm-map attribute ipauniqueid *
- rwm-map attribute jpegphoto *
- rwm-map attribute thumbnailphoto *
- rwm-map attribute dn *
- rwm-map attribute memberof *
- rwm-map attribute member *
- #rwm-map attribute 1.1 *
- # DIese Zeile ignoriert alle nicht oben genannten Attribute!
- rwm-map attribute *
- onerr stop
- uri "xxx"
- readonly yes
- norefs yes
- lastmod off
- chase-referrals no
- rebind-as-user yes
- suffixmassage "xxx" "yyy"
- idassert-bind
- bindmethod=simple
- binddn=""
- credentials=""
- tls_reqcert=allow
- uri "xxx"
- readonly yes
- norefs yes
- lastmod off
- chase-referrals no
- rebind-as-user no
- suffixmassage "xxx" "yyy"
- # authentication parameters
- idassert-bind bindmethod=simple binddn="" credentials="password"
- uri "xxx"
- readonly yes
- norefs yes
- lastmod off
- chase-referrals no
- rebind-as-user no
- suffixmassage "xxx" "yyy"
- # authentication parameters
- idassert-bind bindmethod=simple binddn="" credentials="password"
- # Next one is optional, if you want memberof, for the groups,
- # you have to load it.
- #overlay memberof
- # Now we load the caching module
- #overlay pcache
- # The directive enables proxy caching
- # See slapo-pcache
- # pcache <database> <max_entries> <numattrsets> <entry_limit> <cc_period>
- # Parameters:
- #
- # <database> for cached entries.
- # <max_entries> when reached - cache replacement is invoked
- # <numattrsets> = pcacheAttrset
- # <entry_limit> limit to the number of entries returned
- # <cc_period> Consistency check time to wait
- #pcache hdb 100000 1 1000 100
- # pcachePersist { TRUE | FALSE }
- # Write cached results into the database
- # Results remain in database after restart
- #pcachePersist TRUE
- # Where the database files are physically stored for database #1
- #directory "/var/lib/ldap"
- # Caching templates for general search
- # pcacheTemplate <template_string> <attrset_index> <ttl>
- # First define the query sting to cache
- # Then reference the Attrset
- # Last set the time-to-live
- #pcacheAttrset 0 objectCategory sAMAccountName l cn
- #pcacheTemplate (&(objectCategory=)(sAMAccountName=)) 0 3600
- #pcacheTemplate (sn=) 0 3600
- #pcacheTemplate (dn=) 0 3600
- #pcacheTemplate (&(objectCategory=)(samaccountname=)) 0 3600
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement