OIDs for supported and enabled capabilities

The provided table shows OIDs for supported and enabled capabilities. You can use these OIDs to see if a particular server supports these features.

Table 1. OIDs for supported and enabled capabilities

Short name with OID Description Supported by IBM® Security Directory Base Server v11.0.1 Supported by IBM Security Directory Proxy Server v11.0.1
Without partitioned data With partitioned data
Enhanced Replication Model

1.3.18.0.2.32.1

Identifies the replication model including subtree and cascading replication. Yes N/A N/A
EntryChecksum

1.3.18.0.2.32.2

Indicates that this server supports the ibm-entrychecksum and ibm-entrychecksumop features. Yes Yes Yes
Entry UUID

1.3.18.0.2.32.3

This value is listed in the ibm-capabilities Subentry for those suffixes that support the ibm-entryuuid attribute. Yes Yes Yes
Filter ACLs

1.3.18.0.2.32.4

Identifies that this server supports the IBM Filter ACL model Yes Yes Yes
Password Policy

1.3.18.0.2.32.5

Identifies that this server supports password policies Yes Yes Yes
Sort by DN

1.3.18.0.2.32.6

Enables searches sorted by DNs in addition to regular attributes. Yes No No
Administration Group Delegation

1.3.18.0.2.32.8

Server supports the delegation of server administration to a group of administrators that are specified in the configuration backend. Yes Yes Yes
Denial of Service Prevention

1.3.18.0.2.32.9

Server supports the denial of service prevention feature including read/write time-outs. Yes Yes Yes
Dereference Alias Option

1.3.18.0.2.32.10

Server supports an option to not dereference aliases by default

* Proxy rootDSE does not list

** Aliases across partitions are not dereferenced

Yes Yes(*) Yes(**)
Admin Server Audit Logging

1.3.18.0.2.32.11

Server supports the auditing of the admin server. Yes Yes Yes
128 Character Table Names

1.3.18.0.2.32.12

The server feature to allow name of unique attributes to be higher than 18 characters (with the maximum of 128 characters).

* Proxy rootDSE does not list

** Uniqueness is not guaranteed across partitions

Yes Yes(*) Yes(**)
Attribute Caching Search Filter Resolution

1.3.18.0.2.32.13

The server supports attribute caching for search filter resolution. Yes N/A N/A
Dynamic Tracing

1.3.18.0.2.32.14

Server supports active tracing for the server with an LDAP extended operation. Yes Yes Yes
Entry And Subtree Dynamic Updates

1.3.18.0.2.32.15

The server supports dynamic configuration updates on entries and subtrees. Yes Yes Yes
Globally Unique Attributes

1.3.18.0.2.32.16

The server feature to enforce globally unique attribute values. Yes No No
Group-Specific Search Limits

1.3.18.0.2.32.17

Supports extended search limits for a group of people.

* Proxy rootDSE does not list

** Group Based Search limits don't work consistently when data is partitioned

Yes Yes(*) Yes(**)
IBMpolicies Replication Subtree

1.3.18.0.2.32.18

Server supports the replication of the cn=IBMpolicies subtree. Yes Yes Yes
Max Age ChangeLog Entries

1.3.18.0.2.32.19

Specifies that the server is capable of retaining changelog entries based on age. Yes N/A N/A
Monitor Logging Counts

1.3.18.0.2.32.20

The server provides monitor logging counts for messages added to server, command-line interface, and audit log files. Yes Yes Yes
Monitor Active Workers Information

1.3.18.0.2.32.21

The server provides monitor information for active workers (cn=workers,cn=monitor). Yes Yes Yes
Monitor Connection Type Counts

1.3.18.0.2.32.22

The server provides monitor connection type counts for SSL and TLS connections. Yes Yes Yes
Monitor Connections Information

1.3.18.0.2.32.23

The server provides monitor information for connections by IP address instead of connection ID (cn=connections, cn=monitor) Yes Yes Yes
Monitor Operation Counts

1.3.18.0.2.32.24

The server provides new monitor operation counts for initiated and completed operation types.

* The operations completed counts do not reflect actual operations completed in the proxy. Instead, it represents operations that are either completed or have been sent to a backend server for processing. Use proxy-specific monitors to track the number of completed operations.

Yes Yes(*) Yes(*)
Monitor Tracing Info

1.3.18.0.2.32.25

The server provides monitor information for tracing options currently being used. Yes Yes Yes
Null Base Subtree Search

1.3.18.0.2.32.26

The server allows null based subtree search, which searches the entire DIT defined in the server. Yes No No
Proxy Authorization

1.3.18.0.2.32.27

The server supports Proxy Authorization for a group of users. Yes No No
TLS Capabilities

1.3.18.0.2.32.28

Specifies that the server is actually capable of doing TLS. Yes Yes Yes
Non-Blocking Replication

1.3.18.0.2.32.29

The server is capable of ignoring some errors received from a consumer (replica) that would normally cause an update to be re-transmitted periodically until a successful result code is received. Yes N/A N/A
Kerberos Capability

1.3.18.0.2.32.30

Specifies that the server is capable of using Kerberos. Yes No No
ibm-allMembers and ibm-allGroups operational attributes

1.3.18.0.2.32.31

Indicates whether or not a backend supports searching on the ibm-allGroups and ibm-allMembers operational attributes. Yes Yes Yes
All operational Attributes

1.3.6.1.4.1.4203.1.5.1

All operational Attributes

* Proxy rootDSE does not list

** Some operational attributes are dependent on the data not being distributed.

Yes Yes(*) Yes(**)
Language Tags

1.3.6.1.4.1.4203.1.5.4

Server supports language tags. Yes No No
FIPS mode for GSKit

1.3.18.0.2.32.32

Enables the server to use the encryption algorithms from the ICC FIPS-certified library Yes Yes Yes
Modify DN (leaf move)

1.3.18.0.2.32.35

Indicates if modify DN operation supports new superior for leaf entries. Note that this capability is implied by the pre-existing Modify DN (subtree move) capability. Applications should check for both capabilities.

* modify DN allowed only if the change does not cross partitions

Yes Yes Yes(*)
Simplify resizing of attributes

1.3.18.0.2.32.37

Allows customers to increase the maximum length of attributes through the schema modification facilities. Yes N/A N/A
Global Administration Group

1.3.18.0.2.32.38

Server supports the delegation of server administration to a group of administrators that are specified in the RDBM backend. Global Administrators do not have any authority to the configuration file or log files. Yes Yes Yes
AES Encryption Option

1.3.18.0.2.32.39

Server supports AES Password Encryption. Yes Yes Yes
Auditing of Compare

1.3.18.0.2.32.40

Server supports auditing of compare operations. Yes Yes Yes
Log Management

1.3.18.0.2.32.41

Identifies that this server supports log management. Yes Yes Yes
Multi-threaded Replication

1.3.18.0.2.32.42

Replication agreements can specify using multiple threads and connections to a consumer. Yes N/A N/A
Supplier Replication Configuration

1.3.18.0.2.32.43

Server configuration of suppliers for replication. Yes N/A N/A
Using CN=IBMPOLICIES for Global Updates

1.3.18.0.2.32.44

Server supports the replication of global updates using the replication topology in cn=IBMpolicies subtree. Yes N/A N/A
Multihomed configuration support

1.3.18.0.2.32.45

Server supports configuration on multiple IP addresses (multihomed). Yes Yes Yes
Multiple Directory Server Instances Architecture

1.3.18.0.2.32.46

Server is designed to run with multiple directory server instances on the same machine. Yes Yes Yes
Configuration Tool Auditing

1.3.18.0.2.32.47

Server supports the auditing of the configuration tools. Yes Yes Yes
Audit consolidation configuration settings

1.3.18.0.2.32.48

Indicates that audit log settings are available in the configuration file. Yes Yes Yes
Proxy Server

1.3.18.0.2.32.49

Describes whether this server is capable of acting as a proxy server or a regular RDBM server. Optional Information. Yes Yes Yes
LDAP Attribute Cache Auto Adjust

1.3.18.0.2.32.50

Indicates if the autonomic attribute cache is supported and enabled.
Note: Starting with the IBM Security Directory Server 6.3 release, attribute cache is deprecated. Henceforth, users should avoid using attribute cache.
Yes N/A N/A
Replication conflict resolution max entry size

1.3.18.0.2.32.51

Based on this number, a supplier may decide if an entry should be re-added to a target server in order to resolve a replication conflict. Yes N/A N/A
LostAndFound log file

1.3.18.0.2.32.52

Supports LostAndFound file for archiving replaced entries as a result of replication conflict resolution. Yes N/A N/A
Password Policy Account Lockout

1.3.18.0.2.32.53

Identifies that this server supports password policy Account Locked feature. Yes Yes Yes
Password Policy Admin

1.3.18.0.2.32.54

Identifies that this server supports Admin Password Policy. Yes Yes Yes
SSL Fips processing mode

1.3.18.0.2.32.55

Server supports SSL FIPS mode processing. Yes Yes Yes
IDS 6.0 ibm-entrychecksumop

1.3.18.0.2.32.56

Identifies that the 6.0 version of the ibm-entrychecksumop calculation was used on the server. Yes No No
LDAP Password Global Start Time

1.3.18.0.2.32.57

Indicates that the server can support ibm-pwdPolicyStartTime attribute in the cn=pwdPolicy entry. Yes No No
Audit Configuration Settings Consolidation

1.3.18.0.2.32.58

Identifies that the audit configuration settings are now residing in the ibmslapd configuration file only.

* Transactions are supported only when all updates target a single partition.

Yes Yes(*) Yes(*)
Encrypted Attribute Support

1.3.18.0.2.32.60

Server supports encrypted attributes. Yes Yes Yes
Proxy Monitor search

1.3.18.0.2.32.61

Server supports special monitor searches intended for proxy server. No Yes Yes
SSHA Password Encrypt

1.3.18.0.2.32.63

Server supports SSHA Password Encryption. Yes Yes Yes
MD5 Password Encrypt

1.3.18.0.2.32.64

Server supports MD5 Password Encryption. Yes Yes Yes
Filter Replication

1.3.18.0.2.32.65

The server feature designed to have only required entries and a subset of its attributes to be replicated. Yes N/A N/A
Group Members Cache

1.3.18.0.2.32.66

Server supports caching group members. Yes N/A N/A
PKCS11 Support

1.3.18.0.2.32.67

Server supports PKCS11 Encryption standard. Yes Yes Yes
Server Admin Roles

1.3.18.0.2.32.68

Server supports Server Administration roles. Yes Yes Yes
Digest MD5 Support

1.3.18.0.2.32.69

Server supports Digest MD5 Bind. Yes Yes Yes
External Bind Support

1.3.18.0.2.32.70

Server supports External Bind. Yes Yes Yes
Persistent Search

1.3.18.0.2.32.71

Server supports persistent search. Yes No No
Admin Server Denial of Service Prevention

1.3.18.0.2.32.72

Admin Server supports Denial of Service Prevention. Yes Yes Yes
Admin server Enhanced Monitor Support

1.3.18.0.2.32.73

Admin server supports "cn=monitor", "cn=connections,cn=monitor", and "cn=workers,cn=monitor" searches. Yes Yes Yes
Admin Server Support for Schema Searches

1.3.18.0.2.32.74

Admin server supports searches on schema. Yes Yes Yes
System Monitor Search

1.3.18.0.2.32.76

Server supports cn=system,cn=monitor search. Yes Yes Yes
Multiple Password Policies

1.3.18.0.2.32.77

Server allows multiple password policy to be defined and used. Yes Yes No
Passthrough Authentication

1.3.18.0.2.32.78

Server supports pass through authentication feature. Yes No No
Dynamic Updates of Replication Supplier Request

1.3.18.0.2.32.79

Server supports dynamic updates of replication supplier information. Yes N/A N/A
Audit Performance

1.3.18.0.2.32.81

Server supports auditing of performance for operations. Yes Yes Yes
No Emergency Thread Support

1.3.18.0.2.32.82

Emergency Thread is not supported by server. Yes Yes Yes
Enhanced Replication Group RI handling

1.3.18.0.2.32.83

Enhanced Replication Group RI handling Yes N/A N/A
Reread the DB2® Password

1.3.18.0.2.32.84

Server re-reads the DB2 password to identify any change in DB2 password specified in configuration. Yes N/A N/A
Proxy Failback Based on Replication Queue

1.3.18.0.2.32.85

Proxy Server will failback only when replication queue is below the threshold specified in configuration file. No Yes Yes
Proxy Flow control

1.3.18.0.2.32.86

Proxy server supports flow control algorithm. No Yes Yes
Backup restore configuration capability

1.3.18.0.2.32.87

Server supports configuring automatic backup and restore. Yes N/A N/A
Password Policy Max Consecutive repeated characters

1.3.18.0.2.32.88

Server supports restricting maximum consecutive repeated characters in password policy. Yes Yes Yes
Virtual List View Support

1.3.18.0.2.32.89

Server supports virtual list view control in searches. Yes No No
Proxy Paged Search

1.3.18.0.2.32.90

Proxy Server supports paged control in searches. No Yes Yes
Tombstone Support

1.3.18.0.2.32.92

Server supports tombstone for deleted entries. Yes No No
Proxy Health Check outstanding limit

1.3.18.0.2.32.93

Proxy supports identifying a hung server based on the configured outstanding health check requests. No Yes Yes
Replication Finegrained timestamps

1.3.18.0.2.32.94

Replication uses fine grained timestamp for resolving conflicts. Yes N/A N/A
Distributed Dynamic group enabled

1.3.18.0.2.32.96

Proxy Server Supports enabling/Disabling Distributed dynamic group configuration option. No Yes Yes
Distributed group enabled

1.3.18.0.2.32.97

Proxy Server Supports enabling/Disabling Distributed group configuration option. No Yes Yes
SHA-2

1.3.18.0.2.32.99

Indicates that this server supports SHA-2 family of algorithms, which include: SHA-224, SHA-256, SHA-384, and SHA-512. The server also supports the Salted version of the SHA-2 family of algorithms, which include: SSHA-224, SSHA-256, SSHA-384, and SSHA-512.

* SHA-2 is only applicable for servers with database backend.

Yes N/A(*) N/A(*)
Pass-through support for LDAP compare operations

1.3.18.0.2.32.100

Supports pass-through authentication for LDAP Compare operations. Yes No No
NIST SP800-131A Suite B

1.3.18.0.2.32.101

Supports NIST SP800-131A Suite B, which is a restrictive subset of NIST SP800-131A specification. Yes Yes Yes
TLS 1.0 protocol

1.3.18.0.2.32.102

Indicates that the server supports TLS v1.0 protocol. Yes Yes Yes
TLS 1.1 protocol

1.3.18.0.2.32.103

Indicates that the server supports TLS v1.1 protocol. Yes Yes Yes
TLS 1.2 protocol

1.3.18.0.2.32.104

Indicates that the server supports TLS v1.2 protocol. Yes Yes Yes
Replication of security attributes

1.3.18.0.2.32.105

Indicates that a read-only replica accepts the replication updates for password policy operational attributes. The read-only replica can notify its master servers about a bind operation that affects password policy operational attributes of a user. Indicates that a master server can accept notifications from a read-only replica about a bind operation that affects password policy operational attributes of a user. Yes Yes Yes
Record Last Successful Bind Timestamp in User Entries

1.3.18.0.2.32.106

Supports recording of last successful bind and authentication timestamp in the user entries Yes No No
Vendor Specific Password Policy Processing in Pass-through Authentication

1.3.18.0.2.32.107

Supports IBM Verify Directory for processing login failures from pass-through directories Yes No No
Advanced Password Policy

1.3.18.0.2.32.108

Supports advanced password policy that has additional password policy rules. Yes No No
FD Proxy Server Capability

1.3.18.0.2.32.109

Indicates that the server can act as a Federated Directory (FD) proxy server.
Note: This applies only to the Virtual Directory Server.
No No No
PBKDF2 Encryption Support

1.3.18.0.2.32.110

Indicates that the server can support PBKDF2 family of algorithms for Password Encryption. PBKDF2-SHA1, PBKDF2-SHA224, PBKDF2-SHA256, PBKDF2-SHA384, and PBKDF2-SHA512

Yes Yes Yes
TLS 1.3 Support

1.3.18.0.2.32.111

Indicates that the server supports TLS v1.3 protocol. (when enabled)

Yes Yes Yes
Scrypt Password Encryption

1.3.18.0.2.32.112

Server supports Scrypt Password Encryption algorithm. (when enabled)

Yes Yes Yes
Argon2 Password Encryption

1.3.18.0.2.32.113

Server supports Argon2 Password Encryption algorithm. (when enabled)

Yes Yes Yes