Class CoreConfigManager

    • Constructor Detail

      • CoreConfigManager

        public CoreConfigManager​(ServerContext serverContext)
        Creates a new instance of this core config manager.
        Parameters:
        serverContext - The server context.
    • Method Detail

      • initializeCoreConfig

        public void initializeCoreConfig()
                                  throws ConfigException,
                                         InitializationException
        Initializes the Directory Server's core configuration. This should only be called at server startup.
        Throws:
        ConfigException - If a configuration problem causes the identity mapper initialization process to fail.
        InitializationException - If a problem occurs while initializing the identity mappers that is not related to the server configuration.
      • isConfigurationChangeAcceptable

        public boolean isConfigurationChangeAcceptable​(GlobalCfg configuration,
                                                       List<org.forgerock.i18n.LocalizableMessage> unacceptableReasons)
        Description copied from interface: ConfigurationChangeListener
        Indicates whether the proposed change to the configuration is acceptable to this change listener.
        Specified by:
        isConfigurationChangeAcceptable in interface ConfigurationChangeListener<GlobalCfg>
        Parameters:
        configuration - The new configuration containing the changes.
        unacceptableReasons - A list that can be used to hold messages about why the provided configuration is not acceptable.
        Returns:
        Returns true if the proposed change is acceptable, or false if it is not.
      • getAllowedTasks

        public Set<String> getAllowedTasks()
        Retrieves a set containing the names of the allowed tasks that may be invoked in the server.
        Returns:
        A set containing the names of the allowed tasks that may be invoked in the server.
      • getDefaultPasswordPolicyDN

        public DN getDefaultPasswordPolicyDN()
        Retrieves the DN of the configuration entry for the default password policy for the Directory Server.
        Returns:
        The DN of the configuration entry for the default password policy for the Directory Server.
      • getDisabledPrivileges

        public Set<Privilege> getDisabledPrivileges()
        Retrieves the set of privileges that have been disabled.
        Returns:
        The set of privileges that have been disabled.
      • getIdleTimeLimit

        public long getIdleTimeLimit()
        Retrieves the idle time limit for the server.
        Returns:
        the idle time limit
      • getLookthroughLimit

        public int getLookthroughLimit()
        Retrieves the default maximum number of entries that should checked for matches during a search.
        Returns:
        The default maximum number of entries that should checked for matches during a search.
      • getMailServerPropertySets

        public List<Properties> getMailServerPropertySets()
        Retrieves the sets of information about the mail servers configured for use by the Directory Server.
        Returns:
        The sets of information about the mail servers configured for use by the Directory Server.
      • getMaxAllowedConnections

        public long getMaxAllowedConnections()
        Retrieves the maximum number of connections that will be allowed at any given time.
        Returns:
        the max number of connections allowed
      • getMaxInternalBufferSize

        public int getMaxInternalBufferSize()
        Returns the threshold capacity beyond which internal cached buffers used for encoding and decoding entries and protocol messages will be trimmed after use.
        Returns:
        The threshold capacity beyond which internal cached buffers used for encoding and decoding entries and protocol messages will be trimmed after use.
      • getMaxPSearches

        public int getMaxPSearches()
        Retrieves the maximum number of concurrent persistent searches that will be allowed.
        Returns:
        the max number of persistent searches
      • getProxiedAuthorizationIdentityMapperDN

        public DN getProxiedAuthorizationIdentityMapperDN()
        Retrieves the DN of the configuration entry for the identity mapper that should be used in conjunction with proxied authorization V2 controls.
        Returns:
        The DN of the configuration entry for the identity mapper that should be used in conjunction with proxied authorization V2 controls, or null if none is defined.
      • getServerErrorResultCode

        public ResultCode getServerErrorResultCode()
        Retrieves the result code that should be used when the Directory Server encounters an internal server error.
        Returns:
        The result code that should be used when the Directory Server encounters an internal server error.
      • getSingleStructuralObjectClassPolicy

        public AcceptRejectWarn getSingleStructuralObjectClassPolicy()
        Retrieves the policy that should be used regarding enforcement of a single structural objectclass per entry.
        Returns:
        The policy that should be used regarding enforcement of a single structural objectclass per entry.
      • getSizeLimit

        public int getSizeLimit()
        Retrieves the default maximum number of entries that should be returned for a search.
        Returns:
        The default maximum number of entries that should be returned for a search.
      • getSubordinateBaseDNs

        public Set<DN> getSubordinateBaseDNs()
        Retrieves the restricted set of subordinate base DNs to use when searching the root suffix "".
        Returns:
        the subordinate base DNs, which is empty if there is no restriction
      • getSyntaxEnforcementPolicy

        public AcceptRejectWarn getSyntaxEnforcementPolicy()
        Retrieves the policy that should be used when an attribute value is found that is not valid according to the associated attribute syntax.
        Returns:
        The policy that should be used when an attribute value is found that is not valid according to the associated attribute syntax.
      • getTimeLimit

        public int getTimeLimit()
        Retrieves the default maximum length of time in seconds that should be allowed when processing a search.
        Returns:
        The default maximum length of time in seconds that should be allowed when processing a search.
      • getWritabilityMode

        public WritabilityMode getWritabilityMode()
        Retrieves the writability mode for the Directory Server. This will only be applicable for user suffixes.
        Returns:
        The writability mode for the Directory Server.
      • isAddMissingRDNAttributes

        public boolean isAddMissingRDNAttributes()
        Indicates whether the Directory Server should automatically add missing RDN attributes to an entry whenever it is added.
        Returns:
        true if the Directory Server should automatically add missing RDN attributes to an entry, or false if it should return an error to the client.
      • isAllowAttributeNameExceptions

        @Deprecated
        public boolean isAllowAttributeNameExceptions()
        Deprecated.
        The schema option SchemaOptions.ALLOW_MALFORMED_NAMES_AND_OPTIONS from the schema should be used instead
        Indicates whether to be more flexible in the set of characters allowed for attribute names. The standard requires that only ASCII alphabetic letters, numeric digits, and hyphens be allowed, and that the name start with a letter. If attribute name exceptions are enabled, then underscores will also be allowed, and the name will be allowed to start with a digit.
        Returns:
        true if the server should use a more flexible syntax for attribute names, or false if not.
      • isBindWithDNRequiresPassword

        public boolean isBindWithDNRequiresPassword()
        Indicates whether simple bind requests that contain a bind DN will also be required to have a password.
        Returns:
        true if simple bind requests containing a bind DN will be required to have a password, or false if not (and therefore will be treated as anonymous binds).
      • isCheckSchema

        public boolean isCheckSchema()
        Indicates whether the Directory Server should perform schema checking.
        Returns:
        true if the Directory Server should perform schema checking, or false if not.
      • isDisabled

        public boolean isDisabled​(Privilege privilege)
        Indicates whether the specified privilege is disabled.
        Parameters:
        privilege - The privilege for which to make the determination.
        Returns:
        true if the specified privilege is disabled, or false if not.
      • isMailServerConfigured

        public boolean isMailServerConfigured()
        Indicates whether the Directory Server is configured with information about one or more mail servers and may therefore be used to send e-mail messages.
        Returns:
        true if the Directory Server is configured to be able to send e-mail messages, or false if not.
      • isNotifyAbandonedOperations

        public boolean isNotifyAbandonedOperations()
        Indicates whether the Directory Server should send a response to an operation that has been abandoned. Sending such a response is technically a violation of the LDAP protocol specification, but not doing so in that case can cause problems with clients that are expecting a response and may hang until they get one.
        Returns:
        true if the Directory Server should send a response to an operation that has been abandoned, or false if not.
      • isRejectUnauthenticatedRequests

        public boolean isRejectUnauthenticatedRequests()
        Indicates whether unauthenticated requests should be rejected.
        Returns:
        true if unauthenticated request should be rejected, false otherwise.
      • isReturnBindErrorMessages

        public boolean isReturnBindErrorMessages()
        Indicates whether responses to failed bind operations should include a message explaining the reason for the failure.
        Returns:
        true if bind responses should include error messages, or false if not.
      • isUseNanoTime

        public boolean isUseNanoTime()
        Retrieves whether operation processing times should be collected with nanosecond resolution.
        Returns:
        true if nanosecond resolution times are collected or false if only millisecond resolution times are being collected.
      • isSaveConfigOnSuccessfulStartup

        public boolean isSaveConfigOnSuccessfulStartup()
        Indicates whether configuration should be saved on successful startup of the server.
        Returns:
        true if configuration should be saved, false otherwise.