include
/etc/openldap/schema/corba
.schema
include
/etc/openldap/schema/core
.schema
include
/etc/openldap/schema/cosine
.schema
include
/etc/openldap/schema/duaconf
.schema
include
/etc/openldap/schema/dyngroup
.schema
include
/etc/openldap/schema/inetorgperson
.schema
include
/etc/openldap/schema/java
.schema
include
/etc/openldap/schema/misc
.schema
include
/etc/openldap/schema/nis
.schema
include
/etc/openldap/schema/openldap
.schema
include
/etc/openldap/schema/ppolicy
.schema
include
/etc/openldap/schema/collective
.schema
allow bind_v2
pidfile
/var/run/openldap/slapd
.pid
argsfile
/var/run/openldap/slapd
.args
loglevel -1
modulepath
/usr/lib64/openldap
moduleload memberof.la
TLSCACertificatePath
/etc/openldap/certs
TLSCertificateFile
/etc/pki/tls/certs/slapd
.pem
TLSCertificateKeyFile
/etc/pki/tls/certs/slapd
.pem
database config
rootdn
"cn=admin,cn=config"
rootpw {SSHA}xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
access to *
by dn.exact=
"gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth"
manage
by * none
database monitor
access to *
by dn.exact=
"gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth"
read
by dn.exact=
"cn=Manager,dc=my-domain,dc=com"
read
by * none
database bdb
suffix
"dc=my-domain,dc=com"
rootdn
"cn=Manager,dc=my-domain,dc=com"
rootpw {SSHA}xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
access to dn.subtree=
"dc=my-domain,dc=com"
by self write
by
set
=
"[cn=Administrators,ou=groups,dc=my-domain,dc=com]/member* & user"
write
by
set
=
"[cn=Operators,ou=groups,dc=my-domain,dc=com]/member* & user"
read
by *
break
access to attrs=userPassword
by anonymous auth
by self =rwdx
by
set
=
"user & [cn=Administrators,ou=groups,dc=my-domain,dc=com]/member*"
manage
by dn.children=
"ou=Special Accounts,dc=my-domain,dc=com"
auth
directory
/var/lib/ldap
index objectClass
eq
,pres
index ou,cn,mail,surname,givenname
eq
,pres,sub
index uidNumber,gidNumber,loginShell
eq
,pres
index uid,memberUid
eq
,pres,sub
index nisMapName,nisMapEntry
eq
,pres,sub
overlay memberof
cachesize 10000
checkpoint 1024 15