Also:
root@linux-efi-vm:~# ldapsearch -H ldaps://10.0.0.1:636 -x -b DC=sn,DC=xxxxxxxxxx,DC=de -D CN=global-admin,OU=Management,OU=GLOBAL,DC=sn,DC=xxxxxxxxxx,DC=de -W
Enter LDAP Password:
ldap_sasl_bind(SIMPLE): Can't contact LDAP server (-1)
root@linux-efi-vm:~#
Jedoch statt mit ip den kompletten hostnamen genommen, kommen ein ganzer Schwall von Daten:
root@linux-efi-vm:~# ldapsearch -H ldaps://srv.sn.xxxxxxxxxx.de:636 -x -b DC=sn,DC=xxxxxxxxxx,DC=de -D CN=global-admin,OU=Management,OU=GLOBAL,DC=sn,DC=xxxxxxxxxx,DC=de -W
Enter LDAP Password:
# extended LDIF
#
# LDAPv3
# base <DC=sn,DC=xxxxxxxxxx,DC=de> with scope subtree
# filter: (objectclass=*)
# requesting: ALL
#
(...)
# search reference
ref: ldap://sn.xxxxxxxxxx.de/DC=ForestDnsZones,DC=sn,DC=xxxxxxxxxx,DC=
de
# search result
search: 2
result: 0 Success
# numResponses: 2809
# numEntries: 2805
# numReferences: 3
root@linux-efi-vm:~#
Was uns aber noch aufgefallen ist:
Wir scheinen ein TLS-Problem zu haben?!
Aufruf im linuxclient:
root@linux-efi-vm:~# ldbsearch -H ldaps://srv.sn.xxxxxxxxxx.de -d=1 "cn=test.lehrer" -k yes
WARNING: The option -k|--kerberos is deprecated!
lpcfg_do_global_parameter: WARNING: The "client use spnego" option is deprecated
TLS ../../source4/lib/tls/tls_tstream.c:1423 - check failed for verify_peer[ca_and_name] and peer_name[srv.sn.xxxxxxxxxx.de] status 0x42 (invalid signer_not_found )
Failed to connect to ldap URL 'ldaps://srv.sn.xxxxxxxxxx.de' - LDAP client internal error: NT_STATUS_INVALID_PARAMETER
Failed to connect to 'ldaps://srv.sn.xxxxxxxxxx.de' with backend 'ldaps': LDAP client internal error: NT_STATUS_INVALID_PARAMETER
Failed to connect to ldaps://srv.sn.xxxxxxxxxx.de - LDAP client internal error: NT_STATUS_INVALID_PARAMETER
root@linux-efi-vm:~#
Derselbe Aufruf direkt auf dem linuxmuster-server:
root@srv:~# ldbsearch -H ldaps://srv.sn.xxxxxxxxxx.de -d=1 "cn=test.lehrer" -k yes
Password for [global-admin@SN.xxxxxxxxxx.DE]:
(...)
# Referral
ref: ldap://sn.xxxxxxxxxx.de/DC=ForestDnsZones,DC=sn,DC=xxxxxxxxxx,DC=de
# returned 4 records
# 1 entries
# 3 referrals
Zum System:
Server:
root@srv:~# dpkg -l | grep linuxmuster
ii linuxmuster-base7 7.1.21-0 all linuxmuster.net configuration scripts
ii linuxmuster-linbo-gui7 7.0.6 all Linuxmuster Linbo GUI
ii linuxmuster-linbo7 4.0.46-0 all linuxmuster-linbo7
ii linuxmuster-prepare 7.2.1-1 all linuxmuster.net pre setup configuration scripts
ii linuxmuster-webui7 7.1.51 all Next generation web-based management tool for linuxmuster.net v7.x
root@srv:~#
Linux-Client:
root@linux-efi-vm:~# dpkg -l | grep linuxmuster
ii linuxmuster-linuxclient7 1.0.9 all Package for Ubuntu clients to connect to the linuxmuster.net 7 active directory server.
root@linux-efi-vm:~#