LDAP subentries are analogous to operational attributes in that they are used by the server for administrative purposes. Examples include password policies, entries for allocating collective attributes, and the entry exposing directory schema.

Unlike entries in the server-specific configuration backend, Subentries are present in and replicated with user data. Modifying subentries nevertheless requires the subentry-write administrative privilege.

For details, see the Internet-Draft, LDAP Subentry Schema .

Names ldapSubEntry
Origin draft-ietf-ldup-subentry
Superior Classes top
Description LDAP Subentry class, version 1
Optional Attributes cn
Schema File 00-core.ldif
OID 2.16.840.1.113719.
Class Type STRUCTURAL: for structural specification of the DIT. Entries have only one structural object class superclass chain.
Required Attributes objectClass
