CentOS 7: Difference between revisions
No edit summary |
No edit summary |
||
Line 3: | Line 3: | ||
<syntaxhighlight lang="bash"> | <syntaxhighlight lang="bash"> | ||
authconfig --enablesssd --enablesssdauth --enableldap --enableldapauth --ldapserver=ldaps://LDAP.DOMAIN.COM:636 --ldapbasedn="dc=DOMAIN,dc=COM" --enableldaptls --enablerfc2307bis --disablecachecreds --enablemkhomedir --updateall --test | authconfig --enablesssd --enablesssdauth --enableldap --enableldapauth --ldapserver=ldaps://LDAP.DOMAIN.COM:636 --ldapbasedn="dc=DOMAIN,dc=COM" --enableldaptls --enablerfc2307bis --disablecachecreds --enablemkhomedir --updateall --test | ||
#umask | |||
~] cat /etc/pam.d/system-auth | |||
session optional pam_oddjob_mkhomedir.so umask=0022 | |||
~] cat /etc/pam.d/password-auth | |||
session optional pam_oddjob_mkhomedir.so umask=0022 | |||
</syntaxhighlight> | </syntaxhighlight> | ||
Latest revision as of 02:44, 19 March 2022
authconfig
authconfig --enablesssd --enablesssdauth --enableldap --enableldapauth --ldapserver=ldaps://LDAP.DOMAIN.COM:636 --ldapbasedn="dc=DOMAIN,dc=COM" --enableldaptls --enablerfc2307bis --disablecachecreds --enablemkhomedir --updateall --test
#umask
~] cat /etc/pam.d/system-auth
session optional pam_oddjob_mkhomedir.so umask=0022
~] cat /etc/pam.d/password-auth
session optional pam_oddjob_mkhomedir.so umask=0022
sssd.conf
[domain/default]
autofs_provider = ldap
ldap_schema = rfc2307bis
ldap_search_base = dc=DOMAIN,dc=TLD
id_provider = ldap
auth_provider = ldap
chpass_provider = ldap
ldap_uri = ldaps://LDAPSERVER.DOMAIN.TLD:636
ldap_id_use_start_tls = False
cache_credentials = False
ldap_tls_cacertdir = /etc/openldap/cacerts
ldap_group_member = uniqueMember
entry_cache_timeout = 60
debug_level = 5
ldap_autofs_map_object_class = nisMap
ldap_autofs_map_name = nisMapName
ldap_autofs_entry_object_class = nisObject
ldap_autofs_entry_key = cn
ldap_autofs_entry_value = nisMapEntry
ldap_autofs_search_base = ou=service,dc=DOMAIN,dc=TLD
[sssd]
services = nss, pam, autofs
domains = default
[nss]
homedir_substring = /home
debug_level = 5
filter_groups = root
filter_users = root
[pam]
[sudo]
[autofs]
debug_level = 5
[ssh]
[pac]
[ifp]
[secrets]
[session_recording]