SLAPO-SMBK5PWD - Online Linux Manual PageSection : 5
Updated : RELEASEDATE
Source : OpenLDAP LDVERSION

NAMEslapo-smbk5pwd − Samba & Kerberos password sync overlay to slapd

SYNOPSISETCDIR/slapd.conf include <path to>/krb5-kdc.schema" include <path to>/samba.schema" moduleload smbk5pwd.so
 ...
database mdb
 ...
overlay smbk5pwd

DESCRIPTIONThe smbk5pwd overlay to slapd(8) overloads the Password Modify Extended Operation (RFC 3062) to update Kerberos keys and Samba password hashes for an LDAP user, as well as updating password change related attributes for Kerberos, Samba and/or UNIX user accounts. The Samba support is written using the Samba 3.0 LDAP schema; Kerberos support is written for Heimdal using its hdb-ldap backend. Additionally, a new {K5KEY} password hash mechanism is provided. For krb5KDCEntry objects that have this scheme specifier in their userPassword attribute, Simple Binds will be checked against the Kerberos keys of the entry. No data is needed after the {K5KEY} scheme specifier in the userPassword, it is looked up from the entry directly.

CONFIGURATIONThe smbk5pwd overlay supports the following slapd.conf configuration options, which should appear after the overlay directive: smbk5pwd-enable <module>  can be used to enable only the desired modules. Legal values for <module> are krb5  If the user has the krb5KDCEntry objectclass, update the krb5Key and krb5KeyVersionNumber attributes using the new password in the Password Modify operation, provided the Kerberos account is not expired. Exiration is determined by evaluating the krb5ValidEnd attribute. samba  If the user is a sambaSamAccount object, synchronize the sambaNTPassword to the password entered in the Password Modify operation, and update sambaPwdLastSet accordingly. shadow  Update the attribute shadowLastChange, if the entry has the objectclass shadowAccount. By default all modules compiled in are enabled. Setting the config statement restricts the enabled modules to the ones explicitly mentioned. smbk5pwd-can-change <seconds>  If the samba module is enabled and the user is a sambaSamAccount, update the attribute sambaPwdCanChange to point <seconds> into the future, essentially denying any Samba password change until then. A value of 0 disables this feature. smbk5pwd-must-change <seconds>  If the samba module is enabled and the user is a sambaSamAccount, update the attribute sambaPwdMustChange to point <seconds> into the future, essentially setting the Samba password expiration time. A value of 0 disables this feature. Alternatively, the overlay supports table-driven configuration, and thus can be run-time loaded and configured via back-config.

EXAMPLEThe layout of a slapd.d based, table-driven configuration entry looks like: # {0}smbk5pwd, {1}mdb, config dn: olcOverlay={0}smbk5pwd,olcDatabase={1}mdb,cn=config objectClass: olcOverlayConfig objectClass: olcSmbK5PwdConfig olcOverlay: {0}smbk5pwd olcSmbK5PwdEnable: krb5 olcSmbK5PwdEnable: samba olcSmbK5PwdMustChange: 2592000which enables both krb5 and samba modules with a Samba password expiration time of 30 days (= 2592000 seconds).

SEE ALSOslapd.conf(5), ldappasswd(1), ldap(3), "OpenLDAP Administrator's Guide" (http://www.OpenLDAP.org/doc/admin/)

ACKNOWLEDGEMENTSThis manual page has been written by Peter Marschall based on the module's README file written by Howard Chu. OpenLDAP is developed and maintained by The OpenLDAP Project (http://www.openldap.org/). OpenLDAP is derived from University of Michigan LDAP 3.3 Release.
0
Johanes Gumabo
Data Size   :   11,563 byte
man-slapo-smbk5pwd.5Build   :   2024-12-05, 20:55   :  
Visitor Screen   :   x
Visitor Counter ( page / site )   :   2 / 185,124
Visitor ID   :     :  
Visitor IP   :   18.217.104.36   :  
Visitor Provider   :   AMAZON-02   :  
Provider Position ( lat x lon )   :   39.962500 x -83.006100   :   x
Provider Accuracy Radius ( km )   :   1000   :  
Provider City   :   Columbus   :  
Provider Province   :   Ohio ,   :   ,
Provider Country   :   United States   :  
Provider Continent   :   North America   :  
Visitor Recorder   :   Version   :  
Visitor Recorder   :   Library   :  
Online Linux Manual Page   :   Version   :   Online Linux Manual Page - Fedora.40 - march=x86-64 - mtune=generic - 24.12.05
Online Linux Manual Page   :   Library   :   lib_c - 24.10.03 - march=x86-64 - mtune=generic - Fedora.40
Online Linux Manual Page   :   Library   :   lib_m - 24.10.03 - march=x86-64 - mtune=generic - Fedora.40
Data Base   :   Version   :   Online Linux Manual Page Database - 24.04.13 - march=x86-64 - mtune=generic - fedora-38
Data Base   :   Library   :   lib_c - 23.02.07 - march=x86-64 - mtune=generic - fedora.36

Very long time ago, I have the best tutor, Wenzel Svojanovsky . If someone knows the email address of Wenzel Svojanovsky , please send an email to johanes_gumabo@yahoo.co.id .
If error, please print screen and send to johanes_gumabo@yahoo.co.id
Under development. Support me via PayPal.