- About This Reference
- Attribute Types
- aci
- aclRights
- aclRightsInfo
- administratorsAddress
- aliasedObjectName
- alive
- altServer
- aRecord
- assignedDashboard
- associatedDomain
- associatedName
- attributeMap
- attributeTypes
- audio
- authenticationMethod
- authorityRevocationList
- authPassword
- automountInformation
- automountKey
- automountMapName
- bindTimeLimit
- blockInheritance
- bootFile
- bootParameter
- buildingName
- businessCategory
- c-FacsimileTelephoneNumber
- c-InternationalISDNNumber
- c-l
- c-o
- c-ou
- c-PhysicalDeliveryOfficeName
- c-PostalAddress
- c-PostalCode
- c-PostOfficeBox
- c-st
- c-street
- c-TelephoneNumber
- c-TelexNumber
- c
- cACertificate
- calCalAdrURI
- calCalURI
- calCAPURI
- calFBURL
- calOtherCalAdrURIs
- calOtherCalURIs
- calOtherCAPURIs
- calOtherFBURLs
- carLicense
- certificateRevocationList
- changeInitiatorsName
- changelog
- changeLogCookie
- changeNumber
- changes
- changeTime
- changeType
- cn
- cNAMERecord
- co
- collectiveAttributeSubentries
- collectiveConflictBehavior
- collectiveExclusions
- corbaIor
- corbaRepositoryId
- coreTokenDate01
- coreTokenDate02
- coreTokenDate03
- coreTokenDate04
- coreTokenDate05
- coreTokenExpirationDate
- coreTokenId
- coreTokenInteger01
- coreTokenInteger02
- coreTokenInteger03
- coreTokenInteger04
- coreTokenInteger05
- coreTokenInteger06
- coreTokenInteger07
- coreTokenInteger08
- coreTokenInteger09
- coreTokenInteger10
- coreTokenMultiString01
- coreTokenMultiString02
- coreTokenMultiString03
- coreTokenObject
- coreTokenString01
- coreTokenString02
- coreTokenString03
- coreTokenString04
- coreTokenString05
- coreTokenString06
- coreTokenString07
- coreTokenString08
- coreTokenString09
- coreTokenString10
- coreTokenString11
- coreTokenString12
- coreTokenString13
- coreTokenString14
- coreTokenString15
- coreTokenTtlDate
- coreTokenType
- coreTokenUserId
- createTimestamp
- creatorsName
- credentialLevel
- crossCertificatePair
- dc
- defaultSearchBase
- defaultSearchScope
- defaultServerList
- deleteOldRDN
- deltaRevocationList
- departmentNumber
- dereferenceAliases
- description
- destinationIndicator
- devicePrintProfiles
- deviceProfiles
- displayName
- distinguishedName
- dITContentRules
- dITRedirect
- dITStructureRules
- dmdName
- dnQualifier
- documentAuthor
- documentIdentifier
- documentLocation
- documentPublisher
- documentTitle
- documentVersion
- drink
- ds-certificate-fingerprint
- ds-certificate-issuer-dn
- ds-certificate-subject-dn
- ds-mon-abandoned-requests
- ds-mon-active-connections-count
- ds-mon-active-persistent-searches
- ds-mon-admin-hostport
- ds-mon-alias
- ds-mon-alive-errors
- ds-mon-alive
- ds-mon-backend-degraded-index-count
- ds-mon-backend-degraded-index
- ds-mon-backend-entry-count
- ds-mon-backend-filter-use-indexed
- ds-mon-backend-filter-use-start-time
- ds-mon-backend-filter-use-unindexed
- ds-mon-backend-filter-use
- ds-mon-backend-is-private
- ds-mon-backend-proxy-base-dn
- ds-mon-backend-proxy-shard
- ds-mon-backend-ttl-entries-deleted
- ds-mon-backend-ttl-is-running
- ds-mon-backend-ttl-last-run-time
- ds-mon-backend-ttl-queue-size
- ds-mon-backend-ttl-thread-count
- ds-mon-backend-writability-mode
- ds-mon-base-dn-entry-count
- ds-mon-base-dn
- ds-mon-build-number
- ds-mon-build-time
- ds-mon-bytes-read
- ds-mon-bytes-written
- ds-mon-cache-entry-count
- ds-mon-cache-max-entry-count
- ds-mon-cache-max-size-bytes
- ds-mon-cache-misses
- ds-mon-cache-total-tries
- ds-mon-certificate-expires-at
- ds-mon-certificate-issuer-dn
- ds-mon-certificate-serial-number
- ds-mon-certificate-subject-dn
- ds-mon-changelog-hostport
- ds-mon-changelog-id
- ds-mon-changelog-purge-delay
- ds-mon-compact-version
- ds-mon-config-dn
- ds-mon-connected-to-server-hostport
- ds-mon-connected-to-server-id
- ds-mon-connection
- ds-mon-connections
- ds-mon-current-connections
- ds-mon-current-receive-window
- ds-mon-current-time
- ds-mon-db-cache-evict-internal-nodes-count
- ds-mon-db-cache-evict-leaf-nodes-count
- ds-mon-db-cache-leaf-nodes
- ds-mon-db-cache-misses-internal-nodes
- ds-mon-db-cache-misses-leaf-nodes
- ds-mon-db-cache-size-active
- ds-mon-db-cache-size-total
- ds-mon-db-cache-total-tries-internal-nodes
- ds-mon-db-cache-total-tries-leaf-nodes
- ds-mon-db-checkpoint-count
- ds-mon-db-log-cleaner-file-deletion-count
- ds-mon-db-log-files-open
- ds-mon-db-log-files-opened
- ds-mon-db-log-size-active
- ds-mon-db-log-size-total
- ds-mon-db-log-utilization-max
- ds-mon-db-log-utilization-min
- ds-mon-db-version
- ds-mon-disk-dir
- ds-mon-disk-free
- ds-mon-disk-full-threshold
- ds-mon-disk-low-threshold
- ds-mon-disk-root
- ds-mon-disk-state
- ds-mon-domain-generation-id
- ds-mon-domain-name
- ds-mon-entries-awaiting-updates-count
- ds-mon-fix-ids
- ds-mon-full-version
- ds-mon-group-id
- ds-mon-healthy-errors
- ds-mon-healthy
- ds-mon-install-path
- ds-mon-instance-path
- ds-mon-jvm-architecture
- ds-mon-jvm-arguments
- ds-mon-jvm-available-cpus
- ds-mon-jvm-class-path
- ds-mon-jvm-classes-loaded
- ds-mon-jvm-classes-unloaded
- ds-mon-jvm-java-home
- ds-mon-jvm-java-vendor
- ds-mon-jvm-java-version
- ds-mon-jvm-memory-heap-init
- ds-mon-jvm-memory-heap-max
- ds-mon-jvm-memory-heap-reserved
- ds-mon-jvm-memory-heap-used
- ds-mon-jvm-memory-init
- ds-mon-jvm-memory-max
- ds-mon-jvm-memory-non-heap-init
- ds-mon-jvm-memory-non-heap-max
- ds-mon-jvm-memory-non-heap-reserved
- ds-mon-jvm-memory-non-heap-used
- ds-mon-jvm-memory-reserved
- ds-mon-jvm-memory-used
- ds-mon-jvm-supported-tls-ciphers
- ds-mon-jvm-supported-tls-protocols
- ds-mon-jvm-threads-blocked-count
- ds-mon-jvm-threads-count
- ds-mon-jvm-threads-daemon-count
- ds-mon-jvm-threads-deadlock-count
- ds-mon-jvm-threads-deadlocks
- ds-mon-jvm-threads-new-count
- ds-mon-jvm-threads-runnable-count
- ds-mon-jvm-threads-terminated-count
- ds-mon-jvm-threads-timed-waiting-count
- ds-mon-jvm-threads-waiting-count
- ds-mon-jvm-vendor
- ds-mon-jvm-version
- ds-mon-last-seen
- ds-mon-ldap-hostport
- ds-mon-ldap-starttls-hostport
- ds-mon-ldaps-hostport
- ds-mon-listen-address
- ds-mon-lost-connections
- ds-mon-major-version
- ds-mon-max-connections
- ds-mon-minor-version
- ds-mon-newest-change-number
- ds-mon-newest-csn-timestamp
- ds-mon-newest-csn
- ds-mon-oldest-change-number
- ds-mon-oldest-csn-timestamp
- ds-mon-oldest-csn
- ds-mon-os-architecture
- ds-mon-os-name
- ds-mon-os-version
- ds-mon-point-version
- ds-mon-process-id
- ds-mon-product-name
- ds-mon-protocol
- ds-mon-receive-delay
- ds-mon-replay-delay
- ds-mon-replayed-updates-conflicts-resolved
- ds-mon-replayed-updates-conflicts-unresolved
- ds-mon-replayed-updates
- ds-mon-replication-domain
- ds-mon-replication-protocol-version
- ds-mon-requests-abandon
- ds-mon-requests-add
- ds-mon-requests-bind
- ds-mon-requests-compare
- ds-mon-requests-delete
- ds-mon-requests-extended
- ds-mon-requests-failure-client-invalid-request
- ds-mon-requests-failure-client-redirect
- ds-mon-requests-failure-client-referral
- ds-mon-requests-failure-client-resource-limit
- ds-mon-requests-failure-client-security
- ds-mon-requests-failure-server
- ds-mon-requests-failure-uncategorized
- ds-mon-requests-get
- ds-mon-requests-in-queue
- ds-mon-requests-modify-dn
- ds-mon-requests-modify
- ds-mon-requests-patch
- ds-mon-requests-post
- ds-mon-requests-put
- ds-mon-requests-rejected-queue-full
- ds-mon-requests-search-base
- ds-mon-requests-search-one
- ds-mon-requests-search-sub
- ds-mon-requests-submitted
- ds-mon-requests-unbind
- ds-mon-requests-uncategorized
- ds-mon-revision
- ds-mon-sent-updates
- ds-mon-server-id
- ds-mon-server-is-local
- ds-mon-server-state
- ds-mon-short-name
- ds-mon-ssl-encryption
- ds-mon-start-time
- ds-mon-status-last-changed
- ds-mon-status
- ds-mon-system-name
- ds-mon-total-connections
- ds-mon-total-update-entry-count
- ds-mon-total-update-entry-left
- ds-mon-total-update
- ds-mon-updates-inbound-queue
- ds-mon-updates-outbound-queue
- ds-mon-updates-totals-per-replay-thread
- ds-mon-vendor-name
- ds-mon-version-qualifier
- ds-mon-working-directory
- ds-private-naming-contexts
- ds-privilege-name
- ds-pwp-account-disabled
- ds-pwp-account-expiration-time
- ds-pwp-account-status-notification-handler
- ds-pwp-allow-expired-password-changes
- ds-pwp-allow-multiple-password-values
- ds-pwp-allow-pre-encoded-passwords
- ds-pwp-allow-user-password-changes
- ds-pwp-attribute-value-check-substrings
- ds-pwp-attribute-value-match-attribute
- ds-pwp-attribute-value-min-substring-length
- ds-pwp-attribute-value-test-reversed-password
- ds-pwp-character-set-allow-unclassified-characters
- ds-pwp-character-set-character-set-ranges
- ds-pwp-character-set-character-set
- ds-pwp-character-set-min-character-sets
- ds-pwp-default-password-storage-scheme
- ds-pwp-deprecated-password-storage-scheme
- ds-pwp-dictionary-case-sensitive-validation
- ds-pwp-dictionary-check-substrings
- ds-pwp-dictionary-data
- ds-pwp-dictionary-min-substring-length
- ds-pwp-dictionary-test-reversed-password
- ds-pwp-expire-passwords-without-warning
- ds-pwp-force-change-on-add
- ds-pwp-force-change-on-reset
- ds-pwp-grace-login-count
- ds-pwp-idle-lockout-interval
- ds-pwp-last-login-time-attribute
- ds-pwp-last-login-time-format
- ds-pwp-last-login-time
- ds-pwp-length-based-max-password-length
- ds-pwp-length-based-min-password-length
- ds-pwp-lockout-duration
- ds-pwp-lockout-failure-count
- ds-pwp-lockout-failure-expiration-interval
- ds-pwp-max-password-age
- ds-pwp-max-password-reset-age
- ds-pwp-min-password-age
- ds-pwp-password-attribute
- ds-pwp-password-change-requires-current-password
- ds-pwp-password-changed-by-required-time
- ds-pwp-password-expiration-time
- ds-pwp-password-expiration-warning-interval
- ds-pwp-password-history-count
- ds-pwp-password-history-duration
- ds-pwp-password-policy-dn
- ds-pwp-previous-last-login-time-format
- ds-pwp-random-password-character-set
- ds-pwp-random-password-format
- ds-pwp-repeated-characters-case-sensitive-validation
- ds-pwp-repeated-characters-max-consecutive-length
- ds-pwp-require-change-by-time
- ds-pwp-require-secure-authentication
- ds-pwp-require-secure-password-changes
- ds-pwp-reset-time
- ds-pwp-similarity-based-min-password-difference
- ds-pwp-skip-validation-for-administrators
- ds-pwp-state-update-failure-policy
- ds-pwp-unique-characters-case-sensitive-validation
- ds-pwp-unique-characters-min-unique-characters
- ds-pwp-warned-time
- ds-rlim-cursor-entry-limit
- ds-rlim-idle-time-limit
- ds-rlim-lookthrough-limit
- ds-rlim-size-limit
- ds-rlim-time-limit
- ds-sync-conflict
- ds-sync-fractional-exclude
- ds-sync-fractional-include
- ds-sync-generation-id
- ds-sync-hist
- ds-sync-state
- ds-target-group-dn
- dSAQuality
- emailAddress
- employeeNumber
- employeeType
- enhancedSearchGuide
- entryDN
- entryUUID
- etag
- facsimileTelephoneNumber
- firstChangeNumber
- followReferrals
- fr-idm-accountStatus
- fr-idm-cluster-json
- fr-idm-condition
- fr-idm-consentedMapping
- fr-idm-custom-attrs
- fr-idm-effectiveAssignment
- fr-idm-effectiveRole
- fr-idm-internal-role-authzmembers-internal-user
- fr-idm-internal-role-authzmembers-managed-user
- fr-idm-internal-user-authzroles-internal-role
- fr-idm-internal-user-authzroles-managed-role
- fr-idm-json
- fr-idm-kbaInfo
- fr-idm-lastSync
- fr-idm-link-firstid-constraint
- fr-idm-link-firstid
- fr-idm-link-qualifier
- fr-idm-link-secondid-constraint
- fr-idm-link-secondid
- fr-idm-link-type
- fr-idm-lock-nodeid
- fr-idm-managed-assignment-json
- fr-idm-managed-role-assignments
- fr-idm-managed-role-json
- fr-idm-managed-user-authzroles-internal-role
- fr-idm-managed-user-authzroles-managed-role
- fr-idm-managed-user-custom-attrs
- fr-idm-managed-user-json
- fr-idm-managed-user-manager
- fr-idm-managed-user-meta
- fr-idm-managed-user-notifications
- fr-idm-managed-user-roles
- fr-idm-name
- fr-idm-notification-json
- fr-idm-password
- fr-idm-preferences
- fr-idm-privilege
- fr-idm-recon-id
- fr-idm-recon-targetIds
- fr-idm-reconassoc-finishtime
- fr-idm-reconassoc-isanalysis
- fr-idm-reconassoc-mapping
- fr-idm-reconassoc-reconid
- fr-idm-reconassoc-sourceresourcecollection
- fr-idm-reconassoc-targetresourcecollection
- fr-idm-reconassocentry-action
- fr-idm-reconassocentry-ambiguoustargetobjectids
- fr-idm-reconassocentry-exception
- fr-idm-reconassocentry-linkqualifier
- fr-idm-reconassocentry-message
- fr-idm-reconassocentry-messagedetail
- fr-idm-reconassocentry-phase
- fr-idm-reconassocentry-reconid
- fr-idm-reconassocentry-situation
- fr-idm-reconassocentry-sourceobjectid
- fr-idm-reconassocentry-status
- fr-idm-reconassocentry-targetobjectid
- fr-idm-relationship-json
- fr-idm-role
- fr-idm-syncqueue-context
- fr-idm-syncqueue-createdate
- fr-idm-syncqueue-mapping
- fr-idm-syncqueue-newobject
- fr-idm-syncqueue-nodeid
- fr-idm-syncqueue-objectrev
- fr-idm-syncqueue-oldobject
- fr-idm-syncqueue-remainingretries
- fr-idm-syncqueue-resourcecollection
- fr-idm-syncqueue-resourceid
- fr-idm-syncqueue-state
- fr-idm-syncqueue-syncaction
- fr-idm-temporal-constraints
- fr-idm-uuid
- fullVendorVersion
- gecos
- generationQualifier
- gidNumber
- givenName
- governingStructureRule
- hasSubordinates
- healthy
- homeDirectory
- homePhone
- homePostalAddress
- host
- houseIdentifier
- includedAttributes
- inetUserHttpURL
- inetUserStatus
- info
- inheritable
- inheritAttribute
- inheritFromBaseRDN
- inheritFromDNAttribute
- inheritFromDNParent
- inheritFromRDNAttribute
- inheritFromRDNType
- initials
- internationaliSDNNumber
- ipHostNumber
- iplanet-am-auth-configuration
- iplanet-am-auth-login-failure-url
- iplanet-am-auth-login-success-url
- iplanet-am-auth-post-login-process-class
- iplanet-am-session-destroy-sessions
- iplanet-am-session-get-valid-sessions
- iplanet-am-session-max-caching-time
- iplanet-am-session-max-idle-time
- iplanet-am-session-max-session-time
- iplanet-am-session-quota-limit
- iplanet-am-session-service-status
- iplanet-am-user-account-life
- iplanet-am-user-admin-start-dn
- iplanet-am-user-alias-list
- iplanet-am-user-auth-config
- iplanet-am-user-auth-modules
- iplanet-am-user-failure-url
- iplanet-am-user-login-status
- iplanet-am-user-password-reset-force-reset
- iplanet-am-user-password-reset-options
- iplanet-am-user-password-reset-question-answer
- iplanet-am-user-service-status
- iplanet-am-user-success-url
- ipNetmaskNumber
- ipNetworkNumber
- ipProtocolNumber
- ipServicePort
- ipServiceProtocol
- ipTnetNumber
- ipTnetTemplateName
- isMemberOf
- janetMailbox
- javaClassName
- javaClassNames
- javaCodebase
- javaDoc
- javaFactory
- javaReferenceAddress
- javaSerializedData
- jpegPhoto
- kbaActiveIndex
- kbaInfo
- kbaInfoAttempts
- knowledgeInformation
- l
- labeledURI
- labeledURL
- lastChangeNumber
- lastExternalChangelogCookie
- lastModifiedBy
- lastModifiedTime
- ldapSyntaxes
- loginShell
- macAddress
- mailPreferenceOption
- manager
- matchingRules
- matchingRuleUse
- mDRecord
- member
- memberGid
- memberNisNetgroup
- memberof
- memberUid
- memberURL
- mgrpRFC822MailMember
- mobile
- modifiersName
- modifyTimestamp
- mxRecord
- name
- nameForms
- namingContexts
- newRDN
- newSuperior
- nisDomain
- nisMapEntry
- nisMapName
- nisNetgroupTriple
- nisNetIdGroup
- nisNetIdHost
- nisNetIdUser
- nisplusTimeZone
- nisPublicKey
- nisSecretKey
- nsds50ruv
- nSRecord
- nsUniqueId
- numSubordinates
- o
- oath2faEnabled
- oathDeviceProfiles
- objectClass
- objectClasses
- objectclassMap
- oncRpcNumber
- organizationalStatus
- otherMailbox
- ou
- owner
- pager
- personalSignature
- personalTitle
- photo
- physicalDeliveryOfficeName
- postalAddress
- postalCode
- postOfficeBox
- preferredDeliveryMethod
- preferredLanguage
- preferredLocale
- preferredServerList
- preferredTimeZone
- presentationAddress
- printer-aliases
- printer-charset-configured
- printer-charset-supported
- printer-color-supported
- printer-compression-supported
- printer-copies-supported
- printer-current-operator
- printer-delivery-orientation-supported
- printer-document-format-supported
- printer-finishings-supported
- printer-generated-natural-language-supported
- printer-info
- printer-ipp-versions-supported
- printer-job-k-octets-supported
- printer-job-priority-supported
- printer-location
- printer-make-and-model
- printer-media-local-supported
- printer-media-supported
- printer-more-info
- printer-multiple-document-jobs-supported
- printer-name
- printer-natural-language-configured
- printer-number-up-supported
- printer-output-features-supported
- printer-pages-per-minute-color
- printer-pages-per-minute
- printer-print-quality-supported
- printer-resolution-supported
- printer-service-person
- printer-sides-supported
- printer-stacking-order-supported
- printer-uri
- printer-xri-supported
- profileTTL
- protocolInformation
- push2faEnabled
- pushDeviceProfiles
- pwdAccountLockedTime
- pwdAllowUserChange
- pwdAttribute
- pwdChangedTime
- pwdCheckQuality
- pwdExpireWarning
- pwdFailureCountInterval
- pwdFailureTime
- pwdGraceAuthNLimit
- pwdGraceUseTime
- pwdHistory
- pwdInHistory
- pwdLockout
- pwdLockoutDuration
- pwdMaxAge
- pwdMaxFailure
- pwdMinAge
- pwdMinLength
- pwdMustChange
- pwdPolicySubentry
- pwdReset
- pwdSafeModify
- ref
- registeredAddress
- replicaIdentifier
- replicationCSN
- rfc822mailMember
- roleOccupant
- roomNumber
- sambaAcctFlags
- sambaAlgorithmicRidBase
- sambaBadPasswordCount
- sambaBadPasswordTime
- sambaBoolOption
- sambaDomainName
- sambaForceLogoff
- sambaGroupType
- sambaHomeDrive
- sambaHomePath
- sambaIntegerOption
- sambaKickoffTime
- sambaLMPassword
- sambaLockoutDuration
- sambaLockoutObservationWindow
- sambaLockoutThreshold
- sambaLogoffTime
- sambaLogonHours
- sambaLogonScript
- sambaLogonTime
- sambaLogonToChgPwd
- sambaMaxPwdAge
- sambaMinPwdAge
- sambaMinPwdLength
- sambaMungedDial
- sambaNextGroupRid
- sambaNextRid
- sambaNextUserRid
- sambaNTPassword
- sambaOptionName
- sambaPasswordHistory
- sambaPrimaryGroupSID
- sambaPrivilegeList
- sambaProfilePath
- sambaPwdCanChange
- sambaPwdHistoryLength
- sambaPwdLastSet
- sambaPwdMustChange
- sambaRefuseMachinePwdChange
- sambaShareName
- sambaSID
- sambaSIDList
- sambaStringListOption
- sambaStringOption
- sambaTrustFlags
- sambaUserWorkstations
- searchGuide
- searchTimeLimit
- secretary
- seeAlso
- serialNumber
- service-advert-attribute-authenticator
- service-advert-scopes
- service-advert-service-type
- service-advert-url-authenticator
- serviceAuthenticationMethod
- serviceCredentialLevel
- serviceSearchDescriptor
- shadowExpire
- shadowFlag
- shadowInactive
- shadowLastChange
- shadowMax
- shadowMin
- shadowWarning
- singleLevelQuality
- sn
- sOARecord
- SolarisAttrKeyValue
- SolarisAttrLongDesc
- SolarisAttrReserved1
- SolarisAttrReserved2
- SolarisAttrShortDesc
- SolarisAuditAlways
- SolarisAuditNever
- SolarisAuthMethod
- SolarisBindDN
- SolarisBindPassword
- SolarisBindTimeLimit
- SolarisCacheTTL
- SolarisCertificatePassword
- SolarisCertificatePath
- SolarisDataSearchDN
- SolarisKernelSecurityPolicy
- SolarisLDAPServers
- SolarisPreferredServer
- SolarisPreferredServerOnly
- SolarisProfileId
- SolarisProfileType
- SolarisProjectAttr
- SolarisProjectID
- SolarisProjectName
- SolarisSearchBaseDN
- SolarisSearchReferral
- SolarisSearchScope
- SolarisSearchTimeLimit
- SolarisTransportSecurity
- SolarisUserQualifier
- st
- street
- structuralObjectClass
- subschemaSubentry
- subtreeMaximumQuality
- subtreeMinimumQuality
- subtreeSpecification
- sun-fm-saml2-nameid-info
- sun-fm-saml2-nameid-infokey
- sun-printer-bsdaddr
- sun-printer-kvp
- sunAMAuthInvalidAttemptsData
- sunIdentityMSISDNNumber
- sunKeyValue
- sunPluginSchema
- sunserviceID
- sunServiceSchema
- sunsmspriority
- sunxmlKeyValue
- supportedAlgorithms
- supportedApplicationContext
- supportedAuthPasswordSchemes
- supportedControl
- supportedExtension
- supportedFeatures
- supportedLDAPVersion
- supportedSASLMechanisms
- supportedTLSCiphers
- supportedTLSProtocols
- targetDN
- targetEntryUUID
- telephoneNumber
- teletexTerminalIdentifier
- telexNumber
- template-major-version-number
- template-minor-version-number
- template-url-syntax
- textEncodedORAddress
- title
- uddiAccessPoint
- uddiAddressLine
- uddiAuthorizedName
- uddiBindingKey
- uddiBusinessKey
- uddiCategoryBag
- uddiDescription
- uddiDiscoveryURLs
- uddiEMail
- uddiFromKey
- uddiHostingRedirector
- uddiIdentifierBag
- uddiInstanceDescription
- uddiInstanceParms
- uddiIsHidden
- uddiIsProjection
- uddiKeyedReference
- uddiLang
- uddiName
- uddiOperator
- uddiOverviewDescription
- uddiOverviewURL
- uddiPersonName
- uddiPhone
- uddiServiceKey
- uddiSortCode
- uddiTModelKey
- uddiToKey
- uddiUseType
- uddiUUID
- uddiv3BindingKey
- uddiv3BriefResponse
- uddiv3BusinessKey
- uddiv3DigitalSignature
- uddiv3EntityCreationTime
- uddiv3EntityDeletionTime
- uddiv3EntityKey
- uddiv3EntityModificationTime
- uddiv3ExpiresAfter
- uddiv3MaxEntities
- uddiv3NodeId
- uddiv3NotificationInterval
- uddiv3ServiceKey
- uddiv3SubscriptionFilter
- uddiv3SubscriptionKey
- uddiv3TModelKey
- uid
- uidNumber
- uniqueIdentifier
- uniqueMember
- userCertificate
- userClass
- userPassword
- userPKCS12
- userSMIMECertificate
- vendorName
- vendorVersion
- webauthnDeviceProfiles
- winAccountName
- x121Address
- x500UniqueIdentifier
- DIT Content Rules
- DIT Structure Rules
- uddiAddressStructureRule
- uddiBindingTemplateStructureRule
- uddiBusinessEntityStructureRule
- uddiBusinessServiceStructureRule
- uddiContactStructureRule
- uddiPublisherAssertionStructureRule
- uddiTModelInstanceInfoStructureRule
- uddiTModelStructureRule
- uddiv3EntityObituaryStructureRule
- uddiv3SubscriptionStructureRule
- Matching Rule Uses
- Matching Rules
- 1.3.6.1.4.1.26027.1.4.8.1.3.6.1.4.1.26027.1.3.6
- authPasswordExactMatch
- authPasswordMatch
- bitStringMatch
- booleanMatch
- caseExactIA5Match
- caseExactIA5SubstringsMatch
- caseExactJsonIdMatch
- caseExactJsonQueryMatch
- caseExactMatch
- caseExactOrderingMatch
- caseExactSubstringsMatch
- caseIgnoreIA5Match
- caseIgnoreIA5SubstringsMatch
- caseIgnoreJsonIdMatch
- caseIgnoreJsonQueryMatch
- caseIgnoreJsonQueryMatchClusterObject
- caseIgnoreJsonQueryMatchManagedRole
- caseIgnoreJsonQueryMatchManagedUser
- caseIgnoreJsonQueryMatchRelationship
- caseIgnoreListMatch
- caseIgnoreListSubstringsMatch
- caseIgnoreMatch
- caseIgnoreOrderingMatch
- caseIgnoreSubstringsMatch
- certificateExactMatch
- ctsOAuth2GrantSetEqualityMatch
- directoryStringFirstComponentMatch
- distinguishedNameMatch
- ds-mr-double-metaphone-approx
- ds-mr-user-password-equality
- ds-mr-user-password-exact
- generalizedTimeMatch
- generalizedTimeOrderingMatch
- historicalCsnOrderingMatch
- historicalCsnRangeMatch
- integerFirstComponentMatch
- integerMatch
- integerOrderingMatch
- jsonFirstComponentCaseExactJsonQueryMatch
- jsonFirstComponentCaseIgnoreJsonQueryMatch
- keywordMatch
- nameAndOptionalCaseExactJsonIdEqualityMatch
- nameAndOptionalCaseIgnoreJsonIdEqualityMatch
- nameAndOptionalJsonEqualityMatchingRule
- numericStringMatch
- numericStringOrderingMatch
- numericStringSubstringsMatch
- objectIdentifierFirstComponentMatch
- objectIdentifierMatch
- octetStringMatch
- octetStringOrderingMatch
- octetStringSubstringsMatch
- partialDateAndTimeMatchingRule
- presentationAddressMatch
- protocolInformationMatch
- relativeTimeGTOrderingMatch
- relativeTimeLTOrderingMatch
- telephoneNumberMatch
- telephoneNumberSubstringsMatch
- uniqueMemberMatch
- uuidMatch
- uuidOrderingMatch
- wordMatch
- Name Forms
- Object Classes
- account
- alias
- applicationEntity
- applicationProcess
- authPasswordObject
- automount
- automountMap
- bootableDevice
- calEntry
- certificationAuthority-V2
- certificationAuthority
- changeLogEntry
- collectiveAttributeSubentry
- container
- corbaContainer
- corbaObject
- corbaObjectReference
- country
- cRLDistributionPoint
- dcObject
- deltaCRL
- device
- devicePrintProfilesContainer
- deviceProfilesContainer
- dmd
- dNSDomain
- document
- documentSeries
- domain
- domainRelatedObject
- ds-certificate-user
- ds-monitor-backend-db
- ds-monitor-backend-pluggable
- ds-monitor-backend-proxy
- ds-monitor-backend
- ds-monitor-base-dn
- ds-monitor-branch
- ds-monitor-certificate
- ds-monitor-changelog-domain
- ds-monitor-changelog
- ds-monitor-connected-changelog
- ds-monitor-connected-replica
- ds-monitor-connection-handler
- ds-monitor-disk-space
- ds-monitor-entry-cache
- ds-monitor-health-status
- ds-monitor-http-connection-handler
- ds-monitor-je-database
- ds-monitor-jvm
- ds-monitor-ldap-connection-handler
- ds-monitor-raw-je-database-statistics
- ds-monitor-remote-replica
- ds-monitor-replica-db
- ds-monitor-replica
- ds-monitor-server
- ds-monitor-topology-server
- ds-monitor-work-queue
- ds-monitor
- ds-pwp-attribute-value-validator
- ds-pwp-character-set-validator
- ds-pwp-dictionary-validator
- ds-pwp-length-based-validator
- ds-pwp-password-policy
- ds-pwp-random-generator
- ds-pwp-repeated-characters-validator
- ds-pwp-similarity-based-validator
- ds-pwp-unique-characters-validator
- ds-pwp-validator
- ds-root-dse
- ds-virtual-static-group
- dSA
- DUAConfigProfile
- extensibleObject
- forgerock-am-dashboard-service
- fr-idm-cluster-obj
- fr-idm-generic-obj
- fr-idm-hybrid-obj
- fr-idm-internal-role
- fr-idm-internal-user
- fr-idm-link
- fr-idm-lock
- fr-idm-managed-assignment
- fr-idm-managed-role
- fr-idm-managed-user-explicit
- fr-idm-managed-user-hybrid-obj
- fr-idm-managed-user
- fr-idm-notification
- fr-idm-recon-clusteredTargetIds
- fr-idm-reconassoc
- fr-idm-reconassocentry
- fr-idm-relationship
- fr-idm-syncqueue
- frCoreToken
- friendlyCountry
- glue
- groupOfEntries
- groupOfNames
- groupOfUniqueNames
- groupOfURLs
- ieee802Device
- inetOrgPerson
- inetuser
- inheritableLDAPSubEntry
- inheritedCollectiveAttributeSubentry
- inheritedFromDNCollectiveAttributeSubentry
- inheritedFromRDNCollectiveAttributeSubentry
- ipHost
- iplanet-am-auth-configuration-service
- iplanet-am-managed-person
- iplanet-am-session-service
- iplanet-am-user-service
- iPlanetPreferences
- ipNetwork
- ipProtocol
- ipService
- ipTnetHost
- ipTnetTemplate
- javaContainer
- javaMarshalledObject
- javaNamingReference
- javaObject
- javaSerializedObject
- kbaInfoContainer
- labeledURIObject
- ldapSubEntry
- locality
- mailGroup
- namedObject
- nisDomainObject
- nisKeyObject
- nisMailAlias
- nisMap
- nisNetgroup
- nisNetId
- nisObject
- nisplusTimeZoneData
- oathDeviceProfilesContainer
- oncRpc
- organization
- organizationalPerson
- organizationalRole
- organizationalUnit
- person
- pilotDSA
- pilotObject
- pilotOrganization
- pilotPerson
- pkiCA
- pkiUser
- posixAccount
- posixGroup
- printerAbstract
- printerIPP
- printerLPR
- printerService
- printerServiceAuxClass
- pushDeviceProfilesContainer
- pwdPolicy
- pwdValidatorPolicy
- qualityLabelledData
- referral
- residentialPerson
- rFC822LocalPart
- room
- sambaConfig
- sambaConfigOption
- sambaDomain
- sambaGroupMapping
- sambaIdmapEntry
- sambaPrivilege
- sambaSamAccount
- sambaShare
- sambaSidEntry
- sambaTrustPassword
- sambaUnixIdPool
- shadowAccount
- simpleSecurityObject
- slpService
- slpServicePrinter
- SolarisAuditUser
- SolarisAuthAttr
- SolarisExecAttr
- SolarisNamingProfile
- SolarisProfAttr
- SolarisProject
- SolarisUserAttr
- strongAuthenticationUser
- subentry
- subschema
- sunAMAuthAccountLockout
- sunFMSAML2NameIdentifier
- sunPrinter
- sunRealmService
- sunservice
- sunservicecomponent
- top
- uddiAddress
- uddiBindingTemplate
- uddiBusinessEntity
- uddiBusinessService
- uddiContact
- uddiPublisherAssertion
- uddiTModel
- uddiTModelInstanceInfo
- uddiv3EntityObituary
- uddiv3Subscription
- uidObject
- untypedObject
- userSecurityInformation
- webauthnDeviceProfilesContainer
- Syntaxes
- Attribute Type Description
- Authentication Password Syntax
- Binary
- Bit String
- Boolean
- Certificate
- Certificate List
- Certificate Pair
- Collective Conflict Behavior
- Counter metric
- Country String
- CSN (Change Sequence Number)
- Delivery Method
- Directory String
- DIT Content Rule Description
- DIT Structure Rule Description
- DN
- Duration in milli-seconds
- Enhanced Guide
- Expression syntax for Boolean
- Expression syntax for Certificate
- Expression syntax for Directory String
- Expression syntax for DN
- Expression syntax for Generalized Time
- Expression syntax for IA5 String
- Expression syntax for Integer
- Expression syntax for Numeric String
- Expression syntax for Octet String
- Expression syntax for OID
- Expression syntax for Sun-defined Access Control Information
- Expression syntax for User Password
- Facsimile Telephone Number
- Fax
- Filesystem path
- Generalized Time
- Guide
- Host port
- IA5 String
- Integer
- JPEG
- Json
- Json Query
- LDAP Syntax Description
- Matching Rule Description
- Matching Rule Use Description
- Name and Optional JSON
- Name and Optional UID
- Name Form Description
- Numeric String
- Object Class Description
- Octet String
- OID
- Other Mailbox
- Postal Address
- Presentation Address
- Printable String
- Protocol Information
- Size in bytes
- Substring Assertion
- Subtree Specification
- Summary metric
- Sun-defined Access Control Information
- Supported Algorithm
- Telephone Number
- Teletex Terminal Identifier
- Telex Number
- Timer metric
- User Password
- UTC Time
- UUID
- X.509 Certificate Exact Assertion
About This Reference
This reference describes the default directory schema. Each schema definition has its own section, with links to related sections. Reference pages for the most commonly used elements may include additional descriptions and examples that are not present in the directory schema definitions.
This reference does not include directory configuration attributes and object classes, collation matching rules.
LDAP directory schema defines how data can be stored in the directory. When a directory server receives a request to update directory data, it can check the data changes against the directory schema, refusing any request that would result in a violation of the directory schema and directory data corruption.
Schema checking prevents errors such as the following:
Adding inappropriate attributes to an entry
Removing required attributes from an entry
Using an attribute value that has the wrong syntax
Adding the wrong type of subordinate object
LDAP directory schema consists of definitions for the following:
- Attribute types
Define attributes of directory entries, including their syntaxes and matching rules
- Directory Information Tree (DIT) content rules
Define the content of entries with a given structural object class
- DIT structure rules
Define the names entries may have, and how entries may be related to each other
- Matching rules
Define how values of attributes are matched and compared
- Matching rule uses
List attributes that can be used with an extensibleMatch search filter
- Name forms
Define naming relations for structural object classes
- Object classes
Define the types of objects that an entry represents, and the required and optional attributes for entries of those types
- Syntaxes
Define the encodings used in LDAP
For a technical description of LDAP directory schema, read Directory Schema in Lightweight Directory Access Protocol (LDAP): Directory Information Models (RFC 4512).
LDAP directory servers allow client applications to access directory schema while the server is running. This enables applications to validate their changes against the schema before sending an update request to the server. As a result, LDAP schema definitions are optimized for applications, not humans. The reader must resolve relationships between schema definitions, and must find most documentation elsewhere.