Skip to Content
Sun and Oracle
Channel Sun
How to Buy
Log In
Português brasileiro
Início
>
Sun Java System Directory Server Enterprise Edition 6.0
> Sun Java System Directory Server Enterprise Edition 6.0 Administration Guide
Sun Java System Directory Server Enterprise Edition 6.0 Administration Guide
Procure somente este livro
Pesquisar Ajuda
Exibir este livro em:
Outros Idiomas
日本語
한국어
简体中文
繁體中文
Contidos dentro
Sun Java System Directory Server Enterprise Edition 6.0
Localizar Mais Documentação
Explorar títulos da documentação
Explorar documentação do produto
Destaques de Recursos de Suporte
Cursos de Treinamento da Sun
Portal BigAdmin System Admin
Central de Suporte da Sun
Sun Solve
Fazer download desta apostila em PDF (3974 KB)
Sun Java System Directory Server Enterprise Edition 6.0 Administration Guide
Index
A
B
C
D
E
F
G
I
J
K
L
M
N
O
P
R
S
T
U
V
Book Information
Preface
Who Should Use This Book
Before You Read This Book
How This Book Is Organized
Examples used in this Guide
Directory Server Enterprise Edition Documentation Set
Related Reading
Redistributable Files
Default Paths and Command Locations
Typographic Conventions
Shell Prompts in Command Examples
Symbol Conventions
Documentation, Support, and Training
Third-Party Web Site References
Searching Sun Product Documentation
Sun Welcomes Your Comments
Directory Server Administration
1. Directory Server Tools
Directory Server Administration Overview
Deciding When to Use DSCC and When to Use the Command Line
Directory Service Control Center Interface
Administration Users for DSCC
To Access DSCC
DSCC Tabs Description
DSCC Online Help
Directory Server Command-Line Tools
2. Directory Server Instances and Suffixes
Quick Procedure for Creating Server Instances and Suffixes
Creating and Deleting a Directory Server Instance
To Create a Directory Server Instance
To Delete a Directory Server Instance
Starting, Stopping, and Restarting a Directory Server Instance
To Start, Stop, and Restart Directory Server
Creating Suffixes
To Create a Suffix
Disabling or Enabling a Suffix
To Disable then Enable a Suffix
Setting Referrals and Making a Suffix Read-Only
To Set Referrals to Make a Suffix Read-Only
Deleting a Suffix
To Delete a Suffix
3. Directory Server Configuration
Modifying the Configuration Using DSCC
Modifying the Configuration From the Command Line
Modifying the dse.ldif File
Configuring Administration Users
To Create an Administration User with Root Access
To Configure the Directory Manager
Protecting Configuration Information
Configuring DSCC
To Change the Common Agent Container Port Number
To Reset the Directory Service Manager Password
To Extend the DSCC Session Automatic Timeout Delay
Configuring Failover for DSCC
Troubleshooting DSCC
Changing Directory Server Port Numbers
To Modify a Port Number, Enable a Port, and Disable a Port
Configuring DSML
To Enable the DSML-over-HTTP Service
To Disable the DSML-over-HTTP Service
To Configure DSML Security
DSML Identity Mapping
Setting the Server as Read-Only
To Enable or Disable the Server Read-Only Mode
Configuring Memory
Priming Caches
To Modify Database Cache
To Monitor Database Cache
To Monitor Database Cache
To Monitor Entry Cache
To Modify Entry Cache
To Configure Heap Memory Threshold
Setting Resource Limits For Each Client Account
To View Server Resource Limit Settings
To Set the Look-Through Limit for an Account
To Set the Size Limit for an Account
To Set the Time Limit for an Account
To Set the Idle Timeout for an Account
4. Directory Server Entries
Managing Entries
Managing Entries Using DSCC
Managing Entries Using Directory Editor
Managing Entries ldapmodify and ldapdelete
To Move or Rename an Entry Using ldapmodify
Guidelines and Limitations for Using the Modify DN Operation
Setting Referrals
Checking Valid Attribute Syntax
To Turn Off Automatic Syntax Checking
Tracking Modifications to Directory Entries
To Turn Off Entry Modification Tracking
Encrypting Attribute Values
Attribute Encryption and Performance
Attribute Encryption Usage Considerations
To Configure Attribute Encryption
5. Directory Server Security
Using SSL With Directory Server
Managing Certificates
To View the Default Self-Signed Certificate
To Manage Self-Signed Certificates
To Request a CA-Signed Server Certificate
To Add the CA-Signed Server Certificate and the Trusted CA Certificate
To Renew an Expired CA-Signed Server Certificate
To Export and Import a CA-Signed Server Certificate
Configuring the Certificate Database Password
Backing Up and Restoring the Certificate Database for Directory Server
Configuring SSL Communication
Configuring Client Authentication
Configuring LDAP Clients to Use Security
Pass-Through Authentication
6. Directory Server Access Control
Creating, Viewing, and Modifying ACIs
To Create, Modify, and Delete ACIs
To View ACI Attribute Values
To View ACIs at the Root Level
Access Control Usage Examples
Viewing Effective Rights
Advanced Access Control: Using Macro ACIs
Logging Access Control Information
To Set Logging for ACIs
Client-Host Access Control Through TCP Wrapping
To Enable TCP Wrapping
To Disable TCP Wrapping
7. Directory Server Password Policy
Password Policies and Worksheet
Managing the Default Password Policy
Correlation Between Password Policy Attributes and dsconf Server Properties
To View Default Password Policy Settings
To Change Default Password Policy Settings
Managing Specialized Password Policies
Which Password Policy Applies
To Create a Password Policy
To Assign a Password Policy to an Individual Account
To Assign a Password Policy Using Roles and CoS
To Set Up a First Login Password Policy
Modifying Passwords From the Command Line When pwdSafeModify Is TRUE
Resetting Expired Passwords
To Reset a Password With the Password Modify Extended Operation
To Allow Grace Authentications When Passwords Expire
Manually Locking Accounts
To Check Account Status
To Render Accounts Inactive
To Reactivate Accounts
8. Directory Server Backup and Restore
Binary Backup
Backing Up to LDIF
Binary Restore
To Restore Your Server
Restoring the dse.ldif Configuration File
Importing Data From an LDIF File
Restoring Replicated Suffixes
Disaster Recovery
To Make a Backup for Disaster Recovery
To Restore for Disaster Recovery
9. Directory Server Groups, Roles, and CoS
About Groups, Roles, and Class of Service
Managing Groups
To Create a New Static Group
To Create a New Dynamic Group
Managing Roles
Class of Service
Maintaining Referential Integrity
How Referential Integrity Works
To Configure the Referential Integrity Plug-In
10. Directory Server Replication
Planning Your Replication Deployment
Recommended Interface for Configuring and Managing Replication
Summary of Steps for Configuring Replication
Summary of Steps for Configuring Replication
Enabling Replication on a Dedicated Consumer
To Create a Suffix for a Consumer Replica
To Enable a Consumer Replica
To Perform Advanced Consumer Configuration
Enabling Replication on a Hub
To Create a Suffix for a Hub Replica
To Enable a Hub Replica
To Modify Change Log Settings on a Hub Replica
Enabling Replication on a Master Replica
To Create a Suffix for a Master Replica
To Enable a Master Replica
To Modify Change Log Settings on a Master Replica
Configuring the Replication Manager
Using a Non-Default Replication Manager
To Change the Default Replication Manager Password
Creating Replication Agreements
To Create a Replication Agreement
Fractional Replication
Considerations for Fractional Replication
To Configure Fractional Replication
Replication Priority
To Configure Replication Priority
Initializing Replicas
To Initialize a Replicated Suffix from a Remote (Supplier) Server
Replica Initialization From LDIF
Initializing a Replicated Suffix by Using Binary Copy
Initializing Replicas in Cascading Replication
Indexing Replicated Suffixes
Incrementally Adding Many Entries to Large Replicated Suffixes
To Add Many Entries to Large Replicated Suffixes
Replication and Referential Integrity
Replication Over SSL
To Configure Replication Operations for SSL
Replication Over a WAN
Modifying the Replication Topology
Replication With Releases Prior to Directory Server 6.0
Using the Retro Change Log
To Enable the Retro Change Log
To Configure the Retro Change Log to Record Updates for Specified Suffixes
To Configure the Retro Change Log to Record Attributes of a Deleted Entry
To Trim the Retro Change Log
Accessing Control and the Retro Change Log
Getting Replication Status
Solving Common Replication Conflicts
11. Directory Server Schema
Managing Schema Checking
To Fix Schema Compliance Problems
About Custom Schema
Managing Attribute Types Over LDAP
Creating Attribute Types
Viewing Attribute Types
Deleting Attribute Types
To Delete Attribute Types
Managing Object Classes Over LDAP
Extending Directory Server Schema
Replicating Directory Schema
12. Directory Server Indexing
Managing Indexes
To List Indexes
To Create Indexes
To Modify Indexes
To Generate Indexes
To Delete Indexes
Changing the Index List Threshold
Reindexing a Suffix
Managing Browsing Indexes
13. Directory Server Attribute Value Uniqueness
Overview of Attribute Value Uniqueness
Enforcing Uniqueness of the uid and Other Attributes
To Enforce Uniqueness of the uid Attribute
To Enforce Uniqueness of Another Attribute
Using the Uniqueness Plug-In With Replication
14. Directory Server Logging
Log Analysis Tool
Viewing Directory Server Logs
Configuring Logs for Directory Server
To Modify Log Configuration
To Enable the Audit Log
Rotating Directory Server Logs Manually
To Rotate Log Files Manually
15. Directory Server Monitoring
Setting Up SNMP for Directory Server
To Set Up SNMP
Enabling Java ES MF Monitoring
To Enable Java ES MF Monitoring
Troubleshooting Java ES MF Monitoring
Monitoring a Server Using cn=monitor
Directory Proxy Server Administration
16. Directory Proxy Server Tools
Using DSCC for Directory Proxy Server
To Access DSCC for Directory Proxy Server
Command-Line Tools for Directory Proxy Server
17. Directory Proxy Server Instances
Creating and Deleting a Directory Proxy Server Instance
To Create a Directory Proxy Server Instance
To Delete a Directory Proxy Server Instance
Finding the Status of a Directory Proxy Server Instance
To Find the Status of a Directory Proxy Server Instance
Starting, Stopping, and Restarting a Directory Proxy Server Instance
To Start and Stop Directory Proxy Server
To View Whether It Is Necessary to Restart a Directory Proxy Server Instance
To Restart Directory Proxy Server
18. Directory Proxy Server Configuration
Modifying the Configuration of Directory Proxy Server
To Modify the Configuration of Directory Proxy Server
Backing Up and Restoring a Directory Proxy Server Instance
To Back Up a Directory Proxy Server Instance
To Restore a Directory Proxy Server Instance
Configuring the Proxy Manager
To Configure the Proxy Manager
Configuration Changes Requiring Server Restart
Accessing Configuration Entries for a Directory Server by Using Directory Proxy Server
To Access the Configuration Entries of a Directory Server by Using Directory Proxy Server
19. Directory Proxy Server Certificates
Default Self-Signed Certificate
Viewing the Default Self-Signed Certificate
Creating, Requesting and Installing Certificates for Directory Proxy Server
To Create a Non-default Self-Signed Certificate for Directory Proxy Server
To Request a CA-Signed Certificate for Directory Proxy Server
To Install a CA-Signed Server Certificate for Directory Proxy Server
Renewing an Expired CA-Signed Certificate for Directory Proxy Server
To Renew an Expired CA-Signed Server Certificate for Directory Proxy Server
Listing Certificates
To List Server Certificates
To List CA Certificates
Adding a Certificate From a Back-End LDAP Server to the Certificate Database on Directory Proxy Server
To Add a Certificate From a Back-End Directory Server to the Certificate Database on Directory Proxy Server
Exporting a Certificate to a Back-End LDAP Server
To Configure Directory Proxy Server to Export a Client Certificate to a Back-End LDAP Server
Backing Up and Restoring a Certificate Database for Directory Proxy Server
Prompting for a Password to Access the Certificate Database
To Prompt for a Password to Access the Certificate Database
To Disable the Password Prompt to Access the Certificate Database
20. LDAP Data Sources and Data Source Pools
Creating and Configuring LDAP Data Sources
To Create an LDAP Data Source
To Configure an LDAP Data Source
Creating and Configuring LDAP Data Source Pools
To Create an LDAP Data Source Pool
To Configure an LDAP Data Source Pool
Attaching LDAP Data Sources to a Data Source Pool
To Attach an LDAP Data Source to a Data Source Pool
21. Connections Between Directory Proxy Server and Back-End LDAP Servers
Configuring Connections Between Directory Proxy Server and Back-End LDAP Servers
To Configure the Number of Connections Between Directory Proxy Server and Back-End LDAP Servers
To Configure Connection Timeout
To Configure Connection Pool Wait Timeout
Configuring SSL Between Directory Proxy Server and Back-End LDAP Servers
To Configure SSL Between Directory Proxy Server and a Back-End LDAP Server
Choosing SSL Ciphers and SSL Protocols for Directory Proxy Server
To Choose the List of Ciphers and Protocols
Forwarding Requests to Back-End LDAP Servers
22. Directory Proxy Server Load Balancing and Client Affinity
Configuring Load Balancing
To Select a Load Balancing Algorithm
To Configure Weights for Load Balancing
Example Configurations for Load Balancing
Configuring Client Affinity
To Configure Client Affinity
Example Configurations for Client Affinity
23. Directory Proxy Server Data Views
Creating and Configuring LDAP Data Views
To Create an LDAP Data View
To Configure an LDAP Data View
Renaming Attributes and DNs
To Configure Attribute Renaming
To Configure DN Renaming
Configuring excluded-subtrees and alternate-search-base-dn
To Manually Configure the excluded-subtrees and alternate-search-base-dn Properties
Creating and Configuring Data Views for Example Use Cases
24. Directory Proxy Server Virtual Data Views
Creating and Configuring LDIF Data Views
To Create an LDIF Data View
To Configure an LDIF Data View
Configuring Virtual Data Transformations
To Add a Virtual Transformation
Creating and Configuring Join Data Views
To Create a Join Data View
To Configure a Join Data View
To Configure the Secondary View of a Join View
Creating and Configuring JDBC Data Views
To Create a JDBC Data View
To Configure a JDBC Data View
To Configure JDBC Tables, Attributes, and Object Classes
Defining Relationships Between JDBC Tables
Defining Access Control on Virtual Data Views
To Define a New ACI Storage Repository
To Configure Virtual Access Controls
Defining Schema Checking on Virtual Data Views
To Define Schema Checking
Sample Virtual Configurations
25. Directory Proxy Server Connection Handlers
Creating, Configuring, and Deleting Connection Handlers
To Create a Connection Handler
To Configure a Connection Handler
To Delete a Connection Handler
To Configure Affinity for Data Views
Creating and Configuring Request Filtering Policies and Search Data Hiding Rules
To Create a Request Filtering Policy
To Configure a Request Filtering Policy
To Create Search Data Hiding Rules
Example Request Filtering Policy and Search Data Hiding Rule
Creating and Configuring a Resource Limits Policy
To Create a Resource Limits Policy
To Configure a Resource Limits Policy
To Customize Search Limits
Configuring Directory Proxy Server as a Connection Based Router
To Configure Directory Proxy Server as a Connection Based Router
26. Connections Between Clients and Directory Proxy Server
Configuring Listeners Between Clients and Directory Proxy Server
To Configure the Listeners Between a Client and Directory Proxy Server
Authenticating Clients to Directory Proxy Server
To Configure Certificate-based Authentication
To Configure Anonymous Access
To Configure Directory Proxy Server for SASL External Bind
27. Directory Proxy Server Logging
Viewing Directory Proxy Server Logs
Configuring Directory Proxy Server Logs
To Configure Directory Proxy Server Access and Error Logs
Configuring Directory Proxy Server Log Rotation
To Configure Periodic Rotation of Access and Error Logs
To Rotate Access and Error Logs Files Manually
To Disable Access and Error Log Rotation
Example Configurations for Log Rotation
Deleting Directory Proxy Server Logs
To Configure Access and Error Log Deletion Based on Time
To Configure Access and Error Log Deletion Based on File Size
To Configure Access and Error Log Deletion Based on Free Disk Space
Logging Alerts to the syslogd Daemon
To Configure Directory Proxy Server to Log Alerts to the syslogd Daemon
Configuring the Operating System to Accept syslog Alerts
Tracking Client Requests Through Directory Proxy Server and Directory Server Access Logs
To Track Operations From Directory Server Through Directory Proxy Server to the Client Application
28. Directory Proxy Server Monitoring and Alerts
Retrieving Monitored Data About Directory Proxy Server
Retrieving Monitored Data About Data Sources
To Monitor a Data Source by Listening for Errors
To Monitor a Data Source by Periodically Establishing Dedicated Connections
To Monitor a Data Source by Testing Established Connections
Configuring Administrative Alerts for Directory Proxy Server
To Enable Administrative Alerts
To Configure Administrative Alerts to Be Sent to Syslog
To Configure Administrative Alerts to Be Sent to Email
To Configure Administrative Alerts to Run a Script
Retrieving Monitored Data About Directory Proxy Server by Using the JVM
To View the Heap Size of the JVM
To Monitor the Heap Size of JVM When Directory Proxy Server is Running
News Center
About Sun
Contact Sun
Terms of Use
Privacy
Copyright
1994-2009
Sun Microsystems, Inc.