Sun Identity Manager 8.1 Resources Reference

Account Attribute Support

Information about attribute support is provided in the following Supported Account Attributes and Unsupported Account Attributes sections.

Supported Account Attributes

The following attributes are displayed on the Account Attributes page for the NDS resource adapters.

Resource User Attribute

NDS Syntax

Attribute Type

Description

Create Home Directory 

Boolean 

Boolean 

Indicates whether to create a home directory for the user. The Home Directory Parameter must be set. 

Description 

Case Ignore String 

String 

Text that describes the user. 

Facsimile Telephone Number 

Facsimile Telephone Number 

String 

The telephone number and, optionally, the parameters for a facsimile terminal associated with a user. 

Full Name 

Case Ignore String 

String 

The full name of a user. 

Generational Qualifier 

Case Ignore String 

String 

Indicates a person’s generation. For example, Jr. or II. 

Given Name 

Case Ignore String 

String 

The given (first) name of a user. 

Group Membership 

Distinguished Name 

String 

A list of the groups to which the user belongs. 

GW_AccountID 

Not applicable 

String 

Account ID specified in the User Information field for GroupWise accounting. 

GW_DistributionLists 

Not applicable 

String 

Distribution lists of which the user is a member. The values must be valid distribution list distinguished names (DNs). 

GW_GatewayAccess 

Not applicable 

String 

Restricts access to GroupWise gateways. See your gateway documentation to determine if this field is applicable. 

GW_Name 

Not applicable 

String 

The GroupWise mailbox name. 

GW_PostOffice 

Not applicable 

String 

The name of an existing Post Office that is associated with the GroupWise domain. 

Home Directory 

Path 

String 

The location of a client’s current working directory. See the “Usage Notes” for more information. 

Initials 

Case Ignore String 

String 

The user’s middle initial. 

Internet EMail Address 

Case Ignore String 

String 

Specifies an Internet e-mail address. 

Case Ignore String 

String 

A physical or geographical location. 

Locked By Intruder 

Boolean 

Boolean 

Indicates an account has been locked due to excessive failing login attempts. 

Login Grace Limit 

Integer 

Int 

The total number of times an old password can be used (after the old password has expired) to access the account. 

Login Maximum Simultaneous 

Integer 

Int 

The number of authenticated login sessions a user can initiate simultaneously. 

ou 

Case Ignore String 

String 

The name of an organizational unit. 

Password Allow Change 

Boolean 

Boolean 

Determines whether the person logged in under an account can change the password for that account. 

Password Expiration Interval 

Interval 

Int 

The time interval a password can remain active. 

Password Required 

Boolean 

Boolean 

Establishes that a password is required for the user to log in. 

Password Unique Required 

Boolean 

Boolean 

Establishes that when a user password is changed, it must be different from those in the Passwords Used attribute. 

Surname 

Case Ignore String 

String 

Required. The name an individual inherits from a parent (or assumes by marriage) and by which the individual is commonly known. 

Telephone Number 

Telephone Number 

String 

The user’s telephone number. 

Title 

Case Ignore String 

String 

The designated position or function of a user within an organization. 

userPassword 

N/A 

Encrypted 

Required. The user’s password. 

The following table lists additional supported attributes that are defined in the NDS User object class.

Resource User Attribute  

NDS Syntax  

Attribute Type  

Description  

Account Balance 

Counter 

Int 

The amount of credit the user has to buy network services, such as connection time. 

Allow Unlimited Credit 

Boolean 

Boolean 

Indicates whether the user account has unlimited credit for using network services. 

audio 

Octet String 

String 

An audio file in binary format. 

businessCategory 

Case Ignore String 

String 

Describes the kind of business performed by an organization. 

carLicense 

Case Ignore String 

String 

Vehicle license or registration plate 

departmentNumber 

Case Ignore String 

String 

Identifies a department within an organization 

displayName 

Case Ignore String 

String 

The name to be displayed on admin screens. 

Employee ID 

Case Ignore String 

String 

Numerically identifies an employee within an organization 

employeeType 

Case Ignore String 

String 

Type of employment, such as Employee or Contractor 

Entrust:User 

Case Exact String 

String 

Specifies an Entrust user. 

Higher Privileges 

Distinguished Name 

String 

An alternative set of security access privileges. 

homePhone 

Telephone Number 

String 

The user’s home telephone number. 

homePostalAddress 

Postal Address 

String 

The user’s home address. 

jpegPhoto 

Octet String 

String 

A JPEG file containing a photo of the user 

labeledUri 

Case Ignore String 

String 

The user’s Uniform Resource Identifier (URI). 

Language 

Case Ignore List 

String 

An ordered list of languages 

Last Login Time 

Time 

String 

The login time of the session previous to the current session. 

ldapPhoto 

Octet String 

String 

A photo of the object in binary format. 

Login Allowed Time Map 

Octet String 

String 

The allowed login time periods for an account for each day of the week to a precision of one-half hour. 

Login Disabled 

Boolean 

Int 

Informs the user that the account has been disabled. 

Login Expiration Time 

Time 

String 

A date and time after which a client cannot log in. 

Login Grace Remaining 

Counter 

Int 

The number of grace logins are left before the account is locked. 

Login Intruder Attempts 

Counter 

Int 

The number of failed login attempts that have occurred in the current interval. 

Login Intruder Reset Time 

Time 

String 

The next time that the intruder attempts variable will be reset. 

Login Script 

Stream 

String 

The user’s login script. 

Login Time 

Time 

String 

The login time of the current session. 

manager 

Distinguished Name 

String 

The user’s supervisor. 

Minimum Account Balance 

Integer 

Int 

The minimum amount of credit (or money) a user must have in his or her account to access specified services. 

mobile 

Telephone Number 

String 

The user’s cell phone number. 

NDSPKI:Keystore 

Octet String 

String 

Contains wrapped private keys. 

NRD:Registry Data 

Stream 

String 

NetWare Registry Database 

NRD:Registry Index 

Stream 

String 

The index of the NetWare Registry Database 

pager 

Telephone Number 

String 

The user’s pager number. 

Password Expiration Time 

Time 

String 

Specifies when the password will expire. 

preferredLanguage 

Case Ignore String 

String 

The user’s preference for written or spoken language. 

Print Job Configuration 

Stream 

String 

Contains information on the specified print job configuration. 

Printer Control 

Stream 

String 

The NDS counterpart of the DOS printer definition file, NET$PRN.DAT. 

Profile 

Distinguished Name 

String 

The login profile to be used if the user does not specify one at login time. 

Profile Membership 

Distinguished Name 

String 

A list of profiles that the object can use. 

Public Key 

Octet String 

String 

A certified RSA public key 

roomNumber 

Case Ignore String 

String 

The user’s office or room number. 

secretary 

Distinguished Name 

String 

The user’s administrative assistant. 

Security Equals 

Distinguished Name 

String 

Specifies group membership and security equivalences of a user. 

Security Flags 

Integer 

Int 

The NCP Packet Signature level of the object. 

Timezone 

Octet String 

String 

The time zone offset for a user. 

UID (User ID) 

Integer 

Int 

A unique user ID for use by UNIX clients. 

userCertificate 

Octet String 

String 

A certificate for certificate management.

userSMIMECertificate

Octet String 

String 

The user’s certificate for Netscape Communicator for S/MIME. 

x500UniqueIdentifier 

Octet String 

String 

An identifier to use in distinguishing between users when a DN has been reused. 

Unsupported Account Attributes

The following account attributes are not supported: