SLAPD.CONF(5) File Formats Manual SLAPD.CONF(5) (NAME) slapd.conf - slapd LDAP (SYNOPSIS) /etc/openldap/slapd.conf (DESCRIPTION) /etc/openldap/slapd.conf slapd(8) . SLAPD slapacl(8) slapadd(8) slapauth(8) slapcat(8) slapdn(8) slapindex(8) slapmodify(8) slaptest(8) . slapd.conf slapd ( ) . (case-insensitive) . slapd.conf : # comment - these options apply to every database # first database definition & configuration options database # subsequent database definitions & configuration options ... . ( slapd.conf ). . . `#' . : (unwrap ). . . (`"') (`\') . . slapd-(5) . slapd << OpenLDAP>> . (GLOBAL CONFIGURATION OPTIONS) . <> . access to [ by ]+ ( ) / ( ) ( ). rootdn . ( "access to * by * read"). rootdn ! slapd.access(5) << OpenLDAP>> . allow ( ) ( ). bind_v2 LDAPv2 . slapd(8) LDAPv2 ( RFC 1777 RFC 3494 ) . bind_anon_cred ( DN ) . bind_anon_dn () DN . update_anon () ( ). proxy_authz_anon () ( ). argsfile () slapd ( ) . attributeoptions [option-name]... / . `-' `-' . `lang-' . attributeoptions `lang-' . . . `lang-' : . `x-foo-' `x-foo-bar' . ( `-' ) `-' . `x-foo-bar-' `x-foo-bar' `x-foo-bar-baz' . RFC 4520 `x-' . IANA . RFC 4520 . OpenLDAP `binary' . attributetype ( [NAME ] [DESC ] [OBSOLETE] [SUP ] [EQUALITY ] [ORDERING ] [SUBSTR ] [SYNTAX ] [SINGLE-VALUE] [COLLECTIVE] [NO-USER-MODIFICATION] [USAGE ] ) LDAPv3 RFC 4512 . slapd OID OID OID RFC 4512 . ( objectidentifier .) authid-rewrite DN LDAP . authz-regexp ( ) . authid- slapo-rwm(5) ( rwm- authid- ). authid-rewrite authz-regexp . authz-policy (Proxy Authorization) . . A A B . none . . from authzFrom DN . to authzTo DN . any both ( to from ). all . . authzFrom . authzTo . authzTo . authzTo (ACL) . authzFrom authzTo : ldap:///??[]? dn[.]: u[.[/]]: group[/objectClass[/attributeType]]: :={exact|onelevel|children|subtree|regex} URI LDAP : authzFrom authzTo . DN . dnstyle exact onelevel children subtree DN . dnstyle regex (<<>>) POSIX regex(7) / re_format(7) . * DN . id SASL . SASL (realm) SASL . . . group objectClass attributeType . objectClass groupOfNames . attributeType member . DN (base scope) objectClass . attributeType DN . . DN DN . authzFrom authzTo . authz-regexp ( ) URI dn.exact:. authz-regexp SASL SASL EXTERNAL << >> RFC 4370 DN LDAP . DN . SASL USERNAME REALM MECHANISM SASL : UID=[[,CN=],CN=],CN=auth (<<>>) POSIX match replace . (wildcard) match : UID=([^,]*),CN=.* $1 . $2 $3 $9 . replace : UID=$1,OU=Accounts,DC=example,DC=com DN "dn:" URI LDAP. URI () DN . URI LDAP hostport attrs extensions : ldap:///OU=Accounts,DC=example,DC=com??one?(UID=$1) URI ldap . . "auth" . authz-regexp . . concurrency . (hint) . . . conn_max_pending . . . 100 . conn_max_pending_auth . 1000 . defaultsearchbase (non-base) DN . DN . disallow ( ) ( ). bind_anon . ( "require authc" ). bind_simple () . tls_2_anon StartTLS ( tls_authc ). tls_authc StartTLS ( tls_2_anon ). proxy_authz_non_critical (RFC4370) (criticality) FALSE . dontusecopy_non_critical dontUseCopy ( ) FALSE . ditcontentrule ( [NAME ] [DESC ] [OBSOLETE] [AUX ] [MUST ] [MAY ] [NOT ] ) DIT ( DIT Content Rule) LDAPv3 RFC 4512 . slapd OID OID OID RFC 4512 . ( objectidentifier .) gentlehup { on | off } SIGHUP <<>> : Slapd . unwilling-to-perform . Slapd ( ) - - SIGTERM . slapd . off . idletimeout . idletimeout (idle) . 0 . 0 . writetimeout . include . index_hash64 { on | off } . . . . ( .) . . . index_intlen . . 4 . . index_substr_if_maxlen (subinitial subfinal) . . 4 . index_substr_if_minlen . . 2 . index_substr_any_len subany . . . 4 . subany subinitial subfinal index_substr_if_maxlen . index_substr_any_step subany . subany . 2 . "cn=*abcdefgh*" "abcd" "cdef" "efgh" . : . slapindex(8) . ldapsyntax ( [DESC ] [X-SUBST ] ) LDAP LDAPv3 RFC 4512 . slapd OID OID RFC 4512 . ( objectidentifier .) slapd X-SUBST ( OpenLDAP) ldapsyntax substitute-syntax . substitute-syntax . OID . X-SUBST . listener-threads (threads) . . . localSSF (SSF) LDAP ldapi:// . SSF minssf sasl-secprops . . logfile slapd . loglevel . slapd . stderr . logfile stderr . logfile-format debug|syslog-utc|syslog-localtime|rfc3339-utc . debug slapd (thread ID) . syslog(3) UTC . debug . logfile-only on | off stderr . logfile-rotate (rotation) . . Mbytes hours . Mbytes hours . . loglevel [...] syslog ( LOG_LOCAL4 syslogd(8) ). . loglevel . (additive) : 1 (0x1 trace) (trace) 2 (0x2 packets) 4 (0x4 args) ( ) 8 (0x8 conns) 16 (0x10 BER) 32 (0x20 filter) 64 (0x40 config) 128 (0x80 ACL) (ACL) 256 (0x100 stats) LDAP () 512 (0x200 stats2) stats2 1024 (0x400 shell) (shell backends) 2048 (0x800 parse) (entry parsing) 16384 (0x4000 sync) LDAPSync 32768 (0x8000 none) ( OR ) ( OR ) loglevel 129 loglevel 0x81 loglevel 128 1 loglevel 0x80 0x1 loglevel acl trace . any ( -1) . none loglevel . loglevel none . packets BER parse stderr syslog . loglevel stats . . maxfilterdepth . . moduleload [...] . . modulepath . modulepath slapd --enable-modules . modulepath . (colon) . /usr/lib/openldap OpenLDAP . objectclass ( [NAME ] [DESC ] [OBSOLETE] [SUP ] [{ ABSTRACT | STRUCTURAL | AUXILIARY }] [MUST ] [MAY ] ) objectclass LDAPv3 RFC 4512 . slapd RFC 4512 OID OID (object class OID) . ( objectidentifier .) "STRUCTURAL" . objectidentifier { | [:] } OID . OID objectclass . ":xx" "oid.xx" . password-hash [...] (hash) userPassword LDAP ( RFC 3062) . {SSHA} {SHA} {SMD5} {MD5} {CRYPT} {CLEARTEXT} . {SSHA} . {SHA} {SSHA} SHA-1 ( FIPS 160-1) seed () . {MD5} {SMD5} MD5 ( RFC 1321) seed . {CRYPT} crypt(3) . {CLEARTEXT} (clear text) userPassword . userPassword LDAP Add Modify LDAP . password-crypt-salt-format (salt) crypt(3) {CRYPT} ( password-hash) LDAP ( RFC 3062) . sprintf(3) ( ) %s . [A-Za-z0-9./] . "%.2s" "$1$%.8s" crypt(3) MD5 . "%s" . pidfile () (PID) slapd ( getpid(2)). pluginlog: () SLAPI . slapd.plugin(5) . referral (referral) slapd(8) . (url) . require ( ) ( none ). / . bind bind . LDAPv3 LDAP . authc . SASL SASL . strong . strong <<>> (simple) SASL . none ( ) . reverse-lookup on | off / ( --enable-rlookups off ). rootDSE LDIF(5) root DSE . slapd . root DSE . DN : ldapsearch -x -b "" -s base "+" 5.1 RFC 4512 . sasl-auxprops [...] auxprop . slapd . auxprop . sasl-auxprops-dontusecopy [...] () <> . SASL OTP (replicated) . "cmusaslsecretOTP" . sasl-auxprops-dontusecopy-ignore on | off () sasl-auxprops-dontusecopy . SASL (provider) . . off . sasl-host (FQDN) SASL . sasl-realm (realm) SASL . . sasl-cbinding none | tls-unique | tls-endpoint (channel-binding) LDAP_OPT_X_SASL_CBINDING . none . sasl-secprops Cyrus SASL . none ( ) "noanonymous,noplain" . noplain . noactive . nodict . noanonymous . forwardsec (forward secrecy) . passcred ( ). minssf= . () RC4 Blowfish . . maxssf= ( minssf ). INT_MAX . maxbufsize= . . . schemadn (DN) (subschema subentry) . "cn=Subschema" . security ( ) ( minssf sasl-secprops ). / . ssf= . transport= (transport) . tls= TLS . sasl= SASL . update_ssf= . update_transport= . update_tls= TLS . update_sasl= SASL . simple_bind= / . transport ldapi:// ( IPSEC). . serverID [] . "0x" () . (multi- provider replication) . (glued) . URL . (FQDN) URL . "replica id" CSN . . : serverID 1 ldap://ldap1.example.com serverID 2 ldap://ldap2.example.com sizelimit {|unlimited} sizelimit size[.{soft|hard}]= [...] . . unlimited . . (soft) (hard) . . limits . sockbuf_max_incoming PDU LDAP . . sockbuf_max_incoming_auth PDU LDAP . . sortvals [...] . Modify Compare . . tcp-buffer [listener=] [{read|write}=] TCP . TCP read write . tcp(7) . TCP . threads (thread pool) . . threadqueues . . CPU . timelimit {|unlimited} timelimit time[.{soft|hard}]= [...] ( ) slapd . . unlimited . . . limits . tool-threads . . . writetimeout . . writetimeout . . TLS (TLS OPTIONS) slapd (TLS) . TLSCipherSuite . TLS (OpenSSL GnuTLS) . : OpenSSL: TLSCipherSuite HIGH:MEDIUM:+SSLv2 GnuTLS: TLSCiphersuite SECURE256:!AES-128-CBC OpenSSL : openssl ciphers -v GnuTLS gnutls-cli(1) ( --priority ). GnuTLS gnutls-cli --priority -- -- : gnutls-cli -l TLSCACertificateFile (CA) slapd . (GnuTLS)/(OpenSSL) . CA () CA CA CA . . TLSCACertificatePath . TLSCACertificateFile . . (semi-colon) . TLSCertificateFile slapd . OpenSSL . TLSCertificateKeyFile slapd TLSCertificateFile . . TLSDHParamFile - (Diffie- Hellman ephemeral) . DSA RSA "key encipherment" . - (Anonymous Diffie-Hellman) . (man- in-the-middle) . "!ADH" . TLSECName () - (ECDHE) . OpenSSL . GnuTLS ciphersuite GnuTLS . TLSProtocolMin [.] SSL/TLS . SSL . TLS 1.x 3.(x+1) : TLSProtocolMin 3.2 TLS 1.1 . OpenLDAP . GnuTLS . TLSRandFile /dev/[u]random . EGD/PRNGD . RANDFILE . GnuTLS . TLSVerifyClient ( ) TLS . : never . slapd . allow . . . try . . . demand | hard | true . . . SASL EXTERNAL TLS . SASL EXTERNAL TLSVerifyClient . TLSCRLCheck (CRL) CA . TLSCACertificatePath . GnuTLS . : none CRL . peer CRL . all CRL . TLSCRLFile . GnuTLS . (GENERAL BACKEND OPTIONS) . back-mdb . backend . : asyncmeta config dnssrv ldap ldif mdb meta monitor null passwd perl relay sock sql wt. back-mdb . (GENERAL DATABASE OPTIONS) . . database suffix . database . asyncmeta config dnssrv ldap ldif mdb meta monitor null passwd perl relay sock sql wt . LDAP (subtree) . subordinate . (overlays) . add_content_acl on | off (Add) ACL . off . ACL Add slapd.access(5) . extra_attrs . . ACL . ( ) . . hidden on | off . (hidden) (suffix) . hidden off . lastmod on | off slapd modifiersName modifyTimestamp creatorsName createTimestamp . entryCSN entryUUID syncrepl . lastmod on . lastbind on | off slapd pwdLastSuccess . lastbind off . (replication consumer) updateref chain pwdLastSuccess (provider) (forward) . lastbind-precision lastbind pwdLastSuccess . integer (bind) . . limits [ [...]] DN (base DN) . : anonymous | users | [=] | group[/oc[/at]]= ::= dn[.][.