LLOADD.CONF(5) File Formats Manual LLOADD.CONF(5) (NAME) lloadd.conf - LDAP (lloadd) (SYNOPSIS) /etc/openldap/lloadd.conf (DESCRIPTION) /etc/openldap/lloadd.conf lloadd(8) . lloadd.conf lloadd ( ) . . lloadd.conf : # # slapd : backend lload listen # - # tier # backend-server # / ... (tier) . . . `#' . : (unwrap ). . . (`"') (`\') . . lloadd << OpenLDAP>> . SLAPD (SLAPD INTEGRATION) lloadd slapd slapd.conf(5) slapd lloadd slapd.conf(5) cn=config . TLSShareSlapdCTX lloadd (context) TLS . slapd : listen (URI) . slapd . cn=config olcBkLloadListen URI . . (GLOBAL DIRECTIVES) . <> . argsfile () lloadd ( ) . concurrency . (hint) . . feature [...] LDAP . : proxyauthz (RFC 4370) . (bound) bindconf ( DN ). SASL bind ?LDAP Who Am I . include . io-threads (threads) . CPU . . . logfile lloadd . stderr logfile-format debug | syslog-utc | syslog-localtime . debug slapd . syslog(3) UTC . debug . loglevel . logfile stderr . logfile-only on | off stderr . logfile-rotate . . Mbytes hours . Mbytes hours . . loglevel [...] syslog ( LOG_LOCAL4 syslogd(8) ). . loglevel . : 1 (0x1 trace) 2 (0x2 packets) 4 (0x4 args) ( ) 8 (0x8 conns) 16 (0x10 BER) 64 (0x40 config) 256 (0x100 stats) LDAP () 512 (0x200 stats2) 32768 (0x8000 none) (OR) ( OR ) : loglevel 513 loglevel 0x201 loglevel 512 1 loglevel 0x200 0x1 loglevel stats trace . any ( -1). none loglevel . loglevel 0 none . loglevel stats . . pidfile () lloadd ( getpid(2)). sockbuf_max_incoming_client PDU LDAP . . sockbuf_max_incoming_upstream PDU LDAP . . tcp-buffer [listener=] [{read|write}=] TCP . TCP read write . tcp(7) . TCP . threads (thread pool) . . threadqueues . CPU . CPU . max_pdus_per_cycle 0 PDU I/O . PDU I/O . . . client_max_pending . 0 . iotimeout . . iotimeout 0 . . write_coherence lloadd . ( exop abandon) (search) (compare) (bind). . 0 . . restrict_exop lloadd OID . OID 1.1 ( ). restrict_control . restrict_control lloadd OID . bind . ( ) : reject . connection . (state) . backend write (time out ). write ( write_coherence ). ignore exop . exop/ . TLS (TLS OPTIONS) lloadd (TLS) . TLSShareSlapdCTX { on | off } no () lloadd TLS ( lloadd cn=config ). slapd TLS slapd . . slapd(8) TLS cn=config TLSShareSlapdCTX . TLSCipherSuite . TLS (OpenSSL GnuTLS Mozilla NSS) . : OpenSSL: TLSCipherSuite HIGH:MEDIUM:+SSLv2 GnuTLS: TLSCiphersuite SECURE256:!AES-128-CBC OpenSSL : openssl ciphers -v GnuTLS gnutls-cli(1) ( --priority ). GnuTLS gnutls-cli --priority -- -- : gnutls-cli -l Mozilla NSS OpenSSL Mozilla NSS . . Mozilla NSS sslinfo.c : static const SSLCipherSuiteInfo suiteInfo[] TLSCACertificateFile (CA) lloadd . . CA () CA CA CA . . TLSCACertificatePath . TLSCACertificateFile . GnuTLS . Mozilla NSS / Mozilla NSS . / Mozilla NSS CA OpenLDAP / CA . TLSCertificateFile lloadd . Mozilla NSS / ( TLSCACertificatePath) TLSCertificateFile : TLSCertificateFile Server-Cert : TLSCertificateFile my hardware device:Server-Cert certutil -L : certutil -d /path/to/certdbdir -L TLSCertificateKeyFile lloadd TLSCertificateFile . . Mozilla NSS TLSCertificateKeyFile TLSCertificateFile . modutil / . TLSCACertificatePath /etc/openldap/certdb / modutil : modutil -dbdir /etc/openldap/certdb -changepw 'NSS Certificate DB' ( ) . . 'Enter' . TLSDHParamFile - (Diffie- Hellman ephemeral) . DSA RSA "key encipherment" . - . . "!ADH" . Mozilla NSS . TLSECName - (ECDHE) . ECDHE OpenSSL . GnuTLS ciphersuite GnuTLS . Mozilla NSS . TLSProtocolMin [.] SSL/TLS . SSL . TLS 1.x 3.(x+1) : TLSProtocolMin 3.2 TLS 1.1 . OpenLDAP . GnuTLS . TLSRandFile /dev/[u]random . EGD/PRNGD . RANDFILE . GnuTLS Mozilla NSS . TLSVerifyClient ( ) TLS . : never . lloadd . allow . . . try . . . demand | hard | true . . . TLSCRLCheck (CRL) CA . TLSCACertificatePath . GnuTLS Mozilla NSS . : none CRL peer CRL (peer) all CRL TLSCRLFile . GnuTLS Mozilla NSS . (BACKEND CONFIGURATION) lloadd . ( tiers). . (busy) . ( ) . . bindconf . . bindconf [bindmethod=simple|sasl] [binddn=] [saslmech=] [authcid=] [authzid=] [credentials=] [realm=] [secprops=] [timeout=] [network-timeout=] [keepalive=::] [tcp-user-timeout=] [tls_cert=] [tls_key=] [tls_cacert=] [tls_cacertdir=] [tls_reqcert=never|allow|try|demand] [tls_cipher_suite=] [tls_crlcheck=none|peer|all] [tls_protocol_min=[.]] lloadd . bindmethod simple binddn credentials ( TLS IPSEC) . : simple bind (cleartext) ! bindmethod sasl saslmech . / authcid credentials . authzid . ( sasl-secprops ) bind SASL secprops . (realm) SASL realm . timeout ( ...) . timeout . network-timeout . timeout Bind . Timeout 0 . keepalive idle probes interval idle keepalive TCP probes keepalive TCP interval keepalive . keepalive . tcp-user-timeout TCP_USER_TIMEOUT . . (TIER OPTIONS) tier . . . : roundrobin . weighted weight= . 0 . RFC2782 . bestof weighted weight= . weight . () . ( ) round-robin . weighted <<>> . (BACKEND DIRECTIVES) backend-server uri=ldap[s]://[:port] [retry=] [starttls=yes|critical] [numconns=] [bindconns=] [max-pending-ops=] [conn-max-pending=] . uri LDAP URI . LDAP ( ) . Lloadd numconns bindconns bind . lloadd retry ( ) . (upstreams ) . conn-max-pending 0 () . max-pending-ops 0 . starttls StartTLS TLS (Binding) . critical StartTLS . syncrepl TLS . tls_reqcert "demand" TLS TLS slapd . (EXAMPLES) : argsfile /var/lib/openldap/run/lloadd.args pidfile /var/lib/openldap/run/lloadd.pid # cancel restrict_exop 1.3.6.1.1.8 reject # turn restrict_exop 1.3.6.1.1.19 reject # TXN Exop reject restrict_exop 1.3.6.1.1.21.1 connection # Paged results restrict_control 1.2.840.113556.1.4.319 connection # VLV restrict_control 2.16.840.1.113730.3.4.9 connection bindconf bindmethod=simple binddn=cn=test credentials=pass tier weighted backend-server uri=ldap://ldap1.example.com numconns=3 bindconns=2 retry=5000 max-pending-ops=5 conn-max-pending=3 weight=5 backend-server uri=ldap://ldap2.example.com numconns=3 bindconns=2 retry=5000 max-pending-ops=5 conn-max-pending=3 weight=10 <> . /etc/openldap/lloadd.conf . (LIMITATIONS) SASL Binds EXTERNAL ( DN TLS ) ( Kerberos ) / SASL ( Kerberos DIGEST-MD5 ). (FILES) /etc/openldap/lloadd.conf lloadd (SEE ALSO) ldap(3) gnutls-cli(1) slapd.conf(5) tcp(7) lloadd(8) slapd(8). "OpenLDAP Administrator's Guide" (http://www.OpenLDAP.org/doc/admin) (ACKNOWLEDGEMENTS) OpenLDAP OpenLDAP . OpenLDAP LDAP 3.3 . OpenLDAP 2.6.13 2026/03/09 LLOADD.CONF(5)