![]() | |
Sun Java(TM) System Directory Server 5.2 2005Q1 ¹ÜÀíÖ¸ÄÏ |
µÚ 1 ÕÂ
Directory Server ¹ÜÀí¸ÅÊöDirectory Server ²úÆ·°üÀ¨Ò»¸ö Directory Server¡¢Ò»¸öÓÃÓÚ¹ÜÀí¶à¸öĿ¼µÄ Administration Server ºÍÒ»¸öͨ¹ýͼÐνçÃæ¹ÜÀíÕâÁ½Ì¨·þÎñÆ÷µÄ Server Console¡£±¾Õ¸ÅÀ¨µØ½éÉÜÓÐ¹Ø Directory Server µÄÐÅÏ¢ÒÔ¼°¹ÜÀíĿ¼·þÎñʱËùÐèµÄ×î»ù±¾²Ù×÷¡£
ÑéÖ¤²å¼þÇ©ÃûÊÇÒ»ÖÖ¸½¼Ó°²È«¹¦ÄÜ£¬ËüÔÊÐí·þÎñÆ÷¼ì²â»ò·ÀÖ¹¼ÓÔØÎ´¾ÊÚȨµÄ²å¼þ¡£Ä¿Â¼·þÎñÆ÷±ê¼ÇÓïÑÔ (DSML) ÊÇÒ»ÖÖеĻùÓÚ XML µÄ¸ñʽ£¬ÓÃÓÚ½«ÇëÇó·¢Ë͵½Ä¿Â¼·þÎñÆ÷¡£
±¾Õ°üº¬ÒÔÏÂС½Ú£º
Directory Server ¹ÜÀí¸ÅÊöDirectory Server ÊÇÒ»ÖÖÇ¿´óÇÒ¾ßÉìËõÐԵķþÎñÆ÷£¬ÓÃÓÚ¹ÜÀíÆóÒµ·¶Î§ÄÚµÄÓû§ºÍ×ÊԴĿ¼¡£Ëü»ùÓÚÃûΪÇáÐÍĿ¼·ÃÎÊÐÒé (LDAP) µÄ¿ª·Åϵͳ·þÎñÆ÷ÐÒé¡£Directory Server ×÷Ϊ¼ÆËã»úÉ쵀 ns-slapd ½ø³Ì»ò·þÎñÔËÐС£¸Ã·þÎñÆ÷¹ÜÀíĿ¼ÄÚÈݲ¢¶Ô¿Í»§»úÇëÇó×÷³öÏìÓ¦¡£
Administration Server ÊÇÓÉ Sun Java System ÌṩµÄ¸¨Öú·þÎñÆ÷£¬ÓÃÓÚ°ïÖúÄú¹ÜÀí Directory Server£¨ÒÔ¼°ÆäËû Sun Java System ·þÎñÆ÷£©£¬Í¨¹ýËü£¬Äú¿ÉÒÔÖ´Ðдó¶àÊý Directory Server ¹ÜÀíÈÎÎñ¡£Server Console ÊÇ Administration Server µÄͼÐνçÃæ¡£Directory Server Console ÊÇ Server Console µÄÒ»²¿·Ö£¬×¨ÃÅΪÓë Directory Server Ò»ÆðʹÓöøÉè¼Æ¡£
ͨ¹ý Directory Server Console ¿ÉÒÔÖ´Ðдó¶àÊý Directory Server ¹ÜÀíÈÎÎñ¡£ÄúÒ²¿ÉÒÔͨ¹ý±à¼ÅäÖÃÎļþ»òʹÓÃÃüÁîÐÐʵÓóÌÐòÀ´ÊÖ¶¯Ö´ÐйÜÀíÈÎÎñ¡£ÓÐ¹Ø Server Console µÄÏêϸÐÅÏ¢£¬Çë²Î¼û Administration Server Administration Guide¡£
×¢
Èç¹ûÕýÔÚʹÓà Sun Cluster HA for Directory Server Êý¾Ý·þÎñ£¬ÄÇôͨ¹ýÃüÁîÐйÜÀí Directory Server ʱ£¬±ØÐëʹÓà directoryserver(1M) ÃüÁî¼°Æä×ÓÃüÁî¡£
²»ÒªÖ±½ÓʹÓöÀÁ¢½Å±¾ºÍ¶þ½øÖÆÊý¾Ý¡£
Æô¶¯ºÍÍ£Ö¹ Directory ServerÈç¹ûĿǰûÓÐʹÓð²È«Ì×½Ó×Ö²ã (SSL)£¬Ôò¿ÉÒÔʹÓÃÕâÀïÁгöµÄ·½·¨Æô¶¯ºÍÍ£Ö¹ Directory Server¡£Èç¹ûÕýÔÚʹÓà SSL£¬Çë²Î¼ûÔÚÆôÓà SSL µÄÇé¿öÏÂÆô¶¯·þÎñÆ÷¡£
ͨ¹ýÃüÁîÐÐÆô¶¯ºÍÍ£Ö¹·þÎñÆ÷
Ҫͨ¹ýÃüÁîÐÐÆô¶¯»òÍ£Ö¹·þÎñÆ÷£¬ÇëÔËÐÐÒÔÏÂÃüÁ
»òÕß
Ö»Óе± Directory Server 5.2 ²»ÊÇĬÈϰ汾ʱ£¬²ÅÐèÒª useversion Ñ¡Ïî¡£ÓÐ¹Ø directoryserver ÃüÁîµÄÍêÕûÓï·¨£¬Çë²Î¼û Directory Server Man Page Reference¡£
Èç¹û½«³¬¼¶Óû§Ö¸¶¨Îª Directory Server UID£¬Ôò±ØÐëÒÔ³¬¼¶Óû§Éí·ÝÀ´ÔËÐÐÕâЩÃüÁî¡£
·ñÔò£¬±ØÐëÒÔ³¬¼¶Óû§Éí·ÝÀ´ÔËÐÐÕâÁ½¸öÃüÁ»òÕßʹÓÃÓë Directory Server ÏàͬµÄ UID ºÍ GID À´ÔËÐÐÕâÁ½¸öÃüÁî¡£ÀýÈ磬Èç¹ûÒÔ nobody ÔËÐÐ Directory Server£¬Ôò±ØÐëÒ²ÒÔ nobody ÔËÐÐ start ºÍ stop ʵÓóÌÐò¡£
¶ÔÓÚʹÓà Directory Server ÔçÆÚ°æ±¾µÄÓû§£¬Çë×¢ÒâÔÚÒýÓÃģʽÏÂÆô¶¯·þÎñÆ÷½«²»ÔÙ¿ÉÐС£Äú¿ÉÒÔʹÓà Directory Server Console ÉèÖÃÈ«¾ÖÒýÓá£ÉèÖÃĬÈÏÒýÓÃÖжԴ˹ý³Ì½øÐÐÁË˵Ã÷¡£
ͨ¹ý¿ØÖÆÌ¨Æô¶¯ºÍÍ£Ö¹·þÎñÆ÷
µ± Directory Server Console ÕýÔÚÔËÐÐʱ£¬¿ÉÒÔͨ¹ýÆäͼÐνçÃæÆô¶¯¡¢Í£Ö¹ºÍÖØÐÂÆô¶¯ Directory Server¡£ÓйØÔËÐпØÖÆÌ¨µÄ˵Ã÷£¬Çë²Î¼ûÆô¶¯ Directory Server Console¡£
ͨ¹ý Directory Server Console ³É¹¦µØÆô¶¯»òÍ£Ö¹ Directory Server ºó£¬¿ØÖÆÌ¨½«ÏÔʾһ¸öÏûÏ¢¶Ô»°¿ò£¬ËµÃ÷ÒÑÆô¶¯»ò¹Ø±Õ·þÎñÆ÷¡£ÔÚ³öÏÖ´íÎóµÄÇé¿öÏ£¬¿ØÖÆÌ¨½«ÏÔʾÓë´íÎóÏà¹ØµÄËùÓÐÏûÏ¢¡£
ÔÚÆôÓà SSL µÄÇé¿öÏÂÆô¶¯·þÎñÆ÷
ÆôÓà SSL ֮ǰ£¬±ØÐëÔÚ·þÎñÆ÷Éϰ²×°ºÍÅäÖÃÖ¤Êé¡£ÓйعÜÀíÖ¤ÊéºÍÆôÓà SSL µÄ˵Ã÷£¬Çë²Î¼ûµÚ 11 Õ¡°¹ÜÀíÑéÖ¤ºÍ¼ÓÃÜ¡±ÓйØÖ¤Êé¡¢Ö¤ÊéÊý¾Ý¿âºÍ»ñÈ¡·þÎñÆ÷Ö¤ÊéµÄÐÅÏ¢£¬Çë²Î¼û Administration Server Administration Guide¡£
ÒªÔÚÆôÓà SSL µÄÇé¿öÏÂÆô¶¯·þÎñÆ÷£¬±ØÐëͨ¹ýÃüÁîÐÐÆô¶¯·þÎñÆ÷£¬²¢Ìṩ±£»¤·þÎñÆ÷Ö¤ÊéµÄÃÜÂë¡£
»òÕߣ¬¿ÉÒÔ´´½¨ÃÜÂëÎļþÀ´´æ´¢Ö¤ÊéÃÜÂ롣ͨ¹ý½«Ö¤ÊéÊý¾Ý¿âµÄÃÜÂë´æ·ÅÔÚÒ»¸öÎļþÖУ¬±ã¿ÉÒÔͨ¹ý·þÎñÆ÷¿ØÖÆÌ¨Æô¶¯·þÎñÆ÷£¬»¹¿ÉÒÔÔÊÐí·þÎñÆ÷ÔÚÎÞÈË¿´¹Ü״̬ÏÂÔËÐÐʱ£¬×Ô¶¯µØÖØÐÂÆô¶¯¡£
¾¯¸æ
´ËÃÜÂëÒÔÃ÷ÎÄÐÎʽ´æ´¢ÔÚÃÜÂëÎļþÖУ¬ËùÒÔʹÓÃÃÜÂëÎļþÓкܴóµÄ°²È«Òþ»¼¡£Èç¹û·þÎñÆ÷ÔÚ²»°²È«µÄ»·¾³ÖÐÔËÐУ¬ÇëÎðʹÓÃÃÜÂëÎļþÕâÖÖ·½Ê½¡£
±ØÐ뽫´ËÃÜÂëÎļþ·ÅÔÚÒÔÏÂλÖãº
ServerRoot/alias/slapd-serverID-pin.txt
ÆäÖÐ serverID Êǰ²×°·þÎñÆ÷ʱΪÆäÖ¸¶¨µÄ±êʶ·û¡£
ÔÚ´ËÎļþÖаüÀ¨ÈçϵݲȫÁîÅÆÃû¼°ÆäÃÜÂ룺
tokenName:password
´ËʾÀýÖÐÏÔʾÁËÄÚ²¿Ö¤ÊéÊý¾Ý¿âµÄÉ豸Ãû³Æ£¨´óдºÍ¿Õ¸ñ±ØÐëÍêÈ«ÓëÏÔʾµÄÒ»Ö£©£º
Internal (Software) Token:password
Èç¹û½«Ö¤Êé´æ´¢ÔÚ±¸ÓÃÉ豸ÉÏ£¬ÇëʹÓÓ¹ÜÀíÖ¤Êé¶Ô»°¿ò”¶¥²¿µÄÏÂÀ²Ëµ¥ÖÐÏÔʾµÄÉ豸Ãû³Æ¡£Òª´´½¨Ö¤ÊéÊý¾Ý¿â£¬±ØÐëʹÓà Administration Server ºÍ“Ö¤ÊéÉèÖÃÏòµ¼”¡£
Èç¹ûÒªÔÚÆôÓà SSL µÄÇé¿öÏÂÆô¶¯·þÎñÆ÷£¬µ«½ûÖ¹·þÎñÆ÷ÕìÌý·Ç SSL ¶Ë¿Ú£¬Ôò¿ÉÒÔ½« nssldap-listenhosts ÉèÖÃΪ»ØË͵ØÖ· 127.0.0.1¡£»òÕߣ¬Ò²¿ÉÒÔ½« nsslapd-port ÊôÐÔÉèÖÃΪ 0£¬¾¡¹ÜÕâÑù×ö¿ÉÄÜ»áÖжÏijЩ¹ÜÀí½Å±¾£¬Èç monitor¡¢db2bak.pl ºÍ ldif2db.pl¡£
ÓйØÔÚ Directory Server ÖÐʹÓà SSL µÄÐÅÏ¢£¬Çë²Î¼ûµÚ 11 Õ¡°¹ÜÀíÑéÖ¤ºÍ¼ÓÃÜ¡±¡£
ÔÚСÓÚ 1024 µÄ¶Ë¿ÚÉÏÒԷdz¬¼¶Óû§Éí·ÝÆô¶¯·þÎñÆ÷
ͨ³££¬Èç¹û¶Ë¿ÚСÓÚ 1024£¬Äú±ØÐëÊdz¬¼¶Óû§²ÅÄÜÆô¶¯ Directory Server¡£ÔÚÒÔϹý³ÌÖУ¬Äú¿ÉÒÔʹÓÃÖ¸¶¨µÄ·Ç³¬¼¶Óû§¡£
- °²×° Directory Server ºÍ Administration Server¡£ÔÚÅäÖ÷þÎñÆ÷ʱ£¬È·±£ÕâÁ½¸ö·þÎñÆ÷µÄÓû§Îª³¬¼¶Óû§¡£
ʹÓà Java Enterprise System °²×°Ö¸ÄÏÖеݲװ˵Ã÷¡£
- Í£Ö¹ Directory Server¡£Çë²Î¼ûÆô¶¯ºÍÍ£Ö¹ Directory Server¡£
- ÔÚ ServerRoot Ŀ¼ÖÐÔËÐÐÒÔÏÂÃüÁ½«Ä¿Â¼ºÍÎļþÓµÓÐȨ¸ü¸ÄΪËùÐèµÄ userID¡£
chown -R userID:groupID slapd-hostname
chown -R userID:groupID alias/slapd-hostname-*.db
- ±à¼ dse.ldif Îļþ£¬½« nsslapd-localuser ÖµÓÉ root ¸ü¸ÄΪËùÐèµÄ userID¡£
- ÖØÐÂÆô¶¯ Directory Server¡£Çë²Î¼ûÆô¶¯ºÍÍ£Ö¹ Directory Server¡£
ʹÓà Directory Server ConsoleDirectory Server Console ÊÇÒ»¸ö½çÃæ£¬¿ÉÒÔ×÷Ϊ Server Console µÄÒ»¸ö¶ÀÁ¢´°¿Ú¶ÔÆä½øÐзÃÎÊ¡£¿ÉÒÔ´Ó Server Console Æô¶¯ Directory Server Console£¬Æä²½ÖèÈçÏ¡£
Æô¶¯ Directory Server Console
- ¼ì²é Directory Server ÊØ»¤½ø³Ì slapd-serverID ÊÇ·ñÕýÔÚÔËÐС£Èç¹ûûÓÐÔËÐУ¬ÇëÒÔ³¬¼¶Óû§»ò¹ÜÀíÓû§Éí·ÝÊäÈëÒÔÏÂÃüÁîÀ´Æô¶¯Ëü£º
- ¼ì²é Administration Server ÊØ»¤½ø³Ì ns-httpd ÊÇ·ñÕýÔÚÔËÐС£Èç¹ûûÓÐÔËÐУ¬ÇëÒÔ³¬¼¶Óû§»ò¹ÜÀíÓû§Éí·ÝÊäÈëÒÔÏÂÃüÁîÀ´Æô¶¯Ëü£º
Èç¹ûÔÚδ°²×° Administration Server µÄ¼ÆËã»úÉÏÔËÐÐ Server Console£¬Ôò¿ÉÄÜÐèÒªÔÚ Administration Server ÉÏÅäÖÃÁ¬½ÓÏÞÖÆ£¬Èç Administration Server Administration Guide ÖÐËùÊö¡£
ÆÁÄ»ÉϽ«ÏÔʾ“¿ØÖÆÌ¨”µÇ¼´°¿Ú¡£»òÕߣ¬Èç¹ûÄúµÄÅäÖÃĿ¼£¨¼´°üº¬ o=NetscapeRoot ºó׺µÄĿ¼£©´æ´¢ÔÚµ¥¶ÀµÄ Directory Server ʵÀýÖУ¬ÄÇôÆÁÄ»ÉϽ«ÏÔʾһ¸ö´°¿Ú£¬ÒªÇóÄúÊäÈë¹ÜÀíÔ±Óû§ DN ºÍÃÜÂ룬ÒÔ¼°¸ÃĿ¼·þÎñÆ÷µÄ Administration Server µÄ URL¡£
- ʹÓþßÓÐ×ã¹»·ÃÎÊȨÏÞµÄÓû§°ó¶¨ DN ºÍÃÜÂëµÇ¼¡£
ÆÁÄ»ÉϽ«ÏÔʾ Server Console¡£
- ä¯ÀÀ×óÃæ°åÖеÄÊ÷£¬ÕÒ³ö Directory Server ËùÔÚµÄÖ÷»ú£¬È»ºóµ¥»÷´Ë¼ÆËã»úµÄÃû³Æ»òͼ±êÀ´ÏÔʾÆä³£¹æÊôÐÔ¡£
ͼ 1-1 Sun Java System Server Console
Òª±à¼ Directory Server µÄÃû³ÆºÍ˵Ã÷£¬Çëµ¥»÷“±à¼”°´Å¥¡£ÔÚÎı¾¿òÖÐÊäÈëеÄÃû³ÆºÍ˵Ã÷¡£µ¥»÷“È·¶¨”ÉèÖÃÐÂÃû³ÆºÍ˵Ã÷¡£Ãû³Æ½«ÏÔʾÔÚ×ó²àµÄÊ÷ÖУ¬ÈçÉÏͼËùʾ¡£
- ÔÚÊ÷ÖÐË«»÷ Directory Server µÄÃû³Æ»òµ¥»÷“´ò¿ª”°´Å¥£¬ÒÔÏÔʾÓÃÓÚ¹ÜÀí´ËĿ¼·þÎñÆ÷µÄ Directory Server Console¡£
ä¯ÀÀ Directory Server Console
Directory Server Console ÌṩÁ˽çÃæ£¬ÓÃÓÚä¯ÀÀ Directory Server ʵÀý²¢Ö´ÐйÜÀí²Ù×÷¡£ÆäÖУ¬Ê¼ÖÕÏÔʾËĸöÑ¡Ï£¬Í¨¹ýÕâЩѡÏÄú¿ÉÒÔ·ÃÎÊËùÓÐ Directory Server ¹¦ÄÜ£º
“ÈÎÎñ”Ñ¡Ï
´ò¿ª Directory Server Console ʱ£¬¿´µ½µÄµÚÒ»¸ö½çÃæ¾ÍÊÇ“ÈÎÎñ”Ñ¡Ï¡£ÆäÖÐËù°üº¬µÄ°´Å¥¿ÉÓÃÓÚÖ´Ðи÷ÖÖÖ÷ÒªµÄ¹ÜÀíÈÎÎñ£¨ÈçÆô¶¯»òÍ£Ö¹ Directory Server£©£¬ÈçÏÂͼËùʾ¡£Òª²é¿´ËùÓÐÈÎÎñ¼°Æä¶ÔÓ¦°´Å¥£¬¿ÉÄÜÐèÒª¹ö¶¯ä¯ÀÀÕû¸öÁÐ±í¡£
ͼ 1-2 Directory Server Console µÄ“ÈÎÎñ”Ñ¡Ï
±ØÐëÒÔ¾ßÓйÜÀíԱȨÏÞµÄÓû§Éí·ÝµÇ¼£¬²ÅÄÜÖ´ÐÐÕâЩÈÎÎñ¡£¶ÔÓÚûÓÐ×㹻ȨÏÞµÄÓû§£¬ÈÎÎñ°´Å¥½«²»¿É¼û¡£
“ÅäÖÔѡÏ
Directory Server Console µÄ“ÅäÖÔѡÏÌṩÁ˽çÃæºÍ¶Ô»°¿ò£¬ÓÃÓڲ鿴ºÍÐ޸ĸ÷ÖÖĿ¼ÉèÖã¨Èçºó׺¡¢¸´ÖÆ¡¢Ä£Ê½¡¢ÈÕÖ¾ºÍ²å¼þµÄĿ¼ÉèÖã©¡£Ö»ÓÐÔÚÒԾ߱¸¹ÜÀíԱȨÏÞµÄÓû§Éí·ÝµÇ¼ʱ£¬ÕâЩ¶Ô»°¿ò²Å¿ÉÓûòÉúЧ¡£
´ËÑ¡Ï×ó²à°üº¬Ò»¸ö´øÓÐËùÓÐÅäÖù¦ÄܵÄÊ÷£¬ÓÒ²àÔòÏÔʾרÓÃÓÚ¹ÜÀí¸÷¸ö¹¦ÄܵĽçÃæ¡£ÕâЩ½çÃæÍ¨³£°üº¬ÆäËûÑ¡Ï¡¢¶Ô»°¿ò»òµ¯³ö´°¿Ú¡£ÀýÈ磬ÏÂͼÏÔʾÁËÕû¸öĿ¼µÄ³£¹æÉèÖá£
ͼ 1-3 Directory Server Console µÄ“ÅäÖÔѡÏ
µ±ÔÚ×ó²àÊ÷ÖÐÑ¡Ôñij¸ö¿ÉÅäÖõÄÏîʱ£¬¸ÃÏîµÄµ±Ç°ÉèÖûáÏÔʾÔÚÓÒÃæ°åµÄÒ»¸ö»ò¶à¸öÑ¡ÏÖС£ÒªÁ˽âÕâЩÉèÖõÄ˵Ã÷ºÍÐÐΪ£¬Çë²Î¼û±¾Ö¸ÄÏÖоßÌå½éÉܸ÷ÏÄܵÄÕ½ڡ£¸ù¾ÝÉèÖÃÇé¿ö£¬Ä³Ð©¸ü¸Ä»áÔÚ±£´æÊ±Á¢¼´ÉúЧ£¬¶øÄ³Ð©¸ü¸ÄÔòÒªÔÚÖØÐÂÆô¶¯·þÎñÆ÷ºó²Å»áÉúЧ¡£µ±ÐèÒªÖØÐÂÆô¶¯·þÎñÆ÷ʱ£¬¿ØÖÆÌ¨½«ÏÔʾһ¸ö¶Ô»°¿ò֪ͨÄú¡£
Ñ¡ÏÃû³ÆÅԵĺìÉ«±ê¼Ç±íʾ¸ÃÑ¡ÏÖеĸü¸ÄÉÐδ±£´æ¡£¼´Ê¹ÔÚÅäÖÃÁíÒ»Ïî»ò²é¿´ÆäËûÖ÷ҪѡÏʱ£¬Î´±£´æµÄ¸ü¸ÄÈԻᱣÁôÔÚ¸ÃÑ¡ÏÖС£“±£´æ”ºÍ“¸´Î»”°´Å¥ÊÊÓÃÓÚ¸ø¶¨ÅäÖÃÏîµÄËùÓÐÑ¡Ï£¬µ«²»Ó°ÏìÆäËûÏîµÄδ±£´æÉèÖá£
´ó¶àÊýÎı¾×ֶνöÔÊÐí°´¸ÃÉèÖõÄÕýÈ·Óï·¨ÊäÈëÖµ¡£Ä¬ÈÏÇé¿öÏ£¬Èç¹ûÖµµÄÓï·¨²»ÕýÈ·£¬Ôò¸ÃÉèÖõıêÇ©ºÍÄúÊäÈëµÄÖµ½«»áÒÔºìɫͻ³öÏÔʾ¡£ÔÚËùÓÐÉèÖõÄÓï·¨¾ùÓÐЧ֮ǰ£¬“±£´æ”°´Å¥½«±»½ûÓ᣿ÉÒÔÑ¡ÔñÒÔбÌåÍ»³öÏÔʾ²»ÕýÈ·µÄÖµ£¬Èç¿ÉÊÓÅäÖÃÊ×Ñ¡ÏîÖÐËùÊö¡£
“Ŀ¼”Ñ¡Ï
¿ØÖÆÌ¨µÄ“Ŀ¼”Ñ¡ÏÒÔÊ÷µÄÐÎʽÏÔʾĿ¼ÌõÄ¿£¬ÒÔ·½±ãä¯ÀÀ¡£ÔÚ´ËÑ¡ÏÖУ¬¿ÉÒÔä¯ÀÀ¡¢ÏÔʾºÍ±à¼ËùÓÐÌõÄ¿¼°Æä°üº¬µÄÊôÐÔ¡£
×¢
Èç¹û¼Æ»®ä¯ÀÀ°üº¬Êýǧ¸öÌõÄ¿µÄÁÐ±í£¬Çë´´½¨ä¯ÀÀË÷Òý£¬ÒÔ±ã½øÐпìËÙ·ÃÎÊ¡£ÓйØËµÃ÷£¬Çë²Î¼ûÓÃÓÚ¿ØÖÆÌ¨µÄä¯ÀÀË÷Òý¡£
ͼ 1-4 Directory Server Console µÄ“Ŀ¼”Ñ¡Ï
Èç¹ûµÇ¼ÆÚ¼ä¸ø¶¨µÄ°ó¶¨ DN ¾ßÓÐ×ã¹»µÄ·ÃÎÊȨÏÞ£¬ÄÇôÅäÖÃÌõÄ¿½«±»ÊÓΪÆÕͨÌõÄ¿£¬¿ÉÒÔÖ±½Ó½øÐÐÐ޸ġ£²»¹ý£¬ÈôÒª°²È«µØ¸ü¸ÄÅäÖÃÉèÖã¬ÔòӦʼÖÕʹÓÓÅäÖÔѡÏÉϵĿÉÓöԻ°¿ò¡£
“ÊÓͼ”²Ëµ¥Ïµļ¸¸ö¿ÉÓÃÑ¡Ïî¿ÉÒÔÓÃÀ´¸ü¸Ä“Ŀ¼”Ñ¡ÏµÄ²¼¾ÖºÍÄÚÈÝ¡£ÐµIJ¼¾ÖÑ¡Ïî°üÀ¨ÔÚµ¥¸öÊ÷Öв鿴ËùÓÐÌõÄ¿£¨°üÀ¨Ò¶ÌõÄ¿£©£¬ÒÔ¼°ÔÚÓҲര¸ñÖÐÏÔʾÊôÐÔ¡£Ä¬ÈÏÉèÖÃÊÇÔÚÓÒ²à²é¿´Ò¶ÌõÄ¿£¬¶ø²»ÊÇÔÚ×ó²àµÄÊ÷Öв鿴¡£
“ÊÓͼ”>“ÏÔʾ”Ñ¡ÏîΪĿ¼Ê÷ÖеÄËùÓÐÌõÄ¿ÆôÓà ACI ¼ÆÊý¡¢½ÇÉ«¼ÆÊýºÍÍ£ÓÃ״̬ͼ±ê¡£ÔÚͼ 1-4 ÖУ¬ACI ¼ÆÊýºÍÒ¶ÌõÄ¿ÏÔʾÔÚ×ó²àÊ÷ÖУ¬¶øÑ¡¶¨ÌõÄ¿µÄÊôÐÔÖµÏÔʾÔÚÓҲര¸ñÖС£ÓйØÏêϸÐÅÏ¢£¬Çë²Î¼ûĿ¼Ê÷ÊÓͼѡÏî¡£
“״̬”Ñ¡Ï
“״̬”Ñ¡ÏÏÔʾ·þÎñÆ÷ͳ¼ÆÐÅÏ¢ºÍÈÕÖ¾ÏûÏ¢¡£×ó²àÊ÷ÖÐÁгöÁËÈ«²¿×´Ì¬Ïѡ¶¨Ä³Ïîºó£¬¸ÃÏîµÄÄÚÈÝ»áÏÔʾÔÚÓҲര¸ñÖС£ÀýÈ磬ÏÂͼÏÔʾÁËÒ»¸öÈÕÖ¾ÌõÄ¿±í¡£
ͼ 1-5 Directory Server Console µÄ“״̬”Ñ¡Ï
ͨ¹ý¿ØÖÆÌ¨²é¿´µ±Ç°°ó¶¨ DN
µ¥»÷ÏÔʾÆÁ×óϽǵĵǼͼ±ê£¬¿ÉÒԲ鿴µÇ¼µ½ Directory Server Console ʱʹÓÃµÄ°ó¶¨ DN¡£µ±Ç°°ó¶¨ DN ½«ÏÔʾÔڵǼͼ±êÅÔ£¬ÈçÏÂËùʾ£º
¸ü¸ÄµÇ¼Éí·Ý
ÔÚͨ¹ý Directory Server Console ´´½¨»ò¹ÜÀíÌõĿʱ£¬ÒÔ¼°ÔÚµÚÒ»´Î·ÃÎÊ Server Console ʱ£¬¿ÉÒÔÑ¡Ôñͨ¹ýÌṩ°ó¶¨ DN ºÍÃÜÂëÀ´µÇ¼¡£Õ⽫ʶ±ð·ÃÎÊ´ËĿ¼Ê÷µÄÓû§Éí·Ý£¬²¢È·¶¨ÆäÓÃÒÔÖ´ÐвÙ×÷µÄ·ÃÎÊȨÏÞ¡£
µÚÒ»´ÎÆô¶¯ Server Console ʱ£¬¿ÉÒÔʹÓÃĿ¼¹ÜÀíÔ± DN µÇ¼¡£Äú¿ÉÒÔËæÊ±Ñ¡ÔñÒÔÆäËûÓû§Éí·ÝµÇ¼£¬¶øÎÞÐèÍ£Ö¹²¢ÖØÐÂÆô¶¯¿ØÖÆÌ¨¡£
Òª¸ü¸ÄµÇ¼µ½ Server Console µÄÓû§Éí·Ý£¬ÇëÖ´ÐÐÒÔϲÙ×÷£º
- ÔÚ Directory Server Console ÉÏ£¬Ñ¡Ôñ“ÈÎÎñ”Ñ¡Ï£¬È»ºóµ¥»÷“ÒÔÐÂÓû§Éí·ÝµÇ¼ÖÁ Directory Server”±êÇ©ÅԱߵİ´Å¥¡£´ËÍ⣬µ±Î»ÓÚÆäËû¿ØÖÆÌ¨Ñ¡ÏÖÐʱ£¬¿ÉÒÔÑ¡Ôñ“¿ØÖÆÌ¨”>“ÒÔÐÂÓû§Éí·ÝµÇ¼”²Ëµ¥Ïî¡£
ÆÁÄ»ÉϽ«³öÏÖÒ»¸öµÇ¼¶Ô»°¿ò¡£
- ÊäÈëÐ嵀 DN ºÍÃÜÂ룬Ȼºóµ¥»÷“È·¶¨”¡£
ÊäÈëÒª°ó¶¨ÖÁ·þÎñÆ÷µÄÌõÄ¿µÄÍêÕû±êʶÃû¡£ÀýÈ磬Èç¹ûÒªÒÔĿ¼¹ÜÀíÔ±Éí·ÝÖ´Ðа󶨣¬ÇëÔÚ“±êʶÃû”Îı¾¿òÖÐÊäÈëÒÔÏ DN£º
cn=Directory Manager
ʹÓÃÁª»ú°ïÖú
Áª»ú°ïÖúΪ Directory Server Console Öд󲿷ÖÑ¡ÏºÍ¶Ô»°¿òÌṩÉÏÏÂÎÄÏà¹ØµÄÐÅÏ¢¡£“°ïÖú”°´Å¥Í¨³£Î»ÓÚÕâЩ½çÃæµÄÓÒϽǡ£ÔÚÈÎºÎÆÁÄ»ÉÏ£¬µ÷ÓÃÉÏÏÂÎÄÏà¹Ø°ïÖúµÄ¼üÅÌ¿ì½Ý¼ü×ÜÊÇ Alt-P¡£
µ÷ÓÃÁª»ú°ïÖú½«ÔÚ¿ØÖÆÌ¨µÄÄÚÖÃä¯ÀÀÆ÷ÖÐÏÔʾһ¸ö»ùÓÚ HTML µÄÒ³Ãæ¡£ÔÚ¸ÃÒ³ÃæÖУ¬¿ÉÒÔµ¥»÷“ÔÚä¯ÀÀÆ÷ÖÐÆô¶¯”°´Å¥£¬ÒÔ±ãÔÚÍⲿä¯ÀÀÆ÷£¨Èç Mozilla£©Öдò¿ªÏàͬµÄÒ³Ãæ¡£ÔÚÁª»ú°ïÖúÖУ¬Ö¸Ïò¸ü½øÒ»²½ÐÅÏ¢µÄÁ´½ÓÒ²»á´ò¿ªÒ»¸öÍⲿä¯ÀÀÆ÷´°¿Ú¡£
ÿ¸öÁª»ú°ïÖúÒ³Ãæ¶¼¶ÔÏàÓ¦µÄÑ¡Ï»ò¶Ô»°¿òÖеÄ×ֶκͰ´Å¥½øÐÐ˵Ã÷¡£µ±Í¨¹ý¿ØÖÆÌ¨½âÊÍ¡¢ÊäÈë»òÐÞ¸Äֵʱ£¬ÇëÔÚ¸ÃÐÅÏ¢µÄÖ¸µ¼ÏÂÍê³É¡£
Directory Server µÄ°ïÖúϵͳȡ¾öÓÚ Administration Server¡£Èç¹ûÕýÔÚ Administration Server µÄÔ¶³Ì¼ÆËã»úÖÐÔËÐÐ Directory Server Console£¬ÔòÐèÒªÑéÖ¤ÒÔÏÂÄÚÈÝ£º
- ¿ÉÄÜÐèÒªÅäÖÃÔÚ Administration Server ÉÏÇ¿ÖÆÊµÊ©µÄÁ¬½ÓÏÞÖÆ£¬ÒÔ±ãÔÊÐí¶ÔÄúµÄ¼ÆËã»ú½øÐзÃÎÊ£¬Èç Administration Server Administration Guide ÖÐËùÊö¡£
- Èç¹ûÏ£ÍûʹÓÃÍⲿä¯ÀÀÆ÷²é¿´Áª»ú°ïÖúÒ³£¬ÇÒä¯ÀÀÆ÷ÅäÖÃΪʹÓôúÀí£¬Ôò±ØÐëÖ´ÐÐÒÔϲÙ×÷Ö®Ò»£º
¿ØÖÆÌ¨¼ôÌù°å
Directory Server Console ʹÓÃϵͳ¼ôÌù°åÀ´¸´ÖÆ¡¢¼ôÇкÍÕ³ÌùÎı¾¡£ÔړĿ¼”Ñ¡ÏÖÐä¯ÀÀʱ£¬¿ÉÒÔ½«ÌõÄ¿µÄ DN »ò URL ¸´ÖƵ½¼ôÌù°åÖÐÒÔ¼õÉÙ¼üÈ룺
ÔÚ´ò¿ª¶Ô»°¿ò»òÆäËûÑ¡Ï֮ǰ£¨ÄúÐèÒªÔÚÆäÎı¾×Ö¶ÎÖÐÕ³Ìù DN »ò URL£©£¬ÇëÖ´ÐÐÒÔϲÙ×÷£º
¿ØÖÆÌ¨ÉèÖÃ
Directory Server Console ÌṩÐí¶àÉèÖã¬ÓÃÓÚ¶¨ÖÆÐÅÏ¢ÔÚ“ÅäÖԺ͓Ŀ¼”Ñ¡ÏÖеÄÏÔʾ·½Ê½¡£
¿ÉÊÓÅäÖÃÊ×Ñ¡Ïî
µ±ÔÚ¶¥¼¶“ÅäÖÔѡÏÉϵÄ×Ö¶ÎÖÐÐÞ¸ÄÅäÖòÎÊýºÍÊäÈëֵʱ£¬Directory Server Console ʹÓòÊÉ«Îı¾±íʾÓÐЧµÄÊäÈë¡£ÀýÈ磬Èç¹ûÆôÓÃÁËÒ»¸ö¹¦ÄÜ£¬¸Ã¹¦ÄÜÒªÇóÊäÈë¸üÏêϸµÄÅäÖÃÖµ£¬ÔòËùÐè×ֶεıêÇ©½«ÏÔʾΪºìÉ«£¬ÔÚÄúÊäÈëÁËÓÐЧֵ֮ºó£¬Ôò±äΪÀ¶É«¡£
ĬÈÏÇé¿öÏ£¬¿ØÖÆÌ¨»áʹÓúìÉ«ºÍÀ¶É«£¬µ«Äú¿ÉÒÔʹÓÃÒÔÏ·½·¨Ð޸ĴËÉèÖãº
- ÔÚ Directory Server Console µÄÈÎÒâÑ¡ÏÉÏ£¬Ñ¡Ôñ“±à¼”>“Ê×Ñ¡Ï˵¥Ïî¡£ÔÚ“¿ØÖÆÌ¨Ê×Ñ¡Ïî”¶Ô»°¿òÖУ¬Ñ¡Ôñ“ÆäËû”Ñ¡Ï¡£
- ΪϣÍûµÄ¿ÉÊÓÅäÖÃָʾ·ûÑ¡ÔñÏàÓ¦µÄµ¥Ñ¡°´Å¥¡£¿ÉÒÔÑ¡Ôñ²ÊÉ«×ÖÌå»ò×ÖÌåÍâ¹Û£¨»òÁ½Õߣ©¡£
- Óйؓ¿ØÖÆÌ¨Ê×Ñ¡Ïî”¶Ô»°¿òµÄÆäËûÑ¡ÏÉÏÉèÖõÄ˵Ã÷£¬Çë²Î¼û Administration Server Administration Guide¡£
È»ºóµ¥»÷“È·¶¨”ÒÔ±£´æ¸ü¸Ä¡£
- Í˳ö Server Console µÄËùÓд°¿Ú£¬È»ºóÖØÐÂÆô¶¯¿ØÖÆÌ¨¡£
Ŀ¼Ê÷ÊÓͼѡÏî
ÔÚ Directory Server Console µÄ¶¥¼¶“Ŀ¼”Ñ¡ÏÉÏ£¬“ÊÓͼ”²Ëµ¥Öеĸ÷ÏîÔÊÐíÄúÔÚĿ¼Ê÷ÖÐÏÔʾÆäËûÐÅÏ¢£¬²¢Ñ¡ÔñÒªÔÚÓÒÃæ°åÖгöÏÖµÄÄÚÈÝ¡£
ÒÔÏ“ÊÓͼ”Ñ¡Ïî»áÓ°Ïì“Ŀ¼”Ñ¡ÏµÄÄÚÈÝ£º
- ×ñÑÒýÓ᪡ªÑ¡Öд˸´Ñ¡¿òʱ£¬Ä¿Â¼Ê÷½«ÏÔʾÌõÄ¿ºÍÒýÓÃÄ¿±êµÄËùÓÐ×Ó¼¶£¬ÈçͬËüÃÇÔÚĿ¼ÖÐÒ»Ñù¡£Èç¹ûδѡÖиø´Ñ¡¿ò£¬ÔòÒýÓÃÏÔʾΪÒýÓÃÌõÄ¿¡£ÓйØÏêϸÐÅÏ¢£¬Çë²Î¼û´´½¨ÖÇÄÜÒýÓá£
- ÅÅÐò¶ÔÏ󡪡ªÈç¹ûδѡÖд˸´Ñ¡¿ò£¬Ôò°´·þÎñÆ÷·µ»ØÌõÄ¿µÄ˳ÐòÏÔʾÌõÄ¿¡£Ñ¡Öд˸´Ñ¡¿òʱ£¬Ä¿Â¼Ê÷ÖÐͬһ¼¶µÄÌõÄ¿°´ÏÂÃæËµÃ÷µÄÏÔʾÊôÐÔÅÅÐò¡£ÓйØÈçºÎÔÚ²»Ó°Ïì·þÎñÆ÷ÐÔÄܵÄÇé¿öÏ£¬¶Ô´óÐÍ×ÓÊ÷½øÐÐÅÅÐòµÄÏêϸÐÅÏ¢£¬Çë²Î¼ûÓÃÓÚ¿ØÖÆÌ¨µÄä¯ÀÀË÷Òý¡£
- “ÏÔʾ”>“ACI ¼ÆÊý”¡ª¡ªÈç¹û aci ÊôÐÔÖаüº¬Ò»Ìõ»ò¶àÌõ·ÃÎÊ¿ØÖÆÖ¸Áî (ACI)£¬Ä¿Â¼Ê÷½«ÔÚÌõÄ¿µÄÅÔ±ßÏÔʾָÁîµÄÊýÁ¿¡£ÓйØÏêϸÐÅÏ¢£¬Çë²Î¼ûµÚ 6 Õ¡°¹ÜÀí·ÃÎÊ¿ØÖÆ¡±
- “ÏÔʾ”>“½ÇÉ«¼ÆÊý”¡ª¡ªÈç¹ûÌõÄ¿ÊÇÒ»¸ö»ò¶à¸ö½ÇÉ«µÄ³ÉÔ±£¬Ôò¸ÃĿ¼Ê÷½«ÏÔʾÌõÄ¿ÄڵĽÇÉ«ÊýÁ¿¡£ÓйØÏêϸÐÅÏ¢£¬Çë²Î¼û·ÖÅä½ÇÉ«¡£
- “ÏÔʾ”>“Í£ÓÃ״̬”¡ª¡ªÈç¹ûij¸öÓû§»ò×éÌõÄ¿ÒѾ±»Í£ÓÃÒÔ·À°ó¶¨µ½·þÎñÆ÷£¬ÔòĿ¼Ê÷½«ÏÔʾһ¸öºì¿òºÍ´©¹ý¸ÃÌõĿͼ±êµÄÏßÌõ¡£ÓйØÏêϸÐÅÏ¢£¬Çë²Î¼ûÍ£Óúͼ¤»îÓû§ºÍ½ÇÉ«¡£
- “²¼¾Ö”>“²é¿´×Ó¼¶”¡ª¡ªÑ¡Ôñ´Ë²¼¾ÖÑ¡Ïîʱ£¬×óÃæ°åÖеÄÊ÷²»ÏÔʾĿ¼µÄÒ¶ÌõÄ¿£¬ÔÚ×óÃæ°åÖÐÑ¡Ôñ¸¸½Úµã¿ÉÔÚÓÒÃæ°åÖÐÏÔʾÆäËùÓÐ×ӽڵ㣬°üÀ¨Ò¶ÌõÄ¿¡£ÔÚÕâÁ½¸öÃæ°åÖж¼¿ÉÑ¡ÔñÌõÄ¿¡£
- “²¼¾Ö”>“½ö²é¿´Ê÷”¡ª¡ª ²ÉÓøò¼¾ÖÑ¡Ï“Ŀ¼”Ñ¡Ï½öÓÐÒ»¸öÃæ°åÏÔʾ°üº¬Ä¿Â¼ÖÐËùÓÐÌõÄ¿µÄÊ÷¡£
- “²¼¾Ö”>“²é¿´ÊôÐÔ”¡ª¡ªÔڸò¼¾ÖÖУ¬×óÃæ°åÏÔʾ°üº¬Ä¿Â¼ÖÐËùÓÐÌõÄ¿µÄÊ÷£¬¶øÓÒÃæ°åÏÔʾ´æ´¢ÔÚÊ÷ÖÐÑ¡¶¨µÄÌõÄ¿ÖеÄÊôÐÔºÍÖµ¡£
- “ÏÔʾÊôÐÔ”¡ª¡ªµ¥»÷´Ë²Ëµ¥Ï´ò¿ª“ÏÔʾÊôÐÔ”¶Ô»°¿ò£¬Ñ¡Ôñ“Ŀ¼”Ñ¡ÏÖÐÏÔʾµÄÌõÄ¿µÄ±êÇ©¡£Ä¬ÈÏÇé¿öÏ£¬±êǩΪÌõÄ¿µÄµÚÒ»¸ö RDN ÊôÐÔµÄÖµ£¨ÀýÈç People£©¡£¶ÔÓÚ²»¾ßÓÐ RDN µÄ»ù±¾ÌõÄ¿£¬±êǩΪÕû¸ö DN£¨ÀýÈç dc=example,dc=com£©¡£
ÅäÖà LDAP ²ÎÊýLDAP ²ÎÊýÊÇĿ¼·þÎñÆ÷ÖеĻù±¾ÉèÖã¬ÈçĿ¼¹ÜÀíÔ±µÄ±êʶÃû (DN)¡¢È«¾ÖÖ»¶ÁÉèÖᢶ˿ÚÅäÖÃÒÔ¼°¸ú×ÙËùÓÐĿ¼ÐÞ¸Äʱ¼äµÄ¹¦ÄÜ¡£
ÅäÖÃĿ¼¹ÜÀíÔ±
Ŀ¼¹ÜÀíÔ±ÊǾßÓÐÌØÈ¨µÄ·þÎñÆ÷¹ÜÀíÔ±£¬Óë UNIX ÖÐµÄ root Óû§ÏàËÆ¡£·ÃÎÊ¿ØÖƲ»ÊÊÓÃÓÚÒÔ Directory Manager Éí·Ý¶¨ÒåµÄÌõÄ¿¡£´ËÌõÄ¿µÄÊ״ζ¨ÒåÓ¦¸ÃÔÚ°²×°¹ý³ÌÖÐÍê³É¡£Ä¬ÈÏֵΪ cn=Directory Manager¡£
Ŀ¼¹ÜÀíÔ±µÄ DN ´æ´¢ÔÚ nsslapd-rootDN ÊôÐÔÖУ¬¶øÃÜÂë´æ´¢ÔÚ cn=config ·ÖÖ§µÄ nsslapd-rootpw ÊôÐÔÖС£
¿ÉʹÓà Directory Server Console ¸ü¸ÄĿ¼¹ÜÀíÔ± DN ºÍÃÜÂëÒÔ¼°ÓÃÓÚ´ËÃÜÂëµÄ´æ´¢Ä£Ê½£º
- ÇëÒÔĿ¼¹ÜÀíÔ±Éí·ÝµÇ¼ÖÁ¿ØÖÆÌ¨¡£
Èç¹ûÄúÒѾµÇ¼ÖÁ¿ØÖÆÌ¨£¬ÓйØÈçºÎÒÔÆäËûÓû§Éí·ÝµÇ¼µÄ˵Ã÷£¬Çë²Î¼û¸ü¸ÄµÇ¼Éí·Ý¡£
- ÔÚ¶¥¼¶“ÅäÖÔѡÏÉÏ£¬Ñ¡Ôñµ¼º½Ê÷¸ùµÄ·þÎñÆ÷½Úµã£¬È»ºóÔÚÓÒÃæ°åÖÐÑ¡Ôñ“ÉèÖÔѡÏ¡£
- ÔړĿ¼¹ÜÀíÔ± DN”×Ö¶ÎÖÐÊäÈëеıêʶÃû¡£Ä¬ÈÏֵΪ°²×°¹ý³ÌÖж¨ÒåµÄÖµ¡£
- ÔÚ“¹ÜÀíÔ±ÃÜÂë¼ÓÃÜ”ÏÂÀ²Ëµ¥ÖУ¬Ñ¡Ôñ·þÎñÆ÷ҪʹÓõÄĿ¼¹ÜÀíÔ±ÃÜÂëµÄ´æ´¢Ä£Ê½¡£
- ÇëʹÓÃÌṩµÄÎı¾×Ö¶ÎÊäÈ벢ȷÈÏÐÂÃÜÂë¡£
- µ¥»÷“±£´æ”¡£
¸ü¸Ä Directory Server ¶Ë¿ÚºÅ
ʹÓà Directory Server Console »òÔÚ cn=config ÌõĿϸü¸Ä nsslapd-port »ò nssldap-secureport ÊôÐÔµÄÖµ£¬¿ÉÒÔÐÞ¸ÄÓû§Ä¿Â¼·þÎñÆ÷µÄ¶Ë¿ÚºÅ»ò°²È«¶Ë¿ÚºÅ¡£
Èç¹ûÒªÐ޸İüº¬ Sun Java System ÅäÖÃÐÅÏ¢£¨o=NetscapeRoot ×ÓÊ÷£©µÄ Directory Server µÄ¶Ë¿Ú»ò°²È«¶Ë¿Ú£¬¿ÉÒÔͨ¹ý Directory Server Console Íê³É´Ë²Ù×÷¡£
Èç¹ûÒª¸ü¸ÄÅäÖÃĿ¼¶Ë¿Ú¡¢Óû§Ä¿Â¼¶Ë¿Ú»ò°²È«¶Ë¿ÚºÅ£¬ÄúÐèÒªÃ÷È·ÒÔÏ¿ÉÄܲúÉúµÄÓ°Ï죺
- ÄúÐèÒª¸ü¸ÄÈçÏÂÐÅÏ¢£ºÎª Administration Server ÅäÖõÄÅäÖÃĿ¼¶Ë¿Ú¡¢Óû§Ä¿Â¼¶Ë¿Ú»ò°²È«¶Ë¿ÚºÅ¡£Çë²Î¼û Administration Server Administration Guide¡£
- Èç¹û°²×°Ö¸Ïò´ËÅäÖÃĿ¼»òÓû§Ä¿Â¼µÄÆäËû Sun Java System ·þÎñÆ÷£¬ÔòÄúÐèÒª¸üÐÂÕâЩ·þÎñÆ÷ÒÔʹÆäÖ¸Ïòж˿ںš£
- Èç¹ûÔÚÆäËû·þÎñÆ÷É϶¨ÒåµÄ¸´ÖÆÐÒéÖÐÒýÓÃÁË Directory Server£¬Ôò±ØÐë¸üи´ÖÆÐÒéÒÔʹÓÃеĶ˿ںŻò°²È«¶Ë¿ÚºÅ¡£
- Èç¹ûÉèÖò»¾ßÓÐÌØÈ¨µÄ¶Ë¿ÚºÅ£¬¶øÇÒ Directory Server °²×°ÔÚÆäËûÓû§¿ÉÒÔ·ÃÎʵļÆËã»úÉÏ£¬ÄÇôÄúµÄ¶Ë¿Ú¿ÉÄÜ»áÓб»ÆäËûÓ¦ÓóÌÐòÀ¹½ØµÄΣÏÕ¡£»»ÑÔÖ®£¬ÆäËûÓ¦ÓóÌÐò¿ÉÒ԰󶨵½ÏàͬµÄµØÖ·/¶Ë¿Ú¶Ô¡£¸Ã¶ñÒâÓ¦ÓóÌÐòËæºó¾Í¿ÉÒÔ´¦ÀíרÃÅÕë¶Ô Directory Server µÄÇëÇ󣬶øÇÒ¿ÉÓÃÓÚ²¶»ñÔÚÑéÖ¤¹ý³ÌÖÐʹÓõÄÃÜÂ룬¸ü¸Ä¿Í»§»úÇëÇó»ò·þÎñÆ÷ÏìÓ¦£¬»òÕß²ÉÈ¡¾Ü¾ø·þÎñ¹¥»÷µÄÊֶΡ£Îª±ÜÃâÓöµ½´Ë°²È«·çÏÕ£¬ÇëʹÓà nsslapd-listenhost ÊôÐÔÖ¸¶¨ Directory Server ½«ÕìÌýµÄ½Ó¿Ú£¨µØÖ·£©¡£ÓйشËÊôÐÔµÄÏêϸÐÅÏ¢£¬Çë²Î¼û Directory Server Administration Reference¡£
- ͨ¹ý¿ØÖÆÌ¨¸ü¸Ä¶Ë¿ÚºÅ²¢²»ÐèÒª¶ÔijЩ½Å±¾½øÐбØÒªµÄ¸ü¸Ä¡£ÒÔϽű¾ÈÔ±»Ó²±àÂëΪÔʼ¶Ë¿ÚºÅ£¬±ØÐëÊÖ¶¯½øÐÐÐ޸ģºbak2db.pl¡¢schema_push.pl¡¢db2bak.pl¡¢check-slapd¡¢db2index.pl¡¢db2ldif.pl¡¢monitor¡¢ldif2db.pl¡¢ns-accountstatus.pl¡¢ldif2ldap¡¢ns-activate.pl¡¢ns-inactivate.pl¡£
×¢Ò⣬´Ë´¦ÌṩµÄ½Å±¾Ãû³ÆÊǵ¥¶ÀµÄ¹¤¾ßÃû³Æ£¬ÇÒδ¼Ç¼ check-slapd ÃüÁÒòΪËü²»Êǹ«¿ªµÄ API µÄÒ»²¿·Ö¡£ÓйØÏêϸÐÅÏ¢£¬Çë²Î¼û Directory Server Administration Reference¡£
ÐÞ¸Ä Directory Server ÕìÌý½ÓÊÕ LDAP ÇëÇóËùʹÓõĶ˿ڻò°²È«¶Ë¿ÚÒªÐÞ¸ÄÓÃÓÚ DSML ÇëÇóµÄ¶Ë¿Ú£¬Çë²Î¼ûÅäÖà DSML¡£
- ÔÚ Directory Server Console µÄ¶¥¼¶“ÅäÖÔѡÏÉÏ£¬Ñ¡ÔñÓë·þÎñÆ÷Ãû³ÆÏàͬµÄ¸ù½Úµã£¬È»ºóÔÚÓÒÃæ°åÖÐÑ¡Ôñ“ÍøÂç”Ñ¡Ï¡£
Ñ¡ÏÏÔʾÓÃÓÚ LDAP ÐÒéµÄ·þÎñÆ÷µÄµ±Ç°¶Ë¿ÚÉèÖá£
- ÔÚ“¶Ë¿Ú”×Ö¶ÎÖÐÊäÈë·þÎñÆ÷ÓÃÓÚ·Ç SSL ͨѶµÄ¶Ë¿ÚºÅ¡£Ä¬ÈÏÖµÊÇ 389¡£
- Èç¹ûÔڸ÷þÎñÆ÷ÉϾßÓÐÒѼ¤»îµÄ SSL£¨ÈçµÚ 11 Õ¡°¹ÜÀíÑéÖ¤ºÍ¼ÓÃÜ¡±ÖÐËùÊö£©£¬ÔòÔÊÐíÔÚ°²È«¶Ë¿ÚÉϵÄÁ¬½Ó£º
- µ¥»÷“±£´æ”£¬È»ºóÖØÐÂÆô¶¯·þÎñÆ÷¡£
ÓйØÐÅÏ¢£¬Çë²Î¼ûÆô¶¯ºÍÍ£Ö¹ Directory Server¡£
ÉèÖÃÈ«¾ÖÖ»¶Áģʽ
¿ÉÒÔ½«Ä¿Â¼ÖеÄÿ¸öºó׺¶ÀÁ¢µØÉèΪֻ¶Áģʽ£¬¶¨ÒåΪֻ¶Áģʽºó£¬¿ÉÄܻ᷵»ØÒ»¸öÌØ¶¨ÒýÓá£Directory Server »¹ÌṩÊÊÓÃÓÚËùÓкó׺µÄÈ«¾ÖÖ»¶Áģʽ£¬¶¨ÒåΪ´Ëģʽºó£¬¿ÉÄܻ᷵»ØÒ»¸öÈ«¾ÖÒýÓá£
ʹÓÃÈ«¾ÖÖ»¶Áģʽºó£¬ÔÚÖ´ÐÐÈçÖØÐÂË÷Òýºó׺ÕâÑùµÄÈÎÎñʱ£¬¹ÜÀíÔ±¿ÉÒÔ·ÀÖ¹ÐÞ¸ÄĿ¼ÄÚÈÝ¡£Òò´Ë£¬È«¾ÖÖ»¶Áģʽ²»ÊÊÓÃÓÚÒÔÏÂÅäÖ÷ÖÖ§£º
²»¹ÜÊÇ·ñΪֻ¶ÁÉèÖã¬ÕâЩ·Ö֧ʼÖÕ¶¼Ó¦ÓÉ·ÃÎÊ¿ØÖÆÖ¸Áî (ACI) ±£»¤£¬ÒÔ·À±»·Ç¹ÜÀíÓû§Ð޸ģ¨Çë²Î¼ûµÚ 6 Õ¡°¹ÜÀí·ÃÎÊ¿ØÖÆ¡±£©¡£È«¾ÖÖ»¶Áģʽ½«·ÀÖ¹ÔÚĿ¼ÖеÄËùÓÐÆäËûºó׺ÉÏÖ´ÐиüвÙ×÷£¬°üÀ¨ÓÉĿ¼¹ÜÀíÔ±Ö´ÐеĸüвÙ×÷¡£
Èç¹ûÆôÓÃÁËÖ»¶Áģʽ£¬Ëü»¹»áÖжϺó׺µÄ¸´ÖÆ¡£Ö÷¸±±¾²»ÔÙÓÐÈκÎÒª¸´ÖƵĸü¸Ä£¬²»¹ýËüÈÔ»á¼ÌÐø¸´ÖÆÆôÓÃÖ»¶ÁģʽǰËù×öµÄËùÓиü¸Ä¡£½ûÓÃÖ»¶Áģʽǰ£¬Ïû·ÑÕ߸±±¾²»»áÔÙ½ÓÊÕµ½ÈκθüС£¶àÖ÷¸´ÖÆ·½°¸ÖеÄÖ÷¸±±¾¼È²»»áÓÐÈκÎÒª¸´ÖƵĸü¸Ä£¬Ò²²»ÄÜ´ÓÆäËûÖ÷¸±±¾´¦½ÓÊÕ¸üС£
ÒªÆôÓûò½ûÓÃÈ«¾ÖÖ»¶Áģʽ£¬ÇëÖ´ÐÐÒÔϲÙ×÷£º
Óйؽ«¸ö±ðºó׺ÉèÖÃΪֻ¶ÁģʽµÄÐÅÏ¢£¬Çë²Î¼ûÉèÖúó׺ֻ¶Áģʽ¡£
¸ú×Ù¶ÔĿ¼ÌõÄ¿µÄÐÞ¸Ä
Äú¿ÉÒÔÅäÖ÷þÎñÆ÷£¬ÒÔά»¤Ð´´½¨ÌõÄ¿»òÒÑÐÞ¸ÄÌõÄ¿µÄÌØÊâÊôÐÔ£º
- creatorsName¡ª¡ª×îÏÈ´´½¨´ËÌõÄ¿µÄÈËÔ±µÄ±êʶÃû¡£
- createTimestamp¡ª¡ªÒÔ GMT£¨¸ñÁÖÄáÖαê׼ʱ¼ä£©¸ñʽ´´½¨ÌõĿʱµÄʱ¼ä´Á¡£
- modifiersName¡ª¡ªÉÏ´ÎÐÞ¸ÄÌõÄ¿ÈËÔ±µÄ±êʶÃû¡£
- modifyTimestamp¡ª¡ªÉÏ´ÎÒÔ GMT ¸ñʽÐ޸ĵÄÌõÄ¿µÄʱ¼ä´Á¡£
×¢
µ±¿Í»§»úÓ¦ÓóÌÐòÒª´´½¨»òÐÞ¸ÄÁ´½Óºó׺ÖеÄÌõĿʱ£¬creatorsName ºÍ modifiersName ÊôÐÔ²»·´Ó³ÌõÄ¿µÄʵ¼Ê´´½¨ÈË»òÐÞ¸ÄÈË¡£ÕâЩÊôÐÔ°üº¬°ó¶¨ÖÁÔ¶³Ì·þÎñÆ÷ËùÐèµÄÁ´½Ó´úÀíÃû³Æ¡£ÓйشúÀíÊÚȨµÄÐÅÏ¢£¬Çë²Î¼û´´½¨´úÀíÉí·Ý¡£
¸ú×Ù¸´ÖƵĺó׺µÄÐÞ¸Äʱ¼äʱ£¬Ãû³ÆºÍʱ¼ä´ÁÊôÐÔ×÷Ϊ³£¹æÊôÐÔ±»¸´ÖÆ¡£Òò´Ë£¬ÕâЩÊôÐÔ·´Ó³µÄÊÇÖ÷·þÎñÆ÷É϶ÔÌõÄ¿Ëù×öÔʼÐ޸ĵÄʱ¼ä£¬¶ø²»ÊÇÌõÄ¿¸´ÖƵ½Ïû·ÑÕß·þÎñÆ÷ÉϵÄʱ¼ä¡£
ÒªÆôÓà Directory Server ÒÔ¸ú×Ù´ËÐÅÏ¢£¬ÇëÖ´ÐÐÒÔϲÙ×÷£º
- ÔÚ Directory Server Console µÄ¶¥¼¶“ÅäÖÔѡÏÖУ¬Ñ¡ÔñÅäÖÃÊ÷Öеĸù½Úµã£¬È»ºóÔÚÓÒÃæ°åÖÐÑ¡Ôñ“ÉèÖÔѡÏ¡£
- Ñ¡ÖГ¸ú×ÙÌõÄ¿ÐÞ¸Äʱ¼ä”¸´Ñ¡¿ò¡£
·þÎñÆ÷»á½« creatorsName¡¢createTimestamp¡¢modifiersName ºÍ modifyTimestamp ÊôÐÔÌí¼ÓÖÁÿ¸öд´½¨ÌõÄ¿»òÒÑÐÞ¸ÄÌõÄ¿¡£ÏÖÓÐÌõÄ¿½«²»»á°üº¬´´½¨ÊôÐÔ¡£
- µ¥»÷“±£´æ”£¬È»ºóÖØÐÂÆô¶¯·þÎñÆ÷¡£
ÓйØÏêϸÐÅÏ¢£¬Çë²Î¼ûÆô¶¯ºÍÍ£Ö¹ Directory Server¡£
ÑéÖ¤²å¼þÇ©ÃûÑéÖ¤²å¼þÇ©ÃûÊÇ Directory Server 5.2 µÄÒ»Ïîй¦ÄÜ¡£Directory Server ÌṩµÄÿ¸ö²å¼þ¶¼¾ßÓÐÒ»¸öÊý×ÖÇ©Ãû£¬·þÎñÆ÷¿ÉÒÔÔÚÆô¶¯Ê±¶ÔÆä½øÐÐÑéÖ¤¡£Ä¬ÈÏÇé¿öÏ£¬·þÎñÆ÷½«ÑéÖ¤²å¼þÇ©Ãû£¬µ«ÊDz»¹ÜÇ©ÃûÊÇ·ñ´æÔÚ»òÓÐЧ£¬Ëü¶¼»á¼ÓÔØÃ¿¸ö²å¼þ¡£
Ñé֤ǩÃû¾ßÓÐÒÔÏÂÓŵ㣺
ÅäÖòå¼þÇ©ÃûµÄÑéÖ¤
- ÔÚ Directory Server Console µÄ¶¥¼¶“ÅäÖÔѡÏÉÏ£¬ÔÚÅäÖÃÊ÷ÖÐÑ¡Ôñ“²å¼þ”½Úµã¡£µ±Ç°µÄÇ©ÃûÑéÖ¤²ßÂÔÏÔʾÔÚÓÒÃæ°åÖС£
- Ñ¡ÔñÒÔÏÂÑ¡ÏîÖ®Ò»£º
- ²»ÑéÖ¤²å¼þÇ©Ãû¡ª¡ª½«¼ÓÔØÔÚ·þÎñÆ÷ÅäÖÃÖж¨ÒåµÄËùÓвå¼þ£¬¶ø²»¹ÜÆäÇ©ÃûÈçºÎ¡£½«²»»áÏÔʾÓÉÓÚ²å¼þÇ©ÃûÒýÆðµÄÈκξ¯¸æ»ò´íÎó¡£
- ±ê¼Ç¾ßÓÐÎÞЧǩÃûµÄ²å¼þ¡ª¡ª½«¼ÓÔØÔÚ·þÎñÆ÷ÅäÖÃÖж¨ÒåµÄËùÓвå¼þ£¬µ«·þÎñÆ÷½«Ñé֤ÿ¸ö²å¼þµÄÇ©Ãû¡£Èç¹û²å¼þ¶þ½øÖÆÓÐÈκθı䣬ÔòÇ©Ãû½«²»ÔÙÓÐЧ£¬·þÎñÆ÷½«ÔÚÆô¶¯Ê±ÏÔʾһÌõ¾¯¸æÏûÏ¢²¢½«Æä¼ÇÈë´íÎóÈÕÖ¾ÖС£Ò²½«±ê¼ÇûÓÐÇ©ÃûµÄ²å¼þ¡£
- µ¥»÷“±£´æ”£¬È»ºóÖØÐÂÆô¶¯ Directory Server£¬ÈçÆô¶¯ºÍÍ£Ö¹ Directory Server ÖÐËùÊö¡£
²é¿´²å¼þµÄ״̬
- ÔÚ Directory Server Console µÄ¶¥¼¶“ÅäÖÔѡÏÉÏ£¬Õ¹¿ªÅäÖÃÊ÷Öеē²å¼þ”½Úµã£¬È»ºóÑ¡ÔñÒªÑéÖ¤µÄ²å¼þ¡£¸Ã²å¼þµÄµ±Ç°ÅäÖÃÏÔʾÔÚÓÒÃæ°åÖС£
- “Ç©Ãû״̬”×Ö¶ÎÏÔʾ¾ßÓÐÒÔÏÂijһֵµÄ²å¼þµÄÇ©ÃûÑé֤״̬£º
- δ֪¡ª¡ªµ±·þÎñÆ÷ÅäÖÃΪ²»ÑéÖ¤²å¼þÇ©Ãûʱ£¬ËùÓвå¼þµÄÇ©Ãû״̬¶¼ÊǓδ֪”¡£ÒÔÏÂ״̬½öµ±ÑéÖ¤²å¼þÇ©Ãûʱ²Å¿É¼û¡£
- ÓÐЧǩÃû¡ª¡ª²å¼þÅäÖÃÌṩµÄÇ©ÃûÓë²å¼þ¶þ½øÖƵÄУÑéºÍÆ¥Åä¡£¸Ã²å¼þÒÑÕýʽµÃµ½Ö§³Ö¡£ÒÔÏÂ״̬½öµ±±ê¼Ç£¨µ«²»¾Ü¾ø£©ÎÞЧǩÃûʱ²Å¿É¼û¡£
- ÎÞЧǩÃû¡ª¡ª²å¼þÅäÖðüº¬µÄÇ©ÃûÓë²å¼þ¶þ½øÖƵÄУÑéºÍ²»Æ¥Åä¡£¸Ã״̬±íÃ÷²å¼þ¿ÉÄÜÒѱ»´Û¸Ä¡£
- ÎÞÇ©Ãû¡ª¡ª²å¼þÅäÖÃδÌṩǩÃû¹©·þÎñÆ÷ÑéÖ¤¡£
ÅäÖà DSML³ýÁË´¦ÀíÇáÐÍĿ¼·ÃÎÊÐÒé (LDAP) ÖеÄÇëÇóÖ®Í⣬Directory Server »¹»áÏìӦĿ¼·þÎñ±ê¼ÇÓïÑÔ°æ±¾ 2 (DSMLv2) Öз¢Ë͵ÄÇëÇó¡£DSML Êǿͻ§»ú¶ÔĿ¼²Ù×÷½øÐбàÂëµÄÁíÒ»ÖÖ·½Ê½£¬µ«·þÎñÆ÷½«Ê¹ÓÃËùÓÐÏàͬµÄ·ÃÎÊ¿ØÖƺͰ²È«¹¦ÄÜ£¬ÒÔ´¦ÀíÆäËûÇëÇóµÄ·½Ê½À´´¦Àí DSML ÇëÇó¡£ÊÂʵÉÏ£¬DSML ´¦ÀíÔÊÐí¶àÖÖÆäËûÀàÐ͵Ŀͻ§»ú·ÃÎÊÄúµÄĿ¼ÄÚÈÝ¡£
Directory Server Ö§³Öͨ¹ý³¬Îı¾´«ÊäÐÒé (HTTP/1.1) ʹÓà DSMLv2£¬²¢Ê¹Óüòµ¥¶ÔÏó·ÃÎÊÐÒé (SOAP) °æ±¾ 1.1 ×÷Ϊ´«ËÍ DSML ÄÚÈݵıà³ÌÐÒé¡£ÓйØÕâЩÐÒéÒÔ¼° DSML ÇëÇóʾÀýµÄÏêϸÐÅÏ¢£¬Çë²Î¼ûʹÓà DSMLv2 ·ÃÎÊĿ¼¡£
ÆôÓà DSML ÇëÇó
ÓÉÓÚ LDAP ÊÇÓÃÓÚ·ÃÎÊĿ¼µÄ±ê×¼ÐÒ飬Òò´Ë°²×° Directory Server ºóĬÈÏÇé¿öϲ»»áÆôÓà DSML ÇëÇó¡£Èç¹ûÏ£Íû·þÎñÆ÷¶Ôͨ¹ý HTTP/SOAP ·¢Ë굀 DSML ÇëÇó×÷³öÏìÓ¦£¬±ØÐëÃ÷È·ÆôÓô˹¦ÄÜ¡£
Ҫͨ¹ý¿ØÖÆÌ¨ÔÚ·þÎñÆ÷ÉÏÆôÓà DSML ÇëÇó£¬ÇëÖ´ÐÐÒÔϲÙ×÷£º
- ÔÚ Directory Server Console µÄ¶¥¼¶“ÅäÖÔѡÏÉÏ£¬Ñ¡ÔñÅäÖÃÊ÷Öеĸù½Úµã£¬È»ºóÔÚÓÒÃæ°åÖÐÑ¡Ôñ“ÍøÂç”Ñ¡Ï¡£
- Ñ¡ÖГÆôÓà DSML”¸´Ñ¡¿ò£¬²¢Ñ¡ÔñÒÔϰ²È«Ñ¡ÏîÖ®Ò»¡£½öµ±¾ßÓ줻îµÄ SSL ʱ£¬°²È«¶Ë¿ÚÑ¡Ïî²Å¿ÉÓã¬ÈçµÚ 11 Õ¡°¹ÜÀíÑéÖ¤ºÍ¼ÓÃÜ¡±ÖÐËùÊö
- È»ºó±à¼ÒÔÏÂÈÎÒâ×ֶΣº
- µ¥»÷“±£´æ”£¬ÏµÍ³½«ÌáʾÄú±ØÐëÖØÐÂÆô¶¯·þÎñÆ÷²ÅÄÜ¿ªÊ¼ÏìÓ¦ DSML ÇëÇó¡£
Ҫͨ¹ýÃüÁîÐÐÆôÓà DSML ÇëÇó£¬ÇëÖ´ÐÐÒÔϲÙ×÷£º
- Ö´ÐÐÒÔÏ ldapmodify ÃüÁÒÔÆôÓà DSML ǰ¶Ë²å¼þ²¢ÐÞ¸ÄÆäÉèÖá£ÐÞ¸Ä ds-hdsml-port¡¢ds-hdsml-secureport ºÍ ds-hdsml-rooturl ÊôÐÔÊÇ¿ÉÑ¡µÄ£º
% ldapmodify -h host -p LDAPport -D "cn=Directory Manager" -w passwd
dn:cn=DSMLv2-SOAP-HTTP,cn=frontends,cn=plugins,cn=config
changetype:modify
replace:nsslapd-pluginEnabled
nsslapd-pluginEnabled:on
-
replace:ds-hdsml-port
ds-hdsml-port:DSMLport
-
add:ds-hdsml-secureport
ds-hdsml-port:secureDSMLport
-
replace:ds-hdsml-rooturl
ds-hdsml-root:relativeURL
-
^D¸ù¾ÝÒѶ¨ÒåµÄ²ÎÊýºÍÊôÐÔÖµ£¬DSML ¿Í»§»ú¿ÉÄÜʹÓÃÒÔÏ URL Ïò´Ë·þÎñÆ÷·¢ËÍÇëÇó£º
http://host:DSMLport/relativeURL
https://host:secureDSMLport/relativeURL
- ÐÞ¸Ä DSML ǰ¶Ë²å¼þºó£¬±ØÐëÖØÐÂÆô¶¯·þÎñÆ÷¸ü¸Ä²ÅÄÜÉúЧ¡£²»¹ý£¬ÔÚÖØÐÂÆô¶¯·þÎñÆ÷ǰ£¬Äú¿ÉÄÜÏ£Íû°´ÕÕºóÃæÐ¡½ÚÖеÄ˵Ã÷Ϊ DSML ÑéÖ¤ÅäÖð²È«ºÍ±êʶӳÉä¡£
ÅäÖà DSML °²È«ÐÔ
³ýÉϽÚÖнéÉܵݲȫ¶Ë¿ÚÉèÖÃÍ⣬Äú»¹¿ÉÒÔÅäÖýÓÊÜ DSML ÇëÇóËù±ØÐèµÄ°²È«¼¶±ð¡£DSML ǰ¶Ë²å¼þµÄ ds-hdsml-clientauthmethod ÊôÐÔ¿ÉÒÔ¾ö¶¨¿Í»§»úËùÒªÇóµÄÑéÖ¤·½·¨¡£¸ÃÊôÐÔ¿ÉÄÜÓÐÏÂÁÐÖµ£º
- httpBasicOnly¡ª¡ª·þÎñÆ÷ʹÓÓHTTP ÊÚȨ”±êÍ·µÄÄÚÈÝÀ´²éÕÒ¿ÉÒÔ±»Ó³É䵽Ŀ¼ÖÐÌõÄ¿µÄÓû§Ãû¡£DSML ±êʶӳÉä¶Ô´Ë¹ý³Ì¼°ÆäÅäÖýøÐÐÁËÏêϸ˵Ã÷¡£Ê¹ÓôËÉèÖ㬶԰²È« HTTPS ¶Ë¿ÚµÄ DSML ÇëÇó½«Í¨¹ý SSL ½øÐмÓÃÜ£¬¶ø²»Ê¹Óÿͻ§»úÖ¤Êé¡£
- clientCertOnly¡ª¡ª·þÎñÆ÷ʹÓÿͻ§»úÖ¤ÊéµÄƾ֤À´Ê¶±ð¿Í»§»ú¡£Ê¹ÓôËÖµ£¬ËùÓÐ DSML ¿Í»§»ú±ØÐëʹÓð²È« HTTPS ¶Ë¿ÚÀ´·¢ËÍ DSML ÇëÇ󣬲¢Ìṩһ¸öÖ¤Êé¡£·þÎñÆ÷½«¼ì²éÓëĿ¼ÖÐÌõÄ¿ÏàÆ¥ÅäµÄ¿Í»§»úÖ¤Êé¡£ÓйØÏêϸÐÅÏ¢£¬Çë²Î¼ûµÚ 11 Õ¡°¹ÜÀíÑéÖ¤ºÍ¼ÓÃÜ¡±¡£
- clientCertFirst¡ª¡ªÈç¹ûÌṩÁ˿ͻ§»úÖ¤Ê飬·þÎñÆ÷½«Ê×Ïȳ¢ÊÔʹÓÿͻ§»úÖ¤Êé¶Ô¿Í»§»ú½øÐÐÑéÖ¤¡£Èç¹ûûÓÐÌṩ£¬·þÎñÆ÷½«Ê¹ÓÓÊÚȨ”±êÍ·µÄÄÚÈÝÑéÖ¤¿Í»§»ú¡£
Èç¹û HTTP ÇëÇóÖÐδÌṩ֤ÊéºÍ“ÊÚȨ”±êÍ·£¬Ôò·þÎñÆ÷½«Ê¹ÓÃÄäÃû°ó¶¨Ö´ÐÐ DSML ÇëÇó¡£ÏÂÁÐÇé¿öÒ²½«Ê¹ÓÃÄäÃû°ó¶¨£º
²»ÂÛ ds-hdsml-clientauthmethod ÊôÐÔΪºÎÖµ£¬Èç¹ûÌṩÁËÖ¤Ê鵫֤ÊéÈ´ÓëÌõÄ¿²»Æ¥Å䣬»òÕßËäȻָ¶¨ÁË“HTTP ÊÚȨ”±êÍ·µ«È´²»ÄÜÓ³ÉäÖÁÓû§ÌõÄ¿£¬Ôò DSML ÇëÇ󽫻ᱻ¾Ü¾ø£¬²¢ÇÒ·µ»ØÏûÏ¢ 403£º“ÒѽûÖ¹”¡£
Ҫͨ¹ý¿ØÖÆÌ¨ÉèÖà DSML °²È«ÒªÇó£¬ÇëÖ´ÐÐÒÔϲÙ×÷£º
- ÔÚ Directory Server Console µÄ¶¥¼¶“ÅäÖÔѡÏÉÏ£¬Ñ¡ÔñÅäÖÃÊ÷Öеĸù½Úµã£¬È»ºóÔÚÓÒÃæ°åÖÐÑ¡Ôñ“¼ÓÃܔѡÏ¡£
±ØÐëÒѾÅäÖò¢ÆôÓÃÁË SSL£¬ÈçµÚ 11 Õ¡°¹ÜÀíÑéÖ¤ºÍ¼ÓÃÜ¡±ÖÐËùÊö¡£
- ÔÚ“DSML ¿Í»§»úÑéÖ¤”×ֶεÄÏÂÀ²Ëµ¥ÖУ¬Ñ¡ÔñÑ¡ÏîÖ®Ò»¡£
- µ¥»÷“±£´æ”£¬È»ºóÖØÐÂÆô¶¯·þÎñÆ÷ÒÔʵʩ´Ëа²È«ÉèÖá£
Ҫͨ¹ýÃüÁîÐÐÉèÖà DSML °²È«ÒªÇó£¬ÇëÖ´ÐÐÒÔϲÙ×÷£º
- ÔËÐÐÒÔÏ ldapmodify ÃüÁîÒԱ༠DSML ǰ¶Ë²å¼þµÄÊôÐÔ£º
% ldapmodify -h host -p LDAPport -D "cn=Directory Manager" -w passwd
dn:cn=DSMLv2-SOAP-HTTP,cn=frontends,cn=plugins,cn=config
changetype:modify
replace:ds-hdsml-clientauthmethod
ds-hdsml-clientauthmethod:httpBasicOnly or
clientCertOnly or clientCertFirst
^D- ÐÞ¸Ä DSML ǰ¶Ë²å¼þºó£¬ÐèÒªÖØÐÂÆô¶¯·þÎñÆ÷ÒÔʵʩÐµİ²È«ÉèÖá£
DSML ±êʶӳÉä
ÔÚûÓÐÖ¤ÊéµÄÇé¿öÏÂÖ´Ðлù±¾Ñé֤ʱ£¬Directory Server ʹÓÃÃûΪ±êʶӳÉäµÄ»úÖÆÀ´È·¶¨½ÓÊÜ DSML ÇëÇóʱʹÓÃµÄ°ó¶¨ DN¡£´Ë»úÖÆ´Ó HTTP ÇëÇóµÄ“ÊÚȨ”±êÍ·ÖÐÌáÈ¡ÐÅÏ¢£¬ÒÔÈ·¶¨ÓÃÓڰ󶨵ıêʶ¡£ÓйظûúÖÆµÄÍêÕû˵Ã÷£¬Çë²Î¼û±êʶӳÉä¡£
·þÎñÆ÷ÅäÖÃÖеÄÏÂÁÐÌõÄ¿¸ø³öÁËÓÃÓÚ DSML-over-HTTP µÄĬÈϱêʶӳÉ䣺
dn:cn=default,cn=HTTP-BASIC, cn=identity mapping, cn=config
objectclass:top
objectclass:nsContainer
objectclass:dsIdentityMapping
cn:default
dssearchbasedn:ou=People,userRoot
dssearchfilter:(uid=${Authorization})´ËÓ³ÉäËÑË÷ ou=People,userRoot ×ÓÊ÷ÒÔ²éÕÒÆä uid ÊôÐÔÓë Authorization ±êÍ·Öиø¶¨µÄÓû§ÃûÏàÆ¥ÅäµÄÌõÄ¿¡£userRoot Êǰ²×°Ä¿Â¼Ê±¶¨ÒåµÄºó׺£¬ÀýÈç dc=example,dc=com¡£
ÔÚÕâЩӳÉäÌõÄ¿ÊôÐÔÖУ¬¿ÉÒÔʹÓøñʽΪ ${header} µÄռλ·û£¬ÆäÖÐ header Ϊ HTTP Í·µÄÃû³Æ¡£DSML Ó³ÉäÖÐ×î³£ÓõıêÍ·ÈçÏ£º
- ${Authorization}¡ª¡ª½«ÓÓHTTP ÊÚȨ”±êÍ·Öаüº¬µÄÓû§ÃûÌæ»»´Ë×Ö·û´®¡£“ÊÚȨ”±êÍ·¼È°üº¬Óû§ÃûÒ²°üº¬ÃÜÂ룬µ«´Ëռλ·û½öÌæ»»Óû§Ãû¡£
- ${From}¡ª¡ª½«Óà HTTP“·¢¼þÈË”±êÍ·Öаüº¬µÄµç×ÓÓʼþµØÖ·Ìæ»»´Ë×Ö·û´®¡£
- ${host}¡ª¡ª½«Óà DSML ÇëÇóµÄ URL ÖеÄÖ÷»úÃûºÍ¶Ë¿ÚºÅÌæ»»´Ë×Ö·û´®£¬ÕâЩÖ÷»úÃûºÍ¶Ë¿ÚºÅ¾ÍÊÇ·þÎñÆ÷×ÔÉíµÄÖ÷»úÃûºÍ¶Ë¿ÚºÅ¡£
Ҫʹ DSML ÇëÇóÖ´ÐÐÆäËûµÄ±êʶӳÉ䣬ÇëÖ´ÐÐÒÔϲÙ×÷£¬ÒÔ±ãΪ HTTP Í·¶¨ÒåеıêʶӳÉ䣺
- ±à¼Ä¬È쵀 DSML-over-HTTP ±êʶӳÉä»òΪ¸ÃÐÒé´´½¨×Ô¶¨ÒåÓ³Éä¡£ÓйرêʶӳÉäÌõÄ¿ÖÐÊôÐԵ͍Ò壬Çë²Î¼û±êʶӳÉä¡£ÕâЩӳÉäÌõÄ¿±ØÐëλÓÚÒÔÏÂÌõÄ¿µÄÏ·½£º
cn=HTTP-BASIC, cn=identity mapping, cn=config¡£¿ÉÒÔ²ÉÓÃÒÔÏÂÁ½ÖÖ·½Ê½Ö®Ò»´´½¨ÐµÄÓ³ÉäÌõÄ¿£º
- ʹÓà Directory Server Console µÄ¶¥¼¶“Ŀ¼”Ñ¡Ï´´½¨¾ßÓÐÏàÓ¦¶ÔÏóÀàµÄÐÂÌõÄ¿£¬ÈçʹÓÿØÖÆÌ¨¹ÜÀíÌõÄ¿ÖÐËùÊö¡£
- ʹÓà ldapmodify ¹¤¾ß´ÓÃüÁîÐÐÌí¼Ó´ËÌõÄ¿£¬ÈçʹÓà ldapmodify Ìí¼ÓÌõÄ¿ÖÐËùÊö¡£
- ÖØÐÂÆô¶¯ Directory Server ÒÔʹÐÂÓ³ÉäÉúЧ¡£
Ê×ÏȽ«ÆÀ¹À×Ô¶¨ÒåÓ³É䣬Èç¹ûûÓгɹ¦µÄ¶¨ÖÆÓ³É䣬Ôò½«ÆÀ¹ÀĬÈÏÓ³Éä¡£Èç¹ûËùÓÐÓ³É䶼δÄÜÈ·¶¨ DSML ÇëÇóµÄ°ó¶¨ DN£¬Ôò DSML ÇëÇ󽫱»½ûÖ¹²¢¾Ü¾ø£¨´íÎó 403£©¡£