
Configuring Fractional Replication for Password Policy Attributes
289
8.12.2. Configuring Fractional Replication for Password Policy
Attributes
Setting the
passwordIsGlobalPolicy
attribute affects the consumer in replication, in that it allows
the consumer to receive updates to those attributes. To control whether the password policy attributes
are actually replicated by the supplier, use fractional replication, which controls what specific entry
attributes are replicated.
If the password policy attributes should be replicated, then make sure these attributes are included in
the fractional replication agreement (as they are by default).
If the
passwordIsGlobalPolicy
attribute is set to
off
on the consumer, so no password policy
attributes should be replicated, use fractional replication (described in
Section 8.1.7, “Replicating
Attributes with Fractional Replication”
) to enforce that on the supplier and specifically exclude those
attributes from the replication agreement.
1. When configuring the replication agreement on the supplier, as described (for example) in
Section 8.4.3, “Create the Replication Agreement”
, select the
Enable Fractional Replication
checkbox.
2. By default, every attribute is listed in the
Replicated Attributes
box. Select the
passwordRetryCount
,
retryCountResetTime
, and
accountUnlockTime
parameters and
click the arrow button to move them into the
Do Not Replicate
box.
3. Finish configuring the replication agreement.
8.13. Replication over SSL
The Directory Servers involved in replication can be configured so that all replication operations occur
over an SSL connection. To use replication over SSL, first do the following:
• Configure both the supplier and consumer servers to use SSL.
• Configure the consumer server to recognize the supplier server's certificate as the supplier DN. Do
this only to use SSL client authentication rather than simple authentication.
These procedures are described in
Chapter 11, Managing SSL
.
If attribute encryption is enabled, a secure connection is required for replication.
NOTE
Replication configured over SSL with certificate-based authentication will fail if the
supplier's certificate is only capable of behaving as a server certificate, and not also a
client during an SSL handshake. Replication with certificate-based authentication uses the
Directory Server's server certificate for authentication to the remote server.
When the servers are configured to use SSL, configure an SSL connection for replication in the
Replication Agreement Wizard
. The
Source and Destination
sets how to bind between the supplier
and the consumer, and this is where SSL is set.
There are two ways to use SSL for replication:
Содержание DIRECTORY SERVER 8.0
Страница 18: ...xviii ...
Страница 29: ...Configuring the Directory Manager 11 6 Enter the new password and confirm it 7 Click Save ...
Страница 30: ...12 ...
Страница 112: ...94 ...
Страница 128: ...110 ...
Страница 190: ...Chapter 6 Managing Access Control 172 4 Click New to open the Access Control Editor ...
Страница 224: ...206 ...
Страница 324: ...306 ...
Страница 334: ...316 ...
Страница 358: ...340 ...
Страница 410: ...392 ...
Страница 420: ...402 ...
Страница 444: ...426 ...
Страница 454: ...436 ...
Страница 464: ...446 ...
Страница 484: ...466 ...
Страница 512: ...494 ...
Страница 522: ...504 ...