openldap安装kerberos,想实现kerberos使用ldap的数据库,在安装途中遇到错误kdb5_ldap_util: Kerberos Container create FAILED: Invalid syntax while creating realm 'YAOBILI.COM'
背景说明:我ldap创建的管理员账户admin,cn=admin,dc=yaobili,dc=com
kerberos链接ldap全用ladp的管理员账户admin
同时分配ldap_kerberos_container_dn为cn=kerberos,dc=yaobili,dc=com,这个是在输入命令时手动配置,配置文件中暂未写
命令方面创建数据库只能采用:kdb5_ldap_util -D cn=admin,dc=yaobili,dc=com -w 123456 -H ldap://10.110.38.162:389 create -r YAOBILI.COM -s方式
不能采用:kdb5_util create -r YAOBILI.COM -s方式
我的疑惑点:我的域名叫:YAOBILI.COM,我感觉这4个文件改配置的我都配置了,但是报错:Invalid syntax while creating realm 'YAOBILI.COM'
我没懂这个报错指我配置文件语法有问题?或者少了标签?或者顺序不对?还是哪方面的问题
[root@localhost ~]# kdb5_ldap_util -D cn=admin,dc=yaobili,dc=com -w 123456 -H ldap://10.110.38.162:389 create -r YAOBILI.COM -s
Initializing database for realm 'YAOBILI.COM'
You will be prompted for the database Master Password.
It is important that you NOT FORGET this password.
Enter KDC database master key:
Re-enter KDC database master key to verify:
Enter DN of Kerberos container: ou=kerberos,dc=yaobili,dc=com
kdb5_ldap_util: Kerberos Container create FAILED: Invalid syntax while creating realm 'YAOBILI.COM'
我的配置文件如下:
krb5.conf
[logging]
default = FILE:/var/log/krb5libs.log
kdc = FILE:/var/log/krb5kdc.log
admin_server = FILE:/var/log/kadmind.log
[libdefaults]
default_realm = YAOBILI.COM
dns_lookup_realm = false
dns_lookup_kdc = false
ticket_lifetime = 24h
renew_lifetime = 7d
forwardable = true
rdns = false
# default_ccache_name = KEYRING:persistent:%{uid}
[realms]
YAOBILI.COM = {
kdc = 10.110.38.162:88
admin_server = 10.110.38.162:749
default_domain = YAOBILI.COM
}
[domain_realm]
.yaobili.com = YAOBILI.COM
yaobili.com = YAOBILI.COM
krb5.ldap
cn=admin,dc=yaobili,dc=com#{HEX}313233343536
kdc.conf
[kdcdefaults]
kdc_ports = 88
kdc_tcp_ports = 88
[realms]
YAOBILI.COM = {
#master_key_type = aes256-cts
acl_file = /var/kerberos/krb5kdc/kadm5.acl
dict_file = /usr/share/dict/words
admin_keytab = /var/kerberos/krb5kdc/kadm5.keytab
supported_enctypes = aes256-cts:normal aes128-cts:normal des3-hmac-sha1:normal arcfour-hmac:normal camellia256-cts:normal camellia128-cts:normal des-hmac-sha1:normal des-cbc-md5:normal des-cbc-crc:normal
}
kadm5.acl
*/admin@YAOBILI.COM *