skip to content

LDAP

The protocol behind corporate user and group lookups: an entry tree addressed by Distinguished Names, bind authentication, and filtered searches. Enterprise sign-in still bottoms out here.

on this pageshow

explore

questions

page 2 of 2

A team adds extensibleObject to its directory entries so new attributes need no schema change — what does that cost?

level: seniorimportance: should knowfreq 26%

basics

~20 s

extensibleObject is an auxiliary class letting an entry hold any user attribute the schema defines, so MUST and MAY lists stop constraining it. The cost is that the server can no longer refuse a misspelled or misplaced attribute, and the entry stops being self-describing.

open as a page

A wholeSubtree LDAP search returns 1,000 clinician entries and stops - how does the client tell a complete answer from a truncated one?

level: seniorimportance: should knowfreq 44%

basics

~20 s

Completeness is carried by the result code on the SearchResultDone that ends the search: success (0) means the whole scope was evaluated, while sizeLimitExceeded (4), timeLimitExceeded (3) or adminLimitExceeded (11) mean the server stopped early.

open as a page

When a directory server refuses an unprotected LDAP simple bind, what does an older client that cannot negotiate TLS receive?

level: seniorimportance: should knowfreq 38%

basics

~20 s

A result code, not a dropped socket: confidentialityRequired (13) when the server demands a protected connection, or strongerAuthRequired (8) when it demands stronger authentication. A server may also send an unsolicited Notice of Disconnection before ending the association.

open as a page

In a multi-site LDAP directory whose replicas run minutes to weeks behind, how do you set a staleness window and decide which reads may not take it?

level: principalimportance: should knowfreq 30%

basics

~20 s

Publish a measured bound, not an aspiration: state how far behind a replica may be, measure it continuously, alarm when it is exceeded, and say what happens then. Then classify reads, and route every read that decides access or follows the reader's own write to the writable copy.

open as a page

Two directory entries under one parent would carry the same cn value — how does a multi-valued RDN resolve that?

level: middleimportance: nice to knowfreq 24%

basics

~20 s

A Relative Distinguished Name may hold more than one attribute type and value, joined in the string form with a plus sign, so a second attribute distinguishes the siblings. Every value used must also be present as an attribute of the entry.

open as a page

Why would a service check one attribute value with an LDAP Compare rather than a search?

level: middleimportance: nice to knowfreq 24%

basics

~20 s

Compare asks one yes-or-no question about one named entry and answers with the resultCode compareTrue(6) or compareFalse(5). It returns no attribute data, so it can confirm a value a caller is not permitted to read and cannot be used to enumerate.

open as a page

In a SASL EXTERNAL LDAP Bind, where does the identity come from, and what does an authzId in the request change?

level: seniorimportance: nice to knowfreq 30%

basics

~20 s

SASL EXTERNAL carries no secret: it asks the directory to use an identity the layer beneath LDAP already established. An authzId in its credentials asks to act as someone else instead, which the server may refuse.

open as a page

showing 31–38 of 38