Import from an existing LDAP directory
Checking this directory…

Upload a full export of the directory you are migrating from, produced with slapcat -l full.ldif or ldapsearch -LLL. Nothing is written until you have reviewed every account and group on the next screens.

Before you start: add all of your hosts and apps first, so their groups exist to map onto — source groups can only be merged into groups that already exist here, never created. The file is parsed in memory and held for one hour; it is never written to disk, and the password hashes in it are never sent back to your browser.

This is how the file appears to be laid out. Correct anything that looks wrong — a directory exported from FreeIPA, Active Directory or a hand-rolled schema will not use the same attributes as OpenLDAP.

Prefer the class that carries uidNumber — accounts without one cannot be migrated.
Must be unique across every account.
member/uniqueMember hold DNs; memberUid holds bare usernames.
Username uid / gid Name Email Password Notes Action
Source groups are never created here. A group name from another directory carries no meaning in this one, where access is derived from the group model. Each source group can either have its members merged into a group that already exists, or be dropped. Several source groups may point at the same target.
Source groupMembersMerge into
What will happen
    Onboarding

    Imported accounts have no history in this app, so by default everyone is asked to accept the terms of service and verify their email at first login. If you already collected these in the directory you are migrating from, skip them here.

    Accounts carrying legacy MD5 passwords are always forced to change them at first login, regardless of the settings above. No welcome email is sent to anyone.
    Import complete
    EntryStatusDetail
    Group membership beyond what you mapped, and any nesting the old directory had, is not migrated — set it up from the directory now that the accounts exist.