A read-only replica records the replication updates with
password policy operational attributes from a master that is based
on the value that is set in the ibm-replicateSecurityAttribute attribute.
To summarize the password policy operational attributes updates
between master and read-only replica, the following conditions are
set:
- Replication is configured.
- Password policy is configured.
- On read-only replica servers, the
ibm-replicareferralURL attribute
is set with the IP address or fully qualified domain name with ports
of all its master servers.
The source from which a read-only replica records the timestamp
in its database might differ based on following conditions:
- The availability of master server.
- The
ibm-replicateSecurityAttribute value on master
server and read-only replica server.
- The bind result.
Table 1. The relationship between the ibm-replicateSecurityAttribute value
and password policy operational attributes update for an invalid bind
on a master serverThe relationship
between the ibm-replicateSecurityAttribute value
and password policy operational attributes update for an invalid bind
on a master server.
| Scenarios |
The ibm-replicateSecurityAttribute attribute
value |
Update to password
policy operational attributes |
|
Master server |
Read-only replica server |
Master server |
Read-only replica server |
| 1 |
TRUE |
TRUE |
YES |
YES* |
| 2 |
TRUE |
FALSE/Not set |
YES |
NO |
| 3 |
FALSE/Not set |
TRUE |
YES |
YES* |
| 4 |
FALSE/Not set |
FALSE/Not set |
YES |
NO |
Note: YES* indicates that the
read-only replica records the replication updates from the master
server to record the password policy operational attributes.
Table 2. The relationship between the ibm-replicateSecurityAttribute value
and password policy operational attributes update for an invalid bind
on a read-only replica serverThe
relationship between the ibm-replicateSecurityAttribute value
and password policy operational attributes update for an invalid bind
on a read-only replica server.
| Scenarios |
The ibm-replicateSecurityAttribute attribute
value |
Notifies an invalid bind with
control |
Acknowledges read-only replica
with timestamp in control |
Update to password
policy operational attributes |
|
Master server |
Read-only replica server |
Read-only replica -> Master |
Master -> Read-only replica |
Master server |
Read-only replica server |
| 1 |
TRUE |
TRUE |
YES |
YES |
YES |
YES |
| 2 |
TRUE |
FALSE/Not set |
NO |
NO |
NO |
YES* |
| 3 |
FALSE/Not set |
TRUE |
YES |
NO |
YES |
YES** |
| 4 |
FALSE/Not set |
FALSE/Not set |
NO |
NO |
NO |
YES* |
Note:
YES* indicates that the read-only replica updates
the password policy operational attributes that are based on the bind
result on the read-only replica. The read-only replica server does
not notify the master server with the password policy operational
attributes update. Therefore, the master server does not replicate
these updates to other servers in the replication topology.
YES** indicates that the read-only replica updates
the password policy operational attributes that are based on the bind
result on the read-only replica. The read-only replica server notifies
the master server with the password policy operational attributes
update. Therefore, the master server replicates these updates to other
servers in the replication topology.
Table 3. The relationship between the ibm-replicateSecurityAttribute value
and password policy operational attributes update for a valid bind
on a master serverThe relationship
between the ibm-replicateSecurityAttribute value
and password policy operational attributes update for a valid bind
on a master server.
| Scenarios |
The ibm-replicateSecurityAttribute attribute
value |
Update to password
policy operational attributes |
|
Master server |
Read-only replica server |
Master server |
Read-only replica server |
| 1 |
TRUE |
TRUE |
YES |
YES* |
| 2 |
TRUE |
FALSE/Not set |
YES |
NO |
| 3 |
FALSE/Not set |
TRUE |
YES |
YES* |
| 4 |
FALSE/Not set |
FALSE/Not set |
YES |
NO |
Note: YES* indicates that the
read-only replica records the replication updates from the master
server to record the password policy operational attributes.
Table 4. The relationship between the ibm-replicateSecurityAttribute value
and password policy operational attributes update for a valid bind
on a read-only replica serverThe
relationship between the ibm-replicateSecurityAttribute value
and password policy operational attributes update for a valid bind
on a read-only replica server.
| Scenarios |
The ibm-replicateSecurityAttribute attribute
value |
Notifies an invalid bind with
control |
Acknowledges read-only replica
with timestamp in control |
Update to password
policy operational attributes |
|
Master server |
Read-only replica server |
Read-only replica -> Master |
Master -> Read-only replica |
Master server |
Read-only replica server |
| 1 |
TRUE |
TRUE |
YES |
YES |
YES |
YES |
| 2 |
TRUE |
FALSE/Not set |
NO |
NO |
NO |
YES* |
| 3 |
FALSE/Not set |
TRUE |
YES |
NO |
YES |
YES** |
| 4 |
FALSE/Not set |
FALSE/Not set |
NO |
NO |
NO |
YES* |
Note:
YES* indicates that the read-only replica updates
the password policy operational attributes that are based on the bind
result on the read-only replica. The read-only replica server does
not notify the master server with the password policy operational
attributes update. Therefore, the master server does not replicate
these updates to other servers in the replication topology.
YES** indicates that the read-only replica updates
the password policy operational attributes that are based on the bind
result on the read-only replica. The read-only replica server notifies
the master server with the password policy operational attributes
update. Therefore, the master server replicates these updates to other
servers in the replication topology.