如何通过LDIF文件向OpenLDAP添加自定义属性与对象类并解决权限问题
关于OpenLDAP自定义Schema添加的权限问题
问题描述
我需要通过bash执行ldapmodify/ldapadd命令,利用LDIF文件修改OpenLDAP服务器的Schema,添加一个包含15个自定义属性的辅助对象类myCustomObjectClass。
初始操作示例
- test.ldif 文件内容:
dn: OU=Inter Domain,DC=vlad,DC=lan ou: Inter Domain objectClass: top objectClass: organizationalUnit
- 执行的bash命令(注:原命令存在语法错误,
-D后多了逗号):
ldapadd -x -D "cn=admin,dc=vlad,dc=lan" -w admin -H ldap:// -f ldap/test.ldif
更新1:Schema修改尝试与权限错误
我编写了添加自定义对象类的LDIF文件:
dn: cn=schema,cn=config changetype: modify add: olcObjectClasses olcObjectClasses: ( 1.2.3.4.5.6.7.8.9.0 NAME 'myCustomObjectClass' DESC 'My Custom Object Class' AUXILIARY MAY ( customAttribute1 $ customAttribute2 $ customAttribute3 $ customAttribute4 $ customAttribute5 $ customAttribute6 $ customAttribute7 $ customAttribute8 $ customAttribute9 $ customAttribute10 $ customAttribute11 $ customAttribute12 $ customAttribute13 $ customAttribute14 $ customAttribute15 ) )
执行修改时出现错误:Insufficient access (50)。以下是slapcat -n0的输出:
dn: olcDatabase={0}config,cn=config objectClass: olcDatabaseConfig olcDatabase: {0}config olcAccess: {0}to * by dn.exact=gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth manage by * break olcRootDN: cn=admin,cn=config structuralObjectClass: olcDatabaseConfig entryUUID: 3e49b716-55fd-103e-8582-a14a85261557 creatorsName: cn=config createTimestamp: 20240202095739Z olcRootPW:: e1NTSEF9d3J4NGVYaUFvaGRmc2dDOXlqT0V0cEFmSWhZYklxWXo= entryCSN: 20240202095739.321947Z#000000#000#000000 modifiersName: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth modifyTimestamp: 20240202095739Z dn: olcDatabase={1}mdb,cn=config objectClass: olcDatabaseConfig objectClass: olcMdbConfig olcDatabase: {1}mdb olcDbDirectory: /var/lib/ldap olcSuffix: dc=vlad,dc=lan olcLastMod: TRUE olcRootDN: cn=admin,dc=vlad,dc=lan olcRootPW:: ----- olcDbCheckpoint: 512 30 olcDbMaxSize: 1073741824 structuralObjectClass: olcMdbConfig entryUUID: 3e49fae6-55fd-103e-8589-a14a85261557 creatorsName: cn=admin,cn=config createTimestamp: 20240202095739Z olcDbIndex: uid eq olcDbIndex: mail eq olcDbIndex: memberOf eq olcDbIndex: entryCSN eq olcDbIndex: entryUUID eq olcDbIndex: objectClass eq olcAccess: {0}to * by dn.exact=gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth manage by * break olcAccess: {1}to attrs=userPassword,shadowLastChange by self write by dn="cn=admin,dc=vlad,dc=lan" write by anonymous auth by * none olcAccess: {2}to * by self read by dn="cn=admin,dc=vlad,dc=lan" write by dn="cn=user-ro,dc=vlad,dc=lan" read by * none entryCSN: 20240202095739.438344Z#000000#000#000000 modifiersName: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth modifyTimestamp: 20240202095739Z
解决方案
权限分析
从slapcat -n0输出的config数据库访问控制规则可以看出:
olcAccess: {0}to * by dn.exact=gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth manage by * break
这条规则限制了只有**系统root用户(通过外部认证)**才能对config数据库(包括Schema)进行管理操作。你之前使用的cn=admin,dc=vlad,dc=lan是业务数据域(dc=vlad,dc=lan)的管理员,没有修改config库的权限。
另外,config库的根管理员账号是cn=admin,cn=config,如果知道该账号的密码,也可以使用它进行修改。
可行操作方法
方法1:使用系统root用户通过外部认证执行修改
直接以root身份(或sudo)执行ldapmodify,利用EXTERNAL认证方式:
sudo ldapmodify -Y EXTERNAL -H ldapi:/// -f your-schema.ldif
-Y EXTERNAL:指定使用外部认证,root用户执行时会自动匹配到gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth的DN,获得config库的管理权限。-H ldapi:///:使用本地Unix套接字连接,比TCP更安全且无需密码。
方法2:使用config库管理员账号cn=admin,cn=config
如果你知道cn=admin,cn=config的密码,可以用以下命令执行修改:
ldapmodify -x -D "cn=admin,cn=config" -w <你的config管理员密码> -H ldap:/// -f your-schema.ldif
- 若忘记密码,可以通过root用户修改config库的
olcRootPW字段,用slappasswd生成加密密码后更新。
额外注意事项
你编写的对象类LDIF中引用了customAttribute1至customAttribute15,但这些自定义属性尚未在Schema中定义,直接添加对象类会报错。需要先添加这些属性的定义,示例LDIF如下:
dn: cn=schema,cn=config changetype: modify add: olcAttributeTypes olcAttributeTypes: ( 1.2.3.4.5.6.7.8.9.1 NAME 'customAttribute1' DESC '自定义属性1' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 ) olcAttributeTypes: ( 1.2.3.4.5.6.7.8.9.2 NAME 'customAttribute2' DESC '自定义属性2' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 ) # 依次添加customAttribute3到customAttribute15,每个属性使用唯一的OID(1.2.3.4.5.6.7.8.9.3至1.2.3.4.5.6.7.8.9.15)
执行完属性定义的修改后,再执行对象类的添加操作。
Apache Directory Studio的操作方式
可以通过Apache Directory Studio完成程序化添加:
- 连接到OpenLDAP服务器时,选择使用
EXTERNAL认证(需要启动Studio的用户是系统root,或在Linux下用sudo运行Studio);或者使用cn=admin,cn=config账号登录。 - 找到
cn=schema,cn=config条目,右键选择"Modify Entry",添加olcAttributeTypes和olcObjectClasses属性,填入对应的定义内容后提交即可。
内容的提问来源于stack exchange,提问作者VladC
相关产品推荐
相关产品推荐

