Introduction to LDAP Directory service protocol for CentOS 6.2

Source: Internet
Author: User
Tags ldap ldap protocol centos openldap

LDAP is light weight Directory access Protocol (Lightweight Directory Access Protocol), formerly known as the more ancient DAP protocol. It is based on the X.500 standard, but it is simple and can be tailored to your needs. Unlike X.500, LDAP supports TCP/IP, which is necessary for accessing the Internet. The core specification of LDAP is defined in the RfC, and in general, the LDAP protocol defines the methods for communicating with the backend database, the communication standards between the client software and the LDAP protocol, such as the latter.

LDAP client refers to a variety of software that requires authentication, such as Apache, PROFTPD, and samba. LDAP sever refers to software that implements the LDAP protocol, such as OpenLDAP. Datastorage refers to OPENLDAP data storage, such as relational database (MYSQL) or query-efficient embedded database (BERKELEYDB), or even a flat text database (a txt text file). Visible OpenLDAP software is only an implementation of the LDAP protocol, does not include background database storage, but in many cases, administrators often put ldapserver and datastorage on the same server, so that the common LDAP database, Although background databases can be varied, the LDAP protocol also prescribes how data is stored. The LDAP database is a tree-like structure, similar to DNS.

WEBLDAP Architecture

One of the biggest benefits of storing data in this way is the query speed block, the LDAP database is optimized for read operations, and OpenLDAP with Berkeley DB can greatly improve the efficiency of its read operations, Another benefit of the tree structure of the LDAP database is the ease of distributed management.

Realize the idea

The same identity authentication is to change the original authentication strategy, so that the need to authenticate the software through LDAP authentication, the following figure. After the same authentication, all of the user's information is stored in the LDAP server. End users need to authenticate with the LDAP server when they need to use the internal services of the company. Each employee simply remembers a password and can modify the information in the LDAP server directly from the Web interface provided by the administrator when the user's information needs to be modified.

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.