📚Quellen

Alle Fachangaben stammen aus den unten verlinkten Standards und der offiziellen OpenLDAP-Dokumentation. Schema-Definitionen sind wörtlich aus den Schemadateien bzw. dem slapd-Programm von OpenLDAP 2.7.1 übernommen.

🔬So wurde geprüft

✅ Gegen einen echten slapd getestet
Die Result-Codes und Meldungen der Schemaprüfung (ldapadd/ldapmodify), die Filter-Treffer auf den Beispieldaten, die Entscheidungen des ACL-Auswerters (slapacl), das Base64/Umbruch-Verhalten von LDIF (slapcat), die BER-Bytes von Bind/Search/Unbind (ldapsearch -d) und die Annahme des generierten Schemas (slaptest, ldapadd -Y EXTERNAL in cn=config) wurden mit OpenLDAP 2.7.1 nachgeprüft und sind als automatische Tests hinterlegt.
💡 Vereinfachungen
Die App ist ein Lernmodell, kein Server: Matching-Regeln sind vereinfacht (z. B. ~= wie Gleichheit, keine vollständige Unicode-Aufbereitung nach RFC 4518), der ACL-Auswerter kennt die gängigen <what>/<who>-Formen, aber nicht set, peername, ssf und Ähnliches. Das syncrepl-Modell zeigt das Prinzip der CSN-Vergleiche, nicht jedes Protokolldetail.

📜RFCs und Entwürfe

RFC 4510 – LDAP: Technical Specification Road Map

Überblick über die LDAPv3-Spezifikation (RFC 4510–4519)

https://www.rfc-editor.org/rfc/rfc4510

RFC 4511 – LDAP: The Protocol

LDAPMessage, Operationen, Result-Codes (Anhang A), dreiwertige Filterauswertung

https://www.rfc-editor.org/rfc/rfc4511

RFC 4512 – LDAP: Directory Information Models

DIT, Objektklassen (ABSTRACT/STRUCTURAL/AUXILIARY), Attributtyp- und Objektklassen-Beschreibungen, OIDs

https://www.rfc-editor.org/rfc/rfc4512

RFC 4513 – LDAP: Authentication Methods and Security Mechanisms

Simple Bind (anonym, unauthentifiziert, Name/Passwort), SASL, StartTLS

https://www.rfc-editor.org/rfc/rfc4513

RFC 4514 – LDAP: String Representation of Distinguished Names

DN-Grammatik und Escaping (\, und \2C, #hexstring)

https://www.rfc-editor.org/rfc/rfc4514

RFC 4515 – LDAP: String Representation of Search Filters

Filtergrammatik, Escapes \2a \28 \29 \5c \00

https://www.rfc-editor.org/rfc/rfc4515

RFC 4516 – LDAP: Uniform Resource Locator

ldap://host/dn?attribute?scope?filter?extensions

https://www.rfc-editor.org/rfc/rfc4516

RFC 4517 – LDAP: Syntaxes and Matching Rules

Syntax-OIDs 1.3.6.1.4.1.1466.115.121.1.x, Matching-Regeln 2.5.13.x

https://www.rfc-editor.org/rfc/rfc4517

RFC 4518 – LDAP: Internationalized String Preparation

Normalisierung vor dem Vergleich (Leerzeichen, Groß-/Kleinschreibung)

https://www.rfc-editor.org/rfc/rfc4518

RFC 4519 – LDAP: Schema for User Applications

person, organizationalPerson, organizationalUnit, groupOfNames, cn, sn, ou …

https://www.rfc-editor.org/rfc/rfc4519

RFC 2849 – The LDAP Data Interchange Format (LDIF)

Inhalts- und Änderungsdatensätze, Base64 (::), Zeilenfortsetzung, SAFE-STRING

https://www.rfc-editor.org/rfc/rfc2849

RFC 2798 – Definition of the inetOrgPerson Object Class

inetOrgPerson und ihre Attribute

https://www.rfc-editor.org/rfc/rfc2798

RFC 2307 – An Approach for Using LDAP as a Network Information Service

posixAccount, posixGroup, uidNumber, memberUid (nis.schema)

https://www.rfc-editor.org/rfc/rfc2307

RFC 4533 – LDAP Content Synchronization Operation

Grundlage von syncrepl: refreshOnly, refreshAndPersist, Cookie

https://www.rfc-editor.org/rfc/rfc4533

RFC 4526 – LDAP Absolute True and False Filters

(&) und (|)

https://www.rfc-editor.org/rfc/rfc4526

RFC 4530 – LDAP entryUUID Operational Attribute

entryUUID

https://www.rfc-editor.org/rfc/rfc4530

RFC 4532 – LDAP "Who am I?" Operation

ldapwhoami, OID 1.3.6.1.4.1.4203.1.11.3

https://www.rfc-editor.org/rfc/rfc4532

RFC 2606 – Reserved Top Level DNS Names

example.org / example.net für Beispieldaten

https://www.rfc-editor.org/rfc/rfc2606

draft-howard-rfc2307bis-02

Nie verabschiedeter Nachfolger von RFC 2307: posixGroup als AUXILIARY, damit groupOfNames + posixGroup kombinierbar sind

https://datatracker.ietf.org/doc/html/draft-howard-rfc2307bis-02

📘OpenLDAP Administrator's Guide 2.6

📖man-Seiten (OpenLDAP)

slapd-config(5)

olcLogLevel, olcSyncrepl, olcMultiProvider, olcServerID, olcSizeLimit (Standard 500), olcDisallows

https://www.openldap.org/software/man.cgi?query=slapd-config&sektion=5&apropos=0&manpath=OpenLDAP+2.6-Release

slapd.conf(5)

Konfigurationsdatei-Format

https://www.openldap.org/software/man.cgi?query=slapd.conf&sektion=5&apropos=0&manpath=OpenLDAP+2.6-Release

slapd.access(5)

Zugriffsregeln: <what>/<who>/<access>/<control>, implizites by * none, Rechte m w a z i r s c x d

https://www.openldap.org/software/man.cgi?query=slapd.access&sektion=5&apropos=0&manpath=OpenLDAP+2.6-Release

slapd-mdb(5)

Backend mdb, index pres/eq/approx/sub

https://www.openldap.org/software/man.cgi?query=slapd-mdb&sektion=5&apropos=0&manpath=OpenLDAP+2.6-Release

slapo-syncprov(5)

Provider-Overlay für syncrepl

https://www.openldap.org/software/man.cgi?query=slapo-syncprov&sektion=5&apropos=0&manpath=OpenLDAP+2.6-Release

slapo-memberof(5)

memberOf-Pflege (Alternative: dynlist)

https://www.openldap.org/software/man.cgi?query=slapo-memberof&sektion=5&apropos=0&manpath=OpenLDAP+2.6-Release

slapo-refint(5)

referentielle Integrität

https://www.openldap.org/software/man.cgi?query=slapo-refint&sektion=5&apropos=0&manpath=OpenLDAP+2.6-Release

slapo-ppolicy(5)

Passwort-Richtlinien

https://www.openldap.org/software/man.cgi?query=slapo-ppolicy&sektion=5&apropos=0&manpath=OpenLDAP+2.6-Release

ldapsearch(1)

Suchwerkzeug, -s base|one|sub|children, -o ldif_wrap

https://www.openldap.org/software/man.cgi?query=ldapsearch&sektion=1&apropos=0&manpath=OpenLDAP+2.6-Release

ldapmodify(1)

ldapadd = ldapmodify -a, -c, -Y EXTERNAL

https://www.openldap.org/software/man.cgi?query=ldapmodify&sektion=1&apropos=0&manpath=OpenLDAP+2.6-Release

ldif(5)

LDIF in OpenLDAP (Fortsetzungszeilen mit Leerzeichen oder Tab)

https://www.openldap.org/software/man.cgi?query=ldif&sektion=5&apropos=0&manpath=OpenLDAP+2.6-Release

slapadd(8)

Offline-Import

https://www.openldap.org/software/man.cgi?query=slapadd&sektion=8&apropos=0&manpath=OpenLDAP+2.6-Release

slapcat(8)

Offline-Export, -n 0 = cn=config

https://www.openldap.org/software/man.cgi?query=slapcat&sektion=8&apropos=0&manpath=OpenLDAP+2.6-Release

slaptest(8)

Konfiguration prüfen / umwandeln

https://www.openldap.org/software/man.cgi?query=slaptest&sektion=8&apropos=0&manpath=OpenLDAP+2.6-Release

slapacl(8)

Zugriffsregeln offline prüfen

https://www.openldap.org/software/man.cgi?query=slapacl&sektion=8&apropos=0&manpath=OpenLDAP+2.6-Release

slappasswd(8)

Passwort-Hashes, Standard {SSHA}

https://www.openldap.org/software/man.cgi?query=slappasswd&sektion=8&apropos=0&manpath=OpenLDAP+2.6-Release

🔖Sonstiges