What is the LDIF file format?
An .ldif file contains LDAP object data saved in plain text for LDAP data interchange. The LDIF specification is defined in RFC 2849, published in June 2000. LDAP (Lightweight Directory Access Protocol) is a standard for directory information services based on the X.500 standard but requires far fewer resources and bandwidth; it runs over TCP/IP.
An .ldif file can store either information about a directory or changes made to it, never both in the same file. The file may open with an optional version: 1 line, followed by one or more records. Each record begins with a dn: (distinguished name) line - the unique identifier of the directory object - followed by attribute: value pairs. A blank line separates consecutive records. Non-ASCII or binary attribute values are Base64-encoded and marked with a double colon (attribute:: value); long lines may be folded by inserting a newline and a single leading space.
LDIF file structure is comprised of sets of records and separators. Operations that can be stored in change-record .ldif files include:
add- add a record,delete- delete a record,modify- modify a record,modrdn/moddn- change a distinguished name (the record's unique identifier).
Records of applied changes comprise a changetype: line that identifies the operation and additional lines describing each change. Records that store directory content are represented as multiple lines which identify the object and its attributes in the form of attribute: value pairs.
.ldif files are used with command-line tools such as ldapadd and ldapmodify (part of OpenLDAP), as well as graphical tools like Apache Directory Studio, when importing or exporting directories. Mozilla Thunderbird can export and import address books as .ldif, making them interoperable with vCard files and CSV spreadsheets. Because directory dumps may contain password hashes and personal data, .ldif files should be treated as confidential.
Security & safety
RISK: LOWAn LDIF file is plain text and does not execute, so opening one is safe. The real concern is data sensitivity, not malware: LDIF directory dumps can contain personal data, organisational structure, group memberships and sometimes password hashes (e.g. userPassword attributes) - treat them as confidential, store them securely and avoid emailing raw directory exports. When importing an unfamiliar LDIF into a live directory, review the 'changetype:' lines first, since a change record can delete or overwrite existing entries.
Format details
in a nutshellPrograms that open LDIF files
Technical details
deep spec| MIME type | text/plain; also recognized as application/ldif and text/x-ldif |
| File encoding | Plain UTF-8 text; non-ASCII and binary attribute values are Base64-encoded inline |
| Record identifier | Every record opens with a dn: line (distinguished name) - the unique object identifier in the directory tree |
| Record separator | A single blank line between consecutive records |
| Value encoding marker | Single colon (attribute: value) for plain text; double colon (attribute:: value) for Base64-encoded values |
| Line folding | Long lines may be split by inserting a newline followed by exactly one leading space on the continuation line |
| Record flavours | Content records store a directory snapshot; change records carry changetype: add, modify, delete, or modrdn operations |
| File identification | No binary magic bytes; identified by version: 1 or dn: appearing at the start of a line |
| Format version field | Optional version: 1 declaration on the first line, as defined in RFC 2849 |
| Typical file size | Kilobytes for small address books; hundreds of megabytes for large enterprise LDAP directory exports |
| Security sensitivity | May contain userPassword hashes and personal attributes; must be protected like any confidential directory data |
| Platform support | Cross-platform - Windows, macOS, Linux; usable on any OS with an LDAP client or plain-text editor |
| Released | Early 1990s with the University of Michigan LDAP project; standardized as RFC 2849 (June 2000) |
| Latest version | RFC 2849 (2000); change-record extensions in related RFCs |
| Open standard | Yes · royalty-free |
| Specification | www.rfc-editor.org |
LDIF conversions
Community Q&A
asked by usersNo questions yet - be the first to ask about LDIF files.