INDEX
Symbols
#, in slapd.conf 309-, in change operation 206
::, in LDIF statements 36
\, in parameter values 309
"", in ldapmodify commands 194
'', in ldapsearch 177
A
abstract attribute 416access control
ACI attribute 82
ACI language syntax 117
ACI name 95
allowing or denying access 85
anonymous access 88, 106
bind rules 87
access at specific time or day 91
access based on attribute value 90
access based on authentication method 92
access from a specific location 91
Boolean 92
general access 88
user and group access 88
change log and 248
defining
with LDIF files 116-137
with Server Manager 93-116
dynamic targets 89
overview 81
password protection and 144
permissions 85
rights 86
target DN containing comma and 119, 137
targeting 82
attributes 83
entries 83
using LDAP search filters 84
using LDIF 118
using Server Manager 95
Access Control Overview form 93
Access Control Rules form 94
access log
turning off 216
viewing 216
Access Log parameter
description and syntax 318
disabling 216
viewing and changing 233
access-control information (ACI) instruction, See ACI instruction
access-control list (ACL)
glossary entry 513
overview 81
account lockout 143, 335
lockout duration 143, 337
maximum password failures 336
password failure counter 144, 336
unlocking account 337
Account Lockout parameter 146, 335
account object class 399
accountUnlockTime attribute 416
ACI attribute
default index for 159
overview 82
ACI instruction
bind rules 87
creating
using LDIF 116
using Server Manager 103
deleting 98, 105
editing 105
name 95, 117
password protection and 144
permissions 85
target DN containing comma and 119, 137
targets 82
ACI language syntax 117-130
ACL, See access-control list
aclupg utility, location of 29
Add rights 86
Administration Server 70
base DN 72
functions of 23
master agents and 296
SuiteSpot integration and 70
administratorContactInfo attribute 417
adminUrl attribute 417
agents
master agent 296
Unix 296
Windows NT 296
subagent 296
configuring 303
enabling 306
starting and stopping 306
AIX SNMP daemon 305
algorithms
consumer-initiated replication 271
metaphone phonetic algorithm 154
searching 152-153
supplier-initiated replication 270
alias dereferencing 181
alias object class 399
aliasedObjectName attribute 417
allowed attributes
creating 52
deleting 52
viewing 53
allowing access 85
using LDIF 122
using Server Manager 96
altServer attribute 417
anonymous access
change log restrictions on 248
defining 132
LDIF example 132
overview 88
Server Manager example 106
applet, Replication Settings 249
applicationEntity object class 400
applicationProcess object class 400
approximate index
CPU cycles and 158
overview 154
query string codes 155
when to use 159
approximate search 174
associatedDomain attribute 417
associatedName attribute 418
attribute list, glossary entry 513
attribute parameter 329
Attribute to be Indexed parameter 159, 347
attribute type field (LDIF) 34
attribute value field (LDIF) 35
attribute values
access based on 90
adding 210
deleting 212
modifying 213
replacing 210
syntax 55
attributes
ACI 82
adding 210, 212
creating 52
defining 55
deleting
multiple 211
using LDIF update statements 211
deleting from object class 52, 57
for integrity updates 77
glossary entry 513
indexing existing 164
ntGroupCreateNewAccount attribute 283
ntGroupDomainId 282
ntUserCreateNewAccount 283
ntUserDomainId 282
OID 55
reference 415-489
searching for 173
standard 49, 55
syntax 55
targeting 83
user-defined 55
values
adding 212
deleting 212
modifying 213
replacing 210
See also individual attribute names
attributeTypes attribute 418
audio attribute 418
Audit Log parameter
description and syntax 317
viewing and changing 233
authentication 239
access control and 92
certificate-based 241
glossary entry 513
LDAP URLs and 496
replication and 246
authentication certificates glossary entry 513
authmethod keyword 129
authorCn attribute 418
authorityRevocationList attribute 418
authorityRevocationList;binary attribute 418
authorSn attribute 418
B
backing up the database 66backslash, in parameter values 309
base 64 encoding 36
base DN, ldapsearch and 183
binary data, LDIF and 36
bind failures, account lockout and 144
bind rules
access at specific time or day 91
LDIF example 136
Server Manager example 112
access based on attribute value
example 127
overview 90
access based on authentication method 92
LDIF example 130
Server Manager example 113
access from a specific location 91
LDIF example 136
Server Manager example 113
ACI language syntax 118
anonymous access 88
LDIF example 125
Server Manager example 106
Boolean
example 130
overview 92
general access
example 125
overview 88
group access 90
LDIF example 126
Server Manager example 109
LDAP URLs 89
LDIF keywords for 123
overview 87
syntax 87
user access 89
LDIF example 125
parent 89
self 90
Server Manager example 108
Bind to Server field 27, 200
bindDN
directory tree access and 27
glossary entry 513
Boolean bind rules
example 130
overview 92
Boolean operators, in search filters 175
browser glossary entry 513
buildingName attribute 419
businessCategory attribute 419
C
c attribute 419cACertificate attribute 419
cACertificate;binary attribute 419
cache
specifying maximum entries 346
specifying size in bytes 346
cache hit ratio 225
cacheObject object class 401
carLicense attribute 420
certificate
mapping to a DN 241
password 26
Certificate and Key Directory parameter 328
certificate database
client vs. server 242
password 241
certificate-based authentication 241
key-pair filename 242
replication and 241
certificateRevocationList attribute 420
certificateRevocationList;binary attribute 420
certification authority glossary entry 514
certificationAuthority object class 401
CGI glossary entry 514
change log
access control and 248
configuring 247
consumer access to 248
expiration of entries 67
synchronization and 271
change operations 206
add 210
delete 211
replace 210
changeLog attribute 420
Changelog DB Directory parameter 326
Changelog DB Suffix parameter 327
changeLogEntry object class 387
changeLogMaximumAge attribute 420
changeLogMaximumSize attribute 420
changeNumber attribute 421
changes attribute 421
changeTime attribute 421
changeType attribute 421
changetypes
add 206
delete 208
modify 210
character type 498
Check Password Syntax parameter 145, 335
checking password syntax 142
checking the database schema 50
checkpoint interval 348
ciphers
described 239
list of 240, 316
selecting 239
ciphertext glossary entry 514
cirBeginORC attribute 421
cirBindCredentials attribute 421
cirBindDn attribute 422
cirHost attribute 422
cirLastUpdateApplied attribute 422
cirPort attribute 422
cirReplicaRoot attribute 422
cirReplicaSource object class 355
cirSyncInterval attribute 422
cirUpdateFailedat attribute 422
cirUpdateSchedule attribute 423
cirUsePersistentSearch attribute 423
cirUseSsl attribute 423
client
glossary entry 514
using to find entries 171
client authentication, replication and 252, 255
cn attribute 423
co attribute 424
code page 497
collation order
overview 498
search filters and 185
command line
monitoring database from 228
monitoring server from 222
providing input from 194
command-line utilities
certificate-based authentication and 241
db2ldif 64
ldapdelete 195
ldapmodify 194, 199, 200, 322
ldapsearch 172-184
ldif 36
ldif2index 164
ldif2ldbm 61, 62
location of 29
PATH variable and 30
start 26
stop 26
table of 28
commas, in DNs 177, 194
ACI targets and 119, 137
specifying LDIF entries with 39, 41
specifying suffix with 38, 39, 44
using ldapsearch with 184
commonName attribute 423
Compare rights 86
configuration files
location of 31
slapd.conf 30
slapd.dynamic_ldbm.conf 30, 162, 165
configuration parameters 307-350
changing
using Server Manager 308
using slapd.conf 309
connections
monitoring 221, 222, 224
viewing number of 219
consistency updates 74
consumer server
adding
for consumer initiated replication 254
for supplier-initiated replication 251
certificate database and 241
glossary entry 514
identifying 251
initializing 251, 253
consumer-initiated replication
change log access 248
creating replication agreements 253, 254
identifying suppliers 255
initializing consumers 253
overview 244
replication activity log 256
replication algorithm 271
Replication Settings applet 249
scheduling 256
subtree only 254
using SSL 255
continued lines
in LDIF 35
in LDIF update statements 206
conventions, in this book 21
converting database to LDIF
from the command line 64
using Server Manager 63
copiedFrom attribute 270, 271
counter, password failures 144
country code 499
country object class 359
countryName attribute 419
CPU cycles, index files and 158
createTimestamp attribute 424
creating the directory 43
creatorsName attribute 424
crossCertificatePair attribute 424
crossCertificatePair;binary attribute 424
crypt encryption 144, 328
D
daemonglossary entry 514
dash, in change operation 206
database
backing up 66
controlling access 81-137
converting to LDIF
from the command line 64
using Server Manager 63
costs of indexing 156
creating using LDIF 43
extending the schema 56
integrity update interval 76
maintaining relationships 74
managing with LDIF 60-65
referential integrity 74
restoring 66, 78
restoring with replicated entries 67
schema checking 50
selecting for monitoring 224
updating 156, 205
viewing backend information 224
database backups
creating 66
deleting 67
location of files 66
overview 65
Database Checkpoint Interval parameter 79, 348
Database Durable Transactions parameter 80, 349
database files, directory for 344
database parameter 348
database schema
checking 50
creating new attributes 55
creating new object classes 51
defined 322
deleting attributes 57
deleting object classes 57
editing object classes 54
extending 56
standard 49
viewing object classes 52
database server parameters 341-350
Attribute to be Indexed 159, 347
database 348
Database Checkpoint Interval 79, 348
Database Durable Transactions 80, 349
Database Transaction Log Directory 78, 349
DB Directory 344
dynamicconf 30, 350
Maximum DB Cache size in bytes 232, 346
Maximum Entries in Cache 232, 346
mode 348
Read-only 225, 345
Root DN 344
Root Password 230, 344
Root Password Storage Scheme 345
Suffix 69, 342
table of 341
Database Transaction Log directory parameter 78, 349
database transaction logging
checkpoint interval 79
described 78
durable transactions 80
log file location 78
date format 498
dayofweek keyword 129
DB Directory parameter 344
db2ldif utility
example of use 64
exporting LDIF with 64
parameters 64
dc attribute 425
dcObject object class 402
debug level, specifying 62, 64, 323
default indexes 159
defining
attributes 55
object classes 51
Delete rights 86
deleteOldRdn attribute 425
deleting
ACI instructions 98, 105
attribute values 212
attributes 210, 211
attributes from an object class 52, 57
database backups 67
entries 208
database integrity and 74
synchronization and 283
LDIF files 65
multiple attributes 211
object classes 53, 57
replication agreements 250, 253
deltaRevocationList;binary attribute 425
denying access 85
precedence rule 85
using LDIF 122
using Server Manager 96
departmentNumber attribute 425
DES cipher 240
description attribute 425
destinationIndicator attribute 426
device object class 403
directory creation 43
directory server
integration with SuiteSpot 70
international character sets 497
internationalization and 497
MIB 298
monitoring 218-224
from command line 222
from Server Manager 218
monitoring database
from command line 228
SNMP traps 297
starting and stopping 25
supported languages 499
Directory Server Entry (DSE), searching 182
Directory Server gateway
glossary entry 514
schema checking and 322
directory server manager, capabilities of 28
directory service glossary entry 514
directory trees
finding entries in 177
machine data 272
mapping to URLs 275
disk space
access log and 216
index files and 158
log files and 217
distinguished names
for replication 325
glossary entry 514
root 344
specifying local database suffix 342
synchronization and 287
dITContentRules attribute 426
ditRedirect attribute 426
dITStructureRules attribute 426
dn attribute 426
dn field (LDIF) 34
dn.dbb file 160
dn2id.dbb file 160
dnQualifier attribute 427
DNS alias glossary entry 514
dns keyword 128
DNSDomain object class 403
dNSRecord attribute 427
document object class 404
documentAuthor attribute 427
documentIdentifier attribute 427
documentLocation attribute 427
documentPublisher attribute 427
documentSeries object class 405
documentStore attribute 427
documentTitle attribute 428
documentVersion attribute 428
Domain Name System (DNS) glossary entry 514
domain object class 406
domain, access from specific 91
domainComponent attribute 425
domainRelatedObject object class 407
drink attribute 428
dSA object class 408
dSAQuality attribute 428
DSE See Directory Server Entry
durable transactions 80, 349
dynamic parameter changes 30, 350
dynamically creating indexes 162
dynamicconf parameter 30, 350
E
employeeNumber attribute 428employeeType attribute 428
enabling NT synchronization service 338
Encrypted Port Number parameter
description and syntax 317
viewing and changing 232
encryption
crypt 144
password 144, 148
replication and 251, 255
root password 344, 345
SHA 144
specifying password storage scheme 328
Encryption Alias parameter 329
Encryption Ciphers parameter 316
Encryption Enabled parameter 315
encryption method, for root password 344, 345
end of file marker 194
enhancedSearchGuide attribute 429
entries
adding 199
using LDIF update statements 206
using Server Manager 200
administrator 72
cache hit ratio 225
creating
for SuiteSpot integration 72
synchronization and 279, 282
using LDIF 37-43
deleting 195-198
synchronization and 283
using ldapdelete 195
using LDIF update statements 208
finding 177
maintaining relationships 74
mapping to URLs 275
modifying 200-214
synchronization and 283
using ldapmodify 200
using LDIF update statements 210
moving 210
order of creation 199
order of deletion 195, 208
renaming 210
root 43
targeting 83
working with 193-214
entry cache hit ratio 225
environment variables
LDAP_BASEDN 183
overview 30
EOF marker 194
equality index 154
equality search 173
example 176
international example 190
error log
specifying 318
viewing 216
Error Log parameter
description and syntax 318
viewing and changing 233
expiration of passwords
overview 140
slapd.conf parameter 332
warning message 141
extending the directory schema 56
F
facsimileTelephoneNumber attribute 429favouriteDrink attribute 428
file extension glossary entry 514
file type glossary entry 515
files
access log 216
containing search filters 180
database backup 66
dn.dbb 160
dn2id.dbb 160
EOF marker 194
error log 216
id2children.dbb 160
id2entry.dbb 160
locating configuration 31
slapd.conf 30, 61, 309-310, 344
slapd.dynamic_ldbm.conf 30, 162, 165
filterInfo attribute 429
finding
attributes 173
entries 177
supported suffixes 182
fonts, in this book 21
format, LDIF 34
forms
Access Control Overview 93
Access Control Rules 94
LDAP 147
Manager Preferences 231
Monitor Current Activity 218
Network 216
Password Policy 145
Performance Tuning 231
SNMP Subagent Configuration 303
SuiteSpot 3.0 Settings 73
friendlyCountry object class 408
friendlyCountryName attribute 424
G
general accessexample 125
overview 88
general server parameters 311-339, ??-339, ??-340
Access Log 216, 233, 318
Account Lockout 146, 335
attribute 329
Audit Log 233, 317
Certificate and Key Directory 328
Changelog DB Directory 326
Changelog DB Suffix 327
Check Password Syntax 145, 335
Encrypted Port Number 232, 317
Encryption Alias 329
Encryption Ciphers 316
Encryption Enabled 315
Error Log 233, 318
Lockout Duration 147, 337
Log Level 233, 323
Look Through Limit 231, 321
Max Changelog Age 327
Max Changelog Records 327
Maximum Password Failures 146, 336
maxthreadsperconn 331
NLS 332
NT Synchronization Service Enabled 232, 338
NT Synchronization Service Port Number 233, 338, 340
Number of Passwords to Remember 146, 334
objectClass 330
orcauto 339
order of precedence 309
Password Change 145, 334
Password Expiration 145, 332
Password History 146, 333
Password Maximum Age 145, 332
Password Minimum Length 145, 333
Password Storage Scheme 148, 328
Port Number 232, 315
Referral 233, 274, 324
Reset Password Failure Count After 147, 336
Schema Check 50, 234, 322
Send Warning 146, 335
Size Limit 231, 319
Supplier DN 246, 325
Supplier Password 325
Supplier SSL Clients 247, 325
threadnumber 331
Time Limit 231, 319
Track Modifies 233, 322
Unlock Account 147, 337
generation attribute 429
generationQualifier attribute 429
givenName attribute 429
glossary of terms 513-518
glue object class 356
greater than or equal to search
international example 190, 191
overview 174
groupdn keyword 126
groupOfCertificates object class 388
groupOfMailEnhancedUniqueNames object class 394
groupOfNames object class 352
groupOfUniqueNames object class 353
groups
access control and 88
LDIF example 126
Server Manager example 109
access to directory 90
creating
SuiteSpot integration and 72
synchronization and 282
permissions for 134
H
homePhone attribute 430homePostalAddress attribute 430
homeTelephoneNumber attribute 430
host attribute 430
hostnames glossary entry 515
houseIdentifier attribute 430
HTML glossary entry 515
HTTP glossary entry 515
HTTPD glossary entry 515
HTTP-NG glossary entry 515
HTTPS glossary entry 515
I
id field (LDIF) 34id2children.dbb file 160
id2entry.dbb file 160
illegal strings, passwords 142
importing LDIF
from the command line 61
using Server Manager 60
index files
defaults maintained by directory server 160
directory for 344
specifying cache size 346
index parameter
dynamic changes to 30
slapd.dynamic_ldbm.conf and 162
indexes
approximate 154, 158, 159
cost of 156-158
creating 159
dynamically 162
from Server Manager 161
from slapd.conf 162
defaults maintained by directory server 159
dynamic changes to 162
equality 154
of existing attributes 164
international 165
managing 151-164
presence 153, 159
specifying type 347
substring 155, 158, 159
system resources and 158
types of 153
inetOrgPerson object class 364
info attribute 431
initializing consumer servers 251, 253
initials attribute 431
integrating with SuiteSpot 70
interaction table 302
international character sets 497
international searches 185-191
equality 190
examples 189
greater than 191
greater than or equal to 190
less than 189
less than or equal to 190
matching rule filter syntax 186
substring 191
using OIDs 187
internationalIsdnNumber attribute 431
internationalization
character type 498
collation order 498
country code 499
date format 498
indexing and 165
language tag 499
locales and 497
location of files 332, 499
matching rule filters 186
modifying entries 214
monetary format 498
numeric format 498
object identifiers and 499
of LDIF files 46
search filters and 185
supported languages 497
supported locales 499
time format 498
IP address glossary entry 515
ip keyword 127
J
janetMailbox attribute 431jpeg images 36
jpegPhoto attribute 431
K
keyWords attribute 432knowledgeInformation attribute 432
L
l attribute 432labeledUri attribute 432
labeledURIObject object class 408
language code
in LDIF entries 46
list of supported 500
language support 497
language tag 499
searching and 185
specifying using locales 499
language tags
described 499
in international searches 188
in LDIF update statements 214
lastModifiedBy attribute 432
lastModifiedTime attribute 433
LD_LIBRARY_PATH variable 30
LDAP clients
certificate-based authentication and 241
database schema and 49
glossary entry 515
monitoring database with 228
monitoring server with 222
using to find entries 171
LDAP Data Interchange Format (LDIF)
access control keywords
authmethod 129
dayofweek 129
dns 128
groupdn 126
ip 127
target 119
targetattr 120
targetfilter 122
timeofday 128
userdn 124
userdnattr 127
ACI language syntax and 117
binary data 36
converting to
from the command line 64
using Server Manager 63
deleting files 65
entry format 34
Organization 37
Organizational Person 41
Organizational Unit 39
example 45
glossary entry 515
importing
Maximum DB Cache size in Bytes parameter and 232
with ldif2ldbm 61
with Server Manager 60
internationalization and 46
line continuation 35
managing databases 60-65
reasons for converting to 62
Server Manager and 200
update statements 205
using to create directory 43
LDAP form 147
LDAP search filters
DNs with commas and 184
in targets 84
examples 114, 122
LDAP URLs
access control and 89
components of 492
described 491-496
examples 495
security and 496
syntax 492
LDAP_BASEDN environment variable 183
ldapdelete utility
deleting entries 195
DNs with commas and 194
example of use 198
parameters 196
ldapmodify utility 322
creating multiple entries 199
DNs with commas and 194
example of use 204
location of 29
modifying entries 200
parameters 201
schema checking and 200
smart referrals and 275
using with internationalized entries 214
vs. ldapdelete 200
LDAPReplica object class 272, 357
ldapsearch utility
base DN and 183
DNs with commas and 177, 184
example of use 182
format 177
international searches 185
limiting attributes returned 183
parameters
commonly used 178
optional 180
SSL 179
search filters 172
specifying files 183
using 177
verbose mode 181
LDAPServer object class 272, 356
ldapSyntaxes attribute 433
LDIF entries
binary data in 36
commas in 39, 41, 44
creating 37-46
Organizational People 41
Organizational Units 39
Organizations 37
internationalization and 46
LDIF files
continued lines 35
creating directory using 43
creating multiple entries 199
database management and 60
deleting 65
example 45
importing
from the command line 61
using Server Manager 60
importing from Server Manager 200
internationalization and 46
setting access controls 116-137
LDIF format 34
LDIF update statements 205-214
adding attributes 212
adding entries 206
continued lines 206
deleting attribute values 212
deleting attributes 211
deleting entries 208
format of 205
functions of 205
modifying attribute values 213
modifying entries 210
ldif utility
converting binary data to LDIF 36
location of 29
ldif2index utility
indexing existing attributes 164
location of 29
ldif2ldbm utility
example of use 62
importing LDIF with 61
location of 29
parameters 62
length, password 142, 333
less than or equal to search
international example 190
syntax 174
less than search
international example 189
syntax 174
Lightweight Directory Access Protocol (LDAP)
glossary entry 515
managing settings 233
locales
defined 497
location of files 499
supported 499
locality object class 360
localityName attribute 432
locked accounts 143
lockout duration 143
Lockout Duration parameter 147, 337
log files
access 318
change 271
database transaction 78
error 318
location of 217
monitoring 216-217
replication activity 253, 256
rotating 217
Security Accounts Manager (SAM) 278
synchronization service event log 286
Log Level parameter
description and syntax 323
viewing and changing 233
Look Through Limit parameter
description and syntax 321
role in searching algorithm 152
viewing and changing 231
M
machine data 272machine, access from specific 91
mail accounts
creating automatically 290
synchronizing 290
mail attribute 433, 434, 435, 436, 437, 438, 439, 440, 441, 442
mailGroup object class 396
mailPreferenceOption attribute 436
mailRecipient object class 395
mailRoutingAddress attribute 437
managed device
managed device-initiated communication 297
overview 295
managed object 296
management information base, See MIB
manager attribute 437
Manager Preferences form 231
manual synchronization with NT 289
master agent
hostname 303
overview 296
Unix 296
Windows NT 296
master host 303
matchingRule format 187
using language tag 188
using language tag and suffix 188
using OID 187
using OID and suffix 188
matchingRules attribute 437
matchingRuleUse attribute 437
Max Changelog Age parameter 327
Max Changelog Records parameter 327
Maximum DB Cache size in bytes parameter
description and syntax 346
viewing and changing 232
Maximum Entries in Cache parameter
description and syntax 346
viewing and changing 232
Maximum Password Failures parameter
description and syntax 146, 336
maxthreadsperconn parameter 331
MD5 message authentication 240
glossary entry 516
signature 516
MD5 signature glossary entry 516
member attribute 438
memberCertificateDescription attribute 438
memberURL attribute 438
memory
controlling amount used 158
index files and 158
Maximum DB Cache size in Bytes parameter and 232
messaging server, creating accounts automatically 290
metaphone phonetic algorithm 154
mgrpDeliverTo attribute 439
mgrpPassword attribute 442
MIB
directory server 298
location of 298
netscape-ldap.mib 298
entries table 301
interaction table 302
operations table 299
overview 296
minimum length of passwords 142
minimum password length 333
mobile attribute 443
mobileTelephoneNumber attribute 443
mode parameter 348
modifiersName attribute 443
modifying
attribute values 213
entries 210
international entries 214
modifyTimestamp attribute 443
monetary format 498
Monitor Current Activity form 218
moving entries 210
multiLineDescription attribute 443
multiple indexes, cost of 156
multiple search filters 175
N
nameForms attribute 444namingContexts attribute 444
Netscape MIBs 298
Netscape NT Directory Synchronization service 278
Netscape Servers OU 72
netscapeCalAdmin object class 374
netscapeCalendarServer object class 374
netscapeCalResource object class 376
netscapeCalUserr object class 378
netscapeCertificateServer object class 380
netscapeCompassServer object class 382
netscapeDirectoryServer object class 389
netscape-ldap.mib 298
entries table 301
interaction table 302
location of 298
operations table 299
netscapeMachineData object class 389
netscapeMailServer object class 397
netscapeMediaServer object class 393
netscapeNewsServer object class 380
netscapeProxyServer object class 398
netscapeReplicaState attribute 444
netscapeServer object class 390
netscapeWebServer object class 398
Network form 216
network management station (NMS)
NMS-initiated communication 297
overview 295
network settings, viewing and changing 232
new attributes, creating 55
newPilotPerson object class 365
newRdn attribute 444
newSuperior attribute 444
nginfo object class 381
NIS
glossary entry 516
NLS parameter 332
NMS, See network management station
nsCalAccess attribute 445
nsCalAccessDomain attribute 446
nsCalAdmd attribute 446
nsCalDefaultNoteReminder attribute 446
nsCalDefaultReminder attribute 447
nsCalDefaultTaskReminder attribute 447
nsCalDisplayPrefs attribute 447
nsCalFlags attribute 448
nsCalHost attribute 448
nsCalLanguageId attribute 448
nsCalNodeAlias attribute 448
nsCalNotifMechanism attribute 448
nsCalOperatingPrefs attribute 449
nsCalOrgUnit2 attribute 449
nsCalOrgUnit3 attribute 449
nsCalOrgUnit4 attribute 449
nsCalPasswordRequired attribute 449
nsCalPrmd attribute 450
nsCalRefreshPrefs attribute 450
nsCalResourceCapacity attribute 450
nsCalResourceNumber attribute 450
nsCalServerVersion attribute 451
nsCalSysopCanWritePassword attribute 451
nsCalTimezone attribute 451
nsCalXItemId attribute 451
nsLicensedFor attribute 452
nsLicenseUser object class 366
ns-slapd
glossary entry 516
location of 29
NT Synchronization Service Enabled parameter
description and syntax 338
viewing and changing 232
NT Synchronization Service Port Number parameter
description and syntax 338, 340
viewing and changing 233
NTGroup object class 280, 354
ntGroupAttributes attribute 453
ntGroupCreateNewAccount 283
ntGroupCreateNewGroup attribute 453
ntGroupDeleteGroup attribute 454
ntGroupDomainId attribute 282, 454
ntGroupId attribute 454
ntGroupType attribute 454
NTUser object class 279
ntUserAcctExpires attribute 454
ntUserAuthFlags attribute 454
ntUserBadPwCount attribute 454
ntUserCodePage attribute 455
ntUserComment attribute 455
ntUserCountryCode attribute 455
ntUserCreateNewAccount attribute 283, 455
ntUserDeleteAccount attribute 455
ntUserDomainId attribute 282, 456
ntUserFlags attribute 456
ntUserHomeDir attribute 456
ntUserHomeDirDrive attribute 456
ntUserLastLogoff attribute 456
ntUserLastLogon attribute 457
ntUserLogonHours attribute 457
ntUserLogonServer attribute 457
ntUserMaxStorage attribute 458
ntUserParms attribute 458
ntUserPasswordExpired attribute 458
ntUserPrimaryGroupId attribute 458
ntUserPriv attribute 458
ntUserProfile attribute 459
ntUserScriptPath attribute 459
ntUserUniqueId attribute 459
ntUserUnitsPerWeek attribute 459
ntUserUsrComment attribute 459
ntUserWorkstations attribute 459
Number of Passwords to Remember parameter 146, 334
numeric format 498
O
o attribute 460object class
creating 51
deleting 53, 57
editing 54
glossary entry 516
name 51
OID 51
parent object 51
reference 351-413
standard 49
viewing 52
object identifier (OID) 499
attribute 55
in matchingRule 187
object class 51
objectClass attribute 460
objectClass field (LDIF) 34
objectClass parameter 330
objectClasses attribute 460
obsoletedByDocument attribute 460
obsoletesDocument attribute 460
OID, See object identifier
operating system environment variables 30
operations table 299
operations, defined 219
operators
Boolean 175
international searches and 185
search filters and 173
suffix 186
optional attributes
creating 52
deleting 52
viewing 53
orcauto parameter 339
organization object class 360
organization, specifying entries for 37
organizational person, specifying entries for 41
organizational unit, specifying entries for 39
organizationalPerson object class 369
organizationalRole object class 370
organizationalStatus attribute 460
organizationalUnit object class 362
organizationalUnitName attribute 461
organizationName attribute 460
otherMailbox attribute 461
ou attribute 461
owner attribute 461
P
pager attribute 461pagerTelephoneNumber attribute 461
parent access 89
parent object 51
Password Change parameter 145, 334
password encryption, types of 328
Password Expiration parameter 145, 332
password file 26
glossary entry 516
Password History parameter 146, 333
Password Maximum Age parameter 145, 332
Password Minimum Length parameter 145, 333
password policies
account lockout 143
change after reset 143
expiration warning 141
lockout duration 143
managing 139-149
modifying 149
overview 139-144
password expiration 140
password failure counter 144
password history 141
password length 142
password storage scheme 148
overview 144
setting up 148
syntax checking 142
user defined passwords 142
Password Policy form 145
password storage scheme
configuring 148
overview 148
Password Storage Scheme parameter
configuring 148
description and syntax 328
passwordChange attribute 462
passwordCheckSyntax attribute 462
passwordExp attribute 462
passwordExpirationTime attribute 462
passwordExpWarned attribute 462
passwordHistory attribute 463
passwordInHistory attribute 463
passwordKeepHistory attribute 463
passwordLockout attribute 463
passwordLockoutDuration attribute 464
passwordMaxAge attribute 464
passwordMaxFailure attribute 464
passwordMinLength attribute 464
passwordObject object class 390
passwordPolicy object class 391
passwordResetDuration attribute 464
passwordRetryCount attribute 465
passwords
account lockout 143
certificate 26
changing after reset 143
encryption of 144, 148
encryption types 328
expiration 140, 332
expiration warning 141, 335
failure counter 144
history 141
illegal strings 142
lockout duration 143
managing 139-149
maximum age 332
minimum length 142, 333
modifying preferences 149
resetting 149
reusing 141, 333
root 344
root DN 230
setting 149
setting preferences for 148
supplier 325
synchronizing changes with NT 279
syntax checking 142, 335
user defined 142
passwordUnlock attribute 465
passwordWarning attribute 465
PATH variable 30
PDUs 296
performance tuning 231
Performance Tuning form 231
permissions
ACI language syntax 117
allowing or denying access 85
using LDIF 122
using Server Manager 96
assigning rights 86
using LDIF 122
using Server Manager 97
defining
for all users 131
for group of users 134
for single user 132
overview 85
precedence rule 85
specifying for index files 348
person object class 372
personalInterestProfile object class 382
personalSignature attribute 465
personalTitle attribute 466
photo attribute 466
physicalDeliveryOfficeName attribute 466
pilotObject object class 409
pilotOrganization object class 410
pipcompassservers attribute 466
pipformat attribute 466
pipfrequency attribute 466
pipgroup attribute 467
piphour attribute 467
pipirlist attribute 467
pipiroption attribute 467
piplastcount attribute 468
pipmaxhits attribute 468
pipmedium attribute 468
pipnotify attribute 468
pipprivilege attribute 468
pippwp attribute 468
pipreservedces1 attribute 469
pipreservedces2 attribute 469
pipreservedces3 attribute 469
pipreservedcis1 attribute 469
pipreservedcis2 attribute 469
pipreservedcis3 attribute 469
pipreservedcis4 attribute 470
pipreservedcis5 attribute 470
pipreservedcis6 attribute 470
pipresultset attribute 470
pipsortorder attribute 470
pipstatus attribute 470
pipstcategory attribute 471
pipstformat attribute 471
pipstfrequency attribute 471
pipsthour attribute 471
pipstid attribute 471
pipstinterest attribute 472
pipstirlist attribute 472
pipstiroption attribute 472
pipstlastcount attribute 472
pipstmaxhits attribute 472
pipstmedium attribute 473
pipstname attribute 473
pipstprivacy attribute 473
pipstquery attribute 473
pipstresultset attribute 473
pipstsortorder attribute 474
pipststatus attribute 474
pipsttaxonomy attribute 474
pipsttimestamp attribute 474
pipsttotalcount attribute 474
pipsttotalrun attribute 474
pipsttype attribute 475
piptimestamp attribute 475
piptotalcount attribute 475
piptotalrun attribute 475
pipuid attribute 467, 475
pipuniqueid attribute 476
PIPUser object class 386
PIPUserInfo object class 386
pipusertype attribute 476
Port Number parameter
description and syntax 315
viewing and changing 232
port numbers
less than 1024 315
NT synchronization service 338, 340
synchronization service 286
postalAddress attribute 476, 483
postalCode attribute 476
postOfficeBox attribute 477
pound symbol, in slapd.conf 309
precedence rule 85
preferences, security 239
preferredDeliveryMethod attribute 477
preferredLanguage attribute 477
presence index
defaults 159
overview 153
presence search
example 176
syntax 174
presentationAddress attribute 477
protocol data units, See PDUs
protocol glossary entry 516
protocolInformation attribute 477
public-key encryption glossary entry 516
Q
quotation marks, in parameter values 177, 194, 309R
RAM glossary entry 516rc.local
glossary entry 516
RC2 cipher 240
RC4 cipher 240
Read rights 86
read-only mode 225
Read-only parameter 225, 345
reciprocalNamingLink attribute 477
redirection 274
ref attribute 275, 477
referential integrity
described 74
disabling 75
specifying attributes to update 77
update interval 76
referral object class 275, 392, 393
Referral parameter 274
description and syntax 324
role in searching algorithm 152
Suffix parameter and 342
viewing and changing 233
referrals
example 275
ldapsearch parameter 181
number of hops 181
overview 274
smart 275
URLs 274
registeredAddress attribute 478
relative distinguished name glossary entry 516
renaming entries
database integrity and 74
restrictions 210
replacing attribute values 210
replicaAbandonedChanges attribute 478
replicaBeginOrc attribute 478
replicaBindDn attribute 478
replicaBindMethod attribute 479
replicaCFUpdated attribute 479
replicaCredentials attribute 479
replicaEntryFilter attribute 479
replicaHost attribute 479
replicaNickName attribute 480
replicaPort attribute 480
replicaRoot attribute 480
replicated entries, restoring database with 67
replicatedAttributeList attribute 480
replication
activity log 253, 256
agreements 244
configuring server for 244-249
consumer initiated 244
glossary entry 516
over SSL 246
overview 243
Replication Settings applet 249
restoring database 67
scheduling
consumer-initiated 256
supplier-initiated 253
SSL and 251, 255
subtree 250, 254
Supplier DN parameter 325
supplier-initiated 244
replication activity log
consumer-initiated 256
supplier-initiated 253
replication agreements
adding a consumer 251, 254
consumer identification 251
creating 249-256
consumer-initiated 253, 254
supplier-initiated 250
deleting 250, 253
overview 244
Replication Editor 250, 253
supplier identification 255
Replication Editor 250, 253
Replication Settings applet 249
replicaUpdateFailedAt attribute 480
replicaUpdateReplayed attribute 481
replicaUpdateSchedule attribute 481
replicaUseSSL attribute 481
required attributes
creating 52
deleting 52
viewing 53
Reset Password Failure Count After parameter 147, 336
resetting passwords 149
residentialPerson object class 372
resource use, monitoring 220-221
restoring the database 66, 78
retryCountResetTime attribute 481
reusing passwords 141, 333
RFC glossary entry 516
RFC822LocalPart object class 411
rights
list of 86
setting
using LDIF 122
using Server Manager 97
roleOccupant attribute 482
room object class 412
roomNumber attribute 482
root
glossary entry 517
Root DN parameter
default permissions and 85
description and syntax 344
Suffix parameter and 69
root DN password
managing 230
using default 27
root entry creation 43
Root Password parameter 230, 344
Root Password Storage Scheme parameter 345
root password, root DN and 344
rotating log files 217
S
SASL, See Simple Authentication and Security Layerscheduling
consumer-initiated replication 256
NT synchronization service 288
supplier-initiated replication 253
schema
checking 50
creating new attributes 55
creating new object classes 51
deleting attributes 57
deleting object classes 57
editing object classes 54
extending 56
glossary entry 517
searching 182
standard 49
targets and 83
viewing object classes 52
Schema Check parameter
description and syntax 322
turning schema checking on or off 50
viewing and changing 234
schema checking
attribute parameter and 329
glossary entry 517
ldapmodify and 200
objectclass parameter and 330
overview 50
turning on or off 50
schema entry, searching 182
schema rules, defining 330
search filters 172-176
Boolean operators 175
contained in file 183
examples 172, 176
matching rule 186
operators in 173
specifying attributes 173
specifying file 180, 197
syntax 172
using multiple 175
search operations
limiting entries checked 321
limiting entries returned 319
setting time limits 319
Search rights 86
search types, list of 173, 185
searches
approximate 174
equality 173, 176, 190
example 182
greater than or equal to 174, 190, 191
international 185
international examples 189
less than 189
less than or equal to 174, 190
of directory tree 177
presence 174, 176
restricting scope of one-level 160
restricting scope of subtree 160
sort criteria 181
specifying scope 179
substring 173, 191
searchGuide attribute 482
searching algorithm, process described 152-153
secretary attribute 482
Secure Sockets Layer (SSL)
access control and 92
certificate password 26
enabling 239
Encrypted Port Number parameter 317
Encryption Ciphers parameter 316
Encryption Enabled parameter 315
glossary entry 517
replication and 251, 255
server startup and 26
setting preferences 239
specifying directory location 328
security
certificate database location and 242
certificate-based authentication 241
Encrypted Port Number parameter 317
Encryption Ciphers parameter 316
Encryption Enabled parameter 315
LDAP URLs and 496
setting preferences 239
specifying SSL directory location 328
Security Accounts Manager (SAM) log file 278
seeAlso attribute 482
self access 90
LDIF example 125
Server Manager example 107
Selfwrite rights
description 86
example 116
Send Warning parameter 146, 335
serialNumber attribute 482
server daemon glossary entry 517
Server Manager
backing up database 65
capabilities of 28
changing configuration parameters 308
converting to LDIF 63
creating indexes 161
deleting backups 67
glossary entry 517
importing LDIF with 60
monitoring server 218
restoring database 66
setting access controls 93-116
setting password policies 148-149
validating slapd.conf 311
server parameters
database 341-350
Attribute to be Indexed 159, 347
database 348
Database Checkpoint Interval 79, 348
Database Durable Transactions 80, 349
Database Transaction Log Directory 78, 349
DB Directory 344
dynamicconf 30, 350
Maximum DB Cache size in Bytes 232, 346
Maximum Entries in Cache 232, 346
mode 348
Read-only 225, 345
Root DN 344
Root Password 230, 344
Root Password Storage Scheme 345
Suffix 69, 342
general 311-339, ??-339, ??-340
Access Log 216, 233, 318
Account Lockout 146, 335
attribute 329
Audit Log 233, 317
Certificate and Key Directory 328
Changelog DB Directory 326
Changelog DB Suffix 327
Check Password Syntax 145, 335
Encrypted Port Number 232, 317
Encryption Alias 329
Encryption Ciphers 316
Encryption Enabled 315
Error Log 233, 318
Lockout Duration 147, 337
Log Level 233, 323
Look Through Limit 231, 321
Max Changelog Age 327
Max Changelog Records 327
Maximum Password Failures 146, 336
maxthreadsperconn 331
NLS 332
NT Synchronization Service Enabled 232, 338
NT Synchronization Service Port Number 233, 338, 340
Number of Passwords to Remember 146, 334
objectClass 330
orcautor 339
Password Change 145, 334
Password Expiration 145, 332
Password History 146, 333
Password Maximum Age 145, 332
Password Minimum Length 145, 333
Password Storage Scheme 148, 328
Port Number 232, 315
Referral 233, 274, 324
Reset Password Failure Count After 147, 336
Schema Check 50, 234, 322
Send Warning 146, 335
Size Limit 231, 319
Supplier DN 246, 325
Supplier Password 325
Supplier SSL Clients 247, 325
threadnumber 331
Time Limit 231, 319
Track Modifies 233, 322
Unlock Account 147, 337
server root glossary entry 517
Server Selector glossary entry 517
server service glossary entry 517
server settings, validating 311
servers, updating consumers 67
service glossary entry 517
Services Control Panel 25
setting passwords 149
SHA encryption 144, 328
simple authentication 92
Simple Authentication and Security Layer (SASL), access control and 92
Simple Network Management Protocol, See SNMP
simpleSecurityObject object class 412
single user, permissions for 132
singleLevelQuality attribute 483
Size Limit parameter
description and syntax 319
role in searching algorithm 152
viewing and changing 231
slapd glossary entry 517
slapd.at.conf file, schema checking and 322
slapd.conf file
and dynamic changes 30, 350
changing configuration parameters 309
creating indexes from 162
format of 309-310
ldif2ldbm and 61
location of 31
overview 30
root password and 344
schema checking and 322
validating parameters 311
slapd.dynamic_ldbm.conf file 162, 165
creating indexes using 162
creating international indexes using 166
example 163
international indexes and 165
overview 30
slapd.oc.conf file, schema checking and 322
smart referrals
creating 275
example 275
ldapsearch parameter 181
sn attribute 484
SNMP 295-306
agents 296
AIX SNMP daemon 305
configuring 303, 304-306
managed device 295, 297
managed objects 296
master agent
hostname 303
overview 296
Unix 296
Windows NT 296
MIB
entries table 301
interaction table 302
location of 298
operations table 299
NMS-initiated communication 297
overview 295
SNMP Subagent Configuration form 303
subagent
configuring 303
enabling 306
overview 296
starting and stopping 306
traps 297
SNMP Subagent Configuration form 303
Solaris, thread concurrency 221, 224
sort criteria 181
special characters, in parameters values 309
st attribute 484
standard
attributes 49, 55
database schema 49
object classes 49
standard index files 160
Start at field 289
starting the directory server 25
stateOrProvinceName attribute 484
status, synchronization 291
stopping the directory server 25
street attribute 484
streetAddress attribute 484
strongAuthenticationUser object class 412
styles, in this book 21
subagent
configuring 303
enabling 306
overview 296
starting and stopping 306
subject attribute 484
subschemaSubentry attribute 484
substring index
CPU cycles and 158
overview 155
when to use 159
substring search 173
international example 191
subtree replication 250, 254
subtreeACI attribute 416, 485
subtreeMaximumQuality attribute 485
subtreeMinimumQuality attribute 485
Suffix parameter
commas in DN and 342
description and syntax 342
managing 69
Referral parameter and 324
SuiteSpot integration
creating entries 72
required setup 70
settings 73
superuser
glossary entry 517
Supplier DN parameter
configuring 246
description and syntax 325
Supplier Password parameter
configuring 246
description and syntax 325
supplier server
certificate database and 241
change log 251, 254
glossary entry 517
identifying 255
restoring database 67
Supplier SSL Clients parameter
description and syntax 325
viewing and changing 247
supplier-initiated replication
adding consumers 251, 254
creating replication agreements 250
identifying consumers 251
initializing consumers 251
overview 244
replication activity log 253
replication algorithm 270-271
Replication Settings applet 249
scheduling 253
setting supplier DN 246
subtree only 250
using normal bind 246
using SSL 246, 251
supportedAlgorithms; attribute 485
supportedApplicationContext attribute 485
supportedControl attribute 485
supportedExtension attribute 485
supportedLDAPVersion attribute 485
supportedSASLMechanisms attribute 486
surname attribute 484, 485
symmetric encryption glossary entry 518
synchronization
automatic creation of mail accounts 290
concurrently changing entries 284
configuring 285
directory server to NT 281
creating entries 282
creating groups 282
deleting entries 283
modifying entries 283
multiple synchronization services 281
NTGroup object class 282
ntGroupCreateNewAccount 283
ntGroupDomainId attribute 282
NTUser object class 282
ntUserCreateNewAccount 283
ntUserDomainId attribute 282
disabling 288
event log file location 286
manual 289
NT to directory server 278
add all users 281
creating entries 279
finding changes 278
NTGroup object class 280
NTUser object class 279
scheduling 288
Start at field 289
starting and stopping 291
status 291
Synchronize every field 289
synchronization service 278
enabling 338
port number 338, 340
Synchronize every field 289
syntax
ACI language 117-130
attribute value 55
bind rules 87
LDAP URLs 492
ldapsearch 177
LDIF update statements 205
matching rule filter 186
password 142, 335
search filter 172
specifying for attribute name 329
system resources
cost of indexing 158
monitoring 220-221
T
target keyword 119targetattr keyword 120
targetDn attribute 486
targetfilter keyword 122
targeting
ACI language syntax 117
attributes 83
directory entries 83
DNs containing commas 119, 137
LDIF keywords for 119
overview 82
using LDAP search filters 84
using LDAP URLs 89
using LDIF 118
using Server Manager 95
wildcards and 83
TCP/IP glossary entry 518
telephoneNumber attribute 486
teletexTerminalIdentifier attribute 486
telexNumber attribute 486
terms, in this book 21, 513-518
textEncodedORAddress attribute 487
threadnumber parameter 331
threads, monitoring 220, 222-223
time format 498
Time Limit parameter
description and syntax 319
role in searching algorithm 152
viewing and changing 231
timeofday keyword 128
title attribute 487
top object class 413
Track Modifies parameter
description and syntax 322
viewing and changing 233
transaction logging
checkpoint interval 348
durable transactions 349
traps 297
Triple DES cipher 240
trivial words 142
ttl attribute 487
tuning server performance 231
U
uidglossary entry 518
uid attribute 487
Uniform Resource Locators, See URLs
uniqueIdentifier attribute 488
uniqueMember attribute 488
Unix
AIX SNMP daemon 305
master agent 296
Unlock Account parameter 147, 337
updatedByDocument attribute 488
updatesDocument attribute 488
URL
glossary entry 518
LDAP 324, 491-496
referrals and 274
user access 88
LDIF example 125
Server Manager example 108
to child entries 89
to directory 89
to own entry 90
LDIF example 125
Server Manager example 107
user defined passwords 142
userCertificate attribute 488
userCertificate;binary attribute 488
userClass attribute 489
user-defined attributes 55
userdn keyword 124
userdnattr keyword 127
userid attribute 487
userPassword attribute 489
users, account lockout 143
userSMIMECertificate;binary attribute 489
UTF-8 497
W
warning, password expiration 141, 335white space, in parameter values 309
wildcards
in international searches 189
in matching rule filters 189
in targets 83
Windows NT
directory server NT synchronization configuration tool 284
directory server to NT synchronization 281
master agent 296
NT to directory server synchronization 278
schedule 288
setting up synchronization 285
synchronizing with directory server 278
Write rights 86
X
X.500 standard glossary entry 518x121Address attribute 489
x500UniqueIdentifier attribute 489