Directory Proxy Server Documentation Index
Configuration Reference Home

Distinguished Name Attribute Syntax

Note: this component is designated "advanced", which means that objects of this type are not expected to be created or altered in most environments. If you believe that such a change is necessary, you may want to contact support in order to understand the potential impact of that change.

The Distinguished Name Attribute Syntax defines a syntax for attribute values that can hold LDAP distinguished names.

Values for attributes with this syntax may be compacted by tokenizing portions of the DN as done for the DNs of encoded entries, using the base DN(s), of the associated backend, the set of compact-common-parent-dn values defined in the backend configuration, or portions of the DN of the entry in which the value occurs.
Note that using compaction for DN values may introduce cosmetic differences in the values, such that the value included in entries returned to clients may differ slightly (e.g., in insignificant spacing between components or capitalization in attribute names) from the values originally provided to the server. The values returned will always be logically equivalent to the values that were originally provided, but some clients may expect values to be returned exactly as they were provided to the server, and this cannot be guaranteed if compaction is enabled.

Parent Component
Properties
dsconfig Usage

Parent Component

The Distinguished Name Attribute Syntax component inherits from the Attribute Syntax

Properties

The properties supported by this managed object are as follows:


Basic Properties: Advanced Properties:
↓ enabled ↓ require-binary-transfer

Basic Properties

enabled

Description
Indicates whether the Attribute Syntax is enabled.
Default Value
None
Allowed Values
true
false
Multi-Valued
No
Required
Yes
Admin Action Required
None. Modification requires no further action


Advanced Properties

require-binary-transfer (Advanced Property)

Description
Indicates whether values of this attribute are required to have a "binary" transfer option as described in RFC 4522. Attributes with this syntax will generally be referenced with names including ";binary" (e.g., "userCertificate;binary").
Default Value
false
Allowed Values
true
false
Multi-Valued
No
Required
No
Admin Action Required
The Directory Proxy Server must be restarted for changes to this setting to take effect. Changes to this property will take effect immediately for new attribute type definitions created after the change, but the change will not take effect for existing attributes with this syntax until the server is restarted.


dsconfig Usage

To list the configured Attribute Syntaxes:

dsconfig list-attribute-syntaxes
     [--property {propertyName}] ...

To view the configuration for an existing Attribute Syntax:

dsconfig get-attribute-syntax-prop
     --syntax-name {name}
     [--tab-delimited]
     [--script-friendly]
     [--property {propertyName}] ...

To update the configuration for an existing Attribute Syntax:

dsconfig set-attribute-syntax-prop
     --syntax-name {name}
     (--set|--add|--remove) {propertyName}:{propertyValue}
     [(--set|--add|--remove) {propertyName}:{propertyValue}] ...