Red-hat 8.1 Instrukcja Użytkownika Strona 1

Przeglądaj online lub pobierz Instrukcja Użytkownika dla Komputery Red-hat 8.1. Red Hat 8.1 User Manual Instrukcja obsługi

  • Pobierz
  • Dodaj do moich podręczników
  • Drukuj
  • Strona
    / 292
  • Spis treści
  • BOOKMARKI
  • Oceniono. / 5. Na podstawie oceny klientów

Podsumowanie treści

Strona 1 - Red Hat Directory Server 8.1

Red Hat Directory Server 8.1Configuration and Command ReferenceConfiguring and managing Red Hat Directory Server 8.1 with command-lineutilitiesEdition

Strona 2 - Legal Notice

Using the Admin Server describes the different tasks and tools associated with the AdministrationServer and how to use the Administration Server with

Strona 3 - Abstract

Multi- or Single-Valued Multi-valuedDefined in Directory Server2.5.2 . Legacy Replication At tributesThese attributes were originally used to configur

Strona 4 - Table of Contents

Defined in Directory Server2.5.2 .3. cirBindCre dentialsFor consumer-initiated replication, this attribute is used to identify the bind password for t

Strona 5

For consumer initiated replication, this attribute shows the time of the last failed updated attempt.OID 2.16.840.1.113730.3.1.88Syntax DirectoryStrin

Strona 6 - 6 Table of Contents

replicaCredentials Stores a password of replicaBindDn.replicaBindMethod Specifies the bind method.replicaUseSSL Specifies a flag whether or not to use

Strona 7

OID 2.16.840.1.113730.3.1.202Syntax BinaryMulti- or Single-Valued Multi-valuedDefined in Directory Server2.5.2 .21. replica EntryFilterThis attribute

Strona 8 - About This Reference

2.5.2 .28. replica Upda teFailedAtThis attribute contains the time and date of the most recent replication failure.OID 2.16.840.1.113730.3.1.49Syntax

Strona 9 - 3. Additional Reading

Chapter 3. Plug-in Implemented Server Functionality ReferenceThis chapter contains reference information on Red Hat Directory Server plug-ins.The conf

Strona 10 - 10 About This Reference

3.1 .3. ACL Preope ration Plug- inPlug-in Pa ramet er DescriptionPlug-in Name ACL PreoperationDN of Configuration Entry cn=ACL preoperation, cn=plugin

Strona 11 - Chapter 1. Introduction

Red Hat recommends leaving this plug-in runningat all times.Further Information3.1 .6. Boolean Syntax Plug-inPlug-in Pa ramet er DescriptionPlug-in Na

Strona 12

"Configuring Directory Databases" chapter in theDirectory Server Administrator's Guide.3.1 .10. Cla ss of Service Plug- inPlug-in Pa ra

Strona 13

Chapter 1. IntroductionDirectory Server is based on an open-systems server protocol called the Lightweight Directory AccessProtocol (LDAP). The Direct

Strona 14

Plug-in Pa ramet er DescriptionPlug-in Name Generalized T ime SyntaxDN of Configuration Entry cn=Generalized Time Syntax, cn=plugins,cn=configDescript

Strona 15

Performance Related Information Do not modify the configuration of this plug-in.Red Hat recommends leaving this plug-in runningat all times.Further In

Strona 16

Table 3.2. Details of MemberOf Plug-inPlug-in Information DescriptionPlug-in Name MemberOfConfiguration Entry DN cn=MemberOf Plugin,cn=plugins,cn=con

Strona 17

3.1 .25. Password Storage SchemesThe cn=Password Storage Schemes entry is a container entry, not a plug-in entry itself. All of theplug-ins used for e

Strona 18

3.1 .26. Posta l Address String Syntax Plug-inPlug-in Pa ramet er DescriptionPlug-in Name Postal Address SyntaxDN of Configuration Entry cn=Postal Add

Strona 19

conflict resolution loops. When enabling the plug-in on chainedservers, be sure to analyze the performance resource andtime needs as well as integrity

Strona 20

3.1 .32. Space Insensitive St ring Synt ax Plug-inPlug-in Pa ramet er DescriptionPlug-in Name Space Insensitive String SyntaxDN of Configuration Entry

Strona 21

Configurable Arguments NoneDependencies NonePerformance Related Information Do not modify the configuration of this plug-in.Red Hat recommends leaving

Strona 22

3.2 .3. nsslapd-pluginInitfuncThis attribute specifies the plug-in function to be initiated.Plug-in Pa ramet er DescriptionEntry DN cn=plug-in name, c

Strona 23

Syntax DirectoryStringExample nsslapd-pluginVendor: Red Hat, Inc.3.2 .9. nsslapd- pluginDescriptionThis attribute provides a description of the plug-i

Strona 24

Chapter 2. Core Server Configuration ReferenceThe configuration information for Red Hat Directory Server is stored as LDAP entries within the director

Strona 25

Entry DN cn=referential integrity postoperation, cn=plugins,cn=configValid Values Class of ServiceDefault ValueSyntax DirectoryStringExamplensslapd-pl

Strona 26

cn=configValid Range 100 to the maximum 32-bit integer value(2147483647) entry IDsDefault Value 4000Syntax IntegerExample nsslapd-idlistscanlimit: 40

Strona 27

cache the indexes (the .db4 files) and other files. This value is passed to the Berkeley DB API function set_cachesize. If automatic cache resizing i

Strona 28

Entry DN cn=config, cn=ldbm database, cn=plugins,cn=configValid Values on | offDefault Value offSyntax DirectoryStringExample nsslapd-db-debug: off3.4

Strona 29

database cache size being configured for the server. If this happens, reduce the size of the databasecache size to a value where the server will start

Strona 30

Parameter Descript ionEntry DN cn=config, cn=ldbm database, cn=plugins,cn=configValid Values Any valid path and directory nameDefault ValueSyntax Dire

Strona 31

WARNINGSetting this value will reduce data consistency and may lead to loss of data. T his is because ifthere is a power outage before the server can

Strona 32

by a process. If nsslapd-dbncache is 0 or 1, the cache will be allocated contiguously in memory. If it isgreater than 1, the cache will be broken up i

Strona 33

database (the ldif2db operation).In Directory Server, the import operation can be run as a server task or exclusively on the command-line.In the task

Strona 34

information on these entries, refer to the "Monitoring Server and Database Activity" chapter in theDirectory Server Administrator's Gui

Strona 35

Table 2.1 . Directory Se rver LDIF Configuration FilesConfigurat ion Filename Purposedse.ldif Contains front-end Directory Specific Entriescreated by

Strona 36

cn=plugins, cn=configValid Range1 to 232-1 on 32-bit systems or 26 3-1 on 64-bitsystems or -1, which means limitlessDefault Value -1Syntax IntegerExam

Strona 37

Entry DN cn=database_name, cn=ldbm database,cn=plugins, cn=configValid Values on | offDefault Value offSyntax DirectoryStringExample nsslapd-readonly:

Strona 38

Parameter Descript ionEntry DN cn=index_name, cn=userRoot, cn=ldbmdatabase, cn=plugins, cn=configValid Values 0 (disabled) | 1 (enabled)Default Value

Strona 39

NOTEThis attribute is only available to user databases like userRoot, not configuration databases likeo=NetscapeRoot.Parameter Descript ionEntry DN cn

Strona 40

Valid Values Any Directory Server attributes, in a space-separated listDefault ValueSyntax DirectoryStringExample vlvSort: cn givenname o ou sn3.4 .3.

Strona 41

nsslapd- db-clean-pagesThis attribute shows the clean pages currently in the cache.nsslapd- db-commit- rateThis attribute shows the number of transact

Strona 42

This attribute shows the clean pages forced from the cache.nsslapd- db-page-rw- evict- rateThis attribute shows the dirty pages forced from the cache.

Strona 43 - SSLDescriptors

Attribute Definit ionobjectClass Defines the object classes for the entry.cn Gives the common name of the entry.nsSystemIndex Identify whether or not

Strona 44

Entry DN cn=default indexes, cn=config, cn=ldbmdatabase, cn=plugins, cn=configValid Values true | falseDefault ValueSyntax DirectoryStringExample nsSy

Strona 45

3.4 .7.1 . nsSubStrBe ginBy default, for a search to be indexed, the search string must be at least three characters long, withoutcounting any wildcar

Strona 46

50ns-web.ldif Schema for Netscape Web Server.60pam-plugin.ldif Reserved for future use.99user.ldif User-defined schema maintained by DirectoryServer r

Strona 47 - NOTE>

Example nsSubStrMiddle: 33.4 .8. Dat abase Attributes unde r cn=attribut eName, cn=encrypt ed att ributes,cn=dat abase _name, cn=ldbm dat abase , cn=p

Strona 48

(AES) Triple Data Encryption Standard Block Cipher(3DES)Default ValueSyntax DirectoryStringExample nsEncryptionAlgorithm: AES3.5. Database Link Plug-i

Strona 49

This error detection, performance-related attribute specifies the duration of the test issued by thedatabase link to check whether the remote server i

Strona 50

Contrary to what the name suggests, this attribute does not specify the number of times a database linkretries to bind with the remote server but the

Strona 51

Example nsConcurrentOperationsLimit: 53.5 .2.8 . nsConnectionLifeThis attribute specifies connection lifetime. Connections between the database link a

Strona 52

Example nsslapd-sizelimit: 20003.5 .2.1 3. nsTimeLimitThis attribute shows the default search time limit for the database link.Parameter Descript ionE

Strona 53

Default ValueSyntax DirectoryStringExample nsFarmServerURL: ldap://farm1.example.com:389ldap://farm2.example.com:13893.5 .3.3. nsMultiplexorBindDnThis

Strona 54

headcountThis attribute gives the number of add operations received.nsDelete CountThis attribute gives the number of delete operations received.nsModi

Strona 55

This attribute specifies the name of the directory in which the changelog database is created the firsttime the plug-in is run. By default, the databa

Strona 56

Valid Range Any valid LDAP filterDefault Value NoneSyntax DirectoryStringExample dnaFilter: (objectclass=person)3.7 .2. dnaMagicRegenThis attribute se

Strona 57

These entries and their children have many attributes used to configure different database settings, likethe cache sizes, the paths to the index files

Strona 58

Example dnaNextRange: 100-5003.7 .5. dnaNextValueThis attribute gives the next available number which can be assigned. After being initially set in th

Strona 59

This attribute defines a shared identity that the servers can use to transfer ranges to one another. T hisentry is replicated between servers and is m

Strona 60

The MemberOf Plug-in synchronizes the group membership in group members with the members'individual directory entries by identifying changes to a

Strona 61

Chapter 4. Server Instance File ReferenceThis chapter provides an overview of the files that are specific to an instance of Red Hat DirectoryServer (D

Strona 62

Table 4 .3. HP- UX 11i (IA64 )File or Directory Locat ionBackup files /var/opt/dirsrv/slapd-instance/bakConfiguration files /etc/opt/dirsrv/slapd-ins

Strona 63

Exa mple 4 .2. Ne tscapeRoot Database Direct ory Contents./ entrydn.db4* parentid.db4*../ givenName.db4* sn.db4*DBVERSION* id2entry.db4* uid.db4

Strona 64

Lock table is out of available locks), double the value of the nsslapd-db-locks attributein the cn=config,cn=ldbm database,cn=plugins,cn=config entry

Strona 65

4.10. ScriptsDirectory Server command-line scripts are stored in the /etc/dirsrv/slapd-instance_namedirectory. The contents of the /etc/dirsrv/slapd-i

Strona 66

Chapter 5. Log File ReferenceRed Hat Directory Server (Directory Server) provides logs to help monitor directory activity. Monitoringhelps quickly det

Strona 67

Exa mple 5.1. Example Access Log[21/Apr/2009:11:39:51 -0700] conn=11 fd=608 slot=608 connection from 207.1.153.51 to 192.18.122.139[21/Apr/2009:11:39

Strona 68

2.2.2 .1. Modifying Configuration Ent ries Using LDAPThe configuration entries in the directory can be searched and modified using LDAP either via the

Strona 69

Slot NumberThe slot number, in this case slot=608, is a legacy part of the access log which has the samemeaning as file descriptor. Ignore this part o

Strona 70

Table 5.1 . Commonly-Used T agsTag Descript iontag=97 A result from a client bind operation.tag=100 The actual entry being searched for.tag=101 A res

Strona 71

ENT RYREFERRAL, an LDAP referral or search referenceUninde xed Search IndicatorThe unindexed search indicator, notes=U, indicates that the search perf

Strona 72

An extended operation OID, such as EXT oid="2.16.84 0.1.113730.3.5.3" or EXT oid="2.16.84 0.1.113730.3.5.5" in Example 5.1, “Exam

Strona 73

NOTEThe Directory Server operation number starts counting at 0, and, in the majority of LDAPSDK/client implementations, the message ID number starts c

Strona 74

[12/Jul/2009:16:43:02 +0200] conn=306 fd=60 slot=60 connection from 127.0.0.1 to 127.0.0.1 [12/Jul/2009:16:43:02 +0200] conn=306 op=0 SRCH base="

Strona 75

Table 5.3. Common Connection CodesConnect ion Code Descript ionA1 Client aborts the connection.B1 Corrupt BER tag encountered. If BER tags, whichenca

Strona 76

Table 5.4 . Error Log LevelsSett ing Console Name Descript ion1 Trace function calls Logs a message when theserver enters and exits afunction.2 Packe

Strona 77

A timestamp, such as [05/Jan/2009:02:27:22 -0500], although the format varies dependingon the platform. The ending four digits, -0500, indicate the ti

Strona 78

Red Hat Directory Server 8.1 Configuration and Command Reference 169

Strona 79

nsslapd-schema-ignore-trailing-spaces nsslapd-securelistenhostnsslapd-workingdir nsslapd-return-exact-casensslapd-maxbersize2.3. Core Server Configura

Strona 80

Exa mple 5.4 . Re plication Error Log Entry[09/Jan/2009:13:44:48 -0500] - _csngen_adjust_local_time: gen state before 496799220001:1231526178:0:0[09/J

Strona 81

Plug-in logging records every the name of the plugin and all of the functions called by the plugin. Thishas a simple format:[timestamp] Plugin_name -

Strona 82

Example 5.7, “Access Control Summary Logging” shows the summary access control log entry.Exa mple 5.7. Access Control Summary Logging[09/Jan/2009:16:0

Strona 83

Exa mple 5.8. Audit Log Content ... modifying an entry ... tim e: 20090108181429 dn: uid=scarter,ou=people,dc=example,dc=com changetype: modify repla

Strona 84

Table 5.5 . LDAP Result CodesResultCodeDefined Value ResultCodeDefined Value0 SUCCESS 48 INAPPROPRIATE_AUTHENTICATION1 OPERAT ION_ERROR 49 INVALID_CR

Strona 85

Chapter 6. Command-Line UtilitiesThis chapter contains reference information on command-line utilities used with Red Hat DirectoryServer (Directory Se

Strona 86

Table 6.1 . Commonly-Used Command-Line Utilit iesCommand-Line Utility Descriptionldapsearch Searches the directory and returns searchresults in LDIF

Strona 87

Table 6.2 . ldapsearch SyntaxOption Descriptionoptional_options A series of command-line options. These must bespecified before the search filter, if

Strona 88

Table 6.3. Commonly-Used ldapsearch OptionsOption Description-b Specifies the starting point for the search. T hevalue specified here must be a disti

Strona 89

The default is 389. If -Z is used, the default is 636.-s Specifies the scope of the search. T he scope canbe one of the following: base searches only

Strona 90

Table 2.2 . dse .ldif File Att ributesAttribute Value Logging enabled or disablednsslapd-accesslog-logging-enablednsslapd-accesslogonempty stringDis

Strona 91

Table 6.4 . Pe rsistent Search OptionsOption Description-C Runs the ldapsearch as a persistent search.-r Prints all of the output from the ldapsearch

Strona 92

Table 6.5 . Additional SSL ldapse arch OptionsOption Description-3 Specifies that hostnames should be checked in SSLcertificates.-I Specifies the SSL

Strona 93

command is aborted immediately.SASL OptionsSASL mechanisms can be used to authenticate a user, using the -o the required SASL information.To learn whi

Strona 94

Table 6.7 . Description of CRAM-MD5 Mechanism OptionsRequiredorOptionalOption Description ExampleRequired mech=CRAM-MD5 Gives the SASL mechanism. -o

Strona 95

Table 6.8 . Description of DIGEST- MD5 SASL Mechanism OptionsRequiredorOptionalOption Description ExampleRequired mech=DIGEST-MD5 Gives the SASL mech

Strona 96

Table 6.9 . Description of GSSAPI SASL Mechanism OptionsRequired orOptionalOption Descript ion Exa mpleRequired mech=GSSAPI Gives the SASLmechanism.N

Strona 97

Table 6.1 0. Additional ldapsearch OptionsOption Description-1 Leaves out the opening version: 1 line fromthe LDIF output.-A Specifies that the searc

Strona 98 - 2.5. Legacy Attributes

characterset.ldapsearch converts the input from thesearguments before it processes the searchrequest. For example, -i no indicates that thebind DN, ba

Strona 99

of the content.-U Creates file URLs for the files produced by the -toption.-u Specifies that the user-friendly form of thedistinguished name be used i

Strona 100

Table 6.1 1. Commonly-Used lda pmodify OptionsOption Description-a Adds LDIF entries to the directory withoutrequiring the changetype:add LDIF update

Strona 101

right away instead of having to wait for the log entries to be flushed to the file. Disabling log buffering canseverely impact performance in heavily

Strona 102

SSL OptionsUse the following command-line options to specify that ldapm odify is to use LDAP over SSL (LDAPS)when communicating with the Directory Ser

Strona 103

Table 6.1 2. lda pmodify SSL OptionsOption Descript ion-3 Specifies that hostnames should be checked in SSLcertificates.-I Specifies the SSL key pass

Strona 104

“Commonly-Used ldapsearch Options”.Table 6.1 3. SASL OptionsOption Description-o Specifies SASL options. T he format is -osaslOption=value. saslOptio

Strona 105

Table 6.1 4 . Additional ldapmodify OptionsOption Description-b Causes the utility to check every attribute value todetermine whether the value is a

Strona 106

-V 2LDAPv3 is the default. An LDAPv3 operationcannot be performed against a Directory Serverthat only supports LDAPv2.-Y Specifies the proxy DN to use

Strona 107

Table 6.1 5. Commonly-Used lda pdelete Opt ionsOption Description-D Specifies the distinguished name with which toauthenticate to the server. T he va

Strona 108

Table 6.1 6. lda pde lete SSL Opt ionsOption Descript ion-3 Specifies that hostnames should be checked in SSLcertificates.-I Specifies the SSL key p

Strona 109

To learn which SASL mechanisms are supported, search the root DSE. See the -b option in T able 6.3,“Commonly-Used ldapsearch Options”.Table 6.1 7. SA

Strona 110

Table 6.1 8. Additional ldapdelete Opt ionsOption Description-c Specifies that the utility must run in continuousoperation mode. Errors are reported,

Strona 111

Table 6.1 9. lda ppa sswd-specific Opt ionsOption Description-A Specifies that the command should prompt for theuser's existing password.-a Spe

Strona 112

Legal NoticeCopyright © 20 09 Red Hat, Inc..The text of and illustrations in this document are licensed by Red Hat under a Creative CommonsAttributio

Strona 113

Parameter Descript ionEntry DN cn=configValid Values on | offDefault Value onSyntax DirectoryStringExample nsslapd-accesslog-logging-enabled: off2.3.1

Strona 114

Table 6.2 0. General ldappasswd OptionsOption Descript ion-3 Specifies that hostnames should be checked in SSLcertificates.-D Specifies the distingui

Strona 115

for the browser. For example:-P /security/cert.dbThe client security files can also be stored on theDirectory Server in the /etc/dirsrv/slapd-instance

Strona 116

Table 6.2 1. SASL OptionsOption Description-o Specifies SASL options. T he format is -osaslOption=value. saslOption can have one of sixvalues: mech,

Strona 117

Exa mple 6.4 . User Authenticating Wit h a User Certifica te a nd Changing His PasswordA user, tuser4 , authenticates with the user certificate and ch

Strona 118

Table 6.2 2. ldif Opt ionsOption Description-b Specifies that the ldif utility should interpret theentire input as a single binary value. If -b is no

Strona 119

NOTEThe index file options, listed in Table 6.25, “Index File Options ”, are meaningful only when thedatabase file is the secondary index file.Table

Strona 120

Exa mple 6.13. Displaying the Change log File Cont entsdbscan -f /var/lib/dirsrv/slapd-instance_name/changelogdb/c1a2fc02-1d11b2-8018afa7-fdce000_424c

Strona 121

Chapter 7. Command-Line ScriptsThis chapter provides information on the scripts for managing Red Hat Directory Server, such asbacking-up and restoring

Strona 122

Table 7.2 . Pe rl Scripts in /usr/lib/dirsrv/slapd- instance_name or/usr/lib64 /dirsrv/slapd-instance_namePerl Script Descript ionbak2db.pl Restores

Strona 123

This section covers the following scripts:Section 7.3.1, “bak2db (Restores a Database from Backup)”Section 7.3.2, “cl-dump (Dumps and Decodes the Chan

Strona 124

Parameter Descript ionEntry DN cn=configValid Range 0 through 23Default Value 0Syntax IntegerExample nsslapd-accesslog-logrotationsynchour: 232.3.1.12

Strona 125

OptionsWithout the -i option, the script must be run when the Directory Server is running from a location fromwhich the server's changelog direct

Strona 126

Either the -n or the -s option must be specified. By default, the output LDIF will be stored in one file. Tospecify the use of several files, use the

Strona 127

Table 7.7 . db2index Opt ionsOption Description-n backendInstance Gives the name of the instance to be reindexed.-s includeSuffix Gives suffixes to

Strona 128

Synta xds_removal [ -f ] -s instance_name -w manager_passwordOptions Option Pa ramet er Descript ion-f Forces the removal of theinstance. This can be

Strona 129

Table 7.9 . ldif2db OptionsOption Description-c Merges chunk size.-E Encrypts data during import. T his option is usedonly if database encryption is

Strona 130

Retrieves performance monitoring information using the ldapsearch command-line utility.Synta xm onitormonitor OptionsThere are no options for this scr

Strona 131

[connection]host:port:binddn:bindpwd:bindcerthost:port:binddn:bindpwd:bindcert...[alias]alias = host:portalias = host:port...[color]lowmark = colorlow

Strona 132

log in, use this script to compare the user's password to the password stored in the directory.Synta xpwdhash [ -D config_directory ] [ -H ] [[ -

Strona 133

Synta xsaveconfigOptionsThere are no options for this script.7.3.16. start- slapd (St arts the Directory Server)Starts the Directory Server. It might

Strona 134

7.3.19. vlvindex (Creat es Virtual List View Inde xes)To run the vlvindex script, the server must be stopped. The vlvindex script creates virtual list

Strona 135

Valid Range -1 | 1 to the maximum 32 bit integer value(2147483647), where a value of -1 means the logfile is unlimited in size.Default Value 100Syntax

Strona 136

Synta xbak2db.pl [ -v ] -D rootdn { -w password | -w - | -j filename } -a backupDirectory [ -t databaseType ] [ -n backend ]OptionsThe script bak2db.p

Strona 137

Table 7.1 9. cl-dump.pl comma nd opt ionsOption Description-c Dumps and interprets change sequence numbers(CSN) only. This option can be used with or

Strona 138

Synta xdb2index.pl [ -v ] -D rootdn { -w password | -w - | -j filename } -n backendInstance [ -t attributeName(:indextypes(:mathingrules)) ] [ -T vlvA

Strona 139

Table 7.2 2. db2ldif.pl Opt ionsOption Description-1 Deletes, for reasons of backward compatibility,the first line of the LDIF file that gives the ve

Strona 140

Table 7.2 3. fixup-memberof.pl OptionsOption Description-b baseDN The DN of the subtree containing the entries toupdate.-D rootdn Gives the user DN w

Strona 141

Table 7.2 4 . ldif2db.pl Opt ionsOption Description-c Merges chunk size.-D rootdn Specifies the user DN with root permissions,such as Directory Manag

Strona 142

Table 7.2 5. Informat ion Extracted from Access Logs Number of restarts Total number of connections Total operations requested Total results returned

Strona 143

Table 7.2 6. logconv.pl OptionsOption Description-d mgrDN Specifies the distinguished name (DN) of theDirectory Manger in the logs being analyzed. Th

Strona 144

Table 7.2 7. logconv.pl Options to Displa y OccurrencesOption Descriptione Lists the most frequent error and return codes.f Lists the bind DNs with t

Strona 145

Option Alternat eOptionsDescript ionGeneral.ConfigDirectoryAdminPwd=password Required. This is the password for theconfiguration directory administrat

Strona 146

The nsslapd-allow-unauthenticated-binds attribute sets whether to allow an unauthenticated bindto succeed as an anonymous bind. By default, unauthenti

Strona 147

IMPORTANTDo not run setup-ds-adm in.pl for the new Directory Server 8.1 instance before running themigration script if you are migrating from a 7.1 se

Strona 148

number of d's increases the debug level.--logfile name -l T his parameter specifies a log file to whichto write the output. If this is not set, t

Strona 149

Table 7.2 9. ns-act ivate.pl Opt ionsOption Description-D rootdn Specifies the Directory Server user DN with rootpermissions, such as Directory Manag

Strona 150

Table 7.31. ns-newpwpolicy.pl Opt ionsOption Description-D rootdn Specifies the Directory Server user DN with rootpermissions, such as Directory Mana

Strona 151

database files, like cert8.db and key3.db, are not removed, so the remaining instance directory isrenamed removed.slapd-instance.Synta xrem ove-ds.pl

Strona 152

Configurat ion File FormatThe configuration file defines the following:The connection parameters for connecting to the LDAP servers to get replication

Strona 153

A shadow port can be set in the replication monitor configuration file. For example:host:port=shadowport:binddn:bindpwd:bindcertWhen the replication m

Strona 154 - 4.4. Database Files

Options Option Alt ernate Opt ions Description--silent -s This runs the register script insilent mode, drawing theconfiguration information from afile

Strona 155 - 4.6. Lock Files

Synta xsetup-ds-admin.pl [ --debug ] [ --silent ] [ --file=name ] [ --keepcache ] [ --log=name ] [ --update ]Options Option Alt ernate Opt ions Descri

Strona 156 - 4.7. Log Files

IMPORTANTNever run verify-db.pl when a modify operation is in progress. T his command calls theBerkeleyDB utility db_verify and does not perform any l

Strona 157 - 4.10. Scripts

Example nsslapd-auditlog-list: auditlog2,auditlog32.3.1.22. nsslapd- auditlog-logexpirationtime (Audit Log Expira tion T ime)This attribute sets the m

Strona 158 - Chapter 5. Log File Reference

Using the ns-slapd Command-Line UtilitiesChapter 7, Command-Line Scripts discussed the scripts for performing routine administration tasks onthe Red H

Strona 159

Table A.1. db2 ldif OptionsOption Description-a outputFile Defines the output file in which the server savesthe exported LDIF. This file is stored by

Strona 160

OptionsTable A.2. ldif2db Opt ionsOption Description-d debugLevel Specifies the debug level to use during runtime.For further information, refer to S

Strona 161

ns-slapd archive2db -D configDir -a archiveDirOptionsTable A.3. archive2db OptionsOption Description-D configDir Specifies the location of the server

Strona 162

Table A.5. db2 index Opt ionsOption Description-d debugLevel Specifies the debug level to use during indexcreation. For further information, refer to

Strona 163

All IDs ThresholdReplaced with the ID list scan limit in Directory Server version 7.1. A size limit which is globallyapplied to every index key manage

Strona 164

bind distinguished nameSee bind DN.bind DNDistinguished name used to authenticate to Directory Server when performing an operation.bind ruleIn the con

Strona 165

supplier server then replays these modifications on the replicas stored on replica servers or onother masters, in the case of multi-master replication

Strona 166 - 5.2. Error Log Reference

DdaemonA background process on a Unix machine that is responsible for a particular system task.Daemon processes do not need human intervention to cont

Strona 167

DNSDomain Name System. T he system used by machines on a network to associate standard IPaddresses (such as 198.93.93.10) with hostnames (such as www.

Strona 168

This attribute sets the maximum amount of disk space in megabytes that the audit logs are allowed toconsume. If this value is exceeded, the oldest aud

Strona 169

Generic Security Services. The generic access protocol that is the native way for UNIX-basedsystems to access and authenticate Kerberos services; also

Strona 170

location of a machine on the Internet (for example, 198.93.93.10).ISOInternational Standards Organization.Kknowle dge re fe rencePointers to directory

Strona 171

managed objectA standard value which the SNMP agent can access and send to the NMS. Each managedobject is identified with an official name and a numer

Strona 172 - 5.3. Audit Log Reference

The server containing the database link that communicates with the remote server.Nn + 1 directory problemThe problem of managing multiple instances o

Strona 173 - 5.4. LDAP Result Codes

requested.Pparent accessWhen granted, indicates that users have access to entries below their own in the directory treeif the bind DN is the parent of

Strona 174

PTAMechanism by which one Directory Server consults another to check bind credentials. Alsopass-through authentication.PTA directory serverIn pass-thr

Strona 175 - 6.2. Using Special Characters

Replication configuration where replica servers, either hub or consumer servers, pull directorydata from supplier servers. This method is available on

Strona 176 - 6.4. ldapsearch

Serve r ConsoleJava-based application that allows you to perform administrative management of your DirectoryServer from a GUI.server daemonThe server

Strona 177 - "(objectclass=* )"

master agent. Also called a subagent.SSLA software library establishing a secure connection between two parties (client and server)used to implement H

Strona 178

target entryThe entries within the scope of a CoS.TCP/IPTransmission Control Protocol/Internet Protocol. T he main network protocol for the Internet a

Strona 179 - -w diner892

2.3.1.29. nsslapd- auditlog-logrotat ionsyncmin (Audit Log Rotat ion Sync Minute)This attribute sets the minute of the day for rotating audit logs. T

Strona 180

01common.ldif- ldif files, LDIF and Schema Configuration Files05rfc224 7.ldif- ldif files, LDIF and Schema Configuration Files05rfc2927.ldif- ldif fil

Strona 181 - -W secret

- B4 , Common Connection Codes- P2 , Common Connection Codes- T1 , Common Connection Codes- T2 , Common Connection Codes- U1 , Common Connection Codes

Strona 182 - "authid=test_user"

changeLog, changeLogchangelog configura tion at tributes- changelogmaxentries, nsslapd-changelogmaxentries (Max Changelog Records)- nsslapd-changelogd

Strona 183

- nsInstance, cn=export- nsNoWrap, cn=export- nsPrintKey, cn=export- nsUseId2Entry, cn=export- nsUseOneFile, cn=export- configuration entry, cn=export

Strona 184

- SNMP configuration entries, cn=SNMPcn=t asks- attributes- cn, Task Invocation Attributes for Entries under cn=tasks- nsTaskCancel, T ask Invocation

Strona 185

- restoreconfg , restoreconfig (Restores Administration Server Configuration)- saveconfig , saveconfig (Saves Administration Server Configuration)- st

Strona 186 - -f search_filters

configurat ion entrie s- modifying using LDAP, Modifying Configuration Entries Using LDAP- restrictions to modifying, Restrictions to Modifying Config

Strona 187 - -S sn -S givenname

- nsDumpUniqId, cn=export- nsExcludeSuffix, cn=import, cn=export- nsExportReplica, cn=export- nsFilename, cn=import, cn=export- nsImportChunkSize, cn=

Strona 188 - 6.5. ldapmodify

- nsslapd-changelogmaxentries, nsslapd-changelogmaxentries (Max Changelog Records)- nsslapd-config, nsslapd-config- nsslapd-conntablesize, nsslapd-con

Strona 189 - -w mypassword

- nsslapd-schema-ignore-trailing-spaces, nsslapd-schema-ignore-trailing-spaces (IgnoreTrailing Spaces in Object Class Names)- nsslapd-schemacheck, nss

Strona 190

2.3.1.33. nsslapd-audit log-maxlogsperdir (Audit Log Ma ximum Number of Log Files)This attribute sets the total number of audit logs that can be conta

Strona 191

- nsAttributeEncryption, Database Attributes under cn=attributeName, cn=encryptedattributes, cn=database_name, cn=ldbm database, cn=plugins, cn=config

Strona 192

- dbcachetries, Database Attributes under cn=monitor, cn=ldbm database, cn=plugins,cn=config- dbfilecachehit, Database Attributes under cn=monitor, cn

Strona 193

cn=ldbm database, cn=plugins, cn=config- nsslapd-db-page-rw-evict-rate, Database Attributes under cn=database, cn=monitor,cn=ldbm database, cn=plugins

Strona 194 - 6.6. ldapdelete

- quick reference, Command-Line Scripts Quick Referencedbcachehit ratio attribute, Da tabase Attribut e s under cn=monit or, cn=ldbm database,cn=plugi

Strona 195

- quick reference, Command-Line Scripts Quick Referenceds_re moval command-line utility- options, ds_removal- syntax, ds_removaldTableSize att ribute

Strona 196

- configuration of, Configuration of IndexesJjpeg images, ldifLLDAP- modifying configuration entries, Modifying Configuration Entries Using LDAPLDAP D

Strona 197

- 20subscriber.ldif, LDIF and Schema Configuration Files- 25java-object.ldif, LDIF and Schema Configuration Files- 28pilot.ldif, LDIF and Schema Confi

Strona 198 - 6.7. ldappasswd

mult i-mast er replication change log- changelog, cn=changelog5Nnba ckends at t ribute, cn=monitornewRdn, newRdnnewSuperior, newSuperiorns-accountst a

Strona 199 - -t old_password.txt

nsDatabaseType s, cn=backup, cn=rest orensDelete Count at tribute , Da tabase Link At tributes under cn=monitor, cn=databaseinst ance name, cn=chainin

Strona 200 - -N Server-Cert

nshoplimit att ribute, nshoplimitnsImport ChunkSize, cn=importnsImport IndexAt trs, cn=importnsIncludeSuffix, cn=import, cn=exportnsIndexAt tribute, c

Strona 201

Example /etc/dirsrv/slapd-phonebook2.3.1.36. nsslapd-ce rtmap- base dn (Certificate Map Se arch Base)This attribute can be used when client authentica

Strona 202

nsslapd- accesslog-logrotationt ime att ribute, nsslapd-accesslog-logrotat iontime(Access Log Rotat ion Time)nsslapd- accesslog-maxlogsize attribute,

Strona 203 - 6.8. ldif

cn=monitor, cn=ldbm dat abase , cn=plugins, cn=confignsslapd- db-cache-try att ribute, Dat abase Attributes unde r cn=database , cn=monit or,cn=ldbm d

Strona 204 - 6.9. dbscan

nsslapd- db-verbose at tribute, nsslapd- db-verbosensslapd- dbcache size attribute, nsslapd- dbcache sizensslapd- dbncache attribute, nsslapd-dbncach

Strona 205

nsslapd- maxsasliosize att ribute, nsslapd- maxsasliosize (Maximum SASL Packet Size)nsslapd- maxthreadsperconn a ttribute , nsslapd-maxt hreadspercon

Strona 206

nssnmplocation a ttribut e, nssnmplocationnssnmpmast erhost a ttribut e, nssnmpmaste rhostnssnmpmast erport att ribute, nssnmpmast erportnssnmporganiz

Strona 207

passwordInHistory attribut e, passwordInHistory (Number of Passwords to Remember)passwordLockout at t ribute, passwordLockout (Account Lockout)passwo

Strona 208 - 7.3. Shell Scripts

name, cn=chaining database, cn=plugins, cn=config- nsAbandonedSearchCheckInterval, nsAbandonedSearchCheckInterval- nsActiveChainingComponents, nsActiv

Strona 209

database, cn=plugins, cn=config- nsslapd-db-durable-transactions, nsslapd-db-durable-transactions- nsslapd-db-hash-buckets, Database Attributes under

Strona 210

- nsTimeLimit, nsTimeLimit- nsTransmittedControls, nsT ransmittedControls- nsUnbindCount, Database Link Attributes under cn=monitor, cn=database insta

Strona 211

repl-monit or.pl- command-line perl script, repl-monitor.pl (Monitors Replication Status)- quick reference, Command-Line Scripts Quick Referencereplic

Strona 212 - IMPORTANT

This attribute sets whether change sequence numbers (CSNs), when available, are to be logged in theaccess log. By default, CSN logging is turned on.Pa

Strona 213

retro changelog plug-in configuration a ttribute s- nsslapd-changelogdir, nsslapd-changelogdirretryCountReset T ime, retryCount ResetTimeSSASL configu

Strona 214 - -g deterministic namespace_id

SNMP configura tion at tributes- nssnmpcontact, nssnmpcontact- nssnmpdescription, nssnmpdescription- nssnmpenabled, nssnmpenabled- nssnmplocation, nss

Strona 215

TtargetDn, t argetDntotalConnections att ribute, cn=monit ortrailing space s in object class names, nsslapd- schema- ignore -tra iling-spaces (IgnoreT

Strona 216

AbstractThis reference covers the server configuration and the command-line utilities. It is designed primarily fordirectory administrators and experi

Strona 217

Table 2.6 . Possible Combinat ions for nsslapd-errorlog Configura tion Att ributesAttribute s in dse.ldif Value Logging enabled or disablednsslapd-er

Strona 218

Entry DN cn=configValid ValuesDefault Value NoneSyntax DirectoryStringExample nsslapd-errorlog-list: errorlog2,errorlog32.3.1.4 6. nsslapd- errorlog-l

Strona 219 - 7.4. Perl Scripts

This attribute sets the minimum allowed free disk space in megabytes. When the amount of free diskspace falls below the value specified on this attrib

Strona 220

attribute value to 1 or set the nsslapd-errorlog-logrotationtime attribute to -1. The server checksthe nsslapd-errorlog-maxlogsperdir attribute first,

Strona 221

2.3.1.58. nsslapd- errorlog-mode (Error Log File Permission)This attribute sets the access mode or file permissions with which error log files are to

Strona 222

Default Value 0Syntax IntegerExample nsslapd-idletimeout: 02.3.1.61. nsslapd- inst ance dir (Instance Direct ory)This attribute is deprecated. There a

Strona 223

Default Value offSyntax DirectoryStringExample nsslapd-ldapiautobind: off2.3.1.65. nsslapd- ldapientrysearchba se (Sea rch Base for LDAPI Aut hentica

Strona 224

2.3.1.69. nsslapd- ldapimaprootdn (Autobind Mapping for Root Use r)With autobind, a system user is mapped to a Directory Server user and then automat

Strona 225 - -g deterministic namespaceId

Parameter Descript ionEntry DN cn=configValid Values Any local hostname, IPv4 or IPv6 addressDefault ValueSyntax DirectoryStringExample nsslapd-listen

Strona 226

Entry DN cn=configValid Range 0 - 2 gigabytes (2,147,483,647 bytes)Zero 0 means that the default value should beused.Default Value 2097152Syntax Integ

Strona 227

Table of ContentsAbout T his Reference1. Directory Server Overview2. Examples and Formatting2.1. Command and File Examples2.2. T ool Locations2.3. LDA

Strona 228

When an incoming SASL IO packet is larger than the nsslapd-maxsasliosize limit, the serverimmediately disconnects the client and logs a message to the

Strona 229

system; make sure no other application is attempting to use the same port number. Specifying a portnumber of less than 1024 means the Directory Serve

Strona 230

entries:ou=People,dc=example,dc=combut the request is for this entry:ou=Groups,dc=example,dc=comIn this case, the referral would be passed back to the

Strona 231

nsslapd-reservedescriptor = 20 + (NldbmBackends * 4) + NglobalIndex +ReplicationDescriptor + ChainingBackendDescriptors + PTADescriptors + SSLDescript

Strona 232

attribute. When viewed from the server console, this attribute shows the value * * * ** . When viewedfrom the dse.ldif file, this attribute shows the

Strona 233

An error is returned by default when object classes that include trailing spaces are added to an entry.Additionally, during operations such as add, mo

Strona 234

Default Value replication-onlySyntax DirectoryStringExample nsslapd-schemareplace: replication-only2.3.1.100. nsslapd-securelistenhostThis attribute a

Strona 235

NOTEA value of -1 on this attribute in dse.ldif file is the same as leaving the attribute blank in theserver console, in that it causes no limit to be

Strona 236

Example nsslapd-threadnumber: 602.3.1.106. nsslapd-timelimit (T ime Limit)This attribute sets the maximum number of seconds allocated for a search req

Strona 237

Syntax DirectoryStringExample nsSSLclientauth: allowed2.3.1.111. passwordAllowChangeT imeThis attribute specifies the length of time that must pass be

Strona 238

3.1.7. Case Exact String Syntax Plug-in3.1.8. Case Ignore String Syntax Plug-in3.1.9. Chaining Database Plug-in3.1.10. Class of Service Plug-in3.1.11.

Strona 239

password expires using the passwordMaxAge attribute.For more information on password policies, see the "Managing Users and Passwords" chapte

Strona 240 - A.1. Overview of ns-slapd

stored passwords. Set the number of old passwords the Directory Server stores using the passwordInHistory attribute.For more information on password p

Strona 241

Entry DN cn=configValid Values on | offDefault Value onSyntax DirectoryStringExample passwordLockout: off2.3.1.124 . passwordLockoutDurat ion (Lockout

Strona 242

Valid Range 0 to 64Default Value 0Syntax IntegerExample passwordMaxRepeats: 12.3.1.128. passwordMin8Bit (Password Synt ax)This sets the minimum numbe

Strona 243

2.3.1.132. PasswordMinDigits (Pa ssword Synta x)This sets the minimum number of digits a password must contain.Parameter Descript ionEntry DN cn=confi

Strona 244 - Glossary

2.3.1.137. PasswordMinUppers (Password Synt ax)This sets the minimum number of uppercase letters password must contain.Parameter Descript ionEntry DN

Strona 245

This is an operational attribute, meaning its value is managed by the server and the attribute is notreturned in default searches.Parameter Descript i

Strona 246 - 24 6 Glossary

Example passwordWarning: 864002.3.1.14 5. retryCountRese t T imeThis attribute specifies the length of time that passes before the passwordRetryCount

Strona 247

2.3.2.2. nsslapd- changelogmaxage (Max Cha ngelog Age )This attribute sets the maximum age of any entry in the changelog. The changelog contains a rec

Strona 248 - 24 8 Glossary

This attribute defines a time, in a YYMMDDHHMMSS format, when the entry was added.OID 2.16.840.1.113730.3.1.77Syntax DirectoryStringMulti- or Single-V

Strona 249

3.6.2. nsslapd-changelogmaxage (Max Changelog Age)3.7. Distributed Numeric Assignment Plug-in Attributes3.7.1. dnaFilter3.7.2. dnaMagicRegen3.7.3. dna

Strona 250 - 250 Glossary

2.3.3.1 . nsSSLSessionTimeoutThis attribute sets the lifetime duration of a TLS/SSL. T he minimum timeout value is 5 seconds. If asmaller value is set

Strona 251

Parameter Descript ionEntry DN cn=encryption, cn=configValid Values For SSLv3: rsa_null_md5 rsa_rc4_128_md5 rsa_rc4_40 _md5 rsa_rc2_40_md5 rsa_des_sha

Strona 252 - 252 Glossary

Windows synchronization agreement attributes are stored under cn=syncAgreementName, cn=replica, cn=suffix,cn=m apping tree,cn=config.2.3.6. Suffix Con

Strona 253

cn=configValid Values 0 | 10 means no changes are logged1 means changes are loggedDefault Value 0Syntax IntegerExample nsDS5Flags: 02.3.7.2. nsds5Debu

Strona 254 - 254 Glossary

Example nsDS5ReplicaBindDN: cn=replication manager,cn=config2.3.7.6. nsDS5ReplicaChangeCountThis read-only attribute shows the total number of entries

Strona 255

This attribute controls the maximum age of deleted entries (tombstone entries) and state information.The Directory Server stores tombstone entries and

Strona 256 - 256 Glossary

cn=configValid Range 0 to maximum 32-bit integer (2147483647) insecondsDefault Value 864 00 (1 day)Syntax IntegerExample nsDS5ReplicaT ombstonePurgeIn

Strona 257

Default ValueSyntax DirectoryStringExample cn: MasterAtoMasterB2.3.8.2. de scriptionFree form text description of the replication agreement. T his att

Strona 258 - 258 Glossary

Default Value 3Syntax IntegerExample nsDS5ReplicaBusyWaitT ime: 32.3.8.6. nsDS5ReplicaChangesSe ntSinceStart upThis read-only attribute shows the numb

Strona 259

Parameter Descript ionEntry DN cn=ReplicationAgreementName, cn=replica,cn=suffixDN, cn=mapping tree, cn=configValid Values YYYYMMDDhhmmssZ is the date

Strona 260 - 260 Index

7.3.16. start-slapd (Starts the Directory Server)7.3.17. stop-slapd (Stops the Directory Server)7.3.18. suffix2instance (Maps a Suffix to a Backend Na

Strona 261

Parameter Descript ionEntry DN cn=ReplicationAgreementName, cn=replica,cn=suffixDN, cn=mapping tree, cn=configValid Values 0 (no replication sessions

Strona 262 - 262 Index

2.3.8.19. nsDS5ReplicaSessionPauseT imeThis attribute sets the amount of time in seconds a supplier should wait between update sessions. T hedefault v

Strona 263

Syntax IntegerExample nsDS5ReplicaT imeout: 6002.3.8.22. nsDS5ReplicaTransportInfoThis attribute sets the type of transport used for transporting data

Strona 264 - 264 Index

Windows Active Directory servers.Table 2.7 . List of Attribute s Sha red Betwee n Replication and Synchronizat ion Agreementscn nsDS5ReplicaLastUpdat

Strona 265

Valid Values on | offDefault ValueSyntax DirectoryStringExample nsDS7NewWinUserSyncEnabled: on2.3.9.5. nsds7WindowsDomainThis attribute sets the name

Strona 266 - 266 Index

This attribute lists open connections. T hese are given in the following format:connection: A:YYYYMMDDhhmmssZ:B:C:D:EFor example:connection: 31:200102

Strona 267

threadsThis attribute shows the number of threads used by the Directory Server. T his should correspond to nsslapd-threadnumber in cn=config.nba ckEnd

Strona 268 - 268 Index

Example nsSaslMapRegexString: \(.*\)2.3.13. cn=SNMPSNMP configuration attributes are stored under cn=SNMP,cn=config. The cn=SNMP entry is aninstance o

Strona 269

Parameter Descript ionEntry DN cn=SNMP, cn=configValid Values machine hostname or localhostDefault Value <blank>Syntax DirectoryStringExample ns

Strona 270 - 270 Index

Table 2.8 . SNMP Statistic Att ributesAttribute Descript ionAnonymousBinds This shows the number of anonymous bindrequests.UnAuthBinds This shows the

Strona 271

About This ReferenceRed Hat Directory Server (Directory Server) is a powerful and scalable distributed directory serverbased on the industry-standard

Strona 272 - 272 Index

2.3.15. cn=tasksSome core Directory Server tasks can be initiated by editing a directory entry using LDAP tools. Thesetask entries are contained in cn

Strona 273

Syntax case-exact stringExample nsTaskStatus: Loading entries...nsT askLogThis entry contains all of the log messages for the task, including both wa

Strona 274 - 274 Index

Parameter Descript ionEntry DN cn=task_name, cn=task_type, cn=tasks,cn=configValid Values 0 to the maximum 32 bit integer value(2147483647)Default Val

Strona 275

nsUniqueIdGenerator, analogous to the -g option to generate unique ID numbers for the entriesnsUniqueIdGeneratorNamespace, analogous to the -G option

Strona 276 - 276 Index

Example nsImportChunkSize: 10nsImport IndexAt trsThis attribute sets whether to index the attributes that are imported into database instance.Paramete

Strona 277

nsExportReplica, analogous to the -r option, to indicate whether the exported database is used inreplicationnsPrintKey, analogous to the -N option, to

Strona 278 - 278 Index

Valid Values true | falseDefault Value falseSyntax Case-insensitive stringExample nsUseOneFile: truensExport Re plicaThis attribute identifies whether

Strona 279

the parameters of the task and initiates the task. As soon as the task is complete, the task entry isremoved from the directory.The cn=backup entry is

Strona 280 - 280 Index

nsArchiveDirThis attribute gives the location of the directory to which to write the backup.Parameter Descript ionEntry DN cn=task_name, cn=restore, c

Strona 281

Syntax Case-insensitive string, multi-valuedExamplensIndexAttribute: "cn:pres,eq"nsIndexAttribute: "description:sub"nsIndexVLVAttr

Strona 282 - 282 Index

Monospace with abackgroundThis type of formatting is used for anything entered or returned in acommand prompt.Italicized text Any text which is italic

Strona 283

Syntax DirectoryStringExample cn: example reload task IDsche madirThis contains the full path to the directory containing the custom schema file.Param

Strona 284 - 284 Index

The unique ID generator configuration attributes are stored under cn=uniqueid generator,cn=config. T he cn=uniqueid generator entry is an instance of

Strona 285

topOID2.16.840.1.113730.3.2.40Required Attribute sAttribute Definit ionobjectClass Gives the object classes assigned to the entry.Allowed At tributesA

Strona 286 - 286 Index

2.16.840.1.113730.3.2.104Required Attribute sAttribute Definit ionobjectClass Defines the object classes for the entry.cn Gives the common name of the

Strona 287

Superior ClasstopOID2.16.840.1.113730.3.2.103Required Attribute sobjectClass Defines the object classes for the entry.cn Used for naming the replicati

Strona 288 - 288 Index

attributes for this object class are in chapter 2 of the Red Hat Directory Server Configuration, Command,and File Reference.This object class is defin

Strona 289

(RUV).nsds7DirectoryReplicaSubtree Specifies the Directory Server suffix (root or sub)that is synced.nsds7DirsyncCookie Contains a cookie set by the s

Strona 290 - 290 Index

This object class is defined in Directory Server.Superior ClasstopOID2.16.840.1.113730.3.2.39Required Attribute sAttribute Definit ionobjectClass Give

Strona 291

in after the lockout period.passwordLockoutDuration Sets the time, in seconds, that users will belocked out of the directory.passwordCheckSyntax Ident

Strona 292 - 292 Index

cn Specifies the common name of the entry.Allowed At tributesAttribute Definit iondescription Gives a text description of the entry.l (localityName) G

Komentarze do niniejszej Instrukcji

Brak uwag