LDAP Server Object General Property Page

Use this page to configure or enable the following server-specific properties.

Host Server
Stores the name of the server that is hosting LDAP Services for Novell® eDirectoryTM.

LDAP Group
Specifies the LDAP Group object that contains the configuration settings used by this LDAP server. You can enter the complete name of the LDAP Group object in the text box, or you can use the Browse button to locate and select an LDAP Group object. All servers in an LDAP Group provide the same view of the directory and the same level of security.

When installed, each LDAP server is placed into its own LDAP Group. If you have LDAP servers that you want to share common mappings and security configuration settings, you can have more than one LDAP server in a single LDAP Group.

Search Entry Limit
Defines the maximum number of objects for which the LDAP server will return data. If the search criteria for a request identifies more than the specified number of objects, the LDAP server returns object data until the Search Entry Limit value is reached. When the limit is reached, the LDAP server sends a search result done with a "size limit exceeded" message and considers the request complete. If the Search Entry Limit is set to zero, there is no limit on the number of objects for which the LDAP server will return data.

Default: 0

Minimum: 0

Maximum: 2,147,483,647

Note: The LDAP client can also set a limit.

Search Time Limit
Defines the maximum amount of time in seconds that the LDAP server will use to return data. When the limit is reached, the LDAP server sends a search result done with a "time limit exceeded" message and considers the request complete. If the Search Time Limit is set to zero, there is no limit on the amount of time the LDAP server will use to return data.

Default: 0 seconds

Minimum: 0 second

Maximum: 2,147,483,647 seconds

Bind Limit
Defines the maximum number of simultaneous LDAP binds (or connections) an LDAP server can support. If the Bind Limit is set to zero, there is no limit on the number of binds.

When the Bind Limit is set to a number other than zero, the LDAP server accepts binds until the bind limit is reached. Then it rejects additional binds until the total number of binds drops below the bind limit.

Default: 0

Minimum: 0

Maximum: 2,147,483,647

Note: Each user request requires approximately 160 KB of memory on the server. Unlike eDirectory, in which a client can submit only one request at a time per connection, LDAP users can submit multiple requests. If your server is using most of its available memory before you install LDAP Services for eDirectory, you will need to install more memory or set the Bind Limit so that the available memory limits are not exceeded. If memory is exceeded, LDAP clients will get operation errors. If the bind limit is exceeded, LDAP clients will get connection refused errors.

Idle Timeout
Defines the maximum amount of time in seconds that an LDAP connection can be inactive. If the Idle Timeout is set to zero, there is no limit on idle connections.

If the Idle Timeout is set to a number other than zero, the server disconnects inactive connections after the specified amount of time.

Once a client has been disconnected, the client must repeat the bind process to reconnect to the server.

Default: 0 seconds

Minimum: 0 seconds

Maximum: 2,147,483,647 seconds

TCP Port
Defines the TCP port number for LDAP services on the eDirectory server. The default value is 389, a popular port address for LDAP services.  The TCP port must be different from the SSL port.

Default: 389

Minimum: 0

Maximum: 65,535

Note: The TCP Port is unconfigurable for Novell® Services for eDirectory versions 3.14 or older.

Disable TCP Port
Check this box to restrict the LDAP server from accepting clear text messages through the network. The default value is not selected, so the clear text port is enabled.

Dereference Aliases When Resolving Names

Enable ADSI and Old Netscape Schema Output
Check this box to enable non-standard schema output so that current ADSI and old Netscape* clients can read the schema.

The non-standard output format changes are:

  1. SYNTAX OID is single quoted.
  2. No upper bounds are output.
  3. No X- options are output.
  4. If more than one name is present, only the first encountered will be output.
  5. Any attributes or classes without an OID defined will be output "attributename-oid" or "classname-oid" in lowercase.
  6. If an attribute or class has a dash in the name and it does not have an OID defined, it will not be output.

Note:  The non-standard output does not conform to the current IETF defined standards for LDAP, but it works with the current ADSI and old Netscape clients.

Return Opertational Attributes When All User Attributes Are Requested
Select this option to return operational attributes as well as user attributes when the search operation is asked to return all user attributes (by specifying an empty attribute list or the special * character).

Refresh NLDAP Server Now
Select this button to synchronize the LDAP server with the values contained in the LDAP Group and the LDAP Server objects.

Note: Every time you make changes to your Novell LDAP settings and click OK, eDirectory refreshes itself.

This button is not available for NDS 7 or older versions. To refresh the servers in NDS 7, type LDAP REFRESH IMMEDIATE, or type UNLOAD NLDAP.NLM then type LOAD NLDAP.NLM in the NetWare console.

A trademark symbol (®, TM, etc.) denotes a Novell trademark. An asterisk (*) denotes a third-party trademark. For information on trademarks, see Legal Notices.