User registry considerations

Supported LDAP user registries

Name limitations for supported registries

LDAP configuration information

LDAP data format

The following LDAP data formats are available for user and group tracking information.

If the user and group information in the LDAP registry is used by other ISAM products, such as IBM Tivoli Access Manager for Operating Systems or the Federation Runtime, the same LDAP data format must be used for all products.

Sun Java System Directory Server look-through limit

When the directory server is installed, the default value for look-through limit is 5000. If the user registry contains more entries than the defined look-through limit, the directory server might return the following status that Security Verify Access treats as an error:

We can modify this value from the Sun Java™ System Directory Server Console:

  1. Select...

      Configuration > Data entry > Database Settings LDBM Plug-in Settings tab

  2. In the Look-through Limit field, type one of the following responses:

    • The maximum number of entries that we want the server to check in response to the search, or type
    • -1 to define no maximum limit.

    If we bind the directory as the Directory Manager, the look-through limit is unlimited and overrides any settings that are specified in this field.

Microsoft Active Directory Lightweight Directory Services (AD LDS)

Review this information before configuring a Microsoft AD LDS registry for the environment.

Parent topic: User registry server installation