OIDs for supported and enabled capabilities
The provided table shows OIDs for supported and enabled capabilities. You can use these OIDs to see if a particular server supports these features.
| Short name with OID | Description | Supported by IBM® Security Directory Base Server v10.0.2 | Supported by IBM Security Directory Proxy Server v10.0.2 | |
|---|---|---|---|---|
| Without partitioned data | With partitioned data | |||
| Enhanced Replication Model 1.3.18.0.2.32.1 |
Identifies the replication model including subtree and cascading replication. | Yes | N/A | N/A |
| EntryChecksum 1.3.18.0.2.32.2 |
Indicates that this server supports the ibm-entrychecksum and ibm-entrychecksumop features. | Yes | Yes | Yes |
| Entry UUID 1.3.18.0.2.32.3 |
This value is listed in the ibm-capabilities Subentry for those suffixes that support the ibm-entryuuid attribute. | Yes | Yes | Yes |
| Filter ACLs 1.3.18.0.2.32.4 |
Identifies that this server supports the IBM Filter ACL model | Yes | Yes | Yes |
| Password Policy 1.3.18.0.2.32.5 |
Identifies that this server supports password policies | Yes | Yes | Yes |
| Sort by DN 1.3.18.0.2.32.6 |
Enables searches sorted by DNs in addition to regular attributes. | Yes | No | No |
| Administration Group Delegation 1.3.18.0.2.32.8 |
Server supports the delegation of server administration to a group of administrators that are specified in the configuration backend. | Yes | Yes | Yes |
| Denial of Service Prevention 1.3.18.0.2.32.9 |
Server supports the denial of service prevention feature including read/write time-outs. | Yes | Yes | Yes |
| Dereference Alias Option 1.3.18.0.2.32.10 |
Server supports an option to not dereference
aliases by default * Proxy rootDSE does not list ** Aliases across partitions are not dereferenced |
Yes | Yes(*) | Yes(**) |
| Admin Server Audit Logging 1.3.18.0.2.32.11 |
Server supports the auditing of the admin server. | Yes | Yes | Yes |
| 128 Character Table Names 1.3.18.0.2.32.12 |
The server feature to allow name of unique attributes
to be higher than 18 characters (with the maximum of 128 characters). * Proxy rootDSE does not list ** Uniqueness is not guaranteed across partitions |
Yes | Yes(*) | Yes(**) |
| Attribute Caching Search Filter Resolution 1.3.18.0.2.32.13 |
The server supports attribute caching for search filter resolution. | Yes | N/A | N/A |
| Dynamic Tracing 1.3.18.0.2.32.14 |
Server supports active tracing for the server with an LDAP extended operation. | Yes | Yes | Yes |
| Entry And Subtree Dynamic Updates 1.3.18.0.2.32.15 |
The server supports dynamic configuration updates on entries and subtrees. | Yes | Yes | Yes |
| Globally Unique Attributes 1.3.18.0.2.32.16 |
The server feature to enforce globally unique attribute values. | Yes | No | No |
| Group-Specific Search Limits 1.3.18.0.2.32.17 |
Supports extended search limits for a group
of people. * Proxy rootDSE does not list ** Group Based Search limits don't work consistently when data is partitioned |
Yes | Yes(*) | Yes(**) |
| IBMpolicies Replication Subtree 1.3.18.0.2.32.18 |
Server supports the replication of the cn=IBMpolicies subtree. | Yes | Yes | Yes |
| Max Age ChangeLog Entries 1.3.18.0.2.32.19 |
Specifies that the server is capable of retaining changelog entries based on age. | Yes | N/A | N/A |
| Monitor Logging Counts 1.3.18.0.2.32.20 |
The server provides monitor logging counts for messages added to server, command-line interface, and audit log files. | Yes | Yes | Yes |
| Monitor Active Workers Information 1.3.18.0.2.32.21 |
The server provides monitor information for active workers (cn=workers,cn=monitor). | Yes | Yes | Yes |
| Monitor Connection Type Counts 1.3.18.0.2.32.22 |
The server provides monitor connection type counts for SSL and TLS connections. | Yes | Yes | Yes |
| Monitor Connections Information 1.3.18.0.2.32.23 |
The server provides monitor information for connections by IP address instead of connection ID (cn=connections, cn=monitor) | Yes | Yes | Yes |
| Monitor Operation Counts 1.3.18.0.2.32.24 |
The server provides new monitor operation counts
for initiated and completed operation types. * The operations completed counts do not reflect actual operations completed in the proxy.Instead it represents operations that are either completed or have been sent to a backend server for processing.Proxy Specific Monitors should be used in Security Verify Directory 6.1 and above versions. |
Yes | Yes(*) | Yes(*) |
| Monitor Tracing Info 1.3.18.0.2.32.25 |
The server provides monitor information for tracing options currently being used. | Yes | Yes | Yes |
| Null Base Subtree Search 1.3.18.0.2.32.26 |
Server allows null based subtree search, which searches the entire DIT defined in the server. | Yes | No | No |
| Proxy Authorization 1.3.18.0.2.32.27 |
Server supports Proxy Authorization for a group of users. | Yes | No | No |
| TLS Capabilities 1.3.18.0.2.32.28 |
Specifies that the server is actually capable of doing TLS. | Yes | Yes | Yes |
| Non-Blocking Replication 1.3.18.0.2.32.29 |
The server is capable of ignoring some errors received from a consumer (replica) that would normally cause an update to be re-transmitted periodically until a successful result code was received. | Yes | N/A | N/A |
| Kerberos Capability 1.3.18.0.2.32.30 |
Specifies that the server is capable of using Kerberos. | Yes | No | No |
| ibm-allMembers and ibm-allGroups operational
attributes 1.3.18.0.2.32.31 |
Indicates whether or not a backend supports searching on the ibm-allGroups and ibm-allMembers operational attributes. | Yes | Yes | Yes |
| All operational Attributes 1.3.6.1.4.1.4203.1.5.1 |
All operational Attributes * Proxy rootDSE does not list ** Some operational attributes are dependent on the data not being distributed. |
Yes | Yes(*) | Yes(**) |
| Language Tags 1.3.6.1.4.1.4203.1.5.4 |
Server supports language tags. | Yes | No | No |
| FIPS mode for GSKit 1.3.18.0.2.32.32 |
Enables the server to use the encryption algorithms from the ICC FIPS-certified library | Yes | Yes | Yes |
| Modify DN (leaf move) 1.3.18.0.2.32.35 |
Indicates if modify DN operation supports new
superior for leaf entries.Note that this capability is implied by
the pre-existing Modify DN (subtree move) capability.Applications
should check for both capabilities. * modify DN allowed only if the change does not cross partitions |
Yes | Yes | Yes(*) |
| Simplify resizing of attributes 1.3.18.0.2.32.37 |
Allows customers to increase the maximum length of attributes through the schema modification facilities. | Yes | N/A | N/A |
| Global Administration Group 1.3.18.0.2.32.38 |
Server supports the delegation of server administration to a group of administrators that are specified in the RDBM backend. Global Administrators do not have any authority to the configuration file or log files. | Yes | Yes | Yes |
| AES Encryption Option 1.3.18.0.2.32.39 |
Server supports AES Password Encryption. | Yes | Yes | Yes |
| Auditing of Compare 1.3.18.0.2.32.40 |
Server supports auditing of compare operations. | Yes | Yes | Yes |
| Log Management 1.3.18.0.2.32.41 |
Identifies that this server supports log management. | Yes | Yes | Yes |
| Multi-threaded Replication 1.3.18.0.2.32.42 |
Replication agreements can specify using multiple threads and connections to a consumer. | Yes | N/A | N/A |
| Supplier Replication Configuration 1.3.18.0.2.32.43 |
Server configuration of suppliers for replication. | Yes | N/A | N/A |
| Using CN=IBMPOLICIES for Global Updates 1.3.18.0.2.32.44 |
Server supports the replication of global updates using the replication topology in cn=IBMpolicies subtree. | Yes | N/A | N/A |
| Multihomed configuration support 1.3.18.0.2.32.45 |
Server supports configuration on multiple IP addresses (multihomed). | Yes | Yes | Yes |
| Multiple Directory Server Instances Architecture
1.3.18.0.2.32.46 |
Server is designed to run with multiple directory server instances on the same machine. | Yes | Yes | Yes |
| Configuration Tool Auditing 1.3.18.0.2.32.47 |
Server supports the auditing of the configuration tools. | Yes | Yes | Yes |
| Audit consolidation configuration settings 1.3.18.0.2.32.48 |
Indicates that audit log settings are available in the configuration file. | Yes | Yes | Yes |
| Proxy Server 1.3.18.0.2.32.49 |
Describes whether this server is capable of acting as a proxy server or regular RDBM server. Optional Information. | Yes | Yes | Yes |
| LDAP Attribute Cache Auto Adjust 1.3.18.0.2.32.50 |
Indicates if autonomic attribute cache is supported
and enabled. Note: Starting with the IBM Security
Directory Server 6.3 release, attribute cache is deprecated. Henceforth,
users should avoid using attribute cache. |
Yes | N/A | N/A |
| Replication conflict resolution max entry size
1.3.18.0.2.32.51 |
Based on this number, a supplier may decide if an entry should be re-added to a target server in order to resolve a replication conflict. | Yes | N/A | N/A |
| LostAndFound log file 1.3.18.0.2.32.52 |
Supports LostAndFound file for archiving replaced entries as a result of replication conflict resolution. | Yes | N/A | N/A |
| Password Policy Account Lockout 1.3.18.0.2.32.53 |
Identifies that this server supports password policy Account Locked feature. | Yes | Yes | Yes |
| Password Policy Admin 1.3.18.0.2.32.54 |
Identifies that this server supports Admin Password Policy. | Yes | Yes | Yes |
| SSL Fips processing mode 1.3.18.0.2.32.55 |
Server supports SSL FIPS mode processing. | Yes | Yes | Yes |
| IDS 6.0 ibm-entrychecksumop 1.3.18.0.2.32.56 |
Identifies that the 6.0 version of the ibm-entrychecksumop calculation was used on the server. | Yes | No | No |
| LDAP Password Global Start Time 1.3.18.0.2.32.57 |
Indicates that the server can support ibm-pwdPolicyStartTime attribute in the cn=pwdPolicy entry. | Yes | No | No |
| Audit Configuration Settings Consolidation 1.3.18.0.2.32.58 |
Identifies that the audit configuration settings
are now residing in the ibmslapd configuration file only. * Transactions are supported only when all updates target a single partition. |
Yes | Yes(*) | Yes(*) |
| Encrypted Attribute Support 1.3.18.0.2.32.60 |
Server supports encrypted attributes. | Yes | Yes | Yes |
| Proxy Monitor search 1.3.18.0.2.32.61 |
Server supports special monitor searches intended for proxy server. | No | Yes | Yes |
| SSHA Password Encrypt 1.3.18.0.2.32.63 |
Server supports SSHA Password Encryption. | Yes | Yes | Yes |
| MD5 Password Encrypt 1.3.18.0.2.32.64 |
Server supports MD5 Password Encryption. | Yes | Yes | Yes |
| Filter Replication 1.3.18.0.2.32.65 |
The server feature designed to have only required entries and a subset of its attributes to be replicated. | Yes | N/A | N/A |
| Group Members Cache 1.3.18.0.2.32.66 |
Server supports caching group members. | Yes | N/A | N/A |
| PKCS11 Support 1.3.18.0.2.32.67 |
Server supports PKCS11 Encryption standard. | Yes | Yes | Yes |
| Server Admin Roles 1.3.18.0.2.32.68 |
Server supports Server Administration roles. | Yes | Yes | Yes |
| Digest MD5 Support 1.3.18.0.2.32.69 |
Server supports Digest MD5 Bind. | Yes | Yes | Yes |
| External Bind Support 1.3.18.0.2.32.70 |
Server supports External Bind. | Yes | Yes | Yes |
| Persistent Search 1.3.18.0.2.32.71 |
Server supports persistent search. | Yes | No | No |
| Admin Server Denial of Service Prevention 1.3.18.0.2.32.72 |
Admin Server supports Denial of Service Prevention. | Yes | Yes | Yes |
| Admin server Enhanced Monitor Support 1.3.18.0.2.32.73 |
Admin server supports "cn=monitor", "cn=connections,cn=monitor", and "cn=workers,cn=monitor" searches. | Yes | Yes | Yes |
| Admin Server Support for Schema Searches 1.3.18.0.2.32.74 |
Admin server supports searches on schema. | Yes | Yes | Yes |
| System Monitor Search 1.3.18.0.2.32.76 |
Server supports cn=system,cn=monitor search. | Yes | Yes | Yes |
| Multiple Password Policies 1.3.18.0.2.32.77 |
Server allows multiple password policy to be defined and used. | Yes | Yes | No |
| Passthrough Authentication 1.3.18.0.2.32.78 |
Server supports pass through authentication feature. | Yes | No | No |
| Dynamic Updates of Replication Supplier Request 1.3.18.0.2.32.79 |
Server supports dynamic updates of replication supplier information. | Yes | N/A | N/A |
| Audit Performance 1.3.18.0.2.32.81 |
Server supports auditing of performance for operations. | Yes | Yes | Yes |
| No Emergency Thread Support 1.3.18.0.2.32.82 |
Emergency Thread is not supported by server. | Yes | Yes | Yes |
| Enhanced Replication Group RI handling 1.3.18.0.2.32.83 |
Enhanced Replication Group RI handling | Yes | N/A | N/A |
| Reread the DB2® Password 1.3.18.0.2.32.84 |
Server re-reads the DB2 password to identify any change in DB2 password specified in configuration. | Yes | N/A | N/A |
| Proxy Failback Based on Replication Queue 1.3.18.0.2.32.85 |
Proxy Server will failback only when replication queue is below the threshold specified in configuration file. | No | Yes | Yes |
| Proxy Flow control 1.3.18.0.2.32.86 |
Proxy server supports flow control algorithm. | No | Yes | Yes |
| Backup restore configuration capability 1.3.18.0.2.32.87 |
Server supports configuring automatic backup and restore. | Yes | N/A | N/A |
| Password Policy Max Consecutive repeated characters 1.3.18.0.2.32.88 |
Server supports restricting maximum consecutive repeated characters in password policy. | Yes | Yes | Yes |
| Virtual List View Support 1.3.18.0.2.32.89 |
Server supports virtual list view control in searches. | Yes | No | No |
| Proxy Paged Search 1.3.18.0.2.32.90 |
Proxy Server supports paged control in searches. | No | Yes | Yes |
| Tombstone Support 1.3.18.0.2.32.92 |
Server supports tombstone for deleted entries. | Yes | No | No |
| Proxy Health Check outstanding limit 1.3.18.0.2.32.93 |
Proxy supports identifying a hung server based on the configured outstanding health check requests. | No | Yes | Yes |
| Replication Finegrained timestamps 1.3.18.0.2.32.94 |
Replication uses fine grained timestamp for resolving conflicts. | Yes | N/A | N/A |
| Distributed Dynamic group enabled 1.3.18.0.2.32.96 |
Proxy Server Supports enabling/Disabling Distributed dynamic group configuration option. | No | Yes | Yes |
| Distributed group enabled 1.3.18.0.2.32.97 |
Proxy Server Supports enabling/Disabling Distributed group configuration option. | No | Yes | Yes |
| SHA-2 1.3.18.0.2.32.99 |
Indicates that this server supports SHA-2 family
of algorithms, which include: SHA-224, SHA-256, SHA-384, and SHA-512.
The server also supports the Salted version of the SHA-2 family of
algorithms, which include: SSHA-224, SSHA-256, SSHA-384, and SSHA-512. * SHA-2 is only applicable for servers with database backend. |
Yes | N/A(*) | N/A(*) |
| Pass-through support for LDAP compare operations 1.3.18.0.2.32.100 |
Supports pass-through authentication for LDAP Compare operations | Yes | No | No |
| NIST SP800-131A Suite B 1.3.18.0.2.32.101 |
Supports NIST SP800-131A Suite B, which is a restrictive subset of NIST SP800-131A specification | Yes | Yes | Yes |
| TLS 1.0 protocol 1.3.18.0.2.32.102 |
Indicates that the server supports TLS v1.0 protocol. | Yes | Yes | Yes |
| TLS 1.1 protocol 1.3.18.0.2.32.103 |
Indicates that the server supports TLS v1.1 protocol. | Yes | Yes | Yes |
| TLS 1.2 protocol 1.3.18.0.2.32.104 |
Indicates that the server supports TLS v1.2 protocol. | Yes | Yes | Yes |
| Replication of security attributes 1.3.18.0.2.32.105 |
Indicates that a read-only replica accepts the replication updates for password policy operational attributes. The read-only replica can notify its master servers about a bind operation that affects password policy operational attributes of a user. Indicates that a master server can accept notifications from a read-only replica about a bind operation that affects password policy operational attributes of a user. | Yes | Yes | Yes |
| Record Last Successful Bind Timestamp in User
Entries 1.3.18.0.2.32.106 |
Supports recording of last successful bind and authentication timestamp in the user entries | Yes | No | No |
| Vendor Specific Password Policy Processing in
Pass-through Authentication 1.3.18.0.2.32.107 |
Supports IBM Security Verify Directory for processing login failures from pass-through directories | Yes | No | No |
| Advanced Password Policy 1.3.18.0.2.32.108 |
Supports advanced password policy that has additional password policy rules. | Yes | No | No |
| PBKDF2 Encryption Support 1.3.18.0.2.32.110 |
Indicates that the server can support PBKDF2 family of algorithms for Password Encryption. PBKDF2-SHA1, PBKDF2-SHA224, PBKDF2-SHA256, PBKDF2-SHA384, and PBKDF2-SHA512 |
Yes | Yes | Yes |