{"kind": "auth", "major": "18", "item": {"slug": "ldap", "name": "ldap", "name_zh": "", "category": "\u8eab\u4efd\u8ba4\u8bc1\u4e0e\u8bbf\u95ee\u63a7\u5236", "summary": "\u4f7f\u7528 LDAP \u670d\u52a1\u5668\u8fdb\u884c\u8ba4\u8bc1\u3002\u8be6\u60c5\u53c2\u89c1\u7b2c 20.10 \u8282\u3002", "aliases": [], "content_hash": "3385f9d89d6bddaf5f5b2e77f38818d207e68ebdc2a8f235174389191b42fc29", "versions": {"10": {"facts": [{"label": "\u65b9\u6cd5", "value": "ldap"}, {"label": "\u914d\u7f6e", "value": "pg_hba.conf"}, {"label": "\u6e05\u5355", "value": "\u7528\u6237\u53ef\u89c1\u7684\u6e90\u7801\u8ba4\u8bc1\u65b9\u6cd5"}], "tables": [{"key": "method-options", "rows": [{"name": "ldapserver", "description": "\u8981\u8fde\u63a5\u7684LDAP\u670d\u52a1\u5668\u7684\u540d\u79f0\u6216IP\u5730\u5740\u3002\u53ef\u4ee5\u6307\u5b9a\u591a\u4e2a\u670d\u52a1\u5668\uff0c\u7528\u7a7a\u683c\u5206\u9694\u3002"}, {"name": "ldapport", "description": "\u8981\u8fde\u63a5\u7684LDAP\u670d\u52a1\u5668\u7684\u7aef\u53e3\u53f7\u3002\u5982\u679c\u672a\u6307\u5b9a\u7aef\u53e3\uff0c\u5219\u5c06\u4f7f\u7528LDAP\u5e93\u7684\u9ed8\u8ba4\u7aef\u53e3\u8bbe\u7f6e\u3002"}, {"name": "ldaptls", "description": "\u8bbe\u4e3a 1 \u65f6\uff0cPostgreSQL \u4e0e LDAP \u670d\u52a1\u5668\u4e4b\u95f4\u7684\u8fde\u63a5\u4f1a\u4f7f\u7528 TLS \u52a0\u5bc6\u3002\u6ce8\u610f\uff0c\u8fd9\u53ea\u52a0\u5bc6\u4e0e LDAP \u670d\u52a1\u5668\u4e4b\u95f4\u7684\u6d41\u91cf \u2014 \u9664\u975e\u4f7f\u7528 SSL\uff0c\u5426\u5219\u4e0e\u5ba2\u6237\u7aef\u4e4b\u95f4\u7684\u8fde\u63a5\u4ecd\u4e0d\u52a0\u5bc6\u3002"}, {"name": "ldapprefix", "description": "\u5728\u8fdb\u884c\u7b80\u5355\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u9644\u52a0\u5230\u7528\u6237\u540d\u524d\u9762\u4ee5\u5f62\u6210\u7ed1\u5b9a DN \u7684\u5b57\u7b26\u4e32\u3002"}, {"name": "ldapsuffix", "description": "\u5728\u8fdb\u884c\u7b80\u5355\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u9644\u52a0\u5230\u7528\u6237\u540d\u540e\u9762\u4ee5\u5f62\u6210\u7ed1\u5b9a DN \u7684\u5b57\u7b26\u4e32\u3002"}, {"name": "ldapbasedn", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4f5c\u7528\u6237\u641c\u7d22\u8d77\u70b9\u7684\u6839 DN\u3002"}, {"name": "ldapbinddn", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u7ed1\u5b9a\u5230\u76ee\u5f55\u5e76\u6267\u884c\u641c\u7d22\u7684\u7528\u6237 DN\u3002"}, {"name": "ldapbindpasswd", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u7ed1\u5b9a\u5230\u76ee\u5f55\u5e76\u6267\u884c\u641c\u7d22\u7684\u7528\u6237\u5bc6\u7801\u3002"}, {"name": "ldapsearchattribute", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u4e0e\u7528\u6237\u540d\u5339\u914d\u7684\u5c5e\u6027\u3002\u5982\u679c\u672a\u6307\u5b9a\u5c5e\u6027\uff0c\u5219\u4f1a\u4f7f\u7528 uid \u5c5e\u6027\u3002"}, {"name": "ldapurl", "description": "\u7b26\u5408 RFC 4516 \u7684 LDAP URL\u3002\u5b83\u4ee5\u66f4\u7d27\u51d1\u3001\u6807\u51c6\u7684\u5f62\u5f0f\u66ff\u4ee3\u90e8\u5206\u5176\u4ed6 LDAP \u9009\u9879\u3002\u683c\u5f0f\u4e3a ldap://host[:port]/basedn[?[attribute][?[scope]]]\u3002scope \u5fc5\u987b\u4e3a base\u3001one \u6216 sub\uff0c\u901a\u5e38\u4f7f\u7528 sub\u3002\u53ea\u4f7f\u7528\u4e00\u4e2a\u5c5e\u6027\uff0c\u6807\u51c6 LDAP URL \u4e2d\u7684\u8fc7\u6ee4\u5668\u3001\u6269\u5c55\u7b49\u90e8\u5206\u7ec4\u4ef6\u4e0d\u53d7\u652f\u6301\u3002\u5bf9\u4e8e\u975e\u533f\u540d\u7ed1\u5b9a\uff0c\u5fc5\u987b\u53e6\u884c\u6307\u5b9a ldapbinddn \u548c ldapbindpasswd\u3002\u82e5\u8981\u4f7f\u7528\u52a0\u5bc6 LDAP \u8fde\u63a5\uff0c\u9700\u5728 ldapurl \u4e4b\u5916\u4f7f\u7528 ldaptls\uff1bldaps URL \u65b9\u6848\uff08\u76f4\u63a5 SSL \u8fde\u63a5\uff09\u4e0d\u53d7\u652f\u6301\u3002LDAP URL \u76ee\u524d\u4ec5\u5728 OpenLDAP \u4e2d\u53d7\u652f\u6301\uff0cWindows \u4e0d\u652f\u6301\u3002"}], "title": "\u624b\u518c\u4e2d\u7684\u65b9\u6cd5\u9009\u9879\u4e0e\u66ff\u4ee3\u65b9\u5f0f", "columns": [{"key": "name", "label": "\u9009\u9879\u6216\u672f\u8bed"}, {"key": "description", "label": "\u542b\u4e49"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v10.23/postgresql-10.23.tar.bz2", "label": "10.23", "major": "10", "channel": "historical", "revision": "94a4b2528372458e5662c18d406629266667c437198160a18cdfd2c4a4d6eee9", "source_sha256": "94a4b2528372458e5662c18d406629266667c437198160a18cdfd2c4a4d6eee9", "catalog_fingerprint": "691be281b476dde4374d7f805b2bacc2e75bdef40f1e9d3d42e91f97fe95cfd0"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v10.23/postgresql-10.23.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "94a4b2528372458e5662c18d406629266667c437198160a18cdfd2c4a4d6eee9"}, {"url": "https://pg.center/docs/10/auth-methods.html#AUTH-LDAP", "path": "auth-methods.html", "label": "PostgreSQL 10 English manual", "sha256": "856d36a3fdfe8c45a25832e49bd07e9b7480f2ff9a33e58ac7c392630149bc34", "language": "en", "original_url": "/docs/10/auth-methods.html#AUTH-LDAP"}, {"url": "https://pg.center/docs/10/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 10 English manual", "sha256": "04fed609a50e8fd3013ffebb83039c544d39b6c73a6c2b2e23cd7864a70b42da", "language": "en", "original_url": "/docs/10/auth-pg-hba-conf.html"}], "sections": [], "signature": "", "attributes": {"method": "ldap", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["\u4f7f\u7528 LDAP \u670d\u52a1\u5668\u8fdb\u884c\u8ba4\u8bc1\u3002\u8be6\u60c5\u53c2\u89c1\u7b2c 20.3.7 \u8282\u3002"], "manual_html": "<div class=\"sect2\" id=\"AUTH-LDAP\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h3 class=\"title\" lang=\"zh\"><span class=\"sect2\"><a href=\"/docs/10/auth-methods.html#AUTH-LDAP\">20.3.7. LDAP \u8ba4\u8bc1</a></span></h3>\n</div>\n</div>\n</div>\n<p lang=\"zh\">\u8fd9\u79cd\u8ba4\u8bc1\u65b9\u6cd5\u7684\u5de5\u4f5c\u65b9\u5f0f\u4e0e <code class=\"literal\">password</code> \u7c7b\u4f3c\uff0c\u53ea\u4e0d\u8fc7\u5b83\u4f7f\u7528 LDAP \u4f5c\u4e3a\u5bc6\u7801\u9a8c\u8bc1\u65b9\u6cd5\u3002LDAP \u53ea\u7528\u4e8e\u9a8c\u8bc1\u7528\u6237\u540d/\u5bc6\u7801\u5bf9\u3002\u56e0\u6b64\uff0c\u5728\u4f7f\u7528 LDAP \u8fdb\u884c\u8ba4\u8bc1\u4e4b\u524d\uff0c\u7528\u6237\u5fc5\u987b\u5df2\u7ecf\u5b58\u5728\u4e8e\u6570\u636e\u5e93\u4e2d\u3002</p>\n<p lang=\"zh\">LDAP \u8ba4\u8bc1\u53ef\u4ee5\u5728\u4e24\u79cd\u6a21\u5f0f\u4e0b\u5de5\u4f5c\u3002\u7b2c\u4e00\u79cd\u6a21\u5f0f\u79f0\u4e3a\u7b80\u5355\u7ed1\u5b9a\u6a21\u5f0f\uff0c\u670d\u52a1\u5668\u4f1a\u7ed1\u5b9a\u5230\u6309 <em class=\"replaceable\"><code>prefix</code></em> <em class=\"replaceable\"><code>username</code></em> <em class=\"replaceable\"><code>suffix</code></em> \u5f62\u5f0f\u6784\u9020\u51fa\u7684\u53ef\u5206\u8fa8\u540d\u79f0\u3002\u901a\u5e38\uff0c<em class=\"replaceable\"><code>prefix</code></em> \u53c2\u6570\u7528\u4e8e\u6307\u5b9a <code class=\"literal\">cn=</code>\uff0c\u6216\u5728 Active Directory \u73af\u5883\u4e2d\u6307\u5b9a <em class=\"replaceable\"><code>DOMAIN</code></em><code class=\"literal\">\\</code>\u3002<em class=\"replaceable\"><code>suffix</code></em> \u5219\u7528\u4e8e\u6307\u5b9a\u975e Active Directory \u73af\u5883\u4e2d DN \u7684\u5269\u4f59\u90e8\u5206\u3002</p>\n<p lang=\"zh\">\u7b2c\u4e8c\u79cd\u6a21\u5f0f\u79f0\u4e3a\u641c\u7d22+\u7ed1\u5b9a\u6a21\u5f0f\uff0c\u670d\u52a1\u5668\u9996\u5148\u4f7f\u7528\u7531 <em class=\"replaceable\"><code>ldapbinddn</code></em> \u548c <em class=\"replaceable\"><code>ldapbindpasswd</code></em> \u6307\u5b9a\u7684\u56fa\u5b9a\u7528\u6237\u540d\u548c\u5bc6\u7801\u7ed1\u5b9a\u5230 LDAP \u76ee\u5f55\uff0c\u5e76\u641c\u7d22\u8bd5\u56fe\u767b\u5f55\u6570\u636e\u5e93\u7684\u7528\u6237\u3002\u5982\u679c\u6ca1\u6709\u914d\u7f6e\u7528\u6237\u540d\u548c\u5bc6\u7801\uff0c\u5219\u4f1a\u5c1d\u8bd5\u5bf9\u76ee\u5f55\u8fdb\u884c\u533f\u540d\u7ed1\u5b9a\u3002\u641c\u7d22\u4f1a\u5728 <em class=\"replaceable\"><code>ldapbasedn</code></em> \u6307\u5b9a\u7684\u5b50\u6811\u4e0a\u8fdb\u884c\uff0c\u5e76\u5c1d\u8bd5\u5bf9 <em class=\"replaceable\"><code>ldapsearchattribute</code></em> \u6307\u5b9a\u7684\u5c5e\u6027\u505a\u7cbe\u786e\u5339\u914d\u3002\u4e00\u65e6\u5728\u641c\u7d22\u4e2d\u627e\u5230\u4e86\u8be5\u7528\u6237\uff0c\u670d\u52a1\u5668\u4f1a\u65ad\u5f00\u8fde\u63a5\uff0c\u518d\u4f5c\u4e3a\u8be5\u7528\u6237\u91cd\u65b0\u7ed1\u5b9a\u5230\u76ee\u5f55\uff0c\u5e76\u4f7f\u7528\u5ba2\u6237\u7aef\u6307\u5b9a\u7684\u5bc6\u7801\u6765\u9a8c\u8bc1\u767b\u5f55\u662f\u5426\u6b63\u786e\u3002\u8fd9\u79cd\u6a21\u5f0f\u4e0e Apache <code class=\"literal\">mod_authnz_ldap</code> \u548c <code class=\"literal\">pam_ldap</code> \u7b49\u8f6f\u4ef6\u4e2d\u7684 LDAP \u8ba4\u8bc1\u65b9\u6848\u76f8\u540c\u3002\u8fd9\u79cd\u65b9\u6cd5\u4f7f\u76ee\u5f55\u4e2d\u7528\u6237\u5bf9\u8c61\u7684\u4f4d\u7f6e\u66f4\u5177\u7075\u6d3b\u6027\uff0c\u4f46\u4f1a\u4e0e LDAP \u670d\u52a1\u5668\u5efa\u7acb\u4e24\u4e2a\u72ec\u7acb\u7684\u8fde\u63a5\u3002</p>\n<p lang=\"zh\">\u4ee5\u4e0b\u914d\u7f6e\u9009\u9879\u9002\u7528\u4e8e\u4e24\u79cd\u6a21\u5f0f\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapserver</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8981\u8fde\u63a5\u7684LDAP\u670d\u52a1\u5668\u7684\u540d\u79f0\u6216IP\u5730\u5740\u3002\u53ef\u4ee5\u6307\u5b9a\u591a\u4e2a\u670d\u52a1\u5668\uff0c\u7528\u7a7a\u683c\u5206\u9694\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapport</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8981\u8fde\u63a5\u7684LDAP\u670d\u52a1\u5668\u7684\u7aef\u53e3\u53f7\u3002\u5982\u679c\u672a\u6307\u5b9a\u7aef\u53e3\uff0c\u5219\u5c06\u4f7f\u7528LDAP\u5e93\u7684\u9ed8\u8ba4\u7aef\u53e3\u8bbe\u7f6e\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldaptls</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8bbe\u4e3a 1 \u65f6\uff0cPostgreSQL \u4e0e LDAP \u670d\u52a1\u5668\u4e4b\u95f4\u7684\u8fde\u63a5\u4f1a\u4f7f\u7528 TLS \u52a0\u5bc6\u3002\u6ce8\u610f\uff0c\u8fd9\u53ea\u52a0\u5bc6\u4e0e LDAP \u670d\u52a1\u5668\u4e4b\u95f4\u7684\u6d41\u91cf \u2014 \u9664\u975e\u4f7f\u7528 SSL\uff0c\u5426\u5219\u4e0e\u5ba2\u6237\u7aef\u4e4b\u95f4\u7684\u8fde\u63a5\u4ecd\u4e0d\u52a0\u5bc6\u3002</p>\n</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u4ee5\u4e0b\u9009\u9879\u4ec5\u9002\u7528\u4e8e\u7b80\u5355\u7ed1\u5b9a\u6a21\u5f0f\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapprefix</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u7b80\u5355\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u9644\u52a0\u5230\u7528\u6237\u540d\u524d\u9762\u4ee5\u5f62\u6210\u7ed1\u5b9a DN \u7684\u5b57\u7b26\u4e32\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsuffix</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u7b80\u5355\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u9644\u52a0\u5230\u7528\u6237\u540d\u540e\u9762\u4ee5\u5f62\u6210\u7ed1\u5b9a DN \u7684\u5b57\u7b26\u4e32\u3002</p>\n</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u4ee5\u4e0b\u9009\u9879\u4ec5\u9002\u7528\u4e8e\u641c\u7d22\u52a0\u7ed1\u5b9a\u6a21\u5f0f\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapbasedn</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4f5c\u7528\u6237\u641c\u7d22\u8d77\u70b9\u7684\u6839 DN\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapbinddn</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u7ed1\u5b9a\u5230\u76ee\u5f55\u5e76\u6267\u884c\u641c\u7d22\u7684\u7528\u6237 DN\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapbindpasswd</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u7ed1\u5b9a\u5230\u76ee\u5f55\u5e76\u6267\u884c\u641c\u7d22\u7684\u7528\u6237\u5bc6\u7801\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsearchattribute</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u4e0e\u7528\u6237\u540d\u5339\u914d\u7684\u5c5e\u6027\u3002\u5982\u679c\u672a\u6307\u5b9a\u5c5e\u6027\uff0c\u5219\u4f1a\u4f7f\u7528 <code class=\"literal\">uid</code> \u5c5e\u6027\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapurl</code></span></dt>\n<dd>\n<p lang=\"zh\">\u7b26\u5408 RFC 4516 \u7684 LDAP URL\u3002\u8fd9\u662f\u53e6\u4e00\u79cd\u6307\u5b9a\u90e8\u5206 LDAP \u9009\u9879\u7684\u65b9\u5f0f\uff0c\u5199\u6cd5\u66f4\u7d27\u51d1\u3001\u66f4\u6807\u51c6\u3002\u5176\u683c\u5f0f\u4e3a</p>\n<pre class=\"synopsis\">ldap://<em class=\"replaceable\"><code>host</code></em>[:<em class=\"replaceable\"><code>port</code></em>]/<em class=\"replaceable\"><code>basedn</code></em>[?[<em class=\"replaceable\"><code>attribute</code></em>][?[<em class=\"replaceable\"><code>scope</code></em>]]]\n</pre>\n<p lang=\"zh\"><em class=\"replaceable\"><code>scope</code></em> \u5fc5\u987b\u662f\u4ee5\u4e0b\u503c\u4e4b\u4e00\uff1a<code class=\"literal\">base</code>\uff0c<code class=\"literal\">one</code>\uff0c<code class=\"literal\">sub</code>\uff0c\u901a\u5e38\u4f7f\u7528\u6700\u540e\u4e00\u4e2a\u3002\u53ea\u4f1a\u4f7f\u7528\u4e00\u4e2a\u5c5e\u6027\uff0c\u800c\u4e14\u4e0d\u652f\u6301\u6807\u51c6 LDAP URL \u7684\u5176\u4ed6\u67d0\u4e9b\u7ec4\u4ef6\uff0c\u4f8b\u5982\u8fc7\u6ee4\u5668\u548c\u6269\u5c55\u3002</p>\n<p lang=\"zh\">\u5bf9\u4e8e\u975e\u533f\u540d\u7ed1\u5b9a\uff0c\u5fc5\u987b\u5c06<code class=\"literal\">ldapbinddn</code>\u548c<code class=\"literal\">ldapbindpasswd</code>\u6307\u5b9a\u4e3a\u5355\u72ec\u7684\u9009\u9879\u3002</p>\n<p lang=\"zh\">\u8981\u4f7f\u7528\u52a0\u5bc6 LDAP \u8fde\u63a5\uff0c\u9700\u5728 ldapurl \u4e4b\u5916\u4f7f\u7528 ldaptls \u9009\u9879\u3002ldaps URL \u65b9\u6848\uff0c\u5373\u76f4\u63a5\u4f7f\u7528 SSL \u7684\u8fde\u63a5\u65b9\u5f0f\uff0c\u4e0d\u53d7\u652f\u6301\u3002</p>\n<p lang=\"zh\">\u76ee\u524d\u53ea\u6709 OpenLDAP \u652f\u6301 LDAP URL\uff0cWindows \u4e0d\u652f\u6301\u3002</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u5c06\u7b80\u5355\u7ed1\u5b9a\u6a21\u5f0f\u7684\u914d\u7f6e\u9009\u9879\u4e0e\u641c\u7d22+\u7ed1\u5b9a\u6a21\u5f0f\u7684\u914d\u7f6e\u9009\u9879\u6df7\u7528\u662f\u9519\u8bef\u7684\u3002</p>\n<p lang=\"zh\">\u4e0b\u9762\u662f\u4e00\u4e2a\u7b80\u5355\u7ed1\u5b9a LDAP \u914d\u7f6e\u793a\u4f8b\uff1a</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapprefix=\"cn=\" ldapsuffix=\", dc=example, dc=net\"\n</pre>\n<p lang=\"zh\">\u5f53\u8bf7\u6c42\u4ee5\u6570\u636e\u5e93\u7528\u6237 <code class=\"literal\">someuser</code> \u8fde\u63a5\u6570\u636e\u5e93\u670d\u52a1\u5668\u65f6\uff0cPostgreSQL \u5c06\u5c1d\u8bd5\u4f7f\u7528 DN <code class=\"literal\">cn=someuser, dc=example, dc=net</code> \u548c\u5ba2\u6237\u7aef\u63d0\u4f9b\u7684\u5bc6\u7801\u7ed1\u5b9a\u5230 LDAP \u670d\u52a1\u5668\u3002\u5982\u679c\u8be5\u8fde\u63a5\u6210\u529f\uff0c\u6570\u636e\u5e93\u8bbf\u95ee\u5c31\u4f1a\u88ab\u6388\u4e88\u3002</p>\n<p lang=\"zh\">\u4e0b\u9762\u662f\u641c\u7d22\u52a0\u7ed1\u5b9a\u914d\u7f6e\u7684\u793a\u4f8b\uff1a</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapbasedn=\"dc=example, dc=net\" ldapsearchattribute=uid\n</pre>\n<p lang=\"zh\">\u5f53\u8bf7\u6c42\u4ee5\u6570\u636e\u5e93\u7528\u6237 <code class=\"literal\">someuser</code> \u7684\u8eab\u4efd\u8fde\u63a5\u6570\u636e\u5e93\u670d\u52a1\u5668\u65f6\uff0cPostgreSQL \u4f1a\u5c1d\u8bd5\u533f\u540d\u7ed1\u5b9a\u5230 LDAP \u670d\u52a1\u5668\uff08\u56e0\u4e3a\u6ca1\u6709\u6307\u5b9a <code class=\"literal\">ldapbinddn</code>\uff09\uff0c\u5e76\u5728\u6307\u5b9a\u7684\u57fa\u7840 DN \u4e0b\u641c\u7d22 <code class=\"literal\">(uid=someuser)</code>\u3002\u5982\u679c\u627e\u5230\u4e86\u6761\u76ee\uff0c\u5c31\u4f1a\u5c1d\u8bd5\u4f7f\u7528\u627e\u5230\u7684\u4fe1\u606f\u548c\u5ba2\u6237\u7aef\u63d0\u4f9b\u7684\u5bc6\u7801\u8fdb\u884c\u7ed1\u5b9a\u3002\u5982\u679c\u7b2c\u4e8c\u6b21\u8fde\u63a5\u6210\u529f\uff0c\u5c31\u4f1a\u6388\u4e88\u6570\u636e\u5e93\u8bbf\u95ee\u6743\u9650\u3002</p>\n<p lang=\"zh\">\u4e0b\u9762\u662f\u4ee5 URL \u5f62\u5f0f\u5199\u51fa\u7684\u540c\u4e00\u4e2a\u641c\u7d22+\u7ed1\u5b9a\u914d\u7f6e\uff1a</p>\n<pre class=\"programlisting\">host ... ldap ldapurl=\"ldap://ldap.example.net/dc=example,dc=net?uid?sub\"\n</pre>\n<p lang=\"zh\">\u67d0\u4e9b\u652f\u6301 LDAP \u8ba4\u8bc1\u7684\u5176\u4ed6\u8f6f\u4ef6\u4e5f\u4f7f\u7528\u76f8\u540c\u7684 URL \u683c\u5f0f\uff0c\u56e0\u6b64\u5171\u4eab\u8fd9\u7c7b\u914d\u7f6e\u4f1a\u66f4\u5bb9\u6613\u3002</p>\n<div class=\"tip\">\n<h3 class=\"title\" lang=\"zh\">\u63d0\u793a</h3>\n<p lang=\"zh\">\u5982\u793a\u4f8b\u4e2d\u6240\u793a\uff0c\u7531\u4e8e LDAP \u901a\u5e38\u4f7f\u7528\u9017\u53f7\u548c\u7a7a\u683c\u6765\u5206\u5272\u4e00\u4e2a DN \u7684\u4e0d\u540c\u90e8\u5206\uff0c\u5728\u914d\u7f6e LDAP \u9009\u9879\u65f6\u901a\u5e38\u6709\u5fc5\u8981\u4f7f\u7528\u53cc\u5f15\u53f7\u5305\u56f4\u7684\u53c2\u6570\u503c\u3002</p>\n</div>\n</div>", "manual_path": "/docs/10/auth-methods.html#AUTH-LDAP", "localization": {"status": "complete", "sources": [{"url": "/docs/10/auth-methods.html", "method": "same-major semantic node", "sha256": "128b4f29cf06d6bde5b9e357daacb6d538044ee392e4aece0e31c90b0a37b647", "language": "zh", "matched_nodes": ["#AUTH-METHODS/div[1]/dl[0]/dt[6]", "#AUTH-METHODS/div[9]/div[10]/dl[0]/dd[1]", "#AUTH-METHODS/div[9]/div[10]/dl[0]/dd[3]", "#AUTH-METHODS/div[9]/div[10]/dl[0]/dd[5]", "#AUTH-METHODS/div[9]/div[10]/dl[0]/dd[7]", "#AUTH-METHODS/div[9]/div[10]/dl[0]/dd[9]/p[0]", "#AUTH-METHODS/div[9]/div[10]/dl[0]/dd[9]/p[2]", "#AUTH-METHODS/div[9]/div[10]/dl[0]/dd[9]/p[3]", "#AUTH-METHODS/div[9]/div[10]/dl[0]/dd[9]/p[5]", "#AUTH-METHODS/div[9]/div[21]/h3[0]", "#AUTH-METHODS/div[9]/div[21]/p[1]", "#AUTH-METHODS/div[9]/div[6]/dl[0]/dd[1]", "#AUTH-METHODS/div[9]/div[6]/dl[0]/dd[3]", "#AUTH-METHODS/div[9]/div[6]/dl[0]/dd[5]", "#AUTH-METHODS/div[9]/div[8]/dl[0]/dd[1]", "#AUTH-METHODS/div[9]/div[8]/dl[0]/dd[3]", "#AUTH-METHODS/div[9]/p[11]", "#AUTH-METHODS/div[9]/p[12]", "#AUTH-METHODS/div[9]/p[14]", "#AUTH-METHODS/div[9]/p[15]", "#AUTH-METHODS/div[9]/p[17]", "#AUTH-METHODS/div[9]/p[18]", "#AUTH-METHODS/div[9]/p[20]", "#AUTH-METHODS/div[9]/p[2]", "#AUTH-METHODS/div[9]/p[3]", "#AUTH-METHODS/div[9]/p[4]", "#AUTH-METHODS/div[9]/p[5]", "#AUTH-METHODS/div[9]/p[7]", "#AUTH-METHODS/div[9]/p[9]"]}], "language": "zh", "original_text": {"/versions/10/description/0": "Authenticate using an LDAP server. See Section 20.3.7 for details.", "/versions/10/facts/0/label": "Method", "/versions/10/facts/1/label": "Configuration", "/versions/10/facts/2/label": "Inventory", "/versions/10/facts/2/value": "User-visible source authentication method", "/versions/10/tables/0/title": "Documented method options and alternatives", "/versions/10/tables/0/columns/0/label": "Option or term", "/versions/10/tables/0/columns/1/label": "Meaning", "/versions/10/tables/0/rows/0/description": "Names or IP addresses of LDAP servers to connect to. Multiple servers may be specified, separated by spaces.", "/versions/10/tables/0/rows/1/description": "Port number on LDAP server to connect to. If no port is specified, the LDAP library's default port setting will be used.", "/versions/10/tables/0/rows/2/description": "Set to 1 to make the connection between PostgreSQL and the LDAP server use TLS encryption. Note that this only encrypts the traffic to the LDAP server \u2014 the connection to the client will still be unencrypted unless SSL is used.", "/versions/10/tables/0/rows/3/description": "String to prepend to the user name when forming the DN to bind as, when doing simple bind authentication.", "/versions/10/tables/0/rows/4/description": "String to append to the user name when forming the DN to bind as, when doing simple bind authentication.", "/versions/10/tables/0/rows/5/description": "Root DN to begin the search for the user in, when doing search+bind authentication.", "/versions/10/tables/0/rows/6/description": "DN of user to bind to the directory with to perform the search when doing search+bind authentication.", "/versions/10/tables/0/rows/7/description": "Password for user to bind to the directory with to perform the search when doing search+bind authentication.", "/versions/10/tables/0/rows/8/description": "Attribute to match against the user name in the search when doing search+bind authentication. If no attribute is specified, the uid attribute will be used.", "/versions/10/tables/0/rows/9/description": "An RFC 4516 LDAP URL. This is an alternative way to write some of the other LDAP options in a more compact and standard form. The format is ldap:// host [: port ]/ basedn [?[ attribute ][?[ scope ]]] scope must be one of base , one , sub , typically the latter. Only one attribute is used, and some other components of standard LDAP URLs such as filters and extensions are not supported. For non-anonymous binds, ldapbinddn and ldapbindpasswd must be specified as separate options. To use encrypted LDAP connections, the ldaptls option has to be used in addition to ldapurl . The ldaps URL scheme (direct SSL connection) is not supported. LDAP URLs are currently only supported with OpenLDAP, not on Windows."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "e7847b191a11a4529ddb86280c29e743a1b13ff9f32e7aee1888ad82515e4e80"}, "comparison_data": {"method": "ldap", "documented_option_names": ["ldapbasedn", "ldapbinddn", "ldapbindpasswd", "ldapport", "ldapprefix", "ldapsearchattribute", "ldapserver", "ldapsuffix", "ldaptls", "ldapurl"]}, "comparison_hash": "2f2abb5d29b5bd848efcd20de05fe7fdbe01af244252da0a6b5e8de2ef2933fa", "manual_language": "zh"}, "11": {"facts": [{"label": "\u65b9\u6cd5", "value": "ldap"}, {"label": "\u914d\u7f6e", "value": "pg_hba.conf"}, {"label": "\u6e05\u5355", "value": "\u7528\u6237\u53ef\u89c1\u7684\u6e90\u7801\u8ba4\u8bc1\u65b9\u6cd5"}], "tables": [{"key": "method-options", "rows": [{"name": "ldapserver", "description": "\u8981\u8fde\u63a5\u7684LDAP\u670d\u52a1\u5668\u7684\u540d\u79f0\u6216IP\u5730\u5740\u3002\u53ef\u4ee5\u6307\u5b9a\u591a\u4e2a\u670d\u52a1\u5668\uff0c\u7528\u7a7a\u683c\u5206\u9694\u3002"}, {"name": "ldapport", "description": "\u8981\u8fde\u63a5\u7684LDAP\u670d\u52a1\u5668\u7684\u7aef\u53e3\u53f7\u3002\u5982\u679c\u672a\u6307\u5b9a\u7aef\u53e3\uff0c\u5219\u5c06\u4f7f\u7528LDAP\u5e93\u7684\u9ed8\u8ba4\u7aef\u53e3\u8bbe\u7f6e\u3002"}, {"name": "ldapscheme", "description": "\u8bbe\u7f6e\u4e3a ldaps \u4ee5\u4f7f\u7528LDAPS\u3002\u8fd9\u662f\u4e00\u79cd\u975e\u6807\u51c6\u7684\u901a\u8fc7 SSL \u4f7f\u7528 LDAP \u7684\u65b9\u5f0f\uff0c\u53d7\u4e00\u4e9bLDAP\u670d\u52a1\u5668\u5b9e\u73b0\u652f\u6301\u3002\u53e6\u8bf7\u53c2\u9605 ldaptls \u9009\u9879\u4f5c\u4e3a\u66ff\u4ee3\u3002"}, {"name": "ldaptls", "description": "\u8bbe\u7f6e\u4e3a 1 \u65f6\uff0cPostgreSQL \u4e0e LDAP \u670d\u52a1\u5668\u4e4b\u95f4\u7684\u8fde\u63a5\u4f7f\u7528 TLS \u52a0\u5bc6\uff0c\u901a\u8fc7 RFC 4513 \u89c4\u5b9a\u7684 StartTLS \u64cd\u4f5c\u5b9e\u73b0\u3002\u53e6\u53ef\u53c2\u89c1 ldapscheme \u9009\u9879\u6240\u63d0\u4f9b\u7684\u66ff\u4ee3\u65b9\u5f0f\u3002"}, {"name": "ldapprefix", "description": "\u5728\u8fdb\u884c\u7b80\u5355\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u9644\u52a0\u5230\u7528\u6237\u540d\u524d\u9762\u4ee5\u5f62\u6210\u7ed1\u5b9a DN \u7684\u5b57\u7b26\u4e32\u3002"}, {"name": "ldapsuffix", "description": "\u5728\u8fdb\u884c\u7b80\u5355\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u9644\u52a0\u5230\u7528\u6237\u540d\u540e\u9762\u4ee5\u5f62\u6210\u7ed1\u5b9a DN \u7684\u5b57\u7b26\u4e32\u3002"}, {"name": "ldapbasedn", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4f5c\u7528\u6237\u641c\u7d22\u8d77\u70b9\u7684\u6839 DN\u3002"}, {"name": "ldapbinddn", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u7ed1\u5b9a\u5230\u76ee\u5f55\u5e76\u6267\u884c\u641c\u7d22\u7684\u7528\u6237 DN\u3002"}, {"name": "ldapbindpasswd", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u7ed1\u5b9a\u5230\u76ee\u5f55\u5e76\u6267\u884c\u641c\u7d22\u7684\u7528\u6237\u5bc6\u7801\u3002"}, {"name": "ldapsearchattribute", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u4e0e\u7528\u6237\u540d\u5339\u914d\u7684\u5c5e\u6027\u3002\u5982\u679c\u672a\u6307\u5b9a\u5c5e\u6027\uff0c\u5219\u4f1a\u4f7f\u7528 uid \u5c5e\u6027\u3002"}, {"name": "ldapsearchfilter", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\u4f7f\u7528\u7684\u641c\u7d22\u8fc7\u6ee4\u5668\u3002\u5176\u4e2d\u51fa\u73b0\u7684 $username \u4f1a\u88ab\u66ff\u6362\u4e3a\u7528\u6237\u540d\u3002\u8fd9\u4f7f\u5f97\u641c\u7d22\u8fc7\u6ee4\u5668\u6bd4 ldapsearchattribute \u66f4\u7075\u6d3b\u3002"}, {"name": "ldapurl", "description": "\u7b26\u5408 RFC 4516 \u7684 LDAP URL\u3002\u5b83\u4ee5\u66f4\u7d27\u51d1\u3001\u6807\u51c6\u7684\u5f62\u5f0f\u66ff\u4ee3\u90e8\u5206\u5176\u4ed6 LDAP \u9009\u9879\u3002\u683c\u5f0f\u4e3a ldap[s]://host[:port]/basedn[?[attribute][?[scope][?[filter]]]]\u3002scope \u5fc5\u987b\u4e3a base\u3001one \u6216 sub\uff0c\u901a\u5e38\u4f7f\u7528 sub\uff1b\u9ed8\u8ba4\u503c base \u5728\u6b64\u7528\u9014\u4e0b\u4e00\u822c\u6ca1\u6709\u5b9e\u9645\u5e2e\u52a9\u3002attribute \u53ef\u6307\u5b9a\u4e00\u4e2a\u5c5e\u6027\uff0c\u4f5c\u4e3a ldapsearchattribute \u7684\u503c\uff1battribute \u4e3a\u7a7a\u65f6\uff0cfilter \u53ef\u7528\u4f5c ldapsearchfilter \u7684\u503c\u3002URL \u65b9\u6848 ldaps \u8868\u793a\u901a\u8fc7 SSL \u5efa\u7acb LDAP \u8fde\u63a5\uff0c\u7b49\u540c\u4e8e ldapscheme=ldaps\u3002\u82e5\u8981\u901a\u8fc7 StartTLS \u4f7f\u7528\u52a0\u5bc6 LDAP \u8fde\u63a5\uff0c\u5e94\u4f7f\u7528\u666e\u901a\u7684 ldap URL \u65b9\u6848\uff0c\u5e76\u5728 ldapurl \u4e4b\u5916\u6307\u5b9a ldaptls\u3002\u5bf9\u4e8e\u975e\u533f\u540d\u7ed1\u5b9a\uff0c\u5fc5\u987b\u53e6\u884c\u6307\u5b9a ldapbinddn \u548c ldapbindpasswd\u3002LDAP URL \u76ee\u524d\u4ec5\u5728 OpenLDAP \u4e2d\u53d7\u652f\u6301\uff0cWindows \u4e0d\u652f\u6301\u3002"}], "title": "\u624b\u518c\u4e2d\u7684\u65b9\u6cd5\u9009\u9879\u4e0e\u66ff\u4ee3\u65b9\u5f0f", "columns": [{"key": "name", "label": "\u9009\u9879\u6216\u672f\u8bed"}, {"key": "description", "label": "\u542b\u4e49"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v11.22/postgresql-11.22.tar.bz2", "label": "11.22", "major": "11", "channel": "historical", "revision": "2cb7c97d7a0d7278851bbc9c61f467b69c094c72b81740b751108e7892ebe1f0", "source_sha256": "2cb7c97d7a0d7278851bbc9c61f467b69c094c72b81740b751108e7892ebe1f0", "catalog_fingerprint": "8f21f4444b7f68923f4762af0eb7937fa2907026e91249483e79050de012c901"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v11.22/postgresql-11.22.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "2cb7c97d7a0d7278851bbc9c61f467b69c094c72b81740b751108e7892ebe1f0"}, {"url": "https://pg.center/docs/11/auth-ldap.html", "path": "auth-ldap.html", "label": "PostgreSQL 11 English manual", "sha256": "203b80156660ac4546cd1769ab2acc110aa9abf472688031309458a9798dd37a", "language": "en", "original_url": "/docs/11/auth-ldap.html"}, {"url": "https://pg.center/docs/11/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 11 English manual", "sha256": "5477c61a002171f5b4c462052d91231c405f39d89d825faf71e52fbae358eef7", "language": "en", "original_url": "/docs/11/auth-pg-hba-conf.html"}], "sections": [], "signature": "", "attributes": {"method": "ldap", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["\u4f7f\u7528 LDAP \u670d\u52a1\u5668\u8fdb\u884c\u8ba4\u8bc1\u3002\u8be6\u60c5\u53c2\u89c1\u7b2c 20.10 \u8282\u3002"], "manual_html": "<div class=\"sect1\" id=\"AUTH-LDAP\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\" lang=\"zh\">\n<div>\n<div>\n<h2 class=\"title\" style=\"clear: both\">20.10.\u00a0LDAP \u8ba4\u8bc1 </h2>\n</div>\n</div>\n</h2>\n</div>\n</div>\n</div>\n<p lang=\"zh\">\u8fd9\u79cd\u8ba4\u8bc1\u65b9\u6cd5\u7684\u5de5\u4f5c\u65b9\u5f0f\u4e0e <code class=\"literal\">password</code> \u7c7b\u4f3c\uff0c\u53ea\u4e0d\u8fc7\u5b83\u4f7f\u7528 LDAP \u4f5c\u4e3a\u5bc6\u7801\u9a8c\u8bc1\u65b9\u6cd5\u3002LDAP \u53ea\u7528\u4e8e\u9a8c\u8bc1\u7528\u6237\u540d/\u5bc6\u7801\u5bf9\u3002\u56e0\u6b64\uff0c\u5728\u4f7f\u7528 LDAP \u8fdb\u884c\u8ba4\u8bc1\u4e4b\u524d\uff0c\u7528\u6237\u5fc5\u987b\u5df2\u7ecf\u5b58\u5728\u4e8e\u6570\u636e\u5e93\u4e2d\u3002</p>\n<p lang=\"zh\">LDAP \u8ba4\u8bc1\u53ef\u4ee5\u5728\u4e24\u79cd\u6a21\u5f0f\u4e0b\u5de5\u4f5c\u3002\u7b2c\u4e00\u79cd\u6a21\u5f0f\u79f0\u4e3a\u7b80\u5355\u7ed1\u5b9a\u6a21\u5f0f\uff0c\u670d\u52a1\u5668\u4f1a\u7ed1\u5b9a\u5230\u6309 <em class=\"replaceable\"><code>prefix</code></em> <em class=\"replaceable\"><code>username</code></em> <em class=\"replaceable\"><code>suffix</code></em> \u5f62\u5f0f\u6784\u9020\u51fa\u7684\u53ef\u5206\u8fa8\u540d\u79f0\u3002\u901a\u5e38\uff0c<em class=\"replaceable\"><code>prefix</code></em> \u53c2\u6570\u7528\u4e8e\u6307\u5b9a <code class=\"literal\">cn=</code>\uff0c\u6216\u5728 Active Directory \u73af\u5883\u4e2d\u6307\u5b9a <em class=\"replaceable\"><code>DOMAIN</code></em><code class=\"literal\">\\</code>\u3002<em class=\"replaceable\"><code>suffix</code></em> \u5219\u7528\u4e8e\u6307\u5b9a\u975e Active Directory \u73af\u5883\u4e2d DN \u7684\u5269\u4f59\u90e8\u5206\u3002</p>\n<p lang=\"zh\">\u7b2c\u4e8c\u79cd\u6a21\u5f0f\u79f0\u4e3a\u641c\u7d22+\u7ed1\u5b9a\u6a21\u5f0f\uff0c\u670d\u52a1\u5668\u9996\u5148\u4f7f\u7528\u7531 <em class=\"replaceable\"><code>ldapbinddn</code></em> \u548c <em class=\"replaceable\"><code>ldapbindpasswd</code></em> \u6307\u5b9a\u7684\u56fa\u5b9a\u7528\u6237\u540d\u548c\u5bc6\u7801\u7ed1\u5b9a\u5230 LDAP \u76ee\u5f55\uff0c\u5e76\u641c\u7d22\u8bd5\u56fe\u767b\u5f55\u6570\u636e\u5e93\u7684\u7528\u6237\u3002\u5982\u679c\u6ca1\u6709\u914d\u7f6e\u7528\u6237\u540d\u548c\u5bc6\u7801\uff0c\u5219\u4f1a\u5c1d\u8bd5\u5bf9\u76ee\u5f55\u8fdb\u884c\u533f\u540d\u7ed1\u5b9a\u3002\u641c\u7d22\u4f1a\u5728 <em class=\"replaceable\"><code>ldapbasedn</code></em> \u6307\u5b9a\u7684\u5b50\u6811\u4e0a\u8fdb\u884c\uff0c\u5e76\u5c1d\u8bd5\u5bf9 <em class=\"replaceable\"><code>ldapsearchattribute</code></em> \u6307\u5b9a\u7684\u5c5e\u6027\u505a\u7cbe\u786e\u5339\u914d\u3002\u4e00\u65e6\u5728\u641c\u7d22\u4e2d\u627e\u5230\u4e86\u8be5\u7528\u6237\uff0c\u670d\u52a1\u5668\u4f1a\u65ad\u5f00\u8fde\u63a5\uff0c\u518d\u4f5c\u4e3a\u8be5\u7528\u6237\u91cd\u65b0\u7ed1\u5b9a\u5230\u76ee\u5f55\uff0c\u5e76\u4f7f\u7528\u5ba2\u6237\u7aef\u6307\u5b9a\u7684\u5bc6\u7801\u6765\u9a8c\u8bc1\u767b\u5f55\u662f\u5426\u6b63\u786e\u3002\u8fd9\u79cd\u6a21\u5f0f\u4e0e Apache <code class=\"literal\">mod_authnz_ldap</code> \u548c <code class=\"literal\">pam_ldap</code> \u7b49\u8f6f\u4ef6\u4e2d\u7684 LDAP \u8ba4\u8bc1\u65b9\u6848\u76f8\u540c\u3002\u8fd9\u79cd\u65b9\u6cd5\u4f7f\u76ee\u5f55\u4e2d\u7528\u6237\u5bf9\u8c61\u7684\u4f4d\u7f6e\u66f4\u5177\u7075\u6d3b\u6027\uff0c\u4f46\u4f1a\u4e0e LDAP \u670d\u52a1\u5668\u5efa\u7acb\u4e24\u4e2a\u72ec\u7acb\u7684\u8fde\u63a5\u3002</p>\n<p lang=\"zh\">\u4ee5\u4e0b\u914d\u7f6e\u9009\u9879\u5728\u4e24\u79cd\u6a21\u5f0f\u4e0b\u90fd\u4f7f\u7528\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapserver</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8981\u8fde\u63a5\u7684LDAP\u670d\u52a1\u5668\u7684\u540d\u79f0\u6216IP\u5730\u5740\u3002\u53ef\u4ee5\u6307\u5b9a\u591a\u4e2a\u670d\u52a1\u5668\uff0c\u7528\u7a7a\u683c\u5206\u9694\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapport</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8981\u8fde\u63a5\u7684LDAP\u670d\u52a1\u5668\u7684\u7aef\u53e3\u53f7\u3002\u5982\u679c\u672a\u6307\u5b9a\u7aef\u53e3\uff0c\u5219\u5c06\u4f7f\u7528LDAP\u5e93\u7684\u9ed8\u8ba4\u7aef\u53e3\u8bbe\u7f6e\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapscheme</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8bbe\u7f6e\u4e3a<code class=\"literal\">ldaps</code>\u4ee5\u4f7f\u7528LDAPS\u3002\u8fd9\u662f\u4e00\u79cd\u975e\u6807\u51c6\u7684\u901a\u8fc7 SSL \u4f7f\u7528 LDAP \u7684\u65b9\u5f0f\uff0c\u53d7\u4e00\u4e9bLDAP\u670d\u52a1\u5668\u5b9e\u73b0\u652f\u6301\u3002\u53e6\u8bf7\u53c2\u9605<code class=\"literal\">ldaptls</code> \u9009\u9879\u4f5c\u4e3a\u66ff\u4ee3\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldaptls</code></span></dt>\n<dd>\n<p lang=\"zh\">\u8bbe\u7f6e\u4e3a 1 \u65f6\uff0cPostgreSQL \u4e0e LDAP \u670d\u52a1\u5668\u4e4b\u95f4\u7684\u8fde\u63a5\u4f7f\u7528 TLS \u52a0\u5bc6\uff0c\u901a\u8fc7 RFC 4513 \u89c4\u5b9a\u7684 StartTLS \u64cd\u4f5c\u5b9e\u73b0\u3002\u53e6\u53ef\u53c2\u89c1 ldapscheme \u9009\u9879\u6240\u63d0\u4f9b\u7684\u66ff\u4ee3\u65b9\u5f0f\u3002</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u6ce8\u610f\u4f7f\u7528<code class=\"literal\">ldapscheme</code>\u6216<code class=\"literal\">ldaptls</code>\u4ec5\u4f1a\u52a0\u5bc6PostgreSQL \u670d\u52a1\u5668\u548cLDAP\u670d\u52a1\u5668\u4e4b\u95f4\u7684\u901a\u4fe1\u3002PostgreSQL \u670d\u52a1\u5668\u548cPostgreSQL\u5ba2\u6237\u7aef\u4e4b\u95f4\u7684\u8fde\u63a5\u4ecd\u662f\u672a\u52a0\u5bc6\u7684\uff0c\u9664\u975e\u4e5f\u5728\u5176\u4e0a\u4f7f\u7528SSL\u3002</p>\n<p lang=\"zh\">\u4e0b\u5217\u9009\u9879\u53ea\u88ab\u7528\u4e8e\u7b80\u5355\u7ed1\u5b9a\u6a21\u5f0f\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapprefix</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u7b80\u5355\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u9644\u52a0\u5230\u7528\u6237\u540d\u524d\u9762\u4ee5\u5f62\u6210\u7ed1\u5b9a DN \u7684\u5b57\u7b26\u4e32\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsuffix</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u7b80\u5355\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u9644\u52a0\u5230\u7528\u6237\u540d\u540e\u9762\u4ee5\u5f62\u6210\u7ed1\u5b9a DN \u7684\u5b57\u7b26\u4e32\u3002</p>\n</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u4ee5\u4e0b\u9009\u9879\u4ec5\u5728\u641c\u7d22+\u7ed1\u5b9a\u6a21\u5f0f\u4e2d\u4f7f\u7528\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapbasedn</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4f5c\u7528\u6237\u641c\u7d22\u8d77\u70b9\u7684\u6839 DN\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapbinddn</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u7ed1\u5b9a\u5230\u76ee\u5f55\u5e76\u6267\u884c\u641c\u7d22\u7684\u7528\u6237 DN\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapbindpasswd</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u7ed1\u5b9a\u5230\u76ee\u5f55\u5e76\u6267\u884c\u641c\u7d22\u7684\u7528\u6237\u5bc6\u7801\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsearchattribute</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u4e0e\u7528\u6237\u540d\u5339\u914d\u7684\u5c5e\u6027\u3002\u5982\u679c\u672a\u6307\u5b9a\u5c5e\u6027\uff0c\u5219\u4f1a\u4f7f\u7528 <code class=\"literal\">uid</code> \u5c5e\u6027\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsearchfilter</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\u4f7f\u7528\u7684\u641c\u7d22\u8fc7\u6ee4\u5668\u3002\u5176\u4e2d\u51fa\u73b0\u7684 <code class=\"literal\">$username</code> \u4f1a\u88ab\u66ff\u6362\u4e3a\u7528\u6237\u540d\u3002\u8fd9\u4f7f\u5f97\u641c\u7d22\u8fc7\u6ee4\u5668\u6bd4 <code class=\"literal\">ldapsearchattribute</code> \u66f4\u7075\u6d3b\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapurl</code></span></dt>\n<dd>\n<p lang=\"zh\">\u7b26\u5408 RFC 4516 \u7684 LDAP URL\u3002\u8fd9\u662f\u53e6\u4e00\u79cd\u6307\u5b9a\u90e8\u5206 LDAP \u9009\u9879\u7684\u65b9\u5f0f\uff0c\u5199\u6cd5\u66f4\u7d27\u51d1\u3001\u66f4\u6807\u51c6\u3002\u5176\u683c\u5f0f\u4e3a</p>\n<pre class=\"synopsis\">ldap[s]://<em class=\"replaceable\"><code>host</code></em>[:<em class=\"replaceable\"><code>port</code></em>]/<em class=\"replaceable\"><code>basedn</code></em>[?[<em class=\"replaceable\"><code>attribute</code></em>][?[<em class=\"replaceable\"><code>scope</code></em>][?[<em class=\"replaceable\"><code>filter</code></em>]]]]\n</pre>\n<p lang=\"zh\"><em class=\"replaceable\"><code>scope</code></em> \u5fc5\u987b\u662f\u4ee5\u4e0b\u503c\u4e4b\u4e00\uff1a<code class=\"literal\">base</code>\uff0c<code class=\"literal\">one</code>\uff0c<code class=\"literal\">sub</code>\uff0c\u901a\u5e38\u4f7f\u7528\u6700\u540e\u4e00\u4e2a\u3002\uff08\u9ed8\u8ba4\u503c\u4e3a <code class=\"literal\">base</code>\uff0c\u901a\u5e38\u4e0d\u9002\u7528\u4e8e\u8fd9\u91cc\u7684\u7528\u9014\u3002\uff09<em class=\"replaceable\"><code>attribute</code></em> \u53ef\u4ee5\u6307\u5b9a\u5355\u4e2a\u5c5e\u6027\uff0c\u5e76\u7528\u5b83\u8bbe\u7f6e <code class=\"literal\">ldapsearchattribute</code>\u3002\u5982\u679c <em class=\"replaceable\"><code>attribute</code></em> \u4e3a\u7a7a\uff0c\u5219\u53ef\u4ee5\u7528 <em class=\"replaceable\"><code>filter</code></em> \u8bbe\u7f6e <code class=\"literal\">ldapsearchfilter</code>\u3002</p>\n<p lang=\"zh\">URL \u65b9\u6848 ldaps \u9009\u62e9\u901a\u8fc7 SSL \u5efa\u7acb LDAP \u8fde\u63a5\u7684 LDAPS \u65b9\u5f0f\uff0c\u7b49\u4ef7\u4e8e ldapscheme=ldaps\u3002\u8981\u901a\u8fc7 StartTLS \u4f7f\u7528\u52a0\u5bc6 LDAP \u8fde\u63a5\uff0c\u5e94\u4f7f\u7528\u666e\u901a\u7684 ldap URL \u65b9\u6848\uff0c\u5e76\u5728 ldapurl \u4e4b\u5916\u6307\u5b9a ldaptls\u3002</p>\n<p lang=\"zh\">\u5bf9\u4e8e\u975e\u533f\u540d\u7ed1\u5b9a\uff0c\u5fc5\u987b\u5c06<code class=\"literal\">ldapbinddn</code>\u548c<code class=\"literal\">ldapbindpasswd</code>\u6307\u5b9a\u4e3a\u5355\u72ec\u7684\u9009\u9879\u3002</p>\n<p lang=\"zh\">\u76ee\u524d\u53ea\u6709 OpenLDAP \u652f\u6301 LDAP URL\uff0cWindows \u4e0d\u652f\u6301\u3002</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u5c06\u7b80\u5355\u7ed1\u5b9a\u6a21\u5f0f\u7684\u914d\u7f6e\u9009\u9879\u4e0e\u641c\u7d22+\u7ed1\u5b9a\u6a21\u5f0f\u7684\u914d\u7f6e\u9009\u9879\u6df7\u7528\u662f\u9519\u8bef\u7684\u3002</p>\n<p lang=\"zh\">\u5728\u4f7f\u7528\u641c\u7d22+\u7ed1\u5b9a\u6a21\u5f0f\u65f6\uff0c\u53ef\u4ee5\u4f7f\u7528\u7531 <code class=\"literal\">ldapsearchattribute</code> \u6307\u5b9a\u7684\u5355\u4e2a\u5c5e\u6027\u6267\u884c\u641c\u7d22\uff0c\u4e5f\u53ef\u4ee5\u4f7f\u7528\u7531 <code class=\"literal\">ldapsearchfilter</code> \u6307\u5b9a\u7684\u81ea\u5b9a\u4e49\u641c\u7d22\u8fc7\u6ee4\u5668\u6267\u884c\u641c\u7d22\u3002\u6307\u5b9a <code class=\"literal\">ldapsearchattribute=foo</code> \u7b49\u4ef7\u4e8e\u6307\u5b9a <code class=\"literal\">ldapsearchfilter=\"(foo=$username)\"</code>\u3002\u5982\u679c\u4e24\u4e2a\u9009\u9879\u90fd\u672a\u6307\u5b9a\uff0c\u5219\u9ed8\u8ba4\u4f7f\u7528 <code class=\"literal\">ldapsearchattribute=uid</code>\u3002</p>\n<p lang=\"zh\">\u4e0b\u9762\u662f\u4e00\u4e2a\u7b80\u5355\u7ed1\u5b9a LDAP \u914d\u7f6e\u793a\u4f8b\uff1a</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapprefix=\"cn=\" ldapsuffix=\", dc=example, dc=net\"\n</pre>\n<p lang=\"zh\">\u5f53\u8bf7\u6c42\u4ee5\u6570\u636e\u5e93\u7528\u6237 <code class=\"literal\">someuser</code> \u8fde\u63a5\u6570\u636e\u5e93\u670d\u52a1\u5668\u65f6\uff0cPostgreSQL \u5c06\u5c1d\u8bd5\u4f7f\u7528 DN <code class=\"literal\">cn=someuser, dc=example, dc=net</code> \u548c\u5ba2\u6237\u7aef\u63d0\u4f9b\u7684\u5bc6\u7801\u7ed1\u5b9a\u5230 LDAP \u670d\u52a1\u5668\u3002\u5982\u679c\u8be5\u8fde\u63a5\u6210\u529f\uff0c\u6570\u636e\u5e93\u8bbf\u95ee\u5c31\u4f1a\u88ab\u6388\u4e88\u3002</p>\n<p lang=\"zh\">\u4e0b\u9762\u662f\u641c\u7d22\u52a0\u7ed1\u5b9a\u914d\u7f6e\u7684\u793a\u4f8b\uff1a</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapbasedn=\"dc=example, dc=net\" ldapsearchattribute=uid\n</pre>\n<p lang=\"zh\">\u5f53\u8bf7\u6c42\u4ee5\u6570\u636e\u5e93\u7528\u6237 <code class=\"literal\">someuser</code> \u7684\u8eab\u4efd\u8fde\u63a5\u6570\u636e\u5e93\u670d\u52a1\u5668\u65f6\uff0cPostgreSQL \u4f1a\u5c1d\u8bd5\u533f\u540d\u7ed1\u5b9a\u5230 LDAP \u670d\u52a1\u5668\uff08\u56e0\u4e3a\u6ca1\u6709\u6307\u5b9a <code class=\"literal\">ldapbinddn</code>\uff09\uff0c\u5e76\u5728\u6307\u5b9a\u7684\u57fa\u7840 DN \u4e0b\u641c\u7d22 <code class=\"literal\">(uid=someuser)</code>\u3002\u5982\u679c\u627e\u5230\u4e86\u6761\u76ee\uff0c\u5c31\u4f1a\u5c1d\u8bd5\u4f7f\u7528\u627e\u5230\u7684\u4fe1\u606f\u548c\u5ba2\u6237\u7aef\u63d0\u4f9b\u7684\u5bc6\u7801\u8fdb\u884c\u7ed1\u5b9a\u3002\u5982\u679c\u7b2c\u4e8c\u6b21\u8fde\u63a5\u6210\u529f\uff0c\u5c31\u4f1a\u6388\u4e88\u6570\u636e\u5e93\u8bbf\u95ee\u6743\u9650\u3002</p>\n<p lang=\"zh\">\u4e0b\u9762\u662f\u4ee5 URL \u5f62\u5f0f\u5199\u51fa\u7684\u540c\u4e00\u4e2a\u641c\u7d22+\u7ed1\u5b9a\u914d\u7f6e\uff1a</p>\n<pre class=\"programlisting\">host ... ldap ldapurl=\"ldap://ldap.example.net/dc=example,dc=net?uid?sub\"\n</pre>\n<p lang=\"zh\">\u67d0\u4e9b\u652f\u6301 LDAP \u8ba4\u8bc1\u7684\u5176\u4ed6\u8f6f\u4ef6\u4e5f\u4f7f\u7528\u76f8\u540c\u7684 URL \u683c\u5f0f\uff0c\u56e0\u6b64\u5171\u4eab\u8fd9\u7c7b\u914d\u7f6e\u4f1a\u66f4\u5bb9\u6613\u3002</p>\n<p lang=\"zh\">\u8fd9\u91cc\u662f\u4e00\u4e2a\u641c\u7d22+\u7ed1\u5b9a\u914d\u7f6e\u7684\u793a\u4f8b\uff0c\u5b83\u4f7f\u7528 <code class=\"literal\">ldapsearchfilter</code> \u800c\u4e0d\u662f <code class=\"literal\">ldapsearchattribute</code> \u6765\u5141\u8bb8\u7528\u7528\u6237 ID \u6216\u7535\u5b50\u90ae\u4ef6\u5730\u5740\u8fdb\u884c\u8ba4\u8bc1\uff1a</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapbasedn=\"dc=example, dc=net\" ldapsearchfilter=\"(|(uid=$username)(mail=$username))\"\n</pre>\n<div class=\"tip\">\n<h3 class=\"title\" lang=\"zh\">\u63d0\u793a</h3>\n<p lang=\"zh\">\u5982\u793a\u4f8b\u4e2d\u6240\u793a\uff0c\u7531\u4e8e LDAP \u901a\u5e38\u4f7f\u7528\u9017\u53f7\u548c\u7a7a\u683c\u6765\u5206\u5272\u4e00\u4e2a DN \u7684\u4e0d\u540c\u90e8\u5206\uff0c\u5728\u914d\u7f6e LDAP \u9009\u9879\u65f6\u901a\u5e38\u6709\u5fc5\u8981\u4f7f\u7528\u53cc\u5f15\u53f7\u5305\u56f4\u7684\u53c2\u6570\u503c\u3002</p>\n</div>\n</div>", "manual_path": "/docs/11/auth-ldap.html", "localization": {"status": "complete", "sources": [{"url": "/docs/11/auth-ldap.html", "method": "same-major semantic node", "sha256": "e101b7d334a59251d2c5811a081e46dc4a68e9e89e7c8857dd70856643b6c173", "language": "zh", "matched_nodes": ["#AUTH-LDAP/div[0]", "#AUTH-LDAP/div[11]/dl[0]/dd[11]/p[0]", "#AUTH-LDAP/div[11]/dl[0]/dd[11]/p[2]", "#AUTH-LDAP/div[11]/dl[0]/dd[11]/p[4]", "#AUTH-LDAP/div[11]/dl[0]/dd[11]/p[5]", "#AUTH-LDAP/div[11]/dl[0]/dd[1]", "#AUTH-LDAP/div[11]/dl[0]/dd[3]", "#AUTH-LDAP/div[11]/dl[0]/dd[5]", "#AUTH-LDAP/div[11]/dl[0]/dd[7]", "#AUTH-LDAP/div[11]/dl[0]/dd[9]", "#AUTH-LDAP/div[25]/h3[0]", "#AUTH-LDAP/div[25]/p[1]", "#AUTH-LDAP/div[6]/dl[0]/dd[1]", "#AUTH-LDAP/div[6]/dl[0]/dd[3]", "#AUTH-LDAP/div[6]/dl[0]/dd[5]", "#AUTH-LDAP/div[9]/dl[0]/dd[1]", "#AUTH-LDAP/div[9]/dl[0]/dd[3]", "#AUTH-LDAP/p[10]", "#AUTH-LDAP/p[12]", "#AUTH-LDAP/p[13]", "#AUTH-LDAP/p[14]", "#AUTH-LDAP/p[16]", "#AUTH-LDAP/p[17]", "#AUTH-LDAP/p[19]", "#AUTH-LDAP/p[20]", "#AUTH-LDAP/p[22]", "#AUTH-LDAP/p[23]", "#AUTH-LDAP/p[2]", "#AUTH-LDAP/p[3]", "#AUTH-LDAP/p[4]", "#AUTH-LDAP/p[5]", "#AUTH-LDAP/p[7]", "#AUTH-LDAP/p[8]"]}], "language": "zh", "original_text": {"/versions/11/description/0": "Authenticate using an LDAP server. See Section 20.10 for details.", "/versions/11/facts/0/label": "Method", "/versions/11/facts/1/label": "Configuration", "/versions/11/facts/2/label": "Inventory", "/versions/11/facts/2/value": "User-visible source authentication method", "/versions/11/tables/0/title": "Documented method options and alternatives", "/versions/11/tables/0/columns/0/label": "Option or term", "/versions/11/tables/0/columns/1/label": "Meaning", "/versions/11/tables/0/rows/0/description": "Names or IP addresses of LDAP servers to connect to. Multiple servers may be specified, separated by spaces.", "/versions/11/tables/0/rows/1/description": "Port number on LDAP server to connect to. If no port is specified, the LDAP library's default port setting will be used.", "/versions/11/tables/0/rows/2/description": "Set to ldaps to use LDAPS. This is a non-standard way of using LDAP over SSL, supported by some LDAP server implementations. See also the ldaptls option for an alternative.", "/versions/11/tables/0/rows/3/description": "Set to 1 to make the connection between PostgreSQL and the LDAP server use TLS encryption. This uses the StartTLS operation per RFC 4513. See also the ldapscheme option for an alternative.", "/versions/11/tables/0/rows/4/description": "String to prepend to the user name when forming the DN to bind as, when doing simple bind authentication.", "/versions/11/tables/0/rows/5/description": "String to append to the user name when forming the DN to bind as, when doing simple bind authentication.", "/versions/11/tables/0/rows/6/description": "Root DN to begin the search for the user in, when doing search+bind authentication.", "/versions/11/tables/0/rows/7/description": "DN of user to bind to the directory with to perform the search when doing search+bind authentication.", "/versions/11/tables/0/rows/8/description": "Password for user to bind to the directory with to perform the search when doing search+bind authentication.", "/versions/11/tables/0/rows/9/description": "Attribute to match against the user name in the search when doing search+bind authentication. If no attribute is specified, the uid attribute will be used.", "/versions/11/tables/0/rows/10/description": "The search filter to use when doing search+bind authentication. Occurrences of $username will be replaced with the user name. This allows for more flexible search filters than ldapsearchattribute .", "/versions/11/tables/0/rows/11/description": "An RFC 4516 LDAP URL. This is an alternative way to write some of the other LDAP options in a more compact and standard form. The format is ldap[s]:// host [: port ]/ basedn [?[ attribute ][?[ scope ][?[ filter ]]]] scope must be one of base , one , sub , typically the last. (The default is base , which is normally not useful in this application.) attribute can nominate a single attribute, in which case it is used as a value for ldapsearchattribute . If attribute is empty then filter can be used as a value for ldapsearchfilter . The URL scheme ldaps chooses the LDAPS method for making LDAP connections over SSL, equivalent to using ldapscheme=ldaps . To use encrypted LDAP connections using the StartTLS operation, use the normal URL scheme ldap and specify the ldaptls option in addition to ldapurl . For non-anonymous binds, ldapbinddn and ldapbindpasswd must be specified as separate options. LDAP URLs are currently only supported with OpenLDAP, not on Windows."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "ae6923e5191460f73636b82993c9b14a49487564b7ae77744a190025a1ae96ea"}, "comparison_data": {"method": "ldap", "documented_option_names": ["ldapbasedn", "ldapbinddn", "ldapbindpasswd", "ldapport", "ldapprefix", "ldapscheme", "ldapsearchattribute", "ldapsearchfilter", "ldapserver", "ldapsuffix", "ldaptls", "ldapurl"]}, "comparison_hash": "d40de945ae67b3ac60a284fdd442cc24a4e9d05bc7a7b18009b54e491c381b88", "manual_language": "zh"}, "12": {"facts": [{"label": "\u65b9\u6cd5", "value": "ldap"}, {"label": "\u914d\u7f6e", "value": "pg_hba.conf"}, {"label": "\u6e05\u5355", "value": "\u7528\u6237\u53ef\u89c1\u7684\u6e90\u7801\u8ba4\u8bc1\u65b9\u6cd5"}], "tables": [{"key": "method-options", "rows": [{"name": "ldapserver", "description": "\u8981\u8fde\u63a5\u7684LDAP\u670d\u52a1\u5668\u7684\u540d\u79f0\u6216IP\u5730\u5740\u3002\u53ef\u4ee5\u6307\u5b9a\u591a\u4e2a\u670d\u52a1\u5668\uff0c\u7528\u7a7a\u683c\u5206\u9694\u3002"}, {"name": "ldapport", "description": "\u8981\u8fde\u63a5\u7684LDAP\u670d\u52a1\u5668\u7684\u7aef\u53e3\u53f7\u3002\u5982\u679c\u672a\u6307\u5b9a\u7aef\u53e3\uff0c\u5219\u5c06\u4f7f\u7528LDAP\u5e93\u7684\u9ed8\u8ba4\u7aef\u53e3\u8bbe\u7f6e\u3002"}, {"name": "ldapscheme", "description": "\u8bbe\u7f6e\u4e3a ldaps \u4ee5\u4f7f\u7528LDAPS\u3002\u8fd9\u662f\u4e00\u79cd\u975e\u6807\u51c6\u7684\u901a\u8fc7 SSL \u4f7f\u7528 LDAP \u7684\u65b9\u5f0f\uff0c\u53d7\u4e00\u4e9bLDAP\u670d\u52a1\u5668\u5b9e\u73b0\u652f\u6301\u3002\u53e6\u8bf7\u53c2\u9605 ldaptls \u9009\u9879\u4f5c\u4e3a\u66ff\u4ee3\u3002"}, {"name": "ldaptls", "description": "\u8bbe\u7f6e\u4e3a 1 \u65f6\uff0cPostgreSQL \u4e0e LDAP \u670d\u52a1\u5668\u4e4b\u95f4\u7684\u8fde\u63a5\u4f7f\u7528 TLS \u52a0\u5bc6\uff0c\u901a\u8fc7 RFC 4513 \u89c4\u5b9a\u7684 StartTLS \u64cd\u4f5c\u5b9e\u73b0\u3002\u53e6\u53ef\u53c2\u89c1 ldapscheme \u9009\u9879\u6240\u63d0\u4f9b\u7684\u66ff\u4ee3\u65b9\u5f0f\u3002"}, {"name": "ldapprefix", "description": "\u5728\u8fdb\u884c\u7b80\u5355\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u9644\u52a0\u5230\u7528\u6237\u540d\u524d\u9762\u4ee5\u5f62\u6210\u7ed1\u5b9a DN \u7684\u5b57\u7b26\u4e32\u3002"}, {"name": "ldapsuffix", "description": "\u5728\u8fdb\u884c\u7b80\u5355\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u9644\u52a0\u5230\u7528\u6237\u540d\u540e\u9762\u4ee5\u5f62\u6210\u7ed1\u5b9a DN \u7684\u5b57\u7b26\u4e32\u3002"}, {"name": "ldapbasedn", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4f5c\u7528\u6237\u641c\u7d22\u8d77\u70b9\u7684\u6839 DN\u3002"}, {"name": "ldapbinddn", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u7ed1\u5b9a\u5230\u76ee\u5f55\u5e76\u6267\u884c\u641c\u7d22\u7684\u7528\u6237 DN\u3002"}, {"name": "ldapbindpasswd", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u7ed1\u5b9a\u5230\u76ee\u5f55\u5e76\u6267\u884c\u641c\u7d22\u7684\u7528\u6237\u5bc6\u7801\u3002"}, {"name": "ldapsearchattribute", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u4e0e\u7528\u6237\u540d\u5339\u914d\u7684\u5c5e\u6027\u3002\u5982\u679c\u672a\u6307\u5b9a\u5c5e\u6027\uff0c\u5219\u4f1a\u4f7f\u7528 uid \u5c5e\u6027\u3002"}, {"name": "ldapsearchfilter", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\u4f7f\u7528\u7684\u641c\u7d22\u8fc7\u6ee4\u5668\u3002\u5176\u4e2d\u51fa\u73b0\u7684 $username \u4f1a\u88ab\u66ff\u6362\u4e3a\u7528\u6237\u540d\u3002\u8fd9\u4f7f\u5f97\u641c\u7d22\u8fc7\u6ee4\u5668\u6bd4 ldapsearchattribute \u66f4\u7075\u6d3b\u3002"}, {"name": "ldapurl", "description": "\u7b26\u5408 RFC 4516 \u7684 LDAP URL\u3002\u5b83\u4ee5\u66f4\u7d27\u51d1\u3001\u6807\u51c6\u7684\u5f62\u5f0f\u66ff\u4ee3\u90e8\u5206\u5176\u4ed6 LDAP \u9009\u9879\u3002\u683c\u5f0f\u4e3a ldap[s]://host[:port]/basedn[?[attribute][?[scope][?[filter]]]]\u3002scope \u5fc5\u987b\u4e3a base\u3001one \u6216 sub\uff0c\u901a\u5e38\u4f7f\u7528 sub\uff1b\u9ed8\u8ba4\u503c base \u5728\u6b64\u7528\u9014\u4e0b\u4e00\u822c\u6ca1\u6709\u5b9e\u9645\u5e2e\u52a9\u3002attribute \u53ef\u6307\u5b9a\u4e00\u4e2a\u5c5e\u6027\uff0c\u4f5c\u4e3a ldapsearchattribute \u7684\u503c\uff1battribute \u4e3a\u7a7a\u65f6\uff0cfilter \u53ef\u7528\u4f5c ldapsearchfilter \u7684\u503c\u3002URL \u65b9\u6848 ldaps \u8868\u793a\u901a\u8fc7 SSL \u5efa\u7acb LDAP \u8fde\u63a5\uff0c\u7b49\u540c\u4e8e ldapscheme=ldaps\u3002\u82e5\u8981\u901a\u8fc7 StartTLS \u4f7f\u7528\u52a0\u5bc6 LDAP \u8fde\u63a5\uff0c\u5e94\u4f7f\u7528\u666e\u901a\u7684 ldap URL \u65b9\u6848\uff0c\u5e76\u5728 ldapurl \u4e4b\u5916\u6307\u5b9a ldaptls\u3002\u5bf9\u4e8e\u975e\u533f\u540d\u7ed1\u5b9a\uff0c\u5fc5\u987b\u53e6\u884c\u6307\u5b9a ldapbinddn \u548c ldapbindpasswd\u3002LDAP URL \u76ee\u524d\u4ec5\u5728 OpenLDAP \u4e2d\u53d7\u652f\u6301\uff0cWindows \u4e0d\u652f\u6301\u3002"}], "title": "\u624b\u518c\u4e2d\u7684\u65b9\u6cd5\u9009\u9879\u4e0e\u66ff\u4ee3\u65b9\u5f0f", "columns": [{"key": "name", "label": "\u9009\u9879\u6216\u672f\u8bed"}, {"key": "description", "label": "\u542b\u4e49"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v12.22/postgresql-12.22.tar.bz2", "label": "12.22", "major": "12", "channel": "historical", "revision": "8df3c0474782589d3c6f374b5133b1bd14d168086edbc13c6e72e67dd4527a3b", "source_sha256": "8df3c0474782589d3c6f374b5133b1bd14d168086edbc13c6e72e67dd4527a3b", "catalog_fingerprint": "9f857f4ee4875f9c7de6bfc9df4b757dec8b3a0bb88eadb519c7bd267bd56149"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v12.22/postgresql-12.22.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "8df3c0474782589d3c6f374b5133b1bd14d168086edbc13c6e72e67dd4527a3b"}, {"url": "https://pg.center/docs/12/auth-ldap.html", "path": "auth-ldap.html", "label": "PostgreSQL 12 English manual", "sha256": "0fec6a76b2a86802531890638fe16dcb3f3ae4a4db04693296c29e67e5ddc908", "language": "en", "original_url": "/docs/12/auth-ldap.html"}, {"url": "https://pg.center/docs/12/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 12 English manual", "sha256": "07e8cddcb38076c86dab95b72c4380a7a325f22401b5b7f9af5dd4931876f2cb", "language": "en", "original_url": "/docs/12/auth-pg-hba-conf.html"}], "sections": [], "signature": "", "attributes": {"method": "ldap", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["\u4f7f\u7528 LDAP \u670d\u52a1\u5668\u8fdb\u884c\u8ba4\u8bc1\u3002\u8be6\u60c5\u53c2\u89c1\u7b2c 20.10 \u8282\u3002"], "manual_html": "<div class=\"sect1\" id=\"AUTH-LDAP\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\" lang=\"zh\">\n<div>\n<div>\n<h2 class=\"title\" style=\"clear: both\">20.10.\u00a0LDAP \u8ba4\u8bc1 </h2>\n</div>\n</div>\n</h2>\n</div>\n</div>\n</div>\n<p lang=\"zh\">\u8fd9\u79cd\u8ba4\u8bc1\u65b9\u6cd5\u7684\u5de5\u4f5c\u65b9\u5f0f\u4e0e <code class=\"literal\">password</code> \u7c7b\u4f3c\uff0c\u53ea\u4e0d\u8fc7\u5b83\u4f7f\u7528 LDAP \u4f5c\u4e3a\u5bc6\u7801\u9a8c\u8bc1\u65b9\u6cd5\u3002LDAP \u53ea\u7528\u4e8e\u9a8c\u8bc1\u7528\u6237\u540d/\u5bc6\u7801\u5bf9\u3002\u56e0\u6b64\uff0c\u5728\u4f7f\u7528 LDAP \u8fdb\u884c\u8ba4\u8bc1\u4e4b\u524d\uff0c\u7528\u6237\u5fc5\u987b\u5df2\u7ecf\u5b58\u5728\u4e8e\u6570\u636e\u5e93\u4e2d\u3002</p>\n<p lang=\"zh\">LDAP \u8ba4\u8bc1\u53ef\u4ee5\u5728\u4e24\u79cd\u6a21\u5f0f\u4e0b\u5de5\u4f5c\u3002\u7b2c\u4e00\u79cd\u6a21\u5f0f\u79f0\u4e3a\u7b80\u5355\u7ed1\u5b9a\u6a21\u5f0f\uff0c\u670d\u52a1\u5668\u4f1a\u7ed1\u5b9a\u5230\u6309 <em class=\"replaceable\"><code>prefix</code></em> <em class=\"replaceable\"><code>username</code></em> <em class=\"replaceable\"><code>suffix</code></em> \u5f62\u5f0f\u6784\u9020\u51fa\u7684\u53ef\u5206\u8fa8\u540d\u79f0\u3002\u901a\u5e38\uff0c<em class=\"replaceable\"><code>prefix</code></em> \u53c2\u6570\u7528\u4e8e\u6307\u5b9a <code class=\"literal\">cn=</code>\uff0c\u6216\u5728 Active Directory \u73af\u5883\u4e2d\u6307\u5b9a <em class=\"replaceable\"><code>DOMAIN</code></em><code class=\"literal\">\\</code>\u3002<em class=\"replaceable\"><code>suffix</code></em> \u5219\u7528\u4e8e\u6307\u5b9a\u975e Active Directory \u73af\u5883\u4e2d DN \u7684\u5269\u4f59\u90e8\u5206\u3002</p>\n<p lang=\"zh\">\u7b2c\u4e8c\u79cd\u6a21\u5f0f\u79f0\u4e3a\u641c\u7d22+\u7ed1\u5b9a\u6a21\u5f0f\uff0c\u670d\u52a1\u5668\u9996\u5148\u4f7f\u7528\u7531 <em class=\"replaceable\"><code>ldapbinddn</code></em> \u548c <em class=\"replaceable\"><code>ldapbindpasswd</code></em> \u6307\u5b9a\u7684\u56fa\u5b9a\u7528\u6237\u540d\u548c\u5bc6\u7801\u7ed1\u5b9a\u5230 LDAP \u76ee\u5f55\uff0c\u5e76\u641c\u7d22\u8bd5\u56fe\u767b\u5f55\u6570\u636e\u5e93\u7684\u7528\u6237\u3002\u5982\u679c\u6ca1\u6709\u914d\u7f6e\u7528\u6237\u540d\u548c\u5bc6\u7801\uff0c\u5219\u4f1a\u5c1d\u8bd5\u5bf9\u76ee\u5f55\u8fdb\u884c\u533f\u540d\u7ed1\u5b9a\u3002\u641c\u7d22\u4f1a\u5728 <em class=\"replaceable\"><code>ldapbasedn</code></em> \u6307\u5b9a\u7684\u5b50\u6811\u4e0a\u8fdb\u884c\uff0c\u5e76\u5c1d\u8bd5\u5bf9 <em class=\"replaceable\"><code>ldapsearchattribute</code></em> \u6307\u5b9a\u7684\u5c5e\u6027\u505a\u7cbe\u786e\u5339\u914d\u3002\u4e00\u65e6\u5728\u641c\u7d22\u4e2d\u627e\u5230\u4e86\u8be5\u7528\u6237\uff0c\u670d\u52a1\u5668\u4f1a\u65ad\u5f00\u8fde\u63a5\uff0c\u518d\u4f5c\u4e3a\u8be5\u7528\u6237\u91cd\u65b0\u7ed1\u5b9a\u5230\u76ee\u5f55\uff0c\u5e76\u4f7f\u7528\u5ba2\u6237\u7aef\u6307\u5b9a\u7684\u5bc6\u7801\u6765\u9a8c\u8bc1\u767b\u5f55\u662f\u5426\u6b63\u786e\u3002\u8fd9\u79cd\u6a21\u5f0f\u4e0e Apache <code class=\"literal\">mod_authnz_ldap</code> \u548c <code class=\"literal\">pam_ldap</code> \u7b49\u8f6f\u4ef6\u4e2d\u7684 LDAP \u8ba4\u8bc1\u65b9\u6848\u76f8\u540c\u3002\u8fd9\u79cd\u65b9\u6cd5\u4f7f\u76ee\u5f55\u4e2d\u7528\u6237\u5bf9\u8c61\u7684\u4f4d\u7f6e\u66f4\u5177\u7075\u6d3b\u6027\uff0c\u4f46\u4f1a\u4e0e LDAP \u670d\u52a1\u5668\u5efa\u7acb\u4e24\u4e2a\u72ec\u7acb\u7684\u8fde\u63a5\u3002</p>\n<p lang=\"zh\">\u4ee5\u4e0b\u914d\u7f6e\u9009\u9879\u5728\u4e24\u79cd\u6a21\u5f0f\u4e0b\u90fd\u4f7f\u7528\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapserver</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8981\u8fde\u63a5\u7684LDAP\u670d\u52a1\u5668\u7684\u540d\u79f0\u6216IP\u5730\u5740\u3002\u53ef\u4ee5\u6307\u5b9a\u591a\u4e2a\u670d\u52a1\u5668\uff0c\u7528\u7a7a\u683c\u5206\u9694\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapport</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8981\u8fde\u63a5\u7684LDAP\u670d\u52a1\u5668\u7684\u7aef\u53e3\u53f7\u3002\u5982\u679c\u672a\u6307\u5b9a\u7aef\u53e3\uff0c\u5219\u5c06\u4f7f\u7528LDAP\u5e93\u7684\u9ed8\u8ba4\u7aef\u53e3\u8bbe\u7f6e\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapscheme</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8bbe\u7f6e\u4e3a<code class=\"literal\">ldaps</code>\u4ee5\u4f7f\u7528LDAPS\u3002\u8fd9\u662f\u4e00\u79cd\u975e\u6807\u51c6\u7684\u901a\u8fc7 SSL \u4f7f\u7528 LDAP \u7684\u65b9\u5f0f\uff0c\u53d7\u4e00\u4e9bLDAP\u670d\u52a1\u5668\u5b9e\u73b0\u652f\u6301\u3002\u53e6\u8bf7\u53c2\u9605<code class=\"literal\">ldaptls</code> \u9009\u9879\u4f5c\u4e3a\u66ff\u4ee3\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldaptls</code></span></dt>\n<dd>\n<p lang=\"zh\">\u8bbe\u7f6e\u4e3a 1 \u65f6\uff0cPostgreSQL \u4e0e LDAP \u670d\u52a1\u5668\u4e4b\u95f4\u7684\u8fde\u63a5\u4f7f\u7528 TLS \u52a0\u5bc6\uff0c\u901a\u8fc7 RFC 4513 \u89c4\u5b9a\u7684 StartTLS \u64cd\u4f5c\u5b9e\u73b0\u3002\u53e6\u53ef\u53c2\u89c1 ldapscheme \u9009\u9879\u6240\u63d0\u4f9b\u7684\u66ff\u4ee3\u65b9\u5f0f\u3002</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u6ce8\u610f\u4f7f\u7528<code class=\"literal\">ldapscheme</code>\u6216<code class=\"literal\">ldaptls</code>\u4ec5\u4f1a\u52a0\u5bc6PostgreSQL \u670d\u52a1\u5668\u548cLDAP\u670d\u52a1\u5668\u4e4b\u95f4\u7684\u901a\u4fe1\u3002PostgreSQL \u670d\u52a1\u5668\u548cPostgreSQL\u5ba2\u6237\u7aef\u4e4b\u95f4\u7684\u8fde\u63a5\u4ecd\u662f\u672a\u52a0\u5bc6\u7684\uff0c\u9664\u975e\u4e5f\u5728\u5176\u4e0a\u4f7f\u7528SSL\u3002</p>\n<p lang=\"zh\">\u4e0b\u5217\u9009\u9879\u53ea\u88ab\u7528\u4e8e\u7b80\u5355\u7ed1\u5b9a\u6a21\u5f0f\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapprefix</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u7b80\u5355\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u9644\u52a0\u5230\u7528\u6237\u540d\u524d\u9762\u4ee5\u5f62\u6210\u7ed1\u5b9a DN \u7684\u5b57\u7b26\u4e32\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsuffix</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u7b80\u5355\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u9644\u52a0\u5230\u7528\u6237\u540d\u540e\u9762\u4ee5\u5f62\u6210\u7ed1\u5b9a DN \u7684\u5b57\u7b26\u4e32\u3002</p>\n</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u4ee5\u4e0b\u9009\u9879\u4ec5\u5728\u641c\u7d22+\u7ed1\u5b9a\u6a21\u5f0f\u4e2d\u4f7f\u7528\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapbasedn</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4f5c\u7528\u6237\u641c\u7d22\u8d77\u70b9\u7684\u6839 DN\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapbinddn</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u7ed1\u5b9a\u5230\u76ee\u5f55\u5e76\u6267\u884c\u641c\u7d22\u7684\u7528\u6237 DN\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapbindpasswd</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u7ed1\u5b9a\u5230\u76ee\u5f55\u5e76\u6267\u884c\u641c\u7d22\u7684\u7528\u6237\u5bc6\u7801\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsearchattribute</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u4e0e\u7528\u6237\u540d\u5339\u914d\u7684\u5c5e\u6027\u3002\u5982\u679c\u672a\u6307\u5b9a\u5c5e\u6027\uff0c\u5219\u4f1a\u4f7f\u7528 <code class=\"literal\">uid</code> \u5c5e\u6027\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsearchfilter</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\u4f7f\u7528\u7684\u641c\u7d22\u8fc7\u6ee4\u5668\u3002\u5176\u4e2d\u51fa\u73b0\u7684 <code class=\"literal\">$username</code> \u4f1a\u88ab\u66ff\u6362\u4e3a\u7528\u6237\u540d\u3002\u8fd9\u4f7f\u5f97\u641c\u7d22\u8fc7\u6ee4\u5668\u6bd4 <code class=\"literal\">ldapsearchattribute</code> \u66f4\u7075\u6d3b\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapurl</code></span></dt>\n<dd>\n<p lang=\"zh\">\u7b26\u5408 RFC 4516 \u7684 LDAP URL\u3002\u8fd9\u662f\u53e6\u4e00\u79cd\u6307\u5b9a\u90e8\u5206 LDAP \u9009\u9879\u7684\u65b9\u5f0f\uff0c\u5199\u6cd5\u66f4\u7d27\u51d1\u3001\u66f4\u6807\u51c6\u3002\u5176\u683c\u5f0f\u4e3a</p>\n<pre class=\"synopsis\">ldap[s]://<em class=\"replaceable\"><code>host</code></em>[:<em class=\"replaceable\"><code>port</code></em>]/<em class=\"replaceable\"><code>basedn</code></em>[?[<em class=\"replaceable\"><code>attribute</code></em>][?[<em class=\"replaceable\"><code>scope</code></em>][?[<em class=\"replaceable\"><code>filter</code></em>]]]]\n</pre>\n<p lang=\"zh\"><em class=\"replaceable\"><code>scope</code></em> \u5fc5\u987b\u662f\u4ee5\u4e0b\u503c\u4e4b\u4e00\uff1a<code class=\"literal\">base</code>\uff0c<code class=\"literal\">one</code>\uff0c<code class=\"literal\">sub</code>\uff0c\u901a\u5e38\u4f7f\u7528\u6700\u540e\u4e00\u4e2a\u3002\uff08\u9ed8\u8ba4\u503c\u4e3a <code class=\"literal\">base</code>\uff0c\u901a\u5e38\u4e0d\u9002\u7528\u4e8e\u8fd9\u91cc\u7684\u7528\u9014\u3002\uff09<em class=\"replaceable\"><code>attribute</code></em> \u53ef\u4ee5\u6307\u5b9a\u5355\u4e2a\u5c5e\u6027\uff0c\u5e76\u7528\u5b83\u8bbe\u7f6e <code class=\"literal\">ldapsearchattribute</code>\u3002\u5982\u679c <em class=\"replaceable\"><code>attribute</code></em> \u4e3a\u7a7a\uff0c\u5219\u53ef\u4ee5\u7528 <em class=\"replaceable\"><code>filter</code></em> \u8bbe\u7f6e <code class=\"literal\">ldapsearchfilter</code>\u3002</p>\n<p lang=\"zh\">URL \u65b9\u6848 ldaps \u9009\u62e9\u901a\u8fc7 SSL \u5efa\u7acb LDAP \u8fde\u63a5\u7684 LDAPS \u65b9\u5f0f\uff0c\u7b49\u4ef7\u4e8e ldapscheme=ldaps\u3002\u8981\u901a\u8fc7 StartTLS \u4f7f\u7528\u52a0\u5bc6 LDAP \u8fde\u63a5\uff0c\u5e94\u4f7f\u7528\u666e\u901a\u7684 ldap URL \u65b9\u6848\uff0c\u5e76\u5728 ldapurl \u4e4b\u5916\u6307\u5b9a ldaptls\u3002</p>\n<p lang=\"zh\">\u5bf9\u4e8e\u975e\u533f\u540d\u7ed1\u5b9a\uff0c\u5fc5\u987b\u5c06<code class=\"literal\">ldapbinddn</code>\u548c<code class=\"literal\">ldapbindpasswd</code>\u6307\u5b9a\u4e3a\u5355\u72ec\u7684\u9009\u9879\u3002</p>\n<p lang=\"zh\">LDAP URL\u76ee\u524d\u4ec5\u53d7<span class=\"productname\">OpenLDAP</span>\u652f\u6301\uff0c\u4e0d\u652f\u6301Windows\u3002</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u5c06\u7b80\u5355\u7ed1\u5b9a\u6a21\u5f0f\u7684\u914d\u7f6e\u9009\u9879\u4e0e\u641c\u7d22+\u7ed1\u5b9a\u6a21\u5f0f\u7684\u914d\u7f6e\u9009\u9879\u6df7\u7528\u662f\u9519\u8bef\u7684\u3002</p>\n<p lang=\"zh\">\u5728\u4f7f\u7528\u641c\u7d22+\u7ed1\u5b9a\u6a21\u5f0f\u65f6\uff0c\u53ef\u4ee5\u4f7f\u7528\u7531 <code class=\"literal\">ldapsearchattribute</code> \u6307\u5b9a\u7684\u5355\u4e2a\u5c5e\u6027\u6267\u884c\u641c\u7d22\uff0c\u4e5f\u53ef\u4ee5\u4f7f\u7528\u7531 <code class=\"literal\">ldapsearchfilter</code> \u6307\u5b9a\u7684\u81ea\u5b9a\u4e49\u641c\u7d22\u8fc7\u6ee4\u5668\u6267\u884c\u641c\u7d22\u3002\u6307\u5b9a <code class=\"literal\">ldapsearchattribute=foo</code> \u7b49\u4ef7\u4e8e\u6307\u5b9a <code class=\"literal\">ldapsearchfilter=\"(foo=$username)\"</code>\u3002\u5982\u679c\u4e24\u4e2a\u9009\u9879\u90fd\u672a\u6307\u5b9a\uff0c\u5219\u9ed8\u8ba4\u4f7f\u7528 <code class=\"literal\">ldapsearchattribute=uid</code>\u3002</p>\n<p lang=\"zh\">\u5982\u679c <span class=\"productname\">PostgreSQL</span> \u7f16\u8bd1\u65f6\u4f7f\u7528\u4e86 <span class=\"productname\">OpenLDAP</span> \u4f5c\u4e3a LDAP \u5ba2\u6237\u7aef\u5e93\uff0c\u5219\u53ef\u4ee5\u7701\u7565 <code class=\"literal\">ldapserver</code> \u8bbe\u7f6e\u3002\u5728\u8fd9\u79cd\u60c5\u51b5\u4e0b\uff0c\u4f1a\u901a\u8fc7 RFC 2782 DNS SRV \u8bb0\u5f55\u67e5\u627e\u4e3b\u673a\u540d\u548c\u7aef\u53e3\u5217\u8868\u3002\u67e5\u627e\u7684\u540d\u79f0\u662f <code class=\"literal\">_ldap._tcp.DOMAIN</code>\uff0c\u5176\u4e2d <code class=\"literal\">DOMAIN</code> \u4ece <code class=\"literal\">ldapbasedn</code> \u4e2d\u63d0\u53d6\u3002</p>\n<p lang=\"zh\">\u4e0b\u9762\u662f\u4e00\u4e2a\u7b80\u5355\u7ed1\u5b9a LDAP \u914d\u7f6e\u793a\u4f8b\uff1a</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapprefix=\"cn=\" ldapsuffix=\", dc=example, dc=net\"\n</pre>\n<p lang=\"zh\">\u5f53\u8bf7\u6c42\u4ee5\u6570\u636e\u5e93\u7528\u6237 <code class=\"literal\">someuser</code> \u8fde\u63a5\u6570\u636e\u5e93\u670d\u52a1\u5668\u65f6\uff0cPostgreSQL \u5c06\u5c1d\u8bd5\u4f7f\u7528 DN <code class=\"literal\">cn=someuser, dc=example, dc=net</code> \u548c\u5ba2\u6237\u7aef\u63d0\u4f9b\u7684\u5bc6\u7801\u7ed1\u5b9a\u5230 LDAP \u670d\u52a1\u5668\u3002\u5982\u679c\u8be5\u8fde\u63a5\u6210\u529f\uff0c\u6570\u636e\u5e93\u8bbf\u95ee\u5c31\u4f1a\u88ab\u6388\u4e88\u3002</p>\n<p lang=\"zh\">\u4e0b\u9762\u662f\u641c\u7d22\u52a0\u7ed1\u5b9a\u914d\u7f6e\u7684\u793a\u4f8b\uff1a</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapbasedn=\"dc=example, dc=net\" ldapsearchattribute=uid\n</pre>\n<p lang=\"zh\">\u5f53\u8bf7\u6c42\u4ee5\u6570\u636e\u5e93\u7528\u6237 <code class=\"literal\">someuser</code> \u7684\u8eab\u4efd\u8fde\u63a5\u6570\u636e\u5e93\u670d\u52a1\u5668\u65f6\uff0cPostgreSQL \u4f1a\u5c1d\u8bd5\u533f\u540d\u7ed1\u5b9a\u5230 LDAP \u670d\u52a1\u5668\uff08\u56e0\u4e3a\u6ca1\u6709\u6307\u5b9a <code class=\"literal\">ldapbinddn</code>\uff09\uff0c\u5e76\u5728\u6307\u5b9a\u7684\u57fa\u7840 DN \u4e0b\u641c\u7d22 <code class=\"literal\">(uid=someuser)</code>\u3002\u5982\u679c\u627e\u5230\u4e86\u6761\u76ee\uff0c\u5c31\u4f1a\u5c1d\u8bd5\u4f7f\u7528\u627e\u5230\u7684\u4fe1\u606f\u548c\u5ba2\u6237\u7aef\u63d0\u4f9b\u7684\u5bc6\u7801\u8fdb\u884c\u7ed1\u5b9a\u3002\u5982\u679c\u7b2c\u4e8c\u6b21\u8fde\u63a5\u6210\u529f\uff0c\u5c31\u4f1a\u6388\u4e88\u6570\u636e\u5e93\u8bbf\u95ee\u6743\u9650\u3002</p>\n<p lang=\"zh\">\u4e0b\u9762\u662f\u4ee5 URL \u5f62\u5f0f\u5199\u51fa\u7684\u540c\u4e00\u4e2a\u641c\u7d22+\u7ed1\u5b9a\u914d\u7f6e\uff1a</p>\n<pre class=\"programlisting\">host ... ldap ldapurl=\"ldap://ldap.example.net/dc=example,dc=net?uid?sub\"\n</pre>\n<p lang=\"zh\">\u67d0\u4e9b\u652f\u6301 LDAP \u8ba4\u8bc1\u7684\u5176\u4ed6\u8f6f\u4ef6\u4e5f\u4f7f\u7528\u76f8\u540c\u7684 URL \u683c\u5f0f\uff0c\u56e0\u6b64\u5171\u4eab\u8fd9\u7c7b\u914d\u7f6e\u4f1a\u66f4\u5bb9\u6613\u3002</p>\n<p lang=\"zh\">\u8fd9\u91cc\u662f\u4e00\u4e2a\u641c\u7d22+\u7ed1\u5b9a\u914d\u7f6e\u7684\u793a\u4f8b\uff0c\u5b83\u4f7f\u7528 <code class=\"literal\">ldapsearchfilter</code> \u800c\u4e0d\u662f <code class=\"literal\">ldapsearchattribute</code> \u6765\u5141\u8bb8\u7528\u7528\u6237 ID \u6216\u7535\u5b50\u90ae\u4ef6\u5730\u5740\u8fdb\u884c\u8ba4\u8bc1\uff1a</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapbasedn=\"dc=example, dc=net\" ldapsearchfilter=\"(|(uid=$username)(mail=$username))\"\n</pre>\n<p lang=\"zh\">\u8fd9\u662f\u4e00\u4e2a\u641c\u7d22+\u7ed1\u5b9a\u914d\u7f6e\u7684\u793a\u4f8b\uff0c\u5b83\u4f7f\u7528 DNS SRV \u53d1\u73b0\u6765\u67e5\u627e\u57df\u540d <code class=\"literal\">example.net</code> \u7684 LDAP \u670d\u52a1\u7684\u4e3b\u673a\u540d\u548c\u7aef\u53e3\u3002</p>\n<pre class=\"programlisting\">host ... ldap ldapbasedn=\"dc=example,dc=net\"\n</pre>\n<div class=\"tip\">\n<h3 class=\"title\" lang=\"zh\">\u63d0\u793a</h3>\n<p lang=\"zh\">\u5982\u793a\u4f8b\u4e2d\u6240\u793a\uff0c\u7531\u4e8e LDAP \u901a\u5e38\u4f7f\u7528\u9017\u53f7\u548c\u7a7a\u683c\u6765\u5206\u5272\u4e00\u4e2a DN \u7684\u4e0d\u540c\u90e8\u5206\uff0c\u5728\u914d\u7f6e LDAP \u9009\u9879\u65f6\u901a\u5e38\u6709\u5fc5\u8981\u4f7f\u7528\u53cc\u5f15\u53f7\u5305\u56f4\u7684\u53c2\u6570\u503c\u3002</p>\n</div>\n</div>", "manual_path": "/docs/12/auth-ldap.html", "localization": {"status": "complete", "sources": [{"url": "/docs/12/auth-ldap.html", "method": "same-major semantic node", "sha256": "3b9ddc8c2fd4b5edae38a3f7c9d30ff3c3fb2c6248703b96048536cd1973716a", "language": "zh", "matched_nodes": ["#AUTH-LDAP/div[0]", "#AUTH-LDAP/div[11]/dl[0]/dd[11]/p[0]", "#AUTH-LDAP/div[11]/dl[0]/dd[11]/p[2]", "#AUTH-LDAP/div[11]/dl[0]/dd[11]/p[4]", "#AUTH-LDAP/div[11]/dl[0]/dd[11]/p[5]", "#AUTH-LDAP/div[11]/dl[0]/dd[1]", "#AUTH-LDAP/div[11]/dl[0]/dd[3]", "#AUTH-LDAP/div[11]/dl[0]/dd[5]", "#AUTH-LDAP/div[11]/dl[0]/dd[7]", "#AUTH-LDAP/div[11]/dl[0]/dd[9]", "#AUTH-LDAP/div[28]/h3[0]", "#AUTH-LDAP/div[28]/p[1]", "#AUTH-LDAP/div[6]/dl[0]/dd[1]", "#AUTH-LDAP/div[6]/dl[0]/dd[3]", "#AUTH-LDAP/div[6]/dl[0]/dd[5]", "#AUTH-LDAP/div[9]/dl[0]/dd[1]", "#AUTH-LDAP/div[9]/dl[0]/dd[3]", "#AUTH-LDAP/p[10]", "#AUTH-LDAP/p[12]", "#AUTH-LDAP/p[13]", "#AUTH-LDAP/p[14]", "#AUTH-LDAP/p[15]", "#AUTH-LDAP/p[17]", "#AUTH-LDAP/p[18]", "#AUTH-LDAP/p[20]", "#AUTH-LDAP/p[21]", "#AUTH-LDAP/p[23]", "#AUTH-LDAP/p[24]", "#AUTH-LDAP/p[26]", "#AUTH-LDAP/p[2]", "#AUTH-LDAP/p[3]", "#AUTH-LDAP/p[4]", "#AUTH-LDAP/p[5]", "#AUTH-LDAP/p[7]", "#AUTH-LDAP/p[8]"]}], "language": "zh", "original_text": {"/versions/12/description/0": "Authenticate using an LDAP server. See Section 20.10 for details.", "/versions/12/facts/0/label": "Method", "/versions/12/facts/1/label": "Configuration", "/versions/12/facts/2/label": "Inventory", "/versions/12/facts/2/value": "User-visible source authentication method", "/versions/12/tables/0/title": "Documented method options and alternatives", "/versions/12/tables/0/columns/0/label": "Option or term", "/versions/12/tables/0/columns/1/label": "Meaning", "/versions/12/tables/0/rows/0/description": "Names or IP addresses of LDAP servers to connect to. Multiple servers may be specified, separated by spaces.", "/versions/12/tables/0/rows/1/description": "Port number on LDAP server to connect to. If no port is specified, the LDAP library's default port setting will be used.", "/versions/12/tables/0/rows/2/description": "Set to ldaps to use LDAPS. This is a non-standard way of using LDAP over SSL, supported by some LDAP server implementations. See also the ldaptls option for an alternative.", "/versions/12/tables/0/rows/3/description": "Set to 1 to make the connection between PostgreSQL and the LDAP server use TLS encryption. This uses the StartTLS operation per RFC 4513. See also the ldapscheme option for an alternative.", "/versions/12/tables/0/rows/4/description": "String to prepend to the user name when forming the DN to bind as, when doing simple bind authentication.", "/versions/12/tables/0/rows/5/description": "String to append to the user name when forming the DN to bind as, when doing simple bind authentication.", "/versions/12/tables/0/rows/6/description": "Root DN to begin the search for the user in, when doing search+bind authentication.", "/versions/12/tables/0/rows/7/description": "DN of user to bind to the directory with to perform the search when doing search+bind authentication.", "/versions/12/tables/0/rows/8/description": "Password for user to bind to the directory with to perform the search when doing search+bind authentication.", "/versions/12/tables/0/rows/9/description": "Attribute to match against the user name in the search when doing search+bind authentication. If no attribute is specified, the uid attribute will be used.", "/versions/12/tables/0/rows/10/description": "The search filter to use when doing search+bind authentication. Occurrences of $username will be replaced with the user name. This allows for more flexible search filters than ldapsearchattribute .", "/versions/12/tables/0/rows/11/description": "An RFC 4516 LDAP URL. This is an alternative way to write some of the other LDAP options in a more compact and standard form. The format is ldap[s]:// host [: port ]/ basedn [?[ attribute ][?[ scope ][?[ filter ]]]] scope must be one of base , one , sub , typically the last. (The default is base , which is normally not useful in this application.) attribute can nominate a single attribute, in which case it is used as a value for ldapsearchattribute . If attribute is empty then filter can be used as a value for ldapsearchfilter . The URL scheme ldaps chooses the LDAPS method for making LDAP connections over SSL, equivalent to using ldapscheme=ldaps . To use encrypted LDAP connections using the StartTLS operation, use the normal URL scheme ldap and specify the ldaptls option in addition to ldapurl . For non-anonymous binds, ldapbinddn and ldapbindpasswd must be specified as separate options. LDAP URLs are currently only supported with OpenLDAP , not on Windows."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "0d62e2b0c10f0b9200707236fa72ebce2a751b64ad2be013e0c69849f25fd89e"}, "comparison_data": {"method": "ldap", "documented_option_names": ["ldapbasedn", "ldapbinddn", "ldapbindpasswd", "ldapport", "ldapprefix", "ldapscheme", "ldapsearchattribute", "ldapsearchfilter", "ldapserver", "ldapsuffix", "ldaptls", "ldapurl"]}, "comparison_hash": "d40de945ae67b3ac60a284fdd442cc24a4e9d05bc7a7b18009b54e491c381b88", "manual_language": "zh"}, "13": {"facts": [{"label": "\u65b9\u6cd5", "value": "ldap"}, {"label": "\u914d\u7f6e", "value": "pg_hba.conf"}, {"label": "\u6e05\u5355", "value": "\u7528\u6237\u53ef\u89c1\u7684\u6e90\u7801\u8ba4\u8bc1\u65b9\u6cd5"}], "tables": [{"key": "method-options", "rows": [{"name": "ldapserver", "description": "\u8981\u8fde\u63a5\u7684LDAP\u670d\u52a1\u5668\u7684\u540d\u79f0\u6216IP\u5730\u5740\u3002\u53ef\u4ee5\u6307\u5b9a\u591a\u4e2a\u670d\u52a1\u5668\uff0c\u7528\u7a7a\u683c\u5206\u9694\u3002"}, {"name": "ldapport", "description": "\u8981\u8fde\u63a5\u7684LDAP\u670d\u52a1\u5668\u7684\u7aef\u53e3\u53f7\u3002\u5982\u679c\u672a\u6307\u5b9a\u7aef\u53e3\uff0c\u5219\u5c06\u4f7f\u7528LDAP\u5e93\u7684\u9ed8\u8ba4\u7aef\u53e3\u8bbe\u7f6e\u3002"}, {"name": "ldapscheme", "description": "\u8bbe\u7f6e\u4e3a ldaps \u4ee5\u4f7f\u7528LDAPS\u3002\u8fd9\u662f\u4e00\u79cd\u975e\u6807\u51c6\u7684\u901a\u8fc7 SSL \u4f7f\u7528 LDAP \u7684\u65b9\u5f0f\uff0c\u53d7\u4e00\u4e9bLDAP\u670d\u52a1\u5668\u5b9e\u73b0\u652f\u6301\u3002\u53e6\u8bf7\u53c2\u9605 ldaptls \u9009\u9879\u4f5c\u4e3a\u66ff\u4ee3\u3002"}, {"name": "ldaptls", "description": "\u8bbe\u7f6e\u4e3a 1 \u65f6\uff0cPostgreSQL \u4e0e LDAP \u670d\u52a1\u5668\u4e4b\u95f4\u7684\u8fde\u63a5\u4f7f\u7528 TLS \u52a0\u5bc6\uff0c\u901a\u8fc7 RFC 4513 \u89c4\u5b9a\u7684 StartTLS \u64cd\u4f5c\u5b9e\u73b0\u3002\u53e6\u53ef\u53c2\u89c1 ldapscheme \u9009\u9879\u6240\u63d0\u4f9b\u7684\u66ff\u4ee3\u65b9\u5f0f\u3002"}, {"name": "ldapprefix", "description": "\u5728\u8fdb\u884c\u7b80\u5355\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u9644\u52a0\u5230\u7528\u6237\u540d\u524d\u9762\u4ee5\u5f62\u6210\u7ed1\u5b9a DN \u7684\u5b57\u7b26\u4e32\u3002"}, {"name": "ldapsuffix", "description": "\u5728\u8fdb\u884c\u7b80\u5355\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u9644\u52a0\u5230\u7528\u6237\u540d\u540e\u9762\u4ee5\u5f62\u6210\u7ed1\u5b9a DN \u7684\u5b57\u7b26\u4e32\u3002"}, {"name": "ldapbasedn", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4f5c\u7528\u6237\u641c\u7d22\u8d77\u70b9\u7684\u6839 DN\u3002"}, {"name": "ldapbinddn", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u7ed1\u5b9a\u5230\u76ee\u5f55\u5e76\u6267\u884c\u641c\u7d22\u7684\u7528\u6237 DN\u3002"}, {"name": "ldapbindpasswd", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u7ed1\u5b9a\u5230\u76ee\u5f55\u5e76\u6267\u884c\u641c\u7d22\u7684\u7528\u6237\u5bc6\u7801\u3002"}, {"name": "ldapsearchattribute", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u4e0e\u7528\u6237\u540d\u5339\u914d\u7684\u5c5e\u6027\u3002\u5982\u679c\u672a\u6307\u5b9a\u5c5e\u6027\uff0c\u5219\u4f1a\u4f7f\u7528 uid \u5c5e\u6027\u3002"}, {"name": "ldapsearchfilter", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\u4f7f\u7528\u7684\u641c\u7d22\u8fc7\u6ee4\u5668\u3002\u5176\u4e2d\u51fa\u73b0\u7684 $username \u4f1a\u88ab\u66ff\u6362\u4e3a\u7528\u6237\u540d\u3002\u8fd9\u4f7f\u5f97\u641c\u7d22\u8fc7\u6ee4\u5668\u6bd4 ldapsearchattribute \u66f4\u7075\u6d3b\u3002"}, {"name": "ldapurl", "description": "\u7b26\u5408 RFC 4516 \u7684 LDAP URL\u3002\u5b83\u4ee5\u66f4\u7d27\u51d1\u3001\u6807\u51c6\u7684\u5f62\u5f0f\u66ff\u4ee3\u90e8\u5206\u5176\u4ed6 LDAP \u9009\u9879\u3002\u683c\u5f0f\u4e3a ldap[s]://host[:port]/basedn[?[attribute][?[scope][?[filter]]]]\u3002scope \u5fc5\u987b\u4e3a base\u3001one \u6216 sub\uff0c\u901a\u5e38\u4f7f\u7528 sub\uff1b\u9ed8\u8ba4\u503c base \u5728\u6b64\u7528\u9014\u4e0b\u4e00\u822c\u6ca1\u6709\u5b9e\u9645\u5e2e\u52a9\u3002attribute \u53ef\u6307\u5b9a\u4e00\u4e2a\u5c5e\u6027\uff0c\u4f5c\u4e3a ldapsearchattribute \u7684\u503c\uff1battribute \u4e3a\u7a7a\u65f6\uff0cfilter \u53ef\u7528\u4f5c ldapsearchfilter \u7684\u503c\u3002URL \u65b9\u6848 ldaps \u8868\u793a\u901a\u8fc7 SSL \u5efa\u7acb LDAP \u8fde\u63a5\uff0c\u7b49\u540c\u4e8e ldapscheme=ldaps\u3002\u82e5\u8981\u901a\u8fc7 StartTLS \u4f7f\u7528\u52a0\u5bc6 LDAP \u8fde\u63a5\uff0c\u5e94\u4f7f\u7528\u666e\u901a\u7684 ldap URL \u65b9\u6848\uff0c\u5e76\u5728 ldapurl \u4e4b\u5916\u6307\u5b9a ldaptls\u3002\u5bf9\u4e8e\u975e\u533f\u540d\u7ed1\u5b9a\uff0c\u5fc5\u987b\u53e6\u884c\u6307\u5b9a ldapbinddn \u548c ldapbindpasswd\u3002LDAP URL \u76ee\u524d\u4ec5\u5728 OpenLDAP \u4e2d\u53d7\u652f\u6301\uff0cWindows \u4e0d\u652f\u6301\u3002"}], "title": "\u624b\u518c\u4e2d\u7684\u65b9\u6cd5\u9009\u9879\u4e0e\u66ff\u4ee3\u65b9\u5f0f", "columns": [{"key": "name", "label": "\u9009\u9879\u6216\u672f\u8bed"}, {"key": "description", "label": "\u542b\u4e49"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v13.23/postgresql-13.23.tar.bz2", "label": "13.23", "major": "13", "channel": "historical", "revision": "6ec3c82726af92b7dec873fa1cdf881eca92a4219787dfad05acb6b10e041fd6", "source_sha256": "6ec3c82726af92b7dec873fa1cdf881eca92a4219787dfad05acb6b10e041fd6", "catalog_fingerprint": "c7015c845255c9d721c547c8ab9ef37825d332588c9691d982e6906b7d571002"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v13.23/postgresql-13.23.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "6ec3c82726af92b7dec873fa1cdf881eca92a4219787dfad05acb6b10e041fd6"}, {"url": "https://pg.center/docs/13/auth-ldap.html", "path": "auth-ldap.html", "label": "PostgreSQL 13 English manual", "sha256": "2190e53484a909337f45b923753b310a993d15b4a763b83113945d2192cd8351", "language": "en", "original_url": "/docs/13/auth-ldap.html"}, {"url": "https://pg.center/docs/13/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 13 English manual", "sha256": "3cc6ce851945cba450e6b26ecf9cae1efd3c03fb7b55e17876f4d9ea418a7c2e", "language": "en", "original_url": "/docs/13/auth-pg-hba-conf.html"}], "sections": [], "signature": "", "attributes": {"method": "ldap", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["\u4f7f\u7528 LDAP \u670d\u52a1\u5668\u8fdb\u884c\u8ba4\u8bc1\u3002\u8be6\u60c5\u53c2\u89c1\u7b2c 20.10 \u8282\u3002"], "manual_html": "<div class=\"sect1\" id=\"AUTH-LDAP\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\" lang=\"zh\">\n<div>\n<div>\n<h2 class=\"title\" style=\"clear: both\">20.10.\u00a0LDAP \u8ba4\u8bc1 </h2>\n</div>\n</div>\n</h2>\n</div>\n</div>\n</div>\n<p lang=\"zh\">\u8fd9\u79cd\u8ba4\u8bc1\u65b9\u6cd5\u7684\u5de5\u4f5c\u65b9\u5f0f\u4e0e <code class=\"literal\">password</code> \u7c7b\u4f3c\uff0c\u53ea\u4e0d\u8fc7\u5b83\u4f7f\u7528 LDAP \u4f5c\u4e3a\u5bc6\u7801\u9a8c\u8bc1\u65b9\u6cd5\u3002LDAP \u53ea\u7528\u4e8e\u9a8c\u8bc1\u7528\u6237\u540d/\u5bc6\u7801\u5bf9\u3002\u56e0\u6b64\uff0c\u5728\u4f7f\u7528 LDAP \u8fdb\u884c\u8ba4\u8bc1\u4e4b\u524d\uff0c\u7528\u6237\u5fc5\u987b\u5df2\u7ecf\u5b58\u5728\u4e8e\u6570\u636e\u5e93\u4e2d\u3002</p>\n<p lang=\"zh\">LDAP \u8ba4\u8bc1\u53ef\u4ee5\u5728\u4e24\u79cd\u6a21\u5f0f\u4e0b\u5de5\u4f5c\u3002\u7b2c\u4e00\u79cd\u6a21\u5f0f\u79f0\u4e3a\u7b80\u5355\u7ed1\u5b9a\u6a21\u5f0f\uff0c\u670d\u52a1\u5668\u4f1a\u7ed1\u5b9a\u5230\u6309 <em class=\"replaceable\"><code>prefix</code></em> <em class=\"replaceable\"><code>username</code></em> <em class=\"replaceable\"><code>suffix</code></em> \u5f62\u5f0f\u6784\u9020\u51fa\u7684\u53ef\u5206\u8fa8\u540d\u79f0\u3002\u901a\u5e38\uff0c<em class=\"replaceable\"><code>prefix</code></em> \u53c2\u6570\u7528\u4e8e\u6307\u5b9a <code class=\"literal\">cn=</code>\uff0c\u6216\u5728 Active Directory \u73af\u5883\u4e2d\u6307\u5b9a <em class=\"replaceable\"><code>DOMAIN</code></em><code class=\"literal\">\\</code>\u3002<em class=\"replaceable\"><code>suffix</code></em> \u5219\u7528\u4e8e\u6307\u5b9a\u975e Active Directory \u73af\u5883\u4e2d DN \u7684\u5269\u4f59\u90e8\u5206\u3002</p>\n<p lang=\"zh\">\u7b2c\u4e8c\u79cd\u6a21\u5f0f\u79f0\u4e3a\u641c\u7d22+\u7ed1\u5b9a\u6a21\u5f0f\uff0c\u670d\u52a1\u5668\u9996\u5148\u4f7f\u7528\u7531 <em class=\"replaceable\"><code>ldapbinddn</code></em> \u548c <em class=\"replaceable\"><code>ldapbindpasswd</code></em> \u6307\u5b9a\u7684\u56fa\u5b9a\u7528\u6237\u540d\u548c\u5bc6\u7801\u7ed1\u5b9a\u5230 LDAP \u76ee\u5f55\uff0c\u5e76\u641c\u7d22\u8bd5\u56fe\u767b\u5f55\u6570\u636e\u5e93\u7684\u7528\u6237\u3002\u5982\u679c\u6ca1\u6709\u914d\u7f6e\u7528\u6237\u540d\u548c\u5bc6\u7801\uff0c\u5219\u4f1a\u5c1d\u8bd5\u5bf9\u76ee\u5f55\u8fdb\u884c\u533f\u540d\u7ed1\u5b9a\u3002\u641c\u7d22\u4f1a\u5728 <em class=\"replaceable\"><code>ldapbasedn</code></em> \u6307\u5b9a\u7684\u5b50\u6811\u4e0a\u8fdb\u884c\uff0c\u5e76\u5c1d\u8bd5\u5bf9 <em class=\"replaceable\"><code>ldapsearchattribute</code></em> \u6307\u5b9a\u7684\u5c5e\u6027\u505a\u7cbe\u786e\u5339\u914d\u3002\u4e00\u65e6\u5728\u641c\u7d22\u4e2d\u627e\u5230\u4e86\u8be5\u7528\u6237\uff0c\u670d\u52a1\u5668\u4f1a\u65ad\u5f00\u8fde\u63a5\uff0c\u518d\u4f5c\u4e3a\u8be5\u7528\u6237\u91cd\u65b0\u7ed1\u5b9a\u5230\u76ee\u5f55\uff0c\u5e76\u4f7f\u7528\u5ba2\u6237\u7aef\u6307\u5b9a\u7684\u5bc6\u7801\u6765\u9a8c\u8bc1\u767b\u5f55\u662f\u5426\u6b63\u786e\u3002\u8fd9\u79cd\u6a21\u5f0f\u4e0e Apache <code class=\"literal\">mod_authnz_ldap</code> \u548c <code class=\"literal\">pam_ldap</code> \u7b49\u8f6f\u4ef6\u4e2d\u7684 LDAP \u8ba4\u8bc1\u65b9\u6848\u76f8\u540c\u3002\u8fd9\u79cd\u65b9\u6cd5\u4f7f\u76ee\u5f55\u4e2d\u7528\u6237\u5bf9\u8c61\u7684\u4f4d\u7f6e\u66f4\u5177\u7075\u6d3b\u6027\uff0c\u4f46\u4f1a\u4e0e LDAP \u670d\u52a1\u5668\u5efa\u7acb\u4e24\u4e2a\u72ec\u7acb\u7684\u8fde\u63a5\u3002</p>\n<p lang=\"zh\">\u4ee5\u4e0b\u914d\u7f6e\u9009\u9879\u5728\u4e24\u79cd\u6a21\u5f0f\u4e0b\u90fd\u4f7f\u7528\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapserver</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8981\u8fde\u63a5\u7684LDAP\u670d\u52a1\u5668\u7684\u540d\u79f0\u6216IP\u5730\u5740\u3002\u53ef\u4ee5\u6307\u5b9a\u591a\u4e2a\u670d\u52a1\u5668\uff0c\u7528\u7a7a\u683c\u5206\u9694\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapport</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8981\u8fde\u63a5\u7684LDAP\u670d\u52a1\u5668\u7684\u7aef\u53e3\u53f7\u3002\u5982\u679c\u672a\u6307\u5b9a\u7aef\u53e3\uff0c\u5219\u5c06\u4f7f\u7528LDAP\u5e93\u7684\u9ed8\u8ba4\u7aef\u53e3\u8bbe\u7f6e\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapscheme</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8bbe\u7f6e\u4e3a<code class=\"literal\">ldaps</code>\u4ee5\u4f7f\u7528LDAPS\u3002\u8fd9\u662f\u4e00\u79cd\u975e\u6807\u51c6\u7684\u901a\u8fc7 SSL \u4f7f\u7528 LDAP \u7684\u65b9\u5f0f\uff0c\u53d7\u4e00\u4e9bLDAP\u670d\u52a1\u5668\u5b9e\u73b0\u652f\u6301\u3002\u53e6\u8bf7\u53c2\u9605<code class=\"literal\">ldaptls</code> \u9009\u9879\u4f5c\u4e3a\u66ff\u4ee3\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldaptls</code></span></dt>\n<dd>\n<p lang=\"zh\">\u8bbe\u7f6e\u4e3a 1 \u65f6\uff0cPostgreSQL \u4e0e LDAP \u670d\u52a1\u5668\u4e4b\u95f4\u7684\u8fde\u63a5\u4f7f\u7528 TLS \u52a0\u5bc6\uff0c\u901a\u8fc7 RFC 4513 \u89c4\u5b9a\u7684 StartTLS \u64cd\u4f5c\u5b9e\u73b0\u3002\u53e6\u53ef\u53c2\u89c1 ldapscheme \u9009\u9879\u6240\u63d0\u4f9b\u7684\u66ff\u4ee3\u65b9\u5f0f\u3002</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u6ce8\u610f\u4f7f\u7528<code class=\"literal\">ldapscheme</code>\u6216<code class=\"literal\">ldaptls</code>\u4ec5\u4f1a\u52a0\u5bc6PostgreSQL \u670d\u52a1\u5668\u548cLDAP\u670d\u52a1\u5668\u4e4b\u95f4\u7684\u901a\u4fe1\u3002PostgreSQL \u670d\u52a1\u5668\u548cPostgreSQL\u5ba2\u6237\u7aef\u4e4b\u95f4\u7684\u8fde\u63a5\u4ecd\u662f\u672a\u52a0\u5bc6\u7684\uff0c\u9664\u975e\u4e5f\u5728\u5176\u4e0a\u4f7f\u7528SSL\u3002</p>\n<p lang=\"zh\">\u4e0b\u5217\u9009\u9879\u53ea\u88ab\u7528\u4e8e\u7b80\u5355\u7ed1\u5b9a\u6a21\u5f0f\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapprefix</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u7b80\u5355\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u9644\u52a0\u5230\u7528\u6237\u540d\u524d\u9762\u4ee5\u5f62\u6210\u7ed1\u5b9a DN \u7684\u5b57\u7b26\u4e32\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsuffix</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u7b80\u5355\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u9644\u52a0\u5230\u7528\u6237\u540d\u540e\u9762\u4ee5\u5f62\u6210\u7ed1\u5b9a DN \u7684\u5b57\u7b26\u4e32\u3002</p>\n</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u4ee5\u4e0b\u9009\u9879\u4ec5\u5728\u641c\u7d22+\u7ed1\u5b9a\u6a21\u5f0f\u4e2d\u4f7f\u7528\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapbasedn</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4f5c\u7528\u6237\u641c\u7d22\u8d77\u70b9\u7684\u6839 DN\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapbinddn</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u7ed1\u5b9a\u5230\u76ee\u5f55\u5e76\u6267\u884c\u641c\u7d22\u7684\u7528\u6237 DN\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapbindpasswd</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u7ed1\u5b9a\u5230\u76ee\u5f55\u5e76\u6267\u884c\u641c\u7d22\u7684\u7528\u6237\u5bc6\u7801\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsearchattribute</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u4e0e\u7528\u6237\u540d\u5339\u914d\u7684\u5c5e\u6027\u3002\u5982\u679c\u672a\u6307\u5b9a\u5c5e\u6027\uff0c\u5219\u4f1a\u4f7f\u7528 <code class=\"literal\">uid</code> \u5c5e\u6027\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsearchfilter</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\u4f7f\u7528\u7684\u641c\u7d22\u8fc7\u6ee4\u5668\u3002\u5176\u4e2d\u51fa\u73b0\u7684 <code class=\"literal\">$username</code> \u4f1a\u88ab\u66ff\u6362\u4e3a\u7528\u6237\u540d\u3002\u8fd9\u4f7f\u5f97\u641c\u7d22\u8fc7\u6ee4\u5668\u6bd4 <code class=\"literal\">ldapsearchattribute</code> \u66f4\u7075\u6d3b\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapurl</code></span></dt>\n<dd>\n<p lang=\"zh\">\u7b26\u5408 RFC 4516 \u7684 LDAP URL\u3002\u8fd9\u662f\u53e6\u4e00\u79cd\u6307\u5b9a\u90e8\u5206 LDAP \u9009\u9879\u7684\u65b9\u5f0f\uff0c\u5199\u6cd5\u66f4\u7d27\u51d1\u3001\u66f4\u6807\u51c6\u3002\u5176\u683c\u5f0f\u4e3a</p>\n<pre class=\"synopsis\">ldap[s]://<em class=\"replaceable\"><code>host</code></em>[:<em class=\"replaceable\"><code>port</code></em>]/<em class=\"replaceable\"><code>basedn</code></em>[?[<em class=\"replaceable\"><code>attribute</code></em>][?[<em class=\"replaceable\"><code>scope</code></em>][?[<em class=\"replaceable\"><code>filter</code></em>]]]]\n</pre>\n<p lang=\"zh\"><em class=\"replaceable\"><code>scope</code></em> \u5fc5\u987b\u662f\u4ee5\u4e0b\u503c\u4e4b\u4e00\uff1a<code class=\"literal\">base</code>\uff0c<code class=\"literal\">one</code>\uff0c<code class=\"literal\">sub</code>\uff0c\u901a\u5e38\u4f7f\u7528\u6700\u540e\u4e00\u4e2a\u3002\uff08\u9ed8\u8ba4\u503c\u4e3a <code class=\"literal\">base</code>\uff0c\u901a\u5e38\u4e0d\u9002\u7528\u4e8e\u8fd9\u91cc\u7684\u7528\u9014\u3002\uff09<em class=\"replaceable\"><code>attribute</code></em> \u53ef\u4ee5\u6307\u5b9a\u5355\u4e2a\u5c5e\u6027\uff0c\u5e76\u7528\u5b83\u8bbe\u7f6e <code class=\"literal\">ldapsearchattribute</code>\u3002\u5982\u679c <em class=\"replaceable\"><code>attribute</code></em> \u4e3a\u7a7a\uff0c\u5219\u53ef\u4ee5\u7528 <em class=\"replaceable\"><code>filter</code></em> \u8bbe\u7f6e <code class=\"literal\">ldapsearchfilter</code>\u3002</p>\n<p lang=\"zh\">URL \u65b9\u6848 ldaps \u9009\u62e9\u901a\u8fc7 SSL \u5efa\u7acb LDAP \u8fde\u63a5\u7684 LDAPS \u65b9\u5f0f\uff0c\u7b49\u4ef7\u4e8e ldapscheme=ldaps\u3002\u8981\u901a\u8fc7 StartTLS \u4f7f\u7528\u52a0\u5bc6 LDAP \u8fde\u63a5\uff0c\u5e94\u4f7f\u7528\u666e\u901a\u7684 ldap URL \u65b9\u6848\uff0c\u5e76\u5728 ldapurl \u4e4b\u5916\u6307\u5b9a ldaptls\u3002</p>\n<p lang=\"zh\">\u5bf9\u4e8e\u975e\u533f\u540d\u7ed1\u5b9a\uff0c\u5fc5\u987b\u5c06<code class=\"literal\">ldapbinddn</code>\u548c<code class=\"literal\">ldapbindpasswd</code>\u6307\u5b9a\u4e3a\u5355\u72ec\u7684\u9009\u9879\u3002</p>\n<p lang=\"zh\">LDAP URL\u76ee\u524d\u4ec5\u53d7<span class=\"productname\">OpenLDAP</span>\u652f\u6301\uff0c\u4e0d\u652f\u6301Windows\u3002</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u5c06\u7b80\u5355\u7ed1\u5b9a\u6a21\u5f0f\u7684\u914d\u7f6e\u9009\u9879\u4e0e\u641c\u7d22+\u7ed1\u5b9a\u6a21\u5f0f\u7684\u914d\u7f6e\u9009\u9879\u6df7\u7528\u662f\u9519\u8bef\u7684\u3002</p>\n<p lang=\"zh\">\u5728\u4f7f\u7528\u641c\u7d22+\u7ed1\u5b9a\u6a21\u5f0f\u65f6\uff0c\u53ef\u4ee5\u4f7f\u7528\u7531 <code class=\"literal\">ldapsearchattribute</code> \u6307\u5b9a\u7684\u5355\u4e2a\u5c5e\u6027\u6267\u884c\u641c\u7d22\uff0c\u4e5f\u53ef\u4ee5\u4f7f\u7528\u7531 <code class=\"literal\">ldapsearchfilter</code> \u6307\u5b9a\u7684\u81ea\u5b9a\u4e49\u641c\u7d22\u8fc7\u6ee4\u5668\u6267\u884c\u641c\u7d22\u3002\u6307\u5b9a <code class=\"literal\">ldapsearchattribute=foo</code> \u7b49\u4ef7\u4e8e\u6307\u5b9a <code class=\"literal\">ldapsearchfilter=\"(foo=$username)\"</code>\u3002\u5982\u679c\u4e24\u4e2a\u9009\u9879\u90fd\u672a\u6307\u5b9a\uff0c\u5219\u9ed8\u8ba4\u4f7f\u7528 <code class=\"literal\">ldapsearchattribute=uid</code>\u3002</p>\n<p lang=\"zh\">\u5982\u679c <span class=\"productname\">PostgreSQL</span> \u7f16\u8bd1\u65f6\u4f7f\u7528\u4e86 <span class=\"productname\">OpenLDAP</span> \u4f5c\u4e3a LDAP \u5ba2\u6237\u7aef\u5e93\uff0c\u5219\u53ef\u4ee5\u7701\u7565 <code class=\"literal\">ldapserver</code> \u8bbe\u7f6e\u3002\u5728\u8fd9\u79cd\u60c5\u51b5\u4e0b\uff0c\u4f1a\u901a\u8fc7 RFC 2782 DNS SRV \u8bb0\u5f55\u67e5\u627e\u4e3b\u673a\u540d\u548c\u7aef\u53e3\u5217\u8868\u3002\u67e5\u627e\u7684\u540d\u79f0\u662f <code class=\"literal\">_ldap._tcp.DOMAIN</code>\uff0c\u5176\u4e2d <code class=\"literal\">DOMAIN</code> \u4ece <code class=\"literal\">ldapbasedn</code> \u4e2d\u63d0\u53d6\u3002</p>\n<p lang=\"zh\">\u4e0b\u9762\u662f\u4e00\u4e2a\u7b80\u5355\u7ed1\u5b9a LDAP \u914d\u7f6e\u793a\u4f8b\uff1a</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapprefix=\"cn=\" ldapsuffix=\", dc=example, dc=net\"\n</pre>\n<p lang=\"zh\">\u5f53\u8bf7\u6c42\u4ee5\u6570\u636e\u5e93\u7528\u6237 <code class=\"literal\">someuser</code> \u8fde\u63a5\u6570\u636e\u5e93\u670d\u52a1\u5668\u65f6\uff0cPostgreSQL \u5c06\u5c1d\u8bd5\u4f7f\u7528 DN <code class=\"literal\">cn=someuser, dc=example, dc=net</code> \u548c\u5ba2\u6237\u7aef\u63d0\u4f9b\u7684\u5bc6\u7801\u7ed1\u5b9a\u5230 LDAP \u670d\u52a1\u5668\u3002\u5982\u679c\u8be5\u8fde\u63a5\u6210\u529f\uff0c\u6570\u636e\u5e93\u8bbf\u95ee\u5c31\u4f1a\u88ab\u6388\u4e88\u3002</p>\n<p lang=\"zh\">\u4e0b\u9762\u662f\u641c\u7d22\u52a0\u7ed1\u5b9a\u914d\u7f6e\u7684\u793a\u4f8b\uff1a</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapbasedn=\"dc=example, dc=net\" ldapsearchattribute=uid\n</pre>\n<p lang=\"zh\">\u5f53\u8bf7\u6c42\u4ee5\u6570\u636e\u5e93\u7528\u6237 <code class=\"literal\">someuser</code> \u7684\u8eab\u4efd\u8fde\u63a5\u6570\u636e\u5e93\u670d\u52a1\u5668\u65f6\uff0cPostgreSQL \u4f1a\u5c1d\u8bd5\u533f\u540d\u7ed1\u5b9a\u5230 LDAP \u670d\u52a1\u5668\uff08\u56e0\u4e3a\u6ca1\u6709\u6307\u5b9a <code class=\"literal\">ldapbinddn</code>\uff09\uff0c\u5e76\u5728\u6307\u5b9a\u7684\u57fa\u7840 DN \u4e0b\u641c\u7d22 <code class=\"literal\">(uid=someuser)</code>\u3002\u5982\u679c\u627e\u5230\u4e86\u6761\u76ee\uff0c\u5c31\u4f1a\u5c1d\u8bd5\u4f7f\u7528\u627e\u5230\u7684\u4fe1\u606f\u548c\u5ba2\u6237\u7aef\u63d0\u4f9b\u7684\u5bc6\u7801\u8fdb\u884c\u7ed1\u5b9a\u3002\u5982\u679c\u7b2c\u4e8c\u6b21\u8fde\u63a5\u6210\u529f\uff0c\u5c31\u4f1a\u6388\u4e88\u6570\u636e\u5e93\u8bbf\u95ee\u6743\u9650\u3002</p>\n<p lang=\"zh\">\u4e0b\u9762\u662f\u4ee5 URL \u5f62\u5f0f\u5199\u51fa\u7684\u540c\u4e00\u4e2a\u641c\u7d22+\u7ed1\u5b9a\u914d\u7f6e\uff1a</p>\n<pre class=\"programlisting\">host ... ldap ldapurl=\"ldap://ldap.example.net/dc=example,dc=net?uid?sub\"\n</pre>\n<p lang=\"zh\">\u67d0\u4e9b\u652f\u6301 LDAP \u8ba4\u8bc1\u7684\u5176\u4ed6\u8f6f\u4ef6\u4e5f\u4f7f\u7528\u76f8\u540c\u7684 URL \u683c\u5f0f\uff0c\u56e0\u6b64\u5171\u4eab\u8fd9\u7c7b\u914d\u7f6e\u4f1a\u66f4\u5bb9\u6613\u3002</p>\n<p lang=\"zh\">\u8fd9\u91cc\u662f\u4e00\u4e2a\u641c\u7d22+\u7ed1\u5b9a\u914d\u7f6e\u7684\u793a\u4f8b\uff0c\u5b83\u4f7f\u7528 <code class=\"literal\">ldapsearchfilter</code> \u800c\u4e0d\u662f <code class=\"literal\">ldapsearchattribute</code> \u6765\u5141\u8bb8\u7528\u7528\u6237 ID \u6216\u7535\u5b50\u90ae\u4ef6\u5730\u5740\u8fdb\u884c\u8ba4\u8bc1\uff1a</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapbasedn=\"dc=example, dc=net\" ldapsearchfilter=\"(|(uid=$username)(mail=$username))\"\n</pre>\n<p lang=\"zh\">\u8fd9\u662f\u4e00\u4e2a\u641c\u7d22+\u7ed1\u5b9a\u914d\u7f6e\u7684\u793a\u4f8b\uff0c\u5b83\u4f7f\u7528 DNS SRV \u53d1\u73b0\u6765\u67e5\u627e\u57df\u540d <code class=\"literal\">example.net</code> \u7684 LDAP \u670d\u52a1\u7684\u4e3b\u673a\u540d\u548c\u7aef\u53e3\u3002</p>\n<pre class=\"programlisting\">host ... ldap ldapbasedn=\"dc=example,dc=net\"\n</pre>\n<div class=\"tip\">\n<h3 class=\"title\" lang=\"zh\">\u63d0\u793a</h3>\n<p lang=\"zh\">\u5982\u793a\u4f8b\u4e2d\u6240\u793a\uff0c\u7531\u4e8e LDAP \u901a\u5e38\u4f7f\u7528\u9017\u53f7\u548c\u7a7a\u683c\u6765\u5206\u5272\u4e00\u4e2a DN \u7684\u4e0d\u540c\u90e8\u5206\uff0c\u5728\u914d\u7f6e LDAP \u9009\u9879\u65f6\u901a\u5e38\u6709\u5fc5\u8981\u4f7f\u7528\u53cc\u5f15\u53f7\u5305\u56f4\u7684\u53c2\u6570\u503c\u3002</p>\n</div>\n</div>", "manual_path": "/docs/13/auth-ldap.html", "localization": {"status": "complete", "sources": [{"url": "/docs/13/auth-ldap.html", "method": "same-major semantic node", "sha256": "50e0bde9ab28266cb9d352e162c6f76e8d2de96085c9c633ab8cd4a043b509a7", "language": "zh", "matched_nodes": ["#AUTH-LDAP/div[0]", "#AUTH-LDAP/div[11]/dl[0]/dd[11]/p[0]", "#AUTH-LDAP/div[11]/dl[0]/dd[11]/p[2]", "#AUTH-LDAP/div[11]/dl[0]/dd[11]/p[4]", "#AUTH-LDAP/div[11]/dl[0]/dd[11]/p[5]", "#AUTH-LDAP/div[11]/dl[0]/dd[1]", "#AUTH-LDAP/div[11]/dl[0]/dd[3]", "#AUTH-LDAP/div[11]/dl[0]/dd[5]", "#AUTH-LDAP/div[11]/dl[0]/dd[7]", "#AUTH-LDAP/div[11]/dl[0]/dd[9]", "#AUTH-LDAP/div[28]/h3[0]", "#AUTH-LDAP/div[28]/p[1]", "#AUTH-LDAP/div[6]/dl[0]/dd[1]", "#AUTH-LDAP/div[6]/dl[0]/dd[3]", "#AUTH-LDAP/div[6]/dl[0]/dd[5]", "#AUTH-LDAP/div[9]/dl[0]/dd[1]", "#AUTH-LDAP/div[9]/dl[0]/dd[3]", "#AUTH-LDAP/p[10]", "#AUTH-LDAP/p[12]", "#AUTH-LDAP/p[13]", "#AUTH-LDAP/p[14]", "#AUTH-LDAP/p[15]", "#AUTH-LDAP/p[17]", "#AUTH-LDAP/p[18]", "#AUTH-LDAP/p[20]", "#AUTH-LDAP/p[21]", "#AUTH-LDAP/p[23]", "#AUTH-LDAP/p[24]", "#AUTH-LDAP/p[26]", "#AUTH-LDAP/p[2]", "#AUTH-LDAP/p[3]", "#AUTH-LDAP/p[4]", "#AUTH-LDAP/p[5]", "#AUTH-LDAP/p[7]", "#AUTH-LDAP/p[8]"]}], "language": "zh", "original_text": {"/versions/13/description/0": "Authenticate using an LDAP server. See Section 20.10 for details.", "/versions/13/facts/0/label": "Method", "/versions/13/facts/1/label": "Configuration", "/versions/13/facts/2/label": "Inventory", "/versions/13/facts/2/value": "User-visible source authentication method", "/versions/13/tables/0/title": "Documented method options and alternatives", "/versions/13/tables/0/columns/0/label": "Option or term", "/versions/13/tables/0/columns/1/label": "Meaning", "/versions/13/tables/0/rows/0/description": "Names or IP addresses of LDAP servers to connect to. Multiple servers may be specified, separated by spaces.", "/versions/13/tables/0/rows/1/description": "Port number on LDAP server to connect to. If no port is specified, the LDAP library's default port setting will be used.", "/versions/13/tables/0/rows/2/description": "Set to ldaps to use LDAPS. This is a non-standard way of using LDAP over SSL, supported by some LDAP server implementations. See also the ldaptls option for an alternative.", "/versions/13/tables/0/rows/3/description": "Set to 1 to make the connection between PostgreSQL and the LDAP server use TLS encryption. This uses the StartTLS operation per RFC 4513. See also the ldapscheme option for an alternative.", "/versions/13/tables/0/rows/4/description": "String to prepend to the user name when forming the DN to bind as, when doing simple bind authentication.", "/versions/13/tables/0/rows/5/description": "String to append to the user name when forming the DN to bind as, when doing simple bind authentication.", "/versions/13/tables/0/rows/6/description": "Root DN to begin the search for the user in, when doing search+bind authentication.", "/versions/13/tables/0/rows/7/description": "DN of user to bind to the directory with to perform the search when doing search+bind authentication.", "/versions/13/tables/0/rows/8/description": "Password for user to bind to the directory with to perform the search when doing search+bind authentication.", "/versions/13/tables/0/rows/9/description": "Attribute to match against the user name in the search when doing search+bind authentication. If no attribute is specified, the uid attribute will be used.", "/versions/13/tables/0/rows/10/description": "The search filter to use when doing search+bind authentication. Occurrences of $username will be replaced with the user name. This allows for more flexible search filters than ldapsearchattribute .", "/versions/13/tables/0/rows/11/description": "An RFC 4516 LDAP URL. This is an alternative way to write some of the other LDAP options in a more compact and standard form. The format is ldap[s]:// host [: port ]/ basedn [?[ attribute ][?[ scope ][?[ filter ]]]] scope must be one of base , one , sub , typically the last. (The default is base , which is normally not useful in this application.) attribute can nominate a single attribute, in which case it is used as a value for ldapsearchattribute . If attribute is empty then filter can be used as a value for ldapsearchfilter . The URL scheme ldaps chooses the LDAPS method for making LDAP connections over SSL, equivalent to using ldapscheme=ldaps . To use encrypted LDAP connections using the StartTLS operation, use the normal URL scheme ldap and specify the ldaptls option in addition to ldapurl . For non-anonymous binds, ldapbinddn and ldapbindpasswd must be specified as separate options. LDAP URLs are currently only supported with OpenLDAP , not on Windows."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "03591237c516220407d694491b8c264cf8bcf29a3f7df2875045fb2cae699846"}, "comparison_data": {"method": "ldap", "documented_option_names": ["ldapbasedn", "ldapbinddn", "ldapbindpasswd", "ldapport", "ldapprefix", "ldapscheme", "ldapsearchattribute", "ldapsearchfilter", "ldapserver", "ldapsuffix", "ldaptls", "ldapurl"]}, "comparison_hash": "d40de945ae67b3ac60a284fdd442cc24a4e9d05bc7a7b18009b54e491c381b88", "manual_language": "zh"}, "14": {"facts": [{"label": "\u65b9\u6cd5", "value": "ldap"}, {"label": "\u914d\u7f6e", "value": "pg_hba.conf"}, {"label": "\u6e05\u5355", "value": "\u7528\u6237\u53ef\u89c1\u7684\u6e90\u7801\u8ba4\u8bc1\u65b9\u6cd5"}], "tables": [{"key": "method-options", "rows": [{"name": "ldapserver", "description": "\u8981\u8fde\u63a5\u7684LDAP\u670d\u52a1\u5668\u7684\u540d\u79f0\u6216IP\u5730\u5740\u3002\u53ef\u4ee5\u6307\u5b9a\u591a\u4e2a\u670d\u52a1\u5668\uff0c\u7528\u7a7a\u683c\u5206\u9694\u3002"}, {"name": "ldapport", "description": "\u8981\u8fde\u63a5\u7684LDAP\u670d\u52a1\u5668\u7684\u7aef\u53e3\u53f7\u3002\u5982\u679c\u672a\u6307\u5b9a\u7aef\u53e3\uff0c\u5219\u5c06\u4f7f\u7528LDAP\u5e93\u7684\u9ed8\u8ba4\u7aef\u53e3\u8bbe\u7f6e\u3002"}, {"name": "ldapscheme", "description": "\u8bbe\u7f6e\u4e3a ldaps \u4ee5\u4f7f\u7528LDAPS\u3002\u8fd9\u662f\u4e00\u79cd\u975e\u6807\u51c6\u7684\u901a\u8fc7 SSL \u4f7f\u7528 LDAP \u7684\u65b9\u5f0f\uff0c\u53d7\u4e00\u4e9bLDAP\u670d\u52a1\u5668\u5b9e\u73b0\u652f\u6301\u3002\u53e6\u8bf7\u53c2\u9605 ldaptls \u9009\u9879\u4f5c\u4e3a\u66ff\u4ee3\u3002"}, {"name": "ldaptls", "description": "\u8bbe\u7f6e\u4e3a 1 \u65f6\uff0cPostgreSQL \u4e0e LDAP \u670d\u52a1\u5668\u4e4b\u95f4\u7684\u8fde\u63a5\u4f7f\u7528 TLS \u52a0\u5bc6\uff0c\u901a\u8fc7 RFC 4513 \u89c4\u5b9a\u7684 StartTLS \u64cd\u4f5c\u5b9e\u73b0\u3002\u53e6\u53ef\u53c2\u89c1 ldapscheme \u9009\u9879\u6240\u63d0\u4f9b\u7684\u66ff\u4ee3\u65b9\u5f0f\u3002"}, {"name": "ldapprefix", "description": "\u5728\u8fdb\u884c\u7b80\u5355\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u9644\u52a0\u5230\u7528\u6237\u540d\u524d\u9762\u4ee5\u5f62\u6210\u7ed1\u5b9a DN \u7684\u5b57\u7b26\u4e32\u3002"}, {"name": "ldapsuffix", "description": "\u5728\u8fdb\u884c\u7b80\u5355\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u9644\u52a0\u5230\u7528\u6237\u540d\u540e\u9762\u4ee5\u5f62\u6210\u7ed1\u5b9a DN \u7684\u5b57\u7b26\u4e32\u3002"}, {"name": "ldapbasedn", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4f5c\u7528\u6237\u641c\u7d22\u8d77\u70b9\u7684\u6839 DN\u3002"}, {"name": "ldapbinddn", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u7ed1\u5b9a\u5230\u76ee\u5f55\u5e76\u6267\u884c\u641c\u7d22\u7684\u7528\u6237 DN\u3002"}, {"name": "ldapbindpasswd", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u7ed1\u5b9a\u5230\u76ee\u5f55\u5e76\u6267\u884c\u641c\u7d22\u7684\u7528\u6237\u5bc6\u7801\u3002"}, {"name": "ldapsearchattribute", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u4e0e\u7528\u6237\u540d\u5339\u914d\u7684\u5c5e\u6027\u3002\u5982\u679c\u672a\u6307\u5b9a\u5c5e\u6027\uff0c\u5219\u4f1a\u4f7f\u7528 uid \u5c5e\u6027\u3002"}, {"name": "ldapsearchfilter", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\u4f7f\u7528\u7684\u641c\u7d22\u8fc7\u6ee4\u5668\u3002\u5176\u4e2d\u51fa\u73b0\u7684 $username \u4f1a\u88ab\u66ff\u6362\u4e3a\u7528\u6237\u540d\u3002\u8fd9\u4f7f\u5f97\u641c\u7d22\u8fc7\u6ee4\u5668\u6bd4 ldapsearchattribute \u66f4\u7075\u6d3b\u3002"}, {"name": "ldapurl", "description": "\u7b26\u5408 RFC 4516 \u7684 LDAP URL\u3002\u5b83\u4ee5\u66f4\u7d27\u51d1\u3001\u6807\u51c6\u7684\u5f62\u5f0f\u66ff\u4ee3\u90e8\u5206\u5176\u4ed6 LDAP \u9009\u9879\u3002\u683c\u5f0f\u4e3a ldap[s]://host[:port]/basedn[?[attribute][?[scope][?[filter]]]]\u3002scope \u5fc5\u987b\u4e3a base\u3001one \u6216 sub\uff0c\u901a\u5e38\u4f7f\u7528 sub\uff1b\u9ed8\u8ba4\u503c base \u5728\u6b64\u7528\u9014\u4e0b\u4e00\u822c\u6ca1\u6709\u5b9e\u9645\u5e2e\u52a9\u3002attribute \u53ef\u6307\u5b9a\u4e00\u4e2a\u5c5e\u6027\uff0c\u4f5c\u4e3a ldapsearchattribute \u7684\u503c\uff1battribute \u4e3a\u7a7a\u65f6\uff0cfilter \u53ef\u7528\u4f5c ldapsearchfilter \u7684\u503c\u3002URL \u65b9\u6848 ldaps \u8868\u793a\u901a\u8fc7 SSL \u5efa\u7acb LDAP \u8fde\u63a5\uff0c\u7b49\u540c\u4e8e ldapscheme=ldaps\u3002\u82e5\u8981\u901a\u8fc7 StartTLS \u4f7f\u7528\u52a0\u5bc6 LDAP \u8fde\u63a5\uff0c\u5e94\u4f7f\u7528\u666e\u901a\u7684 ldap URL \u65b9\u6848\uff0c\u5e76\u5728 ldapurl \u4e4b\u5916\u6307\u5b9a ldaptls\u3002\u5bf9\u4e8e\u975e\u533f\u540d\u7ed1\u5b9a\uff0c\u5fc5\u987b\u53e6\u884c\u6307\u5b9a ldapbinddn \u548c ldapbindpasswd\u3002LDAP URL \u76ee\u524d\u4ec5\u5728 OpenLDAP \u4e2d\u53d7\u652f\u6301\uff0cWindows \u4e0d\u652f\u6301\u3002"}], "title": "\u624b\u518c\u4e2d\u7684\u65b9\u6cd5\u9009\u9879\u4e0e\u66ff\u4ee3\u65b9\u5f0f", "columns": [{"key": "name", "label": "\u9009\u9879\u6216\u672f\u8bed"}, {"key": "description", "label": "\u542b\u4e49"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v14.24/postgresql-14.24.tar.bz2", "label": "14.24", "major": "14", "channel": "stable", "revision": "a7fa7ed3d558172355f51406097a7bd4f6b473be80f311ef7cda96bf383d8897", "source_sha256": "a7fa7ed3d558172355f51406097a7bd4f6b473be80f311ef7cda96bf383d8897", "catalog_fingerprint": "b272e6a82e4c46efda81c3a6a4cdf7de6a83dfff7f02f226a392fbe9acdd3adb"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v14.24/postgresql-14.24.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "a7fa7ed3d558172355f51406097a7bd4f6b473be80f311ef7cda96bf383d8897"}, {"url": "https://pg.center/docs/14/auth-ldap.html", "path": "auth-ldap.html", "label": "PostgreSQL 14 English manual", "sha256": "1e6edf4663135d54237da0efbc09280f32eae13c2c0e75ef29931356f244f440", "language": "en", "original_url": "/docs/14/auth-ldap.html"}, {"url": "https://pg.center/docs/14/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 14 English manual", "sha256": "c9a75f04fd4a1069ea261ba061578a75c47a4b7e0bbf88761502fd4c19ccbc3f", "language": "en", "original_url": "/docs/14/auth-pg-hba-conf.html"}], "sections": [], "signature": "", "attributes": {"method": "ldap", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["\u4f7f\u7528 LDAP \u670d\u52a1\u5668\u8fdb\u884c\u8ba4\u8bc1\u3002\u8be6\u60c5\u53c2\u89c1\u7b2c 21.10 \u8282\u3002"], "manual_html": "<div class=\"sect1\" id=\"AUTH-LDAP\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\" lang=\"zh\">\n<div>\n<div>\n<h2 class=\"title\" style=\"clear: both\">21.10.\u00a0LDAP \u8ba4\u8bc1 </h2>\n</div>\n</div>\n</h2>\n</div>\n</div>\n</div>\n<p lang=\"zh\">\u8fd9\u79cd\u8ba4\u8bc1\u65b9\u6cd5\u7684\u5de5\u4f5c\u65b9\u5f0f\u4e0e <code class=\"literal\">password</code> \u7c7b\u4f3c\uff0c\u53ea\u4e0d\u8fc7\u5b83\u4f7f\u7528 LDAP \u4f5c\u4e3a\u5bc6\u7801\u9a8c\u8bc1\u65b9\u6cd5\u3002LDAP \u53ea\u7528\u4e8e\u9a8c\u8bc1\u7528\u6237\u540d/\u5bc6\u7801\u5bf9\u3002\u56e0\u6b64\uff0c\u5728\u4f7f\u7528 LDAP \u8fdb\u884c\u8ba4\u8bc1\u4e4b\u524d\uff0c\u7528\u6237\u5fc5\u987b\u5df2\u7ecf\u5b58\u5728\u4e8e\u6570\u636e\u5e93\u4e2d\u3002</p>\n<p lang=\"zh\">LDAP \u8ba4\u8bc1\u53ef\u4ee5\u5728\u4e24\u79cd\u6a21\u5f0f\u4e0b\u5de5\u4f5c\u3002\u7b2c\u4e00\u79cd\u6a21\u5f0f\u79f0\u4e3a\u7b80\u5355\u7ed1\u5b9a\u6a21\u5f0f\uff0c\u670d\u52a1\u5668\u4f1a\u7ed1\u5b9a\u5230\u6309 <em class=\"replaceable\"><code>prefix</code></em> <em class=\"replaceable\"><code>username</code></em> <em class=\"replaceable\"><code>suffix</code></em> \u5f62\u5f0f\u6784\u9020\u51fa\u7684\u53ef\u5206\u8fa8\u540d\u79f0\u3002\u901a\u5e38\uff0c<em class=\"replaceable\"><code>prefix</code></em> \u53c2\u6570\u7528\u4e8e\u6307\u5b9a <code class=\"literal\">cn=</code>\uff0c\u6216\u5728 Active Directory \u73af\u5883\u4e2d\u6307\u5b9a <em class=\"replaceable\"><code>DOMAIN</code></em><code class=\"literal\">\\</code>\u3002<em class=\"replaceable\"><code>suffix</code></em> \u5219\u7528\u4e8e\u6307\u5b9a\u975e Active Directory \u73af\u5883\u4e2d DN \u7684\u5269\u4f59\u90e8\u5206\u3002</p>\n<p lang=\"zh\">\u7b2c\u4e8c\u79cd\u6a21\u5f0f\u79f0\u4e3a\u641c\u7d22+\u7ed1\u5b9a\u6a21\u5f0f\uff0c\u670d\u52a1\u5668\u9996\u5148\u4f7f\u7528\u7531 <em class=\"replaceable\"><code>ldapbinddn</code></em> \u548c <em class=\"replaceable\"><code>ldapbindpasswd</code></em> \u6307\u5b9a\u7684\u56fa\u5b9a\u7528\u6237\u540d\u548c\u5bc6\u7801\u7ed1\u5b9a\u5230 LDAP \u76ee\u5f55\uff0c\u5e76\u641c\u7d22\u8bd5\u56fe\u767b\u5f55\u6570\u636e\u5e93\u7684\u7528\u6237\u3002\u5982\u679c\u6ca1\u6709\u914d\u7f6e\u7528\u6237\u540d\u548c\u5bc6\u7801\uff0c\u5219\u4f1a\u5c1d\u8bd5\u5bf9\u76ee\u5f55\u8fdb\u884c\u533f\u540d\u7ed1\u5b9a\u3002\u641c\u7d22\u4f1a\u5728 <em class=\"replaceable\"><code>ldapbasedn</code></em> \u6307\u5b9a\u7684\u5b50\u6811\u4e0a\u8fdb\u884c\uff0c\u5e76\u5c1d\u8bd5\u5bf9 <em class=\"replaceable\"><code>ldapsearchattribute</code></em> \u6307\u5b9a\u7684\u5c5e\u6027\u505a\u7cbe\u786e\u5339\u914d\u3002\u4e00\u65e6\u5728\u641c\u7d22\u4e2d\u627e\u5230\u4e86\u8be5\u7528\u6237\uff0c\u670d\u52a1\u5668\u4f1a\u65ad\u5f00\u8fde\u63a5\uff0c\u518d\u4f5c\u4e3a\u8be5\u7528\u6237\u91cd\u65b0\u7ed1\u5b9a\u5230\u76ee\u5f55\uff0c\u5e76\u4f7f\u7528\u5ba2\u6237\u7aef\u6307\u5b9a\u7684\u5bc6\u7801\u6765\u9a8c\u8bc1\u767b\u5f55\u662f\u5426\u6b63\u786e\u3002\u8fd9\u79cd\u6a21\u5f0f\u4e0e Apache <code class=\"literal\">mod_authnz_ldap</code> \u548c <code class=\"literal\">pam_ldap</code> \u7b49\u8f6f\u4ef6\u4e2d\u7684 LDAP \u8ba4\u8bc1\u65b9\u6848\u76f8\u540c\u3002\u8fd9\u79cd\u65b9\u6cd5\u4f7f\u76ee\u5f55\u4e2d\u7528\u6237\u5bf9\u8c61\u7684\u4f4d\u7f6e\u66f4\u5177\u7075\u6d3b\u6027\uff0c\u4f46\u4f1a\u4e0e LDAP \u670d\u52a1\u5668\u5efa\u7acb\u4e24\u4e2a\u72ec\u7acb\u7684\u8fde\u63a5\u3002</p>\n<p lang=\"zh\">\u4ee5\u4e0b\u914d\u7f6e\u9009\u9879\u5728\u4e24\u79cd\u6a21\u5f0f\u4e0b\u90fd\u4f7f\u7528\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapserver</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8981\u8fde\u63a5\u7684LDAP\u670d\u52a1\u5668\u7684\u540d\u79f0\u6216IP\u5730\u5740\u3002\u53ef\u4ee5\u6307\u5b9a\u591a\u4e2a\u670d\u52a1\u5668\uff0c\u7528\u7a7a\u683c\u5206\u9694\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapport</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8981\u8fde\u63a5\u7684LDAP\u670d\u52a1\u5668\u7684\u7aef\u53e3\u53f7\u3002\u5982\u679c\u672a\u6307\u5b9a\u7aef\u53e3\uff0c\u5219\u5c06\u4f7f\u7528LDAP\u5e93\u7684\u9ed8\u8ba4\u7aef\u53e3\u8bbe\u7f6e\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapscheme</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8bbe\u7f6e\u4e3a<code class=\"literal\">ldaps</code>\u4ee5\u4f7f\u7528LDAPS\u3002\u8fd9\u662f\u4e00\u79cd\u975e\u6807\u51c6\u7684\u901a\u8fc7 SSL \u4f7f\u7528 LDAP \u7684\u65b9\u5f0f\uff0c\u53d7\u4e00\u4e9bLDAP\u670d\u52a1\u5668\u5b9e\u73b0\u652f\u6301\u3002\u53e6\u8bf7\u53c2\u9605<code class=\"literal\">ldaptls</code> \u9009\u9879\u4f5c\u4e3a\u66ff\u4ee3\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldaptls</code></span></dt>\n<dd>\n<p lang=\"zh\">\u8bbe\u7f6e\u4e3a 1 \u65f6\uff0cPostgreSQL \u4e0e LDAP \u670d\u52a1\u5668\u4e4b\u95f4\u7684\u8fde\u63a5\u4f7f\u7528 TLS \u52a0\u5bc6\uff0c\u901a\u8fc7 RFC 4513 \u89c4\u5b9a\u7684 StartTLS \u64cd\u4f5c\u5b9e\u73b0\u3002\u53e6\u53ef\u53c2\u89c1 ldapscheme \u9009\u9879\u6240\u63d0\u4f9b\u7684\u66ff\u4ee3\u65b9\u5f0f\u3002</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u6ce8\u610f\u4f7f\u7528<code class=\"literal\">ldapscheme</code>\u6216<code class=\"literal\">ldaptls</code>\u4ec5\u4f1a\u52a0\u5bc6PostgreSQL \u670d\u52a1\u5668\u548cLDAP\u670d\u52a1\u5668\u4e4b\u95f4\u7684\u901a\u4fe1\u3002PostgreSQL \u670d\u52a1\u5668\u548cPostgreSQL\u5ba2\u6237\u7aef\u4e4b\u95f4\u7684\u8fde\u63a5\u4ecd\u662f\u672a\u52a0\u5bc6\u7684\uff0c\u9664\u975e\u4e5f\u5728\u5176\u4e0a\u4f7f\u7528SSL\u3002</p>\n<p lang=\"zh\">\u4e0b\u5217\u9009\u9879\u53ea\u88ab\u7528\u4e8e\u7b80\u5355\u7ed1\u5b9a\u6a21\u5f0f\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapprefix</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u7b80\u5355\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u9644\u52a0\u5230\u7528\u6237\u540d\u524d\u9762\u4ee5\u5f62\u6210\u7ed1\u5b9a DN \u7684\u5b57\u7b26\u4e32\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsuffix</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u7b80\u5355\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u9644\u52a0\u5230\u7528\u6237\u540d\u540e\u9762\u4ee5\u5f62\u6210\u7ed1\u5b9a DN \u7684\u5b57\u7b26\u4e32\u3002</p>\n</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u4ee5\u4e0b\u9009\u9879\u4ec5\u5728\u641c\u7d22+\u7ed1\u5b9a\u6a21\u5f0f\u4e2d\u4f7f\u7528\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapbasedn</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4f5c\u7528\u6237\u641c\u7d22\u8d77\u70b9\u7684\u6839 DN\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapbinddn</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u7ed1\u5b9a\u5230\u76ee\u5f55\u5e76\u6267\u884c\u641c\u7d22\u7684\u7528\u6237 DN\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapbindpasswd</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u7ed1\u5b9a\u5230\u76ee\u5f55\u5e76\u6267\u884c\u641c\u7d22\u7684\u7528\u6237\u5bc6\u7801\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsearchattribute</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u4e0e\u7528\u6237\u540d\u5339\u914d\u7684\u5c5e\u6027\u3002\u5982\u679c\u672a\u6307\u5b9a\u5c5e\u6027\uff0c\u5219\u4f1a\u4f7f\u7528 <code class=\"literal\">uid</code> \u5c5e\u6027\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsearchfilter</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\u4f7f\u7528\u7684\u641c\u7d22\u8fc7\u6ee4\u5668\u3002\u5176\u4e2d\u51fa\u73b0\u7684 <code class=\"literal\">$username</code> \u4f1a\u88ab\u66ff\u6362\u4e3a\u7528\u6237\u540d\u3002\u8fd9\u4f7f\u5f97\u641c\u7d22\u8fc7\u6ee4\u5668\u6bd4 <code class=\"literal\">ldapsearchattribute</code> \u66f4\u7075\u6d3b\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapurl</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4e00\u4e2a<a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc4516\" target=\"_top\">RFC 4516</a> LDAP URL\u3002\u8fd9\u662f\u4ee5\u66f4\u7d27\u51d1\u548c\u6807\u51c6\u5f62\u5f0f\u7f16\u5199\u90e8\u5206\u5176\u4ed6 LDAP \u9009\u9879\u7684\u66ff\u4ee3\u65b9\u5f0f\u3002\u683c\u5f0f\u4e3a</p>\n<pre class=\"synopsis\">ldap[s]://<em class=\"replaceable\"><code>host</code></em>[:<em class=\"replaceable\"><code>port</code></em>]/<em class=\"replaceable\"><code>basedn</code></em>[?[<em class=\"replaceable\"><code>attribute</code></em>][?[<em class=\"replaceable\"><code>scope</code></em>][?[<em class=\"replaceable\"><code>filter</code></em>]]]]\n</pre>\n<p lang=\"zh\"><em class=\"replaceable\"><code>scope</code></em>\u5fc5\u987b\u662f<code class=\"literal\">base</code>\u3001<code class=\"literal\">one</code>\u3001<code class=\"literal\">sub</code>\u4e2d\u7684\u4e00\u4e2a\uff0c\u901a\u5e38\u662f\u6700\u540e\u4e00\u4e2a\u3002\uff08\u9ed8\u8ba4\u4e3a<code class=\"literal\">base</code>\uff0c\u5728\u6b64\u5e94\u7528\u4e2d\u901a\u5e38\u65e0\u7528\u3002\uff09<em class=\"replaceable\"><code>attribute</code></em>\u53ef\u4ee5\u6307\u5b9a\u5355\u4e2a\u5c5e\u6027\uff0c\u6b64\u65f6\u5c06\u7528\u4f5c<code class=\"literal\">ldapsearchattribute</code>\u7684\u503c\u3002\u5982\u679c<em class=\"replaceable\"><code>attribute</code></em>\u4e3a\u7a7a\uff0c\u5219<em class=\"replaceable\"><code>filter</code></em>\u53ef\u7528\u4f5c<code class=\"literal\">ldapsearchfilter</code>\u7684\u503c\u3002</p>\n<p lang=\"zh\">URL \u65b9\u6848 ldaps \u9009\u62e9\u901a\u8fc7 SSL \u5efa\u7acb LDAP \u8fde\u63a5\u7684 LDAPS \u65b9\u5f0f\uff0c\u7b49\u4ef7\u4e8e ldapscheme=ldaps\u3002\u8981\u901a\u8fc7 StartTLS \u4f7f\u7528\u52a0\u5bc6 LDAP \u8fde\u63a5\uff0c\u5e94\u4f7f\u7528\u666e\u901a\u7684 ldap URL \u65b9\u6848\uff0c\u5e76\u5728 ldapurl \u4e4b\u5916\u6307\u5b9a ldaptls\u3002</p>\n<p lang=\"zh\">\u5bf9\u4e8e\u975e\u533f\u540d\u7ed1\u5b9a\uff0c\u5fc5\u987b\u5c06<code class=\"literal\">ldapbinddn</code>\u548c<code class=\"literal\">ldapbindpasswd</code>\u6307\u5b9a\u4e3a\u5355\u72ec\u7684\u9009\u9879\u3002</p>\n<p lang=\"zh\">LDAP URL\u76ee\u524d\u4ec5\u53d7<span class=\"productname\">OpenLDAP</span>\u652f\u6301\uff0c\u4e0d\u652f\u6301Windows\u3002</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u5c06\u7b80\u5355\u7ed1\u5b9a\u6a21\u5f0f\u7684\u914d\u7f6e\u9009\u9879\u4e0e\u641c\u7d22+\u7ed1\u5b9a\u6a21\u5f0f\u7684\u914d\u7f6e\u9009\u9879\u6df7\u7528\u662f\u9519\u8bef\u7684\u3002</p>\n<p lang=\"zh\">\u5728\u4f7f\u7528\u641c\u7d22+\u7ed1\u5b9a\u6a21\u5f0f\u65f6\uff0c\u53ef\u4ee5\u4f7f\u7528\u7531 <code class=\"literal\">ldapsearchattribute</code> \u6307\u5b9a\u7684\u5355\u4e2a\u5c5e\u6027\u6267\u884c\u641c\u7d22\uff0c\u4e5f\u53ef\u4ee5\u4f7f\u7528\u7531 <code class=\"literal\">ldapsearchfilter</code> \u6307\u5b9a\u7684\u81ea\u5b9a\u4e49\u641c\u7d22\u8fc7\u6ee4\u5668\u6267\u884c\u641c\u7d22\u3002\u6307\u5b9a <code class=\"literal\">ldapsearchattribute=foo</code> \u7b49\u4ef7\u4e8e\u6307\u5b9a <code class=\"literal\">ldapsearchfilter=\"(foo=$username)\"</code>\u3002\u5982\u679c\u4e24\u4e2a\u9009\u9879\u90fd\u672a\u6307\u5b9a\uff0c\u5219\u9ed8\u8ba4\u4f7f\u7528 <code class=\"literal\">ldapsearchattribute=uid</code>\u3002</p>\n<p lang=\"zh\">\u5982\u679c <span class=\"productname\">PostgreSQL</span> \u7f16\u8bd1\u65f6\u4f7f\u7528\u4e86 <span class=\"productname\">OpenLDAP</span> \u4f5c\u4e3a LDAP \u5ba2\u6237\u7aef\u5e93\uff0c\u5219\u53ef\u4ee5\u7701\u7565 <code class=\"literal\">ldapserver</code> \u8bbe\u7f6e\u3002\u5728\u8fd9\u79cd\u60c5\u51b5\u4e0b\uff0c\u4f1a\u901a\u8fc7 <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc2782\" target=\"_top\">RFC 2782</a> DNS SRV \u8bb0\u5f55\u67e5\u627e\u4e3b\u673a\u540d\u548c\u7aef\u53e3\u5217\u8868\u3002\u67e5\u627e\u7684\u540d\u79f0\u662f <code class=\"literal\">_ldap._tcp.DOMAIN</code>\uff0c\u5176\u4e2d <code class=\"literal\">DOMAIN</code> \u4ece <code class=\"literal\">ldapbasedn</code> \u4e2d\u63d0\u53d6\u3002</p>\n<p lang=\"zh\">\u4e0b\u9762\u662f\u4e00\u4e2a\u7b80\u5355\u7ed1\u5b9a LDAP \u914d\u7f6e\u793a\u4f8b\uff1a</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapprefix=\"cn=\" ldapsuffix=\", dc=example, dc=net\"\n</pre>\n<p lang=\"zh\">\u5f53\u8bf7\u6c42\u4ee5\u6570\u636e\u5e93\u7528\u6237 <code class=\"literal\">someuser</code> \u8fde\u63a5\u6570\u636e\u5e93\u670d\u52a1\u5668\u65f6\uff0cPostgreSQL \u5c06\u5c1d\u8bd5\u4f7f\u7528 DN <code class=\"literal\">cn=someuser, dc=example, dc=net</code> \u548c\u5ba2\u6237\u7aef\u63d0\u4f9b\u7684\u5bc6\u7801\u7ed1\u5b9a\u5230 LDAP \u670d\u52a1\u5668\u3002\u5982\u679c\u8be5\u8fde\u63a5\u6210\u529f\uff0c\u6570\u636e\u5e93\u8bbf\u95ee\u5c31\u4f1a\u88ab\u6388\u4e88\u3002</p>\n<p lang=\"zh\">\u4e0b\u9762\u662f\u641c\u7d22\u52a0\u7ed1\u5b9a\u914d\u7f6e\u7684\u793a\u4f8b\uff1a</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapbasedn=\"dc=example, dc=net\" ldapsearchattribute=uid\n</pre>\n<p lang=\"zh\">\u5f53\u8bf7\u6c42\u4ee5\u6570\u636e\u5e93\u7528\u6237 <code class=\"literal\">someuser</code> \u7684\u8eab\u4efd\u8fde\u63a5\u6570\u636e\u5e93\u670d\u52a1\u5668\u65f6\uff0cPostgreSQL \u4f1a\u5c1d\u8bd5\u533f\u540d\u7ed1\u5b9a\u5230 LDAP \u670d\u52a1\u5668\uff08\u56e0\u4e3a\u6ca1\u6709\u6307\u5b9a <code class=\"literal\">ldapbinddn</code>\uff09\uff0c\u5e76\u5728\u6307\u5b9a\u7684\u57fa\u7840 DN \u4e0b\u641c\u7d22 <code class=\"literal\">(uid=someuser)</code>\u3002\u5982\u679c\u627e\u5230\u4e86\u6761\u76ee\uff0c\u5c31\u4f1a\u5c1d\u8bd5\u4f7f\u7528\u627e\u5230\u7684\u4fe1\u606f\u548c\u5ba2\u6237\u7aef\u63d0\u4f9b\u7684\u5bc6\u7801\u8fdb\u884c\u7ed1\u5b9a\u3002\u5982\u679c\u7b2c\u4e8c\u6b21\u8fde\u63a5\u6210\u529f\uff0c\u5c31\u4f1a\u6388\u4e88\u6570\u636e\u5e93\u8bbf\u95ee\u6743\u9650\u3002</p>\n<p lang=\"zh\">\u4e0b\u9762\u662f\u4ee5 URL \u5f62\u5f0f\u5199\u51fa\u7684\u540c\u4e00\u4e2a\u641c\u7d22+\u7ed1\u5b9a\u914d\u7f6e\uff1a</p>\n<pre class=\"programlisting\">host ... ldap ldapurl=\"ldap://ldap.example.net/dc=example,dc=net?uid?sub\"\n</pre>\n<p lang=\"zh\">\u67d0\u4e9b\u652f\u6301 LDAP \u8ba4\u8bc1\u7684\u5176\u4ed6\u8f6f\u4ef6\u4e5f\u4f7f\u7528\u76f8\u540c\u7684 URL \u683c\u5f0f\uff0c\u56e0\u6b64\u5171\u4eab\u8fd9\u7c7b\u914d\u7f6e\u4f1a\u66f4\u5bb9\u6613\u3002</p>\n<p lang=\"zh\">\u8fd9\u91cc\u662f\u4e00\u4e2a\u641c\u7d22+\u7ed1\u5b9a\u914d\u7f6e\u7684\u793a\u4f8b\uff0c\u5b83\u4f7f\u7528 <code class=\"literal\">ldapsearchfilter</code> \u800c\u4e0d\u662f <code class=\"literal\">ldapsearchattribute</code> \u6765\u5141\u8bb8\u7528\u7528\u6237 ID \u6216\u7535\u5b50\u90ae\u4ef6\u5730\u5740\u8fdb\u884c\u8ba4\u8bc1\uff1a</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapbasedn=\"dc=example, dc=net\" ldapsearchfilter=\"(|(uid=$username)(mail=$username))\"\n</pre>\n<p lang=\"zh\">\u8fd9\u662f\u4e00\u4e2a\u641c\u7d22+\u7ed1\u5b9a\u914d\u7f6e\u7684\u793a\u4f8b\uff0c\u5b83\u4f7f\u7528 DNS SRV \u53d1\u73b0\u6765\u67e5\u627e\u57df\u540d <code class=\"literal\">example.net</code> \u7684 LDAP \u670d\u52a1\u7684\u4e3b\u673a\u540d\u548c\u7aef\u53e3\u3002</p>\n<pre class=\"programlisting\">host ... ldap ldapbasedn=\"dc=example,dc=net\"\n</pre>\n<div class=\"tip\">\n<h3 class=\"title\" lang=\"zh\">\u63d0\u793a</h3>\n<p lang=\"zh\">\u5982\u793a\u4f8b\u4e2d\u6240\u793a\uff0c\u7531\u4e8e LDAP \u901a\u5e38\u4f7f\u7528\u9017\u53f7\u548c\u7a7a\u683c\u6765\u5206\u9694\u4e00\u4e2a DN \u7684\u4e0d\u540c\u90e8\u5206\uff0c\u5728\u914d\u7f6e LDAP \u9009\u9879\u65f6\u901a\u5e38\u6709\u5fc5\u8981\u4f7f\u7528\u53cc\u5f15\u53f7\u5305\u56f4\u7684\u53c2\u6570\u503c\u3002</p>\n</div>\n</div>", "manual_path": "/docs/14/auth-ldap.html", "localization": {"status": "complete", "sources": [{"url": "/docs/14/auth-ldap.html", "method": "same-major semantic node", "sha256": "3a4d284f0f020f4708fdcbe16010f3a25761a612aa125a9cfbb5a5c40e14808c", "language": "zh", "matched_nodes": ["#AUTH-LDAP/div[0]", "#AUTH-LDAP/div[11]/dl[0]/dd[11]/p[0]", "#AUTH-LDAP/div[11]/dl[0]/dd[11]/p[2]", "#AUTH-LDAP/div[11]/dl[0]/dd[11]/p[4]", "#AUTH-LDAP/div[11]/dl[0]/dd[11]/p[5]", "#AUTH-LDAP/div[11]/dl[0]/dd[1]", "#AUTH-LDAP/div[11]/dl[0]/dd[3]", "#AUTH-LDAP/div[11]/dl[0]/dd[5]", "#AUTH-LDAP/div[11]/dl[0]/dd[7]", "#AUTH-LDAP/div[11]/dl[0]/dd[9]", "#AUTH-LDAP/div[28]/h3[0]", "#AUTH-LDAP/div[28]/p[1]", "#AUTH-LDAP/div[6]/dl[0]/dd[1]", "#AUTH-LDAP/div[6]/dl[0]/dd[3]", "#AUTH-LDAP/div[6]/dl[0]/dd[5]", "#AUTH-LDAP/div[9]/dl[0]/dd[1]", "#AUTH-LDAP/div[9]/dl[0]/dd[3]", "#AUTH-LDAP/p[10]", "#AUTH-LDAP/p[12]", "#AUTH-LDAP/p[13]", "#AUTH-LDAP/p[14]", "#AUTH-LDAP/p[15]", "#AUTH-LDAP/p[17]", "#AUTH-LDAP/p[18]", "#AUTH-LDAP/p[20]", "#AUTH-LDAP/p[21]", "#AUTH-LDAP/p[23]", "#AUTH-LDAP/p[24]", "#AUTH-LDAP/p[26]", "#AUTH-LDAP/p[2]", "#AUTH-LDAP/p[3]", "#AUTH-LDAP/p[4]", "#AUTH-LDAP/p[5]", "#AUTH-LDAP/p[7]", "#AUTH-LDAP/p[8]"]}], "language": "zh", "original_text": {"/versions/14/description/0": "Authenticate using an LDAP server. See Section 21.10 for details.", "/versions/14/facts/0/label": "Method", "/versions/14/facts/1/label": "Configuration", "/versions/14/facts/2/label": "Inventory", "/versions/14/facts/2/value": "User-visible source authentication method", "/versions/14/tables/0/title": "Documented method options and alternatives", "/versions/14/tables/0/columns/0/label": "Option or term", "/versions/14/tables/0/columns/1/label": "Meaning", "/versions/14/tables/0/rows/0/description": "Names or IP addresses of LDAP servers to connect to. Multiple servers may be specified, separated by spaces.", "/versions/14/tables/0/rows/1/description": "Port number on LDAP server to connect to. If no port is specified, the LDAP library's default port setting will be used.", "/versions/14/tables/0/rows/2/description": "Set to ldaps to use LDAPS. This is a non-standard way of using LDAP over SSL, supported by some LDAP server implementations. See also the ldaptls option for an alternative.", "/versions/14/tables/0/rows/3/description": "Set to 1 to make the connection between PostgreSQL and the LDAP server use TLS encryption. This uses the StartTLS operation per RFC 4513 . See also the ldapscheme option for an alternative.", "/versions/14/tables/0/rows/4/description": "String to prepend to the user name when forming the DN to bind as, when doing simple bind authentication.", "/versions/14/tables/0/rows/5/description": "String to append to the user name when forming the DN to bind as, when doing simple bind authentication.", "/versions/14/tables/0/rows/6/description": "Root DN to begin the search for the user in, when doing search+bind authentication.", "/versions/14/tables/0/rows/7/description": "DN of user to bind to the directory with to perform the search when doing search+bind authentication.", "/versions/14/tables/0/rows/8/description": "Password for user to bind to the directory with to perform the search when doing search+bind authentication.", "/versions/14/tables/0/rows/9/description": "Attribute to match against the user name in the search when doing search+bind authentication. If no attribute is specified, the uid attribute will be used.", "/versions/14/tables/0/rows/10/description": "The search filter to use when doing search+bind authentication. Occurrences of $username will be replaced with the user name. This allows for more flexible search filters than ldapsearchattribute .", "/versions/14/tables/0/rows/11/description": "An RFC 4516 LDAP URL. This is an alternative way to write some of the other LDAP options in a more compact and standard form. The format is ldap[s]:// host [: port ]/ basedn [?[ attribute ][?[ scope ][?[ filter ]]]] scope must be one of base , one , sub , typically the last. (The default is base , which is normally not useful in this application.) attribute can nominate a single attribute, in which case it is used as a value for ldapsearchattribute . If attribute is empty then filter can be used as a value for ldapsearchfilter . The URL scheme ldaps chooses the LDAPS method for making LDAP connections over SSL, equivalent to using ldapscheme=ldaps . To use encrypted LDAP connections using the StartTLS operation, use the normal URL scheme ldap and specify the ldaptls option in addition to ldapurl . For non-anonymous binds, ldapbinddn and ldapbindpasswd must be specified as separate options. LDAP URLs are currently only supported with OpenLDAP , not on Windows."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "0bf2f56ca41386b3b571a4c19e36f13589e924e6a150d8f11bbfa975d6c75436"}, "comparison_data": {"method": "ldap", "documented_option_names": ["ldapbasedn", "ldapbinddn", "ldapbindpasswd", "ldapport", "ldapprefix", "ldapscheme", "ldapsearchattribute", "ldapsearchfilter", "ldapserver", "ldapsuffix", "ldaptls", "ldapurl"]}, "comparison_hash": "d40de945ae67b3ac60a284fdd442cc24a4e9d05bc7a7b18009b54e491c381b88", "manual_language": "zh"}, "15": {"facts": [{"label": "\u65b9\u6cd5", "value": "ldap"}, {"label": "\u914d\u7f6e", "value": "pg_hba.conf"}, {"label": "\u6e05\u5355", "value": "\u7528\u6237\u53ef\u89c1\u7684\u6e90\u7801\u8ba4\u8bc1\u65b9\u6cd5"}], "tables": [{"key": "method-options", "rows": [{"name": "ldapserver", "description": "\u8981\u8fde\u63a5\u7684LDAP\u670d\u52a1\u5668\u7684\u540d\u79f0\u6216IP\u5730\u5740\u3002\u53ef\u4ee5\u6307\u5b9a\u591a\u4e2a\u670d\u52a1\u5668\uff0c\u7528\u7a7a\u683c\u5206\u9694\u3002"}, {"name": "ldapport", "description": "\u8981\u8fde\u63a5\u7684LDAP\u670d\u52a1\u5668\u7684\u7aef\u53e3\u53f7\u3002\u5982\u679c\u672a\u6307\u5b9a\u7aef\u53e3\uff0c\u5219\u5c06\u4f7f\u7528LDAP\u5e93\u7684\u9ed8\u8ba4\u7aef\u53e3\u8bbe\u7f6e\u3002"}, {"name": "ldapscheme", "description": "\u8bbe\u7f6e\u4e3a ldaps \u4ee5\u4f7f\u7528LDAPS\u3002\u8fd9\u662f\u4e00\u79cd\u975e\u6807\u51c6\u7684\u901a\u8fc7 SSL \u4f7f\u7528 LDAP \u7684\u65b9\u5f0f\uff0c\u53d7\u4e00\u4e9bLDAP\u670d\u52a1\u5668\u5b9e\u73b0\u652f\u6301\u3002\u53e6\u8bf7\u53c2\u9605 ldaptls \u9009\u9879\u4f5c\u4e3a\u66ff\u4ee3\u3002"}, {"name": "ldaptls", "description": "\u8bbe\u7f6e\u4e3a 1 \u65f6\uff0cPostgreSQL \u4e0e LDAP \u670d\u52a1\u5668\u4e4b\u95f4\u7684\u8fde\u63a5\u4f7f\u7528 TLS \u52a0\u5bc6\uff0c\u901a\u8fc7 RFC 4513 \u89c4\u5b9a\u7684 StartTLS \u64cd\u4f5c\u5b9e\u73b0\u3002\u53e6\u53ef\u53c2\u89c1 ldapscheme \u9009\u9879\u6240\u63d0\u4f9b\u7684\u66ff\u4ee3\u65b9\u5f0f\u3002"}, {"name": "ldapprefix", "description": "\u5728\u8fdb\u884c\u7b80\u5355\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u9644\u52a0\u5230\u7528\u6237\u540d\u524d\u9762\u4ee5\u5f62\u6210\u7ed1\u5b9a DN \u7684\u5b57\u7b26\u4e32\u3002"}, {"name": "ldapsuffix", "description": "\u5728\u8fdb\u884c\u7b80\u5355\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u9644\u52a0\u5230\u7528\u6237\u540d\u540e\u9762\u4ee5\u5f62\u6210\u7ed1\u5b9a DN \u7684\u5b57\u7b26\u4e32\u3002"}, {"name": "ldapbasedn", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4f5c\u7528\u6237\u641c\u7d22\u8d77\u70b9\u7684\u6839 DN\u3002"}, {"name": "ldapbinddn", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u7ed1\u5b9a\u5230\u76ee\u5f55\u5e76\u6267\u884c\u641c\u7d22\u7684\u7528\u6237 DN\u3002"}, {"name": "ldapbindpasswd", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u7ed1\u5b9a\u5230\u76ee\u5f55\u5e76\u6267\u884c\u641c\u7d22\u7684\u7528\u6237\u5bc6\u7801\u3002"}, {"name": "ldapsearchattribute", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u4e0e\u7528\u6237\u540d\u5339\u914d\u7684\u5c5e\u6027\u3002\u5982\u679c\u672a\u6307\u5b9a\u5c5e\u6027\uff0c\u5219\u4f1a\u4f7f\u7528 uid \u5c5e\u6027\u3002"}, {"name": "ldapsearchfilter", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\u4f7f\u7528\u7684\u641c\u7d22\u8fc7\u6ee4\u5668\u3002\u5176\u4e2d\u51fa\u73b0\u7684 $username \u4f1a\u88ab\u66ff\u6362\u4e3a\u7528\u6237\u540d\u3002\u8fd9\u4f7f\u5f97\u641c\u7d22\u8fc7\u6ee4\u5668\u6bd4 ldapsearchattribute \u66f4\u7075\u6d3b\u3002"}, {"name": "ldapurl", "description": "\u7b26\u5408 RFC 4516 \u7684 LDAP URL\u3002\u5b83\u4ee5\u66f4\u7d27\u51d1\u3001\u6807\u51c6\u7684\u5f62\u5f0f\u66ff\u4ee3\u90e8\u5206\u5176\u4ed6 LDAP \u9009\u9879\u3002\u683c\u5f0f\u4e3a ldap[s]://host[:port]/basedn[?[attribute][?[scope][?[filter]]]]\u3002scope \u5fc5\u987b\u4e3a base\u3001one \u6216 sub\uff0c\u901a\u5e38\u4f7f\u7528 sub\uff1b\u9ed8\u8ba4\u503c base \u5728\u6b64\u7528\u9014\u4e0b\u4e00\u822c\u6ca1\u6709\u5b9e\u9645\u5e2e\u52a9\u3002attribute \u53ef\u6307\u5b9a\u4e00\u4e2a\u5c5e\u6027\uff0c\u4f5c\u4e3a ldapsearchattribute \u7684\u503c\uff1battribute \u4e3a\u7a7a\u65f6\uff0cfilter \u53ef\u7528\u4f5c ldapsearchfilter \u7684\u503c\u3002URL \u65b9\u6848 ldaps \u8868\u793a\u901a\u8fc7 SSL \u5efa\u7acb LDAP \u8fde\u63a5\uff0c\u7b49\u540c\u4e8e ldapscheme=ldaps\u3002\u82e5\u8981\u901a\u8fc7 StartTLS \u4f7f\u7528\u52a0\u5bc6 LDAP \u8fde\u63a5\uff0c\u5e94\u4f7f\u7528\u666e\u901a\u7684 ldap URL \u65b9\u6848\uff0c\u5e76\u5728 ldapurl \u4e4b\u5916\u6307\u5b9a ldaptls\u3002\u5bf9\u4e8e\u975e\u533f\u540d\u7ed1\u5b9a\uff0c\u5fc5\u987b\u53e6\u884c\u6307\u5b9a ldapbinddn \u548c ldapbindpasswd\u3002LDAP URL \u76ee\u524d\u4ec5\u5728 OpenLDAP \u4e2d\u53d7\u652f\u6301\uff0cWindows \u4e0d\u652f\u6301\u3002"}], "title": "\u624b\u518c\u4e2d\u7684\u65b9\u6cd5\u9009\u9879\u4e0e\u66ff\u4ee3\u65b9\u5f0f", "columns": [{"key": "name", "label": "\u9009\u9879\u6216\u672f\u8bed"}, {"key": "description", "label": "\u542b\u4e49"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v15.19/postgresql-15.19.tar.bz2", "label": "15.19", "major": "15", "channel": "stable", "revision": "e1a64a87a46b825b88c082e4518161a47aab53c45694964f8ba1df28f7859f89", "source_sha256": "e1a64a87a46b825b88c082e4518161a47aab53c45694964f8ba1df28f7859f89", "catalog_fingerprint": "fefe3c425147a86defada190c9b0663cfe02caa1724f5dede93e46457572252d"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v15.19/postgresql-15.19.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "e1a64a87a46b825b88c082e4518161a47aab53c45694964f8ba1df28f7859f89"}, {"url": "https://pg.center/docs/15/auth-ldap.html", "path": "auth-ldap.html", "label": "PostgreSQL 15 English manual", "sha256": "f355c23a666075dc2968875e229ebead4f0d113db4944f61a5ade70f5f496e9f", "language": "en", "original_url": "/docs/15/auth-ldap.html"}, {"url": "https://pg.center/docs/15/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 15 English manual", "sha256": "0470cd3eeb82cbc32d4b8b79e29f4427bdfd01f5bb15e6d9b7cee2f6dd2bba44", "language": "en", "original_url": "/docs/15/auth-pg-hba-conf.html"}], "sections": [], "signature": "", "attributes": {"method": "ldap", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["\u4f7f\u7528 LDAP \u670d\u52a1\u5668\u8fdb\u884c\u8ba4\u8bc1\u3002\u8be6\u60c5\u53c2\u89c1\u7b2c 21.10 \u8282\u3002"], "manual_html": "<div class=\"sect1\" id=\"AUTH-LDAP\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\" lang=\"zh\">\n<div>\n<div>\n<h2 class=\"title\" style=\"clear: both\">21.10.\u00a0LDAP \u8ba4\u8bc1 </h2>\n</div>\n</div>\n</h2>\n</div>\n</div>\n</div>\n<p lang=\"zh\">\u8fd9\u79cd\u8ba4\u8bc1\u65b9\u6cd5\u7684\u5de5\u4f5c\u65b9\u5f0f\u4e0e <code class=\"literal\">password</code> \u7c7b\u4f3c\uff0c\u53ea\u4e0d\u8fc7\u5b83\u4f7f\u7528 LDAP \u4f5c\u4e3a\u5bc6\u7801\u9a8c\u8bc1\u65b9\u6cd5\u3002LDAP \u53ea\u7528\u4e8e\u9a8c\u8bc1\u7528\u6237\u540d/\u5bc6\u7801\u5bf9\u3002\u56e0\u6b64\uff0c\u5728\u4f7f\u7528 LDAP \u8fdb\u884c\u8ba4\u8bc1\u4e4b\u524d\uff0c\u7528\u6237\u5fc5\u987b\u5df2\u7ecf\u5b58\u5728\u4e8e\u6570\u636e\u5e93\u4e2d\u3002</p>\n<p lang=\"zh\">LDAP \u8ba4\u8bc1\u53ef\u4ee5\u5728\u4e24\u79cd\u6a21\u5f0f\u4e0b\u5de5\u4f5c\u3002\u7b2c\u4e00\u79cd\u6a21\u5f0f\u79f0\u4e3a\u7b80\u5355\u7ed1\u5b9a\u6a21\u5f0f\uff0c\u670d\u52a1\u5668\u4f1a\u7ed1\u5b9a\u5230\u6309 <em class=\"replaceable\"><code>prefix</code></em> <em class=\"replaceable\"><code>username</code></em> <em class=\"replaceable\"><code>suffix</code></em> \u5f62\u5f0f\u6784\u9020\u51fa\u7684\u53ef\u5206\u8fa8\u540d\u79f0\u3002\u901a\u5e38\uff0c<em class=\"replaceable\"><code>prefix</code></em> \u53c2\u6570\u7528\u4e8e\u6307\u5b9a <code class=\"literal\">cn=</code>\uff0c\u6216\u5728 Active Directory \u73af\u5883\u4e2d\u6307\u5b9a <em class=\"replaceable\"><code>DOMAIN</code></em><code class=\"literal\">\\</code>\u3002<em class=\"replaceable\"><code>suffix</code></em> \u5219\u7528\u4e8e\u6307\u5b9a\u975e Active Directory \u73af\u5883\u4e2d DN \u7684\u5269\u4f59\u90e8\u5206\u3002</p>\n<p lang=\"zh\">\u7b2c\u4e8c\u79cd\u6a21\u5f0f\u79f0\u4e3a\u641c\u7d22+\u7ed1\u5b9a\u6a21\u5f0f\uff0c\u670d\u52a1\u5668\u9996\u5148\u4f7f\u7528\u7531 <em class=\"replaceable\"><code>ldapbinddn</code></em> \u548c <em class=\"replaceable\"><code>ldapbindpasswd</code></em> \u6307\u5b9a\u7684\u56fa\u5b9a\u7528\u6237\u540d\u548c\u5bc6\u7801\u7ed1\u5b9a\u5230 LDAP \u76ee\u5f55\uff0c\u5e76\u641c\u7d22\u8bd5\u56fe\u767b\u5f55\u6570\u636e\u5e93\u7684\u7528\u6237\u3002\u5982\u679c\u6ca1\u6709\u914d\u7f6e\u7528\u6237\u540d\u548c\u5bc6\u7801\uff0c\u5219\u4f1a\u5c1d\u8bd5\u5bf9\u76ee\u5f55\u8fdb\u884c\u533f\u540d\u7ed1\u5b9a\u3002\u641c\u7d22\u4f1a\u5728 <em class=\"replaceable\"><code>ldapbasedn</code></em> \u6307\u5b9a\u7684\u5b50\u6811\u4e0a\u8fdb\u884c\uff0c\u5e76\u5c1d\u8bd5\u5bf9 <em class=\"replaceable\"><code>ldapsearchattribute</code></em> \u6307\u5b9a\u7684\u5c5e\u6027\u505a\u7cbe\u786e\u5339\u914d\u3002\u4e00\u65e6\u5728\u641c\u7d22\u4e2d\u627e\u5230\u4e86\u8be5\u7528\u6237\uff0c\u670d\u52a1\u5668\u4f1a\u65ad\u5f00\u8fde\u63a5\uff0c\u518d\u4f5c\u4e3a\u8be5\u7528\u6237\u91cd\u65b0\u7ed1\u5b9a\u5230\u76ee\u5f55\uff0c\u5e76\u4f7f\u7528\u5ba2\u6237\u7aef\u6307\u5b9a\u7684\u5bc6\u7801\u6765\u9a8c\u8bc1\u767b\u5f55\u662f\u5426\u6b63\u786e\u3002\u8fd9\u79cd\u6a21\u5f0f\u4e0e Apache <code class=\"literal\">mod_authnz_ldap</code> \u548c <code class=\"literal\">pam_ldap</code> \u7b49\u8f6f\u4ef6\u4e2d\u7684 LDAP \u8ba4\u8bc1\u65b9\u6848\u76f8\u540c\u3002\u8fd9\u79cd\u65b9\u6cd5\u4f7f\u76ee\u5f55\u4e2d\u7528\u6237\u5bf9\u8c61\u7684\u4f4d\u7f6e\u66f4\u5177\u7075\u6d3b\u6027\uff0c\u4f46\u4f1a\u4e0e LDAP \u670d\u52a1\u5668\u5efa\u7acb\u4e24\u4e2a\u72ec\u7acb\u7684\u8fde\u63a5\u3002</p>\n<p lang=\"zh\">\u4ee5\u4e0b\u914d\u7f6e\u9009\u9879\u5728\u4e24\u79cd\u6a21\u5f0f\u4e0b\u90fd\u4f7f\u7528\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapserver</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8981\u8fde\u63a5\u7684LDAP\u670d\u52a1\u5668\u7684\u540d\u79f0\u6216IP\u5730\u5740\u3002\u53ef\u4ee5\u6307\u5b9a\u591a\u4e2a\u670d\u52a1\u5668\uff0c\u7528\u7a7a\u683c\u5206\u9694\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapport</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8981\u8fde\u63a5\u7684LDAP\u670d\u52a1\u5668\u7684\u7aef\u53e3\u53f7\u3002\u5982\u679c\u672a\u6307\u5b9a\u7aef\u53e3\uff0c\u5219\u5c06\u4f7f\u7528LDAP\u5e93\u7684\u9ed8\u8ba4\u7aef\u53e3\u8bbe\u7f6e\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapscheme</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8bbe\u7f6e\u4e3a<code class=\"literal\">ldaps</code>\u4ee5\u4f7f\u7528LDAPS\u3002\u8fd9\u662f\u4e00\u79cd\u975e\u6807\u51c6\u7684\u901a\u8fc7 SSL \u4f7f\u7528 LDAP \u7684\u65b9\u5f0f\uff0c\u53d7\u4e00\u4e9bLDAP\u670d\u52a1\u5668\u5b9e\u73b0\u652f\u6301\u3002\u53e6\u8bf7\u53c2\u9605<code class=\"literal\">ldaptls</code> \u9009\u9879\u4f5c\u4e3a\u66ff\u4ee3\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldaptls</code></span></dt>\n<dd>\n<p lang=\"zh\">\u8bbe\u7f6e\u4e3a 1 \u65f6\uff0cPostgreSQL \u4e0e LDAP \u670d\u52a1\u5668\u4e4b\u95f4\u7684\u8fde\u63a5\u4f7f\u7528 TLS \u52a0\u5bc6\uff0c\u901a\u8fc7 RFC 4513 \u89c4\u5b9a\u7684 StartTLS \u64cd\u4f5c\u5b9e\u73b0\u3002\u53e6\u53ef\u53c2\u89c1 ldapscheme \u9009\u9879\u6240\u63d0\u4f9b\u7684\u66ff\u4ee3\u65b9\u5f0f\u3002</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u6ce8\u610f\u4f7f\u7528<code class=\"literal\">ldapscheme</code>\u6216<code class=\"literal\">ldaptls</code>\u4ec5\u4f1a\u52a0\u5bc6PostgreSQL \u670d\u52a1\u5668\u548cLDAP\u670d\u52a1\u5668\u4e4b\u95f4\u7684\u901a\u4fe1\u3002PostgreSQL \u670d\u52a1\u5668\u548cPostgreSQL\u5ba2\u6237\u7aef\u4e4b\u95f4\u7684\u8fde\u63a5\u4ecd\u662f\u672a\u52a0\u5bc6\u7684\uff0c\u9664\u975e\u4e5f\u5728\u5176\u4e0a\u4f7f\u7528SSL\u3002</p>\n<p lang=\"zh\">\u4e0b\u5217\u9009\u9879\u53ea\u88ab\u7528\u4e8e\u7b80\u5355\u7ed1\u5b9a\u6a21\u5f0f\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapprefix</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u7b80\u5355\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u9644\u52a0\u5230\u7528\u6237\u540d\u524d\u9762\u4ee5\u5f62\u6210\u7ed1\u5b9a DN \u7684\u5b57\u7b26\u4e32\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsuffix</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u7b80\u5355\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u9644\u52a0\u5230\u7528\u6237\u540d\u540e\u9762\u4ee5\u5f62\u6210\u7ed1\u5b9a DN \u7684\u5b57\u7b26\u4e32\u3002</p>\n</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u4ee5\u4e0b\u9009\u9879\u4ec5\u5728\u641c\u7d22+\u7ed1\u5b9a\u6a21\u5f0f\u4e2d\u4f7f\u7528\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapbasedn</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4f5c\u7528\u6237\u641c\u7d22\u8d77\u70b9\u7684\u6839 DN\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapbinddn</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u7ed1\u5b9a\u5230\u76ee\u5f55\u5e76\u6267\u884c\u641c\u7d22\u7684\u7528\u6237 DN\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapbindpasswd</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u7ed1\u5b9a\u5230\u76ee\u5f55\u5e76\u6267\u884c\u641c\u7d22\u7684\u7528\u6237\u5bc6\u7801\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsearchattribute</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u4e0e\u7528\u6237\u540d\u5339\u914d\u7684\u5c5e\u6027\u3002\u5982\u679c\u672a\u6307\u5b9a\u5c5e\u6027\uff0c\u5219\u4f1a\u4f7f\u7528 <code class=\"literal\">uid</code> \u5c5e\u6027\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsearchfilter</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\u4f7f\u7528\u7684\u641c\u7d22\u8fc7\u6ee4\u5668\u3002\u5176\u4e2d\u51fa\u73b0\u7684 <code class=\"literal\">$username</code> \u4f1a\u88ab\u66ff\u6362\u4e3a\u7528\u6237\u540d\u3002\u8fd9\u4f7f\u5f97\u641c\u7d22\u8fc7\u6ee4\u5668\u6bd4 <code class=\"literal\">ldapsearchattribute</code> \u66f4\u7075\u6d3b\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapurl</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4e00\u4e2a<a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc4516\" target=\"_top\">RFC 4516</a> LDAP URL\u3002\u8fd9\u662f\u4ee5\u66f4\u7d27\u51d1\u548c\u6807\u51c6\u5f62\u5f0f\u7f16\u5199\u90e8\u5206\u5176\u4ed6 LDAP \u9009\u9879\u7684\u66ff\u4ee3\u65b9\u5f0f\u3002\u683c\u5f0f\u4e3a</p>\n<pre class=\"synopsis\">ldap[s]://<em class=\"replaceable\"><code>host</code></em>[:<em class=\"replaceable\"><code>port</code></em>]/<em class=\"replaceable\"><code>basedn</code></em>[?[<em class=\"replaceable\"><code>attribute</code></em>][?[<em class=\"replaceable\"><code>scope</code></em>][?[<em class=\"replaceable\"><code>filter</code></em>]]]]\n</pre>\n<p lang=\"zh\"><em class=\"replaceable\"><code>scope</code></em>\u5fc5\u987b\u662f<code class=\"literal\">base</code>\u3001<code class=\"literal\">one</code>\u3001<code class=\"literal\">sub</code>\u4e2d\u7684\u4e00\u4e2a\uff0c\u901a\u5e38\u662f\u6700\u540e\u4e00\u4e2a\u3002\uff08\u9ed8\u8ba4\u4e3a<code class=\"literal\">base</code>\uff0c\u5728\u6b64\u5e94\u7528\u4e2d\u901a\u5e38\u65e0\u7528\u3002\uff09<em class=\"replaceable\"><code>attribute</code></em>\u53ef\u4ee5\u6307\u5b9a\u5355\u4e2a\u5c5e\u6027\uff0c\u6b64\u65f6\u5c06\u7528\u4f5c<code class=\"literal\">ldapsearchattribute</code>\u7684\u503c\u3002\u5982\u679c<em class=\"replaceable\"><code>attribute</code></em>\u4e3a\u7a7a\uff0c\u5219<em class=\"replaceable\"><code>filter</code></em>\u53ef\u7528\u4f5c<code class=\"literal\">ldapsearchfilter</code>\u7684\u503c\u3002</p>\n<p lang=\"zh\">URL \u65b9\u6848 ldaps \u9009\u62e9\u901a\u8fc7 SSL \u5efa\u7acb LDAP \u8fde\u63a5\u7684 LDAPS \u65b9\u5f0f\uff0c\u7b49\u4ef7\u4e8e ldapscheme=ldaps\u3002\u8981\u901a\u8fc7 StartTLS \u4f7f\u7528\u52a0\u5bc6 LDAP \u8fde\u63a5\uff0c\u5e94\u4f7f\u7528\u666e\u901a\u7684 ldap URL \u65b9\u6848\uff0c\u5e76\u5728 ldapurl \u4e4b\u5916\u6307\u5b9a ldaptls\u3002</p>\n<p lang=\"zh\">\u5bf9\u4e8e\u975e\u533f\u540d\u7ed1\u5b9a\uff0c\u5fc5\u987b\u5c06<code class=\"literal\">ldapbinddn</code>\u548c<code class=\"literal\">ldapbindpasswd</code>\u6307\u5b9a\u4e3a\u5355\u72ec\u7684\u9009\u9879\u3002</p>\n<p lang=\"zh\">LDAP URL\u76ee\u524d\u4ec5\u53d7<span class=\"productname\">OpenLDAP</span>\u652f\u6301\uff0c\u4e0d\u652f\u6301Windows\u3002</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u5c06\u7b80\u5355\u7ed1\u5b9a\u6a21\u5f0f\u7684\u914d\u7f6e\u9009\u9879\u4e0e\u641c\u7d22+\u7ed1\u5b9a\u6a21\u5f0f\u7684\u914d\u7f6e\u9009\u9879\u6df7\u7528\u662f\u9519\u8bef\u7684\u3002</p>\n<p lang=\"zh\">\u5728\u4f7f\u7528\u641c\u7d22+\u7ed1\u5b9a\u6a21\u5f0f\u65f6\uff0c\u53ef\u4ee5\u4f7f\u7528\u7531 <code class=\"literal\">ldapsearchattribute</code> \u6307\u5b9a\u7684\u5355\u4e2a\u5c5e\u6027\u6267\u884c\u641c\u7d22\uff0c\u4e5f\u53ef\u4ee5\u4f7f\u7528\u7531 <code class=\"literal\">ldapsearchfilter</code> \u6307\u5b9a\u7684\u81ea\u5b9a\u4e49\u641c\u7d22\u8fc7\u6ee4\u5668\u6267\u884c\u641c\u7d22\u3002\u6307\u5b9a <code class=\"literal\">ldapsearchattribute=foo</code> \u7b49\u4ef7\u4e8e\u6307\u5b9a <code class=\"literal\">ldapsearchfilter=\"(foo=$username)\"</code>\u3002\u5982\u679c\u4e24\u4e2a\u9009\u9879\u90fd\u672a\u6307\u5b9a\uff0c\u5219\u9ed8\u8ba4\u4f7f\u7528 <code class=\"literal\">ldapsearchattribute=uid</code>\u3002</p>\n<p lang=\"zh\">\u5982\u679c <span class=\"productname\">PostgreSQL</span> \u7f16\u8bd1\u65f6\u4f7f\u7528\u4e86 <span class=\"productname\">OpenLDAP</span> \u4f5c\u4e3a LDAP \u5ba2\u6237\u7aef\u5e93\uff0c\u5219\u53ef\u4ee5\u7701\u7565 <code class=\"literal\">ldapserver</code> \u8bbe\u7f6e\u3002\u5728\u8fd9\u79cd\u60c5\u51b5\u4e0b\uff0c\u4f1a\u901a\u8fc7 <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc2782\" target=\"_top\">RFC 2782</a> DNS SRV \u8bb0\u5f55\u67e5\u627e\u4e3b\u673a\u540d\u548c\u7aef\u53e3\u5217\u8868\u3002\u67e5\u627e\u7684\u540d\u79f0\u662f <code class=\"literal\">_ldap._tcp.DOMAIN</code>\uff0c\u5176\u4e2d <code class=\"literal\">DOMAIN</code> \u4ece <code class=\"literal\">ldapbasedn</code> \u4e2d\u63d0\u53d6\u3002</p>\n<p lang=\"zh\">\u4e0b\u9762\u662f\u4e00\u4e2a\u7b80\u5355\u7ed1\u5b9a LDAP \u914d\u7f6e\u793a\u4f8b\uff1a</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapprefix=\"cn=\" ldapsuffix=\", dc=example, dc=net\"\n</pre>\n<p lang=\"zh\">\u5f53\u8bf7\u6c42\u4ee5\u6570\u636e\u5e93\u7528\u6237 <code class=\"literal\">someuser</code> \u8fde\u63a5\u6570\u636e\u5e93\u670d\u52a1\u5668\u65f6\uff0cPostgreSQL \u5c06\u5c1d\u8bd5\u4f7f\u7528 DN <code class=\"literal\">cn=someuser, dc=example, dc=net</code> \u548c\u5ba2\u6237\u7aef\u63d0\u4f9b\u7684\u5bc6\u7801\u7ed1\u5b9a\u5230 LDAP \u670d\u52a1\u5668\u3002\u5982\u679c\u8be5\u8fde\u63a5\u6210\u529f\uff0c\u6570\u636e\u5e93\u8bbf\u95ee\u5c31\u4f1a\u88ab\u6388\u4e88\u3002</p>\n<p lang=\"zh\">\u4e0b\u9762\u662f\u641c\u7d22\u52a0\u7ed1\u5b9a\u914d\u7f6e\u7684\u793a\u4f8b\uff1a</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapbasedn=\"dc=example, dc=net\" ldapsearchattribute=uid\n</pre>\n<p lang=\"zh\">\u5f53\u8bf7\u6c42\u4ee5\u6570\u636e\u5e93\u7528\u6237 <code class=\"literal\">someuser</code> \u7684\u8eab\u4efd\u8fde\u63a5\u6570\u636e\u5e93\u670d\u52a1\u5668\u65f6\uff0cPostgreSQL \u4f1a\u5c1d\u8bd5\u533f\u540d\u7ed1\u5b9a\u5230 LDAP \u670d\u52a1\u5668\uff08\u56e0\u4e3a\u6ca1\u6709\u6307\u5b9a <code class=\"literal\">ldapbinddn</code>\uff09\uff0c\u5e76\u5728\u6307\u5b9a\u7684\u57fa\u7840 DN \u4e0b\u641c\u7d22 <code class=\"literal\">(uid=someuser)</code>\u3002\u5982\u679c\u627e\u5230\u4e86\u6761\u76ee\uff0c\u5c31\u4f1a\u5c1d\u8bd5\u4f7f\u7528\u627e\u5230\u7684\u4fe1\u606f\u548c\u5ba2\u6237\u7aef\u63d0\u4f9b\u7684\u5bc6\u7801\u8fdb\u884c\u7ed1\u5b9a\u3002\u5982\u679c\u7b2c\u4e8c\u6b21\u8fde\u63a5\u6210\u529f\uff0c\u5c31\u4f1a\u6388\u4e88\u6570\u636e\u5e93\u8bbf\u95ee\u6743\u9650\u3002</p>\n<p lang=\"zh\">\u4e0b\u9762\u662f\u4ee5 URL \u5f62\u5f0f\u5199\u51fa\u7684\u540c\u4e00\u4e2a\u641c\u7d22+\u7ed1\u5b9a\u914d\u7f6e\uff1a</p>\n<pre class=\"programlisting\">host ... ldap ldapurl=\"ldap://ldap.example.net/dc=example,dc=net?uid?sub\"\n</pre>\n<p lang=\"zh\">\u67d0\u4e9b\u652f\u6301 LDAP \u8ba4\u8bc1\u7684\u5176\u4ed6\u8f6f\u4ef6\u4e5f\u4f7f\u7528\u76f8\u540c\u7684 URL \u683c\u5f0f\uff0c\u56e0\u6b64\u5171\u4eab\u8fd9\u7c7b\u914d\u7f6e\u4f1a\u66f4\u5bb9\u6613\u3002</p>\n<p lang=\"zh\">\u8fd9\u91cc\u662f\u4e00\u4e2a\u641c\u7d22+\u7ed1\u5b9a\u914d\u7f6e\u7684\u793a\u4f8b\uff0c\u5b83\u4f7f\u7528 <code class=\"literal\">ldapsearchfilter</code> \u800c\u4e0d\u662f <code class=\"literal\">ldapsearchattribute</code> \u6765\u5141\u8bb8\u7528\u7528\u6237 ID \u6216\u7535\u5b50\u90ae\u4ef6\u5730\u5740\u8fdb\u884c\u8ba4\u8bc1\uff1a</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapbasedn=\"dc=example, dc=net\" ldapsearchfilter=\"(|(uid=$username)(mail=$username))\"\n</pre>\n<p lang=\"zh\">\u8fd9\u662f\u4e00\u4e2a\u641c\u7d22+\u7ed1\u5b9a\u914d\u7f6e\u7684\u793a\u4f8b\uff0c\u5b83\u4f7f\u7528 DNS SRV \u53d1\u73b0\u6765\u67e5\u627e\u57df\u540d <code class=\"literal\">example.net</code> \u7684 LDAP \u670d\u52a1\u7684\u4e3b\u673a\u540d\u548c\u7aef\u53e3\u3002</p>\n<pre class=\"programlisting\">host ... ldap ldapbasedn=\"dc=example,dc=net\"\n</pre>\n<div class=\"tip\">\n<h3 class=\"title\" lang=\"zh\">\u63d0\u793a</h3>\n<p lang=\"zh\">\u5982\u793a\u4f8b\u4e2d\u6240\u793a\uff0c\u7531\u4e8e LDAP \u901a\u5e38\u4f7f\u7528\u9017\u53f7\u548c\u7a7a\u683c\u6765\u5206\u9694\u4e00\u4e2a DN \u7684\u4e0d\u540c\u90e8\u5206\uff0c\u5728\u914d\u7f6e LDAP \u9009\u9879\u65f6\u901a\u5e38\u6709\u5fc5\u8981\u4f7f\u7528\u53cc\u5f15\u53f7\u5305\u56f4\u7684\u53c2\u6570\u503c\u3002</p>\n</div>\n</div>", "manual_path": "/docs/15/auth-ldap.html", "localization": {"status": "complete", "sources": [{"url": "/docs/15/auth-ldap.html", "method": "same-major semantic node", "sha256": "1fb6d6d20d0a96d0108aac8e0bd4dbb4732fe3f1631c208968b4afeb0bcd32a3", "language": "zh", "matched_nodes": ["#AUTH-LDAP/div[0]", "#AUTH-LDAP/div[11]/dl[0]/dd[11]/p[0]", "#AUTH-LDAP/div[11]/dl[0]/dd[11]/p[2]", "#AUTH-LDAP/div[11]/dl[0]/dd[11]/p[4]", "#AUTH-LDAP/div[11]/dl[0]/dd[11]/p[5]", "#AUTH-LDAP/div[11]/dl[0]/dd[1]", "#AUTH-LDAP/div[11]/dl[0]/dd[3]", "#AUTH-LDAP/div[11]/dl[0]/dd[5]", "#AUTH-LDAP/div[11]/dl[0]/dd[7]", "#AUTH-LDAP/div[11]/dl[0]/dd[9]", "#AUTH-LDAP/div[28]/h3[0]", "#AUTH-LDAP/div[28]/p[1]", "#AUTH-LDAP/div[6]/dl[0]/dd[1]", "#AUTH-LDAP/div[6]/dl[0]/dd[3]", "#AUTH-LDAP/div[6]/dl[0]/dd[5]", "#AUTH-LDAP/div[9]/dl[0]/dd[1]", "#AUTH-LDAP/div[9]/dl[0]/dd[3]", "#AUTH-LDAP/p[10]", "#AUTH-LDAP/p[12]", "#AUTH-LDAP/p[13]", "#AUTH-LDAP/p[14]", "#AUTH-LDAP/p[15]", "#AUTH-LDAP/p[17]", "#AUTH-LDAP/p[18]", "#AUTH-LDAP/p[20]", "#AUTH-LDAP/p[21]", "#AUTH-LDAP/p[23]", "#AUTH-LDAP/p[24]", "#AUTH-LDAP/p[26]", "#AUTH-LDAP/p[2]", "#AUTH-LDAP/p[3]", "#AUTH-LDAP/p[4]", "#AUTH-LDAP/p[5]", "#AUTH-LDAP/p[7]", "#AUTH-LDAP/p[8]"]}], "language": "zh", "original_text": {"/versions/15/description/0": "Authenticate using an LDAP server. See Section 21.10 for details.", "/versions/15/facts/0/label": "Method", "/versions/15/facts/1/label": "Configuration", "/versions/15/facts/2/label": "Inventory", "/versions/15/facts/2/value": "User-visible source authentication method", "/versions/15/tables/0/title": "Documented method options and alternatives", "/versions/15/tables/0/columns/0/label": "Option or term", "/versions/15/tables/0/columns/1/label": "Meaning", "/versions/15/tables/0/rows/0/description": "Names or IP addresses of LDAP servers to connect to. Multiple servers may be specified, separated by spaces.", "/versions/15/tables/0/rows/1/description": "Port number on LDAP server to connect to. If no port is specified, the LDAP library's default port setting will be used.", "/versions/15/tables/0/rows/2/description": "Set to ldaps to use LDAPS. This is a non-standard way of using LDAP over SSL, supported by some LDAP server implementations. See also the ldaptls option for an alternative.", "/versions/15/tables/0/rows/3/description": "Set to 1 to make the connection between PostgreSQL and the LDAP server use TLS encryption. This uses the StartTLS operation per RFC 4513 . See also the ldapscheme option for an alternative.", "/versions/15/tables/0/rows/4/description": "String to prepend to the user name when forming the DN to bind as, when doing simple bind authentication.", "/versions/15/tables/0/rows/5/description": "String to append to the user name when forming the DN to bind as, when doing simple bind authentication.", "/versions/15/tables/0/rows/6/description": "Root DN to begin the search for the user in, when doing search+bind authentication.", "/versions/15/tables/0/rows/7/description": "DN of user to bind to the directory with to perform the search when doing search+bind authentication.", "/versions/15/tables/0/rows/8/description": "Password for user to bind to the directory with to perform the search when doing search+bind authentication.", "/versions/15/tables/0/rows/9/description": "Attribute to match against the user name in the search when doing search+bind authentication. If no attribute is specified, the uid attribute will be used.", "/versions/15/tables/0/rows/10/description": "The search filter to use when doing search+bind authentication. Occurrences of $username will be replaced with the user name. This allows for more flexible search filters than ldapsearchattribute .", "/versions/15/tables/0/rows/11/description": "An RFC 4516 LDAP URL. This is an alternative way to write some of the other LDAP options in a more compact and standard form. The format is ldap[s]:// host [: port ]/ basedn [?[ attribute ][?[ scope ][?[ filter ]]]] scope must be one of base , one , sub , typically the last. (The default is base , which is normally not useful in this application.) attribute can nominate a single attribute, in which case it is used as a value for ldapsearchattribute . If attribute is empty then filter can be used as a value for ldapsearchfilter . The URL scheme ldaps chooses the LDAPS method for making LDAP connections over SSL, equivalent to using ldapscheme=ldaps . To use encrypted LDAP connections using the StartTLS operation, use the normal URL scheme ldap and specify the ldaptls option in addition to ldapurl . For non-anonymous binds, ldapbinddn and ldapbindpasswd must be specified as separate options. LDAP URLs are currently only supported with OpenLDAP , not on Windows."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "646c5de13090f1591beff23ec8095e3892e0f2c929ab6a2f7781fbd8cc3ddc42"}, "comparison_data": {"method": "ldap", "documented_option_names": ["ldapbasedn", "ldapbinddn", "ldapbindpasswd", "ldapport", "ldapprefix", "ldapscheme", "ldapsearchattribute", "ldapsearchfilter", "ldapserver", "ldapsuffix", "ldaptls", "ldapurl"]}, "comparison_hash": "d40de945ae67b3ac60a284fdd442cc24a4e9d05bc7a7b18009b54e491c381b88", "manual_language": "zh"}, "16": {"facts": [{"label": "\u65b9\u6cd5", "value": "ldap"}, {"label": "\u914d\u7f6e", "value": "pg_hba.conf"}, {"label": "\u6e05\u5355", "value": "\u7528\u6237\u53ef\u89c1\u7684\u6e90\u7801\u8ba4\u8bc1\u65b9\u6cd5"}], "tables": [{"key": "method-options", "rows": [{"name": "ldapserver", "description": "\u8981\u8fde\u63a5\u7684LDAP\u670d\u52a1\u5668\u7684\u540d\u79f0\u6216IP\u5730\u5740\u3002\u53ef\u4ee5\u6307\u5b9a\u591a\u4e2a\u670d\u52a1\u5668\uff0c\u7528\u7a7a\u683c\u5206\u9694\u3002"}, {"name": "ldapport", "description": "\u8981\u8fde\u63a5\u7684LDAP\u670d\u52a1\u5668\u7684\u7aef\u53e3\u53f7\u3002\u5982\u679c\u672a\u6307\u5b9a\u7aef\u53e3\uff0c\u5219\u5c06\u4f7f\u7528LDAP\u5e93\u7684\u9ed8\u8ba4\u7aef\u53e3\u8bbe\u7f6e\u3002"}, {"name": "ldapscheme", "description": "\u8bbe\u7f6e\u4e3a ldaps \u4ee5\u4f7f\u7528LDAPS\u3002\u8fd9\u662f\u4e00\u79cd\u975e\u6807\u51c6\u7684\u901a\u8fc7 SSL \u4f7f\u7528 LDAP \u7684\u65b9\u5f0f\uff0c\u53d7\u4e00\u4e9bLDAP\u670d\u52a1\u5668\u5b9e\u73b0\u652f\u6301\u3002\u53e6\u8bf7\u53c2\u9605 ldaptls \u9009\u9879\u4f5c\u4e3a\u66ff\u4ee3\u3002"}, {"name": "ldaptls", "description": "\u8bbe\u7f6e\u4e3a 1 \u65f6\uff0cPostgreSQL \u4e0e LDAP \u670d\u52a1\u5668\u4e4b\u95f4\u7684\u8fde\u63a5\u4f7f\u7528 TLS \u52a0\u5bc6\uff0c\u901a\u8fc7 RFC 4513 \u89c4\u5b9a\u7684 StartTLS \u64cd\u4f5c\u5b9e\u73b0\u3002\u53e6\u53ef\u53c2\u89c1 ldapscheme \u9009\u9879\u6240\u63d0\u4f9b\u7684\u66ff\u4ee3\u65b9\u5f0f\u3002"}, {"name": "ldapprefix", "description": "\u5728\u8fdb\u884c\u7b80\u5355\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u9644\u52a0\u5230\u7528\u6237\u540d\u524d\u9762\u4ee5\u5f62\u6210\u7ed1\u5b9a DN \u7684\u5b57\u7b26\u4e32\u3002"}, {"name": "ldapsuffix", "description": "\u5728\u8fdb\u884c\u7b80\u5355\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u9644\u52a0\u5230\u7528\u6237\u540d\u540e\u9762\u4ee5\u5f62\u6210\u7ed1\u5b9a DN \u7684\u5b57\u7b26\u4e32\u3002"}, {"name": "ldapbasedn", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4f5c\u7528\u6237\u641c\u7d22\u8d77\u70b9\u7684\u6839 DN\u3002"}, {"name": "ldapbinddn", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u7ed1\u5b9a\u5230\u76ee\u5f55\u5e76\u6267\u884c\u641c\u7d22\u7684\u7528\u6237 DN\u3002"}, {"name": "ldapbindpasswd", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u7ed1\u5b9a\u5230\u76ee\u5f55\u5e76\u6267\u884c\u641c\u7d22\u7684\u7528\u6237\u5bc6\u7801\u3002"}, {"name": "ldapsearchattribute", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u4e0e\u7528\u6237\u540d\u5339\u914d\u7684\u5c5e\u6027\u3002\u5982\u679c\u672a\u6307\u5b9a\u5c5e\u6027\uff0c\u5219\u4f1a\u4f7f\u7528 uid \u5c5e\u6027\u3002"}, {"name": "ldapsearchfilter", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\u4f7f\u7528\u7684\u641c\u7d22\u8fc7\u6ee4\u5668\u3002\u5176\u4e2d\u51fa\u73b0\u7684 $username \u4f1a\u88ab\u66ff\u6362\u4e3a\u7528\u6237\u540d\u3002\u8fd9\u4f7f\u5f97\u641c\u7d22\u8fc7\u6ee4\u5668\u6bd4 ldapsearchattribute \u66f4\u7075\u6d3b\u3002"}, {"name": "ldapurl", "description": "\u7b26\u5408 RFC 4516 \u7684 LDAP URL\u3002\u5b83\u4ee5\u66f4\u7d27\u51d1\u3001\u6807\u51c6\u7684\u5f62\u5f0f\u66ff\u4ee3\u90e8\u5206\u5176\u4ed6 LDAP \u9009\u9879\u3002\u683c\u5f0f\u4e3a ldap[s]://host[:port]/basedn[?[attribute][?[scope][?[filter]]]]\u3002scope \u5fc5\u987b\u4e3a base\u3001one \u6216 sub\uff0c\u901a\u5e38\u4f7f\u7528 sub\uff1b\u9ed8\u8ba4\u503c base \u5728\u6b64\u7528\u9014\u4e0b\u4e00\u822c\u6ca1\u6709\u5b9e\u9645\u5e2e\u52a9\u3002attribute \u53ef\u6307\u5b9a\u4e00\u4e2a\u5c5e\u6027\uff0c\u4f5c\u4e3a ldapsearchattribute \u7684\u503c\uff1battribute \u4e3a\u7a7a\u65f6\uff0cfilter \u53ef\u7528\u4f5c ldapsearchfilter \u7684\u503c\u3002URL \u65b9\u6848 ldaps \u8868\u793a\u901a\u8fc7 SSL \u5efa\u7acb LDAP \u8fde\u63a5\uff0c\u7b49\u540c\u4e8e ldapscheme=ldaps\u3002\u82e5\u8981\u901a\u8fc7 StartTLS \u4f7f\u7528\u52a0\u5bc6 LDAP \u8fde\u63a5\uff0c\u5e94\u4f7f\u7528\u666e\u901a\u7684 ldap URL \u65b9\u6848\uff0c\u5e76\u5728 ldapurl \u4e4b\u5916\u6307\u5b9a ldaptls\u3002\u5bf9\u4e8e\u975e\u533f\u540d\u7ed1\u5b9a\uff0c\u5fc5\u987b\u53e6\u884c\u6307\u5b9a ldapbinddn \u548c ldapbindpasswd\u3002LDAP URL \u76ee\u524d\u4ec5\u5728 OpenLDAP \u4e2d\u53d7\u652f\u6301\uff0cWindows \u4e0d\u652f\u6301\u3002"}], "title": "\u624b\u518c\u4e2d\u7684\u65b9\u6cd5\u9009\u9879\u4e0e\u66ff\u4ee3\u65b9\u5f0f", "columns": [{"key": "name", "label": "\u9009\u9879\u6216\u672f\u8bed"}, {"key": "description", "label": "\u542b\u4e49"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v16.15/postgresql-16.15.tar.bz2", "label": "16.15", "major": "16", "channel": "stable", "revision": "c1575341fa7bd40f5274ea465b34390f4dc64cdd0770af327005caaeb9f6b7ed", "source_sha256": "c1575341fa7bd40f5274ea465b34390f4dc64cdd0770af327005caaeb9f6b7ed", "catalog_fingerprint": "fa133458dc8f52e15083b4f59b7a582e2e378b608d3ac5c53054df458a374e23"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v16.15/postgresql-16.15.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "c1575341fa7bd40f5274ea465b34390f4dc64cdd0770af327005caaeb9f6b7ed"}, {"url": "https://pg.center/docs/16/auth-ldap.html", "path": "auth-ldap.html", "label": "PostgreSQL 16 English manual", "sha256": "dd667e5c2ce6cb14df859d3da34720144c888a8f3b8d443d789343e538c5e94a", "language": "en", "original_url": "/docs/16/auth-ldap.html"}, {"url": "https://pg.center/docs/16/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 16 English manual", "sha256": "ccc5146375a184646d5992edbc693e12c0de4431a35141d6b56c8dd6b3c52132", "language": "en", "original_url": "/docs/16/auth-pg-hba-conf.html"}], "sections": [], "signature": "", "attributes": {"method": "ldap", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["\u4f7f\u7528 LDAP \u670d\u52a1\u5668\u8fdb\u884c\u8ba4\u8bc1\u3002\u8be6\u60c5\u53c2\u89c1\u7b2c 21.10 \u8282\u3002"], "manual_html": "<div class=\"sect1\" id=\"AUTH-LDAP\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\" lang=\"zh\">\n<div>\n<div>\n<h2 class=\"title\" style=\"clear: both\">21.10.\u00a0LDAP \u8ba4\u8bc1 </h2>\n</div>\n</div>\n</h2>\n</div>\n</div>\n</div>\n<p lang=\"zh\">\u8fd9\u79cd\u8ba4\u8bc1\u65b9\u6cd5\u7684\u5de5\u4f5c\u65b9\u5f0f\u4e0e <code class=\"literal\">password</code> \u7c7b\u4f3c\uff0c\u53ea\u4e0d\u8fc7\u5b83\u4f7f\u7528 LDAP \u4f5c\u4e3a\u5bc6\u7801\u9a8c\u8bc1\u65b9\u6cd5\u3002LDAP \u53ea\u7528\u4e8e\u9a8c\u8bc1\u7528\u6237\u540d/\u5bc6\u7801\u5bf9\u3002\u56e0\u6b64\uff0c\u5728\u4f7f\u7528 LDAP \u8fdb\u884c\u8ba4\u8bc1\u4e4b\u524d\uff0c\u7528\u6237\u5fc5\u987b\u5df2\u7ecf\u5b58\u5728\u4e8e\u6570\u636e\u5e93\u4e2d\u3002</p>\n<p lang=\"zh\">LDAP \u8ba4\u8bc1\u53ef\u4ee5\u5728\u4e24\u79cd\u6a21\u5f0f\u4e0b\u5de5\u4f5c\u3002\u7b2c\u4e00\u79cd\u6a21\u5f0f\u79f0\u4e3a\u7b80\u5355\u7ed1\u5b9a\u6a21\u5f0f\uff0c\u670d\u52a1\u5668\u4f1a\u7ed1\u5b9a\u5230\u6309 <em class=\"replaceable\"><code>prefix</code></em> <em class=\"replaceable\"><code>username</code></em> <em class=\"replaceable\"><code>suffix</code></em> \u5f62\u5f0f\u6784\u9020\u51fa\u7684\u53ef\u5206\u8fa8\u540d\u79f0\u3002\u901a\u5e38\uff0c<em class=\"replaceable\"><code>prefix</code></em> \u53c2\u6570\u7528\u4e8e\u6307\u5b9a <code class=\"literal\">cn=</code>\uff0c\u6216\u5728 Active Directory \u73af\u5883\u4e2d\u6307\u5b9a <em class=\"replaceable\"><code>DOMAIN</code></em><code class=\"literal\">\\</code>\u3002<em class=\"replaceable\"><code>suffix</code></em> \u5219\u7528\u4e8e\u6307\u5b9a\u975e Active Directory \u73af\u5883\u4e2d DN \u7684\u5269\u4f59\u90e8\u5206\u3002</p>\n<p lang=\"zh\">\u7b2c\u4e8c\u79cd\u6a21\u5f0f\u79f0\u4e3a\u641c\u7d22+\u7ed1\u5b9a\u6a21\u5f0f\uff0c\u670d\u52a1\u5668\u9996\u5148\u4f7f\u7528\u7531 <em class=\"replaceable\"><code>ldapbinddn</code></em> \u548c <em class=\"replaceable\"><code>ldapbindpasswd</code></em> \u6307\u5b9a\u7684\u56fa\u5b9a\u7528\u6237\u540d\u548c\u5bc6\u7801\u7ed1\u5b9a\u5230 LDAP \u76ee\u5f55\uff0c\u5e76\u641c\u7d22\u8bd5\u56fe\u767b\u5f55\u6570\u636e\u5e93\u7684\u7528\u6237\u3002\u5982\u679c\u6ca1\u6709\u914d\u7f6e\u7528\u6237\u540d\u548c\u5bc6\u7801\uff0c\u5219\u4f1a\u5c1d\u8bd5\u5bf9\u76ee\u5f55\u8fdb\u884c\u533f\u540d\u7ed1\u5b9a\u3002\u641c\u7d22\u4f1a\u5728 <em class=\"replaceable\"><code>ldapbasedn</code></em> \u6307\u5b9a\u7684\u5b50\u6811\u4e0a\u8fdb\u884c\uff0c\u5e76\u5c1d\u8bd5\u5bf9 <em class=\"replaceable\"><code>ldapsearchattribute</code></em> \u6307\u5b9a\u7684\u5c5e\u6027\u505a\u7cbe\u786e\u5339\u914d\u3002\u4e00\u65e6\u5728\u641c\u7d22\u4e2d\u627e\u5230\u4e86\u8be5\u7528\u6237\uff0c\u670d\u52a1\u5668\u4f1a\u65ad\u5f00\u8fde\u63a5\uff0c\u518d\u4f5c\u4e3a\u8be5\u7528\u6237\u91cd\u65b0\u7ed1\u5b9a\u5230\u76ee\u5f55\uff0c\u5e76\u4f7f\u7528\u5ba2\u6237\u7aef\u6307\u5b9a\u7684\u5bc6\u7801\u6765\u9a8c\u8bc1\u767b\u5f55\u662f\u5426\u6b63\u786e\u3002\u8fd9\u79cd\u6a21\u5f0f\u4e0e Apache <code class=\"literal\">mod_authnz_ldap</code> \u548c <code class=\"literal\">pam_ldap</code> \u7b49\u8f6f\u4ef6\u4e2d\u7684 LDAP \u8ba4\u8bc1\u65b9\u6848\u76f8\u540c\u3002\u8fd9\u79cd\u65b9\u6cd5\u4f7f\u76ee\u5f55\u4e2d\u7528\u6237\u5bf9\u8c61\u7684\u4f4d\u7f6e\u66f4\u5177\u7075\u6d3b\u6027\uff0c\u4f46\u4f1a\u4e0e LDAP \u670d\u52a1\u5668\u5efa\u7acb\u4e24\u4e2a\u72ec\u7acb\u7684\u8fde\u63a5\u3002</p>\n<p lang=\"zh\">\u4ee5\u4e0b\u914d\u7f6e\u9009\u9879\u5728\u4e24\u79cd\u6a21\u5f0f\u4e0b\u90fd\u4f7f\u7528\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapserver</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8981\u8fde\u63a5\u7684LDAP\u670d\u52a1\u5668\u7684\u540d\u79f0\u6216IP\u5730\u5740\u3002\u53ef\u4ee5\u6307\u5b9a\u591a\u4e2a\u670d\u52a1\u5668\uff0c\u7528\u7a7a\u683c\u5206\u9694\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapport</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8981\u8fde\u63a5\u7684LDAP\u670d\u52a1\u5668\u7684\u7aef\u53e3\u53f7\u3002\u5982\u679c\u672a\u6307\u5b9a\u7aef\u53e3\uff0c\u5219\u5c06\u4f7f\u7528LDAP\u5e93\u7684\u9ed8\u8ba4\u7aef\u53e3\u8bbe\u7f6e\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapscheme</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8bbe\u7f6e\u4e3a<code class=\"literal\">ldaps</code>\u4ee5\u4f7f\u7528LDAPS\u3002\u8fd9\u662f\u4e00\u79cd\u975e\u6807\u51c6\u7684\u901a\u8fc7 SSL \u4f7f\u7528 LDAP \u7684\u65b9\u5f0f\uff0c\u53d7\u4e00\u4e9bLDAP\u670d\u52a1\u5668\u5b9e\u73b0\u652f\u6301\u3002\u53e6\u8bf7\u53c2\u9605<code class=\"literal\">ldaptls</code> \u9009\u9879\u4f5c\u4e3a\u66ff\u4ee3\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldaptls</code></span></dt>\n<dd>\n<p lang=\"zh\">\u8bbe\u7f6e\u4e3a 1 \u65f6\uff0cPostgreSQL \u4e0e LDAP \u670d\u52a1\u5668\u4e4b\u95f4\u7684\u8fde\u63a5\u4f7f\u7528 TLS \u52a0\u5bc6\uff0c\u901a\u8fc7 RFC 4513 \u89c4\u5b9a\u7684 StartTLS \u64cd\u4f5c\u5b9e\u73b0\u3002\u53e6\u53ef\u53c2\u89c1 ldapscheme \u9009\u9879\u6240\u63d0\u4f9b\u7684\u66ff\u4ee3\u65b9\u5f0f\u3002</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u6ce8\u610f\u4f7f\u7528<code class=\"literal\">ldapscheme</code>\u6216<code class=\"literal\">ldaptls</code>\u4ec5\u4f1a\u52a0\u5bc6PostgreSQL \u670d\u52a1\u5668\u548cLDAP\u670d\u52a1\u5668\u4e4b\u95f4\u7684\u901a\u4fe1\u3002PostgreSQL \u670d\u52a1\u5668\u548cPostgreSQL\u5ba2\u6237\u7aef\u4e4b\u95f4\u7684\u8fde\u63a5\u4ecd\u662f\u672a\u52a0\u5bc6\u7684\uff0c\u9664\u975e\u4e5f\u5728\u5176\u4e0a\u4f7f\u7528SSL\u3002</p>\n<p lang=\"zh\">\u4e0b\u5217\u9009\u9879\u53ea\u88ab\u7528\u4e8e\u7b80\u5355\u7ed1\u5b9a\u6a21\u5f0f\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapprefix</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u7b80\u5355\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u9644\u52a0\u5230\u7528\u6237\u540d\u524d\u9762\u4ee5\u5f62\u6210\u7ed1\u5b9a DN \u7684\u5b57\u7b26\u4e32\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsuffix</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u7b80\u5355\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u9644\u52a0\u5230\u7528\u6237\u540d\u540e\u9762\u4ee5\u5f62\u6210\u7ed1\u5b9a DN \u7684\u5b57\u7b26\u4e32\u3002</p>\n</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u4ee5\u4e0b\u9009\u9879\u4ec5\u5728\u641c\u7d22+\u7ed1\u5b9a\u6a21\u5f0f\u4e2d\u4f7f\u7528\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapbasedn</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4f5c\u7528\u6237\u641c\u7d22\u8d77\u70b9\u7684\u6839 DN\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapbinddn</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u7ed1\u5b9a\u5230\u76ee\u5f55\u5e76\u6267\u884c\u641c\u7d22\u7684\u7528\u6237 DN\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapbindpasswd</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u7ed1\u5b9a\u5230\u76ee\u5f55\u5e76\u6267\u884c\u641c\u7d22\u7684\u7528\u6237\u5bc6\u7801\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsearchattribute</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u4e0e\u7528\u6237\u540d\u5339\u914d\u7684\u5c5e\u6027\u3002\u5982\u679c\u672a\u6307\u5b9a\u5c5e\u6027\uff0c\u5219\u4f1a\u4f7f\u7528 <code class=\"literal\">uid</code> \u5c5e\u6027\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsearchfilter</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\u4f7f\u7528\u7684\u641c\u7d22\u8fc7\u6ee4\u5668\u3002\u5176\u4e2d\u51fa\u73b0\u7684 <code class=\"literal\">$username</code> \u4f1a\u88ab\u66ff\u6362\u4e3a\u7528\u6237\u540d\u3002\u8fd9\u4f7f\u5f97\u641c\u7d22\u8fc7\u6ee4\u5668\u6bd4 <code class=\"literal\">ldapsearchattribute</code> \u66f4\u7075\u6d3b\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapurl</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4e00\u4e2a<a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc4516\" target=\"_top\">RFC 4516</a> LDAP URL\u3002\u8fd9\u662f\u4ee5\u66f4\u7d27\u51d1\u548c\u6807\u51c6\u5f62\u5f0f\u7f16\u5199\u90e8\u5206\u5176\u4ed6 LDAP \u9009\u9879\u7684\u66ff\u4ee3\u65b9\u5f0f\u3002\u683c\u5f0f\u4e3a</p>\n<pre class=\"synopsis\">ldap[s]://<em class=\"replaceable\"><code>host</code></em>[:<em class=\"replaceable\"><code>port</code></em>]/<em class=\"replaceable\"><code>basedn</code></em>[?[<em class=\"replaceable\"><code>attribute</code></em>][?[<em class=\"replaceable\"><code>scope</code></em>][?[<em class=\"replaceable\"><code>filter</code></em>]]]]\n</pre>\n<p lang=\"zh\"><em class=\"replaceable\"><code>scope</code></em>\u5fc5\u987b\u662f<code class=\"literal\">base</code>\u3001<code class=\"literal\">one</code>\u3001<code class=\"literal\">sub</code>\u4e2d\u7684\u4e00\u4e2a\uff0c\u901a\u5e38\u662f\u6700\u540e\u4e00\u4e2a\u3002\uff08\u9ed8\u8ba4\u4e3a<code class=\"literal\">base</code>\uff0c\u5728\u6b64\u5e94\u7528\u4e2d\u901a\u5e38\u65e0\u7528\u3002\uff09<em class=\"replaceable\"><code>attribute</code></em>\u53ef\u4ee5\u6307\u5b9a\u5355\u4e2a\u5c5e\u6027\uff0c\u6b64\u65f6\u5c06\u7528\u4f5c<code class=\"literal\">ldapsearchattribute</code>\u7684\u503c\u3002\u5982\u679c<em class=\"replaceable\"><code>attribute</code></em>\u4e3a\u7a7a\uff0c\u5219<em class=\"replaceable\"><code>filter</code></em>\u53ef\u7528\u4f5c<code class=\"literal\">ldapsearchfilter</code>\u7684\u503c\u3002</p>\n<p lang=\"zh\">URL \u65b9\u6848 ldaps \u9009\u62e9\u901a\u8fc7 SSL \u5efa\u7acb LDAP \u8fde\u63a5\u7684 LDAPS \u65b9\u5f0f\uff0c\u7b49\u4ef7\u4e8e ldapscheme=ldaps\u3002\u8981\u901a\u8fc7 StartTLS \u4f7f\u7528\u52a0\u5bc6 LDAP \u8fde\u63a5\uff0c\u5e94\u4f7f\u7528\u666e\u901a\u7684 ldap URL \u65b9\u6848\uff0c\u5e76\u5728 ldapurl \u4e4b\u5916\u6307\u5b9a ldaptls\u3002</p>\n<p lang=\"zh\">\u5bf9\u4e8e\u975e\u533f\u540d\u7ed1\u5b9a\uff0c\u5fc5\u987b\u5c06<code class=\"literal\">ldapbinddn</code>\u548c<code class=\"literal\">ldapbindpasswd</code>\u6307\u5b9a\u4e3a\u5355\u72ec\u7684\u9009\u9879\u3002</p>\n<p lang=\"zh\">LDAP URL\u76ee\u524d\u4ec5\u53d7<span class=\"productname\">OpenLDAP</span>\u652f\u6301\uff0c\u4e0d\u652f\u6301Windows\u3002</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u5c06\u7b80\u5355\u7ed1\u5b9a\u6a21\u5f0f\u7684\u914d\u7f6e\u9009\u9879\u4e0e\u641c\u7d22+\u7ed1\u5b9a\u6a21\u5f0f\u7684\u914d\u7f6e\u9009\u9879\u6df7\u7528\u662f\u9519\u8bef\u7684\u3002</p>\n<p lang=\"zh\">\u5728\u4f7f\u7528\u641c\u7d22+\u7ed1\u5b9a\u6a21\u5f0f\u65f6\uff0c\u53ef\u4ee5\u4f7f\u7528\u7531 <code class=\"literal\">ldapsearchattribute</code> \u6307\u5b9a\u7684\u5355\u4e2a\u5c5e\u6027\u6267\u884c\u641c\u7d22\uff0c\u4e5f\u53ef\u4ee5\u4f7f\u7528\u7531 <code class=\"literal\">ldapsearchfilter</code> \u6307\u5b9a\u7684\u81ea\u5b9a\u4e49\u641c\u7d22\u8fc7\u6ee4\u5668\u6267\u884c\u641c\u7d22\u3002\u6307\u5b9a <code class=\"literal\">ldapsearchattribute=foo</code> \u7b49\u4ef7\u4e8e\u6307\u5b9a <code class=\"literal\">ldapsearchfilter=\"(foo=$username)\"</code>\u3002\u5982\u679c\u4e24\u4e2a\u9009\u9879\u90fd\u672a\u6307\u5b9a\uff0c\u5219\u9ed8\u8ba4\u4f7f\u7528 <code class=\"literal\">ldapsearchattribute=uid</code>\u3002</p>\n<p lang=\"zh\">\u5982\u679c <span class=\"productname\">PostgreSQL</span> \u7f16\u8bd1\u65f6\u4f7f\u7528\u4e86 <span class=\"productname\">OpenLDAP</span> \u4f5c\u4e3a LDAP \u5ba2\u6237\u7aef\u5e93\uff0c\u5219\u53ef\u4ee5\u7701\u7565 <code class=\"literal\">ldapserver</code> \u8bbe\u7f6e\u3002\u5728\u8fd9\u79cd\u60c5\u51b5\u4e0b\uff0c\u4f1a\u901a\u8fc7 <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc2782\" target=\"_top\">RFC 2782</a> DNS SRV \u8bb0\u5f55\u67e5\u627e\u4e3b\u673a\u540d\u548c\u7aef\u53e3\u5217\u8868\u3002\u67e5\u627e\u7684\u540d\u79f0\u662f <code class=\"literal\">_ldap._tcp.DOMAIN</code>\uff0c\u5176\u4e2d <code class=\"literal\">DOMAIN</code> \u4ece <code class=\"literal\">ldapbasedn</code> \u4e2d\u63d0\u53d6\u3002</p>\n<p lang=\"zh\">\u4e0b\u9762\u662f\u4e00\u4e2a\u7b80\u5355\u7ed1\u5b9a LDAP \u914d\u7f6e\u793a\u4f8b\uff1a</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapprefix=\"cn=\" ldapsuffix=\", dc=example, dc=net\"\n</pre>\n<p lang=\"zh\">\u5f53\u8bf7\u6c42\u4ee5\u6570\u636e\u5e93\u7528\u6237 <code class=\"literal\">someuser</code> \u8fde\u63a5\u6570\u636e\u5e93\u670d\u52a1\u5668\u65f6\uff0cPostgreSQL \u5c06\u5c1d\u8bd5\u4f7f\u7528 DN <code class=\"literal\">cn=someuser, dc=example, dc=net</code> \u548c\u5ba2\u6237\u7aef\u63d0\u4f9b\u7684\u5bc6\u7801\u7ed1\u5b9a\u5230 LDAP \u670d\u52a1\u5668\u3002\u5982\u679c\u8be5\u8fde\u63a5\u6210\u529f\uff0c\u6570\u636e\u5e93\u8bbf\u95ee\u5c31\u4f1a\u88ab\u6388\u4e88\u3002</p>\n<p lang=\"zh\">\u4e0b\u9762\u662f\u641c\u7d22\u52a0\u7ed1\u5b9a\u914d\u7f6e\u7684\u793a\u4f8b\uff1a</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapbasedn=\"dc=example, dc=net\" ldapsearchattribute=uid\n</pre>\n<p lang=\"zh\">\u5f53\u8bf7\u6c42\u4ee5\u6570\u636e\u5e93\u7528\u6237 <code class=\"literal\">someuser</code> \u7684\u8eab\u4efd\u8fde\u63a5\u6570\u636e\u5e93\u670d\u52a1\u5668\u65f6\uff0cPostgreSQL \u4f1a\u5c1d\u8bd5\u533f\u540d\u7ed1\u5b9a\u5230 LDAP \u670d\u52a1\u5668\uff08\u56e0\u4e3a\u6ca1\u6709\u6307\u5b9a <code class=\"literal\">ldapbinddn</code>\uff09\uff0c\u5e76\u5728\u6307\u5b9a\u7684\u57fa\u7840 DN \u4e0b\u641c\u7d22 <code class=\"literal\">(uid=someuser)</code>\u3002\u5982\u679c\u627e\u5230\u4e86\u6761\u76ee\uff0c\u5c31\u4f1a\u5c1d\u8bd5\u4f7f\u7528\u627e\u5230\u7684\u4fe1\u606f\u548c\u5ba2\u6237\u7aef\u63d0\u4f9b\u7684\u5bc6\u7801\u8fdb\u884c\u7ed1\u5b9a\u3002\u5982\u679c\u7b2c\u4e8c\u6b21\u8fde\u63a5\u6210\u529f\uff0c\u5c31\u4f1a\u6388\u4e88\u6570\u636e\u5e93\u8bbf\u95ee\u6743\u9650\u3002</p>\n<p lang=\"zh\">\u4e0b\u9762\u662f\u4ee5 URL \u5f62\u5f0f\u5199\u51fa\u7684\u540c\u4e00\u4e2a\u641c\u7d22+\u7ed1\u5b9a\u914d\u7f6e\uff1a</p>\n<pre class=\"programlisting\">host ... ldap ldapurl=\"ldap://ldap.example.net/dc=example,dc=net?uid?sub\"\n</pre>\n<p lang=\"zh\">\u67d0\u4e9b\u652f\u6301 LDAP \u8ba4\u8bc1\u7684\u5176\u4ed6\u8f6f\u4ef6\u4e5f\u4f7f\u7528\u76f8\u540c\u7684 URL \u683c\u5f0f\uff0c\u56e0\u6b64\u5171\u4eab\u8fd9\u7c7b\u914d\u7f6e\u4f1a\u66f4\u5bb9\u6613\u3002</p>\n<p lang=\"zh\">\u8fd9\u91cc\u662f\u4e00\u4e2a\u641c\u7d22+\u7ed1\u5b9a\u914d\u7f6e\u7684\u793a\u4f8b\uff0c\u5b83\u4f7f\u7528 <code class=\"literal\">ldapsearchfilter</code> \u800c\u4e0d\u662f <code class=\"literal\">ldapsearchattribute</code> \u6765\u5141\u8bb8\u7528\u7528\u6237 ID \u6216\u7535\u5b50\u90ae\u4ef6\u5730\u5740\u8fdb\u884c\u8ba4\u8bc1\uff1a</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapbasedn=\"dc=example, dc=net\" ldapsearchfilter=\"(|(uid=$username)(mail=$username))\"\n</pre>\n<p lang=\"zh\">\u8fd9\u662f\u4e00\u4e2a\u641c\u7d22+\u7ed1\u5b9a\u914d\u7f6e\u7684\u793a\u4f8b\uff0c\u5b83\u4f7f\u7528 DNS SRV \u53d1\u73b0\u6765\u67e5\u627e\u57df\u540d <code class=\"literal\">example.net</code> \u7684 LDAP \u670d\u52a1\u7684\u4e3b\u673a\u540d\u548c\u7aef\u53e3\u3002</p>\n<pre class=\"programlisting\">host ... ldap ldapbasedn=\"dc=example,dc=net\"\n</pre>\n<div class=\"tip\">\n<h3 class=\"title\" lang=\"zh\">\u63d0\u793a</h3>\n<p lang=\"zh\">\u5982\u793a\u4f8b\u4e2d\u6240\u793a\uff0c\u7531\u4e8e LDAP \u901a\u5e38\u4f7f\u7528\u9017\u53f7\u548c\u7a7a\u683c\u6765\u5206\u9694\u4e00\u4e2a DN \u7684\u4e0d\u540c\u90e8\u5206\uff0c\u5728\u914d\u7f6e LDAP \u9009\u9879\u65f6\u901a\u5e38\u6709\u5fc5\u8981\u4f7f\u7528\u53cc\u5f15\u53f7\u5305\u56f4\u7684\u53c2\u6570\u503c\u3002</p>\n</div>\n</div>", "manual_path": "/docs/16/auth-ldap.html", "localization": {"status": "complete", "sources": [{"url": "/docs/16/auth-ldap.html", "method": "same-major semantic node", "sha256": "fee5f923817f48252d31b99047b4ded6e818d16da9a4573e8d5c2d8b2d4022e3", "language": "zh", "matched_nodes": ["#AUTH-LDAP/div[0]", "#AUTH-LDAP/div[11]/dl[0]/dd[11]/p[0]", "#AUTH-LDAP/div[11]/dl[0]/dd[11]/p[2]", "#AUTH-LDAP/div[11]/dl[0]/dd[11]/p[4]", "#AUTH-LDAP/div[11]/dl[0]/dd[11]/p[5]", "#AUTH-LDAP/div[11]/dl[0]/dd[1]", "#AUTH-LDAP/div[11]/dl[0]/dd[3]", "#AUTH-LDAP/div[11]/dl[0]/dd[5]", "#AUTH-LDAP/div[11]/dl[0]/dd[7]", "#AUTH-LDAP/div[11]/dl[0]/dd[9]", "#AUTH-LDAP/div[28]/h3[0]", "#AUTH-LDAP/div[28]/p[1]", "#AUTH-LDAP/div[6]/dl[0]/dd[1]", "#AUTH-LDAP/div[6]/dl[0]/dd[3]", "#AUTH-LDAP/div[6]/dl[0]/dd[5]", "#AUTH-LDAP/div[9]/dl[0]/dd[1]", "#AUTH-LDAP/div[9]/dl[0]/dd[3]", "#AUTH-LDAP/p[10]", "#AUTH-LDAP/p[12]", "#AUTH-LDAP/p[13]", "#AUTH-LDAP/p[14]", "#AUTH-LDAP/p[15]", "#AUTH-LDAP/p[17]", "#AUTH-LDAP/p[18]", "#AUTH-LDAP/p[20]", "#AUTH-LDAP/p[21]", "#AUTH-LDAP/p[23]", "#AUTH-LDAP/p[24]", "#AUTH-LDAP/p[26]", "#AUTH-LDAP/p[2]", "#AUTH-LDAP/p[3]", "#AUTH-LDAP/p[4]", "#AUTH-LDAP/p[5]", "#AUTH-LDAP/p[7]", "#AUTH-LDAP/p[8]"]}], "language": "zh", "original_text": {"/versions/16/description/0": "Authenticate using an LDAP server. See Section 21.10 for details.", "/versions/16/facts/0/label": "Method", "/versions/16/facts/1/label": "Configuration", "/versions/16/facts/2/label": "Inventory", "/versions/16/facts/2/value": "User-visible source authentication method", "/versions/16/tables/0/title": "Documented method options and alternatives", "/versions/16/tables/0/columns/0/label": "Option or term", "/versions/16/tables/0/columns/1/label": "Meaning", "/versions/16/tables/0/rows/0/description": "Names or IP addresses of LDAP servers to connect to. Multiple servers may be specified, separated by spaces.", "/versions/16/tables/0/rows/1/description": "Port number on LDAP server to connect to. If no port is specified, the LDAP library's default port setting will be used.", "/versions/16/tables/0/rows/2/description": "Set to ldaps to use LDAPS. This is a non-standard way of using LDAP over SSL, supported by some LDAP server implementations. See also the ldaptls option for an alternative.", "/versions/16/tables/0/rows/3/description": "Set to 1 to make the connection between PostgreSQL and the LDAP server use TLS encryption. This uses the StartTLS operation per RFC 4513 . See also the ldapscheme option for an alternative.", "/versions/16/tables/0/rows/4/description": "String to prepend to the user name when forming the DN to bind as, when doing simple bind authentication.", "/versions/16/tables/0/rows/5/description": "String to append to the user name when forming the DN to bind as, when doing simple bind authentication.", "/versions/16/tables/0/rows/6/description": "Root DN to begin the search for the user in, when doing search+bind authentication.", "/versions/16/tables/0/rows/7/description": "DN of user to bind to the directory with to perform the search when doing search+bind authentication.", "/versions/16/tables/0/rows/8/description": "Password for user to bind to the directory with to perform the search when doing search+bind authentication.", "/versions/16/tables/0/rows/9/description": "Attribute to match against the user name in the search when doing search+bind authentication. If no attribute is specified, the uid attribute will be used.", "/versions/16/tables/0/rows/10/description": "The search filter to use when doing search+bind authentication. Occurrences of $username will be replaced with the user name. This allows for more flexible search filters than ldapsearchattribute .", "/versions/16/tables/0/rows/11/description": "An RFC 4516 LDAP URL. This is an alternative way to write some of the other LDAP options in a more compact and standard form. The format is ldap[s]:// host [: port ]/ basedn [?[ attribute ][?[ scope ][?[ filter ]]]] scope must be one of base , one , sub , typically the last. (The default is base , which is normally not useful in this application.) attribute can nominate a single attribute, in which case it is used as a value for ldapsearchattribute . If attribute is empty then filter can be used as a value for ldapsearchfilter . The URL scheme ldaps chooses the LDAPS method for making LDAP connections over SSL, equivalent to using ldapscheme=ldaps . To use encrypted LDAP connections using the StartTLS operation, use the normal URL scheme ldap and specify the ldaptls option in addition to ldapurl . For non-anonymous binds, ldapbinddn and ldapbindpasswd must be specified as separate options. LDAP URLs are currently only supported with OpenLDAP , not on Windows."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "56e068ba1f0d16582d393e22f5861a42d647e1d0ab08715f2e4f1cb2c57f3989"}, "comparison_data": {"method": "ldap", "documented_option_names": ["ldapbasedn", "ldapbinddn", "ldapbindpasswd", "ldapport", "ldapprefix", "ldapscheme", "ldapsearchattribute", "ldapsearchfilter", "ldapserver", "ldapsuffix", "ldaptls", "ldapurl"]}, "comparison_hash": "d40de945ae67b3ac60a284fdd442cc24a4e9d05bc7a7b18009b54e491c381b88", "manual_language": "zh"}, "17": {"facts": [{"label": "\u65b9\u6cd5", "value": "ldap"}, {"label": "\u914d\u7f6e", "value": "pg_hba.conf"}, {"label": "\u6e05\u5355", "value": "\u7528\u6237\u53ef\u89c1\u7684\u6e90\u7801\u8ba4\u8bc1\u65b9\u6cd5"}], "tables": [{"key": "method-options", "rows": [{"name": "ldapserver", "description": "\u8981\u8fde\u63a5\u7684LDAP\u670d\u52a1\u5668\u7684\u540d\u79f0\u6216IP\u5730\u5740\u3002\u53ef\u4ee5\u6307\u5b9a\u591a\u4e2a\u670d\u52a1\u5668\uff0c\u7528\u7a7a\u683c\u5206\u9694\u3002"}, {"name": "ldapport", "description": "\u8981\u8fde\u63a5\u7684LDAP\u670d\u52a1\u5668\u7684\u7aef\u53e3\u53f7\u3002\u5982\u679c\u672a\u6307\u5b9a\u7aef\u53e3\uff0c\u5219\u5c06\u4f7f\u7528LDAP\u5e93\u7684\u9ed8\u8ba4\u7aef\u53e3\u8bbe\u7f6e\u3002"}, {"name": "ldapscheme", "description": "\u8bbe\u7f6e\u4e3a ldaps \u4ee5\u4f7f\u7528LDAPS\u3002\u8fd9\u662f\u4e00\u79cd\u975e\u6807\u51c6\u7684\u901a\u8fc7 SSL \u4f7f\u7528 LDAP \u7684\u65b9\u5f0f\uff0c\u53d7\u4e00\u4e9bLDAP\u670d\u52a1\u5668\u5b9e\u73b0\u652f\u6301\u3002\u53e6\u8bf7\u53c2\u9605 ldaptls \u9009\u9879\u4f5c\u4e3a\u66ff\u4ee3\u3002"}, {"name": "ldaptls", "description": "\u8bbe\u7f6e\u4e3a 1 \u65f6\uff0cPostgreSQL \u4e0e LDAP \u670d\u52a1\u5668\u4e4b\u95f4\u7684\u8fde\u63a5\u4f7f\u7528 TLS \u52a0\u5bc6\uff0c\u901a\u8fc7 RFC 4513 \u89c4\u5b9a\u7684 StartTLS \u64cd\u4f5c\u5b9e\u73b0\u3002\u53e6\u53ef\u53c2\u89c1 ldapscheme \u9009\u9879\u6240\u63d0\u4f9b\u7684\u66ff\u4ee3\u65b9\u5f0f\u3002"}, {"name": "ldapprefix", "description": "\u5728\u8fdb\u884c\u7b80\u5355\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u9644\u52a0\u5230\u7528\u6237\u540d\u524d\u9762\u4ee5\u5f62\u6210\u7ed1\u5b9a DN \u7684\u5b57\u7b26\u4e32\u3002"}, {"name": "ldapsuffix", "description": "\u5728\u8fdb\u884c\u7b80\u5355\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u9644\u52a0\u5230\u7528\u6237\u540d\u540e\u9762\u4ee5\u5f62\u6210\u7ed1\u5b9a DN \u7684\u5b57\u7b26\u4e32\u3002"}, {"name": "ldapbasedn", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4f5c\u7528\u6237\u641c\u7d22\u8d77\u70b9\u7684\u6839 DN\u3002"}, {"name": "ldapbinddn", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u7ed1\u5b9a\u5230\u76ee\u5f55\u5e76\u6267\u884c\u641c\u7d22\u7684\u7528\u6237 DN\u3002"}, {"name": "ldapbindpasswd", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u7ed1\u5b9a\u5230\u76ee\u5f55\u5e76\u6267\u884c\u641c\u7d22\u7684\u7528\u6237\u5bc6\u7801\u3002"}, {"name": "ldapsearchattribute", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u4e0e\u7528\u6237\u540d\u5339\u914d\u7684\u5c5e\u6027\u3002\u5982\u679c\u672a\u6307\u5b9a\u5c5e\u6027\uff0c\u5219\u4f1a\u4f7f\u7528 uid \u5c5e\u6027\u3002"}, {"name": "ldapsearchfilter", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\u4f7f\u7528\u7684\u641c\u7d22\u8fc7\u6ee4\u5668\u3002\u5176\u4e2d\u51fa\u73b0\u7684 $username \u4f1a\u88ab\u66ff\u6362\u4e3a\u7528\u6237\u540d\u3002\u8fd9\u4f7f\u5f97\u641c\u7d22\u8fc7\u6ee4\u5668\u6bd4 ldapsearchattribute \u66f4\u7075\u6d3b\u3002"}, {"name": "ldapurl", "description": "\u7b26\u5408 RFC 4516 \u7684 LDAP URL\u3002\u5b83\u4ee5\u66f4\u7d27\u51d1\u3001\u6807\u51c6\u7684\u5f62\u5f0f\u66ff\u4ee3\u90e8\u5206\u5176\u4ed6 LDAP \u9009\u9879\u3002\u683c\u5f0f\u4e3a ldap[s]://host[:port]/basedn[?[attribute][?[scope][?[filter]]]]\u3002scope \u5fc5\u987b\u4e3a base\u3001one \u6216 sub\uff0c\u901a\u5e38\u4f7f\u7528 sub\uff1b\u9ed8\u8ba4\u503c base \u5728\u6b64\u7528\u9014\u4e0b\u4e00\u822c\u6ca1\u6709\u5b9e\u9645\u5e2e\u52a9\u3002attribute \u53ef\u6307\u5b9a\u4e00\u4e2a\u5c5e\u6027\uff0c\u4f5c\u4e3a ldapsearchattribute \u7684\u503c\uff1battribute \u4e3a\u7a7a\u65f6\uff0cfilter \u53ef\u7528\u4f5c ldapsearchfilter \u7684\u503c\u3002URL \u65b9\u6848 ldaps \u8868\u793a\u901a\u8fc7 SSL \u5efa\u7acb LDAP \u8fde\u63a5\uff0c\u7b49\u540c\u4e8e ldapscheme=ldaps\u3002\u82e5\u8981\u901a\u8fc7 StartTLS \u4f7f\u7528\u52a0\u5bc6 LDAP \u8fde\u63a5\uff0c\u5e94\u4f7f\u7528\u666e\u901a\u7684 ldap URL \u65b9\u6848\uff0c\u5e76\u5728 ldapurl \u4e4b\u5916\u6307\u5b9a ldaptls\u3002\u5bf9\u4e8e\u975e\u533f\u540d\u7ed1\u5b9a\uff0c\u5fc5\u987b\u53e6\u884c\u6307\u5b9a ldapbinddn \u548c ldapbindpasswd\u3002LDAP URL \u76ee\u524d\u4ec5\u5728 OpenLDAP \u4e2d\u53d7\u652f\u6301\uff0cWindows \u4e0d\u652f\u6301\u3002"}], "title": "\u624b\u518c\u4e2d\u7684\u65b9\u6cd5\u9009\u9879\u4e0e\u66ff\u4ee3\u65b9\u5f0f", "columns": [{"key": "name", "label": "\u9009\u9879\u6216\u672f\u8bed"}, {"key": "description", "label": "\u542b\u4e49"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v17.11/postgresql-17.11.tar.bz2", "label": "17.11", "major": "17", "channel": "stable", "revision": "dd27f2b3c59e73ed14aa3324901242bf69a032a6347805f274e6260322d42979", "source_sha256": "dd27f2b3c59e73ed14aa3324901242bf69a032a6347805f274e6260322d42979", "catalog_fingerprint": "4bbe3ac77becd618478f66aec420a533e9017be356c5c1d51a4b17f0fd497c07"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v17.11/postgresql-17.11.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "dd27f2b3c59e73ed14aa3324901242bf69a032a6347805f274e6260322d42979"}, {"url": "https://pg.center/docs/17/auth-ldap.html", "path": "auth-ldap.html", "label": "PostgreSQL 17 English manual", "sha256": "1d4c4c0be025c634cba458a751de54b97831a71c8380adc23d7c02c75c855a59", "language": "en", "original_url": "/docs/17/auth-ldap.html"}, {"url": "https://pg.center/docs/17/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 17 English manual", "sha256": "00c7a7c25d46aa1b2f24cd744cd4990ca4218cfafed2a4cab8c1dc1092090bba", "language": "en", "original_url": "/docs/17/auth-pg-hba-conf.html"}], "sections": [], "signature": "", "attributes": {"method": "ldap", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["\u4f7f\u7528 LDAP \u670d\u52a1\u5668\u8fdb\u884c\u8ba4\u8bc1\u3002\u8be6\u60c5\u53c2\u89c1\u7b2c 20.10 \u8282\u3002"], "manual_html": "<div class=\"sect1\" id=\"AUTH-LDAP\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\" lang=\"zh\">\n<div>\n<div>\n<h2 class=\"title\" style=\"clear: both\">20.10.\u00a0LDAP \u8ba4\u8bc1 </h2>\n</div>\n</div>\n</h2>\n</div>\n</div>\n</div>\n<p lang=\"zh\">\u8fd9\u79cd\u8ba4\u8bc1\u65b9\u6cd5\u7684\u5de5\u4f5c\u65b9\u5f0f\u4e0e <code class=\"literal\">password</code> \u7c7b\u4f3c\uff0c\u53ea\u4e0d\u8fc7\u5b83\u4f7f\u7528 LDAP \u4f5c\u4e3a\u5bc6\u7801\u9a8c\u8bc1\u65b9\u6cd5\u3002LDAP \u53ea\u7528\u4e8e\u9a8c\u8bc1\u7528\u6237\u540d/\u5bc6\u7801\u5bf9\u3002\u56e0\u6b64\uff0c\u5728\u4f7f\u7528 LDAP \u8fdb\u884c\u8ba4\u8bc1\u4e4b\u524d\uff0c\u7528\u6237\u5fc5\u987b\u5df2\u7ecf\u5b58\u5728\u4e8e\u6570\u636e\u5e93\u4e2d\u3002</p>\n<p lang=\"zh\">LDAP \u8ba4\u8bc1\u53ef\u4ee5\u5728\u4e24\u79cd\u6a21\u5f0f\u4e0b\u5de5\u4f5c\u3002\u7b2c\u4e00\u79cd\u6a21\u5f0f\u79f0\u4e3a\u7b80\u5355\u7ed1\u5b9a\u6a21\u5f0f\uff0c\u670d\u52a1\u5668\u4f1a\u7ed1\u5b9a\u5230\u6309 <em class=\"replaceable\"><code>prefix</code></em> <em class=\"replaceable\"><code>username</code></em> <em class=\"replaceable\"><code>suffix</code></em> \u5f62\u5f0f\u6784\u9020\u51fa\u7684\u53ef\u5206\u8fa8\u540d\u79f0\u3002\u901a\u5e38\uff0c<em class=\"replaceable\"><code>prefix</code></em> \u53c2\u6570\u7528\u4e8e\u6307\u5b9a <code class=\"literal\">cn=</code>\uff0c\u6216\u5728 Active Directory \u73af\u5883\u4e2d\u6307\u5b9a <em class=\"replaceable\"><code>DOMAIN</code></em><code class=\"literal\">\\</code>\u3002<em class=\"replaceable\"><code>suffix</code></em> \u5219\u7528\u4e8e\u6307\u5b9a\u975e Active Directory \u73af\u5883\u4e2d DN \u7684\u5269\u4f59\u90e8\u5206\u3002</p>\n<p lang=\"zh\">\u7b2c\u4e8c\u79cd\u6a21\u5f0f\u79f0\u4e3a\u641c\u7d22+\u7ed1\u5b9a\u6a21\u5f0f\uff0c\u670d\u52a1\u5668\u9996\u5148\u4f7f\u7528\u7531 <em class=\"replaceable\"><code>ldapbinddn</code></em> \u548c <em class=\"replaceable\"><code>ldapbindpasswd</code></em> \u6307\u5b9a\u7684\u56fa\u5b9a\u7528\u6237\u540d\u548c\u5bc6\u7801\u7ed1\u5b9a\u5230 LDAP \u76ee\u5f55\uff0c\u5e76\u641c\u7d22\u8bd5\u56fe\u767b\u5f55\u6570\u636e\u5e93\u7684\u7528\u6237\u3002\u5982\u679c\u6ca1\u6709\u914d\u7f6e\u7528\u6237\u540d\u548c\u5bc6\u7801\uff0c\u5219\u4f1a\u5c1d\u8bd5\u5bf9\u76ee\u5f55\u8fdb\u884c\u533f\u540d\u7ed1\u5b9a\u3002\u641c\u7d22\u4f1a\u5728 <em class=\"replaceable\"><code>ldapbasedn</code></em> \u6307\u5b9a\u7684\u5b50\u6811\u4e0a\u8fdb\u884c\uff0c\u5e76\u5c1d\u8bd5\u5bf9 <em class=\"replaceable\"><code>ldapsearchattribute</code></em> \u6307\u5b9a\u7684\u5c5e\u6027\u505a\u7cbe\u786e\u5339\u914d\u3002\u4e00\u65e6\u5728\u641c\u7d22\u4e2d\u627e\u5230\u4e86\u8be5\u7528\u6237\uff0c\u670d\u52a1\u5668\u5c31\u4f1a\u4f5c\u4e3a\u8be5\u7528\u6237\u91cd\u65b0\u7ed1\u5b9a\u5230\u76ee\u5f55\uff0c\u5e76\u4f7f\u7528\u5ba2\u6237\u7aef\u6307\u5b9a\u7684\u5bc6\u7801\u6765\u9a8c\u8bc1\u767b\u5f55\u662f\u5426\u6b63\u786e\u3002\u8fd9\u79cd\u6a21\u5f0f\u4e0e Apache <code class=\"literal\">mod_authnz_ldap</code> \u548c <code class=\"literal\">pam_ldap</code> \u7b49\u8f6f\u4ef6\u4e2d\u7684 LDAP \u8ba4\u8bc1\u65b9\u6848\u76f8\u540c\u3002\u8fd9\u79cd\u65b9\u6cd5\u4f7f\u76ee\u5f55\u4e2d\u7528\u6237\u5bf9\u8c61\u7684\u4f4d\u7f6e\u66f4\u5177\u7075\u6d3b\u6027\uff0c\u4f46\u4f1a\u5bf9 LDAP \u670d\u52a1\u5668\u989d\u5916\u53d1\u8d77\u4e24\u6b21\u8bf7\u6c42\u3002</p>\n<p lang=\"zh\">\u4ee5\u4e0b\u914d\u7f6e\u9009\u9879\u5728\u4e24\u79cd\u6a21\u5f0f\u4e0b\u90fd\u4f7f\u7528\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapserver</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8981\u8fde\u63a5\u7684LDAP\u670d\u52a1\u5668\u7684\u540d\u79f0\u6216IP\u5730\u5740\u3002\u53ef\u4ee5\u6307\u5b9a\u591a\u4e2a\u670d\u52a1\u5668\uff0c\u7528\u7a7a\u683c\u5206\u9694\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapport</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8981\u8fde\u63a5\u7684LDAP\u670d\u52a1\u5668\u7684\u7aef\u53e3\u53f7\u3002\u5982\u679c\u672a\u6307\u5b9a\u7aef\u53e3\uff0c\u5219\u5c06\u4f7f\u7528LDAP\u5e93\u7684\u9ed8\u8ba4\u7aef\u53e3\u8bbe\u7f6e\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapscheme</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8bbe\u7f6e\u4e3a<code class=\"literal\">ldaps</code>\u4ee5\u4f7f\u7528LDAPS\u3002\u8fd9\u662f\u4e00\u79cd\u975e\u6807\u51c6\u7684\u901a\u8fc7 SSL \u4f7f\u7528 LDAP \u7684\u65b9\u5f0f\uff0c\u53d7\u4e00\u4e9bLDAP\u670d\u52a1\u5668\u5b9e\u73b0\u652f\u6301\u3002\u53e6\u8bf7\u53c2\u9605<code class=\"literal\">ldaptls</code> \u9009\u9879\u4f5c\u4e3a\u66ff\u4ee3\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldaptls</code></span></dt>\n<dd>\n<p lang=\"zh\">\u8bbe\u7f6e\u4e3a 1 \u65f6\uff0cPostgreSQL \u4e0e LDAP \u670d\u52a1\u5668\u4e4b\u95f4\u7684\u8fde\u63a5\u4f7f\u7528 TLS \u52a0\u5bc6\uff0c\u901a\u8fc7 RFC 4513 \u89c4\u5b9a\u7684 StartTLS \u64cd\u4f5c\u5b9e\u73b0\u3002\u53e6\u53ef\u53c2\u89c1 ldapscheme \u9009\u9879\u6240\u63d0\u4f9b\u7684\u66ff\u4ee3\u65b9\u5f0f\u3002</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u6ce8\u610f\u4f7f\u7528<code class=\"literal\">ldapscheme</code>\u6216<code class=\"literal\">ldaptls</code>\u4ec5\u4f1a\u52a0\u5bc6PostgreSQL \u670d\u52a1\u5668\u548cLDAP\u670d\u52a1\u5668\u4e4b\u95f4\u7684\u901a\u4fe1\u3002PostgreSQL \u670d\u52a1\u5668\u548cPostgreSQL\u5ba2\u6237\u7aef\u4e4b\u95f4\u7684\u8fde\u63a5\u4ecd\u662f\u672a\u52a0\u5bc6\u7684\uff0c\u9664\u975e\u4e5f\u5728\u5176\u4e0a\u4f7f\u7528SSL\u3002</p>\n<p lang=\"zh\">\u4e0b\u5217\u9009\u9879\u53ea\u88ab\u7528\u4e8e\u7b80\u5355\u7ed1\u5b9a\u6a21\u5f0f\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapprefix</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u7b80\u5355\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u9644\u52a0\u5230\u7528\u6237\u540d\u524d\u9762\u4ee5\u5f62\u6210\u7ed1\u5b9a DN \u7684\u5b57\u7b26\u4e32\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsuffix</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u7b80\u5355\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u9644\u52a0\u5230\u7528\u6237\u540d\u540e\u9762\u4ee5\u5f62\u6210\u7ed1\u5b9a DN \u7684\u5b57\u7b26\u4e32\u3002</p>\n</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u4ee5\u4e0b\u9009\u9879\u4ec5\u5728\u641c\u7d22+\u7ed1\u5b9a\u6a21\u5f0f\u4e2d\u4f7f\u7528\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapbasedn</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4f5c\u7528\u6237\u641c\u7d22\u8d77\u70b9\u7684\u6839 DN\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapbinddn</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u7ed1\u5b9a\u5230\u76ee\u5f55\u5e76\u6267\u884c\u641c\u7d22\u7684\u7528\u6237 DN\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapbindpasswd</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u7ed1\u5b9a\u5230\u76ee\u5f55\u5e76\u6267\u884c\u641c\u7d22\u7684\u7528\u6237\u5bc6\u7801\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsearchattribute</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u4e0e\u7528\u6237\u540d\u5339\u914d\u7684\u5c5e\u6027\u3002\u5982\u679c\u672a\u6307\u5b9a\u5c5e\u6027\uff0c\u5219\u4f1a\u4f7f\u7528 <code class=\"literal\">uid</code> \u5c5e\u6027\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsearchfilter</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\u4f7f\u7528\u7684\u641c\u7d22\u8fc7\u6ee4\u5668\u3002\u5176\u4e2d\u51fa\u73b0\u7684 <code class=\"literal\">$username</code> \u4f1a\u88ab\u66ff\u6362\u4e3a\u7528\u6237\u540d\u3002\u8fd9\u4f7f\u5f97\u641c\u7d22\u8fc7\u6ee4\u5668\u6bd4 <code class=\"literal\">ldapsearchattribute</code> \u66f4\u7075\u6d3b\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapurl</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4e00\u4e2a<a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc4516\" target=\"_top\">RFC 4516</a> LDAP URL\u3002\u8fd9\u662f\u4ee5\u66f4\u7d27\u51d1\u548c\u6807\u51c6\u5f62\u5f0f\u7f16\u5199\u90e8\u5206\u5176\u4ed6 LDAP \u9009\u9879\u7684\u66ff\u4ee3\u65b9\u5f0f\u3002\u683c\u5f0f\u4e3a</p>\n<pre class=\"synopsis\">ldap[s]://<em class=\"replaceable\"><code>host</code></em>[:<em class=\"replaceable\"><code>port</code></em>]/<em class=\"replaceable\"><code>basedn</code></em>[?[<em class=\"replaceable\"><code>attribute</code></em>][?[<em class=\"replaceable\"><code>scope</code></em>][?[<em class=\"replaceable\"><code>filter</code></em>]]]]\n</pre>\n<p lang=\"zh\"><em class=\"replaceable\"><code>scope</code></em>\u5fc5\u987b\u662f<code class=\"literal\">base</code>\u3001<code class=\"literal\">one</code>\u3001<code class=\"literal\">sub</code>\u4e2d\u7684\u4e00\u4e2a\uff0c\u901a\u5e38\u662f\u6700\u540e\u4e00\u4e2a\u3002\uff08\u9ed8\u8ba4\u4e3a<code class=\"literal\">base</code>\uff0c\u5728\u6b64\u5e94\u7528\u4e2d\u901a\u5e38\u65e0\u7528\u3002\uff09<em class=\"replaceable\"><code>attribute</code></em>\u53ef\u4ee5\u6307\u5b9a\u5355\u4e2a\u5c5e\u6027\uff0c\u6b64\u65f6\u5c06\u7528\u4f5c<code class=\"literal\">ldapsearchattribute</code>\u7684\u503c\u3002\u5982\u679c<em class=\"replaceable\"><code>attribute</code></em>\u4e3a\u7a7a\uff0c\u5219<em class=\"replaceable\"><code>filter</code></em>\u53ef\u7528\u4f5c<code class=\"literal\">ldapsearchfilter</code>\u7684\u503c\u3002</p>\n<p lang=\"zh\">URL \u65b9\u6848 ldaps \u9009\u62e9\u901a\u8fc7 SSL \u5efa\u7acb LDAP \u8fde\u63a5\u7684 LDAPS \u65b9\u5f0f\uff0c\u7b49\u4ef7\u4e8e ldapscheme=ldaps\u3002\u8981\u901a\u8fc7 StartTLS \u4f7f\u7528\u52a0\u5bc6 LDAP \u8fde\u63a5\uff0c\u5e94\u4f7f\u7528\u666e\u901a\u7684 ldap URL \u65b9\u6848\uff0c\u5e76\u5728 ldapurl \u4e4b\u5916\u6307\u5b9a ldaptls\u3002</p>\n<p lang=\"zh\">\u5bf9\u4e8e\u975e\u533f\u540d\u7ed1\u5b9a\uff0c\u5fc5\u987b\u5c06<code class=\"literal\">ldapbinddn</code>\u548c<code class=\"literal\">ldapbindpasswd</code>\u6307\u5b9a\u4e3a\u5355\u72ec\u7684\u9009\u9879\u3002</p>\n<p lang=\"zh\">LDAP URL\u76ee\u524d\u4ec5\u53d7<span class=\"productname\">OpenLDAP</span>\u652f\u6301\uff0c\u4e0d\u652f\u6301Windows\u3002</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u5c06\u7b80\u5355\u7ed1\u5b9a\u6a21\u5f0f\u7684\u914d\u7f6e\u9009\u9879\u4e0e\u641c\u7d22+\u7ed1\u5b9a\u6a21\u5f0f\u7684\u914d\u7f6e\u9009\u9879\u6df7\u7528\u662f\u9519\u8bef\u7684\u3002</p>\n<p lang=\"zh\">\u5728\u4f7f\u7528\u641c\u7d22+\u7ed1\u5b9a\u6a21\u5f0f\u65f6\uff0c\u53ef\u4ee5\u4f7f\u7528\u7531 <code class=\"literal\">ldapsearchattribute</code> \u6307\u5b9a\u7684\u5355\u4e2a\u5c5e\u6027\u6267\u884c\u641c\u7d22\uff0c\u4e5f\u53ef\u4ee5\u4f7f\u7528\u7531 <code class=\"literal\">ldapsearchfilter</code> \u6307\u5b9a\u7684\u81ea\u5b9a\u4e49\u641c\u7d22\u8fc7\u6ee4\u5668\u6267\u884c\u641c\u7d22\u3002\u6307\u5b9a <code class=\"literal\">ldapsearchattribute=foo</code> \u7b49\u4ef7\u4e8e\u6307\u5b9a <code class=\"literal\">ldapsearchfilter=\"(foo=$username)\"</code>\u3002\u5982\u679c\u4e24\u4e2a\u9009\u9879\u90fd\u672a\u6307\u5b9a\uff0c\u5219\u9ed8\u8ba4\u4f7f\u7528 <code class=\"literal\">ldapsearchattribute=uid</code>\u3002</p>\n<p lang=\"zh\">\u5982\u679c <span class=\"productname\">PostgreSQL</span> \u7f16\u8bd1\u65f6\u4f7f\u7528\u4e86 <span class=\"productname\">OpenLDAP</span> \u4f5c\u4e3a LDAP \u5ba2\u6237\u7aef\u5e93\uff0c\u5219\u53ef\u4ee5\u7701\u7565 <code class=\"literal\">ldapserver</code> \u8bbe\u7f6e\u3002\u5728\u8fd9\u79cd\u60c5\u51b5\u4e0b\uff0c\u4f1a\u901a\u8fc7 <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc2782\" target=\"_top\">RFC 2782</a> DNS SRV \u8bb0\u5f55\u67e5\u627e\u4e3b\u673a\u540d\u548c\u7aef\u53e3\u5217\u8868\u3002\u67e5\u627e\u7684\u540d\u79f0\u662f <code class=\"literal\">_ldap._tcp.DOMAIN</code>\uff0c\u5176\u4e2d <code class=\"literal\">DOMAIN</code> \u4ece <code class=\"literal\">ldapbasedn</code> \u4e2d\u63d0\u53d6\u3002</p>\n<p lang=\"zh\">\u4e0b\u9762\u662f\u4e00\u4e2a\u7b80\u5355\u7ed1\u5b9a LDAP \u914d\u7f6e\u793a\u4f8b\uff1a</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapprefix=\"cn=\" ldapsuffix=\", dc=example, dc=net\"\n</pre>\n<p lang=\"zh\">\u5f53\u8bf7\u6c42\u4ee5\u6570\u636e\u5e93\u7528\u6237 <code class=\"literal\">someuser</code> \u8fde\u63a5\u6570\u636e\u5e93\u670d\u52a1\u5668\u65f6\uff0cPostgreSQL \u5c06\u5c1d\u8bd5\u4f7f\u7528 DN <code class=\"literal\">cn=someuser, dc=example, dc=net</code> \u548c\u5ba2\u6237\u7aef\u63d0\u4f9b\u7684\u5bc6\u7801\u7ed1\u5b9a\u5230 LDAP \u670d\u52a1\u5668\u3002\u5982\u679c\u8be5\u8fde\u63a5\u6210\u529f\uff0c\u6570\u636e\u5e93\u8bbf\u95ee\u5c31\u4f1a\u88ab\u6388\u4e88\u3002</p>\n<p lang=\"zh\">\u4e0b\u9762\u662f\u4e00\u4e2a\u641c\u7d22+\u7ed1\u5b9a\u914d\u7f6e\u793a\u4f8b\uff1a</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapbasedn=\"dc=example, dc=net\" ldapsearchattribute=uid\n</pre>\n<p lang=\"zh\">\u5f53\u8bf7\u6c42\u4ee5\u6570\u636e\u5e93\u7528\u6237 <code class=\"literal\">someuser</code> \u8fde\u63a5\u6570\u636e\u5e93\u670d\u52a1\u5668\u65f6\uff0cPostgreSQL \u5c06\u5c1d\u8bd5\u5bf9 LDAP \u670d\u52a1\u5668\u8fdb\u884c\u533f\u540d\u7ed1\u5b9a\uff08\u56e0\u4e3a\u672a\u6307\u5b9a <code class=\"literal\">ldapbinddn</code>\uff09\uff0c\u5e76\u5728\u6307\u5b9a\u7684\u57fa\u7840 DN \u4e0b\u6267\u884c\u4e00\u6b21 <code class=\"literal\">(uid=someuser)</code> \u641c\u7d22\u3002\u5982\u679c\u627e\u5230\u4e86\u5bf9\u5e94\u6761\u76ee\uff0c\u968f\u540e\u5c31\u4f1a\u5c1d\u8bd5\u4f7f\u7528\u8be5\u6761\u76ee\u7684\u4fe1\u606f\u4ee5\u53ca\u5ba2\u6237\u7aef\u63d0\u4f9b\u7684\u5bc6\u7801\u8fdb\u884c\u7ed1\u5b9a\u3002\u5982\u679c\u7b2c\u4e8c\u6b21\u7ed1\u5b9a\u6210\u529f\uff0c\u6570\u636e\u5e93\u8bbf\u95ee\u5c31\u4f1a\u88ab\u6388\u4e88\u3002</p>\n<p lang=\"zh\">\u4e0b\u9762\u662f\u4ee5 URL \u5f62\u5f0f\u5199\u51fa\u7684\u540c\u4e00\u4e2a\u641c\u7d22+\u7ed1\u5b9a\u914d\u7f6e\uff1a</p>\n<pre class=\"programlisting\">host ... ldap ldapurl=\"ldap://ldap.example.net/dc=example,dc=net?uid?sub\"\n</pre>\n<p lang=\"zh\">\u67d0\u4e9b\u652f\u6301 LDAP \u8ba4\u8bc1\u7684\u5176\u4ed6\u8f6f\u4ef6\u4e5f\u4f7f\u7528\u76f8\u540c\u7684 URL \u683c\u5f0f\uff0c\u56e0\u6b64\u5171\u4eab\u8fd9\u7c7b\u914d\u7f6e\u4f1a\u66f4\u5bb9\u6613\u3002</p>\n<p lang=\"zh\">\u8fd9\u91cc\u662f\u4e00\u4e2a\u641c\u7d22+\u7ed1\u5b9a\u914d\u7f6e\u7684\u793a\u4f8b\uff0c\u5b83\u4f7f\u7528 <code class=\"literal\">ldapsearchfilter</code> \u800c\u4e0d\u662f <code class=\"literal\">ldapsearchattribute</code> \u6765\u5141\u8bb8\u7528\u7528\u6237 ID \u6216\u7535\u5b50\u90ae\u4ef6\u5730\u5740\u8fdb\u884c\u8ba4\u8bc1\uff1a</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapbasedn=\"dc=example, dc=net\" ldapsearchfilter=\"(|(uid=$username)(mail=$username))\"\n</pre>\n<p lang=\"zh\">\u8fd9\u662f\u4e00\u4e2a\u641c\u7d22+\u7ed1\u5b9a\u914d\u7f6e\u7684\u793a\u4f8b\uff0c\u5b83\u4f7f\u7528 DNS SRV \u53d1\u73b0\u6765\u67e5\u627e\u57df\u540d <code class=\"literal\">example.net</code> \u7684 LDAP \u670d\u52a1\u7684\u4e3b\u673a\u540d\u548c\u7aef\u53e3\u3002</p>\n<pre class=\"programlisting\">host ... ldap ldapbasedn=\"dc=example,dc=net\"\n</pre>\n<div class=\"tip\">\n<h3 class=\"title\" lang=\"zh\">\u63d0\u793a</h3>\n<p lang=\"zh\">\u5982\u793a\u4f8b\u4e2d\u6240\u793a\uff0c\u7531\u4e8e LDAP \u901a\u5e38\u4f7f\u7528\u9017\u53f7\u548c\u7a7a\u683c\u6765\u5206\u9694\u4e00\u4e2a DN \u7684\u4e0d\u540c\u90e8\u5206\uff0c\u5728\u914d\u7f6e LDAP \u9009\u9879\u65f6\u901a\u5e38\u6709\u5fc5\u8981\u4f7f\u7528\u53cc\u5f15\u53f7\u5305\u56f4\u7684\u53c2\u6570\u503c\u3002</p>\n</div>\n</div>", "manual_path": "/docs/17/auth-ldap.html", "localization": {"status": "complete", "sources": [{"url": "/docs/17/auth-ldap.html", "method": "same-major semantic node", "sha256": "db1d99195ec0188e3bceecf9327fb85c9f9fa90c83d1d92e84e7203d13d51524", "language": "zh", "matched_nodes": ["#AUTH-LDAP/div[0]", "#AUTH-LDAP/div[11]/dl[0]/dd[11]/p[0]", "#AUTH-LDAP/div[11]/dl[0]/dd[11]/p[2]", "#AUTH-LDAP/div[11]/dl[0]/dd[11]/p[4]", "#AUTH-LDAP/div[11]/dl[0]/dd[11]/p[5]", "#AUTH-LDAP/div[11]/dl[0]/dd[1]", "#AUTH-LDAP/div[11]/dl[0]/dd[3]", "#AUTH-LDAP/div[11]/dl[0]/dd[5]", "#AUTH-LDAP/div[11]/dl[0]/dd[7]", "#AUTH-LDAP/div[11]/dl[0]/dd[9]", "#AUTH-LDAP/div[28]/h3[0]", "#AUTH-LDAP/div[28]/p[1]", "#AUTH-LDAP/div[6]/dl[0]/dd[1]", "#AUTH-LDAP/div[6]/dl[0]/dd[3]", "#AUTH-LDAP/div[6]/dl[0]/dd[5]", "#AUTH-LDAP/div[9]/dl[0]/dd[1]", "#AUTH-LDAP/div[9]/dl[0]/dd[3]", "#AUTH-LDAP/p[10]", "#AUTH-LDAP/p[12]", "#AUTH-LDAP/p[13]", "#AUTH-LDAP/p[14]", "#AUTH-LDAP/p[15]", "#AUTH-LDAP/p[17]", "#AUTH-LDAP/p[18]", "#AUTH-LDAP/p[20]", "#AUTH-LDAP/p[21]", "#AUTH-LDAP/p[23]", "#AUTH-LDAP/p[24]", "#AUTH-LDAP/p[26]", "#AUTH-LDAP/p[2]", "#AUTH-LDAP/p[3]", "#AUTH-LDAP/p[4]", "#AUTH-LDAP/p[5]", "#AUTH-LDAP/p[7]", "#AUTH-LDAP/p[8]"]}], "language": "zh", "original_text": {"/versions/17/description/0": "Authenticate using an LDAP server. See Section 20.10 for details.", "/versions/17/facts/0/label": "Method", "/versions/17/facts/1/label": "Configuration", "/versions/17/facts/2/label": "Inventory", "/versions/17/facts/2/value": "User-visible source authentication method", "/versions/17/tables/0/title": "Documented method options and alternatives", "/versions/17/tables/0/columns/0/label": "Option or term", "/versions/17/tables/0/columns/1/label": "Meaning", "/versions/17/tables/0/rows/0/description": "Names or IP addresses of LDAP servers to connect to. Multiple servers may be specified, separated by spaces.", "/versions/17/tables/0/rows/1/description": "Port number on LDAP server to connect to. If no port is specified, the LDAP library's default port setting will be used.", "/versions/17/tables/0/rows/2/description": "Set to ldaps to use LDAPS. This is a non-standard way of using LDAP over SSL, supported by some LDAP server implementations. See also the ldaptls option for an alternative.", "/versions/17/tables/0/rows/3/description": "Set to 1 to make the connection between PostgreSQL and the LDAP server use TLS encryption. This uses the StartTLS operation per RFC 4513 . See also the ldapscheme option for an alternative.", "/versions/17/tables/0/rows/4/description": "String to prepend to the user name when forming the DN to bind as, when doing simple bind authentication.", "/versions/17/tables/0/rows/5/description": "String to append to the user name when forming the DN to bind as, when doing simple bind authentication.", "/versions/17/tables/0/rows/6/description": "Root DN to begin the search for the user in, when doing search+bind authentication.", "/versions/17/tables/0/rows/7/description": "DN of user to bind to the directory with to perform the search when doing search+bind authentication.", "/versions/17/tables/0/rows/8/description": "Password for user to bind to the directory with to perform the search when doing search+bind authentication.", "/versions/17/tables/0/rows/9/description": "Attribute to match against the user name in the search when doing search+bind authentication. If no attribute is specified, the uid attribute will be used.", "/versions/17/tables/0/rows/10/description": "The search filter to use when doing search+bind authentication. Occurrences of $username will be replaced with the user name. This allows for more flexible search filters than ldapsearchattribute .", "/versions/17/tables/0/rows/11/description": "An RFC 4516 LDAP URL. This is an alternative way to write some of the other LDAP options in a more compact and standard form. The format is ldap[s]:// host [: port ]/ basedn [?[ attribute ][?[ scope ][?[ filter ]]]] scope must be one of base , one , sub , typically the last. (The default is base , which is normally not useful in this application.) attribute can nominate a single attribute, in which case it is used as a value for ldapsearchattribute . If attribute is empty then filter can be used as a value for ldapsearchfilter . The URL scheme ldaps chooses the LDAPS method for making LDAP connections over SSL, equivalent to using ldapscheme=ldaps . To use encrypted LDAP connections using the StartTLS operation, use the normal URL scheme ldap and specify the ldaptls option in addition to ldapurl . For non-anonymous binds, ldapbinddn and ldapbindpasswd must be specified as separate options. LDAP URLs are currently only supported with OpenLDAP , not on Windows."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "b20ff3b368afca52cd32af32887cf0b3e4350309dab936d9365e10521fa6dedc"}, "comparison_data": {"method": "ldap", "documented_option_names": ["ldapbasedn", "ldapbinddn", "ldapbindpasswd", "ldapport", "ldapprefix", "ldapscheme", "ldapsearchattribute", "ldapsearchfilter", "ldapserver", "ldapsuffix", "ldaptls", "ldapurl"]}, "comparison_hash": "d40de945ae67b3ac60a284fdd442cc24a4e9d05bc7a7b18009b54e491c381b88", "manual_language": "zh"}, "18": {"facts": [{"label": "\u65b9\u6cd5", "value": "ldap"}, {"label": "\u914d\u7f6e", "value": "pg_hba.conf"}, {"label": "\u6e05\u5355", "value": "\u7528\u6237\u53ef\u89c1\u7684\u6e90\u7801\u8ba4\u8bc1\u65b9\u6cd5"}], "tables": [{"key": "method-options", "rows": [{"name": "ldapserver", "description": "\u8981\u8fde\u63a5\u7684LDAP\u670d\u52a1\u5668\u7684\u540d\u79f0\u6216IP\u5730\u5740\u3002\u53ef\u4ee5\u6307\u5b9a\u591a\u4e2a\u670d\u52a1\u5668\uff0c\u7528\u7a7a\u683c\u5206\u9694\u3002"}, {"name": "ldapport", "description": "\u8981\u8fde\u63a5\u7684LDAP\u670d\u52a1\u5668\u7684\u7aef\u53e3\u53f7\u3002\u5982\u679c\u672a\u6307\u5b9a\u7aef\u53e3\uff0c\u5219\u5c06\u4f7f\u7528LDAP\u5e93\u7684\u9ed8\u8ba4\u7aef\u53e3\u8bbe\u7f6e\u3002"}, {"name": "ldapscheme", "description": "\u8bbe\u7f6e\u4e3a ldaps \u4ee5\u4f7f\u7528LDAPS\u3002\u8fd9\u662f\u4e00\u79cd\u975e\u6807\u51c6\u7684\u901a\u8fc7 SSL \u4f7f\u7528 LDAP \u7684\u65b9\u5f0f\uff0c\u53d7\u4e00\u4e9bLDAP\u670d\u52a1\u5668\u5b9e\u73b0\u652f\u6301\u3002\u53e6\u8bf7\u53c2\u9605 ldaptls \u9009\u9879\u4f5c\u4e3a\u66ff\u4ee3\u3002"}, {"name": "ldaptls", "description": "\u8bbe\u7f6e\u4e3a 1 \u65f6\uff0cPostgreSQL \u4e0e LDAP \u670d\u52a1\u5668\u4e4b\u95f4\u7684\u8fde\u63a5\u4f7f\u7528 TLS \u52a0\u5bc6\uff0c\u901a\u8fc7 RFC 4513 \u89c4\u5b9a\u7684 StartTLS \u64cd\u4f5c\u5b9e\u73b0\u3002\u53e6\u53ef\u53c2\u89c1 ldapscheme \u9009\u9879\u6240\u63d0\u4f9b\u7684\u66ff\u4ee3\u65b9\u5f0f\u3002"}, {"name": "ldapprefix", "description": "\u5728\u8fdb\u884c\u7b80\u5355\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u9644\u52a0\u5230\u7528\u6237\u540d\u524d\u9762\u4ee5\u5f62\u6210\u7ed1\u5b9a DN \u7684\u5b57\u7b26\u4e32\u3002"}, {"name": "ldapsuffix", "description": "\u5728\u8fdb\u884c\u7b80\u5355\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u9644\u52a0\u5230\u7528\u6237\u540d\u540e\u9762\u4ee5\u5f62\u6210\u7ed1\u5b9a DN \u7684\u5b57\u7b26\u4e32\u3002"}, {"name": "ldapbasedn", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4f5c\u7528\u6237\u641c\u7d22\u8d77\u70b9\u7684\u6839 DN\u3002"}, {"name": "ldapbinddn", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u7ed1\u5b9a\u5230\u76ee\u5f55\u5e76\u6267\u884c\u641c\u7d22\u7684\u7528\u6237 DN\u3002"}, {"name": "ldapbindpasswd", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u7ed1\u5b9a\u5230\u76ee\u5f55\u5e76\u6267\u884c\u641c\u7d22\u7684\u7528\u6237\u5bc6\u7801\u3002"}, {"name": "ldapsearchattribute", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u4e0e\u7528\u6237\u540d\u5339\u914d\u7684\u5c5e\u6027\u3002\u5982\u679c\u672a\u6307\u5b9a\u5c5e\u6027\uff0c\u5219\u4f1a\u4f7f\u7528 uid \u5c5e\u6027\u3002"}, {"name": "ldapsearchfilter", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\u4f7f\u7528\u7684\u641c\u7d22\u8fc7\u6ee4\u5668\u3002\u5176\u4e2d\u51fa\u73b0\u7684 $username \u4f1a\u88ab\u66ff\u6362\u4e3a\u7528\u6237\u540d\u3002\u8fd9\u4f7f\u5f97\u641c\u7d22\u8fc7\u6ee4\u5668\u6bd4 ldapsearchattribute \u66f4\u7075\u6d3b\u3002"}, {"name": "ldapurl", "description": "\u7b26\u5408 RFC 4516 \u7684 LDAP URL\u3002\u683c\u5f0f\u4e3a ldap[s]://host[:port]/basedn[?[attribute][?[scope][?[filter]]]]\u3002scope \u5fc5\u987b\u4e3a base\u3001one \u6216 sub\uff0c\u901a\u5e38\u4f7f\u7528 sub\uff1b\u9ed8\u8ba4\u503c base \u5728\u6b64\u7528\u9014\u4e0b\u4e00\u822c\u6ca1\u6709\u5b9e\u9645\u5e2e\u52a9\u3002attribute \u53ef\u6307\u5b9a\u4e00\u4e2a\u5c5e\u6027\uff0c\u4f5c\u4e3a ldapsearchattribute \u7684\u503c\uff1battribute \u4e3a\u7a7a\u65f6\uff0cfilter \u53ef\u7528\u4f5c ldapsearchfilter \u7684\u503c\u3002URL \u65b9\u6848 ldaps \u8868\u793a\u901a\u8fc7 SSL \u5efa\u7acb LDAP \u8fde\u63a5\uff0c\u7b49\u540c\u4e8e ldapscheme=ldaps\u3002\u82e5\u8981\u901a\u8fc7 StartTLS \u4f7f\u7528\u52a0\u5bc6 LDAP \u8fde\u63a5\uff0c\u5e94\u4f7f\u7528\u666e\u901a\u7684 ldap URL \u65b9\u6848\uff0c\u5e76\u5728 ldapurl \u4e4b\u5916\u6307\u5b9a ldaptls\u3002\u5bf9\u4e8e\u975e\u533f\u540d\u7ed1\u5b9a\uff0c\u5fc5\u987b\u53e6\u884c\u6307\u5b9a ldapbinddn \u548c ldapbindpasswd\u3002LDAP URL \u76ee\u524d\u4ec5\u5728 OpenLDAP \u4e2d\u53d7\u652f\u6301\uff0cWindows \u4e0d\u652f\u6301\u3002"}], "title": "\u624b\u518c\u4e2d\u7684\u65b9\u6cd5\u9009\u9879\u4e0e\u66ff\u4ee3\u65b9\u5f0f", "columns": [{"key": "name", "label": "\u9009\u9879\u6216\u672f\u8bed"}, {"key": "description", "label": "\u542b\u4e49"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "label": "18.6", "major": "18", "channel": "stable", "revision": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f", "source_sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f", "catalog_fingerprint": "65c93d6048ef30e61023a84f9680fa6a92b1c383b7eb226741170077eb078502"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"}, {"url": "https://pg.center/docs/18/auth-ldap.html", "path": "auth-ldap.html", "label": "PostgreSQL 18 English manual", "sha256": "8f02f50758b63b0d9a9011b2c3c1ee12e8caa3830408f5ea5d97e0e81ee52628", "language": "en", "original_url": "/docs/18/auth-ldap.html"}, {"url": "https://pg.center/docs/18/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 18 English manual", "sha256": "6340d4abea2e0a3482afc31bcd1599a0fa10dc28a6f1e05d79ba831e2dd0b4c9", "language": "en", "original_url": "/docs/18/auth-pg-hba-conf.html"}], "sections": [], "signature": "", "attributes": {"method": "ldap", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["\u4f7f\u7528 LDAP \u670d\u52a1\u5668\u8fdb\u884c\u8ba4\u8bc1\u3002\u8be6\u60c5\u53c2\u89c1\u7b2c 20.10 \u8282\u3002"], "manual_html": "<div class=\"sect1\" id=\"AUTH-LDAP\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\" lang=\"zh\">\n<div>\n<div>\n<h2 class=\"title\" style=\"clear: both\">20.10.\u00a0LDAP \u8ba4\u8bc1 </h2>\n</div>\n</div>\n</h2>\n</div>\n</div>\n</div>\n<p lang=\"zh\">\u8fd9\u79cd\u8ba4\u8bc1\u65b9\u6cd5\u7684\u5de5\u4f5c\u65b9\u5f0f\u4e0e <code class=\"literal\">password</code> \u7c7b\u4f3c\uff0c\u53ea\u4e0d\u8fc7\u5b83\u4f7f\u7528 LDAP \u4f5c\u4e3a\u5bc6\u7801\u9a8c\u8bc1\u65b9\u6cd5\u3002LDAP \u53ea\u7528\u4e8e\u9a8c\u8bc1\u7528\u6237\u540d/\u5bc6\u7801\u5bf9\u3002\u56e0\u6b64\uff0c\u5728\u4f7f\u7528 LDAP \u8fdb\u884c\u8ba4\u8bc1\u4e4b\u524d\uff0c\u7528\u6237\u5fc5\u987b\u5df2\u7ecf\u5b58\u5728\u4e8e\u6570\u636e\u5e93\u4e2d\u3002</p>\n<p lang=\"zh\">LDAP \u8ba4\u8bc1\u53ef\u4ee5\u5728\u4e24\u79cd\u6a21\u5f0f\u4e0b\u5de5\u4f5c\u3002\u7b2c\u4e00\u79cd\u6a21\u5f0f\u79f0\u4e3a\u7b80\u5355\u7ed1\u5b9a\u6a21\u5f0f\uff0c\u670d\u52a1\u5668\u4f1a\u7ed1\u5b9a\u5230\u6309 <em class=\"replaceable\"><code>prefix</code></em> <em class=\"replaceable\"><code>username</code></em> <em class=\"replaceable\"><code>suffix</code></em> \u5f62\u5f0f\u6784\u9020\u51fa\u7684\u53ef\u5206\u8fa8\u540d\u79f0\u3002\u901a\u5e38\uff0c<em class=\"replaceable\"><code>prefix</code></em> \u53c2\u6570\u7528\u4e8e\u6307\u5b9a <code class=\"literal\">cn=</code>\uff0c\u6216\u5728 Active Directory \u73af\u5883\u4e2d\u6307\u5b9a <em class=\"replaceable\"><code>DOMAIN</code></em><code class=\"literal\">\\</code>\u3002<em class=\"replaceable\"><code>suffix</code></em> \u5219\u7528\u4e8e\u6307\u5b9a\u975e Active Directory \u73af\u5883\u4e2d DN \u7684\u5269\u4f59\u90e8\u5206\u3002</p>\n<p lang=\"zh\">\u7b2c\u4e8c\u79cd\u6a21\u5f0f\u79f0\u4e3a\u641c\u7d22+\u7ed1\u5b9a\u6a21\u5f0f\uff0c\u670d\u52a1\u5668\u9996\u5148\u4f7f\u7528\u7531 <em class=\"replaceable\"><code>ldapbinddn</code></em> \u548c <em class=\"replaceable\"><code>ldapbindpasswd</code></em> \u6307\u5b9a\u7684\u56fa\u5b9a\u7528\u6237\u540d\u548c\u5bc6\u7801\u7ed1\u5b9a\u5230 LDAP \u76ee\u5f55\uff0c\u5e76\u641c\u7d22\u8bd5\u56fe\u767b\u5f55\u6570\u636e\u5e93\u7684\u7528\u6237\u3002\u5982\u679c\u6ca1\u6709\u914d\u7f6e\u7528\u6237\u540d\u548c\u5bc6\u7801\uff0c\u5219\u4f1a\u5c1d\u8bd5\u5bf9\u76ee\u5f55\u8fdb\u884c\u533f\u540d\u7ed1\u5b9a\u3002\u641c\u7d22\u4f1a\u5728 <em class=\"replaceable\"><code>ldapbasedn</code></em> \u6307\u5b9a\u7684\u5b50\u6811\u4e0a\u8fdb\u884c\uff0c\u5e76\u5c1d\u8bd5\u5bf9 <em class=\"replaceable\"><code>ldapsearchattribute</code></em> \u6307\u5b9a\u7684\u5c5e\u6027\u505a\u7cbe\u786e\u5339\u914d\u3002\u4e00\u65e6\u5728\u641c\u7d22\u4e2d\u627e\u5230\u4e86\u8be5\u7528\u6237\uff0c\u670d\u52a1\u5668\u5c31\u4f1a\u4f5c\u4e3a\u8be5\u7528\u6237\u91cd\u65b0\u7ed1\u5b9a\u5230\u76ee\u5f55\uff0c\u5e76\u4f7f\u7528\u5ba2\u6237\u7aef\u6307\u5b9a\u7684\u5bc6\u7801\u6765\u9a8c\u8bc1\u767b\u5f55\u662f\u5426\u6b63\u786e\u3002\u8fd9\u79cd\u6a21\u5f0f\u4e0e Apache <code class=\"literal\">mod_authnz_ldap</code> \u548c <code class=\"literal\">pam_ldap</code> \u7b49\u8f6f\u4ef6\u4e2d\u7684 LDAP \u8ba4\u8bc1\u65b9\u6848\u76f8\u540c\u3002\u8fd9\u79cd\u65b9\u6cd5\u4f7f\u76ee\u5f55\u4e2d\u7528\u6237\u5bf9\u8c61\u7684\u4f4d\u7f6e\u66f4\u5177\u7075\u6d3b\u6027\uff0c\u4f46\u4f1a\u5bf9 LDAP \u670d\u52a1\u5668\u989d\u5916\u53d1\u8d77\u4e24\u6b21\u8bf7\u6c42\u3002</p>\n<p lang=\"zh\">\u4ee5\u4e0b\u914d\u7f6e\u9009\u9879\u5728\u4e24\u79cd\u6a21\u5f0f\u4e0b\u90fd\u4f7f\u7528\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapserver</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8981\u8fde\u63a5\u7684LDAP\u670d\u52a1\u5668\u7684\u540d\u79f0\u6216IP\u5730\u5740\u3002\u53ef\u4ee5\u6307\u5b9a\u591a\u4e2a\u670d\u52a1\u5668\uff0c\u7528\u7a7a\u683c\u5206\u9694\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapport</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8981\u8fde\u63a5\u7684LDAP\u670d\u52a1\u5668\u7684\u7aef\u53e3\u53f7\u3002\u5982\u679c\u672a\u6307\u5b9a\u7aef\u53e3\uff0c\u5219\u5c06\u4f7f\u7528LDAP\u5e93\u7684\u9ed8\u8ba4\u7aef\u53e3\u8bbe\u7f6e\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapscheme</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8bbe\u7f6e\u4e3a<code class=\"literal\">ldaps</code>\u4ee5\u4f7f\u7528LDAPS\u3002\u8fd9\u662f\u4e00\u79cd\u975e\u6807\u51c6\u7684\u901a\u8fc7 SSL \u4f7f\u7528 LDAP \u7684\u65b9\u5f0f\uff0c\u53d7\u4e00\u4e9bLDAP\u670d\u52a1\u5668\u5b9e\u73b0\u652f\u6301\u3002\u53e6\u8bf7\u53c2\u9605<code class=\"literal\">ldaptls</code> \u9009\u9879\u4f5c\u4e3a\u66ff\u4ee3\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldaptls</code></span></dt>\n<dd>\n<p lang=\"zh\">\u8bbe\u7f6e\u4e3a 1 \u65f6\uff0cPostgreSQL \u4e0e LDAP \u670d\u52a1\u5668\u4e4b\u95f4\u7684\u8fde\u63a5\u4f7f\u7528 TLS \u52a0\u5bc6\uff0c\u901a\u8fc7 RFC 4513 \u89c4\u5b9a\u7684 StartTLS \u64cd\u4f5c\u5b9e\u73b0\u3002\u53e6\u53ef\u53c2\u89c1 ldapscheme \u9009\u9879\u6240\u63d0\u4f9b\u7684\u66ff\u4ee3\u65b9\u5f0f\u3002</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u6ce8\u610f\u4f7f\u7528<code class=\"literal\">ldapscheme</code>\u6216<code class=\"literal\">ldaptls</code>\u4ec5\u4f1a\u52a0\u5bc6PostgreSQL \u670d\u52a1\u5668\u548cLDAP\u670d\u52a1\u5668\u4e4b\u95f4\u7684\u901a\u4fe1\u3002PostgreSQL \u670d\u52a1\u5668\u548cPostgreSQL\u5ba2\u6237\u7aef\u4e4b\u95f4\u7684\u8fde\u63a5\u4ecd\u662f\u672a\u52a0\u5bc6\u7684\uff0c\u9664\u975e\u4e5f\u5728\u5176\u4e0a\u4f7f\u7528SSL\u3002</p>\n<p lang=\"zh\">\u4e0b\u5217\u9009\u9879\u53ea\u88ab\u7528\u4e8e\u7b80\u5355\u7ed1\u5b9a\u6a21\u5f0f\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapprefix</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u7b80\u5355\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u9644\u52a0\u5230\u7528\u6237\u540d\u524d\u9762\u4ee5\u5f62\u6210\u7ed1\u5b9a DN \u7684\u5b57\u7b26\u4e32\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsuffix</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u7b80\u5355\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u9644\u52a0\u5230\u7528\u6237\u540d\u540e\u9762\u4ee5\u5f62\u6210\u7ed1\u5b9a DN \u7684\u5b57\u7b26\u4e32\u3002</p>\n</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u4ee5\u4e0b\u9009\u9879\u4ec5\u5728\u641c\u7d22+\u7ed1\u5b9a\u6a21\u5f0f\u4e2d\u4f7f\u7528\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapbasedn</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4f5c\u7528\u6237\u641c\u7d22\u8d77\u70b9\u7684\u6839 DN\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapbinddn</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u7ed1\u5b9a\u5230\u76ee\u5f55\u5e76\u6267\u884c\u641c\u7d22\u7684\u7528\u6237 DN\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapbindpasswd</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u7ed1\u5b9a\u5230\u76ee\u5f55\u5e76\u6267\u884c\u641c\u7d22\u7684\u7528\u6237\u5bc6\u7801\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsearchattribute</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u4e0e\u7528\u6237\u540d\u5339\u914d\u7684\u5c5e\u6027\u3002\u5982\u679c\u672a\u6307\u5b9a\u5c5e\u6027\uff0c\u5219\u4f1a\u4f7f\u7528 <code class=\"literal\">uid</code> \u5c5e\u6027\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsearchfilter</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\u4f7f\u7528\u7684\u641c\u7d22\u8fc7\u6ee4\u5668\u3002\u5176\u4e2d\u51fa\u73b0\u7684 <code class=\"literal\">$username</code> \u4f1a\u88ab\u66ff\u6362\u4e3a\u7528\u6237\u540d\u3002\u8fd9\u4f7f\u5f97\u641c\u7d22\u8fc7\u6ee4\u5668\u6bd4 <code class=\"literal\">ldapsearchattribute</code> \u66f4\u7075\u6d3b\u3002</p>\n</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u4ee5\u4e0b\u9009\u9879\u63d0\u4f9b\u4e86\u53e6\u4e00\u79cd\u5199\u6cd5\uff0c\u53ef\u4ee5\u7528\u66f4\u7d27\u51d1\u3001\u6807\u51c6\u7684\u5f62\u5f0f\u8868\u793a\u4e0a\u8ff0\u90e8\u5206 LDAP \u9009\u9879\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapurl</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4e00\u4e2a<a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc4516\" target=\"_top\">RFC 4516</a> LDAP URL\u3002\u683c\u5f0f\u4e3a</p>\n<pre class=\"synopsis\">ldap[s]://<em class=\"replaceable\"><code>host</code></em>[:<em class=\"replaceable\"><code>port</code></em>]/<em class=\"replaceable\"><code>basedn</code></em>[?[<em class=\"replaceable\"><code>attribute</code></em>][?[<em class=\"replaceable\"><code>scope</code></em>][?[<em class=\"replaceable\"><code>filter</code></em>]]]]\n</pre>\n<p lang=\"zh\"><em class=\"replaceable\"><code>scope</code></em>\u5fc5\u987b\u662f<code class=\"literal\">base</code>\u3001<code class=\"literal\">one</code>\u3001<code class=\"literal\">sub</code>\u4e2d\u7684\u4e00\u4e2a\uff0c\u901a\u5e38\u662f\u6700\u540e\u4e00\u4e2a\u3002\uff08\u9ed8\u8ba4\u4e3a<code class=\"literal\">base</code>\uff0c\u5728\u6b64\u5e94\u7528\u4e2d\u901a\u5e38\u65e0\u7528\u3002\uff09<em class=\"replaceable\"><code>attribute</code></em>\u53ef\u4ee5\u6307\u5b9a\u5355\u4e2a\u5c5e\u6027\uff0c\u6b64\u65f6\u5c06\u7528\u4f5c<code class=\"literal\">ldapsearchattribute</code>\u7684\u503c\u3002\u5982\u679c<em class=\"replaceable\"><code>attribute</code></em>\u4e3a\u7a7a\uff0c\u5219<em class=\"replaceable\"><code>filter</code></em>\u53ef\u7528\u4f5c<code class=\"literal\">ldapsearchfilter</code>\u7684\u503c\u3002</p>\n<p lang=\"zh\">URL \u65b9\u6848 ldaps \u9009\u62e9\u901a\u8fc7 SSL \u5efa\u7acb LDAP \u8fde\u63a5\u7684 LDAPS \u65b9\u5f0f\uff0c\u7b49\u4ef7\u4e8e ldapscheme=ldaps\u3002\u8981\u901a\u8fc7 StartTLS \u4f7f\u7528\u52a0\u5bc6 LDAP \u8fde\u63a5\uff0c\u5e94\u4f7f\u7528\u666e\u901a\u7684 ldap URL \u65b9\u6848\uff0c\u5e76\u5728 ldapurl \u4e4b\u5916\u6307\u5b9a ldaptls\u3002</p>\n<p lang=\"zh\">\u5bf9\u4e8e\u975e\u533f\u540d\u7ed1\u5b9a\uff0c\u5fc5\u987b\u5c06<code class=\"literal\">ldapbinddn</code>\u548c<code class=\"literal\">ldapbindpasswd</code>\u6307\u5b9a\u4e3a\u5355\u72ec\u7684\u9009\u9879\u3002</p>\n<p lang=\"zh\">LDAP URL\u76ee\u524d\u4ec5\u53d7<span class=\"productname\">OpenLDAP</span>\u652f\u6301\uff0c\u4e0d\u652f\u6301Windows\u3002</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u5c06\u7b80\u5355\u7ed1\u5b9a\u9009\u9879\u4e0e\u641c\u7d22+\u7ed1\u5b9a\u9009\u9879\u6df7\u7528\u662f\u9519\u8bef\u7684\u3002\u82e5\u8981\u5728\u7b80\u5355\u7ed1\u5b9a\u6a21\u5f0f\u4e0b\u4f7f\u7528 <code class=\"literal\">ldapurl</code>\uff0c\u8be5 URL \u4e2d\u4e0d\u80fd\u5305\u542b <code class=\"literal\">basedn</code> \u6216\u67e5\u8be2\u5143\u7d20\u3002</p>\n<p lang=\"zh\">\u5728\u4f7f\u7528\u641c\u7d22+\u7ed1\u5b9a\u6a21\u5f0f\u65f6\uff0c\u53ef\u4ee5\u4f7f\u7528\u7531 <code class=\"literal\">ldapsearchattribute</code> \u6307\u5b9a\u7684\u5355\u4e2a\u5c5e\u6027\u6267\u884c\u641c\u7d22\uff0c\u4e5f\u53ef\u4ee5\u4f7f\u7528\u7531 <code class=\"literal\">ldapsearchfilter</code> \u6307\u5b9a\u7684\u81ea\u5b9a\u4e49\u641c\u7d22\u8fc7\u6ee4\u5668\u6267\u884c\u641c\u7d22\u3002\u6307\u5b9a <code class=\"literal\">ldapsearchattribute=foo</code> \u7b49\u4ef7\u4e8e\u6307\u5b9a <code class=\"literal\">ldapsearchfilter=\"(foo=$username)\"</code>\u3002\u5982\u679c\u4e24\u4e2a\u9009\u9879\u90fd\u672a\u6307\u5b9a\uff0c\u5219\u9ed8\u8ba4\u4f7f\u7528 <code class=\"literal\">ldapsearchattribute=uid</code>\u3002</p>\n<p lang=\"zh\">\u5982\u679c <span class=\"productname\">PostgreSQL</span> \u7f16\u8bd1\u65f6\u4f7f\u7528\u4e86 <span class=\"productname\">OpenLDAP</span> \u4f5c\u4e3a LDAP \u5ba2\u6237\u7aef\u5e93\uff0c\u5219\u53ef\u4ee5\u7701\u7565 <code class=\"literal\">ldapserver</code> \u8bbe\u7f6e\u3002\u5728\u8fd9\u79cd\u60c5\u51b5\u4e0b\uff0c\u4f1a\u901a\u8fc7 <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc2782\" target=\"_top\">RFC 2782</a> DNS SRV \u8bb0\u5f55\u67e5\u627e\u4e3b\u673a\u540d\u548c\u7aef\u53e3\u5217\u8868\u3002\u67e5\u627e\u7684\u540d\u79f0\u662f <code class=\"literal\">_ldap._tcp.DOMAIN</code>\uff0c\u5176\u4e2d <code class=\"literal\">DOMAIN</code> \u4ece <code class=\"literal\">ldapbasedn</code> \u4e2d\u63d0\u53d6\u3002</p>\n<p lang=\"zh\">\u4e0b\u9762\u662f\u4e00\u4e2a\u7b80\u5355\u7ed1\u5b9a LDAP \u914d\u7f6e\u793a\u4f8b\uff1a</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapprefix=\"cn=\" ldapsuffix=\", dc=example, dc=net\"\n</pre>\n<p lang=\"zh\">\u5f53\u8bf7\u6c42\u4ee5\u6570\u636e\u5e93\u7528\u6237 <code class=\"literal\">someuser</code> \u8fde\u63a5\u6570\u636e\u5e93\u670d\u52a1\u5668\u65f6\uff0cPostgreSQL \u5c06\u5c1d\u8bd5\u4f7f\u7528 DN <code class=\"literal\">cn=someuser, dc=example, dc=net</code> \u548c\u5ba2\u6237\u7aef\u63d0\u4f9b\u7684\u5bc6\u7801\u7ed1\u5b9a\u5230 LDAP \u670d\u52a1\u5668\u3002\u5982\u679c\u8be5\u8fde\u63a5\u6210\u529f\uff0c\u6570\u636e\u5e93\u8bbf\u95ee\u5c31\u4f1a\u88ab\u6388\u4e88\u3002</p>\n<p lang=\"zh\">\u4e0b\u9762\u662f\u53e6\u4e00\u79cd\u7b80\u5355\u7ed1\u5b9a\u914d\u7f6e\uff0c\u5b83\u4f7f\u7528 LDAPS \u65b9\u6848\u548c\u81ea\u5b9a\u4e49\u7aef\u53e3\u53f7\uff0c\u5e76\u4ee5 URL \u5f62\u5f0f\u5199\u51fa\uff1a</p>\n<pre class=\"programlisting\">host ... ldap ldapurl=\"ldaps://ldap.example.net:49151\" ldapprefix=\"cn=\" ldapsuffix=\", dc=example, dc=net\"\n</pre>\n<p lang=\"zh\">\u8fd9\u79cd\u5199\u6cd5\u6bd4\u5355\u72ec\u6307\u5b9a <code class=\"literal\">ldapserver</code>\u3001<code class=\"literal\">ldapscheme</code> \u548c <code class=\"literal\">ldapport</code> \u7a0d\u5fae\u66f4\u7d27\u51d1\u3002</p>\n<p lang=\"zh\">\u4e0b\u9762\u662f\u4e00\u4e2a\u641c\u7d22+\u7ed1\u5b9a\u914d\u7f6e\u793a\u4f8b\uff1a</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapbasedn=\"dc=example, dc=net\" ldapsearchattribute=uid\n</pre>\n<p lang=\"zh\">\u5f53\u8bf7\u6c42\u4ee5\u6570\u636e\u5e93\u7528\u6237 <code class=\"literal\">someuser</code> \u8fde\u63a5\u6570\u636e\u5e93\u670d\u52a1\u5668\u65f6\uff0cPostgreSQL \u5c06\u5c1d\u8bd5\u5bf9 LDAP \u670d\u52a1\u5668\u8fdb\u884c\u533f\u540d\u7ed1\u5b9a\uff08\u56e0\u4e3a\u672a\u6307\u5b9a <code class=\"literal\">ldapbinddn</code>\uff09\uff0c\u5e76\u5728\u6307\u5b9a\u7684\u57fa\u7840 DN \u4e0b\u6267\u884c\u4e00\u6b21 <code class=\"literal\">(uid=someuser)</code> \u641c\u7d22\u3002\u5982\u679c\u627e\u5230\u4e86\u5bf9\u5e94\u6761\u76ee\uff0c\u968f\u540e\u5c31\u4f1a\u5c1d\u8bd5\u4f7f\u7528\u8be5\u6761\u76ee\u7684\u4fe1\u606f\u4ee5\u53ca\u5ba2\u6237\u7aef\u63d0\u4f9b\u7684\u5bc6\u7801\u8fdb\u884c\u7ed1\u5b9a\u3002\u5982\u679c\u7b2c\u4e8c\u6b21\u7ed1\u5b9a\u6210\u529f\uff0c\u6570\u636e\u5e93\u8bbf\u95ee\u5c31\u4f1a\u88ab\u6388\u4e88\u3002</p>\n<p lang=\"zh\">\u4e0b\u9762\u662f\u4ee5 URL \u5f62\u5f0f\u5199\u51fa\u7684\u540c\u4e00\u4e2a\u641c\u7d22+\u7ed1\u5b9a\u914d\u7f6e\uff1a</p>\n<pre class=\"programlisting\">host ... ldap ldapurl=\"ldap://ldap.example.net/dc=example,dc=net?uid?sub\"\n</pre>\n<p lang=\"zh\">\u67d0\u4e9b\u652f\u6301 LDAP \u8ba4\u8bc1\u7684\u5176\u4ed6\u8f6f\u4ef6\u4e5f\u4f7f\u7528\u76f8\u540c\u7684 URL \u683c\u5f0f\uff0c\u56e0\u6b64\u5171\u4eab\u8fd9\u7c7b\u914d\u7f6e\u4f1a\u66f4\u5bb9\u6613\u3002</p>\n<p lang=\"zh\">\u8fd9\u91cc\u662f\u4e00\u4e2a\u641c\u7d22+\u7ed1\u5b9a\u914d\u7f6e\u7684\u793a\u4f8b\uff0c\u5b83\u4f7f\u7528 <code class=\"literal\">ldapsearchfilter</code> \u800c\u4e0d\u662f <code class=\"literal\">ldapsearchattribute</code> \u6765\u5141\u8bb8\u7528\u7528\u6237 ID \u6216\u7535\u5b50\u90ae\u4ef6\u5730\u5740\u8fdb\u884c\u8ba4\u8bc1\uff1a</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapbasedn=\"dc=example, dc=net\" ldapsearchfilter=\"(|(uid=$username)(mail=$username))\"\n</pre>\n<p lang=\"zh\">\u8fd9\u662f\u4e00\u4e2a\u641c\u7d22+\u7ed1\u5b9a\u914d\u7f6e\u7684\u793a\u4f8b\uff0c\u5b83\u4f7f\u7528 DNS SRV \u53d1\u73b0\u6765\u67e5\u627e\u57df\u540d <code class=\"literal\">example.net</code> \u7684 LDAP \u670d\u52a1\u7684\u4e3b\u673a\u540d\u548c\u7aef\u53e3\u3002</p>\n<pre class=\"programlisting\">host ... ldap ldapbasedn=\"dc=example,dc=net\"\n</pre>\n<div class=\"tip\">\n<h3 class=\"title\" lang=\"zh\">\u63d0\u793a</h3>\n<p lang=\"zh\">\u5982\u793a\u4f8b\u4e2d\u6240\u793a\uff0c\u7531\u4e8e LDAP \u901a\u5e38\u4f7f\u7528\u9017\u53f7\u548c\u7a7a\u683c\u6765\u5206\u9694\u4e00\u4e2a DN \u7684\u4e0d\u540c\u90e8\u5206\uff0c\u5728\u914d\u7f6e LDAP \u9009\u9879\u65f6\u901a\u5e38\u6709\u5fc5\u8981\u4f7f\u7528\u53cc\u5f15\u53f7\u5305\u56f4\u7684\u53c2\u6570\u503c\u3002</p>\n</div>\n</div>", "manual_path": "/docs/18/auth-ldap.html", "localization": {"status": "complete", "sources": [{"url": "/docs/18/auth-ldap.html", "method": "same-major semantic node", "sha256": "065da171765af4f43f5d9405a7594cb88fbc5c9a8566612a459af67e1079cce0", "language": "zh", "matched_nodes": ["#AUTH-LDAP/div[0]", "#AUTH-LDAP/div[11]/dl[0]/dd[1]", "#AUTH-LDAP/div[11]/dl[0]/dd[3]", "#AUTH-LDAP/div[11]/dl[0]/dd[5]", "#AUTH-LDAP/div[11]/dl[0]/dd[7]", "#AUTH-LDAP/div[11]/dl[0]/dd[9]", "#AUTH-LDAP/div[13]/dl[0]/dd[1]/p[0]", "#AUTH-LDAP/div[13]/dl[0]/dd[1]/p[2]", "#AUTH-LDAP/div[13]/dl[0]/dd[1]/p[4]", "#AUTH-LDAP/div[13]/dl[0]/dd[1]/p[5]", "#AUTH-LDAP/div[33]/h3[0]", "#AUTH-LDAP/div[33]/p[1]", "#AUTH-LDAP/div[6]/dl[0]/dd[1]", "#AUTH-LDAP/div[6]/dl[0]/dd[3]", "#AUTH-LDAP/div[6]/dl[0]/dd[5]", "#AUTH-LDAP/div[9]/dl[0]/dd[1]", "#AUTH-LDAP/div[9]/dl[0]/dd[3]", "#AUTH-LDAP/p[10]", "#AUTH-LDAP/p[12]", "#AUTH-LDAP/p[14]", "#AUTH-LDAP/p[15]", "#AUTH-LDAP/p[16]", "#AUTH-LDAP/p[17]", "#AUTH-LDAP/p[19]", "#AUTH-LDAP/p[20]", "#AUTH-LDAP/p[22]", "#AUTH-LDAP/p[23]", "#AUTH-LDAP/p[25]", "#AUTH-LDAP/p[26]", "#AUTH-LDAP/p[28]", "#AUTH-LDAP/p[29]", "#AUTH-LDAP/p[2]", "#AUTH-LDAP/p[31]", "#AUTH-LDAP/p[3]", "#AUTH-LDAP/p[4]", "#AUTH-LDAP/p[5]", "#AUTH-LDAP/p[7]", "#AUTH-LDAP/p[8]"]}], "language": "zh", "original_text": {"/versions/18/description/0": "Authenticate using an LDAP server. See Section 20.10 for details.", "/versions/18/facts/0/label": "Method", "/versions/18/facts/1/label": "Configuration", "/versions/18/facts/2/label": "Inventory", "/versions/18/facts/2/value": "User-visible source authentication method", "/versions/18/tables/0/title": "Documented method options and alternatives", "/versions/18/tables/0/columns/0/label": "Option or term", "/versions/18/tables/0/columns/1/label": "Meaning", "/versions/18/tables/0/rows/0/description": "Names or IP addresses of LDAP servers to connect to. Multiple servers may be specified, separated by spaces.", "/versions/18/tables/0/rows/1/description": "Port number on LDAP server to connect to. If no port is specified, the LDAP library's default port setting will be used.", "/versions/18/tables/0/rows/2/description": "Set to ldaps to use LDAPS. This is a non-standard way of using LDAP over SSL, supported by some LDAP server implementations. See also the ldaptls option for an alternative.", "/versions/18/tables/0/rows/3/description": "Set to 1 to make the connection between PostgreSQL and the LDAP server use TLS encryption. This uses the StartTLS operation per RFC 4513 . See also the ldapscheme option for an alternative.", "/versions/18/tables/0/rows/4/description": "String to prepend to the user name when forming the DN to bind as, when doing simple bind authentication.", "/versions/18/tables/0/rows/5/description": "String to append to the user name when forming the DN to bind as, when doing simple bind authentication.", "/versions/18/tables/0/rows/6/description": "Root DN to begin the search for the user in, when doing search+bind authentication.", "/versions/18/tables/0/rows/7/description": "DN of user to bind to the directory with to perform the search when doing search+bind authentication.", "/versions/18/tables/0/rows/8/description": "Password for user to bind to the directory with to perform the search when doing search+bind authentication.", "/versions/18/tables/0/rows/9/description": "Attribute to match against the user name in the search when doing search+bind authentication. If no attribute is specified, the uid attribute will be used.", "/versions/18/tables/0/rows/10/description": "The search filter to use when doing search+bind authentication. Occurrences of $username will be replaced with the user name. This allows for more flexible search filters than ldapsearchattribute .", "/versions/18/tables/0/rows/11/description": "An RFC 4516 LDAP URL. The format is ldap[s]:// host [: port ]/ basedn [?[ attribute ][?[ scope ][?[ filter ]]]] scope must be one of base , one , sub , typically the last. (The default is base , which is normally not useful in this application.) attribute can nominate a single attribute, in which case it is used as a value for ldapsearchattribute . If attribute is empty then filter can be used as a value for ldapsearchfilter . The URL scheme ldaps chooses the LDAPS method for making LDAP connections over SSL, equivalent to using ldapscheme=ldaps . To use encrypted LDAP connections using the StartTLS operation, use the normal URL scheme ldap and specify the ldaptls option in addition to ldapurl . For non-anonymous binds, ldapbinddn and ldapbindpasswd must be specified as separate options. LDAP URLs are currently only supported with OpenLDAP , not on Windows."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "cd042d43565e1460d7789e6c328e4902c31423a24f7d95653d8b81545f596da2"}, "comparison_data": {"method": "ldap", "documented_option_names": ["ldapbasedn", "ldapbinddn", "ldapbindpasswd", "ldapport", "ldapprefix", "ldapscheme", "ldapsearchattribute", "ldapsearchfilter", "ldapserver", "ldapsuffix", "ldaptls", "ldapurl"]}, "comparison_hash": "d40de945ae67b3ac60a284fdd442cc24a4e9d05bc7a7b18009b54e491c381b88", "manual_language": "zh"}, "19": {"facts": [{"label": "\u65b9\u6cd5", "value": "ldap"}, {"label": "\u914d\u7f6e", "value": "pg_hba.conf"}, {"label": "\u6e05\u5355", "value": "\u7528\u6237\u53ef\u89c1\u7684\u6e90\u7801\u8ba4\u8bc1\u65b9\u6cd5"}], "tables": [{"key": "method-options", "rows": [{"name": "ldapserver", "description": "\u8981\u8fde\u63a5\u7684LDAP\u670d\u52a1\u5668\u7684\u540d\u79f0\u6216IP\u5730\u5740\u3002\u53ef\u4ee5\u6307\u5b9a\u591a\u4e2a\u670d\u52a1\u5668\uff0c\u7528\u7a7a\u683c\u5206\u9694\u3002"}, {"name": "ldapport", "description": "\u8981\u8fde\u63a5\u7684LDAP\u670d\u52a1\u5668\u7684\u7aef\u53e3\u53f7\u3002\u5982\u679c\u672a\u6307\u5b9a\u7aef\u53e3\uff0c\u5219\u5c06\u4f7f\u7528LDAP\u5e93\u7684\u9ed8\u8ba4\u7aef\u53e3\u8bbe\u7f6e\u3002"}, {"name": "ldapscheme", "description": "\u8bbe\u7f6e\u4e3a ldaps \u4ee5\u4f7f\u7528LDAPS\u3002\u8fd9\u662f\u4e00\u79cd\u975e\u6807\u51c6\u7684\u901a\u8fc7 SSL \u4f7f\u7528 LDAP \u7684\u65b9\u5f0f\uff0c\u53d7\u4e00\u4e9bLDAP\u670d\u52a1\u5668\u5b9e\u73b0\u652f\u6301\u3002\u53e6\u8bf7\u53c2\u9605 ldaptls \u9009\u9879\u4f5c\u4e3a\u66ff\u4ee3\u3002"}, {"name": "ldaptls", "description": "\u8bbe\u7f6e\u4e3a 1 \u65f6\uff0cPostgreSQL \u4e0e LDAP \u670d\u52a1\u5668\u4e4b\u95f4\u7684\u8fde\u63a5\u4f7f\u7528 TLS \u52a0\u5bc6\uff0c\u901a\u8fc7 RFC 4513 \u89c4\u5b9a\u7684 StartTLS \u64cd\u4f5c\u5b9e\u73b0\u3002\u53e6\u53ef\u53c2\u89c1 ldapscheme \u9009\u9879\u6240\u63d0\u4f9b\u7684\u66ff\u4ee3\u65b9\u5f0f\u3002"}, {"name": "ldapprefix", "description": "\u5728\u8fdb\u884c\u7b80\u5355\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u9644\u52a0\u5230\u7528\u6237\u540d\u524d\u9762\u4ee5\u5f62\u6210\u7ed1\u5b9a DN \u7684\u5b57\u7b26\u4e32\u3002"}, {"name": "ldapsuffix", "description": "\u5728\u8fdb\u884c\u7b80\u5355\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u9644\u52a0\u5230\u7528\u6237\u540d\u540e\u9762\u4ee5\u5f62\u6210\u7ed1\u5b9a DN \u7684\u5b57\u7b26\u4e32\u3002"}, {"name": "ldapbasedn", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4f5c\u7528\u6237\u641c\u7d22\u8d77\u70b9\u7684\u6839 DN\u3002"}, {"name": "ldapbinddn", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u7ed1\u5b9a\u5230\u76ee\u5f55\u5e76\u6267\u884c\u641c\u7d22\u7684\u7528\u6237 DN\u3002"}, {"name": "ldapbindpasswd", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u7ed1\u5b9a\u5230\u76ee\u5f55\u5e76\u6267\u884c\u641c\u7d22\u7684\u7528\u6237\u5bc6\u7801\u3002"}, {"name": "ldapsearchattribute", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u4e0e\u7528\u6237\u540d\u5339\u914d\u7684\u5c5e\u6027\u3002\u5982\u679c\u672a\u6307\u5b9a\u5c5e\u6027\uff0c\u5219\u4f1a\u4f7f\u7528 uid \u5c5e\u6027\u3002"}, {"name": "ldapsearchfilter", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\u4f7f\u7528\u7684\u641c\u7d22\u8fc7\u6ee4\u5668\u3002\u5176\u4e2d\u51fa\u73b0\u7684 $username \u4f1a\u88ab\u66ff\u6362\u4e3a\u7528\u6237\u540d\u3002\u8fd9\u4f7f\u5f97\u641c\u7d22\u8fc7\u6ee4\u5668\u6bd4 ldapsearchattribute \u66f4\u7075\u6d3b\u3002"}, {"name": "ldapurl", "description": "\u7b26\u5408 RFC 4516 \u7684 LDAP URL\u3002\u683c\u5f0f\u4e3a ldap[s]://host[:port]/basedn[?[attribute][?[scope][?[filter]]]]\u3002scope \u5fc5\u987b\u4e3a base\u3001one \u6216 sub\uff0c\u901a\u5e38\u4f7f\u7528 sub\uff1b\u9ed8\u8ba4\u503c base \u5728\u6b64\u7528\u9014\u4e0b\u4e00\u822c\u6ca1\u6709\u5b9e\u9645\u5e2e\u52a9\u3002attribute \u53ef\u6307\u5b9a\u4e00\u4e2a\u5c5e\u6027\uff0c\u4f5c\u4e3a ldapsearchattribute \u7684\u503c\uff1battribute \u4e3a\u7a7a\u65f6\uff0cfilter \u53ef\u7528\u4f5c ldapsearchfilter \u7684\u503c\u3002URL \u65b9\u6848 ldaps \u8868\u793a\u901a\u8fc7 SSL \u5efa\u7acb LDAP \u8fde\u63a5\uff0c\u7b49\u540c\u4e8e ldapscheme=ldaps\u3002\u82e5\u8981\u901a\u8fc7 StartTLS \u4f7f\u7528\u52a0\u5bc6 LDAP \u8fde\u63a5\uff0c\u5e94\u4f7f\u7528\u666e\u901a\u7684 ldap URL \u65b9\u6848\uff0c\u5e76\u5728 ldapurl \u4e4b\u5916\u6307\u5b9a ldaptls\u3002\u5bf9\u4e8e\u975e\u533f\u540d\u7ed1\u5b9a\uff0c\u5fc5\u987b\u53e6\u884c\u6307\u5b9a ldapbinddn \u548c ldapbindpasswd\u3002LDAP URL \u76ee\u524d\u4ec5\u5728 OpenLDAP \u4e2d\u53d7\u652f\u6301\uff0cWindows \u4e0d\u652f\u6301\u3002"}], "title": "\u624b\u518c\u4e2d\u7684\u65b9\u6cd5\u9009\u9879\u4e0e\u66ff\u4ee3\u65b9\u5f0f", "columns": [{"key": "name", "label": "\u9009\u9879\u6216\u672f\u8bed"}, {"key": "description", "label": "\u542b\u4e49"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v19beta4/postgresql-19beta4.tar.bz2", "label": "19beta4", "major": "19", "channel": "preview", "revision": "83157ee9c599d03b2f7a3d73ef3a56ec24e0e79cc2b3501a64d1364f56398c86", "source_sha256": "83157ee9c599d03b2f7a3d73ef3a56ec24e0e79cc2b3501a64d1364f56398c86", "catalog_fingerprint": "62fbf1a3689dbe8bf7e6b3372cfe6fbf867581427b3858a94c8419b77a4d2d1d"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v19beta4/postgresql-19beta4.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "83157ee9c599d03b2f7a3d73ef3a56ec24e0e79cc2b3501a64d1364f56398c86"}, {"url": "https://pg.center/docs/19/auth-ldap.html", "path": "auth-ldap.html", "label": "PostgreSQL 19 English manual", "sha256": "e7f0c5ec2b27f9479614d22f87ffeca99e87ae03e00f0f7ffcb78e2e9df84b3d", "language": "en", "original_url": "/docs/19/auth-ldap.html"}, {"url": "https://pg.center/docs/19/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 19 English manual", "sha256": "d05e9155d5388148c2c680ff208b62c6b3b0b1c30f302ada5ab4befec36c19b7", "language": "en", "original_url": "/docs/19/auth-pg-hba-conf.html"}], "sections": [], "signature": "", "attributes": {"method": "ldap", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["\u4f7f\u7528 LDAP \u670d\u52a1\u5668\u8fdb\u884c\u8ba4\u8bc1\u3002\u8be6\u60c5\u53c2\u89c1\u7b2c 20.10 \u8282\u3002"], "manual_html": "<div class=\"sect1\" id=\"AUTH-LDAP\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\" lang=\"zh\">\n<div>\n<div>\n<h2 class=\"title\" style=\"clear: both\">20.10.\u00a0LDAP \u8ba4\u8bc1 </h2>\n</div>\n</div>\n</h2>\n</div>\n</div>\n</div>\n<p lang=\"zh\">\u8fd9\u79cd\u8ba4\u8bc1\u65b9\u6cd5\u7684\u5de5\u4f5c\u65b9\u5f0f\u4e0e <code class=\"literal\">password</code> \u7c7b\u4f3c\uff0c\u53ea\u4e0d\u8fc7\u5b83\u4f7f\u7528 LDAP \u4f5c\u4e3a\u5bc6\u7801\u9a8c\u8bc1\u65b9\u6cd5\u3002LDAP \u53ea\u7528\u4e8e\u9a8c\u8bc1\u7528\u6237\u540d/\u5bc6\u7801\u5bf9\u3002\u56e0\u6b64\uff0c\u5728\u4f7f\u7528 LDAP \u8fdb\u884c\u8ba4\u8bc1\u4e4b\u524d\uff0c\u7528\u6237\u5fc5\u987b\u5df2\u7ecf\u5b58\u5728\u4e8e\u6570\u636e\u5e93\u4e2d\u3002</p>\n<p lang=\"zh\">LDAP \u8ba4\u8bc1\u53ef\u4ee5\u5728\u4e24\u79cd\u6a21\u5f0f\u4e0b\u5de5\u4f5c\u3002\u7b2c\u4e00\u79cd\u6a21\u5f0f\u79f0\u4e3a\u7b80\u5355\u7ed1\u5b9a\u6a21\u5f0f\uff0c\u670d\u52a1\u5668\u4f1a\u7ed1\u5b9a\u5230\u6309 <em class=\"replaceable\"><code>prefix</code></em> <em class=\"replaceable\"><code>username</code></em> <em class=\"replaceable\"><code>suffix</code></em> \u5f62\u5f0f\u6784\u9020\u51fa\u7684\u53ef\u5206\u8fa8\u540d\u79f0\u3002\u901a\u5e38\uff0c<em class=\"replaceable\"><code>prefix</code></em> \u53c2\u6570\u7528\u4e8e\u6307\u5b9a <code class=\"literal\">cn=</code>\uff0c\u6216\u5728 Active Directory \u73af\u5883\u4e2d\u6307\u5b9a <em class=\"replaceable\"><code>DOMAIN</code></em><code class=\"literal\">\\</code>\u3002<em class=\"replaceable\"><code>suffix</code></em> \u5219\u7528\u4e8e\u6307\u5b9a\u975e Active Directory \u73af\u5883\u4e2d DN \u7684\u5269\u4f59\u90e8\u5206\u3002</p>\n<p lang=\"zh\">\u7b2c\u4e8c\u79cd\u6a21\u5f0f\u79f0\u4e3a\u641c\u7d22+\u7ed1\u5b9a\u6a21\u5f0f\uff0c\u670d\u52a1\u5668\u9996\u5148\u4f7f\u7528\u7531 <em class=\"replaceable\"><code>ldapbinddn</code></em> \u548c <em class=\"replaceable\"><code>ldapbindpasswd</code></em> \u6307\u5b9a\u7684\u56fa\u5b9a\u7528\u6237\u540d\u548c\u5bc6\u7801\u7ed1\u5b9a\u5230 LDAP \u76ee\u5f55\uff0c\u5e76\u641c\u7d22\u8bd5\u56fe\u767b\u5f55\u6570\u636e\u5e93\u7684\u7528\u6237\u3002\u5982\u679c\u6ca1\u6709\u914d\u7f6e\u7528\u6237\u540d\u548c\u5bc6\u7801\uff0c\u5219\u4f1a\u5c1d\u8bd5\u5bf9\u76ee\u5f55\u8fdb\u884c\u533f\u540d\u7ed1\u5b9a\u3002\u641c\u7d22\u4f1a\u5728 <em class=\"replaceable\"><code>ldapbasedn</code></em> \u6307\u5b9a\u7684\u5b50\u6811\u4e0a\u8fdb\u884c\uff0c\u5e76\u5c1d\u8bd5\u5bf9 <em class=\"replaceable\"><code>ldapsearchattribute</code></em> \u6307\u5b9a\u7684\u5c5e\u6027\u505a\u7cbe\u786e\u5339\u914d\u3002\u4e00\u65e6\u5728\u641c\u7d22\u4e2d\u627e\u5230\u4e86\u8be5\u7528\u6237\uff0c\u670d\u52a1\u5668\u5c31\u4f1a\u4f5c\u4e3a\u8be5\u7528\u6237\u91cd\u65b0\u7ed1\u5b9a\u5230\u76ee\u5f55\uff0c\u5e76\u4f7f\u7528\u5ba2\u6237\u7aef\u6307\u5b9a\u7684\u5bc6\u7801\u6765\u9a8c\u8bc1\u767b\u5f55\u662f\u5426\u6b63\u786e\u3002\u8fd9\u79cd\u6a21\u5f0f\u4e0e Apache <code class=\"literal\">mod_authnz_ldap</code> \u548c <code class=\"literal\">pam_ldap</code> \u7b49\u8f6f\u4ef6\u4e2d\u7684 LDAP \u8ba4\u8bc1\u65b9\u6848\u76f8\u540c\u3002\u8fd9\u79cd\u65b9\u6cd5\u4f7f\u76ee\u5f55\u4e2d\u7528\u6237\u5bf9\u8c61\u7684\u4f4d\u7f6e\u66f4\u5177\u7075\u6d3b\u6027\uff0c\u4f46\u4f1a\u5bf9 LDAP \u670d\u52a1\u5668\u989d\u5916\u53d1\u8d77\u4e24\u6b21\u8bf7\u6c42\u3002</p>\n<p lang=\"zh\">\u4ee5\u4e0b\u914d\u7f6e\u9009\u9879\u5728\u4e24\u79cd\u6a21\u5f0f\u4e0b\u90fd\u4f7f\u7528\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapserver</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8981\u8fde\u63a5\u7684LDAP\u670d\u52a1\u5668\u7684\u540d\u79f0\u6216IP\u5730\u5740\u3002\u53ef\u4ee5\u6307\u5b9a\u591a\u4e2a\u670d\u52a1\u5668\uff0c\u7528\u7a7a\u683c\u5206\u9694\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapport</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8981\u8fde\u63a5\u7684LDAP\u670d\u52a1\u5668\u7684\u7aef\u53e3\u53f7\u3002\u5982\u679c\u672a\u6307\u5b9a\u7aef\u53e3\uff0c\u5219\u5c06\u4f7f\u7528LDAP\u5e93\u7684\u9ed8\u8ba4\u7aef\u53e3\u8bbe\u7f6e\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapscheme</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8bbe\u7f6e\u4e3a<code class=\"literal\">ldaps</code>\u4ee5\u4f7f\u7528LDAPS\u3002\u8fd9\u662f\u4e00\u79cd\u975e\u6807\u51c6\u7684\u901a\u8fc7 SSL \u4f7f\u7528 LDAP \u7684\u65b9\u5f0f\uff0c\u53d7\u4e00\u4e9bLDAP\u670d\u52a1\u5668\u5b9e\u73b0\u652f\u6301\u3002\u53e6\u8bf7\u53c2\u9605<code class=\"literal\">ldaptls</code> \u9009\u9879\u4f5c\u4e3a\u66ff\u4ee3\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldaptls</code></span></dt>\n<dd>\n<p lang=\"zh\">\u8bbe\u7f6e\u4e3a 1 \u65f6\uff0cPostgreSQL \u4e0e LDAP \u670d\u52a1\u5668\u4e4b\u95f4\u7684\u8fde\u63a5\u4f7f\u7528 TLS \u52a0\u5bc6\uff0c\u901a\u8fc7 RFC 4513 \u89c4\u5b9a\u7684 StartTLS \u64cd\u4f5c\u5b9e\u73b0\u3002\u53e6\u53ef\u53c2\u89c1 ldapscheme \u9009\u9879\u6240\u63d0\u4f9b\u7684\u66ff\u4ee3\u65b9\u5f0f\u3002</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u6ce8\u610f\u4f7f\u7528<code class=\"literal\">ldapscheme</code>\u6216<code class=\"literal\">ldaptls</code>\u4ec5\u4f1a\u52a0\u5bc6PostgreSQL \u670d\u52a1\u5668\u548cLDAP\u670d\u52a1\u5668\u4e4b\u95f4\u7684\u901a\u4fe1\u3002PostgreSQL \u670d\u52a1\u5668\u548cPostgreSQL\u5ba2\u6237\u7aef\u4e4b\u95f4\u7684\u8fde\u63a5\u4ecd\u662f\u672a\u52a0\u5bc6\u7684\uff0c\u9664\u975e\u4e5f\u5728\u5176\u4e0a\u4f7f\u7528SSL\u3002</p>\n<p lang=\"zh\">\u4e0b\u5217\u9009\u9879\u53ea\u88ab\u7528\u4e8e\u7b80\u5355\u7ed1\u5b9a\u6a21\u5f0f\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapprefix</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u7b80\u5355\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u9644\u52a0\u5230\u7528\u6237\u540d\u524d\u9762\u4ee5\u5f62\u6210\u7ed1\u5b9a DN \u7684\u5b57\u7b26\u4e32\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsuffix</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u7b80\u5355\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u9644\u52a0\u5230\u7528\u6237\u540d\u540e\u9762\u4ee5\u5f62\u6210\u7ed1\u5b9a DN \u7684\u5b57\u7b26\u4e32\u3002</p>\n</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u4ee5\u4e0b\u9009\u9879\u4ec5\u5728\u641c\u7d22+\u7ed1\u5b9a\u6a21\u5f0f\u4e2d\u4f7f\u7528\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapbasedn</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4f5c\u7528\u6237\u641c\u7d22\u8d77\u70b9\u7684\u6839 DN\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapbinddn</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u7ed1\u5b9a\u5230\u76ee\u5f55\u5e76\u6267\u884c\u641c\u7d22\u7684\u7528\u6237 DN\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapbindpasswd</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u7ed1\u5b9a\u5230\u76ee\u5f55\u5e76\u6267\u884c\u641c\u7d22\u7684\u7528\u6237\u5bc6\u7801\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsearchattribute</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u4e0e\u7528\u6237\u540d\u5339\u914d\u7684\u5c5e\u6027\u3002\u5982\u679c\u672a\u6307\u5b9a\u5c5e\u6027\uff0c\u5219\u4f1a\u4f7f\u7528 <code class=\"literal\">uid</code> \u5c5e\u6027\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsearchfilter</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\u4f7f\u7528\u7684\u641c\u7d22\u8fc7\u6ee4\u5668\u3002\u5176\u4e2d\u51fa\u73b0\u7684 <code class=\"literal\">$username</code> \u4f1a\u88ab\u66ff\u6362\u4e3a\u7528\u6237\u540d\u3002\u8fd9\u4f7f\u5f97\u641c\u7d22\u8fc7\u6ee4\u5668\u6bd4 <code class=\"literal\">ldapsearchattribute</code> \u66f4\u7075\u6d3b\u3002</p>\n</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u4ee5\u4e0b\u9009\u9879\u63d0\u4f9b\u4e86\u53e6\u4e00\u79cd\u5199\u6cd5\uff0c\u53ef\u4ee5\u7528\u66f4\u7d27\u51d1\u3001\u6807\u51c6\u7684\u5f62\u5f0f\u8868\u793a\u4e0a\u8ff0\u90e8\u5206 LDAP \u9009\u9879\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapurl</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4e00\u4e2a<a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc4516\" target=\"_top\">RFC 4516</a> LDAP URL\u3002\u683c\u5f0f\u4e3a</p>\n<pre class=\"synopsis\">ldap[s]://<em class=\"replaceable\"><code>host</code></em>[:<em class=\"replaceable\"><code>port</code></em>]/<em class=\"replaceable\"><code>basedn</code></em>[?[<em class=\"replaceable\"><code>attribute</code></em>][?[<em class=\"replaceable\"><code>scope</code></em>][?[<em class=\"replaceable\"><code>filter</code></em>]]]]\n</pre>\n<p lang=\"zh\"><em class=\"replaceable\"><code>scope</code></em>\u5fc5\u987b\u662f<code class=\"literal\">base</code>\u3001<code class=\"literal\">one</code>\u3001<code class=\"literal\">sub</code>\u4e2d\u7684\u4e00\u4e2a\uff0c\u901a\u5e38\u662f\u6700\u540e\u4e00\u4e2a\u3002\uff08\u9ed8\u8ba4\u4e3a<code class=\"literal\">base</code>\uff0c\u5728\u6b64\u5e94\u7528\u4e2d\u901a\u5e38\u65e0\u7528\u3002\uff09<em class=\"replaceable\"><code>attribute</code></em>\u53ef\u4ee5\u6307\u5b9a\u5355\u4e2a\u5c5e\u6027\uff0c\u6b64\u65f6\u5c06\u7528\u4f5c<code class=\"literal\">ldapsearchattribute</code>\u7684\u503c\u3002\u5982\u679c<em class=\"replaceable\"><code>attribute</code></em>\u4e3a\u7a7a\uff0c\u5219<em class=\"replaceable\"><code>filter</code></em>\u53ef\u7528\u4f5c<code class=\"literal\">ldapsearchfilter</code>\u7684\u503c\u3002</p>\n<p lang=\"zh\">URL \u65b9\u6848 ldaps \u9009\u62e9\u901a\u8fc7 SSL \u5efa\u7acb LDAP \u8fde\u63a5\u7684 LDAPS \u65b9\u5f0f\uff0c\u7b49\u4ef7\u4e8e ldapscheme=ldaps\u3002\u8981\u901a\u8fc7 StartTLS \u4f7f\u7528\u52a0\u5bc6 LDAP \u8fde\u63a5\uff0c\u5e94\u4f7f\u7528\u666e\u901a\u7684 ldap URL \u65b9\u6848\uff0c\u5e76\u5728 ldapurl \u4e4b\u5916\u6307\u5b9a ldaptls\u3002</p>\n<p lang=\"zh\">\u5bf9\u4e8e\u975e\u533f\u540d\u7ed1\u5b9a\uff0c\u5fc5\u987b\u5c06<code class=\"literal\">ldapbinddn</code>\u548c<code class=\"literal\">ldapbindpasswd</code>\u6307\u5b9a\u4e3a\u5355\u72ec\u7684\u9009\u9879\u3002</p>\n<p lang=\"zh\">LDAP URL\u76ee\u524d\u4ec5\u53d7<span class=\"productname\">OpenLDAP</span>\u652f\u6301\uff0c\u4e0d\u652f\u6301Windows\u3002</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u5c06\u7b80\u5355\u7ed1\u5b9a\u9009\u9879\u4e0e\u641c\u7d22+\u7ed1\u5b9a\u9009\u9879\u6df7\u7528\u662f\u9519\u8bef\u7684\u3002\u82e5\u8981\u5728\u7b80\u5355\u7ed1\u5b9a\u6a21\u5f0f\u4e0b\u4f7f\u7528 <code class=\"literal\">ldapurl</code>\uff0c\u8be5 URL \u4e2d\u4e0d\u80fd\u5305\u542b <code class=\"literal\">basedn</code> \u6216\u67e5\u8be2\u5143\u7d20\u3002</p>\n<p lang=\"zh\">\u5728\u4f7f\u7528\u641c\u7d22+\u7ed1\u5b9a\u6a21\u5f0f\u65f6\uff0c\u53ef\u4ee5\u4f7f\u7528\u7531 <code class=\"literal\">ldapsearchattribute</code> \u6307\u5b9a\u7684\u5355\u4e2a\u5c5e\u6027\u6267\u884c\u641c\u7d22\uff0c\u4e5f\u53ef\u4ee5\u4f7f\u7528\u7531 <code class=\"literal\">ldapsearchfilter</code> \u6307\u5b9a\u7684\u81ea\u5b9a\u4e49\u641c\u7d22\u8fc7\u6ee4\u5668\u6267\u884c\u641c\u7d22\u3002\u6307\u5b9a <code class=\"literal\">ldapsearchattribute=foo</code> \u7b49\u4ef7\u4e8e\u6307\u5b9a <code class=\"literal\">ldapsearchfilter=\"(foo=$username)\"</code>\u3002\u5982\u679c\u4e24\u4e2a\u9009\u9879\u90fd\u672a\u6307\u5b9a\uff0c\u5219\u9ed8\u8ba4\u4f7f\u7528 <code class=\"literal\">ldapsearchattribute=uid</code>\u3002</p>\n<p lang=\"zh\">\u5982\u679c <span class=\"productname\">PostgreSQL</span> \u7f16\u8bd1\u65f6\u4f7f\u7528\u4e86 <span class=\"productname\">OpenLDAP</span> \u4f5c\u4e3a LDAP \u5ba2\u6237\u7aef\u5e93\uff0c\u5219\u53ef\u4ee5\u7701\u7565 <code class=\"literal\">ldapserver</code> \u8bbe\u7f6e\u3002\u5728\u8fd9\u79cd\u60c5\u51b5\u4e0b\uff0c\u4f1a\u901a\u8fc7 <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc2782\" target=\"_top\">RFC 2782</a> DNS SRV \u8bb0\u5f55\u67e5\u627e\u4e3b\u673a\u540d\u548c\u7aef\u53e3\u5217\u8868\u3002\u67e5\u627e\u7684\u540d\u79f0\u662f <code class=\"literal\">_ldap._tcp.DOMAIN</code>\uff0c\u5176\u4e2d <code class=\"literal\">DOMAIN</code> \u4ece <code class=\"literal\">ldapbasedn</code> \u4e2d\u63d0\u53d6\u3002</p>\n<p lang=\"zh\">\u4e0b\u9762\u662f\u4e00\u4e2a\u7b80\u5355\u7ed1\u5b9a LDAP \u914d\u7f6e\u793a\u4f8b\uff1a</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapprefix=\"cn=\" ldapsuffix=\", dc=example, dc=net\"\n</pre>\n<p lang=\"zh\">\u5f53\u8bf7\u6c42\u4ee5\u6570\u636e\u5e93\u7528\u6237 <code class=\"literal\">someuser</code> \u8fde\u63a5\u6570\u636e\u5e93\u670d\u52a1\u5668\u65f6\uff0cPostgreSQL \u5c06\u5c1d\u8bd5\u4f7f\u7528 DN <code class=\"literal\">cn=someuser, dc=example, dc=net</code> \u548c\u5ba2\u6237\u7aef\u63d0\u4f9b\u7684\u5bc6\u7801\u7ed1\u5b9a\u5230 LDAP \u670d\u52a1\u5668\u3002\u5982\u679c\u8be5\u8fde\u63a5\u6210\u529f\uff0c\u6570\u636e\u5e93\u8bbf\u95ee\u5c31\u4f1a\u88ab\u6388\u4e88\u3002</p>\n<p lang=\"zh\">\u4e0b\u9762\u662f\u53e6\u4e00\u79cd\u7b80\u5355\u7ed1\u5b9a\u914d\u7f6e\uff0c\u5b83\u4f7f\u7528 LDAPS \u65b9\u6848\u548c\u81ea\u5b9a\u4e49\u7aef\u53e3\u53f7\uff0c\u5e76\u4ee5 URL \u5f62\u5f0f\u5199\u51fa\uff1a</p>\n<pre class=\"programlisting\">host ... ldap ldapurl=\"ldaps://ldap.example.net:49151\" ldapprefix=\"cn=\" ldapsuffix=\", dc=example, dc=net\"\n</pre>\n<p lang=\"zh\">\u8fd9\u79cd\u5199\u6cd5\u6bd4\u5355\u72ec\u6307\u5b9a <code class=\"literal\">ldapserver</code>\u3001<code class=\"literal\">ldapscheme</code> \u548c <code class=\"literal\">ldapport</code> \u7a0d\u5fae\u66f4\u7d27\u51d1\u3002</p>\n<p lang=\"zh\">\u4e0b\u9762\u662f\u4e00\u4e2a\u641c\u7d22+\u7ed1\u5b9a\u914d\u7f6e\u793a\u4f8b\uff1a</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapbasedn=\"dc=example, dc=net\" ldapsearchattribute=uid\n</pre>\n<p lang=\"zh\">\u5f53\u8bf7\u6c42\u4ee5\u6570\u636e\u5e93\u7528\u6237 <code class=\"literal\">someuser</code> \u8fde\u63a5\u6570\u636e\u5e93\u670d\u52a1\u5668\u65f6\uff0cPostgreSQL \u5c06\u5c1d\u8bd5\u5bf9 LDAP \u670d\u52a1\u5668\u8fdb\u884c\u533f\u540d\u7ed1\u5b9a\uff08\u56e0\u4e3a\u672a\u6307\u5b9a <code class=\"literal\">ldapbinddn</code>\uff09\uff0c\u5e76\u5728\u6307\u5b9a\u7684\u57fa\u7840 DN \u4e0b\u6267\u884c\u4e00\u6b21 <code class=\"literal\">(uid=someuser)</code> \u641c\u7d22\u3002\u5982\u679c\u627e\u5230\u4e86\u5bf9\u5e94\u6761\u76ee\uff0c\u968f\u540e\u5c31\u4f1a\u5c1d\u8bd5\u4f7f\u7528\u8be5\u6761\u76ee\u7684\u4fe1\u606f\u4ee5\u53ca\u5ba2\u6237\u7aef\u63d0\u4f9b\u7684\u5bc6\u7801\u8fdb\u884c\u7ed1\u5b9a\u3002\u5982\u679c\u7b2c\u4e8c\u6b21\u7ed1\u5b9a\u6210\u529f\uff0c\u6570\u636e\u5e93\u8bbf\u95ee\u5c31\u4f1a\u88ab\u6388\u4e88\u3002</p>\n<p lang=\"zh\">\u4e0b\u9762\u662f\u4ee5 URL \u5f62\u5f0f\u5199\u51fa\u7684\u540c\u4e00\u4e2a\u641c\u7d22+\u7ed1\u5b9a\u914d\u7f6e\uff1a</p>\n<pre class=\"programlisting\">host ... ldap ldapurl=\"ldap://ldap.example.net/dc=example,dc=net?uid?sub\"\n</pre>\n<p lang=\"zh\">\u67d0\u4e9b\u652f\u6301 LDAP \u8ba4\u8bc1\u7684\u5176\u4ed6\u8f6f\u4ef6\u4e5f\u4f7f\u7528\u76f8\u540c\u7684 URL \u683c\u5f0f\uff0c\u56e0\u6b64\u5171\u4eab\u8fd9\u7c7b\u914d\u7f6e\u4f1a\u66f4\u5bb9\u6613\u3002</p>\n<p lang=\"zh\">\u8fd9\u91cc\u662f\u4e00\u4e2a\u641c\u7d22+\u7ed1\u5b9a\u914d\u7f6e\u7684\u793a\u4f8b\uff0c\u5b83\u4f7f\u7528 <code class=\"literal\">ldapsearchfilter</code> \u800c\u4e0d\u662f <code class=\"literal\">ldapsearchattribute</code> \u6765\u5141\u8bb8\u7528\u7528\u6237 ID \u6216\u7535\u5b50\u90ae\u4ef6\u5730\u5740\u8fdb\u884c\u8ba4\u8bc1\uff1a</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapbasedn=\"dc=example, dc=net\" ldapsearchfilter=\"(|(uid=$username)(mail=$username))\"\n</pre>\n<p lang=\"zh\">\u8fd9\u662f\u4e00\u4e2a\u641c\u7d22+\u7ed1\u5b9a\u914d\u7f6e\u7684\u793a\u4f8b\uff0c\u5b83\u4f7f\u7528 DNS SRV \u53d1\u73b0\u6765\u67e5\u627e\u57df\u540d <code class=\"literal\">example.net</code> \u7684 LDAP \u670d\u52a1\u7684\u4e3b\u673a\u540d\u548c\u7aef\u53e3\u3002</p>\n<pre class=\"programlisting\">host ... ldap ldapbasedn=\"dc=example,dc=net\"\n</pre>\n<div class=\"tip\">\n<h3 class=\"title\" lang=\"zh\">\u63d0\u793a</h3>\n<p lang=\"zh\">\u5982\u793a\u4f8b\u4e2d\u6240\u793a\uff0c\u7531\u4e8e LDAP \u901a\u5e38\u4f7f\u7528\u9017\u53f7\u548c\u7a7a\u683c\u6765\u5206\u9694\u4e00\u4e2a DN \u7684\u4e0d\u540c\u90e8\u5206\uff0c\u5728\u914d\u7f6e LDAP \u9009\u9879\u65f6\u901a\u5e38\u6709\u5fc5\u8981\u4f7f\u7528\u53cc\u5f15\u53f7\u5305\u56f4\u7684\u53c2\u6570\u503c\u3002</p>\n</div>\n</div>", "manual_path": "/docs/19/auth-ldap.html", "localization": {"status": "complete", "sources": [{"url": "/docs/19/auth-ldap.html", "method": "same-major semantic node", "sha256": "3668c350cc408b7d489c4b74849ab3e28ebf1c75bfe94d0cd21633e2ec1e84b3", "language": "zh", "matched_nodes": ["#AUTH-LDAP/div[0]", "#AUTH-LDAP/div[11]/dl[0]/dd[1]", "#AUTH-LDAP/div[11]/dl[0]/dd[3]", "#AUTH-LDAP/div[11]/dl[0]/dd[5]", "#AUTH-LDAP/div[11]/dl[0]/dd[7]", "#AUTH-LDAP/div[11]/dl[0]/dd[9]", "#AUTH-LDAP/div[13]/dl[0]/dd[1]/p[0]", "#AUTH-LDAP/div[13]/dl[0]/dd[1]/p[2]", "#AUTH-LDAP/div[13]/dl[0]/dd[1]/p[4]", "#AUTH-LDAP/div[13]/dl[0]/dd[1]/p[5]", "#AUTH-LDAP/div[33]/h3[0]", "#AUTH-LDAP/div[33]/p[1]", "#AUTH-LDAP/div[6]/dl[0]/dd[1]", "#AUTH-LDAP/div[6]/dl[0]/dd[3]", "#AUTH-LDAP/div[6]/dl[0]/dd[5]", "#AUTH-LDAP/div[9]/dl[0]/dd[1]", "#AUTH-LDAP/div[9]/dl[0]/dd[3]", "#AUTH-LDAP/p[10]", "#AUTH-LDAP/p[12]", "#AUTH-LDAP/p[14]", "#AUTH-LDAP/p[15]", "#AUTH-LDAP/p[16]", "#AUTH-LDAP/p[17]", "#AUTH-LDAP/p[19]", "#AUTH-LDAP/p[20]", "#AUTH-LDAP/p[22]", "#AUTH-LDAP/p[23]", "#AUTH-LDAP/p[25]", "#AUTH-LDAP/p[26]", "#AUTH-LDAP/p[28]", "#AUTH-LDAP/p[29]", "#AUTH-LDAP/p[2]", "#AUTH-LDAP/p[31]", "#AUTH-LDAP/p[3]", "#AUTH-LDAP/p[4]", "#AUTH-LDAP/p[5]", "#AUTH-LDAP/p[7]", "#AUTH-LDAP/p[8]"]}], "language": "zh", "original_text": {"/versions/19/description/0": "Authenticate using an LDAP server. See Section 20.10 for details.", "/versions/19/facts/0/label": "Method", "/versions/19/facts/1/label": "Configuration", "/versions/19/facts/2/label": "Inventory", "/versions/19/facts/2/value": "User-visible source authentication method", "/versions/19/tables/0/title": "Documented method options and alternatives", "/versions/19/tables/0/columns/0/label": "Option or term", "/versions/19/tables/0/columns/1/label": "Meaning", "/versions/19/tables/0/rows/0/description": "Names or IP addresses of LDAP servers to connect to. Multiple servers may be specified, separated by spaces.", "/versions/19/tables/0/rows/1/description": "Port number on LDAP server to connect to. If no port is specified, the LDAP library's default port setting will be used.", "/versions/19/tables/0/rows/2/description": "Set to ldaps to use LDAPS. This is a non-standard way of using LDAP over SSL, supported by some LDAP server implementations. See also the ldaptls option for an alternative.", "/versions/19/tables/0/rows/3/description": "Set to 1 to make the connection between PostgreSQL and the LDAP server use TLS encryption. This uses the StartTLS operation per RFC 4513 . See also the ldapscheme option for an alternative.", "/versions/19/tables/0/rows/4/description": "String to prepend to the user name when forming the DN to bind as, when doing simple bind authentication.", "/versions/19/tables/0/rows/5/description": "String to append to the user name when forming the DN to bind as, when doing simple bind authentication.", "/versions/19/tables/0/rows/6/description": "Root DN to begin the search for the user in, when doing search+bind authentication.", "/versions/19/tables/0/rows/7/description": "DN of user to bind to the directory with to perform the search when doing search+bind authentication.", "/versions/19/tables/0/rows/8/description": "Password for user to bind to the directory with to perform the search when doing search+bind authentication.", "/versions/19/tables/0/rows/9/description": "Attribute to match against the user name in the search when doing search+bind authentication. If no attribute is specified, the uid attribute will be used.", "/versions/19/tables/0/rows/10/description": "The search filter to use when doing search+bind authentication. Occurrences of $username will be replaced with the user name. This allows for more flexible search filters than ldapsearchattribute .", "/versions/19/tables/0/rows/11/description": "An RFC 4516 LDAP URL. The format is ldap[s]:// host [: port ]/ basedn [?[ attribute ][?[ scope ][?[ filter ]]]] scope must be one of base , one , sub , typically the last. (The default is base , which is normally not useful in this application.) attribute can nominate a single attribute, in which case it is used as a value for ldapsearchattribute . If attribute is empty then filter can be used as a value for ldapsearchfilter . The URL scheme ldaps chooses the LDAPS method for making LDAP connections over SSL, equivalent to using ldapscheme=ldaps . To use encrypted LDAP connections using the StartTLS operation, use the normal URL scheme ldap and specify the ldaptls option in addition to ldapurl . For non-anonymous binds, ldapbinddn and ldapbindpasswd must be specified as separate options. LDAP URLs are currently only supported with OpenLDAP , not on Windows."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "2932a992489c1cea78e1803233004428deb7be4ec18e3a8fb8e73cfbd34a6da9"}, "comparison_data": {"method": "ldap", "documented_option_names": ["ldapbasedn", "ldapbinddn", "ldapbindpasswd", "ldapport", "ldapprefix", "ldapscheme", "ldapsearchattribute", "ldapsearchfilter", "ldapserver", "ldapsuffix", "ldaptls", "ldapurl"]}, "comparison_hash": "d40de945ae67b3ac60a284fdd442cc24a4e9d05bc7a7b18009b54e491c381b88", "manual_language": "zh"}, "20": {"facts": [{"label": "\u65b9\u6cd5", "value": "ldap"}, {"label": "\u914d\u7f6e", "value": "pg_hba.conf"}, {"label": "\u6e05\u5355", "value": "\u7528\u6237\u53ef\u89c1\u7684\u6e90\u7801\u8ba4\u8bc1\u65b9\u6cd5"}], "tables": [{"key": "method-options", "rows": [{"name": "ldapserver", "description": "\u8981\u8fde\u63a5\u7684LDAP\u670d\u52a1\u5668\u7684\u540d\u79f0\u6216IP\u5730\u5740\u3002\u53ef\u4ee5\u6307\u5b9a\u591a\u4e2a\u670d\u52a1\u5668\uff0c\u7528\u7a7a\u683c\u5206\u9694\u3002"}, {"name": "ldapport", "description": "\u8981\u8fde\u63a5\u7684LDAP\u670d\u52a1\u5668\u7684\u7aef\u53e3\u53f7\u3002\u5982\u679c\u672a\u6307\u5b9a\u7aef\u53e3\uff0c\u5219\u5c06\u4f7f\u7528LDAP\u5e93\u7684\u9ed8\u8ba4\u7aef\u53e3\u8bbe\u7f6e\u3002"}, {"name": "ldapscheme", "description": "\u8bbe\u7f6e\u4e3a ldaps \u4ee5\u4f7f\u7528LDAPS\u3002\u8fd9\u662f\u4e00\u79cd\u975e\u6807\u51c6\u7684\u901a\u8fc7 SSL \u4f7f\u7528 LDAP \u7684\u65b9\u5f0f\uff0c\u53d7\u4e00\u4e9bLDAP\u670d\u52a1\u5668\u5b9e\u73b0\u652f\u6301\u3002\u53e6\u8bf7\u53c2\u9605 ldaptls \u9009\u9879\u4f5c\u4e3a\u66ff\u4ee3\u3002"}, {"name": "ldaptls", "description": "\u8bbe\u7f6e\u4e3a 1 \u65f6\uff0cPostgreSQL \u4e0e LDAP \u670d\u52a1\u5668\u4e4b\u95f4\u7684\u8fde\u63a5\u4f7f\u7528 TLS \u52a0\u5bc6\uff0c\u901a\u8fc7 RFC 4513 \u89c4\u5b9a\u7684 StartTLS \u64cd\u4f5c\u5b9e\u73b0\u3002\u53e6\u53ef\u53c2\u89c1 ldapscheme \u9009\u9879\u6240\u63d0\u4f9b\u7684\u66ff\u4ee3\u65b9\u5f0f\u3002"}, {"name": "ldapprefix", "description": "\u5728\u8fdb\u884c\u7b80\u5355\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u9644\u52a0\u5230\u7528\u6237\u540d\u524d\u9762\u4ee5\u5f62\u6210\u7ed1\u5b9a DN \u7684\u5b57\u7b26\u4e32\u3002"}, {"name": "ldapsuffix", "description": "\u5728\u8fdb\u884c\u7b80\u5355\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u9644\u52a0\u5230\u7528\u6237\u540d\u540e\u9762\u4ee5\u5f62\u6210\u7ed1\u5b9a DN \u7684\u5b57\u7b26\u4e32\u3002"}, {"name": "ldapbasedn", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4f5c\u7528\u6237\u641c\u7d22\u8d77\u70b9\u7684\u6839 DN\u3002"}, {"name": "ldapbinddn", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u7ed1\u5b9a\u5230\u76ee\u5f55\u5e76\u6267\u884c\u641c\u7d22\u7684\u7528\u6237 DN\u3002"}, {"name": "ldapbindpasswd", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u7ed1\u5b9a\u5230\u76ee\u5f55\u5e76\u6267\u884c\u641c\u7d22\u7684\u7528\u6237\u5bc6\u7801\u3002"}, {"name": "ldapsearchattribute", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u4e0e\u7528\u6237\u540d\u5339\u914d\u7684\u5c5e\u6027\u3002\u5982\u679c\u672a\u6307\u5b9a\u5c5e\u6027\uff0c\u5219\u4f1a\u4f7f\u7528 uid \u5c5e\u6027\u3002"}, {"name": "ldapsearchfilter", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\u4f7f\u7528\u7684\u641c\u7d22\u8fc7\u6ee4\u5668\u3002\u5176\u4e2d\u51fa\u73b0\u7684 $username \u4f1a\u88ab\u66ff\u6362\u4e3a\u7528\u6237\u540d\u3002\u8fd9\u4f7f\u5f97\u641c\u7d22\u8fc7\u6ee4\u5668\u6bd4 ldapsearchattribute \u66f4\u7075\u6d3b\u3002"}, {"name": "ldapurl", "description": "\u7b26\u5408 RFC 4516 \u7684 LDAP URL\u3002\u683c\u5f0f\u4e3a ldap[s]://host[:port]/basedn[?[attribute][?[scope][?[filter]]]]\u3002scope \u5fc5\u987b\u4e3a base\u3001one \u6216 sub\uff0c\u901a\u5e38\u4f7f\u7528 sub\uff1b\u9ed8\u8ba4\u503c base \u5728\u6b64\u7528\u9014\u4e0b\u4e00\u822c\u6ca1\u6709\u5b9e\u9645\u5e2e\u52a9\u3002attribute \u53ef\u6307\u5b9a\u4e00\u4e2a\u5c5e\u6027\uff0c\u4f5c\u4e3a ldapsearchattribute \u7684\u503c\uff1battribute \u4e3a\u7a7a\u65f6\uff0cfilter \u53ef\u7528\u4f5c ldapsearchfilter \u7684\u503c\u3002URL \u65b9\u6848 ldaps \u8868\u793a\u901a\u8fc7 SSL \u5efa\u7acb LDAP \u8fde\u63a5\uff0c\u7b49\u540c\u4e8e ldapscheme=ldaps\u3002\u82e5\u8981\u901a\u8fc7 StartTLS \u4f7f\u7528\u52a0\u5bc6 LDAP \u8fde\u63a5\uff0c\u5e94\u4f7f\u7528\u666e\u901a\u7684 ldap URL \u65b9\u6848\uff0c\u5e76\u5728 ldapurl \u4e4b\u5916\u6307\u5b9a ldaptls\u3002\u5bf9\u4e8e\u975e\u533f\u540d\u7ed1\u5b9a\uff0c\u5fc5\u987b\u53e6\u884c\u6307\u5b9a ldapbinddn \u548c ldapbindpasswd\u3002LDAP URL \u76ee\u524d\u4ec5\u5728 OpenLDAP \u4e2d\u53d7\u652f\u6301\uff0cWindows \u4e0d\u652f\u6301\u3002"}], "title": "\u624b\u518c\u4e2d\u7684\u65b9\u6cd5\u9009\u9879\u4e0e\u66ff\u4ee3\u65b9\u5f0f", "columns": [{"key": "name", "label": "\u9009\u9879\u6216\u672f\u8bed"}, {"key": "description", "label": "\u542b\u4e49"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/snapshot/dev/postgresql-snapshot.tar.bz2", "label": "20devel", "major": "20", "channel": "devel", "revision": "4d3346909b201ac1648232cf290462a7070c119326f56196f1f0253ed80fae41", "source_sha256": "4d3346909b201ac1648232cf290462a7070c119326f56196f1f0253ed80fae41", "catalog_fingerprint": "398fbb9f262264053c02fbf79f88be0a6770c1473faa6ecd5931d6ec41b8258b", "source_snapshot_utc": "26-Sep-2026 20:22"}, "sources": [{"url": "https://ftp.postgresql.org/pub/snapshot/dev/postgresql-snapshot.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "4d3346909b201ac1648232cf290462a7070c119326f56196f1f0253ed80fae41"}, {"url": "https://pg.center/docs/devel/auth-ldap.html", "path": "auth-ldap.html", "label": "PostgreSQL 20 English manual", "sha256": "456fc2af52e32b229e6251f4107c0a1bc9e4c991485386042a521112407eb56e", "language": "en", "original_url": "/docs/devel/auth-ldap.html"}, {"url": "https://pg.center/docs/devel/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 20 English manual", "sha256": "cf2069461da3eec62f6fb4e3df8e46fd69ff4b3a2ad059eec355cee256d7996e", "language": "en", "original_url": "/docs/devel/auth-pg-hba-conf.html"}], "sections": [], "signature": "", "attributes": {"method": "ldap", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["\u4f7f\u7528 LDAP \u670d\u52a1\u5668\u8fdb\u884c\u8ba4\u8bc1\u3002\u8be6\u60c5\u53c2\u89c1\u7b2c 20.10 \u8282\u3002"], "manual_html": "<div class=\"sect1\" id=\"AUTH-LDAP\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\" lang=\"zh\">\n<div>\n<div>\n<h2 class=\"title\" style=\"clear: both\">20.10.\u00a0LDAP \u8ba4\u8bc1 </h2>\n</div>\n</div>\n</h2>\n</div>\n</div>\n</div>\n<p lang=\"zh\">\u8fd9\u79cd\u8ba4\u8bc1\u65b9\u6cd5\u7684\u5de5\u4f5c\u65b9\u5f0f\u4e0e <code class=\"literal\">password</code> \u7c7b\u4f3c\uff0c\u53ea\u4e0d\u8fc7\u5b83\u4f7f\u7528 LDAP \u4f5c\u4e3a\u5bc6\u7801\u9a8c\u8bc1\u65b9\u6cd5\u3002LDAP \u53ea\u7528\u4e8e\u9a8c\u8bc1\u7528\u6237\u540d/\u5bc6\u7801\u5bf9\u3002\u56e0\u6b64\uff0c\u5728\u4f7f\u7528 LDAP \u8fdb\u884c\u8ba4\u8bc1\u4e4b\u524d\uff0c\u7528\u6237\u5fc5\u987b\u5df2\u7ecf\u5b58\u5728\u4e8e\u6570\u636e\u5e93\u4e2d\u3002</p>\n<p lang=\"zh\">LDAP \u8ba4\u8bc1\u53ef\u4ee5\u5728\u4e24\u79cd\u6a21\u5f0f\u4e0b\u5de5\u4f5c\u3002\u7b2c\u4e00\u79cd\u6a21\u5f0f\u79f0\u4e3a\u7b80\u5355\u7ed1\u5b9a\u6a21\u5f0f\uff0c\u670d\u52a1\u5668\u4f1a\u7ed1\u5b9a\u5230\u6309 <em class=\"replaceable\"><code>prefix</code></em> <em class=\"replaceable\"><code>username</code></em> <em class=\"replaceable\"><code>suffix</code></em> \u5f62\u5f0f\u6784\u9020\u51fa\u7684\u53ef\u5206\u8fa8\u540d\u79f0\u3002\u901a\u5e38\uff0c<em class=\"replaceable\"><code>prefix</code></em> \u53c2\u6570\u7528\u4e8e\u6307\u5b9a <code class=\"literal\">cn=</code>\uff0c\u6216\u5728 Active Directory \u73af\u5883\u4e2d\u6307\u5b9a <em class=\"replaceable\"><code>DOMAIN</code></em><code class=\"literal\">\\</code>\u3002<em class=\"replaceable\"><code>suffix</code></em> \u5219\u7528\u4e8e\u6307\u5b9a\u975e Active Directory \u73af\u5883\u4e2d DN \u7684\u5269\u4f59\u90e8\u5206\u3002</p>\n<p lang=\"zh\">\u7b2c\u4e8c\u79cd\u6a21\u5f0f\u79f0\u4e3a\u641c\u7d22+\u7ed1\u5b9a\u6a21\u5f0f\uff0c\u670d\u52a1\u5668\u9996\u5148\u4f7f\u7528\u7531 <em class=\"replaceable\"><code>ldapbinddn</code></em> \u548c <em class=\"replaceable\"><code>ldapbindpasswd</code></em> \u6307\u5b9a\u7684\u56fa\u5b9a\u7528\u6237\u540d\u548c\u5bc6\u7801\u7ed1\u5b9a\u5230 LDAP \u76ee\u5f55\uff0c\u5e76\u641c\u7d22\u8bd5\u56fe\u767b\u5f55\u6570\u636e\u5e93\u7684\u7528\u6237\u3002\u5982\u679c\u6ca1\u6709\u914d\u7f6e\u7528\u6237\u540d\u548c\u5bc6\u7801\uff0c\u5219\u4f1a\u5c1d\u8bd5\u5bf9\u76ee\u5f55\u8fdb\u884c\u533f\u540d\u7ed1\u5b9a\u3002\u641c\u7d22\u4f1a\u5728 <em class=\"replaceable\"><code>ldapbasedn</code></em> \u6307\u5b9a\u7684\u5b50\u6811\u4e0a\u8fdb\u884c\uff0c\u5e76\u5c1d\u8bd5\u5bf9 <em class=\"replaceable\"><code>ldapsearchattribute</code></em> \u6307\u5b9a\u7684\u5c5e\u6027\u505a\u7cbe\u786e\u5339\u914d\u3002\u4e00\u65e6\u5728\u641c\u7d22\u4e2d\u627e\u5230\u4e86\u8be5\u7528\u6237\uff0c\u670d\u52a1\u5668\u5c31\u4f1a\u4f5c\u4e3a\u8be5\u7528\u6237\u91cd\u65b0\u7ed1\u5b9a\u5230\u76ee\u5f55\uff0c\u5e76\u4f7f\u7528\u5ba2\u6237\u7aef\u6307\u5b9a\u7684\u5bc6\u7801\u6765\u9a8c\u8bc1\u767b\u5f55\u662f\u5426\u6b63\u786e\u3002\u8fd9\u79cd\u6a21\u5f0f\u4e0e Apache <code class=\"literal\">mod_authnz_ldap</code> \u548c <code class=\"literal\">pam_ldap</code> \u7b49\u8f6f\u4ef6\u4e2d\u7684 LDAP \u8ba4\u8bc1\u65b9\u6848\u76f8\u540c\u3002\u8fd9\u79cd\u65b9\u6cd5\u4f7f\u76ee\u5f55\u4e2d\u7528\u6237\u5bf9\u8c61\u7684\u4f4d\u7f6e\u66f4\u5177\u7075\u6d3b\u6027\uff0c\u4f46\u4f1a\u5bf9 LDAP \u670d\u52a1\u5668\u989d\u5916\u53d1\u8d77\u4e24\u6b21\u8bf7\u6c42\u3002</p>\n<p lang=\"zh\">\u4ee5\u4e0b\u914d\u7f6e\u9009\u9879\u5728\u4e24\u79cd\u6a21\u5f0f\u4e0b\u90fd\u4f7f\u7528\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapserver</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8981\u8fde\u63a5\u7684LDAP\u670d\u52a1\u5668\u7684\u540d\u79f0\u6216IP\u5730\u5740\u3002\u53ef\u4ee5\u6307\u5b9a\u591a\u4e2a\u670d\u52a1\u5668\uff0c\u7528\u7a7a\u683c\u5206\u9694\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapport</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8981\u8fde\u63a5\u7684LDAP\u670d\u52a1\u5668\u7684\u7aef\u53e3\u53f7\u3002\u5982\u679c\u672a\u6307\u5b9a\u7aef\u53e3\uff0c\u5219\u5c06\u4f7f\u7528LDAP\u5e93\u7684\u9ed8\u8ba4\u7aef\u53e3\u8bbe\u7f6e\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapscheme</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8bbe\u7f6e\u4e3a<code class=\"literal\">ldaps</code>\u4ee5\u4f7f\u7528LDAPS\u3002\u8fd9\u662f\u4e00\u79cd\u975e\u6807\u51c6\u7684\u901a\u8fc7 SSL \u4f7f\u7528 LDAP \u7684\u65b9\u5f0f\uff0c\u53d7\u4e00\u4e9bLDAP\u670d\u52a1\u5668\u5b9e\u73b0\u652f\u6301\u3002\u53e6\u8bf7\u53c2\u9605<code class=\"literal\">ldaptls</code> \u9009\u9879\u4f5c\u4e3a\u66ff\u4ee3\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldaptls</code></span></dt>\n<dd>\n<p lang=\"zh\">\u8bbe\u7f6e\u4e3a 1 \u65f6\uff0cPostgreSQL \u4e0e LDAP \u670d\u52a1\u5668\u4e4b\u95f4\u7684\u8fde\u63a5\u4f7f\u7528 TLS \u52a0\u5bc6\uff0c\u901a\u8fc7 RFC 4513 \u89c4\u5b9a\u7684 StartTLS \u64cd\u4f5c\u5b9e\u73b0\u3002\u53e6\u53ef\u53c2\u89c1 ldapscheme \u9009\u9879\u6240\u63d0\u4f9b\u7684\u66ff\u4ee3\u65b9\u5f0f\u3002</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u6ce8\u610f\u4f7f\u7528<code class=\"literal\">ldapscheme</code>\u6216<code class=\"literal\">ldaptls</code>\u4ec5\u4f1a\u52a0\u5bc6PostgreSQL \u670d\u52a1\u5668\u548cLDAP\u670d\u52a1\u5668\u4e4b\u95f4\u7684\u901a\u4fe1\u3002PostgreSQL \u670d\u52a1\u5668\u548cPostgreSQL\u5ba2\u6237\u7aef\u4e4b\u95f4\u7684\u8fde\u63a5\u4ecd\u662f\u672a\u52a0\u5bc6\u7684\uff0c\u9664\u975e\u4e5f\u5728\u5176\u4e0a\u4f7f\u7528SSL\u3002</p>\n<p lang=\"zh\">\u4e0b\u5217\u9009\u9879\u53ea\u88ab\u7528\u4e8e\u7b80\u5355\u7ed1\u5b9a\u6a21\u5f0f\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapprefix</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u7b80\u5355\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u9644\u52a0\u5230\u7528\u6237\u540d\u524d\u9762\u4ee5\u5f62\u6210\u7ed1\u5b9a DN \u7684\u5b57\u7b26\u4e32\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsuffix</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u7b80\u5355\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u9644\u52a0\u5230\u7528\u6237\u540d\u540e\u9762\u4ee5\u5f62\u6210\u7ed1\u5b9a DN \u7684\u5b57\u7b26\u4e32\u3002</p>\n</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u4ee5\u4e0b\u9009\u9879\u4ec5\u5728\u641c\u7d22+\u7ed1\u5b9a\u6a21\u5f0f\u4e2d\u4f7f\u7528\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapbasedn</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4f5c\u7528\u6237\u641c\u7d22\u8d77\u70b9\u7684\u6839 DN\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapbinddn</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u7ed1\u5b9a\u5230\u76ee\u5f55\u5e76\u6267\u884c\u641c\u7d22\u7684\u7528\u6237 DN\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapbindpasswd</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u7ed1\u5b9a\u5230\u76ee\u5f55\u5e76\u6267\u884c\u641c\u7d22\u7684\u7528\u6237\u5bc6\u7801\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsearchattribute</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u4e0e\u7528\u6237\u540d\u5339\u914d\u7684\u5c5e\u6027\u3002\u5982\u679c\u672a\u6307\u5b9a\u5c5e\u6027\uff0c\u5219\u4f1a\u4f7f\u7528 <code class=\"literal\">uid</code> \u5c5e\u6027\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsearchfilter</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\u4f7f\u7528\u7684\u641c\u7d22\u8fc7\u6ee4\u5668\u3002\u5176\u4e2d\u51fa\u73b0\u7684 <code class=\"literal\">$username</code> \u4f1a\u88ab\u66ff\u6362\u4e3a\u7528\u6237\u540d\u3002\u8fd9\u4f7f\u5f97\u641c\u7d22\u8fc7\u6ee4\u5668\u6bd4 <code class=\"literal\">ldapsearchattribute</code> \u66f4\u7075\u6d3b\u3002</p>\n</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u4ee5\u4e0b\u9009\u9879\u63d0\u4f9b\u4e86\u53e6\u4e00\u79cd\u5199\u6cd5\uff0c\u53ef\u4ee5\u7528\u66f4\u7d27\u51d1\u3001\u6807\u51c6\u7684\u5f62\u5f0f\u8868\u793a\u4e0a\u8ff0\u90e8\u5206 LDAP \u9009\u9879\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapurl</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4e00\u4e2a<a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc4516\" target=\"_top\">RFC 4516</a> LDAP URL\u3002\u683c\u5f0f\u4e3a</p>\n<pre class=\"synopsis\">ldap[s]://<em class=\"replaceable\"><code>host</code></em>[:<em class=\"replaceable\"><code>port</code></em>]/<em class=\"replaceable\"><code>basedn</code></em>[?[<em class=\"replaceable\"><code>attribute</code></em>][?[<em class=\"replaceable\"><code>scope</code></em>][?[<em class=\"replaceable\"><code>filter</code></em>]]]]\n</pre>\n<p lang=\"zh\"><em class=\"replaceable\"><code>scope</code></em>\u5fc5\u987b\u662f<code class=\"literal\">base</code>\u3001<code class=\"literal\">one</code>\u3001<code class=\"literal\">sub</code>\u4e2d\u7684\u4e00\u4e2a\uff0c\u901a\u5e38\u662f\u6700\u540e\u4e00\u4e2a\u3002\uff08\u9ed8\u8ba4\u4e3a<code class=\"literal\">base</code>\uff0c\u5728\u6b64\u5e94\u7528\u4e2d\u901a\u5e38\u65e0\u7528\u3002\uff09<em class=\"replaceable\"><code>attribute</code></em>\u53ef\u4ee5\u6307\u5b9a\u5355\u4e2a\u5c5e\u6027\uff0c\u6b64\u65f6\u5c06\u7528\u4f5c<code class=\"literal\">ldapsearchattribute</code>\u7684\u503c\u3002\u5982\u679c<em class=\"replaceable\"><code>attribute</code></em>\u4e3a\u7a7a\uff0c\u5219<em class=\"replaceable\"><code>filter</code></em>\u53ef\u7528\u4f5c<code class=\"literal\">ldapsearchfilter</code>\u7684\u503c\u3002</p>\n<p lang=\"zh\">URL \u65b9\u6848 ldaps \u9009\u62e9\u901a\u8fc7 SSL \u5efa\u7acb LDAP \u8fde\u63a5\u7684 LDAPS \u65b9\u5f0f\uff0c\u7b49\u4ef7\u4e8e ldapscheme=ldaps\u3002\u8981\u901a\u8fc7 StartTLS \u4f7f\u7528\u52a0\u5bc6 LDAP \u8fde\u63a5\uff0c\u5e94\u4f7f\u7528\u666e\u901a\u7684 ldap URL \u65b9\u6848\uff0c\u5e76\u5728 ldapurl \u4e4b\u5916\u6307\u5b9a ldaptls\u3002</p>\n<p lang=\"zh\">\u5bf9\u4e8e\u975e\u533f\u540d\u7ed1\u5b9a\uff0c\u5fc5\u987b\u5c06<code class=\"literal\">ldapbinddn</code>\u548c<code class=\"literal\">ldapbindpasswd</code>\u6307\u5b9a\u4e3a\u5355\u72ec\u7684\u9009\u9879\u3002</p>\n<p lang=\"zh\">LDAP URL\u76ee\u524d\u4ec5\u53d7<span class=\"productname\">OpenLDAP</span>\u652f\u6301\uff0c\u4e0d\u652f\u6301Windows\u3002</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u5c06\u7b80\u5355\u7ed1\u5b9a\u9009\u9879\u4e0e\u641c\u7d22+\u7ed1\u5b9a\u9009\u9879\u6df7\u7528\u662f\u9519\u8bef\u7684\u3002\u82e5\u8981\u5728\u7b80\u5355\u7ed1\u5b9a\u6a21\u5f0f\u4e0b\u4f7f\u7528 <code class=\"literal\">ldapurl</code>\uff0c\u8be5 URL \u4e2d\u4e0d\u80fd\u5305\u542b <code class=\"literal\">basedn</code> \u6216\u67e5\u8be2\u5143\u7d20\u3002</p>\n<p lang=\"zh\">\u5728\u4f7f\u7528\u641c\u7d22+\u7ed1\u5b9a\u6a21\u5f0f\u65f6\uff0c\u53ef\u4ee5\u4f7f\u7528\u7531 <code class=\"literal\">ldapsearchattribute</code> \u6307\u5b9a\u7684\u5355\u4e2a\u5c5e\u6027\u6267\u884c\u641c\u7d22\uff0c\u4e5f\u53ef\u4ee5\u4f7f\u7528\u7531 <code class=\"literal\">ldapsearchfilter</code> \u6307\u5b9a\u7684\u81ea\u5b9a\u4e49\u641c\u7d22\u8fc7\u6ee4\u5668\u6267\u884c\u641c\u7d22\u3002\u6307\u5b9a <code class=\"literal\">ldapsearchattribute=foo</code> \u7b49\u4ef7\u4e8e\u6307\u5b9a <code class=\"literal\">ldapsearchfilter=\"(foo=$username)\"</code>\u3002\u5982\u679c\u4e24\u4e2a\u9009\u9879\u90fd\u672a\u6307\u5b9a\uff0c\u5219\u9ed8\u8ba4\u4f7f\u7528 <code class=\"literal\">ldapsearchattribute=uid</code>\u3002</p>\n<p lang=\"zh\">\u5982\u679c <span class=\"productname\">PostgreSQL</span> \u7f16\u8bd1\u65f6\u4f7f\u7528\u4e86 <span class=\"productname\">OpenLDAP</span> \u4f5c\u4e3a LDAP \u5ba2\u6237\u7aef\u5e93\uff0c\u5219\u53ef\u4ee5\u7701\u7565 <code class=\"literal\">ldapserver</code> \u8bbe\u7f6e\u3002\u5728\u8fd9\u79cd\u60c5\u51b5\u4e0b\uff0c\u4f1a\u901a\u8fc7 <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc2782\" target=\"_top\">RFC 2782</a> DNS SRV \u8bb0\u5f55\u67e5\u627e\u4e3b\u673a\u540d\u548c\u7aef\u53e3\u5217\u8868\u3002\u67e5\u627e\u7684\u540d\u79f0\u662f <code class=\"literal\">_ldap._tcp.DOMAIN</code>\uff0c\u5176\u4e2d <code class=\"literal\">DOMAIN</code> \u4ece <code class=\"literal\">ldapbasedn</code> \u4e2d\u63d0\u53d6\u3002</p>\n<p lang=\"zh\">\u4e0b\u9762\u662f\u4e00\u4e2a\u7b80\u5355\u7ed1\u5b9a LDAP \u914d\u7f6e\u793a\u4f8b\uff1a</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapprefix=\"cn=\" ldapsuffix=\", dc=example, dc=net\"\n</pre>\n<p lang=\"zh\">\u5f53\u8bf7\u6c42\u4ee5\u6570\u636e\u5e93\u7528\u6237 <code class=\"literal\">someuser</code> \u8fde\u63a5\u6570\u636e\u5e93\u670d\u52a1\u5668\u65f6\uff0cPostgreSQL \u5c06\u5c1d\u8bd5\u4f7f\u7528 DN <code class=\"literal\">cn=someuser, dc=example, dc=net</code> \u548c\u5ba2\u6237\u7aef\u63d0\u4f9b\u7684\u5bc6\u7801\u7ed1\u5b9a\u5230 LDAP \u670d\u52a1\u5668\u3002\u5982\u679c\u8be5\u8fde\u63a5\u6210\u529f\uff0c\u6570\u636e\u5e93\u8bbf\u95ee\u5c31\u4f1a\u88ab\u6388\u4e88\u3002</p>\n<p lang=\"zh\">\u4e0b\u9762\u662f\u53e6\u4e00\u79cd\u7b80\u5355\u7ed1\u5b9a\u914d\u7f6e\uff0c\u5b83\u4f7f\u7528 LDAPS \u65b9\u6848\u548c\u81ea\u5b9a\u4e49\u7aef\u53e3\u53f7\uff0c\u5e76\u4ee5 URL \u5f62\u5f0f\u5199\u51fa\uff1a</p>\n<pre class=\"programlisting\">host ... ldap ldapurl=\"ldaps://ldap.example.net:49151\" ldapprefix=\"cn=\" ldapsuffix=\", dc=example, dc=net\"\n</pre>\n<p lang=\"zh\">\u8fd9\u79cd\u5199\u6cd5\u6bd4\u5355\u72ec\u6307\u5b9a <code class=\"literal\">ldapserver</code>\u3001<code class=\"literal\">ldapscheme</code> \u548c <code class=\"literal\">ldapport</code> \u7a0d\u5fae\u66f4\u7d27\u51d1\u3002</p>\n<p lang=\"zh\">\u4e0b\u9762\u662f\u4e00\u4e2a\u641c\u7d22+\u7ed1\u5b9a\u914d\u7f6e\u793a\u4f8b\uff1a</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapbasedn=\"dc=example, dc=net\" ldapsearchattribute=uid\n</pre>\n<p lang=\"zh\">\u5f53\u8bf7\u6c42\u4ee5\u6570\u636e\u5e93\u7528\u6237 <code class=\"literal\">someuser</code> \u8fde\u63a5\u6570\u636e\u5e93\u670d\u52a1\u5668\u65f6\uff0cPostgreSQL \u5c06\u5c1d\u8bd5\u5bf9 LDAP \u670d\u52a1\u5668\u8fdb\u884c\u533f\u540d\u7ed1\u5b9a\uff08\u56e0\u4e3a\u672a\u6307\u5b9a <code class=\"literal\">ldapbinddn</code>\uff09\uff0c\u5e76\u5728\u6307\u5b9a\u7684\u57fa\u7840 DN \u4e0b\u6267\u884c\u4e00\u6b21 <code class=\"literal\">(uid=someuser)</code> \u641c\u7d22\u3002\u5982\u679c\u627e\u5230\u4e86\u5bf9\u5e94\u6761\u76ee\uff0c\u968f\u540e\u5c31\u4f1a\u5c1d\u8bd5\u4f7f\u7528\u8be5\u6761\u76ee\u7684\u4fe1\u606f\u4ee5\u53ca\u5ba2\u6237\u7aef\u63d0\u4f9b\u7684\u5bc6\u7801\u8fdb\u884c\u7ed1\u5b9a\u3002\u5982\u679c\u7b2c\u4e8c\u6b21\u7ed1\u5b9a\u6210\u529f\uff0c\u6570\u636e\u5e93\u8bbf\u95ee\u5c31\u4f1a\u88ab\u6388\u4e88\u3002</p>\n<p lang=\"zh\">\u4e0b\u9762\u662f\u4ee5 URL \u5f62\u5f0f\u5199\u51fa\u7684\u540c\u4e00\u4e2a\u641c\u7d22+\u7ed1\u5b9a\u914d\u7f6e\uff1a</p>\n<pre class=\"programlisting\">host ... ldap ldapurl=\"ldap://ldap.example.net/dc=example,dc=net?uid?sub\"\n</pre>\n<p lang=\"zh\">\u67d0\u4e9b\u652f\u6301 LDAP \u8ba4\u8bc1\u7684\u5176\u4ed6\u8f6f\u4ef6\u4e5f\u4f7f\u7528\u76f8\u540c\u7684 URL \u683c\u5f0f\uff0c\u56e0\u6b64\u5171\u4eab\u8fd9\u7c7b\u914d\u7f6e\u4f1a\u66f4\u5bb9\u6613\u3002</p>\n<p lang=\"zh\">\u8fd9\u91cc\u662f\u4e00\u4e2a\u641c\u7d22+\u7ed1\u5b9a\u914d\u7f6e\u7684\u793a\u4f8b\uff0c\u5b83\u4f7f\u7528 <code class=\"literal\">ldapsearchfilter</code> \u800c\u4e0d\u662f <code class=\"literal\">ldapsearchattribute</code> \u6765\u5141\u8bb8\u7528\u7528\u6237 ID \u6216\u7535\u5b50\u90ae\u4ef6\u5730\u5740\u8fdb\u884c\u8ba4\u8bc1\uff1a</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapbasedn=\"dc=example, dc=net\" ldapsearchfilter=\"(|(uid=$username)(mail=$username))\"\n</pre>\n<p lang=\"zh\">\u8fd9\u662f\u4e00\u4e2a\u641c\u7d22+\u7ed1\u5b9a\u914d\u7f6e\u7684\u793a\u4f8b\uff0c\u5b83\u4f7f\u7528 DNS SRV \u53d1\u73b0\u6765\u67e5\u627e\u57df\u540d <code class=\"literal\">example.net</code> \u7684 LDAP \u670d\u52a1\u7684\u4e3b\u673a\u540d\u548c\u7aef\u53e3\u3002</p>\n<pre class=\"programlisting\">host ... ldap ldapbasedn=\"dc=example,dc=net\"\n</pre>\n<div class=\"tip\">\n<h3 class=\"title\" lang=\"zh\">\u63d0\u793a</h3>\n<p lang=\"zh\">\u5982\u793a\u4f8b\u4e2d\u6240\u793a\uff0c\u7531\u4e8e LDAP \u901a\u5e38\u4f7f\u7528\u9017\u53f7\u548c\u7a7a\u683c\u6765\u5206\u9694\u4e00\u4e2a DN \u7684\u4e0d\u540c\u90e8\u5206\uff0c\u5728\u914d\u7f6e LDAP \u9009\u9879\u65f6\u901a\u5e38\u6709\u5fc5\u8981\u4f7f\u7528\u53cc\u5f15\u53f7\u5305\u56f4\u7684\u53c2\u6570\u503c\u3002</p>\n</div>\n</div>", "manual_path": "/docs/devel/auth-ldap.html", "localization": {"status": "complete", "sources": [{"url": "/docs/devel/auth-ldap.html", "method": "same-major semantic node", "sha256": "90b4bbeb9c3af769a0aecd260ad7086f4fd979051ac448d3dd9509fdcc628118", "language": "zh", "matched_nodes": ["#AUTH-LDAP/div[0]", "#AUTH-LDAP/div[11]/dl[0]/dd[1]", "#AUTH-LDAP/div[11]/dl[0]/dd[3]", "#AUTH-LDAP/div[11]/dl[0]/dd[5]", "#AUTH-LDAP/div[11]/dl[0]/dd[7]", "#AUTH-LDAP/div[11]/dl[0]/dd[9]", "#AUTH-LDAP/div[13]/dl[0]/dd[1]/p[0]", "#AUTH-LDAP/div[13]/dl[0]/dd[1]/p[2]", "#AUTH-LDAP/div[13]/dl[0]/dd[1]/p[4]", "#AUTH-LDAP/div[13]/dl[0]/dd[1]/p[5]", "#AUTH-LDAP/div[33]/h3[0]", "#AUTH-LDAP/div[33]/p[1]", "#AUTH-LDAP/div[6]/dl[0]/dd[1]", "#AUTH-LDAP/div[6]/dl[0]/dd[3]", "#AUTH-LDAP/div[6]/dl[0]/dd[5]", "#AUTH-LDAP/div[9]/dl[0]/dd[1]", "#AUTH-LDAP/div[9]/dl[0]/dd[3]", "#AUTH-LDAP/p[10]", "#AUTH-LDAP/p[12]", "#AUTH-LDAP/p[14]", "#AUTH-LDAP/p[15]", "#AUTH-LDAP/p[16]", "#AUTH-LDAP/p[17]", "#AUTH-LDAP/p[19]", "#AUTH-LDAP/p[20]", "#AUTH-LDAP/p[22]", "#AUTH-LDAP/p[23]", "#AUTH-LDAP/p[25]", "#AUTH-LDAP/p[26]", "#AUTH-LDAP/p[28]", "#AUTH-LDAP/p[29]", "#AUTH-LDAP/p[2]", "#AUTH-LDAP/p[31]", "#AUTH-LDAP/p[3]", "#AUTH-LDAP/p[4]", "#AUTH-LDAP/p[5]", "#AUTH-LDAP/p[7]", "#AUTH-LDAP/p[8]"]}], "language": "zh", "original_text": {"/summary": "Authenticate using an LDAP server. See Section 20.10 for details.", "/category": "Authentication and access control", "/versions/20/description/0": "Authenticate using an LDAP server. See Section 20.10 for details.", "/versions/20/facts/0/label": "Method", "/versions/20/facts/1/label": "Configuration", "/versions/20/facts/2/label": "Inventory", "/versions/20/facts/2/value": "User-visible source authentication method", "/versions/20/tables/0/title": "Documented method options and alternatives", "/versions/20/tables/0/columns/0/label": "Option or term", "/versions/20/tables/0/columns/1/label": "Meaning", "/versions/20/tables/0/rows/0/description": "Names or IP addresses of LDAP servers to connect to. Multiple servers may be specified, separated by spaces.", "/versions/20/tables/0/rows/1/description": "Port number on LDAP server to connect to. If no port is specified, the LDAP library's default port setting will be used.", "/versions/20/tables/0/rows/2/description": "Set to ldaps to use LDAPS. This is a non-standard way of using LDAP over SSL, supported by some LDAP server implementations. See also the ldaptls option for an alternative.", "/versions/20/tables/0/rows/3/description": "Set to 1 to make the connection between PostgreSQL and the LDAP server use TLS encryption. This uses the StartTLS operation per RFC 4513 . See also the ldapscheme option for an alternative.", "/versions/20/tables/0/rows/4/description": "String to prepend to the user name when forming the DN to bind as, when doing simple bind authentication.", "/versions/20/tables/0/rows/5/description": "String to append to the user name when forming the DN to bind as, when doing simple bind authentication.", "/versions/20/tables/0/rows/6/description": "Root DN to begin the search for the user in, when doing search+bind authentication.", "/versions/20/tables/0/rows/7/description": "DN of user to bind to the directory with to perform the search when doing search+bind authentication.", "/versions/20/tables/0/rows/8/description": "Password for user to bind to the directory with to perform the search when doing search+bind authentication.", "/versions/20/tables/0/rows/9/description": "Attribute to match against the user name in the search when doing search+bind authentication. If no attribute is specified, the uid attribute will be used.", "/versions/20/tables/0/rows/10/description": "The search filter to use when doing search+bind authentication. Occurrences of $username will be replaced with the user name. This allows for more flexible search filters than ldapsearchattribute .", "/versions/20/tables/0/rows/11/description": "An RFC 4516 LDAP URL. The format is ldap[s]:// host [: port ]/ basedn [?[ attribute ][?[ scope ][?[ filter ]]]] scope must be one of base , one , sub , typically the last. (The default is base , which is normally not useful in this application.) attribute can nominate a single attribute, in which case it is used as a value for ldapsearchattribute . If attribute is empty then filter can be used as a value for ldapsearchfilter . The URL scheme ldaps chooses the LDAPS method for making LDAP connections over SSL, equivalent to using ldapscheme=ldaps . To use encrypted LDAP connections using the StartTLS operation, use the normal URL scheme ldap and specify the ldaptls option in addition to ldapurl . For non-anonymous binds, ldapbinddn and ldapbindpasswd must be specified as separate options. LDAP URLs are currently only supported with OpenLDAP , not on Windows."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "91ef48555387aa22b26205331f03130249f8d0d567f8fcf20c65d45a27f92d31"}, "comparison_data": {"method": "ldap", "documented_option_names": ["ldapbasedn", "ldapbinddn", "ldapbindpasswd", "ldapport", "ldapprefix", "ldapscheme", "ldapsearchattribute", "ldapsearchfilter", "ldapserver", "ldapsuffix", "ldaptls", "ldapurl"]}, "comparison_hash": "d40de945ae67b3ac60a284fdd442cc24a4e9d05bc7a7b18009b54e491c381b88", "manual_language": "zh"}}}, "snapshot": {"facts": [{"label": "\u65b9\u6cd5", "value": "ldap"}, {"label": "\u914d\u7f6e", "value": "pg_hba.conf"}, {"label": "\u6e05\u5355", "value": "\u7528\u6237\u53ef\u89c1\u7684\u6e90\u7801\u8ba4\u8bc1\u65b9\u6cd5"}], "tables": [{"key": "method-options", "rows": [{"name": "ldapserver", "description": "\u8981\u8fde\u63a5\u7684LDAP\u670d\u52a1\u5668\u7684\u540d\u79f0\u6216IP\u5730\u5740\u3002\u53ef\u4ee5\u6307\u5b9a\u591a\u4e2a\u670d\u52a1\u5668\uff0c\u7528\u7a7a\u683c\u5206\u9694\u3002"}, {"name": "ldapport", "description": "\u8981\u8fde\u63a5\u7684LDAP\u670d\u52a1\u5668\u7684\u7aef\u53e3\u53f7\u3002\u5982\u679c\u672a\u6307\u5b9a\u7aef\u53e3\uff0c\u5219\u5c06\u4f7f\u7528LDAP\u5e93\u7684\u9ed8\u8ba4\u7aef\u53e3\u8bbe\u7f6e\u3002"}, {"name": "ldapscheme", "description": "\u8bbe\u7f6e\u4e3a ldaps \u4ee5\u4f7f\u7528LDAPS\u3002\u8fd9\u662f\u4e00\u79cd\u975e\u6807\u51c6\u7684\u901a\u8fc7 SSL \u4f7f\u7528 LDAP \u7684\u65b9\u5f0f\uff0c\u53d7\u4e00\u4e9bLDAP\u670d\u52a1\u5668\u5b9e\u73b0\u652f\u6301\u3002\u53e6\u8bf7\u53c2\u9605 ldaptls \u9009\u9879\u4f5c\u4e3a\u66ff\u4ee3\u3002"}, {"name": "ldaptls", "description": "\u8bbe\u7f6e\u4e3a 1 \u65f6\uff0cPostgreSQL \u4e0e LDAP \u670d\u52a1\u5668\u4e4b\u95f4\u7684\u8fde\u63a5\u4f7f\u7528 TLS \u52a0\u5bc6\uff0c\u901a\u8fc7 RFC 4513 \u89c4\u5b9a\u7684 StartTLS \u64cd\u4f5c\u5b9e\u73b0\u3002\u53e6\u53ef\u53c2\u89c1 ldapscheme \u9009\u9879\u6240\u63d0\u4f9b\u7684\u66ff\u4ee3\u65b9\u5f0f\u3002"}, {"name": "ldapprefix", "description": "\u5728\u8fdb\u884c\u7b80\u5355\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u9644\u52a0\u5230\u7528\u6237\u540d\u524d\u9762\u4ee5\u5f62\u6210\u7ed1\u5b9a DN \u7684\u5b57\u7b26\u4e32\u3002"}, {"name": "ldapsuffix", "description": "\u5728\u8fdb\u884c\u7b80\u5355\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u9644\u52a0\u5230\u7528\u6237\u540d\u540e\u9762\u4ee5\u5f62\u6210\u7ed1\u5b9a DN \u7684\u5b57\u7b26\u4e32\u3002"}, {"name": "ldapbasedn", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4f5c\u7528\u6237\u641c\u7d22\u8d77\u70b9\u7684\u6839 DN\u3002"}, {"name": "ldapbinddn", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u7ed1\u5b9a\u5230\u76ee\u5f55\u5e76\u6267\u884c\u641c\u7d22\u7684\u7528\u6237 DN\u3002"}, {"name": "ldapbindpasswd", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u7ed1\u5b9a\u5230\u76ee\u5f55\u5e76\u6267\u884c\u641c\u7d22\u7684\u7528\u6237\u5bc6\u7801\u3002"}, {"name": "ldapsearchattribute", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u4e0e\u7528\u6237\u540d\u5339\u914d\u7684\u5c5e\u6027\u3002\u5982\u679c\u672a\u6307\u5b9a\u5c5e\u6027\uff0c\u5219\u4f1a\u4f7f\u7528 uid \u5c5e\u6027\u3002"}, {"name": "ldapsearchfilter", "description": "\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\u4f7f\u7528\u7684\u641c\u7d22\u8fc7\u6ee4\u5668\u3002\u5176\u4e2d\u51fa\u73b0\u7684 $username \u4f1a\u88ab\u66ff\u6362\u4e3a\u7528\u6237\u540d\u3002\u8fd9\u4f7f\u5f97\u641c\u7d22\u8fc7\u6ee4\u5668\u6bd4 ldapsearchattribute \u66f4\u7075\u6d3b\u3002"}, {"name": "ldapurl", "description": "\u7b26\u5408 RFC 4516 \u7684 LDAP URL\u3002\u683c\u5f0f\u4e3a ldap[s]://host[:port]/basedn[?[attribute][?[scope][?[filter]]]]\u3002scope \u5fc5\u987b\u4e3a base\u3001one \u6216 sub\uff0c\u901a\u5e38\u4f7f\u7528 sub\uff1b\u9ed8\u8ba4\u503c base \u5728\u6b64\u7528\u9014\u4e0b\u4e00\u822c\u6ca1\u6709\u5b9e\u9645\u5e2e\u52a9\u3002attribute \u53ef\u6307\u5b9a\u4e00\u4e2a\u5c5e\u6027\uff0c\u4f5c\u4e3a ldapsearchattribute \u7684\u503c\uff1battribute \u4e3a\u7a7a\u65f6\uff0cfilter \u53ef\u7528\u4f5c ldapsearchfilter \u7684\u503c\u3002URL \u65b9\u6848 ldaps \u8868\u793a\u901a\u8fc7 SSL \u5efa\u7acb LDAP \u8fde\u63a5\uff0c\u7b49\u540c\u4e8e ldapscheme=ldaps\u3002\u82e5\u8981\u901a\u8fc7 StartTLS \u4f7f\u7528\u52a0\u5bc6 LDAP \u8fde\u63a5\uff0c\u5e94\u4f7f\u7528\u666e\u901a\u7684 ldap URL \u65b9\u6848\uff0c\u5e76\u5728 ldapurl \u4e4b\u5916\u6307\u5b9a ldaptls\u3002\u5bf9\u4e8e\u975e\u533f\u540d\u7ed1\u5b9a\uff0c\u5fc5\u987b\u53e6\u884c\u6307\u5b9a ldapbinddn \u548c ldapbindpasswd\u3002LDAP URL \u76ee\u524d\u4ec5\u5728 OpenLDAP \u4e2d\u53d7\u652f\u6301\uff0cWindows \u4e0d\u652f\u6301\u3002"}], "title": "\u624b\u518c\u4e2d\u7684\u65b9\u6cd5\u9009\u9879\u4e0e\u66ff\u4ee3\u65b9\u5f0f", "columns": [{"key": "name", "label": "\u9009\u9879\u6216\u672f\u8bed"}, {"key": "description", "label": "\u542b\u4e49"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "label": "18.6", "major": "18", "channel": "stable", "revision": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f", "source_sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f", "catalog_fingerprint": "65c93d6048ef30e61023a84f9680fa6a92b1c383b7eb226741170077eb078502"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"}, {"url": "https://pg.center/docs/18/auth-ldap.html", "path": "auth-ldap.html", "label": "PostgreSQL 18 English manual", "sha256": "8f02f50758b63b0d9a9011b2c3c1ee12e8caa3830408f5ea5d97e0e81ee52628", "language": "en", "original_url": "/docs/18/auth-ldap.html"}, {"url": "https://pg.center/docs/18/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 18 English manual", "sha256": "6340d4abea2e0a3482afc31bcd1599a0fa10dc28a6f1e05d79ba831e2dd0b4c9", "language": "en", "original_url": "/docs/18/auth-pg-hba-conf.html"}], "sections": [], "signature": "", "attributes": {"method": "ldap", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["\u4f7f\u7528 LDAP \u670d\u52a1\u5668\u8fdb\u884c\u8ba4\u8bc1\u3002\u8be6\u60c5\u53c2\u89c1\u7b2c 20.10 \u8282\u3002"], "manual_html": "<div class=\"sect1\" id=\"AUTH-LDAP\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\" lang=\"zh\">\n<div>\n<div>\n<h2 class=\"title\" style=\"clear: both\">20.10.\u00a0LDAP \u8ba4\u8bc1 </h2>\n</div>\n</div>\n</h2>\n</div>\n</div>\n</div>\n<p lang=\"zh\">\u8fd9\u79cd\u8ba4\u8bc1\u65b9\u6cd5\u7684\u5de5\u4f5c\u65b9\u5f0f\u4e0e <code class=\"literal\">password</code> \u7c7b\u4f3c\uff0c\u53ea\u4e0d\u8fc7\u5b83\u4f7f\u7528 LDAP \u4f5c\u4e3a\u5bc6\u7801\u9a8c\u8bc1\u65b9\u6cd5\u3002LDAP \u53ea\u7528\u4e8e\u9a8c\u8bc1\u7528\u6237\u540d/\u5bc6\u7801\u5bf9\u3002\u56e0\u6b64\uff0c\u5728\u4f7f\u7528 LDAP \u8fdb\u884c\u8ba4\u8bc1\u4e4b\u524d\uff0c\u7528\u6237\u5fc5\u987b\u5df2\u7ecf\u5b58\u5728\u4e8e\u6570\u636e\u5e93\u4e2d\u3002</p>\n<p lang=\"zh\">LDAP \u8ba4\u8bc1\u53ef\u4ee5\u5728\u4e24\u79cd\u6a21\u5f0f\u4e0b\u5de5\u4f5c\u3002\u7b2c\u4e00\u79cd\u6a21\u5f0f\u79f0\u4e3a\u7b80\u5355\u7ed1\u5b9a\u6a21\u5f0f\uff0c\u670d\u52a1\u5668\u4f1a\u7ed1\u5b9a\u5230\u6309 <em class=\"replaceable\"><code>prefix</code></em> <em class=\"replaceable\"><code>username</code></em> <em class=\"replaceable\"><code>suffix</code></em> \u5f62\u5f0f\u6784\u9020\u51fa\u7684\u53ef\u5206\u8fa8\u540d\u79f0\u3002\u901a\u5e38\uff0c<em class=\"replaceable\"><code>prefix</code></em> \u53c2\u6570\u7528\u4e8e\u6307\u5b9a <code class=\"literal\">cn=</code>\uff0c\u6216\u5728 Active Directory \u73af\u5883\u4e2d\u6307\u5b9a <em class=\"replaceable\"><code>DOMAIN</code></em><code class=\"literal\">\\</code>\u3002<em class=\"replaceable\"><code>suffix</code></em> \u5219\u7528\u4e8e\u6307\u5b9a\u975e Active Directory \u73af\u5883\u4e2d DN \u7684\u5269\u4f59\u90e8\u5206\u3002</p>\n<p lang=\"zh\">\u7b2c\u4e8c\u79cd\u6a21\u5f0f\u79f0\u4e3a\u641c\u7d22+\u7ed1\u5b9a\u6a21\u5f0f\uff0c\u670d\u52a1\u5668\u9996\u5148\u4f7f\u7528\u7531 <em class=\"replaceable\"><code>ldapbinddn</code></em> \u548c <em class=\"replaceable\"><code>ldapbindpasswd</code></em> \u6307\u5b9a\u7684\u56fa\u5b9a\u7528\u6237\u540d\u548c\u5bc6\u7801\u7ed1\u5b9a\u5230 LDAP \u76ee\u5f55\uff0c\u5e76\u641c\u7d22\u8bd5\u56fe\u767b\u5f55\u6570\u636e\u5e93\u7684\u7528\u6237\u3002\u5982\u679c\u6ca1\u6709\u914d\u7f6e\u7528\u6237\u540d\u548c\u5bc6\u7801\uff0c\u5219\u4f1a\u5c1d\u8bd5\u5bf9\u76ee\u5f55\u8fdb\u884c\u533f\u540d\u7ed1\u5b9a\u3002\u641c\u7d22\u4f1a\u5728 <em class=\"replaceable\"><code>ldapbasedn</code></em> \u6307\u5b9a\u7684\u5b50\u6811\u4e0a\u8fdb\u884c\uff0c\u5e76\u5c1d\u8bd5\u5bf9 <em class=\"replaceable\"><code>ldapsearchattribute</code></em> \u6307\u5b9a\u7684\u5c5e\u6027\u505a\u7cbe\u786e\u5339\u914d\u3002\u4e00\u65e6\u5728\u641c\u7d22\u4e2d\u627e\u5230\u4e86\u8be5\u7528\u6237\uff0c\u670d\u52a1\u5668\u5c31\u4f1a\u4f5c\u4e3a\u8be5\u7528\u6237\u91cd\u65b0\u7ed1\u5b9a\u5230\u76ee\u5f55\uff0c\u5e76\u4f7f\u7528\u5ba2\u6237\u7aef\u6307\u5b9a\u7684\u5bc6\u7801\u6765\u9a8c\u8bc1\u767b\u5f55\u662f\u5426\u6b63\u786e\u3002\u8fd9\u79cd\u6a21\u5f0f\u4e0e Apache <code class=\"literal\">mod_authnz_ldap</code> \u548c <code class=\"literal\">pam_ldap</code> \u7b49\u8f6f\u4ef6\u4e2d\u7684 LDAP \u8ba4\u8bc1\u65b9\u6848\u76f8\u540c\u3002\u8fd9\u79cd\u65b9\u6cd5\u4f7f\u76ee\u5f55\u4e2d\u7528\u6237\u5bf9\u8c61\u7684\u4f4d\u7f6e\u66f4\u5177\u7075\u6d3b\u6027\uff0c\u4f46\u4f1a\u5bf9 LDAP \u670d\u52a1\u5668\u989d\u5916\u53d1\u8d77\u4e24\u6b21\u8bf7\u6c42\u3002</p>\n<p lang=\"zh\">\u4ee5\u4e0b\u914d\u7f6e\u9009\u9879\u5728\u4e24\u79cd\u6a21\u5f0f\u4e0b\u90fd\u4f7f\u7528\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapserver</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8981\u8fde\u63a5\u7684LDAP\u670d\u52a1\u5668\u7684\u540d\u79f0\u6216IP\u5730\u5740\u3002\u53ef\u4ee5\u6307\u5b9a\u591a\u4e2a\u670d\u52a1\u5668\uff0c\u7528\u7a7a\u683c\u5206\u9694\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapport</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8981\u8fde\u63a5\u7684LDAP\u670d\u52a1\u5668\u7684\u7aef\u53e3\u53f7\u3002\u5982\u679c\u672a\u6307\u5b9a\u7aef\u53e3\uff0c\u5219\u5c06\u4f7f\u7528LDAP\u5e93\u7684\u9ed8\u8ba4\u7aef\u53e3\u8bbe\u7f6e\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapscheme</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8bbe\u7f6e\u4e3a<code class=\"literal\">ldaps</code>\u4ee5\u4f7f\u7528LDAPS\u3002\u8fd9\u662f\u4e00\u79cd\u975e\u6807\u51c6\u7684\u901a\u8fc7 SSL \u4f7f\u7528 LDAP \u7684\u65b9\u5f0f\uff0c\u53d7\u4e00\u4e9bLDAP\u670d\u52a1\u5668\u5b9e\u73b0\u652f\u6301\u3002\u53e6\u8bf7\u53c2\u9605<code class=\"literal\">ldaptls</code> \u9009\u9879\u4f5c\u4e3a\u66ff\u4ee3\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldaptls</code></span></dt>\n<dd>\n<p lang=\"zh\">\u8bbe\u7f6e\u4e3a 1 \u65f6\uff0cPostgreSQL \u4e0e LDAP \u670d\u52a1\u5668\u4e4b\u95f4\u7684\u8fde\u63a5\u4f7f\u7528 TLS \u52a0\u5bc6\uff0c\u901a\u8fc7 RFC 4513 \u89c4\u5b9a\u7684 StartTLS \u64cd\u4f5c\u5b9e\u73b0\u3002\u53e6\u53ef\u53c2\u89c1 ldapscheme \u9009\u9879\u6240\u63d0\u4f9b\u7684\u66ff\u4ee3\u65b9\u5f0f\u3002</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u6ce8\u610f\u4f7f\u7528<code class=\"literal\">ldapscheme</code>\u6216<code class=\"literal\">ldaptls</code>\u4ec5\u4f1a\u52a0\u5bc6PostgreSQL \u670d\u52a1\u5668\u548cLDAP\u670d\u52a1\u5668\u4e4b\u95f4\u7684\u901a\u4fe1\u3002PostgreSQL \u670d\u52a1\u5668\u548cPostgreSQL\u5ba2\u6237\u7aef\u4e4b\u95f4\u7684\u8fde\u63a5\u4ecd\u662f\u672a\u52a0\u5bc6\u7684\uff0c\u9664\u975e\u4e5f\u5728\u5176\u4e0a\u4f7f\u7528SSL\u3002</p>\n<p lang=\"zh\">\u4e0b\u5217\u9009\u9879\u53ea\u88ab\u7528\u4e8e\u7b80\u5355\u7ed1\u5b9a\u6a21\u5f0f\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapprefix</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u7b80\u5355\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u9644\u52a0\u5230\u7528\u6237\u540d\u524d\u9762\u4ee5\u5f62\u6210\u7ed1\u5b9a DN \u7684\u5b57\u7b26\u4e32\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsuffix</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u7b80\u5355\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u9644\u52a0\u5230\u7528\u6237\u540d\u540e\u9762\u4ee5\u5f62\u6210\u7ed1\u5b9a DN \u7684\u5b57\u7b26\u4e32\u3002</p>\n</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u4ee5\u4e0b\u9009\u9879\u4ec5\u5728\u641c\u7d22+\u7ed1\u5b9a\u6a21\u5f0f\u4e2d\u4f7f\u7528\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapbasedn</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4f5c\u7528\u6237\u641c\u7d22\u8d77\u70b9\u7684\u6839 DN\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapbinddn</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u7ed1\u5b9a\u5230\u76ee\u5f55\u5e76\u6267\u884c\u641c\u7d22\u7684\u7528\u6237 DN\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapbindpasswd</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u7ed1\u5b9a\u5230\u76ee\u5f55\u5e76\u6267\u884c\u641c\u7d22\u7684\u7528\u6237\u5bc6\u7801\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsearchattribute</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\uff0c\u7528\u4e8e\u4e0e\u7528\u6237\u540d\u5339\u914d\u7684\u5c5e\u6027\u3002\u5982\u679c\u672a\u6307\u5b9a\u5c5e\u6027\uff0c\u5219\u4f1a\u4f7f\u7528 <code class=\"literal\">uid</code> \u5c5e\u6027\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsearchfilter</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8fdb\u884c\u641c\u7d22+\u7ed1\u5b9a\u8ba4\u8bc1\u65f6\u4f7f\u7528\u7684\u641c\u7d22\u8fc7\u6ee4\u5668\u3002\u5176\u4e2d\u51fa\u73b0\u7684 <code class=\"literal\">$username</code> \u4f1a\u88ab\u66ff\u6362\u4e3a\u7528\u6237\u540d\u3002\u8fd9\u4f7f\u5f97\u641c\u7d22\u8fc7\u6ee4\u5668\u6bd4 <code class=\"literal\">ldapsearchattribute</code> \u66f4\u7075\u6d3b\u3002</p>\n</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u4ee5\u4e0b\u9009\u9879\u63d0\u4f9b\u4e86\u53e6\u4e00\u79cd\u5199\u6cd5\uff0c\u53ef\u4ee5\u7528\u66f4\u7d27\u51d1\u3001\u6807\u51c6\u7684\u5f62\u5f0f\u8868\u793a\u4e0a\u8ff0\u90e8\u5206 LDAP \u9009\u9879\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapurl</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4e00\u4e2a<a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc4516\" target=\"_top\">RFC 4516</a> LDAP URL\u3002\u683c\u5f0f\u4e3a</p>\n<pre class=\"synopsis\">ldap[s]://<em class=\"replaceable\"><code>host</code></em>[:<em class=\"replaceable\"><code>port</code></em>]/<em class=\"replaceable\"><code>basedn</code></em>[?[<em class=\"replaceable\"><code>attribute</code></em>][?[<em class=\"replaceable\"><code>scope</code></em>][?[<em class=\"replaceable\"><code>filter</code></em>]]]]\n</pre>\n<p lang=\"zh\"><em class=\"replaceable\"><code>scope</code></em>\u5fc5\u987b\u662f<code class=\"literal\">base</code>\u3001<code class=\"literal\">one</code>\u3001<code class=\"literal\">sub</code>\u4e2d\u7684\u4e00\u4e2a\uff0c\u901a\u5e38\u662f\u6700\u540e\u4e00\u4e2a\u3002\uff08\u9ed8\u8ba4\u4e3a<code class=\"literal\">base</code>\uff0c\u5728\u6b64\u5e94\u7528\u4e2d\u901a\u5e38\u65e0\u7528\u3002\uff09<em class=\"replaceable\"><code>attribute</code></em>\u53ef\u4ee5\u6307\u5b9a\u5355\u4e2a\u5c5e\u6027\uff0c\u6b64\u65f6\u5c06\u7528\u4f5c<code class=\"literal\">ldapsearchattribute</code>\u7684\u503c\u3002\u5982\u679c<em class=\"replaceable\"><code>attribute</code></em>\u4e3a\u7a7a\uff0c\u5219<em class=\"replaceable\"><code>filter</code></em>\u53ef\u7528\u4f5c<code class=\"literal\">ldapsearchfilter</code>\u7684\u503c\u3002</p>\n<p lang=\"zh\">URL \u65b9\u6848 ldaps \u9009\u62e9\u901a\u8fc7 SSL \u5efa\u7acb LDAP \u8fde\u63a5\u7684 LDAPS \u65b9\u5f0f\uff0c\u7b49\u4ef7\u4e8e ldapscheme=ldaps\u3002\u8981\u901a\u8fc7 StartTLS \u4f7f\u7528\u52a0\u5bc6 LDAP \u8fde\u63a5\uff0c\u5e94\u4f7f\u7528\u666e\u901a\u7684 ldap URL \u65b9\u6848\uff0c\u5e76\u5728 ldapurl \u4e4b\u5916\u6307\u5b9a ldaptls\u3002</p>\n<p lang=\"zh\">\u5bf9\u4e8e\u975e\u533f\u540d\u7ed1\u5b9a\uff0c\u5fc5\u987b\u5c06<code class=\"literal\">ldapbinddn</code>\u548c<code class=\"literal\">ldapbindpasswd</code>\u6307\u5b9a\u4e3a\u5355\u72ec\u7684\u9009\u9879\u3002</p>\n<p lang=\"zh\">LDAP URL\u76ee\u524d\u4ec5\u53d7<span class=\"productname\">OpenLDAP</span>\u652f\u6301\uff0c\u4e0d\u652f\u6301Windows\u3002</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u5c06\u7b80\u5355\u7ed1\u5b9a\u9009\u9879\u4e0e\u641c\u7d22+\u7ed1\u5b9a\u9009\u9879\u6df7\u7528\u662f\u9519\u8bef\u7684\u3002\u82e5\u8981\u5728\u7b80\u5355\u7ed1\u5b9a\u6a21\u5f0f\u4e0b\u4f7f\u7528 <code class=\"literal\">ldapurl</code>\uff0c\u8be5 URL \u4e2d\u4e0d\u80fd\u5305\u542b <code class=\"literal\">basedn</code> \u6216\u67e5\u8be2\u5143\u7d20\u3002</p>\n<p lang=\"zh\">\u5728\u4f7f\u7528\u641c\u7d22+\u7ed1\u5b9a\u6a21\u5f0f\u65f6\uff0c\u53ef\u4ee5\u4f7f\u7528\u7531 <code class=\"literal\">ldapsearchattribute</code> \u6307\u5b9a\u7684\u5355\u4e2a\u5c5e\u6027\u6267\u884c\u641c\u7d22\uff0c\u4e5f\u53ef\u4ee5\u4f7f\u7528\u7531 <code class=\"literal\">ldapsearchfilter</code> \u6307\u5b9a\u7684\u81ea\u5b9a\u4e49\u641c\u7d22\u8fc7\u6ee4\u5668\u6267\u884c\u641c\u7d22\u3002\u6307\u5b9a <code class=\"literal\">ldapsearchattribute=foo</code> \u7b49\u4ef7\u4e8e\u6307\u5b9a <code class=\"literal\">ldapsearchfilter=\"(foo=$username)\"</code>\u3002\u5982\u679c\u4e24\u4e2a\u9009\u9879\u90fd\u672a\u6307\u5b9a\uff0c\u5219\u9ed8\u8ba4\u4f7f\u7528 <code class=\"literal\">ldapsearchattribute=uid</code>\u3002</p>\n<p lang=\"zh\">\u5982\u679c <span class=\"productname\">PostgreSQL</span> \u7f16\u8bd1\u65f6\u4f7f\u7528\u4e86 <span class=\"productname\">OpenLDAP</span> \u4f5c\u4e3a LDAP \u5ba2\u6237\u7aef\u5e93\uff0c\u5219\u53ef\u4ee5\u7701\u7565 <code class=\"literal\">ldapserver</code> \u8bbe\u7f6e\u3002\u5728\u8fd9\u79cd\u60c5\u51b5\u4e0b\uff0c\u4f1a\u901a\u8fc7 <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc2782\" target=\"_top\">RFC 2782</a> DNS SRV \u8bb0\u5f55\u67e5\u627e\u4e3b\u673a\u540d\u548c\u7aef\u53e3\u5217\u8868\u3002\u67e5\u627e\u7684\u540d\u79f0\u662f <code class=\"literal\">_ldap._tcp.DOMAIN</code>\uff0c\u5176\u4e2d <code class=\"literal\">DOMAIN</code> \u4ece <code class=\"literal\">ldapbasedn</code> \u4e2d\u63d0\u53d6\u3002</p>\n<p lang=\"zh\">\u4e0b\u9762\u662f\u4e00\u4e2a\u7b80\u5355\u7ed1\u5b9a LDAP \u914d\u7f6e\u793a\u4f8b\uff1a</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapprefix=\"cn=\" ldapsuffix=\", dc=example, dc=net\"\n</pre>\n<p lang=\"zh\">\u5f53\u8bf7\u6c42\u4ee5\u6570\u636e\u5e93\u7528\u6237 <code class=\"literal\">someuser</code> \u8fde\u63a5\u6570\u636e\u5e93\u670d\u52a1\u5668\u65f6\uff0cPostgreSQL \u5c06\u5c1d\u8bd5\u4f7f\u7528 DN <code class=\"literal\">cn=someuser, dc=example, dc=net</code> \u548c\u5ba2\u6237\u7aef\u63d0\u4f9b\u7684\u5bc6\u7801\u7ed1\u5b9a\u5230 LDAP \u670d\u52a1\u5668\u3002\u5982\u679c\u8be5\u8fde\u63a5\u6210\u529f\uff0c\u6570\u636e\u5e93\u8bbf\u95ee\u5c31\u4f1a\u88ab\u6388\u4e88\u3002</p>\n<p lang=\"zh\">\u4e0b\u9762\u662f\u53e6\u4e00\u79cd\u7b80\u5355\u7ed1\u5b9a\u914d\u7f6e\uff0c\u5b83\u4f7f\u7528 LDAPS \u65b9\u6848\u548c\u81ea\u5b9a\u4e49\u7aef\u53e3\u53f7\uff0c\u5e76\u4ee5 URL \u5f62\u5f0f\u5199\u51fa\uff1a</p>\n<pre class=\"programlisting\">host ... ldap ldapurl=\"ldaps://ldap.example.net:49151\" ldapprefix=\"cn=\" ldapsuffix=\", dc=example, dc=net\"\n</pre>\n<p lang=\"zh\">\u8fd9\u79cd\u5199\u6cd5\u6bd4\u5355\u72ec\u6307\u5b9a <code class=\"literal\">ldapserver</code>\u3001<code class=\"literal\">ldapscheme</code> \u548c <code class=\"literal\">ldapport</code> \u7a0d\u5fae\u66f4\u7d27\u51d1\u3002</p>\n<p lang=\"zh\">\u4e0b\u9762\u662f\u4e00\u4e2a\u641c\u7d22+\u7ed1\u5b9a\u914d\u7f6e\u793a\u4f8b\uff1a</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapbasedn=\"dc=example, dc=net\" ldapsearchattribute=uid\n</pre>\n<p lang=\"zh\">\u5f53\u8bf7\u6c42\u4ee5\u6570\u636e\u5e93\u7528\u6237 <code class=\"literal\">someuser</code> \u8fde\u63a5\u6570\u636e\u5e93\u670d\u52a1\u5668\u65f6\uff0cPostgreSQL \u5c06\u5c1d\u8bd5\u5bf9 LDAP \u670d\u52a1\u5668\u8fdb\u884c\u533f\u540d\u7ed1\u5b9a\uff08\u56e0\u4e3a\u672a\u6307\u5b9a <code class=\"literal\">ldapbinddn</code>\uff09\uff0c\u5e76\u5728\u6307\u5b9a\u7684\u57fa\u7840 DN \u4e0b\u6267\u884c\u4e00\u6b21 <code class=\"literal\">(uid=someuser)</code> \u641c\u7d22\u3002\u5982\u679c\u627e\u5230\u4e86\u5bf9\u5e94\u6761\u76ee\uff0c\u968f\u540e\u5c31\u4f1a\u5c1d\u8bd5\u4f7f\u7528\u8be5\u6761\u76ee\u7684\u4fe1\u606f\u4ee5\u53ca\u5ba2\u6237\u7aef\u63d0\u4f9b\u7684\u5bc6\u7801\u8fdb\u884c\u7ed1\u5b9a\u3002\u5982\u679c\u7b2c\u4e8c\u6b21\u7ed1\u5b9a\u6210\u529f\uff0c\u6570\u636e\u5e93\u8bbf\u95ee\u5c31\u4f1a\u88ab\u6388\u4e88\u3002</p>\n<p lang=\"zh\">\u4e0b\u9762\u662f\u4ee5 URL \u5f62\u5f0f\u5199\u51fa\u7684\u540c\u4e00\u4e2a\u641c\u7d22+\u7ed1\u5b9a\u914d\u7f6e\uff1a</p>\n<pre class=\"programlisting\">host ... ldap ldapurl=\"ldap://ldap.example.net/dc=example,dc=net?uid?sub\"\n</pre>\n<p lang=\"zh\">\u67d0\u4e9b\u652f\u6301 LDAP \u8ba4\u8bc1\u7684\u5176\u4ed6\u8f6f\u4ef6\u4e5f\u4f7f\u7528\u76f8\u540c\u7684 URL \u683c\u5f0f\uff0c\u56e0\u6b64\u5171\u4eab\u8fd9\u7c7b\u914d\u7f6e\u4f1a\u66f4\u5bb9\u6613\u3002</p>\n<p lang=\"zh\">\u8fd9\u91cc\u662f\u4e00\u4e2a\u641c\u7d22+\u7ed1\u5b9a\u914d\u7f6e\u7684\u793a\u4f8b\uff0c\u5b83\u4f7f\u7528 <code class=\"literal\">ldapsearchfilter</code> \u800c\u4e0d\u662f <code class=\"literal\">ldapsearchattribute</code> \u6765\u5141\u8bb8\u7528\u7528\u6237 ID \u6216\u7535\u5b50\u90ae\u4ef6\u5730\u5740\u8fdb\u884c\u8ba4\u8bc1\uff1a</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapbasedn=\"dc=example, dc=net\" ldapsearchfilter=\"(|(uid=$username)(mail=$username))\"\n</pre>\n<p lang=\"zh\">\u8fd9\u662f\u4e00\u4e2a\u641c\u7d22+\u7ed1\u5b9a\u914d\u7f6e\u7684\u793a\u4f8b\uff0c\u5b83\u4f7f\u7528 DNS SRV \u53d1\u73b0\u6765\u67e5\u627e\u57df\u540d <code class=\"literal\">example.net</code> \u7684 LDAP \u670d\u52a1\u7684\u4e3b\u673a\u540d\u548c\u7aef\u53e3\u3002</p>\n<pre class=\"programlisting\">host ... ldap ldapbasedn=\"dc=example,dc=net\"\n</pre>\n<div class=\"tip\">\n<h3 class=\"title\" lang=\"zh\">\u63d0\u793a</h3>\n<p lang=\"zh\">\u5982\u793a\u4f8b\u4e2d\u6240\u793a\uff0c\u7531\u4e8e LDAP \u901a\u5e38\u4f7f\u7528\u9017\u53f7\u548c\u7a7a\u683c\u6765\u5206\u9694\u4e00\u4e2a DN \u7684\u4e0d\u540c\u90e8\u5206\uff0c\u5728\u914d\u7f6e LDAP \u9009\u9879\u65f6\u901a\u5e38\u6709\u5fc5\u8981\u4f7f\u7528\u53cc\u5f15\u53f7\u5305\u56f4\u7684\u53c2\u6570\u503c\u3002</p>\n</div>\n</div>", "manual_path": "/docs/18/auth-ldap.html", "localization": {"status": "complete", "sources": [{"url": "/docs/18/auth-ldap.html", "method": "same-major semantic node", "sha256": "065da171765af4f43f5d9405a7594cb88fbc5c9a8566612a459af67e1079cce0", "language": "zh", "matched_nodes": ["#AUTH-LDAP/div[0]", "#AUTH-LDAP/div[11]/dl[0]/dd[1]", "#AUTH-LDAP/div[11]/dl[0]/dd[3]", "#AUTH-LDAP/div[11]/dl[0]/dd[5]", "#AUTH-LDAP/div[11]/dl[0]/dd[7]", "#AUTH-LDAP/div[11]/dl[0]/dd[9]", "#AUTH-LDAP/div[13]/dl[0]/dd[1]/p[0]", "#AUTH-LDAP/div[13]/dl[0]/dd[1]/p[2]", "#AUTH-LDAP/div[13]/dl[0]/dd[1]/p[4]", "#AUTH-LDAP/div[13]/dl[0]/dd[1]/p[5]", "#AUTH-LDAP/div[33]/h3[0]", "#AUTH-LDAP/div[33]/p[1]", "#AUTH-LDAP/div[6]/dl[0]/dd[1]", "#AUTH-LDAP/div[6]/dl[0]/dd[3]", "#AUTH-LDAP/div[6]/dl[0]/dd[5]", "#AUTH-LDAP/div[9]/dl[0]/dd[1]", "#AUTH-LDAP/div[9]/dl[0]/dd[3]", "#AUTH-LDAP/p[10]", "#AUTH-LDAP/p[12]", "#AUTH-LDAP/p[14]", "#AUTH-LDAP/p[15]", "#AUTH-LDAP/p[16]", "#AUTH-LDAP/p[17]", "#AUTH-LDAP/p[19]", "#AUTH-LDAP/p[20]", "#AUTH-LDAP/p[22]", "#AUTH-LDAP/p[23]", "#AUTH-LDAP/p[25]", "#AUTH-LDAP/p[26]", "#AUTH-LDAP/p[28]", "#AUTH-LDAP/p[29]", "#AUTH-LDAP/p[2]", "#AUTH-LDAP/p[31]", "#AUTH-LDAP/p[3]", "#AUTH-LDAP/p[4]", "#AUTH-LDAP/p[5]", "#AUTH-LDAP/p[7]", "#AUTH-LDAP/p[8]"]}], "language": "zh", "original_text": {"/versions/18/description/0": "Authenticate using an LDAP server. See Section 20.10 for details.", "/versions/18/facts/0/label": "Method", "/versions/18/facts/1/label": "Configuration", "/versions/18/facts/2/label": "Inventory", "/versions/18/facts/2/value": "User-visible source authentication method", "/versions/18/tables/0/title": "Documented method options and alternatives", "/versions/18/tables/0/columns/0/label": "Option or term", "/versions/18/tables/0/columns/1/label": "Meaning", "/versions/18/tables/0/rows/0/description": "Names or IP addresses of LDAP servers to connect to. Multiple servers may be specified, separated by spaces.", "/versions/18/tables/0/rows/1/description": "Port number on LDAP server to connect to. If no port is specified, the LDAP library's default port setting will be used.", "/versions/18/tables/0/rows/2/description": "Set to ldaps to use LDAPS. This is a non-standard way of using LDAP over SSL, supported by some LDAP server implementations. See also the ldaptls option for an alternative.", "/versions/18/tables/0/rows/3/description": "Set to 1 to make the connection between PostgreSQL and the LDAP server use TLS encryption. This uses the StartTLS operation per RFC 4513 . See also the ldapscheme option for an alternative.", "/versions/18/tables/0/rows/4/description": "String to prepend to the user name when forming the DN to bind as, when doing simple bind authentication.", "/versions/18/tables/0/rows/5/description": "String to append to the user name when forming the DN to bind as, when doing simple bind authentication.", "/versions/18/tables/0/rows/6/description": "Root DN to begin the search for the user in, when doing search+bind authentication.", "/versions/18/tables/0/rows/7/description": "DN of user to bind to the directory with to perform the search when doing search+bind authentication.", "/versions/18/tables/0/rows/8/description": "Password for user to bind to the directory with to perform the search when doing search+bind authentication.", "/versions/18/tables/0/rows/9/description": "Attribute to match against the user name in the search when doing search+bind authentication. If no attribute is specified, the uid attribute will be used.", "/versions/18/tables/0/rows/10/description": "The search filter to use when doing search+bind authentication. Occurrences of $username will be replaced with the user name. This allows for more flexible search filters than ldapsearchattribute .", "/versions/18/tables/0/rows/11/description": "An RFC 4516 LDAP URL. The format is ldap[s]:// host [: port ]/ basedn [?[ attribute ][?[ scope ][?[ filter ]]]] scope must be one of base , one , sub , typically the last. (The default is base , which is normally not useful in this application.) attribute can nominate a single attribute, in which case it is used as a value for ldapsearchattribute . If attribute is empty then filter can be used as a value for ldapsearchfilter . The URL scheme ldaps chooses the LDAPS method for making LDAP connections over SSL, equivalent to using ldapscheme=ldaps . To use encrypted LDAP connections using the StartTLS operation, use the normal URL scheme ldap and specify the ldaptls option in addition to ldapurl . For non-anonymous binds, ldapbinddn and ldapbindpasswd must be specified as separate options. LDAP URLs are currently only supported with OpenLDAP , not on Windows."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "cd042d43565e1460d7789e6c328e4902c31423a24f7d95653d8b81545f596da2"}, "comparison_data": {"method": "ldap", "documented_option_names": ["ldapbasedn", "ldapbinddn", "ldapbindpasswd", "ldapport", "ldapprefix", "ldapscheme", "ldapsearchattribute", "ldapsearchfilter", "ldapserver", "ldapsuffix", "ldaptls", "ldapurl"]}, "comparison_hash": "d40de945ae67b3ac60a284fdd442cc24a4e9d05bc7a7b18009b54e491c381b88", "manual_language": "zh"}, "comparison": {"left": "10", "right": "11", "status": "changed", "diff": "--- PostgreSQL 10\n+++ PostgreSQL 11\n@@ -5,7 +5,9 @@\n     \"ldapbindpasswd\",\n     \"ldapport\",\n     \"ldapprefix\",\n+    \"ldapscheme\",\n     \"ldapsearchattribute\",\n+    \"ldapsearchfilter\",\n     \"ldapserver\",\n     \"ldapsuffix\",\n     \"ldaptls\","}}