06-06-2013 11:17 PM
Need to configure ldap client in HPUX 11.31 without adding to domain.
I dont want every user registered in AD,able to access the client.
Plan is to manually create AD userid in client,but password should take from AD.So that only these users has access to ldap client.
LDAP server is windows.
I have executed /opt/ldapux/config/autosetup script,but its asking to add to domain.
Current version of LDAP is B.05.01.
06-09-2013 12:19 AM
Please see the limitations you may have while configuring HPUX Ldapclient with Microsoft AD
You can limit the AD accounts to login to UNIX servers by adding "ABORT_LOGIN_ON_MISSING_HOMEDIR=1" in /etc/default/security and manually creating home directories for only needed accounts.
Also you can use "disable_uid_range=xxxx" to disable some accounts to be logged in HPUX servers by configuring ldapux_client.conf.
06-10-2013 01:47 AM - edited 06-10-2013 01:52 AM
Thanks for the response.
The links you provided was not veru clear to me on connecting to ldap server without adding to domain.
"ABORT_LOGIN_ON_MISSING_HOMEDIR=1" in /etc/default/security >>> If we creating manual home folder in client,but real home folder exists in AD server.Thus which home folder, system may use to ogin.