You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

基于PostgreSQL的OpenLDAP Back-SQL:如何添加mail属性

OpenLDAP Back-SQL 后端属性配置问题解决方案

一、mail/description 属性不显示的排查修复

  • 先检查表结构:确保PostgreSQL里的persons表已经添加mail和description字段,字段类型要匹配(比如mail用varchar(255),description用text)。直接执行SQL确认:
    ALTER TABLE persons ADD COLUMN mail varchar(255);
    ALTER TABLE persons ADD COLUMN description text;
    
  • 核对属性映射:在back-sql的sql.conf(或你的映射配置文件)中,必须添加这两个属性的映射条目,格式不能错:
    attribute mail,mail,1,2,mail
    attribute description,description,1,2,description
    
    格式说明:attribute <LDAP属性名>,<SQL列名>,<是否单值>,<是否必填>,<对应表列>,1代表单值,2代表可选。
  • 确认schema加载顺序:core.schema和inetorgperson.schema必须正确加载,且core在前。查看slapd.conf或cn=config配置,确保包含:
    include /etc/openldap/schema/core.schema
    include /etc/openldap/schema/inetorgperson.schema
    
  • 重启服务刷新配置:修改配置后,重启slapd服务:systemctl restart slapd(或用slapd -u ldap -g ldap启动)。
  • 检查数据库数据:直接查询PostgreSQL的persons表,确保目标用户的mail和description字段有值——空值的话LDAP不会返回该属性。

二、mobile 属性添加报错的修复

  • 核对mobile映射配置:InetOrgPerson中的mobile是单值电话属性,sql.conf里的映射要这么写:
    attribute mobile,mobile,1,2,mobile
    
  • 检查表字段类型:persons表的mobile字段设为varchar(20)足够存储电话号码,执行:
    ALTER TABLE persons ADD COLUMN mobile varchar(20);
    
  • 解决对象类冲突:如果报错是object class violation,说明用户条目未添加inetOrgPerson对象类。用ldapmodify补加:
    ldapmodify -x -D cn=admin,dc=example,dc=com -W
    dn: uid=testuser,ou=people,dc=example,dc=com
    changetype: modify
    add: objectClass
    objectClass: inetOrgPerson
    
  • 确认对象类映射:sql.conf里要把inetOrgPerson映射到persons表,条目如下:
    objectclass inetOrgPerson,inetOrgPerson,1,2,persons
    

三、通用验证步骤

  • 用ldapsearch测试:执行命令查询用户条目,查看返回的属性:
    ldapsearch -x -b dc=example,dc=com uid=testuser
    
    要是仍不显示,开启slapd调试日志(slapd -d 256),查看查询时生成的SQL语句,确认Back-SQL是否正确查询了对应字段。
  • 检查ACL权限:确保ACL允许读取这些属性,比如在配置中添加:
    access to attrs=mail,description,mobile
      by self write
      by users read
      by * none
    

内容的提问来源于stack exchange,提问作者LMO

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.25 16:24:31