Red-hat 8.1 Manuale Utente

Navigare online o scaricare Manuale Utente per Computer Red-hat 8.1. Red Hat 8.1 User Manual Manuale Utente

  • Scaricare
  • Aggiungi ai miei manuali
  • Stampa
  • Pagina
    / 292
  • Indice
  • SEGNALIBRI
  • Valutato. / 5. Basato su recensioni clienti

Sommario

Pagina 1 - Red Hat Directory Server 8.1

Red Hat Directory Server 8.1Configuration and Command ReferenceConfiguring and managing Red Hat Directory Server 8.1 with command-lineutilitiesEdition

Pagina 2 - Legal Notice

Using the Admin Server describes the different tasks and tools associated with the AdministrationServer and how to use the Administration Server with

Pagina 3 - Abstract

Multi- or Single-Valued Multi-valuedDefined in Directory Server2.5.2 . Legacy Replication At tributesThese attributes were originally used to configur

Pagina 4 - Table of Contents

Defined in Directory Server2.5.2 .3. cirBindCre dentialsFor consumer-initiated replication, this attribute is used to identify the bind password for t

Pagina 5

For consumer initiated replication, this attribute shows the time of the last failed updated attempt.OID 2.16.840.1.113730.3.1.88Syntax DirectoryStrin

Pagina 6 - 6 Table of Contents

replicaCredentials Stores a password of replicaBindDn.replicaBindMethod Specifies the bind method.replicaUseSSL Specifies a flag whether or not to use

Pagina 7

OID 2.16.840.1.113730.3.1.202Syntax BinaryMulti- or Single-Valued Multi-valuedDefined in Directory Server2.5.2 .21. replica EntryFilterThis attribute

Pagina 8 - About This Reference

2.5.2 .28. replica Upda teFailedAtThis attribute contains the time and date of the most recent replication failure.OID 2.16.840.1.113730.3.1.49Syntax

Pagina 9 - 3. Additional Reading

Chapter 3. Plug-in Implemented Server Functionality ReferenceThis chapter contains reference information on Red Hat Directory Server plug-ins.The conf

Pagina 10 - 10 About This Reference

3.1 .3. ACL Preope ration Plug- inPlug-in Pa ramet er DescriptionPlug-in Name ACL PreoperationDN of Configuration Entry cn=ACL preoperation, cn=plugin

Pagina 11 - Chapter 1. Introduction

Red Hat recommends leaving this plug-in runningat all times.Further Information3.1 .6. Boolean Syntax Plug-inPlug-in Pa ramet er DescriptionPlug-in Na

Pagina 12

"Configuring Directory Databases" chapter in theDirectory Server Administrator's Guide.3.1 .10. Cla ss of Service Plug- inPlug-in Pa ra

Pagina 13

Chapter 1. IntroductionDirectory Server is based on an open-systems server protocol called the Lightweight Directory AccessProtocol (LDAP). The Direct

Pagina 14

Plug-in Pa ramet er DescriptionPlug-in Name Generalized T ime SyntaxDN of Configuration Entry cn=Generalized Time Syntax, cn=plugins,cn=configDescript

Pagina 15

Performance Related Information Do not modify the configuration of this plug-in.Red Hat recommends leaving this plug-in runningat all times.Further In

Pagina 16

Table 3.2. Details of MemberOf Plug-inPlug-in Information DescriptionPlug-in Name MemberOfConfiguration Entry DN cn=MemberOf Plugin,cn=plugins,cn=con

Pagina 17

3.1 .25. Password Storage SchemesThe cn=Password Storage Schemes entry is a container entry, not a plug-in entry itself. All of theplug-ins used for e

Pagina 18

3.1 .26. Posta l Address String Syntax Plug-inPlug-in Pa ramet er DescriptionPlug-in Name Postal Address SyntaxDN of Configuration Entry cn=Postal Add

Pagina 19

conflict resolution loops. When enabling the plug-in on chainedservers, be sure to analyze the performance resource andtime needs as well as integrity

Pagina 20

3.1 .32. Space Insensitive St ring Synt ax Plug-inPlug-in Pa ramet er DescriptionPlug-in Name Space Insensitive String SyntaxDN of Configuration Entry

Pagina 21

Configurable Arguments NoneDependencies NonePerformance Related Information Do not modify the configuration of this plug-in.Red Hat recommends leaving

Pagina 22

3.2 .3. nsslapd-pluginInitfuncThis attribute specifies the plug-in function to be initiated.Plug-in Pa ramet er DescriptionEntry DN cn=plug-in name, c

Pagina 23

Syntax DirectoryStringExample nsslapd-pluginVendor: Red Hat, Inc.3.2 .9. nsslapd- pluginDescriptionThis attribute provides a description of the plug-i

Pagina 24

Chapter 2. Core Server Configuration ReferenceThe configuration information for Red Hat Directory Server is stored as LDAP entries within the director

Pagina 25

Entry DN cn=referential integrity postoperation, cn=plugins,cn=configValid Values Class of ServiceDefault ValueSyntax DirectoryStringExamplensslapd-pl

Pagina 26

cn=configValid Range 100 to the maximum 32-bit integer value(2147483647) entry IDsDefault Value 4000Syntax IntegerExample nsslapd-idlistscanlimit: 40

Pagina 27

cache the indexes (the .db4 files) and other files. This value is passed to the Berkeley DB API function set_cachesize. If automatic cache resizing i

Pagina 28

Entry DN cn=config, cn=ldbm database, cn=plugins,cn=configValid Values on | offDefault Value offSyntax DirectoryStringExample nsslapd-db-debug: off3.4

Pagina 29

database cache size being configured for the server. If this happens, reduce the size of the databasecache size to a value where the server will start

Pagina 30

Parameter Descript ionEntry DN cn=config, cn=ldbm database, cn=plugins,cn=configValid Values Any valid path and directory nameDefault ValueSyntax Dire

Pagina 31

WARNINGSetting this value will reduce data consistency and may lead to loss of data. T his is because ifthere is a power outage before the server can

Pagina 32

by a process. If nsslapd-dbncache is 0 or 1, the cache will be allocated contiguously in memory. If it isgreater than 1, the cache will be broken up i

Pagina 33

database (the ldif2db operation).In Directory Server, the import operation can be run as a server task or exclusively on the command-line.In the task

Pagina 34

information on these entries, refer to the "Monitoring Server and Database Activity" chapter in theDirectory Server Administrator's Gui

Pagina 35

Table 2.1 . Directory Se rver LDIF Configuration FilesConfigurat ion Filename Purposedse.ldif Contains front-end Directory Specific Entriescreated by

Pagina 36

cn=plugins, cn=configValid Range1 to 232-1 on 32-bit systems or 26 3-1 on 64-bitsystems or -1, which means limitlessDefault Value -1Syntax IntegerExam

Pagina 37

Entry DN cn=database_name, cn=ldbm database,cn=plugins, cn=configValid Values on | offDefault Value offSyntax DirectoryStringExample nsslapd-readonly:

Pagina 38

Parameter Descript ionEntry DN cn=index_name, cn=userRoot, cn=ldbmdatabase, cn=plugins, cn=configValid Values 0 (disabled) | 1 (enabled)Default Value

Pagina 39

NOTEThis attribute is only available to user databases like userRoot, not configuration databases likeo=NetscapeRoot.Parameter Descript ionEntry DN cn

Pagina 40

Valid Values Any Directory Server attributes, in a space-separated listDefault ValueSyntax DirectoryStringExample vlvSort: cn givenname o ou sn3.4 .3.

Pagina 41

nsslapd- db-clean-pagesThis attribute shows the clean pages currently in the cache.nsslapd- db-commit- rateThis attribute shows the number of transact

Pagina 42

This attribute shows the clean pages forced from the cache.nsslapd- db-page-rw- evict- rateThis attribute shows the dirty pages forced from the cache.

Pagina 43 - SSLDescriptors

Attribute Definit ionobjectClass Defines the object classes for the entry.cn Gives the common name of the entry.nsSystemIndex Identify whether or not

Pagina 44

Entry DN cn=default indexes, cn=config, cn=ldbmdatabase, cn=plugins, cn=configValid Values true | falseDefault ValueSyntax DirectoryStringExample nsSy

Pagina 45

3.4 .7.1 . nsSubStrBe ginBy default, for a search to be indexed, the search string must be at least three characters long, withoutcounting any wildcar

Pagina 46

50ns-web.ldif Schema for Netscape Web Server.60pam-plugin.ldif Reserved for future use.99user.ldif User-defined schema maintained by DirectoryServer r

Pagina 47 - NOTE>

Example nsSubStrMiddle: 33.4 .8. Dat abase Attributes unde r cn=attribut eName, cn=encrypt ed att ributes,cn=dat abase _name, cn=ldbm dat abase , cn=p

Pagina 48

(AES) Triple Data Encryption Standard Block Cipher(3DES)Default ValueSyntax DirectoryStringExample nsEncryptionAlgorithm: AES3.5. Database Link Plug-i

Pagina 49

This error detection, performance-related attribute specifies the duration of the test issued by thedatabase link to check whether the remote server i

Pagina 50

Contrary to what the name suggests, this attribute does not specify the number of times a database linkretries to bind with the remote server but the

Pagina 51

Example nsConcurrentOperationsLimit: 53.5 .2.8 . nsConnectionLifeThis attribute specifies connection lifetime. Connections between the database link a

Pagina 52

Example nsslapd-sizelimit: 20003.5 .2.1 3. nsTimeLimitThis attribute shows the default search time limit for the database link.Parameter Descript ionE

Pagina 53

Default ValueSyntax DirectoryStringExample nsFarmServerURL: ldap://farm1.example.com:389ldap://farm2.example.com:13893.5 .3.3. nsMultiplexorBindDnThis

Pagina 54

headcountThis attribute gives the number of add operations received.nsDelete CountThis attribute gives the number of delete operations received.nsModi

Pagina 55

This attribute specifies the name of the directory in which the changelog database is created the firsttime the plug-in is run. By default, the databa

Pagina 56

Valid Range Any valid LDAP filterDefault Value NoneSyntax DirectoryStringExample dnaFilter: (objectclass=person)3.7 .2. dnaMagicRegenThis attribute se

Pagina 57

These entries and their children have many attributes used to configure different database settings, likethe cache sizes, the paths to the index files

Pagina 58

Example dnaNextRange: 100-5003.7 .5. dnaNextValueThis attribute gives the next available number which can be assigned. After being initially set in th

Pagina 59

This attribute defines a shared identity that the servers can use to transfer ranges to one another. T hisentry is replicated between servers and is m

Pagina 60

The MemberOf Plug-in synchronizes the group membership in group members with the members'individual directory entries by identifying changes to a

Pagina 61

Chapter 4. Server Instance File ReferenceThis chapter provides an overview of the files that are specific to an instance of Red Hat DirectoryServer (D

Pagina 62

Table 4 .3. HP- UX 11i (IA64 )File or Directory Locat ionBackup files /var/opt/dirsrv/slapd-instance/bakConfiguration files /etc/opt/dirsrv/slapd-ins

Pagina 63

Exa mple 4 .2. Ne tscapeRoot Database Direct ory Contents./ entrydn.db4* parentid.db4*../ givenName.db4* sn.db4*DBVERSION* id2entry.db4* uid.db4

Pagina 64

Lock table is out of available locks), double the value of the nsslapd-db-locks attributein the cn=config,cn=ldbm database,cn=plugins,cn=config entry

Pagina 65

4.10. ScriptsDirectory Server command-line scripts are stored in the /etc/dirsrv/slapd-instance_namedirectory. The contents of the /etc/dirsrv/slapd-i

Pagina 66

Chapter 5. Log File ReferenceRed Hat Directory Server (Directory Server) provides logs to help monitor directory activity. Monitoringhelps quickly det

Pagina 67

Exa mple 5.1. Example Access Log[21/Apr/2009:11:39:51 -0700] conn=11 fd=608 slot=608 connection from 207.1.153.51 to 192.18.122.139[21/Apr/2009:11:39

Pagina 68

2.2.2 .1. Modifying Configuration Ent ries Using LDAPThe configuration entries in the directory can be searched and modified using LDAP either via the

Pagina 69

Slot NumberThe slot number, in this case slot=608, is a legacy part of the access log which has the samemeaning as file descriptor. Ignore this part o

Pagina 70

Table 5.1 . Commonly-Used T agsTag Descript iontag=97 A result from a client bind operation.tag=100 The actual entry being searched for.tag=101 A res

Pagina 71

ENT RYREFERRAL, an LDAP referral or search referenceUninde xed Search IndicatorThe unindexed search indicator, notes=U, indicates that the search perf

Pagina 72

An extended operation OID, such as EXT oid="2.16.84 0.1.113730.3.5.3" or EXT oid="2.16.84 0.1.113730.3.5.5" in Example 5.1, “Exam

Pagina 73

NOTEThe Directory Server operation number starts counting at 0, and, in the majority of LDAPSDK/client implementations, the message ID number starts c

Pagina 74

[12/Jul/2009:16:43:02 +0200] conn=306 fd=60 slot=60 connection from 127.0.0.1 to 127.0.0.1 [12/Jul/2009:16:43:02 +0200] conn=306 op=0 SRCH base="

Pagina 75

Table 5.3. Common Connection CodesConnect ion Code Descript ionA1 Client aborts the connection.B1 Corrupt BER tag encountered. If BER tags, whichenca

Pagina 76

Table 5.4 . Error Log LevelsSett ing Console Name Descript ion1 Trace function calls Logs a message when theserver enters and exits afunction.2 Packe

Pagina 77

A timestamp, such as [05/Jan/2009:02:27:22 -0500], although the format varies dependingon the platform. The ending four digits, -0500, indicate the ti

Pagina 78

Red Hat Directory Server 8.1 Configuration and Command Reference 169

Pagina 79

nsslapd-schema-ignore-trailing-spaces nsslapd-securelistenhostnsslapd-workingdir nsslapd-return-exact-casensslapd-maxbersize2.3. Core Server Configura

Pagina 80

Exa mple 5.4 . Re plication Error Log Entry[09/Jan/2009:13:44:48 -0500] - _csngen_adjust_local_time: gen state before 496799220001:1231526178:0:0[09/J

Pagina 81

Plug-in logging records every the name of the plugin and all of the functions called by the plugin. Thishas a simple format:[timestamp] Plugin_name -

Pagina 82

Example 5.7, “Access Control Summary Logging” shows the summary access control log entry.Exa mple 5.7. Access Control Summary Logging[09/Jan/2009:16:0

Pagina 83

Exa mple 5.8. Audit Log Content ... modifying an entry ... tim e: 20090108181429 dn: uid=scarter,ou=people,dc=example,dc=com changetype: modify repla

Pagina 84

Table 5.5 . LDAP Result CodesResultCodeDefined Value ResultCodeDefined Value0 SUCCESS 48 INAPPROPRIATE_AUTHENTICATION1 OPERAT ION_ERROR 49 INVALID_CR

Pagina 85

Chapter 6. Command-Line UtilitiesThis chapter contains reference information on command-line utilities used with Red Hat DirectoryServer (Directory Se

Pagina 86

Table 6.1 . Commonly-Used Command-Line Utilit iesCommand-Line Utility Descriptionldapsearch Searches the directory and returns searchresults in LDIF

Pagina 87

Table 6.2 . ldapsearch SyntaxOption Descriptionoptional_options A series of command-line options. These must bespecified before the search filter, if

Pagina 88

Table 6.3. Commonly-Used ldapsearch OptionsOption Description-b Specifies the starting point for the search. T hevalue specified here must be a disti

Pagina 89

The default is 389. If -Z is used, the default is 636.-s Specifies the scope of the search. T he scope canbe one of the following: base searches only

Pagina 90

Table 2.2 . dse .ldif File Att ributesAttribute Value Logging enabled or disablednsslapd-accesslog-logging-enablednsslapd-accesslogonempty stringDis

Pagina 91

Table 6.4 . Pe rsistent Search OptionsOption Description-C Runs the ldapsearch as a persistent search.-r Prints all of the output from the ldapsearch

Pagina 92

Table 6.5 . Additional SSL ldapse arch OptionsOption Description-3 Specifies that hostnames should be checked in SSLcertificates.-I Specifies the SSL

Pagina 93

command is aborted immediately.SASL OptionsSASL mechanisms can be used to authenticate a user, using the -o the required SASL information.To learn whi

Pagina 94

Table 6.7 . Description of CRAM-MD5 Mechanism OptionsRequiredorOptionalOption Description ExampleRequired mech=CRAM-MD5 Gives the SASL mechanism. -o

Pagina 95

Table 6.8 . Description of DIGEST- MD5 SASL Mechanism OptionsRequiredorOptionalOption Description ExampleRequired mech=DIGEST-MD5 Gives the SASL mech

Pagina 96

Table 6.9 . Description of GSSAPI SASL Mechanism OptionsRequired orOptionalOption Descript ion Exa mpleRequired mech=GSSAPI Gives the SASLmechanism.N

Pagina 97

Table 6.1 0. Additional ldapsearch OptionsOption Description-1 Leaves out the opening version: 1 line fromthe LDIF output.-A Specifies that the searc

Pagina 98 - 2.5. Legacy Attributes

characterset.ldapsearch converts the input from thesearguments before it processes the searchrequest. For example, -i no indicates that thebind DN, ba

Pagina 99

of the content.-U Creates file URLs for the files produced by the -toption.-u Specifies that the user-friendly form of thedistinguished name be used i

Pagina 100

Table 6.1 1. Commonly-Used lda pmodify OptionsOption Description-a Adds LDIF entries to the directory withoutrequiring the changetype:add LDIF update

Pagina 101

right away instead of having to wait for the log entries to be flushed to the file. Disabling log buffering canseverely impact performance in heavily

Pagina 102

SSL OptionsUse the following command-line options to specify that ldapm odify is to use LDAP over SSL (LDAPS)when communicating with the Directory Ser

Pagina 103

Table 6.1 2. lda pmodify SSL OptionsOption Descript ion-3 Specifies that hostnames should be checked in SSLcertificates.-I Specifies the SSL key pass

Pagina 104

“Commonly-Used ldapsearch Options”.Table 6.1 3. SASL OptionsOption Description-o Specifies SASL options. T he format is -osaslOption=value. saslOptio

Pagina 105

Table 6.1 4 . Additional ldapmodify OptionsOption Description-b Causes the utility to check every attribute value todetermine whether the value is a

Pagina 106

-V 2LDAPv3 is the default. An LDAPv3 operationcannot be performed against a Directory Serverthat only supports LDAPv2.-Y Specifies the proxy DN to use

Pagina 107

Table 6.1 5. Commonly-Used lda pdelete Opt ionsOption Description-D Specifies the distinguished name with which toauthenticate to the server. T he va

Pagina 108

Table 6.1 6. lda pde lete SSL Opt ionsOption Descript ion-3 Specifies that hostnames should be checked in SSLcertificates.-I Specifies the SSL key p

Pagina 109

To learn which SASL mechanisms are supported, search the root DSE. See the -b option in T able 6.3,“Commonly-Used ldapsearch Options”.Table 6.1 7. SA

Pagina 110

Table 6.1 8. Additional ldapdelete Opt ionsOption Description-c Specifies that the utility must run in continuousoperation mode. Errors are reported,

Pagina 111

Table 6.1 9. lda ppa sswd-specific Opt ionsOption Description-A Specifies that the command should prompt for theuser's existing password.-a Spe

Pagina 112

Legal NoticeCopyright © 20 09 Red Hat, Inc..The text of and illustrations in this document are licensed by Red Hat under a Creative CommonsAttributio

Pagina 113

Parameter Descript ionEntry DN cn=configValid Values on | offDefault Value onSyntax DirectoryStringExample nsslapd-accesslog-logging-enabled: off2.3.1

Pagina 114

Table 6.2 0. General ldappasswd OptionsOption Descript ion-3 Specifies that hostnames should be checked in SSLcertificates.-D Specifies the distingui

Pagina 115

for the browser. For example:-P /security/cert.dbThe client security files can also be stored on theDirectory Server in the /etc/dirsrv/slapd-instance

Pagina 116

Table 6.2 1. SASL OptionsOption Description-o Specifies SASL options. T he format is -osaslOption=value. saslOption can have one of sixvalues: mech,

Pagina 117

Exa mple 6.4 . User Authenticating Wit h a User Certifica te a nd Changing His PasswordA user, tuser4 , authenticates with the user certificate and ch

Pagina 118

Table 6.2 2. ldif Opt ionsOption Description-b Specifies that the ldif utility should interpret theentire input as a single binary value. If -b is no

Pagina 119

NOTEThe index file options, listed in Table 6.25, “Index File Options ”, are meaningful only when thedatabase file is the secondary index file.Table

Pagina 120

Exa mple 6.13. Displaying the Change log File Cont entsdbscan -f /var/lib/dirsrv/slapd-instance_name/changelogdb/c1a2fc02-1d11b2-8018afa7-fdce000_424c

Pagina 121

Chapter 7. Command-Line ScriptsThis chapter provides information on the scripts for managing Red Hat Directory Server, such asbacking-up and restoring

Pagina 122

Table 7.2 . Pe rl Scripts in /usr/lib/dirsrv/slapd- instance_name or/usr/lib64 /dirsrv/slapd-instance_namePerl Script Descript ionbak2db.pl Restores

Pagina 123

This section covers the following scripts:Section 7.3.1, “bak2db (Restores a Database from Backup)”Section 7.3.2, “cl-dump (Dumps and Decodes the Chan

Pagina 124

Parameter Descript ionEntry DN cn=configValid Range 0 through 23Default Value 0Syntax IntegerExample nsslapd-accesslog-logrotationsynchour: 232.3.1.12

Pagina 125

OptionsWithout the -i option, the script must be run when the Directory Server is running from a location fromwhich the server's changelog direct

Pagina 126

Either the -n or the -s option must be specified. By default, the output LDIF will be stored in one file. Tospecify the use of several files, use the

Pagina 127

Table 7.7 . db2index Opt ionsOption Description-n backendInstance Gives the name of the instance to be reindexed.-s includeSuffix Gives suffixes to

Pagina 128

Synta xds_removal [ -f ] -s instance_name -w manager_passwordOptions Option Pa ramet er Descript ion-f Forces the removal of theinstance. This can be

Pagina 129

Table 7.9 . ldif2db OptionsOption Description-c Merges chunk size.-E Encrypts data during import. T his option is usedonly if database encryption is

Pagina 130

Retrieves performance monitoring information using the ldapsearch command-line utility.Synta xm onitormonitor OptionsThere are no options for this scr

Pagina 131

[connection]host:port:binddn:bindpwd:bindcerthost:port:binddn:bindpwd:bindcert...[alias]alias = host:portalias = host:port...[color]lowmark = colorlow

Pagina 132

log in, use this script to compare the user's password to the password stored in the directory.Synta xpwdhash [ -D config_directory ] [ -H ] [[ -

Pagina 133

Synta xsaveconfigOptionsThere are no options for this script.7.3.16. start- slapd (St arts the Directory Server)Starts the Directory Server. It might

Pagina 134

7.3.19. vlvindex (Creat es Virtual List View Inde xes)To run the vlvindex script, the server must be stopped. The vlvindex script creates virtual list

Pagina 135

Valid Range -1 | 1 to the maximum 32 bit integer value(2147483647), where a value of -1 means the logfile is unlimited in size.Default Value 100Syntax

Pagina 136

Synta xbak2db.pl [ -v ] -D rootdn { -w password | -w - | -j filename } -a backupDirectory [ -t databaseType ] [ -n backend ]OptionsThe script bak2db.p

Pagina 137

Table 7.1 9. cl-dump.pl comma nd opt ionsOption Description-c Dumps and interprets change sequence numbers(CSN) only. This option can be used with or

Pagina 138

Synta xdb2index.pl [ -v ] -D rootdn { -w password | -w - | -j filename } -n backendInstance [ -t attributeName(:indextypes(:mathingrules)) ] [ -T vlvA

Pagina 139

Table 7.2 2. db2ldif.pl Opt ionsOption Description-1 Deletes, for reasons of backward compatibility,the first line of the LDIF file that gives the ve

Pagina 140

Table 7.2 3. fixup-memberof.pl OptionsOption Description-b baseDN The DN of the subtree containing the entries toupdate.-D rootdn Gives the user DN w

Pagina 141

Table 7.2 4 . ldif2db.pl Opt ionsOption Description-c Merges chunk size.-D rootdn Specifies the user DN with root permissions,such as Directory Manag

Pagina 142

Table 7.2 5. Informat ion Extracted from Access Logs Number of restarts Total number of connections Total operations requested Total results returned

Pagina 143

Table 7.2 6. logconv.pl OptionsOption Description-d mgrDN Specifies the distinguished name (DN) of theDirectory Manger in the logs being analyzed. Th

Pagina 144

Table 7.2 7. logconv.pl Options to Displa y OccurrencesOption Descriptione Lists the most frequent error and return codes.f Lists the bind DNs with t

Pagina 145

Option Alternat eOptionsDescript ionGeneral.ConfigDirectoryAdminPwd=password Required. This is the password for theconfiguration directory administrat

Pagina 146

The nsslapd-allow-unauthenticated-binds attribute sets whether to allow an unauthenticated bindto succeed as an anonymous bind. By default, unauthenti

Pagina 147

IMPORTANTDo not run setup-ds-adm in.pl for the new Directory Server 8.1 instance before running themigration script if you are migrating from a 7.1 se

Pagina 148

number of d's increases the debug level.--logfile name -l T his parameter specifies a log file to whichto write the output. If this is not set, t

Pagina 149

Table 7.2 9. ns-act ivate.pl Opt ionsOption Description-D rootdn Specifies the Directory Server user DN with rootpermissions, such as Directory Manag

Pagina 150

Table 7.31. ns-newpwpolicy.pl Opt ionsOption Description-D rootdn Specifies the Directory Server user DN with rootpermissions, such as Directory Mana

Pagina 151

database files, like cert8.db and key3.db, are not removed, so the remaining instance directory isrenamed removed.slapd-instance.Synta xrem ove-ds.pl

Pagina 152

Configurat ion File FormatThe configuration file defines the following:The connection parameters for connecting to the LDAP servers to get replication

Pagina 153

A shadow port can be set in the replication monitor configuration file. For example:host:port=shadowport:binddn:bindpwd:bindcertWhen the replication m

Pagina 154 - 4.4. Database Files

Options Option Alt ernate Opt ions Description--silent -s This runs the register script insilent mode, drawing theconfiguration information from afile

Pagina 155 - 4.6. Lock Files

Synta xsetup-ds-admin.pl [ --debug ] [ --silent ] [ --file=name ] [ --keepcache ] [ --log=name ] [ --update ]Options Option Alt ernate Opt ions Descri

Pagina 156 - 4.7. Log Files

IMPORTANTNever run verify-db.pl when a modify operation is in progress. T his command calls theBerkeleyDB utility db_verify and does not perform any l

Pagina 157 - 4.10. Scripts

Example nsslapd-auditlog-list: auditlog2,auditlog32.3.1.22. nsslapd- auditlog-logexpirationtime (Audit Log Expira tion T ime)This attribute sets the m

Pagina 158 - Chapter 5. Log File Reference

Using the ns-slapd Command-Line UtilitiesChapter 7, Command-Line Scripts discussed the scripts for performing routine administration tasks onthe Red H

Pagina 159

Table A.1. db2 ldif OptionsOption Description-a outputFile Defines the output file in which the server savesthe exported LDIF. This file is stored by

Pagina 160

OptionsTable A.2. ldif2db Opt ionsOption Description-d debugLevel Specifies the debug level to use during runtime.For further information, refer to S

Pagina 161

ns-slapd archive2db -D configDir -a archiveDirOptionsTable A.3. archive2db OptionsOption Description-D configDir Specifies the location of the server

Pagina 162

Table A.5. db2 index Opt ionsOption Description-d debugLevel Specifies the debug level to use during indexcreation. For further information, refer to

Pagina 163

All IDs ThresholdReplaced with the ID list scan limit in Directory Server version 7.1. A size limit which is globallyapplied to every index key manage

Pagina 164

bind distinguished nameSee bind DN.bind DNDistinguished name used to authenticate to Directory Server when performing an operation.bind ruleIn the con

Pagina 165

supplier server then replays these modifications on the replicas stored on replica servers or onother masters, in the case of multi-master replication

Pagina 166 - 5.2. Error Log Reference

DdaemonA background process on a Unix machine that is responsible for a particular system task.Daemon processes do not need human intervention to cont

Pagina 167

DNSDomain Name System. T he system used by machines on a network to associate standard IPaddresses (such as 198.93.93.10) with hostnames (such as www.

Pagina 168

This attribute sets the maximum amount of disk space in megabytes that the audit logs are allowed toconsume. If this value is exceeded, the oldest aud

Pagina 169

Generic Security Services. The generic access protocol that is the native way for UNIX-basedsystems to access and authenticate Kerberos services; also

Pagina 170

location of a machine on the Internet (for example, 198.93.93.10).ISOInternational Standards Organization.Kknowle dge re fe rencePointers to directory

Pagina 171

managed objectA standard value which the SNMP agent can access and send to the NMS. Each managedobject is identified with an official name and a numer

Pagina 172 - 5.3. Audit Log Reference

The server containing the database link that communicates with the remote server.Nn + 1 directory problemThe problem of managing multiple instances o

Pagina 173 - 5.4. LDAP Result Codes

requested.Pparent accessWhen granted, indicates that users have access to entries below their own in the directory treeif the bind DN is the parent of

Pagina 174

PTAMechanism by which one Directory Server consults another to check bind credentials. Alsopass-through authentication.PTA directory serverIn pass-thr

Pagina 175 - 6.2. Using Special Characters

Replication configuration where replica servers, either hub or consumer servers, pull directorydata from supplier servers. This method is available on

Pagina 176 - 6.4. ldapsearch

Serve r ConsoleJava-based application that allows you to perform administrative management of your DirectoryServer from a GUI.server daemonThe server

Pagina 177 - "(objectclass=* )"

master agent. Also called a subagent.SSLA software library establishing a secure connection between two parties (client and server)used to implement H

Pagina 178

target entryThe entries within the scope of a CoS.TCP/IPTransmission Control Protocol/Internet Protocol. T he main network protocol for the Internet a

Pagina 179 - -w diner892

2.3.1.29. nsslapd- auditlog-logrotat ionsyncmin (Audit Log Rotat ion Sync Minute)This attribute sets the minute of the day for rotating audit logs. T

Pagina 180

01common.ldif- ldif files, LDIF and Schema Configuration Files05rfc224 7.ldif- ldif files, LDIF and Schema Configuration Files05rfc2927.ldif- ldif fil

Pagina 181 - -W secret

- B4 , Common Connection Codes- P2 , Common Connection Codes- T1 , Common Connection Codes- T2 , Common Connection Codes- U1 , Common Connection Codes

Pagina 182 - "authid=test_user"

changeLog, changeLogchangelog configura tion at tributes- changelogmaxentries, nsslapd-changelogmaxentries (Max Changelog Records)- nsslapd-changelogd

Pagina 183

- nsInstance, cn=export- nsNoWrap, cn=export- nsPrintKey, cn=export- nsUseId2Entry, cn=export- nsUseOneFile, cn=export- configuration entry, cn=export

Pagina 184

- SNMP configuration entries, cn=SNMPcn=t asks- attributes- cn, Task Invocation Attributes for Entries under cn=tasks- nsTaskCancel, T ask Invocation

Pagina 185

- restoreconfg , restoreconfig (Restores Administration Server Configuration)- saveconfig , saveconfig (Saves Administration Server Configuration)- st

Pagina 186 - -f search_filters

configurat ion entrie s- modifying using LDAP, Modifying Configuration Entries Using LDAP- restrictions to modifying, Restrictions to Modifying Config

Pagina 187 - -S sn -S givenname

- nsDumpUniqId, cn=export- nsExcludeSuffix, cn=import, cn=export- nsExportReplica, cn=export- nsFilename, cn=import, cn=export- nsImportChunkSize, cn=

Pagina 188 - 6.5. ldapmodify

- nsslapd-changelogmaxentries, nsslapd-changelogmaxentries (Max Changelog Records)- nsslapd-config, nsslapd-config- nsslapd-conntablesize, nsslapd-con

Pagina 189 - -w mypassword

- nsslapd-schema-ignore-trailing-spaces, nsslapd-schema-ignore-trailing-spaces (IgnoreTrailing Spaces in Object Class Names)- nsslapd-schemacheck, nss

Pagina 190

2.3.1.33. nsslapd-audit log-maxlogsperdir (Audit Log Ma ximum Number of Log Files)This attribute sets the total number of audit logs that can be conta

Pagina 191

- nsAttributeEncryption, Database Attributes under cn=attributeName, cn=encryptedattributes, cn=database_name, cn=ldbm database, cn=plugins, cn=config

Pagina 192

- dbcachetries, Database Attributes under cn=monitor, cn=ldbm database, cn=plugins,cn=config- dbfilecachehit, Database Attributes under cn=monitor, cn

Pagina 193

cn=ldbm database, cn=plugins, cn=config- nsslapd-db-page-rw-evict-rate, Database Attributes under cn=database, cn=monitor,cn=ldbm database, cn=plugins

Pagina 194 - 6.6. ldapdelete

- quick reference, Command-Line Scripts Quick Referencedbcachehit ratio attribute, Da tabase Attribut e s under cn=monit or, cn=ldbm database,cn=plugi

Pagina 195

- quick reference, Command-Line Scripts Quick Referenceds_re moval command-line utility- options, ds_removal- syntax, ds_removaldTableSize att ribute

Pagina 196

- configuration of, Configuration of IndexesJjpeg images, ldifLLDAP- modifying configuration entries, Modifying Configuration Entries Using LDAPLDAP D

Pagina 197

- 20subscriber.ldif, LDIF and Schema Configuration Files- 25java-object.ldif, LDIF and Schema Configuration Files- 28pilot.ldif, LDIF and Schema Confi

Pagina 198 - 6.7. ldappasswd

mult i-mast er replication change log- changelog, cn=changelog5Nnba ckends at t ribute, cn=monitornewRdn, newRdnnewSuperior, newSuperiorns-accountst a

Pagina 199 - -t old_password.txt

nsDatabaseType s, cn=backup, cn=rest orensDelete Count at tribute , Da tabase Link At tributes under cn=monitor, cn=databaseinst ance name, cn=chainin

Pagina 200 - -N Server-Cert

nshoplimit att ribute, nshoplimitnsImport ChunkSize, cn=importnsImport IndexAt trs, cn=importnsIncludeSuffix, cn=import, cn=exportnsIndexAt tribute, c

Pagina 201

Example /etc/dirsrv/slapd-phonebook2.3.1.36. nsslapd-ce rtmap- base dn (Certificate Map Se arch Base)This attribute can be used when client authentica

Pagina 202

nsslapd- accesslog-logrotationt ime att ribute, nsslapd-accesslog-logrotat iontime(Access Log Rotat ion Time)nsslapd- accesslog-maxlogsize attribute,

Pagina 203 - 6.8. ldif

cn=monitor, cn=ldbm dat abase , cn=plugins, cn=confignsslapd- db-cache-try att ribute, Dat abase Attributes unde r cn=database , cn=monit or,cn=ldbm d

Pagina 204 - 6.9. dbscan

nsslapd- db-verbose at tribute, nsslapd- db-verbosensslapd- dbcache size attribute, nsslapd- dbcache sizensslapd- dbncache attribute, nsslapd-dbncach

Pagina 205

nsslapd- maxsasliosize att ribute, nsslapd- maxsasliosize (Maximum SASL Packet Size)nsslapd- maxthreadsperconn a ttribute , nsslapd-maxt hreadspercon

Pagina 206

nssnmplocation a ttribut e, nssnmplocationnssnmpmast erhost a ttribut e, nssnmpmaste rhostnssnmpmast erport att ribute, nssnmpmast erportnssnmporganiz

Pagina 207

passwordInHistory attribut e, passwordInHistory (Number of Passwords to Remember)passwordLockout at t ribute, passwordLockout (Account Lockout)passwo

Pagina 208 - 7.3. Shell Scripts

name, cn=chaining database, cn=plugins, cn=config- nsAbandonedSearchCheckInterval, nsAbandonedSearchCheckInterval- nsActiveChainingComponents, nsActiv

Pagina 209

database, cn=plugins, cn=config- nsslapd-db-durable-transactions, nsslapd-db-durable-transactions- nsslapd-db-hash-buckets, Database Attributes under

Pagina 210

- nsTimeLimit, nsTimeLimit- nsTransmittedControls, nsT ransmittedControls- nsUnbindCount, Database Link Attributes under cn=monitor, cn=database insta

Pagina 211

repl-monit or.pl- command-line perl script, repl-monitor.pl (Monitors Replication Status)- quick reference, Command-Line Scripts Quick Referencereplic

Pagina 212 - IMPORTANT

This attribute sets whether change sequence numbers (CSNs), when available, are to be logged in theaccess log. By default, CSN logging is turned on.Pa

Pagina 213

retro changelog plug-in configuration a ttribute s- nsslapd-changelogdir, nsslapd-changelogdirretryCountReset T ime, retryCount ResetTimeSSASL configu

Pagina 214 - -g deterministic namespace_id

SNMP configura tion at tributes- nssnmpcontact, nssnmpcontact- nssnmpdescription, nssnmpdescription- nssnmpenabled, nssnmpenabled- nssnmplocation, nss

Pagina 215

TtargetDn, t argetDntotalConnections att ribute, cn=monit ortrailing space s in object class names, nsslapd- schema- ignore -tra iling-spaces (IgnoreT

Pagina 216

AbstractThis reference covers the server configuration and the command-line utilities. It is designed primarily fordirectory administrators and experi

Pagina 217

Table 2.6 . Possible Combinat ions for nsslapd-errorlog Configura tion Att ributesAttribute s in dse.ldif Value Logging enabled or disablednsslapd-er

Pagina 218

Entry DN cn=configValid ValuesDefault Value NoneSyntax DirectoryStringExample nsslapd-errorlog-list: errorlog2,errorlog32.3.1.4 6. nsslapd- errorlog-l

Pagina 219 - 7.4. Perl Scripts

This attribute sets the minimum allowed free disk space in megabytes. When the amount of free diskspace falls below the value specified on this attrib

Pagina 220

attribute value to 1 or set the nsslapd-errorlog-logrotationtime attribute to -1. The server checksthe nsslapd-errorlog-maxlogsperdir attribute first,

Pagina 221

2.3.1.58. nsslapd- errorlog-mode (Error Log File Permission)This attribute sets the access mode or file permissions with which error log files are to

Pagina 222

Default Value 0Syntax IntegerExample nsslapd-idletimeout: 02.3.1.61. nsslapd- inst ance dir (Instance Direct ory)This attribute is deprecated. There a

Pagina 223

Default Value offSyntax DirectoryStringExample nsslapd-ldapiautobind: off2.3.1.65. nsslapd- ldapientrysearchba se (Sea rch Base for LDAPI Aut hentica

Pagina 224

2.3.1.69. nsslapd- ldapimaprootdn (Autobind Mapping for Root Use r)With autobind, a system user is mapped to a Directory Server user and then automat

Pagina 225 - -g deterministic namespaceId

Parameter Descript ionEntry DN cn=configValid Values Any local hostname, IPv4 or IPv6 addressDefault ValueSyntax DirectoryStringExample nsslapd-listen

Pagina 226

Entry DN cn=configValid Range 0 - 2 gigabytes (2,147,483,647 bytes)Zero 0 means that the default value should beused.Default Value 2097152Syntax Integ

Pagina 227

Table of ContentsAbout T his Reference1. Directory Server Overview2. Examples and Formatting2.1. Command and File Examples2.2. T ool Locations2.3. LDA

Pagina 228

When an incoming SASL IO packet is larger than the nsslapd-maxsasliosize limit, the serverimmediately disconnects the client and logs a message to the

Pagina 229

system; make sure no other application is attempting to use the same port number. Specifying a portnumber of less than 1024 means the Directory Serve

Pagina 230

entries:ou=People,dc=example,dc=combut the request is for this entry:ou=Groups,dc=example,dc=comIn this case, the referral would be passed back to the

Pagina 231

nsslapd-reservedescriptor = 20 + (NldbmBackends * 4) + NglobalIndex +ReplicationDescriptor + ChainingBackendDescriptors + PTADescriptors + SSLDescript

Pagina 232

attribute. When viewed from the server console, this attribute shows the value * * * ** . When viewedfrom the dse.ldif file, this attribute shows the

Pagina 233

An error is returned by default when object classes that include trailing spaces are added to an entry.Additionally, during operations such as add, mo

Pagina 234

Default Value replication-onlySyntax DirectoryStringExample nsslapd-schemareplace: replication-only2.3.1.100. nsslapd-securelistenhostThis attribute a

Pagina 235

NOTEA value of -1 on this attribute in dse.ldif file is the same as leaving the attribute blank in theserver console, in that it causes no limit to be

Pagina 236

Example nsslapd-threadnumber: 602.3.1.106. nsslapd-timelimit (T ime Limit)This attribute sets the maximum number of seconds allocated for a search req

Pagina 237

Syntax DirectoryStringExample nsSSLclientauth: allowed2.3.1.111. passwordAllowChangeT imeThis attribute specifies the length of time that must pass be

Pagina 238

3.1.7. Case Exact String Syntax Plug-in3.1.8. Case Ignore String Syntax Plug-in3.1.9. Chaining Database Plug-in3.1.10. Class of Service Plug-in3.1.11.

Pagina 239

password expires using the passwordMaxAge attribute.For more information on password policies, see the "Managing Users and Passwords" chapte

Pagina 240 - A.1. Overview of ns-slapd

stored passwords. Set the number of old passwords the Directory Server stores using the passwordInHistory attribute.For more information on password p

Pagina 241

Entry DN cn=configValid Values on | offDefault Value onSyntax DirectoryStringExample passwordLockout: off2.3.1.124 . passwordLockoutDurat ion (Lockout

Pagina 242

Valid Range 0 to 64Default Value 0Syntax IntegerExample passwordMaxRepeats: 12.3.1.128. passwordMin8Bit (Password Synt ax)This sets the minimum numbe

Pagina 243

2.3.1.132. PasswordMinDigits (Pa ssword Synta x)This sets the minimum number of digits a password must contain.Parameter Descript ionEntry DN cn=confi

Pagina 244 - Glossary

2.3.1.137. PasswordMinUppers (Password Synt ax)This sets the minimum number of uppercase letters password must contain.Parameter Descript ionEntry DN

Pagina 245

This is an operational attribute, meaning its value is managed by the server and the attribute is notreturned in default searches.Parameter Descript i

Pagina 246 - 24 6 Glossary

Example passwordWarning: 864002.3.1.14 5. retryCountRese t T imeThis attribute specifies the length of time that passes before the passwordRetryCount

Pagina 247

2.3.2.2. nsslapd- changelogmaxage (Max Cha ngelog Age )This attribute sets the maximum age of any entry in the changelog. The changelog contains a rec

Pagina 248 - 24 8 Glossary

This attribute defines a time, in a YYMMDDHHMMSS format, when the entry was added.OID 2.16.840.1.113730.3.1.77Syntax DirectoryStringMulti- or Single-V

Pagina 249

3.6.2. nsslapd-changelogmaxage (Max Changelog Age)3.7. Distributed Numeric Assignment Plug-in Attributes3.7.1. dnaFilter3.7.2. dnaMagicRegen3.7.3. dna

Pagina 250 - 250 Glossary

2.3.3.1 . nsSSLSessionTimeoutThis attribute sets the lifetime duration of a TLS/SSL. T he minimum timeout value is 5 seconds. If asmaller value is set

Pagina 251

Parameter Descript ionEntry DN cn=encryption, cn=configValid Values For SSLv3: rsa_null_md5 rsa_rc4_128_md5 rsa_rc4_40 _md5 rsa_rc2_40_md5 rsa_des_sha

Pagina 252 - 252 Glossary

Windows synchronization agreement attributes are stored under cn=syncAgreementName, cn=replica, cn=suffix,cn=m apping tree,cn=config.2.3.6. Suffix Con

Pagina 253

cn=configValid Values 0 | 10 means no changes are logged1 means changes are loggedDefault Value 0Syntax IntegerExample nsDS5Flags: 02.3.7.2. nsds5Debu

Pagina 254 - 254 Glossary

Example nsDS5ReplicaBindDN: cn=replication manager,cn=config2.3.7.6. nsDS5ReplicaChangeCountThis read-only attribute shows the total number of entries

Pagina 255

This attribute controls the maximum age of deleted entries (tombstone entries) and state information.The Directory Server stores tombstone entries and

Pagina 256 - 256 Glossary

cn=configValid Range 0 to maximum 32-bit integer (2147483647) insecondsDefault Value 864 00 (1 day)Syntax IntegerExample nsDS5ReplicaT ombstonePurgeIn

Pagina 257

Default ValueSyntax DirectoryStringExample cn: MasterAtoMasterB2.3.8.2. de scriptionFree form text description of the replication agreement. T his att

Pagina 258 - 258 Glossary

Default Value 3Syntax IntegerExample nsDS5ReplicaBusyWaitT ime: 32.3.8.6. nsDS5ReplicaChangesSe ntSinceStart upThis read-only attribute shows the numb

Pagina 259

Parameter Descript ionEntry DN cn=ReplicationAgreementName, cn=replica,cn=suffixDN, cn=mapping tree, cn=configValid Values YYYYMMDDhhmmssZ is the date

Pagina 260 - 260 Index

7.3.16. start-slapd (Starts the Directory Server)7.3.17. stop-slapd (Stops the Directory Server)7.3.18. suffix2instance (Maps a Suffix to a Backend Na

Pagina 261

Parameter Descript ionEntry DN cn=ReplicationAgreementName, cn=replica,cn=suffixDN, cn=mapping tree, cn=configValid Values 0 (no replication sessions

Pagina 262 - 262 Index

2.3.8.19. nsDS5ReplicaSessionPauseT imeThis attribute sets the amount of time in seconds a supplier should wait between update sessions. T hedefault v

Pagina 263

Syntax IntegerExample nsDS5ReplicaT imeout: 6002.3.8.22. nsDS5ReplicaTransportInfoThis attribute sets the type of transport used for transporting data

Pagina 264 - 264 Index

Windows Active Directory servers.Table 2.7 . List of Attribute s Sha red Betwee n Replication and Synchronizat ion Agreementscn nsDS5ReplicaLastUpdat

Pagina 265

Valid Values on | offDefault ValueSyntax DirectoryStringExample nsDS7NewWinUserSyncEnabled: on2.3.9.5. nsds7WindowsDomainThis attribute sets the name

Pagina 266 - 266 Index

This attribute lists open connections. T hese are given in the following format:connection: A:YYYYMMDDhhmmssZ:B:C:D:EFor example:connection: 31:200102

Pagina 267

threadsThis attribute shows the number of threads used by the Directory Server. T his should correspond to nsslapd-threadnumber in cn=config.nba ckEnd

Pagina 268 - 268 Index

Example nsSaslMapRegexString: \(.*\)2.3.13. cn=SNMPSNMP configuration attributes are stored under cn=SNMP,cn=config. The cn=SNMP entry is aninstance o

Pagina 269

Parameter Descript ionEntry DN cn=SNMP, cn=configValid Values machine hostname or localhostDefault Value <blank>Syntax DirectoryStringExample ns

Pagina 270 - 270 Index

Table 2.8 . SNMP Statistic Att ributesAttribute Descript ionAnonymousBinds This shows the number of anonymous bindrequests.UnAuthBinds This shows the

Pagina 271

About This ReferenceRed Hat Directory Server (Directory Server) is a powerful and scalable distributed directory serverbased on the industry-standard

Pagina 272 - 272 Index

2.3.15. cn=tasksSome core Directory Server tasks can be initiated by editing a directory entry using LDAP tools. Thesetask entries are contained in cn

Pagina 273

Syntax case-exact stringExample nsTaskStatus: Loading entries...nsT askLogThis entry contains all of the log messages for the task, including both wa

Pagina 274 - 274 Index

Parameter Descript ionEntry DN cn=task_name, cn=task_type, cn=tasks,cn=configValid Values 0 to the maximum 32 bit integer value(2147483647)Default Val

Pagina 275

nsUniqueIdGenerator, analogous to the -g option to generate unique ID numbers for the entriesnsUniqueIdGeneratorNamespace, analogous to the -G option

Pagina 276 - 276 Index

Example nsImportChunkSize: 10nsImport IndexAt trsThis attribute sets whether to index the attributes that are imported into database instance.Paramete

Pagina 277

nsExportReplica, analogous to the -r option, to indicate whether the exported database is used inreplicationnsPrintKey, analogous to the -N option, to

Pagina 278 - 278 Index

Valid Values true | falseDefault Value falseSyntax Case-insensitive stringExample nsUseOneFile: truensExport Re plicaThis attribute identifies whether

Pagina 279

the parameters of the task and initiates the task. As soon as the task is complete, the task entry isremoved from the directory.The cn=backup entry is

Pagina 280 - 280 Index

nsArchiveDirThis attribute gives the location of the directory to which to write the backup.Parameter Descript ionEntry DN cn=task_name, cn=restore, c

Pagina 281

Syntax Case-insensitive string, multi-valuedExamplensIndexAttribute: "cn:pres,eq"nsIndexAttribute: "description:sub"nsIndexVLVAttr

Pagina 282 - 282 Index

Monospace with abackgroundThis type of formatting is used for anything entered or returned in acommand prompt.Italicized text Any text which is italic

Pagina 283

Syntax DirectoryStringExample cn: example reload task IDsche madirThis contains the full path to the directory containing the custom schema file.Param

Pagina 284 - 284 Index

The unique ID generator configuration attributes are stored under cn=uniqueid generator,cn=config. T he cn=uniqueid generator entry is an instance of

Pagina 285

topOID2.16.840.1.113730.3.2.40Required Attribute sAttribute Definit ionobjectClass Gives the object classes assigned to the entry.Allowed At tributesA

Pagina 286 - 286 Index

2.16.840.1.113730.3.2.104Required Attribute sAttribute Definit ionobjectClass Defines the object classes for the entry.cn Gives the common name of the

Pagina 287

Superior ClasstopOID2.16.840.1.113730.3.2.103Required Attribute sobjectClass Defines the object classes for the entry.cn Used for naming the replicati

Pagina 288 - 288 Index

attributes for this object class are in chapter 2 of the Red Hat Directory Server Configuration, Command,and File Reference.This object class is defin

Pagina 289

(RUV).nsds7DirectoryReplicaSubtree Specifies the Directory Server suffix (root or sub)that is synced.nsds7DirsyncCookie Contains a cookie set by the s

Pagina 290 - 290 Index

This object class is defined in Directory Server.Superior ClasstopOID2.16.840.1.113730.3.2.39Required Attribute sAttribute Definit ionobjectClass Give

Pagina 291

in after the lockout period.passwordLockoutDuration Sets the time, in seconds, that users will belocked out of the directory.passwordCheckSyntax Ident

Pagina 292 - 292 Index

cn Specifies the common name of the entry.Allowed At tributesAttribute Definit iondescription Gives a text description of the entry.l (localityName) G

Commenti su questo manuale

Nessun commento