Network Working Group K. Zeilenga Request for Comments: 3673 OpenLDAP Foundation Category: Standards Track December 2003Lightweight Directory Access Protocol version 3 (LDAPv3): All Operational Attributes
1. Overview
X.500 [X.500] provides a mechanism for clients to request all operational attributes be returned with entries provided in response to a search operation. This mechanism is often used by clients to discover which operational attributes are present in an entry.
Zeilenga Standards Track [Page 1]
RFC 3673 LDAPv3: All Operational Attributes December 2003 2. All Operational AttributesThe presence of the attribute description "+" (ASCII 43) in the list of attributes in a Search Request [RFC2251] SHALL signify a request for the return of all operational attributes.
3. Interoperability Considerations
This mechanism is specifically designed to allow users to request all operational attributes using existing LDAP clients. In particular, the mechanism is designed to be compatible with existing general purpose LDAP clients including those supporting LDAP URLs [RFC2255].
4. Security Considerations
This document provides a general mechanism which clients may use to discover operational attributes. Prior to the introduction of this mechanism, operational attributes were only returned when requested by name. Some might have viewed this as obscurity feature. However, this feature offers a false sense of security as the attributes were still transferable.
Zeilenga Standards Track [Page 2]
RFC 3673 LDAPv3: All Operational Attributes December 2003 5. IANA ConsiderationsThis document uses the OID 1.3.6.1.4.1.4203.1.5.1 to identify the feature described above. This OID was assigned [ASSIGN] by OpenLDAP Foundation, under its IANA-assigned private enterprise allocation [PRIVATE], for use in this specification.
6. Acknowledgment
The "+" mechanism is believed to have been first suggested by Bruce Greenblatt in a November 1998 post to the IETF LDAPext Working Group mailing list.
7. Intellectual Property Statement
The IETF takes no position regarding the validity or scope of any intellectual property or other rights that might be claimed to pertain to the implementation or use of the technology described in this document or the extent to which any license under such rights might or might not be available; neither does it represent that it has made any effort to identify any such rights. Information on the IETF's procedures with respect to rights in standards-track and standards-related documentation can be found in BCP-11. Copies of claims of rights made available for publication and any assurances of licenses to be made available, or the result of an attempt made to obtain a general license or permission for the use of such proprietary rights by implementors or users of this specification can be obtained from the IETF Secretariat. The IETF invites any interested party to bring to its attention any copyrights, patents or patent applications, or other proprietary rights which may cover technology that may be required to practice this standard. Please address the information to the IETF Executive Director.
Zeilenga Standards Track [Page 3]
RFC 3673 LDAPv3: All Operational Attributes December 2003 8. References 8.1. Normative References[RFC2119] Bradner, S., "Key words for use in RFCs to Indicate
8.2. Informative References
[RFC2255] Howes, T. and M. Smith, "The LDAP URL Format", RFC 2255,
9. Author's Address
Kurt D. Zeilenga OpenLDAP Foundation
Zeilenga Standards Track [Page 4]
RFC 3673 LDAPv3: All Operational Attributes December 2003 10. Full Copyright StatementCopyright (C) The Internet Society (2003). All Rights Reserved.