Overview
ISO/IEC 9594-3:2020 (ITU‑T X.511) - Information technology - Open systems interconnection - Part 3: The Directory: Abstract service definition - defines, at an abstract level, the externally visible service provided by the Directory. It specifies the Directory’s capabilities and service semantics without prescribing particular implementations or products. The standard underpins directory services (e.g., X.500-based systems) and provides the conceptual foundation for protocol versions 1 and 2, Directory Information Base (DIB) structures, and service behaviour.
Key Topics and Technical Requirements
- Directory service model: Abstract definition of the Directory, its role in Open Systems Interconnection (OSI), and the Directory Information Base (DIB) used to represent entries (people, application entities, devices, distribution lists).
- Operations and procedures: Bind/Unbind, Read, Compare, List, Search, Add/Remove/Modify Entry, Modify DN, Change/Administer Password, Abandon, and LDAP transport/linked operations.
- Information types and controls: Entry information selection, filters, paged results, request/response arguments, common results and service controls.
- Authentication and access control: Simple authentication, password policy, security parameters, and operational semantics for Basic Access Control (annexed).
- Error handling and analysis: Error precedence, specific error categories (Name Error, Attribute Error, Security Error, Referral, etc.), and analysis of search arguments and filters.
- Protocol versions and extensibility: Supports Directory protocol versions 1 and 2; some enhanced services (e.g., signed errors) require all parties to negotiate version 2. Extensibility rules align with the broader 9594 series.
- Data representation: Annex A provides the ASN.1 module for the abstract service; Annex D contains related external ASN.1 modules.
Practical Applications and Users
- Directory architects and engineers designing interoperable directory services and identity repositories.
- LDAP/X.500 implementers and vendors building server and client products that conform to abstract service semantics.
- Systems integrators and enterprise IT planning directory-based authentication, address books, resource discovery, and identity management.
- Standards bodies and industry forums that profile or mandate optional features for specific environments (e.g., enterprise, government).
- Security teams enforcing password policies, access control models, and secure Bind operations.
Related Standards
- ISO/IEC 9594 series (other parts of the Directory specifications)
- ITU‑T X.518 and X.519 (protocols, information models and extensibility guidance)
- ASN.1 modules referenced throughout (see Annex A and D)
ISO/IEC 9594-3:2020 is essential reading for anyone designing or implementing interoperable directory services compliant with OSI/X.500 principles and for organizations that require a standardized, abstract service definition for directory-driven identity and resource management.