For a complete list of properties, see General Consent Service configuration. The following table shows some basic properties.

Property Description

description

A description of the virtual attribute.

enabled

Specifies whether the virtual attribute is enabled for use.

base-DN

Specifies the base DNs for the branches containing entries that are eligible to use this virtual attribute.

If no values are given, the server generates virtual attributes anywhere in the server.

group-DN

Specifies the DNs of the groups whose members can use this virtual attribute.

If no values are given, the group membership is not taken into account when generating the virtual attribute.

If one or more group DNs are specified, then only members of those groups are allowed to have the virtual attribute.

filter

Specifies the filters that the server applies to entries to determine if they require virtual attributes

If no values are given, then any entry is eligible to have a virtual attribute value generated.

  • To view the properties of a virtual attribute, use dsconfig.
    $ bin/dsconfig get-virtual-attribute-prop --name isMemberOf