Solved

How to Create OpenLDAP schema

Posted on 2012-03-28
3
900 Views
Last Modified: 2012-03-31
I have configured the openldap (2.4.23) server in centos 6 and running successfully. I want to store secret question and answer in ldap for all user, by using this user can able to reset their password by answering the secret question.  For this i need to create a custom schema. i don't know how to create a own schema for this. Please help.
0
Comment
Question by:rajasekarramasamy
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 31

Expert Comment

by:farzanj
ID: 37776707
It depends upon your current set up.  Is the current schema accessible by the users?  Can they query the LDAP and see at least the hashes of their passwords?  Basically, your questions and answers should be hidden just like the password hashes.

There is no complicated schema.  Just add
secret question:
secret answer:

Just like the password field.
0
 

Author Comment

by:rajasekarramasamy
ID: 37777787
Can they query the LDAP and see at least the hashes of their passwords?

Yes.

Having any sample schema for my requirement?
0
 
LVL 31

Accepted Solution

by:
farzanj earned 500 total points
ID: 37777897
This might be a little help
http://publib.boulder.ibm.com/infocenter/iseries/v5r3/index.jsp?topic=%2Frzahy%2Frzahyunderdn.htm

First you have to see which object class is the password stored in or a member of.  Use your object browser to see that.
http://publib.boulder.ibm.com/infocenter/iseries/v5r3/index.jsp?topic=%2Frzahy%2Frzahyunderdn.htm

In that object class, you need to add two more fields, secretQuestion and secretAnswer.  Since this object class would also be a part of person's LDIF, you will have to make minimal changes.  You will only need to add these attributes.
0

Featured Post

Save the day with this special offer from ATEN!

Save 30% on the CV211 using promo code EXPERTS30 now through April 30th. The ATEN CV211 connects a laptop directly to any server allowing you instant access to perform data maintenance and local operations, for quick troubleshooting, updating, service and repair.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The purpose of this article is to show how we can create Linux Mint virtual machine using Oracle Virtual Box. To install Linux Mint we have to download the ISO file from its website i.e. http://www.linuxmint.com. Once you open the link you will see …
Google Drive is extremely cheap offsite storage, and it's even possible to get extra storage for free for two years.  You can use the free account 15GB, and if you have an Android device..when you install Google Drive for the first time it will give…
Learn how to get help with Linux/Unix bash shell commands. Use help to read help documents for built in bash shell commands.: Use man to interface with the online reference manuals for shell commands.: Use man to search man pages for unknown command…
Connecting to an Amazon Linux EC2 Instance from Windows Using PuTTY.

717 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question