Pages

Showing posts with label Ldap. Show all posts
Showing posts with label Ldap. Show all posts

Tuesday, October 1, 2013

Open LDAP

Ldap is nothing but Light Weight Directory Access Protocol. it is a lightweight client-server protocol for accessing directory services. LDAP runs over TCP/IP or other connection oriented transfer services.

A Directory is much similar like a Database ,but tends to contain more descriptive, attribute-based information. The information in a directory is generally read much more often than it is written. Directories are tuned to give quick-response to high-volume lookup or search operations. They may have the ability to replicate information widely in order to increase availability and reliability, while reducing response time

LDAP directory service is based on a client-server model. One or more LDAP servers contain the data making up the LDAP directory tree or LDAP backend database. An LDAP client connects to an LDAP server and asks it a question. The server responds with the answer, or with a pointer to where the client can get more information

The LDAP server supports a variety of different database back ends which you can use. They include the primary choice BDB, a high-performance transactional database back end.

Open LDAP
Open ldap is open source implementation of the LDAP protocol. Many Linux distributions have support to the open ldap

In this article we will see how we can configure Open LDAP on Redhat Linux 6 and also see how to add data and access that.

Requirements
Make sure you install all the Necessary Packages

[root@vx111a slapd.d]# yum list installed | grep ldap
apr-util-ldap.x86_64 1.3.9-3.el6_0.1 @anaconda-RedHatEnterpriseLinux-201105101844.x86_64/6.1
compat-openldap.x86_64 1:2.3.43-2.el6 @anaconda-RedHatEnterpriseLinux-201105101844.x86_64/6.1
openldap.x86_64 2.4.23-15.el6 @anaconda-RedHatEnterpriseLinux-201105101844.x86_64/6.1
openldap-clients.x86_64 2.4.23-15.el6 @rhel-source
openldap-devel.x86_64 2.4.23-15.el6 @rhel-source
openldap-servers.x86_64 2.4.23-15.el6 @rhel-source
python-ldap.x86_64 2.3.10-1.el6 @anaconda-RedHatEnterpriseLinux-201105101844.x86_64/6.1

Install all the open Ldap packages using
yum install *openldap* -y

Configuration
Once the Installation of the Open Ldap packages are completed. We then go for configuring the openldap. The main core file for open ldap is slapd.conf file

[root@vx111a slapd.d]# cd /etc/openldap/
[root@vx111a openldap]# updatedb
[root@vx111a openldap]# locate slapd.conf
/root/slapd.conf
****
****
/usr/share/openldap-servers/slapd.conf.obsolete

For the /etc/openldap/ location
[root@vx111a openldap]# cp /usr/share/openldap-servers/slapd.conf.obsolete slapd.conf

Password Configuration
Once the slapd.conf file is available ,create a password for connecting to the open ldap server using

[root@vx111a openldap]# slappasswd
New password:
Re-enter new password:
{SSHA}gGyRLMZEQWSj0G5aJr43PY9AeqGSBm2p

Copy the DB Configuration File
[root@vx111a openldap]# cp /usr/share/openldap-servers/DB_CONFIG.example /var/lib/ldap/DB_CONFIG

Modify the slapd.conf File
The Important elements that needs to be done are ,

database bdb
suffix "dc=example,dc=com" #Change according to you Domain
rootdn "cn=Manager,dc=example,dc=com" #Change according to you Domain
#rootpw secret
rootpw {SSHA}gGyRLMZEQWSj0G5aJr43PY9AeqGSBm2p
mode 0700
directory /var/lib/ldap


# enable monitoring
database monitor #To use Database monitor

# allow onlu rootdn to read the monitor #Permissions for the Users on the monitor Darabase
access to *
by dn.exact="cn=Manager,dc=my-domain,dc=com" read
by * none

Test the Configurations
Test the Configurations using ,

[root@vx111a openldap]# slaptest -f slapd.conf -F slapd.d/
bdb_db_open: DB_CONFIG for suffix "dc=example,dc=com" has changed.
Performing database recovery to activate new settings.
bdb_db_open: database "dc=example,dc=com": recovery skipped in read-only mode. Run manual recovery if errors are encountered.
config file testing succeeded

We can also use
slapd -Tt
config file testing Succeded

Start the Service
[root@vx111a openldap]# service slapd restart
Stopping slapd: [ OK ]
Starting slapd: [ OK ]

Test
Test the ldap Configuration using the ldap tool available like

[root@vx111a Desktop]# ldapsearch -x -b '' -s base '(objectclass=*)' namingContexts
# extended LDIF
#
# LDAPv3
# base <> with scope baseObject
# filter: (objectclass=*)
# requesting: namingContexts
#

#
dn:
namingContexts: dc=example,dc=com

# search result
search: 2
result: 0 Success

# numResponses: 2
# numEntries: 1

Note the use of single quotes around command parameters to prevent special characters from being interpreted by the shell. This should return:

dn:
namingContexts: dc=example,dc=com


Add Data
Once the Ldap test is successful ,we will add the Data. Copy the below content to a text file as example.ldif

dn: dc=example,dc=com
objectclass: dcObject
objectclass: organization
o: Example Company
dc: example

dn: cn=Manager,dc=example,dc=com
objectclass: organizationalRole
cn: Manager

Now save and add to ldap using
[root@vx111a Desktop]# ldapadd -x -D "cn=Manager,dc=example,dc=com" -W -f example.ldif
Enter LDAP Password:
adding new entry "dc=example,dc=com"

adding new entry "cn=Manager,dc=example,dc=com"


#it asks for the password for connecting to the ldap , use the password that we encrypted and added to the sladp.conf file

Search The Data
Once the Data is added successfully ,we can search the data using

[root@vx111a Desktop]# ldapsearch -x -b 'dc=example,dc=com' '(objectclass=*)'
# extended LDIF
#
# LDAPv3
# base <dc=example,dc=com> with scope subtree
# filter: (objectclass=*)
# requesting: ALL
#

# example.com
dn: dc=example,dc=com
objectClass: dcObject
objectClass: organization
o: Example Company
dc: example

# Manager, example.com
dn: cn=Manager,dc=example,dc=com
objectClass: organizationalRole
cn: Manager

# search result
search: 2
result: 0 Success

# numResponses: 3
# numEntries: 2

By this we complete the Configuration of Ldap on Redhat Linux.
Happy Learning :-) , More to Come.


Read More

Saturday, December 17, 2011

OpenDS Directory Server


OpenDS is a directory server entirely written in java and fully compliment with LDAP protocol version 3.The main features of OpenDS are

  • OpenDS is a open Source Directory server
  • OpenDS is simple to install and configure.
  • OpenDS contains rich features and provides excellent performance
  • You can extend OpenDS to add custom capabilities.
  • You can easily embed OpenDS in your own application or test framework.
In this article, we will see how we can configure OpenDS in Rhel5.

Download the OpenDS zip file from Here

Once you got the Zip file, extract to a location. Go to the extracted location and in bin directory execute the command

. /setup

A GUI interface will start. The Configuration proceeds in the following,















Click Next .In The Next screen select the Host Name ,LDAP Listener port , Administration Connector Port and Password.The LDAP Listener Port is 389.In most cases it is taken as 10389 , since any port opened above the 1024 can be restarted by any user.If the port is below 1024,then some of the actions on these ports may be done only by root user.The administration connector port is chosen as 4444 by default.Enter the Password and remember since this will be used when we connect to control panel to perform operations on server.
 














In the Next screen , Select whether this is a standalone server or it is a replication server.In a replication server topology when one server goes down the other server will be available and provides the support to application.Select the Standalone Server.  















In the next screen , select the Directory Data Information.You can use the default one "dc=example,dc=com".















In the next screen , you will be shown with all the configurations.Check them and if they are OK,click the Finish.














 It takes a few minutes for configuring the server and directory data.Once every thing goes fine ,you will see the below screen.Click the Control Panal and enter the password that we configured previously.You will shown a screen with the Directory Data.We can add users, groups in this screen.


















By This we completed the configuration of OpenDS server.
More Articles to Come...
Read More

Thursday, November 10, 2011

LifeRay With OpenID


In This article, we will see how we can configure the OpenID server and link that to the LifeRay Portal Server. For this article I have used the Atlassian Crowd Server as OpenID server. This article goes in steps.

1.    What is an OpenID ?
2.    Benefits of OpendID
3.    How Does It Work
4.    Backend Library
5.    Download the Atlassian Crowd OpenID Server.
6.    Configure the Crowd Open ID Server.
7.    Configure LifeRay with the Crowd Open ID Server.
8.    Create a user in Crowd OpenID Server.
9.    Generate OpenID for the User.
10. Login into LifeRay using OpenID.

This article mainly focuses on OpenID details, configuration of LifeRay with Atlassian's CrowdID OpenID server.

1. What is an OpenID?

OpenID is an open, decentralized, free framework for user-centric digital identity.

OpenID starts with the concept that anyone can identify themselves on the Internet the same way websites do-with a URI (also called a URL or web address). Since URIs are at the very core of Web architecture, they provide a solid foundation for user-centric identity.


2. Benefits of OpenID

From end user View, An OpenID is a single username and password that lets you login to any OpenID-enabled site. OpenID makes remembering different usernames and passwords for different sites a thing of the past.

From Website View, facilitates registration for end users.

The end purpose of OpenID is to keep all the sensible information in the provider so that it's not spread through all the websites where the user has an account. This makes it much easier to protect and keep up to date.

3. How does it work?

  1. User selects an OpenID Provider and creates an account in it. The provider gives the user a unique URL that identifies him.
  2. User finds a new website and wants to create an account. He finds out happily that the website supports OpenID (it's an OpenID consumer).
  3. User logs in with his OpenID URL
  4. The website uses the URL to contact the OpenID provider of the user and requests it some information to be able to create the new account for the user
  5. The user is redirected to his provider's website to:
    1. Login to demonstrate he is the owner of the URL
    2. Accept the request for information from the original website (the providers usually allow maintaining several profiles and the user can select which one to use)
  6. The user is then redirected to the original website with all the necessary information
  7. The website takes that information and creates an account for the user (only the first time) and logs him in
  8. The user logs in

4. Backend Library

LifeRay uses OpenId4java as the backend library to implement the OpenID functionality. This library was chosen because:
  • It is free software with a License compatible with Life ray’s (Apache License 2.0)
  • It seems to have the largest community among the alternatives

5. Download the Atlassian Crowd Server.

Download the Crowd OpenID server from Here .

6. Configure the Crowd Open ID Server.

The first step in configuring the Crowd OpenID server are ,

Specify your Crowd Home directory by editing the configuration file at CROWD-INSTALLATION/WEB-INF/classes/crowd-init.properties for Unix(if working in Unix) and
windows(if working for windows)

crowd.home=/usr/crowd (I changed the directory name to crowd)

2. Go To /usr/crowd/apache-tomcat/conf/Catalina/localhost and open the file crowd.xml (else create one with the data)

Change the docBase with the correct path of crowd-webapp like

<Context path="/crowd" docBase="/usr/crowd/crowd-webapp" debug="0" reloadable="false">
..
..
..
</Context>
3. Go to the Location, /usr/crowd/crowd-openidserver-webapp/WEB-INF/classes
and modify the crowd.properties like,

application.name                       crowd-openid-server
application.password                 password
application.login.url                   http://localhost:8095/openidserver

crowd.server.url                        http://localhost:8095/crowd/services/

session.isauthenticated              session.isauthenticated
session.tokenkey                       session.tokenkey
session.validationinterval           0
session.lastvalidation                 session.lastvalidation

Modify the crowd.server.url and application.login.url.

4. Go to the Location, /usr/crowd/apache-tomcat/conf/Catalina/localhost
and create a file(if not available) openidserver.xml with the following content

<Context path="/openidserver" docBase="../../crowd-openidserver-webapp" debug="0">

    <Resource name="jdbc/CrowdIDDS" auth="Container" type="javax.sql.DataSource"
              username="sa"
              password=""
              driverClassName="org.hsqldb.jdbcDriver"
              url="jdbc:hsqldb:${catalina.home}/../database/crowdopenidserverdb"
              minEvictableIdleTimeMillis="4000"
              timeBetweenEvictionRunsMillis="5000"
              maxActive="20"
            />

<Manager className="org.apache.catalina.session.PersistentManager" saveOnRestart="false"/>

</Context>

If the file exists, add the line leaving the rest untouched,

<Manager className="org.apache.catalina.session.PersistentManager" saveOnRestart="false"/>

5. Once all these modifications are done. Restart the tomcat server . The url will be

For OpenID server: http://localhost:8095/openidserver/login.action

6. Once the configurations are done , Start the Tomcat server in the same directory location and access the url in a browser and follow the steps,


Since the Crowd OpenID server is available only for a trail version, it will ask for a Evaluation key. We need to register with Atlassian Crowd Server and get a key from the web site. Once the get the key , the server will allow us to move further .The next step would be to configure Type of Database

 










The Next Step would be to select the options,












Give a name to the Deployment Title, Value to Session Time Out and Base URL.

The next step would be to configure the Internal Directory, I just gave the Name and took the default value for others

















The Next step would be to configure and Administrator account,












The next step is to configure the Integrated applications .I have taken the default options.










And Then the final step, 







Once the configuration is done correctly, a login screen will be shown. We can login using the username and password which we created as a administrator.

7. Configure LifeRay with the Crowd Open ID Server.

The Configuration of LifeRay with Crowd OpenID server is done in the 3 step above.

8. Create a User in Crowd OpenID Server.

Login in as administrator (the user that we created while configuring the Crowd OpenID server).Once we login into the Server, we see the screen

















Select Users on the top panel . In the Left pane , click on the Add User. 
 

 














 Create a user with all required details



 













9. Generate OpenID for the User.

Once the user is configured, open the url
http://localhost:8095/openidserver/login.action in a browser and login using the username and password that we created before.









Once we login, we are given with a OpenID.
 











10. Login into LifeRay using OpenID.

Start the LifeRay Server and sign in using the OpenID option under the Sign In portal.

 









Enter the OpenID url that we got and click sign in. It will take us to the OpenID server. Once we are logged in, we see the following page. Select the Allow Always option.











Once we select the Allow Always, we will be taken back to the LifeRay server










By This we complete the Configuration of OpenID server with Liferay.
More Articles To Come , Happy Coding..






Read More