Lightweight Directory Access Protocol (v3): Technical Specification
obsoleted by
- rfc-4510 — Lightweight Directory Access Protocol (LDAP): Technical Specification Road Map
updates
- rfc-2251 — Lightweight Directory Access Protocol (v3)
- rfc-2252 — Lightweight Directory Access Protocol (v3): Attribute Syntax Definitions
- rfc-2253 — Lightweight Directory Access Protocol (v3): UTF-8 String Representation of Distinguished Names
- rfc-2254 — The String Representation of LDAP Search Filters
- rfc-2255 — The LDAP URL Format
- rfc-2256 — A Summary of the X.500(96) User Schema for use with LDAPv3
- rfc-2829 — Authentication Methods for LDAP
- rfc-2830 — Lightweight Directory Access Protocol (v3): Extension for Transport Layer Security
Extracted elements (5)
RFC 2251 through 2256 were published with an IESG Note discouraging deployment of LDAPv3 update functionality because they did not mandate any satisfactory authentication mechanism. RFC 2829 was subsequently published to address this gap, and RFC 3377 formally incorporates RFC 2829 into the LDAPv3 suite to resolve the IESG Note.
The term 'LDAPv3' is often used informally to refer to subsets of the nine-RFC suite. For formal interoperability and protocol identification purposes, documents must reference the complete suite as defined in RFC 3377 rather than relying on informal usage.
Other documents formally identifying the LDAPv3 protocol suite SHOULD cite RFC 3377 as the normative reference, rather than citing individual component RFCs or using the informal term 'LDAPv3'.
LDAPv3 is specified by nine RFCs: RFC 2251 (wire protocol), RFC 2252 (attribute syntax), RFC 2253 (UTF-8 DN representation), RFC 2254 (search filters), RFC 2255 (URL format), RFC 2256 (X.500 user schema), RFC 2829 (authentication methods), RFC 2830 (TLS extension), and RFC 3377 (this document). Other documents should identify LDAPv3 by normative reference to RFC 3377.
The IESG Note in RFC 2251–2256 discouraged deployment of LDAPv3 clients or servers implementing update functionality until a Proposed Standard for mandatory authentication was published. RFC 2829 satisfies that requirement, formally addressing the security concern. Implementors should refer to RFC 2829, RFC 2251, and RFC 2830 for LDAPv3 security details.