LDAP at U of C

(2009-09-15 Mike Morrow)

Introduction

Reason for LDAP

This Document (http://www.ucalgary.ca/~morrow/ldap/index.html)

What the public can know

How to build an LDAP server

Sharepoint files

Current Configuration

Host machines
Domain nameIP numberFunction
ldapsrv11.acs.ucalgary.ca136.159.86.98Master
ldapsrv12.acs.ucalgary.ca136.159.86.98Slave
ldapsrv13.acs.ucalgary.ca136.159.86.98Slave
ldapsrv14.acs.ucalgary.ca136.159.86.98Failover, High Availability
Aliases

NameAliased toIPHostFailover
Implemented
LDAP user
master.ldap.ucalgary.ca 136.159.34.172ldapsrv11  
public.ldap.ucalgary.ca 136.159.34.176  seek,
virtual.ldap.ucalgary.ca 136.159.230.60   
failover.ldap.ucalgary.caslave-f   failover, high availability
slave-a.ldap.ucalgary.ca 136.159.34.173ldapsrv11  
slave-e.ldap.ucalgary.ca 136.159.34.230ldapsrv12  
slave-g.ldap.ucalgary.ca 136.159.34.12ldapsrv13  
slave-f.ldap.ucalgary.ca 136.159.34.231ldapsrv14  
public-test.ldap.ucalgary.ca 136.159.34.84   
lcpam.ldap.ucalgary.caslave-e    
smtp.ldap.ucalgary.caslave-e    
dcs.ldap.ucalgary.caslave-e    
pgina.ldap.ucalgary.caslave-e    
uidauthent.ldap.ucalgary.caslave-e    
perdition.ldap.ucalgary.caslave-e    
ssl.ldap.ucalgary.caslave-e    
misc.ldap.ucalgary.caslave-e   access to master
webdisk.ldap.ucalgary.caslave-e  *Webdisk mod_authldap
blackboard.ldap.ucalgary.caslave-e  *Blackboard
ucaccess.ldap.ucalgary.caslave-e    
mail.ldap.ucalgary.caslave-g    
imap.ldap.ucalgary.caslave-g   IMAP pam
iproxy.ldap.ucalgary.caslave-g    
engg.ldap.ucalgary.caslave-d   Engineering (Sebastian Maurice)

How LDAP works

slapd -- LDAP daemon, answers requests from LDAP clients

slurpd -- replication daemon, replicates changes on master.ldap.ucalgary.ca to slaves.

Important directories

Asynchronous updates

Active Directory Updates

PCI commands

Support scripts

Located in /home/ldap/bin

Daily maintenance -- runs at 0315 every morning

/home/ldap/bin/dailymaint (test|master)
Functions

Data sources (feed files)