Sun ONE logo     Previous      Contents      Index      Next     
Sun ONE Directory Server 5.2 Reference Manual



Appendix D      LDAP URLs

One way to express an LDAP query is to use a URL to specify the directory server host machine and the DN or filter for the search. Sun ONE Directory Server will respond to queries sent as LDAP URLs and return an HTML page representing the results. This allows web browsers to perform searches of the directory, if anonymous searching is permitted.

You can also use LDAP URLs to specify target entries when managing Directory Server referrals or access control instructions.

This chapter contains the following sections:

Components of an LDAP URL

LDAP URLs have the following syntax:

ldap[s]://hostname:port/base_dn?attributes?scope?filter

When ldap://... is specified, standard LDAP is used to connect to the LDAP servers. When ldaps://... is specified, LDAP over SSL is used to connect to the LDAP server.

Table D-1    LDAP URL Components

Component

Description

hostname

Name (or IP address in dotted format) of the LDAP server. For example:

ldap.example.com or 192.202.185.90

port

Port number of the LDAP server (for example, 49153).

If no port is specified, the standard LDAP port (389) or LDAPS port (636) is used.

base_dn

Distinguished name (DN) of an entry in the directory. This DN identifies the entry that is the starting point of the search.

If no base DN is specified, the search starts at the root of the directory tree.

attributes

The attributes to be returned. To specify more than one attribute, use commas to separate the attributes (for example, "cn,mail,telephoneNumber").

If no attributes are specified in the URL, all attributes are returned.

scope

The scope of the search, which can be one of these values:

  • base retrieves information about the distinguished name (base_dn) specified in the URL only.
  • one retrieves information about entries one level below the distinguished name (base_dn) specified in the URL. The base entry is not included in this scope.
  • sub retrieves information about entries at all levels below the distinguished name (base_dn) specified in the URL. The base entry is included in this scope.

If no scope is specified, the server performs a base search.

filter

Search filter to apply to entries within the specified scope of the search.

If no filter is specified, the server uses the filter (objectClass=*).

The attributes, scope, and filter components are identified by their positions in the URL. If you do not want to specify any attributes, you must still include the question marks delimiting that field. For example, to specify a subtree search starting from "dc=example,dc=com" that returns all attributes for entries matching "(sn=Jensen)", use the following LDAP URL:

ldap://ldap.example.com/dc=example,dc=com??sub?(sn=Jensen)

The two consecutive question marks ?? indicate that no attributes have been specified. Since no specific attributes are identified in the URL, all attributes are returned in the search.

Escaping Unsafe Characters

Any unsafe characters in the URL must be represented by a special sequence of characters. This is called escaping unsafe characters. For example, a space is an unsafe character that must be represented as %20 within the URL. Thus, the distinguished name "o=example corporation" must be encoded as "o=example%20corporation".

The following table lists the characters that are considered unsafe within URLs and provides the associated escape characters to use in place of the unsafe character:

Unsafe Character

Escape Characters

space

%20

<

%3c

>

%3e

"

%22

#

%23

%

%25

{

%7b

}

%7d

|

%7c

\

%5c

^

%5e

~

%7e

[

%5b

]

%5d

`

%60

Examples of LDAP URLs

  • The following LDAP URL specifies a base search for the entry with the distinguished name dc=example,dc=com.
  • ldap://ldap.example.com/dc=example,dc=com

    • Because no port number is specified, the standard LDAP port number (389) is used.
    • Because no attributes are specified, the search returns all attributes.
    • Because no search scope is specified, the search is restricted to the base entry dc=example,dc=com.
    • Because no filter is specified, the directory uses the default filter (objectclass=*).

  • The following LDAP URL retrieves the postalAddress attribute of the entry with the DN dc=example,dc=com:
  • ldap://ldap.example.com/dc=example,dc=com?postalAddress

    • Because no search scope is specified, the search is restricted to the base entry dc=example,dc=com.
    • Because no filter is specified, the directory uses the default filter (objectclass=*).

  • The following LDAP URL retrieves the cn, and mail attributes of the entry for Barbara Jensen:
  • ldap://ldap.example.com/cn=Barbara%20Jensen,dc=example,
     dc=com?cn,mail

    • Because no search scope is specified, the search is restricted to the base entry cn=Barbara Jensen,dc=example,dc=com.
    • Because no filter is specified, the directory uses the default filter (objectclass=*).

  • The following LDAP URL specifies a search for entries that have the surname Jensen and are at any level under dc=example,dc=com:
  • ldap://ldap.example.com/dc=example,dc=com??sub?(sn=Jensen)

    • Because no attributes are specified, the search returns all attributes.
    • Because the search scope is sub, the search encompasses the base entry dc=example,dc=com and entries at all levels under the base entry.

  • The following LDAP URL specifies a search for the object class for all entries one level under dc=example,dc=com:
  • ldap://ldap.example.com/dc=example,dc=com?objectClass?one

    • Because the search scope is one, the search encompasses all entries one level under the base entry dc=example,dc=com. The search scope does not include the base entry.
    • Because no filter is specified,the directory uses the default filter (objectclass=*).


    • Note

      The syntax for LDAP URLs does not include any means for specifying credentials or passwords. Search requests initiated through LDAP URLs are unauthenticated (anonymous), unless the LDAP client that supports LDAP URLs provides an authentication mechanism.




Previous      Contents      Index      Next     
Copyright 2003 Sun Microsystems, Inc. All rights reserved.