Northwestern University
 
Information Technology
Information Systems Architecture

LDAP Directory Database

Main Record Schema

The LDAP Registry as the central repository for electronic identities and attributes within Northwestern network. This Web site is both a definition of the data elements that are housed in the LDAP Registry and a starting point for application authors seeking what attributes are available.

Access to information in the LDAP Registry is limited to authorized programs and computers. White Pages directory information is available to anonymous queries as described on the White Pages Directory Data Items Web page. Display of personal information can be managed by the user through several privacy controls.

Note: Rows shaded in dark gray are not implemented.

Fields most commonly used by applications

Attribute Name Description Single or
Multiple Value
Search By: Privacy Notes
nuIdTag Valid Identifier(s). This is the field searched during authentication to identify the user.
Multiple
Value
displayname Display name
Single
Value & substrings
cn Common name. This is the field searched when attempting to find a user by name.
Multiple
Value & substrings
employeeNumber HR emplid
Single
Value
nuStudentNumber SES emplid
Single
Value
eduPersonPrimaryAffiliation Primary affiliation ("student", "employee", etc.)
Single
employeeType Employee attribute
Single
uid Unique Identifier (Northwestern NetID).
Single
Value
nuRoles Role(s) assigned to this identity
Multiple
Value
nuSnapGroups List of open SNAP group memberships
Multiple
Value & substrings
nuCurriculumOnly School affiliation
Multiple
Value

Additional fields of personal information that are subject to privacy policies.

Attribute Name Description Single or
Multiple Value
Search By: Privacy Notes
givenName First name string of displayname
Single
Value & substrings
nuMiddleName Middle name of displayname
Single
sn Surname of displayname
Single
Value & substrings
nuLegalName Legal name
Single
nuProName Professional name
Single
ou Organization unit(s) or department(s)
Multiple
telephoneNumber Primary office telephone number
Single
nuGivenNameSearch All visible given names
Multiple
Value & substrings
nuMiddleNameSearch All visible middle names
Multiple
Value & substrings
nuSnSearch All visible surnames
Multiple
Value & substrings
homePhone Employee home telephone number
Single
postalAddress Employee primary mailing address
Single
homePostalAddress Employee home address
Single
nuOffCampusAddress Employee second address
Single
nuTelephoneNumber2 Second office telephone number
Single
nuTelephoneNumber3 Third office telephone number
Single
mobile Mobile telephone number
Single
nuPartner Domestic partner
Single
nuVoiceMailPhone Voice mail telephone number
Single
nuPosition1 Summary block - position 1
Single
nuPosition2 Summary block - position 2
Single
nuPosition3 Summary block - position 3
Single
nuPosition4 Summary block - position 4
Single
nuPosition5 Summary block - position 5
Single
nuPosition6 Summary block - position 6
Single
nuPosition7 Summary block - position 7
Single
nuPosition8 Summary block - position 8
Single
nuPosition9 Summary block - position 9
Single
nuPosition10 Summary block - position 10
Single
title University title(s)
Multiple
nuDepartmentTitle Informal title(s)
Multiple
nuDepartmentAffiliations Department affiliation(s)
Multiple
departmentNumber HR department code(s)
Multiple
nuAcademicDepartment Academic Department Affiliation(s)
Multiple
nuAcDepartmentNumber HR department code(s)
Multiple
nuCurriculum Short/long school name(s) with nuGradYear(s)
Multiple
a, f
nuGradYear Year(s) of graduation
Multiple
a, f
nuStudentCurrentAddress Local residence address
Single
nuStudentCurrentPhone Local residence telephone number
Single
nuStudentPermanentAddress Student home address
Single
nuStudentPermanentPhone Student home telephone number
Single
nuSchoolAffiliations School & role pair(s)
Multiple
nuClassAffiliations Registration information by class(es)
Multiple
nuBarCode WildCard barcode
Single
   
nuMagneticStrip WildCard identification number as present on magnetic strip
Single
   
nuWildCardExpirationDate Month and Year through which WildCard is valid
Single
   
nuWildCardLostIndicator WildCard issue sequence number
Single
   
nuLastQuarterRegistration Last quarter a student was registered for classes
Single
   
nuParkingPermission Campuses on which a person has permission to obtain a parking permit
Multiple
   

Fields originating from Human Resources information (rarely used by applications)

Attribute Name Description Single or
Multiple Value
Search By: Privacy Notes
manager DN of supervisor
Single
nuAllLegalName Legal name
Single
nuLegalGivenName Legal given name
Single
nuLegalMiddleName Legal middle name
Single
nuLegalSn Legal surname
Single
nuAllProName Professional name
Single
nuProGivenName Professional given name
Single
nuProMiddleName Professional middle name
Single
nuProSn Professional surname
Single
nuAllHomePhone Employee home telephone number
Single
nuAllHomePostalAddress Employee home address
Single
nuAllPartner Domestic partner
Single
nuAllTelephoneNumber Primary office telephone number
Single
nuAllTelephoneNumber2 Second office telephone number
Single
nuAllTelephoneNumber3 Third office telephone number
Single
nuAllMobile Mobile telephone number
Single
nuAllPager Radio pager telephone number
Single
nuAllVoiceMailPhone Voice mail telephone number
Single
nuAllTitle All University title(s)
Multiple
nuAllDepartmentTitle All Informal title(s)
Multiple
nuAllDepartmentName All Department Name(s)
Multiple
nuAllDepartmentAffiliations All Department Affiliation(s)
Multiple
nuAllAcademicDepartment All Academic Department Affiliation(s)
Multiple
nuAllPostalAddress All Office address(es)
Multiple
nuAllOffCampusAddress Employee second address
Single

Fields originating from Student Records (SES) information (rarely used by applications)

Attribute Name Description Single or
Multiple Value
Search By: Privacy Notes
nuUnlisted Invisible to white page query
Single
nuStudentName Student name (subject to Unlisted)
Single
nuStudentGivenName Student given name
Single
nuStudentMiddleName Student middle name
Single
nuStudentSn Student surname
Single
nuAllStudentName Student name
Single
nuAllCurriculum Short/long school name(s) with nuGradYear(s)
Multiple
nuAllGradYear Graduation Year(s)
Multiple
nuAllStudentCurrentAddress Local residence address
Single
nuAllStudentCurrentPhone Local residence telephone number
Single
nuAllStudentPermanentAddress Student home address
Single
nuAllStudentPermanentPhone Student home telephone number
Single
nuAllClassAffiliations Identification of registered classes
Multiple
Value & substring
nuAllSchoolAffiliations School & role pair(s)
Multiple

Fields the User Sets or Can Modify Through Direct Record Editing

Attribute Name Description Single or
Multiple Value
Search By: Privacy Notes
nuAlumniPassword Alumni e-mail re-direct password
Single
seeAlso DN(s) of related user(s) or team member(s)
Multiple
nuNotificationEmail E-mail address for SNAP notifications
Single
nuChatIdentity Chat/IM service information
Single
nuFratOrSorority Fraternity or Sorority Name
Single
nuhours Hours when available
Single
pager Radio pager telephone number
Single
nuother User choice - free field
Single
nuwebPage User's Web home page - displayed as a clickable link
Single
nunickName Value string of max. 10 nicknames
Single
facsimileTelephoneNumber Fax telephone number
Single
numailbox Delivery host e-mail address
Single
g, h
mail Preferred e-mail address
Single
nuemailPref Controls if item "mail" is from "numail" or "numailbox"
Single
nuAlias Email address unique portion
Single
Value
nuproxy NetID(s) with proxy authorization for information in this entry
Multiple
Value

Fields the User Sets or Can Modify Through Special Web Pages

Attribute Name Description Single or
Multiple Value
Search By: Privacy Notes
nuPIN Personal PIN
Single
nuVacationText Text of vacation message
Single
nuPrivacyRestrictedFields Item(s) elected to be not visible both on-campus and off-campus
Multiple
e, g
nuOffCampus Full, no, or partial - view for off-campus
Single
e, g
userPassword SNAP password one-way SHAA hash
Single

Internal or Standard Fields

Attribute Name Description Single or
Multiple Value
Search By: Privacy Notes
nuAllcn All possible common name tokens, regardless of privacy settings
Multiple
Value & substrings
 
nuAllDisplayName Display name regardless of privacy settings
Multiple
Value & substrings
 
nuAllGivenNameSearch All possible given name tokens, regardless of privacy settings
Multiple
Value & substrings
 
nuAllMiddleNameSearch All possible middle name tokens, regardless of privacy settings
Multiple
Value & substrings
 
nuAllSnSearch All possible last name tokens, regardless of privacy settings
Multiple
Value & substrings
 
nuPreferAlias Preferred alias
Single
     
nuAssertions Holds identity assertions as source and expiration date
Multiple
   
nuDOB Date of Birth
Single
   
nuMailAuthority Authorizing authority for this mail address
Single
   
nuDeptDependentGroups List of manual SNAP groups identified by department membership
Multiple
nuSchoolDependentGroups List of manual SNAP groups identified by student membership
Multiple
eduPersonAffiliation Affiliation (student, faculty, staff, ...)
Multiple
eduPersonOrgDn DN of Northwestern University
Single
eduPersonNickname nunickName as multi-value
Multiple
eduPersonOrgUnitDn Reserved for future use
Multiple
eduPersonPrincipalName <netid>@northwestern.edu
Single
eduPersonEntitlement Reserved for future use
Multiple
eduPersonPrimaryOrgUnitDn Primary organizatonal unit
Single
userCertificate Binary form of user certificate
Single
UserSMIMECertificate A zero-length S/MIME signed message
Single
nuAccountOwner NetID of owner - controls charging
Single
jpegPhoto Reserved for future use
Single
nuPartialResponseData List of attributes revealed for partial white pages return
Multiple
nuDirectoryExpirationDate Date that LDAP entry will be removed
Single
nuNetIDExpirationDate Date that NetID and services are rendered inactive
Single
commURI labeled URL(s) to H.323 information
Multiple
nucommURI URL to NU video search
Single
description Reserved for future use
Single
labeledURI Reserved for future use
Single
nuvisible Visibility to regular user query
Single
nutype Type of directory entry
Single
numail Valid e-mail address(es) for numailbox
Multiple
Value
nuCanChangeAlias User can/cannot change nuAlias item
Single
nuOtherName Manually asserted display name
Single
nuOtherAddress Manually asserted office address
Single
nuOtherPhone Manually asserted office telephone number
Single
nuOtherTitle Manually asserted title
Single
nuOtherDepartment Manually asserted department name
Single
uidNumber Unique operating system UID
Single
initials User's identifying initials
Single
     
nuNetidService List of services provisioned for this NetID
Multiple
   
nuNetidStatus NetID status
Single

Entitlements

Attribute Name Description Single or
Multiple Value
Search By: Privacy Notes
nuResearchPI Principle investigator
Single
 
nuNetworkAccess Can/cannot use University network
Single
nuEntModemPool Can/cannot use commodity modems
Single
nuEntTravelerPool Can/cannot use traveler modems
Single
nuEntMaintPool Can/cannot use maintenance modems
Single
nuEntVPN Can/cannot use VPN service from off-network
Single
nuEntWireless Can/cannot use NU wireless network
Single
nuEntXModemSvc Can/cannot use external modem services
Single
nuEntSubnetAdmin List of IP Subnets Administered
Multiple

Notes

a. This field is not to be displayed off-campus.
b. One of either, or both, the nuLegalName or nuProName must be visible.
c. This field should only be displayed during record maintenance by the user, proxy, or an authorized administrator.
d. This field is never displayed.
e. This field can only be changed by the user.
f. The user can block display of this field through privacy settings.
g. This field is initialized by SNAP, but is thereafter controlled by the user.
h. This field is initially provisioned when the NetID is activated. Changing this field can interrupt e-mail service.