Manual Pages for UNIX Darwin command on man slapo-unique
MyWebUniversity

Manual Pages for UNIX Darwin command on man slapo-unique

SLAPO-UNIQUE(5) SLAPO-UNIQUE(5)

NAME

slapo-unique - Attribute Uniqueness overlay

SYNOPSIS

/etc/openldap/slapd.conf

DESCRIPTION

The Attribute Uniqueness overlay can be used with a backend database

such as ssllaappdd-bbddbb(5) to enforce the uniqueness of some or all

attributes within a subtree. This subtree defaults to the base DN of the database for which the Uniqueness overlay is configured.

Uniqueness is enforced by searching the subtree to ensure that the val-

ues of all attributes presented with an aadddd, mmooddiiffyy or mmooddrrddnn operation are unique within the subtree. For example, if uniqueness were enforced for the uuiidd attribute, the subtree would be searched for any other records which also have a uuiidd attribute containing the same value. If any are found, the request is rejected. CCOONNFFIIGGUURRAATTIIOONN These ssllaappdd..ccoonnff options apply to the Attribute Uniqueness overlay. They should appear after the oovveerrllaayy directive. uunniiqquueebbaassee <> Configure the subtree against which uniqueness searches will be invoked. The bbaasseeddnn defaults to the base DN of the database for which uniqueness is configured. uunniiqquueeiiggnnoorree <> Configure one or more attributes for which uniqueness will not

be enforced. If not configured, all non-operational (eg, sys-

tem) attributes must be unique. Note that the uunniiqquueeiiggnnoorree list should generally contain the oobbjjeeccttCCllaassss, ddcc, oouu and oo attributes, as these will generally not be unique, nor are they operational attributes. uunniiqquueeaattttrriibbuutteess <> Specify one or more attributes for which uniqueness will be

enforced. If not specified, all attributes which are not opera-

tional (eg, system attributes such as eennttrryyUUUUIIDD )) or specified via the uunniiqquueeiiggnnoorree directive above must be unique within the subtree. uunniiqquueessttrriicctt By default, uniqueness is not enforced for null values. Enabling uunniiqquueessttrriicctt mode extends the concept of uniqueness to include null values, such that only one attribute within a subtree will be allowed to have a null value. CCAAVVEEAATTSS

The search key is generated with attributes that are non-operational,

not on the uunniiqquueeiiggnnoorree list, and included in the uunniiqquueeaattttrriibbuutteess list, in that order. This makes it possible to create interesting and unusable configurations. Usually only one of uunniiqquueeiiggnnoorree or

uunniiqquueeaattttrriibbuutteess should be configured; use uunniiqquueeiiggnnoorree if the major-

ity of attributes should be unique, and use uunniiqquueeaattttrriibbuutteess if only a small set of attributes should be unique. Typical attributes for the uunniiqquueeiiggnnoorree directive are intentionally not hardcoded into the overlay to allow for maximum flexibility in

meeting site-specific requirements.

FILES /etc/openldap/slapd.conf default slapd configuration file

SEE ALSO

ssllaappdd..ccoonnff(5).

OpenLDAP 2.3.27 2006/08/19 SLAPO-UNIQUE(5)




Contact us      |      About us      |      Term of use      |       Copyright © 2000-2019 MyWebUniversity.com ™