Servers in a replication topology with the ibm-replicateSecurityAttribute attribute

A read-only replica records the replication updates with password policy operational attributes from a master that is based on the value that is set in the ibm-replicateSecurityAttribute attribute.

To summarize the password policy operational attributes updates between master and read-only replica, the following conditions are set:

  • Replication is configured.
  • Password policy is configured.
  • On read-only replica servers, the ibm-replicareferralURL attribute is set with the IP address or fully qualified domain name with ports of all its master servers.

The source from which a read-only replica records the timestamp in its database might differ based on following conditions:

  • The availability of master server.
  • The ibm-replicateSecurityAttribute value on master server and read-only replica server.
  • The bind result.
Table 1. The relationship between the ibm-replicateSecurityAttribute value and password policy operational attributes update for an invalid bind on a master server

The relationship between the ibm-replicateSecurityAttribute value and password policy operational attributes update for an invalid bind on a master server.

Scenarios The ibm-replicateSecurityAttribute attribute value Update to password policy operational attributes
Master server Read-only replica server Master server Read-only replica server
1 TRUE TRUE YES YES*
2 TRUE FALSE/Not set YES NO
3 FALSE/Not set TRUE YES YES*
4 FALSE/Not set FALSE/Not set YES NO
Note: YES* indicates that the read-only replica records the replication updates from the master server to record the password policy operational attributes.
Table 2. The relationship between the ibm-replicateSecurityAttribute value and password policy operational attributes update for an invalid bind on a read-only replica server

The relationship between the ibm-replicateSecurityAttribute value and password policy operational attributes update for an invalid bind on a read-only replica server.

Scenarios The ibm-replicateSecurityAttribute attribute value Notifies an invalid bind with control Acknowledges read-only replica with timestamp in control Update to password policy operational attributes
Master server Read-only replica server Read-only replica -> Master Master -> Read-only replica Master server Read-only replica server
1 TRUE TRUE YES YES YES YES
2 TRUE FALSE/Not set NO NO NO YES*
3 FALSE/Not set TRUE YES NO YES YES**
4 FALSE/Not set FALSE/Not set NO NO NO YES*
Note:
  • YES* indicates that the read-only replica updates the password policy operational attributes that are based on the bind result on the read-only replica. The read-only replica server does not notify the master server with the password policy operational attributes update. Therefore, the master server does not replicate these updates to other servers in the replication topology.
  • YES** indicates that the read-only replica updates the password policy operational attributes that are based on the bind result on the read-only replica. The read-only replica server notifies the master server with the password policy operational attributes update. Therefore, the master server replicates these updates to other servers in the replication topology.
Table 3. The relationship between the ibm-replicateSecurityAttribute value and password policy operational attributes update for a valid bind on a master server

The relationship between the ibm-replicateSecurityAttribute value and password policy operational attributes update for a valid bind on a master server.

Scenarios The ibm-replicateSecurityAttribute attribute value Update to password policy operational attributes
Master server Read-only replica server Master server Read-only replica server
1 TRUE TRUE YES YES*
2 TRUE FALSE/Not set YES NO
3 FALSE/Not set TRUE YES YES*
4 FALSE/Not set FALSE/Not set YES NO
Note: YES* indicates that the read-only replica records the replication updates from the master server to record the password policy operational attributes.
Table 4. The relationship between the ibm-replicateSecurityAttribute value and password policy operational attributes update for a valid bind on a read-only replica server

The relationship between the ibm-replicateSecurityAttribute value and password policy operational attributes update for a valid bind on a read-only replica server.

Scenarios The ibm-replicateSecurityAttribute attribute value Notifies an invalid bind with control Acknowledges read-only replica with timestamp in control Update to password policy operational attributes
Master server Read-only replica server Read-only replica -> Master Master -> Read-only replica Master server Read-only replica server
1 TRUE TRUE YES YES YES YES
2 TRUE FALSE/Not set NO NO NO YES*
3 FALSE/Not set TRUE YES NO YES YES**
4 FALSE/Not set FALSE/Not set NO NO NO YES*
Note:
  • YES* indicates that the read-only replica updates the password policy operational attributes that are based on the bind result on the read-only replica. The read-only replica server does not notify the master server with the password policy operational attributes update. Therefore, the master server does not replicate these updates to other servers in the replication topology.
  • YES** indicates that the read-only replica updates the password policy operational attributes that are based on the bind result on the read-only replica. The read-only replica server notifies the master server with the password policy operational attributes update. Therefore, the master server replicates these updates to other servers in the replication topology.