Red Hat 8.1 User Manual
Red hat directory server 8.1
Table of contents
Document Outline
- Configuration and Command Reference
- Legal Notice
- Abstract
- Table of Contents
- About This Reference
- Chapter 1. Introduction
- Chapter 2. Core Server Configuration Reference
- 2.1. Overview of the Directory Server Configuration
- NOTE
- 2.2. Accessing and Modifying Server Configuration
- NOTE
- NOTE
- 2.3. Core Server Configuration Attributes Reference
- NOTE
- 2.3.1. cn=config
- 2.3.1.1. nsslapd-accesslog (Access Log)
- 2.3.1.2. nsslapd-accesslog-level (Access Log Level)
- 2.3.1.3. nsslapd-accesslog-list (List of Access Log Files)
- 2.3.1.4. nsslapd-accesslog-logbuffering (Log Buffering)
- 2.3.1.5. nsslapd-accesslog-logexpirationtime (Access Log Expiration Time)
- 2.3.1.6. nsslapd-accesslog-logexpirationtimeunit (Access Log Expiration Time Unit)
- 2.3.1.7. nsslapd-accesslog-logging-enabled (Access Log Enable Logging)
- 2.3.1.8. nsslapd-accesslog-logmaxdiskspace (Access Log Maximum Disk Space)
- 2.3.1.9. nsslapd-accesslog-logminfreediskspace (Access Log Minimum Free Disk Space)
- 2.3.1.10. nsslapd-accesslog-logrotationsync-enabled (Access Log Rotation Sync Enabled)
- 2.3.1.11. nsslapd-accesslog-logrotationsynchour (Access Log Rotation Sync Hour)
- 2.3.1.12. nsslapd-accesslog-logrotationsyncmin (Access Log Rotation Sync Minute)
- 2.3.1.13. nsslapd-accesslog-logrotationtime (Access Log Rotation Time)
- 2.3.1.14. nsslapd-accesslog-logrotationtimeunit (Access Log Rotation Time Unit)
- 2.3.1.15. nsslapd-accesslog-maxlogsize (Access Log Maximum Log Size)
- 2.3.1.16. nsslapd-accesslog-maxlogsperdir (Access Log Maximum Number of Log Files)
- 2.3.1.17. nsslapd-accesslog-mode (Access Log File Permission)
- 2.3.1.18. nsslapd-allow-unauthenticated-binds
- 2.3.1.19. nsslapd-attribute-name-exceptions
- 2.3.1.20. nsslapd-auditlog (Audit Log)
- 2.3.1.21. nsslapd-auditlog-list
- 2.3.1.22. nsslapd-auditlog-logexpirationtime (Audit Log Expiration Time)
- 2.3.1.23. nsslapd-auditlog-logexpirationtimeunit (Audit Log Expiration Time Unit)
- 2.3.1.24. nsslapd-auditlog-logging-enabled (Audit Log Enable Logging)
- 2.3.1.25. nsslapd-auditlog-logmaxdiskspace (Audit Log Maximum Disk Space)
- 2.3.1.26. nsslapd-auditlog-logminfreediskspace (Audit Log Minimum Free Disk Space)
- 2.3.1.27. nsslapd-auditlog-logrotationsync-enabled (Audit Log Rotation Sync Enabled)
- 2.3.1.28. nsslapd-auditlog-logrotationsynchour (Audit Log Rotation Sync Hour)
- 2.3.1.29. nsslapd-auditlog-logrotationsyncmin (Audit Log Rotation Sync Minute)
- 2.3.1.30. nsslapd-auditlog-logrotationtime (Audit Log Rotation Time)
- 2.3.1.31. nsslapd-auditlog-logrotationtimeunit (Audit Log Rotation Time Unit)
- 2.3.1.32. nsslapd-auditlog-maxlogsize (Audit Log Maximum Log Size)
- 2.3.1.33. nsslapd-auditlog-maxlogsperdir (Audit Log Maximum Number of Log Files)
- 2.3.1.34. nsslapd-auditlog-mode (Audit Log File Permission)
- 2.3.1.35. nsslapd-certdir (Certificate and Key Database Directory)
- 2.3.1.36. nsslapd-certmap-basedn (Certificate Map Search Base)
- 2.3.1.37. nsslapd-config
- 2.3.1.38. nsslapd-conntablesize
- 2.3.1.39. nsslapd-counters
- 2.3.1.40. nsslapd-csnlogging
- 2.3.1.41. nsslapd-ds4-compatible-schema
- 2.3.1.42. nsslapd-enquote-sup-oc (Enable Superior Object Class Enquoting)
- 2.3.1.43. nsslapd-errorlog (Error Log)
- 2.3.1.44. nsslapd-errorlog-level (Error Log Level)
- 2.3.1.45. nsslapd-errorlog-list
- 2.3.1.46. nsslapd-errorlog-logexpirationtime (Error Log Expiration Time)
- 2.3.1.47. nsslapd-errorlog-logexpirationtimeunit (Error Log Expiration Time Unit)
- 2.3.1.48. nsslapd-errorlog-logging-enabled (Enable Error Logging)
- 2.3.1.49. nsslapd-errorlog-logmaxdiskspace (Error Log Maximum Disk Space)
- 2.3.1.50. nsslapd-errorlog-logminfreediskspace (Error Log Minimum Free Disk Space)
- 2.3.1.51. nsslapd-errorlog-logrotationsync-enabled (Error Log Rotation Sync Enabled)
- 2.3.1.52. nsslapd-errorlog-logrotationsynchour (Error Log Rotation Sync Hour)
- 2.3.1.53. nsslapd-errorlog-logrotationsyncmin (Error Log Rotation Sync Minute)
- 2.3.1.54. nsslapd-errorlog-logrotationtime (Error Log Rotation Time)
- 2.3.1.55. nsslapd-errorlog-logrotationtimeunit (Error Log Rotation Time Unit)
- 2.3.1.56. nsslapd-errorlog-maxlogsize (Maximum Error Log Size)
- 2.3.1.57. nsslapd-errorlog-maxlogsperdir (Maximum Number of Error Log Files)
- 2.3.1.58. nsslapd-errorlog-mode (Error Log File Permission)
- 2.3.1.59. nsslapd-groupevalnestlevel
- 2.3.1.60. nsslapd-idletimeout (Default Idle Timeout)
- 2.3.1. cn=config
- NOTE
- WARNING
- 2.3.1.64. nsslapd-ldapiautobind (Enable Autobind)
- 2.3.1.65. nsslapd-ldapientrysearchbase (Search Base for LDAPI Authentication Entries)
- 2.3.1.66. nsslapd-ldapifilepath (File Location for LDAPI Socket)
- 2.3.1.67. nsslapd-ldapigidnumbertype (Attribute Mapping for System GUID Number)
- 2.3.1.68. nsslapd-ldapilisten (Enable LDAPI)
- 2.3.1.69. nsslapd-ldapimaprootdn (Autobind Mapping for Root User)
- 2.3.1.70. nsslapd-ldapimaptoentries (Enable Autobind Mapping for Regular Users)
- 2.3.1.71. nsslapd-ldapiuidnumbertype
- 2.3.1.72. nsslapd-listenhost (Listen to IP Address)
- NOTE
- NOTE
- NOTE
- NOTE
- WARNING
- WARNING
- NOTE
- NOTE
- NOTE>
- NOTE
- 2.3.1.107. nsslapd-tmpdir
- 2.3.1.108. nsslapd-versionstring
- 2.3.1.109. nsslapd-workingdir
- 2.3.1.110. nsSSLclientauth (Client Authentication)
- 2.3.1.111. passwordAllowChangeTime
- 2.3.1.112. passwordChange (Password Change)
- 2.3.1.113. passwordCheckSyntax (Check Password Syntax)
- 2.3.1.114. passwordExp (Password Expiration)
- 2.3.1.115. passwordExpirationTime
- 2.3.1.116. passwordExpWarned
- 2.3.1.117. passwordGraceLimit (Password Expiration)
- 2.3.1.118. passwordGraceUserTime
- 2.3.1.119. passwordHistory (Password History)
- 2.3.1.120. passwordInHistory (Number of Passwords to Remember)
- 2.3.1.121. passwordIsGlobalPolicy (Password Policy and Replication)
- 2.3.1.122. passwordKeepHistory
- 2.3.1.123. passwordLockout (Account Lockout)
- 2.3.1.124. passwordLockoutDuration (Lockout Duration)
- 2.3.1.125. passwordMaxAge (Password Maximum Age)
- 2.3.1.126. passwordMaxFailure (Maximum Password Failures)
- 2.3.1.127. passwordMaxRepeats (Password Syntax)
- 2.3.1.128. passwordMin8Bit (Password Syntax)
- NOTE
- 2.3.1.129. passwordMinAge (Password Minimum Age)
- 2.3.1.130. passwordMinAlphas (Password Syntax)
- 2.3.1.131. passwordMinCategories (Password Syntax)
- 2.3.1.132. PasswordMinDigits (Password Syntax)
- 2.3.1.133. passwordMinLength (Password Minimum Length)
- 2.3.1.134. PasswordMinLowers (Password Syntax)
- 2.3.1.135. PasswordMinSpecials (Password Syntax)
- 2.3.1.136. PasswordMinTokenLength (Password Syntax)
- 2.3.1.137. PasswordMinUppers (Password Syntax)
- 2.3.1.138. passwordMustChange (Password Must Change)
- 2.3.1.139. passwordResetDuration
- 2.3.1.140. passwordResetFailureCount (Reset Password Failure Count After)
- 2.3.1.141. passwordRetryCount
- 2.3.1.142. passwordStorageScheme (Password Storage Scheme)
- NOTE
- NOTE
- WARNING
- NOTE
- 2.3.2.2. nsslapd-changelogmaxage (Max Changelog Age)
- 2.3.2.3. nsslapd-changelogmaxentries (Max Changelog Records)
- 2.3.2.4. changes
- 2.3.2.5. changeLog
- 2.3.2.6. changeNumber
- 2.3.2.7. changeTime
- 2.3.2.8. changeType
- 2.3.2.9. deleteOldRdn
- 2.3.2.10. filterInfo
- 2.3.2.11. newRdn
- 2.3.2.12. newSuperior
- 2.3.2.13. targetDn
- 2.3.3. cn=encryption
- 2.3.4. cn=features
- 2.3.5. cn=mapping tree
- 2.3.6. Suffix Configuration Attributes under cn="suffixName"
- 2.3.7. Replication Attributes under cn=replica, cn="suffixDN", cn=mapping tree, cn=config
- NOTE
- 2.3.7.10. nsDS5ReplicaPurgeDelay
- 2.3.7.11. nsDS5ReplicaReferral
- 2.3.7.12. nsDS5ReplicaRoot
- 2.3.7.13. nsDS5ReplicaTombstonePurgeInterval
- 2.3.7.14. nsDS5ReplicaType
- 2.3.7.15. nsDS5ReplicaReapActive
- 2.3.7.16. nsds5Task
- 2.3.7.17. nsState
- 2.3.8. Replication Attributes under cn=ReplicationAgreementName, cn=replica, cn="suffixName", cn=mapping tree, cn=config
- 2.3.8.1. cn
- 2.3.8.2. description
- 2.3.8.3. nsDS5ReplicaBindDN
- 2.3.8.4. nsDS5ReplicaBindMethod
- 2.3.8.5. nsDS5ReplicaBusyWaitTime
- 2.3.8.6. nsDS5ReplicaChangesSentSinceStartup
- 2.3.8.7. nsDS5ReplicaCredentials
- 2.3.8.8. nsDS5ReplicaHost
- 2.3.8.9. nsDS5ReplicaLastInitEnd
- 2.3.8.10. nsDS5ReplicaLastInitStart
- 2.3.8.11. nsDS5ReplicaLastInitStatus
- 2.3.8.12. nsDS5ReplicaLastUpdateEnd
- 2.3.8.13. nsDS5ReplicaLastUpdateStart
- 2.3.8.14. nsDS5ReplicaLastUpdateStatus
- 2.3.8.15. nsDS5ReplicaPort
- 2.3.8.16. nsDS5ReplicaReapActive
- 2.3.8.17. nsDS5BeginReplicaRefresh
- 2.3.8.18. nsDS5ReplicaRoot
- 2.3.8.19. nsDS5ReplicaSessionPauseTime
- 2.3.8.20. nsDS5ReplicatedAttributeList
- 2.3.8.21. nsDS5ReplicaTimeout
- 2.3.8.22. nsDS5ReplicaTransportInfo
- 2.3.8.23. nsDS5ReplicaUpdateInProgress
- 2.3.8.24. nsDS5ReplicaUpdateSchedule
- 2.3.8.25. nsDS50ruv
- 2.3.8.26. nsruvReplicaLastModified
- 2.3.9. Synchronization Attributes under cn=syncAgreementName, cn=WindowsReplica,cn="suffixName", cn=mapping tree, cn=config
- Table 2.7. List of Attributes Shared Between Replication and Synchronization Agreements
- 2.3.9.1. nsds7DirectoryReplicaSubtree
- 2.3.9.2. nsds7DirsyncCookie
- 2.3.9.3. nsds7NewWinGroupSyncEnabled
- 2.3.9.4. nsds7NewWinUserSyncEnabled
- 2.3.9.5. nsds7WindowsDomain
- 2.3.9.6. nsds7WindowsReplicaSubtree
- 2.3.9.7. winSyncInterval
- 2.3.10. cn=monitor
- NOTE
- NOTE
- IMPORTANT
- IMPORTANT
- 2.4. Configuration Object Classes
- 2.4.1. changeLogEntry (Object Class)
- 2.4.2. directoryServerFeature (Object Class)
- 2.4.3. nsBackendInstance (Object Class)
- 2.4.4. nsChangelog4Config (Object Class)
- 2.4.5. nsContainer (Object Class)
- 2.4.6. nsDS5Replica (Object Class)
- 2.4.7. nsDS5ReplicationAgreement (Object Class)
- 2.4.8. nsDSWindowsReplicationAgreement (Object Class)
- 2.4.9. nsMappingTree (Object Class)
- 2.4.10. nsSaslMapping (Object Class)
- 2.4.11. nsslapdConfig (Object Class)
- 2.4.12. passwordpolicy (Object Class)
- 2.5. Legacy Attributes
- WARNING
- 2.5.2.1. cirReplicaSource (Object Class)
- 2.5.2.2. cirBeginORC
- 2.5.2.3. cirBindCredentials
- 2.5.2.4. cirBindDN
- 2.5.2.5. cirHost
- 2.5.2.6. cirLastUpdateApplied
- 2.5.2.7. cirPort
- 2.5.2.8. cirReplicaRoot
- 2.5.2.9. cirSyncInterval
- 2.5.2.10. cirUpdateFailedAt
- 2.5.2.11. cirUpdateSchedule
- 2.5.2.12. cirUsePersistentSearch
- 2.5.2.13. cirUseSSL
- 2.5.2.14. LDAPReplica (Object Class)
- 2.5.2.15. replicaAbandonedChanges
- 2.5.2.16. replicaBeginOrc
- 2.5.2.17. replicaBindDn
- 2.5.2.18. replicaBindMethod
- 2.5.2.19. replicaCFUpdated
- 2.5.2.20. replicaCredentials
- 2.5.2.21. replicaEntryFilter
- 2.5.2.22. replicaHost
- 2.5.2.23. replicaLastRelevantChange
- 2.5.2.24. replicaNickName
- 2.5.2.25. replicaPort
- 2.5.2.26. replicaRoot
- 2.5.2.27. replicatedAttributeList
- 2.5.2.28. replicaUpdateFailedAt
- 2.5.2.29. replicaUpdateReplayed
- 2.5.2.30. replicaUpdateSchedule
- 2.5.2.31. replicaUseSSL
- Chapter 3. Plug-in Implemented Server Functionality Reference
- 3.1. Server Plug-in Functionality Reference
- 3.1.1. 7-bit Check Plug-in
- 3.1.2. ACL Plug-in
- 3.1.3. ACL Preoperation Plug-in
- 3.1.4. Attribute Uniqueness Plug-in
- 3.1.5. Binary Syntax Plug-in
- 3.1.6. Boolean Syntax Plug-in
- 3.1.7. Case Exact String Syntax Plug-in
- 3.1.8. Case Ignore String Syntax Plug-in
- 3.1.9. Chaining Database Plug-in
- 3.1.10. Class of Service Plug-in
- 3.1.11. Country String Syntax Plug-in
- 3.1.12. Distinguished Name Syntax Plug-in
- 3.1.13. Distributed Numeric Assignment Plug-in
- 3.1.14. Generalized Time Syntax Plug-in
- 3.1.15. HTTP Client Plug-in
- 3.1.16. Integer Syntax Plug-in
- 3.1.17. Internationalization Plug-in
- 3.1.18. JPEG Syntax Plug-in
- 3.1.19. ldbm database Plug-in
- 3.1.20. Legacy Replication Plug-in
- 3.1.21. MemberOf Plug-in
- 3.1.22. Multi-master Replication Plug-in
- 3.1.23. Octet String Syntax Plug-in
- 3.1.24. OID Syntax Plug-in
- 3.1.25. Password Storage Schemes
- CAUTION
- Table 3.3. Password Storage Plugins
- 3.1.26. Postal Address String Syntax Plug-in
- 3.1.27. PTA Plug-in
- 3.1.28. Referential Integrity Postoperation Plug-in
- 3.1.29. Retro Changelog Plug-in
- 3.1.30. Roles Plug-in
- 3.1.31. Schema Reload Plug-in
- 3.1.32. Space Insensitive String Syntax Plug-in
- 3.1.33. State Change Plug-in
- 3.1.34. Telephone Syntax Plug-in
- 3.1.35. URI Syntax Plug-in
- 3.1.36. Views Plug-in
- 3.2. List of Attributes Common to All Plug-ins
- 3.3. Attributes Allowed by Certain Plug-ins
- 3.4. Database Plug-in Attributes
- NOTE
- NOTE
- WARNING
- WARNING
- WARNING
- NOTE
- NOTE
- NOTE
- NOTE
- NOTE
- NOTE
- NOTE
- NOTE
- NOTE
- NOTE
- NOTE
- NOTE
- NOTE
- NOTE
- nsslapd-db-abort-rate
- nsslapd-db-active-txns
- nsslapd-db-cache-hit
- nsslapd-db-cache-try
- nsslapd-db-cache-region-wait-rate
- nsslapd-db-cache-size-bytes
- nsslapd-db-clean-pages
- nsslapd-db-commit-rate
- nsslapd-db-deadlock-rate
- nsslapd-db-dirty-pages
- nsslapd-db-hash-buckets
- nsslapd-db-hash-elements-examine-rate
- nsslapd-db-hash-search-rate
- nsslapd-db-lock-conflicts
- nsslapd-db-lock-region-wait-rate
- nsslapd-db-lock-request-rate
- nsslapd-db-lockers
- nsslapd-db-log-bytes-since-checkpoint
- nsslapd-db-log-region-wait-rate
- nsslapd-db-log-write-rate
- nsslapd-db-longest-chain-length
- nsslapd-db-page-create-rate
- nsslapd-db-page-read-rate
- nsslapd-db-page-ro-evict-rate
- nsslapd-db-page-rw-evict-rate
- nsslapd-db-page-trickle-rate
- nsslapd-db-page-write-rate
- nsslapd-db-pages-in-use
- nsslapd-db-txn-region-wait-rate
- 3.4.5. Database Attributes under cn=default indexes, cn=config, cn=ldbm database, cn=plugins, cn=config
- NOTE
- 3.4.5.6. nsSystemIndex
- 3.4.6. Database Attributes under cn=monitor, cn=NetscapeRoot, cn=ldbm database, cn=plugins, cn=config
- 3.4.7. Database Attributes under cn=index, cn=NetscapeRoot, cn=ldbm database, cn=plugins, cn=config and cn=index, cn=UserRoot, cn=ldbm database, cn=plugins, cn=config
- 3.4.8. Database Attributes under cn=attributeName, cn=encrypted attributes, cn=database_name, cn=ldbm database, cn=plugins, cn=config
- 3.5. Database Link Plug-in Attributes (Chaining Attributes)
- NOTE
- 3.5.2.4. nsBindTimeout
- 3.5.2.5. nsCheckLocalACI
- 3.5.2.6. nsConcurrentBindLimit
- 3.5.2.7. nsConcurrentOperationsLimit
- 3.5.2.8. nsConnectionLife
- 3.5.2.9. nsOperationConnectionsLimit
- 3.5.2.10. nsProxiedAuthorization
- 3.5.2.11. nsReferralOnScopedSearch
- 3.5.2.12. nsSizeLimit
- 3.5.2.13. nsTimeLimit
- 3.5.3. Database Link Attributes under cn=database_link_name, cn=chaining database, cn=plugins, cn=config
- 3.5.4. Database Link Attributes under cn=monitor, cn=database instance name, cn=chaining database, cn=plugins, cn=config
- 3.6. Retro Changelog Plug-in Attributes
- NOTE
- NOTE
- 3.7. Distributed Numeric Assignment Plug-in Attributes
- NOTE
- NOTE
- 3.8. MemberOf Plug-in Attributes
- NOTE
- 3.1. Server Plug-in Functionality Reference
- Chapter 4. Server Instance File Reference
- Chapter 5. Log File Reference
- Chapter 6. Command-Line Utilities
- 6.1. Finding and Executing Command-Line Utilities
- NOTE
- 6.2. Using Special Characters
- 6.3. Command-Line Utilities Quick Reference
- 6.4. ldapsearch
- NOTE
- 6.5. ldapmodify
- NOTE
- 6.6. ldapdelete
- 6.7. ldappasswd
- NOTE
- NOTE
- 6.8. ldif
- NOTE
- 6.9. dbscan
- NOTE
- NOTE
- Table 6.25. Index File Options
- Examples
- Example 6.7. Dumping the Entry File
- Example 6.8. Displaying the Index Keys in cn.db4
- Example 6.9. Displaying the Index Keys and the Count of Entries with the Key in mail.db4
- Example 6.10. Displaying the Index Keys and the All IDs with More Than 20 IDs in sn.db4
- Example 6.11. Displaying the Summary of objectclass.db4
- Example 6.12. Displaying VLV Index File Contents
- Example 6.13. Displaying the Changelog File Contents
- Example 6.14. Dumping the Index File uid.db4 with Raw Mode
- Example 6.15. Displaying the entryID with the Common Name Key "=hr managers"
- Example 6.16. Displaying an Entry with the entry ID of 7
- Chapter 7. Command-Line Scripts
- 7.1. Finding and Executing Command-Line Scripts
- 7.2. Command-Line Scripts Quick Reference
- 7.3. Shell Scripts
- IMPORTANT
- NOTE
- Syntax
- Options
- 7.3.9. ldif2ldap (Performs Import Operation over LDAP)
- 7.3.10. monitor (Retrieves Monitoring Information)
- 7.3.11. repl-monitor (Monitors Replication Status)
- 7.3.12. pwdhash (Prints Encrypted Passwords)
- 7.3.13. restart-slapd (Restarts the Directory Server)
- 7.3.14. restoreconfig (Restores Administration Server Configuration)
- 7.3.15. saveconfig (Saves Administration Server Configuration)
- 7.3.16. start-slapd (Starts the Directory Server)
- 7.3.17. stop-slapd (Stops the Directory Server)
- 7.3.18. suffix2instance (Maps a Suffix to a Backend Name)
- 7.3.19. vlvindex (Creates Virtual List View Indexes)
- 7.4. Perl Scripts
- NOTE
- NOTE
- IMPORTANT
- NOTE
- IMPORTANT
- Syntax
- Options
- 7.4.11. ns-accountstatus.pl (Establishes Account Status)
- 7.4.12. ns-activate.pl (Activates an Entry or Group of Entries)
- 7.4.13. ns-inactivate.pl (Inactivates an Entry or Group of Entries)
- 7.4.14. ns-newpwpolicy.pl (Adds Attributes for Fine-Grained Password Policy)
- 7.4.15. register-ds-admin.pl
- IMPORTANT
- NOTE
- IMPORTANT
- NOTE
- WARNING
- WARNING
- IMPORTANT
- Using the ns-slapd Command-Line Utilities
- A.1. Overview of ns-slapd
- A.2. Finding and Executing the ns-slapd Command-Line Utilities
- NOTE
- A.3. Utilities for Exporting Databases: db2ldif
- A.4. Utilities for Restoring and Backing up Databases: ldif2db
- A.5. Utilities for Restoring and Backing up Databases: archive2db
- A.6. Utilities for Restoring and Backing up Databases: db2archive
- A.7. Utilities for Creating and Regenerating Indexes: db2index
- Glossary
- Index