TT Lab
Get started
Learn Learning paths Courses

Enterprise Authentication Integration

Load an LDAP Directory and Query It With Filters

Continue in TT Lab

Goal

You start slapd yourself, load the organization LDIF, and combine LDAP search filters to pull out exactly the users and groups you want.

Why it matters

In an SI project, "please connect the company accounts to our system" ends up as an LDAP lookup. But if you write the filter carelessly, inactive accounts and service accounts get into the user list too, and if you do not specify returned attributes, you pull all attributes from a 100,000-person directory and torment the server. Also, the directory in this lab has a structure where groups point to people (member), and code that scans all groups to find "this person's groups" on every login really does get written. With 100 users nobody notices, and at 10,000 users login takes 3 seconds.

Steps

  1. Start slapd on port 1389. slapd -h ldap://127.0.0.1:1389 -F /opt/lab/ldap/slapd.d Then query the Root DSE and save it to /root/ldap/root-dse.txt. The file must contain dc=labhub,dc=co,dc=kr.
  2. Load /opt/lab/fixtures/auth/ldif/00-base.ldif. A query on the Base DN dc=labhub,dc=co,dc=kr must succeed.
  3. Load /opt/lab/fixtures/auth/ldif/10-people.ldif. There must be 30 entries with objectClass=inetOrgPerson.
  4. Load /opt/lab/fixtures/auth/ldif/20-groups.ldif. There must be 6 entries with objectClass=groupOfNames.
  5. Select only the uid of people who belong to the development team and whose rank is section chief (Gwajang) and save them, one per line in ascending order, to /root/ldap/q1.txt. (The department attribute is ou and the rank attribute is title.)
  6. Save the uid of people whose rank is general manager (Bujang) or deputy general manager (Chajang) and who are not in the General Affairs team to /root/ldap/q2.txt in the same format.
  7. Save the cn of the groups that uid=hong belongs to, one per line in ascending order, to /root/ldap/groups-of-hong.txt.
  8. Create /root/ldap/whois.sh. It takes one argument (a uid) and prints the four lines below in exactly this order. If the uid does not exist, end with a non-zero exit code.
    cn=<이름>
    ou=<부서>
    title=<직급>
    groups=<소속 그룹 수>
    

Notes

Start slapd and check the Root DSE

Start slapd on port 1389. slapd -h ldap://127.0.0.1:1389 -F /opt/lab/ldap/slapd.d Then query the Root DSE and save it to /root/ldap/root-dse.txt. The file must contain dc=labhub,dc=co,dc=kr.

This environment cannot bind to ports below 1024. You can query the Root DSE by giving an empty string as the base and base as the scope. It tells you which naming contexts the server has.

Load the base entry

Load /opt/lab/fixtures/auth/ldif/00-base.ldif. A query on the Base DN dc=labhub,dc=co,dc=kr must succeed.

LDIF is applied from top to bottom, so the parent entry must exist first before you can add children. Give the file to ldapadd with -f.

Load the user entries

Load /opt/lab/fixtures/auth/ldif/10-people.ldif. There must be 30 entries with objectClass=inetOrgPerson.

Get into the habit of counting after loading. Feeding in an LDIF does not mean everything went in. If there is a duplicate DN, only that entry fails.

Load the group entries

Load /opt/lab/fixtures/auth/ldif/20-groups.ldif. There must be 6 entries with objectClass=groupOfNames.

groupOfNames needs at least one member attribute. Trying to create an empty group and running into a schema violation is the first hurdle.

Compound condition filter

Select only the uid of people who belong to the development team and whose rank is section chief (Gwajang) and save them, one per line in ascending order, to /root/ldap/q1.txt. (The department attribute is ou and the rank attribute is title.)

An LDAP filter is prefix notation where the operator comes first. AND takes the form (&(...)(...)) and the parentheses must balance.

Combining OR and NOT

Save the uid of people whose rank is general manager (Bujang) or deputy general manager (Chajang) and who are not in the General Affairs team to /root/ldap/q2.txt in the same format.

Put several conditions inside an OR, wrap the whole thing in an AND, and exclude one with NOT. Drawing the parentheses on paper reduces mistakes.

Reverse lookup of group membership

Save the cn of the groups that uid=hong belongs to, one per line in ascending order, to /root/ldap/groups-of-hong.txt.

In this directory, people do not point to groups; groups point to people. So "the groups this person belongs to" must be looked up from the group side.

User lookup script

Create /root/ldap/whois.sh. It takes one argument (a uid) and prints the four lines below in exactly this order. If the uid does not exist, end with a non-zero exit code.

cn=<이름>
ou=<부서>
title=<직급>
groups=<소속 그룹 수>

Gather and print the needed information for the single uid passed as an argument. The -LLL option helps when extracting only values from ldapsearch output.