You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot集成ApacheDS测试时,无法添加Microsoft LDAP属性的求助

问题

我正在模拟真实的Microsoft LDAP目录树,应用对接真实LDAP正常,但在Spring Boot中使用内存LDAP服务器ApacheDS测试时,无法复现memberOf、distinguishedname、objectCategory这类属性。

基准DN为ou=users,dc=oficinas,dc=com,现有LDAP条目示例:

dn: cn=user01,ou=users,dc=oficinas,dc=com
objectClass: top
objectClass: person
objectClass: organizationalPerson
cn: user01
sn: user

尝试通过LDIF创建自定义Schema来添加memberOf属性,但ApacheDS报错,使用的LDIF内容如下:

dn: ou=schema
objectClass: organizationalUnit
objectClass: top
ou: schema

dn: m-oid=1.3.6.1.4.1.42.2.27.32.1.1,ou=schema
m-collective: FALSE
m-singlevalue: TRUE
m-oid: 1.3.6.1.4.1.42.2.27.32.1.1
m-obsolete: FALSE
m-description: Custom Attribute
m-nousermodification: FALSE
objectclass: metaAttributeType
objectclass: metaTop
objectclass: top
m-syntax: 1.3.6.1.4.1.1466.115.121.1.15
m-usage: USER_APPLICATIONS
m-name: memberOf

dn: m-oid=1.3.6.1.4.1.42.2.27.32.1,ou=schema
m-oid: 1.3.6.1.4.1.42.2.27.32.1
m-obsolete: FALSE
m-supobjectclass: inetOrgPerson
m-description: -
objectclass: metaObjectClass
objectclass: metaTop
objectclass: top
m-name: customPerson
m-typeobjectclass: STRUCTURAL
m-may: memberOf
m-equality: objectIdentifierMatch

运行时错误信息:

'm-oid=1.3.6.1.4.1.42.2.27.32.1.1,ou=attributeTypes,ou=schema,dc=oficinas,dc=sepg,dc=minhac,dc=age' because it violates the provided schema:  The entry contains object class metaAttributeType which is not defined in the schema.  The entry contains object class metaTop which is not defined in the schema.  The entry contains attribute m-oid which is not defined in the schema.  The entry contains attribute m-syntax which is not defined in the schema.  The entry contains attribute m-obsolete which is not defined in the schema.  The entry contains attribute m-collective which is not defined in the schema.  The entry contains attribute m-usage which is not defined in the schema.  The entry contains attribute m-name which is not defined in the schema.  The entry contains attribute m-nousermodification which is not defined in the schema.  The entry contains attribute m-singlevalue which is not defined in the schema.  The entry contains attribute m-description which is not defined in the schema.  The entry's RDN contains attribute m-oid which is not defined in the schema.]
    at java.naming/com.sun.jndi.ldap.LdapCtx.mapErrorCode(LdapCtx.java:3291) ~[na:na]

需要这些属性来模拟真实操作(使用Bitnami本地服务器也遇到同样问题),请问:

  1. 如何在Schema中添加自定义属性?
  2. 能否通过Spring Boot的.ldif文件实现?
解决方案

错误根源是你使用了ApacheDS的Meta Schema(metaAttributeType、metaTop等类),但默认内存服务器未加载这些元类,且这种方式适合在线修改Schema,不适合Spring Boot启动时批量加载LDIF的场景。以下是两种可行方案:

方案一:通过标准LDIF格式定义Schema(支持Spring Boot加载)

ApacheDS支持用标准LDAP Schema语法定义属性和对象类,只需确保Schema定义的LDIF优先于业务条目加载:

  1. 创建Schema定义LDIF(命名为00-schema.ldif,保证加载顺序):
# 初始化schema容器(若不存在)
dn: cn=schema
objectClass: top
objectClass: subschema

# 添加memberOf属性定义
dn: cn=schema
changetype: modify
add: attributeTypes
attributeTypes: ( 1.3.6.1.4.1.42.2.27.32.1.1 NAME 'memberOf' DESC 'Custom group membership attribute' EQUALITY distinguishedNameMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 SINGLE-VALUE USAGE userApplications )

# 添加自定义对象类customPerson,继承inetOrgPerson并允许memberOf
dn: cn=schema
changetype: modify
add: objectClasses
objectClasses: ( 1.3.6.1.4.1.42.2.27.32.1 NAME 'customPerson' DESC 'Custom person class with memberOf' SUP inetOrgPerson STRUCTURAL MAY ( memberOf ) )
  1. 修改用户条目LDIF(命名为01-users.ldif),使用自定义对象类:
dn: cn=user01,ou=users,dc=oficinas,dc=com
objectClass: top
objectClass: person
objectClass: organizationalPerson
objectClass: inetOrgPerson
objectClass: customPerson
cn: user01
sn: user
memberOf: cn=group01,ou=groups,dc=oficinas,dc=com
  1. Spring Boot会按文件名前缀顺序加载LDIF,确保00-schema.ldif先被加载即可。

方案二:加载Microsoft AD兼容Schema(贴合真实场景)

若要模拟AD原生属性(如memberOf、objectCategory),可直接使用ApacheDS提供的AD兼容Schema:

  1. 添加Maven依赖(仅测试环境使用):
<dependency>
    <groupId>org.apache.directory.server</groupId>
    <artifactId>apacheds-server-jndi</artifactId>
    <version>2.0.0.AM26</version>
    <scope>test</scope>
</dependency>
<dependency>
    <groupId>org.apache.directory.server</groupId>
    <artifactId>apacheds-core-api</artifactId>
    <version>2.0.0.AM26</version>
    <scope>test</scope>
</dependency>
  1. 在Spring Boot测试配置中指定加载AD Schema:
@Configuration
public class LdapTestConfig {
    @Bean
    public DefaultSpringSecurityContextSource contextSource() {
        DefaultSpringSecurityContextSource contextSource = 
            new DefaultSpringSecurityContextSource("ldap://localhost:33389/dc=oficinas,dc=com");
        contextSource.setUserDn("uid=admin,ou=system");
        contextSource.setPassword("secret");
        
        // 配置加载AD兼容Schema
        contextSource.setBaseEnvironmentProperties(Map.of(
            "org.apache.directory.server.schema", "ad",
            "java.naming.ldap.attributes.binary", "objectSID objectGUID"
        ));
        return contextSource;
    }
}
  1. 之后可直接在LDIF中使用AD属性:
dn: cn=user01,ou=users,dc=oficinas,dc=com
objectClass: top
objectClass: person
objectClass: organizationalPerson
objectClass: user
cn: user01
sn: user
memberOf: cn=group01,ou=groups,dc=oficinas,dc=com
objectCategory: CN=Person,CN=Schema,CN=Configuration,DC=oficinas,DC=com

关键注意事项

  • distinguishedName是LDAP服务器自动维护的操作属性,无需手动添加,查询时会自动返回。
  • Bitnami LDAP服务器同样支持导入标准Schema LDIF,操作步骤与ApacheDS一致。
  • Schema定义必须先于业务条目加载,否则会出现属性未定义的错误。

内容的提问来源于stack exchange,提问作者sergiopf

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.20 20:43:16