LDAP FAQ
约 1 分钟阅读
标签:FAQ
属性命名
[a-zA-Z0-9-]- Best Practices For LDAP Naming Attributes
LDAPv3 password modify
ldappasswd -H ldap://ldap.example.com:389 -D "uid=account-name,ou=serviceaccounts,dc=example,dc=com" -S -W -ZZ- LDAPv3 Password Modify Extended Operation (RFC-3062)
- Password Modify Extended Operation
认证方式
| method | value |
|---|---|
| simple | 0 |
| 1 | |
| 2 | |
| sasl | 3 |
Bind DN vs Simple Auth
- Bind DN
- DN + Password
- Bind Request
- 服务使用自己的账号去校验用户的账号密码是否匹配
- 可以预先知道账号信息
- 可用于导入账号、同步账号
- Simple Authentication / simple bind
- Username + Password
- 直接校验
- 最小粒度权限
- ldapwiki Simple Auth
lldap vs glauth
| lldap | glauth笔记glauthglauth/glauth · MIT, Go · LDAP server for development, home use, or CI · 只用于 Auth 场景 - 只有 user 和 group · 支持自定义属性,但不可以用于搜索打开:/notes/service/auth/ldap/glauth |
|---|---|
| GPLv3 | MIT |
| Rust | Go |
| Single Binary | Binary + Plugin |
- lldap vs glauth笔记glauthglauth/glauth · MIT, Go · LDAP server for development, home use, or CI · 只用于 Auth 场景 - 只有 user 和 group · 支持自定义属性,但不可以用于搜索打开:/notes/service/auth/ldap/glauth
- 不支持自定义属性
- 不支持嵌套分组
- 通过分组固定权限
- 固定了 user 的 baseDn
- 支持用户登录 - 因此需要维护 JWT
- glauth vs lldap
- UI 能力弱
- 无 API
关联信息
反向链接、本文链接的其他页面和外部资料。
References
其他外链4 条
- ldapwiki.com/wiki/Best Practices For LDAP Naming Attributesldapwiki.com/wiki/Best%20Practices%20For%20LDAP%20Naming%20Attributes
- ldapwiki.com/wiki/LDAP Authentication Methodsldapwiki.com/wiki/LDAP%20Authentication%20Methods
- ldapwiki.com/wiki/Password Modify Extended Operationldapwiki.com/wiki/Password%20Modify%20Extended%20Operation
- ldapwiki.com/wiki/Simple Authenticationldapwiki.com/wiki/Simple%20Authentication