Symas OpenLDAP Knowledge Base

Replace slapo memberOf with slapo dyngroup

Add new schema files (Symas OpenLDAP versions below 2.4.45)

Add: “/opt/symas/etc/openldap/schema/memberof.schema”

attributetype ( 1.2.840.113556.1.2.102
        NAME 'memberOf'
        DESC 'Group that the entry belongs to'
        EQUALITY distinguishedNameMatch
        SYNTAX ''

Add: “/opt/symas/etc/openldap/schema/dyngroup-memberof.schema”

objectclass (
        NAME 'memberOfOC'
        SUP top
        MUST ( memberOf )

objectClass ( NetscapeLDAPobjectClass:33
    NAME 'groupOfURLs'
    MUST cn
    MAY ( memberURL $ businessCategory $ description $ o $ ou $
    owner $ seeAlso ) 

Example configuration: Note: Remove the memberOf module load and memberOf overlay configurations

include "/opt/symas/etc/openldap/schema/memberof.schema"
include "/opt/symas/etc/openldap/schema/dyngroup-memberof.schema"

database mdb
index memberOf

overlay dynlist
dynlist-attrset groupOfUrls memberURL member

User Creation

All user entries must have “groupOfURLs” as an objectClass and must have a memberURL attribute in the following format:

memberURL: ldap:///<suffix>??sub?(member=<user DN>)


dn: cn=Marice McCaugherty,ou=Product Testing,dc=example,dc=com
objectClass: top
objectClass: person
objectClass: organizationalPerson
objectClass: inetOrgPerson
objectClass: groupOfURLs
memberURL: ldap:///dc=example,dc=com??sub?(member=cn=Marice McCaugherty,ou=Product Testing,dc=example,dc=com)
memberOf: cn=testgroup,ou=Group,dc=example,dc=com
memberOf: cn=alttestgroup,ou=Group,dc=example,dc=com