Skip to main content

cmem-plugin-ldap

Query LDAP directory services such as OpenLDAP or Active Directory.

eccenca Corporate Memory

This is a plugin for eccenca Corporate Memory. You can install it with the cmemc command line client like this:

cmemc admin workspace python install cmem-plugin-ldap

pypi version license poetry ruff mypy copier

Search LDAP directory

Searches a directory server over LDAP and returns each matching entry as an entity, so that the people, groups and devices a directory holds can be mapped into a Knowledge Graph. It works with any LDAPv3 directory, among them OpenLDAP, Active Directory and Apple Open Directory.

A search needs the URL of the directory, where to start, what to match and what to return:

Parameter Example
LDAP URL ldaps://directory.example.org:636
Bind DN cn=reader,ou=services,dc=example,dc=org
Search base ou=people,dc=example,dc=org
Search filter (&(objectClass=person)(mail=*))
Attributes cn, mail, memberOf

Leaving the bind name and password empty binds anonymously. The attributes have to be named one by one: the entities are described to the workflow while it is being drawn, and * would only be resolved by the directory once the search runs.

What comes out

One entity per entry, identified by the LDAP URL of that entry as defined by RFC 4516:

ldaps://directory.example.org/uid%3Djdoe%2Cou%3Dpeople%2Cdc%3Dexample%2Cdc%3Dorg

Each entity carries the distinguished name of the entry, followed by the values of the requested attributes in the order they were requested. An attribute an entry does not carry produces no value, which keeps it distinguishable from an attribute that is present and empty, and an attribute holding several values keeps all of them.

Values arrive in the lexical form a Knowledge Graph expects - timestamps as ISO 8601, booleans as true and false - and a value which is not text, such as jpegPhoto or objectSid, is Base64 encoded. The schema of the directory is read while connecting to make that possible, since a directory sends every value as text and only its schema says which of them is a timestamp.

Large directories

Searching is always paged, so a result set is not cut short by the maximum result size of the directory, which is 1000 entries on a default Active Directory installation. A search which reaches the configured maximum number of entries stops there and reports a warning saying so.

References to other directory servers are not followed unless this is asked for, since following one opens an anonymous connection to a server named by the directory rather than by the task.

Connecting securely

ldaps:// is encrypted from the start, and an ldap:// connection can be upgraded with StartTLS before authenticating. Certificates are validated in both cases. Where the directory uses an internal certificate authority, configure that authority rather than switching validation off.

Release files for cmem-plugin-ldap 0.5.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for cmem-plugin-ldap 0.5.0
File Size Uploaded
cmem_plugin_ldap-0.5.0.tar.gz 15.8 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for cmem-plugin-ldap 0.5.0
File Interpreter ABI Platform
cmem_plugin_ldap-0.5.0-py3-none-any.whl Python 3 none any Details

Total release size: 32.7 kB

Release files / cmem_plugin_ldap-0.5.0.tar.gz

Download URL cmem_plugin_ldap-0.5.0.tar.gz
Size 15.8 kB
Tags Source
SHA-256 checksum
How to use checksums
989fd1076e9666a8953332cbd32b60f5f841830bddbcc6d076d6becca636982e
BLAKE2b-256 checksum
How to use checksums
29c77c8a07a3eb59b745d424dc7fc5a3a2f92e65c310972aa9abbdcd750d7359
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via poetry/2.3.4 CPython/3.13.13 Linux/6.1.0-52-amd64

Release files / cmem_plugin_ldap-0.5.0-py3-none-any.whl

Download URL cmem_plugin_ldap-0.5.0-py3-none-any.whl
Size 16.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
7fda38c8e2cf00fc144e3ed40be5d43cc5f08aae14db323ecb7092cfb18e0ae4
BLAKE2b-256 checksum
How to use checksums
f0842d71c7f759945c5f909d0a425eadc52238d06fd21fc1f74ceeeedeee6377
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via poetry/2.3.4 CPython/3.13.13 Linux/6.1.0-52-amd64

Release history Release notifications | RSS feed

This release

0.5.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page