如何通过C语言OpenLDAP库API为现有user对象类新增phoneNumber属性
phoneNumber attribute to my custom user object class via OpenLDAP APIs without editing schema files directly? Question
I'm developing an Identity and Access Management (IAM) application in C, using OpenLDAP to store user details. The library provides APIs for operations like bind, add, search, modify. I've created the following custom
userobject class:attributetype ( 2.5.4.1 NAME 'id' DESC 'RFC2256: user identifier' EQUALITY caseIgnoreMatch SUBSTR caseIgnoreSubstringsMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{32768} ) attributetype ( 2.5.4.2 NAME 'name' DESC 'RFC2256: user name' EQUALITY caseIgnoreMatch SUBSTR caseIgnoreSubstringsMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{32768} ) attributetype ( 2.5.4.3 NAME 'email' DESC 'RFC2256: user mail address' EQUALITY caseIgnoreMatch SUBSTR caseIgnoreSubstringsMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{32768} ) objectclass ( 2.5.4.4 NAME 'user' DESC 'user details' SUP top STRUCTURAL MUST id MAY ( name $ email ) )I want to know if it's possible to add a
phoneNumberattribute to thisuserobject class using OpenLDAP APIs, without directly editing the schema files.
Answer
Absolutely! OpenLDAP supports dynamic schema modifications through its C APIs, so you don’t need to manually edit schema files to update your custom user object class. Here’s a step-by-step breakdown of how to do it:
1. Ensure the phoneNumber attribute type exists
First, check if the standard phoneNumber attribute (OID 2.5.4.20, defined in RFC 2256) is already available in your OpenLDAP server. If it is, you can skip this step. If not, you’ll need to add it to the schema via an ldap_add_ext_s call:
#include <ldap.h> #include <stdlib.h> #include <string.h> int addPhoneNumberAttribute(LDAP *ld, const char *rootDN, const char *rootPW) { // Bind as a privileged user (rootDN) to modify schema int rc = ldap_simple_bind_s(ld, rootDN, rootPW, LDAP_AUTH_SIMPLE); if (rc != LDAP_SUCCESS) { ldap_perror(ld, "Failed to bind as privileged user"); return rc; } // Define the phoneNumber attribute type entry const char *attrEntry[] = { "objectClass: top", "objectClass: attributeType", "cn: phoneNumber", "attributeType: ( 2.5.4.20 NAME 'phoneNumber' " "DESC 'RFC2256: Telephone Number' " "EQUALITY caseIgnoreMatch " "SUBSTR caseIgnoreSubstringsMatch " "SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{32768} )", NULL }; // Add the attribute to the schema entry rc = ldap_add_ext_s(ld, "cn=schema", attrEntry, NULL, NULL, NULL); if (rc != LDAP_SUCCESS) { ldap_perror(ld, "Failed to add phoneNumber attribute"); } return rc; }
2. Update your custom user object class to include phoneNumber
Next, use the ldap_modify_ext_s API to update your existing user object class, adding phoneNumber to its list of allowed (MAY) attributes:
int updateUserObjectClass(LDAP *ld, const char *rootDN, const char *rootPW) { // Bind as privileged user (if not already bound) int rc = ldap_simple_bind_s(ld, rootDN, rootPW, LDAP_AUTH_SIMPLE); if (rc != LDAP_SUCCESS) { ldap_perror(ld, "Failed to bind as privileged user"); return rc; } // Define the modification: replace the objectClass definition with the updated version LDAPMod mod = {0}; mod.mod_op = LDAP_MOD_REPLACE; mod.mod_type = "objectClass"; mod.mod_values = (char**)malloc(2 * sizeof(char*)); mod.mod_values[0] = strdup("( 2.5.4.4 NAME 'user' DESC 'user details' SUP top STRUCTURAL MUST id MAY ( name $ email $ phoneNumber ) )"); mod.mod_values[1] = NULL; LDAPMod *mods[] = {&mod, NULL}; // Perform the modification on the user object class entry rc = ldap_modify_ext_s(ld, "cn=user,cn=schema", mods, NULL, NULL); if (rc != LDAP_SUCCESS) { ldap_perror(ld, "Failed to update user object class"); } // Clean up allocated memory free(mod.mod_values[0]); free(mod.mod_values); return rc; }
Key Notes
- Permissions: You must bind as a user with schema modification privileges (typically the OpenLDAP rootDN or a user with access to
cn=config). - Existing Users: After updating the schema, you can add the
phoneNumberattribute to existing user entries using standardldap_modifyoperations. - Schema Consistency: Make sure the
phoneNumberattribute’s syntax matches the requirements of youruserobject class (in this case, it uses the same string syntax as your other attributes, so it’s compatible).
内容的提问来源于stack exchange,提问作者Ajith C Narayanan

