You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过LDIF文件向OpenLDAP添加自定义属性与对象类并解决权限问题

关于OpenLDAP自定义Schema添加的权限问题

问题描述

我需要通过bash执行ldapmodify/ldapadd命令,利用LDIF文件修改OpenLDAP服务器的Schema,添加一个包含15个自定义属性的辅助对象类myCustomObjectClass。

初始操作示例

  • test.ldif 文件内容:
dn: OU=Inter Domain,DC=vlad,DC=lan
ou: Inter Domain
objectClass: top
objectClass: organizationalUnit
  • 执行的bash命令(注:原命令存在语法错误,-D后多了逗号):
ldapadd -x -D "cn=admin,dc=vlad,dc=lan" -w admin -H ldap:// -f ldap/test.ldif

更新1:Schema修改尝试与权限错误

我编写了添加自定义对象类的LDIF文件:

dn: cn=schema,cn=config
changetype: modify
add: olcObjectClasses
olcObjectClasses: ( 1.2.3.4.5.6.7.8.9.0 NAME 'myCustomObjectClass'
  DESC 'My Custom Object Class'
  AUXILIARY
  MAY ( customAttribute1 $ customAttribute2 $ customAttribute3 $
        customAttribute4 $ customAttribute5 $ customAttribute6 $
        customAttribute7 $ customAttribute8 $ customAttribute9 $
        customAttribute10 $ customAttribute11 $ customAttribute12 $
        customAttribute13 $ customAttribute14 $ customAttribute15 ) )

执行修改时出现错误:Insufficient access (50)。以下是slapcat -n0的输出:

dn: olcDatabase={0}config,cn=config
objectClass: olcDatabaseConfig
olcDatabase: {0}config
olcAccess: {0}to * by dn.exact=gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth manage by * break
olcRootDN: cn=admin,cn=config
structuralObjectClass: olcDatabaseConfig
entryUUID: 3e49b716-55fd-103e-8582-a14a85261557
creatorsName: cn=config
createTimestamp: 20240202095739Z
olcRootPW:: e1NTSEF9d3J4NGVYaUFvaGRmc2dDOXlqT0V0cEFmSWhZYklxWXo=
entryCSN: 20240202095739.321947Z#000000#000#000000
modifiersName: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth
modifyTimestamp: 20240202095739Z

dn: olcDatabase={1}mdb,cn=config
objectClass: olcDatabaseConfig
objectClass: olcMdbConfig
olcDatabase: {1}mdb
olcDbDirectory: /var/lib/ldap
olcSuffix: dc=vlad,dc=lan
olcLastMod: TRUE
olcRootDN: cn=admin,dc=vlad,dc=lan
olcRootPW:: -----
olcDbCheckpoint: 512 30
olcDbMaxSize: 1073741824
structuralObjectClass: olcMdbConfig
entryUUID: 3e49fae6-55fd-103e-8589-a14a85261557
creatorsName: cn=admin,cn=config
createTimestamp: 20240202095739Z
olcDbIndex: uid eq
olcDbIndex: mail eq
olcDbIndex: memberOf eq
olcDbIndex: entryCSN eq
olcDbIndex: entryUUID eq
olcDbIndex: objectClass eq
olcAccess: {0}to * by dn.exact=gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth manage by * break
olcAccess: {1}to attrs=userPassword,shadowLastChange by self write by dn="cn=admin,dc=vlad,dc=lan" write by anonymous auth by * none
olcAccess: {2}to * by self read by dn="cn=admin,dc=vlad,dc=lan" write by dn="cn=user-ro,dc=vlad,dc=lan" read by * none
entryCSN: 20240202095739.438344Z#000000#000#000000
modifiersName: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth
modifyTimestamp: 20240202095739Z

解决方案

权限分析

从slapcat -n0输出的config数据库访问控制规则可以看出:

olcAccess: {0}to * by dn.exact=gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth manage by * break

这条规则限制了只有**系统root用户(通过外部认证)**才能对config数据库(包括Schema)进行管理操作。你之前使用的cn=admin,dc=vlad,dc=lan是业务数据域(dc=vlad,dc=lan)的管理员,没有修改config库的权限。

另外,config库的根管理员账号是cn=admin,cn=config,如果知道该账号的密码,也可以使用它进行修改。

可行操作方法

方法1:使用系统root用户通过外部认证执行修改

直接以root身份(或sudo)执行ldapmodify,利用EXTERNAL认证方式:

sudo ldapmodify -Y EXTERNAL -H ldapi:/// -f your-schema.ldif
  • -Y EXTERNAL:指定使用外部认证,root用户执行时会自动匹配到gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth的DN,获得config库的管理权限。
  • -H ldapi:///:使用本地Unix套接字连接,比TCP更安全且无需密码。

方法2:使用config库管理员账号cn=admin,cn=config

如果你知道cn=admin,cn=config的密码,可以用以下命令执行修改:

ldapmodify -x -D "cn=admin,cn=config" -w <你的config管理员密码> -H ldap:/// -f your-schema.ldif
  • 若忘记密码,可以通过root用户修改config库的olcRootPW字段,用slappasswd生成加密密码后更新。

额外注意事项

你编写的对象类LDIF中引用了customAttribute1至customAttribute15,但这些自定义属性尚未在Schema中定义,直接添加对象类会报错。需要先添加这些属性的定义,示例LDIF如下:

dn: cn=schema,cn=config
changetype: modify
add: olcAttributeTypes
olcAttributeTypes: ( 1.2.3.4.5.6.7.8.9.1 NAME 'customAttribute1' DESC '自定义属性1' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 )
olcAttributeTypes: ( 1.2.3.4.5.6.7.8.9.2 NAME 'customAttribute2' DESC '自定义属性2' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 )
# 依次添加customAttribute3到customAttribute15,每个属性使用唯一的OID(1.2.3.4.5.6.7.8.9.3至1.2.3.4.5.6.7.8.9.15)

执行完属性定义的修改后,再执行对象类的添加操作。

Apache Directory Studio的操作方式

可以通过Apache Directory Studio完成程序化添加:

  1. 连接到OpenLDAP服务器时,选择使用EXTERNAL认证(需要启动Studio的用户是系统root,或在Linux下用sudo运行Studio);或者使用cn=admin,cn=config账号登录。
  2. 找到cn=schema,cn=config条目,右键选择"Modify Entry",添加olcAttributeTypes和olcObjectClasses属性,填入对应的定义内容后提交即可。

内容的提问来源于stack exchange,提问作者VladC

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.01 01:15:13