Symas employee?Sign in

← Knowledge Base

Reference

LDIF - LDAP Data Interchange Format

LDIF (LDAP Data Interchange Format) is a plain-text format for representing LDAP directory entries and describing changes to them.

This guide explains the naming terms used in the examples, then shows how to add, modify, delete, rename, and move entries.

Understanding directory names

DN — Distinguished Name
The name that identifies an entry within the directory. For example: uid=jsmith1,ou=People,dc=example,dc=com.
RDN — Relative Distinguished Name
The leftmost naming component of a DN. In the example above, the RDN is uid=jsmith1. A common name can also be used, as in cn=John Smith.
dc — Domain Component
A domain-name component used in a directory name. For example, dc=symas,dc=com uses the components of symas.com. A directory does not have to use domain-based naming.
ou — Organizational Unit
A name used for an organizational unit, such as ou=People. Multiple ou components in a DN describe nested locations, not multiple group memberships.
cn — Common Name
A name for an object, such as a person or room. It may be used in the RDN, but it is not required to be the naming attribute for every entry.

These terms are not interchangeable: dn: identifies the entry in an LDIF record; dc, ou, cn, and uid are attribute names that may appear in directory names and entries.

Reading the examples

The examples below are change records. Each is a separate example, not a single script to run from beginning to end. The parent entry must exist before a child can be added, and attributes must be permitted by the entry’s schema.

  • Start an LDIF change file with version: 1, once at the beginning.
  • Separate records with a blank line. Keep each field on its own line.
  • For a modification, end each attribute operation with a line containing only -.
  • Do not indent the LDIF lines: a leading space indicates continuation of the preceding line.

The changetype field selects the entry operation: add, modify, delete, or modrdn (also called moddn). Within a modify record, use add:, replace:, or delete: to change attribute values.

Add an entry

This adds John Smith beneath ou=People,dc=example,dc=com. Adding an entry whose DN already exists fails.

dn: uid=jsmith1,ou=People,dc=example,dc=com
changetype: add
objectClass: inetOrgPerson
cn: John Smith
sn: Smith
uid: jsmith1
description: John Smith from Accounting; building project manager.

Modify an existing entry

Add an email address

This adds a mail value to the existing entry.

dn: uid=sbrown20,ou=People,dc=example,dc=com
changetype: modify
add: mail
mail: sbrown@example.com
-

Replace the email address

This replaces all existing mail values with the address shown.

dn: uid=sbrown20,ou=People,dc=example,dc=com
changetype: modify
replace: mail
mail: sbrown2@example.com
-

Remove one email address

This removes the specified value, leaving any other email addresses unchanged.

dn: uid=sbrown20,ou=People,dc=example,dc=com
changetype: modify
delete: mail
mail: sbrown2@example.com
-

Delete an entry

changetype: delete removes the entry itself. It is different from delete: mail inside a modification. This example assumes ou=othergroup has no child entries.

dn: ou=othergroup,dc=example,dc=com
changetype: delete

Rename an entry

This changes the RDN from uid=sbrown20 to uid=sbrown200.

dn: uid=sbrown20,ou=People,dc=example,dc=com
changetype: modrdn
newrdn: uid=sbrown200
deleteoldrdn: 0

deleteoldrdn: 0 retains the old naming value as an attribute value. Setting it to 1 removes the old naming value when it is not needed by the new RDN; it does not mean “delete the entire uid attribute.”

Move an entry to another organizational unit

The first record creates ou=superusers. The second moves the existing uid=sbrown2 entry beneath it, retaining its RDN. Moving an entry does not by itself grant privileges.

dn: ou=superusers,dc=example,dc=com
changetype: add
objectClass: organizationalUnit
ou: superusers

dn: uid=sbrown2,ou=People,dc=example,dc=com
changetype: modrdn
newrdn: uid=sbrown2
deleteoldrdn: 0
newsuperior: ou=superusers,dc=example,dc=com

Load a photograph from a file

The :< notation supplies an attribute value from a URL. Here, the importing client reads the local JPEG file and uses its contents as the value of jpegPhoto.

dn: uid=jsmith1,ou=People,dc=example,dc=com
changetype: modify
add: jpegPhoto
jpegPhoto:< file:///tmp/john.jpg
-

Other binary attributes can use the same notation, but the file’s encoding must match the attribute’s definition. Do not assume that an arbitrary MP3 is suitable for the standard audio attribute.

References