From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Date: Mon, 18 Apr 2005 11:05:36 +0400 From: Anton Gorlov aka stalker X-Mailer: The Bat! (v3.0.1.33) Professional X-Priority: 3 (Normal) Message-ID: <505159012.20050418110536@mail.ru> To: ALT Linux Sisyphus discussion list Subject: Re: [sisyphus] Re: SSH +ldap In-Reply-To: <20050418062929.GE11819@osdn.org.ua> References: <1802698194.20050416154823@mail.ru> <20050417151353.GN6352@osdn.org.ua> <162974050.20050417200546@mail.ru> <4262B323.9010801@inbox.ru> <157469756.20050417233934@mail.ru> <20050418062929.GE11819@osdn.org.ua> MIME-Version: 1.0 Content-Type: text/plain; charset=koi8-r Content-Transfer-Encoding: quoted-printable X-BeenThere: sisyphus@altlinux.ru X-Mailman-Version: 2.1.5 Precedence: list Reply-To: Anton Gorlov aka stalker , ALT Linux Sisyphus discussion list List-Id: ALT Linux Sisyphus discussion list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 18 Apr 2005 07:07:14 -0000 Archived-At: List-Archive: =FA=C4=D2=C1=D7=D3=D4=D7=D5=CA=D4=C5, Michael. =F7=D9 =D0=C9=D3=C1=CC=C9 18 =C1=D0=D2=C5=CC=D1 2005 =C7., 10:29:29: > On Sun, Apr 17, 2005 at 11:39:34PM +0400, Gor_lov aka Stalker wrote: >> > =DA=D2=D1 =D7=D9 =C2=CF=C9=D4=C5=D3=D8, ldap over tls =D2=C1=C2=CF=D4= =C1=C5=D4 =D0=CF=DE=D4=C9 =D7=C5=DA=C4=C5... >> =EB=D3=D4=C1=D4=C9 -=C1 =DE=C5=CD =C7=C5=CE=C5=D2=C9=D4=D8 =D3=C5=D2=D4= =C5=C6=C9=CB=C1=D4? > openssl -- =CB=C1=D6=C5=D4=D3=D1, =D7 =C4=CF=CB=D5=CD=C5=CE=D4=C1=C3=C9= =C9 Master 2.4 (=D3=CD. docs/ =D7 =C5=C7=CF > =CB=CF=D2=CE=C5 =CE=C1 ftp) =D0=D2=C9=D7=CF=C4=C9=CC=D3=D1 =D0=D2=C9=CD= =C5=D2, =FA=C4=C5=D3=D8 =DE=D4=CF-=D4=CF =CE=C9=DE=C5=C7=CF =C9=CE=D4=C5=D2=C5=D3= =CE=CF=C7=CF =CE=C5 =D5=D7=C9=C4=C5=CC :-( > =C4=C1 =C9 =CE=C1 opennet.ru =C9=C8 =C2=D9=CC=CF. =FA=C4=C5=D3=D8 =D5=D6=C5 =D5=D7=C9=C4=C5=CC =DE=D4=CF-=D4=CF =D0=CF=C8=CF= =D6=C5=C5 =CE=C1 =D0=D2=C1=D7=C4=D5 (Samba-full-LDAP-integration-HOWTO.html). =EE=CF =DE=D4=CF-=D4=CF =CE=C5 = =D0=CF=CE=D1=D4=CE=CF, =CB=C1=CB =D3=CB=C1=D6=C5=CD =D3=CB=D7=C9=C4=D5 (=D4=CF=DE=CE=C5=C5 squid_ldap_auth = =C9 squid_ldap_group) =D3=CB=CF=D2=CD=C9=D4=D8 =CB=CC=C9=C5=CE=D4=D3=CB=C9=CA =CB=CC=C0=DE... =F7= =CF=D0=C3=C9=D1=C8 =DC=D4=C9=C8 =CD=CF=C4=D5=CC=C5=CA =CE=C9=DE=C5=C7=CF = =D0=D2=CF =CB=CC=C0=DE =CE=C5 =CE=C1=DB=A3=CC, =D4=CF=CC=D8=CB=CF "-Z TLS encrypt the LDAP connection" - =E6=C1=CA=CC=D9 =CE=C5=CF=C2=C8=CF=C4=C9=CD=D9=C5 =C4=CC=D1 =C7=C5=CE=C5= =D2=C1=C3=C9=C9 =D3=C5=D2=D4=C9=C6=C9=CB=C1=D4=CF=D7 =C9 =CB=CC=C0=DE=C5=CA. ldap.cnf [ req ] default_bits =3D 1024 encrypt_key =3D yes distinguished_name =3D req_dn x509_extensions =3D cert_type prompt =3D no [ req_dn ] C=3DRU ST=3DRussia L=3DLinux O=3DLinux LDAP OU=3DLDAP SSL Key CN=3Dldap.ru emailAddress=3Dadmin@ldap.ru [ cert_type ] nsCertType =3D client slapd.cnf req ] default_bits =3D 1024 encrypt_key =3D yes distinguished_name =3D req_dn x509_extensions =3D cert_type prompt =3D no [ req_dn ] C=3DRU ST=3DRussia L=3DLinux O=3DLinux LDAP OU=3DLDAP SSL Key CN=3Dldap.ru emailAddress=3Dadmin@ldap.ru [ cert_type ] nsCertType =3D server =F0=CF=D3=CC=C5 =D3=CF=DA=C4=C1=CE=C9=D1 =DC=D4=C9=C8 =C6=C1=CA=CC=CF=D7 = =D3=CF=DA=C4=C1=CA=D4=C5 =C9=D3=D0=CF=CC=CE=D1=C5=CD=D9=CA =C6=C1=CA=CC mkldapcert #!/bin/sh /usr/bin/openssl req -new -x509 -days 365 -nodes -config ldap.cnf -out ldap.pem -keyout ldap.pem /usr/bin/openssl req -new -x509 -days 365 -nodes -config slapd.cnf -out slapd.pem -keyout slapd.pem --=20 =F3 =D5=D7=C1=D6=C5=CE=C9=C5=CD, Anton mailto:pnz37@mail.ru