IDMAP_LDAP - Online Linux Manual PageSection : 8
Updated : 04/07/2021
Source : Samba 4​.14​.2
Note : System Administration tools

NAMEidmap_ldap − Samba's idmap_ldap Backend for Winbind

DESCRIPTIONThe idmap_ldap plugin provides a means for Winbind to store and retrieve SID/uid/gid mapping tables in an LDAP directory service​. In contrast to read only backends like idmap_rid, it is an allocating backend: This means that it needs to allocate new user and group IDs in order to create new mappings​.

IDMAP OPTIONSldap_base_dn = DN Defines the directory base suffix to use for SID/uid/gid mapping entries​. If not defined, idmap_ldap will default to using the "ldap idmap suffix" option from smb​.conf​. ldap_user_dn = DN Defines the user DN to be used for authentication​. The secret for authenticating this user should be stored with net idmap secret (see net(8))​. If absent, the ldap credentials from the ldap passdb configuration are used, and if these are also absent, an anonymous bind will be performed as last fallback​. ldap_url = ldap://server/ Specifies the LDAP server to use for SID/uid/gid map entries​. If not defined, idmap_ldap will assume that ldap://localhost/ should be used​. range = low − high Defines the available matching uid and gid range for which the backend is authoritative​.

EXAMPLESThe following example shows how an ldap directory is used as the default idmap backend​. It also configures the idmap range and base directory suffix​. The secret for the ldap_user_dn has to be set with "net idmap secret '*' password"​. [global] idmap config * : backend = ldap idmap config * : range = 1000000−1999999 idmap config * : ldap_url = ldap://localhost/ idmap config * : ldap_base_dn = ou=idmap,dc=example,dc=com idmap config * : ldap_user_dn = cn=idmap_admin,dc=example,dc=com This example shows how ldap can be used as a readonly backend while tdb is the default backend used to store the mappings​. It adds an explicit configuration for some domain DOM1, that uses the ldap idmap backend​. Note that a range disjoint from the default range is used​. [global] # "backend = tdb" is redundant here since it is the default idmap config * : backend = tdb idmap config * : range = 1000000−1999999 idmap config DOM1 : backend = ldap idmap config DOM1 : range = 2000000−2999999 idmap config DOM1 : read only = yes idmap config DOM1 : ldap_url = ldap://server/ idmap config DOM1 : ldap_base_dn = ou=idmap,dc=dom1,dc=example,dc=com idmap config DOM1 : ldap_user_dn = cn=idmap_admin,dc=dom1,dc=example,dc=com

NOTEIn order to use authentication against ldap servers you may need to provide a DN and a password​. To avoid exposing the password in plain text in the configuration file we store it into a security store​. The "net idmap " command is used to store a secret for the DN specified in a specific idmap domain​.

AUTHORThe original Samba software and related utilities were created by Andrew Tridgell​. Samba is now developed by the Samba Team as an Open Source project similar to the way the Linux kernel is developed​.
0
Johanes Gumabo
Data Size   :   7,585 byte
man-idmap_ldap.8Build   :   2024-12-05, 20:55   :  
Visitor Screen   :   x
Visitor Counter ( page / site )   :   4 / 193,419
Visitor ID   :     :  
Visitor IP   :   3.146.107.152   :  
Visitor Provider   :   AMAZON-02   :  
Provider Position ( lat x lon )   :   39.962500 x -83.006100   :   x
Provider Accuracy Radius ( km )   :   1000   :  
Provider City   :   Columbus   :  
Provider Province   :   Ohio ,   :   ,
Provider Country   :   United States   :  
Provider Continent   :   North America   :  
Visitor Recorder   :   Version   :  
Visitor Recorder   :   Library   :  
Online Linux Manual Page   :   Version   :   Online Linux Manual Page - Fedora.40 - march=x86-64 - mtune=generic - 24.12.05
Online Linux Manual Page   :   Library   :   lib_c - 24.10.03 - march=x86-64 - mtune=generic - Fedora.40
Online Linux Manual Page   :   Library   :   lib_m - 24.10.03 - march=x86-64 - mtune=generic - Fedora.40
Data Base   :   Version   :   Online Linux Manual Page Database - 24.04.13 - march=x86-64 - mtune=generic - fedora-38
Data Base   :   Library   :   lib_c - 23.02.07 - march=x86-64 - mtune=generic - fedora.36

Very long time ago, I have the best tutor, Wenzel Svojanovsky . If someone knows the email address of Wenzel Svojanovsky , please send an email to johanes_gumabo@yahoo.co.id .
If error, please print screen and send to johanes_gumabo@yahoo.co.id
Under development. Support me via PayPal.