📚Quellen
🔬So wurde geprüft
📜RFCs und Entwürfe
Überblick über die LDAPv3-Spezifikation (RFC 4510–4519)
https://www.rfc-editor.org/rfc/rfc4510
LDAPMessage, Operationen, Result-Codes (Anhang A), dreiwertige Filterauswertung
https://www.rfc-editor.org/rfc/rfc4511
DIT, Objektklassen (ABSTRACT/STRUCTURAL/AUXILIARY), Attributtyp- und Objektklassen-Beschreibungen, OIDs
https://www.rfc-editor.org/rfc/rfc4512
Simple Bind (anonym, unauthentifiziert, Name/Passwort), SASL, StartTLS
https://www.rfc-editor.org/rfc/rfc4513
DN-Grammatik und Escaping (\, und \2C, #hexstring)
https://www.rfc-editor.org/rfc/rfc4514
Filtergrammatik, Escapes \2a \28 \29 \5c \00
https://www.rfc-editor.org/rfc/rfc4515
ldap://host/dn?attribute?scope?filter?extensions
https://www.rfc-editor.org/rfc/rfc4516
Syntax-OIDs 1.3.6.1.4.1.1466.115.121.1.x, Matching-Regeln 2.5.13.x
https://www.rfc-editor.org/rfc/rfc4517
Normalisierung vor dem Vergleich (Leerzeichen, Groß-/Kleinschreibung)
https://www.rfc-editor.org/rfc/rfc4518
person, organizationalPerson, organizationalUnit, groupOfNames, cn, sn, ou …
https://www.rfc-editor.org/rfc/rfc4519
Inhalts- und Änderungsdatensätze, Base64 (::), Zeilenfortsetzung, SAFE-STRING
https://www.rfc-editor.org/rfc/rfc2849
inetOrgPerson und ihre Attribute
https://www.rfc-editor.org/rfc/rfc2798
posixAccount, posixGroup, uidNumber, memberUid (nis.schema)
https://www.rfc-editor.org/rfc/rfc2307
Grundlage von syncrepl: refreshOnly, refreshAndPersist, Cookie
https://www.rfc-editor.org/rfc/rfc4533
(&) und (|)
https://www.rfc-editor.org/rfc/rfc4526
entryUUID
https://www.rfc-editor.org/rfc/rfc4530
ldapwhoami, OID 1.3.6.1.4.1.4203.1.11.3
https://www.rfc-editor.org/rfc/rfc4532
example.org / example.net für Beispieldaten
https://www.rfc-editor.org/rfc/rfc2606
Nie verabschiedeter Nachfolger von RFC 2307: posixGroup als AUXILIARY, damit groupOfNames + posixGroup kombinierbar sind
https://datatracker.ietf.org/doc/html/draft-howard-rfc2307bis-02
📘OpenLDAP Administrator's Guide 2.6
Gesamtdokumentation
https://www.openldap.org/doc/admin26/
olcAccess, Reihenfolge, Beispiele
https://www.openldap.org/doc/admin26/access-control.html
syncrepl, Delta-syncrepl, Multi-Provider
https://www.openldap.org/doc/admin26/replication.html
Eigene Schemata, OID bei der IANA, objectIdentifier-Makros, Namenspräfix „x-“
https://www.openldap.org/doc/admin26/schema.html
cn=config, Index-Präfixe {n}, Umwandlung mit slaptest -f … -F …
https://www.openldap.org/doc/admin26/slapdconf2.html
memberof, refint, ppolicy, syncprov, accesslog …
https://www.openldap.org/doc/admin26/overlays.html
Indexe, Loglevel
https://www.openldap.org/doc/admin26/tuning.html
📖man-Seiten (OpenLDAP)
olcLogLevel, olcSyncrepl, olcMultiProvider, olcServerID, olcSizeLimit (Standard 500), olcDisallows
https://www.openldap.org/software/man.cgi?query=slapd-config&sektion=5&apropos=0&manpath=OpenLDAP+2.6-Release
Konfigurationsdatei-Format
https://www.openldap.org/software/man.cgi?query=slapd.conf&sektion=5&apropos=0&manpath=OpenLDAP+2.6-Release
Zugriffsregeln: <what>/<who>/<access>/<control>, implizites by * none, Rechte m w a z i r s c x d
https://www.openldap.org/software/man.cgi?query=slapd.access&sektion=5&apropos=0&manpath=OpenLDAP+2.6-Release
Backend mdb, index pres/eq/approx/sub
https://www.openldap.org/software/man.cgi?query=slapd-mdb&sektion=5&apropos=0&manpath=OpenLDAP+2.6-Release
Provider-Overlay für syncrepl
https://www.openldap.org/software/man.cgi?query=slapo-syncprov&sektion=5&apropos=0&manpath=OpenLDAP+2.6-Release
memberOf-Pflege (Alternative: dynlist)
https://www.openldap.org/software/man.cgi?query=slapo-memberof&sektion=5&apropos=0&manpath=OpenLDAP+2.6-Release
referentielle Integrität
https://www.openldap.org/software/man.cgi?query=slapo-refint&sektion=5&apropos=0&manpath=OpenLDAP+2.6-Release
Passwort-Richtlinien
https://www.openldap.org/software/man.cgi?query=slapo-ppolicy&sektion=5&apropos=0&manpath=OpenLDAP+2.6-Release
Suchwerkzeug, -s base|one|sub|children, -o ldif_wrap
https://www.openldap.org/software/man.cgi?query=ldapsearch&sektion=1&apropos=0&manpath=OpenLDAP+2.6-Release
ldapadd = ldapmodify -a, -c, -Y EXTERNAL
https://www.openldap.org/software/man.cgi?query=ldapmodify&sektion=1&apropos=0&manpath=OpenLDAP+2.6-Release
LDIF in OpenLDAP (Fortsetzungszeilen mit Leerzeichen oder Tab)
https://www.openldap.org/software/man.cgi?query=ldif&sektion=5&apropos=0&manpath=OpenLDAP+2.6-Release
Offline-Import
https://www.openldap.org/software/man.cgi?query=slapadd&sektion=8&apropos=0&manpath=OpenLDAP+2.6-Release
Offline-Export, -n 0 = cn=config
https://www.openldap.org/software/man.cgi?query=slapcat&sektion=8&apropos=0&manpath=OpenLDAP+2.6-Release
Konfiguration prüfen / umwandeln
https://www.openldap.org/software/man.cgi?query=slaptest&sektion=8&apropos=0&manpath=OpenLDAP+2.6-Release
Zugriffsregeln offline prüfen
https://www.openldap.org/software/man.cgi?query=slapacl&sektion=8&apropos=0&manpath=OpenLDAP+2.6-Release
Passwort-Hashes, Standard {SSHA}
https://www.openldap.org/software/man.cgi?query=slappasswd&sektion=8&apropos=0&manpath=OpenLDAP+2.6-Release
🔖Sonstiges
Tag-Länge-Wert-Kodierung der LDAP-Nachrichten
https://www.itu.int/rec/T-REC-X.690
Eigenen OID-Zweig 1.3.6.1.4.1.<PEN> kostenlos beantragen
https://www.iana.org/assignments/enterprise-numbers/
Beispielnummern 030 23125 xxx sind nie geschaltet
https://www.bundesnetzagentur.de/DE/Fachthemen/Telekommunikation/Nummerierung/_DL/mittlg148_2021.pdf?__blob=publicationFile&v=1