Changes between Initial Version and Version 1 of LDAPInstall


Ignore:
Timestamp:
06/02/13 07:10:59 (11 years ago)
Author:
uaguest_SPatel1@…
Comment:

--

Legend:

Unmodified
Added
Removed
Modified
  • LDAPInstall

    v1 v1  
     1This document explains the steps to install and configure the Oracle DSEE on grinnell.  Note that the DSCC has not been configured on grinnell yet. 
     2 
     31.  Install packages to help with debugging. 
     4 
     5 
     6{{{ 
     7yum install openldap-clients* 
     8yum install telnet 
     9yum install nmap 
     10}}} 
     11 
     122.  Download the x86-64 bit version of Oracle Directory Server Enterprise Edition (11.1.1.7.0). 
     13 
     143.  Extract contents into /var/tmp/ldap/. 
     15 
     164.  The extracted contents contain a ZIP file called sun-dsee7.zip.  Simply unzipping this file installs the Oracle DSEE. 
     17 
     18 
     19{{{ 
     20unzip -qq sun-dsee7.zip -d /srv/ 
     21}}} 
     22 
     235.  Install required 32-bit packages. 
     24 
     25 
     26{{{ 
     27yum install libstdc++-4.4.7-3.el6.i686 
     28}}} 
     29 
     306.  Prepare creation of directory server instance. 
     31 
     32 
     33{{{ 
     34mkdir /srv/servers 
     35chown oracle /srv/servers/ 
     36su - oracle 
     37}}} 
     38 
     397.  Create directory server instance 
     40 
     41{{{ 
     42[oracle@grinnell ~]$ /srv/dsee7/bin/dsadm create /srv/servers/slapd-grouper-test 
     43Choose the Directory Manager password: 
     44Confirm the Directory Manager password: 
     45Use command 'dsadm start '/srv/servers/slapd-grouper-test'' to start the instance 
     46}}} 
     47 
     488.  Start instance 
     49 
     50 
     51{{{ 
     52[oracle@grinnell ~]$ /srv/dsee7/bin/dsadm start /srv/servers/slapd-grouper-test 
     53Directory Server instance '/srv/servers/slapd-grouper-test' started: pid=16604 
     54}}} 
     55 
     569.  Set ssl-cipher-family property.  This is based on existing UA documentation the production directory servers. 
     57 
     58 
     59{{{ 
     60[oracle@grinnell ~]$ /srv/dsee7/bin/dsconf set-server-prop -h localhost -p 1389 ssl-cipher-family:TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA ssl-cipher-family:TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA ssl-cipher-family:TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA ssl-cipher-family:TLS_DHE_DSS_WITH_CAMELLIA_256_CBC_SHA ssl-cipher-family:TLS_DHE_RSA_WITH_AES_256_CBC_SHA ssl-cipher-family:TLS_DHE_DSS_WITH_AES_256_CBC_SHA ssl-cipher-family:TLS_ECDH_RSA_WITH_AES_256_CBC_SHA ssl-cipher-family:TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA ssl-cipher-family:TLS_RSA_WITH_CAMELLIA_256_CBC_SHA ssl-cipher-family:TLS_RSA_WITH_AES_256_CBC_SHA ssl-cipher-family:TLS_ECDHE_ECDSA_WITH_RC4_128_SHA ssl-cipher-family:TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA ssl-cipher-family:TLS_ECDHE_RSA_WITH_RC4_128_SHA ssl-cipher-family:TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA ssl-cipher-family:TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA ssl-cipher-family:TLS_DHE_DSS_WITH_CAMELLIA_128_CBC_SHA ssl-cipher-family:TLS_DHE_DSS_WITH_RC4_128_SHA ssl-cipher-family:TLS_DHE_RSA_WITH_AES_128_CBC_SHA ssl-cipher-family:TLS_DHE_DSS_WITH_AES_128_CBC_SHA ssl-cipher-family:TLS_ECDH_RSA_WITH_RC4_128_SHA ssl-cipher-family:TLS_ECDH_RSA_WITH_AES_128_CBC_SHA ssl-cipher-family:TLS_ECDH_ECDSA_WITH_RC4_128_SHA ssl-cipher-family:TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA ssl-cipher-family:TLS_RSA_WITH_SEED_CBC_SHA ssl-cipher-family:TLS_RSA_WITH_CAMELLIA_128_CBC_SHA ssl-cipher-family:SSL_RSA_WITH_RC4_128_MD5 ssl-cipher-family:SSL_RSA_WITH_RC4_128_SHA ssl-cipher-family:TLS_RSA_WITH_AES_128_CBC_SHA ssl-cipher-family:TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA ssl-cipher-family:TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA ssl-cipher-family:SSL_DHE_RSA_WITH_3DES_EDE_CBC_SHA ssl-cipher-family:SSL_DHE_DSS_WITH_3DES_EDE_CBC_SHA ssl-cipher-family:TLS_ECDH_RSA_WITH_3DES_EDE_CBC_SHA ssl-cipher-family:TLS_ECDH_ECDSA_WITH_3DES_EDE_CBC_SHA ssl-cipher-family:SSL_RSA_FIPS_WITH_3DES_EDE_CBC_SHA ssl-cipher-family:SSL_RSA_WITH_3DES_EDE_CBC_SHA ssl-cipher-family:SSL_CK_RC4_128_WITH_MD5 ssl-cipher-family:SSL_CK_RC2_128_CBC_WITH_MD5 ssl-cipher-family:SSL_CK_DES_192_EDE3_CBC_WITH_MD5 ssl-cipher-family:SSL_CK_DES_64_CBC_WITH_MD5 
     61Certificate "CN=grinnell.alaska.edu, CN=1636, CN=Directory Server, O=Sun Microsystems" presented by the server is not trusted. 
     62Type "Y" to accept, "y" to accept just once, "n" to refuse, "d" for more details: Y 
     63Enter "cn=Directory Manager" password: 
     64Before setting SSL configuration, export Directory Server data. 
     65Do you want to continue [y/n] ?  y 
     66Directory Server must be restarted for changes to take effect. 
     67}}}