Class DirectoryServer

  • All Implemented Interfaces:
    AlertGenerator

    public final class DirectoryServer
    extends Object
    implements AlertGenerator
    This class defines the core of the Directory Server. It manages the startup and shutdown processes and coordinates activities between all other components.
    • Field Detail

      • DEFAULT_TIMEOUT

        public static final int DEFAULT_TIMEOUT
        The default timeout used to start the server in detach mode.
        See Also:
        Constant Field Values
    • Method Detail

      • getInstance

        public static DirectoryServer getInstance()
        Retrieves the instance of the Directory Server that is associated with this JVM.
        Returns:
        The instance of the Directory Server that is associated with this JVM.
      • getEnvironmentConfig

        public static DirectoryEnvironmentConfig getEnvironmentConfig()
        Retrieves the environment configuration for the Directory Server.
        Returns:
        The environment configuration for the Directory Server.
      • setEnvironmentConfig

        public void setEnvironmentConfig​(DirectoryEnvironmentConfig config)
                                  throws InitializationException
        Sets the environment configuration for the Directory Server. This method may only be invoked when the server is not running.
        Parameters:
        config - The environment configuration for the Directory Server.
        Throws:
        InitializationException - If the Directory Server is currently running.
      • getServerContext

        public ServerContext getServerContext()
        Returns the server context.
        Returns:
        the server context
      • isRunning

        public static boolean isRunning()
        Indicates whether the Directory Server is currently running.
        Returns:
        true if the server is currently running, or false if not.
      • bootstrapClient

        public static void bootstrapClient()
        Bootstraps the appropriate Directory Server structures that may be needed by both server and client-side tools.
      • initializeJMX

        public static void initializeJMX()
                                  throws InitializationException
        Performs a minimal set of JMX initialization. This may be used by the core Directory Server or by command-line tools.
        Throws:
        InitializationException - If a problem occurs while attempting to initialize the JMX subsystem.
      • initializeConfiguration

        public void initializeConfiguration​(String configFile)
                                     throws InitializationException
        Instantiates the configuration handler and loads the Directory Server configuration.
        Parameters:
        configFile - The path to the file that will hold either the entire server configuration or enough information to allow the server to access the configuration in some other repository.
        Throws:
        InitializationException - If a problem occurs while trying to initialize the config handler.
      • initializeConfiguration

        public void initializeConfiguration()
                                     throws InitializationException
        Initializes the configuration.

        Creates the configuration handler, the server management context and the configuration backend.

        Throws:
        InitializationException - If an error occurs.
      • getConfigFile

        public static String getConfigFile()
        Retrieves the path to the configuration file used to initialize the Directory Server.
        Returns:
        The path to the configuration file used to initialize the Directory Server.
      • startServer

        public void startServer()
                         throws ConfigException,
                                InitializationException
        Starts up the Directory Server. It must have already been bootstrapped and cannot be running.
        Throws:
        ConfigException - If there is a problem with the Directory Server configuration that prevents a critical component from being instantiated.
        InitializationException - If some other problem occurs while attempting to initialize and start the Directory Server.
      • getAuthenticatedUsers

        public static AuthenticatedUsers getAuthenticatedUsers()
        Retrieves the authenticated users manager for the Directory Server.
        Returns:
        The authenticated users manager for the Directory Server.
      • getCryptoManager

        public static CryptoManagerImpl getCryptoManager()
        Retrieves a reference to the Directory Server crypto manager.
        Returns:
        A reference to the Directory Server crypto manager.
      • initializeSchema

        public void initializeSchema()
                              throws InitializationException,
                                     ConfigException
        Initializes the schema handler, which is responsible for building the complete schema for the server.
        Throws:
        ConfigException - If there is a configuration problem with any of the schema elements.
        InitializationException - If a problem occurs while initializing the schema that is not related to the server configuration.
      • getDefaultCompressedSchema

        public static CompressedSchema getDefaultCompressedSchema()
        Retrieves the default compressed schema manager for the Directory Server.
        Returns:
        The default compressed schema manager for the Directory Server.
      • getGroupManager

        public static GroupManager getGroupManager()
        Retrieves the Directory Server group manager.
        Returns:
        The Directory Server group manager.
      • getSubentryManager

        public static SubentryManager getSubentryManager()
        Retrieves the Directory Server subentry manager.
        Returns:
        The Directory Server subentry manager.
      • getOperatingSystem

        public static OperatingSystem getOperatingSystem()
        Retrieves the operating system on which the Directory Server is running.
        Returns:
        The operating system on which the Directory Server is running.
      • getPluginConfigManager

        public static PluginConfigManager getPluginConfigManager()
        Retrieves a reference to the Directory Server plugin configuration manager.
        Returns:
        A reference to the Directory Server plugin configuration manager.
      • registerInternalPlugin

        public static void registerInternalPlugin​(InternalDirectoryServerPlugin plugin)
        Registers the provided internal plugin with the Directory Server and ensures that it will be invoked in the specified ways.
        Parameters:
        plugin - The internal plugin to register with the Directory Server. The plugin must specify a configuration entry which is guaranteed to be unique.
      • deregisterInternalPlugin

        public static void deregisterInternalPlugin​(InternalDirectoryServerPlugin plugin)
        Deregisters the provided internal plugin with the Directory Server.
        Parameters:
        plugin - The internal plugin to deregister from the Directory Server.
      • getConfigEntry

        @Deprecated
        public static Entry getConfigEntry​(DN entryDN)
                                    throws ConfigException
        Deprecated.
        use getEntry(DN) when possible
        Retrieves the requested entry from the Directory Server configuration.

        The main difference with getEntry(DN) is that virtual attributes are not processed. This is important when the whole directory server is not initialized yet (when initializing all backends).

        Parameters:
        entryDN - The DN of the configuration entry to retrieve.
        Returns:
        The requested entry from the Directory Server configuration.
        Throws:
        ConfigException - If a problem occurs while trying to retrieve the requested entry.
      • getServerRoot

        public static String getServerRoot()
        Retrieves the path to the root directory for this instance of the Directory Server.
        Returns:
        The path to the root directory for this instance of the Directory Server.
      • getInstanceRoot

        public static String getInstanceRoot()
        Retrieves the path to the instance directory for this instance of the Directory Server.
        Returns:
        The path to the instance directory for this instance of the Directory Server.
      • getStartTime

        public static long getStartTime()
        Retrieves the time that the Directory Server was started, in milliseconds since the epoch.
        Returns:
        The time that the Directory Server was started, in milliseconds since the epoch.
      • getStartTimeUTC

        public static String getStartTimeUTC()
        Retrieves the time that the Directory Server was started, formatted in UTC.
        Returns:
        The time that the Directory Server was started, formatted in UTC.
      • getVirtualAttributes

        public static Collection<VirtualAttributeRule> getVirtualAttributes()
        Retrieves the set of virtual attribute rules registered with the Directory Server.
        Returns:
        The set of virtual attribute rules registered with the Directory Server.
      • getVirtualAttributes

        public static List<VirtualAttributeRule> getVirtualAttributes​(Entry entry)
        Retrieves the set of virtual attribute rules registered with the Directory Server that are applicable to the provided entry.
        Parameters:
        entry - The entry for which to retrieve the applicable virtual attribute rules.
        Returns:
        The set of virtual attribute rules registered with the Directory Server that apply to the given entry. It may be an empty list if there are no applicable virtual attribute rules.
      • registerVirtualAttribute

        public static void registerVirtualAttribute​(VirtualAttributeRule rule)
        Registers the provided virtual attribute rule with the Directory Server.
        Parameters:
        rule - The virtual attribute rule to be registered.
      • deregisterVirtualAttribute

        public static void deregisterVirtualAttribute​(VirtualAttributeRule rule)
        Deregisters the provided virtual attribute rule with the Directory Server.
        Parameters:
        rule - The virtual attribute rule to be deregistered.
      • getJMXMBeanServer

        public static MBeanServer getJMXMBeanServer()
        Retrieves a reference to the JMX MBean server that is associated with the Directory Server.
        Returns:
        The JMX MBean server that is associated with the Directory Server.
      • getJMXMBeans

        public static Collection<JMXMBean> getJMXMBeans()
        Retrieves the set of JMX MBeans that are associated with the server.
        Returns:
        The set of JMX MBeans that are associated with the server.
      • getJMXMBean

        public static JMXMBean getJMXMBean​(DN configEntryDN)
        Retrieves the JMX MBean associated with the specified entry in the Directory Server configuration.
        Parameters:
        configEntryDN - The DN of the configuration entry for which to retrieve the associated JMX MBean.
        Returns:
        The JMX MBean associated with the specified entry in the Directory Server configuration, or null if there is no MBean for the specified entry.
      • registerAlertGenerator

        public static void registerAlertGenerator​(AlertGenerator alertGenerator)
        Registers the provided alert generator with the Directory Server.
        Parameters:
        alertGenerator - The alert generator to register.
      • deregisterAlertGenerator

        public static void deregisterAlertGenerator​(AlertGenerator alertGenerator)
        Deregisters the provided alert generator with the Directory Server.
        Parameters:
        alertGenerator - The alert generator to deregister.
      • getAlertHandlers

        public static List<AlertHandler<?>> getAlertHandlers()
        Retrieves the set of alert handlers that have been registered with the Directory Server.
        Returns:
        The set of alert handlers that have been registered with the Directory Server.
      • registerAlertHandler

        public static void registerAlertHandler​(AlertHandler<?> alertHandler)
        Registers the provided alert handler with the Directory Server.
        Parameters:
        alertHandler - The alert handler to register.
      • deregisterAlertHandler

        public static void deregisterAlertHandler​(AlertHandler<?> alertHandler)
        Deregisters the provided alert handler with the Directory Server.
        Parameters:
        alertHandler - The alert handler to deregister.
      • sendAlertNotification

        public static void sendAlertNotification​(AlertGenerator generator,
                                                 String alertType,
                                                 org.forgerock.i18n.LocalizableMessage alertMessage)
        Sends an alert notification with the provided information.
        Parameters:
        generator - The alert generator that created the alert.
        alertType - The alert type name for this alert.
        alertMessage - A message (possibly null) that can
      • getPasswordStorageScheme

        public static PasswordStorageScheme<?> getPasswordStorageScheme​(DN configEntryDN)
        Retrieves the password storage scheme defined in the specified configuration entry.
        Parameters:
        configEntryDN - The DN of the configuration entry that defines the password storage scheme to retrieve.
        Returns:
        The requested password storage scheme, or null if no such scheme is defined.
      • getPasswordStorageSchemes

        public static Collection<PasswordStorageScheme<?>> getPasswordStorageSchemes()
        Retrieves the set of password storage schemes defined in the Directory Server, as a mapping between the all-lowercase scheme name and the corresponding implementation.
        Returns:
        The set of password storage schemes defined in the Directory Server.
      • getPasswordStorageScheme

        public static PasswordStorageScheme<?> getPasswordStorageScheme​(String lowerName)
        Retrieves the specified password storage scheme.
        Parameters:
        lowerName - The name of the password storage scheme to retrieve, formatted in all lowercase characters.
        Returns:
        The requested password storage scheme, or null if no such scheme is defined.
      • getAuthPasswordStorageSchemes

        public static ConcurrentHashMap<String,​PasswordStorageScheme<?>> getAuthPasswordStorageSchemes()
        Retrieves the set of authentication password storage schemes defined in the Directory Server, as a mapping between the scheme name and the corresponding implementation.
        Returns:
        The set of authentication password storage schemes defined in the Directory Server.
      • getAuthPasswordStorageScheme

        public static PasswordStorageScheme<?> getAuthPasswordStorageScheme​(String name)
        Retrieves the specified authentication password storage scheme.
        Parameters:
        name - The case-sensitive name of the authentication password storage scheme to retrieve.
        Returns:
        The requested authentication password storage scheme, or null if no such scheme is defined.
      • registerPasswordStorageScheme

        public static void registerPasswordStorageScheme​(DN configEntryDN,
                                                         PasswordStorageScheme<?> scheme)
        Registers the provided password storage scheme with the Directory Server. If an existing password storage scheme is registered with the same name, then it will be replaced with the provided scheme.
        Parameters:
        configEntryDN - The DN of the configuration entry that defines the password storage scheme.
        scheme - The password storage scheme to register with the Directory Server.
      • deregisterPasswordStorageScheme

        public static void deregisterPasswordStorageScheme​(DN configEntryDN)
        Deregisters the specified password storage scheme with the Directory Server. If no scheme is registered with the specified name, then no action will be taken.
        Parameters:
        configEntryDN - The DN of the configuration entry that defines the password storage scheme.
      • getPasswordValidator

        public static PasswordValidator<? extends PasswordValidatorCfg> getPasswordValidator​(DN configEntryDN)
        Retrieves the password validator registered with the provided configuration entry DN.
        Parameters:
        configEntryDN - The DN of the configuration entry for which to retrieve the associated password validator.
        Returns:
        The requested password validator, or null if no such validator is defined.
      • registerPasswordValidator

        public static void registerPasswordValidator​(DN configEntryDN,
                                                     PasswordValidator<? extends PasswordValidatorCfg> validator)
        Registers the provided password validator for use with the Directory Server.
        Parameters:
        configEntryDN - The DN of the configuration entry that defines the specified password validator.
        validator - The password validator to register with the Directory Server.
      • deregisterPasswordValidator

        public static void deregisterPasswordValidator​(DN configEntryDN)
        Deregisters the provided password validator for use with the Directory Server.
        Parameters:
        configEntryDN - The DN of the configuration entry that defines the password validator to deregister.
      • getAccountStatusNotificationHandler

        public static AccountStatusNotificationHandler<?> getAccountStatusNotificationHandler​(DN handlerDN)
        Retrieves the account status notification handler with the specified configuration entry DN.
        Parameters:
        handlerDN - The DN of the configuration entry associated with the account status notification handler to retrieve.
        Returns:
        The requested account status notification handler, or null if no such handler is defined in the server.
      • registerAccountStatusNotificationHandler

        public static void registerAccountStatusNotificationHandler​(DN handlerDN,
                                                                    AccountStatusNotificationHandler<?> handler)
        Registers the provided account status notification handler with the Directory Server.
        Parameters:
        handlerDN - The DN of the configuration entry that defines the provided account status notification handler.
        handler - The account status notification handler to register with the Directory Server.
      • deregisterAccountStatusNotificationHandler

        public static void deregisterAccountStatusNotificationHandler​(DN handlerDN)
        Deregisters the specified account status notification handler with the Directory Server.
        Parameters:
        handlerDN - The DN of the configuration entry for the account status notification handler to deregister.
      • getPasswordGenerator

        public static PasswordGenerator<?> getPasswordGenerator​(DN configEntryDN)
        Retrieves the password generator registered with the provided configuration entry DN.
        Parameters:
        configEntryDN - The DN of the configuration entry for which to retrieve the associated password generator.
        Returns:
        The requested password generator, or null if no such generator is defined.
      • registerPasswordGenerator

        public static void registerPasswordGenerator​(DN configEntryDN,
                                                     PasswordGenerator<?> generator)
        Registers the provided password generator for use with the Directory Server.
        Parameters:
        configEntryDN - The DN of the configuration entry that defines the specified password generator.
        generator - The password generator to register with the Directory Server.
      • deregisterPasswordGenerator

        public static void deregisterPasswordGenerator​(DN configEntryDN)
        Deregisters the provided password generator for use with the Directory Server.
        Parameters:
        configEntryDN - The DN of the configuration entry that defines the password generator to deregister.
      • getAuthenticationPolicies

        public static Collection<AuthenticationPolicy> getAuthenticationPolicies()
        Returns an unmodifiable collection containing all of the authentication policies registered with the Directory Server. The references returned are to the actual authentication policy objects currently in use by the directory server and the referenced objects must not be modified.
        Returns:
        The unmodifiable collection containing all of the authentication policies registered with the Directory Server.
      • getAuthenticationPolicy

        public static AuthenticationPolicy getAuthenticationPolicy​(DN configEntryDN)
        Retrieves the authentication policy registered for the provided configuration entry.
        Parameters:
        configEntryDN - The DN of the configuration entry for which to retrieve the associated authentication policy.
        Returns:
        The authentication policy registered for the provided configuration entry, or null if there is no such policy.
      • registerAuthenticationPolicy

        public static void registerAuthenticationPolicy​(DN configEntryDN,
                                                        AuthenticationPolicy policy)
        Registers the provided authentication policy with the Directory Server. If a policy is already registered for the provided configuration entry DN, then it will be replaced.
        Parameters:
        configEntryDN - The DN of the configuration entry that defines the authentication policy.
        policy - The authentication policy to register with the server.
      • deregisterAuthenticationPolicy

        public static void deregisterAuthenticationPolicy​(DN configEntryDN)
        Deregisters the provided authentication policy with the Directory Server. If no such policy is registered, then no action will be taken.
        Parameters:
        configEntryDN - The DN of the configuration entry that defines the authentication policy to deregister.
      • resetDefaultPasswordPolicy

        public static void resetDefaultPasswordPolicy()
        Resets the default password policy to null.
      • getDefaultPasswordPolicy

        public static PasswordPolicy getDefaultPasswordPolicy()
        Retrieves the default password policy for the Directory Server. This method is equivalent to invoking getAuthenticationPolicy on the DN returned from DirectoryServer.getDefaultPasswordPolicyDN().
        Returns:
        The default password policy for the Directory Server.
      • getRotationPolicy

        public static RotationPolicy<?> getRotationPolicy​(DN configEntryDN)
        Retrieves the log rotation policy registered for the provided configuration entry.
        Parameters:
        configEntryDN - The DN of the configuration entry for which to retrieve the associated rotation policy.
        Returns:
        The rotation policy registered for the provided configuration entry, or null if there is no such policy.
      • registerRotationPolicy

        public static void registerRotationPolicy​(DN configEntryDN,
                                                  RotationPolicy<?> policy)
        Registers the provided log rotation policy with the Directory Server. If a policy is already registered for the provided configuration entry DN, then it will be replaced.
        Parameters:
        configEntryDN - The DN of the configuration entry that defines the password policy.
        policy - The rotation policy to register with the server.
      • deregisterRotationPolicy

        public static void deregisterRotationPolicy​(DN configEntryDN)
        Deregisters the provided log rotation policy with the Directory Server. If no such policy is registered, then no action will be taken.
        Parameters:
        configEntryDN - The DN of the configuration entry that defines the rotation policy to deregister.
      • getRetentionPolicy

        public static RetentionPolicy<?> getRetentionPolicy​(DN configEntryDN)
        Retrieves the log retention policy registered for the provided configuration entry.
        Parameters:
        configEntryDN - The DN of the configuration entry for which to retrieve the associated retention policy.
        Returns:
        The retention policy registered for the provided configuration entry, or null if there is no such policy.
      • registerRetentionPolicy

        public static void registerRetentionPolicy​(DN configEntryDN,
                                                   RetentionPolicy<?> policy)
        Registers the provided log retention policy with the Directory Server. If a policy is already registered for the provided configuration entry DN, then it will be replaced.
        Parameters:
        configEntryDN - The DN of the configuration entry that defines the password policy.
        policy - The retention policy to register with the server.
      • deregisterRetentionPolicy

        public static void deregisterRetentionPolicy​(DN configEntryDN)
        Deregisters the provided log retention policy with the Directory Server. If no such policy is registered, then no action will be taken.
        Parameters:
        configEntryDN - The DN of the configuration entry that defines the retention policy to deregister.
      • getMonitorProviders

        public static ConcurrentMap<String,​MonitorProvider<? extends MonitorProviderCfg>> getMonitorProviders()
        Retrieves the set of monitor providers that have been registered with the Directory Server, as a mapping between the monitor name (in all lowercase characters) and the monitor implementation.
        Returns:
        The set of monitor providers that have been registered with the Directory Server.
      • registerMonitorProvider

        public static void registerMonitorProvider​(MonitorProvider<? extends MonitorProviderCfg> monitorProvider)
        Registers the provided monitor provider with the Directory Server. Note that if a monitor provider is already registered with the specified name, then it will be replaced with the provided implementation.
        Parameters:
        monitorProvider - The monitor provider to register with the Directory Server.
      • deregisterMonitorProvider

        public static void deregisterMonitorProvider​(MonitorProvider<? extends MonitorProviderCfg> monitorProvider)
        Deregisters the specified monitor provider from the Directory Server. If no such monitor provider is registered, no action will be taken.
        Parameters:
        monitorProvider - The monitor provider to deregister from the Directory Server.
      • getEntryCache

        public static EntryCache<?> getEntryCache()
        Retrieves the entry cache for the Directory Server.
        Returns:
        The entry cache for the Directory Server.
      • setEntryCache

        public static void setEntryCache​(EntryCache<?> entryCache)
        Specifies the entry cache that should be used by the Directory Server. This should only be called by the entry cache configuration manager.
        Parameters:
        entryCache - The entry cache for the Directory Server.
      • getKeyManagerProvider

        public static KeyManagerProvider<?> getKeyManagerProvider​(DN providerDN)
        Retrieves the key manager provider registered with the provided entry DN.
        Parameters:
        providerDN - The DN with which the key manager provider is registered.
        Returns:
        The key manager provider registered with the provided entry DN, or null if there is no such key manager provider registered with the server.
      • registerKeyManagerProvider

        public static void registerKeyManagerProvider​(DN providerDN,
                                                      KeyManagerProvider<?> provider)
        Registers the provided key manager provider with the Directory Server.
        Parameters:
        providerDN - The DN with which to register the key manager provider.
        provider - The key manager provider to register with the server.
      • deregisterKeyManagerProvider

        public static void deregisterKeyManagerProvider​(DN providerDN)
        Deregisters the specified key manager provider with the Directory Server.
        Parameters:
        providerDN - The DN with which the key manager provider is registered.
      • getTrustManagerProvider

        public static TrustManagerProvider<?> getTrustManagerProvider​(DN providerDN)
        Retrieves the trust manager provider registered with the provided entry DN.
        Parameters:
        providerDN - The DN with which the trust manager provider is registered.
        Returns:
        The trust manager provider registered with the provided entry DN, or null if there is no such trust manager provider registered with the server.
      • registerTrustManagerProvider

        public static void registerTrustManagerProvider​(DN providerDN,
                                                        TrustManagerProvider<?> provider)
        Registers the provided trust manager provider with the Directory Server.
        Parameters:
        providerDN - The DN with which to register the trust manager provider.
        provider - The trust manager provider to register with the server.
      • deregisterTrustManagerProvider

        public static void deregisterTrustManagerProvider​(DN providerDN)
        Deregisters the specified trust manager provider with the Directory Server.
        Parameters:
        providerDN - The DN with which the trust manager provider is registered.
      • getCertificateMapper

        public static CertificateMapper<?> getCertificateMapper​(DN mapperDN)
        Retrieves the certificate mapper registered with the provided entry DN.
        Parameters:
        mapperDN - The DN with which the certificate mapper is registered.
        Returns:
        The certificate mapper registered with the provided entry DN, or null if there is no such certificate mapper registered with the server.
      • registerCertificateMapper

        public static void registerCertificateMapper​(DN mapperDN,
                                                     CertificateMapper<?> mapper)
        Registers the provided certificate mapper with the Directory Server.
        Parameters:
        mapperDN - The DN with which to register the certificate mapper.
        mapper - The certificate mapper to register with the server.
      • deregisterCertificateMapper

        public static void deregisterCertificateMapper​(DN mapperDN)
        Deregisters the specified certificate mapper with the Directory Server.
        Parameters:
        mapperDN - The DN with which the certificate mapper is registered.
      • getRootPrivileges

        public static Set<Privilege> getRootPrivileges()
        Retrieves the set of privileges that should automatically be granted to root users when they authenticate.
        Returns:
        The set of privileges that should automatically be granted to root users when they authenticate.
      • getRootDNs

        public static Set<DN> getRootDNs()
        Retrieves the DNs for the root users configured in the Directory Server. Note that this set should only contain the actual DNs for the root users and not any alternate DNs. Also, the contents of the returned set must not be altered by the caller.
        Returns:
        The DNs for the root users configured in the Directory Server.
      • isRootDN

        public static boolean isRootDN​(DN userDN)
        Indicates whether the provided DN is the DN for one of the root users configured in the Directory Server.
        Parameters:
        userDN - The user DN for which to make the determination.
        Returns:
        true if the provided user DN is a Directory Server root DN, or false if not.
      • registerRootDN

        public static void registerRootDN​(DN rootDN)
        Registers the provided root DN with the Directory Server.
        Parameters:
        rootDN - The root DN to register with the Directory Server.
      • deregisterRootDN

        public static void deregisterRootDN​(DN rootDN)
        Deregisters the provided root DN with the Directory Server. This will have no effect if the provided DN is not registered as a root DN.
        Parameters:
        rootDN - The root DN to deregister.
      • getActualRootBindDN

        public static DN getActualRootBindDN​(DN alternateRootBindDN)
        Retrieves the real entry DN for the root user with the provided alternate bind DN.
        Parameters:
        alternateRootBindDN - The alternate root bind DN for which to retrieve the real entry DN.
        Returns:
        The real entry DN for the root user with the provided alternate bind DN, or null if no such mapping has been defined.
      • registerAlternateRootDN

        public static void registerAlternateRootDN​(DN actualRootEntryDN,
                                                   DN alternateRootBindDN)
                                            throws DirectoryException
        Registers an alternate root bind DN using the provided information.
        Parameters:
        actualRootEntryDN - The actual DN for the root user's entry.
        alternateRootBindDN - The alternate DN that should be interpreted as if it were the provided actual root entry DN.
        Throws:
        DirectoryException - If the provided alternate bind DN is already in use for another root user.
      • deregisterAlternateRootBindDN

        public static DN deregisterAlternateRootBindDN​(DN alternateRootBindDN)
        Deregisters the provided alternate root bind DN from the server. This will have no effect if there was no mapping defined for the provided alternate root bind DN.
        Parameters:
        alternateRootBindDN - The alternate root bind DN to be deregistered.
        Returns:
        The actual root entry DN to which the provided alternate bind DN was mapped, or null if there was no mapping for the provided DN.
      • getSchemaDN

        public static DN getSchemaDN()
        Retrieves the DN of the entry containing the server schema definitions.
        Returns:
        The DN of the entry containing the server schema definitions, or null if none has been defined (e.g., if no schema backend has been configured).
      • setSchemaDN

        public static void setSchemaDN​(DN schemaDN)
        Specifies the DN of the entry containing the server schema definitions.
        Parameters:
        schemaDN - The DN of the entry containing the server schema definitions.
      • getEntry

        public static Entry getEntry​(DN entryDN)
                              throws DirectoryException
        Retrieves the entry with the requested DN. It will first determine which backend should be used for this DN and will then use that backend to retrieve the entry. The caller is not required to hold any locks on the specified DN.
        Parameters:
        entryDN - The DN of the entry to retrieve.
        Returns:
        The requested entry, or null if it does not exist.
        Throws:
        DirectoryException - If a problem occurs while attempting to retrieve the entry.
      • entryExists

        public static boolean entryExists​(DN entryDN)
                                   throws DirectoryException
        Indicates whether the specified entry exists in the Directory Server. The caller is not required to hold any locks when invoking this method.
        Parameters:
        entryDN - The DN of the entry for which to make the determination.
        Returns:
        true if the specified entry exists in one of the backends, or false if it does not.
        Throws:
        DirectoryException - If a problem occurs while attempting to make the determination.
      • getSupportedControls

        public static TreeSet<String> getSupportedControls()
        Retrieves the set of supported controls registered with the Directory Server.
        Returns:
        The set of supported controls registered with the Directory Server.
      • isSupportedControl

        public static boolean isSupportedControl​(String controlOID)
        Indicates whether the specified OID is registered with the Directory Server as a supported control.
        Parameters:
        controlOID - The OID of the control for which to make the determination.
        Returns:
        true if the specified OID is registered with the server as a supported control, or false if not.
      • registerSupportedControl

        public static void registerSupportedControl​(String controlOID)
        Registers the provided OID as a supported control for the Directory Server. This will have no effect if the specified control OID is already present in the list of supported controls.
        Parameters:
        controlOID - The OID of the control to register as a supported control.
      • deregisterSupportedControl

        public static void deregisterSupportedControl​(String controlOID)
        Deregisters the provided OID as a supported control for the Directory Server. This will have no effect if the specified control OID is not present in the list of supported controls.
        Parameters:
        controlOID - The OID of the control to deregister as a supported control.
      • getSupportedFeatures

        public static TreeSet<String> getSupportedFeatures()
        Retrieves the set of supported features registered with the Directory Server.
        Returns:
        The set of supported features registered with the Directory Server.
      • isSupportedFeature

        public static boolean isSupportedFeature​(String featureOID)
        Indicates whether the specified OID is registered with the Directory Server as a supported feature.
        Parameters:
        featureOID - The OID of the feature for which to make the determination.
        Returns:
        true if the specified OID is registered with the server as a supported feature, or false if not.
      • registerSupportedFeature

        public static void registerSupportedFeature​(String featureOID)
        Registers the provided OID as a supported feature for the Directory Server. This will have no effect if the specified feature OID is already present in the list of supported features.
        Parameters:
        featureOID - The OID of the feature to register as a supported feature.
      • deregisterSupportedFeature

        public static void deregisterSupportedFeature​(String featureOID)
        Deregisters the provided OID as a supported feature for the Directory Server. This will have no effect if the specified feature OID is not present in the list of supported features.
        Parameters:
        featureOID - The OID of the feature to deregister as a supported feature.
      • getSupportedExtensions

        public static Set<String> getSupportedExtensions()
        Retrieves the set of extended operations that may be processed by the Directory Server.
        Returns:
        The set of extended operations that may be processed by the Directory Server.
      • getExtendedOperationHandler

        public static ExtendedOperationHandler<?> getExtendedOperationHandler​(String oid)
        Retrieves the handler for the extended operation for the provided OID.
        Parameters:
        oid - The OID of the extended operation to retrieve.
        Returns:
        The handler for the specified extended operation, or null if there is none.
      • registerSupportedExtension

        public static void registerSupportedExtension​(String oid,
                                                      ExtendedOperationHandler<?> handler)
        Registers the provided extended operation handler with the Directory Server.
        Parameters:
        oid - The OID for the extended operation to register.
        handler - The extended operation handler to register with the Directory Server.
      • deregisterSupportedExtension

        public static void deregisterSupportedExtension​(String oid)
        Deregisters the provided extended operation handler with the Directory Server.
        Parameters:
        oid - The OID for the extended operation to deregister.
      • getSupportedSASLMechanisms

        public static Set<String> getSupportedSASLMechanisms()
        Retrieves the set of SASL mechanisms that are supported by the Directory Server.
        Returns:
        The set of SASL mechanisms that are supported by the Directory Server.
      • getSASLMechanismHandler

        public static SASLMechanismHandler<?> getSASLMechanismHandler​(String name)
        Retrieves the handler for the specified SASL mechanism.
        Parameters:
        name - The name of the SASL mechanism to retrieve.
        Returns:
        The handler for the specified SASL mechanism, or null if there is none.
      • registerSASLMechanismHandler

        public static void registerSASLMechanismHandler​(String name,
                                                        SASLMechanismHandler<?> handler)
        Registers the provided SASL mechanism handler with the Directory Server.
        Parameters:
        name - The name of the SASL mechanism to be registered.
        handler - The SASL mechanism handler to register with the Directory Server.
      • deregisterSASLMechanismHandler

        public static void deregisterSASLMechanismHandler​(String name)
        Deregisters the provided SASL mechanism handler with the Directory Server.
        Parameters:
        name - The name of the SASL mechanism to be deregistered.
      • getSupportedLDAPVersions

        public static Set<Integer> getSupportedLDAPVersions()
        Retrieves the supported LDAP versions for the Directory Server.
        Returns:
        The supported LDAP versions for the Directory Server.
      • registerSupportedLDAPVersion

        public static void registerSupportedLDAPVersion​(int supportedLDAPVersion,
                                                        ConnectionHandler<?> connectionHandler)
        Registers the provided LDAP protocol version as supported within the Directory Server.
        Parameters:
        supportedLDAPVersion - The LDAP protocol version to register as supported.
        connectionHandler - The connection handler that supports the provided LDAP version. Note that multiple connection handlers can provide support for the same LDAP versions.
      • deregisterSupportedLDAPVersion

        public static void deregisterSupportedLDAPVersion​(int supportedLDAPVersion,
                                                          ConnectionHandler<?> connectionHandler)
        Deregisters the provided LDAP protocol version as supported within the Directory Server.
        Parameters:
        supportedLDAPVersion - The LDAP protocol version to deregister.
        connectionHandler - The connection handler that no longer supports the provided LDAP version.
      • getIdentityMapper

        public static IdentityMapper<?> getIdentityMapper​(DN configEntryDN)
        Retrieves the Directory Server identity mapper whose configuration resides in the specified configuration entry.
        Parameters:
        configEntryDN - The DN of the configuration entry for the identity mapper to retrieve.
        Returns:
        The requested identity mapper, or null if the provided entry DN is not associated with an active identity mapper.
      • registerIdentityMapper

        public static void registerIdentityMapper​(DN configEntryDN,
                                                  IdentityMapper<?> identityMapper)
        Registers the provided identity mapper for use with the Directory Server.
        Parameters:
        configEntryDN - The DN of the configuration entry in which the identity mapper definition resides.
        identityMapper - The identity mapper to be registered.
      • deregisterIdentityMapper

        public static void deregisterIdentityMapper​(DN configEntryDN)
        Deregisters the provided identity mapper for use with the Directory Server.
        Parameters:
        configEntryDN - The DN of the configuration entry in which the identity mapper definition resides.
      • getProxiedAuthorizationIdentityMapper

        public static IdentityMapper<?> getProxiedAuthorizationIdentityMapper()
        Retrieves the identity mapper that should be used to resolve authorization IDs contained in proxied authorization V2 controls.
        Returns:
        The identity mapper that should be used to resolve authorization IDs contained in proxied authorization V2 controls, or null if none is defined.
      • getConnectionHandlers

        public static List<ConnectionHandler<?>> getConnectionHandlers()
        Retrieves the set of connection handlers configured in the Directory Server. The returned list must not be altered.
        Returns:
        The set of connection handlers configured in the Directory Server.
      • registerConnectionHandler

        public static void registerConnectionHandler​(ConnectionHandler<? extends ConnectionHandlerCfg> handler)
        Registers the provided connection handler with the Directory Server.
        Parameters:
        handler - The connection handler to register with the Directory Server.
      • deregisterConnectionHandler

        public static void deregisterConnectionHandler​(ConnectionHandler<?> handler)
        Deregisters the provided connection handler with the Directory Server.
        Parameters:
        handler - The connection handler to deregister with the Directory Server.
      • getWorkQueue

        public static WorkQueue<?> getWorkQueue()
        Retrieves a reference to the Directory Server work queue.
        Returns:
        A reference to the Directory Server work queue.
      • checkCanEnqueueRequest

        public static void checkCanEnqueueRequest​(Operation operation,
                                                  boolean isAllowedInLockDownMode)
                                           throws DirectoryException
        Runs all the necessary checks prior to adding an operation to the work queue. It throws a DirectoryException if one of the check fails.
        Parameters:
        operation - The operation to be added to the work queue.
        isAllowedInLockDownMode - Flag to indicate if the request can be added to the work queue regardless of the server's lock down mode.
        Throws:
        DirectoryException - If a check failed preventing the operation from being added to the queue
      • enqueueRequest

        public static void enqueueRequest​(Operation operation)
                                   throws DirectoryException
        Adds the provided operation to the work queue so that it will be processed by one of the worker threads.
        Parameters:
        operation - The operation to be added to the work queue.
        Throws:
        DirectoryException - If a problem prevents the operation from being added to the queue (e.g., the queue is full).
      • tryEnqueueRequest

        public static boolean tryEnqueueRequest​(Operation operation)
                                         throws DirectoryException
        Tries to add the provided operation to the work queue if not full so that it will be processed by one of the worker threads.
        Parameters:
        operation - The operation to be added to the work queue.
        Returns:
        true if the operation could be enqueued, false otherwise
        Throws:
        DirectoryException - If a problem prevents the operation from being added to the queue (e.g., the queue is full).
      • getSynchronizationProviders

        public static List<SynchronizationProvider<SynchronizationProviderCfg>> getSynchronizationProviders()
        Retrieves the set of synchronization providers that have been registered with the Directory Server.
        Returns:
        The set of synchronization providers that have been registered with the Directory Server.
      • registerSynchronizationProvider

        public static void registerSynchronizationProvider​(SynchronizationProvider<SynchronizationProviderCfg> provider)
        Registers the provided synchronization provider with the Directory Server.
        Parameters:
        provider - The synchronization provider to register.
      • deregisterSynchronizationProvider

        public static void deregisterSynchronizationProvider​(SynchronizationProvider<?> provider)
        Deregisters the provided synchronization provider with the Directory Server.
        Parameters:
        provider - The synchronization provider to deregister.
      • getCoreConfigManager

        public static CoreConfigManager getCoreConfigManager()
        Returns the core configuration manager.
        Returns:
        the core config manager
      • isDisabled

        public static boolean isDisabled​(Privilege privilege)
        Indicates whether the specified privilege is disabled.
        Parameters:
        privilege - The privilege for which to make the determination.
        Returns:
        true if the specified privilege is disabled, or false if not.
      • getIdleTimeLimit

        public static long getIdleTimeLimit()
        Retrieves the maximum length of time in milliseconds that client connections should be allowed to remain idle without being disconnected.
        Returns:
        The maximum length of time in milliseconds that client connections should be allowed to remain idle without being disconnected.
      • setIdleTimeLimit

        public static void setIdleTimeLimit​(long idleTimeLimit)
        Specifies the maximum length of time in milliseconds that client connections should be allowed to remain idle without being disconnected.
        Parameters:
        idleTimeLimit - The maximum length of time in milliseconds that client connections should be allowed to remain idle without being disconnected.
      • registerBackupTaskListener

        public static void registerBackupTaskListener​(BackupTaskListener listener)
        Registers the provided backup task listener with the Directory Server.
        Parameters:
        listener - The backup task listener to register with the Directory Server.
      • deregisterBackupTaskListener

        public static void deregisterBackupTaskListener​(BackupTaskListener listener)
        Deregisters the provided backup task listener with the Directory Server.
        Parameters:
        listener - The backup task listener to deregister with the Directory Server.
      • notifyBackupBeginning

        public static void notifyBackupBeginning​(LocalBackend<?> backend,
                                                 BackupConfig config)
        Notifies the registered backup task listeners that the server will be beginning a backup task with the provided information.
        Parameters:
        backend - The backend in which the backup is to be performed.
        config - The configuration for the backup to be performed.
      • notifyBackupEnded

        public static void notifyBackupEnded​(LocalBackend<?> backend,
                                             BackupConfig config,
                                             boolean successful)
        Notifies the registered backup task listeners that the server has completed processing on a backup task with the provided information.
        Parameters:
        backend - The backend in which the backup was performed.
        config - The configuration for the backup that was performed.
        successful - Indicates whether the backup completed successfully.
      • registerRestoreTaskListener

        public static void registerRestoreTaskListener​(RestoreTaskListener listener)
        Registers the provided restore task listener with the Directory Server.
        Parameters:
        listener - The restore task listener to register with the Directory Server.
      • deregisterRestoreTaskListener

        public static void deregisterRestoreTaskListener​(RestoreTaskListener listener)
        Deregisters the provided restore task listener with the Directory Server.
        Parameters:
        listener - The restore task listener to deregister with the Directory Server.
      • notifyRestoreBeginning

        public static void notifyRestoreBeginning​(LocalBackend<?> backend,
                                                  RestoreConfig config)
        Notifies the registered restore task listeners that the server will be beginning a restore task with the provided information.
        Parameters:
        backend - The backend in which the restore is to be performed.
        config - The configuration for the restore to be performed.
      • notifyRestoreEnded

        public static void notifyRestoreEnded​(LocalBackend<?> backend,
                                              RestoreConfig config,
                                              boolean successful)
        Notifies the registered restore task listeners that the server has completed processing on a restore task with the provided information.
        Parameters:
        backend - The backend in which the restore was performed.
        config - The configuration for the restore that was performed.
        successful - Indicates whether the restore completed successfully.
      • registerExportTaskListener

        public static void registerExportTaskListener​(ExportTaskListener listener)
        Registers the provided LDIF export task listener with the Directory Server.
        Parameters:
        listener - The export task listener to register with the Directory Server.
      • deregisterExportTaskListener

        public static void deregisterExportTaskListener​(ExportTaskListener listener)
        Deregisters the provided LDIF export task listener with the Directory Server.
        Parameters:
        listener - The export task listener to deregister with the Directory Server.
      • notifyExportBeginning

        public static void notifyExportBeginning​(LocalBackend<?> backend,
                                                 LDIFExportConfig config)
        Notifies the registered LDIF export task listeners that the server will be beginning an export task with the provided information.
        Parameters:
        backend - The backend in which the export is to be performed.
        config - The configuration for the export to be performed.
      • notifyExportEnded

        public static void notifyExportEnded​(LocalBackend<?> backend,
                                             LDIFExportConfig config,
                                             boolean successful)
        Notifies the registered LDIF export task listeners that the server has completed processing on an export task with the provided information.
        Parameters:
        backend - The backend in which the export was performed.
        config - The configuration for the export that was performed.
        successful - Indicates whether the export completed successfully.
      • registerImportTaskListener

        public static void registerImportTaskListener​(ImportTaskListener listener)
        Registers the provided LDIF import task listener with the Directory Server.
        Parameters:
        listener - The import task listener to register with the Directory Server.
      • deregisterImportTaskListener

        public static void deregisterImportTaskListener​(ImportTaskListener listener)
        Deregisters the provided LDIF import task listener with the Directory Server.
        Parameters:
        listener - The import task listener to deregister with the Directory Server.
      • notifyImportBeginning

        public static void notifyImportBeginning​(LocalBackend<?> backend,
                                                 LDIFImportConfig config)
        Notifies the registered LDIF import task listeners that the server will be beginning an import task with the provided information.
        Parameters:
        backend - The backend in which the import is to be performed.
        config - The configuration for the import to be performed.
      • notifyImportEnded

        public static void notifyImportEnded​(LocalBackend<?> backend,
                                             LDIFImportConfig config,
                                             boolean successful)
        Notifies the registered LDIF import task listeners that the server has completed processing on an import task with the provided information.
        Parameters:
        backend - The backend in which the import was performed.
        config - The configuration for the import that was performed.
        successful - Indicates whether the import completed successfully.
      • registerInitializationCompletedListener

        public static void registerInitializationCompletedListener​(InitializationCompletedListener listener)
        Registers the provided initialization completed listener with the Directory Server so that it will be notified when the server initialization completes.
        Parameters:
        listener - The initialization competed listener to register with the Directory Server.
      • deregisterInitializationCompletedListener

        public static void deregisterInitializationCompletedListener​(InitializationCompletedListener listener)
        Deregisters the provided initialization completed listener with the Directory Server.
        Parameters:
        listener - The initialization completed listener to deregister with the Directory Server.
      • registerShutdownListener

        public static void registerShutdownListener​(ServerShutdownListener listener)
        Registers the provided shutdown listener with the Directory Server so that it will be notified when the server shuts down.
        Parameters:
        listener - The shutdown listener to register with the Directory Server.
      • deregisterShutdownListener

        public static void deregisterShutdownListener​(ServerShutdownListener listener)
        Deregisters the provided shutdown listener with the Directory Server.
        Parameters:
        listener - The shutdown listener to deregister with the Directory Server.
      • shutDown

        public static void shutDown​(String className,
                                    org.forgerock.i18n.LocalizableMessage reason)
        Initiates the Directory Server shutdown process. Note that once this has started, it should not be interrupted.
        Parameters:
        className - The fully-qualified name of the Java class that initiated the shutdown.
        reason - The human-readable reason that the directory server is shutting down.
      • restart

        public static void restart​(String className,
                                   org.forgerock.i18n.LocalizableMessage reason)
        Causes the Directory Server to perform an in-core restart. This will cause virtually all components of the Directory Server to shut down, and once that has completed it will be restarted.
        Parameters:
        className - The fully-qualified name of the Java class that initiated the shutdown.
        reason - The human-readable reason that the directory server is shutting down.
      • restart

        public static void restart​(String className,
                                   org.forgerock.i18n.LocalizableMessage reason,
                                   DirectoryEnvironmentConfig config)
        Causes the Directory Server to perform an in-core restart. This will cause virtually all components of the Directory Server to shut down, and once that has completed it will be restarted.
        Parameters:
        className - The fully-qualified name of the Java class that initiated the shutdown.
        reason - The human-readable reason that the directory server is shutting down.
        config - The environment configuration to use for the server.
      • reinitialize

        public static DirectoryServer reinitialize​(DirectoryEnvironmentConfig config)
                                            throws InitializationException
        Reinitializes the server following a shutdown, preparing it for a call to startServer.
        Parameters:
        config - The environment configuration for the Directory Server.
        Returns:
        The new Directory Server instance created during the re-initialization process.
        Throws:
        InitializationException - If a problem occurs while trying to initialize the config handler or bootstrap that server.
      • newConnectionAccepted

        public static long newConnectionAccepted​(ClientConnection clientConnection)
        Indicates that a new connection has been accepted and increments the associated counters.
        Parameters:
        clientConnection - The client connection that has been established.
        Returns:
        The connection ID that should be used for this connection, or -1 if the connection has been rejected for some reason (e.g., the maximum number of concurrent connections have already been established).
      • connectionClosed

        public static void connectionClosed​(ClientConnection clientConnection)
        Indicates that the specified client connection has been closed.
        Parameters:
        clientConnection - The client connection that has been closed.
      • getCurrentConnections

        public static long getCurrentConnections()
        Retrieves the number of client connections that are currently established.
        Returns:
        The number of client connections that are currently established.
      • getMaxConnections

        public static long getMaxConnections()
        Retrieves the maximum number of client connections that have been established concurrently.
        Returns:
        The maximum number of client connections that have been established concurrently.
      • getTotalConnections

        public static long getTotalConnections()
        Retrieves the total number of client connections that have been established since the Directory Server started.
        Returns:
        The total number of client connections that have been established since the Directory Server started.
      • getVersionString

        public static String getVersionString()
        Retrieves the full version string for the Directory Server.
        Returns:
        The full version string for the Directory Server.
      • registerPersistentSearch

        public static void registerPersistentSearch()
        Registers a new persistent search by increasing the count of active persistent searches. After receiving a persistent search request, a Local or Remote WFE must call this method to let the core server manage the count of concurrent persistent searches.
      • deregisterPersistentSearch

        public static void deregisterPersistentSearch()
        Deregisters a canceled persistent search. After a persistent search is canceled, the handler must call this method to let the core server manage the count of concurrent persistent searches.
      • allowNewPersistentSearch

        public static boolean allowNewPersistentSearch()
        Indicates whether a new persistent search is allowed.
        Returns:
        trueif a new persistent search is allowed or falsef if not.
      • lockdownMode

        public static boolean lockdownMode()
        Indicates whether the Directory Server is currently configured to operate in the lockdown mode, in which all non-root requests will be rejected and all connection attempts from non-loopback clients will be rejected.
        Returns:
        true if the Directory Server is currently configured to operate in the lockdown mode, or false if not.
      • setLockdownMode

        public static void setLockdownMode​(boolean lockdownMode)
        Specifies whether the server should operate in lockdown mode.
        Parameters:
        lockdownMode - Indicates whether the Directory Server should operate in lockdown mode.
      • getComponentEntryDN

        public DN getComponentEntryDN()
        Retrieves the DN of the configuration entry with which this alert generator is associated.
        Specified by:
        getComponentEntryDN in interface AlertGenerator
        Returns:
        The DN of the configuration entry with which this alert generator is associated.
      • getClassName

        public String getClassName()
        Retrieves the fully-qualified name of the Java class for this alert generator implementation.
        Specified by:
        getClassName in interface AlertGenerator
        Returns:
        The fully-qualified name of the Java class for this alert generator implementation.
      • getAlerts

        public Map<String,​String> getAlerts()
        Retrieves information about the set of alerts that this generator may produce. The map returned should be between the notification type for a particular notification and the human-readable description for that notification. This alert generator must not generate any alerts with types that are not contained in this list.
        Specified by:
        getAlerts in interface AlertGenerator
        Returns:
        Information about the set of alerts that this generator may produce.
      • isShuttingDown

        public boolean isShuttingDown()
        Indicates whether the server is currently in the process of shutting down.
        Returns:
        true if this server is currently in the process of shutting down and false otherwise.
      • main

        public static void main​(String[] args)
        Parses the provided command-line arguments and uses that information to bootstrap and start the Directory Server.
        Parameters:
        args - The command-line arguments provided to this program.
      • getMonitorProviderDN

        public static DN getMonitorProviderDN​(MonitorProvider<?> provider)
        Construct the DN of a monitor provider entry.
        Parameters:
        provider - The monitor provider for which a DN is desired.
        Returns:
        The DN of the monitor provider entry.
      • getClassLoader

        public static ClassLoader getClassLoader()
        Gets the class loader to be used with this directory server application.

        The class loader will automatically load classes from plugins where required.

        Note: public access is required for compiling the org.opends.server.snmp.SNMPConnectionHandler.

        Returns:
        Returns the class loader to be used with this directory server application.
      • isRunningAsWindowsService

        public static boolean isRunningAsWindowsService()
        Returns true if this server is configured to run as a windows service.
        Returns:
        true if this server is configured to run as a windows service and false otherwise.
      • getLockManager

        public static LockManager getLockManager()
        Returns the lock manager which will be used for coordinating access to LDAP entries.
        Returns:
        the lock manager which will be used for coordinating access to LDAP entries.