Known limitations
Use the descriptions of the known limitations in IBM® Security Verify
Directory , version 10.0.3 and later of directory servers to
identify and work around the problems.
Remote migration from Security Directory Server Virtual Appliance 8.0.1.x to IBM Security Verify Directory 10.0.3 on AIX fails with GLPCTL106E error idsldapreplcfg fails to clean up complete replication topology idsldapreplcfg with -r option attempts to clean up the replication topology, but it might leave some of the replication topology entries. idsicrt creates RDBM instance with -x flag instead of Proxy instance. With idsicrt command, RDBM instance is created whereas it Proxy instance should be created when -x is specified. Instance administration GUI tool might hang in some scenarios Instance Administration GUI tool(idsxinst) might hangs if password field is left blankAfter modifying TCP/IP properties instance is shown as started in Config mode only in idsxinst tool. When use modified TCP/IP properties of the instance and tries to restart it in normal mode, the instance starts in normal mode. But idsxinst tool shows it Started(Config only) under Server State. Classpath change is required to print help using the JNDI tools. When use JNDI tools and printing help with -? need to include the xalan.jar file in the classpath. The jar file located in the configuration -> csa_runtime directory .Maximum distinguished name (DN) length The maximum length of the DN or distinguished name is 1000 characters.Command-line utilities allow an option to be entered more than once You can run a command that specifies an option more than once. If an option is specified more than once, the option entered last is used.Invalid data entered on command-line utilities A known limitation is that some types of invalid data that are entered on command-line utilities do not produce an error.No locking mechanism for conflicting commands No locking mechanism exists to prevent conflicting commands from running at the same time for the same directory instance.Unable to drop database On Windows™ systems, you might not be able to drop the database immediately after you stop a directory server instance.Partial replication Partial replication is a replication feature that replicates only the specified entries and a subset of attributes for the specified entries within a subtree. The entries and attributes that are to be replicated are specified by the LDAP administrator. Using partial replication, an administrator can enhance the replication bandwidth according to deployment requirements.Replication is not initiated In a replication environment, if a supplier uses a password encryption setting that is not supported by the consumer, then replication is not initiated.Alias dereferencing does not work In IBM Security Verify Directory , alias dereferencing might not work when persistent search is run on a server with no alias entries.Operation times out Suppose that both proxy and back-end servers are configured to use PKCS#11 mode. They are required to communicate with a remote nCipher cryptographic hardware for SSL operation. In this scenario, the operation times out. To increase the operation timeout duration, you must increase the number of times that a proxy server must try to attempt to establish a connection.Instance stops when nCipher cryptographic hardware client is restarted IBM Security Verify Directory , Version 6.2 or later instance stops when nCipher cryptographic hardware client is restarted.Error with idsldapdiff tool query When you query an entry of large size by using the idsldapdiff tool, an error might occur.Operations error during null base search Operations error is displayed when null base search is run against a proxy server.User account gets locked When the pwdLockout attribute is set to true , the user account might get locked even if the number of invalid bind attempts is less than the pwdMaxFailure value.Possible memory leak with PKCS#11 support configured When you configure a directory server over SSL to use PKCS#11 SYMMETRIC acceleration support, there are chances for memory leak.LDIF files with SHA-2 encrypted password or attributes When you import LDIF files that contain SHA-2 encrypted password or encrypted attributes to versions earlier than 6.3, the data is encrypted based on the value of ibm-slapdPwdEncryption attribute.Multivalued attributes in a virtual list view search Duplicate entries might be returned in a virtual list view search if the sort key is a multivalued attribute.Distributed directory environment search scope In a distributed directory environment, only base scope search with ibm-allMembers is supported.Instance fails to start if system date is modified A directory server instance might fail to start if the system date is modified.Format of the DN gets changed In the configuration file, the format of the DN gets changed when a composite DN is added as suffix.idsdbmaint tool error message The idsdbmaint tool might give an error message, which states that it is unable to estimate the database size. This error is related to the privileges of the instance owner.Error opening filename.cat An error message which states that there is an error opening filename.cat gets displayed when you run a directory server. This error is related to the language pack or locale.The values TRUE and FALSEare not translated The directory server messages do not translate the values TRUE and FALSE to the corresponding locales of the translated version. You can see the issue in the translated versions of IBM Security Verify Directory , the graphical user interface (GUI) tools, such as the Web Administration Tool .Some schema-related keywords are not translated The values of some schema-related keywords such as syntax and matching rules are not translated. You might see the issue in the Web Administration Tool for the translated versions of IBM Security Verify Directory .Date is not displayed properly for the Russian locale You might see the following issue in the translated version of the Web Administration Tool in the Russian locale: Sometimes, the date format either gets displayed in wrong format or the last character of the month name gets truncated. This issue is a limitation with the tool.Date and time are displayed in English in translated versions You can see the following issue on certain panels, such as Manage backup and restore , in the translated versions of the Web Administration Tool : The date and time values that are displayed on the panels are in the English locale instead of the locale of the translated version.Error logo is not displayed with error messages If you access panels on the Web Administration Tool when the directory server is in the stopped state, an error panel is displayed with error messages. However, on this error panel, the error logo is not displayed. This issue is a limitation with the Web Administration Tool .Mnemonics missing from tool panels Mnemonics are missing from the panels of the Instance Administration Tool and Configuration Tool . This limitation in the tools is specific to the French and Korean translated versions.Attribute encryption in RDN of an entry The encrypted attribute of the RDN is displayed in clear text instead of being displayed in the encrypted format. This issue is a known limitation.LDAP search filters that exceed 4K are not supported If an LDAP search filter exceeds the 4K limit, then the server might throw an ldap_search:bad search filter error. To avoid this error, you must use search filters that do not exceed the 4K limit.Error during creation of a directory server instance from an existing instance If the version of DB2® on the source and target server are different, the idsideploy tool displays an error when you create a directory server instance from an existing directory server instance.The idsideploy tool fails to restore a database The idsideploy tool might fail to restore a database if the backup location has backup images of the database.Creation of online backup image fails The idsdbback command might fail to create an online backup image of a directory server instance that is created by the idsideploy tool.Unable to connect from OpenLDAP client over DIGEST-MD5 A directory server instance of version 6.2 fails to authenticate an OpenLDAP client over the DIGEST-MD5 SASL mechanism, if the version of OpenLDAP client is 2.4.11. However, with the directory server instance of version 6.2, you can use OpenLDAP clients version 2.3.33.Inconsistent data when transaction updates are replicated There is a possibility of inconsistent data on a directory server when transaction updates are replicated in an environment with failover setup.Directory server instance creation fails IBM Security Verify Directory might fail to create a directory server instance.Unable to log on to a system When migrated users use the LDAP operating system authentication mechanism, they might not be able to log on to the system. Follow the steps to work around this limitation.Propagated schema updates rejected In some scenarios, a back-end server that is configured as the primary write server might be from earlier versions of IBM Security Verify Directory . In this case, the back-end server rejects the propagated schema updates with an error.Accessibility tool is unable to read messages in the Configuration Tool The Accessibility tool, JAWS, is not able to read the message that is displayed on two dialog boxes of the Configuration Tool , which is a limitation.PBKDF2 password encryption algorithm limitations Known limitations exist with PBKDF2 password encryption.