OpenLDAP技术问题:如何在Schema中添加日期属性
LDAP自定义属性添加失败问题处理
我在网上找不到解决方案,尝试操作后未成功,恳请帮助(LDAP实在太折腾人)。
执行命令及报错信息:
root@9ae33b5bc07e:/# ldapadd -Y EXTERNAL -H ldapi:/// -f add_attribute.ldif SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 ldapadd: invalid format (line 4) entry: "cn=schema,cn=config"
对应的LDIF文件内容:
dn: cn=schema,cn=config add: olcAttributeTypes olcAttributeTypes: ( 1.3.6.1.4.1.5427.1.389.4.2 NAME 'dateOfBirth' DESC 'Date of birth (format YYYYMMDD, only numeric chars)' EQUALITY numericStringMatch SUBSTR numericStringSubstringsMatch SINGLE-VALUE SYNTAX 1.3.6.1.4.1.1466.115.121.1.36{8} )
问题原因及解决方法
报错提示第4行格式错误,核心是OpenLDAP对LDIF文件的多行属性续行格式有严格要求:
- 所有续行必须以单个空格开头(不能用制表符或多个空格,否则会被判定格式非法)
- 确保属性定义的括号完全配对,没有语法遗漏
修正后的LDIF文件
dn: cn=schema,cn=config add: olcAttributeTypes olcAttributeTypes: ( 1.3.6.1.4.1.5427.1.389.4.2 NAME 'dateOfBirth' DESC 'Date of birth (format YYYYMMDD, only numeric chars)' EQUALITY numericStringMatch SUBSTR numericStringSubstringsMatch SINGLE-VALUE SYNTAX 1.3.6.1.4.1.1466.115.121.1.36{8} )
重新执行命令
使用原命令或ldapmodify均可:
ldapadd -Y EXTERNAL -H ldapi:/// -f add_attribute.ldif
如果仍有问题,可检查:
- OID
1.3.6.1.4.1.5427.1.389.4.2是否已被其他属性占用 - SYNTAX定义的长度限制
{8}是否符合需求(这里对应YYYYMMDD的8位长度,是正确的)
内容的提问来源于stack exchange,提问作者user23537799
相关产品推荐
相关产品推荐

