To edit a previously created database, select its base DN in the tree to the left. In the
right part of the window, YaST displays a dialog similar to the one used for the creation
of a new database—with the main difference that the base DN entry is grayed out and
cannot be changed.
After leaving the LDAP server configuration by selecting Finish, you are ready to go
with a basic working configuration for your LDAP server. To fine-tune this setup, make
use of OpenLDAP's dynamic configuration backend.
The OpenLDAP's dynamic configuration backend stores the configuration in an LDAP
database itself. That database consists of a set of .ldif files in /etc/openldap/
slapd.d. There is no need to access these files directly. To access the settings you
can either use the YaST LDAP server module (the yast2-ldap-server package)
or an LDAP client such as ldapmodify or ldapsearch. For more information on
the dymanic configuration of OpenLDAP, see the OpenLDAP Administration Guide.
4.4 Configuring an LDAP Client with
YaST
YaST includes a module to set up LDAP-based user management. If you did not enable
this feature during the installation, start the module by selecting Network Services >
LDAP Client. YaST automatically enables any PAM and NSS related changes as required
by LDAP and installs the necessary files. Simply connect your client to the server and
let YaST manage users over LDAP. This basic setup is described in
Section 4.4.1,
"Configuring Basic Settings"
(page 50).
Use the YaST LDAP client to further configure the YaST group and user configuration
modules. This includes manipulating the default settings for new users and groups and
the number and nature of the attributes assigned to a user or group. LDAP user manage-
ment allows you to assign far more and different attributes to users and groups than
traditional user or group management solutions. This is described in
Section 4.4.2,
"Configuring the YaST Group and User Administration Modules"
(page 53).
LDAP—A Directory Service
49
Need help?
Do you have a question about the LINUX ENTERPRISE SERVER 11 - SECURITY and is the answer not in the manual?