LDAP
Lightweight Directory Access Protocol
- Pronunciation
- EL-dap
In short
LDAP is an open protocol for searching and updating a directory service, the central database of an organization's users, groups and devices.
What is LDAP?
A directory is a database built for frequent reads: it stores entries for people, groups, computers and printers in a tree, much like folders. Each entry has a unique distinguished name (DN), such as uid=alice,ou=people,dc=example,dc=com, and attributes such as mail or memberOf. LDAP, created in the early 1990s as a lighter way to reach X.500 directories, is the standard protocol for working with them; its current version, LDAPv3, is defined in RFC 4511 and related RFCs.
A client connects to an LDAP server and sends operations: bind to authenticate, search to find entries that match a filter such as (uid=alice), and add, modify or delete to change them. Plain LDAP runs on port 389 and sends everything, including passwords, unencrypted, so it should be protected with StartTLS or replaced by LDAPS on port 636. Popular servers include Microsoft Active Directory, OpenLDAP and FreeIPA.
Think of LDAP as the way to look things up in a company phone book that also lists every employee's team and access badge. Many tools, such as VPNs, Git servers, CI systems and Linux machines, connect to the company directory over LDAP: they check a user's password with a bind and read their groups to decide what they may do, so accounts are managed in one place.
LDAP is often confused with Active Directory and with Kerberos. Active Directory is Microsoft's directory service, and LDAP is one of the protocols used to talk to it; Active Directory also uses Kerberos, which proves who a user is with tickets, while LDAP looks up information about them. LDAP authentication is also not single sign-on: each app shows its own login form and checks the password against the directory, whereas SAML or OpenID Connect send users to one identity provider, which often reads its accounts from LDAP behind the scenes.
Key takeaways
- LDAP is a protocol for searching and updating directory services.
- Entries form a tree and are named by distinguished names (DNs).
- Apps use an LDAP bind to check passwords and read group membership.
- Use LDAPS on port 636 or StartTLS; plain LDAP on port 389 is unencrypted.
- Active Directory, OpenLDAP and FreeIPA all support LDAP.
Example
# Find Alice's entry and her groups, over an encrypted LDAPS connection
ldapsearch -H ldaps://ldap.example.com \
-D "cn=app-reader,ou=services,dc=example,dc=com" -W \
-b "ou=people,dc=example,dc=com" \
"(uid=alice)" cn mail memberOf
# The result, in LDIF format:
# dn: uid=alice,ou=people,dc=example,dc=com
# cn: Alice Smith
# mail: alice@example.com
# memberOf: cn=developers,ou=groups,dc=example,dc=comReaders ask
What is the difference between LDAP and Active Directory?
Active Directory is Microsoft's directory service for Windows networks. LDAP is an open protocol for querying and updating directories, and Active Directory is one of many servers that support it, alongside OpenLDAP and FreeIPA.
What is the difference between LDAP and Kerberos?
LDAP stores and looks up information about users, groups and devices. Kerberos proves identity by issuing tickets. In a Windows domain, signing in uses Kerberos, and applications then use LDAP to find a user's details and groups.
Is LDAP secure?
Only when it is encrypted. Plain LDAP sends passwords in readable form, so use LDAPS or StartTLS, give applications read-only service accounts, and escape user input in search filters to prevent LDAP injection.
See also
- AuthenticationSecurity, p. 3Authentication is the process of verifying that a user, device, or service really is who it claims to be, for example by checking a password or passkey.
- KerberosSecurity, p. 24Kerberos is a network authentication protocol in which a trusted server issues time-limited tickets, so users prove who they are without sending passwords.
- SSOSecurity, p. 48SSO lets a user sign in once with a central identity provider and then access many separate applications without entering credentials again.
- AuthorizationSecurity, p. 4Authorization is the process of deciding what an authenticated user or service is allowed to do, such as which data it can read, change, or delete.
- SAMLSecurity, p. 42SAML is an XML-based single sign-on standard: an identity provider authenticates the user and sends the application a signed assertion that logs them in.
- RBACSecurity, p. 38RBAC is an authorization model that grants permissions to roles, such as admin or editor, and then gives users access by assigning them those roles.
Sources
Spotted a mistake or something missing on this page?Suggest an edit