在服务器上安装libnss-ldap,
sudo apt-get install libnss-ldap,
修改/etc/ldap.conf,如:
base dc=imd,dc=com
uri ldap://ldap.prod.i-md.com/
ldap_version 3
pam_login_attribute uid
pam_lookup_policy yes
pam_check_host_attr no
pam_password md5
nss_base_passwd ou=People,dc=imd,dc=com
nss_base_shadow ou=People,dc=imd,dc=com
nss_base_group ou=Group,dc=imd,dc=com
nss_initgroups_ignoreusers backup,bin,daemon,ftp,games,gnats,irc,libuuid,list,lp,mail,man,messagebus,news,postfix,proftpd,proxy,root,sshd,statd,sync,sys,syslog,uucp,www-data
另外,要让登录后自动建立home目录,只需要在/etc/pam.d/common-account中加入:
session required pam_mkhomedir.so skel=/etc/skel/ umask=0022