What Is LDAP?
The best place to begin when explaining LDAP is to examine how it got its name. Let’s start at the beginning. The latest incarnation of LDAP (Version 3) is defined in a set of nine documents outlined in RFC 3377. This list includes:
- RFC 2251-2256
The original core set of LDAPv3 RFCs
- RFC 2829
“Authentication Methods for LDAP”
- RFC 2830
“Lightweight Directory Access Protocol (v3): Extension for Transport Layer Security”
- RFC 3377
“Lightweight Directory Access Protocol (v3): Technical Specification”
Lightweight
Why is LDAP considered lightweight? Lightweight compared to what? (As we look at LDAP in more detail, you’ll certainly be asking how something this complex could ever be considered lightweight.) To answer these questions, it is necessary to look at LDAP’s origins. The roots of LDAP are closely tied to the X.500 directory service; LDAP was originally designed as a lighter desktop protocol used to gateway requests to X.500 servers. X.500 is actually a set of standards; anything approaching thorough coverage of X.500 is beyond the scope of this book.[2]
X.500 earned the title “heavyweight.” It required the client and server to communicate using the Open Systems Interface (OSI) protocol stack. This seven-layered stack was a good academic exercise in designing a network protocol suite, but when compared to the TCP/IP protocol suite, it is akin to traveling the European train system with four fully loaded footlockers.[3]
LDAP is lightweight in comparison because it uses low ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access