이 콘텐츠는 선택한 언어로 제공되지 않습니다.
4.2. Configuring autofs
- Edit the
/etc/sysconfig/autofsfile to specify the schema attributes that autofs searches for:# # Other common LDAP naming # MAP_OBJECT_CLASS="automountMap" ENTRY_OBJECT_CLASS="automount" MAP_ATTRIBUTE="automountMapName" ENTRY_ATTRIBUTE="automountKey" VALUE_ATTRIBUTE="automountInformation" - Specify the LDAP configuration. There are two ways to do this. The simplest is to let the automount service discover the LDAP server and locations on its own:
LDAP_URI="ldap:///dc=example,dc=com"Alternatively, explicitly set which LDAP server to use and the base DN for LDAP searches:LDAP_URI="ldap://ipa.example.com" SEARCH_BASE="cn=location,cn=automount,dc=example,dc=com"Note
The default value for location isdefault. If additional locations are added, then the client can be pointed to use those locations, instead. - Edit the
/etc/autofs_ldap_auth.conffile so that autofs allows client authentication with the IPA LDAP server. Changeauthrequiredto yes and set the principal to the Kerberos host principal:<autofs_ldap_sasl_conf usetls="no" tlsrequired="no" authrequired="yes" authtype="GSSAPI" clientprinc="host/server.example.com@EXAMPLE COM" />If necessary, runklist -kto get the exact host principal information. - Check the
/etc/nssswitch.conffile, so that LDAP is listed as a source for automount configuration:automount: files ldap - Restart autofs:
# service autofs restart - Test the configuration by listing a user's
/homedirectory:# ls /home/userNameIf this does not mount the remote file system, check the/var/log/messagesfile for errors. If necessary, increase the debug level in the/etc/sysconfig/autofsfile by setting theLOGGINGparameter todebug.
Note
If there are problems with automount, then cross-reference the automount attempts with the 389 Directory Server access logs for the IPA instance, which will show the attempted access, user, and search base.
It is also simple to run automount in the foreground with debug logging on.
This prints the debug log information directly, without having to cross-check the LDAP access log with automount's log.
automount -f -d