I just double-checked, even though I was certain before. I can still do this by just SSHing into barnard, and without doing anything else, running ldapsearch -x -w $password -D 'cn=Directory Manager' -b "ou=users,dc=kosmos,dc=org" -H "ldaps://ldap.kosmos.org" -v will yield the result almost exactly as posted in the example:
I agree, fit for beginners doesn't sound as good to me. I guess that settles it then.
I cannot tell you how it's possible. Only that it happened exactly as I described. I never looked up the password or copied it anywhere.
FYI: uploaded the source files for the diagram straight to master of this repo. I used Dia to create it:
Get you some easy kredits for updating this one, too: https://wiki.kosmos.org/Infrastructure
I have added doc/ldap.md with the instructions to get the admin password from the encrypted data bag
The same result, meaning successful search results without a password? I can’t reproduce that
ldapsearch -x -w $password -D 'cn=Directory Manager' -b "ou=users,dc=kosmos,dc=org" -H "ldaps://ldap.kosmos.org" -v