1DSCONF(8)                   Generated Python Manual                  DSCONF(8)
2
3
4

NAME

6       dsconf
7

SYNOPSIS

9       dsconf  [-h] [-v] [-D BINDDN] [-w BINDPW] [-W] [-y PWDFILE] [-b BASEDN]
10       [-Z]   [-j]   instance   {backend,backup,chaining,config,directory_man‐
11       ager,monitor,plugin,pwpolicy,localpwp,replication,repl,repl-agmt,repl-
12       winsync-agmt,repl-tasks,sasl,security,schema,repl-conflict} ...
13
14

POSITIONAL ARGUMENTS

16       dsconf backend
17              Manage database suffixes and backends
18
19       dsconf backup
20              Manage online backups
21
22       dsconf chaining
23              Manage database chaining and database links
24
25       dsconf config
26              Manage the server configuration
27
28       dsconf directory_manager
29              Manage the Directory Manager account
30
31       dsconf monitor
32              Monitor the state of the instance
33
34       dsconf plugin
35              Manage plug-ins available on the server
36
37       dsconf pwpolicy
38              Manage the global password policy settings
39
40       dsconf localpwp
41              Manage the local user and subtree password policies
42
43       dsconf replication
44              Manage replication for a suffix
45
46       dsconf repl-agmt
47              Manage replication agreements
48
49       dsconf repl-winsync-agmt
50              Manage Winsync agreements
51
52       dsconf repl-tasks
53              Manage replication tasks
54
55       dsconf sasl
56              Manage SASL mappings
57
58       dsconf security
59              Manage security settings
60
61       dsconf schema
62              Manage the directory schema
63
64       dsconf repl-conflict
65              Manage replication conflicts
66
67

COMMAND 'dsconf backend'

69       usage: dsconf instance backend [-h]
70                                      {suffix,index,vlv-index,attr-en‐
71       crypt,config,monitor,import,export,create,delete,get-tree,compact-db}
72                                      ...
73
74

POSITIONAL ARGUMENTS 'dsconf backend'

76       dsconf backend suffix
77              Manage backend suffixes
78
79       dsconf backend index
80              Manage backend indexes
81
82       dsconf backend vlv-index
83              Manage VLV searches and indexes
84
85       dsconf backend attr-encrypt
86              Manage encrypted attribute settings
87
88       dsconf backend config
89              Manage the global database configuration settings
90
91       dsconf backend monitor
92              Displays global database or suffix monitoring information
93
94       dsconf backend import
95              Online import of a suffix
96
97       dsconf backend export
98              Online export of a suffix
99
100       dsconf backend create
101              Create a backend database
102
103       dsconf backend delete
104              Delete a backend database
105
106       dsconf backend get-tree
107              Display the suffix tree
108
109       dsconf backend compact-db
110              Compact the database and the replication changelog
111
112

COMMAND 'dsconf backend suffix'

114       usage: dsconf instance backend suffix [-h]
115                                             {list,get,get-dn,get-sub-suf‐
116       fixes,set}
117                                             ...
118
119

POSITIONAL ARGUMENTS 'dsconf backend suffix'

121       dsconf backend suffix list
122              List active backends and suffixes
123
124       dsconf backend suffix get
125              Display the suffix entry
126
127       dsconf backend suffix get-dn
128              Display the DN of a backend
129
130       dsconf backend suffix get-sub-suffixes
131              Display sub-suffixes
132
133       dsconf backend suffix set
134              Set configuration settings for a specific backend
135
136

COMMAND 'dsconf backend suffix list'

138       usage: dsconf instance backend suffix list [-h] [--suffix]
139                                                  [--skip-subsuffixes]
140
141

OPTIONS 'dsconf backend suffix list'

143       --suffix
144              Displays the suffixes without backend name
145
146
147       --skip-subsuffixes
148              Displays the list of suffixes without sub-suffixes
149
150

COMMAND 'dsconf backend suffix get'

152       usage: dsconf instance backend suffix get [-h] [selector]
153
154
155       selector
156              The backend database name to search for
157
158

COMMAND 'dsconf backend suffix get-dn'

160       usage: dsconf instance backend suffix get-dn [-h] [dn]
161
162
163       dn     The DN  to  the  database  entry  in  cn=ldbm  database,cn=plug‐
164              ins,cn=config
165
166

COMMAND 'dsconf backend suffix get-sub-suffixes'

168       usage:  dsconf instance backend suffix get-sub-suffixes [-h] [--suffix]
169       be_name
170
171
172       be_name
173              The backend name or suffix
174
175

OPTIONS 'dsconf backend suffix get-sub-suffixes'

177       --suffix
178              Displays the list of suffixes without backend name
179
180

COMMAND 'dsconf backend suffix set'

182       usage: dsconf instance backend suffix set [-h] [--enable-readonly]
183                                                 [--disable-readonly]
184                                                 [--enable-orphan]     [--dis‐
185       able-orphan]
186                                                 [--require-index]      [--ig‐
187       nore-index]
188                                                 [--add-referral ADD_REFERRAL]
189                                                 [--del-referral DEL_REFERRAL]
190                                                 [--enable] [--disable]
191                                                 [--cache-size CACHE_SIZE]
192                                                 [--cache-memsize   CACHE_MEM‐
193       SIZE]
194                                                 [--dncache-memsize
195       DNCACHE_MEMSIZE]
196                                                 [--state STATE]
197                                                 be_name
198
199
200       be_name
201              The backend name or suffix
202
203

OPTIONS 'dsconf backend suffix set'

205       --enable-readonly
206              Enables read-only mode for the backend database
207
208
209       --disable-readonly
210              Disables read-only mode for the backend database
211
212
213       --enable-orphan
214              Disconnect a subsuffix from its parent suffix.
215
216
217       --disable-orphan
218              Let the subsuffix be connected to its parent suffix.
219
220
221       --require-index
222              Allows only indexed searches
223
224
225       --ignore-index
226              Allows all searches even if they are unindexed
227
228
229       --add-referral ADD_REFERRAL
230              Adds an LDAP referral to the backend
231
232
233       --del-referral DEL_REFERRAL
234              Removes an LDAP referral from the backend
235
236
237       --enable
238              Enables the backend database
239
240
241       --disable
242              Disables the backend database
243
244
245       --cache-size CACHE_SIZE
246              Sets the maximum number of entries to keep in the entry cache
247
248
249       --cache-memsize CACHE_MEMSIZE
250              Sets the maximum size in bytes that the entry cache can grow to
251
252
253       --dncache-memsize DNCACHE_MEMSIZE
254              Sets the maximum size in bytes that the DN cache can grow to
255
256
257       --state STATE
258              Changes the backend state to:  "database",  "disabled",  "refer‐
259              ral", or "referral on update"
260
261

COMMAND 'dsconf backend index'

263       usage: dsconf instance backend index [-h]
264                                            {add,set,get,list,delete,reindex}
265       ...
266
267

POSITIONAL ARGUMENTS 'dsconf backend index'

269       dsconf backend index add
270              Add an index
271
272       dsconf backend index set
273              Update an index
274
275       dsconf backend index get
276              Display an index entry
277
278       dsconf backend index list
279              Display the index
280
281       dsconf backend index delete
282              Delete an index
283
284       dsconf backend index reindex
285              Re-index the database for a single index or all indexes
286
287

COMMAND 'dsconf backend index add'

289       usage: dsconf instance backend index add [-h] --index-type INDEX_TYPE
290                                                [--matching-rule        MATCH‐
291       ING_RULE]
292                                                [--reindex] --attr ATTR
293                                                be_name
294
295
296       be_name
297              The backend name or suffix
298
299

OPTIONS 'dsconf backend index add'

301       --index-type INDEX_TYPE
302              Sets the indexing type (eq, sub, pres, or approx)
303
304
305       --matching-rule MATCHING_RULE
306              Sets the matching rule for the index
307
308
309       --reindex
310              Re-indexes the database after adding a new index
311
312
313       --attr ATTR
314              Sets the attribute name to index
315
316

COMMAND 'dsconf backend index set'

318       usage: dsconf instance backend index set [-h] --attr ATTR
319                                                [--add-type ADD_TYPE]
320                                                [--del-type DEL_TYPE]
321                                                [--add-mr   ADD_MR]  [--del-mr
322       DEL_MR]
323                                                [--reindex]
324                                                be_name
325
326
327       be_name
328              The backend name or suffix
329
330

OPTIONS 'dsconf backend index set'

332       --attr ATTR
333              Sets the indexed attribute to update
334
335
336       --add-type ADD_TYPE
337              Adds an index type to the index (eq, sub, pres, or approx)
338
339
340       --del-type DEL_TYPE
341              Removes an index type from the index: (eq, sub, pres, or approx)
342
343
344       --add-mr ADD_MR
345              Adds a matching-rule to the index
346
347
348       --del-mr DEL_MR
349              Removes a matching-rule from the index
350
351
352       --reindex
353              Re-indexes the database after editing the index
354
355

COMMAND 'dsconf backend index get'

357       usage: dsconf instance backend index get [-h] --attr ATTR be_name
358
359
360       be_name
361              The backend name or suffix
362
363

OPTIONS 'dsconf backend index get'

365       --attr ATTR
366              Sets the index name to display
367
368

COMMAND 'dsconf backend index list'

370       usage: dsconf instance backend index list [-h] [--just-names] be_name
371
372
373       be_name
374              The backend name or suffix
375
376

OPTIONS 'dsconf backend index list'

378       --just-names
379              Displays only the names of indexed attributes
380
381

COMMAND 'dsconf backend index delete'

383       usage: dsconf instance backend index delete [-h] [--attr ATTR] be_name
384
385
386       be_name
387              The backend name or suffix
388
389

OPTIONS 'dsconf backend index delete'

391       --attr ATTR
392              Sets the name of the attribute to delete from the index
393
394

COMMAND 'dsconf backend index reindex'

396       usage:  dsconf  instance  backend  index  reindex  [-h]  [--attr  ATTR]
397       [--wait]
398                                                    be_name
399
400
401       be_name
402              The backend name or suffix
403
404

OPTIONS 'dsconf backend index reindex'

406       --attr ATTR
407              Sets  the  name of the attribute to re-index. Omit this argument
408              to re-index all attributes
409
410
411       --wait Waits for the index task to complete and reports the status
412
413

COMMAND 'dsconf backend vlv-index'

415       usage: dsconf instance backend vlv-index [-h]
416                                                {list,get,add-search,edit-search,del-search,add-in‐
417       dex,del-index,reindex}
418                                                ...
419
420

POSITIONAL ARGUMENTS 'dsconf backend vlv-index'

422       dsconf backend vlv-index list
423              List VLV search and index entries
424
425       dsconf backend vlv-index get
426              Display a VLV search and indexes
427
428       dsconf backend vlv-index add-search
429              Add  a VLV search entry. The search entry is the parent entry of
430              the VLV index entries, and it specifies  the  search  parameters
431              that are used to match entries for those indexes.
432
433       dsconf backend vlv-index edit-search
434              Update a VLV search and index
435
436       dsconf backend vlv-index del-search
437              Delete VLV search & index
438
439       dsconf backend vlv-index add-index
440              Create  a VLV index under a VLV search entry (parent entry). The
441              VLV index specifies the attributes to sort
442
443       dsconf backend vlv-index del-index
444              Delete a VLV index under a VLV search entry (parent entry)
445
446       dsconf backend vlv-index reindex
447              Index/re-index the VLV database index
448
449

COMMAND 'dsconf backend vlv-index list'

451       usage: dsconf  instance  backend  vlv-index  list  [-h]  [--just-names]
452       be_name
453
454
455       be_name
456              The backend name of the VLV index
457
458

OPTIONS 'dsconf backend vlv-index list'

460       --just-names
461              Displays only the names of VLV search entries
462
463

COMMAND 'dsconf backend vlv-index get'

465       usage: dsconf instance backend vlv-index get [-h] [--name NAME] be_name
466
467
468       be_name
469              The backend name of the VLV index
470
471

OPTIONS 'dsconf backend vlv-index get'

473       --name NAME
474              Displays the VLV search entry and its index entries
475
476

COMMAND 'dsconf backend vlv-index add-search'

478       usage: dsconf instance backend vlv-index add-search [-h] --name NAME
479                                                           --search-base
480       SEARCH_BASE
481                                                           --search-scope
482                                                           SEARCH_SCOPE
483                                                           --search-filter
484                                                           SEARCH_FILTER
485                                                           be_name
486
487
488       be_name
489              The backend name of the VLV index
490
491

OPTIONS 'dsconf backend vlv-index add-search'

493       --name NAME
494              Sets the name of the VLV search entry
495
496
497       --search-base SEARCH_BASE
498              Sets the VLV search base
499
500
501       --search-scope SEARCH_SCOPE
502              Sets the  VLV  search  scope:  0  (base  search),  1  (one-level
503              search), or 2 (subtree search)
504
505
506       --search-filter SEARCH_FILTER
507              Sets the VLV search filter
508
509

COMMAND 'dsconf backend vlv-index edit-search'

511       usage: dsconf instance backend vlv-index edit-search [-h] --name NAME
512                                                            [--search-base
513       SEARCH_BASE]
514                                                            [--search-scope
515       SEARCH_SCOPE]
516                                                            [--search-filter
517       SEARCH_FILTER]
518                                                            [--reindex]
519                                                            be_name
520
521
522       be_name
523              The backend name of the VLV index to update
524
525

OPTIONS 'dsconf backend vlv-index edit-search'

527       --name NAME
528              Sets the name of the VLV index
529
530
531       --search-base SEARCH_BASE
532              Sets the VLV search base
533
534
535       --search-scope SEARCH_SCOPE
536              Sets the  VLV  search  scope:  0  (base  search),  1  (one-level
537              search), or 2 (subtree search)
538
539
540       --search-filter SEARCH_FILTER
541              Sets the VLV search filter
542
543
544       --reindex
545              Re-indexes all VLV database indexes
546
547

COMMAND 'dsconf backend vlv-index del-search'

549       usage:  dsconf  instance  backend vlv-index del-search [-h] --name NAME
550       be_name
551
552
553       be_name
554              The backend name of the VLV index
555
556

OPTIONS 'dsconf backend vlv-index del-search'

558       --name NAME
559              Sets the name of the VLV search index
560
561

COMMAND 'dsconf backend vlv-index add-index'

563       usage: dsconf instance backend vlv-index add-index [-h] --parent-name
564                                                          PARENT_NAME    --in‐
565       dex-name
566                                                          INDEX_NAME    --sort
567       SORT
568                                                          [--index-it]
569                                                          be_name
570
571
572       be_name
573              The backend name of the VLV index
574
575

OPTIONS 'dsconf backend vlv-index add-index'

577       --parent-name PARENT_NAME
578              Sets the name or "cn" attribute of the parent VLV search entry
579
580
581       --index-name INDEX_NAME
582              Sets the name of the new VLV index
583
584
585       --sort SORT
586              Sets a space-separated list of attributes to sort for  this  VLV
587              index
588
589
590       --index-it
591              Creates the database index for this VLV index definition
592
593

COMMAND 'dsconf backend vlv-index del-index'

595       usage: dsconf instance backend vlv-index del-index [-h] --parent-name
596                                                          PARENT_NAME
597                                                          [--index-name    IN‐
598       DEX_NAME]
599                                                          [--sort SORT]
600                                                          be_name
601
602
603       be_name
604              The backend name of the VLV index
605
606

OPTIONS 'dsconf backend vlv-index del-index'

608       --parent-name PARENT_NAME
609              Sets the name or "cn" attribute value of the parent  VLV  search
610              entry
611
612
613       --index-name INDEX_NAME
614              Sets the name of the VLV index to delete
615
616
617       --sort SORT
618              Delete a VLV index that has this vlvsort value
619
620

COMMAND 'dsconf backend vlv-index reindex'

622       usage: dsconf instance backend vlv-index reindex [-h]
623                                                        [--index-name      IN‐
624       DEX_NAME]
625                                                        --parent-name     PAR‐
626       ENT_NAME
627                                                        be_name
628
629
630       be_name
631              The backend name of the VLV index
632
633

OPTIONS 'dsconf backend vlv-index reindex'

635       --index-name INDEX_NAME
636              Sets  the  name  of the VLV index entry to re-index. If not set,
637              all indexes are re-indexed
638
639
640       --parent-name PARENT_NAME
641              Sets the name or "cn" attribute value of the parent  VLV  search
642              entry
643
644

COMMAND 'dsconf backend attr-encrypt'

646       usage:    dsconf    instance   backend   attr-encrypt   [-h]   [--list]
647       [--just-names]
648                                                   [--add-attr ADD_ATTR]
649                                                   [--del-attr DEL_ATTR]
650                                                   be_name
651
652
653       be_name
654              The backend name or suffix
655
656

OPTIONS 'dsconf backend attr-encrypt'

658       --list Lists all encrypted attributes in the backend
659
660
661       --just-names
662              List only the names of the encrypted attributes when  used  with
663              --list
664
665
666       --add-attr ADD_ATTR
667              Enables encryption for the specified attribute
668
669
670       --del-attr DEL_ATTR
671              Disables encryption for the specified attribute
672
673

COMMAND 'dsconf backend config'

675       usage: dsconf instance backend config [-h] {get,set} ...
676
677

POSITIONAL ARGUMENTS 'dsconf backend config'

679       dsconf backend config get
680              Display the global database configuration
681
682       dsconf backend config set
683              Set the global database configuration
684
685

COMMAND 'dsconf backend config get'

687       usage: dsconf instance backend config get [-h]
688
689

COMMAND 'dsconf backend config set'

691       usage: dsconf instance backend config set [-h]
692                                                 [--lookthroughlimit     LOOK‐
693       THROUGHLIMIT]
694                                                 [--mode MODE]
695                                                 [--idlistscanlimit
696       IDLISTSCANLIMIT]
697                                                 [--directory DIRECTORY]
698                                                 [--dbcachesize DBCACHESIZE]
699                                                 [--logdirectory LOGDIRECTORY]
700                                                 [--txn-wait TXN_WAIT]
701                                                 [--checkpoint-interval CHECK‐
702       POINT_INTERVAL]
703                                                 [--compactdb-interval    COM‐
704       PACTDB_INTERVAL]
705                                                 [--compactdb-time        COM‐
706       PACTDB_TIME]
707                                                 [--txn-batch-val
708       TXN_BATCH_VAL]
709                                                 [--txn-batch-min
710       TXN_BATCH_MIN]
711                                                 [--txn-batch-max
712       TXN_BATCH_MAX]
713                                                 [--logbufsize LOGBUFSIZE]
714                                                 [--locks LOCKS]
715                                                 [--locks-monitoring-enabled
716       LOCKS_MONITORING_ENABLED]
717                                                 [--locks-monitoring-threshold
718       LOCKS_MONITORING_THRESHOLD]
719                                                 [--locks-monitoring-pause
720       LOCKS_MONITORING_PAUSE]
721                                                 [--import-cache-autosize  IM‐
722       PORT_CACHE_AUTOSIZE]
723                                                 [--cache-autosize CACHE_AUTO‐
724       SIZE]
725                                                 [--cache-autosize-split
726       CACHE_AUTOSIZE_SPLIT]
727                                                 [--import-cachesize       IM‐
728       PORT_CACHESIZE]
729                                                 [--exclude-from-export    EX‐
730       CLUDE_FROM_EXPORT]
731                                                 [--pagedlookthroughlimit
732       PAGEDLOOKTHROUGHLIMIT]
733                                                 [--pagedidlistscanlimit PAGE‐
734       DIDLISTSCANLIMIT]
735                                                 [--rangelookthroughlimit
736       RANGELOOKTHROUGHLIMIT]
737                                                 [--backend-opt-level    BACK‐
738       END_OPT_LEVEL]
739                                                 [--deadlock-policy      DEAD‐
740       LOCK_POLICY]
741                                                 [--db-home-directory
742       DB_HOME_DIRECTORY]
743                                                 [--db-lib DB_LIB]
744
745

OPTIONS 'dsconf backend config set'

747       --lookthroughlimit LOOKTHROUGHLIMIT
748              Specifies  the  maximum  number  of entries that the server will
749              check when examining candidate entries in response to  a  search
750              request
751
752
753       --mode MODE
754              Specifies the permissions used for newly created index files
755
756
757       --idlistscanlimit IDLISTSCANLIMIT
758              Specifies  the  number  of  entry IDs that are searched during a
759              search operation
760
761
762       --directory DIRECTORY
763              Specifies absolute path to database instance
764
765
766       --dbcachesize DBCACHESIZE
767              Specifies the database index cache size in bytes
768
769
770       --logdirectory LOGDIRECTORY
771              Specifies the path to the directory that contains  the  database
772              transaction logs
773
774
775       --txn-wait TXN_WAIT
776              Sets  whether  the  server should should wait if there are no db
777              locks available
778
779
780       --checkpoint-interval CHECKPOINT_INTERVAL
781              Sets the amount of time in seconds after which the server  sends
782              a checkpoint entry to the database transaction log
783
784
785       --compactdb-interval COMPACTDB_INTERVAL
786              Sets the interval in seconds when the database is compacted
787
788
789       --compactdb-time COMPACTDB_TIME
790              Sets the time (HH:MM format) of day when to compact the database
791              after the "compactdb interval" has been reached
792
793
794       --txn-batch-val TXN_BATCH_VAL
795              Specifies how many transactions will  be  batched  before  being
796              committed
797
798
799       --txn-batch-min TXN_BATCH_MIN
800              Controls  when transactions should be flushed earliest, indepen‐
801              dently of the batch count. Requires that txn-batch-val is set
802
803
804       --txn-batch-max TXN_BATCH_MAX
805              Controls when transactions should be  flushed  latest,  indepen‐
806              dently of the batch count. Requires that txn-batch-val is set)
807
808
809       --logbufsize LOGBUFSIZE
810              Specifies the transaction log information buffer size
811
812
813       --locks LOCKS
814              Sets the maximum number of database locks
815
816
817       --locks-monitoring-enabled LOCKS_MONITORING_ENABLED
818              Enables  or  disables  monitoring  of  DB  locks  when the value
819              crosses the percentage set with "--locks-monitoring-threshold"
820
821
822       --locks-monitoring-threshold LOCKS_MONITORING_THRESHOLD
823              Sets the DB lock exhaustion threshold in percentage (valid range
824              is  70-90).   When  the  threshold  is reached, all searches are
825              aborted until the number of active  locks  decreases  below  the
826              configured threshold and/or the administrator increases the num‐
827              ber of database locks (nsslapd-db-locks). This  threshold  is  a
828              safeguard  against  DB corruption which might be caused by locks
829              exhaustion.
830
831
832       --locks-monitoring-pause LOCKS_MONITORING_PAUSE
833              Sets the DB lock monitoring value in milliseconds for the amount
834              of  time  that  the  monitoring  thread  spends  waiting between
835              checks.
836
837
838       --import-cache-autosize IMPORT_CACHE_AUTOSIZE
839              Enables or disables to automatically set the size of the  import
840              cache to be used during the import process of LDIF files
841
842
843       --cache-autosize CACHE_AUTOSIZE
844              Sets the percentage of free memory that is used in total for the
845              database and entry cache. "0" disables this feature.
846
847
848       --cache-autosize-split CACHE_AUTOSIZE_SPLIT
849              Sets the percentage of RAM that is used for the database  cache.
850              The remaining percentage is used for the entry cache
851
852
853       --import-cachesize IMPORT_CACHESIZE
854              Sets  the size in bytes of the database cache used in the import
855              process.
856
857
858       --exclude-from-export EXCLUDE_FROM_EXPORT
859              List of attributes to not include during database export  opera‐
860              tions
861
862
863       --pagedlookthroughlimit PAGEDLOOKTHROUGHLIMIT
864              Specifies  the  maximum  number  of entries that the server will
865              check when examining candidate entries for a search  which  uses
866              the simple paged results control
867
868
869       --pagedidlistscanlimit PAGEDIDLISTSCANLIMIT
870              Specifies  the  number  of entry IDs that are searched, specifi‐
871              cally, for a search operation using  the  simple  paged  results
872              control.
873
874
875       --rangelookthroughlimit RANGELOOKTHROUGHLIMIT
876              Specifies  the  maximum  number  of entries that the server will
877              check when examining candidate entries in response  to  a  range
878              search request.
879
880
881       --backend-opt-level BACKEND_OPT_LEVEL
882              Sets the backend optimization level for write performance (0, 1,
883              2, or 4).  WARNING:  This  parameter  can  trigger  experimental
884              code.
885
886
887       --deadlock-policy DEADLOCK_POLICY
888              Adjusts the backend database deadlock policy (Advanced setting)
889
890
891       --db-home-directory DB_HOME_DIRECTORY
892              Sets the directory for the database mmapped files (Advanced set‐
893              ting)
894
895
896       --db-lib DB_LIB
897              Sets which db lib is used. Valid values are: bdb or mdb
898
899

COMMAND 'dsconf backend monitor'

901       usage: dsconf instance backend monitor [-h] [--suffix SUFFIX]
902
903

OPTIONS 'dsconf backend monitor'

905       --suffix SUFFIX
906              Displays monitoring information only for the specified suffix
907
908

COMMAND 'dsconf backend import'

910       usage: dsconf instance backend import [-h] [-c CHUNKS_SIZE] [-E]
911                                             [-g GEN_UNIQ_ID] [-O]
912                                             [-s     INCLUDE_SUFFIXES     [IN‐
913       CLUDE_SUFFIXES ...]]
914                                             [-x     EXCLUDE_SUFFIXES     [EX‐
915       CLUDE_SUFFIXES ...]]
916                                             [be_name] [ldifs ...]
917
918
919       be_name
920              The backend name or the root suffix
921
922
923       ldifs  Specifies the filename of the input LDIF files.  Multiple  files
924              are imported in the specified order.
925
926

OPTIONS 'dsconf backend import'

928       -c CHUNKS_SIZE, --chunks-size CHUNKS_SIZE
929              The number of chunks to have during the import operation
930
931
932       -E, --encrypted
933              Encrypt attributes configured in the database for encryption
934
935
936       -g GEN_UNIQ_ID, --gen-uniq-id GEN_UNIQ_ID
937              Generate  a  unique id. Set "none" for no unique ID to be gener‐
938              ated and "deterministic" for  the  generated  unique  ID  to  be
939              name-based.  By  default,  a  time-based unique ID is generated.
940              When using the deterministic generation  to  have  a  name-based
941              unique  ID, it is also possible to specify the namespace for the
942              server to use. namespaceId is a string of characters in the for‐
943              mat 00-xxxxxxxx-xxxxxxxx-xxxxxxxx-xxxxxxxx.
944
945
946       -O, --only-core
947              Creates only the core database attribute indexes
948
949
950       -s  INCLUDE_SUFFIXES  [INCLUDE_SUFFIXES  ...],  --include-suffixes  IN‐
951       CLUDE_SUFFIXES [INCLUDE_SUFFIXES ...]
952              Specifies the suffixes or the subtrees to be included
953
954
955       -x  EXCLUDE_SUFFIXES  [EXCLUDE_SUFFIXES  ...],  --exclude-suffixes  EX‐
956       CLUDE_SUFFIXES [EXCLUDE_SUFFIXES ...]
957              Specifies the suffixes to be excluded
958
959

COMMAND 'dsconf backend export'

961       usage:  dsconf  instance  backend  export [-h] [-l LDIF] [-C] [-E] [-m]
962       [-N] [-r]
963                                             [-u] [-U]
964                                             [-s     INCLUDE_SUFFIXES     [IN‐
965       CLUDE_SUFFIXES ...]]
966                                             [-x     EXCLUDE_SUFFIXES     [EX‐
967       CLUDE_SUFFIXES ...]]
968                                             be_names [be_names ...]
969
970
971       be_names
972              The backend names or the root suffixes
973
974

OPTIONS 'dsconf backend export'

976       -l LDIF, --ldif LDIF
977              Sets the filename of the output  LDIF  file.  Separate  multiple
978              file names with spaces.
979
980
981       -C, --use-id2entry
982              Uses only the main database file
983
984
985       -E, --encrypted
986              Decrypts  encrypted data during export. This option is used only
987              if database encryption is enabled.
988
989
990       -m, --min-base64
991              Sets minimal base-64 encoding
992
993
994       -N, --no-seq-num
995              Suppresses printing the sequence numbers
996
997
998       -r, --replication
999              Exports the data  with  information  required  to  initialize  a
1000              replica
1001
1002
1003       -u, --no-dump-uniq-id
1004              Omits exporting the unique ID
1005
1006
1007       -U, --not-folded
1008              Disables folding the output
1009
1010
1011       -s  INCLUDE_SUFFIXES  [INCLUDE_SUFFIXES  ...],  --include-suffixes  IN‐
1012       CLUDE_SUFFIXES [INCLUDE_SUFFIXES ...]
1013              Specifies the suffixes or the subtrees to be included
1014
1015
1016       -x  EXCLUDE_SUFFIXES  [EXCLUDE_SUFFIXES  ...],  --exclude-suffixes  EX‐
1017       CLUDE_SUFFIXES [EXCLUDE_SUFFIXES ...]
1018              Specifies the suffixes to be excluded
1019
1020

COMMAND 'dsconf backend create'

1022       usage: dsconf instance backend create [-h] [--parent-suffix PARENT_SUF‐
1023       FIX]
1024                                             --suffix SUFFIX --be-name BE_NAME
1025                                             [--create-entries] [--create-suf‐
1026       fix]
1027
1028

OPTIONS 'dsconf backend create'

1030       --parent-suffix PARENT_SUFFIX
1031              Sets the parent suffix only if this backend is a sub-suffix
1032
1033
1034       --suffix SUFFIX
1035              Sets the database suffix DN
1036
1037
1038       --be-name BE_NAME
1039              Sets the database backend name"
1040
1041
1042       --create-entries
1043              Adds sample entries to the database
1044
1045
1046       --create-suffix
1047              Creates  the  suffix object entry in the database. Only suffixes
1048              using the 'dc',
1049
1050

COMMAND 'dsconf backend delete'

1052       usage: dsconf instance backend delete [-h] be_name
1053
1054
1055       be_name
1056              The backend name or suffix
1057
1058

COMMAND 'dsconf backend get-tree'

1060       usage: dsconf instance backend get-tree [-h]
1061
1062

COMMAND 'dsconf backend compact-db'

1064       usage: dsconf instance backend compact-db [-h] [--only-changelog]
1065
1066

OPTIONS 'dsconf backend compact-db'

1068       --only-changelog
1069              Compacts only the replication change log
1070
1071

COMMAND 'dsconf backup'

1073       usage: dsconf instance backup [-h] {create,restore} ...
1074
1075

POSITIONAL ARGUMENTS 'dsconf backup'

1077       dsconf backup create
1078              Creates a backup of the database
1079
1080       dsconf backup restore
1081              Restores a database from a backup
1082
1083

COMMAND 'dsconf backup create'

1085       usage: dsconf instance backup create [-h] [-t DB_TYPE] [archive]
1086
1087
1088       archive
1089              Sets the directory where to store the backup files. Format:  in‐
1090              stance_name-    year_month_date_hour_minutes_seconds.   Default:
1091              /var/lib/dirsrv/slapd- instance/bak/
1092
1093

OPTIONS 'dsconf backup create'

1095       -t DB_TYPE, --db-type DB_TYPE
1096              Sets the database type. Default: ldbm database
1097
1098

COMMAND 'dsconf backup restore'

1100       usage: dsconf instance backup restore [-h] [-t DB_TYPE] archive
1101
1102
1103       archive
1104              Set the directory that contains the backup files
1105
1106

OPTIONS 'dsconf backup restore'

1108       -t DB_TYPE, --db-type DB_TYPE
1109              Sets the database type. Default: ldbm database
1110
1111

COMMAND 'dsconf chaining'

1113       usage: dsconf instance chaining [-h]
1114                                       {config-get,config-set,con‐
1115       fig-get-def,config-set-def,link-cre‐
1116       ate,link-get,link-set,link-delete,monitor,link-list}
1117                                       ...
1118
1119

POSITIONAL ARGUMENTS 'dsconf chaining'

1121       dsconf chaining config-get
1122              Display the chaining controls and server component lists
1123
1124       dsconf chaining config-set
1125              Set the chaining controls and server component lists
1126
1127       dsconf chaining config-get-def
1128              Display the default creation parameters for new database links
1129
1130       dsconf chaining config-set-def
1131              Set the default creation parameters for new database links
1132
1133       dsconf chaining link-create
1134              Create a database link to a remote server
1135
1136       dsconf chaining link-get
1137              Displays chaining database links
1138
1139       dsconf chaining link-set
1140              Edit a database link to a remote server
1141
1142       dsconf chaining link-delete
1143              Delete a database link
1144
1145       dsconf chaining monitor
1146              Display monitor information for a database chaining link
1147
1148       dsconf chaining link-list
1149              List database links
1150
1151

COMMAND 'dsconf chaining config-get'

1153       usage: dsconf instance chaining config-get [-h] [--avail-controls]
1154                                                  [--avail-comps]
1155
1156

OPTIONS 'dsconf chaining config-get'

1158       --avail-controls
1159              Lists available chaining controls
1160
1161
1162       --avail-comps
1163              Lists available chaining plugin components
1164
1165

COMMAND 'dsconf chaining config-set'

1167       usage: dsconf instance chaining config-set [-h] [--add-control ADD_CON‐
1168       TROL]
1169                                                  [--del-control DEL_CONTROL]
1170                                                  [--add-comp ADD_COMP]
1171                                                  [--del-comp DEL_COMP]
1172
1173

OPTIONS 'dsconf chaining config-set'

1175       --add-control ADD_CONTROL
1176              Adds a transmitted control OID
1177
1178
1179       --del-control DEL_CONTROL
1180              Deletes a transmitted control OID
1181
1182
1183       --add-comp ADD_COMP
1184              Adds a chaining component
1185
1186
1187       --del-comp DEL_COMP
1188              Deletes a chaining component
1189
1190

COMMAND 'dsconf chaining config-get-def'

1192       usage: dsconf instance chaining config-get-def [-h]
1193
1194

COMMAND 'dsconf chaining config-set-def'

1196       usage: dsconf instance chaining config-set-def [-h]
1197                                                      [--conn-bind-limit
1198       CONN_BIND_LIMIT]
1199                                                      [--conn-op-limit
1200       CONN_OP_LIMIT]
1201                                                      [--abandon-check-inter‐
1202       val ABANDON_CHECK_INTERVAL]
1203                                                      [--bind-limit
1204       BIND_LIMIT]
1205                                                      [--op-limit OP_LIMIT]
1206                                                      [--proxied-auth    PROX‐
1207       IED_AUTH]
1208                                                      [--conn-lifetime
1209       CONN_LIFETIME]
1210                                                      [--bind-timeout
1211       BIND_TIMEOUT]
1212                                                      [--return-ref        RE‐
1213       TURN_REF]
1214                                                      [--check-aci CHECK_ACI]
1215                                                      [--bind-attempts
1216       BIND_ATTEMPTS]
1217                                                      [--size-limit
1218       SIZE_LIMIT]
1219                                                      [--time-limit
1220       TIME_LIMIT]
1221                                                      [--hop-limit HOP_LIMIT]
1222                                                      [--response-delay    RE‐
1223       SPONSE_DELAY]
1224                                                      [--test-response-delay
1225       TEST_RESPONSE_DELAY]
1226                                                      [--use-starttls
1227       USE_STARTTLS]
1228
1229

OPTIONS 'dsconf chaining config-set-def'

1231       --conn-bind-limit CONN_BIND_LIMIT
1232              Sets  the  maximum  number of BIND connections the database link
1233              establishes with the remote server
1234
1235
1236       --conn-op-limit CONN_OP_LIMIT
1237              Sets the maximum number of LDAP connections  the  database  link
1238              establishes with the remote server
1239
1240
1241       --abandon-check-interval ABANDON_CHECK_INTERVAL
1242              Sets  the  number  of seconds that pass before the server checks
1243              for abandoned operations
1244
1245
1246       --bind-limit BIND_LIMIT
1247              Sets the maximum number of concurrent bind  operations  per  TCP
1248              connection
1249
1250
1251       --op-limit OP_LIMIT
1252              Sets the maximum number of concurrent operations allowed
1253
1254
1255       --proxied-auth PROXIED_AUTH
1256              Enables  or disables proxied authorization. If set to "off", the
1257              server executes bind for chained operations as the user  set  in
1258              the nsMultiplexorBindDn attribute.
1259
1260
1261       --conn-lifetime CONN_LIFETIME
1262              Specifies  connection lifetime in seconds. "0" keeps the connec‐
1263              tion open forever.
1264
1265
1266       --bind-timeout BIND_TIMEOUT
1267              Sets the amount of time in seconds before a bind  attempt  times
1268              out
1269
1270
1271       --return-ref RETURN_REF
1272              Enables  or  disables  whether  referrals are returned by scoped
1273              searches
1274
1275
1276       --check-aci CHECK_ACI
1277              Enables or disables whether the server  evaluates  ACIs  on  the
1278              database link as well as the remote data server
1279
1280
1281       --bind-attempts BIND_ATTEMPTS
1282              Sets  the number of times the server tries to bind to the remote
1283              server
1284
1285
1286       --size-limit SIZE_LIMIT
1287              Sets the maximum number of entries to return from a search oper‐
1288              ation
1289
1290
1291       --time-limit TIME_LIMIT
1292              Sets the maximum number of seconds allowed for an operation
1293
1294
1295       --hop-limit HOP_LIMIT
1296              Sets the maximum number of times a database is allowed to chain.
1297              That is the number of times a request can be forwarded from  one
1298              database link to another.
1299
1300
1301       --response-delay RESPONSE_DELAY
1302              Sets  the  maximum amount of time it can take a remote server to
1303              respond to an LDAP operation request made by a database link be‐
1304              fore an error is suspected
1305
1306
1307       --test-response-delay TEST_RESPONSE_DELAY
1308              Sets  the  duration  of  the test issued by the database link to
1309              check whether the remote server is responding
1310
1311
1312       --use-starttls USE_STARTTLS
1313              Configured that database links use StartTLS if set to "on"
1314
1315
1317       usage: dsconf instance chaining link-create [-h]
1318                                                   [--conn-bind-limit
1319       CONN_BIND_LIMIT]
1320                                                   [--conn-op-limit
1321       CONN_OP_LIMIT]
1322                                                   [--abandon-check-interval
1323       ABANDON_CHECK_INTERVAL]
1324                                                   [--bind-limit BIND_LIMIT]
1325                                                   [--op-limit OP_LIMIT]
1326                                                   [--proxied-auth       PROX‐
1327       IED_AUTH]
1328                                                   [--conn-lifetime CONN_LIFE‐
1329       TIME]
1330                                                   [--bind-timeout  BIND_TIME‐
1331       OUT]
1332                                                   [--return-ref RETURN_REF]
1333                                                   [--check-aci CHECK_ACI]
1334                                                   [--bind-attempts   BIND_AT‐
1335       TEMPTS]
1336                                                   [--size-limit SIZE_LIMIT]
1337                                                   [--time-limit TIME_LIMIT]
1338                                                   [--hop-limit HOP_LIMIT]
1339                                                   [--response-delay       RE‐
1340       SPONSE_DELAY]
1341                                                   [--test-response-delay
1342       TEST_RESPONSE_DELAY]
1343                                                   [--use-starttls  USE_START‐
1344       TLS]
1345                                                   --suffix             SUFFIX
1346       --server-url
1347                                                   SERVER_URL      --bind-mech
1348       BIND_MECH
1349                                                   --bind-dn BIND_DN --bind-pw
1350                                                   BIND_PW
1351                                                   CHAIN_NAME
1352
1353
1354       CHAIN_NAME
1355              The name of the database link
1356
1357
1359       --conn-bind-limit CONN_BIND_LIMIT
1360              Sets the maximum number of BIND connections  the  database  link
1361              establishes with the remote server
1362
1363
1364       --conn-op-limit CONN_OP_LIMIT
1365              Sets  the  maximum  number of LDAP connections the database link
1366              establishes with the remote server
1367
1368
1369       --abandon-check-interval ABANDON_CHECK_INTERVAL
1370              Sets the number of seconds that pass before  the  server  checks
1371              for abandoned operations
1372
1373
1374       --bind-limit BIND_LIMIT
1375              Sets  the  maximum  number of concurrent bind operations per TCP
1376              connection
1377
1378
1379       --op-limit OP_LIMIT
1380              Sets the maximum number of concurrent operations allowed
1381
1382
1383       --proxied-auth PROXIED_AUTH
1384              Enables or disables proxied authorization. If set to "off",  the
1385              server  executes  bind for chained operations as the user set in
1386              the nsMultiplexorBindDn attribute.
1387
1388
1389       --conn-lifetime CONN_LIFETIME
1390              Specifies connection lifetime in seconds. "0" keeps the  connec‐
1391              tion open forever.
1392
1393
1394       --bind-timeout BIND_TIMEOUT
1395              Sets  the  amount of time in seconds before a bind attempt times
1396              out
1397
1398
1399       --return-ref RETURN_REF
1400              Enables or disables whether referrals  are  returned  by  scoped
1401              searches
1402
1403
1404       --check-aci CHECK_ACI
1405              Enables  or  disables  whether  the server evaluates ACIs on the
1406              database link as well as the remote data server
1407
1408
1409       --bind-attempts BIND_ATTEMPTS
1410              Sets the number of times the server tries to bind to the  remote
1411              server
1412
1413
1414       --size-limit SIZE_LIMIT
1415              Sets the maximum number of entries to return from a search oper‐
1416              ation
1417
1418
1419       --time-limit TIME_LIMIT
1420              Sets the maximum number of seconds allowed for an operation
1421
1422
1423       --hop-limit HOP_LIMIT
1424              Sets the maximum number of times a database is allowed to chain.
1425              That  is the number of times a request can be forwarded from one
1426              database link to another.
1427
1428
1429       --response-delay RESPONSE_DELAY
1430              Sets the maximum amount of time it can take a remote  server  to
1431              respond to an LDAP operation request made by a database link be‐
1432              fore an error is suspected
1433
1434
1435       --test-response-delay TEST_RESPONSE_DELAY
1436              Sets the duration of the test issued by  the  database  link  to
1437              check whether the remote server is responding
1438
1439
1440       --use-starttls USE_STARTTLS
1441              Configured that database links use StartTLS if set to "on"
1442
1443
1444       --suffix SUFFIX
1445              Sets the suffix managed by the database link
1446
1447
1448       --server-url SERVER_URL
1449              Sets the LDAP/LDAPS URL to the remote server
1450
1451
1452       --bind-mech BIND_MECH
1453              Sets the authentication method to use to authenticate to the re‐
1454              mote server.  Valid values: "SIMPLE" (default), "EXTERNAL", "DI‐
1455              GEST-MD5", or "GSSAPI"
1456
1457
1458       --bind-dn BIND_DN
1459              Sets the DN of the administrative entry used to communicate with
1460              the remote server
1461
1462
1463       --bind-pw BIND_PW
1464              Sets the password of the administrative user
1465
1466
1468       usage: dsconf instance chaining link-get [-h] CHAIN_NAME
1469
1470
1471       CHAIN_NAME
1472              The chaining link name or suffix to retrieve
1473
1474
1476       usage: dsconf instance chaining link-set [-h]
1477                                                [--conn-bind-limit
1478       CONN_BIND_LIMIT]
1479                                                [--conn-op-limit
1480       CONN_OP_LIMIT]
1481                                                [--abandon-check-interval
1482       ABANDON_CHECK_INTERVAL]
1483                                                [--bind-limit BIND_LIMIT]
1484                                                [--op-limit OP_LIMIT]
1485                                                [--proxied-auth PROXIED_AUTH]
1486                                                [--conn-lifetime    CONN_LIFE‐
1487       TIME]
1488                                                [--bind-timeout BIND_TIMEOUT]
1489                                                [--return-ref RETURN_REF]
1490                                                [--check-aci CHECK_ACI]
1491                                                [--bind-attempts      BIND_AT‐
1492       TEMPTS]
1493                                                [--size-limit SIZE_LIMIT]
1494                                                [--time-limit TIME_LIMIT]
1495                                                [--hop-limit HOP_LIMIT]
1496                                                [--response-delay RESPONSE_DE‐
1497       LAY]
1498                                                [--test-response-delay
1499       TEST_RESPONSE_DELAY]
1500                                                [--use-starttls USE_STARTTLS]
1501                                                [--suffix SUFFIX]
1502                                                [--server-url SERVER_URL]
1503                                                [--bind-mech BIND_MECH]
1504                                                [--bind-dn BIND_DN]
1505                                                [--bind-pw BIND_PW]
1506                                                CHAIN_NAME
1507
1508
1509       CHAIN_NAME
1510              The name of the database link
1511
1512
1514       --conn-bind-limit CONN_BIND_LIMIT
1515              Sets  the  maximum  number of BIND connections the database link
1516              establishes with the remote server
1517
1518
1519       --conn-op-limit CONN_OP_LIMIT
1520              Sets the maximum number of LDAP connections  the  database  link
1521              establishes with the remote server
1522
1523
1524       --abandon-check-interval ABANDON_CHECK_INTERVAL
1525              Sets  the  number  of seconds that pass before the server checks
1526              for abandoned operations
1527
1528
1529       --bind-limit BIND_LIMIT
1530              Sets the maximum number of concurrent bind  operations  per  TCP
1531              connection
1532
1533
1534       --op-limit OP_LIMIT
1535              Sets the maximum number of concurrent operations allowed
1536
1537
1538       --proxied-auth PROXIED_AUTH
1539              Enables  or disables proxied authorization. If set to "off", the
1540              server executes bind for chained operations as the user  set  in
1541              the nsMultiplexorBindDn attribute.
1542
1543
1544       --conn-lifetime CONN_LIFETIME
1545              Specifies  connection lifetime in seconds. "0" keeps the connec‐
1546              tion open forever.
1547
1548
1549       --bind-timeout BIND_TIMEOUT
1550              Sets the amount of time in seconds before a bind  attempt  times
1551              out
1552
1553
1554       --return-ref RETURN_REF
1555              Enables  or  disables  whether  referrals are returned by scoped
1556              searches
1557
1558
1559       --check-aci CHECK_ACI
1560              Enables or disables whether the server  evaluates  ACIs  on  the
1561              database link as well as the remote data server
1562
1563
1564       --bind-attempts BIND_ATTEMPTS
1565              Sets  the number of times the server tries to bind to the remote
1566              server
1567
1568
1569       --size-limit SIZE_LIMIT
1570              Sets the maximum number of entries to return from a search oper‐
1571              ation
1572
1573
1574       --time-limit TIME_LIMIT
1575              Sets the maximum number of seconds allowed for an operation
1576
1577
1578       --hop-limit HOP_LIMIT
1579              Sets the maximum number of times a database is allowed to chain.
1580              That is the number of times a request can be forwarded from  one
1581              database link to another.
1582
1583
1584       --response-delay RESPONSE_DELAY
1585              Sets  the  maximum amount of time it can take a remote server to
1586              respond to an LDAP operation request made by a database link be‐
1587              fore an error is suspected
1588
1589
1590       --test-response-delay TEST_RESPONSE_DELAY
1591              Sets  the  duration  of  the test issued by the database link to
1592              check whether the remote server is responding
1593
1594
1595       --use-starttls USE_STARTTLS
1596              Configured that database links use StartTLS if set to "on"
1597
1598
1599       --suffix SUFFIX
1600              Sets the suffix managed by the database link
1601
1602
1603       --server-url SERVER_URL
1604              Sets the LDAP/LDAPS URL to the remote server
1605
1606
1607       --bind-mech BIND_MECH
1608              Sets the authentication method to use to authenticate to the re‐
1609              mote  server: Valid values: "SIMPLE" (default), "EXTERNAL", "DI‐
1610              GEST-MD5", or "GSSAPI"
1611
1612
1613       --bind-dn BIND_DN
1614              Sets the DN of the administrative entry used to communicate with
1615              the remote server
1616
1617
1618       --bind-pw BIND_PW
1619              Sets the password of the administrative user
1620
1621
1623       usage: dsconf instance chaining link-delete [-h] CHAIN_NAME
1624
1625
1626       CHAIN_NAME
1627              The name of the database link
1628
1629

COMMAND 'dsconf chaining monitor'

1631       usage: dsconf instance chaining monitor [-h] CHAIN_NAME
1632
1633
1634       CHAIN_NAME
1635              The name of the database link
1636
1637
1639       usage: dsconf instance chaining link-list [-h]
1640
1641

COMMAND 'dsconf config'

1643       usage: dsconf instance config [-h] {get,add,replace,delete} ...
1644
1645

POSITIONAL ARGUMENTS 'dsconf config'

1647       dsconf config get
1648              get
1649
1650       dsconf config add
1651              Add attribute value to configuration
1652
1653       dsconf config replace
1654              Replace attribute value in configuration
1655
1656       dsconf config delete
1657              Delete attribute value in configuration
1658
1659

COMMAND 'dsconf config get'

1661       usage: dsconf instance config get [-h] [attrs ...]
1662
1663
1664       attrs  Configuration attribute(s) to get
1665
1666

COMMAND 'dsconf config add'

1668       usage: dsconf instance config add [-h] [attr ...]
1669
1670
1671       attr   Configuration attribute to add
1672
1673

COMMAND 'dsconf config replace'

1675       usage: dsconf instance config replace [-h] [attr ...]
1676
1677
1678       attr   Configuration attribute to replace
1679
1680

COMMAND 'dsconf config delete'

1682       usage: dsconf instance config delete [-h] [attr ...]
1683
1684
1685       attr   Configuration attribute to delete
1686
1687

COMMAND 'dsconf directory_manager'

1689       usage: dsconf instance directory_manager [-h] {password_change} ...
1690
1691

POSITIONAL ARGUMENTS 'dsconf directory_manager'

1693       dsconf directory_manager password_change
1694              Changes the password of the Directory Manager account
1695
1696

COMMAND 'dsconf directory_manager password_change'

1698       usage: dsconf instance directory_manager password_change [-h]
1699
1700

COMMAND 'dsconf monitor'

1702       usage: dsconf instance monitor [-h]
1703                                      {server,dbmon,ldbm,backend,snmp,chain‐
1704       ing,disk}
1705                                      ...
1706
1707

POSITIONAL ARGUMENTS 'dsconf monitor'

1709       dsconf monitor server
1710              Displays the server statistics, connections, and operations
1711
1712       dsconf monitor dbmon
1713              Monitor all database statistics in a single report
1714
1715       dsconf monitor ldbm
1716              Monitor the LDBM statistics, such as dbcache
1717
1718       dsconf monitor backend
1719              Monitor the behavior of a backend database
1720
1721       dsconf monitor snmp
1722              Displays the SNMP statistics
1723
1724       dsconf monitor chaining
1725              Monitor database chaining statistics
1726
1727       dsconf monitor disk
1728              Displays the disk space statistics. All values are in bytes.
1729
1730

COMMAND 'dsconf monitor server'

1732       usage: dsconf instance monitor server [-h]
1733
1734

COMMAND 'dsconf monitor dbmon'

1736       usage: dsconf instance monitor dbmon [-h] [-b BACKENDS] [-x]
1737
1738

OPTIONS 'dsconf monitor dbmon'

1740       -b BACKENDS, --backends BACKENDS
1741              Specifies a list of space-separated backends to monitor. Default
1742              is all backends.
1743
1744
1745       -x, --indexes
1746              Shows index stats for each backend
1747
1748

COMMAND 'dsconf monitor ldbm'

1750       usage: dsconf instance monitor ldbm [-h]
1751
1752

COMMAND 'dsconf monitor backend'

1754       usage: dsconf instance monitor backend [-h] [backend]
1755
1756
1757       backend
1758              The optional name of the backend to monitor
1759
1760

COMMAND 'dsconf monitor snmp'

1762       usage: dsconf instance monitor snmp [-h]
1763
1764

COMMAND 'dsconf monitor chaining'

1766       usage: dsconf instance monitor chaining [-h] [backend]
1767
1768
1769       backend
1770              The optional name of the chaining backend to monitor
1771
1772

COMMAND 'dsconf monitor disk'

1774       usage: dsconf instance monitor disk [-h]
1775
1776

COMMAND 'dsconf plugin'

1778       usage: dsconf instance plugin [-h]
1779                                     {memberof,automember,referential-integ‐
1780       rity,root-dn,usn,account-pol‐
1781       icy,attr-uniq,dna,ldap-pass-through-auth,linked-attr,managed-en‐
1782       tries,pam-pass-through-auth,retro-changelog,posix-winsync,con‐
1783       tentsync,entryuuid,list,show,set}
1784                                     ...
1785
1786

POSITIONAL ARGUMENTS 'dsconf plugin'

1788       dsconf plugin memberof
1789              Manage and configure MemberOf plugin
1790
1791       dsconf plugin automember
1792              Manage and configure Automembership plugin
1793
1794       dsconf plugin referential-integrity
1795              Manage and configure Referential Integrity Postoperation plugin
1796
1797       dsconf plugin root-dn
1798              Manage and configure RootDN Access Control plugin
1799
1800       dsconf plugin usn
1801              Manage and configure USN plugin
1802
1803       dsconf plugin account-policy
1804              Manage and configure Account Policy plugin
1805
1806       dsconf plugin attr-uniq
1807              Manage and configure Attribute Uniqueness plugin
1808
1809       dsconf plugin dna
1810              Manage and configure DNA plugin
1811
1812       dsconf plugin ldap-pass-through-auth
1813              Manage and configure LDAP Pass-Through Authentication Plugin
1814
1815       dsconf plugin linked-attr
1816              Manage and configure Linked Attributes plugin
1817
1818       dsconf plugin managed-entries
1819              Manage and configure Managed Entries Plugin
1820
1821       dsconf plugin pam-pass-through-auth
1822              Manage  and  configure Pass-Through Authentication plugins (LDAP
1823              URLs and PAM)
1824
1825       dsconf plugin retro-changelog
1826              Manage and configure Retro Changelog plugin
1827
1828       dsconf plugin posix-winsync
1829              Manage and configure the Posix Winsync API plugin
1830
1831       dsconf plugin contentsync
1832              Manage and configure Content Sync Plugin (aka syncrepl)
1833
1834       dsconf plugin entryuuid
1835              Manage and configure EntryUUID plugin
1836
1837       dsconf plugin list
1838              List current configured (enabled and disabled) plugins
1839
1840       dsconf plugin show
1841              Show the plugin data
1842
1843       dsconf plugin set
1844              Edit the plugin settings
1845
1846

COMMAND 'dsconf plugin memberof'

1848       usage: dsconf instance plugin memberof [-h]
1849                                              {show,enable,disable,sta‐
1850       tus,set,config-entry,fixup,fixup-status}
1851                                              ...
1852
1853

POSITIONAL ARGUMENTS 'dsconf plugin memberof'

1855       dsconf plugin memberof show
1856              Displays the plugin configuration
1857
1858       dsconf plugin memberof enable
1859              Enables the plugin
1860
1861       dsconf plugin memberof disable
1862              Disables the plugin
1863
1864       dsconf plugin memberof status
1865              Displays the plugin status
1866
1867       dsconf plugin memberof set
1868              Edit the plugin settings
1869
1870       dsconf plugin memberof config-entry
1871              Manage the config entry
1872
1873       dsconf plugin memberof fixup
1874              Run the fix-up task for memberOf plugin
1875
1876       dsconf plugin memberof fixup-status
1877              Check the status of a fix-up task
1878
1879

COMMAND 'dsconf plugin memberof show'

1881       usage: dsconf instance plugin memberof show [-h]
1882
1883

COMMAND 'dsconf plugin memberof enable'

1885       usage: dsconf instance plugin memberof enable [-h]
1886
1887

COMMAND 'dsconf plugin memberof disable'

1889       usage: dsconf instance plugin memberof disable [-h]
1890
1891

COMMAND 'dsconf plugin memberof status'

1893       usage: dsconf instance plugin memberof status [-h]
1894
1895

COMMAND 'dsconf plugin memberof set'

1897       usage: dsconf instance plugin memberof set [-h] [--attr ATTR]
1898                                                  [--groupattr       GROUPATTR
1899       [GROUPATTR ...]]
1900                                                  [--allbackends {on,off}]
1901                                                  [--skipnested {on,off}]
1902                                                  [--scope SCOPE [SCOPE ...]]
1903                                                  [--exclude EXCLUDE  [EXCLUDE
1904       ...]]
1905                                                  [--autoaddoc AUTOADDOC]
1906                                                  [--config-entry   CONFIG_EN‐
1907       TRY]
1908
1909

OPTIONS 'dsconf plugin memberof set'

1911       --attr ATTR
1912              Specifies the attribute in the  user  entry  for  the  Directory
1913              Server to manage to reflect group membership (memberOfAttr)
1914
1915
1916       --groupattr GROUPATTR [GROUPATTR ...]
1917              Specifies  the  attribute  in the group entry to use to identify
1918              the DNs of group members (memberOfGroupAttr)
1919
1920
1921       --allbackends {on,off}
1922              Specifies whether to search the local suffix for user entries on
1923              all available suffixes (memberOfAllBackends)
1924
1925
1926       --skipnested {on,off}
1927              Specifies  whether  to  skip nested groups or not (memberOfSkip‐
1928              Nested)
1929
1930
1931       --scope SCOPE [SCOPE ...]
1932              Specifies backends or multiple-nested suffixes for the  MemberOf
1933              plug-in to work on (memberOfEntryScope)
1934
1935
1936       --exclude EXCLUDE [EXCLUDE ...]
1937              Specifies  backends or multiple-nested suffixes for the MemberOf
1938              plug-in to exclude (memberOfEntryScopeExcludeSubtree)
1939
1940
1941       --autoaddoc AUTOADDOC
1942              If an entry does not have an object class that allows  the  mem‐
1943              berOf  attribute then the memberOf plugin will automatically add
1944              the object class listed in the memberOfAutoAddOC parameter
1945
1946
1947       --config-entry CONFIG_ENTRY
1948              The value to set as nsslapd-pluginConfigArea
1949
1950

COMMAND 'dsconf plugin memberof config-entry'

1952       usage: dsconf instance plugin memberof config-entry [-h]
1953                                                           {add,set,show,delete}
1954       ...
1955
1956

POSITIONAL ARGUMENTS 'dsconf plugin memberof config-entry'

1958       dsconf plugin memberof config-entry add
1959              Add the config entry
1960
1961       dsconf plugin memberof config-entry set
1962              Edit the config entry
1963
1964       dsconf plugin memberof config-entry show
1965              Display the config entry
1966
1967       dsconf plugin memberof config-entry delete
1968              Delete the config entry
1969
1970

COMMAND 'dsconf plugin memberof config-entry add'

1972       usage:  dsconf  instance  plugin memberof config-entry add [-h] [--attr
1973       ATTR]
1974                                                               [--groupattr
1975       GROUPATTR [GROUPATTR ...]]
1976                                                               [--allbackends
1977       {on,off}]
1978                                                               [--skipnested
1979       {on,off}]
1980                                                               [--scope  SCOPE
1981       [SCOPE ...]]
1982                                                               [--exclude  EX‐
1983       CLUDE [EXCLUDE ...]]
1984                                                               [--autoaddoc
1985       AUTOADDOC]
1986                                                               DN
1987
1988
1989       DN     The config entry full DN
1990
1991

OPTIONS 'dsconf plugin memberof config-entry add'

1993       --attr ATTR
1994              Specifies the attribute in the  user  entry  for  the  Directory
1995              Server to manage to reflect group membership (memberOfAttr)
1996
1997
1998       --groupattr GROUPATTR [GROUPATTR ...]
1999              Specifies  the  attribute  in the group entry to use to identify
2000              the DNs of group members (memberOfGroupAttr)
2001
2002
2003       --allbackends {on,off}
2004              Specifies whether to search the local suffix for user entries on
2005              all available suffixes (memberOfAllBackends)
2006
2007
2008       --skipnested {on,off}
2009              Specifies  whether  to  skip nested groups or not (memberOfSkip‐
2010              Nested)
2011
2012
2013       --scope SCOPE [SCOPE ...]
2014              Specifies backends or multiple-nested suffixes for the  MemberOf
2015              plug-in to work on (memberOfEntryScope)
2016
2017
2018       --exclude EXCLUDE [EXCLUDE ...]
2019              Specifies  backends or multiple-nested suffixes for the MemberOf
2020              plug-in to exclude (memberOfEntryScopeExcludeSubtree)
2021
2022
2023       --autoaddoc AUTOADDOC
2024              If an entry does not have an object class that allows  the  mem‐
2025              berOf  attribute then the memberOf plugin will automatically add
2026              the object class listed in the memberOfAutoAddOC parameter
2027
2028

COMMAND 'dsconf plugin memberof config-entry set'

2030       usage: dsconf instance plugin memberof config-entry  set  [-h]  [--attr
2031       ATTR]
2032                                                               [--groupattr
2033       GROUPATTR [GROUPATTR ...]]
2034                                                               [--allbackends
2035       {on,off}]
2036                                                               [--skipnested
2037       {on,off}]
2038                                                               [--scope  SCOPE
2039       [SCOPE ...]]
2040                                                               [--exclude  EX‐
2041       CLUDE [EXCLUDE ...]]
2042                                                               [--autoaddoc
2043       AUTOADDOC]
2044                                                               DN
2045
2046
2047       DN     The config entry full DN
2048
2049

OPTIONS 'dsconf plugin memberof config-entry set'

2051       --attr ATTR
2052              Specifies  the  attribute  in  the  user entry for the Directory
2053              Server to manage to reflect group membership (memberOfAttr)
2054
2055
2056       --groupattr GROUPATTR [GROUPATTR ...]
2057              Specifies the attribute in the group entry to  use  to  identify
2058              the DNs of group members (memberOfGroupAttr)
2059
2060
2061       --allbackends {on,off}
2062              Specifies whether to search the local suffix for user entries on
2063              all available suffixes (memberOfAllBackends)
2064
2065
2066       --skipnested {on,off}
2067              Specifies whether to skip nested groups  or  not  (memberOfSkip‐
2068              Nested)
2069
2070
2071       --scope SCOPE [SCOPE ...]
2072              Specifies  backends or multiple-nested suffixes for the MemberOf
2073              plug-in to work on (memberOfEntryScope)
2074
2075
2076       --exclude EXCLUDE [EXCLUDE ...]
2077              Specifies backends or multiple-nested suffixes for the  MemberOf
2078              plug-in to exclude (memberOfEntryScopeExcludeSubtree)
2079
2080
2081       --autoaddoc AUTOADDOC
2082              If  an  entry does not have an object class that allows the mem‐
2083              berOf attribute then the memberOf plugin will automatically  add
2084              the object class listed in the memberOfAutoAddOC parameter
2085
2086

COMMAND 'dsconf plugin memberof config-entry show'

2088       usage: dsconf instance plugin memberof config-entry show [-h] DN
2089
2090
2091       DN     The config entry full DN
2092
2093

COMMAND 'dsconf plugin memberof config-entry delete'

2095       usage: dsconf instance plugin memberof config-entry delete [-h] DN
2096
2097
2098       DN     The config entry full DN
2099
2100

COMMAND 'dsconf plugin memberof fixup'

2102       usage:  dsconf instance plugin memberof fixup [-h] [-f FILTER] [--wait]
2103       DN
2104
2105
2106       DN     Base DN that contains entries to fix up
2107
2108

OPTIONS 'dsconf plugin memberof fixup'

2110       -f FILTER, --filter FILTER
2111              Filter for entries to fix up. If omitted, all entries  with  ob‐
2112              jectclass inetuser/inetadmin/nsmemberof under the specified base
2113              will have their memberOf attribute regenerated.
2114
2115
2116       --wait Wait for the task to finish, this could take a long time
2117
2118

COMMAND 'dsconf plugin memberof fixup-status'

2120       usage: dsconf instance plugin memberof fixup-status [-h] [--dn DN]
2121                                                           [--show-log]
2122       [--watch]
2123
2124

OPTIONS 'dsconf plugin memberof fixup-status'

2126       --dn DN
2127              The task entry's DN
2128
2129
2130       --show-log
2131              Display the task log
2132
2133
2134       --watch
2135              Watch the task's status and wait for it to finish
2136
2137

COMMAND 'dsconf plugin automember'

2139       usage: dsconf instance plugin automember [-h]
2140                                                {show,enable,disable,sta‐
2141       tus,list,definition,fixup,fixup-status,abort-fixup}
2142                                                ...
2143
2144

POSITIONAL ARGUMENTS 'dsconf plugin automember'

2146       dsconf plugin automember show
2147              Displays the plugin configuration
2148
2149       dsconf plugin automember enable
2150              Enables the plugin
2151
2152       dsconf plugin automember disable
2153              Disables the plugin
2154
2155       dsconf plugin automember status
2156              Displays the plugin status
2157
2158       dsconf plugin automember list
2159              List Automembership definitions or regex rules.
2160
2161       dsconf plugin automember definition
2162              Manage Automembership definition.
2163
2164       dsconf plugin automember fixup
2165              Run a rebuild membership task.
2166
2167       dsconf plugin automember fixup-status
2168              Check the status of a fix-up task
2169
2170       dsconf plugin automember abort-fixup
2171              Abort the rebuild membership task.
2172
2173

COMMAND 'dsconf plugin automember show'

2175       usage: dsconf instance plugin automember show [-h]
2176
2177

COMMAND 'dsconf plugin automember enable'

2179       usage: dsconf instance plugin automember enable [-h]
2180
2181

COMMAND 'dsconf plugin automember disable'

2183       usage: dsconf instance plugin automember disable [-h]
2184
2185

COMMAND 'dsconf plugin automember status'

2187       usage: dsconf instance plugin automember status [-h]
2188
2189

COMMAND 'dsconf plugin automember list'

2191       usage:  dsconf  instance   plugin   automember   list   [-h]   {defini‐
2192       tions,regexes} ...
2193
2194

POSITIONAL ARGUMENTS 'dsconf plugin automember list'

2196       dsconf plugin automember list definitions
2197              Lists Automembership definitions.
2198
2199       dsconf plugin automember list regexes
2200              List Automembership regex rules.
2201
2202

COMMAND 'dsconf plugin automember list definitions'

2204       usage: dsconf instance plugin automember list definitions [-h]
2205
2206

COMMAND 'dsconf plugin automember list regexes'

2208       usage: dsconf instance plugin automember list regexes [-h] DEFNAME
2209
2210
2211       DEFNAME
2212              The definition entry CN
2213
2214

COMMAND 'dsconf plugin automember definition'

2216       usage: dsconf instance plugin automember definition [-h]
2217                                                           DEFNAME
2218                                                           {add,set,delete,show,regex}
2219                                                           ...
2220
2221

POSITIONAL ARGUMENTS 'dsconf plugin automember definition'

2223       dsconf plugin automember definition add
2224              Creates Automembership definition.
2225
2226       dsconf plugin automember definition set
2227              Edits Automembership definition.
2228
2229       dsconf plugin automember definition delete
2230              Removes Automembership definition.
2231
2232       dsconf plugin automember definition show
2233              Displays Automembership definition.
2234
2235       dsconf plugin automember definition regex
2236              Manage Automembership regex rules.
2237
2238

COMMAND 'dsconf plugin automember definition add'

2240       usage: dsconf instance plugin automember definition DEFNAME add
2241              [-h]   --grouping-attr   GROUPING_ATTR   [--default-group    DE‐
2242       FAULT_GROUP]
2243              --scope SCOPE --filter FILTER
2244
2245

OPTIONS 'dsconf plugin automember definition add'

2247       --grouping-attr GROUPING_ATTR
2248              Specifies  the  name  of the member attribute in the group entry
2249              and the attribute in the object entry that supplies  the  member
2250              attribute value, in the format group_member_attr:entry_attr (au‐
2251              toMemberGroupingAttr)
2252
2253
2254       --default-group DEFAULT_GROUP
2255              Sets default or fallback group to add the entry to as  a  member
2256              attribute in group entry (autoMemberDefaultGroup)
2257
2258
2259       --scope SCOPE
2260              Sets the subtree DN to search for entries (autoMemberScope)
2261
2262
2263       --filter FILTER
2264              Sets a standard LDAP search filter to use to search for matching
2265              entries (autoMemberFilter)
2266
2267

COMMAND 'dsconf plugin automember definition set'

2269       usage: dsconf instance plugin automember definition DEFNAME set
2270              [-h]   --grouping-attr   GROUPING_ATTR   [--default-group    DE‐
2271       FAULT_GROUP]
2272              --scope SCOPE --filter FILTER
2273
2274

OPTIONS 'dsconf plugin automember definition set'

2276       --grouping-attr GROUPING_ATTR
2277              Specifies  the  name  of the member attribute in the group entry
2278              and the attribute in the object entry that supplies  the  member
2279              attribute value, in the format group_member_attr:entry_attr (au‐
2280              toMemberGroupingAttr)
2281
2282
2283       --default-group DEFAULT_GROUP
2284              Sets default or fallback group to add the entry to as  a  member
2285              attribute in group entry (autoMemberDefaultGroup)
2286
2287
2288       --scope SCOPE
2289              Sets the subtree DN to search for entries (autoMemberScope)
2290
2291
2292       --filter FILTER
2293              Sets a standard LDAP search filter to use to search for matching
2294              entries (autoMemberFilter)
2295
2296

COMMAND 'dsconf plugin automember definition delete'

2298       usage: dsconf instance plugin automember definition DEFNAME delete [-h]
2299
2300

COMMAND 'dsconf plugin automember definition show'

2302       usage: dsconf instance plugin automember definition DEFNAME show [-h]
2303
2304

COMMAND 'dsconf plugin automember definition regex'

2306       usage: dsconf instance plugin automember definition DEFNAME regex
2307              [-h] REGEXNAME {add,set,delete,show} ...
2308
2309

POSITIONAL ARGUMENTS 'dsconf plugin automember definition regex'

2311       dsconf plugin automember definition regex add
2312              Creates Automembership regex.
2313
2314       dsconf plugin automember definition regex set
2315              Edits Automembership regex.
2316
2317       dsconf plugin automember definition regex delete
2318              Removes Automembership regex.
2319
2320       dsconf plugin automember definition regex show
2321              Displays Automembership regex.
2322
2323

COMMAND 'dsconf plugin automember definition regex add'

2325       usage: dsconf  instance  plugin  automember  definition  DEFNAME  regex
2326       REGEXNAME add
2327              [-h] [--exclusive EXCLUSIVE [EXCLUSIVE ...]]
2328              [--inclusive  INCLUSIVE  [INCLUSIVE  ...]]  --target-group  TAR‐
2329       GET_GROUP
2330
2331

OPTIONS 'dsconf plugin automember definition regex add'

2333       --exclusive EXCLUSIVE [EXCLUSIVE ...]
2334              Sets a single regular expression to use to identify  entries  to
2335              exclude (autoMemberExclusiveRegex)
2336
2337
2338       --inclusive INCLUSIVE [INCLUSIVE ...]
2339              Sets  a  single regular expression to use to identify entries to
2340              include (autoMemberInclusiveRegex)
2341
2342
2343       --target-group TARGET_GROUP
2344              Sets which group to add the entry to as a member,  if  it  meets
2345              the regular expression conditions (autoMemberTargetGroup)
2346
2347

COMMAND 'dsconf plugin automember definition regex set'

2349       usage:  dsconf  instance  plugin  automember  definition  DEFNAME regex
2350       REGEXNAME set
2351              [-h] [--exclusive EXCLUSIVE [EXCLUSIVE ...]]
2352              [--inclusive  INCLUSIVE  [INCLUSIVE  ...]]  --target-group  TAR‐
2353       GET_GROUP
2354
2355

OPTIONS 'dsconf plugin automember definition regex set'

2357       --exclusive EXCLUSIVE [EXCLUSIVE ...]
2358              Sets  a  single regular expression to use to identify entries to
2359              exclude (autoMemberExclusiveRegex)
2360
2361
2362       --inclusive INCLUSIVE [INCLUSIVE ...]
2363              Sets a single regular expression to use to identify  entries  to
2364              include (autoMemberInclusiveRegex)
2365
2366
2367       --target-group TARGET_GROUP
2368              Sets  which  group  to add the entry to as a member, if it meets
2369              the regular expression conditions (autoMemberTargetGroup)
2370
2371

COMMAND 'dsconf plugin automember definition regex delete'

2373       usage: dsconf  instance  plugin  automember  definition  DEFNAME  regex
2374       REGEXNAME delete
2375              [-h]
2376
2377

COMMAND 'dsconf plugin automember definition regex show'

2379       usage:  dsconf  instance  plugin  automember  definition  DEFNAME regex
2380       REGEXNAME show
2381              [-h]
2382
2383

COMMAND 'dsconf plugin automember fixup'

2385       usage: dsconf instance plugin automember fixup [-h] -f FILTER -s
2386                                                      {sub,base,one} [--wait]
2387                                                      DN
2388
2389
2390       DN     Base DN that contains entries to fix up
2391
2392

OPTIONS 'dsconf plugin automember fixup'

2394       -f FILTER, --filter FILTER
2395              Sets the LDAP filter for entries to fix up
2396
2397
2398       -s {sub,base,one}, --scope {sub,base,one}
2399              Sets the LDAP search scope for entries to fix up
2400
2401
2402       --wait Wait for the task to finish, this could take a long time
2403
2404

COMMAND 'dsconf plugin automember fixup-status'

2406       usage: dsconf instance plugin automember fixup-status [-h] [--dn DN]
2407                                                             [--show-log]
2408       [--watch]
2409
2410

OPTIONS 'dsconf plugin automember fixup-status'

2412       --dn DN
2413              The task entry's DN
2414
2415
2416       --show-log
2417              Display the task log
2418
2419
2420       --watch
2421              Watch the task's status and wait for it to finish
2422
2423

COMMAND 'dsconf plugin automember abort-fixup'

2425       usage: dsconf instance plugin automember abort-fixup [-h]
2426
2427

COMMAND 'dsconf plugin referential-integrity'

2429       usage: dsconf instance plugin referential-integrity [-h]
2430                                                           {show,enable,dis‐
2431       able,status,set,config-entry}
2432                                                           ...
2433
2434

POSITIONAL ARGUMENTS 'dsconf plugin referential-integrity'

2436       dsconf plugin referential-integrity show
2437              Displays the plugin configuration
2438
2439       dsconf plugin referential-integrity enable
2440              Enables the plugin
2441
2442       dsconf plugin referential-integrity disable
2443              Disables the plugin
2444
2445       dsconf plugin referential-integrity status
2446              Displays the plugin status
2447
2448       dsconf plugin referential-integrity set
2449              Edit the plugin settings
2450
2451       dsconf plugin referential-integrity config-entry
2452              Manage the config entry
2453
2454

COMMAND 'dsconf plugin referential-integrity show'

2456       usage: dsconf instance plugin referential-integrity show [-h]
2457
2458

COMMAND 'dsconf plugin referential-integrity enable'

2460       usage: dsconf instance plugin referential-integrity enable [-h]
2461
2462

COMMAND 'dsconf plugin referential-integrity disable'

2464       usage: dsconf instance plugin referential-integrity disable [-h]
2465
2466

COMMAND 'dsconf plugin referential-integrity status'

2468       usage: dsconf instance plugin referential-integrity status [-h]
2469
2470

COMMAND 'dsconf plugin referential-integrity set'

2472       usage: dsconf instance plugin referential-integrity set [-h]
2473                                                               [--update-delay
2474       UPDATE_DELAY]
2475                                                               [--member‐
2476       ship-attr MEMBERSHIP_ATTR [MEMBERSHIP_ATTR ...]]
2477                                                               [--entry-scope
2478       ENTRY_SCOPE]
2479                                                               [--exclude-en‐
2480       try-scope EXCLUDE_ENTRY_SCOPE]
2481                                                               [--con‐
2482       tainer-scope CONTAINER_SCOPE]
2483                                                               [--log-file
2484       LOG_FILE]
2485                                                               [--config-entry
2486       CONFIG_ENTRY]
2487
2488

OPTIONS 'dsconf plugin referential-integrity set'

2490       --update-delay UPDATE_DELAY
2491              Sets  the update interval. Special values: 0 - The check is per‐
2492              formed immediately, -1 - No  check  is  performed  (referint-up‐
2493              date-delay)
2494
2495
2496       --membership-attr MEMBERSHIP_ATTR [MEMBERSHIP_ATTR ...]
2497              Specifies  attributes  to check for and update (referint-member‐
2498              ship-attr)
2499
2500
2501       --entry-scope ENTRY_SCOPE
2502              Defines the subtree in which the plug-in looks for the delete or
2503              rename operations of a user entry (nsslapd-pluginEntryScope)
2504
2505
2506       --exclude-entry-scope EXCLUDE_ENTRY_SCOPE
2507              Defines  the subtree in which the plug-in ignores any operations
2508              for  deleting  or  renaming  a  user   (nsslapd-pluginExcludeEn‐
2509              tryScope)
2510
2511
2512       --container-scope CONTAINER_SCOPE
2513              Specifies  which  branch  the plug-in searches for the groups to
2514              which the user belongs. It only updates groups  that  are  under
2515              the  specified container branch, and leaves all other groups not
2516              updated (nsslapd-pluginContainerScope)
2517
2518
2519       --log-file LOG_FILE
2520              Specifies a path to the Referential integrity logfile.For  exam‐
2521              ple: /var/log/dirsrv/slapd-YOUR_INSTANCE/referint
2522
2523
2524       --config-entry CONFIG_ENTRY
2525              The value to set as nsslapd-pluginConfigArea
2526
2527

COMMAND 'dsconf plugin referential-integrity config-entry'

2529       usage: dsconf instance plugin referential-integrity config-entry
2530              [-h] {add,set,show,delete} ...
2531
2532

POSITIONAL ARGUMENTS 'dsconf plugin referential-integrity config-entry'

2534       dsconf plugin referential-integrity config-entry add
2535              Add the config entry
2536
2537       dsconf plugin referential-integrity config-entry set
2538              Edit the config entry
2539
2540       dsconf plugin referential-integrity config-entry show
2541              Display the config entry
2542
2543       dsconf plugin referential-integrity config-entry delete
2544              Delete the config entry
2545
2546

COMMAND 'dsconf plugin referential-integrity config-entry add'

2548       usage: dsconf instance plugin referential-integrity config-entry add
2549              [-h] [--update-delay UPDATE_DELAY]
2550              [--membership-attr MEMBERSHIP_ATTR [MEMBERSHIP_ATTR ...]]
2551              [--entry-scope  ENTRY_SCOPE]  [--exclude-entry-scope EXCLUDE_EN‐
2552       TRY_SCOPE]
2553              [--container-scope CONTAINER_SCOPE] [--log-file LOG_FILE]
2554              DN
2555
2556
2557       DN     The config entry full DN
2558
2559

OPTIONS 'dsconf plugin referential-integrity config-entry add'

2561       --update-delay UPDATE_DELAY
2562              Sets the update interval. Special values: 0 - The check is  per‐
2563              formed  immediately,  -1  -  No check is performed (referint-up‐
2564              date-delay)
2565
2566
2567       --membership-attr MEMBERSHIP_ATTR [MEMBERSHIP_ATTR ...]
2568              Specifies attributes to check for and  update  (referint-member‐
2569              ship-attr)
2570
2571
2572       --entry-scope ENTRY_SCOPE
2573              Defines the subtree in which the plug-in looks for the delete or
2574              rename operations of a user entry (nsslapd-pluginEntryScope)
2575
2576
2577       --exclude-entry-scope EXCLUDE_ENTRY_SCOPE
2578              Defines the subtree in which the plug-in ignores any  operations
2579              for   deleting  or  renaming  a  user  (nsslapd-pluginExcludeEn‐
2580              tryScope)
2581
2582
2583       --container-scope CONTAINER_SCOPE
2584              Specifies which branch the plug-in searches for  the  groups  to
2585              which  the  user  belongs. It only updates groups that are under
2586              the specified container branch, and leaves all other groups  not
2587              updated (nsslapd-pluginContainerScope)
2588
2589
2590       --log-file LOG_FILE
2591              Specifies  a path to the Referential integrity logfile.For exam‐
2592              ple: /var/log/dirsrv/slapd-YOUR_INSTANCE/referint
2593
2594

COMMAND 'dsconf plugin referential-integrity config-entry set'

2596       usage: dsconf instance plugin referential-integrity config-entry set
2597              [-h] [--update-delay UPDATE_DELAY]
2598              [--membership-attr MEMBERSHIP_ATTR [MEMBERSHIP_ATTR ...]]
2599              [--entry-scope ENTRY_SCOPE]  [--exclude-entry-scope  EXCLUDE_EN‐
2600       TRY_SCOPE]
2601              [--container-scope CONTAINER_SCOPE] [--log-file LOG_FILE]
2602              DN
2603
2604
2605       DN     The config entry full DN
2606
2607

OPTIONS 'dsconf plugin referential-integrity config-entry set'

2609       --update-delay UPDATE_DELAY
2610              Sets  the update interval. Special values: 0 - The check is per‐
2611              formed immediately, -1 - No  check  is  performed  (referint-up‐
2612              date-delay)
2613
2614
2615       --membership-attr MEMBERSHIP_ATTR [MEMBERSHIP_ATTR ...]
2616              Specifies  attributes  to check for and update (referint-member‐
2617              ship-attr)
2618
2619
2620       --entry-scope ENTRY_SCOPE
2621              Defines the subtree in which the plug-in looks for the delete or
2622              rename operations of a user entry (nsslapd-pluginEntryScope)
2623
2624
2625       --exclude-entry-scope EXCLUDE_ENTRY_SCOPE
2626              Defines  the subtree in which the plug-in ignores any operations
2627              for  deleting  or  renaming  a  user   (nsslapd-pluginExcludeEn‐
2628              tryScope)
2629
2630
2631       --container-scope CONTAINER_SCOPE
2632              Specifies  which  branch  the plug-in searches for the groups to
2633              which the user belongs. It only updates groups  that  are  under
2634              the  specified container branch, and leaves all other groups not
2635              updated (nsslapd-pluginContainerScope)
2636
2637
2638       --log-file LOG_FILE
2639              Specifies a path to the Referential integrity logfile.For  exam‐
2640              ple: /var/log/dirsrv/slapd-YOUR_INSTANCE/referint
2641
2642

COMMAND 'dsconf plugin referential-integrity config-entry show'

2644       usage:  dsconf  instance plugin referential-integrity config-entry show
2645       [-h] DN
2646
2647
2648       DN     The config entry full DN
2649
2650

COMMAND 'dsconf plugin referential-integrity config-entry delete'

2652       usage: dsconf instance plugin referential-integrity config-entry delete
2653              [-h] DN
2654
2655
2656       DN     The config entry full DN
2657
2658

COMMAND 'dsconf plugin root-dn'

2660       usage: dsconf instance plugin root-dn [-h]
2661                                             {show,enable,disable,status,set}
2662       ...
2663
2664

POSITIONAL ARGUMENTS 'dsconf plugin root-dn'

2666       dsconf plugin root-dn show
2667              Displays the plugin configuration
2668
2669       dsconf plugin root-dn enable
2670              Enables the plugin
2671
2672       dsconf plugin root-dn disable
2673              Disables the plugin
2674
2675       dsconf plugin root-dn status
2676              Displays the plugin status
2677
2678       dsconf plugin root-dn set
2679              Edit the plugin settings
2680
2681

COMMAND 'dsconf plugin root-dn show'

2683       usage: dsconf instance plugin root-dn show [-h]
2684
2685

COMMAND 'dsconf plugin root-dn enable'

2687       usage: dsconf instance plugin root-dn enable [-h]
2688
2689

COMMAND 'dsconf plugin root-dn disable'

2691       usage: dsconf instance plugin root-dn disable [-h]
2692
2693

COMMAND 'dsconf plugin root-dn status'

2695       usage: dsconf instance plugin root-dn status [-h]
2696
2697

COMMAND 'dsconf plugin root-dn set'

2699       usage: dsconf instance plugin root-dn set [-h]
2700                                                 [--allow-host ALLOW_HOST [AL‐
2701       LOW_HOST ...]]
2702                                                 [--deny-host        DENY_HOST
2703       [DENY_HOST ...]]
2704                                                 [--allow-ip   ALLOW_IP   [AL‐
2705       LOW_IP ...]]
2706                                                 [--deny-ip  DENY_IP  [DENY_IP
2707       ...]]
2708                                                 [--open-time OPEN_TIME]
2709                                                 [--close-time CLOSE_TIME]
2710                                                 [--days-allowed DAYS_ALLOWED]
2711
2712

OPTIONS 'dsconf plugin root-dn set'

2714       --allow-host ALLOW_HOST [ALLOW_HOST ...]
2715              Sets  what  hosts, by fully-qualified domain name, the root user
2716              is allowed to use to access  Directory  Server.  Any  hosts  not
2717              listed are implicitly denied (rootdn-allow-host)
2718
2719
2720       --deny-host DENY_HOST [DENY_HOST ...]
2721              Sets  what  hosts, by fully-qualified domain name, the root user
2722              is not allowed to use to access Directory Server. Any hosts  not
2723              listed  are implicitly allowed (rootdn-deny-host). If a host ad‐
2724              dress   is   listed   in   both   the   rootdn-allow-host    and
2725              rootdn-deny-host attributes, it is denied access.
2726
2727
2728       --allow-ip ALLOW_IP [ALLOW_IP ...]
2729              Sets  what  IP  addresses, either IPv4 or IPv6, for machines the
2730              root user is allowed to use to access Directory Server.  Any  IP
2731              addresses not listed are implicitly denied (rootdn-allow-ip)
2732
2733
2734       --deny-ip DENY_IP [DENY_IP ...]
2735              Sets  what  IP  addresses, either IPv4 or IPv6, for machines the
2736              root user is not allowed to use to access Directory Server.  Any
2737              IP addresses not listed are implicitly allowed (rootdn-deny-ip).
2738              If an IP address is  listed  in  both  the  rootdn-allow-ip  and
2739              rootdn-deny-ip attributes, it is denied access.
2740
2741
2742       --open-time OPEN_TIME
2743              Sets  part  of  a time period or range when the root user is al‐
2744              lowed to access Directory Server. This sets when the  time-based
2745              access begins (rootdn-open- time)
2746
2747
2748       --close-time CLOSE_TIME
2749              Sets  part  of  a time period or range when the root user is al‐
2750              lowed to access Directory Server. This sets when the  time-based
2751              access ends (rootdn-close- time)
2752
2753
2754       --days-allowed DAYS_ALLOWED
2755              Sets  a  comma-separated  list of what days the root user is al‐
2756              lowed to use to access Directory Server. Any days listed are im‐
2757              plicitly denied (rootdn-days- allowed)
2758
2759

COMMAND 'dsconf plugin usn'

2761       usage: dsconf instance plugin usn [-h]
2762                                         {show,enable,disable,sta‐
2763       tus,global,cleanup}
2764                                         ...
2765
2766

POSITIONAL ARGUMENTS 'dsconf plugin usn'

2768       dsconf plugin usn show
2769              Displays the plugin configuration
2770
2771       dsconf plugin usn enable
2772              Enables the plugin
2773
2774       dsconf plugin usn disable
2775              Disables the plugin
2776
2777       dsconf plugin usn status
2778              Displays the plugin status
2779
2780       dsconf plugin usn global
2781              Get or manage global USN mode (nsslapd-entryusn-global)
2782
2783       dsconf plugin usn cleanup
2784              Runs the USN tombstone cleanup task
2785
2786

COMMAND 'dsconf plugin usn show'

2788       usage: dsconf instance plugin usn show [-h]
2789
2790

COMMAND 'dsconf plugin usn enable'

2792       usage: dsconf instance plugin usn enable [-h]
2793
2794

COMMAND 'dsconf plugin usn disable'

2796       usage: dsconf instance plugin usn disable [-h]
2797
2798

COMMAND 'dsconf plugin usn status'

2800       usage: dsconf instance plugin usn status [-h]
2801
2802

COMMAND 'dsconf plugin usn global'

2804       usage: dsconf instance plugin usn global [-h] {on,off} ...
2805
2806

POSITIONAL ARGUMENTS 'dsconf plugin usn global'

2808       dsconf plugin usn global on
2809              Enables USN global mode
2810
2811       dsconf plugin usn global off
2812              Disables USN global mode
2813
2814

COMMAND 'dsconf plugin usn global on'

2816       usage: dsconf instance plugin usn global on [-h]
2817
2818

COMMAND 'dsconf plugin usn global off'

2820       usage: dsconf instance plugin usn global off [-h]
2821
2822

COMMAND 'dsconf plugin usn cleanup'

2824       usage: dsconf instance plugin usn cleanup [-h] (-s SUFFIX | -n BACKEND)
2825                                                 [-m MAX_USN]
2826
2827

OPTIONS 'dsconf plugin usn cleanup'

2829       -s SUFFIX, --suffix SUFFIX
2830              Sets the suffix or  subtree  in  Directory  Server  to  run  the
2831              cleanup  operation against. If the suffix is not specified, then
2832              the back end must be specified (suffix).
2833
2834
2835       -n BACKEND, --backend BACKEND
2836              Sets the Directory Server instance back end, or database, to run
2837              the cleanup operation against. If the back end is not specified,
2838              then the suffix must be specified. Backend instance in which USN
2839              tombstone entries (backend)
2840
2841
2842       -m MAX_USN, --max-usn MAX_USN
2843              Sets the highest USN value to delete when removing tombstone en‐
2844              tries (max_usn_to_delete)
2845
2846

COMMAND 'dsconf plugin account-policy'

2848       usage: dsconf instance plugin account-policy [-h]
2849                                                    {show,enable,disable,sta‐
2850       tus,set,config-entry}
2851                                                    ...
2852
2853

POSITIONAL ARGUMENTS 'dsconf plugin account-policy'

2855       dsconf plugin account-policy show
2856              Displays the plugin configuration
2857
2858       dsconf plugin account-policy enable
2859              Enables the plugin
2860
2861       dsconf plugin account-policy disable
2862              Disables the plugin
2863
2864       dsconf plugin account-policy status
2865              Displays the plugin status
2866
2867       dsconf plugin account-policy set
2868              Edit the plugin settings
2869
2870       dsconf plugin account-policy config-entry
2871              Manage the config entry
2872
2873

COMMAND 'dsconf plugin account-policy show'

2875       usage: dsconf instance plugin account-policy show [-h]
2876
2877

COMMAND 'dsconf plugin account-policy enable'

2879       usage: dsconf instance plugin account-policy enable [-h]
2880
2881

COMMAND 'dsconf plugin account-policy disable'

2883       usage: dsconf instance plugin account-policy disable [-h]
2884
2885

COMMAND 'dsconf plugin account-policy status'

2887       usage: dsconf instance plugin account-policy status [-h]
2888
2889

COMMAND 'dsconf plugin account-policy set'

2891       usage: dsconf instance plugin account-policy set [-h]
2892                                                        [--config-entry   CON‐
2893       FIG_ENTRY]
2894
2895

OPTIONS 'dsconf plugin account-policy set'

2897       --config-entry CONFIG_ENTRY
2898              Sets the nsslapd-pluginConfigArea attribute
2899
2900

COMMAND 'dsconf plugin account-policy config-entry'

2902       usage: dsconf instance plugin account-policy config-entry [-h]
2903                                                                 {add,set,show,delete}
2904                                                                 ...
2905
2906

POSITIONAL ARGUMENTS 'dsconf plugin account-policy config-entry'

2908       dsconf plugin account-policy config-entry add
2909              Add the config entry
2910
2911       dsconf plugin account-policy config-entry set
2912              Edit the config entry
2913
2914       dsconf plugin account-policy config-entry show
2915              Display the config entry
2916
2917       dsconf plugin account-policy config-entry delete
2918              Delete the config entry
2919
2920

COMMAND 'dsconf plugin account-policy config-entry add'

2922       usage: dsconf instance plugin account-policy config-entry add
2923              [-h]    [--always-record-login    {yes,no}]    [--alt-state-attr
2924       ALT_STATE_ATTR]
2925              [--always-record-login-attr ALWAYS_RECORD_LOGIN_ATTR]
2926              [--limit-attr LIMIT_ATTR] [--spec-attr SPEC_ATTR]
2927              [--state-attr STATE_ATTR]
2928              DN
2929
2930
2931       DN     The full DN of the config entry
2932
2933

OPTIONS 'dsconf plugin account-policy config-entry add'

2935       --always-record-login {yes,no}
2936              Sets that every entry records its last login time (alwaysRecord‐
2937              Login)
2938
2939
2940       --alt-state-attr ALT_STATE_ATTR
2941              Provides a backup attribute for the server to reference to eval‐
2942              uate the expiration time (altStateAttrName)
2943
2944
2945       --always-record-login-attr ALWAYS_RECORD_LOGIN_ATTR
2946              Specifies the attribute to store the time of the last successful
2947              login  in  this  attribute  in  the  users  directory entry (al‐
2948              waysRecordLoginAttr)
2949
2950
2951       --limit-attr LIMIT_ATTR
2952              Specifies the attribute within the policy to use for the account
2953              inactivation limit (limitAttrName)
2954
2955
2956       --spec-attr SPEC_ATTR
2957              Specifies  the  attribute  to identify which entries are account
2958              policy configuration entries (specAttrName)
2959
2960
2961       --state-attr STATE_ATTR
2962              Specifies the primary time attribute used to evaluate an account
2963              policy (stateAttrName)
2964
2965

COMMAND 'dsconf plugin account-policy config-entry set'

2967       usage: dsconf instance plugin account-policy config-entry set
2968              [-h]    [--always-record-login    {yes,no}]    [--alt-state-attr
2969       ALT_STATE_ATTR]
2970              [--always-record-login-attr ALWAYS_RECORD_LOGIN_ATTR]
2971              [--limit-attr LIMIT_ATTR] [--spec-attr SPEC_ATTR]
2972              [--state-attr STATE_ATTR]
2973              DN
2974
2975
2976       DN     The full DN of the config entry
2977
2978

OPTIONS 'dsconf plugin account-policy config-entry set'

2980       --always-record-login {yes,no}
2981              Sets that every entry records its last login time (alwaysRecord‐
2982              Login)
2983
2984
2985       --alt-state-attr ALT_STATE_ATTR
2986              Provides a backup attribute for the server to reference to eval‐
2987              uate the expiration time (altStateAttrName)
2988
2989
2990       --always-record-login-attr ALWAYS_RECORD_LOGIN_ATTR
2991              Specifies the attribute to store the time of the last successful
2992              login  in  this  attribute  in  the  users  directory entry (al‐
2993              waysRecordLoginAttr)
2994
2995
2996       --limit-attr LIMIT_ATTR
2997              Specifies the attribute within the policy to use for the account
2998              inactivation limit (limitAttrName)
2999
3000
3001       --spec-attr SPEC_ATTR
3002              Specifies  the  attribute  to identify which entries are account
3003              policy configuration entries (specAttrName)
3004
3005
3006       --state-attr STATE_ATTR
3007              Specifies the primary time attribute used to evaluate an account
3008              policy (stateAttrName)
3009
3010

COMMAND 'dsconf plugin account-policy config-entry show'

3012       usage: dsconf instance plugin account-policy config-entry show [-h] DN
3013
3014
3015       DN     The full DN of the config entry
3016
3017

COMMAND 'dsconf plugin account-policy config-entry delete'

3019       usage:  dsconf  instance plugin account-policy config-entry delete [-h]
3020       DN
3021
3022
3023       DN     The full DN of the config entry
3024
3025

COMMAND 'dsconf plugin attr-uniq'

3027       usage: dsconf instance plugin attr-uniq [-h]
3028                                               {list,add,set,show,delete,en‐
3029       able,disable,status}
3030                                               ...
3031
3032

POSITIONAL ARGUMENTS 'dsconf plugin attr-uniq'

3034       dsconf plugin attr-uniq list
3035              Lists available plugin configs
3036
3037       dsconf plugin attr-uniq add
3038              Add the config entry
3039
3040       dsconf plugin attr-uniq set
3041              Edit the config entry
3042
3043       dsconf plugin attr-uniq show
3044              Display the config entry
3045
3046       dsconf plugin attr-uniq delete
3047              Delete the config entry
3048
3049       dsconf plugin attr-uniq enable
3050              enable plugin
3051
3052       dsconf plugin attr-uniq disable
3053              disable plugin
3054
3055       dsconf plugin attr-uniq status
3056              display plugin status
3057
3058

COMMAND 'dsconf plugin attr-uniq list'

3060       usage: dsconf instance plugin attr-uniq list [-h]
3061
3062

COMMAND 'dsconf plugin attr-uniq add'

3064       usage: dsconf instance plugin attr-uniq add [-h] [--enabled {on,off}]
3065                                                   [--attr-name      ATTR_NAME
3066       [ATTR_NAME ...]]
3067                                                   [--subtree SUBTREE [SUBTREE
3068       ...]]
3069                                                   [--across-all-subtrees
3070       {on,off}]
3071                                                   [--top-entry-oc     TOP_EN‐
3072       TRY_OC]
3073                                                   [--subtree-entries-oc  SUB‐
3074       TREE_ENTRIES_OC]
3075                                                   NAME
3076
3077
3078       NAME   The name of the plug-in configuration record. (cn) You  can  use
3079              any  string, but "attribute_name Attribute Uniqueness" is recom‐
3080              mended.
3081
3082

OPTIONS 'dsconf plugin attr-uniq add'

3084       --enabled {on,off}
3085              Identifies whether or not the config is enabled.
3086
3087
3088       --attr-name ATTR_NAME [ATTR_NAME ...]
3089              Sets the name of the attribute whose values must be unique. This
3090              attribute is multi-valued. (uniqueness-attribute-name)
3091
3092
3093       --subtree SUBTREE [SUBTREE ...]
3094              Sets the DN under which the plug-in checks for uniqueness of the
3095              attributes  value.  This  attribute  is  multi-valued   (unique‐
3096              ness-subtrees)
3097
3098
3099       --across-all-subtrees {on,off}
3100              If enabled (on), the plug-in checks that the attribute is unique
3101              across all subtrees set.  If  you  set  the  attribute  to  off,
3102              uniqueness  is  only  enforced within the subtree of the updated
3103              entry (uniqueness-across-all-subtrees)
3104
3105
3106       --top-entry-oc TOP_ENTRY_OC
3107              Verifies that the value of the attribute set  in  uniqueness-at‐
3108              tribute-name is unique in this subtree (uniqueness-top-entry-oc)
3109
3110
3111       --subtree-entries-oc SUBTREE_ENTRIES_OC
3112              Verifies  if  an  attribute is unique, if the entry contains the
3113              object  class  set  in  this  parameter  (uniqueness-subtree-en‐
3114              tries-oc)
3115
3116

COMMAND 'dsconf plugin attr-uniq set'

3118       usage: dsconf instance plugin attr-uniq set [-h] [--enabled {on,off}]
3119                                                   [--attr-name      ATTR_NAME
3120       [ATTR_NAME ...]]
3121                                                   [--subtree SUBTREE [SUBTREE
3122       ...]]
3123                                                   [--across-all-subtrees
3124       {on,off}]
3125                                                   [--top-entry-oc     TOP_EN‐
3126       TRY_OC]
3127                                                   [--subtree-entries-oc  SUB‐
3128       TREE_ENTRIES_OC]
3129                                                   NAME
3130
3131
3132       NAME   The name of the plug-in configuration record. (cn) You  can  use
3133              any  string, but "attribute_name Attribute Uniqueness" is recom‐
3134              mended.
3135
3136

OPTIONS 'dsconf plugin attr-uniq set'

3138       --enabled {on,off}
3139              Identifies whether or not the config is enabled.
3140
3141
3142       --attr-name ATTR_NAME [ATTR_NAME ...]
3143              Sets the name of the attribute whose values must be unique. This
3144              attribute is multi-valued. (uniqueness-attribute-name)
3145
3146
3147       --subtree SUBTREE [SUBTREE ...]
3148              Sets the DN under which the plug-in checks for uniqueness of the
3149              attributes  value.  This  attribute  is  multi-valued   (unique‐
3150              ness-subtrees)
3151
3152
3153       --across-all-subtrees {on,off}
3154              If enabled (on), the plug-in checks that the attribute is unique
3155              across all subtrees set.  If  you  set  the  attribute  to  off,
3156              uniqueness  is  only  enforced within the subtree of the updated
3157              entry (uniqueness-across-all-subtrees)
3158
3159
3160       --top-entry-oc TOP_ENTRY_OC
3161              Verifies that the value of the attribute set  in  uniqueness-at‐
3162              tribute-name is unique in this subtree (uniqueness-top-entry-oc)
3163
3164
3165       --subtree-entries-oc SUBTREE_ENTRIES_OC
3166              Verifies  if  an  attribute is unique, if the entry contains the
3167              object  class  set  in  this  parameter  (uniqueness-subtree-en‐
3168              tries-oc)
3169
3170

COMMAND 'dsconf plugin attr-uniq show'

3172       usage: dsconf instance plugin attr-uniq show [-h] NAME
3173
3174
3175       NAME   The name of the plug-in configuration record
3176
3177

COMMAND 'dsconf plugin attr-uniq delete'

3179       usage: dsconf instance plugin attr-uniq delete [-h] NAME
3180
3181
3182       NAME   The name of the plug-in configuration record
3183
3184

COMMAND 'dsconf plugin attr-uniq enable'

3186       usage: dsconf instance plugin attr-uniq enable [-h] NAME
3187
3188
3189       NAME   The name of the plug-in configuration record
3190
3191

COMMAND 'dsconf plugin attr-uniq disable'

3193       usage: dsconf instance plugin attr-uniq disable [-h] NAME
3194
3195
3196       NAME   The name of the plug-in configuration record
3197
3198

COMMAND 'dsconf plugin attr-uniq status'

3200       usage: dsconf instance plugin attr-uniq status [-h] NAME
3201
3202
3203       NAME   The name of the plug-in configuration record
3204
3205

COMMAND 'dsconf plugin dna'

3207       usage: dsconf instance plugin dna [-h]
3208                                         {show,enable,disable,status,list,con‐
3209       fig} ...
3210
3211

POSITIONAL ARGUMENTS 'dsconf plugin dna'

3213       dsconf plugin dna show
3214              Displays the plugin configuration
3215
3216       dsconf plugin dna enable
3217              Enables the plugin
3218
3219       dsconf plugin dna disable
3220              Disables the plugin
3221
3222       dsconf plugin dna status
3223              Displays the plugin status
3224
3225       dsconf plugin dna list
3226              List available plugin configs
3227
3228       dsconf plugin dna config
3229              Manage plugin configs
3230
3231

COMMAND 'dsconf plugin dna show'

3233       usage: dsconf instance plugin dna show [-h]
3234
3235

COMMAND 'dsconf plugin dna enable'

3237       usage: dsconf instance plugin dna enable [-h]
3238
3239

COMMAND 'dsconf plugin dna disable'

3241       usage: dsconf instance plugin dna disable [-h]
3242
3243

COMMAND 'dsconf plugin dna status'

3245       usage: dsconf instance plugin dna status [-h]
3246
3247

COMMAND 'dsconf plugin dna list'

3249       usage: dsconf instance plugin dna  list  [-h]  {configs,shared-configs}
3250       ...
3251
3252

POSITIONAL ARGUMENTS 'dsconf plugin dna list'

3254       dsconf plugin dna list configs
3255              List main DNA plugin config entries
3256
3257       dsconf plugin dna list shared-configs
3258              List DNA plugin shared config entries
3259
3260

COMMAND 'dsconf plugin dna list configs'

3262       usage: dsconf instance plugin dna list configs [-h]
3263
3264

COMMAND 'dsconf plugin dna list shared-configs'

3266       usage: dsconf instance plugin dna list shared-configs [-h] BASEDN
3267
3268
3269       BASEDN The search DN
3270
3271

COMMAND 'dsconf plugin dna config'

3273       usage: dsconf instance plugin dna config [-h]
3274                                                NAME
3275                                                {add,set,show,delete,shared-con‐
3276       fig-entry}
3277                                                ...
3278
3279

POSITIONAL ARGUMENTS 'dsconf plugin dna config'

3281       dsconf plugin dna config add
3282              Add the config entry
3283
3284       dsconf plugin dna config set
3285              Edit the config entry
3286
3287       dsconf plugin dna config show
3288              Display the config entry
3289
3290       dsconf plugin dna config delete
3291              Delete the config entry
3292
3293       dsconf plugin dna config shared-config-entry
3294              Manage the shared config entry
3295
3296

COMMAND 'dsconf plugin dna config add'

3298       usage: dsconf instance plugin dna config NAME add [-h]
3299                                                         [--type  TYPE   [TYPE
3300       ...]]
3301                                                         [--prefix PREFIX]
3302                                                         [--next-value
3303       NEXT_VALUE]
3304                                                         [--max-value
3305       MAX_VALUE]
3306                                                         [--interval INTERVAL]
3307                                                         [--magic-regen
3308       MAGIC_REGEN]
3309                                                         [--filter FILTER]
3310                                                         [--scope SCOPE]
3311                                                         [--remote-bind-dn RE‐
3312       MOTE_BIND_DN]
3313                                                         [--remote-bind-cred
3314       REMOTE_BIND_CRED]
3315                                                         [--shared-config-en‐
3316       try SHARED_CONFIG_ENTRY]
3317                                                         [--threshold  THRESH‐
3318       OLD]
3319                                                         [--next-range
3320       NEXT_RANGE]
3321                                                         [--range-re‐
3322       quest-timeout RANGE_REQUEST_TIMEOUT]
3323
3324

OPTIONS 'dsconf plugin dna config add'

3326       --type TYPE [TYPE ...]
3327              Sets which attributes have unique numbers  being  generated  for
3328              them (dnaType)
3329
3330
3331       --prefix PREFIX
3332              Defines  a  prefix that can be prepended to the generated number
3333              values for the attribute (dnaPrefix)
3334
3335
3336       --next-value NEXT_VALUE
3337              Sets  the  next  available  number   which   can   be   assigned
3338              (dnaNextValue)
3339
3340
3341       --max-value MAX_VALUE
3342              Sets  the maximum value that can be assigned for the range (dna‐
3343              MaxValue)
3344
3345
3346       --interval INTERVAL
3347              Sets an interval to use to increment through numbers in a  range
3348              (dnaInterval)
3349
3350
3351       --magic-regen MAGIC_REGEN
3352              Sets a user-defined value that instructs the plug-in to assign a
3353              new value for the entry (dnaMagicRegen)
3354
3355
3356       --filter FILTER
3357              Sets an LDAP filter to use to search for and  identify  the  en‐
3358              tries to which to apply the distributed numeric assignment range
3359              (dnaFilter)
3360
3361
3362       --scope SCOPE
3363              Sets the base DN to search for entries to  which  to  apply  the
3364              distributed numeric assignment (dnaScope)
3365
3366
3367       --remote-bind-dn REMOTE_BIND_DN
3368              Specifies the Replication Manager DN (dnaRemoteBindDN)
3369
3370
3371       --remote-bind-cred REMOTE_BIND_CRED
3372              Specifies the Replication Manager's password (dnaRemoteBindCred)
3373
3374
3375       --shared-config-entry SHARED_CONFIG_ENTRY
3376              Defines  a  shared identity that the servers can use to transfer
3377              ranges to one another (dnaSharedCfgDN)
3378
3379
3380       --threshold THRESHOLD
3381              Sets a threshold of remaining available numbers  in  the  range.
3382              When the server hits the threshold, it sends a request for a new
3383              range (dnaThreshold)
3384
3385
3386       --next-range NEXT_RANGE
3387              Defines the next range to use when  the  current  range  is  ex‐
3388              hausted (dnaNextRange)
3389
3390
3391       --range-request-timeout RANGE_REQUEST_TIMEOUT
3392              Sets  a  timeout  period, in seconds, for range requests so that
3393              the server does not stall waiting on a new range from one server
3394              and  can request a range from a new server (dnaRangeRequestTime‐
3395              out)
3396
3397

COMMAND 'dsconf plugin dna config set'

3399       usage: dsconf instance plugin dna config NAME set [-h]
3400                                                         [--type  TYPE   [TYPE
3401       ...]]
3402                                                         [--prefix PREFIX]
3403                                                         [--next-value
3404       NEXT_VALUE]
3405                                                         [--max-value
3406       MAX_VALUE]
3407                                                         [--interval INTERVAL]
3408                                                         [--magic-regen
3409       MAGIC_REGEN]
3410                                                         [--filter FILTER]
3411                                                         [--scope SCOPE]
3412                                                         [--remote-bind-dn RE‐
3413       MOTE_BIND_DN]
3414                                                         [--remote-bind-cred
3415       REMOTE_BIND_CRED]
3416                                                         [--shared-config-en‐
3417       try SHARED_CONFIG_ENTRY]
3418                                                         [--threshold  THRESH‐
3419       OLD]
3420                                                         [--next-range
3421       NEXT_RANGE]
3422                                                         [--range-re‐
3423       quest-timeout RANGE_REQUEST_TIMEOUT]
3424
3425

OPTIONS 'dsconf plugin dna config set'

3427       --type TYPE [TYPE ...]
3428              Sets which attributes have unique numbers  being  generated  for
3429              them (dnaType)
3430
3431
3432       --prefix PREFIX
3433              Defines  a  prefix that can be prepended to the generated number
3434              values for the attribute (dnaPrefix)
3435
3436
3437       --next-value NEXT_VALUE
3438              Sets  the  next  available  number   which   can   be   assigned
3439              (dnaNextValue)
3440
3441
3442       --max-value MAX_VALUE
3443              Sets  the maximum value that can be assigned for the range (dna‐
3444              MaxValue)
3445
3446
3447       --interval INTERVAL
3448              Sets an interval to use to increment through numbers in a  range
3449              (dnaInterval)
3450
3451
3452       --magic-regen MAGIC_REGEN
3453              Sets a user-defined value that instructs the plug-in to assign a
3454              new value for the entry (dnaMagicRegen)
3455
3456
3457       --filter FILTER
3458              Sets an LDAP filter to use to search for and  identify  the  en‐
3459              tries to which to apply the distributed numeric assignment range
3460              (dnaFilter)
3461
3462
3463       --scope SCOPE
3464              Sets the base DN to search for entries to  which  to  apply  the
3465              distributed numeric assignment (dnaScope)
3466
3467
3468       --remote-bind-dn REMOTE_BIND_DN
3469              Specifies the Replication Manager DN (dnaRemoteBindDN)
3470
3471
3472       --remote-bind-cred REMOTE_BIND_CRED
3473              Specifies the Replication Manager's password (dnaRemoteBindCred)
3474
3475
3476       --shared-config-entry SHARED_CONFIG_ENTRY
3477              Defines  a  shared identity that the servers can use to transfer
3478              ranges to one another (dnaSharedCfgDN)
3479
3480
3481       --threshold THRESHOLD
3482              Sets a threshold of remaining available numbers  in  the  range.
3483              When the server hits the threshold, it sends a request for a new
3484              range (dnaThreshold)
3485
3486
3487       --next-range NEXT_RANGE
3488              Defines the next range to use when  the  current  range  is  ex‐
3489              hausted (dnaNextRange)
3490
3491
3492       --range-request-timeout RANGE_REQUEST_TIMEOUT
3493              Sets  a  timeout  period, in seconds, for range requests so that
3494              the server does not stall waiting on a new range from one server
3495              and  can request a range from a new server (dnaRangeRequestTime‐
3496              out)
3497
3498

COMMAND 'dsconf plugin dna config show'

3500       usage: dsconf instance plugin dna config NAME show [-h]
3501
3502

COMMAND 'dsconf plugin dna config delete'

3504       usage: dsconf instance plugin dna config NAME delete [-h]
3505
3506

COMMAND 'dsconf plugin dna config shared-config-entry'

3508       usage: dsconf instance plugin dna config NAME shared-config-entry
3509              [-h] SHARED_CFG {set,show,delete} ...
3510
3511

POSITIONAL ARGUMENTS 'dsconf plugin dna config shared-config-entry'

3513       dsconf plugin dna config shared-config-entry set
3514              Edit the shared config entry
3515
3516       dsconf plugin dna config shared-config-entry show
3517              Display the shared config entry
3518
3519       dsconf plugin dna config shared-config-entry delete
3520              Delete the shared config entry
3521
3522

COMMAND 'dsconf plugin dna config shared-config-entry set'

3524       usage: dsconf  instance  plugin  dna  config  NAME  shared-config-entry
3525       SHARED_CFG set
3526              [-h] [--remote-bind-method REMOTE_BIND_METHOD]
3527              [--remote-conn-protocol REMOTE_CONN_PROTOCOL]
3528
3529

OPTIONS 'dsconf plugin dna config shared-config-entry set'

3531       --remote-bind-method REMOTE_BIND_METHOD
3532              Specifies the remote bind method "SIMPLE", "SSL" (for SSL client
3533              auth), "SASL/GSSAPI", or "SASL/DIGEST-MD5" (dnaRemoteBindMethod)
3534
3535
3536       --remote-conn-protocol REMOTE_CONN_PROTOCOL
3537              Specifies  the  remote  connection  protocol  "LDAP",  or  "TLS"
3538              (dnaRemoteConnProtocol)
3539
3540

COMMAND 'dsconf plugin dna config shared-config-entry show'

3542       usage:  dsconf  instance  plugin  dna  config  NAME shared-config-entry
3543       SHARED_CFG show
3544              [-h]
3545
3546

COMMAND 'dsconf plugin dna config shared-config-entry delete'

3548       usage: dsconf  instance  plugin  dna  config  NAME  shared-config-entry
3549       SHARED_CFG delete
3550              [-h]
3551
3552

COMMAND 'dsconf plugin ldap-pass-through-auth'

3554       usage: dsconf instance plugin ldap-pass-through-auth [-h]
3555                                                            {show,enable,dis‐
3556       able,status,list,add,modify,delete}
3557                                                            ...
3558
3559

POSITIONAL ARGUMENTS 'dsconf plugin ldap-pass-through-auth'

3561       dsconf plugin ldap-pass-through-auth show
3562              Displays the plugin configuration
3563
3564       dsconf plugin ldap-pass-through-auth enable
3565              Enables the plugin
3566
3567       dsconf plugin ldap-pass-through-auth disable
3568              Disables the plugin
3569
3570       dsconf plugin ldap-pass-through-auth status
3571              Displays the plugin status
3572
3573       dsconf plugin ldap-pass-through-auth list
3574              Lists LDAP URLs
3575
3576       dsconf plugin ldap-pass-through-auth add
3577              Add an LDAP url to the config entry
3578
3579       dsconf plugin ldap-pass-through-auth modify
3580              Edit the LDAP pass through config entry
3581
3582       dsconf plugin ldap-pass-through-auth delete
3583              Delete a URL from the config entry
3584
3585

COMMAND 'dsconf plugin ldap-pass-through-auth show'

3587       usage: dsconf instance plugin ldap-pass-through-auth show [-h]
3588
3589

COMMAND 'dsconf plugin ldap-pass-through-auth enable'

3591       usage: dsconf instance plugin ldap-pass-through-auth enable [-h]
3592
3593

COMMAND 'dsconf plugin ldap-pass-through-auth disable'

3595       usage: dsconf instance plugin ldap-pass-through-auth disable [-h]
3596
3597

COMMAND 'dsconf plugin ldap-pass-through-auth status'

3599       usage: dsconf instance plugin ldap-pass-through-auth status [-h]
3600
3601

COMMAND 'dsconf plugin ldap-pass-through-auth list'

3603       usage: dsconf instance plugin ldap-pass-through-auth list [-h]
3604
3605

COMMAND 'dsconf plugin ldap-pass-through-auth add'

3607       usage: dsconf instance plugin ldap-pass-through-auth add [-h] URL
3608
3609
3610       URL    The full LDAP URL in  format  "ldap|ldaps://authDS/subtree  max‐
3611              conns,maxops,timeout,ldver,connlifetime,startTLS".  If  one  op‐
3612              tional parameter is specified the rest should be specified too
3613
3614

COMMAND 'dsconf plugin ldap-pass-through-auth modify'

3616       usage: dsconf instance plugin ldap-pass-through-auth modify
3617              [-h] OLD_URL NEW_URL
3618
3619
3620       OLD_URL
3621              The full LDAP URL you get from the "list" command
3622
3623
3624       NEW_URL
3625              Sets the full LDAP URL  in  format  "ldap|ldaps://authDS/subtree
3626              maxconns,maxops,timeout,ldver,connlifetime,startTLS". If one op‐
3627              tional parameter is specified the rest should be specified too.
3628
3629

COMMAND 'dsconf plugin ldap-pass-through-auth delete'

3631       usage: dsconf instance plugin ldap-pass-through-auth delete [-h] URL
3632
3633
3634       URL    The full LDAP URL you get from the "list" command
3635
3636

COMMAND 'dsconf plugin linked-attr'

3638       usage: dsconf instance plugin linked-attr [-h]
3639                                                 {show,enable,disable,sta‐
3640       tus,fixup,fixup-status,list,config}
3641                                                 ...
3642
3643

POSITIONAL ARGUMENTS 'dsconf plugin linked-attr'

3645       dsconf plugin linked-attr show
3646              Displays the plugin configuration
3647
3648       dsconf plugin linked-attr enable
3649              Enables the plugin
3650
3651       dsconf plugin linked-attr disable
3652              Disables the plugin
3653
3654       dsconf plugin linked-attr status
3655              Displays the plugin status
3656
3657       dsconf plugin linked-attr fixup
3658              Run the fix-up task for linked attributes plugin
3659
3660       dsconf plugin linked-attr fixup-status
3661              Check the status of a fix-up task
3662
3663       dsconf plugin linked-attr list
3664              List available plugin configs
3665
3666       dsconf plugin linked-attr config
3667              Manage plugin configs
3668
3669

COMMAND 'dsconf plugin linked-attr show'

3671       usage: dsconf instance plugin linked-attr show [-h]
3672
3673

COMMAND 'dsconf plugin linked-attr enable'

3675       usage: dsconf instance plugin linked-attr enable [-h]
3676
3677

COMMAND 'dsconf plugin linked-attr disable'

3679       usage: dsconf instance plugin linked-attr disable [-h]
3680
3681

COMMAND 'dsconf plugin linked-attr status'

3683       usage: dsconf instance plugin linked-attr status [-h]
3684
3685

COMMAND 'dsconf plugin linked-attr fixup'

3687       usage:  dsconf  instance  plugin  linked-attr  fixup  [-h]  [-l LINKDN]
3688       [--wait]
3689
3690

OPTIONS 'dsconf plugin linked-attr fixup'

3692       -l LINKDN, --linkdn LINKDN
3693              Sets the base DN that contains entries to fix up
3694
3695
3696       --wait Wait for the task to finish, this could take a long time
3697
3698

COMMAND 'dsconf plugin linked-attr fixup-status'

3700       usage: dsconf instance plugin linked-attr fixup-status [-h] [--dn DN]
3701                                                              [--show-log]
3702       [--watch]
3703
3704

OPTIONS 'dsconf plugin linked-attr fixup-status'

3706       --dn DN
3707              The task entry's DN
3708
3709
3710       --show-log
3711              Display the task log
3712
3713
3714       --watch
3715              Watch the task's status and wait for it to finish
3716
3717

COMMAND 'dsconf plugin linked-attr list'

3719       usage: dsconf instance plugin linked-attr list [-h]
3720
3721

COMMAND 'dsconf plugin linked-attr config'

3723       usage: dsconf instance plugin linked-attr config [-h]
3724                                                        NAME
3725       {add,set,show,delete}
3726                                                        ...
3727
3728

POSITIONAL ARGUMENTS 'dsconf plugin linked-attr config'

3730       dsconf plugin linked-attr config add
3731              Add the config entry
3732
3733       dsconf plugin linked-attr config set
3734              Edit the config entry
3735
3736       dsconf plugin linked-attr config show
3737              Display the config entry
3738
3739       dsconf plugin linked-attr config delete
3740              Delete the config entry
3741
3742

COMMAND 'dsconf plugin linked-attr config add'

3744       usage: dsconf instance plugin linked-attr config NAME add [-h]
3745                                                                 [--link-type
3746       LINK_TYPE]
3747                                                                 [--man‐
3748       aged-type MANAGED_TYPE]
3749                                                                 [--link-scope
3750       LINK_SCOPE]
3751
3752

OPTIONS 'dsconf plugin linked-attr config add'

3754       --link-type LINK_TYPE
3755              Sets  the  attribute  that is managed manually by administrators
3756              (linkType)
3757
3758
3759       --managed-type MANAGED_TYPE
3760              Sets the attribute that is created  dynamically  by  the  plugin
3761              (managedType)
3762
3763
3764       --link-scope LINK_SCOPE
3765              Sets  the  scope that restricts the plugin to a specific part of
3766              the directory tree (linkScope)
3767
3768

COMMAND 'dsconf plugin linked-attr config set'

3770       usage: dsconf instance plugin linked-attr config NAME set [-h]
3771                                                                 [--link-type
3772       LINK_TYPE]
3773                                                                 [--man‐
3774       aged-type MANAGED_TYPE]
3775                                                                 [--link-scope
3776       LINK_SCOPE]
3777
3778

OPTIONS 'dsconf plugin linked-attr config set'

3780       --link-type LINK_TYPE
3781              Sets  the  attribute  that is managed manually by administrators
3782              (linkType)
3783
3784
3785       --managed-type MANAGED_TYPE
3786              Sets the attribute that is created  dynamically  by  the  plugin
3787              (managedType)
3788
3789
3790       --link-scope LINK_SCOPE
3791              Sets  the  scope that restricts the plugin to a specific part of
3792              the directory tree (linkScope)
3793
3794

COMMAND 'dsconf plugin linked-attr config show'

3796       usage: dsconf instance plugin linked-attr config NAME show [-h]
3797
3798

COMMAND 'dsconf plugin linked-attr config delete'

3800       usage: dsconf instance plugin linked-attr config NAME delete [-h]
3801
3802

COMMAND 'dsconf plugin managed-entries'

3804       usage: dsconf instance plugin managed-entries [-h]
3805                                                     {show,enable,disable,sta‐
3806       tus,set,list,config,template}
3807                                                     ...
3808
3809

POSITIONAL ARGUMENTS 'dsconf plugin managed-entries'

3811       dsconf plugin managed-entries show
3812              Displays the plugin configuration
3813
3814       dsconf plugin managed-entries enable
3815              Enables the plugin
3816
3817       dsconf plugin managed-entries disable
3818              Disables the plugin
3819
3820       dsconf plugin managed-entries status
3821              Displays the plugin status
3822
3823       dsconf plugin managed-entries set
3824              Edit the plugin settings
3825
3826       dsconf plugin managed-entries list
3827              List Managed Entries Plugin configs and templates
3828
3829       dsconf plugin managed-entries config
3830              Handle Managed Entries Plugin configs
3831
3832       dsconf plugin managed-entries template
3833              Handle Managed Entries Plugin templates
3834
3835

COMMAND 'dsconf plugin managed-entries show'

3837       usage: dsconf instance plugin managed-entries show [-h]
3838
3839

COMMAND 'dsconf plugin managed-entries enable'

3841       usage: dsconf instance plugin managed-entries enable [-h]
3842
3843

COMMAND 'dsconf plugin managed-entries disable'

3845       usage: dsconf instance plugin managed-entries disable [-h]
3846
3847

COMMAND 'dsconf plugin managed-entries status'

3849       usage: dsconf instance plugin managed-entries status [-h]
3850
3851

COMMAND 'dsconf plugin managed-entries set'

3853       usage: dsconf instance plugin managed-entries set [-h]
3854                                                         [--config-area   CON‐
3855       FIG_AREA]
3856
3857

OPTIONS 'dsconf plugin managed-entries set'

3859       --config-area CONFIG_AREA
3860              Sets the value of the nsslapd-pluginConfigArea attribute
3861
3862

COMMAND 'dsconf plugin managed-entries list'

3864       usage: dsconf instance plugin managed-entries list [-h]
3865                                                          {configs,templates}
3866       ...
3867
3868

POSITIONAL ARGUMENTS 'dsconf plugin managed-entries list'

3870       dsconf plugin managed-entries list configs
3871              List  Managed Entries Plugin configs (list config-area if speci‐
3872              fied in the main plugin entry)
3873
3874       dsconf plugin managed-entries list templates
3875              List Managed Entries Plugin templates in the directory
3876
3877

COMMAND 'dsconf plugin managed-entries list configs'

3879       usage: dsconf instance plugin managed-entries list configs [-h]
3880
3881

COMMAND 'dsconf plugin managed-entries list templates'

3883       usage: dsconf  instance  plugin  managed-entries  list  templates  [-h]
3884       [BASEDN]
3885
3886
3887       BASEDN The base DN where to search the templates
3888
3889

COMMAND 'dsconf plugin managed-entries config'

3891       usage: dsconf instance plugin managed-entries config [-h]
3892                                                            NAME
3893                                                            {add,set,show,delete}
3894       ...
3895
3896

POSITIONAL ARGUMENTS 'dsconf plugin managed-entries config'

3898       dsconf plugin managed-entries config add
3899              Add the config entry
3900
3901       dsconf plugin managed-entries config set
3902              Edit the config entry
3903
3904       dsconf plugin managed-entries config show
3905              Display the config entry
3906
3907       dsconf plugin managed-entries config delete
3908              Delete the config entry
3909
3910

COMMAND 'dsconf plugin managed-entries config add'

3912       usage: dsconf instance plugin managed-entries config NAME add
3913              [-h] [--scope  SCOPE]  [--filter  FILTER]  [--managed-base  MAN‐
3914       AGED_BASE]
3915              [--managed-template MANAGED_TEMPLATE]
3916
3917

OPTIONS 'dsconf plugin managed-entries config add'

3919       --scope SCOPE
3920              Sets  the  scope  of  the search to use to see which entries the
3921              plug-in monitors (originScope)
3922
3923
3924       --filter FILTER
3925              Sets the search filter to use to search for and identify the en‐
3926              tries  within the subtree which require a managed entry (origin‐
3927              Filter)
3928
3929
3930       --managed-base MANAGED_BASE
3931              Sets the subtree under which to create the managed entries (man‐
3932              agedBase)
3933
3934
3935       --managed-template MANAGED_TEMPLATE
3936              Identifies the template entry to use to create the managed entry
3937              (managedTemplate)
3938
3939

COMMAND 'dsconf plugin managed-entries config set'

3941       usage: dsconf instance plugin managed-entries config NAME set
3942              [-h] [--scope  SCOPE]  [--filter  FILTER]  [--managed-base  MAN‐
3943       AGED_BASE]
3944              [--managed-template MANAGED_TEMPLATE]
3945
3946

OPTIONS 'dsconf plugin managed-entries config set'

3948       --scope SCOPE
3949              Sets  the  scope  of  the search to use to see which entries the
3950              plug-in monitors (originScope)
3951
3952
3953       --filter FILTER
3954              Sets the search filter to use to search for and identify the en‐
3955              tries  within the subtree which require a managed entry (origin‐
3956              Filter)
3957
3958
3959       --managed-base MANAGED_BASE
3960              Sets the subtree under which to create the managed entries (man‐
3961              agedBase)
3962
3963
3964       --managed-template MANAGED_TEMPLATE
3965              Identifies the template entry to use to create the managed entry
3966              (managedTemplate)
3967
3968

COMMAND 'dsconf plugin managed-entries config show'

3970       usage: dsconf instance plugin managed-entries config NAME show [-h]
3971
3972

COMMAND 'dsconf plugin managed-entries config delete'

3974       usage: dsconf instance plugin managed-entries config NAME delete [-h]
3975
3976

COMMAND 'dsconf plugin managed-entries template'

3978       usage: dsconf instance plugin managed-entries template [-h]
3979                                                              DN
3980                                                              {add,set,show,delete}
3981                                                              ...
3982
3983

POSITIONAL ARGUMENTS 'dsconf plugin managed-entries template'

3985       dsconf plugin managed-entries template add
3986              Add the template entry
3987
3988       dsconf plugin managed-entries template set
3989              Edit the template entry
3990
3991       dsconf plugin managed-entries template show
3992              Display the template entry
3993
3994       dsconf plugin managed-entries template delete
3995              Delete the template entry
3996
3997

COMMAND 'dsconf plugin managed-entries template add'

3999       usage: dsconf instance plugin managed-entries template DN add
4000              [-h] [--rdn-attr RDN_ATTR]
4001              [--static-attr STATIC_ATTR [STATIC_ATTR ...]]
4002              [--mapped-attr MAPPED_ATTR [MAPPED_ATTR ...]]
4003
4004

OPTIONS 'dsconf plugin managed-entries template add'

4006       --rdn-attr RDN_ATTR
4007              Sets which attribute to use as the naming attribute in the auto‐
4008              matically- generated entry (mepRDNAttr)
4009
4010
4011       --static-attr STATIC_ATTR [STATIC_ATTR ...]
4012              Sets an attribute with a defined value that must be added to the
4013              automatically-generated entry (mepStaticAttr)
4014
4015
4016       --mapped-attr MAPPED_ATTR [MAPPED_ATTR ...]
4017              Sets attributes in the Managed Entries template entry which must
4018              exist in the generated entry (mepMappedAttr)
4019
4020

COMMAND 'dsconf plugin managed-entries template set'

4022       usage: dsconf instance plugin managed-entries template DN set
4023              [-h] [--rdn-attr RDN_ATTR]
4024              [--static-attr STATIC_ATTR [STATIC_ATTR ...]]
4025              [--mapped-attr MAPPED_ATTR [MAPPED_ATTR ...]]
4026
4027

OPTIONS 'dsconf plugin managed-entries template set'

4029       --rdn-attr RDN_ATTR
4030              Sets which attribute to use as the naming attribute in the auto‐
4031              matically- generated entry (mepRDNAttr)
4032
4033
4034       --static-attr STATIC_ATTR [STATIC_ATTR ...]
4035              Sets an attribute with a defined value that must be added to the
4036              automatically-generated entry (mepStaticAttr)
4037
4038
4039       --mapped-attr MAPPED_ATTR [MAPPED_ATTR ...]
4040              Sets attributes in the Managed Entries template entry which must
4041              exist in the generated entry (mepMappedAttr)
4042
4043

COMMAND 'dsconf plugin managed-entries template show'

4045       usage: dsconf instance plugin managed-entries template DN show [-h]
4046
4047

COMMAND 'dsconf plugin managed-entries template delete'

4049       usage: dsconf instance plugin managed-entries template DN delete [-h]
4050
4051

COMMAND 'dsconf plugin pam-pass-through-auth'

4053       usage: dsconf instance plugin pam-pass-through-auth [-h]
4054                                                           {show,enable,dis‐
4055       able,status,list,config}
4056                                                           ...
4057
4058

POSITIONAL ARGUMENTS 'dsconf plugin pam-pass-through-auth'

4060       dsconf plugin pam-pass-through-auth show
4061              Displays the plugin configuration
4062
4063       dsconf plugin pam-pass-through-auth enable
4064              Enables the plugin
4065
4066       dsconf plugin pam-pass-through-auth disable
4067              Disables the plugin
4068
4069       dsconf plugin pam-pass-through-auth status
4070              Displays the plugin status
4071
4072       dsconf plugin pam-pass-through-auth list
4073              Lists PAM configurations
4074
4075       dsconf plugin pam-pass-through-auth config
4076              Manage PAM PTA configurations.
4077
4078

COMMAND 'dsconf plugin pam-pass-through-auth show'

4080       usage: dsconf instance plugin pam-pass-through-auth show [-h]
4081
4082

COMMAND 'dsconf plugin pam-pass-through-auth enable'

4084       usage: dsconf instance plugin pam-pass-through-auth enable [-h]
4085
4086

COMMAND 'dsconf plugin pam-pass-through-auth disable'

4088       usage: dsconf instance plugin pam-pass-through-auth disable [-h]
4089
4090

COMMAND 'dsconf plugin pam-pass-through-auth status'

4092       usage: dsconf instance plugin pam-pass-through-auth status [-h]
4093
4094

COMMAND 'dsconf plugin pam-pass-through-auth list'

4096       usage: dsconf instance plugin pam-pass-through-auth list [-h]
4097
4098

COMMAND 'dsconf plugin pam-pass-through-auth config'

4100       usage: dsconf instance plugin pam-pass-through-auth config [-h]
4101                                                                  NAME
4102                                                                  {add,set,show,delete}
4103                                                                  ...
4104
4105

POSITIONAL ARGUMENTS 'dsconf plugin pam-pass-through-auth config'

4107       dsconf plugin pam-pass-through-auth config add
4108              Add the config entry
4109
4110       dsconf plugin pam-pass-through-auth config set
4111              Edit the config entry
4112
4113       dsconf plugin pam-pass-through-auth config show
4114              Display the config entry
4115
4116       dsconf plugin pam-pass-through-auth config delete
4117              Delete the config entry
4118
4119

COMMAND 'dsconf plugin pam-pass-through-auth config add'

4121       usage: dsconf instance plugin pam-pass-through-auth config NAME add
4122              [-h] [--exclude-suffix EXCLUDE_SUFFIX [EXCLUDE_SUFFIX ...]]
4123              [--include-suffix INCLUDE_SUFFIX [INCLUDE_SUFFIX ...]]
4124              [--missing-suffix  {ERROR,ALLOW,IGNORE,delete,}]  [--filter FIL‐
4125       TER]
4126              [--id-attr ID_ATTR] [--id_map_method ID_MAP_METHOD]
4127              [--fallback  {TRUE,FALSE}]  [--secure  {TRUE,FALSE}]  [--service
4128       SERVICE]
4129
4130

OPTIONS 'dsconf plugin pam-pass-through-auth config add'

4132       --exclude-suffix EXCLUDE_SUFFIX [EXCLUDE_SUFFIX ...]
4133              Specifies  a  suffix  to exclude from PAM authentication (pamEx‐
4134              cludeSuffix)
4135
4136
4137       --include-suffix INCLUDE_SUFFIX [INCLUDE_SUFFIX ...]
4138              Sets a suffix to include for PAM authentication  (pamIncludeSuf‐
4139              fix)
4140
4141
4142       --missing-suffix {ERROR,ALLOW,IGNORE,delete,}
4143              Identifies  how  to  handle  missing include or exclude suffixes
4144              (pamMissingSuffix)
4145
4146
4147       --filter FILTER
4148              Sets an LDAP filter to use to identify specific  entries  within
4149              the  included suffixes for which to use PAM pass-through authen‐
4150              tication (pamFilter)
4151
4152
4153       --id-attr ID_ATTR
4154              Contains the attribute name which is used to hold the  PAM  user
4155              ID (pamIDAttr)
4156
4157
4158       --id_map_method ID_MAP_METHOD
4159              Sets the method to use to map the LDAP bind DN to a PAM identity
4160              (pamIDMapMethod)
4161
4162
4163       --fallback {TRUE,FALSE}
4164              Sets whether to fallback to regular LDAP authentication  if  PAM
4165              authentication fails (pamFallback)
4166
4167
4168       --secure {TRUE,FALSE}
4169              Requires  secure  TLS  connection for PAM authentication (pamSe‐
4170              cure)
4171
4172
4173       --service SERVICE
4174              Contains the service name to pass to PAM (pamService)
4175
4176

COMMAND 'dsconf plugin pam-pass-through-auth config set'

4178       usage: dsconf instance plugin pam-pass-through-auth config NAME set
4179              [-h] [--exclude-suffix EXCLUDE_SUFFIX [EXCLUDE_SUFFIX ...]]
4180              [--include-suffix INCLUDE_SUFFIX [INCLUDE_SUFFIX ...]]
4181              [--missing-suffix {ERROR,ALLOW,IGNORE,delete,}]  [--filter  FIL‐
4182       TER]
4183              [--id-attr ID_ATTR] [--id_map_method ID_MAP_METHOD]
4184              [--fallback  {TRUE,FALSE}]  [--secure  {TRUE,FALSE}]  [--service
4185       SERVICE]
4186
4187

OPTIONS 'dsconf plugin pam-pass-through-auth config set'

4189       --exclude-suffix EXCLUDE_SUFFIX [EXCLUDE_SUFFIX ...]
4190              Specifies a suffix to exclude from  PAM  authentication  (pamEx‐
4191              cludeSuffix)
4192
4193
4194       --include-suffix INCLUDE_SUFFIX [INCLUDE_SUFFIX ...]
4195              Sets  a suffix to include for PAM authentication (pamIncludeSuf‐
4196              fix)
4197
4198
4199       --missing-suffix {ERROR,ALLOW,IGNORE,delete,}
4200              Identifies how to handle missing  include  or  exclude  suffixes
4201              (pamMissingSuffix)
4202
4203
4204       --filter FILTER
4205              Sets  an  LDAP filter to use to identify specific entries within
4206              the included suffixes for which to use PAM pass-through  authen‐
4207              tication (pamFilter)
4208
4209
4210       --id-attr ID_ATTR
4211              Contains  the  attribute name which is used to hold the PAM user
4212              ID (pamIDAttr)
4213
4214
4215       --id_map_method ID_MAP_METHOD
4216              Sets the method to use to map the LDAP bind DN to a PAM identity
4217              (pamIDMapMethod)
4218
4219
4220       --fallback {TRUE,FALSE}
4221              Sets  whether  to fallback to regular LDAP authentication if PAM
4222              authentication fails (pamFallback)
4223
4224
4225       --secure {TRUE,FALSE}
4226              Requires secure TLS connection for  PAM  authentication  (pamSe‐
4227              cure)
4228
4229
4230       --service SERVICE
4231              Contains the service name to pass to PAM (pamService)
4232
4233

COMMAND 'dsconf plugin pam-pass-through-auth config show'

4235       usage:  dsconf  instance  plugin pam-pass-through-auth config NAME show
4236       [-h]
4237
4238

COMMAND 'dsconf plugin pam-pass-through-auth config delete'

4240       usage: dsconf instance plugin pam-pass-through-auth config NAME  delete
4241       [-h]
4242
4243

COMMAND 'dsconf plugin retro-changelog'

4245       usage: dsconf instance plugin retro-changelog [-h]
4246                                                     {show,enable,disable,sta‐
4247       tus,set,add,del}
4248                                                     ...
4249
4250

POSITIONAL ARGUMENTS 'dsconf plugin retro-changelog'

4252       dsconf plugin retro-changelog show
4253              Displays the plugin configuration
4254
4255       dsconf plugin retro-changelog enable
4256              Enables the plugin
4257
4258       dsconf plugin retro-changelog disable
4259              Disables the plugin
4260
4261       dsconf plugin retro-changelog status
4262              Displays the plugin status
4263
4264       dsconf plugin retro-changelog set
4265              Edit the plugin
4266
4267       dsconf plugin retro-changelog add
4268              Add attributes to the plugin
4269
4270       dsconf plugin retro-changelog del
4271              Delete an attribute from plugin scope
4272
4273

COMMAND 'dsconf plugin retro-changelog show'

4275       usage: dsconf instance plugin retro-changelog show [-h]
4276
4277

COMMAND 'dsconf plugin retro-changelog enable'

4279       usage: dsconf instance plugin retro-changelog enable [-h]
4280
4281

COMMAND 'dsconf plugin retro-changelog disable'

4283       usage: dsconf instance plugin retro-changelog disable [-h]
4284
4285

COMMAND 'dsconf plugin retro-changelog status'

4287       usage: dsconf instance plugin retro-changelog status [-h]
4288
4289

COMMAND 'dsconf plugin retro-changelog set'

4291       usage: dsconf instance plugin retro-changelog set [-h]
4292                                                         [--is-replicated
4293       {TRUE,FALSE}]
4294                                                         [--attribute   ATTRI‐
4295       BUTE]
4296                                                         [--directory   DIREC‐
4297       TORY]
4298                                                         [--max-age MAX_AGE]
4299                                                         [--trim-interval
4300       TRIM_INTERVAL]
4301                                                         [--exclude-suffix
4302       [EXCLUDE_SUFFIX ...]]
4303                                                         [--exclude-attrs [EX‐
4304       CLUDE_ATTRS ...]]
4305
4306

OPTIONS 'dsconf plugin retro-changelog set'

4308       --is-replicated {TRUE,FALSE}
4309              Sets a flag to indicate on a change in the changelog whether the
4310              change is newly made on that server or whether it was replicated
4311              over from another server (isReplicated)
4312
4313
4314       --attribute ATTRIBUTE
4315              Specifies another Directory Server attribute which must  be  in‐
4316              cluded in the retro changelog entries (nsslapd-attribute)
4317
4318
4319       --directory DIRECTORY
4320              Specifies the name of the directory in which the changelog data‐
4321              base is created the first time the plug-in is run
4322
4323
4324       --max-age MAX_AGE
4325              Specifies the maximum age of any entry in the changelog. Used to
4326              trim the changelog (nsslapd-changelogmaxage)
4327
4328
4329       --trim-interval TRIM_INTERVAL
4330
4331
4332       --exclude-suffix [EXCLUDE_SUFFIX ...]
4333              Specifies  the  suffix  which will be excluded from the scope of
4334              the plugin (nsslapd-exclude-suffix)
4335
4336
4337       --exclude-attrs [EXCLUDE_ATTRS ...]
4338              Specifies the attributes which will be excluded from  the  scope
4339              of the plugin (nsslapd-exclude-attrs)
4340
4341

COMMAND 'dsconf plugin retro-changelog add'

4343       usage: dsconf instance plugin retro-changelog add [-h]
4344                                                         [--is-replicated
4345       {TRUE,FALSE}]
4346                                                         [--attribute   ATTRI‐
4347       BUTE]
4348                                                         [--directory   DIREC‐
4349       TORY]
4350                                                         [--max-age MAX_AGE]
4351                                                         [--trim-interval
4352       TRIM_INTERVAL]
4353                                                         [--exclude-suffix
4354       [EXCLUDE_SUFFIX ...]]
4355                                                         [--exclude-attrs [EX‐
4356       CLUDE_ATTRS ...]]
4357
4358

OPTIONS 'dsconf plugin retro-changelog add'

4360       --is-replicated {TRUE,FALSE}
4361              Sets a flag to indicate on a change in the changelog whether the
4362              change is newly made on that server or whether it was replicated
4363              over from another server (isReplicated)
4364
4365
4366       --attribute ATTRIBUTE
4367              Specifies  another  Directory Server attribute which must be in‐
4368              cluded in the retro changelog entries (nsslapd-attribute)
4369
4370
4371       --directory DIRECTORY
4372              Specifies the name of the directory in which the changelog data‐
4373              base is created the first time the plug-in is run
4374
4375
4376       --max-age MAX_AGE
4377              Specifies the maximum age of any entry in the changelog. Used to
4378              trim the changelog (nsslapd-changelogmaxage)
4379
4380
4381       --trim-interval TRIM_INTERVAL
4382
4383
4384       --exclude-suffix [EXCLUDE_SUFFIX ...]
4385              Specifies the suffix which will be excluded from  the  scope  of
4386              the plugin (nsslapd-exclude-suffix)
4387
4388
4389       --exclude-attrs [EXCLUDE_ATTRS ...]
4390              Specifies  the  attributes which will be excluded from the scope
4391              of the plugin (nsslapd-exclude-attrs)
4392
4393

COMMAND 'dsconf plugin retro-changelog del'

4395       usage: dsconf instance plugin retro-changelog del [-h]
4396                                                         [--is-replicated
4397       {TRUE,FALSE}]
4398                                                         [--attribute   ATTRI‐
4399       BUTE]
4400                                                         [--directory   DIREC‐
4401       TORY]
4402                                                         [--max-age MAX_AGE]
4403                                                         [--trim-interval
4404       TRIM_INTERVAL]
4405                                                         [--exclude-suffix
4406       [EXCLUDE_SUFFIX ...]]
4407                                                         [--exclude-attrs [EX‐
4408       CLUDE_ATTRS ...]]
4409
4410

OPTIONS 'dsconf plugin retro-changelog del'

4412       --is-replicated {TRUE,FALSE}
4413              Sets a flag to indicate on a change in the changelog whether the
4414              change is newly made on that server or whether it was replicated
4415              over from another server (isReplicated)
4416
4417
4418       --attribute ATTRIBUTE
4419              Specifies another Directory Server attribute which must  be  in‐
4420              cluded in the retro changelog entries (nsslapd-attribute)
4421
4422
4423       --directory DIRECTORY
4424              Specifies the name of the directory in which the changelog data‐
4425              base is created the first time the plug-in is run
4426
4427
4428       --max-age MAX_AGE
4429              Specifies the maximum age of any entry in the changelog. Used to
4430              trim the changelog (nsslapd-changelogmaxage)
4431
4432
4433       --trim-interval TRIM_INTERVAL
4434
4435
4436       --exclude-suffix [EXCLUDE_SUFFIX ...]
4437              Specifies  the  suffix  which will be excluded from the scope of
4438              the plugin (nsslapd-exclude-suffix)
4439
4440
4441       --exclude-attrs [EXCLUDE_ATTRS ...]
4442              Specifies the attributes which will be excluded from  the  scope
4443              of the plugin (nsslapd-exclude-attrs)
4444
4445

COMMAND 'dsconf plugin posix-winsync'

4447       usage: dsconf instance plugin posix-winsync [-h]
4448                                                   {show,enable,disable,sta‐
4449       tus,set,fixup}
4450                                                   ...
4451
4452

POSITIONAL ARGUMENTS 'dsconf plugin posix-winsync'

4454       dsconf plugin posix-winsync show
4455              Displays the plugin configuration
4456
4457       dsconf plugin posix-winsync enable
4458              Enables the plugin
4459
4460       dsconf plugin posix-winsync disable
4461              Disables the plugin
4462
4463       dsconf plugin posix-winsync status
4464              Displays the plugin status
4465
4466       dsconf plugin posix-winsync set
4467              Edit the plugin settings
4468
4469       dsconf plugin posix-winsync fixup
4470              Run the memberOf fix-up task to correct  mismatched  member  and
4471              uniquemember values for synced users
4472
4473

COMMAND 'dsconf plugin posix-winsync show'

4475       usage: dsconf instance plugin posix-winsync show [-h]
4476
4477

COMMAND 'dsconf plugin posix-winsync enable'

4479       usage: dsconf instance plugin posix-winsync enable [-h]
4480
4481

COMMAND 'dsconf plugin posix-winsync disable'

4483       usage: dsconf instance plugin posix-winsync disable [-h]
4484
4485

COMMAND 'dsconf plugin posix-winsync status'

4487       usage: dsconf instance plugin posix-winsync status [-h]
4488
4489

COMMAND 'dsconf plugin posix-winsync set'

4491       usage: dsconf instance plugin posix-winsync set [-h]
4492                                                       [--create-memberof-task
4493       {true,false}]
4494                                                       [--lower-case-uid
4495       {true,false}]
4496                                                       [--map-member-uid
4497       {true,false}]
4498                                                       [--map-nested-grouping
4499       {true,false}]
4500                                                       [--ms-sfu-schema
4501       {true,false}]
4502
4503

OPTIONS 'dsconf plugin posix-winsync set'

4505       --create-memberof-task {true,false}
4506              Sets whether to run the memberUID fix-up task immediately  after
4507              a sync run in order to update group memberships for synced users
4508              (posixWinsyncCreateMemberOfTask)
4509
4510
4511       --lower-case-uid {true,false}
4512              Sets whether to store (and, if necessary, convert) the UID value
4513              in  the  memberUID  attribute  in lower case.(posixWinsyncLower‐
4514              CaseUID)
4515
4516
4517       --map-member-uid {true,false}
4518              Sets whether to map the memberUID attribute in an Active  Direc‐
4519              tory  group  to the uniqueMember attribute in a Directory Server
4520              group (posixWinsyncMapMemberUID)
4521
4522
4523       --map-nested-grouping {true,false}
4524              Manages if nested groups are updated when  memberUID  attributes
4525              in  an Active Directory POSIX group change (posixWinsyncMapNest‐
4526              edGrouping)
4527
4528
4529       --ms-sfu-schema {true,false}
4530              Sets whether to the older Microsoft System Services for Unix 3.0
4531              (msSFU30)  schema  when syncing Posix attributes from Active Di‐
4532              rectory (posixWinsyncMsSFUSchema)
4533
4534

COMMAND 'dsconf plugin posix-winsync fixup'

4536       usage: dsconf instance plugin posix-winsync fixup [-h] [-f FILTER] DN
4537
4538
4539       DN     Set the base DN that contains entries to fix up
4540
4541

OPTIONS 'dsconf plugin posix-winsync fixup'

4543       -f FILTER, --filter FILTER
4544              Filter for entries to fix up. If omitted, all entries  with  ob‐
4545              jectclass inetuser/inetadmin/nsmemberof under the specified base
4546              will have their memberOf attribute regenerated.
4547
4548

COMMAND 'dsconf plugin contentsync'

4550       usage: dsconf instance plugin contentsync [-h]
4551                                                 {show,enable,disable,sta‐
4552       tus,set,add}
4553                                                 ...
4554
4555

POSITIONAL ARGUMENTS 'dsconf plugin contentsync'

4557       dsconf plugin contentsync show
4558              Displays the plugin configuration
4559
4560       dsconf plugin contentsync enable
4561              Enables the plugin
4562
4563       dsconf plugin contentsync disable
4564              Disables the plugin
4565
4566       dsconf plugin contentsync status
4567              Displays the plugin status
4568
4569       dsconf plugin contentsync set
4570              Edit the plugin settings
4571
4572       dsconf plugin contentsync add
4573              Add attributes to the plugin
4574
4575

COMMAND 'dsconf plugin contentsync show'

4577       usage: dsconf instance plugin contentsync show [-h]
4578
4579

COMMAND 'dsconf plugin contentsync enable'

4581       usage: dsconf instance plugin contentsync enable [-h]
4582
4583

COMMAND 'dsconf plugin contentsync disable'

4585       usage: dsconf instance plugin contentsync disable [-h]
4586
4587

COMMAND 'dsconf plugin contentsync status'

4589       usage: dsconf instance plugin contentsync status [-h]
4590
4591

COMMAND 'dsconf plugin contentsync set'

4593       usage:  dsconf  instance  plugin contentsync set [-h] [--allow-openldap
4594       {on,off}]
4595
4596

OPTIONS 'dsconf plugin contentsync set'

4598       --allow-openldap {on,off}
4599              Allows openldap servers to act as read only  consumers  of  this
4600              server via syncrepl
4601
4602

COMMAND 'dsconf plugin contentsync add'

4604       usage:  dsconf  instance  plugin contentsync add [-h] [--allow-openldap
4605       {on,off}]
4606
4607

OPTIONS 'dsconf plugin contentsync add'

4609       --allow-openldap {on,off}
4610              Allows openldap servers to act as read only  consumers  of  this
4611              server via syncrepl
4612
4613

COMMAND 'dsconf plugin entryuuid'

4615       usage: dsconf instance plugin entryuuid [-h]
4616                                               {show,enable,disable,sta‐
4617       tus,fixup,fixup-status}
4618                                               ...
4619
4620

POSITIONAL ARGUMENTS 'dsconf plugin entryuuid'

4622       dsconf plugin entryuuid show
4623              Displays the plugin configuration
4624
4625       dsconf plugin entryuuid enable
4626              Enables the plugin
4627
4628       dsconf plugin entryuuid disable
4629              Disables the plugin
4630
4631       dsconf plugin entryuuid status
4632              Displays the plugin status
4633
4634       dsconf plugin entryuuid fixup
4635              Run the fix-up task for EntryUUID plugin
4636
4637       dsconf plugin entryuuid fixup-status
4638              Check the status of a fix-up task
4639
4640

COMMAND 'dsconf plugin entryuuid show'

4642       usage: dsconf instance plugin entryuuid show [-h]
4643
4644

COMMAND 'dsconf plugin entryuuid enable'

4646       usage: dsconf instance plugin entryuuid enable [-h]
4647
4648

COMMAND 'dsconf plugin entryuuid disable'

4650       usage: dsconf instance plugin entryuuid disable [-h]
4651
4652

COMMAND 'dsconf plugin entryuuid status'

4654       usage: dsconf instance plugin entryuuid status [-h]
4655
4656

COMMAND 'dsconf plugin entryuuid fixup'

4658       usage: dsconf instance plugin entryuuid fixup [-h] [-f FILTER] [--wait]
4659       DN
4660
4661
4662       DN     Base DN that contains entries to fix up
4663
4664

OPTIONS 'dsconf plugin entryuuid fixup'

4666       -f FILTER, --filter FILTER
4667              Filter for entries to fix up. If omitted, all entries under base
4668              DNwill  have  their  EntryUUID  attribute  regenerated  if   not
4669              present.
4670
4671
4672       --wait Wait for the task to finish, this could take a long time
4673
4674

COMMAND 'dsconf plugin entryuuid fixup-status'

4676       usage: dsconf instance plugin entryuuid fixup-status [-h] [--dn DN]
4677                                                            [--show-log]
4678       [--watch]
4679
4680

OPTIONS 'dsconf plugin entryuuid fixup-status'

4682       --dn DN
4683              The task entry's DN
4684
4685
4686       --show-log
4687              Display the task log
4688
4689
4690       --watch
4691              Watch the task's status and wait for it to finish
4692
4693

COMMAND 'dsconf plugin list'

4695       usage: dsconf instance plugin list [-h]
4696
4697

COMMAND 'dsconf plugin show'

4699       usage: dsconf instance plugin show [-h] [selector]
4700
4701
4702       selector
4703              The plugin to search for
4704
4705

COMMAND 'dsconf plugin set'

4707       usage:  dsconf  instance  plugin  set  [-h]  [--type  TYPE]  [--enabled
4708       {on,off}]
4709                                         [--path PATH] [--initfunc INITFUNC]
4710                                         [--id ID] [--vendor VENDOR]
4711                                         [--version VERSION]
4712                                         [--description DESCRIPTION]
4713                                         [--depends-on-type DEPENDS_ON_TYPE]
4714                                         [--depends-on-named DEPENDS_ON_NAMED]
4715                                         [--precedence PRECEDENCE]
4716                                         [selector]
4717
4718
4719       selector
4720              The plugin to edit
4721
4722

OPTIONS 'dsconf plugin set'

4724       --type TYPE
4725              The type of plugin.
4726
4727
4728       --enabled {on,off}
4729              Identifies whether or not the plugin is enabled.
4730
4731
4732       --path PATH
4733              The plugin library name (without the library suffix).
4734
4735
4736       --initfunc INITFUNC
4737              An initialization function of the plugin.
4738
4739
4740       --id ID
4741              The plugin ID.
4742
4743
4744       --vendor VENDOR
4745              The vendor of plugin.
4746
4747
4748       --version VERSION
4749              The version of plugin.
4750
4751
4752       --description DESCRIPTION
4753              The description of the plugin.
4754
4755
4756       --depends-on-type DEPENDS_ON_TYPE
4757              All  plug-ins  with a type value which matches one of the values
4758              in the following valid range will be started by the server prior
4759              to this plug-in.
4760
4761
4762       --depends-on-named DEPENDS_ON_NAMED
4763              The  plug-in  name  matching one of the following values will be
4764              started by the server prior to this plug-in
4765
4766
4767       --precedence PRECEDENCE
4768              The priority it has in the execution order of plug-ins
4769
4770

COMMAND 'dsconf pwpolicy'

4772       usage: dsconf instance pwpolicy [-h] {get,set} ...
4773
4774

POSITIONAL ARGUMENTS 'dsconf pwpolicy'

4776       dsconf pwpolicy get
4777              Get the global password policy entry
4778
4779       dsconf pwpolicy set
4780              Set an attribute in a global password policy
4781
4782

COMMAND 'dsconf pwpolicy get'

4784       usage: dsconf instance pwpolicy get [-h]
4785
4786

COMMAND 'dsconf pwpolicy set'

4788       usage: dsconf instance pwpolicy set [-h] [--pwdscheme PWDSCHEME]
4789                                           [--pwdchange PWDCHANGE]
4790                                           [--pwdmustchange PWDMUSTCHANGE]
4791                                           [--pwdhistory PWDHISTORY]
4792                                           [--pwdhistorycount PWDHISTORYCOUNT]
4793                                           [--pwdadmin PWDADMIN]
4794                                           [--pwdtrack PWDTRACK]
4795                                           [--pwdwarning PWDWARNING]
4796                                           [--pwdexpire PWDEXPIRE]
4797                                           [--pwdmaxage PWDMAXAGE]
4798                                           [--pwdminage PWDMINAGE]
4799                                           [--pwdgracelimit PWDGRACELIMIT]
4800                                           [--pwdsendexpiring PWDSENDEXPIRING]
4801                                           [--pwdlockout PWDLOCKOUT]
4802                                           [--pwdunlock PWDUNLOCK]
4803                                           [--pwdlockoutduration PWDLOCKOUTDU‐
4804       RATION]
4805                                           [--pwdmaxfailures PWDMAXFAILURES]
4806                                           [--pwdresetfailcount  PWDRESETFAIL‐
4807       COUNT]
4808                                           [--pwdchecksyntax PWDCHECKSYNTAX]
4809                                           [--pwdminlen PWDMINLEN]
4810                                           [--pwdmindigits PWDMINDIGITS]
4811                                           [--pwdminalphas PWDMINALPHAS]
4812                                           [--pwdminuppers PWDMINUPPERS]
4813                                           [--pwdminlowers PWDMINLOWERS]
4814                                           [--pwdminspecials PWDMINSPECIALS]
4815                                           [--pwdmin8bits PWDMIN8BITS]
4816                                           [--pwdmaxrepeats PWDMAXREPEATS]
4817                                           [--pwdpalindrome PWDPALINDROME]
4818                                           [--pwdmaxseq PWDMAXSEQ]
4819                                           [--pwdmaxseqsets PWDMAXSEQSETS]
4820                                           [--pwdmaxclasschars    PWDMAXCLASS‐
4821       CHARS]
4822                                           [--pwdmincatagories         PWDMIN‐
4823       CATAGORIES]
4824                                           [--pwdmintokenlen PWDMINTOKENLEN]
4825                                           [--pwdbadwords PWDBADWORDS]
4826                                           [--pwduserattrs PWDUSERATTRS]
4827                                           [--pwddictcheck PWDDICTCHECK]
4828                                           [--pwddictpath PWDDICTPATH]
4829                                           [--pwptprmaxuse PWPTPRMAXUSE]
4830                                           [--pwptprdelayexpireat PWPTPRDELAY‐
4831       EXPIREAT]
4832                                           [--pwptprdelayvalidfrom   PWPTPRDE‐
4833       LAYVALIDFROM]
4834                                           [--pwdlocal PWDLOCAL]
4835                                           [--pwdisglobal PWDISGLOBAL]
4836                                           [--pwdallowhash PWDALLOWHASH]
4837                                           [--pwpinheritglobal     PWPINHERIT‐
4838       GLOBAL]
4839
4840

OPTIONS 'dsconf pwpolicy set'

4842       --pwdscheme PWDSCHEME
4843              The password storage scheme
4844
4845
4846       --pwdchange PWDCHANGE
4847              Allow users to change their passwords
4848
4849
4850       --pwdmustchange PWDMUSTCHANGE
4851              Users must change their password after it was reset by an admin‐
4852              istrator
4853
4854
4855       --pwdhistory PWDHISTORY
4856              To enable password history set this to "on", otherwise "off"
4857
4858
4859       --pwdhistorycount PWDHISTORYCOUNT
4860              The number of passwords to keep in history
4861
4862
4863       --pwdadmin PWDADMIN
4864              The DN of an entry or a group of account that can  bypass  pass‐
4865              word policy constraints
4866
4867
4868       --pwdtrack PWDTRACK
4869              Set to "on" to track the time the password was last changed
4870
4871
4872       --pwdwarning PWDWARNING
4873              Send  an  expiring  warning if password expires within this time
4874              (in seconds)
4875
4876
4877       --pwdexpire PWDEXPIRE
4878              Set to "on" to enable password expiration
4879
4880
4881       --pwdmaxage PWDMAXAGE
4882              The password expiration time in seconds
4883
4884
4885       --pwdminage PWDMINAGE
4886              The number of seconds that must pass before a  user  can  change
4887              their password
4888
4889
4890       --pwdgracelimit PWDGRACELIMIT
4891              The number of allowed logins after the password has expired
4892
4893
4894       --pwdsendexpiring PWDSENDEXPIRING
4895              Set  to  "on"  to always send the expiring control regardless of
4896              the warning period
4897
4898
4899       --pwdlockout PWDLOCKOUT
4900              Set to "on" to enable account lockout
4901
4902
4903       --pwdunlock PWDUNLOCK
4904              Set to "on" to allow an account to  become  unlocked  after  the
4905              lockout duration
4906
4907
4908       --pwdlockoutduration PWDLOCKOUTDURATION
4909              The number of seconds an account stays locked out
4910
4911
4912       --pwdmaxfailures PWDMAXFAILURES
4913              The  maximum  number  of allowed failed password attempts before
4914              the account gets locked
4915
4916
4917       --pwdresetfailcount PWDRESETFAILCOUNT
4918              The number of seconds to wait before reducing the  failed  login
4919              count on an account
4920
4921
4922       --pwdchecksyntax PWDCHECKSYNTAX
4923              Set to "on" to enable password syntax checking
4924
4925
4926       --pwdminlen PWDMINLEN
4927              The minimum number of characters required in a password
4928
4929
4930       --pwdmindigits PWDMINDIGITS
4931              The minimum number of digit/number characters in a password
4932
4933
4934       --pwdminalphas PWDMINALPHAS
4935              The minimum number of alpha characters required in a password
4936
4937
4938       --pwdminuppers PWDMINUPPERS
4939              The  minimum  number of uppercase characters required in a pass‐
4940              word
4941
4942
4943       --pwdminlowers PWDMINLOWERS
4944              The minimum number of lowercase characters required in  a  pass‐
4945              word
4946
4947
4948       --pwdminspecials PWDMINSPECIALS
4949              The minimum number of special characters required in a password
4950
4951
4952       --pwdmin8bits PWDMIN8BITS
4953              The minimum number of 8-bit characters required in a password
4954
4955
4956       --pwdmaxrepeats PWDMAXREPEATS
4957              The  maximum  number  of times the same character can appear se‐
4958              quentially in the password
4959
4960
4961       --pwdpalindrome PWDPALINDROME
4962              Set to "on" to reject passwords that are palindromes
4963
4964
4965       --pwdmaxseq PWDMAXSEQ
4966              The maximum number of allowed monotonic character sequences in a
4967              password
4968
4969
4970       --pwdmaxseqsets PWDMAXSEQSETS
4971              The maximum number of allowed monotonic character sequences that
4972              can be duplicated in a password
4973
4974
4975       --pwdmaxclasschars PWDMAXCLASSCHARS
4976              The maximum number of sequential characters from the same  char‐
4977              acter class that is allowed in a password
4978
4979
4980       --pwdmincatagories PWDMINCATAGORIES
4981              The minimum number of syntax category checks
4982
4983
4984       --pwdmintokenlen PWDMINTOKENLEN
4985              Sets  the smallest attribute value length that is used for triv‐
4986              ial/user words checking. This also impacts "--pwduserattrs"
4987
4988
4989       --pwdbadwords PWDBADWORDS
4990              A space-separated list of words that can not be in a password
4991
4992
4993       --pwduserattrs PWDUSERATTRS
4994              A space-separated list of attributes whose values can not appear
4995              in the password (See "--pwdmintokenlen")
4996
4997
4998       --pwddictcheck PWDDICTCHECK
4999              Set to "on" to enforce CrackLib dictionary checking
5000
5001
5002       --pwddictpath PWDDICTPATH
5003              Filesystem path to specific/custom CrackLib dictionary files
5004
5005
5006       --pwptprmaxuse PWPTPRMAXUSE
5007              Number of times a reset password can be used for authentication
5008
5009
5010       --pwptprdelayexpireat PWPTPRDELAYEXPIREAT
5011              Number of seconds after which a reset password expires
5012
5013
5014       --pwptprdelayvalidfrom PWPTPRDELAYVALIDFROM
5015              Number  of  seconds to wait before using a reset password to au‐
5016              thenticated
5017
5018
5019       --pwdlocal PWDLOCAL
5020              Set to "on" to enable fine-grained (subtree/user-level) password
5021              policies
5022
5023
5024       --pwdisglobal PWDISGLOBAL
5025              Set  to  "on"  to  enable password policy state attributes to be
5026              replicated
5027
5028
5029       --pwdallowhash PWDALLOWHASH
5030              Set to "on" to allow adding prehashed passwords
5031
5032
5033       --pwpinheritglobal PWPINHERITGLOBAL
5034              Set to "on" to allow local policies to inherit the global policy
5035
5036

COMMAND 'dsconf localpwp'

5038       usage: dsconf instance localpwp [-h]
5039                                       {list,get,set,remove,adduser,addsub‐
5040       tree} ...
5041
5042

POSITIONAL ARGUMENTS 'dsconf localpwp'

5044       dsconf localpwp list
5045              List all the local password policies
5046
5047       dsconf localpwp get
5048              Get local password policy entry
5049
5050       dsconf localpwp set
5051              Set an attribute in a local password policy
5052
5053       dsconf localpwp remove
5054              Remove a local password policy
5055
5056       dsconf localpwp adduser
5057              Add new user password policy
5058
5059       dsconf localpwp addsubtree
5060              Add new subtree password policy
5061
5062

COMMAND 'dsconf localpwp list'

5064       usage: dsconf instance localpwp list [-h] [DN]
5065
5066
5067       DN     Suffix to search for local password policies
5068
5069

COMMAND 'dsconf localpwp get'

5071       usage: dsconf instance localpwp get [-h] DN
5072
5073
5074       DN     Get the local policy for this entry DN
5075
5076

COMMAND 'dsconf localpwp set'

5078       usage: dsconf instance localpwp set [-h] [--pwdscheme PWDSCHEME]
5079                                           [--pwdchange PWDCHANGE]
5080                                           [--pwdmustchange PWDMUSTCHANGE]
5081                                           [--pwdhistory PWDHISTORY]
5082                                           [--pwdhistorycount PWDHISTORYCOUNT]
5083                                           [--pwdadmin PWDADMIN]
5084                                           [--pwdtrack PWDTRACK]
5085                                           [--pwdwarning PWDWARNING]
5086                                           [--pwdexpire PWDEXPIRE]
5087                                           [--pwdmaxage PWDMAXAGE]
5088                                           [--pwdminage PWDMINAGE]
5089                                           [--pwdgracelimit PWDGRACELIMIT]
5090                                           [--pwdsendexpiring PWDSENDEXPIRING]
5091                                           [--pwdlockout PWDLOCKOUT]
5092                                           [--pwdunlock PWDUNLOCK]
5093                                           [--pwdlockoutduration PWDLOCKOUTDU‐
5094       RATION]
5095                                           [--pwdmaxfailures PWDMAXFAILURES]
5096                                           [--pwdresetfailcount  PWDRESETFAIL‐
5097       COUNT]
5098                                           [--pwdchecksyntax PWDCHECKSYNTAX]
5099                                           [--pwdminlen PWDMINLEN]
5100                                           [--pwdmindigits PWDMINDIGITS]
5101                                           [--pwdminalphas PWDMINALPHAS]
5102                                           [--pwdminuppers PWDMINUPPERS]
5103                                           [--pwdminlowers PWDMINLOWERS]
5104                                           [--pwdminspecials PWDMINSPECIALS]
5105                                           [--pwdmin8bits PWDMIN8BITS]
5106                                           [--pwdmaxrepeats PWDMAXREPEATS]
5107                                           [--pwdpalindrome PWDPALINDROME]
5108                                           [--pwdmaxseq PWDMAXSEQ]
5109                                           [--pwdmaxseqsets PWDMAXSEQSETS]
5110                                           [--pwdmaxclasschars    PWDMAXCLASS‐
5111       CHARS]
5112                                           [--pwdmincatagories         PWDMIN‐
5113       CATAGORIES]
5114                                           [--pwdmintokenlen PWDMINTOKENLEN]
5115                                           [--pwdbadwords PWDBADWORDS]
5116                                           [--pwduserattrs PWDUSERATTRS]
5117                                           [--pwddictcheck PWDDICTCHECK]
5118                                           [--pwddictpath PWDDICTPATH]
5119                                           [--pwptprmaxuse PWPTPRMAXUSE]
5120                                           [--pwptprdelayexpireat PWPTPRDELAY‐
5121       EXPIREAT]
5122                                           [--pwptprdelayvalidfrom   PWPTPRDE‐
5123       LAYVALIDFROM]
5124                                           DN
5125
5126
5127       DN     Set the local policy for this entry DN
5128
5129

OPTIONS 'dsconf localpwp set'

5131       --pwdscheme PWDSCHEME
5132              The password storage scheme
5133
5134
5135       --pwdchange PWDCHANGE
5136              Allow users to change their passwords
5137
5138
5139       --pwdmustchange PWDMUSTCHANGE
5140              Users must change their password after it was reset by an admin‐
5141              istrator
5142
5143
5144       --pwdhistory PWDHISTORY
5145              To enable password history set this to "on", otherwise "off"
5146
5147
5148       --pwdhistorycount PWDHISTORYCOUNT
5149              The number of passwords to keep in history
5150
5151
5152       --pwdadmin PWDADMIN
5153              The DN of an entry or a group of account that can  bypass  pass‐
5154              word policy constraints
5155
5156
5157       --pwdtrack PWDTRACK
5158              Set to "on" to track the time the password was last changed
5159
5160
5161       --pwdwarning PWDWARNING
5162              Send  an  expiring  warning if password expires within this time
5163              (in seconds)
5164
5165
5166       --pwdexpire PWDEXPIRE
5167              Set to "on" to enable password expiration
5168
5169
5170       --pwdmaxage PWDMAXAGE
5171              The password expiration time in seconds
5172
5173
5174       --pwdminage PWDMINAGE
5175              The number of seconds that must pass before a  user  can  change
5176              their password
5177
5178
5179       --pwdgracelimit PWDGRACELIMIT
5180              The number of allowed logins after the password has expired
5181
5182
5183       --pwdsendexpiring PWDSENDEXPIRING
5184              Set  to  "on"  to always send the expiring control regardless of
5185              the warning period
5186
5187
5188       --pwdlockout PWDLOCKOUT
5189              Set to "on" to enable account lockout
5190
5191
5192       --pwdunlock PWDUNLOCK
5193              Set to "on" to allow an account to  become  unlocked  after  the
5194              lockout duration
5195
5196
5197       --pwdlockoutduration PWDLOCKOUTDURATION
5198              The number of seconds an account stays locked out
5199
5200
5201       --pwdmaxfailures PWDMAXFAILURES
5202              The  maximum  number  of allowed failed password attempts before
5203              the account gets locked
5204
5205
5206       --pwdresetfailcount PWDRESETFAILCOUNT
5207              The number of seconds to wait before reducing the  failed  login
5208              count on an account
5209
5210
5211       --pwdchecksyntax PWDCHECKSYNTAX
5212              Set to "on" to enable password syntax checking
5213
5214
5215       --pwdminlen PWDMINLEN
5216              The minimum number of characters required in a password
5217
5218
5219       --pwdmindigits PWDMINDIGITS
5220              The minimum number of digit/number characters in a password
5221
5222
5223       --pwdminalphas PWDMINALPHAS
5224              The minimum number of alpha characters required in a password
5225
5226
5227       --pwdminuppers PWDMINUPPERS
5228              The  minimum  number of uppercase characters required in a pass‐
5229              word
5230
5231
5232       --pwdminlowers PWDMINLOWERS
5233              The minimum number of lowercase characters required in  a  pass‐
5234              word
5235
5236
5237       --pwdminspecials PWDMINSPECIALS
5238              The minimum number of special characters required in a password
5239
5240
5241       --pwdmin8bits PWDMIN8BITS
5242              The minimum number of 8-bit characters required in a password
5243
5244
5245       --pwdmaxrepeats PWDMAXREPEATS
5246              The  maximum  number  of times the same character can appear se‐
5247              quentially in the password
5248
5249
5250       --pwdpalindrome PWDPALINDROME
5251              Set to "on" to reject passwords that are palindromes
5252
5253
5254       --pwdmaxseq PWDMAXSEQ
5255              The maximum number of allowed monotonic character sequences in a
5256              password
5257
5258
5259       --pwdmaxseqsets PWDMAXSEQSETS
5260              The maximum number of allowed monotonic character sequences that
5261              can be duplicated in a password
5262
5263
5264       --pwdmaxclasschars PWDMAXCLASSCHARS
5265              The maximum number of sequential characters from the same  char‐
5266              acter class that is allowed in a password
5267
5268
5269       --pwdmincatagories PWDMINCATAGORIES
5270              The minimum number of syntax category checks
5271
5272
5273       --pwdmintokenlen PWDMINTOKENLEN
5274              Sets  the smallest attribute value length that is used for triv‐
5275              ial/user words checking. This also impacts "--pwduserattrs"
5276
5277
5278       --pwdbadwords PWDBADWORDS
5279              A space-separated list of words that can not be in a password
5280
5281
5282       --pwduserattrs PWDUSERATTRS
5283              A space-separated list of attributes whose values can not appear
5284              in the password (See "--pwdmintokenlen")
5285
5286
5287       --pwddictcheck PWDDICTCHECK
5288              Set to "on" to enforce CrackLib dictionary checking
5289
5290
5291       --pwddictpath PWDDICTPATH
5292              Filesystem path to specific/custom CrackLib dictionary files
5293
5294
5295       --pwptprmaxuse PWPTPRMAXUSE
5296              Number of times a reset password can be used for authentication
5297
5298
5299       --pwptprdelayexpireat PWPTPRDELAYEXPIREAT
5300              Number of seconds after which a reset password expires
5301
5302
5303       --pwptprdelayvalidfrom PWPTPRDELAYVALIDFROM
5304              Number  of  seconds to wait before using a reset password to au‐
5305              thenticated
5306
5307

COMMAND 'dsconf localpwp remove'

5309       usage: dsconf instance localpwp remove [-h] DN
5310
5311
5312       DN     Remove local policy for this entry DN
5313
5314

COMMAND 'dsconf localpwp adduser'

5316       usage: dsconf instance localpwp adduser [-h] [--pwdscheme PWDSCHEME]
5317                                               [--pwdchange PWDCHANGE]
5318                                               [--pwdmustchange PWDMUSTCHANGE]
5319                                               [--pwdhistory PWDHISTORY]
5320                                               [--pwdhistorycount    PWDHISTO‐
5321       RYCOUNT]
5322                                               [--pwdadmin PWDADMIN]
5323                                               [--pwdtrack PWDTRACK]
5324                                               [--pwdwarning PWDWARNING]
5325                                               [--pwdexpire PWDEXPIRE]
5326                                               [--pwdmaxage PWDMAXAGE]
5327                                               [--pwdminage PWDMINAGE]
5328                                               [--pwdgracelimit PWDGRACELIMIT]
5329                                               [--pwdsendexpiring   PWDSENDEX‐
5330       PIRING]
5331                                               [--pwdlockout PWDLOCKOUT]
5332                                               [--pwdunlock PWDUNLOCK]
5333                                               [--pwdlockoutduration  PWDLOCK‐
5334       OUTDURATION]
5335                                               [--pwdmaxfailures   PWDMAXFAIL‐
5336       URES]
5337                                               [--pwdresetfailcount  PWDRESET‐
5338       FAILCOUNT]
5339                                               [--pwdchecksyntax  PWDCHECKSYN‐
5340       TAX]
5341                                               [--pwdminlen PWDMINLEN]
5342                                               [--pwdmindigits PWDMINDIGITS]
5343                                               [--pwdminalphas PWDMINALPHAS]
5344                                               [--pwdminuppers PWDMINUPPERS]
5345                                               [--pwdminlowers PWDMINLOWERS]
5346                                               [--pwdminspecials    PWDMINSPE‐
5347       CIALS]
5348                                               [--pwdmin8bits PWDMIN8BITS]
5349                                               [--pwdmaxrepeats PWDMAXREPEATS]
5350                                               [--pwdpalindrome PWDPALINDROME]
5351                                               [--pwdmaxseq PWDMAXSEQ]
5352                                               [--pwdmaxseqsets PWDMAXSEQSETS]
5353                                               [--pwdmaxclasschars     PWDMAX‐
5354       CLASSCHARS]
5355                                               [--pwdmincatagories     PWDMIN‐
5356       CATAGORIES]
5357                                               [--pwdmintokenlen     PWDMINTO‐
5358       KENLEN]
5359                                               [--pwdbadwords PWDBADWORDS]
5360                                               [--pwduserattrs PWDUSERATTRS]
5361                                               [--pwddictcheck PWDDICTCHECK]
5362                                               [--pwddictpath PWDDICTPATH]
5363                                               [--pwptprmaxuse PWPTPRMAXUSE]
5364                                               [--pwptprdelayexpireat    PWPT‐
5365       PRDELAYEXPIREAT]
5366                                               [--pwptprdelayvalidfrom   PWPT‐
5367       PRDELAYVALIDFROM]
5368                                               DN
5369
5370
5371       DN     Add/replace the local password policy for this entry DN
5372
5373

OPTIONS 'dsconf localpwp adduser'

5375       --pwdscheme PWDSCHEME
5376              The password storage scheme
5377
5378
5379       --pwdchange PWDCHANGE
5380              Allow users to change their passwords
5381
5382
5383       --pwdmustchange PWDMUSTCHANGE
5384              Users must change their password after it was reset by an admin‐
5385              istrator
5386
5387
5388       --pwdhistory PWDHISTORY
5389              To enable password history set this to "on", otherwise "off"
5390
5391
5392       --pwdhistorycount PWDHISTORYCOUNT
5393              The number of passwords to keep in history
5394
5395
5396       --pwdadmin PWDADMIN
5397              The  DN  of an entry or a group of account that can bypass pass‐
5398              word policy constraints
5399
5400
5401       --pwdtrack PWDTRACK
5402              Set to "on" to track the time the password was last changed
5403
5404
5405       --pwdwarning PWDWARNING
5406              Send an expiring warning if password expires  within  this  time
5407              (in seconds)
5408
5409
5410       --pwdexpire PWDEXPIRE
5411              Set to "on" to enable password expiration
5412
5413
5414       --pwdmaxage PWDMAXAGE
5415              The password expiration time in seconds
5416
5417
5418       --pwdminage PWDMINAGE
5419              The  number  of  seconds that must pass before a user can change
5420              their password
5421
5422
5423       --pwdgracelimit PWDGRACELIMIT
5424              The number of allowed logins after the password has expired
5425
5426
5427       --pwdsendexpiring PWDSENDEXPIRING
5428              Set to "on" to always send the expiring  control  regardless  of
5429              the warning period
5430
5431
5432       --pwdlockout PWDLOCKOUT
5433              Set to "on" to enable account lockout
5434
5435
5436       --pwdunlock PWDUNLOCK
5437              Set  to  "on"  to  allow an account to become unlocked after the
5438              lockout duration
5439
5440
5441       --pwdlockoutduration PWDLOCKOUTDURATION
5442              The number of seconds an account stays locked out
5443
5444
5445       --pwdmaxfailures PWDMAXFAILURES
5446              The maximum number of allowed failed  password  attempts  before
5447              the account gets locked
5448
5449
5450       --pwdresetfailcount PWDRESETFAILCOUNT
5451              The  number  of seconds to wait before reducing the failed login
5452              count on an account
5453
5454
5455       --pwdchecksyntax PWDCHECKSYNTAX
5456              Set to "on" to enable password syntax checking
5457
5458
5459       --pwdminlen PWDMINLEN
5460              The minimum number of characters required in a password
5461
5462
5463       --pwdmindigits PWDMINDIGITS
5464              The minimum number of digit/number characters in a password
5465
5466
5467       --pwdminalphas PWDMINALPHAS
5468              The minimum number of alpha characters required in a password
5469
5470
5471       --pwdminuppers PWDMINUPPERS
5472              The minimum number of uppercase characters required in  a  pass‐
5473              word
5474
5475
5476       --pwdminlowers PWDMINLOWERS
5477              The  minimum  number of lowercase characters required in a pass‐
5478              word
5479
5480
5481       --pwdminspecials PWDMINSPECIALS
5482              The minimum number of special characters required in a password
5483
5484
5485       --pwdmin8bits PWDMIN8BITS
5486              The minimum number of 8-bit characters required in a password
5487
5488
5489       --pwdmaxrepeats PWDMAXREPEATS
5490              The maximum number of times the same character  can  appear  se‐
5491              quentially in the password
5492
5493
5494       --pwdpalindrome PWDPALINDROME
5495              Set to "on" to reject passwords that are palindromes
5496
5497
5498       --pwdmaxseq PWDMAXSEQ
5499              The maximum number of allowed monotonic character sequences in a
5500              password
5501
5502
5503       --pwdmaxseqsets PWDMAXSEQSETS
5504              The maximum number of allowed monotonic character sequences that
5505              can be duplicated in a password
5506
5507
5508       --pwdmaxclasschars PWDMAXCLASSCHARS
5509              The  maximum number of sequential characters from the same char‐
5510              acter class that is allowed in a password
5511
5512
5513       --pwdmincatagories PWDMINCATAGORIES
5514              The minimum number of syntax category checks
5515
5516
5517       --pwdmintokenlen PWDMINTOKENLEN
5518              Sets the smallest attribute value length that is used for  triv‐
5519              ial/user words checking. This also impacts "--pwduserattrs"
5520
5521
5522       --pwdbadwords PWDBADWORDS
5523              A space-separated list of words that can not be in a password
5524
5525
5526       --pwduserattrs PWDUSERATTRS
5527              A space-separated list of attributes whose values can not appear
5528              in the password (See "--pwdmintokenlen")
5529
5530
5531       --pwddictcheck PWDDICTCHECK
5532              Set to "on" to enforce CrackLib dictionary checking
5533
5534
5535       --pwddictpath PWDDICTPATH
5536              Filesystem path to specific/custom CrackLib dictionary files
5537
5538
5539       --pwptprmaxuse PWPTPRMAXUSE
5540              Number of times a reset password can be used for authentication
5541
5542
5543       --pwptprdelayexpireat PWPTPRDELAYEXPIREAT
5544              Number of seconds after which a reset password expires
5545
5546
5547       --pwptprdelayvalidfrom PWPTPRDELAYVALIDFROM
5548              Number of seconds to wait before using a reset password  to  au‐
5549              thenticated
5550
5551

COMMAND 'dsconf localpwp addsubtree'

5553       usage: dsconf instance localpwp addsubtree [-h] [--pwdscheme PWDSCHEME]
5554                                                  [--pwdchange PWDCHANGE]
5555                                                  [--pwdmustchange        PWD‐
5556       MUSTCHANGE]
5557                                                  [--pwdhistory PWDHISTORY]
5558                                                  [--pwdhistorycount PWDHISTO‐
5559       RYCOUNT]
5560                                                  [--pwdadmin PWDADMIN]
5561                                                  [--pwdtrack PWDTRACK]
5562                                                  [--pwdwarning PWDWARNING]
5563                                                  [--pwdexpire PWDEXPIRE]
5564                                                  [--pwdmaxage PWDMAXAGE]
5565                                                  [--pwdminage PWDMINAGE]
5566                                                  [--pwdgracelimit   PWDGRACE‐
5567       LIMIT]
5568                                                  [--pwdsendexpiring  PWDSEND‐
5569       EXPIRING]
5570                                                  [--pwdlockout PWDLOCKOUT]
5571                                                  [--pwdunlock PWDUNLOCK]
5572                                                  [--pwdlockoutduration   PWD‐
5573       LOCKOUTDURATION]
5574                                                  [--pwdmaxfailures    PWDMAX‐
5575       FAILURES]
5576                                                  [--pwdresetfailcount     PW‐
5577       DRESETFAILCOUNT]
5578                                                  [--pwdchecksyntax       PWD‐
5579       CHECKSYNTAX]
5580                                                  [--pwdminlen PWDMINLEN]
5581                                                  [--pwdmindigits   PWDMINDIG‐
5582       ITS]
5583                                                  [--pwdminalphas    PWDMINAL‐
5584       PHAS]
5585                                                  [--pwdminuppers    PWDMINUP‐
5586       PERS]
5587                                                  [--pwdminlowers   PWDMINLOW‐
5588       ERS]
5589                                                  [--pwdminspecials PWDMINSPE‐
5590       CIALS]
5591                                                  [--pwdmin8bits PWDMIN8BITS]
5592                                                  [--pwdmaxrepeats   PWDMAXRE‐
5593       PEATS]
5594                                                  [--pwdpalindrome   PWDPALIN‐
5595       DROME]
5596                                                  [--pwdmaxseq PWDMAXSEQ]
5597                                                  [--pwdmaxseqsets   PWDMAXSE‐
5598       QSETS]
5599                                                  [--pwdmaxclasschars  PWDMAX‐
5600       CLASSCHARS]
5601                                                  [--pwdmincatagories  PWDMIN‐
5602       CATAGORIES]
5603                                                  [--pwdmintokenlen  PWDMINTO‐
5604       KENLEN]
5605                                                  [--pwdbadwords PWDBADWORDS]
5606                                                  [--pwduserattrs   PWDUSERAT‐
5607       TRS]
5608                                                  [--pwddictcheck         PWD‐
5609       DICTCHECK]
5610                                                  [--pwddictpath PWDDICTPATH]
5611                                                  [--pwptprmaxuse        PWPT‐
5612       PRMAXUSE]
5613                                                  [--pwptprdelayexpireat PWPT‐
5614       PRDELAYEXPIREAT]
5615                                                  [--pwptprdelayvalidfrom  PW‐
5616       PTPRDELAYVALIDFROM]
5617                                                  DN
5618
5619
5620       DN     Add/replace the subtree policy for this entry DN
5621
5622

OPTIONS 'dsconf localpwp addsubtree'

5624       --pwdscheme PWDSCHEME
5625              The password storage scheme
5626
5627
5628       --pwdchange PWDCHANGE
5629              Allow users to change their passwords
5630
5631
5632       --pwdmustchange PWDMUSTCHANGE
5633              Users must change their password after it was reset by an admin‐
5634              istrator
5635
5636
5637       --pwdhistory PWDHISTORY
5638              To enable password history set this to "on", otherwise "off"
5639
5640
5641       --pwdhistorycount PWDHISTORYCOUNT
5642              The number of passwords to keep in history
5643
5644
5645       --pwdadmin PWDADMIN
5646              The DN of an entry or a group of account that can  bypass  pass‐
5647              word policy constraints
5648
5649
5650       --pwdtrack PWDTRACK
5651              Set to "on" to track the time the password was last changed
5652
5653
5654       --pwdwarning PWDWARNING
5655              Send  an  expiring  warning if password expires within this time
5656              (in seconds)
5657
5658
5659       --pwdexpire PWDEXPIRE
5660              Set to "on" to enable password expiration
5661
5662
5663       --pwdmaxage PWDMAXAGE
5664              The password expiration time in seconds
5665
5666
5667       --pwdminage PWDMINAGE
5668              The number of seconds that must pass before a  user  can  change
5669              their password
5670
5671
5672       --pwdgracelimit PWDGRACELIMIT
5673              The number of allowed logins after the password has expired
5674
5675
5676       --pwdsendexpiring PWDSENDEXPIRING
5677              Set  to  "on"  to always send the expiring control regardless of
5678              the warning period
5679
5680
5681       --pwdlockout PWDLOCKOUT
5682              Set to "on" to enable account lockout
5683
5684
5685       --pwdunlock PWDUNLOCK
5686              Set to "on" to allow an account to  become  unlocked  after  the
5687              lockout duration
5688
5689
5690       --pwdlockoutduration PWDLOCKOUTDURATION
5691              The number of seconds an account stays locked out
5692
5693
5694       --pwdmaxfailures PWDMAXFAILURES
5695              The  maximum  number  of allowed failed password attempts before
5696              the account gets locked
5697
5698
5699       --pwdresetfailcount PWDRESETFAILCOUNT
5700              The number of seconds to wait before reducing the  failed  login
5701              count on an account
5702
5703
5704       --pwdchecksyntax PWDCHECKSYNTAX
5705              Set to "on" to enable password syntax checking
5706
5707
5708       --pwdminlen PWDMINLEN
5709              The minimum number of characters required in a password
5710
5711
5712       --pwdmindigits PWDMINDIGITS
5713              The minimum number of digit/number characters in a password
5714
5715
5716       --pwdminalphas PWDMINALPHAS
5717              The minimum number of alpha characters required in a password
5718
5719
5720       --pwdminuppers PWDMINUPPERS
5721              The  minimum  number of uppercase characters required in a pass‐
5722              word
5723
5724
5725       --pwdminlowers PWDMINLOWERS
5726              The minimum number of lowercase characters required in  a  pass‐
5727              word
5728
5729
5730       --pwdminspecials PWDMINSPECIALS
5731              The minimum number of special characters required in a password
5732
5733
5734       --pwdmin8bits PWDMIN8BITS
5735              The minimum number of 8-bit characters required in a password
5736
5737
5738       --pwdmaxrepeats PWDMAXREPEATS
5739              The  maximum  number  of times the same character can appear se‐
5740              quentially in the password
5741
5742
5743       --pwdpalindrome PWDPALINDROME
5744              Set to "on" to reject passwords that are palindromes
5745
5746
5747       --pwdmaxseq PWDMAXSEQ
5748              The maximum number of allowed monotonic character sequences in a
5749              password
5750
5751
5752       --pwdmaxseqsets PWDMAXSEQSETS
5753              The maximum number of allowed monotonic character sequences that
5754              can be duplicated in a password
5755
5756
5757       --pwdmaxclasschars PWDMAXCLASSCHARS
5758              The maximum number of sequential characters from the same  char‐
5759              acter class that is allowed in a password
5760
5761
5762       --pwdmincatagories PWDMINCATAGORIES
5763              The minimum number of syntax category checks
5764
5765
5766       --pwdmintokenlen PWDMINTOKENLEN
5767              Sets  the smallest attribute value length that is used for triv‐
5768              ial/user words checking. This also impacts "--pwduserattrs"
5769
5770
5771       --pwdbadwords PWDBADWORDS
5772              A space-separated list of words that can not be in a password
5773
5774
5775       --pwduserattrs PWDUSERATTRS
5776              A space-separated list of attributes whose values can not appear
5777              in the password (See "--pwdmintokenlen")
5778
5779
5780       --pwddictcheck PWDDICTCHECK
5781              Set to "on" to enforce CrackLib dictionary checking
5782
5783
5784       --pwddictpath PWDDICTPATH
5785              Filesystem path to specific/custom CrackLib dictionary files
5786
5787
5788       --pwptprmaxuse PWPTPRMAXUSE
5789              Number of times a reset password can be used for authentication
5790
5791
5792       --pwptprdelayexpireat PWPTPRDELAYEXPIREAT
5793              Number of seconds after which a reset password expires
5794
5795
5796       --pwptprdelayvalidfrom PWPTPRDELAYVALIDFROM
5797              Number  of  seconds to wait before using a reset password to au‐
5798              thenticated
5799
5800

COMMAND 'dsconf replication'

5802       usage: dsconf instance replication [-h]
5803                                          {enable,disable,get-ruv,list,sta‐
5804       tus,winsync-status,promote,create-manager,delete-manager,de‐
5805       mote,get,set-changelog,get-changelog,export-changelog,im‐
5806       port-changelog,set,monitor}
5807                                          ...
5808
5809

POSITIONAL ARGUMENTS 'dsconf replication'

5811       dsconf replication enable
5812              Enable replication for a suffix
5813
5814       dsconf replication disable
5815              Disable replication for a suffix
5816
5817       dsconf replication get-ruv
5818              Display the database RUV entry for a suffix
5819
5820       dsconf replication list
5821              Lists all the replicated suffixes
5822
5823       dsconf replication status
5824              Display the current status of all the replication agreements
5825
5826       dsconf replication winsync-status
5827              Display the current status of all the replication agreements
5828
5829       dsconf replication promote
5830              Promote a replica to a hub or supplier
5831
5832       dsconf replication create-manager
5833              Create a replication manager entry
5834
5835       dsconf replication delete-manager
5836              Delete a replication manager entry
5837
5838       dsconf replication demote
5839              Demote replica to a hub or consumer
5840
5841       dsconf replication get
5842              Display the replication configuration
5843
5844       dsconf replication set-changelog
5845              Set replication changelog attributes
5846
5847       dsconf replication get-changelog
5848              Display replication changelog attributes
5849
5850       dsconf replication export-changelog
5851              Export  the  Directory  Server  replication changelog to an LDIF
5852              file
5853
5854       dsconf replication import-changelog
5855              Restore/import Directory Server replication change log  from  an
5856              LDIF  file.  This  is typically used when managing changelog en‐
5857              cryption
5858
5859       dsconf replication set
5860              Set an attribute in the replication configuration
5861
5862       dsconf replication monitor
5863              Display the full replication topology report
5864
5865

COMMAND 'dsconf replication enable'

5867       usage: dsconf instance replication enable [-h] --suffix  SUFFIX  --role
5868       ROLE
5869                                                 [--replica-id REPLICA_ID]
5870                                                 [--bind-group-dn
5871       BIND_GROUP_DN]
5872                                                 [--bind-dn BIND_DN]
5873                                                 [--bind-passwd BIND_PASSWD]
5874
5875

OPTIONS 'dsconf replication enable'

5877       --suffix SUFFIX
5878              Sets the DN of the suffix to be enabled for replication
5879
5880
5881       --role ROLE
5882              Sets the replication role: "supplier", "hub", or "consumer"
5883
5884
5885       --replica-id REPLICA_ID
5886              Sets the replication identifier for a "supplier".  Values  range
5887              from 1 - 65534
5888
5889
5890       --bind-group-dn BIND_GROUP_DN
5891              Sets  a  group  entry  DN containing members that are "bind/sup‐
5892              plier" DNs
5893
5894
5895       --bind-dn BIND_DN
5896              Sets the bind or supplier DN that can make replication updates
5897
5898
5899       --bind-passwd BIND_PASSWD
5900              Sets the password for replication manager (--bind-dn). This will
5901              create the manager entry if a value is set
5902
5903

COMMAND 'dsconf replication disable'

5905       usage: dsconf instance replication disable [-h] --suffix SUFFIX
5906
5907

OPTIONS 'dsconf replication disable'

5909       --suffix SUFFIX
5910              Sets the DN of the suffix to have replication disabled
5911
5912

COMMAND 'dsconf replication get-ruv'

5914       usage: dsconf instance replication get-ruv [-h] --suffix SUFFIX
5915
5916

OPTIONS 'dsconf replication get-ruv'

5918       --suffix SUFFIX
5919              Sets the DN of the replicated suffix
5920
5921

COMMAND 'dsconf replication list'

5923       usage: dsconf instance replication list [-h]
5924
5925

COMMAND 'dsconf replication status'

5927       usage: dsconf instance replication status [-h] --suffix SUFFIX
5928                                                 [--bind-dn BIND_DN]
5929                                                 [--bind-passwd BIND_PASSWD]
5930
5931

OPTIONS 'dsconf replication status'

5933       --suffix SUFFIX
5934              Sets the DN of the replication suffix
5935
5936
5937       --bind-dn BIND_DN
5938              Sets the DN to use to authenticate to the consumer
5939
5940
5941       --bind-passwd BIND_PASSWD
5942              Sets the password for the bind DN
5943
5944

COMMAND 'dsconf replication winsync-status'

5946       usage: dsconf instance replication winsync-status [-h] --suffix SUFFIX
5947                                                         [--bind-dn BIND_DN]
5948                                                         [--bind-passwd
5949       BIND_PASSWD]
5950
5951

OPTIONS 'dsconf replication winsync-status'

5953       --suffix SUFFIX
5954              Sets the DN of the replication suffix
5955
5956
5957       --bind-dn BIND_DN
5958              Sets the DN to use to authenticate to the consumer
5959
5960
5961       --bind-passwd BIND_PASSWD
5962              Sets the password of the bind DN
5963
5964

COMMAND 'dsconf replication promote'

5966       usage: dsconf instance replication promote [-h] --suffix SUFFIX  --new‐
5967       role
5968                                                  NEWROLE        [--replica-id
5969       REPLICA_ID]
5970                                                  [--bind-group-dn
5971       BIND_GROUP_DN]
5972                                                  [--bind-dn BIND_DN]
5973
5974

OPTIONS 'dsconf replication promote'

5976       --suffix SUFFIX
5977              Sets the DN of the replication suffix to promote
5978
5979
5980       --newrole NEWROLE
5981              Sets the new replica role to "hub" or "supplier"
5982
5983
5984       --replica-id REPLICA_ID
5985              Sets  the  replication identifier for a "supplier". Values range
5986              from 1 - 65534
5987
5988
5989       --bind-group-dn BIND_GROUP_DN
5990              Sets a group entry DN containing  members  that  are  "bind/sup‐
5991              plier" DNs
5992
5993
5994       --bind-dn BIND_DN
5995              Sets the bind or supplier DN that can make replication updates
5996
5997

COMMAND 'dsconf replication create-manager'

5999       usage: dsconf instance replication create-manager [-h] [--name NAME]
6000                                                         [--passwd PASSWD]
6001                                                         [--suffix SUFFIX]
6002
6003

OPTIONS 'dsconf replication create-manager'

6005       --name NAME
6006              Sets  the name of the new replication manager entry.For example,
6007              if the name is "replication manager" then the  new  manager  en‐
6008              try's DN would be "cn=replication manager,cn=config".
6009
6010
6011       --passwd PASSWD
6012              Sets  the password for replication manager. If not provided, you
6013              will be prompted for the password
6014
6015
6016       --suffix SUFFIX
6017              The DN of the replication suffix whose replication configuration
6018              you want to add this new manager to (OPTIONAL)
6019
6020

COMMAND 'dsconf replication delete-manager'

6022       usage: dsconf instance replication delete-manager [-h] [--name NAME]
6023                                                         [--suffix SUFFIX]
6024
6025

OPTIONS 'dsconf replication delete-manager'

6027       --name NAME
6028              Sets  the name of the replication manager entry under cn=config:
6029              "cn=NAME,cn=config"
6030
6031
6032       --suffix SUFFIX
6033              Sets the DN of the replication suffix whose replication configu‐
6034              ration you want to remove this manager from (OPTIONAL)
6035
6036

COMMAND 'dsconf replication demote'

6038       usage:  dsconf  instance replication demote [-h] --suffix SUFFIX --new‐
6039       role
6040                                                 NEWROLE
6041
6042

OPTIONS 'dsconf replication demote'

6044       --suffix SUFFIX
6045              Sets the DN of the replication suffix
6046
6047
6048       --newrole NEWROLE
6049              Sets the new replication role to "hub", or "consumer"
6050
6051

COMMAND 'dsconf replication get'

6053       usage: dsconf instance replication get [-h] --suffix SUFFIX
6054
6055

OPTIONS 'dsconf replication get'

6057       --suffix SUFFIX
6058              Sets the suffix DN for the replication configuration to display
6059
6060

COMMAND 'dsconf replication set-changelog'

6062       usage: dsconf instance replication set-changelog [-h] --suffix SUFFIX
6063                                                        [--max-entries MAX_EN‐
6064       TRIES]
6065                                                        [--max-age MAX_AGE]
6066                                                        [--trim-interval
6067       TRIM_INTERVAL]
6068                                                        [--encrypt]
6069                                                        [--disable-encrypt]
6070
6071

OPTIONS 'dsconf replication set-changelog'

6073       --suffix SUFFIX
6074              Sets the suffix that uses the changelog
6075
6076
6077       --max-entries MAX_ENTRIES
6078              Sets the maximum number of entries to  get  in  the  replication
6079              changelog
6080
6081
6082       --max-age MAX_AGE
6083              Set the maximum age of a replication changelog entry
6084
6085
6086       --trim-interval TRIM_INTERVAL
6087              Sets  the  interval to check if the replication changelog can be
6088              trimmed
6089
6090
6091       --encrypt
6092              Sets the replication changelog to use encryption. You  must  ex‐
6093              port and import the changelog after setting this.
6094
6095
6096       --disable-encrypt
6097              Sets  the  replication changelog to not use encryption. You must
6098              export and import the changelog after setting this.
6099
6100

COMMAND 'dsconf replication get-changelog'

6102       usage: dsconf instance replication get-changelog [-h] --suffix SUFFIX
6103
6104

OPTIONS 'dsconf replication get-changelog'

6106       --suffix SUFFIX
6107              Sets the suffix that uses the changelog
6108
6109

COMMAND 'dsconf replication export-changelog'

6111       usage: dsconf instance replication export-changelog  [-h]  {to-ldif,de‐
6112       fault} ...
6113
6114

POSITIONAL ARGUMENTS 'dsconf replication export-changelog'

6116       dsconf replication export-changelog to-ldif
6117              Sets  the  LDIF file name. This is typically used for setting up
6118              changelog encryption
6119
6120       dsconf replication export-changelog default
6121              Export the replication changelog to the  server's  default  LDIF
6122              directory
6123
6124

COMMAND 'dsconf replication export-changelog to-ldif'

6126       usage: dsconf instance replication export-changelog to-ldif
6127              [-h]  [-c]  [-d]  [-l]  [-i  CHANGELOG_LDIF]  -o  OUTPUT_FILE -r
6128       REPLICA_ROOT
6129
6130

OPTIONS 'dsconf replication export-changelog to-ldif'

6132       -c, --csn-only
6133              Enables to export and interpret CSN only.  This  option  can  be
6134              used  with or without -i option. The LDIF file that is generated
6135              can not be imported and is only used for debugging purposes.
6136
6137
6138       -d, --decode
6139              Decodes the base64 values in each changelog entry. The LDIF file
6140              that  is  generated can not be imported and is only used for de‐
6141              bugging purposes.
6142
6143
6144       -l, --preserve-ldif-done
6145              Preserves generated LDIF "files.done" files in changelog  direc‐
6146              tory.
6147
6148
6149       -i CHANGELOG_LDIF, --changelog-ldif CHANGELOG_LDIF
6150              Decodes  changes in an LDIF file. Use this option if you already
6151              have a changelog LDIF file, but the changes in that file are en‐
6152              coded.
6153
6154
6155       -o OUTPUT_FILE, --output-file OUTPUT_FILE
6156              Sets the path name for the final result
6157
6158
6159       -r REPLICA_ROOT, --replica-root REPLICA_ROOT
6160              Specifies the replica root whose changelog you want to export
6161
6162

COMMAND 'dsconf replication export-changelog default'

6164       usage: dsconf instance replication export-changelog default
6165              [-h] -r REPLICA_ROOT
6166
6167

OPTIONS 'dsconf replication export-changelog default'

6169       -r REPLICA_ROOT, --replica-root REPLICA_ROOT
6170              Specifies the replica root whose changelog you want to export
6171
6172

COMMAND 'dsconf replication import-changelog'

6174       usage: dsconf instance replication import-changelog [-h]
6175                                                           {from-ldif,default}
6176       ...
6177
6178

POSITIONAL ARGUMENTS 'dsconf replication import-changelog'

6180       dsconf replication import-changelog from-ldif
6181              Restore/import a specific single LDIF file
6182
6183       dsconf replication import-changelog default
6184              Import the default changelog LDIF file created by the server
6185
6186

COMMAND 'dsconf replication import-changelog from-ldif'

6188       usage: dsconf instance replication import-changelog from-ldif
6189              [-h] -r REPLICA_ROOT LDIF_PATH
6190
6191
6192       LDIF_PATH
6193              The path of the changelog LDIF file
6194
6195

OPTIONS 'dsconf replication import-changelog from-ldif'

6197       -r REPLICA_ROOT, --replica-root REPLICA_ROOT
6198              Specifies the replica root whose changelog you want to import
6199
6200

COMMAND 'dsconf replication import-changelog default'

6202       usage: dsconf instance replication import-changelog default
6203              [-h] -r REPLICA_ROOT
6204
6205

OPTIONS 'dsconf replication import-changelog default'

6207       -r REPLICA_ROOT, --replica-root REPLICA_ROOT
6208              Specifies the replica root whose changelog you want to import
6209
6210

COMMAND 'dsconf replication set'

6212       usage: dsconf instance replication set [-h] --suffix SUFFIX
6213                                              [--repl-add-bind-dn
6214       REPL_ADD_BIND_DN]
6215                                              [--repl-del-bind-dn
6216       REPL_DEL_BIND_DN]
6217                                              [--repl-add-ref REPL_ADD_REF]
6218                                              [--repl-del-ref REPL_DEL_REF]
6219                                              [--repl-purge-delay
6220       REPL_PURGE_DELAY]
6221                                              [--repl-tombstone-purge-interval
6222       REPL_TOMBSTONE_PURGE_INTERVAL]
6223                                              [--repl-fast-tombstone-purging
6224       REPL_FAST_TOMBSTONE_PURGING]
6225                                              [--repl-bind-group
6226       REPL_BIND_GROUP]
6227                                              [--repl-bind-group-interval
6228       REPL_BIND_GROUP_INTERVAL]
6229                                              [--repl-protocol-timeout
6230       REPL_PROTOCOL_TIMEOUT]
6231                                              [--repl-backoff-max   REPL_BACK‐
6232       OFF_MAX]
6233                                              [--repl-backoff-min   REPL_BACK‐
6234       OFF_MIN]
6235                                              [--repl-release-timeout REPL_RE‐
6236       LEASE_TIMEOUT]
6237                                              [--repl-keepalive-update-inter‐
6238       val REPL_KEEPALIVE_UPDATE_INTERVAL]
6239
6240

OPTIONS 'dsconf replication set'

6242       --suffix SUFFIX
6243              Sets the DN of the replication suffix
6244
6245
6246       --repl-add-bind-dn REPL_ADD_BIND_DN
6247              Adds a bind (supplier) DN
6248
6249
6250       --repl-del-bind-dn REPL_DEL_BIND_DN
6251              Removes a bind (supplier) DN
6252
6253
6254       --repl-add-ref REPL_ADD_REF
6255              Adds a replication referral (for consumers only)
6256
6257
6258       --repl-del-ref REPL_DEL_REF
6259              Removes a replication referral (for conusmers only)
6260
6261
6262       --repl-purge-delay REPL_PURGE_DELAY
6263              Sets the replication purge delay
6264
6265
6266       --repl-tombstone-purge-interval REPL_TOMBSTONE_PURGE_INTERVAL
6267              Sets the interval in seconds to check for tombstones that can be
6268              purged
6269
6270
6271       --repl-fast-tombstone-purging REPL_FAST_TOMBSTONE_PURGING
6272              Enables or disables improving the tombstone purging performance
6273
6274
6275       --repl-bind-group REPL_BIND_GROUP
6276              Sets  a  group  entry  DN containing members that are "bind/sup‐
6277              plier" DNs
6278
6279
6280       --repl-bind-group-interval REPL_BIND_GROUP_INTERVAL
6281              Sets an interval in seconds to check if the bind group has  been
6282              updated
6283
6284
6285       --repl-protocol-timeout REPL_PROTOCOL_TIMEOUT
6286              Sets  a  timeout  in seconds on how long to wait before stopping
6287              replication when the server is under load
6288
6289
6290       --repl-backoff-max REPL_BACKOFF_MAX
6291              The maximum time in seconds a replication agreement should  stay
6292              in  a  backoff  state while waiting to acquire the consumer. De‐
6293              fault is 300 seconds
6294
6295
6296       --repl-backoff-min REPL_BACKOFF_MIN
6297              The starting time in seconds a replication agreement should stay
6298              in  a  backoff  state while waiting to acquire the consumer. De‐
6299              fault is 3 seconds
6300
6301
6302       --repl-release-timeout REPL_RELEASE_TIMEOUT
6303              A timeout in seconds a replication supplier should send  updates
6304              before it yields its replication session
6305
6306
6307       --repl-keepalive-update-interval REPL_KEEPALIVE_UPDATE_INTERVAL
6308              Interval  in  seconds for how often the server will apply an in‐
6309              ternal update to keep the RUV from getting stale. The default is
6310              1 hour (3600 seconds)
6311
6312

COMMAND 'dsconf replication monitor'

6314       usage: dsconf instance replication monitor [-h] [-c [CONNECTIONS ...]]
6315                                                  [-a [ALIASES ...]]
6316
6317

OPTIONS 'dsconf replication monitor'

6319       -c [CONNECTIONS ...], --connections [CONNECTIONS ...]
6320              Sets  the  connection  values for monitoring other not connected
6321              topologies. The format: 'host:port:binddn:bindpwd'. You can  use
6322              regex for host and port. You can set bindpwd to * and it will be
6323              requested at the runtime or you can  include  the  path  to  the
6324              password file in square brackets - [~/pwd.txt]
6325
6326
6327       -a [ALIASES ...], --aliases [ALIASES ...]
6328              Enables displaying an alias instead of host:port, if an alias is
6329              assigned to a host:port combination. The format: alias=host:port
6330
6331

COMMAND 'dsconf repl-agmt'

6333       usage: dsconf instance repl-agmt [-h]
6334                                        {list,enable,disable,init,init-sta‐
6335       tus,poke,status,delete,create,set,get}
6336                                        ...
6337
6338

POSITIONAL ARGUMENTS 'dsconf repl-agmt'

6340       dsconf repl-agmt list
6341              List all replication agreements
6342
6343       dsconf repl-agmt enable
6344              Enable replication agreement
6345
6346       dsconf repl-agmt disable
6347              Disable replication agreement
6348
6349       dsconf repl-agmt init
6350              Initialize replication agreement
6351
6352       dsconf repl-agmt init-status
6353              Check the agreement initialization status
6354
6355       dsconf repl-agmt poke
6356              Trigger replication to send updates now
6357
6358       dsconf repl-agmt status
6359              Displays the current status of the replication agreement
6360
6361       dsconf repl-agmt delete
6362              Delete replication agreement
6363
6364       dsconf repl-agmt create
6365              Initialize replication agreement
6366
6367       dsconf repl-agmt set
6368              Set an attribute in the replication agreement
6369
6370       dsconf repl-agmt get
6371              Get replication configuration
6372
6373

COMMAND 'dsconf repl-agmt list'

6375       usage: dsconf instance repl-agmt list [-h] --suffix SUFFIX [--entry EN‐
6376       TRY]
6377
6378

OPTIONS 'dsconf repl-agmt list'

6380       --suffix SUFFIX
6381              Sets the DN of the suffix to look up replication agreements for
6382
6383
6384       --entry ENTRY
6385              Returns the entire entry for each agreement
6386
6387

COMMAND 'dsconf repl-agmt enable'

6389       usage: dsconf instance repl-agmt enable [-h] --suffix SUFFIX AGMT_NAME
6390
6391
6392       AGMT_NAME
6393              The name of the replication agreement
6394
6395

OPTIONS 'dsconf repl-agmt enable'

6397       --suffix SUFFIX
6398              Sets the DN of the replication suffix
6399
6400

COMMAND 'dsconf repl-agmt disable'

6402       usage: dsconf instance repl-agmt disable [-h] --suffix SUFFIX AGMT_NAME
6403
6404
6405       AGMT_NAME
6406              The name of the replication agreement
6407
6408

OPTIONS 'dsconf repl-agmt disable'

6410       --suffix SUFFIX
6411              Sets the DN of the replication suffix
6412
6413

COMMAND 'dsconf repl-agmt init'

6415       usage: dsconf instance repl-agmt init [-h] --suffix SUFFIX AGMT_NAME
6416
6417
6418       AGMT_NAME
6419              The name of the replication agreement
6420
6421

OPTIONS 'dsconf repl-agmt init'

6423       --suffix SUFFIX
6424              Sets the DN of the replication suffix
6425
6426

COMMAND 'dsconf repl-agmt init-status'

6428       usage: dsconf  instance  repl-agmt  init-status  [-h]  --suffix  SUFFIX
6429       AGMT_NAME
6430
6431
6432       AGMT_NAME
6433              The name of the replication agreement
6434
6435

OPTIONS 'dsconf repl-agmt init-status'

6437       --suffix SUFFIX
6438              Sets the DN of the replication suffix
6439
6440

COMMAND 'dsconf repl-agmt poke'

6442       usage: dsconf instance repl-agmt poke [-h] --suffix SUFFIX AGMT_NAME
6443
6444
6445       AGMT_NAME
6446              The name of the replication agreement
6447
6448

OPTIONS 'dsconf repl-agmt poke'

6450       --suffix SUFFIX
6451              Sets the DN of the replication suffix
6452
6453

COMMAND 'dsconf repl-agmt status'

6455       usage: dsconf instance repl-agmt status [-h] --suffix SUFFIX
6456                                               [--bind-dn BIND_DN]
6457                                               [--bind-passwd BIND_PASSWD]
6458                                               AGMT_NAME
6459
6460
6461       AGMT_NAME
6462              The name of the replication agreement
6463
6464

OPTIONS 'dsconf repl-agmt status'

6466       --suffix SUFFIX
6467              Sets the DN of the replication suffix
6468
6469
6470       --bind-dn BIND_DN
6471              Sets the DN to use to authenticate to the consumer
6472
6473
6474       --bind-passwd BIND_PASSWD
6475              Sets the password for the bind DN
6476
6477

COMMAND 'dsconf repl-agmt delete'

6479       usage: dsconf instance repl-agmt delete [-h] --suffix SUFFIX AGMT_NAME
6480
6481
6482       AGMT_NAME
6483              The name of the replication agreement
6484
6485

OPTIONS 'dsconf repl-agmt delete'

6487       --suffix SUFFIX
6488              Sets the DN of the replication suffix
6489
6490

COMMAND 'dsconf repl-agmt create'

6492       usage:  dsconf  instance  repl-agmt  create [-h] --suffix SUFFIX --host
6493       HOST
6494                                               --port PORT --conn-protocol
6495                                               CONN_PROTOCOL        [--bind-dn
6496       BIND_DN]
6497                                               [--bind-passwd BIND_PASSWD]
6498                                               --bind-method BIND_METHOD
6499                                               [--frac-list FRAC_LIST]
6500                                               [--frac-list-total
6501       FRAC_LIST_TOTAL]
6502                                               [--strip-list STRIP_LIST]
6503                                               [--schedule SCHEDULE]
6504                                               [--conn-timeout CONN_TIMEOUT]
6505                                               [--protocol-timeout      PROTO‐
6506       COL_TIMEOUT]
6507                                               [--wait-async-results
6508       WAIT_ASYNC_RESULTS]
6509                                               [--busy-wait-time
6510       BUSY_WAIT_TIME]
6511                                               [--session-pause-time      SES‐
6512       SION_PAUSE_TIME]
6513                                               [--flow-control-window
6514       FLOW_CONTROL_WINDOW]
6515                                               [--flow-control-pause FLOW_CON‐
6516       TROL_PAUSE]
6517                                               [--bootstrap-bind-dn      BOOT‐
6518       STRAP_BIND_DN]
6519                                               [--bootstrap-bind-passwd  BOOT‐
6520       STRAP_BIND_PASSWD]
6521                                               [--bootstrap-conn-protocol
6522       BOOTSTRAP_CONN_PROTOCOL]
6523                                               [--bootstrap-bind-method  BOOT‐
6524       STRAP_BIND_METHOD]
6525                                               [--init]
6526                                               AGMT_NAME
6527
6528
6529       AGMT_NAME
6530              The name of the replication agreement
6531
6532

OPTIONS 'dsconf repl-agmt create'

6534       --suffix SUFFIX
6535              Sets the DN of the replication suffix
6536
6537
6538       --host HOST
6539              Sets the hostname of the remote replica
6540
6541
6542       --port PORT
6543              Sets the port number of the remote replica
6544
6545
6546       --conn-protocol CONN_PROTOCOL
6547              Sets the replication connection protocol: LDAP, LDAPS, or Start‐
6548              TLS
6549
6550
6551       --bind-dn BIND_DN
6552              Sets  the  bind  DN  the  agreement  uses to authenticate to the
6553              replica
6554
6555
6556       --bind-passwd BIND_PASSWD
6557              Sets the credentials for the bind DN
6558
6559
6560       --bind-method BIND_METHOD
6561              Sets the bind method: "SIMPLE", "SSLCLIENTAUTH",  "SASL/DIGEST",
6562              or "SASL/GSSAPI"
6563
6564
6565       --frac-list FRAC_LIST
6566              Sets  the  list  of  attributes to NOT replicate to the consumer
6567              during incremental updates
6568
6569
6570       --frac-list-total FRAC_LIST_TOTAL
6571              Sets the list of attributes to NOT replicate during a total ini‐
6572              tialization
6573
6574
6575       --strip-list STRIP_LIST
6576              Sets  a list of attributes that are removed from updates only if
6577              the event would otherwise be empty. Typically  this  is  set  to
6578              "modifiersname" and "modifytimestmap"
6579
6580
6581       --schedule SCHEDULE
6582              Sets  the  replication  update schedule: 'HHMM-HHMM DDDDDDD' D =
6583              0-6 (Sunday - Saturday).
6584
6585
6586       --conn-timeout CONN_TIMEOUT
6587              Sets the timeout used for replication connections
6588
6589
6590       --protocol-timeout PROTOCOL_TIMEOUT
6591              Sets a timeout in seconds on how long to  wait  before  stopping
6592              replication when the server is under load
6593
6594
6595       --wait-async-results WAIT_ASYNC_RESULTS
6596              Sets  the amount of time in milliseconds the server waits if the
6597              consumer is not ready before resending data
6598
6599
6600       --busy-wait-time BUSY_WAIT_TIME
6601              Sets the amount of time in seconds a supplier should wait  after
6602              a  consumer sends back a busy response before making another at‐
6603              tempt to acquire access.
6604
6605
6606       --session-pause-time SESSION_PAUSE_TIME
6607              Sets the amount of time in seconds a supplier  should  wait  be‐
6608              tween update sessions.
6609
6610
6611       --flow-control-window FLOW_CONTROL_WINDOW
6612              Sets  the  maximum  number of entries and updates sent by a sup‐
6613              plier, which are not acknowledged by the consumer.
6614
6615
6616       --flow-control-pause FLOW_CONTROL_PAUSE
6617              Sets the time in milliseconds to pause after reaching the number
6618              of entries and updates set in "--flow-control-window"
6619
6620
6621       --bootstrap-bind-dn BOOTSTRAP_BIND_DN
6622              Sets an optional bind DN the agreement can use to bootstrap ini‐
6623              tialization when bind groups are being used
6624
6625
6626       --bootstrap-bind-passwd BOOTSTRAP_BIND_PASSWD
6627              Sets the bootstrap credentials for the bind DN
6628
6629
6630       --bootstrap-conn-protocol BOOTSTRAP_CONN_PROTOCOL
6631              Sets the replication bootstrap connection protocol: LDAP, LDAPS,
6632              or StartTLS
6633
6634
6635       --bootstrap-bind-method BOOTSTRAP_BIND_METHOD
6636              Sets the bind method: "SIMPLE", or "SSLCLIENTAUTH"
6637
6638
6639       --init Initializes the agreement after creating it
6640
6641

COMMAND 'dsconf repl-agmt set'

6643       usage: dsconf instance repl-agmt set [-h] --suffix SUFFIX [--host HOST]
6644                                            [--port PORT]
6645                                            [--conn-protocol CONN_PROTOCOL]
6646                                            [--bind-dn BIND_DN]
6647                                            [--bind-passwd BIND_PASSWD]
6648                                            [--bind-method BIND_METHOD]
6649                                            [--frac-list FRAC_LIST]
6650                                            [--frac-list-total   FRAC_LIST_TO‐
6651       TAL]
6652                                            [--strip-list STRIP_LIST]
6653                                            [--schedule SCHEDULE]
6654                                            [--conn-timeout CONN_TIMEOUT]
6655                                            [--protocol-timeout PROTOCOL_TIME‐
6656       OUT]
6657                                            [--wait-async-results
6658       WAIT_ASYNC_RESULTS]
6659                                            [--busy-wait-time BUSY_WAIT_TIME]
6660                                            [--session-pause-time         SES‐
6661       SION_PAUSE_TIME]
6662                                            [--flow-control-window   FLOW_CON‐
6663       TROL_WINDOW]
6664                                            [--flow-control-pause    FLOW_CON‐
6665       TROL_PAUSE]
6666                                            [--bootstrap-bind-dn         BOOT‐
6667       STRAP_BIND_DN]
6668                                            [--bootstrap-bind-passwd     BOOT‐
6669       STRAP_BIND_PASSWD]
6670                                            [--bootstrap-conn-protocol   BOOT‐
6671       STRAP_CONN_PROTOCOL]
6672                                            [--bootstrap-bind-method     BOOT‐
6673       STRAP_BIND_METHOD]
6674                                            AGMT_NAME
6675
6676
6677       AGMT_NAME
6678              The name of the replication agreement
6679
6680

OPTIONS 'dsconf repl-agmt set'

6682       --suffix SUFFIX
6683              Sets the DN of the replication suffix
6684
6685
6686       --host HOST
6687              Sets the hostname of the remote replica
6688
6689
6690       --port PORT
6691              Sets the port number of the remote replica
6692
6693
6694       --conn-protocol CONN_PROTOCOL
6695              Sets the replication connection protocol: LDAP, LDAPS, or Start‐
6696              TLS
6697
6698
6699       --bind-dn BIND_DN
6700              Sets the Bind DN the  agreement  uses  to  authenticate  to  the
6701              replica
6702
6703
6704       --bind-passwd BIND_PASSWD
6705              Sets the credentials for the bind DN
6706
6707
6708       --bind-method BIND_METHOD
6709              Sets  the bind method: "SIMPLE", "SSLCLIENTAUTH", "SASL/DIGEST",
6710              or "SASL/GSSAPI"
6711
6712
6713       --frac-list FRAC_LIST
6714              Sets a list of attributes to NOT replicate to the consumer  dur‐
6715              ing incremental updates
6716
6717
6718       --frac-list-total FRAC_LIST_TOTAL
6719              Sets  a  list of attributes to NOT replicate during a total ini‐
6720              tialization
6721
6722
6723       --strip-list STRIP_LIST
6724              Sets a list of attributes that are removed from updates only  if
6725              the  event  would  otherwise  be empty. Typically this is set to
6726              "modifiersname" and "modifytimestmap"
6727
6728
6729       --schedule SCHEDULE
6730              Sets the replication update schedule: 'HHMM-HHMM  DDDDDDD'  D  =
6731              0-6 (Sunday - Saturday).
6732
6733
6734       --conn-timeout CONN_TIMEOUT
6735              Sets the timeout used for replication connections
6736
6737
6738       --protocol-timeout PROTOCOL_TIMEOUT
6739              Sets  a  timeout  in seconds on how long to wait before stopping
6740              replication when the server is under load
6741
6742
6743       --wait-async-results WAIT_ASYNC_RESULTS
6744              Sets the amount of time in milliseconds the server waits if  the
6745              consumer is not ready before resending data
6746
6747
6748       --busy-wait-time BUSY_WAIT_TIME
6749              Sets  the amount of time in seconds a supplier should wait after
6750              a consumer sends back a busy response before making another  at‐
6751              tempt to acquire access.
6752
6753
6754       --session-pause-time SESSION_PAUSE_TIME
6755              Sets  the  amount  of time in seconds a supplier should wait be‐
6756              tween update sessions.
6757
6758
6759       --flow-control-window FLOW_CONTROL_WINDOW
6760              Sets the maximum number of entries and updates sent  by  a  sup‐
6761              plier, which are not acknowledged by the consumer.
6762
6763
6764       --flow-control-pause FLOW_CONTROL_PAUSE
6765              Sets the time in milliseconds to pause after reaching the number
6766              of entries and updates set in "--flow-control-window"
6767
6768
6769       --bootstrap-bind-dn BOOTSTRAP_BIND_DN
6770              Sets an optional bind DN the agreement can use to bootstrap ini‐
6771              tialization when bind groups are being used
6772
6773
6774       --bootstrap-bind-passwd BOOTSTRAP_BIND_PASSWD
6775              sets the bootstrap credentials for the bind DN
6776
6777
6778       --bootstrap-conn-protocol BOOTSTRAP_CONN_PROTOCOL
6779              Sets the replication bootstrap connection protocol: LDAP, LDAPS,
6780              or StartTLS
6781
6782
6783       --bootstrap-bind-method BOOTSTRAP_BIND_METHOD
6784              Sets the bind method: "SIMPLE", or "SSLCLIENTAUTH"
6785
6786

COMMAND 'dsconf repl-agmt get'

6788       usage: dsconf instance repl-agmt get [-h] --suffix SUFFIX AGMT_NAME
6789
6790
6791       AGMT_NAME
6792              The suffix DN for which to display the replication configuration
6793
6794

OPTIONS 'dsconf repl-agmt get'

6796       --suffix SUFFIX
6797              Sets the DN of the replication suffix
6798
6799

COMMAND 'dsconf repl-winsync-agmt'

6801       usage: dsconf instance repl-winsync-agmt [-h]
6802                                                {list,enable,dis‐
6803       able,init,init-status,poke,status,delete,create,set,get}
6804                                                ...
6805
6806

POSITIONAL ARGUMENTS 'dsconf repl-winsync-agmt'

6808       dsconf repl-winsync-agmt list
6809              List all the replication winsync agreements
6810
6811       dsconf repl-winsync-agmt enable
6812              Enable replication winsync agreement
6813
6814       dsconf repl-winsync-agmt disable
6815              Disable replication winsync agreement
6816
6817       dsconf repl-winsync-agmt init
6818              Initialize replication winsync agreement
6819
6820       dsconf repl-winsync-agmt init-status
6821              Check the agreement initialization status
6822
6823       dsconf repl-winsync-agmt poke
6824              Trigger replication to send updates now
6825
6826       dsconf repl-winsync-agmt status
6827              Display the current status of the replication agreement
6828
6829       dsconf repl-winsync-agmt delete
6830              Delete replication winsync agreement
6831
6832       dsconf repl-winsync-agmt create
6833              Initialize replication winsync agreement
6834
6835       dsconf repl-winsync-agmt set
6836              Set an attribute in the replication winsync agreement
6837
6838       dsconf repl-winsync-agmt get
6839              Display replication configuration
6840
6841

COMMAND 'dsconf repl-winsync-agmt list'

6843       usage: dsconf instance repl-winsync-agmt list [-h] --suffix SUFFIX
6844
6845

OPTIONS 'dsconf repl-winsync-agmt list'

6847       --suffix SUFFIX
6848              Sets  the DN of the suffix to look up replication winsync agree‐
6849              ments
6850
6851

COMMAND 'dsconf repl-winsync-agmt enable'

6853       usage: dsconf instance repl-winsync-agmt enable  [-h]  --suffix  SUFFIX
6854       AGMT_NAME
6855
6856
6857       AGMT_NAME
6858              The name of the replication winsync agreement
6859
6860

OPTIONS 'dsconf repl-winsync-agmt enable'

6862       --suffix SUFFIX
6863              Sets the DN of the replication winsync suffix
6864
6865

COMMAND 'dsconf repl-winsync-agmt disable'

6867       usage: dsconf instance repl-winsync-agmt disable [-h] --suffix SUFFIX
6868                                                        AGMT_NAME
6869
6870
6871       AGMT_NAME
6872              The name of the replication winsync agreement
6873
6874

OPTIONS 'dsconf repl-winsync-agmt disable'

6876       --suffix SUFFIX
6877              Sets the DN of the replication winsync suffix
6878
6879

COMMAND 'dsconf repl-winsync-agmt init'

6881       usage:  dsconf  instance  repl-winsync-agmt  init  [-h] --suffix SUFFIX
6882       AGMT_NAME
6883
6884
6885       AGMT_NAME
6886              The name of the replication winsync agreement
6887
6888

OPTIONS 'dsconf repl-winsync-agmt init'

6890       --suffix SUFFIX
6891              Sets the DN of the replication winsync suffix
6892
6893

COMMAND 'dsconf repl-winsync-agmt init-status'

6895       usage: dsconf instance repl-winsync-agmt init-status [-h] --suffix SUF‐
6896       FIX
6897                                                            AGMT_NAME
6898
6899
6900       AGMT_NAME
6901              The name of the replication agreement
6902
6903

OPTIONS 'dsconf repl-winsync-agmt init-status'

6905       --suffix SUFFIX
6906              Sets the DN of the replication suffix
6907
6908

COMMAND 'dsconf repl-winsync-agmt poke'

6910       usage:  dsconf  instance  repl-winsync-agmt  poke  [-h] --suffix SUFFIX
6911       AGMT_NAME
6912
6913
6914       AGMT_NAME
6915              The name of the replication winsync agreement
6916
6917

OPTIONS 'dsconf repl-winsync-agmt poke'

6919       --suffix SUFFIX
6920              Sets the DN of the replication winsync suffix
6921
6922

COMMAND 'dsconf repl-winsync-agmt status'

6924       usage: dsconf instance repl-winsync-agmt status  [-h]  --suffix  SUFFIX
6925       AGMT_NAME
6926
6927
6928       AGMT_NAME
6929              The name of the replication agreement
6930
6931

OPTIONS 'dsconf repl-winsync-agmt status'

6933       --suffix SUFFIX
6934              Sets the DN of the replication suffix
6935
6936

COMMAND 'dsconf repl-winsync-agmt delete'

6938       usage:  dsconf  instance  repl-winsync-agmt delete [-h] --suffix SUFFIX
6939       AGMT_NAME
6940
6941
6942       AGMT_NAME
6943              The name of the replication winsync agreement
6944
6945

OPTIONS 'dsconf repl-winsync-agmt delete'

6947       --suffix SUFFIX
6948              Sets the DN of the replication winsync suffix
6949
6950

COMMAND 'dsconf repl-winsync-agmt create'

6952       usage: dsconf instance repl-winsync-agmt create  [-h]  --suffix  SUFFIX
6953       --host
6954                                                       HOST --port PORT
6955                                                       --conn-protocol
6956       CONN_PROTOCOL
6957                                                       --bind-dn BIND_DN
6958                                                       --bind-passwd
6959       BIND_PASSWD
6960                                                       [--frac-list FRAC_LIST]
6961                                                       [--schedule SCHEDULE]
6962                                                       --win-subtree  WIN_SUB‐
6963       TREE
6964                                                       --ds-subtree DS_SUBTREE
6965                                                       --win-domain WIN_DOMAIN
6966                                                       [--sync-users
6967       SYNC_USERS]
6968                                                       [--sync-groups
6969       SYNC_GROUPS]
6970                                                       [--sync-interval
6971       SYNC_INTERVAL]
6972                                                       [--one-way-sync
6973       ONE_WAY_SYNC]
6974                                                       [--move-action MOVE_AC‐
6975       TION]
6976                                                       [--win-filter  WIN_FIL‐
6977       TER]
6978                                                       [--ds-filter DS_FILTER]
6979                                                       [--subtree-pair    SUB‐
6980       TREE_PAIR]
6981                                                       [--conn-timeout
6982       CONN_TIMEOUT]
6983                                                       [--busy-wait-time
6984       BUSY_WAIT_TIME]
6985                                                       [--session-pause-time
6986       SESSION_PAUSE_TIME]
6987                                                       [--flatten-tree]
6988       [--init]
6989                                                       AGMT_NAME
6990
6991
6992       AGMT_NAME
6993              The name of the replication winsync agreement
6994
6995

OPTIONS 'dsconf repl-winsync-agmt create'

6997       --suffix SUFFIX
6998              Sets the DN of the replication winsync suffix
6999
7000
7001       --host HOST
7002              Sets the hostname of the AD server
7003
7004
7005       --port PORT
7006              Sets the port number of the AD server
7007
7008
7009       --conn-protocol CONN_PROTOCOL
7010              Sets  the  replication winsync connection protocol: LDAP, LDAPS,
7011              or StartTLS
7012
7013
7014       --bind-dn BIND_DN
7015              Sets the bind DN the agreement uses to authenticate  to  the  AD
7016              Server
7017
7018
7019       --bind-passwd BIND_PASSWD
7020              Sets the credentials for the Bind DN
7021
7022
7023       --frac-list FRAC_LIST
7024              Sets  a list of attributes to NOT replicate to the consumer dur‐
7025              ing incremental updates
7026
7027
7028       --schedule SCHEDULE
7029              Sets the replication update schedule
7030
7031
7032       --win-subtree WIN_SUBTREE
7033              Sets the suffix of the AD Server
7034
7035
7036       --ds-subtree DS_SUBTREE
7037              Sets the Directory Server suffix
7038
7039
7040       --win-domain WIN_DOMAIN
7041              Sets the AD Domain
7042
7043
7044       --sync-users SYNC_USERS
7045              Synchronizes users between AD and DS
7046
7047
7048       --sync-groups SYNC_GROUPS
7049              Synchronizes groups between AD and DS
7050
7051
7052       --sync-interval SYNC_INTERVAL
7053              Sets the interval that DS checks AD for changes in entries
7054
7055
7056       --one-way-sync ONE_WAY_SYNC
7057              Sets which direction to perform synchronization: "toWindows", or
7058              "fromWindows\,. By default sync occurs in both directions.
7059
7060
7061       --move-action MOVE_ACTION
7062              Sets  instructions  on  how  to handle moved or deleted entries:
7063              "none", "unsync", or "delete"
7064
7065
7066       --win-filter WIN_FILTER
7067              Sets a custom filter for finding users in AD Server
7068
7069
7070       --ds-filter DS_FILTER
7071              Sets a custom filter for finding AD users in DS
7072
7073
7074       --subtree-pair SUBTREE_PAIR
7075              Sets the subtree pair: <DS_SUBTREE>:<WINDOWS_SUBTREE>
7076
7077
7078       --conn-timeout CONN_TIMEOUT
7079              Sets the timeout used for replicaton connections
7080
7081
7082       --busy-wait-time BUSY_WAIT_TIME
7083              Sets the amount of time in seconds a supplier should wait  after
7084              a  consumer sends back a busy response before making another at‐
7085              tempt to acquire access
7086
7087
7088       --session-pause-time SESSION_PAUSE_TIME
7089              Sets the amount of time in seconds a supplier  should  wait  be‐
7090              tween update sessions
7091
7092
7093       --flatten-tree
7094              By default, the tree structure of AD is preserved into 389. This
7095              MAY cause replication to fail in some cases, as you may need  to
7096              create  missing  OU's  to  recreate the same treestructure. This
7097              setting when enabled, removes the tree structure of AD and flat‐
7098              tens  all  entries  into the ds-subtree. This does NOT affect or
7099              change the tree structure of the AD directory.
7100
7101
7102       --init Initializes the agreement after creating it
7103
7104

COMMAND 'dsconf repl-winsync-agmt set'

7106       usage: dsconf instance repl-winsync-agmt set [-h] [--suffix SUFFIX]
7107                                                    [--host   HOST]    [--port
7108       PORT]
7109                                                    [--conn-protocol CONN_PRO‐
7110       TOCOL]
7111                                                    [--bind-dn BIND_DN]
7112                                                    [--bind-passwd
7113       BIND_PASSWD]
7114                                                    [--frac-list FRAC_LIST]
7115                                                    [--schedule SCHEDULE]
7116                                                    [--win-subtree    WIN_SUB‐
7117       TREE]
7118                                                    [--ds-subtree DS_SUBTREE]
7119                                                    [--win-domain WIN_DOMAIN]
7120                                                    [--sync-users SYNC_USERS]
7121                                                    [--sync-groups
7122       SYNC_GROUPS]
7123                                                    [--sync-interval  SYNC_IN‐
7124       TERVAL]
7125                                                    [--one-way-sync
7126       ONE_WAY_SYNC]
7127                                                    [--move-action    MOVE_AC‐
7128       TION]
7129                                                    [--win-filter WIN_FILTER]
7130                                                    [--ds-filter DS_FILTER]
7131                                                    [--subtree-pair       SUB‐
7132       TREE_PAIR]
7133                                                    [--conn-timeout CONN_TIME‐
7134       OUT]
7135                                                    [--busy-wait-time
7136       BUSY_WAIT_TIME]
7137                                                    [--session-pause-time SES‐
7138       SION_PAUSE_TIME]
7139                                                    AGMT_NAME
7140
7141
7142       AGMT_NAME
7143              The name of the replication winsync agreement
7144
7145

OPTIONS 'dsconf repl-winsync-agmt set'

7147       --suffix SUFFIX
7148              Sets the DN of the replication winsync suffix
7149
7150
7151       --host HOST
7152              Sets the hostname of the AD server
7153
7154
7155       --port PORT
7156              Sets the port number of the AD server
7157
7158
7159       --conn-protocol CONN_PROTOCOL
7160              Sets the replication winsync connection protocol:  LDAP,  LDAPS,
7161              or StartTLS
7162
7163
7164       --bind-dn BIND_DN
7165              Sets  the  bind  DN the agreement uses to authenticate to the AD
7166              Server
7167
7168
7169       --bind-passwd BIND_PASSWD
7170              Sets the credentials for the Bind DN
7171
7172
7173       --frac-list FRAC_LIST
7174              Sets a list of attributes to NOT replicate to the consumer  dur‐
7175              ing incremental updates
7176
7177
7178       --schedule SCHEDULE
7179              Sets the replication update schedule
7180
7181
7182       --win-subtree WIN_SUBTREE
7183              Sets the suffix of the AD Server
7184
7185
7186       --ds-subtree DS_SUBTREE
7187              Sets the Directory Server suffix
7188
7189
7190       --win-domain WIN_DOMAIN
7191              Sets the AD Domain
7192
7193
7194       --sync-users SYNC_USERS
7195              Synchronizes users between AD and DS
7196
7197
7198       --sync-groups SYNC_GROUPS
7199              Synchronizes groups between AD and DS
7200
7201
7202       --sync-interval SYNC_INTERVAL
7203              Sets the interval that DS checks AD for changes in entries
7204
7205
7206       --one-way-sync ONE_WAY_SYNC
7207              Sets which direction to perform synchronization: "toWindows", or
7208              "fromWindows". By default sync occurs in both directions.
7209
7210
7211       --move-action MOVE_ACTION
7212              Sets instructions on how to handle  moved  or  deleted  entries:
7213              "none", "unsync", or "delete"
7214
7215
7216       --win-filter WIN_FILTER
7217              Sets a custom filter for finding users in AD Server
7218
7219
7220       --ds-filter DS_FILTER
7221              Sets a custom filter for finding AD users in DS
7222
7223
7224       --subtree-pair SUBTREE_PAIR
7225              Sets the subtree pair: <DS_SUBTREE>:<WINDOWS_SUBTREE>
7226
7227
7228       --conn-timeout CONN_TIMEOUT
7229              Sets the timeout used for replicaton connections
7230
7231
7232       --busy-wait-time BUSY_WAIT_TIME
7233              Sets  the amount of time in seconds a supplier should wait after
7234              a consumer sends back a busy response before making another  at‐
7235              tempt to acquire access
7236
7237
7238       --session-pause-time SESSION_PAUSE_TIME
7239              Sets  the  amount  of time in seconds a supplier should wait be‐
7240              tween update sessions
7241
7242

COMMAND 'dsconf repl-winsync-agmt get'

7244       usage: dsconf  instance  repl-winsync-agmt  get  [-h]  --suffix  SUFFIX
7245       AGMT_NAME
7246
7247
7248       AGMT_NAME
7249              The suffix DN for the replication configuration to display
7250
7251

OPTIONS 'dsconf repl-winsync-agmt get'

7253       --suffix SUFFIX
7254              Sets the DN of the replication suffix
7255
7256

COMMAND 'dsconf repl-tasks'

7258       usage: dsconf instance repl-tasks [-h]
7259                                         {cleanallruv,list-clean‐
7260       ruv-tasks,abort-cleanallruv,list-abortruv-tasks}
7261                                         ...
7262
7263

POSITIONAL ARGUMENTS 'dsconf repl-tasks'

7265       dsconf repl-tasks cleanallruv
7266              Cleanup old/removed replica IDs
7267
7268       dsconf repl-tasks list-cleanruv-tasks
7269              List all the running CleanAllRUV tasks
7270
7271       dsconf repl-tasks abort-cleanallruv
7272              Abort cleanallruv tasks
7273
7274       dsconf repl-tasks list-abortruv-tasks
7275              List all the running CleanAllRUV abort tasks
7276
7277

COMMAND 'dsconf repl-tasks cleanallruv'

7279       usage: dsconf instance repl-tasks cleanallruv [-h] --suffix SUFFIX
7280                                                     --replica-id REPLICA_ID
7281                                                     [--force-cleaning]
7282
7283

OPTIONS 'dsconf repl-tasks cleanallruv'

7285       --suffix SUFFIX
7286              Sets the Directory Server suffix
7287
7288
7289       --replica-id REPLICA_ID
7290              Sets the replica ID to remove/clean
7291
7292
7293       --force-cleaning
7294              Ignores errors and make a best attempt to clean all replicas
7295
7296

COMMAND 'dsconf repl-tasks list-cleanruv-tasks'

7298       usage: dsconf instance repl-tasks  list-cleanruv-tasks  [-h]  [--suffix
7299       SUFFIX]
7300
7301

OPTIONS 'dsconf repl-tasks list-cleanruv-tasks'

7303       --suffix SUFFIX
7304              Lists only tasks for the specified suffix
7305
7306

COMMAND 'dsconf repl-tasks abort-cleanallruv'

7308       usage:  dsconf instance repl-tasks abort-cleanallruv [-h] --suffix SUF‐
7309       FIX
7310                                                           --replica-id
7311       REPLICA_ID
7312                                                           [--certify]
7313
7314

OPTIONS 'dsconf repl-tasks abort-cleanallruv'

7316       --suffix SUFFIX
7317              Sets the Directory Server suffix
7318
7319
7320       --replica-id REPLICA_ID
7321              Sets the replica ID of the cleaning task to abort
7322
7323
7324       --certify
7325              Enforces that the abort task completed on all replicas
7326
7327

COMMAND 'dsconf repl-tasks list-abortruv-tasks'

7329       usage:  dsconf  instance  repl-tasks list-abortruv-tasks [-h] [--suffix
7330       SUFFIX]
7331
7332

OPTIONS 'dsconf repl-tasks list-abortruv-tasks'

7334       --suffix SUFFIX
7335              Lists only tasks for the specified suffix
7336
7337

COMMAND 'dsconf sasl'

7339       usage: dsconf instance sasl [-h]
7340                                   {list,get-mechs,get-avail‐
7341       able-mechs,get,create,delete}
7342                                   ...
7343
7344

POSITIONAL ARGUMENTS 'dsconf sasl'

7346       dsconf sasl list
7347              Display available SASL mappings
7348
7349       dsconf sasl get-mechs
7350              Display the SASL mechanisms that the server will accept
7351
7352       dsconf sasl get-available-mechs
7353              Display the SASL mechanisms that are available to the server
7354
7355       dsconf sasl get
7356              Displays SASL mappings
7357
7358       dsconf sasl create
7359              Create a SASL mapping
7360
7361       dsconf sasl delete
7362              Deletes the SASL object
7363
7364

COMMAND 'dsconf sasl list'

7366       usage: dsconf instance sasl list [-h] [--details]
7367
7368

OPTIONS 'dsconf sasl list'

7370       --details
7371              Displays each SASL mapping in detail
7372
7373

COMMAND 'dsconf sasl get-mechs'

7375       usage: dsconf instance sasl get-mechs [-h]
7376
7377

COMMAND 'dsconf sasl get-available-mechs'

7379       usage: dsconf instance sasl get-available-mechs [-h]
7380
7381

COMMAND 'dsconf sasl get'

7383       usage: dsconf instance sasl get [-h] [selector]
7384
7385
7386       selector
7387              The SASL mapping name to display
7388
7389

COMMAND 'dsconf sasl create'

7391       usage: dsconf instance sasl create [-h] [--cn [CN]]
7392                                          [--nsSaslMapRegexString
7393       [NSSASLMAPREGEXSTRING]]
7394                                          [--nsSaslMapBaseDNTemplate
7395       [NSSASLMAPBASEDNTEMPLATE]]
7396                                          [--nsSaslMapFilterTemplate
7397       [NSSASLMAPFILTERTEMPLATE]]
7398                                          [--nsSaslMapPriority  [NSSASLMAPPRI‐
7399       ORITY]]
7400
7401

OPTIONS 'dsconf sasl create'

7403       --cn [CN]
7404              Value of cn
7405
7406
7407       --nsSaslMapRegexString [NSSASLMAPREGEXSTRING]
7408              Value of nsSaslMapRegexString
7409
7410
7411       --nsSaslMapBaseDNTemplate [NSSASLMAPBASEDNTEMPLATE]
7412              Value of nsSaslMapBaseDNTemplate
7413
7414
7415       --nsSaslMapFilterTemplate [NSSASLMAPFILTERTEMPLATE]
7416              Value of nsSaslMapFilterTemplate
7417
7418
7419       --nsSaslMapPriority [NSSASLMAPPRIORITY]
7420              Value of nsSaslMapPriority
7421
7422

COMMAND 'dsconf sasl delete'

7424       usage: dsconf instance sasl delete [-h] map_name
7425
7426
7427       map_name
7428              The SASL mapping name ("cn" value)
7429
7430

COMMAND 'dsconf security'

7432       usage: dsconf instance security [-h]
7433                                       {set,get,enable,disable,dis‐
7434       able_plain_port,certificate,ca-certificate,rsa,ciphers,csr,key}
7435                                       ...
7436
7437

POSITIONAL ARGUMENTS 'dsconf security'

7439       dsconf security set
7440              Set general security options
7441
7442       dsconf security get
7443              Display general security options
7444
7445       dsconf security enable
7446              Enable security
7447
7448       dsconf security disable
7449              Disable security
7450
7451       dsconf security disable_plain_port
7452              Disables the plain text LDAP port, allowing only LDAPS to  func‐
7453              tion
7454
7455       dsconf security certificate
7456              Manage TLS certificates
7457
7458       dsconf security ca-certificate
7459              Manage TLS certificate authorities
7460
7461       dsconf security rsa
7462              Query and update RSA security options
7463
7464       dsconf security ciphers
7465              Manage secure ciphers
7466
7467       dsconf security csr
7468              Manage certificate signing requests
7469
7470       dsconf security key
7471              Manage keys in NSS DB
7472
7473

COMMAND 'dsconf security set'

7475       usage: dsconf instance security set [-h] [--security SECURITY]
7476                                           [--listen-host LISTEN_HOST]
7477                                           [--secure-port SECURE_PORT]
7478                                           [--tls-client-auth TLS_CLIENT_AUTH]
7479                                           [--tls-client-renegotiation
7480       TLS_CLIENT_RENEGOTIATION]
7481                                           [--require-secure-authentication
7482       REQUIRE_SECURE_AUTHENTICATION]
7483                                           [--check-hostname CHECK_HOSTNAME]
7484                                           [--verify-cert-chain-on-startup
7485       VERIFY_CERT_CHAIN_ON_STARTUP]
7486                                           [--session-timeout SESSION_TIMEOUT]
7487                                           [--tls-protocol-min      TLS_PROTO‐
7488       COL_MIN]
7489                                           [--tls-protocol-max      TLS_PROTO‐
7490       COL_MAX]
7491                                           [--allow-insecure-ciphers ALLOW_IN‐
7492       SECURE_CIPHERS]
7493                                           [--allow-weak-dh-param          AL‐
7494       LOW_WEAK_DH_PARAM]
7495                                           [--cipher-pref CIPHER_PREF]
7496
7497       Use this command  for  setting  security  related  options  located  in
7498       cn=config and cn=encryption,cn=config.
7499
7500       To  enable/disable security you can use enable and disable commands in‐
7501       stead.
7502
7503

OPTIONS 'dsconf security set'

7505       --security SECURITY
7506              Enables or disables security (nsslapd-security)
7507
7508
7509       --listen-host LISTEN_HOST
7510              Sets the host or IP address to listen on for LDAPS  (nsslapd-se‐
7511              curelistenhost)
7512
7513
7514       --secure-port SECURE_PORT
7515              Sets the port for LDAPS to listen on (nsslapd-securePort)
7516
7517
7518       --tls-client-auth TLS_CLIENT_AUTH
7519              Configures client authentication requirement (nsSSLClientAuth)
7520
7521
7522       --tls-client-renegotiation TLS_CLIENT_RENEGOTIATION
7523              Allows client TLS renegotiation (nsTLSAllowClientRenegotiation)
7524
7525
7526       --require-secure-authentication REQUIRE_SECURE_AUTHENTICATION
7527              Configures  whether  binds over LDAPS, StartTLS, or SASL are re‐
7528              quired (nsslapd- require-secure-binds)
7529
7530
7531       --check-hostname CHECK_HOSTNAME
7532              Checks the subject of remote certificate  against  the  hostname
7533              (nsslapd-ssl- check-hostname)
7534
7535
7536       --verify-cert-chain-on-startup VERIFY_CERT_CHAIN_ON_STARTUP
7537              Validates  the  server certificate during startup (nsslapd-vali‐
7538              date-cert)
7539
7540
7541       --session-timeout SESSION_TIMEOUT
7542              Sets the secure session timeout (nsSSLSessionTimeout)
7543
7544
7545       --tls-protocol-min TLS_PROTOCOL_MIN
7546              Sets the minimal allowed secure protocol version (sslVersionMin)
7547
7548
7549       --tls-protocol-max TLS_PROTOCOL_MAX
7550              Sets the maximal allowed secure protocol version (sslVersionMax)
7551
7552
7553       --allow-insecure-ciphers ALLOW_INSECURE_CIPHERS
7554              Allows weak ciphers for legacy use (allowWeakCipher)
7555
7556
7557       --allow-weak-dh-param ALLOW_WEAK_DH_PARAM
7558              Allows short DH params for legacy use (allowWeakDHParam)
7559
7560
7561       --cipher-pref CIPHER_PREF
7562              Directly sets the nsSSL3Ciphers attribute. It is  a  comma-sepa‐
7563              rated  list  of  cipher names (prefixed with + or -), optionally
7564              including +all or -all. The attribute may optionally be prefixed
7565              by  keyword  "default". Please refer to documentation of the at‐
7566              tribute for a more detailed description.  (nsSSL3Ciphers)
7567
7568

COMMAND 'dsconf security get'

7570       usage: dsconf instance security get [-h]
7571
7572

COMMAND 'dsconf security enable'

7574       usage: dsconf instance security enable [-h] [--cert-name CERT_NAME]
7575
7576       If missing, create security database, then turn on security functional‐
7577       ity. Please note this is usually not enough for TLS connections to work
7578       - proper setup of CA and server certificate is necessary.
7579
7580

OPTIONS 'dsconf security enable'

7582       --cert-name CERT_NAME
7583              Sets the name of the certificate the server should use
7584
7585

COMMAND 'dsconf security disable'

7587       usage: dsconf instance security disable [-h]
7588
7589       Turn off security functionality. The rest of the configuration will  be
7590       left untouched.
7591
7592

COMMAND 'dsconf security disable_plain_port'

7594       usage: dsconf instance security disable_plain_port [-h]
7595
7596

COMMAND 'dsconf security certificate'

7598       usage: dsconf instance security certificate [-h]
7599                                                   {add,set-trust-flags,del,get,list}
7600                                                   ...
7601
7602

POSITIONAL ARGUMENTS 'dsconf security certificate'

7604       dsconf security certificate add
7605              Add a server certificate
7606
7607       dsconf security certificate set-trust-flags
7608              Set the Trust flags
7609
7610       dsconf security certificate del
7611              Delete a certificate
7612
7613       dsconf security certificate get
7614              Display a server certificate's information
7615
7616       dsconf security certificate list
7617              List the server certificates
7618
7619

COMMAND 'dsconf security certificate add'

7621       usage: dsconf instance security certificate add [-h] --file FILE --name
7622       NAME
7623                                                       [--primary-cert]
7624
7625       Add a server certificate to the NSS database
7626
7627

OPTIONS 'dsconf security certificate add'

7629       --file FILE
7630              Sets the file name of the certificate
7631
7632
7633       --name NAME
7634              Sets the name/nickname of the certificate
7635
7636
7637       --primary-cert
7638              Sets this certificate as the server's certificate
7639
7640

COMMAND 'dsconf security certificate set-trust-flags'

7642       usage: dsconf instance security certificate set-trust-flags
7643              [-h] --flags FLAGS name
7644
7645       Change the trust flags of a server certificate
7646
7647
7648       name   The name/nickname of the certificate
7649
7650

OPTIONS 'dsconf security certificate set-trust-flags'

7652       --flags FLAGS
7653              Sets the trust flags for the server certificate
7654
7655

COMMAND 'dsconf security certificate del'

7657       usage: dsconf instance security certificate del [-h] name
7658
7659       Delete a certificate from the NSS database
7660
7661
7662       name   The name/nickname of the certificate
7663
7664

COMMAND 'dsconf security certificate get'

7666       usage: dsconf instance security certificate get [-h] name
7667
7668       Displays  detailed  information  about a certificate, such as trust at‐
7669       tributes, expiration dates, Subject and Issuer DNs
7670
7671
7672       name   Set the name/nickname of the certificate
7673
7674

COMMAND 'dsconf security certificate list'

7676       usage: dsconf instance security certificate list [-h]
7677
7678       Lists the server certificates in the NSS database
7679
7680

COMMAND 'dsconf security ca-certificate'

7682       usage: dsconf instance security ca-certificate [-h]
7683                                                      {add,set-trust-flags,del,get,list}
7684                                                      ...
7685
7686

POSITIONAL ARGUMENTS 'dsconf security ca-certificate'

7688       dsconf security ca-certificate add
7689              Add a Certificate Authority
7690
7691       dsconf security ca-certificate set-trust-flags
7692              Set the Trust flags
7693
7694       dsconf security ca-certificate del
7695              Delete a certificate
7696
7697       dsconf security ca-certificate get
7698              Displays a Certificate Authority's information
7699
7700       dsconf security ca-certificate list
7701              List the Certificate Authorities
7702
7703

COMMAND 'dsconf security ca-certificate add'

7705       usage:  dsconf  instance  security  ca-certificate add [-h] --file FILE
7706       --name
7707                                                          NAME [NAME ...]
7708
7709       Add a Certificate Authority to the NSS database
7710
7711

OPTIONS 'dsconf security ca-certificate add'

7713       --file FILE
7714              Sets the file name of the CA certificate
7715
7716
7717       --name NAME [NAME ...]
7718              Sets the name/nickname of the CA certificate, if  adding  a  PEM
7719              bundle  then  specify  multiple  names one for each certificate,
7720              otherwise a number increment will be added to the previous name.
7721
7722

COMMAND 'dsconf security ca-certificate set-trust-flags'

7724       usage: dsconf instance security ca-certificate set-trust-flags
7725              [-h] --flags FLAGS name
7726
7727       Change the trust attributes of a CA certificate.  Certificate  Authori‐
7728       ties typically use "CT,,"
7729
7730
7731       name   The name/nickname of the CA certificate
7732
7733

OPTIONS 'dsconf security ca-certificate set-trust-flags'

7735       --flags FLAGS
7736              Sets the trust flags for the CA certificate
7737
7738

COMMAND 'dsconf security ca-certificate del'

7740       usage: dsconf instance security ca-certificate del [-h] name
7741
7742       Delete a CA certificate from the NSS database
7743
7744
7745       name   The name/nickname of the CA certificate
7746
7747

COMMAND 'dsconf security ca-certificate get'

7749       usage: dsconf instance security ca-certificate get [-h] name
7750
7751       Get detailed information about a CA certificate, like trust attributes,
7752       expiration dates, Subject and Issuer DN
7753
7754
7755       name   The name/nickname of the CA certificate
7756
7757

COMMAND 'dsconf security ca-certificate list'

7759       usage: dsconf instance security ca-certificate list [-h]
7760
7761       List the CA certificates in the NSS database
7762
7763

COMMAND 'dsconf security rsa'

7765       usage: dsconf instance security rsa [-h] {set,get,enable,disable} ...
7766
7767

POSITIONAL ARGUMENTS 'dsconf security rsa'

7769       dsconf security rsa set
7770              Set RSA security options
7771
7772       dsconf security rsa get
7773              Get RSA security options
7774
7775       dsconf security rsa enable
7776              Enable RSA
7777
7778       dsconf security rsa disable
7779              Disable RSA
7780
7781

COMMAND 'dsconf security rsa set'

7783       usage: dsconf instance security rsa set [-h]
7784                                               [--tls-allow-rsa-certificates
7785       TLS_ALLOW_RSA_CERTIFICATES]
7786                                               [--nss-cert-name NSS_CERT_NAME]
7787                                               [--nss-token NSS_TOKEN]
7788
7789       Use  this command for setting RSA (private key) related options located
7790       in cn=RSA,cn=encryption,cn=config.
7791
7792       To enable/disable RSA you can use enable and disable commands instead.
7793
7794

OPTIONS 'dsconf security rsa set'

7796       --tls-allow-rsa-certificates TLS_ALLOW_RSA_CERTIFICATES
7797              Activates the use of RSA certificates (nsSSLActivation)
7798
7799
7800       --nss-cert-name NSS_CERT_NAME
7801              Sets the server certificate name in NSS DB (nsSSLPersonalitySSL)
7802
7803
7804       --nss-token NSS_TOKEN
7805              Sets the security token name (module of NSS DB) (nsSSLToken)
7806
7807

COMMAND 'dsconf security rsa get'

7809       usage: dsconf instance security rsa get [-h]
7810
7811

COMMAND 'dsconf security rsa enable'

7813       usage: dsconf instance security rsa enable [-h]
7814
7815

COMMAND 'dsconf security rsa disable'

7817       usage: dsconf instance security rsa disable [-h]
7818
7819

COMMAND 'dsconf security ciphers'

7821       usage:   dsconf   instance   security   ciphers    [-h]    {enable,dis‐
7822       able,get,set,list} ...
7823
7824

POSITIONAL ARGUMENTS 'dsconf security ciphers'

7826       dsconf security ciphers enable
7827              Enable ciphers
7828
7829       dsconf security ciphers disable
7830              Disable ciphers
7831
7832       dsconf security ciphers get
7833              Get ciphers attribute
7834
7835       dsconf security ciphers set
7836              Set ciphers attribute
7837
7838       dsconf security ciphers list
7839              List ciphers
7840
7841

COMMAND 'dsconf security ciphers enable'

7843       usage: dsconf instance security ciphers enable [-h] cipher [cipher ...]
7844
7845       Use this command to enable specific ciphers.
7846
7847
7848       cipher
7849
7850

COMMAND 'dsconf security ciphers disable'

7852       usage:  dsconf  instance  security  ciphers disable [-h] cipher [cipher
7853       ...]
7854
7855       Use this command to disable specific ciphers.
7856
7857
7858       cipher
7859
7860

COMMAND 'dsconf security ciphers get'

7862       usage: dsconf instance security ciphers get [-h]
7863
7864       Use this command to get contents of nsSSL3Ciphers attribute.
7865
7866

COMMAND 'dsconf security ciphers set'

7868       usage: dsconf instance security ciphers set [-h] cipher-string
7869
7870       Use this command to directly set nsSSL3Ciphers attribute. It is a comma
7871       separated  list  of cipher names (prefixed with + or -), optionally in‐
7872       cluding +all or -all. The attribute may optionally be  set  to  keyword
7873       default.  Please refer to documentation of the attribute for a more de‐
7874       tailed description.
7875
7876
7877       cipher-string
7878
7879

COMMAND 'dsconf security ciphers list'

7881       usage: dsconf instance security ciphers list [-h]
7882                                                    [--enabled | --supported |
7883       --disabled]
7884
7885       List  secure  ciphers. Without arguments, list ciphers as configured in
7886       nsSSL3Ciphers attribute.
7887
7888

OPTIONS 'dsconf security ciphers list'

7890       --enabled
7891              Lists only enabled ciphers
7892
7893
7894       --supported
7895              Lists only supported ciphers
7896
7897
7898       --disabled
7899              Lists only supported ciphers but without enabled ciphers
7900
7901

COMMAND 'dsconf security csr'

7903       usage: dsconf instance security csr [-h] {list,get,req,del} ...
7904
7905

POSITIONAL ARGUMENTS 'dsconf security csr'

7907       dsconf security csr list
7908              List CSRs
7909
7910       dsconf security csr get
7911              Display CSR content
7912
7913       dsconf security csr req
7914              Generate a Certificate Signing Request
7915
7916       dsconf security csr del
7917              Delete a CSR file
7918
7919

COMMAND 'dsconf security csr list'

7921       usage: dsconf instance security csr list [-h] [--path PATH]
7922
7923       List all CSR files in instance configuration directiory
7924
7925

OPTIONS 'dsconf security csr list'

7927       --path PATH, -p PATH
7928              Directory contanining CSR file
7929
7930

COMMAND 'dsconf security csr get'

7932       usage: dsconf instance security csr get [-h] name
7933
7934       Displays the contents of a CSR,  which can be used for submittal to CA
7935
7936
7937       name   Name of the CSR file to display
7938
7939

COMMAND 'dsconf security csr req'

7941       usage: dsconf instance security csr req [-h] --subject  SUBJECT  --name
7942       NAME
7943                                               [alt_names ...]
7944
7945       Generate a CSR that can be submitted to a CA for verification
7946
7947
7948       alt_names
7949              CSR alternative names. These are auto-detected if not provided
7950
7951

OPTIONS 'dsconf security csr req'

7953       --subject SUBJECT, -s SUBJECT
7954              Subject field
7955
7956
7957       --name NAME, -n NAME
7958              Name
7959
7960

COMMAND 'dsconf security csr del'

7962       usage: dsconf instance security csr del [-h] name
7963
7964       Delete a CSR file
7965
7966
7967       name   Name of the CSR file to delete
7968
7969

COMMAND 'dsconf security key'

7971       usage: dsconf instance security key [-h] {list,del} ...
7972
7973

POSITIONAL ARGUMENTS 'dsconf security key'

7975       dsconf security key list
7976              List all keys in NSS DB
7977
7978       dsconf security key del
7979              Delete a key from NSS DB
7980
7981

COMMAND 'dsconf security key list'

7983       usage: dsconf instance security key list [-h] [--orphan]
7984
7985

OPTIONS 'dsconf security key list'

7987       --orphan
7988              List  orphan  keys (An orphan key is a private key in the NSS DB
7989              for which there is NO cert with the corresponding  public  key).
7990              An orphan key is created during CSR generation, when the associ‐
7991              ated certificate is imported into the NSS DB, its  orphan  state
7992              will be removed.
7993
7994

COMMAND 'dsconf security key del'

7996       usage: dsconf instance security key del [-h] key_id
7997
7998       Remove  a  key  from the NSS DB. Make sure the key is not in use before
7999       you delete
8000
8001
8002       key_id This is the key ID displayed when listing keys
8003
8004

COMMAND 'dsconf schema'

8006       usage: dsconf instance schema [-h]
8007                                     {list,attributetypes,objectclasses,match‐
8008       ingrules,reload,validate-syntax,import-openldap-file}
8009                                     ...
8010
8011

POSITIONAL ARGUMENTS 'dsconf schema'

8013       dsconf schema list
8014              List all schema objects on this system
8015
8016       dsconf schema attributetypes
8017              Work with attribute types on this system
8018
8019       dsconf schema objectclasses
8020              Work with objectClasses on this system
8021
8022       dsconf schema matchingrules
8023              Work with matching rules on this system
8024
8025       dsconf schema reload
8026              Dynamically reload schema while server is running
8027
8028       dsconf schema validate-syntax
8029              Run  a  task  to  check every modification to attributes to make
8030              sure that the new value has the required syntax for that  attri‐
8031              bute type
8032
8033       dsconf schema import-openldap-file
8034              Import  an  openldap  formatted dynamic schema ldifs. These will
8035              contain values like olcAttributeTypes and olcObjectClasses.
8036
8037

COMMAND 'dsconf schema list'

8039       usage: dsconf instance schema list [-h]
8040
8041

COMMAND 'dsconf schema attributetypes'

8043       usage: dsconf instance schema attributetypes [-h]
8044                                                    {get_syn‐
8045       taxes,list,query,add,replace,remove}
8046                                                    ...
8047
8048

POSITIONAL ARGUMENTS 'dsconf schema attributetypes'

8050       dsconf schema attributetypes get_syntaxes
8051              List all available attribute type syntaxes
8052
8053       dsconf schema attributetypes list
8054              List available attribute types on this system
8055
8056       dsconf schema attributetypes query
8057              Query  an attribute to determine object classes that may or must
8058              take it
8059
8060       dsconf schema attributetypes add
8061              Add an attribute type to this system
8062
8063       dsconf schema attributetypes replace
8064              Replace an attribute type on this system
8065
8066       dsconf schema attributetypes remove
8067              Remove an attribute type on this system
8068
8069

COMMAND 'dsconf schema attributetypes get_syntaxes'

8071       usage: dsconf instance schema attributetypes get_syntaxes [-h]
8072
8073

COMMAND 'dsconf schema attributetypes list'

8075       usage: dsconf instance schema attributetypes list [-h]
8076
8077

COMMAND 'dsconf schema attributetypes query'

8079       usage: dsconf instance schema attributetypes query [-h] [name]
8080
8081
8082       name   Attribute type to query
8083
8084

COMMAND 'dsconf schema attributetypes add'

8086       usage: dsconf instance schema attributetypes add [-h] [--oid OID]
8087                                                        [--desc DESC]
8088                                                        [--x-origin X_ORIGIN]
8089                                                        [--aliases     ALIASES
8090       [ALIASES ...]]
8091                                                        [--single-value]
8092                                                        [--multi-value]
8093                                                        [--no-user-mod]
8094       [--user-mod]
8095                                                        [--equality   EQUALITY
8096       [EQUALITY ...]]
8097                                                        [--substr SUBSTR [SUB‐
8098       STR ...]]
8099                                                        [--ordering   ORDERING
8100       [ORDERING ...]]
8101                                                        [--usage USAGE] [--sup
8102       SUP]
8103                                                        --syntax SYNTAX
8104                                                        name
8105
8106
8107       name   NAME of the object
8108
8109

OPTIONS 'dsconf schema attributetypes add'

8111       --oid OID
8112              OID assigned to the object
8113
8114
8115       --desc DESC
8116              Description text(DESC) of the object
8117
8118
8119       --x-origin X_ORIGIN
8120              Provides information about where the attribute type is defined
8121
8122
8123       --aliases ALIASES [ALIASES ...]
8124              Additional NAMEs of the object.
8125
8126
8127       --single-value
8128              True if the matching rule must have only one  valueOnly  one  of
8129              the flags this or --multi-value should be specified
8130
8131
8132       --multi-value
8133              True if the matching rule may have multiple values (default)Only
8134              one of the flags this or --single-value should be specified
8135
8136
8137       --no-user-mod
8138              True if the attribute is not modifiable  by  a  client  applica‐
8139              tionOnly one of the flags this or --user-mod should be specified
8140
8141
8142       --user-mod
8143              True if the attribute is modifiable by a client application (de‐
8144              fault)Only one of the flags this  or  --no-user-mode  should  be
8145              specified
8146
8147
8148       --equality EQUALITY [EQUALITY ...]
8149              NAME  or  OID of the matching rules used for checkingwhether at‐
8150              tribute values are equal
8151
8152
8153       --substr SUBSTR [SUBSTR ...]
8154              NAME or OID of the matching rules used  for  checkingwhether  an
8155              attribute value contains another value
8156
8157
8158       --ordering ORDERING [ORDERING ...]
8159              NAME  or  OID of the matching rules used for checkingwhether at‐
8160              tribute values are lesser - equal than
8161
8162
8163       --usage USAGE
8164              The flag indicates how the attribute type is to be used.  Choose
8165              from  the  list: userApplications (default), directoryOperation,
8166              distributedOperation, dSAOperation
8167
8168
8169       --sup SUP
8170              The NAME or OID of attribute type this attribute type is derived
8171              from
8172
8173
8174       --syntax SYNTAX
8175              OID of the LDAP syntax assigned to the attribute
8176
8177

COMMAND 'dsconf schema attributetypes replace'

8179       usage: dsconf instance schema attributetypes replace [-h] [--oid OID]
8180                                                            [--desc DESC]
8181                                                            [--x-origin X_ORI‐
8182       GIN]
8183                                                            [--aliases ALIASES
8184       [ALIASES ...]]
8185                                                            [--single-value]
8186                                                            [--multi-value]
8187                                                            [--no-user-mod]
8188                                                            [--user-mod]
8189                                                            [--equality EQUAL‐
8190       ITY [EQUALITY ...]]
8191                                                            [--substr   SUBSTR
8192       [SUBSTR ...]]
8193                                                            [--ordering ORDER‐
8194       ING [ORDERING ...]]
8195                                                            [--usage USAGE]
8196                                                            [--sup SUP]
8197                                                            [--syntax SYNTAX]
8198                                                            name
8199
8200
8201       name   NAME of the object
8202
8203

OPTIONS 'dsconf schema attributetypes replace'

8205       --oid OID
8206              OID assigned to the object
8207
8208
8209       --desc DESC
8210              Description text(DESC) of the object
8211
8212
8213       --x-origin X_ORIGIN
8214              Provides information about where the attribute type is defined
8215
8216
8217       --aliases ALIASES [ALIASES ...]
8218              Additional NAMEs of the object.
8219
8220
8221       --single-value
8222              True if the matching rule must have only one  valueOnly  one  of
8223              the flags this or --multi-value should be specified
8224
8225
8226       --multi-value
8227              True if the matching rule may have multiple values (default)Only
8228              one of the flags this or --single-value should be specified
8229
8230
8231       --no-user-mod
8232              True if the attribute is not modifiable  by  a  client  applica‐
8233              tionOnly one of the flags this or --user-mod should be specified
8234
8235
8236       --user-mod
8237              True if the attribute is modifiable by a client application (de‐
8238              fault)Only one of the flags this  or  --no-user-mode  should  be
8239              specified
8240
8241
8242       --equality EQUALITY [EQUALITY ...]
8243              NAME  or  OID of the matching rules used for checkingwhether at‐
8244              tribute values are equal
8245
8246
8247       --substr SUBSTR [SUBSTR ...]
8248              NAME or OID of the matching rules used  for  checkingwhether  an
8249              attribute value contains another value
8250
8251
8252       --ordering ORDERING [ORDERING ...]
8253              NAME  or  OID of the matching rules used for checkingwhether at‐
8254              tribute values are lesser - equal than
8255
8256
8257       --usage USAGE
8258              The flag indicates how the attribute type is to be used.  Choose
8259              from  the  list: userApplications (default), directoryOperation,
8260              distributedOperation, dSAOperation
8261
8262
8263       --sup SUP
8264              The NAME or OID of attribute type this attribute type is derived
8265              from
8266
8267
8268       --syntax SYNTAX
8269              OID of the LDAP syntax assigned to the attribute
8270
8271

COMMAND 'dsconf schema attributetypes remove'

8273       usage: dsconf instance schema attributetypes remove [-h] name
8274
8275
8276       name   NAME of the object
8277
8278

COMMAND 'dsconf schema objectclasses'

8280       usage: dsconf instance schema objectclasses [-h]
8281                                                   {list,query,add,replace,re‐
8282       move}
8283                                                   ...
8284
8285

POSITIONAL ARGUMENTS 'dsconf schema objectclasses'

8287       dsconf schema objectclasses list
8288              List available objectClasses on this system
8289
8290       dsconf schema objectclasses query
8291              Query an objectClass
8292
8293       dsconf schema objectclasses add
8294              Add an objectClass to this system
8295
8296       dsconf schema objectclasses replace
8297              Replace an objectClass on this system
8298
8299       dsconf schema objectclasses remove
8300              Remove an objectClass on this system
8301
8302

COMMAND 'dsconf schema objectclasses list'

8304       usage: dsconf instance schema objectclasses list [-h]
8305
8306

COMMAND 'dsconf schema objectclasses query'

8308       usage: dsconf instance schema objectclasses query [-h] [name]
8309
8310
8311       name   ObjectClass to query
8312
8313

COMMAND 'dsconf schema objectclasses add'

8315       usage: dsconf  instance  schema  objectclasses  add  [-h]  [--oid  OID]
8316       [--desc DESC]
8317                                                       [--x-origin X_ORIGIN]
8318                                                       [--must    MUST   [MUST
8319       ...]]
8320                                                       [--may MAY [MAY ...]]
8321                                                       [--kind KIND]
8322                                                       [--sup SUP [SUP ...]]
8323                                                       name
8324
8325
8326       name   NAME of the object
8327
8328

OPTIONS 'dsconf schema objectclasses add'

8330       --oid OID
8331              OID assigned to the object
8332
8333
8334       --desc DESC
8335              Description text(DESC) of the object
8336
8337
8338       --x-origin X_ORIGIN
8339              Provides information about where the attribute type is defined
8340
8341
8342       --must MUST [MUST ...]
8343              NAMEs or OIDs of all attributes an entry of the object must have
8344
8345
8346       --may MAY [MAY ...]
8347              NAMEs or OIDs of additional attributes an entry  of  the  object
8348              may have
8349
8350
8351       --kind KIND
8352              Kind of an object. STRUCTURAL (default), ABSTRACT, AUXILIARY
8353
8354
8355       --sup SUP [SUP ...]
8356              NAME or OIDs of object classes this object is derived from
8357
8358

COMMAND 'dsconf schema objectclasses replace'

8360       usage: dsconf instance schema objectclasses replace [-h] [--oid OID]
8361                                                           [--desc DESC]
8362                                                           [--x-origin  X_ORI‐
8363       GIN]
8364                                                           [--must MUST  [MUST
8365       ...]]
8366                                                           [--may   MAY   [MAY
8367       ...]]
8368                                                           [--kind KIND]
8369                                                           [--sup   SUP   [SUP
8370       ...]]
8371                                                           name
8372
8373
8374       name   NAME of the object
8375
8376

OPTIONS 'dsconf schema objectclasses replace'

8378       --oid OID
8379              OID assigned to the object
8380
8381
8382       --desc DESC
8383              Description text(DESC) of the object
8384
8385
8386       --x-origin X_ORIGIN
8387              Provides information about where the attribute type is defined
8388
8389
8390       --must MUST [MUST ...]
8391              NAMEs or OIDs of all attributes an entry of the object must have
8392
8393
8394       --may MAY [MAY ...]
8395              NAMEs  or  OIDs  of additional attributes an entry of the object
8396              may have
8397
8398
8399       --kind KIND
8400              Kind of an object. STRUCTURAL (default), ABSTRACT, AUXILIARY
8401
8402
8403       --sup SUP [SUP ...]
8404              NAME or OIDs of object classes this object is derived from
8405
8406

COMMAND 'dsconf schema objectclasses remove'

8408       usage: dsconf instance schema objectclasses remove [-h] name
8409
8410
8411       name   NAME of the object
8412
8413

COMMAND 'dsconf schema matchingrules'

8415       usage: dsconf instance schema matchingrules [-h] {list,query} ...
8416
8417

POSITIONAL ARGUMENTS 'dsconf schema matchingrules'

8419       dsconf schema matchingrules list
8420              List available matching rules on this system
8421
8422       dsconf schema matchingrules query
8423              Query a matching rule
8424
8425

COMMAND 'dsconf schema matchingrules list'

8427       usage: dsconf instance schema matchingrules list [-h]
8428
8429

COMMAND 'dsconf schema matchingrules query'

8431       usage: dsconf instance schema matchingrules query [-h] [name]
8432
8433
8434       name   Matching rule to query
8435
8436

COMMAND 'dsconf schema reload'

8438       usage: dsconf instance schema reload [-h] [-d SCHEMADIR] [--wait]
8439
8440

OPTIONS 'dsconf schema reload'

8442       -d SCHEMADIR, --schemadir SCHEMADIR
8443              directory where schema files are located
8444
8445
8446       --wait Wait for the reload task to complete
8447
8448

COMMAND 'dsconf schema validate-syntax'

8450       usage: dsconf instance schema validate-syntax [-h] [-f FILTER] DN
8451
8452
8453       DN     Base DN that contains entries to validate
8454
8455

OPTIONS 'dsconf schema validate-syntax'

8457       -f FILTER, --filter FILTER
8458              Filter for entries to validate. If  omitted,  all  entries  with
8459              filter "(objectclass=*)" are validated
8460
8461

COMMAND 'dsconf schema import-openldap-file'

8463       usage: dsconf instance schema import-openldap-file [-h] [--confirm]
8464                                                          schema_file
8465
8466
8467       schema_file
8468              Path to the openldap dynamic schema ldif to import
8469
8470

OPTIONS 'dsconf schema import-openldap-file'

8472       --confirm
8473              Confirm that you want to apply these schema migration actions to
8474              the 389-ds instance. By default no actions are taken.
8475
8476

COMMAND 'dsconf repl-conflict'

8478       usage: dsconf instance repl-conflict [-h]
8479                                            {list,compare,delete,swap,con‐
8480       vert,list-glue,delete-glue,convert-glue}
8481                                            ...
8482
8483

POSITIONAL ARGUMENTS 'dsconf repl-conflict'

8485       dsconf repl-conflict list
8486              List conflict entries
8487
8488       dsconf repl-conflict compare
8489              Compare the conflict entry with its valid counterpart
8490
8491       dsconf repl-conflict delete
8492              Delete a conflict entry
8493
8494       dsconf repl-conflict swap
8495              Replace the valid entry with the conflict entry
8496
8497       dsconf repl-conflict convert
8498              Convert  the  conflict entry to a valid entry, while keeping the
8499              original valid entry counterpart.  This requires that  the  con‐
8500              verted  conflict  entry  have  a  new  RDN  value.  For example:
8501              "cn=my_new_rdn_value".
8502
8503       dsconf repl-conflict list-glue
8504              List replication glue entries
8505
8506       dsconf repl-conflict delete-glue
8507              Delete the glue entry and its child entries
8508
8509       dsconf repl-conflict convert-glue
8510              Convert the glue entry into a regular entry
8511
8512

COMMAND 'dsconf repl-conflict list'

8514       usage: dsconf instance repl-conflict list [-h] suffix
8515
8516
8517       suffix Sets the backend name, or suffix, to look for conflict entries
8518
8519

COMMAND 'dsconf repl-conflict compare'

8521       usage: dsconf instance repl-conflict compare [-h] DN
8522
8523
8524       DN     The DN of the conflict entry
8525
8526

COMMAND 'dsconf repl-conflict delete'

8528       usage: dsconf instance repl-conflict delete [-h] DN
8529
8530
8531       DN     The DN of the conflict entry
8532
8533

COMMAND 'dsconf repl-conflict swap'

8535       usage: dsconf instance repl-conflict swap [-h] DN
8536
8537
8538       DN     The DN of the conflict entry
8539
8540

COMMAND 'dsconf repl-conflict convert'

8542       usage: dsconf instance repl-conflict convert [-h] --new-rdn NEW_RDN DN
8543
8544
8545       DN     The DN of the conflict entry
8546
8547

OPTIONS 'dsconf repl-conflict convert'

8549       --new-rdn NEW_RDN
8550              Sets the new RDN for the converted conflict entry. For  example:
8551              "cn=my_new_rdn_value"
8552
8553

COMMAND 'dsconf repl-conflict list-glue'

8555       usage: dsconf instance repl-conflict list-glue [-h] suffix
8556
8557
8558       suffix The backend name, or suffix, to look for glue entries
8559
8560

COMMAND 'dsconf repl-conflict delete-glue'

8562       usage: dsconf instance repl-conflict delete-glue [-h] DN
8563
8564
8565       DN     The DN of the glue entry
8566
8567

COMMAND 'dsconf repl-conflict convert-glue'

8569       usage: dsconf instance repl-conflict convert-glue [-h] DN
8570
8571
8572       DN     The DN of the glue entry
8573
8574

OPTIONS

8576       -v, --verbose
8577              Display verbose operation tracing during command execution
8578
8579
8580       -D BINDDN, --binddn BINDDN
8581              The account to bind as for executing operations
8582
8583
8584       -w BINDPW, --bindpw BINDPW
8585              Password for the bind DN
8586
8587
8588       -W, --prompt
8589              Prompt for password of the bind DN
8590
8591
8592       -y PWDFILE, --pwdfile PWDFILE
8593              Specifies a file containing the password of the bind DN
8594
8595
8596       -b BASEDN, --basedn BASEDN
8597              Base DN (root naming context) of the instance to manage
8598
8599
8600       -Z, --starttls
8601              Connect with StartTLS
8602
8603
8604       -j, --json
8605              Return result in JSON object
8606
8607

AUTHORS

8609       Red Hat, Inc., and William Brown <389-devel@lists.fedoraproject.org>
8610
8611

DISTRIBUTION

8613       The    latest    version    of    lib389   may   be   downloaded   from
8614http://www.port389.org/docs/389ds/FAQ/upstream-test-framework.html
8615
8616
8617
8618lib389 1.4.0.1                    2023-01-23                         DSCONF(8)
Impressum