📡Operationen & Protokoll
ldapsearch senden würde – für Bind, Search und Unbind Byte für Byte mit einem Mitschnitt von OpenLDAP abgeglichen.🎬Sequenzdiagramm
$ ldapsearch -x -H ldap://ldap.example.org -ZZ -D "uid=anna.schmidt,ou=people,dc=example,dc=org" -W -b "ou=people,dc=example,dc=org" -s sub "(ou=Vertrieb)" cn mailBindRequest
Client → ServerSimple Bind als uid=anna.schmidt,ou=people,dc=example,dc=org. Das Passwort steht im Klartext in der Nachricht – deshalb nur über TLS!
📚 Quellen: RFC 4511 – LDAP: The Protocol · RFC 4513 – LDAP: Authentication Methods and Security Mechanisms · RFC 4532 – LDAP "Who am I?" Operation · ITU-T X.690 – ASN.1 Encoding Rules (BER/CER/DER)
🧩Aufbau einer Nachricht
LDAPMessage ::= SEQUENCE {
messageID MessageID, -- INTEGER (0 .. 2^31-1)
protocolOp CHOICE {
bindRequest BindRequest, -- [APPLICATION 0]
bindResponse BindResponse, -- [APPLICATION 1]
unbindRequest UnbindRequest, -- [APPLICATION 2]
searchRequest SearchRequest, -- [APPLICATION 3]
searchResEntry SearchResultEntry, -- [APPLICATION 4]
searchResDone SearchResultDone, -- [APPLICATION 5]
modifyRequest ... addRequest ... delRequest ...
compareRequest ... extendedReq ... },
controls [0] Controls OPTIONAL }30 0c heißt „SEQUENCE, 12 Byte folgen“. 60 ist [APPLICATION 0] konstruiert = BindRequest. Längen über 127 Byte werden mehrbytig (81 c8 = 200).ldapsearch -s children nutzt zusätzlich subordinateSubtree (3) aus einem Entwurf – alles unterhalb, ohne Basis.📚 Quellen: RFC 4511 – LDAP: The Protocol · ITU-T X.690 – ASN.1 Encoding Rules (BER/CER/DER)
🔑Bind-Varianten
ldapsearch -x …DN und Passwort leer. Erlaubt, solange olcDisallows nicht bind_anon enthält.
-D "uid=…" (ohne Passwort)DN ohne Passwort. RFC 4513 warnt davor; slapd lehnt ab: 53 „unauthenticated bind (DN with no password) disallowed“.
-x -D "uid=…" -WPasswort im Klartext in der Nachricht – nur mit TLS (-ZZ oder ldaps://).
-Y EXTERNAL -H ldapi:///Mechanismen wie EXTERNAL (Unix-Benutzer über den Socket oder TLS-Clientzertifikat), GSSAPI (Kerberos), SCRAM.
userPassword, antwortet slapd mit 48 inappropriateAuthentication.📚 Quellen: RFC 4513 – LDAP: Authentication Methods and Security Mechanisms · slapd-config(5)
🔗LDAP-URLs
$ ldapsearch -x -H ldap://ldap.example.org -b ou=people,dc=example,dc=org -s sub "(ou=Vertrieb)" cn mail📚 Quellen: RFC 4516 – LDAP: Uniform Resource Locator