03.03.2015 Views

CA eTrust SiteMinder Policy Server Management

CA eTrust SiteMinder Policy Server Management

CA eTrust SiteMinder Policy Server Management

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Configure LDAP Storage Options<br />

Configure Support for Large LDAP <strong>Policy</strong> Stores<br />

Large LDAP policy stores can cause <strong>Policy</strong> <strong>Server</strong> User Interface performance<br />

issues.<br />

To prevent these problems, you can modify the values of these two registry<br />

settings:<br />

Max AdmComm Buffer Size<br />

Specifies the <strong>Policy</strong> <strong>Server</strong> User Interface buffer size (specifically, the<br />

maximum amount of data, in bytes, that is passed from the <strong>Policy</strong> <strong>Server</strong><br />

to the <strong>Policy</strong> <strong>Server</strong> User Interface in a single packet).<br />

The Max AdmComm Buffer Size registry setting should be configured at<br />

the following registry location:<br />

HKEY_LO<strong>CA</strong>L_MACHINE\SOFTWARE\Netegrity\<strong>SiteMinder</strong>\CurrentVersion<br />

\<strong>Policy</strong>Serv\<br />

The value of this setting must be set very carefully as allocation of a larger<br />

buffer results in a decrease in overall performance. The acceptable range<br />

of Max AdmComm Buffer Size is 256KB to 2 GB. The default value this is<br />

256KB (also applies when this registry setting does not exist).<br />

SearchTimeout<br />

Specifies the search timeout, in seconds, for LDAP policy stores.<br />

The SearchTimeout registry setting should be configured at the following<br />

registry location:<br />

HKEY_LO<strong>CA</strong>L_MACHINE\SOFTWARE\Netegrity\<strong>SiteMinder</strong>\CurrentVersion<br />

\Ldap<strong>Policy</strong>Store\SearchTimeout<br />

The appropriate value for this setting depends upon and can vary<br />

according to several factors including network speed, size of the LDAP<br />

search query response, the LDAP connection state, load on LDAP server,<br />

and so on. The value should be large enough to prevent LDAP timeout<br />

when fetching large amounts of policy store data from the LDAP server.<br />

The default value is 20 seconds (also applies when this registry setting<br />

does not exist).<br />

More information:<br />

Configure the <strong>Policy</strong> Store Database (see page 28)<br />

Configure a Separate Database for the Key Store (see page 30)<br />

<strong>Policy</strong> <strong>Server</strong> <strong>Management</strong> Console (see page 153)<br />

<strong>Management</strong> Console--Data Tab Fields and Controls (see page 160)<br />

Chapter 3: Configuring <strong>Policy</strong> <strong>Server</strong> Data Storage Options 35

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!