> For the complete documentation index, see [llms.txt](https://ghoulsec.gitbook.io/ghoulsec-vault/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ghoulsec.gitbook.io/ghoulsec-vault/server-are-fun/servers/linux-sever/openldap-server-setup.md).

# OpenLDAP Server Setup

**OpenLDAP Server** is an open-source implementation of the Lightweight Directory Access Protocol (LDAP) used to manage and access directory information over a network. It acts as a centralized directory service that stores and organizes data, such as user information, network resources, and organizational structures, in a hierarchical format. OpenLDAP is widely used for authentication and authorization in enterprise environments, allowing applications and systems to query and manage user credentials, access controls, and other directory-based data. Its flexibility, scalability, and compliance with LDAP standards make it a popular choice for organizations needing a robust directory service.

We will be using the following hardware and softwares during the deployment :&#x20;

```
OS :  Ubuntu Sever 22.04LTS
Storage :  100GiB Min
Ram : 4GiB Min 
CPU : 4vCPU

Refrence URL : https://adamtheautomator.com/openldap/
```

***

#### Step -1 : Setting up the hostname & FQDN of the linux severs

```
sudo hostnamectl set-hostname ldapserver
```

Now we have to setup the FQDN of the machine so we will have to edit the file "/etc/hosts"

```
sudo vi /etc/hosts
> 172.0.1.0    ldapserver.rookie.com    ldapserver 
```

Upon rebooting the system we have sucessfully configured the server hostname & the FQDN to verify the same :&#x20;

```
$> hostname 
ldapserver

$> hostname --fqdn
ldapserver.rookie.com
```

<figure><img src="https://2332860236-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fq6mjlFfyDOi3mV0lemKE%2Fuploads%2FfD6vi5PH40LjtVapf07r%2Fimage.png?alt=media&amp;token=e6b62caf-db24-49de-acb3-ad7c72f8c7b4" alt=""><figcaption><p>Machine Hostname Details</p></figcaption></figure>

***

#### Step -2 Installing the required packages :&#x20;

```
$> sudo apt update -y
$> sudo apt install apache2 php php-cgi libapache2-mod-php php-mbstring php-common php-pear -y
```

This will install all the dependencies and now we will install the LDAP packages on the server

```
$> sudo apt install slapd ldap-utils -y && sudo apt install ldap-account-manager -y
```

upon installing this there will be a pinkish page appers with some necessary details to be required&#x20;

<figure><img src="https://2332860236-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fq6mjlFfyDOi3mV0lemKE%2Fuploads%2FKu86q8BsUWPI6RCzH8BT%2Fimage.png?alt=media&amp;token=2b0b0985-c342-4065-a347-6f1b2e8db49f" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2332860236-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fq6mjlFfyDOi3mV0lemKE%2Fuploads%2FKOWtc5w2W8fyzH8b52zs%2Fimage.png?alt=media&amp;token=24f04c8e-b99a-4e23-996a-c23ae5f7e7fb" alt=""><figcaption></figcaption></figure>

After configuring the Administrative password we can see the LDAP service is running&#x20;

<figure><img src="https://2332860236-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fq6mjlFfyDOi3mV0lemKE%2Fuploads%2FSvEq5oGWnc6Qn0h2xhnU%2Fimage.png?alt=media&amp;token=c999c9e3-3e4c-4be9-b036-fcee1fc80760" alt=""><figcaption></figcaption></figure>

Once the ldap service is up & running we will reconfigure the server settings to configure the LDAP service on the server

```
$> sudo dpkg-reconfigure slapd 
```

Again the pinkish screen will apper and we will have to configure the settings here

<figure><img src="https://2332860236-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fq6mjlFfyDOi3mV0lemKE%2Fuploads%2FXa76tHuEjJcGPenQ08fW%2Fimage.png?alt=media&amp;token=c00536a6-1d58-415f-8202-91d9c64d9258" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2332860236-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fq6mjlFfyDOi3mV0lemKE%2Fuploads%2FTfZwraJ8dOXPbXvaNyBa%2Fimage.png?alt=media&amp;token=11fe7195-b7c9-4d23-b6c3-371ff595c273" alt=""><figcaption></figcaption></figure>

Enter the domain name in my case it is rookie.com

<figure><img src="https://2332860236-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fq6mjlFfyDOi3mV0lemKE%2Fuploads%2FtQ7qRe4zlEIzPssNkvB1%2Fimage.png?alt=media&amp;token=d90dde92-be5c-47db-a843-f1303701a424" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2332860236-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fq6mjlFfyDOi3mV0lemKE%2Fuploads%2FMsUMwkoLvcQpDPRIk5en%2Fimage.png?alt=media&amp;token=c5290ec6-569a-4865-83e6-54694594658b" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2332860236-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fq6mjlFfyDOi3mV0lemKE%2Fuploads%2F0RiyK9tp1Jhv2Pnxs8ND%2Fimage.png?alt=media&amp;token=e2b96a98-8de4-4f1d-9f41-c7a32e486f8e" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2332860236-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fq6mjlFfyDOi3mV0lemKE%2Fuploads%2FkBX8hwECffezJDy2IsB5%2Fimage.png?alt=media&amp;token=3f0e7df2-428a-477d-a22c-8b37ad22a610" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2332860236-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fq6mjlFfyDOi3mV0lemKE%2Fuploads%2FlJ1er37dWpcE1P3wA2nn%2Fimage.png?alt=media&amp;token=34126d13-b806-4642-bfa2-7cdd201bc988" alt=""><figcaption></figcaption></figure>

Upon configuring all the options we can complete the setup & it should result in output like this :&#x20;

<figure><img src="https://2332860236-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fq6mjlFfyDOi3mV0lemKE%2Fuploads%2FLQ1SvQPZueUlK2mXhP94%2Fimage.png?alt=media&amp;token=ad9c0db8-925a-4814-b558-ffdd97896402" alt=""><figcaption></figcaption></figure>

Now we have to edit the config file as follows :&#x20;

```
$> sudo vi /etc/ldap/ldap.conf    
```

<figure><img src="https://2332860236-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fq6mjlFfyDOi3mV0lemKE%2Fuploads%2FcrEOaIDu9u4yilbXJnFw%2Fimage.png?alt=media&amp;token=53cc5d8e-418e-455d-acec-9c19a8914da9" alt=""><figcaption></figcaption></figure>

We have to add two lines as shown in the last of the image above&#x20;

```
BASE    dc=rookie,dc=com
URI    ldap://localhost
```

Now we have sucessfully configured the LDAP server&#x20;

***

#### Step -3 : Testing & Verification

```
$> ldapserarch -x
$> sudo slapcat
```

<figure><img src="https://2332860236-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fq6mjlFfyDOi3mV0lemKE%2Fuploads%2FIhrqqyt3BH5iujxoWO4N%2Fimage.png?alt=media&amp;token=bcb2f55c-a578-4078-97db-383d8f6b3453" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2332860236-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fq6mjlFfyDOi3mV0lemKE%2Fuploads%2FfGP2XQQntsV0nmpphc2v%2Fimage.png?alt=media&amp;token=6f727198-fe7f-4ca1-892f-27efd1da0791" alt=""><figcaption></figcaption></figure>

Now we have sucessfully deployed the LDAP server, On the next section we will learn how to setup the LDAP Account Manager to efficiently manage the LDAP server.
