Provides an interface to a Lightweight Directory Access Protocol
(LDAP) directory server, such as the Netscape Directory Server.

 <cfldap server="">


Attribute Reference for the cfldap tag


Required: Yes
Host name or IP address of LDAP server.


Required: No
Default: 389
Port of the LDAP server (default 389).


Required: No
The User ID. Required if secure = "CFSSL_BASIC"


Required: No
Password that corresponds to user name.
If secure = "CFSSL_BASIC", V2 encrypts the password before


Required: No
Default: query
* query: returns LDAP entry information only. Requires name,
start, and attributes attributes.
* add: adds LDAP entries to LDAP server. Requires attributes
* modify: modifies LDAP entries, except distinguished name dn
attribute, on LDAP server. Requires dn. See modifyType attribute.
* modifyDN: modifies distinguished name attribute for LDAP
entries on LDAP server. Requires dn.
* delete: deletes LDAP entries on an LDAP server. Requires dn. Values:
  • query
  • add
  • modify
  • modifyDN
  • delete


Required: No
Required if action = "Query"
Name of LDAP query. The tag validates the value.


Required: No
Default: 60000
Maximum length of time, in seconds, to wait for LDAP processing.
Default 60000


Required: No
Maximum number of entries for LDAP queries.


Required: No
Required if action = "Query"
Distinguished name of entry to be used to start a search.


Required: No
Default: onelevel
Scope of search, from entry specified in start attribute for
action = "Query".
* oneLevel: entries one level below entry.
* base: only the entry.
* subtree: entry and all levels below it. Values:
  • onelevel
  • base
  • subtree


Required: No
Required if action = "Query", "Add", "ModifyDN", or "Modify"
For queries: comma-delimited list of attributes to return. For
queries, to get all attributes, specify "*".

If action = "add" or "modify", you can specify a list of update
columns. Separate attributes with a semicolon.

If action = "ModifyDN", CFML passes attributes to the
LDAP server without syntax checking.


Required: No
CF 7+ A comma-delimited list of columns that are to
be returned as binary values.


Required: No
Search criteria for action = "Query".
List attributes in the form:
"(attribute operator value)" Example: "(sn = Smith)"


Required: No
Attribute(s) by which to sort query results. Use a comma


Required: No
Default: asc
Default asc
* nocase: case-insensitive sort
* asc: ascending (a to z) case-sensitive sort
* desc: descending (z to a) case-sensitive sort

You can enter a combination of sort types; for example,
sortControl = "nocase, asc". Values:
  • nocase
  • asc
  • desc
  • nocase, desc
  • nocase, asc


Required: No
Distinguished name, for update action. Example:
"cn = Bob Jensen, o = Ace Industry, c = US"


Required: No
Used with action = "query". First row of LDAP query to insert
into a CFML query.


Required: No
Default: replace
Default replace

How to process an attribute in a multi-value list.
* add: appends it to any attributes
* delete: deletes it from the set of attributes
* replace: replaces it with specified attributes

You cannot add an attribute that is already present or that is
empty. Values:
  • add
  • delete
  • replace


Required: No
Default: NO
* Yes: attempt to rebind referral callback and reissue query by
referred address using original credentials.
* No: referred connections are anonymous


Required: No
Number of hops allowed in a referral. A value of 0 disables
referred addresses for LDAP; no data is returned.


Required: No
Security to employ, and required information. One option:

"CFSSL_BASIC" provides V2 SSL encryption
and server authentication. Values:


Required: No
Default: ,
Default , (a comma)
Delimiter to separate attribute values of multi-value
attributes. Used by query, add, and modify actions, and by
cfldap to output multi-value attributes.

For example, if $ (dollar sign), the attributes attribute could
be "objectclass = top$person", where the first value of
objectclass is top, and the second value is person. This avoids
confusion if values include commas. Values:
  • ,
  • ;
  • |
  • :


Required: No
Default: ;
Separator between attribute name-value pairs. Use this
attribute if:

* the attributes attribute specifies more than one item, or
* an attribute contains the default delimiter (semicolon). For
example: mgrpmsgrejecttext;lang-en

Used by query, add, and modify actions, and by cfldap to output
multi-value attributes.

For example, if $ (dollar sign), you could specify
"cn = Double Tree Inn$street = 1111 Elm; Suite 100 where the
semicolon is part of the street value. Values:
  • ,
  • ;
  • |
  • :


Required: No
CF 11+ A file path to a client certificate.


Required: No
CF 11+ The password for the client certificate file.


Required: No
Default: false
CF 11+ Indicates that the connection should be made using transport layer security.

Fork me on GitHub