Once you have installed and configured LDAP on your Linux server you will probably need to change user’s passwords in future. For this you can allow user to login and change their password from shell.
User management from shell is not a sufficient way, you might be interested to find a way to change password without allowing user to log into server. And in case if you has particular login registration framework, then you would like to integrate LDAP with it.
I choose PHP to perform the task.
First thing, allow user to change password in slapd.conf file;
access to attr=userPassword
by self write
by anonymous auth
by * none
The next step is ldap bind with user credentials for authentication;
if(isset($username) and isset($newpassword) and isset($oldpassword)) {
$ldapconn = ldap_connect("hostname", 389);
$ldapbind=@ldap_bind($ldapconn,"uid=".$username.",dc=example,dc=com",$oldpassword);
if($ldapbind){
//If user gives correct username and password, then;
if( ldap_mod_replace ($ldapconn, "uid=".$username.",dc=host,dc=com",
array('userpassword' => "{MD5}".base64_encode(pack("H*",md5($newpassword)) ){
print "Password changed successfully ";
}else{
print "Failed to change password";
}
}
Showing posts with label ldap. Show all posts
Showing posts with label ldap. Show all posts
Friday, March 13, 2009
Monday, March 2, 2009
Ldap authentication with Openbravo
The following instructions allow use of an Ldap server to authenticate users to OpenBravo ERP. I first unsuccessfully attempted to use a custom authentication manager to implement LDAP support. If you have been able to do it, I would be very keen to know how it was done.
- Copy this file to
/AppsOpenbravo/src/com/riksof/authentication/LdapLoginHandler.java - Please modify objectDN string to correspond to your setup.
- Login to postgres with the database user created at installation time: psql - U tad -d openbravo
- Insert the following entry:
insert into ad_model_object(ad_model_object_id, ad_client_id, ad_org_id, isactive, action, classname, isdefault, created, createdby, updated, updatedby) values (1006100001, 0, 0, 'Y', 'X','com.riksof.authentication.LdapLoginHandler', 'Y', current_timestamp, 100, current_timestamp, 100);
- Also update entry to use our login class:
update ad_model_object_mapping set ad_model_object_id=1006100001 where mappingname='/secureApp/LoginHandler.html';
- Compile and deploy OpenBravo to use Ldap.
Subscribe to:
Posts (Atom)