SLAPD-CONFIG(5) (NAME) slapd-config - cn=config slapd (SYNOPSIS) /etc/ldap/slapd.d (DESCRIPTION) slapd-config slapd cn=config . config slapd(8) . SLAPD slapacl(8) slapadd(8) slapauth(8) slapcat(8) slapdn(8) slapindex(8) slapmodify(8) slaptest(8) . config slapd.conf(5) . slapd slapd.conf . slapd slapd.d . config . cn=config slapd . : cn=Module cn=Schema olcBackend=xxx olcDatabase=xxx cn=Module slapd . . . . cn=Schema . . include include . cn=core,cn=schema,cn=config . olcBackend ( ) . back-mdb . olcDatabase . olcOverlay . olcDatabase olcOverlay . - config "frontend" . frontend (override) . . LDAP . LDAP slapd.conf "olc" . (parser) slapd.conf . slapd.conf . LDAP . slapd-(5) . slapd " OpenLDAP" . (GLOBAL CONFIGURATION OPTIONS) . <> . cn=config . (objectClass) olcGlobal . olcAllows: ( ). bind_v2 bind LDAPv2 . slapd(8) LDAPv2 ( RFC 1777 RFC 3494 ) . bind_anon_cred ( DN ) . bind_anon_dn () DN . update_anon () ( ). proxy_authz_anon () ( ). olcArgsFile: () slapd ( ) . olcAttributeOptions: ... / . `-' `-' . `lang-' . olcAttributeOptions `lang-' . . . `lang-' : . `x-foo-' `x-foo-bar' . ( `-' ) `-' . `x-foo-bar-' `x-foo-bar' `x-foo-bar-baz' . RFC 4520 `x-' . IANA . RFC 4520 . OpenLDAP `binary' . olcAuthIDRewrite: DN LDAP . olcAuthzRegexp ( ) . rewrite-rule slapo-rwm(5) ( rwm-). olcAuthIDRewrite olcAuthzRegexp . olcAuthzPolicy: (Proxy Authorization) . . A B A . none . . from authzFrom DN . to authzTo DN . any both ( to from). all . . authzFrom . authzTo . authzTo . authzTo (ACL) . authzFrom authzTo : ldap:///??[]? dn[.]: u[.[]]: group[/objectClass[/attributeType]]: :={exact|onelevel|children|subtree|regex} URI LDAP : authzFrom authzTo . DN exact onelevel children subtree DN regex () POSIX regex(7) re_format(7) . * DN . id SASL SASL (realm) SASL . . . group objectClass attributeType . objectClass groupOfNames . attributeType member . DN (base scope) objectClass . attributeType DN . . DN DN . authzFrom authzTo . olcAuthzRegexp ( ) URI ( ) dn.exact:. olcAuthzRegexp: SASL SASL EXTERNAL " " RFC 4370 DN LDAP . DN . SASL USERNAME REALM MECHANISM SASL : UID=[[,CN=],CN=],CN=auth () POSIX match replace . (wildcard) match : UID=([^,]*),CN=.* $1 . $2 $3 $9 . replace : UID=$1,OU=Accounts,DC=example,DC=com DN "dn:" URI LDAP. URI () DN . URI LDAP hostport attrs extensions : ldap:///OU=Accounts,DC=example,DC=com??one?(UID=$1) URI ldap . . "auth" . olcAuthzRegexp . . olcConcurrency: . (hint) . . . olcConnMaxPending: . . . 100 . olcConnMaxPendingAuth: . 1000 . olcDisallows: ( ). bind_anon . ( "require authc" ). bind_simple (bind) . tls_2_anon StartTLS ( tls_authc ). tls_authc StartTLS ( tls_2_anon ). proxy_authz_non_critical (RFC 4370) FALSE . dontusecopy_non_critical dontUseCopy ( ) FALSE . olcGentleHUP: { TRUE | FALSE } SIGHUP '' : Slapd . unwilling-to-perform . Slapd ( ) - - SIGTERM . slapd . FALSE . olcIdleTimeout . olcIdleTimeout: (idle) . 0 . 0 . olcWriteTimeout . olcIndexHash64: { TRUE | FALSE } . . . . ( .) . . . olcIndexIntLen: . . 4 . . olcIndexSubstrIfMaxlen: (subinitial subfinal) . . 4 . olcIndexSubstrIfMinlen: . . 2 . olcIndexSubstrAnyLen: subany . . . 4 . subany subinitial subfinal olcIndexSubstrIfMaxlen . olcIndexSubstrAnyStep: subany . subany . 2 . "cn=*abcdefgh*" "abcd" "cdef" "efgh" . : . slapindex(8) . olcListenerThreads: . 1 CPU . . olcLocalSSF: (SSF) LDAP ldapi:// . SSF minssf olcSaslSecProps . 71 . olcLogFile: slapd . olcLogLevel . slapd . stderr . stderr . olcLogFileFormat: debug|syslog-utc|syslog-localtime|rfc3339-utc . debug slapd . syslog(3) UTC . debug . olcLogFileOnly: TRUE | FALSE stderr . olcLogFileRotate: . . Mbytes hours . Mbytes hours . . olcLogLevel: [...] syslog ( LOG_LOCAL4 syslogd(8) ). . loglevel . : 1 (0x1 trace) 2 (0x2 packets) 4 (0x4 args) ( ) 8 (0x8 conns) 16 (0x10 BER) 32 (0x20 filter) 64 (0x40 config) 128 (0x80 ACL) 256 (0x100 stats) LDAP () 512 (0x200 stats2) stats2 1024 (0x400 shell) 2048 (0x800 parse) 16384 (0x4000 sync) LDAPSync 32768 (0x8000 none) (OR) ( OR ) : olcLogLevel: 129 olcLogLevel: 0x81 olcLogLevel: 128 1 olcLogLevel: 0x80 0x1 olcLogLevel: acl trace . any ( -1). none olcLogLevel . olcLogLevel ( 0 ) none . packets BER parse stderr syslog . stats . . olcMaxFilterDepth: . 1000 . olcPasswordCryptSaltFormat: (salt) crypt(3) {CRYPT} ( olcPasswordHash ) LDAP (RFC 3062) . sprintf(3) ( ) %s . [A-Za-z0-9./] . "%.2s" "$1$%.8s" crypt(3) MD5 . "%s" . olcPidFile: () (PID) slapd ( getpid(2) ). olcPluginLogFile: () SLAPI . slapd.plugin(5) . olcReferral: slapd(8) . url . olcReverseLookup: TRUE | FALSE / ( FALSE --enable-rlookups ). olcRootDSE: LDIF(5) DSE . slapd . DSE . DN : ldapsearch -x -b "" -s base "+" . RFC 4512 . olcSaslAuxprops: [...] auxprop . slapd . auxprop . olcSaslAuxpropsDontUseCopy: [...] () don't use copy . SASL OTP (replicated) . "cmusaslsecretOTP" . olcSaslAuxpropsDontUseCopyIgnore TRUE | FALSE () olcSaslAuxpropsDontUseCopy . SASL . . FALSE . olcSaslHost: (FQDN) SASL . olcSaslRealm: (realm) SASL . . olcSaslCbinding: none | tls-unique | tls-endpoint (channel-binding) LDAP_OPT_X_SASL_CBINDING . none . olcSaslSecProps: Cyrus SASL . none ( ) "noanonymous,noplain" . noplain . noactive . nodict . noanonymous . forwardsec (forward secrecy) . passcred ( ). minssf= (SSF) . 0 () 1 128 RC4 Blowfish 256 . 0 . maxssf= ( minssf ). INT_MAX . maxbufsize= . 0 . 65536 . olcServerID: [] 0 4095 . "0x" . (multi- provider) . (glued) . URL . URL . " " (replica id) CSN . . : olcServerID: 1 ldap://ldap1.example.com olcServerID: 2 ldap://ldap2.example.com olcSockbufMaxIncoming: PDU LDAP . 262143 . olcSockbufMaxIncomingAuth: PDU LDAP . 4194303 . olcTCPBuffer [listener=] [{read|write}=] TCP . TCP . tcp(7) . TCP . olcThreads: (primary thread pool) . 16 2 . olcThreadQueues: . 1 CPU . CPU . olcToolThreads: (tool mode) . CPU . 1 . olcWriteTimeout: . (hang) . 0 . 0 . TLS (TLS OPTIONS) slapd (TLS) . olcTLSCipherSuite: . TLS (OpenSSL GnuTLS) . : OpenSSL: olcTLSCipherSuite: HIGH:MEDIUM:+SSLv2 GnuTLS: olcTLSCiphersuite: SECURE256:!AES-128-CBC OpenSSL : openssl ciphers -v GnuTLS gnutls-cli(1) ( --priority ). GnuTLS gnutls-cli --priority : gnutls-cli -l olcTLSCACertificateFile: (CA) slapd . . () CA CA CA . . olcTLSCACertificatePath: . olcTLSCACertificateFile . . (semi-colon) . olcTLSCACertificate: CA DER . olcTLSCACertificateFile olcTLSCACertificatePath . CA olcTLSCACertificateFile olcTLSCACertificatePath . olcTLSCertificateFile: slapd . OpenSSL . olcTLSCertificate: DER . olcTLSCertificateFile . olcTLSCertificateKeyFile: slapd . slapd . slapd . olcTLSCertificateKey . olcTLSCertificateKeyFile . olcTLSDHParamFile: - (Diffie- Hellman ephemeral) . DSA RSA "key encipherment" . - . (man-in-the-middle) . "!ADH" . olcTLSECName: () - (ECDHE) . OpenSSL . GnuTLS ciphersuite GnuTLS . olcTLSProtocolMin: [.] SSL/TLS . SSL . TLS 1.x 3.(x+1) : olcTLSProtocolMin: 3.2 TLS 1.1 . OpenLDAP . GnuTLS . olcTLSRandFile: /dev/[u]random . EGD/PRNGD . RANDFILE . GnuTLS . olcTLSVerifyClient: ( ) TLS . : never . slapd . allow . . . try . . . demand | hard | true . . . SASL EXTERNAL TLS . SASL EXTERNAL olcTLSVerifyClient . olcTLSCRLCheck: (CRL) CA . olcTLSCACertificatePath . GnuTLS . : none CRL . peer CRL . all CRL . olcTLSCRLFile: . GnuTLS . (DYNAMIC MODULE OPTIONS) slapd --enable-modules . cn=module{x},cn=config olcModuleList . olcModulePath . "{x}" RDN . olcModuleLoad: [...] . . olcModulePath . olcModulePath: . (colon) . /usr/lib/ldap OpenLDAP . (SCHEMA OPTIONS) cn=schema,cn=config . olcSchemaConfig . cn=schema,cn=config . olcAttributetypes: ( [NAME ] [DESC ] [OBSOLETE] [SUP ] [EQUALITY ] [ORDERING ] [SUBSTR ] [SYNTAX ] [SINGLE-VALUE] [COLLECTIVE] [NO-USER-MODIFICATION] [USAGE ] ) LDAPv3 RFC 4512 . slapd OID OID OID RFC 4512 ( olcObjectIdentifier ). olcDitContentRules: ( [NAME ] [DESC ] [OBSOLETE] [AUX ] [MUST ] [MAY ] [NOT ] ) DIT LDAPv3 RFC 4512 . slapd OID OID OID RFC 4512 ( olcObjectIdentifier ). olcLdapSyntaxes ( [DESC ] [X-SUBST ] ) LDAP LDAPv3 RFC 4512 . slapd OID OID RFC 4512 ( objectidentifier ). slapd X-SUBST ( OpenLDAP) olcLdapSyntaxes ( substitute-syntax) . substitute-syntax . OID . X-SUBST . olcObjectClasses: ( [NAME ] [DESC ] [OBSOLETE] [SUP ] [{ ABSTRACT | STRUCTURAL | AUXILIARY }] [MUST ] [MAY ] ) LDAPv3 RFC 4512 . slapd OID OID RFC 4512 ( olcObjectIdentifier ). "STRUCTURAL" . olcObjectIdentifier: { | [:] } OID . OID . ":xx" "oid.xx" . (GENERAL BACKEND OPTIONS) . back-mdb . olcBackend=,cn=config olcBackendConfig . : asyncmeta config dnssrv ldap ldif mdb meta monitor null passwd perl relay sock sql wt. back-mdb . (DATABASE OPTIONS) olcDatabase={x},cn=config olcDatabaseConfig . "{x}" RDN . frontend "{-1}" config "{0}" . (GLOBAL DATABASE OPTIONS) "frontend" . . frontend olcDatabase=frontend,cn=config olcFrontendConfig . olcAccess: to [ by ]+ ( ) / ( ) ( ). rootdn (: "olcAccess: to * by * read"). slapd.access(5) " OpenLDAP" . frontend () . rootdn . config . config rootdn . . olcDefaultSearchBase: DN . DN . frontend . olcExtraAttrs: . frontend . frontend ACL . . . . olcPasswordHash: [...] userPassword LDAP (RFC 3062) . {SSHA} {SHA} {SMD5} {MD5} {CRYPT} {CLEARTEXT} . {SSHA} . {SHA} {SSHA} SHA-1 (FIPS 160-1) (seed) . {MD5} {SMD5} MD5 (RFC 1321) . {CRYPT} crypt(3) . {CLEARTEXT} userPassword . userPassword Add Modify LDAP . frontend . olcReadOnly: TRUE | FALSE "" . "unwilling to perform" . olcReadOnly FALSE . frontend TRUE config . olcRequires: ( ). / . bind (bind) . LDAPv3 LDAP . authc . SASL SASL . strong . strong "" SASL . none ( ) . olcRestrict: . frontend . add bind compare delete extended[=] modify rename search read write . restrict write olcReadOnly: TRUE ( ). extended OID . olcSchemaDN: (DN) subschema . "cn=Subschema" . olcSecurity: ( ) ( minssf olcSaslSecprops ). / . ssf= . transport= . tls= TLS . sasl= SASL . update_ssf= . update_transport= . update_tls= TLS . update_sasl= SASL . simple_bind= / . transport ldapi:// ( IPSEC). . olcSizeLimit: {|unlimited} olcSizeLimit: size[.{soft|hard}]= [...] . 500 . unlimited . . (soft) (hard) . . olcLimits . olcSortVals: [...] . Modify Compare . . frontend . olcTimeLimit: {|unlimited} olcTimeLimit: time[.{soft|hard}]= [...] ( ) slapd . 3600 . unlimited . . . olcLimits . (GENERAL DATABASE OPTIONS) . . . olcAddContentAcl: TRUE | FALSE Add ACL . . ACL Add slapd.access(5) . olcHidden: TRUE | FALSE . (suffix) . olcHidden FALSE . olcLastMod: TRUE | FALSE slapd modifiersName modifyTimestamp creatorsName createTimestamp . entryCSN entryUUID syncrepl . olcLastMod TRUE . olcLastBind: TRUE | FALSE slapd pwdLastSuccess . olcLastBind FALSE . olcLastBindPrecision: olcLastBind pwdLastSuccess . integer . bind . olcLimits: [ [...]] DN . : anonymous | users | [=] | group[/oc[/at]]= : ::= dn[.][.