2.4.2. 루트가 아닌 사용자로 새 인스턴스 설치
루트 권한 없이 Directory Server를 설치하려면 대화형 설치 프로그램을 사용할 수 있습니다. 설치 후 Directory Server는 사용자 지정 위치에 인스턴스를 생성하고 사용자가 정상적으로dsctl, 유틸리티를 실행할 수 있습니다.
ds conf
사전 요구 사항
- 루트가 아닌 설치를 위한 환경을 준비하셨습니다.
-
firewall-cmd유틸리티를 사용할 수 있는sudo권한이 있는 경우 외부에서 Directory Server 인스턴스를 사용할 수 있도록 해야 합니다.
절차
대화식 설치 프로그램을 사용하여 인스턴스 생성
대화형 설치 프로그램을 시작합니다.
$ dscreate interactive대화형 설치 프로그램의 질문에 대답합니다.
설치 프로그램에서 대부분의 질문 뒤에 대괄호로 표시된 기본값을 사용하려면 값을 입력하지 않고 Enter 를 누릅니다.
참고설치하는 동안 인스턴스 포트 및 보안 포트 번호 1024(예: 1389 및 1636)를 선택해야 합니다. 그렇지 않으면 사용자에게 권한 있는 포트(1-1023)에 바인딩할 수 있는 권한이 없습니다.
Install Directory Server (interactive mode) =========================================== Non privileged user cannot use semanage, will not relabel ports or files. Selinux support will be disabled, continue? [yes]: yes Enter system's hostname [server.example.com]: Enter the instance name [server]: instance_name Enter port number [389]: 1389 Create self-signed certificate database [yes]: Enter secure port number [636]: 1636 Enter Directory Manager DN [cn=Directory Manager]: Enter the Directory Manager password: password Confirm the Directory Manager Password: password Choose whether mdb or bdb is used. [bdb]:참고기본적으로 Directory Server는 Berkeley Database(BDB)를 사용하여 인스턴스를 생성합니다. Directory Server 12.5로 시작하는 기술 프리뷰인 LMDB 인스턴스를 설치하려면
mdb를 설정하고 다음 단계에서 LMDB 데이터베이스 크기를 바이트 단위로 설정합니다.Enter the database suffix (or enter "none" to skip) [dc=server,dc=example,dc=com]: dc=example,dc=com Create sample entries in the suffix [no]: Create just the top suffix entry [no]: yes Do you want to start the instance after the installation? [yes]: Are you ready to install? [no]: yes참고일반 텍스트로 암호를 설정하는 대신
pwdhash유틸리티로 생성된 {algorithm} 해시문자열을 설정할 수 있습니다. 예를 들면 다음과 같습니다.Enter the Directory Manager password: {PBKDF2-SHA512}100000$Haw7UDcBKUBejEjOTVHbiefT6cokHLo2$PeoP7W3B92Jzby7DGRkicovTN4LDGhnsC4EWCsv6crA2KA0Xn6rxPePX9UXhlM2utOPSQHeVpZzscNTx+fGi7A==
선택 사항: 외부에서 Directory Server 인스턴스를 사용할 수 있도록 하려면 다음을 수행합니다.
방화벽에서 포트를 엽니다.
# sudo firewall-cmd --permanent --add-port={1389/tcp,1636/tcp}방화벽 구성을 다시 로드합니다.
# sudo firewall-cmd --reload
검증
ldapsearch명령을 실행하여 사용자가 인스턴스에 연결할 수 있는지 테스트합니다.$ ldapsearch -D "cn=Directory Manager" -W -H ldap://server.example.com:1389 -b "dc=example,dc=com" -s sub -x "(objectclass=*)"