Lightweight Directory Access Protocol (LDAP): Technical Specification Road Map
obsoletes
- rfc-2251 — Lightweight Directory Access Protocol (v3)
- rfc-2252 — Lightweight Directory Access Protocol (v3): Attribute Syntax Definitions
- rfc-2253 — Lightweight Directory Access Protocol (v3): UTF-8 String Representation of Distinguished Names
- rfc-2254 — The String Representation of LDAP Search Filters
- rfc-2255 — The LDAP URL Format
- rfc-2256 — A Summary of the X.500(96) User Schema for use with LDAPv3
- rfc-2829 — Authentication Methods for LDAP
- rfc-2830 — Lightweight Directory Access Protocol (v3): Extension for Transport Layer Security
- rfc-3377 — Lightweight Directory Access Protocol (v3): Technical Specification
- rfc-3771 — The Lightweight Directory Access Protocol (LDAP) Intermediate Response Message
Extracted elements (9)
LDAP is defined in terms of X.500 as an X.500 access mechanism, but only X.500(93) is incorporated; later revisions of X.500 do not automatically apply to this technical specification. This pins the specification to a stable baseline without obligating implementors to track evolving ITU-T revisions.
LDAP is designed as an extensible protocol; extensions are expected to be truly optional. Considerations for LDAP extensions are governed by BCP 118 (RFC 4521), and those considerations fully apply to this revision of the technical specification.
RFC 4518 (Internationalized String Preparation) is new to this revision of the LDAP technical specification and has no predecessor document in the obsoleted RFC 3377 suite.
This technical specification entirely obsoletes the previous LDAP technical specification defined in RFC 3377 (comprising RFCs 2251–2256, 2829, 2830, 3771, and 3377). The specification was significantly reorganized across the component RFCs listed in Section 1.
An LDAP server MUST act in accordance with the X.500 (1993) series of ITU-T Recommendations when providing the directory service. However, an LDAP server is not required to use X.500 protocols internally; LDAP may be mapped onto any other directory system as long as the X.500 data and service models are not violated at the LDAP interface.
Other documents that formally identify the LDAP suite SHOULD do so by a normative reference to RFC 4510 (this document), rather than to individual component RFCs. The terms 'LDAP' and 'LDAPv3' informally refer to the protocol specified by this technical specification.
The LDAP Technical Specification version 3 consists of RFC 4510 (this road map) plus RFC 4511 (Protocol), RFC 4512 (Directory Information Models), RFC 4513 (Authentication Methods and Security Mechanisms), RFC 4514 (String Representation of Distinguished Names), RFC 4515 (String Representation of Search Filters), RFC 4516 (Uniform Resource Locator), RFC 4517 (Syntaxes and Matching Rules), RFC 4518 (Internationalized String Preparation), and RFC 4519 (Schema for User Applications).
IANA considerations for LDAP are governed by BCP 64 (RFC 4520), which fully applies to this revision of the LDAP technical specification. RFC 4520 defines the registries and procedures for LDAP-related assignments.
LDAP security considerations are not consolidated in this road map document; instead they are discussed in each document comprising the technical specification (RFC 4511 through RFC 4519). Implementors must consult all component specifications for complete security guidance.