FreeIPA: Central LDAP and Kerberos for Linux Servers - 夜莺博客

FreeIPA: Central LDAP and Kerberos for Linux Servers

FreeIPA bundles 389 Directory Server, Kerberos, DNS, certificate services and a policy engine into one identity domain for Linux and Unix estates. For a mixed server fleet that currently relies on local accounts and shared root passwords, it is the shortest path to named users, sudo control and an auditable identity source. This guide covers the server install, client enrolment, and the two policy features that matter most in operations: HBAC service rules and sudo rules.

Design decisions before installing

  • Domain and realm — corp.example.net / CORP.EXAMPLE.NET. The realm must be uppercase and should match a DNS domain you control.
  • DNS — let FreeIPA manage an integrated DNS zone, or point clients at existing resolvers with the correct SRV records. Half-configured DNS is the most common install failure.
  • Topology — start with one server plus one replica for availability.
# Basic server install (RHEL / Rocky / Alma)
sudo dnf install -y ipa-server ipa-server-dns
sudo ipa-server-install \
  --domain=corp.example.net \
  --realm=CORP.EXAMPLE.NET \
  --ds-password='<dirsrv-pw>' \
  --admin-password='<admin-pw>' \
  --setup-dns --forwarder=10.10.10.53 --no-reverse \
  --hostname=ipa1.corp.example.net \
  --unattended

Add a replica so the domain survives the loss of one node:

sudo dnf install -y ipa-server
sudo ipa-replica-install --setup-ca --setup-dns --forwarder=10.10.10.53 \
  --principal admin --admin-password '<admin-pw>'

Enrolling clients

sudo dnf install -y ipa-client
sudo ipa-client-install --domain=corp.example.net --server=ipa1.corp.example.net \
  --mkhomedir --ssh-trust-dns --enable-dns-updates --unattended \
  --principal admin --password '<admin-pw>'

# verify on the client
kinit opsuser
klist
id opsuser
sudo systemctl status sssd

Enrolment writes SSSD configuration and a host Kerberos keytab at /etc/krb5.keytab. If id resolves users slowly, check sssd logs for an incorrect ldap_uri or a stalled DNS SRV lookup rather than a slow directory.

Identity and access policy

# users, groups, hosts
ipa user-add opsuser --first=Ops --last=User --shell=/bin/bash --password
ipa group-add netops --desc="Network operations"
ipa group-add-member netops --users=opsuser
ipa host-add server42.corp.example.net --ip-address=10.10.20.42

# host-based access control: who may SSH where
ipa hbacrule-add allow-netops-ssh --servicecat=all --hostcat=all
ipa hbacrule-add-user allow-netops-ssh --groups=netops
ipa hbacrule-add-service allow-netops-ssh --hbacsvcs=sshd
ipa hbacrule-add-host allow-netops-ssh --hosts=server42.corp.example.net
ipa hbacrule-mod allow-netops-ssh --accessrule-type=allow

# sudo rules from the directory
ipa sudorule-add netops-all-servers --hostcat=all
ipa sudorule-add-user netops-all-servers --groups=netops
ipa sudorule-add-allow-command netops-all-servers --sudocmds='/usr/bin/systemctl status'
ipa sudorule-mod netops-all-servers --cmdcat=all

HBAC answers "may this user authenticate to this host" and sudo rules answer "what may they run once they are there". Keeping the two separate makes least privilege enforceable without touching individual servers.

Operability

ipa config-show | head -30
ipa-replica-manage list
ipactl status
kinit admin && ipa user-find --all | head
# rotate a compromised user
ipa user-disable opsuser
ipa passwd opsuser

Do not point the domain at a single server without also managing certificate renewal — expired CA certificates lock every client out at once. Add monitoring on the CA expiry, the replication agreement status, and the backend directory size.

Related reading: Linux SSSD Active Directory realm join troubleshooting, Fail2ban jails with nftables, and FreeRADIUS EAP-TLS for wired 802.1X.

原文链接:https://www.freeipa.org/page/Documentation