An LDAP server MUST provide information about itself and other information that is specific to each server. This is represented as a group of attributes located in the rootDSE (DSA-Specific Entry), which is named with the zero-length LDAPDN. These attributes are retrievable if a client performs a base object search of the root with filter (objectClass=*)", however they are subject to access control restrictions. The RootDSE MUST NOT be included if the client performs a subtree search starting from the root.
DSAs may allow DUAs to modify these attributes.RootDSE is primarily a Discovery Mechanism for Lightweight Directory Access Protocol
If the server does not master entries and does not know the locations of schema information, the subschemaSubentry attribute is not present in the root DSE. If the server masters directory entries under one or more schema rules, there may be any number of values of the subschemaSubentry attribute in the root DSE.
- based on informayion retreived 2013-06-15