Install OpenLDAP on Ubuntu

Install OpenLDAP on Ubuntu, configure the directory suffix and administrator, verify the service, run a test search, and apply baseline security.

On this page

Link to Introduction: Why Install OpenLDAP on Ubuntu?Introduction: Why Install OpenLDAP on Ubuntu?

OpenLDAP provides a standards-compliant, extensible directory service used to centralize user identity and authentication across applications and infrastructure. On Ubuntu, OpenLDAP is a common choice for building backend authentication platforms, supporting LDAP-based SSO, and integrating with heterogeneous systems—including UNIX, Linux, and compatible third-party applications. Administrators and developers use it to unify user management and provide foundational identity data, whether for enterprise IT or developer-focused environments. This guide targets those preparing to deploy, secure, and operate OpenLDAP on modern Ubuntu LTS systems.

Link to System Requirements and PreparationSystem Requirements and Preparation

Recent LTS versions of Ubuntu are fully supported for OpenLDAP deployment; Ubuntu 20.04, 22.04, and 24.04 are typical environments. Root or sudo privileges are required throughout installation and configuration. Before installation:

  • Ensure the system has Internet connectivity or direct access to Ubuntu's package repositories to use apt.
  • Set a stable hostname and make certain network and DNS settings are correct.
  • Update the system with the latest patches using apt.
  • Consider local firewall settings. By default, slapd listens on all interfaces. Confirm firewall rules permit required access or plan to adjust them post-install.
  • No advance installation of additional dependencies is required; Ubuntu’s packaging resolves these automatically.

Link to Step-by-Step: Installing OpenLDAP (slapd and ldap-utils)Step-by-Step: Installing OpenLDAP (slapd and ldap-utils)

OpenLDAP on Ubuntu is provided via two primary packages:

  • slapd: The LDAP server daemon.
  • ldap-utils: Tools to administer and test your directory.

Link to Installation StepsInstallation Steps

  1. Update package lists:

    sudo apt update
    
  2. Install OpenLDAP server and utilities:

    sudo apt install slapd ldap-utils
    

    You will be prompted during installation for several core parameters:

    • Administrator password: Sets the initial password for the LDAP admin account.
    • Base DN (suffix): The root of your directory tree (e.g., dc=example,dc=com).
  3. If you need to re-run the configuration wizard (for instance, to fix a mistake in the admin password or base DN), execute:

    sudo dpkg-reconfigure slapd
    

    Answer the prompts carefully—especially the base DN and admin password, as these dictate how clients connect and authenticate.

  4. The OpenLDAP service (slapd) starts automatically upon installation. Configuration is managed dynamically and stored in /etc/ldap/slapd.d/ as LDIF files.

Do not edit these files directly; use standard tools for all post-install modifications.

Link to Understanding OpenLDAP's Dynamic Configuration on UbuntuUnderstanding OpenLDAP's Dynamic Configuration on Ubuntu

Modern OpenLDAP deployments on Ubuntu do not use the old slapd.conf file. Instead, configuration is governed by the dynamic cn=config backend, organized as LDIF files within /etc/ldap/slapd.d/.

Key characteristics:

  • Changes must be made via LDAP operations, or safe editing through provided commands—not by manually editing LDIF files.
  • The slapd process monitors these files for updates and applies configuration changes live, eliminating the need for restarts in most cases.
  • All core parameters, schemas, and Access Control Lists (ACLs) reside in cn=config. Administration is commonly performed with LDAP command-line tools or scripts.

This approach supports programmatic changes, safer upgrades, and easier configuration management. Attempting to use or edit slapd.conf will have no effect on Ubuntu-packaged OpenLDAP.

Link to Post-Install Verification and TroubleshootingPost-Install Verification and Troubleshooting

A successful OpenLDAP deployment should be immediately verifiable at both the service and directory levels.

Check the slapd service status:

bash
sudo systemctl status slapd

Look for output indicating the service is active (running) and enabled on boot.

Test LDAP connectivity and search:

bash
ldapsearch -x -H ldap://localhost -b dc=example,dc=com

Change dc=example,dc=com to match your chosen base DN during installation. This command queries the root of your directory and confirms the service is reachable.

Check logs for errors or warnings:

  • Use journalctl to view recent service logs:
    sudo journalctl -u slapd
    
  • Review general system logs (e.g., /var/log/syslog) for slapd-related entries.

Troubleshooting common issues:

  • Service will not start or fails to run: Verify privileged access, correct DNS/hostname, and the absence of port conflicts.
  • LDAP queries fail or reject authentication: Re-execute sudo dpkg-reconfigure slapd to ensure the base DN and admin password were set correctly.
  • Configuration changes not taking effect: Make all modifications through LDAP interfaces or supported tooling; direct file edits are ignored and may corrupt configuration.

Always operate as root or with sudo—administration and configuration changes require it.

Link to Securing and Hardening OpenLDAP on UbuntuSecuring and Hardening OpenLDAP on Ubuntu

OpenLDAP defaults to unencrypted traffic over port 389. Credentials and data are sent in cleartext. Explicit hardening is required before production use.

Enabling TLS/SSL:

  • Obtain a signed SSL certificate and private key (or generate a self-signed certificate for test use).
  • Place the certificate and key where slapd can read them (commonly /etc/ssl/certs/ and /etc/ssl/private/).
  • Prepare an LDIF file to update slapd's configuration, substituting your certificate paths:
    dn: cn=config
    changetype: modify
    replace: olcTLSCertificateFile
    olcTLSCertificateFile: /etc/ssl/certs/your_cert.pem
    -
    replace: olcTLSCertificateKeyFile
    olcTLSCertificateKeyFile: /etc/ssl/private/your_key.pem
    
  • Apply the LDIF change as root (using ldapmodify with appropriate authentication).

Post-change, restart slapd or verify service reload as needed. TLS/SSL enables encrypted LDAP (StartTLS or ldaps://).

Limiting network exposure:

  • By default, slapd listens on all interfaces. Restrict access to trusted hosts using your host firewall. With Ubuntu's uncomplicated firewall (ufw), for example:
    sudo ufw allow from 192.168.1.0/24 to any port 636 proto tcp
    sudo ufw allow from 192.168.1.0/24 to any port 389 proto tcp
    sudo ufw enable
    
    Adjust the allowed IP range as appropriate.

Review and enforce directory ACLs to control who can view or modify data. ACL configuration must be set using LDIF updates via cn=config.

OpenLDAP is not secure by default. Encrypted traffic and limited access are required to protect sensitive directory contents and authentication flows.

Link to Alternatives to OpenLDAP on UbuntuAlternatives to OpenLDAP on Ubuntu

OpenLDAP is Ubuntu’s standard LDAP directory implementation, but other options are available for specific needs:

  • FreeIPA: Provides integrated identity management with SSO, Kerberos, and web administration. Installation demands more packages and initial setup than OpenLDAP.
  • Samba AD: Ideal for enterprises needing full Active Directory protocol compatibility. Requires Samba-specific packages and often additional DNS setup.
  • 389 Directory Server: LDAPv3-compliant and enterprise-grade, with a distinct management model and dependency set.

Each alternative has different installation steps and configuration requirements compared to OpenLDAP. Review their documentation for setup procedures.

Link to Common Misconceptions and FAQsCommon Misconceptions and FAQs

  • Does OpenLDAP use slapd.conf on Ubuntu?
    No. All recent Ubuntu OpenLDAP packages use dynamic LDIF-based configuration (cn=config). The old slapd.conf file is obsolete and ignored.

  • Is a fresh OpenLDAP install secure?
    No. LDAP traffic and passwords are unencrypted by default. Deploy TLS/SSL and configure robust firewall and ACL policies before exposing to untrusted networks.

  • Can slapd be configured by editing files?
    No. Manual edits to configuration files (except with supported tools) are unsupported and can break the service. Use LDAP tools and LDIF updates only.

  • Can phpLDAPadmin be used on Ubuntu Server?
    Typically not. Many recent Ubuntu LTS versions lack up-to-date phpLDAPadmin support, often due to PHP changes. LDAP Account Manager (LAM) is a suitable alternative.

  • Is root or sudo required for admin tasks?
    Yes. All installation, configuration, and most LDAP administrative tasks require privileged access.

Link to Summary and Next StepsSummary and Next Steps

Installing OpenLDAP on Ubuntu is a clear, package-driven process for those with root or sudo privileges. Configuration is managed exclusively through the dynamic, LDIF-based cn=config backend. After installation and verification, immediate attention to securing the service is critical—configure TLS/SSL, apply local firewall restrictions, and maintain strict access controls.

For ongoing operation:

  • Regularly consult both the [OpenLDAP Administrator's Guide] and the [Ubuntu OpenLDAP documentation] for authoritative configuration, maintenance, and security procedures.
  • Prioritize backup strategies and review available LDAP utilities for administration.
  • When planning advanced integration or specialized identity services, evaluate FreeIPA, Samba AD, and 389 Directory Server to ensure optimal fit.

Link to SourcesSources