Use this page to configure or enable the following server-specific properties.
Host Server
Stores the name of the server that is hosting LDAP Services for Novell®
eDirectoryTM.
LDAP Group
Specifies the LDAP Group object that contains the configuration settings used by this LDAP
server. You can enter the complete name of the LDAP Group object in the text box, or you
can use the Browse button to locate and select an LDAP Group object. All servers in an
LDAP Group provide the same view of the directory and the same level of security.
When installed, each LDAP server is placed into its own LDAP Group. If you have LDAP servers that you want to share common mappings and security configuration settings, you can have more than one LDAP server in a single LDAP Group.
Search Entry Limit
Defines the maximum number of objects for which the LDAP server will return data. If the
search criteria for a request identifies more than the specified number of objects, the
LDAP server returns object data until the Search Entry Limit value is reached. When the
limit is reached, the LDAP server sends a search result done with a "size limit
exceeded" message and considers the request complete. If the Search Entry Limit is
set to zero, there is no limit on the number of objects for which the LDAP server will
return data.
Default: 0
Minimum: 0
Maximum: 2,147,483,647
Note: The LDAP client can also set a limit.
Search Time Limit
Defines the maximum amount of time in seconds that the LDAP server will use to return
data. When the limit is reached, the LDAP server sends a search result done with a
"time limit exceeded" message and considers the request complete. If the Search
Time Limit is set to zero, there is no limit on the amount of time the LDAP server will
use to return data.
Default: 0 seconds
Minimum: 0 second
Maximum: 2,147,483,647 seconds
Bind Limit
Defines the maximum number of simultaneous LDAP binds (or connections) an LDAP server can
support. If the Bind Limit is set to zero, there is no limit on the number of binds.
When the Bind Limit is set to a number other than zero, the LDAP server accepts binds until the bind limit is reached. Then it rejects additional binds until the total number of binds drops below the bind limit.
Default: 0
Minimum: 0
Maximum: 2,147,483,647
Note: Each user request requires approximately 160 KB of memory on the server. Unlike eDirectory, in which a client can submit only one request at a time per connection, LDAP users can submit multiple requests. If your server is using most of its available memory before you install LDAP Services for eDirectory, you will need to install more memory or set the Bind Limit so that the available memory limits are not exceeded. If memory is exceeded, LDAP clients will get operation errors. If the bind limit is exceeded, LDAP clients will get connection refused errors.
Idle Timeout
Defines the maximum amount of time in seconds that an LDAP connection can be inactive. If
the Idle Timeout is set to zero, there is no limit on idle connections.
If the Idle Timeout is set to a number other than zero, the server disconnects inactive connections after the specified amount of time.
Once a client has been disconnected, the client must repeat the bind process to reconnect to the server.
Default: 0 seconds
Minimum: 0 seconds
Maximum: 2,147,483,647 seconds
TCP Port
Defines the TCP port number for LDAP services on the eDirectory server. The default value
is 389, a popular port address for LDAP services. The TCP port must be different
from the SSL port.
Default: 389
Minimum: 0
Maximum: 65,535
Note: The TCP Port is unconfigurable for Novell® Services for eDirectory versions 3.14 or older.
Disable TCP Port
Check this box to restrict the LDAP server from accepting clear text messages through the network. The default value is not selected, so the clear text port is enabled.
Dereference Aliases When Resolving Names
Enable ADSI and Old Netscape Schema Output
Check this box to enable non-standard schema output so that current ADSI and old Netscape*
clients can read the schema.
The non-standard output format changes are:
Note: The non-standard output does not conform to the current IETF defined standards for LDAP, but it works with the current ADSI and old Netscape clients.
Return Opertational Attributes When All User Attributes Are Requested
Select this option to return operational attributes as well as user attributes when the
search operation is asked to return all user attributes (by specifying an empty attribute
list or the special * character).
Refresh NLDAP Server Now
Select this button to synchronize the LDAP server with the values contained in the LDAP
Group and the LDAP Server objects.
Note: Every time you make changes to your Novell LDAP settings and click OK, eDirectory refreshes itself.
This button is not available for NDS 7 or older versions. To refresh the servers in NDS 7, type LDAP REFRESH IMMEDIATE, or type UNLOAD NLDAP.NLM then type LOAD NLDAP.NLM in the NetWare console.
A trademark symbol (®, TM, etc.) denotes a Novell trademark. An asterisk (*) denotes a third-party trademark. For information on trademarks, see Legal Notices.