25.02.2013 Views

TCP/IP Tutorial and Technical Overview - IBM Redbooks

TCP/IP Tutorial and Technical Overview - IBM Redbooks

TCP/IP Tutorial and Technical Overview - IBM Redbooks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

12.4.4 LDAP models<br />

distinguished names. This tree of directory entries is called the directory<br />

information tree (DIT).<br />

LDAP defines operations for accessing <strong>and</strong> modifying directory entries, such as:<br />

► Searching for entries meeting user-specified criteria<br />

► Adding an entry<br />

► Deleting an entry<br />

► Modifying an entry<br />

► Modifying the distinguished name or relative distinguished name of an entry<br />

(move)<br />

► Comparing an entry<br />

LDAP can be better understood by considering the four models upon which it is<br />

based:<br />

Information Describes the structure of information stored in an LDAP<br />

directory.<br />

Naming Describes how information in an LDAP directory is organized<br />

<strong>and</strong> identified.<br />

Functional Describes the operations that can be performed on the<br />

information stored in an LDAP directory.<br />

Security Describes how the information in an LDAP directory can be<br />

protected from unauthorized access.<br />

The following sections discuss the first three LDAP models. We describe LDAP<br />

security in 12.4.5, “LDAP security” on page 471.<br />

The information model<br />

The basic unit of information stored in the directory is an entry, which represents<br />

an object of interest in the real world such as a person, server, or organization.<br />

Each entry contains one or more attributes that describe the entry. Each attribute<br />

has a type <strong>and</strong> one or more values. For example, the directory entry for a person<br />

might have an attribute called telephoneNumber. The syntax of the<br />

telephoneNumber attribute specifies that a telephone number must be a string of<br />

numbers that can contain spaces <strong>and</strong> hyphens. The value of the attribute is the<br />

person's telephone number, such as 123-456-7890 (a person might have<br />

multiple telephone numbers, in which case this attribute would have multiple<br />

values).<br />

464 <strong>TCP</strong>/<strong>IP</strong> <strong>Tutorial</strong> <strong>and</strong> <strong>Technical</strong> <strong>Overview</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!