JavaScript is required to for searching.
Skip Navigation Links
Exit Print View
Oracle Directory Server Enterprise Edition Man Page Reference 11g Release 1 (11.1.1.5.0)
search filter icon
search icon

Document Information

Preface

User Commands

Administration Commands

Directory Server Configuration

algorithm(5dsconf)

all-ids-threshold(5dsconf)

all-ids-threshold-eq(5dsconf)

all-ids-threshold-pres(5dsconf)

all-ids-threshold-sub(5dsconf)

approx-enabled(5dsconf)

argument(5dsconf)

attr(5dsconf)

auth-bind-dn(5dsconf)

auth-protocol(5dsconf)

auth-pwd(5dsconf)

auth-pwd-file(5dsconf)

base-dn(5dsconf)

bind-dn(5dsconf)

buffering-enabled(5dsconf)

check-schema-enabled(5dsconf)

check-syntax-enabled(5dsconf)

compat-flag(5dsconf)

compressed-entries(5dsconf)

compression-mode(5dsconf)

config-magic-number(5dsconf)

controls(5dsconf)

db-batched-transaction-count(5dsconf)

db-cache-size(5dsconf)

db-checkpoint-interval(5dsconf)

db-env-path(5dsconf)

db-lock-count(5dsconf)

db-log-buf-size(5dsconf)

db-log-path(5dsconf)

db-name(5dsconf)

db-path(5dsconf)

def-repl-manager-pwd(5dsconf)

def-repl-manager-pwd-file(5dsconf)

depends-on-named(5dsconf)

depends-on-type(5dsconf)

desc(5dsconf)

dn-cache-count(5dsconf)

dn-cache-size(5dsconf)

ds5AgreementEnable(5dsconf)

ds5BeginReplicaAcceptUpdates(5dsconf)

ds5LastInitTimeStamp(5dsconf)

ds5ReferralDelayAfterInit(5dsconf)

ds5ReplicaAutomaticInit(5dsconf)

ds5ReplicaConsumerTimeout(5dsconf)

ds5ReplicaTransportCompressionLevel(5dsconf)

ds5ReplicaTransportConcurrencyLevel(5dsconf)

ds5ReplicaTransportGroupSize(5dsconf)

ds5ReplicaTransportGrpPktSize(5dsconf)

ds5ReplicaTransportWindowSize(5dsconf)

ds6ruv(5dsconf)

dsChangelogMaxAge(5dsconf)

dsChangelogMaxentries(5dsconf)

dsFilterSPConfigchecksum(5dsconf)

ds-hdsml-clientauthmethod(5dsconf)

ds-hdsml-dsmlschemalocation(5dsconf)

ds-hdsml-iobuffersize(5dsconf)

ds-hdsml-poolmaxsize(5dsconf)

ds-hdsml-poolsize(5dsconf)

ds-hdsml-port(5dsconf)

ds-hdsml-requestmaxsize(5dsconf)

ds-hdsml-responsemsgsize(5dsconf)

ds-hdsml-rooturl(5dsconf)

ds-hdsml-secureport(5dsconf)

ds-hdsml-soapschemalocation(5dsconf)

ds-maxheaphigh(5dsconf)

ds-maxheaplow(5dsconf)

dsml-answer-size(5dsconf)

dsml-buffer-size(5dsconf)

dsml-client-auth-mode(5dsconf)

dsml-enabled(5dsconf)

dsml-max-parser-count(5dsconf)

dsml-min-parser-count(5dsconf)

dsml-port(5dsconf)

dsml-relative-root-url(5dsconf)

dsml-request-max-size(5dsconf)

dsml-secure-port(5dsconf)

dsReplFractionalExclude(5dsconf)

dsReplFractionalInclude(5dsconf)

enabled(5dsconf)

encryption(5dsconf)

entry-cache-count(5dsconf)

entry-cache-size(5dsconf)

entry-count(5dsconf)

entry-crc-enabled(5dsconf)

eq-enabled(5dsconf)

extended-operations(5dsconf)

feature(5dsconf)

file-descriptor-count(5dsconf)

heap-high-threshold-size(5dsconf)

heap-low-threshold-size(5dsconf)

heapmaxhighhits(5dsconf)

heapmaxlowhits(5dsconf)

host-access-dir-path(5dsconf)

idle-timeout(5dsconf)

import-cache-size(5dsconf)

index(5dsconf)

index-filter-analyzer-enabled(5dsconf)

index-filter-analyzer-max-entries(5dsconf)

init-func(5dsconf)

instance-path(5dsconf)

ldap-port(5dsconf)

ldap-secure-port(5dsconf)

level(5dsconf)

lib-path(5dsconf)

listen-address(5dsconf)

log(5dsconf)

look-through-limit(5dsconf)

matching-rule(5dsconf)

max-age(5dsconf)

max-disk-space-size(5dsconf)

max-file-count(5dsconf)

max-psearch-count(5dsconf)

max-size(5dsconf)

max-thread-count(5dsconf)

max-thread-per-connection-count(5dsconf)

min-free-disk-space-size(5dsconf)

moddn-enabled(5dsconf)

mod-tracking-enabled(5dsconf)

nsAbandonedSearchCheckInterval(5dsconf)

nsActiveChainingComponents(5dsconf)

nsBindConnectionsLimit(5dsconf)

nsBindRetryLimit(5dsconf)

nsBindTimeout(5dsconf)

nsCheckLocalACI(5dsconf)

nsConcurrentBindLimit(5dsconf)

nsConcurrentOperationsLimit(5dsconf)

nsConnectionLife(5dsconf)

nsds50ruv(5dsconf)

nsds5BeginReplicaRefresh(5dsconf)

nsDS5Flags(5dsconf)

nsDS5Replica(5dsconf)

nsDS5ReplicaAutoReferral(5dsconf)

nsDS5ReplicaBindDN(5dsconf)

nsDS5ReplicaBindMethod(5dsconf)

nsDS5ReplicaChangeCount(5dsconf)

nsds5replicaChangesSentSinceStartup(5dsconf)

nsDS5ReplicaCredentials(5dsconf)

nsDS5ReplicaHost(5dsconf)

nsDS5ReplicaId(5dsconf)

nsds5replicaLastInitEnd(5dsconf)

nsds5replicaLastInitStart(5dsconf)

nsds5replicaLastInitStatus(5dsconf)

nsds5replicaLastUpdateEnd(5dsconf)

nsds5replicaLastUpdateStart(5dsconf)

nsds5replicaLastUpdateStatus(5dsconf)

nsDS5ReplicaName(5dsconf)

nsDS5ReplicaPort(5dsconf)

nsDS5ReplicaPurgeDelay(5dsconf)

nsDS5ReplicaReferral(5dsconf)

nsDS5ReplicaRoot(5dsconf)

nsDS5ReplicatedAttributeList(5dsconf)

nsds5ReplicaTimeout(5dsconf)

nsDS5ReplicationAgreement(5dsconf)

nsDS5ReplicaTombstonePurgeInterval(5dsconf)

nsDS5ReplicaTransportInfo(5dsconf)

nsDS5ReplicaType(5dsconf)

nsds5replicaUpdateInProgress(5dsconf)

nsDS5ReplicaUpdateSchedule(5dsconf)

nsDS5Task(5dsconf)

nsFarmServerURL(5dsconf)

nshoplimit(5dsconf)

nsIndexType(5dsconf)

nsLookthroughLimit(5dsconf)

nsMatchingRule(5dsconf)

nsMaxResponseDelay(5dsconf)

nsMaxTestResponseDelay(5dsconf)

nsMultiplexorBindDN(5dsconf)

nsMultiplexorCredentials(5dsconf)

nsOperationConnectionsLimit(5dsconf)

nsProxiedAuthorization(5dsconf)

nsReferralOnScopedSearch(5dsconf)

nsslapd-accesscontrol(5dsconf)

nsslapd-accesslog(5dsconf)

nsslapd-accesslog-level(5dsconf)

nsslapd-accesslog-list(5dsconf)

nsslapd-accesslog-logbuffering(5dsconf)

nsslapd-accesslog-logexpirationtime(5dsconf)

nsslapd-accesslog-logexpirationtimeunit(5dsconf)

nsslapd-accesslog-logging-enabled(5dsconf)

nsslapd-accesslog-logmaxdiskspace(5dsconf)

nsslapd-accesslog-logminfreediskspace(5dsconf)

nsslapd-accesslog-logrotationtime(5dsconf)

nsslapd-accesslog-logrotationtimeunit(5dsconf)

nsslapd-accesslog-maxlogsize(5dsconf)

nsslapd-accesslog-maxlogsperdir(5dsconf)

nsslapd-accesslog-permissions(5dsconf)

nsslapd-allidsthreshold(5dsconf)

nsslapd-attribute-name-exceptions(5dsconf)

nsslapd-auditlog(5dsconf)

nsslapd-auditlog-level(5dsconf)

nsslapd-auditlog-list(5dsconf)

nsslapd-auditlog-logbuffering(5dsconf)

nsslapd-auditlog-logexpirationtime(5dsconf)

nsslapd-auditlog-logexpirationtimeunit(5dsconf)

nsslapd-auditlog-logging-enabled(5dsconf)

nsslapd-auditlog-logmaxdiskspace(5dsconf)

nsslapd-auditlog-logminfreediskspace(5dsconf)

nsslapd-auditlog-logrotationtime(5dsconf)

nsslapd-auditlog-logrotationtimeunit(5dsconf)

nsslapd-auditlog-maxlogsize(5dsconf)

nsslapd-auditlog-maxlogsperdir(5dsconf)

nsslapd-auditlog-permissions(5dsconf)

nsslapd-backend(5dsconf)

nsslapd-berbufsize(5dsconf)

nsslapd-cachememsize(5dsconf)

nsslapd-cachesize(5dsconf)

nsslapd-certmap-basedn(5dsconf)

nsslapd-changelogdir(5dsconf)

nsslapd-changelogmaxage(5dsconf)

nsslapd-changelogmaxentries(5dsconf)

nsslapd-config(5dsconf)

nsslapd-dbcachesize(5dsconf)

nsslapd-db-checkpoint-interval(5dsconf)

nsslapd-db-circular-logging(5dsconf)

nsslapd-db-durable-transactions(5dsconf)

nsslapd-db-home-directory(5dsconf)

nsslapd-db-idl-divisor(5dsconf)

nsslapd-db-locks(5dsconf)

nsslapd-db-logbuf-size(5dsconf)

nsslapd-db-logdirectory(5dsconf)

nsslapd-db-logfile-size(5dsconf)

nsslapd-dbncache(5dsconf)

nsslapd-db-page-size(5dsconf)

nsslapd-db-transaction-batch-val(5dsconf)

nsslapd-db-tx-max(5dsconf)

nsslapd-directory(5dsconf)

nsslapd-disk-full-threshold(5dsconf)

nsslapd-disk-low-threshold(5dsconf)

nsslapd-distribution-funct(5dsconf)

nsslapd-distribution-plugin(5dsconf)

nsslapd-dn-cachememsize(5dsconf)

nsslapd-dn-cachesize(5dsconf)

nsslapd-ds4-compatible-schema(5dsconf)

nsslapd-enquote-sup-oc(5dsconf)

nsslapd-errorlog(5dsconf)

nsslapd-errorlog-level(5dsconf)

nsslapd-errorlog-list(5dsconf)

nsslapd-errorlog-logbuffering(5dsconf)

nsslapd-errorlog-logexpirationtime(5dsconf)

nsslapd-errorlog-logexpirationtimeunit(5dsconf)

nsslapd-errorlog-logging-enabled(5dsconf)

nsslapd-errorlog-logmaxdiskspace(5dsconf)

nsslapd-errorlog-logminfreediskspace(5dsconf)

nsslapd-errorlog-logrotationtime(5dsconf)

nsslapd-errorlog-logrotationtimeunit(5dsconf)

nsslapd-errorlog-maxlogsize(5dsconf)

nsslapd-errorlog-maxlogsperdir(5dsconf)

nsslapd-errorlog-permissions(5dsconf)

nsslapd-exclude-from-export(5dsconf)

nsslapd-groupevalnestlevel(5dsconf)

nsslapd-groupevalsizelimit(5dsconf)

nsslapd-idletimeout(5dsconf)

nsslapd-import-cachesize(5dsconf)

nsslapd-infolog-area(5dsconf)

nsslapd-infolog-level(5dsconf)

nsslapd-instancedir(5dsconf)

nsslapd-ioblocktimeout(5dsconf)

nsslapd-lastmod(5dsconf)

nsslapd-listenBacklog(5dsconf)

nsslapd-listenhost(5dsconf)

nsslapd-localhost(5dsconf)

nsslapd-localuser(5dsconf)

nsslapd-maxbersize(5dsconf)

nsslapd-maxconnections(5dsconf)

nsslapd-maxdescriptors(5dsconf)

nsslapd-maxpsearch(5dsconf)

nsslapd-maxthreadsperconn(5dsconf)

nsslapd-mode(5dsconf)

nsslapd-nagle(5dsconf)

nsslapd-plugin(5dsconf)

nsslapd-plugin-depends-on-named(5dsconf)

nsslapd-plugin-depends-on-type(5dsconf)

nsslapd-pluginDescription(5dsconf)

nsslapd-pluginEnabled(5dsconf)

nsslapd-pluginId(5dsconf)

nsslapd-pluginInitfunc(5dsconf)

nsslapd-pluginPath(5dsconf)

nsslapd-pluginType(5dsconf)

nsslapd-pluginVendor(5dsconf)

nsslapd-pluginVersion(5dsconf)

nsslapd-port(5dsconf)

nsslapd-privatenamespaces(5dsconf)

nsslapd-pwdgeneratorpwdlen(5dsconf)

nsslapd-readonly(5dsconf)

nsslapd-referral(5dsconf)

nsslapd-referralmode(5dsconf)

nsslapd-require-index(5dsconf)

nsslapd-reservedescriptors(5dsconf)

nsslapd-return-exact-case(5dsconf)

nsslapd-rootdn(5dsconf)

nsslapd-rootpw(5dsconf)

nsslapd-rootpwstoragescheme(5dsconf)

nsslapd-schemacheck(5dsconf)

nsslapd-schema-repl-useronly(5dsconf)

nsslapd-search-tune(5dsconf)

nsslapd-securelistenhost(5dsconf)

nsslapd-securePort(5dsconf)

nsslapd-security(5dsconf)

nsslapd-sizelimit(5dsconf)

nsslapd-state(5dsconf)

nsslapd-suffix(5dsconf)

nsslapd-threadnumber(5dsconf)

nsslapd-timelimit(5dsconf)

nsslapd-versionstring(5dsconf)

nsSSL2(5dsconf)

nsSSL3(5dsconf)

nsSSL3ciphers(5dsconf)

nsSSLClientAuth(5dsconf)

nsSSLServerAuth(5dsconf)

nsSSLSessionTimeout(5dsconf)

nsState(5dsconf)

nsSystemIndex(5dsconf)

nsTransmittedControls(5dsconf)

op-type(5dsconf)

parent-suffix-dn(5dsconf)

path(5dsconf)

perm(5dsconf)

plugin(5dsconf)

polling-thread-count(5dsconf)

pres-enabled(5dsconf)

pwd-accept-hashed-pwd-enabled(5dsconf)

pwd-check-enabled(5dsconf)

pwd-compat-mode(5dsconf)

pwd-expire-no-warning-enabled(5dsconf)

pwd-expire-warning-delay(5dsconf)

pwd-failure-count-interval(5dsconf)

pwd-grace-login-limit(5dsconf)

pwd-keep-last-auth-time-enabled(5dsconf)

pwd-lockout-duration(5dsconf)

pwd-lockout-enabled(5dsconf)

pwd-lockout-repl-priority-enabled(5dsconf)

pwd-max-age(5dsconf)

pwd-max-failure-count(5dsconf)

pwd-max-history-count(5dsconf)

pwd-min-age(5dsconf)

pwd-min-length(5dsconf)

pwd-mod-gen-length(5dsconf)

pwd-must-change-enabled(5dsconf)

pwd-root-dn-bypass-enabled(5dsconf)

pwd-safe-modify-enabled(5dsconf)

pwd-storage-scheme(5dsconf)

pwd-strong-check-dictionary-path(5dsconf)

pwd-strong-check-enabled(5dsconf)

pwd-strong-check-require-charset(5dsconf)

pwd-supported-storage-scheme(5dsconf)

pwd-user-change-enabled(5dsconf)

read-write-mode(5dsconf)

referral-mode(5dsconf)

referral-url(5dsconf)

ref-integrity-attr(5dsconf)

ref-integrity-check-delay(5dsconf)

ref-integrity-enabled(5dsconf)

repl-accept-client-update-enabled(5dsconf)

repl-agmt(5dsconf)

repl-cl-max-age(5dsconf)

repl-cl-max-entry-count(5dsconf)

repl-fractional-exclude-attr(5dsconf)

repl-fractional-include-attr(5dsconf)

replication(5dsconf)

repl-id(5dsconf)

repl-manager-bind-dn(5dsconf)

repl-priority(5dsconf)

replPriorityAttribute(5dsconf)

replPriorityBaseDN(5dsconf)

replPriorityBindDN(5dsconf)

ReplPriorityRule(5dsconf)

replPriorityType(5dsconf)

repl-purge-delay(5dsconf)

repl-rewrite-referrals-enabled(5dsconf)

repl-role(5dsconf)

repl-schedule(5dsconf)

repl-user-schema-enabled(5dsconf)

require-bind-pwd-enabled(5dsconf)

require-index-enabled(5dsconf)

retro-cl-deleted-entry-attr(5dsconf)

retro-cl-enabled(5dsconf)

retro-cl-ignored-attr(5dsconf)

retro-cl-max-age(5dsconf)

retro-cl-max-entry-count(5dsconf)

retro-cl-path(5dsconf)

retro-cl-suffix-dn(5dsconf)

root-dn(5dsconf)

root-pwd(5dsconf)

root-pwd-file(5dsconf)

root-pwd-storage-scheme(5dsconf)

rotation-interval(5dsconf)

rotation-min-file-size(5dsconf)

rotation-time(5dsconf)

search-size-limit(5dsconf)

search-time-limit(5dsconf)

secure-listen-address(5dsconf)

server(5dsconf)

ssl-cipher-family(5dsconf)

ssl-client-auth-mode(5dsconf)

ssl-enabled(5dsconf)

ssl-rsa-cert-name(5dsconf)

ssl-rsa-security-device(5dsconf)

ssl-supported-ciphers(5dsconf)

sub-enabled(5dsconf)

suffix(5dsconf)

system(5dsconf)

thread-count(5dsconf)

transport-compression(5dsconf)

transport-group-size(5dsconf)

transport-window-size(5dsconf)

type(5dsconf)

useAuthzIdForAuditAttrs(5dsconf)

vendor(5dsconf)

verbose-enabled(5dsconf)

version(5dsconf)

Directory Proxy Server Configuration

File Formats

LDAP Schema Collections

LDAP Schema Attribute Types

LDAP Schema Object Classes

Index

server

, check-schema-enabled

, check-syntax-enabled

, compat-flag

, config-magic-number

, db-batched-transaction-count

, db-cache-size

, db-checkpoint-interval

, db-env-path

, db-lock-count

, db-log-buf-size

, db-log-path

, def-repl-manager-pwd

, def-repl-manager-pwd-file

, dn-cache-count

, dn-cache-size

, dsml-answer-size

, dsml-buffer-size

, dsml-client-auth-mode

, dsml-enabled

, dsml-max-parser-count

, dsml-min-parser-count

, dsml-port

, dsml-relative-root-url

, dsml-request-max-size

, dsml-secure-port

, file-descriptor-count

, heap-high-threshold-size

, heap-low-threshold-size

, host-access-dir-path

, idle-timeout

, import-cache-size

, instance-path

, ldap-port

, ldap-secure-port

, listen-address

, look-through-limit

, max-psearch-count

, max-thread-count

, max-thread-per-connection-count

, mod-tracking-enabled

, polling-thread-count

, pwd-accept-hashed-pwd-enabled

, pwd-check-enabled

, pwd-compat-mode

, pwd-expire-no-warning-enabled

, pwd-expire-warning-delay

, pwd-failure-count-interval

, pwd-grace-login-limit

, pwd-keep-last-auth-time-enabled

, pwd-lockout-duration

, pwd-lockout-enabled

, pwd-lockout-repl-priority-enabled

, pwd-max-age

, pwd-max-failure-count

, pwd-max-history-count

, pwd-min-age

, pwd-min-length

, pwd-mod-gen-length

, pwd-must-change-enabled

, pwd-root-dn-bypass-enabled

, pwd-safe-modify-enabled

, pwd-storage-scheme

, pwd-strong-check-dictionary-path

, pwd-strong-check-enabled

, pwd-strong-check-require-charset

, pwd-supported-storage-scheme

, pwd-user-change-enabled

, read-write-mode

, ref-integrity-attr

, ref-integrity-check-delay

, ref-integrity-enabled

, repl-user-schema-enabled

, require-bind-pwd-enabled

, retro-cl-deleted-entry-attr

, retro-cl-enabled

, retro-cl-ignored-attr

, retro-cl-max-age

, retro-cl-max-entry-count

, retro-cl-path

, retro-cl-suffix-dn

, root-dn

, root-pwd

, root-pwd-file

, root-pwd-storage-scheme

, search-size-limit

, search-time-limit

, secure-listen-address

, ssl-cipher-family

, ssl-client-auth-mode

, ssl-enabled

, ssl-rsa-cert-name

, ssl-rsa-security-device

, ssl-supported-ciphers

, thread-count

- DS server instance configuration (SER) properties

Description

The behavior of a Directory Server instance is configured according to server properties documented here and in the documentation specified under the SEE ALSO section.

PROPERTY: check-schema-enabled

Syntax
on | off
Default Value
on
Is readable
Yes
Is modifiable
Yes
Is multi-valued
No

This property specifies whether the server checks that entries being updated still conform to the server schema.

PROPERTY: check-syntax-enabled

Syntax
on | off
Default Value
off
Is readable
Yes
Is modifiable
Yes
Is multi-valued
No

This property specifies whether the server checks that attribute values being updated have valid syntax. The server logs an error message when encountering an invalid value and prevents the update. When this property is set to on, the server checks updates to attribute values defined as Boolean, DN, Directory String, Generalized Time, IA5 String, INTEGER, or Telephone Number syntax. This behavior holds both for offline import and for normal write operations.

By default, syntax checking is off. When syntax checking is on, all import and update operations are checked. Directory Manager (directory super user) cannot bypass syntax checking.

Syntax is not checked on existing entries in the database. To clean up existing data, dump the database to LDIF, turn syntax checking on, and reload the database. Data that violates the syntax is visible in the errors log, and can be corrected and reloaded. You can also repair existing bad data by deleting or replacing the bad value using an LDAP client. If syntax checking is on, when a database is reloaded from LDIF, invalid syntax values are skipped and recorded in the errors log. Valid syntax values are reloaded.

PROPERTY: compat-flag

Syntax
none | no-rfc4511 | no-rfc4522
Default Value
none
Is readable
Yes
Is modifiable
Yes
Is multi-valued
Yes

Flag which forces server to behave as in previous releases, for compatibility reasons.

The following values are accepted:

Application requests
Directory Server 6 responds
Directory Server 7 responds (without no-rfc4522)
Directory Server 7 responds (with no-rfc4522)
userCertificate
userCertificate
userCertificate;binary
userCertificate
userCertificate;binary
userCertificate;binary
userCertificate;binary
userCertificate;binary

PROPERTY: config-magic-number

Syntax
STRING
Default Value
D-A00
Is readable
Yes
Is modifiable
No
Is multi-valued
No

This property specifies a value used by the Directory Server administration framework and tools to determine the capabilities of a server instance.

PROPERTY: db-batched-transaction-count

Syntax
INTEGER
Default Value
0
Is readable
Yes
Is modifiable
Yes
Is multi-valued
No

This property specifies how many server transactions are gathered into a batch before being written to the transaction log. If writes to the transaction log are a bottleneck, you may potentially improve performance by increasing this value. Valid range is 0-30, 0 meaning that batching is turned off.

PROPERTY: db-cache-size

Syntax
MEMORY_SIZE
Default Value
32M
Is readable
Yes
Is modifiable
Yes
Is multi-valued
No

This property specifies the amount of physical memory Directory Server requests from the operating system to cache indexes for all suffixes supported by the server instance. See Directory Server Data Caching in Directory Server Enterprise Edition Reference for suggestions on sizing cache.

PROPERTY: db-checkpoint-interval

Syntax
DURATION
Default Value
60s
Is readable
Yes
Is modifiable
Yes
Is multi-valued
No

This property specifies the interval between checkpoints recorded in the database transaction log.

PROPERTY: db-env-path

Syntax
PATH
Default Value
instance-path/db
Is readable
Yes
Is modifiable
Yes
Is multi-valued
No

This property specifies a valid directory, unique to the server instance. There must be enough space available on the file system to house at least the actual size of the database cache.

When changing this property, you must stop the server, delete the existing database, and reimport all suffixes from LDIF, before restarting the server.

PROPERTY: db-lock-count

Syntax
INTEGER
Default Value
20000
Is readable
Yes
Is modifiable
Yes
Is multi-valued
No

This property specifies the number of locks available to the server instance database. Increase this value if you observe the following message in the errors log:

libdb: Lock table is out of available locks

PROPERTY: db-log-buf-size

Syntax
MEMORY_SIZE
Default Value
512k
Is readable
Yes
Is modifiable
Yes
Is multi-valued
No

This property specifies the transaction log buffer size. Valid range is 0 to the size of the transaction log, which is 10M by default.

After changing this property, you must restart the server in order to take the change into account.

PROPERTY: db-log-path

Syntax
PATH
Default Value
instance-path/db
Is readable
Yes
Is modifiable
Yes
Is multi-valued
No

This property specifies the file system directory containing the database transaction log.

When changing this property, you must stop the server, delete the existing database, and reimport all suffixes from LDIF, before restarting the server.

PROPERTY: def-repl-manager-pwd

Syntax
STRING
Default Value
See the description that follows.
Is readable
Yes
Is modifiable
No
Is multi-valued
No

This property lets you read the password used for replication binds performed using simple authentication. Either you specify the password before setting up replication by setting def-repl-manager-pwd-file to specify the file containing the password you want to use, or you accept the password value generated by the dsconf accord-replication subcommand.

PROPERTY: def-repl-manager-pwd-file

Syntax
PATH | ""
Default Value
""
Is readable
No
Is modifiable
Yes
Is multi-valued
No

This property specifies the file from which the default replication password is read and stored for future use when setting up replication.

PROPERTY: dn-cache-count

Syntax
INTEGER | unlimited | disabled
Default Value
unlimited
Is readable
Yes
Is modifiable
Yes
Is multi-valued
No

This property specifies the size of the DN cache in terms of number of entries. The value of dn-cache-count is unlimited by default. The value of dn-cache-count can be an integer, unlimited, and disabled and each of these has the following effect on dn-cache-size.

Changing this property requires you to restart the server.

PROPERTY: dn-cache-size

Syntax
MEMORY_SIZE
Default Value
10M
Is readable
Yes
Is modifiable
Yes
Is multi-valued
No

This property specifies the size of the DN cache in terms of memory space. This property is set by default. The cache size must be larger than 1M. The DN cache size specified for this property is taken into account only when dn-cache-count is set to unlimited.

Changing this property requires you to restart the server.

PROPERTY: dsml-answer-size

Syntax
MEMORY_SIZE
Default Value
64k
Is readable
Yes
Is modifiable
Yes
Is multi-valued
No

This property specifies the maximum size of a server response to a DSML request. Larger responses are chunked.

PROPERTY: dsml-buffer-size

Syntax
MEMORY_SIZE
Default Value
8k
Is readable
Yes
Is modifiable
Yes
Is multi-valued
No

This property specifies the size of the buffer used to store DSML requests. If the server receives many DSML requests larger than this limit, increase the buffer size.

PROPERTY: dsml-client-auth-mode

Syntax
clientCertOnly | httpBasicOnly | clientCertFirst
Default Value
httpBasicOnly
Is readable
Yes
Is modifiable
Yes
Is multi-valued
No

This property specifies how the server identifies a client application. The following settings are supported.

clientCertOnly

Use credentials from the client certificate to identify the client.

httpBasicOnly

Use credentials from the HTTP authorization header to identify the client.

clientCertFirst

Attempt to use the client certificate credentials to identify the client. If there are no client certificate credentials, credentials from the HTTP authorization header are used.

PROPERTY: dsml-enabled

Syntax
on | off
Default Value
off
Is readable
Yes
Is modifiable
Yes
Is multi-valued
No

This property specifies whether the server accepts DSML requests.

PROPERTY: dsml-max-parser-count

Syntax
INTEGER
Default Value
5
Is readable
Yes
Is modifiable
Yes
Is multi-valued
No

This property specifies the maximum number of DSML parsers allocated to handle client requests. Increase the value of this property if the server must handle sustained, high numbers of DSML client requests.

PROPERTY: dsml-min-parser-count

Syntax
INTEGER
Default Value
10
Is readable
Yes
Is modifiable
Yes
Is multi-valued
No

This property specifies the minimum number of DSML parsers allocated to handle client requests. Increase the value of this property if the server must handle sustained, high numbers of DSML client requests.

PROPERTY: dsml-port

Syntax
INTEGER | disabled
Default Value
disabled
Is readable
Yes
Is modifiable
Yes
Is multi-valued
No

This property specifies the port number on which the server listens for DSML requests. Changing the value requires that you restart the server.

PROPERTY: dsml-relative-root-url

Syntax
STRING
Default Value
/dsml
Is readable
Yes
Is modifiable
Yes
Is multi-valued
No

This property specifies the root URL HTTP clients should specify in their POST requests.

PROPERTY: dsml-request-max-size

Syntax
MEMORY_SIZE
Default Value
32k
Is readable
Yes
Is modifiable
Yes
Is multi-valued
No

This property specifies the maximum size for DSML client requests.

PROPERTY: dsml-secure-port

Syntax
INTEGER | disabled
Default Value
disabled
Is readable
Yes
Is modifiable
Yes
Is multi-valued
No

This property specifies the port number on which the server listens for DSML requests over HTTPS. Changing the value requires that you restart the server.

PROPERTY: file-descriptor-count

Syntax
INTEGER
Default Value
1024
Is readable
Yes
Is modifiable
Yes
Is multi-valued
No

This property specifies the maximum number of file descriptors the server instance attempts to use to handle client requests. Increase this value if you observe the following message in the errors log:

Not listening for new connections -- too many fds open

PROPERTY: heap-high-threshold-size

Syntax
MEMORY_SIZE | undefined
Default Value
undefined
Is readable
Yes
Is modifiable
Yes
Is multi-valued
No

This property specifies a threshold value for the dynamic memory footprint. When the threshold memory is reached, Directory Server attempts to free memory from the entry caches, and to limit memory use.

heap-high-threshold-size and heap-low-threshold-size must be configured in conjunction with each other, as follows.

The number of times the memory thresholds have been exceeded can be monitored by using the heapmaxhighhits and heapmaxlowhits attributes on cn=monitor.

PROPERTY: heap-low-threshold-size

Syntax
MEMORY_SIZE | undefined
Default Value
undefined
Is readable
Yes
Is modifiable
Yes
Is multi-valued
No

See the description for heap-high-threshold-size.

PROPERTY: host-access-dir-path

Syntax
PATH | ""
Default Value
""
Is readable
Yes
Is modifiable
Yes
Is multi-valued
No

This property specifies the local directory path on the server host where hosts.allow and hosts.deny files are located. If this property is not set, or if the files are not found, Directory Server does not enable the additional connection-based access controls provided by these files.

PROPERTY: idle-timeout

Syntax
INTEGER | none
Default Value
none
Is readable
Yes
Is modifiable
Yes
Is multi-valued
No

This property specifies how many seconds the server waits for traffic on an idle LDAP client connection before closing the connection.

PROPERTY: import-cache-size

Syntax
MEMORY_SIZE
Default Value
64M
Is readable
Yes
Is modifiable
Yes
Is multi-valued
No

This property specifies the amount of physical memory Directory Server requests from the operating system to cache data used when initializing a suffix from LDIF. See Directory Server Data Caching in Directory Server Enterprise Edition Reference for suggestions on sizing cache.

PROPERTY: instance-path

Syntax
PATH
Default Value
Path set at server creation
Is readable
Yes
Is modifiable
No
Is multi-valued
No

This property specifies the file system directory under which the server instance was created using the dsadm create command.

PROPERTY: ldap-port

Syntax
INTEGER | disabled
Default Value
389 | 1389
Is readable
Yes
Is modifiable
Yes
Is multi-valued
No

This property specifies the port on which the server listens for LDAP client requests. The default port is 389 when the instance is created by the system super user, 1389 otherwise. Changing this property requires that you restart the server.

If you set both ldap-port and ldap-secure-port to disabled, you can no longer use dsconf to configure the server.

PROPERTY: ldap-secure-port

Syntax
INTEGER | disabled
Default Value
636 | 1636
Is readable
Yes
Is modifiable
Yes
Is multi-valued
No

This property specifies the port on which the server listens for LDAPS client requests using TLS or SSL. The default port is 636 when the instance is created by the system super user, 1636 otherwise. Changing this property requires that you restart the server.

If you set both ldap-port and ldap-secure-port to disabled, you can no longer use dsconf to configure the server.

PROPERTY: listen-address

Syntax
STRING
Default Value
0.0.0.0
Is readable
Yes
Is modifiable
Yes
Is multi-valued
Yes

This property specifies the IP address at which the server listens for LDAP client requests using the regular LDAP port. You can specify more than one listen address for the same port number. The default listen address is 0.0.0.0. Changing this property requires that you restart the server.

PROPERTY: look-through-limit

Syntax
INTEGER | unlimited
Default Value
5000
Is readable
Yes
Is modifiable
Yes
Is multi-valued
No

This property specifies the maximum number of entries the server examines when checking candidates to respond to a search request.

PROPERTY: max-psearch-count

Syntax
INTEGER
Default Value
30
Is readable
Yes
Is modifiable
Yes
Is multi-valued
No

This property specifies the maximum number persistent searches allowed. You can read the number of active persistent searches in the value of currentpsearches on cn=monitor.

PROPERTY: max-thread-count

Syntax
INTEGER
Default Value
30
Is readable
Yes
Is modifiable
Yes
Is multi-valued
No

This property specifies the number of threads created at startup to process operations. When tuning server performance, try setting this to twice the number of processors or 20 plus the number of simultaneous updates expected. You can read the number of active threads in the value of threads on cn=monitor.

PROPERTY: max-thread-per-connection-count

Syntax
INTEGER
Default Value
5
Is readable
Yes
Is modifiable
Yes
Is multi-valued
No

This property specifies the maximum number of concurrent threads used to process operations on a single connection.

PROPERTY: mod-tracking-enabled

Syntax
on | off
Default Value
on
Is readable
Yes
Is modifiable