The Lightweight Directory Access Protocol (LDAP) is an open, vendor-neutral application protocol for accessing and maintaining distributed directory information services over an IP network, standardised in RFC 4511 (2006) as a simplification of the X.500 Directory Access Protocol. LDAP organises directory entries in a hierarchical tree structure (Directory Information Tree, DIT) where entries contain typed attribute-value pairs conforming to object class schemas, and supports operations for search, add, modify, delete, compare, and bind (authentication). It serves as the foundational protocol for enterprise identity management, enabling centralised authentication, authorisation, and user attribute storage across heterogeneous systems.
Content
- LDAP was developed at the University of Michigan in 1993 by Tim Howes, Mark Smith, and Gordon Good as a lightweight alternative to the complex OSI-layer X.500 Directory Access Protocol. The original DAP required a full OSI protocol stack that was impractical over TCP/IP networks; LDAP replaced it with a simplified binary protocol (ASN.1 BER encoding) that operated directly over TCP port 389 (or 636 for LDAPS with TLS). LDAP v3, published as RFC 2251 in 1997 and revised to RFC 4511 in 2006, added extensions including StartTLS, SASL authentication, and server-side sorting, becoming the stable standard still in use.
- The LDAP data model is built on the Directory Information Tree: each entry has a Distinguished Name (DN) that uniquely identifies its position in the hierarchy (e.g., uid=jsmith,ou=users,dc=example,dc=com). Entries are typed by object classes (inetOrgPerson, groupOfNames, organizationalUnit) that define which attributes are required and permitted. Schema definitions are themselves stored in the directory’s subschema subentry. Search operations specify a base DN, scope (base, one-level, or subtree), filter expression (using a prefix notation combining attribute tests with AND/OR/NOT), and requested attributes, returning matching entries efficiently through indexed attribute values.
- LDAP’s significance in enterprise IT is difficult to overstate: virtually all corporate environments rely on LDAP-compatible directories (primarily Microsoft Active Directory) for user authentication and authorisation. Email systems, VPNs, file servers, web applications, databases, and network devices all authenticate against LDAP, making it a single point of trust and a high-value attack target. Common attack vectors include LDAP injection (analogous to SQL injection but against LDAP filters), anonymous bind disclosure of directory structure, and credential stuffing attacks against the BIND operation.
- By 2024–2025 LDAP remains the dominant enterprise directory protocol despite its age, but is increasingly complemented or replaced in cloud-native environments. Azure AD (now Entra ID) provides LDAP-compatible interfaces alongside modern REST APIs and SCIM for provisioning. Zero-trust architectures de-emphasise network perimeter directory integration in favour of device identity and continuous authentication, reducing LDAP’s role. However, the billions of on-premises devices and legacy applications that speak only LDAP ensure its continued relevance for many years, driving investment in LDAP-to-modern-IdP gateways and cloud directory synchronisation.