Spring Boot集成ApacheDS测试时,无法添加Microsoft LDAP属性的求助
问题
我正在模拟真实的Microsoft LDAP目录树,应用对接真实LDAP正常,但在Spring Boot中使用内存LDAP服务器ApacheDS测试时,无法复现memberOf、distinguishedname、objectCategory这类属性。
基准DN为ou=users,dc=oficinas,dc=com,现有LDAP条目示例:
dn: cn=user01,ou=users,dc=oficinas,dc=com objectClass: top objectClass: person objectClass: organizationalPerson cn: user01 sn: user
尝试通过LDIF创建自定义Schema来添加memberOf属性,但ApacheDS报错,使用的LDIF内容如下:
dn: ou=schema objectClass: organizationalUnit objectClass: top ou: schema dn: m-oid=1.3.6.1.4.1.42.2.27.32.1.1,ou=schema m-collective: FALSE m-singlevalue: TRUE m-oid: 1.3.6.1.4.1.42.2.27.32.1.1 m-obsolete: FALSE m-description: Custom Attribute m-nousermodification: FALSE objectclass: metaAttributeType objectclass: metaTop objectclass: top m-syntax: 1.3.6.1.4.1.1466.115.121.1.15 m-usage: USER_APPLICATIONS m-name: memberOf dn: m-oid=1.3.6.1.4.1.42.2.27.32.1,ou=schema m-oid: 1.3.6.1.4.1.42.2.27.32.1 m-obsolete: FALSE m-supobjectclass: inetOrgPerson m-description: - objectclass: metaObjectClass objectclass: metaTop objectclass: top m-name: customPerson m-typeobjectclass: STRUCTURAL m-may: memberOf m-equality: objectIdentifierMatch
运行时错误信息:
'm-oid=1.3.6.1.4.1.42.2.27.32.1.1,ou=attributeTypes,ou=schema,dc=oficinas,dc=sepg,dc=minhac,dc=age' because it violates the provided schema: The entry contains object class metaAttributeType which is not defined in the schema. The entry contains object class metaTop which is not defined in the schema. The entry contains attribute m-oid which is not defined in the schema. The entry contains attribute m-syntax which is not defined in the schema. The entry contains attribute m-obsolete which is not defined in the schema. The entry contains attribute m-collective which is not defined in the schema. The entry contains attribute m-usage which is not defined in the schema. The entry contains attribute m-name which is not defined in the schema. The entry contains attribute m-nousermodification which is not defined in the schema. The entry contains attribute m-singlevalue which is not defined in the schema. The entry contains attribute m-description which is not defined in the schema. The entry's RDN contains attribute m-oid which is not defined in the schema.] at java.naming/com.sun.jndi.ldap.LdapCtx.mapErrorCode(LdapCtx.java:3291) ~[na:na]
需要这些属性来模拟真实操作(使用Bitnami本地服务器也遇到同样问题),请问:
- 如何在Schema中添加自定义属性?
- 能否通过Spring Boot的.ldif文件实现?
解决方案
错误根源是你使用了ApacheDS的Meta Schema(metaAttributeType、metaTop等类),但默认内存服务器未加载这些元类,且这种方式适合在线修改Schema,不适合Spring Boot启动时批量加载LDIF的场景。以下是两种可行方案:
方案一:通过标准LDIF格式定义Schema(支持Spring Boot加载)
ApacheDS支持用标准LDAP Schema语法定义属性和对象类,只需确保Schema定义的LDIF优先于业务条目加载:
- 创建Schema定义LDIF(命名为
00-schema.ldif,保证加载顺序):
# 初始化schema容器(若不存在) dn: cn=schema objectClass: top objectClass: subschema # 添加memberOf属性定义 dn: cn=schema changetype: modify add: attributeTypes attributeTypes: ( 1.3.6.1.4.1.42.2.27.32.1.1 NAME 'memberOf' DESC 'Custom group membership attribute' EQUALITY distinguishedNameMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 SINGLE-VALUE USAGE userApplications ) # 添加自定义对象类customPerson,继承inetOrgPerson并允许memberOf dn: cn=schema changetype: modify add: objectClasses objectClasses: ( 1.3.6.1.4.1.42.2.27.32.1 NAME 'customPerson' DESC 'Custom person class with memberOf' SUP inetOrgPerson STRUCTURAL MAY ( memberOf ) )
- 修改用户条目LDIF(命名为
01-users.ldif),使用自定义对象类:
dn: cn=user01,ou=users,dc=oficinas,dc=com objectClass: top objectClass: person objectClass: organizationalPerson objectClass: inetOrgPerson objectClass: customPerson cn: user01 sn: user memberOf: cn=group01,ou=groups,dc=oficinas,dc=com
- Spring Boot会按文件名前缀顺序加载LDIF,确保
00-schema.ldif先被加载即可。
方案二:加载Microsoft AD兼容Schema(贴合真实场景)
若要模拟AD原生属性(如memberOf、objectCategory),可直接使用ApacheDS提供的AD兼容Schema:
- 添加Maven依赖(仅测试环境使用):
<dependency> <groupId>org.apache.directory.server</groupId> <artifactId>apacheds-server-jndi</artifactId> <version>2.0.0.AM26</version> <scope>test</scope> </dependency> <dependency> <groupId>org.apache.directory.server</groupId> <artifactId>apacheds-core-api</artifactId> <version>2.0.0.AM26</version> <scope>test</scope> </dependency>
- 在Spring Boot测试配置中指定加载AD Schema:
@Configuration public class LdapTestConfig { @Bean public DefaultSpringSecurityContextSource contextSource() { DefaultSpringSecurityContextSource contextSource = new DefaultSpringSecurityContextSource("ldap://localhost:33389/dc=oficinas,dc=com"); contextSource.setUserDn("uid=admin,ou=system"); contextSource.setPassword("secret"); // 配置加载AD兼容Schema contextSource.setBaseEnvironmentProperties(Map.of( "org.apache.directory.server.schema", "ad", "java.naming.ldap.attributes.binary", "objectSID objectGUID" )); return contextSource; } }
- 之后可直接在LDIF中使用AD属性:
dn: cn=user01,ou=users,dc=oficinas,dc=com objectClass: top objectClass: person objectClass: organizationalPerson objectClass: user cn: user01 sn: user memberOf: cn=group01,ou=groups,dc=oficinas,dc=com objectCategory: CN=Person,CN=Schema,CN=Configuration,DC=oficinas,DC=com
关键注意事项
distinguishedName是LDAP服务器自动维护的操作属性,无需手动添加,查询时会自动返回。- Bitnami LDAP服务器同样支持导入标准Schema LDIF,操作步骤与ApacheDS一致。
- Schema定义必须先于业务条目加载,否则会出现属性未定义的错误。
内容的提问来源于stack exchange,提问作者sergiopf
相关产品推荐
相关产品推荐

