RFC 2830 (rfc2830) - Page 1 of 12


Lightweight Directory Access Protocol (v3): Extension for Transport Layer Security



Alternative Format: Original Text Document



Network Working Group                                          J. Hodges
Request for Comments: 2830                                    Oblix Inc.
Category: Standards Track                                      R. Morgan
                                                      Univ of Washington
                                                                 M. Wahl
                                                  Sun Microsystems, Inc.
                                                                May 2000


              Lightweight Directory Access Protocol (v3):
                 Extension for Transport Layer Security

Status of this Memo

   This document specifies an Internet standards track protocol for the
   Internet community, and requests discussion and suggestions for
   improvements.  Please refer to the current edition of the "Internet
   Official Protocol Standards" (STD 1) for the standardization state
   and status of this protocol.  Distribution of this memo is unlimited.

Copyright Notice

   Copyright (C) The Internet Society (2000).  All Rights Reserved.

Abstract

   This document defines the "Start Transport Layer Security (TLS)
   Operation" for LDAP [LDAPv3, TLS]. This operation provides for TLS
   establishment in an LDAP association and is defined in terms of an
   LDAP extended request.

1.  Conventions Used in this Document

   The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT",
   "SHOULD", "SHOULD NOT", "RECOMMENDED",  "MAY", and "OPTIONAL" in this
   document are to be interpreted as described in [ReqsKeywords].

2.  The Start TLS Request

   This section describes the Start TLS extended request and extended
   response themselves: how to form the request, the form of the
   response, and enumerates the various result codes the client MUST be
   prepared to handle.

   The section following this one then describes how to sequence an
   overall Start TLS Operation.





Hodges, et al.              Standards Track