日韩性视频-久久久蜜桃-www中文字幕-在线中文字幕av-亚洲欧美一区二区三区四区-撸久久-香蕉视频一区-久久无码精品丰满人妻-国产高潮av-激情福利社-日韩av网址大全-国产精品久久999-日本五十路在线-性欧美在线-久久99精品波多结衣一区-男女午夜免费视频-黑人极品ⅴideos精品欧美棵-人人妻人人澡人人爽精品欧美一区-日韩一区在线看-欧美a级在线免费观看

歡迎訪問 生活随笔!

生活随笔

當(dāng)前位置: 首頁 > 编程资源 > 编程问答 >内容正文

编程问答

Self Service Password (SSP)

發(fā)布時間:2025/3/21 编程问答 17 豆豆
生活随笔 收集整理的這篇文章主要介紹了 Self Service Password (SSP) 小編覺得挺不錯的,現(xiàn)在分享給大家,幫大家做個參考.

安裝SSP, 依賴包包括php5, php5-ldap, php5-mcrypt

啟用mcrypt功能: sudo php5enmod mcrypt

?

第一部分: Apache

安裝Apache, 并且啟用SSL模塊:?sudo a2enmod ssl

在/etc/apache2/apache2.conf中加入以下字段:

<Directory /usr/share/self-service-password>Options Indexes FollowSymLinksAllowOverride NoneRequire all granted </Directory>

新建/etc/apache2/sites-available/self-service-password.conf, 插入以下字段:

<IfModule mod_ssl.c><VirtualHost *:443>DocumentRoot /usr/share/self-service-passwordSSLEngine onSSLCertificateFile /home/chen/ssp.crtSSLCertificateKeyFile /home/chen/ssp.keySSLCACertificateFile /home/chen/ca.crt</VirtualHost> </IfModule>

啟用該網(wǎng)站:?sudo a2ensite self-service-password

若想讓用戶強(qiáng)制訪問HTTPS, 則先運(yùn)行sudo a2enmod rewrite, 然后在/etc/apache2/apache2.conf里面加入下列代碼:

RewriteEngine On RewriteCond %{HTTPS} !on RewriteRule (.*) https://%{HTTP_HOST}%{REQUEST_URI}

?

第二部分: LDAP

修改/usr/share/self-service-password/conf/config.inc.php

# LDAP $ldap_url = "ldaps://dc1.abc.local"; $ldap_binddn = "cn=administrator,cn=users,dc=abc,dc=local"; $ldap_bindpw = 'XXXXXX'; $ldap_base = "ou=vb-user,dc=abc,dc=local"; $ldap_login_attribute = "uid"; $ldap_fullname_attribute = "cn"; $ldap_filter = "(&(objectClass=user)(sAMAccountName={login})(!(userAccountControl:1.2.840.113556.1.4.803:=2)))"; # Active Directory mode # true: use unicodePwd as password field # false: LDAPv3 standard behavior $ad_mode = true; # Force account unlock when password is changed $ad_options['force_unlock'] = true; # Force user change password at next login $ad_options['force_pwd_change'] = false;....略...# Who changes the password? # Also applicable for question/answer save # user: the user itself # manager: the above binddn $who_change_password = "manager";

修改/etc/ldap/ldap.conf

TLS_CACERT /home/chen/ca.crt ##指定CA證書的路徑

若有問題, 可以嘗試查看/var/log/apaches2下的各種日志文件.

?

第三部分: Mail

安裝sendmail.?修改/usr/share/self-service-password/conf/config.inc.php

## Mail # LDAP mail attribute $mail_attribute = "mail"; # Who the email should come from $mail_from = "VBPR@abc.cn"; # Notify users anytime their password is changed $notify_on_change = false;

?

?

Self Service Password: http://ltb-project.org/wiki/start?

中文語言包: http://tools.ltb-project.org/issues/632

PWM:?https://github.com/jrivard/pwm

轉(zhuǎn)載于:https://www.cnblogs.com/IvanChen/p/4763473.html

總結(jié)

以上是生活随笔為你收集整理的Self Service Password (SSP)的全部內(nèi)容,希望文章能夠幫你解決所遇到的問題。

如果覺得生活随笔網(wǎng)站內(nèi)容還不錯,歡迎將生活随笔推薦給好友。