RFC 4513 - LDAP: 認証方法とセキュリティメカニズム (Authentication Methods and Security Mechanisms)
Network Working Group R. Harrison, Ed. Request for Comments: 4513 Novell, Inc. Obsoletes: 2251, 2829, 2830 June 2006 Category: Standards Track
本メモの位置づけ (Status of This Memo)
本文書はインターネットコミュニティ向けのインターネット標準トラックプロトコルを規定し、議論と改善提案を求めます。本プロトコルの標準化状態とステータスについては、"Internet Official Protocol Standards" (STD 1) の現行版を参照してください。本メモの配布は無制限です。
著作権表示 (Copyright Notice)
Copyright (C) The Internet Society (2006).
概要 (Abstract)
本文書は Lightweight Directory Access Protocol (LDAP) の認証方法とセキュリティメカニズムを記述します。StartTLS 操作を用いた Transport Layer Security (TLS) の確立について詳述します。
匿名 (anonymous)、未認証 (unauthenticated)、名前/パスワード (name/password) メカニズムを含む simple Bind 認証方法、および EXTERNAL メカニズムを含む Simple Authentication and Security Layer (SASL) Bind 認証方法について詳述します。
LDAP サーバへのセッションが取り得る各種の認証・認可状態と、それらの状態遷移を引き起こす動作について議論します。
本文書は LDAP 技術仕様の他文書 (仕様ロードマップ第 1 節参照) と合わせて、RFC 2251、RFC 2829、RFC 2830 を廃止します。
目次 (Table of Contents)
- はじめに (Introduction)
- 実装要件 (Implementation Requirements)
- StartTLS 操作 (StartTLS Operation)
- 認可状態 (Authorization State)
- Bind 操作 (Bind Operation)
- セキュリティの考慮事項 (Security Considerations)
- IANA の考慮事項 (IANA Considerations)
- 謝辞 (Acknowledgements)
- 規範的参照 (Normative References)
- 参考情報 (Informative References)
- 付録 A. 認証と認可の概念
- 付録 B. 変更の要約