Skip site navigation (1)Skip section navigation (2)

FreeBSD Manual Pages

  
 
  

home | help
SLAPD(8C)							       SLAPD(8C)

NAME
     slapd - Stand-alone LDAP Daemon

SYNOPSIS
     /usr/local/libexec/slapd	[-V[V[V]]   [-4|-6]   [-T {acl|a[dd]|auth|c[at]|
     d[n]|i[ndex]|m[odify]|p[asswd]|s[chema]|t[est]}]		[-d debug-level]
     [-f slapd-config-file]  [-F slapd-config-directory]  [-h URLs] [-n service-
     name] [-s syslog-level] [-l syslog-local-user] [-o option[=value]]  [-r di-
     rectory] [-u user] [-g group] [-c cookie]

DESCRIPTION
     Slapd  is	the  stand-alone LDAP daemon. It listens for LDAP connections on
     any number of ports (default 389), responding to the LDAP operations it re-
     ceives over these connections.  slapd is typically invoked  at  boot  time,
     usually  out of /etc/rc.local.  Upon startup, slapd normally forks and dis-
     associates itself from the invoking tty.  If configured in the config  file
     (or  config  directory),  the  slapd process will print its process ID (see
     getpid(2)) to a .pid file, as well as the command line options during invo-
     cation to an .args file (see slapd.conf(5)).  If the -d flag is given, even
     with a zero argument, slapd will not fork and disassociate from the  invok-
     ing tty.

     See the "OpenLDAP Administrator's Guide" for more details on slapd.

OPTIONS
     -V[V[V]]
	    Print  version info and proceed with startup.  If -VV is given, exit
	    after providing version info. If -VVV is given, additionally provide
	    information on static overlays and backends.

     -4     Listen on IPv4 addresses only.

     -6     Listen on IPv6 addresses only.

     -T tool
	    Run in Tool mode. The tool argument selects whether to run	as  sla-
	    padd,  slapcat,  slapdn,  slapindex,  slapmodify,  slappasswd, slap-
	    schema, or slaptest (slapacl and slapauth need the	entire	acl  and
	    auth  option  value to be spelled out, as a is reserved to slapadd).
	    This option should be the first option specified when  it  is  used;
	    any  remaining options will be interpreted by the corresponding slap
	    tool program, according to the  respective	man  pages.   Note  that
	    these  tool  programs will usually be symbolic links to slapd.  This
	    option is provided for situations where symbolic links are not  pro-
	    vided or not usable.

     -d debug-level
	    Turn  on  debugging  as  defined  by debug-level.  If this option is
	    specified, even with a zero argument, slapd will not fork or  disas-
	    sociate from the invoking terminal.  Some general operation and sta-
	    tus  messages are printed for any value of debug-level.  debug-level
	    is taken as a bit string, with each bit corresponding to a different
	    kind  of  debugging  information.	See  <ldap_log.h>  for	details.
	    Comma-separated  arrays of friendly names can be specified to select
	    debugging output of the corresponding  debugging  information.   All
	    the   names  recognized  by  the  loglevel	directive  described  in
	    slapd.conf(5) are supported.  If debug-level is ?,	a  list  of  in-
	    stalled debug-levels is printed, and slapd exits.

	    Remember that if you turn on packet logging, packets containing bind
	    passwords  will  be output, so if you redirect the log to a logfile,
	    that file should be read-protected.

     -s syslog-level
	    This option tells slapd at	what  debug-level  debugging  statements
	    should  be logged to the syslog(8) facility.  The value syslog-level
	    can be set to any value or combination allowed  by	the  -d  switch.
	    Slapd  logs  all  messages selected by syslog-level at the syslog(3)
	    severity debug-level DEBUG, on the unit specified with -l.

     -n service-name
	    Specifies the service name for logging and other purposes.	Defaults
	    to basename of argv[0], i.e.: "slapd".

     -l syslog-local-user
	    Selects the local user of the syslog(8) facility. Value can  be  LO-
	    CAL0,  through  LOCAL7,  as well as USER and DAEMON.  The default is
	    LOCAL4.  However, this option is only permitted on systems that sup-
	    port local users with the syslog(8) facility.  Logging to  syslog(8)
	    occurs at the "DEBUG" severity debug-level.

     -f slapd-config-file
	    Specifies  the  slapd  configuration  file.  The default is /usr/lo-
	    cal/etc/openldap/slapd.conf.

     -F slapd-config-directory
	    Specifies the slapd configuration directory. The default is /usr/lo-
	    cal/etc/openldap/slapd.d.  If both -f and -F are specified, the con-
	    fig file will be read and converted to config directory  format  and
	    written to the specified directory.  If neither option is specified,
	    slapd  will attempt to read the default config directory before try-
	    ing to use the default config file. If a valid config directory  ex-
	    ists  then the default config file is ignored. All of the slap tools
	    that use the config options observe this same behavior.

     -h URLlist
	    slapd will by default serve ldap:/// (LDAP over TCP  on  all  inter-
	    faces on default LDAP port).  That is, it will bind using INADDR_ANY
	    and  port 389.  The -h option may be used to specify LDAP (and other
	    scheme)  URLs  to  serve.	For  example,  if  slapd  is  given   -h
	    "ldap://127.0.0.1:9009/  ldaps:///	ldapi:///",  it  will  listen on
	    127.0.0.1:9009 for LDAP, 0.0.0.0:636 for LDAP  over  TLS,  and  LDAP
	    over  IPC (Unix domain sockets).  Host 0.0.0.0 represents INADDR_ANY
	    (any interface).  A space separated list of URLs is  expected.   The
	    URLs  should be of the LDAP, PLDAP, LDAPS, PLDAPS, or LDAPI schemes,
	    and generally without a DN or other optional  parameters  (excepting
	    as	discussed  below).  Support for the latter three schemes depends
	    on selected configuration options. Hosts may be specified by name or
	    IPv4 and IPv6 address formats.  Ports, if  specified,  must  be  nu-
	    meric.   The  default  ldap://  port is 389 and the default ldaps://
	    port is 636, same for the proxy enabled variants.

	    The PLDAP and PLDAPS URL schemes provide  support  for  the  HAProxy
	    proxy  protocol  version  2,  which  allows a load balancer or proxy
	    server to provide the remote client IP address to slapd to	be  used
	    for  access control or logging. Ports configured for PLDAP or PLDAPS
	    will only accept connections that include the necessary proxy proto-
	    col header. Connections to these ports should be restricted  at  the
	    network  level  to	only  trusted load balancers or proxies to avoid
	    spoofing of client IP addresses by third parties.

	    For LDAP over IPC, name is the name of the socket, and  no	port  is
	    required,  nor  allowed; note that directory separators must be URL-
	    encoded, like any other characters that are special to URLs; so  the
	    socket

		    /usr/local/var/ldapi

	    must be specified as

		    ldapi://%2Fusr%2Flocal%2Fvar%2Fldapi

	    The default location for the IPC socket is /var/db/run/ldapi

	    The   listener  permissions  are  indicated  by  "x-mod=-rwxrwxrwx",
	    "x-mod=0777" or "x-mod=777", where any of the "rwx" can  be  "-"  to
	    suppress the related permission, while any of the "7" can be any le-
	    gal  octal digit, according to chmod(1).  The listeners can take ad-
	    vantage of the "x-mod" extension to apply rough limitations to oper-
	    ations, e.g. allow read operations ("r", which applies to search and
	    compare), write operations ("w", which applies to add, delete,  mod-
	    ify  and  modrdn),	and execute operations ("x", which means bind is
	    required).	"User" permissions apply to authenticated  users,  while
	    "other"  apply  to anonymous users; "group" permissions are ignored.
	    For example,  "ldap:///????x-mod=-rw-------"  means  that  read  and
	    write is only allowed for authenticated connections, and bind is re-
	    quired  for  all  operations.  This feature is experimental, and re-
	    quires to be manually enabled at configure time.

     -r directory
	    Specifies a directory to become  the  root	directory.   slapd  will
	    change  the current working directory to this directory and then ch-
	    root(2) to this directory.	This is done after opening listeners but
	    before reading any configuration file or initializing  any	backend.
	    When  used as a security mechanism, it should be used in conjunction
	    with -u and -g options.

     -u user
	    slapd will run slapd with the specified user name or  id,  and  that
	    user's  supplementary  group  access list as set with initgroups(3).
	    The group ID is also changed to this user's gid, unless the  -g  op-
	    tion  is  used  to override.  Note when used with -r, slapd will use
	    the user database in the change root environment.

	    Note that on some systems, running as  a  non-privileged  user  will
	    prevent  passwd  back-ends	from  accessing the encrypted passwords.
	    Note also that any shell back-ends will run as  the  specified  non-
	    privileged user.

     -g group
	    slapd  will run with the specified group name or id.  Note when used
	    with -r, slapd will use the group database in the change root  envi-
	    ronment.

     -c cookie
	    This option provides a cookie for the syncrepl replication consumer.
	    The cookie is a comma separated list of name=value pairs.  Currently
	    supported syncrepl cookie fields are rid, sid, and csn.  rid identi-
	    fies  a replication thread within the consumer server and is used to
	    find the syncrepl specification in slapd.conf(5) or  slapd-config(5)
	    having  the  matching  replication identifier in its definition. The
	    rid must be provided in order for any other specified values  to  be
	    used.   sid is the server id in a multi-provider configuration.  csn
	    is the commit sequence number received by a previous synchronization
	    and represents the state of the consumer content which the	syncrepl
	    engine will synchronize to the current provider content.  In case of
	    multi-provider replication agreement, multiple csn values, semicolon
	    separated,	can  appear.   Use only the rid part to force a full re-
	    load.

     -o option[=value]
	    This option provides a generic means to specify options without  the
	    need to reserve a separate letter for them.

	    It supports the following options:

	    slp={on|off|slp-attrs}
		   When SLP support is compiled into slapd, disable it (off),
		    enable it by registering at SLP DAs without specific SLP at-
		   tributes (on), or with specific SLP attributes slp-attrs that
		   must be an SLP attribute list definition according to the SLP
		   standard.

		   For	  example,    "slp=(tree=production),(server-type=OpenL-
		   DAP),(server-version=2.4.15)" registers at SLP DAs  with  the
		   three  SLP  attributes  tree,  server-type and server-version
		   that have the values given above.  This allows one to specif-
		   ically query the SLP DAs for LDAP servers holding the produc-
		   tion tree in case multiple trees are available.

EXAMPLES
     To start slapd and have it fork and detach  from  the  terminal  and  start
     serving the LDAP databases defined in the default config file, just type:

	  /usr/local/libexec/slapd

     To start slapd with an alternate configuration file, and turn on voluminous
     debugging which will be printed on standard error, type:

	  /usr/local/libexec/slapd -f /var/tmp/slapd.conf -d 255

     To test whether the configuration file is correct or not, type:

	  /usr/local/libexec/slapd -Tt

SEE ALSO
     ldap(3),  slapd.conf(5), slapd-config(5), slapd.access(5), slapacl(8), sla-
     padd(8), slapauth(8), slapcat(8), slapdn(8),  slapindex(8),  slapmodify(8),
     slappasswd(8), slapschema(8), slaptest(8).

     "OpenLDAP Administrator's Guide" (http://www.OpenLDAP.org/doc/admin/)

BUGS
     See http://www.openldap.org/its/

ACKNOWLEDGEMENTS
     OpenLDAP  Software  is  developed	and  maintained  by The OpenLDAP Project
     <http://www.openldap.org/>.  OpenLDAP Software is derived from the  Univer-
     sity of Michigan LDAP 3.3 Release.

OpenLDAP 2.6.13 		   2026/03/09			       SLAPD(8C)

Want to link to this manual page? Use this URL:
<https://man.freebsd.org/cgi/man.cgi?query=slapd&sektion=8&manpath=FreeBSD+Ports+15.1.quarterly>

home | help