JavaScript is required to for searching.
Skip Navigation Links
Exit Print View
Oracle Directory Server Enterprise Edition Upgrade and Migration Guide 11 g Release 1 (11.1.1.5.0)
search filter icon
search icon

Document Information

Preface

1.  Upgrading and Migrating to Directory Server Enterprise Edition to Version 11g Release 1 (11.1.1.5.0)

Upgrade and Migration Paths

Part I Patching Directory Server Enterprise Edition 7 to 11g Release 1 (11.1.1.5.0)

2.  Patching Directory Server Enterprise Edition 7 to Version 11g Release 1 (11.1.1.5.0)

Part II Upgrading Directory Server Enterprise Edition 6 to 11g Release 1 (11.1.1.5.0)

3.  Upgrading Directory Server Enterprise Edition 6 to Version 11g Release 1 (11.1.1.5.0)

Part III Migrating Directory Server Enterprise Edition 5.2 to Version 11g Release 1 (11.1.1.5.0)

4.  Overview of the Migration Process for Directory Server

5.  Automated Migration Using the dsmig Command

6.  Migrating Directory Server Manually

7.  Migrating a Replicated Topology

8.  Architectural Changes in Directory Server Since Version 5.2

Changes in the Administration Framework

Removal of the ServerRoot Directory

Removal of the o=netscapeRoot Suffix

Changes to ACIs

Changes in the ACI Scope

Changes in Suffix-Level ACIs

Command Line Changes

Changes to the Console

Password Policy

Changes to Plug-Ins

New Plug-Ins

Changes to the Plug-In API

Changes to the Installed Product Layout

Administration Utilities Previously Under ServerRoot

Binaries Previously Under ServerRoot/bin

Libraries and Plug-Ins Previously Under ServerRoot/lib

Online Help Previously Under ServerRoot/manual

Plug-Ins Previously Under ServerRoot/plugins

Utilities Previously Under ServerRoot/shared/bin

Certificate and Key Files

Silent Installation and Uninstallation Templates

Server Instance Scripts Previously Under ServerRoot/slapd-ServerID

Server Instance Subdirectories

9.  Migrating Directory Proxy Server

10.  Migrating Identity Synchronization for Windows

Index

Password Policy

Directory Server11g Release 1 (11.1.1.5.0) implements a password policy that uses the standard object class and attributes described in the “Password Policy for LDAP Directories” Internet-Draft.

The password policy provides the following new features:

In addition, the password policy provides the following controls:

These controls enable LDAP clients to obtain account status information.

The LDAP_CONTROL_PWP control provides account status information on LDAP bind, search, modify, add, delete, modDN, and compare operations.

The following information is available, using the OID 1.3.6.1.4.1.42.2.27.8.5.1 in the search:

The LDAP_CONTROL_PWP control indicates warning and error conditions. The control value is a BER octet string, with the format {tii}, which has the following meaning:

pwp_resp_no_error (-1)
pwp_resp_expired_error (0)
pwp_resp_locked_error (1)
pwp_resp_need_change_error (2)
pwp_resp_mod_not_allowed_error (3)
pwp_resp_give_old_error (4)
pwp_resp_bad_qa_error (5)
pwp_resp_too_short_error (6)
pwp_resp_too_young_error (7)
pwp_resp_in_hist_error (8)

The LDAP_CONTROL_ACCOUNT_USABLE control provides account status information on LDAP search operations only.

For information about password policy compatibility issues, see Oracle Directory Server Enterprise Edition Administration Guide