Enterprise Authentication Integration
Load an LDAP Directory and Query It With Filters
Goal
You start slapd yourself, load the organization LDIF, and combine LDAP search filters to pull out exactly the users and groups you want.
Why it matters
In an SI project, "please connect the company accounts to our system" ends up as an LDAP lookup.
But if you write the filter carelessly, inactive accounts and service accounts get into the user list too,
and if you do not specify returned attributes, you pull all attributes from a 100,000-person directory and torment the server.
Also, the directory in this lab has a structure where groups point to people (member),
and code that scans all groups to find "this person's groups" on every login
really does get written. With 100 users nobody notices, and at 10,000 users login takes 3 seconds.
Steps
- Start slapd on port 1389.
slapd -h ldap://127.0.0.1:1389 -F /opt/lab/ldap/slapd.dThen query the Root DSE and save it to/root/ldap/root-dse.txt. The file must containdc=labhub,dc=co,dc=kr. - Load
/opt/lab/fixtures/auth/ldif/00-base.ldif. A query on the Base DNdc=labhub,dc=co,dc=krmust succeed. - Load
/opt/lab/fixtures/auth/ldif/10-people.ldif. There must be 30 entries withobjectClass=inetOrgPerson. - Load
/opt/lab/fixtures/auth/ldif/20-groups.ldif. There must be 6 entries withobjectClass=groupOfNames. - Select only the
uidof people who belong to the development team and whose rank is section chief (Gwajang) and save them, one per line in ascending order, to/root/ldap/q1.txt. (The department attribute isouand the rank attribute istitle.) - Save the
uidof people whose rank is general manager (Bujang) or deputy general manager (Chajang) and who are not in the General Affairs team to/root/ldap/q2.txtin the same format. - Save the cn of the groups that
uid=hongbelongs to, one per line in ascending order, to/root/ldap/groups-of-hong.txt. - Create
/root/ldap/whois.sh. It takes one argument (a uid) and prints the four lines below in exactly this order. If the uid does not exist, end with a non-zero exit code.cn=<이름> ou=<부서> title=<직급> groups=<소속 그룹 수>
Notes
- Basic search:
ldapsearch -x -H ldap://127.0.0.1:1389 -b "dc=labhub,dc=co,dc=kr" -LLL "(필터)" 속성명(the placeholders are the filter and the attribute name) - Loading:
ldapadd -x -H ldap://127.0.0.1:1389 -D "cn=admin,dc=labhub,dc=co,dc=kr" -w labhub123 -f 파일.ldif(the placeholder is the LDIF file) - Counting: count the lines that start with
dn:in the result. - Common mistake 1: unbalanced filter parentheses. You must wrap the whole thing once more, as in
(&(a=1)(b=2)). - Common mistake 2: not specifying returned attributes, so all attributes pour out.
- Common mistake 3: leaving out
-b. Without a Base, the server does not know where to start looking.
Start slapd and check the Root DSE
Start slapd on port 1389.
slapd -h ldap://127.0.0.1:1389 -F /opt/lab/ldap/slapd.d
Then query the Root DSE and save it to /root/ldap/root-dse.txt.
The file must contain dc=labhub,dc=co,dc=kr.
This environment cannot bind to ports below 1024. You can query the Root DSE by giving an empty string as the base and base as the scope. It tells you which naming contexts the server has.
Load the base entry
Load /opt/lab/fixtures/auth/ldif/00-base.ldif.
A query on the Base DN dc=labhub,dc=co,dc=kr must succeed.
LDIF is applied from top to bottom, so the parent entry must exist first before you can add children. Give the file to ldapadd with -f.
Load the user entries
Load /opt/lab/fixtures/auth/ldif/10-people.ldif.
There must be 30 entries with objectClass=inetOrgPerson.
Get into the habit of counting after loading. Feeding in an LDIF does not mean everything went in. If there is a duplicate DN, only that entry fails.
Load the group entries
Load /opt/lab/fixtures/auth/ldif/20-groups.ldif.
There must be 6 entries with objectClass=groupOfNames.
groupOfNames needs at least one member attribute. Trying to create an empty group and running into a schema violation is the first hurdle.
Compound condition filter
Select only the uid of people who belong to the development team and whose rank is section chief (Gwajang) and
save them, one per line in ascending order, to /root/ldap/q1.txt.
(The department attribute is ou and the rank attribute is title.)
An LDAP filter is prefix notation where the operator comes first. AND takes the form (&(...)(...)) and the parentheses must balance.
Combining OR and NOT
Save the uid of people whose rank is general manager (Bujang) or deputy general manager (Chajang) and who are not in the General Affairs team
to /root/ldap/q2.txt in the same format.
Put several conditions inside an OR, wrap the whole thing in an AND, and exclude one with NOT. Drawing the parentheses on paper reduces mistakes.
Reverse lookup of group membership
Save the cn of the groups that uid=hong belongs to, one per line in ascending order, to
/root/ldap/groups-of-hong.txt.
In this directory, people do not point to groups; groups point to people. So "the groups this person belongs to" must be looked up from the group side.
User lookup script
Create /root/ldap/whois.sh. It takes one argument (a uid) and prints the four lines below
in exactly this order. If the uid does not exist, end with a non-zero exit code.
cn=<이름>
ou=<부서>
title=<직급>
groups=<소속 그룹 수>
Gather and print the needed information for the single uid passed as an argument. The -LLL option helps when extracting only values from ldapsearch output.