Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revision Previous revision
Next revision
Previous revision
technical:fr-ldap [2026/07/24 10:28] – [Sign the request] systemtechnical:fr-ldap [2026/07/26 18:39] (current) – [Configure OpenLDAP for ldaps] system
Line 349: Line 349:
     * **ldap.crt**  - The LDAP public file     * **ldap.crt**  - The LDAP public file
  
 +  * Everything is now in place in terms of our PKI for us to configure slapd (OpenLDAP) to support ldaps.
  
 +===== Configure OpenLDAP for ldaps =====
 +  * Issue the following commands
 +<code bash>
 +sudo mkdir /etc/ldap/tls
 +#Copy the following files over
 +sudo cp ca.crt ldap.key ldap.crt /etc/ldap/tls
 +#Change their permissions
 +sudo chown openldap:openldap /etc/ldap/tls/*
 +sudo chmod 600 /etc/ldap/tls/ldap.key
 +sudo chmod 644 /etc/ldap/tls/*.crt
 +</code>
 +  * Configure slapd to use those files.
 +  * Create **tls.ldif** with the following contents
 +<code>
 +dn: cn=config
 +changetype: modify
 +replace: olcTLSCertificateFile
 +olcTLSCertificateFile: /etc/ldap/tls/ldap.crt
 +-
 +replace: olcTLSCertificateKeyFile
 +olcTLSCertificateKeyFile: /etc/ldap/tls/ldap.key
 +-
 +replace: olcTLSCACertificateFile
 +olcTLSCACertificateFile: /etc/ldap/tls/ca.crt
 +</code>
 +  * Apply it to the directory with the following commnand:
 +<code>
 +sudo ldapmodify -Y EXTERNAL -H ldapi:/// -f tls.ldif
 +</code>
 +  * Enable LDAPS by editing **/etc/default/slapd**.
 +  * Look for the following section and change accordingly:
 +<code bash>
 +# slapd normally serves ldap only on all TCP-ports 389. slapd can also
 +# service requests on TCP-port 636 (ldaps) and requests via unix
 +# sockets.
 +# Example usage:
 +# SLAPD_SERVICES="ldap://127.0.0.1:389/ ldaps:/// ldapi:///"
 +#SLAPD_SERVICES="ldap:/// ldapi:///"
 +SLAPD_SERVICES="ldap:/// ldapi:/// ldaps:///"
 +</code bash>
 +  * Restart **slapd**.
 +<code>
 +sudo systemctl restart slapd
 +</code>
 +  * Confirm that it is now listening on port 636 also:
 +<code bash>
 +sudo ss -lnpt | grep 636
 +LISTEN 0      2048         0.0.0.0:636        0.0.0.0:   users:(("slapd",pid=698775,fd=11))                       
 +LISTEN 0      2048            [::]:636           [::]:   users:(("slapd",pid=698775,fd=12))      
 +</code>
 +  * To make the cert's FQDN work smooth add it to the /etc/hosts file (ldap.radiusdesk.com in our case).
 +<code>
 +127.0.0.1 localhost
 +127.0.1.1 xubuntu-24-4
 +127.0.0.1 ldap.radiusdesk.com
 +
 +# The following lines are desirable for IPv6 capable hosts
 +::1     ip6-localhost ip6-loopback
 +fe00::0 ip6-localnet
 +ff00::0 ip6-mcastprefix
 +ff02::1 ip6-allnodes
 +ff02::2 ip6-allrouters
 +</code>
 +  * Test the certificate with the following command:
 +<code>
 +openssl s_client -connect ldap.radiusdesk.com:636 -CAfile ca.crt
 +
 +#IT should end with something like this:
 +---
 +SSL handshake has read 3905 bytes and written 401 bytes
 +Verification: OK
 +---
 +New, TLSv1.3, Cipher is TLS_AES_256_GCM_SHA384
 +Server public key is 4096 bit
 +Secure Renegotiation IS NOT supported
 +Compression: NONE
 +Expansion: NONE
 +No ALPN negotiated
 +Early data was not sent
 +Verify return code: 0 (ok)
 +
 +</code>
 +  * You can now test with the ldapsearch utility. 
 +<WRAP center round important>
 +Important is to specify the CA cert (LDAPTLS_CACERT) that ldapsearch needs to use else if **will fail**.
 +</WRAP>
 +
 +<code>
 +LDAPTLS_CACERT=/etc/ldap/tls/ca.crt ldapsearch -H ldaps://ldap.radiusdesk.com -x -D "cn=admin,dc=radiusdesk,dc=com" -w testing123 -b dc=radiusdesk,dc=com
 +</code>
 +<WRAP center round tip>
 +  * If you want this CA to be part of the list of trusted CA's on the system you can do the following:
 +<code bash>
 +sudo cp /etc/ldap/tls/ca.crt /usr/local/share/ca-certificates/radiusdesk-ca.crt
 +sudo update-ca-certificates
 +#This is the output on our system
 +Updating certificates in /etc/ssl/certs...
 +rehash: warning: skipping ca-certificates.crt,it does not contain exactly one certificate or CRL
 +1 added, 0 removed; done.
 +Running hooks in /etc/ca-certificates/update.d...
 +Processing triggers for ca-certificates-java (20240118) ...
 +Adding debian:radiusdesk-ca.pem
 +done.
 +done.
 +#Now we can just use plain ldapsearch
 +ldapsearch -H ldaps://ldap.radiusdesk.com -x -D "cn=admin,dc=radiusdesk,dc=com" -w testing123 -b dc=radiusdesk,dc=com
 +</code>
 +</WRAP>
 +==== What does update-ca-certificates do? ====
 +I like to know how things work. If you also like to know how things work the following insert is for you :-)
 +  * The primary master CA file that is updated and can be used on Ubuntu is  **/etc/ssl/certs/ca-certificates.crt**
 +  * This command rebuilds the system's trusted certificate store by consolidating certificates from a few key locations:
 +    * **System Certificates:** The command reads the configuration file **/etc/ca-certificates.conf** to determine which certificates from **/usr/share/ca-certificates/** should be trusted.
 +    * **Local Certificates:** It automatically trusts all .crt files found in /usr/local/share/ca-certificates/. This is the place where we add our internal CA certificate.
 +  * **Output:** It then generates the single, concatenated bundle file at **/etc/ssl/certs/ca-certificates.crt**. This file is the master list used by many applications (like OpenSSL) to verify SSL/TLS connections.
 +
 +
 +
 +
 +
 +==== Update FreeRADIUS for ldaps:// ====
 +  * Do the following steps.
 +<code bash>
 +sudo su
 +#Copy the OpenLDAP's CA to FreeRADIUS
 +cp /etc/ldap/tls/ca /etc/freeradius/3.0/certs/ca.crt
 +</code>
 +  * Edit **/etc/freeradius/3.0/mods-enabled/ldap**
 +<code bash>
 +#Look for these items...
 +#server = 'localhost'
 +#---This has to match the cert' ubjectAltName (SAN)--- 
 +server = 'ldap.radiusdesk.com'
 +#       server = 'ldap.rrdns.example.org'
 +#       server = 'ldap.rrdns.example.org'
 +
 +#  Port to connect on, defaults to 389, will be ignored for LDAP URIs.
 +##port = 389
 +#--We specify the ldaps port--
 +port = 636
 +
 +#--- Then loop for the tls section
 +tls {
 +        # Set this to 'yes' to use TLS encrypted connections
 +        # to the LDAP database by using the StartTLS extended
 +        # operation.
 +        #
 +        # The StartTLS operation is supposed to be
 +        # used with normal ldap connections instead of
 +        # using ldaps (port 636) connections
 +        
 +        #--- Disable start_tls since we are forcing ssl/tls ---
 +        
 +        #start_tls = yes
 +
 +#               ca_file = ${certdir}/cacert.pem
 +
 +       #--- The CA file from OpenLDAP--
 +       
 +        ca_file = /etc/freeradius/3.0/certs/ca.crt
 +
 +#               ca_path = ${certdir}
 +#               certificate_file = /path/to/radius.crt
 +#               private_key_file = /path/to/radius.key
 +#               random_file = /dev/urandom
 +
 +        #  Certificate Verification requirements.  Can be:
 +        #    'never' (do not even bother trying)
 +        #    'allow' (try, but don't fail if the certificate
 +        #               cannot be verified)
 +        #    'demand' (fail if the certificate does not verify)
 +        #    'hard'  (similar to 'demand' but fails if TLS
 +        #             cannot negotiate)
 +        #
 +        #  The default is libldap's default, which varies based
 +        #  on the contents of ldap.conf.
 +
 +        #---Enforce FreeRADIUS to check the validity of the certificate ---
 +        
 +        require_cert    = 'demand'
 +
 +        #
 +        #  Check the CRL, as with the EAP module.
 +        #
 +</code>
 +  * After you made these changes, restart FreeRADIUS in debug mode and to a test authentication to confirm that it is now using ldaps (port 636)
 +  * See the results from out setup below:
 +<code bash>
 +rlm_ldap (ldap): Reserved connection (3)
 +(3) ldap: EXPAND (uid=%{%{Stripped-User-Name}:-%{User-Name}})
 +(3) ldap:    --> (uid=testuser)
 +(3) ldap: Performing search in "ou=people,dc=radiusdesk,dc=com" with filter "(uid=testuser)", scope "sub"
 +(3) ldap: Waiting for search result...
 +(3) ldap: User object found at DN "uid=testuser,ou=people,dc=radiusdesk,dc=com"
 +(3) ldap: Processing user attributes
 +(3) ldap: control:Password-With-Header += 'mysecretpassword'
 +rlm_ldap (ldap): Released connection (3)
 +Need more connections to reach 10 spares
 +rlm_ldap (ldap): Opening additional connection (7), 1 of 25 pending slots used
 +rlm_ldap (ldap): Connecting to ldap://ldap.radiusdesk.com:636
 +rlm_ldap (ldap): Waiting for bind result...
 +rlm_ldap (ldap): Bind successful
 +
 +</code>
  
  
-==== Install OpenLDAP ==== 
  
  
  • technical/fr-ldap.1784881705.txt.gz
  • Last modified: 2026/07/24 10:28
  • by system