Lightweight Directory Access Protocol (LDAP)

The standard protocol for querying and updating a directory service, defined in RFC 4511; also used to check credentials by binding to the directory as a user.

The Lightweight Directory Access Protocol (LDAP) is the standard protocol clients use to search, read and update a directory service. Version 3 is specified in a set of RFCs whose roadmap is RFC 4510, with the protocol itself in RFC 4511. It grew out of the X.500 directory standards as a lighter way to reach the same kind of hierarchical directory, in which each entry is named by a distinguished name that shows its place in the tree.

Applications commonly use LDAP for authentication as well as lookup: they “bind” to the directory with the user’s name and password, and a successful bind confirms the credentials. That makes transport protection important. A simple bind sends the password as supplied, so without TLS, applied through the StartTLS operation described in RFC 4513 or by running LDAP inside a TLS connection from the start (commonly called LDAPS), it can be read on the network. Applications that build LDAP queries from unchecked input are also open to LDAP injection. Many enterprise directories pair LDAP with Kerberos for authentication.

Exam relevance: a scenario is likely to describe an application checking passwords against a corporate directory. Candidates are expected to recognise LDAP, and to see an unencrypted simple bind as the weakness that a protected channel addresses.