openskills.info
Course Preview

LDAP

LDAP is a network protocol for reading and changing hierarchical directory data. Applications use it to find entries such as people, groups, devices, and services through a shared schema and namespace.

itIdentity, access, and cryptography

Don't Panic - LDAP

LDAP is a protocol for reading and changing entries in a directory. A directory holds attribute-based records in a hierarchy. It is commonly used for identity data, inventories, and configuration that is searched more often than it is changed. LDAP is not one product: OpenLDAP, 389 Directory Server, Active Directory Domain Services, and others speak LDAP while choosing their own storage, replication, and extensions. An application can also use LDAP only as an integration interface to a larger identity system.

Entries live in a directory information tree. Each entry has a distinguished name that places it in the namespace, plus typed attributes constrained by schema. Structural and auxiliary object classes say which attributes must or may appear. Clients connect, optionally protect the channel with TLS, bind to establish an authentication identity, then search or update. Bind success is not the same as authorization; access control is evaluated separately for each operation and attribute.

A search combines a base DN, a scope, and a filter. Scope chooses how far to walk. Filters are data with escaping rules of their own. Untrusted text must not be concatenated into a filter string; use the library encoder. Servers may impose size and time limits, and sizeLimitExceeded means the result may be incomplete. Updates include add, delete, modify, and Modify DN. Renaming changes the entry's place in the tree, so long-lived references should prefer stable identifiers when the server exposes them.

Replication and referrals are operational realities. Replicas can lag, so a write that succeeds on one node does not prove every replica already serves the new value. Referrals can cross trust boundaries and reuse credentials unsafely if the client follows them blindly. Network loss after an update can leave the client unsure whether the change applied, so blind retries need care. LDAP is not a browser sign-in protocol; modern web apps usually use OpenID Connect or SAML for interactive federation and may still talk LDAP behind an identity provider.

Read the Intro for the protocol model and security boundaries. Use the Cheatsheet for the search and schema maps. Landscape and Timeline place LDAP among related identity systems; Updates tracks OpenLDAP release lines that often accompany the worked examples.

Where this skill leads

Relevant careers

See how this topic contributes to broader role-level skill maps.

Sources