Class aaa:LdapProvider (CONCRETE)

Class ID:259
Encrypted: true - Exportable: true - Persistent: true
Privileges: [aaa, admin]
SNMP OID: .1.3.6.1.4.1.9.9.719.1.1.14

NO COMMENTS


Naming Rules
RN FORMAT: provider-[name]

    [1] PREFIX=provider- PROPERTY = name




DN FORMAT: 

[0] sys/ldap-ext/provider-[name]

                



Containers Hierarchies
top:Root This class represents the root element in the object hierarchy. All managed objects in the system are descendants of the Root element.
 ├
top:System Provides general information about this system, such as the name, IP address and current time.
 
 ├
aaa:LdapEp
 
 
 ├
aaa:LdapProvider


Contained Hierarchy
aaa:LdapProvider
 ├
aaa:LdapGroupRule This MO is the end point for all Ldap Group related configuration. When contained under LdapEp, this represents the global configuration. When contained under LdapProvider, this represents per server configuration

Inheritance
policy:Item The base class for all objects contained by policy:Definition. Though no containment rules are specified here, by convention policy:Item must be contained by either policy:Definition or another policy:Item.
 ├
aaa:Item
 
 ├
aaa:Provider
 
 
 ├
aaa:LdapProvider

Events
                



Faults
                



Fsms
                



Properties Summary
Defined in: aaa:LdapProvider
aaa:LdapAttribute
          string:Basic
attribute  (aaa:LdapProvider:attribute)
           This property names the attribute to be downloaded which has user's roles and locales information. The value of this property takes precendence over the value of 'attribute' property in LdapEp MO
aaa:LdapDn
          string:Basic
basedn  (aaa:LdapProvider:basedn)
           Ldap Base DN to be used while searching for the user. The value of this property takes precendence over the value of 'basedn' property in LdapEp MO
scalar:Bool enableSSL  (aaa:LdapProvider:enableSSL)
           NO COMMENTS
aaa:EncKey
          string:Password
encKey  (aaa:LdapProvider:encKey)
           Overrides:aaa:Provider:encKey
           NO COMMENTS
aaa:LdapFilter
          string:Basic
filter  (aaa:LdapProvider:filter)
           Ldap filter to be used while searching for the user. The value of this property takes precendence over the value of 'filter' property in LdapEp MO
aaa:Key
          string:Password
key  (aaa:LdapProvider:key)
           Overrides:aaa:Provider:key
           NO COMMENTS
aaa:Port
          scalar:Uint32
port  (aaa:LdapProvider:port)
           NO COMMENTS
aaa:LdapDn
          string:Basic
rootdn  (aaa:LdapProvider:rootdn)
           NO COMMENTS
aaa:TimeSec
          scalar:Uint32
timeout  (aaa:LdapProvider:timeout)
           Overrides:aaa:Provider:timeout
           Per server configuration for timeout if set to 0, it uses global settings value
aaa:LdapVendor
          scalar:Enum8
vendor  (aaa:LdapProvider:vendor)
           This property holds the Ldap Provider vendor Information. Which would be used by ldap_client to provide vendor specific features in Ldap.
Defined in: aaa:Provider
scalar:Bool keySet  (aaa:Provider:keySet)
           NO COMMENTS
naming:Name
          string:Basic
name  (aaa:Provider:name)
           Overrides:aaa:Item:name
           NO COMMENTS
aaa:Order
          scalar:Uint16
order  (aaa:Provider:order)
           NO COMMENTS
aaa:Retries
          scalar:Uint32
retries  (aaa:Provider:retries)
           NO COMMENTS
Defined in: aaa:Item
naming:Descr
          string:Basic
descr  (aaa:Item:descr)
           NO COMMENTS
Defined in: mo:TopProps
mo:ModificationChildAction
          scalar:Bitmask32
childAction  (mo:TopProps:childAction)
          
reference:Object dn  (mo:TopProps:dn)
           The Distinguished Name (dn) unambiguously identifies an object in the system.
The dn provides a fully qualified path from the top of the object tree, all the way to the object. It is built as a sequence of relative names separated by the "/" character.
For example:
< ... dn = "sys/chassis-5/blade-2/adaptor-1" />
reference:RN rn  (mo:TopProps:rn)
           The Relative Name (rn) uniquely identifies an object within a given context.
Note that a dn is comprised of a sequence of relative names. For example, the context "sys/chassis-1/blade-1/adaptor-1/host-eth-2" can be thought of as the following expression:
dn = <root object>/{rn}/{rn}/{rn}/{rn}/{rn}.
The rn can then be used to identify the object (for instance, "adaptor-1") within the context:
<... rn ="../" />
mo:InstSaclType
          scalar:Bitmask8
sacl  (mo:TopProps:sacl)
           The system acl property for each Managed Object. br/> This property is a 8 bit mask and supports the following values :-
a: del
b: mod
c: addchild
d: cascade

By default all Managed Objects have the following permissions
a: del
b: mod
c: addchild
This property is persisted in the db. If this property has a value none
it means, the user has read only permissions on this object.
mo:ModificationStatus
          scalar:Bitmask32
status  (mo:TopProps:status)
           This property controls the life cycle of a managed object

Properties Detail

attribute

Type: aaa:LdapAttribute
Primitive Type: string:Basic
Units: null
Encrypted: false
Access: admin
Category: TopLevelRegular
Property Validators:
    Range:  min: "0"  max: "63"
Comments:
This property names the attribute to be downloaded which has user's roles and locales information. The value of this property takes precendence over the value of 'attribute' property in LdapEp MO
Constants
defaultValue "" NO COMMENTS

basedn

Type: aaa:LdapDn
Primitive Type: string:Basic
Units: null
Encrypted: false
Access: admin
Category: TopLevelRegular
Property Validators:
    Range:  min: "0"  max: "255"
Comments:
Ldap Base DN to be used while searching for the user. The value of this property takes precendence over the value of 'basedn' property in LdapEp MO
Constants
defaultValue "" NO COMMENTS

childAction

Type: mo:ModificationChildAction
Primitive Type: scalar:Bitmask32
Units: null
Encrypted: false
Access: implicit
Category: TopLevelChildAction
Property Validators:
Comments:
Constants
deleteAll 16384u NO COMMENTS
ignore 4096u NO COMMENTS
deleteNonPresent 8192u NO COMMENTS
DEFAULT 0 This type is used to

descr

Type: naming:Descr
Primitive Type: string:Basic
Like: naming:Described:descr
Units: null
Encrypted: false
Access: admin
Category: TopLevelRegular
Property Validators:
    Range:  min: "0"  max: "256"
        Allowed Chars:
            Regex: [a-zA-Z0-9\[\]!#$%()*+,-./:;@ _{|}˜?&]+
Comments:
NO COMMENTS

dn

Type: reference:Object
Units: null
Encrypted: false
Access: implicit
Category: TopLevelDn
Property Validators:
Comments:
The Distinguished Name (dn) unambiguously identifies an object in the system.
The dn provides a fully qualified path from the top of the object tree, all the way to the object. It is built as a sequence of relative names separated by the "/" character.
For example:
< ... dn = "sys/chassis-5/blade-2/adaptor-1" />

enableSSL

Type: scalar:Bool
Units: null
Encrypted: false
Access: admin
Category: TopLevelRegular
Property Validators:
Comments:
NO COMMENTS
Constants
yes true NO COMMENTS
no false NO COMMENTS

encKey

Type: aaa:EncKey
Primitive Type: string:Password
Overrides:aaa:Provider:encKey
Units: null
Encrypted: true
Access: admin
Category: TopLevelRegular
Property Validators:
    Range:  min: "1"  max: "127"
Comments:
NO COMMENTS

filter

Type: aaa:LdapFilter
Primitive Type: string:Basic
Units: null
Encrypted: false
Access: admin
Category: TopLevelRegular
Property Validators:
    Range:  min: "0"  max: "127"
Comments:
Ldap filter to be used while searching for the user. The value of this property takes precendence over the value of 'filter' property in LdapEp MO

key

Type: aaa:Key
Primitive Type: string:Password
Overrides:aaa:Provider:key
Units: null
Encrypted: true
Access: admin
Category: TopLevelRegular
Property Validators:
    Range:  min: "0"  max: "127"
        Allowed Chars:
            Regex: [$]
            Regex: [\\a-zA-Z0-9'"\[\]!#%&()*+,-./:;@_{|}˜`<>ˆ]+
Comments:
NO COMMENTS

keySet

Type: scalar:Bool
Units: null
Encrypted: false
Access: implicit
Category: TopLevelRegular
Property Validators:
Comments:
NO COMMENTS
Constants
yes true NO COMMENTS
defaultValue false NO COMMENTS

name

Type: naming:Name
Primitive Type: string:Basic
Overrides:aaa:Item:name
Units: null
Encrypted: false
Naming Property -- [NAMING RULES]
Access: naming
Category: TopLevelRegular
Property Validators:
    Regex: ˆ[a-zA-Z0-9][a-zA-Z0-9_.-]{0,63}$|ˆ([0-9a-fA-F]{1,4}:){7,7}[0-9a-fA-F]{1,4}$|ˆ([0-9a-fA-F]{1,4}:){1,7}:$|ˆ([0-9a-fA-F]{1,4}:){1,6}:[0-9a-fA-F]{1,4}$|ˆ([0-9a-fA-F]{1,4}:){1,5}(:[0-9a-fA-F]{1,4}){1,2}$|ˆ([0-9a-fA-F]{1,4}:){1,4}(:[0-9a-fA-F]{1,4}){1,3}$|ˆ([0-9a-fA-F]{1,4}:){1,3}(:[0-9a-fA-F]{1,4}){1,4}$|ˆ([0-9a-fA-F]{1,4}:){1,2}(:[0-9a-fA-F]{1,4}){1,5}$|ˆ[0-9a-fA-F]{1,4}:((:[0-9a-fA-F]{1,4}){1,6})$|ˆ:((:[0-9a-fA-F]{1,4}){1,7}|:)$
Comments:
NO COMMENTS

order

Type: aaa:Order
Primitive Type: scalar:Uint16
Units: null
Encrypted: false
Access: admin
Category: TopLevelRegular
Property Validators:
    Range:  min: 0  max: 16
Comments:
NO COMMENTS
Constants
lowest-available 0 NO COMMENTS
DEFAULT 0 NO COMMENTS

port

Type: aaa:Port
Primitive Type: scalar:Uint32
Units: null
Encrypted: false
Access: admin
Category: TopLevelRegular
Property Validators:
    Range:  min: (long)1l  max: (long)65535l
Comments:
NO COMMENTS
Constants
defaultValue 389u NO COMMENTS

retries

Type: aaa:Retries
Primitive Type: scalar:Uint32
Units: null
Encrypted: false
Access: admin
Category: TopLevelRegular
Property Validators:
    Range:  min: (long)0l  max: (long)5l
Comments:
NO COMMENTS
Constants
defaultValue 1u NO COMMENTS

rn

Type: reference:RN
Units: null
Encrypted: false
Access: implicit
Category: TopLevelRn
Property Validators:
Comments:
The Relative Name (rn) uniquely identifies an object within a given context.
Note that a dn is comprised of a sequence of relative names. For example, the context "sys/chassis-1/blade-1/adaptor-1/host-eth-2" can be thought of as the following expression:
dn = <root object>/{rn}/{rn}/{rn}/{rn}/{rn}.
The rn can then be used to identify the object (for instance, "adaptor-1") within the context:
<... rn ="../" />

rootdn

Type: aaa:LdapDn
Primitive Type: string:Basic
Units: null
Encrypted: false
Access: admin
Category: TopLevelRegular
Property Validators:
    Range:  min: "0"  max: "255"
Comments:
NO COMMENTS

sacl

Type: mo:InstSaclType
Primitive Type: scalar:Bitmask8
Units: null
Encrypted: false
Access: implicit
Category: TopLevelSacl
Property Validators:
Comments:
The system acl property for each Managed Object. br/> This property is a 8 bit mask and supports the following values :-
a: del
b: mod
c: addchild
d: cascade

By default all Managed Objects have the following permissions
a: del
b: mod
c: addchild
This property is persisted in the db. If this property has a value none
it means, the user has read only permissions on this object.
Constants
none 0 NO COMMENTS
del 1 NO COMMENTS
mod 2 NO COMMENTS
addchild 4 NO COMMENTS
cascade 8 NO COMMENTS
DEFAULT 0 NO COMMENTS

status

Type: mo:ModificationStatus
Primitive Type: scalar:Bitmask32
Units: null
Encrypted: false
Access: implicit
Category: TopLevelStatus
Property Validators:
Comments:
This property controls the life cycle of a managed object
Constants
removed 16u In a setter method: specifies that an object should be removed.
In the return value of a setter method: indicates that an object has been removed.
created 2u In a setter method: specifies that an object should be created. An error is returned if the object already exists.
In the return value of a setter method: indicates that an object has been created.
modified 4u In a setter method: specifies that an object should be modified
In the return value of a setter method: indicates that an object has been modified.
deleted 8u In a setter method: specifies that an object should be deleted.
In the return value of a setter method: indicates that an object has been deleted.
DEFAULT 0 This type controls the life cycle of objects passed in the XML API.

When used in a setter method (such as configConfMo), the ModificationStatus specifies whether an object should be created, modified, deleted or removed.
In the return value of a setter method, the ModificationStatus indicates the actual operation that was performed. For example, the ModificationStatus is set to "created" if the object was created. The ModificationStatus is not set if the object was neither created, modified, deleted or removed.

When invoking a setter method, the ModificationStatus is optional:
If a setter method such as configConfMo is invoked and the ModificationStatus is not set, the system automatically determines if the object should be created or modified.


timeout

Type: aaa:TimeSec
Primitive Type: scalar:Uint32
Overrides:aaa:Provider:timeout
Units: sec
Encrypted: false
Access: admin
Category: TopLevelRegular
Property Validators:
    Range:  min: (long)0l  max: (long)60l
Comments:
Per server configuration for timeout if set to 0, it uses global settings value
Constants
defaultValue 30u NO COMMENTS

vendor

Type: aaa:LdapVendor
Primitive Type: scalar:Enum8
Units: null
Encrypted: false
Access: admin
Category: TopLevelRegular
Property Validators:
Comments:
This property holds the Ldap Provider vendor Information. Which would be used by ldap_client to provide vendor specific features in Ldap.
Constants
OpenLdap 0 NO COMMENTS
MS-AD 1 NO COMMENTS
DEFAULT 0 Type: LdapVendor, holds the Ldap Provider vendor information. Which would be used later to provide vendor specific features.