dkluenter

include         /home/dieter/openldap/etc/openldap/schema/core.schema
include         /home/dieter/openldap/etc/openldap/schema/cosine.schema
include         /home/dieter/openldap/etc/openldap/schema/inetorgperson.schema
include         /home/dieter/openldap/etc/openldap/schema/nis.schema
include         /home/dieter/openldap/etc/openldap/schema/dyngroup.schema
include         /home/dieter/openldap/etc/openldap/schema/ppolicy.schema

pidfile         
/home/dieter/openldap/var/run/slapd.pid
argsfile        
/home/dieter/openldap/var/run/slapd.args
loglevel 0

modulepath      
/home/dieter/openldap/libexec/openldap
# moduleload    back_meta.la
# moduleload      accesslog.la

TLSCACertificateFile    /home/dieter/certs/avciCA.pem
TLSCertificateFile      
/home/dieter/certs/magenta.pem
TLSCertificateKeyFile   
/home/dieter/certs/magenta-key.pem
TLSCipherSuite  HIGH
:TLSv1
TLSVerifyClient 
try

password-hash {CLEARTEXT}
include /
home/dieter/openldap/etc/openldap/dkluenter.acl
sizelimit 
-1

authz
-regexp uid=(.*),cn=.*,cn=auth
             ldap
:///dc=dkluenter,dc=de??sub?uid=$1
authz-regexp
    gidNumber
=0\\+uidNumber=0,cn=peercred,cn=external,cn=auth
    cn
=config


database        config
rootdn          cn
=config
rootpw          xxxxx

database        hdb
suffix          
"ou=hamburg,dc=dkluenter,dc=de"
subordinate advertise
rootdn          
"cn=admin,dc=dkluenter,dc=de"
directory       /home/dieter/openldap/var/hamburg-data  
checkpoint      4096    5
index           
default pres,eq
index           objectclass eq
index           mail sub
,eq
index           cn
,sn sub,eq
index           entryCSN
,entryUUID
cachesize       5000
idlcachesize    15000
dbconfig set_cachesize 0 68157440 0
dbconfig set_lg_dir 
/home/dieter/openldap/var/log/hamburg
dbconfig set_lg_regionmax 262144
dbconfig set_lg_bsize 2097152
dbconfig set_flags DB_LOG_AUTOREMOVE
syncrepl rid
=42
        provider
=ldap://rubin.avci.de
        
sizelimit=unlimited
        bindmethod
=simple
        binddn
=cn=replicator,ou=Administrative,dc=dkluenter,dc=de
        credentials
=xxxxx
        searchbase
="ou=hamburg,dc=dkluenter,dc=de"
        
scope=sub
        type
=refreshAndPersist
        retry
="5 5 300 5"
        
logbase="cn=log"
        
logfilter=(&(objectClass=auditWriteObject)(reqResult=0))
        
syncdata=accesslog
updateref ldap
://rubin.avci.de

database        hdb
suffix          
"ou=bremen,dc=dkluenter,dc=de"
subordinate advertise
rootdn  
"cn=admin,dc=dkluenter,dc=de"
directory       /home/dieter/openldap/var/bremen-data
checkpoint      4096 5
cachesize       5000
idlcachesize    1500
index   objectclass eq
index   sn
,cn,mail eq,sub
index   entryCSN
,entryUUID eq
dbconfig set_cachesize 0 68157440 0
dbconfig set_lg_dir 
/home/dieter/openldap/var/log/bremen
dbconfig set_lg_regionmax 262144
dbconfig set_lg_bsize 2097152
dbconfig set_flags DB_LOG_AUTOREMOVE
syncrepl rid
=99
        provider
=ldap://rubin.avci.de
        
sizelimit=unlimited
        bindmethod
=simple
        binddn
=cn=replicator,ou=Administrative,dc=dkluenter,dc=de
        credentials
=xxxxxxx
        searchbase
="ou=bremen,dc=dkluenter,dc=de"
        
scope=sub
        type
=refreshAndPersist
        retry
="5 5 300 5"
        
logbase="cn=log"
        
logfilter=(&(objectClass=auditWriteObject)(reqResult=0))
        
syncdata=accesslog
updateref ldap
://rubin.avci.de

database        hdb
suffix          
"dc=dkluenter,dc=de"
rootdn          "cn=admin,dc=dkluenter,dc=de"
rootpw          xxxxxx
checkpoint      1024    5
cachesize       2000
idlcachesize    6000
directory       
/home/dieter/openldap/var/hdk-data
checkpoint      4096 5
cachesize       5000
idlcachesize    1500
dbconfig set_cachesize 0 68157440 0
dbconfig set_lg_dir 
/home/dieter/openldap/var/log/hdk
dbconfig set_lg_regionmax 262144
dbconfig set_lg_bsize 2097152
dbconfig set_flags DB_LOG_AUTOREMOVE

index   objectClass     eq
index 
default pres,eq
index mail
,telephoneNumber
index cn
,sn,uid eq,sub
index entryUUID
,entryCSN eq
overlay glue

database        monitor
access to dn
.subtree="cn=Monitor" by read
# EOF

 


» ohne Titel
« ohne Titel