9 Aralık 2011 Cuma

Manage OpenDS LDAP Accounts

Some opends commands to manage accounts : ( execute commands in directory OPENDS_HOME/bin )

<X> defines a variable and replace your own value in the command.
For example cn=<DIR_ADM> will be (or may be) cn=Directory Manager in your command

<DIR_ADM> : Directory admin user name i.e. Directory Manager
<DIR_ADM_PAWD> : Directory admin user paswword i.e. 123456
<TARGET_USER> : dn of the user to operate on i.e. uid=olcay,ou=People,dc=codeflt,dc=blogspot,dc=com



Disable an account :

./manage-account set-account-is-disabled \
                -h localhost -p 4444 -D "cn=
<DIR_ADM>" \
                --bindPassword <DIR_ADM_PAWD> \
                -X --targetDN "
<TARGET_USER>" --operationValue true


Enable an disabled account

./manage-account clear-account-is-disabled \
                --hostname localhost --port 4444 --bindDN "cn=<DIR_ADM>" \

                --bindPassword <DIR_ADM_PAWD> \
                --targetDN "<TARGET_USER>"




Check if an account is disabled

./manage-account get-account-is-disabled \
                -h localhost -p 4444 -D "cn=<DIR_ADM>" \

               --bindPassword <DIR_ADM_PAWD> \
                -X --targetDN "<TARGET_USER>"



List password history of an account

./manage-account get-password-history \
                --hostname localhost --port 4444 --bindDN "cn=<DIR_ADM>" \

                --bindPassword <DIR_ADM_PAWD> \
                --targetDN "uid=<TARGET_USER>"



Get failed login attempts of an account

./manage-account get-authentication-failure-times \
                -h localhost -p 4444 -D "cn=<DIR_ADM>" \

                --bindPassword <DIR_ADM_PAWD> \
                -X --targetDN "<TARGET_USER>"



Get remaining failed login attempts before account is locked

./manage-account get-remaining-authentication-failure-count \
                -h localhost -p 4444 -D "cn=<DIR_ADM>"-w password -
<DIR_ADM_PAWD> \
                --targetDN "<TARGET_USER>"






Hiç yorum yok:

Yorum Gönder