ldap (nrcmd)							ldap (nrcmd)

NAME
    ldap - Specifies the LDAP remote server's properties

SYNOPSIS
    ldap list 
    ldap listnames
    ldap <name> create <hostname> [<attribute>=<value>...]
    ldap <name> delete 
    ldap <name> get <attribute>
    ldap <name> set <attribute>=<value> [<attribute>=<value> ...]
    ldap <name> unset <attribute> 
    
    ldap <name> disable <attribute>
    ldap <name> enable <attribute>
    ldap <name> show
    
    ldap <name> setEntry <dictionary> <key>=<value>
    ldap <name> getEntry <dictionary> <key>
    ldap <name> unsetEntry <dictionary> <key>

DESCRIPTION
    The ldap command configures the  LDAP servers that the DHCP server
    should communicate with. The DHCP server can read client configuration
    information from or write lease information to an LDAP enabled directory.

    Use the setEntry, getEntry, and unsetEntry commands to set, query,
    and clear elements of the various dictionary properties in the LDAP server 
    configuration. These dictionary properties provide a convenient mapping 
    from strings keys to string values.

    The dictionary values for the setEntry command are:

    create-dictionary
    create-string-dictionary
    env-dictionary
    query-dictionary
    update-dictionary

EXAMPLES

STATUS

SEE ALSO

PROPERTIES
  Attributes:

    can-create[36] (AT_BOOL, Optional, default: disabled)
        Controls whether a particular LDAP server can create new entries
        to use to store lease state updates. See the create properties:
        create-dictionary, create-string-dictionary, dn-create-format,
        create-object-classes.

    can-query[16] (AT_BOOL, Optional, default: disabled)
        Controls whether a particular LDAP server can be used for client
        queries. See the query properties: env-dictionary,
        query-dictionary, search-attribute, search-filter, search-path,
        and search-scope.

    can-update[17] (AT_BOOL, Optional, default: disabled)
        Controls whether a particular LDAP server can be used to store
        lease state updates. See the update properties: update-dictionary,
        update-search-attribute, update-search-filter, update-search-path
        update-search-scope.

    connections[24] (AT_INT, Optional, default: 1)
        Determines the number of connections that the server can make to an
        LDAP object.
        Network Registrar creates one thread for each connection configured
        in an LDAP object, and each thread can have a maximum of LDAP
        requests associated with its request queue.
        This is primarily a performance-tuning attribute. In some cases,
        having more than one connection can improve overall throughput.

    create-dictionary[37] (AT_DICT(AT_STRING), Optional, default: <none>)
        Maps LDAP attributes to DHCP lease attributes.  If an entry does
        not exist and needs to be created, entries in this dictionary
        are set to the value of its corresponding DHCP lease attribute.

    create-object-classes[39] (AT_STRING, Optional, default: <none>)
        If can-create is enabled, specifies the object classes from
        which a new entry inherits.

    create-string-dictionary[40] (AT_DICT(AT_STRING), Optional, default: <none>)
        Maps LDAP attributes to user specified strings. If an entry does not
        exist and needs to be created, entries in this dictionary are set to
        the matching string.

    default-attribute-value[41] (AT_STRING, Optional, default: <default>)
        Provides a default attribute value (a string) to insert in any LDAP
        attribute whose associated lease attribute values are not present in
        the lease.

    dn-attribute[31] (AT_STRING, Optional, default: <none>)
        Determines how the server constructs the distinguished name (DN)
        of the LDAP entry to update or create.
        If the server can use one of the lease attributes, it formats the
        specified dn-attribute using the dn-format  string to construct
        the object filter that specifies the LDAP server to modify.

    dn-create-format[38] (AT_STRING, Optional, default: <none>)
        Provides the distinguished name (DN) for entry creation. A % is
        required at the entry level and is replaced by the value of the
        dn-attribute. If you can construct the DN of the LDAP object created
        from one of the leases attributes,  the server formats the specified
        dn-attribute using the dn-format string.

    dn-format[30] (AT_STRING, Optional, default: <none>)
        If the DN of the ldap object that is to be updated can be
        constructed from one of the lease's attributes, the specified
        dn-attribute will be formatted using the dn-format string to
        construct the query filter.

    enabled[44] (AT_BOOL, Optional, default: true)
        Enables or disables this LDAP remote server.
        Prevents DHCP from attempting to use an LDAP server that is
        known to be unavailable.

    env-dictionary[33] (AT_DICT(AT_STRING), Optional, default: <none>)
        Specifies the environment dictionary that allows the server to
        retrieve additional LDAP attributes along with client-entry
        attributes. If any of these are present in a query's results,
        their values are made available to scripts through the request's
        environment dictionary. The LDA{ value is keyed by the value in
        the LDAP query env-dictionary.

    hostname[2] (AT_STRING, Required, default: <none>)
        Sets the hostname of the server to connect to. LDAP servers require
        hostnames.

    limit-requests[18] (AT_BOOL, Optional, default: enabled)
        Controls whether there should be a limit on the number of
        outstanding queries on each LDAP client connection. See the limit
        property: max-requests.

    max-referrals[23] (AT_INT, Optional, default: 0)
        Limits the number of LDAP referrals the server follows when
        querying. A value of zero prohibits following referrals.

    max-requests[19] (AT_INT, Optional, default: 20)
        Controls the number of outstanding queries.
        If you have set the 'limit-requests' feature to TRUE, any single
        LDAP connection will limit the number of outstanding queries to
        'max-requests.' You can improve performance by limiting the
        number of outstanding queries.

    name[1] (AT_STRING, Required, default: <none>)
        An arbitrary name used to refer to an individual server.

    password[7] (AT_STRING, Optional, default: <none>)
        Sets the password of a user with access to the parts of the directory
        that DHCP uses. Because you can configure LDAP servers to allow
        anonymous access, this is optional.

    port[4] (AT_INT, Optional, default: <none>)
        Specifies the port on the remote server to connect to.

    preference[25] (AT_INT, Optional, default: 1)
        Specifies the preference order in which LDAP servers are used.
        A positive integer greater than or equal to one. One (1) is the
        highest preference value.

    query-dictionary[32] (AT_DICT(AT_STRING), Optional, default: <none>)
        Maps LDAP attributes and DHCP attribute names. The server attempts
        to retrieve all LDAP attributes specified in the dictionary. When a
        query succeeds, the values for any ldap attributes that it returns
        are set in the corresponding client-entry attribute.

    query-timeout[43] (AT_TIME, Optional, default: 3s)
        Specifies the number of seconds the DHCP server waits for a response
        to individual LDAP Query requests. After a query request times out,
        the DHCP server will drop the request and not process it again on
        another LDAP connection or LDAP Server. A query-timeout value of 3
        seconds is a good value.
        Note: The timeout attribute configures the timeout for LDAP
        Update and Create requests.

    referral-attr[22] (AT_STRING, Optional, default: <none>)
        Indicates whether an LDAP response is a referral. The referral may
        or may not contain the DN for this query. If the DN is present (the
        default), the server uses it as the search path, along with a
        wildcard search-scope in the query that follows the referral. If not,
        the server builds the search path by formatting the data in the
        referral attribute with the referral-filter, using the existing
        search scope.

    referral-filter[21] (AT_STRING, Optional, default: <none>)
        In the absence of a distinguished name (DN), controls how a
        server formats referral-attr data. In such cases, the server formats
        the referral attribute's data with this filter expression to build a
        search path that uses the existing search-scope for the LDAP server.

    search-filter[11] (AT_STRING, Optional, default: <none>)
        Specifies the filter to apply in the client-entry query. The server
        formats the client's MAC address using the filter to specify the
        object that contains the client-entry data.

    search-path[9] (AT_STRING, Optional, default: <none>)
        Designates an object in the directory to use as a query
        starting-point. Together, the path and the search-scope control the
        portion of the directory that the server will search.

    search-scope[10] (AT_ENUMINT(), Optional, default: SUBTREE)
        Controls the comprehensiveness of a search:
        If you specify the  scope to be SUBTREE, the server searches all
        the children of the searchpath.
        If you specify the scope to be ONELEVEL, the server searches only
        the immediate children of the base object.
        If you specify the scope to be BASE, the server searches only the
        base object itself.

    threadwaittime[14] (AT_MSTIME, Optional, default: 100)
        Sets the number of milliseconds that an LDAP client connection
        polls for the results of outstanding queries or updates.

    timeout[15] (AT_TIME, Optional, default: 10s)
        Controls the number of seconds the DHCP server waits for a response
        to an individual LDAP update or create request. If an LDAP request
        times out, the DHCP server resubmits it to other LDAP connections.
        Further, if the DHCP server receives no response (that is, a result
        for an LDAP update or create) from an LDAP connection for the timeout
        seconds, DHCP marks this LDAP connection as 'Inactive' and tears down
        the connection, then reconnects.  A timeout value of 10 seconds is a
        good value for LDAP create and update operations.
        Note: You can configure a separate timeout for LDAP query operations
        using the query-timeout attribute.

    update-dictionary[34] (AT_DICT(AT_STRING), Optional, default: <none>)
        Maps LDAP attributes to DHCP lease attributes.  When an LDAP object
        is modified, each LDAP attribute that is present in this dictionary
        is set to the value of its corresponding DHCP lease attribute.

    update-search-attribute[29] (AT_STRING, Optional, default: <none>)
        If the DN of the object to be updated cannot be determined
        directly, the DHCP server must issue a query to retrieve the DN.
        In that case, the DHCP server uses data in the lease's
        'search-attribute,' and formats it using the
        'update-search-filter' expression.

    update-search-filter[28] (AT_STRING, Optional, default: <none>)
        If the DN of the object to be updated cannot be determined
        directly, the DHCP server must issue a query to retrieve the DN.
        In that case, the DHCP server uses data in the lease's
        'search-attribute,' and formats it using the
        'update-search-filter' expression.

    update-search-path[26] (AT_STRING, Optional, default: <none>)
        Determines the starting point for the portion of the directory
        containing  LDAP objects for the server to update.

    update-search-scope[27] (AT_ENUMINT(), Optional, default: <none>)
        With update-search-path, controls the portion of the directory
        that contains the objects to be updated.
        The scope can be SUBTREE (includes all children of the
        searchpath), ONELEVEL (includes only the immediate children of the
        base object), or BASE (includes only the base object itself).

    username[6] (AT_STRING, Optional, default: <none>)
        Designates a user with access to the parts of the directory that DHCP
        uses. Because you can configure LDAP servers to allow anonymous
        access, this is optional.

