How to Install OpenLDAP Server on AlmaLinux 9

Estimated reading: 5 minutes 498 views

OpenLDAP is a powerful and versatile software implementation of the Lightweight Directory Access Protocol (LDAP). It allows for efficient management of user information and authentication within a network. In this comprehensive guide, we will walk you through the step-by-step process of installing OpenLDAP Server on your AlmaLinux 9 machine. By the end of this tutorial, you will have a fully functional OpenLDAP Server up and running, ready to be integrated into your applications.

Prerequisites

Before we dive into the installation process, let’s make sure we have all the necessary prerequisites in place:

  1. An AlmaLinux 9 machine: For this demonstration, we will assume the hostname and IP address of our server.
  2. A non-root user with administrator privileges: Ensure that you have a non-root user account with sudo privileges to carry out the installation and configuration steps.

Setting Up FQDN

Before installing the OpenLDAP server, it is essential to configure the Fully Qualified Domain Name (FQDN) and ensure it points to the correct IP address. Follow these steps to set up the FQDN on your AlmaLinux machine:

  1. Set up the FQDN of your AlmaLinux machine by running the following command:
hostnamectl set-hostname ldapgreencloud.example.net
echo "nameserver 8.8.8.8" | sudo tee -a /etc/resolv.conf
  1. Open the /etc/hosts file with the nano editor using the following command:
nano /etc/hosts
  1. Insert the following configuration into the file, making sure to replace the IP address, FQDN, and hostname with your own values:
Your_IP ldapgreencloud.example.net
  1. Save the file and exit the editor.
  2. To verify that the FQDN is correctly set up and pointing to the proper IP address, run the following commands:
hostname -f
ping -c3 ldapgreencloud.example.net

If successful, you should see the FQDN ldapgreencloud.example.net associated with the IP address.

Installing OpenLDAP Server

To install the OpenLDAP server on your AlmaLinux machine, follow these steps:

  1. Add the EPEL repository to your AlmaLinux server by running the following command:
dnf install epel-release -y

  1. Install the OpenLDAP server and client packages by running the following command:
dnf install openldap-servers openldap-clients
  1. When prompted, type y To confirm the installation, press ENTER.
  2. When asked to add the GPG key of the EPEL repository, type y and press ENTER.
  3. Start and enable the OpenLDAP service by running the following commands:
systemctl start slapd
systemctl enable slapd
  1. Verify that the slapd service is running by executing the following command:
systemctl status slapd

If running, you should see an output indicating that the service is active (running).

  1. Open both the LDAP and LDAPS services on firewalld to allow client connections. Run the following firewall-cmd commands, and then reload firewalld to apply the changes:
firewall-cmd --add-service={ldap,ldaps} --permanent
firewall-cmd --reload
  1. Verify the list of firewalld rules by running the following command:
firewall-cmd --list-all

If successful, you should see both LDAP and LDAPS services listed.

Congratulations! You have successfully installed the OpenLDAP server on your AlmaLinux machine. In the next section, we will guide you through the basic configuration steps for your OpenLDAP server.

Basic OpenLDAP Server Configuration

After installing the OpenLDAP server, it is crucial to configure it properly. In this section, we will cover the initial configuration steps, including setting up the domain name and base domain, creating an administrator user, and importing basic schemas.

Setting Up Domain and Base Domain

To set up the domain name and base domain on your OpenLDAP server, follow these steps:

1: Generate LDAP Administrator Password

Create a hashed password for the LDAP administrator:

slappasswd
Enter your desired password and copy the generated {SSHA} hash.

2: Configure the LDAP Database

Create a configuration file:

nano setroot.ldif
Add the following configuration (replace the password hash):
dn: olcDatabase={2}mdb,cn=config
changetype: modify
replace: olcSuffix
olcSuffix: dc=example,dc=net

dn: olcDatabase={2}mdb,cn=config
changetype: modify
replace: olcRootDN
olcRootDN: cn=Manager,dc=example,dc=net

dn: olcDatabase={2}mdb,cn=config
changetype: modify
replace: olcRootPW
olcRootPW: {SSHA}PASTE_YOUR_HASH_HERE
Apply the configuration:
ldapmodify -Y EXTERNAL -H ldapi:/// -f setroot.ldif

3: Create the Base Domain Structure

Create a file named:

nano basedomain.ldif
Add:
dn: dc=izviet,dc=net
objectClass: top
objectClass: dcObject
objectClass: organization
o: Izviet Network
dc: izviet

dn: ou=People,dc=izviet,dc=net
objectClass: organizationalUnit
ou: People

dn: ou=Groups,dc=izviet,dc=net
objectClass: organizationalUnit
ou: Groups
Add the base structure to LDAP:
ldapadd -x -D "cn=Manager,dc=izviet,dc=net" -W -f basedomain.ldif

4: Verify LDAP Configuration

Test administrator authentication:

ldapwhoami -x -D "cn=Manager,dc=izviet,dc=net" -W
You should see:
dn:cn=Manager,dc=izviet,dc=net
Test directory search:
ldapsearch -x -b dc=izviet,dc=net

Conclusion

Congratulations! You have successfully installed and configured the OpenLDAP server on your AlmaLinux 9 machine. You are now ready to leverage its powerful features for efficient user management and authentication within your network. For further security and scalability, consider setting up SSL/TLS for your OpenLDAP server and exploring web-based frontends such as php OpenLDAP. GreenCloud offers reliable and secure cloud hosting solutions, including Linux SSD VPS, to empower your business with efficient and scalable infrastructure. Happy LDAP-ing!

Share this Doc

How to Install OpenLDAP Server on AlmaLinux 9

Or copy link

CONTENTS