LDAP
The protocol behind corporate user and group lookups: an entry tree addressed by Distinguished Names, bind authentication, and filtered searches. Enterprise sign-in still bottoms out here.
on this pageshowhide
explore
- Entry Tree and DNs5 questions
- Schema & Object Classes5 questions
- Bind & Authentication5 questions
- Search Filters & Scope4 questions
- Controls and Extensions5 questions
- Core Operations6 questions
- Channel Protection3 questions
- Replication & Referrals5 questions
questions
page 2 of 2A team adds extensibleObject to its directory entries so new attributes need no schema change — what does that cost?
basics
~20 sextensibleObject is an auxiliary class letting an entry hold any user attribute the schema defines, so MUST and MAY lists stop constraining it. The cost is that the server can no longer refuse a misspelled or misplaced attribute, and the entry stops being self-describing.
A wholeSubtree LDAP search returns 1,000 clinician entries and stops - how does the client tell a complete answer from a truncated one?
basics
~20 sCompleteness is carried by the result code on the SearchResultDone that ends the search: success (0) means the whole scope was evaluated, while sizeLimitExceeded (4), timeLimitExceeded (3) or adminLimitExceeded (11) mean the server stopped early.
When a directory server refuses an unprotected LDAP simple bind, what does an older client that cannot negotiate TLS receive?
basics
~20 sA result code, not a dropped socket: confidentialityRequired (13) when the server demands a protected connection, or strongerAuthRequired (8) when it demands stronger authentication. A server may also send an unsolicited Notice of Disconnection before ending the association.
In a multi-site LDAP directory whose replicas run minutes to weeks behind, how do you set a staleness window and decide which reads may not take it?
basics
~20 sPublish a measured bound, not an aspiration: state how far behind a replica may be, measure it continuously, alarm when it is exceeded, and say what happens then. Then classify reads, and route every read that decides access or follows the reader's own write to the writable copy.
Two directory entries under one parent would carry the same cn value — how does a multi-valued RDN resolve that?
basics
~20 sA Relative Distinguished Name may hold more than one attribute type and value, joined in the string form with a plus sign, so a second attribute distinguishes the siblings. Every value used must also be present as an attribute of the entry.
Why would a service check one attribute value with an LDAP Compare rather than a search?
basics
~20 sCompare asks one yes-or-no question about one named entry and answers with the resultCode compareTrue(6) or compareFalse(5). It returns no attribute data, so it can confirm a value a caller is not permitted to read and cannot be used to enumerate.
In a SASL EXTERNAL LDAP Bind, where does the identity come from, and what does an authzId in the request change?
basics
~20 sSASL EXTERNAL carries no secret: it asks the directory to use an identity the layer beneath LDAP already established. An authzId in its credentials asks to act as someone else instead, which the server may refuse.
A replica reconnects after three weeks with an old syncCookie — what may an RFC 4533 server answer, and what must the replica then do?
basics
~20 sThe server may honour the old syncCookie and send a delta, or, at its discretion, answer e-syncRefreshRequired (4096), meaning the cookie is too stale to build a delta from and the replica must start a fresh session with no cookie and take a full refresh of the content.
showing 31–38 of 38