data:image/s3,"s3://crabby-images/0e749/0e749112835d22090537edbb9c821fd3a6e717e4" alt="Cray Urika-GX Administration Manual Download Page 228"
7.9.9
Reset an Administrator LDAP Password when the OLC Scheme Password is Known
Prerequisites
●
This procedure requires root privileges.
●
The
cn=admin,cn=config
LDAP OLC schema password needs to be known while carrying out this
procedure.
●
This procedure requires Urika-GX 2.0UP00 or latter installed on the system.
About this task
This procedure provides instructions for updating the LDAP admin server password for the root domain name,
i.e.,
cn=crayadm,dc=urika,dc=com
. It can be used to reset the password in case it is forgotten.
This procedure contains instructions for systems that have their LDAP running in OLC mode. For such systems,
the
/etc/default/slapd.conf
file contains the following entry:
SLAPD_CONF_DIR="/usr/local/openldap/etc/openldap/slapd.d"
Procedure
1. Log on to the LDAP host server as root.
2. Generate a new hashed password.
[root@nid00030]# slappasswd
New password:
Re-enter new password:
{SSHA}I1/QKXFN+RjLFlJwdPBt2dmX
3. Create the
crayadmpw_bdb.ldif
file with the newly hashed password.
dn: olcDatabase={1}bdb,cn=config
changetype: modify
replace: olcRootPW
olcRootPW: {SSHA}I1/QKXFN+RjLFlJwdPBt2dmX
4. Create the
crayadmpw_meta.ldif
file with the newly hashed password.
dn: olcDatabase={2}meta,cn=config
changetype: modify
replace: olcRootPW
olcRootPW: {SSHA}I1/QKXFN+RjLFlJwdPBt2dmX
5. Execute the following commands and enter the
cn=admin,cn=config
password when prompted for the
LDAP password.
#
ldapmodify -x -W -D "cn=admin,cn=config" -H ldap://localhost -f crayadmpw_bdb.ldif
Enter LDAP Password:
modifying entry "olcDatabase={1}bdb,cn=config"
Security
S3016
228