Chapter 8. Installing an IdM server or replica with custom Directory Server and certificate authority settings from LDIF and INI files
You can use a configuration file to install an Identity Management (IdM) server or replicas with custom settings for:
- The IdM Directory Server.
- The IdM Certificate Authority.
8.1. Installing an IdM server or replica with custom Directory Server settings from an LDIF file
You can install an Identity Management (IdM) server and replicas with custom settings for the Directory Server (DS). The following procedure shows you how to create an LDAP Data Interchange Format (LDIF) file with the IdM DS settings, and how to pass those settings to the IdM server and replica installation commands.
Prerequisites
- You have determined custom Directory Server settings that improve the performance of your IdM environment. See Adjusting IdM Directory Server performance.
-
You have
root
privileges.
Procedure
Create a text file in LDIF format with your custom DS settings. Separate LDAP attribute modifications with a dash (-). This example sets non-default values for the idle timeout and maximum file descriptors.
changetype: modify replace: nsslapd-idletimeout nsslapd-idletimeout: 1800 - replace: nsslapd-maxdescriptors nsslapd-maxdescriptors: 8192
changetype: modify replace: nsslapd-idletimeout nsslapd-idletimeout: 1800 - replace: nsslapd-maxdescriptors nsslapd-maxdescriptors: 8192
Copy to Clipboard Copied! Use the
--dirsrv-config-file
parameter to pass the LDIF file to the installation script.To install an IdM server:
ipa-server-install --dirsrv-config-file <filename.ldif>
# ipa-server-install --dirsrv-config-file <filename.ldif>
Copy to Clipboard Copied! To install an IdM replica:
ipa-replica-install --dirsrv-config-file <filename.ldif>
# ipa-replica-install --dirsrv-config-file <filename.ldif>
Copy to Clipboard Copied!
8.2. Installing an IdM server or replica with custom certificate authority settings from an INI file
You can install an Identity Management (IdM) server and IdM replicas with custom settings for the IdM Certificate Authority (CA) and Key Recovery Authority (KRA).
The following procedure describes how to create an INI
file containing an override for the CA, and how to pass it to the IdM server and replica installation commands.
Prerequisites
-
You have
root
privileges.
Procedure
Create a text file in
INI
format with your custom CA settings. Write each parameter on a new line. This example sets the CA signing key size to 4096 bits.[CA] pki_ca_signing_key_size=4096
[CA] pki_ca_signing_key_size=4096
Copy to Clipboard Copied! Use the
--pki-config-override
parameter to pass the INI file to the installation script.To install an IdM server:
ipa-server-install --pki-config-override <pkiconfig.ini>
# ipa-server-install --pki-config-override <pkiconfig.ini>
Copy to Clipboard Copied! To install an IdM replica:
ipa-replica-install --pki-config-override <pkiconfig.ini>
# ipa-replica-install --pki-config-override <pkiconfig.ini>
Copy to Clipboard Copied!