Over time, memories fade slowly and become chaotic in our minds. It turns out that the same is true for technology: as early as 1980s, people created Lightweight Directory Access Protocol LDAP) to enable various applications to interwork with OSI in an open system) in the X.500 Directory Service, LDAP initially stores/retrieves information because the X386 computer running the dossystem cannot load X.500's normal access protocol-Directory Access Protocol dap in the 640KRAM required by DOS ), people created such a "lightweight" DAP version so that these platforms can query this directory ). Although the X.500 Directory and x386 computers have disappeared like dinosaurs, the General Open Architecture library repository continues to exist.
Although LDAP retains the original X.500 Directory Service standard, it has now evolved from a low-level protocol that supports the DOS system to the directory service itself. The concepts of LDAP and database are not only confusing, but even the Open Architecture OpenLDAP is confused with LDAP. Many companies now have LDAP-compatible directories, such as Microsoft's Active Directory, IBM's Tivoli Directory Service, and Oracle's Java System Directory Server Enterprise Edition, both have private architectures within the enterprise. When X.500 disappears, the Open Architecture library disappears.
The X.500 open and standardized directory can be replaced by the database of another vendor directly) has been replaced by the LDAP compatible directory today, which provides interoperability, that is, the products of the two suppliers can be compatible with each other. However, OpenLDAP uses the old standard OSI model for community development for interoperability. Unlike existing commercial products, OpenLDAP is an open-source LDAP-compatible directory. It is actually composed of a lot of residual content of the earlier X.500. OpenLDAP is maintained and supported by the OpenLDAP organization and coordinated by the OpenLDAP Foundation. The OpenLDAP Foundation is a non-profit organization that relies on corporate sponsorship and personal donations) to promote open-source LDAP development. OpenLDAP follows the Internet Engineering Task Group IETF RFC-4510 standards like most LDAP-compatible products. This standard defines the standards and protocols required for collaboration with LDAP-compatible directories.
Best Use Cases of OpenLDAP
What are the values of OpenLDAP and how should enterprises use it? OpenLDAP can run on Windows and Unix platforms and is a free directory software compatible with LDAP. This means that it can be used as an independent library or as source code used in the vendor's proprietary library and application software.
Using OpenLDAP in Windows cannot replace Microsoft's Active Directory, because as described above, all commercial LDAP compatible libraries are proprietary to various companies. This means that the Active Directory implements other specialized objects and APIs used by other Microsoft products. By purchasing Microsoft's authorized products, enterprises that use Windows systems will obtain some advanced features. However, if the applications used by enterprises are not compatible with the Active Directory, they must pay more for integration, purchase authorization plug-ins, or select another directory structure. When multiple applications need to access the LDAP directory, OpenLDAP can be used as a substitute for the Active Directory. enterprises do not have to pay additional fees or gain authorization to use the Active Directory. For example, OpenLDAP can follow the common address list GAL in the Active Directory to provide this information for internal development applications that need this information. In addition, other applications and platforms that use LDAP for authentication and object storage can also use this free library.
OpenLDAP is also developed by the community. Compared with limited vendors and budgets, OpenLDAP provides more innovation. OpenLDAP supports many optional LDAP functions and extensions in the latest LDAP standard v3.3), which may not appear in other commercial LDAP compatibility products. The current OpenLDAP release version supports more than 30 optional features and extensions, including DNS-based service location RFC 2247 & RFC 3088), X.509 Certificate chart RFC 4523), and password Modification Operation RFC 3062) and other functions. Because these features are generally not supported by commercial vendors, OpenLDAP may be the only choice for enterprises because they need to obtain these features to support a variety of applications. Are there any potential adverse factors? Free does not mean that the cost will not increase. This is because any open-source software will have some fixed costs, either in time or in resources, such:
◆ OpenLDAP does not provide services by professionals. Therefore, the personnel responsible for installation, configuration, and maintenance of OpenLDAP must be proficient in LDAP software and be able to create consolidation programs, to bind OpenLDAP to an application that uses OpenLDAP data.
◆ OpenLDAP does not have a GUI. All installation and configuration must be completed through the command line.
◆ Multi-language support only exists in the mailing list outside the OpenLDAP project, especially the mailing list that has not been approved or approved by the OpenLDAP project ).
◆ Product support is provided by the problem tracking system of the OpenLDAP website, which is independently supported by members of OpenLDAP.
◆ Although the OpenLDAP technical support website plans and records updates and patches, updates and patches are not published on a regular basis.
Finally, it must be noted that the operation of OpenLDAP is not guaranteed. As mentioned above, organizations that provide support can only rely on sponsorship and personal donations. However, even with these restrictions, OpenLDAP still provides features that are not available and cannot be provided by proprietary software products. OpenLDAP stands out when enterprises want to maintain the diversity of application infrastructure and business directory products cannot meet the user-defined requirements. With OpenLDAP on the market, suppliers always think of the Database Interchange era. They need to continue to provide a variety of innovative products, or one day OpenLDAP may make their products kill.
- OpenLDAP migration: migrate data from the Active Directory to OpenLDAP
- Multiple unknown code execution vulnerabilities in OpenLDAP