[INFRA] OpenLDAP๊ณผ LDAP Account Manager ์„ค์น˜ํ•˜๊ธฐ

2023. 1. 5. 00:05ใ†System ์ž‘์—…์‹ค/DevOps

728x90
๋ฐ˜์‘ํ˜•

 

 

 




๐Ÿ—‚ ๋ชฉ์ฐจ

โ— [INFRA] OpenLDAP๊ณผ LDAP Account Manager ์„ค์น˜ํ•˜๊ธฐ
โ— [INFRA] OpenLDAP๊ณผ Client CentOS 7.9 ์—ฐ๋™ํ•˜๊ธฐ
โ— [INFRA] Installation Keycloak of Ubuntu 22.04.01 LTS in Docker Container
โ— 

 

 

 

LDAP System Administration Paperback

COUPANG

www.coupang.com

"์ด ํฌ์ŠคํŒ…์€ ์ฟ ํŒก ํŒŒํŠธ๋„ˆ์Šค ํ™œ๋™์˜ ์ผํ™˜์œผ๋กœ, ์ด์— ๋”ฐ๋ฅธ ์ผ์ •์•ก์˜ ์ˆ˜์ˆ˜๋ฃŒ๋ฅผ ์ œ๊ณต๋ฐ›์Šต๋‹ˆ๋‹ค."

 

 

๐Ÿš€ Ubuntu 22.04 Docker์— OpenLDAP ๊ตฌ์„ฑ

    ๐Ÿ”ฝ  ๊ตฌ์„ฑ    

        ๐Ÿ“ฆ OpenLDAP ์„ค์น˜

์ตœ์ดˆ ์ฃผ๋‹ˆํ•˜๋ž‘์€ Ubuntu 22.04 LTS Docker Container๋ฅผ ์ด์šฉํ•  ๊ฑฐ์—์š”.


์œ„์™€ ๊ฐ™์ด Docker๋ฅผ ๊ธฐ๋™ํ•  ์ˆ˜ ์žˆ๋Š” Shell Script๋ฅผ ๋งŒ๋“ค๊ณ , ๊ธฐ๋™ํ•˜์—ฌ ์ฃผ์—ˆ์–ด์š”.

๊ทธ๋Ÿฐ ๋’ค Ubuntu Package ์ตœ์‹ ํ™”๋ฅผ ์ง„ํ–‰ํ•ด ์ค„๊ฒŒ์š”.

apt-get update && apt-get upgrade -y

 

apt-get install -y vim systemd net-tools iputils-ping ntp


๊ทธ๋Ÿฐ ๋’ค ์œ„์™€ ๊ฐ™์ด ํ•„์š”ํ•œ Package๋ฅผ ์ถ”๊ฐ€ ์„ค์น˜ํ•ด ์ฃผ์—ˆ์–ด์š”.


OpenLDAP์„ ์„ค์น˜ํ•˜๊ธฐ ์ „์— OpenLDAP Server FQDN(์ •๊ทœํ™”๋œ Domain Name) ๊ตฌ์„ฑ์ด ์˜ฌ๋ฐ”๋ฅธ์ง€ ํ™•์ธํ•ด์•ผ ํ•ด์š”.
์ด๋ฒˆ ๊ธ€์—์„œ ๊ตฌ์„ฑํ•˜๋Š” Server์—์„œ๋Š” Server Host Name "http" ๋ฐ Domain "giggalpeople.com"๊ณผ IP ์ฃผ์†Œ "172.17.0.7"์„ ์ด์šฉํ•˜์—ฌ OpenLDAP Server๋ฅผ ๋งž์ถฐ๋ณด๋„๋ก ํ• ๊ฑฐ์—์š”.


์ด ๋‚ด์šฉ์€ ์œ„์—์„œ Container๋ฅผ ๋งŒ๋“ค ๋•Œ ์ง„ํ–‰ ํ•ด ์ฃผ์—ˆ์–ด์š”.

cat /etc/hosts



hostname -f


hostname์ด ์œ„์™€ ๊ฐ™์ด ์ž˜ ์„ค์ • ๋˜์–ด ์žˆ์–ด์š”.


์ด์ œ OpenLDAP ๊ด€๋ จ Package๋ฅผ ์„ค์น˜ํ•ด ๋ณผ๊ฒŒ์š”.

apt-get install -y slapd ldap-utils

๋ฐ˜์‘ํ˜•


์œ„ ๋ช…๋ น์–ด๋กœ Package ์„ค์น˜๋ฅผ ํ•ด ์ฃผ์—ˆ์–ด์š”.




์ตœ์ดˆ OpenLDAP Package ์„ค์น˜ ์‹œ OpenLDAP ๊ด€๋ฆฌ์ž ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ์„ค์ •ํ•˜๋ผ๊ณ  ํ•  ๊ฑฐ์—์š”.
OpenLDAP ๊ด€๋ฆฌ์ž์˜ ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ์ž…๋ ฅํ•˜๊ณ , ENTER๋ฅผ ๋ˆŒ๋Ÿฌ์ฃผ๋ฉด ๋˜ ํ•œ๋ฒˆ ๋” ๋ฌผ์–ด๋ณผ๊ฑฐ๊ณ , ๋™์ผํ•œ ์ž‘์—…์„ ์ง„ํ–‰ํ•ด ์ฃผ๋ฉด ๋˜์š”.

 

 

 

 

 

        ๐Ÿ“ฆ ์ดˆ๊ธฐ ๊ตฌ์„ฑ

OpenLDAP Server ์„ค์ •์„ ์‹œ์ž‘ํ•˜๋ ค๋ฉด ์•„๋ž˜ ๋ช…๋ น์–ด๋ฅผ ์ž…๋ ฅํ•ด ์ค˜์•ผ ํ•ด์š”.
์ด ๋ช…๋ น์–ด๋Š” OpenLDAP Main Package slapd๋ฅผ ์žฌ์„ค์ •ํ•˜๊ณ , ๊ธฐ๋ณธ OpenLDAP ๊ตฌ์„ฑ ์ค‘ ์ผ๋ถ€๋ฅผ ์ž…๋ ฅํ•˜๋ผ๋Š” Message๋ฅผ ์ถœ๋ ฅํ•˜๊ฒŒ ๋ ๊ฑฐ์—์š”.

dpkg-reconfigure slapd


์œ„์™€ ๊ฐ™์ด Omit OpenLDAP Server Configuraion? ์„ ๋ฌผ์–ด๋ณด๋ฉด no๋ฅผ ์„ ํƒํ•ด์ค๋‹ˆ๋‹ค.
๊ทธ๋Ÿฌ๋ฉด OpenLDAP Server์— ์ƒˆ ๊ตฌ์„ฑ File๊ณผ DB๊ฐ€ ์„ค์ •๋  ๊ฑฐ์—์š”.



์ด๋ฒˆ์—” Domain Name์„ ์„ค์ •ํ•ด ๋ณผ๊ฒŒ์š”.
Domain Name์€ OpenLDAP Server์˜ DN(Distinguished Name)์œผ๋กœ ์‚ฌ์šฉ๋ ๊ฑฐ์—์š”.
์ด๋ฒˆ ๊ตฌ์„ฑ์—์„œ๋Š” Domain Name์ด giggalpeople.com ์ด๊ธฐ ๋•Œ๋ฌธ์— dc=giggalpeole,dc=com์ด ๋ฉ๋‹ˆ๋‹ค.


์ด๋ฒˆ์—๋Š” ์กฐ์ง ์ด๋ฆ„์„ ์„ค์ •ํ•ด ๋ณด๋ ค๊ณ  ํ•ด์š”.
Domain์„ ์ด์šฉํ• ์ˆ˜๋„ ์žˆ๊ณ , ๋‹ค๋ฅธ ์ด๋ฆ„์„ ์ด์šฉํ• ์ˆ˜๋„ ์žˆ์ง€๋งŒ, ์ฃผ๋‹ˆํ•˜๋ž‘์€ Domain ์ •๋ณด๋ฅผ ์ด์šฉํ•  ๊ฑฐ์—์š”.



์ด๋ฒˆ์—๋Š” OpenLDAP์˜ ๊ด€๋ฆฌ์ž ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ์ž…๋ ฅํ•ด ์ค„๊ฑฐ์—์š”.
๋‘ ๋ฒˆ ๋ฌผ์–ด๋ณด๊ฒŒ ๋œ๋‹ต๋‹ˆ๋‹ค.



์ด๋ฒˆ์—๋Š” ์ด์ „ DB๋ฅผ ์ œ๊ฑฐํ• ๊ฑด์ง€ ๋ฌผ์–ด๋ณด๊ณ  ์žˆ์–ด์š”.
์—ฌ๊ธฐ์„œ๋Š” no๋ฅผ ์„ ํƒํ•ด ์ค„๊ฒŒ์š”.


์ด๋ฒˆ์—๋Š” OpenLDAP DB๋ฅผ ์ด๋™ํ• ๊ฑด์ง€ ๋ฌผ์–ด๋ณด๊ณ  ์žˆ์–ด์š”. yes๋ฅผ ์„ ํƒํ•˜์—ฌ OpenLDAP ๊ตฌ์„ฑ์„ ๋งˆ๋ฌด๋ฆฌ ํ•ด์ค„๊ฑฐ์—์š”.



์œ„์™€ ๊ฐ™์ด ๋‚˜์˜จ๋‹ค๋ฉด ์ •์ƒ ์„ค์ •๋œ ๊ฒƒ์ด์—์š”.


์•„๋ž˜ ๋ช…๋ น์–ด๋ฅผ ์ด์šฉํ•˜์—ฌ slapd Package ๊ตฌ์„ฑ์„ ์ˆ˜์ •ํ•ด ์ค„๊ฒŒ์š”.

vim /etc/ldap/ldap.conf ๋ณ€๊ฒฝ ์ „

 

vim /etc/ldap/ldap.conf ๋ณ€๊ฒฝ ๋’ค


์œ„์™€ ๊ฐ™์ด 8 ~ 9๋ฒˆ์งธ ์ค„์„ ์ˆ˜์ •ํ•˜์—ฌ ์ฃผ์—ˆ์–ด์š”.


service slapd restart


์œ„์™€ ๊ฐ™์ด slapd Service๋ฅผ ์žฌ์‹œ์ž‘ํ•˜์—ฌ OpenLDAP Server์— ์ƒˆ๋กœ์šด ๋ณ€๊ฒฝ์‚ฌํ•ญ์„ ์ ์šฉํ•ด ์ฃผ๋„๋ก ํ•˜์˜€์–ด์š”.
ํ˜„์žฌ OpenLDAP Server๋Š” DN๊ฐ’์œผ๋กœ dc=giggalpeople,dc=com ์„ ์ด์šฉํ•˜์—ฌ ๊ตฌ๋™์ค‘์— ์žˆ์–ด์š”.


์ด์ œ ์•„๋ž˜ ๋ช…๋ น์–ด๋ฅผ ํ†ตํ•ด OpenLDAP ๊ธฐ๋ณธ ์„ค์ •์„ ํ™•์ธํ•ด ๋ณด๋„๋ก ํ• ๊ฒŒ์š”.


ldapsearch -Q -LLL -Y EXTERNAL -H ldapi:///


์„ค์ •์ด ์ž˜ ๋œ ๊ฒƒ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ์–ด์š”.






 

        ๐Ÿ“ฆ ๊ธฐ๋ณธ ๊ทธ๋ฃน ์„ค์ •

OpenLDAP Server์˜ ๊ธฐ๋ณธ DN(Distinguished Name)์„ ์„ค์ •ํ•˜๋ฉด Open LDAP ์‚ฌ์šฉ์ž์˜ ์ƒˆ๋กœ์šด ๊ธฐ๋ณธ ๊ทธ๋ฃน์ด ์ƒ์„ฑ๋  ๊ฑฐ์—์š”. ์ด๋ฒˆ ๊ตฌ์„ฑ์—์„œ๋Š” ๊ธฐ๊น”๋‚˜๋Š” ์‚ฌ๋žŒ๋“ค ํฌ๋ฃจ ๋ชจ๋‘๋ฅผ ์ €์žฅํ•˜๋Š” crew ๋ผ๋Š” ์ด๋ฆ„์˜ ๊ทธ๋ฃน๊ณผ OpenLDAP Server์— ๊ทธ๋ฃน์„ ์ €์žฅํ•˜๋Š” Groups๋ผ๋Š” ์ด๋ฆ„์˜ ๋‘ ๊ฐœ์˜ ์„œ๋กœ ๋‹ค๋ฅธ ๊ธฐ๋ณธ ๊ทธ๋ฃน์„ ๋งŒ๋“ค์–ด ๋ณด๋„๋ก ํ• ๊ฒŒ์š”.

์ด๋ฅผ ์œ„ํ•ด ์‚ฌ์šฉ์ž ๋ฐ ๊ทธ๋ฃน๋“ฑ์˜ ์ƒˆ๋กœ์šด LDAP Contans๋ฅผ ์ž‘์„ฑํ•˜๊ธฐ ์œ„ํ•ด LDIF File(LDAP Data Interchange Format)๊ณผ LDAP ๋„๊ตฌ์ธ ldapadd๋ฅผ ์ด์šฉํ•ด ์ฃผ๋„๋ก ํ• ๊ฒŒ์š”.

์ตœ์ดˆ ์•„๋ž˜ ๋ช…๋ น์–ด๋ฅผ ์ด์šฉํ•˜์—ฌ LDIF File base-groups.ldif๋ฅผ ๋งŒ๋“ค์–ด์ค„๊ฒŒ์š”.

mkdir /opt/openLDAP_ldif

 

 

vim base-groups.ldif

dn: ou=crew,dc=giggalpeople,dc=com
objectClass: organizationalUnit
ou: crew

dn: ou=Groups,dc=giggalpeople,dc=com
objectClass: organizationalUnit
ou: Groups


์œ„์™€ ๊ฐ™์ด ์ž‘์„ฑํ•˜๊ณ , ldapadd ๋ช…๋ น์–ด๋ฅผ ์ด์šฉํ•˜์—ฌ ์ƒˆ ๊ธฐ๋ณธ ๊ทธ๋ฃน์„ ์‹คํ–‰ํ•ด์ฃผ๋„๋ก ํ• ๊ฒŒ์š”.
OpenLDAP ๊ด€๋ฆฌ์ž ์•”ํ˜ธ๋ฅผ ์ž…๋ ฅํ•˜๋ผ๊ณ  ํ•˜๊ธฐ ๋•Œ๋ฌธ์— ์˜ฌ๋ฐ”๋ฅธ ์•”ํ˜ธ๋ฅผ ์ž…๋ ฅํ•ด ์ฃผ์–ด์•ผ ํ•ด์š”.

ldapadd -x -D cn=admin,dc=giggalpeople,dc=com -W -f base-groups.ldif

 

728x90


์ด์ œ ์•„๋ž˜ ๋ช…๋ น์–ด๋ฅผ ํ†ตํ•˜์—ฌ OpenLDAP Server์˜ ๊ธฐ๋ณธ ๊ทธ๋ฃน์„ ํ™•์ธํ•˜๋„๋ก ํ•ด ๋ณผ๊ฒŒ์š”.
์‚ฌ์šฉ ๊ฐ€๋Šฅํ•œ ๋‘ ๊ฐœ์˜ ๊ธฐ๋ณธ ๊ทธ๋ฃน, ์ฆ‰ crew์™€ Groups๊ฐ€ ํ‘œ์‹œ ๋˜์—ˆ์–ด์š”.


ldapsearch -Q -LLL -Y EXTERNAL -H ldapi:///


์ด๋ฒˆ์—๋Š” ์ƒˆ ๊ทธ๋ฃน์„ ์ถ”๊ฐ€ํ•ด๋ณด๋„๋ก ํ• ๊ฒŒ์š”.

LDAP Server์— ๊ธฐ๋ณธ ๊ทธ๋ฃน์„ ์ƒ์„ฑํ•œ ๋’ค ์ƒˆ LDAP ๊ทธ๋ฃน ๋ฐ ์‚ฌ์šฉ์ž๋ฅผ ๋งŒ๋“ค ์ˆ˜ ์žˆ์–ด์š”.

์ด๋ฒˆ์—๋Š” LDIF File์„ ์ด์šฉํ•˜์—ฌ ์ƒˆ ๊ทธ๋ฃน์„ ๋งŒ๋“ค์–ด ๋ณด๋„๋ก ํ• ๊ฒŒ์š”.

์•„๋ž˜ ๋ช…๋ น์–ด๋ฅผ ํ†ตํ•ด ์ƒˆ๋กœ์šด LDIF File group.ldif๋ฅผ ๋งŒ๋“ค์–ด ์ค„๊ฒŒ์š”.



vim group.ldif

 

dn: cn=DevOpsSec,ou=crew,dc=giggalpeople,dc=com
objectClass: posixGroup
cn: DevOpsSec
gidNumber: 5000

 


์œ„์˜ ๊ตฌ์„ฑ File์„ ๋งŒ๋“ค์–ด์ค„๊ฑฐ์—์š”.
์—ฌ๊ธฐ์„œ๋Š” DevOpsSec์ด๋ผ๋Š” ์ด๋ฆ„์˜ ์ƒˆ ๊ทธ๋ฃน์„ ์ƒ์„ฑํ•˜์—ฌ ๊ธฐ๋ณธ ๊ทธ๋ฃน Groups์— ์ €์žฅํ•˜๊ณ ,
gidNumber๋ฅผ 5000์œผ๋กœ ์ •์˜ํ•ด ์ฃผ๋„๋ก ํ•˜์˜€์–ด์š”.


ldapsearch -x -LLL -b dc=giggalpeople,dc=com '(cn=DevOpsSec)' gidNumber






 

 

        ๐Ÿ“ฆ ์‚ฌ์šฉ์ž ์ถ”๊ฐ€

OpenLDAP Server์— ๊ทธ๋ฃน์„ ๋งŒ๋“ค๊ฒŒ ๋˜๋ฉด LDIF File์„ ํ†ตํ•ด LDAP ์‚ฌ์šฉ์ž๋ฅผ ๋งŒ๋“ค์–ด ์ค„ ์ˆ˜ ์žˆ์–ด์š”.

 ์ƒˆ ์‚ฌ์šฉ์ž๋ฅผ ์ž‘์„ฑํ•˜๊ธฐ ์ „์— ์•„๋ž˜ ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰ํ•˜์—ฌ ์ƒˆ LDAP ์‚ฌ์šฉ์ž์˜ ์•”ํ˜ธํ™”๋œ ์•”ํ˜ธ๋ฅผ ๋งŒ๋“ค์–ด ์ฃผ์–ด์•ผ ํ•ด์š”.
์ƒˆ ์•”ํ˜ธ๋ฅผ ์ž…๋ ฅํ•˜๊ณ , ๋ฐ˜๋ณตํ•œ ๋‹ค์Œ ๋‹ดํ˜ธํ™”๋œ ์•”ํ˜ธ๋ฅผ ์–ป์„ ์ˆ˜ ์žˆ์–ด์š”.

slappasswd


์•”ํ˜ธํ™”๋œ ๊ฐ’์€ ์ž˜ ๊ธฐ๋กํ•ด ์ฃผ์…”์•ผ ํ•ด์š”.


vim user.ldif

 

dn: uid=testuser,ou=crew,dc=giggalpeople,dc=com
objectClass: inetOrgPerson
objectClass: posixAccount
objectClass: shadowAccount
uid: testuser
sn: test
givenName: user
cn: testuser
displayName: OpenLDAP_Test_User
uidNumber: 10000
gidNumber: 5000
userPassword: {SSHA}uU+7XJzExwx0uQCjuAU2L/BwFsxt4oxw
gecos: testuser
loginShell: /bin/bash
homeDirectory: /home/testuser




์œ„์™€ ๊ฐ™์ด ์‚ฌ์šฉ์ž ์ •๋ณด๋ฅผ ์ž…๋ ฅํ•ด ์ฃผ์—ˆ์–ด์š”.


ldapadd -x -D cn=admin,dc=giggalpeople,dc=com -W -f user.ldif


๊ทธ๋Ÿฐ ๋’ค ์œ„์˜ ๋ช…๋ น์–ด๋ฅผ ์ž…๋ ฅํ•˜์—ฌ ์ƒˆ LDAP ์‚ฌ์šฉ์ž๋ฅผ ํ™•์ธํ•˜์—ฌ ์ฃผ์—ˆ์–ด์š”.


ldapsearch -x -LLL -b dc=giggalpeople,dc=com '(uid=testuser)' cn uidNumber gidNumber


OpenLDAP์—๋Š”testuser์ด๋ผ๋Š” ๊ณ„์ •์ด ์ƒ์„ฑ ๋˜์—ˆ์–ด์š”.


์ด๊ฒƒ์œผ๋กœ ๊ธฐ๋ณธ์ ์ธ OpenLDAP ์„ค์น˜ ๋ฐ ๊ตฌ์„ฑ์„ ์™„๋ฃŒ ํ•˜์˜€์–ด์š”.


 

 

 

        ๐Ÿ“ฆ LDAP Account Manager ์„ค์น˜

์ด๋ฒˆ์—๋Š” WEB์„ ํ†ตํ•ด LDAP์„ ๊ด€๋ฆฌํ•  ์ˆ˜ ์žˆ๋Š” LDAP ๊ณ„์ • ๊ด€๋ฆฌ์ž๋ฅผ ์„ค์น˜ํ•ด๋ณด๋„๋ก ํ• ๊ฒŒ์š”.
LDAP Account Manager(LAM; LDAP ๊ณ„์ • ๊ด€๋ฆฌ์ž)๋Š” OpenLDAP Server์˜ Front End๋กœ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋Š” WEB Applicaion Program ์ด์—์š”. ๋ธŒ๋ผ์šฐ์ €๋ฅผ ํ†ตํ•ด OpenLDAP Server๋ฅผ ๊ด€๋ฆฌํ•˜๊ณ , WEB ๋ธŒ๋ผ์šฐ์ €์—์„œ ์ƒˆ ์‚ฌ์šฉ์ž, ๊ทธ๋ฃน๋“ฑ์„ ์„ค์ •ํ•  ์ˆ˜ ์žˆ๋„๋ก ๊ตฌ์„ฑํ•ด ๋ณผ๊ฒŒ์š”.

LAM์€ Ubuntu ์ €์žฅ์†Œ์—์„œ ๊ธฐ๋ณธ์ ์œผ๋กœ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์–ด์š”.
์•„๋ž˜ apt ๋ช…๋ น์–ด๋ฅผ ํ†ตํ•ด ์„ค์น˜ํ•  ๊ฒƒ์ธ๋ฐ, ๊ทธ๋ ‡๊ฒŒ ํ•˜๋ฉด PHP ๋ฐ Apache2 WEB Server๋ฅผ ํฌํ•จํ•œ ๋‹ค๋ฅธ Package๊ฐ€ ์„ค์น˜๋  ๊ฑฐ์—์š”.

apt-get install -y ldap-account-manager




์ฃผ๋‹ˆํ•˜๋ž‘์€ ํ•ด๋‹น Docker Container๋ฅผ ๋งŒ๋“ค ๋•Œ, Port Mapping์„ ํ•ด์ฃผ์ง€ ์•Š์•˜๊ธฐ ๋•Œ๋ฌธ์— ์ง€๊ธˆ์€ WEB์„ ํ†ตํ•ด ์ ‘์†ํ•  ์ˆ˜ ์—†์–ด์š”.

๊ทธ๋ž˜์„œ ์•„๋ž˜์™€ ๊ฐ™์ด ์ž‘์—…์„ ํ•ด ์ฃผ์—ˆ์–ด์š”.


์ตœ์ดˆ ๊ธฐ์กด์— ๊ธฐ๋™์ค‘์ธ Docker Container๋ฅผ ์ค‘์ง€ํ•˜๊ณ , ํ•ด๋‹น Container๋ฅผ Docker Image๋กœ ๋งŒ๋“ค์–ด ์ฃผ์—ˆ์–ด์š”.



๊ทธ๋Ÿฐ ๋’ค ์œ„์™€ ๊ฐ™์ด Shell Script๋ฅผ ๋งŒ๋“ค์–ด์„œ Port Mapping์„ ํ•œ ๋ช…๋ น์–ด๋ฅผ ์ฒ˜๋ฆฌํ•  ์ˆ˜ ์žˆ๋„๋ก ํ•˜๊ณ , Docker Container๋ฅผ ๊ธฐ๋™ํ•˜์—ฌ ์ฃผ์—ˆ์–ด์š”.


ํ•ด๋‹น Shell Script๋ฅผ ์ž‘๋™์‹œํ‚ค๋ฉด ๋ฐ”๋กœ ํ•ด๋‹น Container๋กœ ์ ‘์†ํ•  ์ˆ˜ ์žˆ์–ด์š”.



๊ทธ๋Ÿฐ ๋’ค ์œ„์™€ ๊ฐ™์ด slapd์™€ apache2๋ฅผ ์žฌ๊ธฐ๋™ ํ•ด์ฃผ๋„๋ก ํ• ๊ฒŒ์š”.


http://{OpenLDAP Server IP}:{apache2 Port}/lam


์œ„์™€ ๊ฐ™์ด ์›น ๋ธŒ๋ผ์šฐ์ €๋กœ ์ •์ƒ ์ ‘์†ํ•œ๊ฑธ ํ™•์ธํ•  ์ˆ˜ ์žˆ์–ด์š”.


์˜ค๋ฅธ์ชฝ ์œ„์— LAM configuraion์„ ๋ˆŒ๋Ÿฌ์ค„๊ฒŒ์š”.


๊ทธ๋Ÿฐ ๋’ค ์œ„์™€ ๊ฐ™์ด Edit server profiles๋ฅผ ๋ˆŒ๋Ÿฌ์ค„๊ฒŒ์š”.



์ตœ์ดˆ ๋น„๋ฐ€๋ฒˆํ˜ธ๋Š” lam ์ด์—์š”.



์ตœ์ดˆ Time zone์„ ์œ„์™€ ๊ฐ™์ด ๋ณ€๊ฒฝํ•ด ์ฃผ์—ˆ์–ด์š”.


Tools settins์—์„œ OpenLDAP Server ๊ธฐ๋ณธ DN(Distinguished Name)์„ ์ž…๋ ฅํ•ด ์ฃผ์—ˆ์–ด์š”.

๊ทธ๋Ÿฐ ๋’ค security settings์—์„œ Login Method(๋ฐฉ๋ฒ•)์„ ๊ณ ์ • ๋ชฉ๋ก(Fixed list)๋กœ ์„ ํƒํ•˜๊ณ , OpenLDAP Server ์ƒ์„ธ Login ์ •๋ณด๋ฅผ ์ž…๋ ฅํ•ด ์ฃผ์—ˆ์–ด์š”. ์ฆ‰, OpenLDAP ๊ธฐ๋ณธ ์‚ฌ์šฉ์ž๋Š” admin์ด๊ธฐ ๋•Œ๋ฌธ์— ์œ„์™€ ๊ฐ™์ด ์ž…๋ ฅํ•ด ์ฃผ์—ˆ์Šต๋‹ˆ๋‹ค.

๋งˆ์ง€๋ง‰์œผ๋กœ Profile password์—๋Š” ์ƒˆ ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ์ž…๋ ฅํ•ด ์ฃผ์—ˆ์–ด์š”.
์ด ๋น„๋ฐ€๋ฒˆํ˜ธ๊ฐ€ ์•„๊นŒ lam์„ ์ž…๋ ฅํ•˜๊ณ , ๋“ค์–ด์˜จ ์œ„ ์„œ๋น„์Šค์— ์ƒˆ๋กœ์šด ๋น„๋ฐ€๋ฒˆํ˜ธ๊ฐ€ ๋  ๊ฑฐ์—์š”.

์œ„์™€ ๊ฐ™์ด ์„ค์ •์„ ๋‹คํ–ˆ๋‹ค๋ฉด SAVE๋ฅผ ๋ˆŒ๋Ÿฌ์ค๋‹ˆ๋‹ค.



๊ทธ๋Ÿผ ์œ„์™€ ๊ฐ™์ด LDAP ๊ณ„์ • ๊ด€๋ฆฌ์ž Login Page๋กœ ์ด๋™ํ•˜๊ฒŒ ๋ ๊ฑฐ์—์š”.
LAM configuration์„ ๋‹ค์‹œ ํด๋ฆญํ•˜๊ณ , ๊ธฐ๋ณธ Profile LAM์„ ํŽธ์ง‘ํ•ด ์ค„๊ฒŒ์š”.



์ด๋ฒˆ์—๋Š” Account types๋กœ ์ด๋™ํ•˜์—ฌ OpenLDAP ๊ธฐ๋ณธ ๊ทธ๋ฃน์„ ์„ค์ •ํ•ด ๋ณด๋„๋ก ํ• ๊ฒŒ์š”.

Users ๋ถ€๋ถ„์—๋Š” LDAP ์ ‘๋ฏธ์‚ฌ๋ฅผ ou=crew,dc=giggalpeople,dc=com์œผ๋กœ ์ž…๋ ฅํ•ด ์ฃผ์—ˆ์–ด์š”.
์ด๋Š” OpenLDAP์„ ์„ค์น˜ํ•˜๊ณ , ๊ธฐ๋ณธ ๊ทธ๋ฃน์„ ๋งŒ๋“ค ๋•Œ ์„ค์ •ํ•ด ์ค€ ๋‚ด์šฉ์ด์—์š”.

Groups ๋ถ€๋ถ„์—๋Š” LDAP ์ ‘๋ฏธ์‚ฌ๋ฅผ ou=Groups,dc=giggalpeople,dc=com์œผ๋กœ ์ž…๋ ฅํ•ด ์ฃผ์—ˆ์–ด์š”.
์ด ์˜ˆ์—์„œ๋Š” ๋ชจ๋“  ๊ทธ๋ฃน์„ ๊ธฐ๋ณธ ๊ทธ๋ฃน Groups์—์„œ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์–ด์•ผ ํ•ด์š”.

์œ„์™€ ๊ฐ™์ด ์„ค์ •ํ•œ ๋’ค SAVE ๋ฒ„ํŠผ์„ ๋ˆŒ๋Ÿฌ ๊ธฐ๋ณธ Profile lam ๋ณ€๊ฒฝ ๋‚ด์šฉ์„ ์ €์žฅํ•ด ์ฃผ๋„๋ก ํ• ๊ฒŒ์š”.



๊ทธ๋Ÿผ ๋‹ค์‹œ ์ด ๊ณณ์œผ๋กœ ์ด๋™ํ•˜๊ฒŒ ๋˜๋Š”๋ฐ, User name์ด ์•„๊นŒ์™€๋Š” ๋‹ค๋ฅด๊ฒŒ admin์œผ๋กœ ๋ณ€๊ฒฝ๋œ ๊ฒƒ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ์–ด์š”.
์œ„์—์„œ ์„ค์ •ํ–ˆ๋˜ OpenLDAP ๊ด€๋ฆฌ์ž ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ์ž…๋ ฅํ•ด์„œ Login ํ•ด ์ค„๊ฒŒ์š”.

 


Users Tab์—์„œ OpenLDAP์— ๊ณ„์ •์„ ์ƒ์„ฑํ•˜๋ฉฐ ๋งŒ๋“ค์—ˆ๋˜ ๊ณ„์ •์ด ํ™•์ธ ๋˜์—ˆ์–ด์š”.


์ด์ œ ์ด LAM์„ ์ด์šฉํ•ด์„œ OpenLDAP์„ ๋ณด๋‹ค ํŽธํ•˜๊ฒŒ ์ด์šฉํ•  ์ˆ˜ ์žˆ๊ฒŒ ๋˜์—ˆ์–ด์š”!

 

 

 

 

๐Ÿง ์ฐธ๊ณ  ์ž๋ฃŒ

 

How to Install OpenLDAP on Ubuntu 22.04

OpenLDAP is a software implementation of the Lightweight Directory Access Protocol (LDAP). This guide will teach you how to set up LDAP Server with Op...

www.howtoforge.com

 

 

 

LDAP System Administration Paperback

COUPANG

www.coupang.com

"์ด ํฌ์ŠคํŒ…์€ ์ฟ ํŒก ํŒŒํŠธ๋„ˆ์Šค ํ™œ๋™์˜ ์ผํ™˜์œผ๋กœ, ์ด์— ๋”ฐ๋ฅธ ์ผ์ •์•ก์˜ ์ˆ˜์ˆ˜๋ฃŒ๋ฅผ ์ œ๊ณต๋ฐ›์Šต๋‹ˆ๋‹ค."

 

 

 

 

 

 

 

 

728x90
๋ฐ˜์‘ํ˜•