Virtual Attribute
This is an abstract object type that cannot be instantiated.
Virtual Attributes are responsible for dynamically generating attribute values that appear in entries but are not persistently stored in the backend.
Virtual attributes are associated with a virtual attribute provider, which contains the logic for generating the value.
Virtual Attributes
The following Virtual Attributes are available:
These Virtual Attributes inherit the properties described below.
Virtual Attribute Properties
You can use configuration expressions to set property values at startup time. For details, see Property Value Substitution.
Basic Properties |
---|
attribute-type |
attribute-type
Synopsis |
Specifies the attribute type for the attribute whose values are to be dynamically assigned by the virtual attribute. |
Default Value |
None |
Allowed Values |
The name of an attribute type defined in the LDAP schema. |
Multi-valued |
No |
Required |
Yes |
Admin Action Required |
None |
Advanced |
No |
Read-Only |
No |
base-dn
Synopsis |
Specifies the base DNs for the branches containing entries that are eligible to use this virtual attribute. |
Description |
If no values are given, then the server generates virtual attributes anywhere in the server. |
Default Value |
The location of the entry in the server is not taken into account when determining whether an entry is eligible to use this virtual attribute. |
Allowed Values |
A valid DN. |
Multi-valued |
Yes |
Required |
No |
Admin Action Required |
None |
Advanced |
No |
Read-Only |
No |
conflict-behavior
Synopsis |
Specifies the behavior that the server is to exhibit for entries that already contain one or more real values for the associated attribute. |
Default Value |
real-overrides-virtual |
Allowed Values |
|
Multi-valued |
No |
Required |
No |
Admin Action Required |
None |
Advanced |
No |
Read-Only |
No |
enabled
Synopsis |
Indicates whether the Virtual Attribute is enabled for use. |
Default Value |
None |
Allowed Values |
true false |
Multi-valued |
No |
Required |
Yes |
Admin Action Required |
None |
Advanced |
No |
Read-Only |
No |
filter
Synopsis |
Specifies the search filters to be applied against entries to determine if the virtual attribute is to be generated for those entries. |
Description |
If no values are given, then any entry is eligible to have the value generated. If one or more filters are specified, then only entries that match at least one of those filters are allowed to have the virtual attribute. |
Default Value |
(objectClass=*) |
Allowed Values |
Any valid search filter string. |
Multi-valued |
Yes |
Required |
No |
Admin Action Required |
None |
Advanced |
No |
Read-Only |
No |
group-dn
Synopsis |
Specifies the DNs of the groups whose members can be eligible to use this virtual attribute. |
Description |
If no values are given, then group membership is not taken into account when generating the virtual attribute. If one or more group DNs are specified, then only members of those groups are allowed to have the virtual attribute. |
Default Value |
Group membership is not taken into account when determining whether an entry is eligible to use this virtual attribute. |
Allowed Values |
A valid DN. |
Multi-valued |
Yes |
Required |
No |
Admin Action Required |
None |
Advanced |
No |
Read-Only |
No |
java-class
Synopsis |
Specifies the fully-qualified name of the virtual attribute provider class that generates the attribute values. |
Default Value |
None |
Allowed Values |
A Java class that extends or implements:
|
Multi-valued |
No |
Required |
Yes |
Admin Action Required |
The object must be disabled and re-enabled for changes to take effect. |
Advanced |
No |
Read-Only |
No |
scope
Synopsis |
Specifies the LDAP scope associated with base DNs for entries that are eligible to use this virtual attribute. |
Default Value |
whole-subtree |
Allowed Values |
|
Multi-valued |
No |
Required |
No |
Admin Action Required |
None |
Advanced |
No |
Read-Only |
No |