JavaScript is required to for searching.
Skip Navigation Links
Exit Print View
Oracle Directory Server Enterprise Edition Man Page Reference 11g Release 1 (11.1.1.5.0)
search filter icon
search icon

Document Information

Preface

User Commands

Administration Commands

Directory Server Configuration

algorithm(5dsconf)

all-ids-threshold(5dsconf)

all-ids-threshold-eq(5dsconf)

all-ids-threshold-pres(5dsconf)

all-ids-threshold-sub(5dsconf)

approx-enabled(5dsconf)

argument(5dsconf)

attr(5dsconf)

auth-bind-dn(5dsconf)

auth-protocol(5dsconf)

auth-pwd(5dsconf)

auth-pwd-file(5dsconf)

base-dn(5dsconf)

bind-dn(5dsconf)

buffering-enabled(5dsconf)

check-schema-enabled(5dsconf)

check-syntax-enabled(5dsconf)

compat-flag(5dsconf)

compressed-entries(5dsconf)

compression-mode(5dsconf)

config-magic-number(5dsconf)

controls(5dsconf)

db-batched-transaction-count(5dsconf)

db-cache-size(5dsconf)

db-checkpoint-interval(5dsconf)

db-env-path(5dsconf)

db-lock-count(5dsconf)

db-log-buf-size(5dsconf)

db-log-path(5dsconf)

db-name(5dsconf)

db-path(5dsconf)

def-repl-manager-pwd(5dsconf)

def-repl-manager-pwd-file(5dsconf)

depends-on-named(5dsconf)

depends-on-type(5dsconf)

desc(5dsconf)

dn-cache-count(5dsconf)

dn-cache-size(5dsconf)

ds5AgreementEnable(5dsconf)

ds5BeginReplicaAcceptUpdates(5dsconf)

ds5LastInitTimeStamp(5dsconf)

ds5ReferralDelayAfterInit(5dsconf)

ds5ReplicaAutomaticInit(5dsconf)

ds5ReplicaConsumerTimeout(5dsconf)

ds5ReplicaTransportCompressionLevel(5dsconf)

ds5ReplicaTransportConcurrencyLevel(5dsconf)

ds5ReplicaTransportGroupSize(5dsconf)

ds5ReplicaTransportGrpPktSize(5dsconf)

ds5ReplicaTransportWindowSize(5dsconf)

ds6ruv(5dsconf)

dsChangelogMaxAge(5dsconf)

dsChangelogMaxentries(5dsconf)

dsFilterSPConfigchecksum(5dsconf)

ds-hdsml-clientauthmethod(5dsconf)

ds-hdsml-dsmlschemalocation(5dsconf)

ds-hdsml-iobuffersize(5dsconf)

ds-hdsml-poolmaxsize(5dsconf)

ds-hdsml-poolsize(5dsconf)

ds-hdsml-port(5dsconf)

ds-hdsml-requestmaxsize(5dsconf)

ds-hdsml-responsemsgsize(5dsconf)

ds-hdsml-rooturl(5dsconf)

ds-hdsml-secureport(5dsconf)

ds-hdsml-soapschemalocation(5dsconf)

ds-maxheaphigh(5dsconf)

ds-maxheaplow(5dsconf)

dsml-answer-size(5dsconf)

dsml-buffer-size(5dsconf)

dsml-client-auth-mode(5dsconf)

dsml-enabled(5dsconf)

dsml-max-parser-count(5dsconf)

dsml-min-parser-count(5dsconf)

dsml-port(5dsconf)

dsml-relative-root-url(5dsconf)

dsml-request-max-size(5dsconf)

dsml-secure-port(5dsconf)

dsReplFractionalExclude(5dsconf)

dsReplFractionalInclude(5dsconf)

enabled(5dsconf)

encryption(5dsconf)

entry-cache-count(5dsconf)

entry-cache-size(5dsconf)

entry-count(5dsconf)

entry-crc-enabled(5dsconf)

eq-enabled(5dsconf)

extended-operations(5dsconf)

feature(5dsconf)

file-descriptor-count(5dsconf)

heap-high-threshold-size(5dsconf)

heap-low-threshold-size(5dsconf)

heapmaxhighhits(5dsconf)

heapmaxlowhits(5dsconf)

host-access-dir-path(5dsconf)

idle-timeout(5dsconf)

import-cache-size(5dsconf)

index(5dsconf)

index-filter-analyzer-enabled(5dsconf)

index-filter-analyzer-max-entries(5dsconf)

init-func(5dsconf)

instance-path(5dsconf)

ldap-port(5dsconf)

ldap-secure-port(5dsconf)

level(5dsconf)

lib-path(5dsconf)

listen-address(5dsconf)

log(5dsconf)

look-through-limit(5dsconf)

matching-rule(5dsconf)

max-age(5dsconf)

max-disk-space-size(5dsconf)

max-file-count(5dsconf)

max-psearch-count(5dsconf)

max-size(5dsconf)

max-thread-count(5dsconf)

max-thread-per-connection-count(5dsconf)

min-free-disk-space-size(5dsconf)

moddn-enabled(5dsconf)

mod-tracking-enabled(5dsconf)

nsAbandonedSearchCheckInterval(5dsconf)

nsActiveChainingComponents(5dsconf)

nsBindConnectionsLimit(5dsconf)

nsBindRetryLimit(5dsconf)

nsBindTimeout(5dsconf)

nsCheckLocalACI(5dsconf)

nsConcurrentBindLimit(5dsconf)

nsConcurrentOperationsLimit(5dsconf)

nsConnectionLife(5dsconf)

nsds50ruv(5dsconf)

nsds5BeginReplicaRefresh(5dsconf)

nsDS5Flags(5dsconf)

nsDS5Replica(5dsconf)

nsDS5ReplicaAutoReferral(5dsconf)

nsDS5ReplicaBindDN(5dsconf)

nsDS5ReplicaBindMethod(5dsconf)

nsDS5ReplicaChangeCount(5dsconf)

nsds5replicaChangesSentSinceStartup(5dsconf)

nsDS5ReplicaCredentials(5dsconf)

nsDS5ReplicaHost(5dsconf)

nsDS5ReplicaId(5dsconf)

nsds5replicaLastInitEnd(5dsconf)

nsds5replicaLastInitStart(5dsconf)

nsds5replicaLastInitStatus(5dsconf)

nsds5replicaLastUpdateEnd(5dsconf)

nsds5replicaLastUpdateStart(5dsconf)

nsds5replicaLastUpdateStatus(5dsconf)

nsDS5ReplicaName(5dsconf)

nsDS5ReplicaPort(5dsconf)

nsDS5ReplicaPurgeDelay(5dsconf)

nsDS5ReplicaReferral(5dsconf)

nsDS5ReplicaRoot(5dsconf)

nsDS5ReplicatedAttributeList(5dsconf)

nsds5ReplicaTimeout(5dsconf)

nsDS5ReplicationAgreement(5dsconf)

nsDS5ReplicaTombstonePurgeInterval(5dsconf)

nsDS5ReplicaTransportInfo(5dsconf)

nsDS5ReplicaType(5dsconf)

nsds5replicaUpdateInProgress(5dsconf)

nsDS5ReplicaUpdateSchedule(5dsconf)

nsDS5Task(5dsconf)

nsFarmServerURL(5dsconf)

nshoplimit(5dsconf)

nsIndexType(5dsconf)

nsLookthroughLimit(5dsconf)

nsMatchingRule(5dsconf)

nsMaxResponseDelay(5dsconf)

nsMaxTestResponseDelay(5dsconf)

nsMultiplexorBindDN(5dsconf)

nsMultiplexorCredentials(5dsconf)

nsOperationConnectionsLimit(5dsconf)

nsProxiedAuthorization(5dsconf)

nsReferralOnScopedSearch(5dsconf)

nsslapd-accesscontrol(5dsconf)

nsslapd-accesslog(5dsconf)

nsslapd-accesslog-level(5dsconf)

nsslapd-accesslog-list(5dsconf)

nsslapd-accesslog-logbuffering(5dsconf)

nsslapd-accesslog-logexpirationtime(5dsconf)

nsslapd-accesslog-logexpirationtimeunit(5dsconf)

nsslapd-accesslog-logging-enabled(5dsconf)

nsslapd-accesslog-logmaxdiskspace(5dsconf)

nsslapd-accesslog-logminfreediskspace(5dsconf)

nsslapd-accesslog-logrotationtime(5dsconf)

nsslapd-accesslog-logrotationtimeunit(5dsconf)

nsslapd-accesslog-maxlogsize(5dsconf)

nsslapd-accesslog-maxlogsperdir(5dsconf)

nsslapd-accesslog-permissions(5dsconf)

nsslapd-allidsthreshold(5dsconf)

nsslapd-attribute-name-exceptions(5dsconf)

nsslapd-auditlog(5dsconf)

nsslapd-auditlog-level(5dsconf)

nsslapd-auditlog-list(5dsconf)

nsslapd-auditlog-logbuffering(5dsconf)

nsslapd-auditlog-logexpirationtime(5dsconf)

nsslapd-auditlog-logexpirationtimeunit(5dsconf)

nsslapd-auditlog-logging-enabled(5dsconf)

nsslapd-auditlog-logmaxdiskspace(5dsconf)

nsslapd-auditlog-logminfreediskspace(5dsconf)

nsslapd-auditlog-logrotationtime(5dsconf)

nsslapd-auditlog-logrotationtimeunit(5dsconf)

nsslapd-auditlog-maxlogsize(5dsconf)

nsslapd-auditlog-maxlogsperdir(5dsconf)

nsslapd-auditlog-permissions(5dsconf)

nsslapd-backend(5dsconf)

nsslapd-berbufsize(5dsconf)

nsslapd-cachememsize(5dsconf)

nsslapd-cachesize(5dsconf)

nsslapd-certmap-basedn(5dsconf)

nsslapd-changelogdir(5dsconf)

nsslapd-changelogmaxage(5dsconf)

nsslapd-changelogmaxentries(5dsconf)

nsslapd-config(5dsconf)

nsslapd-dbcachesize(5dsconf)

nsslapd-db-checkpoint-interval(5dsconf)

nsslapd-db-circular-logging(5dsconf)

nsslapd-db-durable-transactions(5dsconf)

nsslapd-db-home-directory(5dsconf)

nsslapd-db-idl-divisor(5dsconf)

nsslapd-db-locks(5dsconf)

nsslapd-db-logbuf-size(5dsconf)

nsslapd-db-logdirectory(5dsconf)

nsslapd-db-logfile-size(5dsconf)

nsslapd-dbncache(5dsconf)

nsslapd-db-page-size(5dsconf)

nsslapd-db-transaction-batch-val(5dsconf)

nsslapd-db-tx-max(5dsconf)

nsslapd-directory(5dsconf)

nsslapd-disk-full-threshold(5dsconf)

nsslapd-disk-low-threshold(5dsconf)

nsslapd-distribution-funct(5dsconf)

nsslapd-distribution-plugin(5dsconf)

nsslapd-dn-cachememsize(5dsconf)

nsslapd-dn-cachesize(5dsconf)

nsslapd-ds4-compatible-schema(5dsconf)

nsslapd-enquote-sup-oc(5dsconf)

nsslapd-errorlog(5dsconf)

nsslapd-errorlog-level(5dsconf)

nsslapd-errorlog-list(5dsconf)

nsslapd-errorlog-logbuffering(5dsconf)

nsslapd-errorlog-logexpirationtime(5dsconf)

nsslapd-errorlog-logexpirationtimeunit(5dsconf)

nsslapd-errorlog-logging-enabled(5dsconf)

nsslapd-errorlog-logmaxdiskspace(5dsconf)

nsslapd-errorlog-logminfreediskspace(5dsconf)

nsslapd-errorlog-logrotationtime(5dsconf)

nsslapd-errorlog-logrotationtimeunit(5dsconf)

nsslapd-errorlog-maxlogsize(5dsconf)

nsslapd-errorlog-maxlogsperdir(5dsconf)

nsslapd-errorlog-permissions(5dsconf)

nsslapd-exclude-from-export(5dsconf)

nsslapd-groupevalnestlevel(5dsconf)

nsslapd-groupevalsizelimit(5dsconf)

nsslapd-idletimeout(5dsconf)

nsslapd-import-cachesize(5dsconf)

nsslapd-infolog-area(5dsconf)

nsslapd-infolog-level(5dsconf)

nsslapd-instancedir(5dsconf)

nsslapd-ioblocktimeout(5dsconf)

nsslapd-lastmod(5dsconf)

nsslapd-listenBacklog(5dsconf)

nsslapd-listenhost(5dsconf)

nsslapd-localhost(5dsconf)

nsslapd-localuser(5dsconf)

nsslapd-maxbersize(5dsconf)

nsslapd-maxconnections(5dsconf)

nsslapd-maxdescriptors(5dsconf)

nsslapd-maxpsearch(5dsconf)

nsslapd-maxthreadsperconn(5dsconf)

nsslapd-mode(5dsconf)

nsslapd-nagle(5dsconf)

nsslapd-plugin(5dsconf)

nsslapd-plugin-depends-on-named(5dsconf)

nsslapd-plugin-depends-on-type(5dsconf)

nsslapd-pluginDescription(5dsconf)

nsslapd-pluginEnabled(5dsconf)

nsslapd-pluginId(5dsconf)

nsslapd-pluginInitfunc(5dsconf)

nsslapd-pluginPath(5dsconf)

nsslapd-pluginType(5dsconf)

nsslapd-pluginVendor(5dsconf)

nsslapd-pluginVersion(5dsconf)

nsslapd-port(5dsconf)

nsslapd-privatenamespaces(5dsconf)

nsslapd-pwdgeneratorpwdlen(5dsconf)

nsslapd-readonly(5dsconf)

nsslapd-referral(5dsconf)

nsslapd-referralmode(5dsconf)

nsslapd-require-index(5dsconf)

nsslapd-reservedescriptors(5dsconf)

nsslapd-return-exact-case(5dsconf)

nsslapd-rootdn(5dsconf)

nsslapd-rootpw(5dsconf)

nsslapd-rootpwstoragescheme(5dsconf)

nsslapd-schemacheck(5dsconf)

nsslapd-schema-repl-useronly(5dsconf)

nsslapd-search-tune(5dsconf)

nsslapd-securelistenhost(5dsconf)

nsslapd-securePort(5dsconf)

nsslapd-security(5dsconf)

nsslapd-sizelimit(5dsconf)

nsslapd-state(5dsconf)

nsslapd-suffix(5dsconf)

nsslapd-threadnumber(5dsconf)

nsslapd-timelimit(5dsconf)

nsslapd-versionstring(5dsconf)

nsSSL2(5dsconf)

nsSSL3(5dsconf)

nsSSL3ciphers(5dsconf)

nsSSLClientAuth(5dsconf)

nsSSLServerAuth(5dsconf)

nsSSLSessionTimeout(5dsconf)

nsState(5dsconf)

nsSystemIndex(5dsconf)

nsTransmittedControls(5dsconf)

op-type(5dsconf)

parent-suffix-dn(5dsconf)

path(5dsconf)

perm(5dsconf)

plugin(5dsconf)

polling-thread-count(5dsconf)

pres-enabled(5dsconf)

pwd-accept-hashed-pwd-enabled(5dsconf)

pwd-check-enabled(5dsconf)

pwd-compat-mode(5dsconf)

pwd-expire-no-warning-enabled(5dsconf)

pwd-expire-warning-delay(5dsconf)

pwd-failure-count-interval(5dsconf)

pwd-grace-login-limit(5dsconf)

pwd-keep-last-auth-time-enabled(5dsconf)

pwd-lockout-duration(5dsconf)

pwd-lockout-enabled(5dsconf)

pwd-lockout-repl-priority-enabled(5dsconf)

pwd-max-age(5dsconf)

pwd-max-failure-count(5dsconf)

pwd-max-history-count(5dsconf)

pwd-min-age(5dsconf)

pwd-min-length(5dsconf)

pwd-mod-gen-length(5dsconf)

pwd-must-change-enabled(5dsconf)

pwd-root-dn-bypass-enabled(5dsconf)

pwd-safe-modify-enabled(5dsconf)

pwd-storage-scheme(5dsconf)

pwd-strong-check-dictionary-path(5dsconf)

pwd-strong-check-enabled(5dsconf)

pwd-strong-check-require-charset(5dsconf)

pwd-supported-storage-scheme(5dsconf)

pwd-user-change-enabled(5dsconf)

read-write-mode(5dsconf)

referral-mode(5dsconf)

referral-url(5dsconf)

ref-integrity-attr(5dsconf)

ref-integrity-check-delay(5dsconf)

ref-integrity-enabled(5dsconf)

repl-accept-client-update-enabled(5dsconf)

repl-agmt(5dsconf)

repl-cl-max-age(5dsconf)

repl-cl-max-entry-count(5dsconf)

repl-fractional-exclude-attr(5dsconf)

repl-fractional-include-attr(5dsconf)

replication(5dsconf)

repl-id(5dsconf)

repl-manager-bind-dn(5dsconf)

repl-priority(5dsconf)

replPriorityAttribute(5dsconf)

replPriorityBaseDN(5dsconf)

replPriorityBindDN(5dsconf)

ReplPriorityRule(5dsconf)

replPriorityType(5dsconf)

repl-purge-delay(5dsconf)

repl-rewrite-referrals-enabled(5dsconf)

repl-role(5dsconf)

repl-schedule(5dsconf)

repl-user-schema-enabled(5dsconf)

require-bind-pwd-enabled(5dsconf)

require-index-enabled(5dsconf)

retro-cl-deleted-entry-attr(5dsconf)

retro-cl-enabled(5dsconf)

retro-cl-ignored-attr(5dsconf)

retro-cl-max-age(5dsconf)

retro-cl-max-entry-count(5dsconf)

retro-cl-path(5dsconf)

retro-cl-suffix-dn(5dsconf)

root-dn(5dsconf)

root-pwd(5dsconf)

root-pwd-file(5dsconf)

root-pwd-storage-scheme(5dsconf)

rotation-interval(5dsconf)

rotation-min-file-size(5dsconf)

rotation-time(5dsconf)

search-size-limit(5dsconf)

search-time-limit(5dsconf)

secure-listen-address(5dsconf)

server(5dsconf)

ssl-cipher-family(5dsconf)

ssl-client-auth-mode(5dsconf)

ssl-enabled(5dsconf)

ssl-rsa-cert-name(5dsconf)

ssl-rsa-security-device(5dsconf)

ssl-supported-ciphers(5dsconf)

sub-enabled(5dsconf)

suffix(5dsconf)

system(5dsconf)

thread-count(5dsconf)

transport-compression(5dsconf)

transport-group-size(5dsconf)

transport-window-size(5dsconf)

type(5dsconf)

useAuthzIdForAuditAttrs(5dsconf)

vendor(5dsconf)

verbose-enabled(5dsconf)

version(5dsconf)

Directory Proxy Server Configuration

File Formats

LDAP Schema Collections

LDAP Schema Attribute Types

LDAP Schema Object Classes

Index

encryption

, algorithm

- DS attribute encryption (ETA) properties

Description

Directory Server allows you to encrypt individual attributes to protect sensitive information stored in the directory. The encryption does not prevent client applications from reading the attributes. Instead it works at the database index file level to prevent users with access to read database index files from being able to search through the indexes for sensitive information.

For example, before attribute encryption is configured for uid attributes, a user with read access to database index files could easily find out that bjensen is a uid attribute value:

$ strings example_uid.db3 | grep bjensen
=bjensen
$ 

Once uid attributes are encrypted, the job is not so easy:

$ strings example_uid.db3 | grep bjensen
$ 

Notice however that encrypted RDN values are not fully hidden. Instead they appear in clear in the DN index:

$ strings example_entrydn.db3 | grep bjensen
=uid=bjensen,ou=people,dc=example,dc=com
=uid=bjensen,ou=people,dc=example,dc=com
$ 

PROPERTY: algorithm

Syntax
des|des3|rc2|rc4
Default Value
None
Is readable
Yes
Is modifiable
Yes
Is multi-valued
No

Directory Server uses a cipher to encrypt a specified attribute in a given suffix. This property specifies the cipher used.

The following property values are supported:

des

DES block cipher

des3

Triple-DES block cipher

rc2

RC2 block cipher

rc4

RC4 stream cipher

SYNTAX VALUES

Syntax values shown in lower case or partly in lower case are literal values.

Those shown in upper case are syntax types, defined as follows:

ATTR_NAME

A valid attribute type name such as cn or objectClass.

BOOLEAN

true or false.

DN

A valid distinguished name such as ou=People,dc=example,dc=com.

DURATION

A duration specified in months (M), weeks (w), days (d), hours (h), minutes (m), seconds (s), and miliseconds (ms), or some combination with multiple specifiers. For example, you can specify one week as 1w, 7d, 168h, 10080m, or 604800s. You can also specify one week as 1w0d0h0m0s.

DURATION properties typically do not each support all duration specifiers (Mwdhms). Examine the output of dsconf help-properties for the property to determine which duration specifiers are supported.

EMAIL_ADDRESS

A valid e-mail address.

HOST_NAME

An IP address or host name.

INTEGER

A positive integer value between 0 and the maximum supported integer value in the system address space. On 32-bit systems, 2147483647. On 64-bit systems, 9223372036854775807.

INTERVAL

An interval value of the form hhmm-hhmm 0123456, where the first element specifies the starting hour, the next element the finishing hour in 24-hour time format, from 0000-2359, and the second specifies days, starting with Sunday (0) to Saturday (6).

IP_RANGE

An IP address or range of address in one of the following formats:

  • IP address in dotted decimal form.

  • IP address and bits, in the form of network number/mask bits.

  • IP address and quad, in the form of a pair of dotted decimal quads.

  • All address. A catch-all for clients that are note placed into other, higher priority groups.

  • 0.0.0.0. This address is for groups to which initial membership is not considered. For example, for groups that clients switch to after their initial bind.

  • IP address of the local host.

LDAP_URL

A valid LDAP URL as specified by RFC 2255.

MEMORY_SIZE

A memory size specified in gigabytes (G), megabytes (M),kilobytes (k), or bytes (b). Unlike DURATION properties, MEMORY_SIZE properties cannot combine multiple specifiers. However, MEMORY_SIZE properties allow decimal values, for example, 1.5M.

NAME

A valid cn (common name).

OCTAL_MODE

A three-digit, octal file permissions specifier. The first digit specifies permissions for the server user ID, the second for the server group ID, the last for other users. Each digit consists of a bitmask defining read (4), write (2), execute (1), or no access (0) permissions, thus 640 specifies read-write access for the server user, read-only access for other users of the server group, and no access for other users.

PASSWORD_FILE

The full path to the file from which the bind password should be read.

PATH

A valid, absolute file system path.

STRING

A DirectoryString value, as specified by RFC 2252.

SUPPORTED_SSL_CIPHER

An SSL cipher supported by the server. See the Reference for a list of supported ciphers.

SUPPORTED_SSL_PROTOCOL

An SSL protocol supported by the server. See the Reference for a list of supported protocols.

TIME

A time of the form hhmm in 24-hour format, where hh stands for hours and mm stands for minutes.

Attributes

See attributes(5) for descriptions of the following attributes:

ATTRIBUTE TYPE
ATTRIBUTE VALUE
Availability
SUNWdsee7
Stability Level
Evolving

See Also

dsconf(1M), desc(5dsconf)