Configuration Changes Requiring Administrative Action
This page lists the set of configuration properties that require some form of administrative action for changes to take full effect.
Note that any changes to the java.properties file (which is used to specify the Java runtime and JVM options that should be used when running the Directory Server and associated tools) require that the dsjavaproperties tool be run to apply those changes. If the changes impact the Java runtime or JVM arguments used to run the Directory Server itself, then the server must be restarted.
Attribute Syntax
- require-binary-transfer - The Directory Server must be restarted for changes to this configuration property to take full effect. Changes to this property will take effect immediately for new attribute type definitions created after the change, but the change will not take effect for existing attributes with this syntax until the server is restarted.
Bit String Attribute Syntax
- enable-compaction - No further action is required for changes to this configuration property but there is other information that administrators should know about this property. Contact Ping Identity for more information.
Integer Attribute Syntax
- enable-compaction - No further action is required for changes to this configuration property but there is other information that administrators should know about this property. Contact Ping Identity for more information.
Backend
- base-dn - No administrative action is required by default although some action may be required on a per-backend basis before the new base DN may be used.
Although it is currently supported, the use of multiple base DNs per backend is not recommended and this capability may be removed in the future. If you are considering the use of multiple base DNs in a backend, you should first contact Ping Identity support to discuss this configuration
Alarm Backend
- base-dn - No administrative action is required by default although some action may be required on a per-backend basis before the new base DN may be used.
Although it is currently supported, the use of multiple base DNs per backend is not recommended and this capability may be removed in the future. If you are considering the use of multiple base DNs in a backend, you should first contact Ping Identity support to discuss this configuration
Alert Backend
- base-dn - No administrative action is required by default although some action may be required on a per-backend basis before the new base DN may be used.
Although it is currently supported, the use of multiple base DNs per backend is not recommended and this capability may be removed in the future. If you are considering the use of multiple base DNs in a backend, you should first contact Ping Identity support to discuss this configuration
Backup Backend
- base-dn - No administrative action is required by default although some action may be required on a per-backend basis before the new base DN may be used.
Although it is currently supported, the use of multiple base DNs per backend is not recommended and this capability may be removed in the future. If you are considering the use of multiple base DNs in a backend, you should first contact Ping Identity support to discuss this configuration
Changelog Backend
- base-dn - No administrative action is required by default although some action may be required on a per-backend basis before the new base DN may be used.
Although it is currently supported, the use of multiple base DNs per backend is not recommended and this capability may be removed in the future. If you are considering the use of multiple base DNs in a backend, you should first contact Ping Identity support to discuss this configuration
- db-directory - The Directory Server must be restarted for changes to this configuration property to take full effect. Modification requires that the Directory Server be stopped, the database directory manually relocated, and then the Directory Server restarted. While the Directory Server is stopped, the directory and files pertaining to this backend in the old database directory must be manually moved or copied to the new location.
- db-cache-percent - The Directory Server must be restarted for changes to this configuration property to take full effect. In order for this modification to take effect the server must be restarted
- je-property - The Directory Server must be restarted for changes to this configuration property to take full effect. In order for this modification to take effect the server must be restarted
- changelog-write-queue-capacity - The Directory Server must be restarted for changes to this configuration property to take full effect. In order for this modification to take effect the server must be restarted
Config File Handler Backend
- base-dn - No administrative action is required by default although some action may be required on a per-backend basis before the new base DN may be used.
Although it is currently supported, the use of multiple base DNs per backend is not recommended and this capability may be removed in the future. If you are considering the use of multiple base DNs in a backend, you should first contact Ping Identity support to discuss this configuration
Encryption Settings Backend
- base-dn - No administrative action is required by default although some action may be required on a per-backend basis before the new base DN may be used.
Although it is currently supported, the use of multiple base DNs per backend is not recommended and this capability may be removed in the future. If you are considering the use of multiple base DNs in a backend, you should first contact Ping Identity support to discuss this configuration
JE Backend
- is-private-backend - The JE Backend must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- db-directory - The Directory Server must be restarted for changes to this configuration property to take full effect. Modification requires that the Directory Server be stopped, the database directory manually relocated, and then the Directory Server restarted. While the Directory Server is stopped, the directory and files pertaining to this backend in the old database directory must be manually moved or copied to the new location.
- db-num-cleaner-threads - The JE Backend must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- db-cleaner-min-utilization - The JE Backend must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- db-evictor-critical-percentage - The JE Backend must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- db-log-file-max - The JE Backend must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- db-logging-level - The JE Backend must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- je-property - The JE Backend must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- db-cache-percent - The JE Backend must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- default-cache-mode - The JE Backend must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- id2entry-cache-mode - The JE Backend must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- dn2id-cache-mode - The JE Backend must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- id2children-cache-mode - The JE Backend must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- id2subtree-cache-mode - The JE Backend must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- dn2uri-cache-mode - The JE Backend must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- index-entry-limit - If any index keys have already reached this limit, indexes must be rebuilt before they will be allowed to use the new limit.
- composite-index-entry-limit - If any composite index keys have already reached this limit, those composite indexes must be rebuilt before they will be allowed to use the new limit.
- id2children-index-entry-limit - If this limit is increased, then the contents of the backend must be exported to LDIF and re-imported to allow the new limit to be used for any id2children keys that had already hit the previous limit.
- id2subtree-index-entry-limit - If this limit is increased, then the contents of the backend must be exported to LDIF and re-imported to allow the new limit to be used for any id2subtree keys that had already hit the previous limit.
- db-txn-write-no-sync - The JE Backend must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- num-recent-changes - The Directory Server must be restarted for changes to this configuration property to take full effect. In order for this modification to take effect the server must be restarted
Large Attribute Backend
- enabled - DEPRECATION NOTE: The large attribute backend has been deprecated. It will continue to be supported for existing deployments already using the large attribute feature, but new deployments wishing for similar behavior should configure uncached attributes rather than large attributes.
- base-dn - No administrative action is required by default although some action may be required on a per-backend basis before the new base DN may be used.
Although it is currently supported, the use of multiple base DNs per backend is not recommended and this capability may be removed in the future. If you are considering the use of multiple base DNs in a backend, you should first contact Ping Identity support to discuss this configuration
- is-private-backend - The Large Attribute Backend must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- db-cache-percent - The Large Attribute Backend must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- default-cache-mode - The Large Attribute Backend must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
Local DB Backend
- uncached-id2entry-cache-mode - The Local DB Backend must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
LDIF Backend
- is-private-backend - The LDIF Backend must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- ldif-file - The LDIF Backend must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
Monitor Backend
- base-dn - No administrative action is required by default although some action may be required on a per-backend basis before the new base DN may be used.
Although it is currently supported, the use of multiple base DNs per backend is not recommended and this capability may be removed in the future. If you are considering the use of multiple base DNs in a backend, you should first contact Ping Identity support to discuss this configuration
Schema Backend
- base-dn - No administrative action is required by default although some action may be required on a per-backend basis before the new base DN may be used.
Although it is currently supported, the use of multiple base DNs per backend is not recommended and this capability may be removed in the future. If you are considering the use of multiple base DNs in a backend, you should first contact Ping Identity support to discuss this configuration
Task Backend
- base-dn - No administrative action is required by default although some action may be required on a per-backend basis before the new base DN may be used.
Although it is currently supported, the use of multiple base DNs per backend is not recommended and this capability may be removed in the future. If you are considering the use of multiple base DNs in a backend, you should first contact Ping Identity support to discuss this configuration
Trust Store Backend
- base-dn - No administrative action is required by default although some action may be required on a per-backend basis before the new base DN may be used.
Although it is currently supported, the use of multiple base DNs per backend is not recommended and this capability may be removed in the future. If you are considering the use of multiple base DNs in a backend, you should first contact Ping Identity support to discuss this configuration
Logging Change Subscription Handler
- log-file - The Logging Change Subscription Handler must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
HTTP Connection Handler
- listen-address - The HTTP Connection Handler must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- listen-port - The HTTP Connection Handler must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- use-ssl - The HTTP Connection Handler must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- ssl-cert-nickname - The HTTP Connection Handler must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- http-servlet-extension - The HTTP Connection Handler must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- web-application-extension - The HTTP Connection Handler must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- ssl-protocol - The HTTP Connection Handler must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- ssl-cipher-suite - The HTTP Connection Handler must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- key-manager-provider - The HTTP Connection Handler must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- trust-manager-provider - The HTTP Connection Handler must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- num-request-handlers - The HTTP Connection Handler must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- enable-multipart-mime-parameters - The HTTP Connection Handler must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- use-forwarded-headers - The HTTP Connection Handler must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- http-request-header-size - The HTTP Connection Handler must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- response-header - The HTTP Connection Handler must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- ssl-client-auth-policy - The HTTP Connection Handler must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
JMX Connection Handler
- listen-port - The JMX Connection Handler must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- use-ssl - The JMX Connection Handler must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- ssl-cert-nickname - The JMX Connection Handler must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
LDAP Connection Handler
- listen-address - The LDAP Connection Handler must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- listen-port - No further action is required for changes to this configuration property but there is other information that administrators should know about this property. Contact Ping Identity for more information.
- use-ssl - The LDAP Connection Handler must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- allow-start-tls - No further action is required for changes to this configuration property but there is other information that administrators should know about this property. Contact Ping Identity for more information.
- ssl-cert-nickname - The LDAP Connection Handler must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- max-cancel-handlers - The LDAP Connection Handler must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- num-accept-handlers - The LDAP Connection Handler must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- num-request-handlers - The LDAP Connection Handler must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- ssl-client-auth-policy - The LDAP Connection Handler must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- accept-backlog - The LDAP Connection Handler must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
Correlated LDAP Data View
- auxiliary-ldap-objectclass - The Directory Server must be restarted for changes to this configuration property to take full effect. Changes to this property will not take effect until the server is restarted.
Crypto Manager
- ssl-protocol - The Directory Server must be restarted for changes to this configuration property to take full effect. For LDAP connection handlers that inherit their TLS protocol configuration from the crypto manager, changes to the set of enabled TLS protocols in the crypto manager will take effect immediately for new TLS sessions negotiated after the change is made. For other connection handlers that inherit their TLS protocol configuration from the crypto manager, changes to the set of enabled TLS protocols in the crypto manager will only take effect for that connection handler after it is disabled and re-enabled or after the server is restarted. Changes to the TLS protocols allowed for replication will only take effect after a server restart.
- ssl-cipher-suite - The Directory Server must be restarted for changes to this configuration property to take full effect. For LDAP connection handlers that inherit their TLS cipher suite configuration from the crypto manager, changes to the set of enabled TLS cipher suites in the crypto manager will take effect immediately for new TLS sessions negotiated after the change is made. For other connection handlers that inherit their TLS cipher suite configuration from the crypto manager, changes to the set of enabled TLS cipher suites in the crypto manager will only take effect for that connection handler after it is disabled and re-enabled or after the server is restarted. Changes to the TLS cipher suites allowed for replication will only take effect after a server restart.
- enable-sha-1-cipher-suites - The Directory Server must be restarted for changes to this configuration property to take full effect. For outbound connections, changes to this property take effect immediately but only impact new TLS sessions negotiated after the change.
For inbound connections to a connection handler that inherits its TLS cipher suite configuration from the crypto manager, changes to the set of enabled TLS cipher suites in the crypto manager will only take effect for that connection handler after it is disabled and re-enabled or after the server is restarted. Changes to the TLS cipher suites allowed for replication will only take effect after a server restart.
- enable-rsa-key-exchange-cipher-suites - The Directory Server must be restarted for changes to this configuration property to take full effect. For outbound connections, changes to this property take effect immediately but only impact new TLS sessions negotiated after the change.
For inbound connections to a connection handler that inherits its TLS cipher suite configuration from the crypto manager, changes to the set of enabled TLS cipher suites in the crypto manager will only take effect for that connection handler after it is disabled and re-enabled or after the server is restarted. Changes to the TLS cipher suites allowed for replication will only take effect after a server restart.
- ssl-cert-nickname - The Directory Server must be restarted for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
FIFO Entry Cache
- min-cache-entry-value-count - The FIFO Entry Cache must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- min-cache-entry-attribute - The FIFO Entry Cache must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
File System Entry Cache
- cache-type - The File System Entry Cache must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- cache-directory - The File System Entry Cache must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
Interactive Transactions Extended Operation Handler
- enabled - No further action is required for changes to this configuration property but there is other information that administrators should know about this property. Contact Ping Identity for more information.
Validate TOTP Password Extended Operation Handler
- prevent-totp-reuse - No further action is required for changes to this configuration property but there is other information that administrators should know about this property. Contact Ping Identity for more information.
Delay Bind Response Failure Lockout Action
- allow-blocking-delay - No further action is required for changes to this configuration property but there is other information that administrators should know about this property. Contact Ping Identity for more information.
Global Configuration
- location - The Directory Server must be restarted for changes to this configuration property to take full effect. In order for this modification to take effect the server must be restarted. This modification must also be made to the Server Instance representing this server in the topology registry. This will ensure that topology-related operations involving communication with other servers prefer servers in the same location as this server. For example, when replication data is initialized on this server using a topology file, then another server in the same location as this server will be used, if available.
- force-as-master-for-mirrored-data - No further action is required for changes to this configuration property but there is other information that administrators should know about this property. Contact Ping Identity for more information.
- encrypt-data - Note that enabling and/or disabling data encryption in a server that has existing data will not cause that data to be automatically encrypted or decrypted. That is, existing encrypted data will remain encrypted, and existing unencrypted entries will remain unencrypted, until those entries are updated causing them to be rewritten. Unencrypted indexes will remain unencrypted until the data is re-imported using the export-ldif and import-ldif commands. See the Directory Server documentation for information about how to safely apply the new encryption settings for all existing data.
- encryption-settings-cipher-stream-provider - No further action is required for changes to this configuration property but there is other information that administrators should know about this property. Contact Ping Identity for more information.
- allow-insecure-local-jmx-connections - The Directory Server must be restarted for changes to this configuration property to take full effect. In order for this modification to take effect the server must be restarted
- background-thread-for-each-persistent-search - Changes to this configuration property will only take effect for new persistent searches requested after the change. Persistent searches that are already active will not be affected.
- invalid-attribute-syntax-behavior - DEPRECATION NOTE: The wholesale option to allow attribute values to violate their associated syntax has been deprecated. This is a very broad option and permits inadvertent corruption of the data over time.
If you are trying to import legacy data with syntax violations, or if you have applications that may attempt to store values that violate the associated attribute syntax, then the recommended options to address this are as follows:
* Update the legacy data so that all attribute values conform to the associated syntax, and update any applications that are known to try to store invalid values.
* Modify the server schema to specify an alternate syntax for the attribute types for which there are known syntax violations. If there are indexes defined for any of the updated attribute types, then those indexes must be rebuilt. This option is only recommended for custom schema elements that are not shipped with the server.
* Use the permit-syntax-violations-for-attribute property to specify the attribute types for which the server should allow non-compliant values. The permit-syntax-violations-for-attribute property should only be used if neither of the above options are possible, and you should be aware that the server may behave in unexpected ways when interacting with values that do not fit the constraints expected by the associated attribute syntax or matching rules.
- unrecoverable-database-error-mode - The Directory Server must be restarted for changes to this configuration property to take full effect. In order for this modification to take effect the server must be restarted
- database-on-virtualized-or-network-storage - See the Directory Server documentation for information about how to safely apply this setting.
- replication-set-name - The Directory Server must be restarted for changes to this configuration property to take full effect. In order for this modification to take effect the server must be restarted. This modification must also be made to the Server Instance representing this server in the topology registry. This ensures that the most up-to-date information is used by topology-related tools.
- allow-inherited-replication-of-subordinate-backends - No further action is required for changes to this configuration property but there is other information that administrators should know about this property. Contact Ping Identity for more information.
- maximum-shutdown-time - No further action is required for changes to this configuration property but there is other information that administrators should know about this property. Contact Ping Identity for more information.
- jmx-use-legacy-mbean-names - The Directory Server must be restarted for changes to this configuration property to take full effect. In order for this modification to take effect the server must be restarted
HTTP Configuration
- include-servlet-information-in-error-pages - For this modification to take effect, you must either restart the server or else disable and then re-enable any HTTP Connection Handler referencing this component.
HTTP Servlet Extension
- response-header - HTTP Connection Handlers hosting this HTTP Servlet Extension must be disabled and then re-enabled, or the server restarted, in order for this change to take effect.
Availability State HTTP Servlet Extension
- base-context-path - The Directory Server must be restarted for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
Config HTTP Servlet Extension
- identity-mapper - For this modification to take effect, you must either restart the server or else disable and then re-enable any HTTP Connection Handler referencing this component.
Consent HTTP Servlet Extension
- bearer-token-auth-enabled - The Directory Server must be restarted for changes to this configuration property to take full effect. For this modification to take effect, you must either restart the server or else disable and then re-enable any HTTP Connection Handler referencing this component.
- basic-auth-enabled - The Directory Server must be restarted for changes to this configuration property to take full effect. For this modification to take effect, you must either restart the server or else disable and then re-enable any HTTP Connection Handler referencing this component.
- identity-mapper - The Directory Server must be restarted for changes to this configuration property to take full effect. For this modification to take effect, you must either restart the server or else disable and then re-enable any HTTP Connection Handler referencing this component.
- access-token-validator - The Directory Server must be restarted for changes to this configuration property to take full effect. For this modification to take effect, you must either restart the server or else disable and then re-enable any HTTP Connection Handler referencing this component.
Delegated Admin HTTP Servlet Extension
- basic-auth-enabled - The Directory Server must be restarted for changes to this configuration property to take full effect. For this modification to take effect, you must either restart the server or else disable and then re-enable any HTTP Connection Handler referencing this component.
- identity-mapper - For this modification to take effect, you must either restart the server or else disable and then re-enable any HTTP Connection Handler referencing this component.
- access-token-validator - The Directory Server must be restarted for changes to this configuration property to take full effect. For this modification to take effect, you must either restart the server or else disable and then re-enable any HTTP Connection Handler referencing this component.
Directory REST API HTTP Servlet Extension
- basic-auth-enabled - The Directory Server must be restarted for changes to this configuration property to take full effect. For this modification to take effect, you must either restart the server or else disable and then re-enable any HTTP Connection Handler referencing this component.
- identity-mapper - For this modification to take effect, you must either restart the server or else disable and then re-enable any HTTP Connection Handler referencing this component.
- access-token-validator - For this modification to take effect, you must either restart the server or else disable and then re-enable any HTTP Connection Handler referencing this component.
File Server HTTP Servlet Extension
- base-context-path - The Directory Server must be restarted for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
Gateway HTTP Servlet Extension
- request-limit - The Directory Server must be restarted for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- response-limit - The Directory Server must be restarted for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
SCIM HTTP Servlet Extension
- base-context-path - The Directory Server must be restarted for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- debug-enabled - The Directory Server debug logger must be enabled and correctly configured for the debug messages to be forwarded.
LDAP Mapped SCIM HTTP Servlet Extension
- oauth-token-handler - The Directory Server must be restarted for changes to this configuration property to take full effect. The OAuth Token Handler changes will not take effect until the associated HTTP Connection Handler is disabled and re-enabled, or until the server is restarted.
- basic-auth-enabled - The Directory Server must be restarted for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- include-ldap-objectclass - If you have specified a large number of object classes or used the '*' value you should ensure that the Directory Server has been allocated a sufficient amount of memory (typically at least 512MB) to host the HTTP endpoints.
Metrics HTTP Servlet Extension
- identity-mapper - For this modification to take effect, you must either restart the server or else disable and then re-enable any HTTP Connection Handler referencing this component.
Open Banking HTTP Servlet Extension
- path-prefix - The Directory Server must be restarted for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- consent-definition-id - The Directory Server must be restarted for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
Prometheus Monitoring HTTP Servlet Extension
- base-context-path - The Directory Server must be restarted for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
SCIM2 HTTP Servlet Extension
- base-context-path - The Directory Server must be restarted for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- debug-enabled - The Directory Server debug logger must be enabled and correctly configured for the debug messages to be forwarded.
- swagger-enabled - The Directory Server must be restarted for changes to this configuration property to take full effect. For this modification to take effect, you must either restart the server or else disable and then re-enable any HTTP Connection Handler referencing this SCIM2 HTTP Servlet Extension.
Sideband API HTTP Servlet Extension
- request-limit - The Directory Server must be restarted for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
Velocity HTTP Servlet Extension
- identity-mapper - For this modification to take effect, you must either restart the server or disable then re-enable all HTTP Connection Handlers referencing this component.
JSON Field Constraints
- index-values - When adding a new JSON field index, you may need to use the rebuild-index tool to initialize the index based on existing data in the backend before the server will use or maintain that index. However, if the server can determine that either the backend is empty or the associated JSON field has never been used in any entries in the backend, then the new index may automatically be considered trusted. To determine whether an index needs to be initialized with the rebuild-index tool, use the command:
dbtest list-database-containers --backendID {backendID}
If the "Index Status" field has a value of "TRUSTED", then the server has determined that the JSON field is not used in the backend and it is not necessary to use rebuild-index to initialize that index. If the "Index Status" field has a different value (e.g., "UNTRUSTED" or "NEW"), then it needs to be initialized with the rebuild-index tool before it can be used.
- index-entry-limit - When increasing the index-entry-limit for a field that may contain values that have already exceeded the previous limit, you must use the rebuild-index tool (or export the contents of the backend to LDIF and re-import the data) before the new limit will be used for those values.
LDAP SDK Debug Logger
- queue-size - The LDAP SDK Debug Logger must be restarted if this property is changed and the asynchronous property is set to true.
- sign-log - The LDAP SDK Debug Logger must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- encrypt-log - The LDAP SDK Debug Logger must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
Local DB Composite Index
- index-entry-limit - If you raise the index entry limit, then that new limit will take effect immediately for any index keys that have not already exceeded the limit. If there are keys that have already exceeded an earlier limit but would not exceed the new limit, then you will need to rebuild the index for the new limit to be recognized for those keys.
Local DB Index
- index-entry-limit - If any index keys have already reached this limit, indexes must be rebuilt before they will be allowed to use the new limit.
- substring-index-entry-limit - If this limit is increased, and any substring index keys have already reached the previous limit, then the substring index must be rebuilt to use the new limit.
- maintain-match-count-for-keys-exceeding-entry-limit - If the index is updated to maintain a match count after this capability has been disabled for any period of time, then the index must be rebuilt before the count can actually be maintained.
- index-type - If any new index types are added for an attribute, and values for that attribute already exist in the database, the index must be rebuilt before it will be accurate.
- substring-length - The index must be rebuilt before it will reflect the new value.
- cache-mode - The Directory Server must be restarted for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
Local DB VLV Index
- base-dn - The index must be rebuilt after modifying this property.
- scope - The index must be rebuilt after modifying this property.
- filter - The index must be rebuilt after modifying this property.
- sort-order - The index must be rebuilt after modifying this property.
- cache-mode - The Directory Server must be restarted for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
Log Field Behavior
- default-behavior - The Directory Server must be restarted for changes to this configuration property to take full effect. Any changes made to the set of default-behavior values will not take effect until the server is restarted or access loggers configured to use it have been disabled and re-enabled.
JSON Formatted Access Log Field Behavior
- preserve-field - The Directory Server must be restarted for changes to this configuration property to take full effect. Any changes made to the set of preserve-field values will not take effect until the server is restarted or access loggers configured to use it have been disabled and re-enabled.
- preserve-field-name - The Directory Server must be restarted for changes to this configuration property to take full effect. Any changes made to the set of preserve-field-name values will not take effect until the server is restarted or access loggers configured to use it have been disabled and re-enabled.
- omit-field - The Directory Server must be restarted for changes to this configuration property to take full effect. Any changes made to the set of omit-field values will not take effect until the server is restarted or access loggers configured to use it have been disabled and re-enabled.
- omit-field-name - The Directory Server must be restarted for changes to this configuration property to take full effect. Any changes made to the set of omit-field-name values will not take effect until the server is restarted or access loggers configured to use it have been disabled and re-enabled.
- redact-entire-value-field - The Directory Server must be restarted for changes to this configuration property to take full effect. Any changes made to the set of redact-entire-value-field values will not take effect until the server is restarted or access loggers configured to use it have been disabled and re-enabled.
- redact-entire-value-field-name - The Directory Server must be restarted for changes to this configuration property to take full effect. Any changes made to the set of redact-entire-value-field-name values will not take effect until the server is restarted or access loggers configured to use it have been disabled and re-enabled.
- redact-value-components-field - The Directory Server must be restarted for changes to this configuration property to take full effect. Any changes made to the set of redact-value-components-field values will not take effect until the server is restarted or access loggers configured to use it have been disabled and re-enabled.
- tokenize-entire-value-field - The Directory Server must be restarted for changes to this configuration property to take full effect. Any changes made to the set of tokenize-entire-value-field values will not take effect until the server is restarted or access loggers configured to use it have been disabled and re-enabled.
- tokenize-entire-value-field-name - The Directory Server must be restarted for changes to this configuration property to take full effect. Any changes made to the set of tokenize-entire-value-field-name values will not take effect until the server is restarted or access loggers configured to use it have been disabled and re-enabled.
- tokenize-value-components-field - The Directory Server must be restarted for changes to this configuration property to take full effect. Any changes made to the set of tokenize-value-components-field values will not take effect until the server is restarted or access loggers configured to use it have been disabled and re-enabled.
- tokenize-value-components-field-name - The Directory Server must be restarted for changes to this configuration property to take full effect. Any changes made to the set of tokenize-value-components-field-name values will not take effect until the server is restarted or access loggers configured to use it have been disabled and re-enabled.
Text Access Log Field Behavior
- preserve-field - The Directory Server must be restarted for changes to this configuration property to take full effect. Any changes made to the set of preserve-field values will not take effect until the server is restarted or access loggers configured to use it have been disabled and re-enabled.
- preserve-field-name - The Directory Server must be restarted for changes to this configuration property to take full effect. Any changes made to the set of preserve-field-name values will not take effect until the server is restarted or access loggers configured to use it have been disabled and re-enabled.
- omit-field - The Directory Server must be restarted for changes to this configuration property to take full effect. Any changes made to the set of omit-field values will not take effect until the server is restarted or access loggers configured to use it have been disabled and re-enabled.
- omit-field-name - The Directory Server must be restarted for changes to this configuration property to take full effect. Any changes made to the set of omit-field-name values will not take effect until the server is restarted or access loggers configured to use it have been disabled and re-enabled.
- redact-entire-value-field - The Directory Server must be restarted for changes to this configuration property to take full effect. Any changes made to the set of redact-entire-value-field values will not take effect until the server is restarted or access loggers configured to use it have been disabled and re-enabled.
- redact-entire-value-field-name - The Directory Server must be restarted for changes to this configuration property to take full effect. Any changes made to the set of redact-entire-value-field-name values will not take effect until the server is restarted or access loggers configured to use it have been disabled and re-enabled.
- redact-value-components-field - The Directory Server must be restarted for changes to this configuration property to take full effect. Any changes made to the set of redact-value-components-field values will not take effect until the server is restarted or access loggers configured to use it have been disabled and re-enabled.
- redact-value-components-field-name - The Directory Server must be restarted for changes to this configuration property to take full effect. Any changes made to the set of redact-value-components-field-name values will not take effect until the server is restarted or access loggers configured to use it have been disabled and re-enabled.
- tokenize-entire-value-field - The Directory Server must be restarted for changes to this configuration property to take full effect. Any changes made to the set of tokenize-entire-value-field values will not take effect until the server is restarted or access loggers configured to use it have been disabled and re-enabled.
- tokenize-entire-value-field-name - The Directory Server must be restarted for changes to this configuration property to take full effect. Any changes made to the set of tokenize-entire-value-field-name values will not take effect until the server is restarted or access loggers configured to use it have been disabled and re-enabled.
- tokenize-value-components-field - The Directory Server must be restarted for changes to this configuration property to take full effect. Any changes made to the set of tokenize-value-components-field values will not take effect until the server is restarted or access loggers configured to use it have been disabled and re-enabled.
- tokenize-value-components-field-name - The Directory Server must be restarted for changes to this configuration property to take full effect. Any changes made to the set of tokenize-value-components-field-name values will not take effect until the server is restarted or access loggers configured to use it have been disabled and re-enabled.
Log Field Syntax
- default-behavior - The Directory Server must be restarted for changes to this configuration property to take full effect. Any changes made to the set of default-behavior values will not take effect until the server is restarted or access loggers using this syntax have been disabled and re-enabled.
Attribute Based Log Field Syntax
- included-sensitive-attribute - The Directory Server must be restarted for changes to this configuration property to take full effect. Any changes made to the set of included-sensitive-attribute values will not take effect until the server is restarted or access loggers using this syntax have been disabled and re-enabled.
- excluded-sensitive-attribute - The Directory Server must be restarted for changes to this configuration property to take full effect. Any changes made to the set of excluded-sensitive-attribute values will not take effect until the server is restarted or access loggers using this syntax have been disabled and re-enabled.
JSON Log Field Syntax
- included-sensitive-field - The Directory Server must be restarted for changes to this configuration property to take full effect. Any changes made to the set of included-sensitive-field values will not take effect until the server is restarted or access loggers using this syntax have been disabled and re-enabled.
- excluded-sensitive-field - The Directory Server must be restarted for changes to this configuration property to take full effect. Any changes made to the set of excluded-sensitive-field values will not take effect until the server is restarted or access loggers using this syntax have been disabled and re-enabled.
Writer Based Access Log Publisher
- queue-size - The Writer Based Access Log Publisher must be restarted if this property is changed and the asynchronous property is set to true.
Admin Alert Access Log Publisher
- queue-size - The Admin Alert Access Log Publisher must be restarted if this property is changed and the asynchronous property is set to true.
File Based Access Log Publisher
- log-file - The File Based Access Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- sign-log - The File Based Access Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- encrypt-log - The File Based Access Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
Syslog Based Access Log Publisher
- enabled - No further action is required for changes to this configuration property but there is other information that administrators should know about this property. Contact Ping Identity for more information.
Syslog Text Access Log Publisher
- queue-size - The Syslog Text Access Log Publisher must be restarted if this property is changed and the asynchronous property is set to true.
Console JSON Access Log Publisher
- enabled - The Console JSON Access Log Publisher is primarily intended to be used for server instances that are run in no-detach mode (that is, instances that are started with the --nodetach argument). When the logger is used in a server that is not running in no-detach mode, it may have reduced performance and functionality.
JSON Access Log Publisher
- log-file - The JSON Access Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- sign-log - The JSON Access Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- encrypt-log - The JSON Access Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- queue-size - The JSON Access Log Publisher must be restarted if this property is changed and the asynchronous property is set to true.
Syslog JSON Access Log Publisher
- queue-size - The Syslog JSON Access Log Publisher must be restarted if this property is changed and the asynchronous property is set to true.
Console JSON Audit Log Publisher
- enabled - The Console JSON Audit Log Publisher is primarily intended to be used for server instances that are run in no-detach mode (that is, instances that are started with the --nodetach argument). When the logger is used in a server that is not running in no-detach mode, it may have reduced performance and functionality.
File Based JSON Audit Log Publisher
- log-file - The File Based JSON Audit Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- sign-log - The File Based JSON Audit Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- encrypt-log - The File Based JSON Audit Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- queue-size - The File Based JSON Audit Log Publisher must be restarted if this property is changed and the asynchronous property is set to true.
Syslog JSON Audit Log Publisher
- queue-size - The Syslog JSON Audit Log Publisher must be restarted if this property is changed and the asynchronous property is set to true.
Debug Access Log Publisher
- log-file - The Debug Access Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- sign-log - The Debug Access Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- encrypt-log - The Debug Access Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- queue-size - The Debug Access Log Publisher must be restarted if this property is changed and the asynchronous property is set to true.
File Based Audit Log Publisher
- log-file - The File Based Audit Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- sign-log - The File Based Audit Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- encrypt-log - The File Based Audit Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- queue-size - The File Based Audit Log Publisher must be restarted if this property is changed and the asynchronous property is set to true.
Scripted File Based Access Log Publisher
- log-file - The Scripted File Based Access Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- sign-log - The Scripted File Based Access Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- encrypt-log - The Scripted File Based Access Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- queue-size - The Scripted File Based Access Log Publisher must be restarted if this property is changed and the asynchronous property is set to true.
JDBC Based Access Log Publisher
- queue-size - The JDBC Based Access Log Publisher must be restarted if this property is changed and the asynchronous property is set to true.
Operation Timing Access Log Publisher
- log-file - The Operation Timing Access Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- sign-log - The Operation Timing Access Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- encrypt-log - The Operation Timing Access Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- queue-size - The Operation Timing Access Log Publisher must be restarted if this property is changed and the asynchronous property is set to true.
Third Party File Based Access Log Publisher
- log-file - The Third Party File Based Access Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- sign-log - The Third Party File Based Access Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- encrypt-log - The Third Party File Based Access Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- queue-size - The Third Party File Based Access Log Publisher must be restarted if this property is changed and the asynchronous property is set to true.
Common Log File HTTP Operation Log Publisher
- log-file - The Common Log File HTTP Operation Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- sign-log - The Common Log File HTTP Operation Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- encrypt-log - The Common Log File HTTP Operation Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- queue-size - The Common Log File HTTP Operation Log Publisher must be restarted if this property is changed and the asynchronous property is set to true.
Console JSON HTTP Operation Log Publisher
- enabled - The Console JSON HTTP Operation Log Publisher is primarily intended to be used for server instances that are run in no-detach mode (that is, instances that are started with the --nodetach argument). When the logger is used in a server that is not running in no-detach mode, it may have reduced performance and functionality.
File Based JSON HTTP Operation Log Publisher
- log-file - The File Based JSON HTTP Operation Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- sign-log - The File Based JSON HTTP Operation Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- encrypt-log - The File Based JSON HTTP Operation Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- queue-size - The File Based JSON HTTP Operation Log Publisher must be restarted if this property is changed and the asynchronous property is set to true.
Syslog JSON HTTP Operation Log Publisher
- queue-size - The Syslog JSON HTTP Operation Log Publisher must be restarted if this property is changed and the asynchronous property is set to true.
Detailed HTTP Operation Log Publisher
- log-file - The Detailed HTTP Operation Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- sign-log - The Detailed HTTP Operation Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- encrypt-log - The Detailed HTTP Operation Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- queue-size - The Detailed HTTP Operation Log Publisher must be restarted if this property is changed and the asynchronous property is set to true.
Console JSON Error Log Publisher
- enabled - The Console JSON Error Log Publisher is primarily intended to be used for server instances that are run in no-detach mode (that is, instances that are started with the --nodetach argument). When the logger is used in a server that is not running in no-detach mode, it may have reduced performance and functionality.
JSON Error Log Publisher
- log-file - The JSON Error Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- sign-log - The JSON Error Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- encrypt-log - The JSON Error Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- queue-size - The JSON Error Log Publisher must be restarted if this property is changed and the asynchronous property is set to true.
Syslog JSON Error Log Publisher
- queue-size - The Syslog JSON Error Log Publisher must be restarted if this property is changed and the asynchronous property is set to true.
File Based Error Log Publisher
- log-file - The File Based Error Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- sign-log - The File Based Error Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- encrypt-log - The File Based Error Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- queue-size - The File Based Error Log Publisher must be restarted if this property is changed and the asynchronous property is set to true.
Scripted File Based Error Log Publisher
- log-file - The Scripted File Based Error Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- sign-log - The Scripted File Based Error Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- encrypt-log - The Scripted File Based Error Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- queue-size - The Scripted File Based Error Log Publisher must be restarted if this property is changed and the asynchronous property is set to true.
JDBC Based Error Log Publisher
- queue-size - The JDBC Based Error Log Publisher must be restarted if this property is changed and the asynchronous property is set to true.
Syslog Based Error Log Publisher
- enabled - No further action is required for changes to this configuration property but there is other information that administrators should know about this property. Contact Ping Identity for more information.
- queue-size - The Syslog Based Error Log Publisher must be restarted if this property is changed and the asynchronous property is set to true.
Syslog Text Error Log Publisher
- queue-size - The Syslog Text Error Log Publisher must be restarted if this property is changed and the asynchronous property is set to true.
Third Party File Based Error Log Publisher
- log-file - The Third Party File Based Error Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- sign-log - The Third Party File Based Error Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- encrypt-log - The Third Party File Based Error Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- queue-size - The Third Party File Based Error Log Publisher must be restarted if this property is changed and the asynchronous property is set to true.
Console JSON Sync Failed Ops Log Publisher
- enabled - The Console JSON Sync Failed Ops Log Publisher is primarily intended to be used for server instances that are run in no-detach mode (that is, instances that are started with the --nodetach argument). When the logger is used in a server that is not running in no-detach mode, it may have reduced performance and functionality.
File Based JSON Sync Failed Ops Log Publisher
- log-file - The File Based JSON Sync Failed Ops Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- sign-log - The File Based JSON Sync Failed Ops Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- encrypt-log - The File Based JSON Sync Failed Ops Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- queue-size - The File Based JSON Sync Failed Ops Log Publisher must be restarted if this property is changed and the asynchronous property is set to true.
Syslog JSON Sync Failed Ops Log Publisher
- queue-size - The Syslog JSON Sync Failed Ops Log Publisher must be restarted if this property is changed and the asynchronous property is set to true.
Sync Failed Ops Log Publisher
- log-file - The Sync Failed Ops Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- sign-log - The Sync Failed Ops Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- encrypt-log - The Sync Failed Ops Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- queue-size - The Sync Failed Ops Log Publisher must be restarted if this property is changed and the asynchronous property is set to true.
Console JSON Sync Log Publisher
- enabled - The Console JSON Sync Log Publisher is primarily intended to be used for server instances that are run in no-detach mode (that is, instances that are started with the --nodetach argument). When the logger is used in a server that is not running in no-detach mode, it may have reduced performance and functionality.
File Based JSON Sync Log Publisher
- log-file - The File Based JSON Sync Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- sign-log - The File Based JSON Sync Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- encrypt-log - The File Based JSON Sync Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- queue-size - The File Based JSON Sync Log Publisher must be restarted if this property is changed and the asynchronous property is set to true.
Syslog JSON Sync Log Publisher
- queue-size - The Syslog JSON Sync Log Publisher must be restarted if this property is changed and the asynchronous property is set to true.
File Based Sync Log Publisher
- log-file - The File Based Sync Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- sign-log - The File Based Sync Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- encrypt-log - The File Based Sync Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- queue-size - The File Based Sync Log Publisher must be restarted if this property is changed and the asynchronous property is set to true.
File Based Debug Log Publisher
- log-file - The File Based Debug Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- sign-log - The File Based Debug Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- encrypt-log - The File Based Debug Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- queue-size - The File Based Debug Log Publisher must be restarted if this property is changed and the asynchronous property is set to true.
File Based Policy Decision Log Publisher
- queue-size - The File Based Policy Decision Log Publisher must be restarted if this property is changed and the asynchronous property is set to true.
- log-file - The File Based Policy Decision Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- sign-log - The File Based Policy Decision Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- encrypt-log - The File Based Policy Decision Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
Writer Based Trace Log Publisher
- queue-size - The Writer Based Trace Log Publisher must be restarted if this property is changed and the asynchronous property is set to true.
File Based Trace Log Publisher
- log-file - The File Based Trace Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- sign-log - The File Based Trace Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- encrypt-log - The File Based Trace Log Publisher must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
Host System Monitor Provider
- enabled - Enabling host system cpu, memory, disk and network interface I/O monitoring requires running an external collector helper process except on Linux systems.
Notes:
- Enabling the host system monitor does not require restarting the server on Linux systems.
- Enabling the host system monitor provider on UNIX (non-Linux) requires restarting the server. Changes to disk-devices and network-devices cannot be validated until the server is restarted.
- Host system monitoring is not available on Windows systems.
Password Policy
- enable-debug -
When enable-debug is set to true, additional configuration changes are required.
1. Create a Debug Target targeting the password policy class:
dsconfig create-debug-target --publisher-name "File-Based Debug Logger" --target-name com.unboundid.directory.server.core.PasswordPolicyState --set debug-level:verbose
2. Enable the debug logger:
dsconfig set-log-publisher-prop --publisher-name "File-Based Debug Logger" --set enabled:true
With the default configuration settings, debugging information will be written to the logs/debug file.
- idle-lockout-interval - Last login time tracking is required for idle account lockout to work properly. If you are enabling idle account lockout, then you should ensure that the last-login-time-attribute and last-login-time-format properties are also defined and that last login time tracking has been enabled long enough so that user accounts have had time to be marked with last login times. Ideally, last login time tracking should be enabled for at least as long as the idle lockout interval to ensure that users are not incorrectly locked out merely because their accounts do not have last login time information.
Base64 Password Storage Scheme
- enabled - No further action is required for changes to this configuration property but there is other information that administrators should know about this property. Contact Ping Identity for more information.
Clear Password Storage Scheme
- enabled - No further action is required for changes to this configuration property but there is other information that administrators should know about this property. Contact Ping Identity for more information.
MD5 Password Storage Scheme
- enabled - No further action is required for changes to this configuration property but there is other information that administrators should know about this property. Contact Ping Identity for more information.
PBKDF2 Password Storage Scheme
- digest-algorithm - No further action is required for changes to this configuration property but there is other information that administrators should know about this property. Contact Ping Identity for more information.
RC4 Password Storage Scheme
- enabled - No further action is required for changes to this configuration property but there is other information that administrators should know about this property. Contact Ping Identity for more information.
SHA1 Password Storage Scheme
- enabled - No further action is required for changes to this configuration property but there is other information that administrators should know about this property. Contact Ping Identity for more information.
Salted MD5 Password Storage Scheme
- enabled - No further action is required for changes to this configuration property but there is other information that administrators should know about this property. Contact Ping Identity for more information.
Salted SHA1 Password Storage Scheme
- enabled - No further action is required for changes to this configuration property but there is other information that administrators should know about this property. Contact Ping Identity for more information.
Triple DES Password Storage Scheme
- enabled - No further action is required for changes to this configuration property but there is other information that administrators should know about this property. Contact Ping Identity for more information.
Plugin
- plugin-type - The Plugin must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
Attribute Mapper Plugin
- plugin-type - The Attribute Mapper Plugin must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
Change Subscription Notification Plugin
- plugin-type - The Change Subscription Notification Plugin must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
Changelog Password Encryption Plugin
- plugin-type - The Changelog Password Encryption Plugin must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
Composed Attribute Plugin
- plugin-type - The Composed Attribute Plugin must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
DN Mapper Plugin
- plugin-type - The DN Mapper Plugin must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
Delay Plugin
- plugin-type - The Delay Plugin must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
Encrypt Attribute Values Plugin
- plugin-type - The Encrypt Attribute Values Plugin must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
Entry UUID Plugin
- plugin-type - The Entry UUID Plugin must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
Internal Search Rate Plugin
- plugin-type - The Internal Search Rate Plugin must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
LDAP Result Code Tracker Plugin
- plugin-type - The LDAP Result Code Tracker Plugin must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
Last Mod Plugin
- plugin-type - The Last Mod Plugin must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
Monitor History Plugin
- log-file - The Monitor History Plugin must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
Pass Through Authentication Plugin
- plugin-type - The Pass Through Authentication Plugin must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
Periodic GC Plugin
- plugin-type - The Periodic GC Plugin must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
Periodic Stats Logger Plugin
- log-file - The Periodic Stats Logger Plugin must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
Stats Collector Plugin
- per-application-ldap-stats - When setting this option to per-application-only, you must also set the separate-monitor-entry-per-tracked-application property in the Processing Time Histogram Plugin to true.
Pre Update Config Plugin
- plugin-type - The Pre Update Config Plugin must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
Processing Time Histogram Plugin
- plugin-type - The Processing Time Histogram Plugin must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- histogram-category-boundary - The Processing Time Histogram Plugin must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. The Data Metrics Server can only aggregate response-time data when the boundary values are the same across both time and monitored servers. If you change the boundary values on one monitored server, you should change them on all monitored servers.
- separate-monitor-entry-per-tracked-application - When setting this option to true, you must also set the per-application-ldap-stats property in the Stats Collector Plugin to per-application-only.
Referential Integrity Plugin
- plugin-type - The Referential Integrity Plugin must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
Referral On Update Plugin
- plugin-type - The Referral On Update Plugin must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
SNMP Master Agent Plugin
- listen-address - The SNMP Master Agent Plugin must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- listen-port - The SNMP Master Agent Plugin must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- agentx-listen-address - The SNMP Master Agent Plugin must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- agentx-listen-port - The SNMP Master Agent Plugin must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- notification-target-address - The SNMP Master Agent Plugin must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- notification-target-port - The SNMP Master Agent Plugin must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- agent-snmp-version - The SNMP Master Agent Plugin must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- community-name - The SNMP Master Agent Plugin must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- agent-security-name - The SNMP Master Agent Plugin must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- agent-security-level - The SNMP Master Agent Plugin must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- num-worker-threads - The SNMP Master Agent Plugin must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
SNMP Subagent Plugin
- context-name - The SNMP Subagent Plugin must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- agentx-address - The SNMP Subagent Plugin must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- agentx-port - The SNMP Subagent Plugin must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
- num-worker-threads - The SNMP Subagent Plugin must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
Secret Key Delete Alert Plugin
- plugin-type - The Secret Key Delete Alert Plugin must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
Seven Bit Clean Plugin
- plugin-type - The Seven Bit Clean Plugin must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
Sub Operation Timing Plugin
- plugin-type - The Sub Operation Timing Plugin must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
Unique Attribute Plugin
- plugin-type - The Unique Attribute Plugin must be disabled and re-enabled (or the Directory Server restarted) for changes to this configuration property to take full effect. In order for this modification to take effect, the component must be restarted, either by disabling and re-enabling it, or by restarting the server
Replication Server
- replication-db-directory - The Directory Server must be restarted for changes to this configuration property to take full effect. Modification requires that the Directory Server be stopped, the database directory manually relocated, and then the Directory Server restarted. While the Directory Server is stopped, the old database directory and its contents must be manually moved or copied to the new location.
- je-property - Changes to this configuration property will only take effect if the associated multimaster replication synchronization provider is disabled and re-enabled (or the Directory Server is restarted).
- replication-purge-delay - No further action is required for changes to this configuration property but there is other information that administrators should know about this property. Contact Ping Identity for more information.
- replication-port - No further action is required for changes to this configuration property but there is other information that administrators should know about this property. Contact Ping Identity for more information.
UnboundID TOTP SASL Mechanism Handler
- prevent-totp-reuse - No further action is required for changes to this configuration property but there is other information that administrators should know about this property. Contact Ping Identity for more information.
SCIM Resource Type
- auxiliary-ldap-objectclass - The Directory Server must be restarted for changes to this configuration property to take full effect. Changes to this property will not take effect until the server is restarted.
Directory Server Instance
- replication-set-name - The Directory Server must be restarted for changes to this configuration property to take full effect. In order for this modification to take effect the server must be restarted
Replication Synchronization Provider
- num-update-replay-threads - The Directory Server must be restarted for changes to this configuration property to take full effect. In order for this modification to take effect the server must be restarted
Web Application Extension
- base-context-path - For this modification to take effect, you must either restart the server or else disable and then re-enable any HTTP Connection Handler referencing this component.
- war-file - For this modification to take effect, you must either restart the server or else disable and then re-enable any HTTP Connection Handler referencing this component.
- document-root-directory - For this modification to take effect, you must either restart the server or else disable and then re-enable any HTTP Connection Handler referencing this component.
- deployment-descriptor-file - For this modification to take effect, you must either restart the server or else disable and then re-enable any HTTP Connection Handler referencing this component.
- temporary-directory - For this modification to take effect, you must either restart the server or else disable and then re-enable any HTTP Connection Handler referencing this component.
- init-parameter - For this modification to take effect, you must either restart the server or else disable and then re-enable any HTTP Connection Handler referencing this component.
Console Web Application Extension
- sso-enabled - For this modification to take effect, you must either restart the server or else disable and then re-enable any HTTP Connection Handler referencing this component.
- oidc-client-id - For this modification to take effect, you must either restart the server or else disable and then re-enable any HTTP Connection Handler referencing this component.
- oidc-client-secret - For this modification to take effect, you must either restart the server or else disable and then re-enable any HTTP Connection Handler referencing this component.
- oidc-client-secret-passphrase-provider - For this modification to take effect, you must either restart the server or else disable and then re-enable any HTTP Connection Handler referencing this component.
- oidc-issuer-url - For this modification to take effect, you must either restart the server or else disable and then re-enable any HTTP Connection Handler referencing this component.
- oidc-trust-store-file - For this modification to take effect, you must either restart the server or else disable and then re-enable any HTTP Connection Handler referencing this component.
- oidc-trust-store-type - For this modification to take effect, you must either restart the server or else disable and then re-enable any HTTP Connection Handler referencing this component.
- oidc-trust-store-pin-passphrase-provider - For this modification to take effect, you must either restart the server or else disable and then re-enable any HTTP Connection Handler referencing this component.
- oidc-strict-hostname-verification - For this modification to take effect, you must either restart the server or else disable and then re-enable any HTTP Connection Handler referencing this component.
- oidc-trust-all - For this modification to take effect, you must either restart the server or else disable and then re-enable any HTTP Connection Handler referencing this component.
- ldap-server - For this modification to take effect, you must either restart the server or else disable and then re-enable any HTTP Connection Handler referencing this component.
- trust-store-file - For this modification to take effect, you must either restart the server or else disable and then re-enable any HTTP Connection Handler referencing this component.
- trust-store-type - For this modification to take effect, you must either restart the server or else disable and then re-enable any HTTP Connection Handler referencing this component.
- trust-store-pin-passphrase-provider - For this modification to take effect, you must either restart the server or else disable and then re-enable any HTTP Connection Handler referencing this component.
- log-file - For this modification to take effect, you must either restart the server or else disable and then re-enable any HTTP Connection Handler referencing this component.
- complexity - For this modification to take effect, you must either restart the server or else disable and then re-enable any HTTP Connection Handler referencing this component.
High Throughput Work Queue
- num-worker-threads - The Directory Server must be restarted for changes to this configuration property to take full effect. In order for this modification to take effect the server must be restarted
- num-write-worker-threads - The Directory Server must be restarted for changes to this configuration property to take full effect. In order for this modification to take effect the server must be restarted
- num-administrative-session-worker-threads - The Directory Server must be restarted for changes to this configuration property to take full effect. In order for this modification to take effect the server must be restarted
- num-queues - The Directory Server must be restarted for changes to this configuration property to take full effect. In order for this modification to take effect the server must be restarted
- num-write-queues - The Directory Server must be restarted for changes to this configuration property to take full effect. In order for this modification to take effect the server must be restarted
- max-work-queue-capacity - The Directory Server must be restarted for changes to this configuration property to take full effect. In order for this modification to take effect the server must be restarted
Traditional Work Queue
- max-work-queue-capacity - The Directory Server must be restarted for changes to this configuration property to take full effect. In order for this modification to take effect the server must be restarted
Wait Notify Work Queue
- num-worker-threads - The Directory Server must be restarted for changes to this configuration property to take full effect. In order for this modification to take effect the server must be restarted