If you install a Directory Server instance as part of a replicated topology that includes a version 5 server, the compatibility state should be set to DS5-compatible-mode. In this state both old and new password policy attributes are recognized. Only version 5 password policy attributes are replicated, but both sets of attributes are stored in the database.

New Password Policy

$ dsconf get-server-prop pwd-compat-mode

The pwd-compat-mode property can have one of the following values:

DS5-compatible-mode

 

 

If you upgrade an existing standalone server to Directory Server 6.0,

 

 

the compatibility state is set to DS5-compatible-mode. The server

 

 

generates the new equivalent password policy attributes.

 

 

If you upgrade an existing server as part of a replicated topology

 

 

that includes Directory Server 5 servers, the compatibility state

 

 

should also set to DS5-compatible-mode. The server accepts both

 

 

old and new password policy attributes. Both sets of attributes are

 

 

stored in the database. Only version 5 attributes can be replicated

 

 

(using fractional replication).

 

DS6-migration-mode

As part of your migration, you can set the compatibility state to

 

 

DS6-migration-mode. In this mode, all servers in the topology are

 

 

version 6 servers, but there may be some existing Directory Server 5

 

 

password policy attributes in the database.

 

DS6-mode

If you install a standalone Directory Server instance, set

 

 

compatibility mode to DS6-mode. In this case, only new password

 

 

policy attributes are recognized.

 

 

A server in DS6-mode can never be a supplier to or consumer of a

 

 

Directory Server 5 server. When all servers have been migrated to

 

 

version 6.0, DS6-mode should be the only compatibility mode.

 

The compatibility mode is set using the dsconf command as follows:

 

$ dsconf pwd-compat new-mode

 

The new-modeaction takes one of the following values:

 

to-DS6-migration-mode

Change to DS6-migration-mode from DS5-compatible-mode.

 

 

Once the change is made, only DS6-migration-mode and

 

 

DS6-mode are available.

 

to-DS6-mode

Change to DS6-mode from DS6-migration-mode.

76

Sun Java System Directory Server Enterprise Edition 6.0 Migration Guide • March 2007

 

 

Sun Confidential: Registered

Page 76
Image 76
Sun Microsystems 8190994 manual Generates the new equivalent password policy attributes, Using fractional replication