Aller au contenu

CPYTOLDIF

Copier vers LDIF

Copy To LDIF

En bref

La commande Copier vers LDIF (CPYTOLDIF) permet de copier le contenu de l'annuaire d'une instance de Directory Server vers un fichier au format LDIF (LDAP Data Interchange Format). The Copy To LDIF (CPYTOLDIF) command is used to copy the directory contents of a Directory Server instance to a LDAP Data Interchange Format (LDIF) file.

CPYTOLDIF se lit CPY (Copier) + TOLDIF. Sur IBM i, le nom d'une commande associe presque toujours un verbe et un objet.

Syntaxe minimale

CPYTOLDIF LDIFSTMF(…)

Paramètres

  • INSTANCE Instance
  • LDIFSTMF Fichier STREAM LDIF LDIF stream file obligatoire
  • ADMIN Administrateur Administrator
  • SUBTREE Nom distinctif du sous-arbre Subtree distinguished name
  • LOCALHOST Copier cn=localhost Copy cn=localhost
  • PWDPOLICY Copier cn=pwdpolicy Copy cn=pwdpolicy
  • NESTRPLC Copier la réplication imbriquée Copy nested replication
  • OPRATR Copier les attributs opérationnels Copy operational attributes
  • PASSPHRASE Phrase secrète Passphrase
  • ENCSALT Sel de chiffrement Encryption salt
  • FILTERDN Nom distinctif du filtre Filter distinguished name
  • FILTERCMT Commentaires du filtre Filter comments
  • EXPORTDLT Exporter les entrées supprimées Export deleted entries

Astuce : dans une session 5250, tapez CPYTOLDIF puis F4 pour l'invite de saisie, et F1 sur un paramètre pour son aide.

Aide IBM i de la commande

Texte du F1, IBM i 7.5 en français (bibliothèque QSYS)

Où s'exécute : Tous les environnements (*ALL)
Compatible multitâche : Oui

La commande Copier vers LDIF (CPYTOLDIF) permet de copier le contenu de l'annuaire d'une instance de Directory Server vers un fichier au format LDIF (LDAP Data Interchange Format). Directory Server fournit un serveur LDAP (Lightweight Directory Access Protocol) sur IBM i. The Copy To LDIF (CPYTOLDIF) command is used to copy the directory contents of a Directory Server instance to a LDAP Data Interchange Format (LDIF) file. The Directory Server provides a Lightweight Directory Access Protocol (LDAP) server on IBM i.

Restriction : Vous devez remplir l'une des conditions suivantes pour utiliser cette commande : Restriction: You must do or satisfy one of the following conditions to use this command:

  • Posséder les droits spéciaux sur tous les objets (*ALLOBJ) et de configuration des E/S système (*IOSYSCFG). Have all object (*ALLOBJ) and input/output system configuration (*IOSYSCFG) special authorities.
  • Fournir le nom distinctif et le mot de passe de l'administrateur. Supply the administrator distinguished name and password.
  • Être administrateur Directory Services. L'appelant est un administrateur Directory Services si le serveur Directory Services a été configuré pour accorder l'accès d'administrateur aux utilisateurs autorisés et que l'appelant est autorisé à la fonction « Directory Services Administrator » du système d'exploitation. Be a Directory Services administrator. The caller is a Directory Services administrator if the Directory Services server has been configured to grant administrator access to authorized users and the caller is authorized to the 'Directory Services Administrator' function of the operating system.

Paramètres

Mot-clé Description Valeurs possibles Remarques
INSTANCE Instance Nom, QUSRDIR Facultatif, positionnel 2
LDIFSTMF Fichier STREAM LDIFLDIF stream file Chemin d'accès Obligatoire, positionnel 1
ADMIN AdministrateurAdministrator Liste d'éléments Facultatif
Élément 1: Distinguished name Valeur caractère
Élément 2: Password Valeur caractère
SUBTREE Nom distinctif du sous-arbreSubtree distinguished name Valeur caractère, *ALL Facultatif
LOCALHOST Copier cn=localhostCopy cn=localhost *NOCOPY, *COPY Facultatif
PWDPOLICY Copier cn=pwdpolicyCopy cn=pwdpolicy *NOCOPY, *COPY Facultatif
NESTRPLC Copier la réplication imbriquéeCopy nested replication *COPY, *NOCOPY Facultatif
OPRATR Copier les attributs opérationnelsCopy operational attributes *COPY, *NOCOPY Facultatif
PASSPHRASE Phrase secrètePassphrase Valeur caractère Facultatif
ENCSALT Sel de chiffrementEncryption salt Valeur caractère Facultatif
FILTERDN Nom distinctif du filtreFilter distinguished name Valeur caractère Facultatif
FILTERCMT Commentaires du filtreFilter comments Valeur caractère Facultatif
EXPORTDLT Exporter les entrées suppriméesExport deleted entries *NO, *YES Facultatif

Instance (INSTANCE)

Indique l'instance de Directory Server dont les entrées d'annuaire doivent être copiées. Specifies the Directory Server instance whose directory entries are to be copied.

QUSRDIR
Le nom de l'instance par défaut du serveur d'annuaire du système. The name of the system default Directory Server instance.
nom
Indiquez le nom de l'instance de Directory Server. Le nom comporte au minimum un caractère et au maximum huit caractères. Specify the Directory Server instance name. The name has a minimum of one character and a maximum of eight characters.

Fichier STREAM LDIF (LDIFSTMF)LDIF stream file (LDIFSTMF)

Indique le chemin d'accès, dans le système de fichiers intégré, du fichier STREAM au format LDIF (LDAP Data Interchange Format). Specifies the integrated file system path to the LDAP Data Interchange Format (LDIF) stream file.

Ce paramètre est obligatoire. This is a required parameter.

chemin-d'accès
Indiquez le chemin d'accès du fichier STREAM LDIF qui contiendra la copie des entrées d'annuaire de l'instance de Directory Server. Specify the path name of the LDIF stream file to contain the copy of the Directory Server instance directory entries.

Administrateur (ADMIN)Administrator (ADMIN)

Indique l'administrateur de Directory Server. S'il n'est pas indiqué, l'utilisateur doit posséder les droits spéciaux sur tous les objets (*ALLOBJ) et de configuration des E/S système (*IOSYSCFG). Specifies the Directory Server administrator. If not specified, the user must have all object (*ALLOBJ) and input/output system configuration (*IOSYSCFG) special authorities.

Élément 1: Distinguished name

valeur-caractère
Indiquez le nom distinctif de l'administrateur de Directory Server, par exemple cn=administrator. Un maximum de 50 caractères est autorisé. Specify the distinguished name for the Directory Server administrator, for example, cn=administrator. A maximum of 50 characters is allowed.

Élément 2: Password

valeur-caractère
Indiquez le mot de passe de l'administrateur de Directory Server. Le mot de passe respecte la casse et doit être placé entre apostrophes. Un maximum de 50 caractères est autorisé. Specify the password for the Directory Server administrator. The password is case sensitive and must be enclosed in apostrophes. A maximum of 50 characters is allowed.

Nom distinctif du sous-arbre (SUBTREE)Subtree distinguished name (SUBTREE)

Indique le nom distinctif (DN) de la racine d'un sous-arbre d'annuaire à copier vers le fichier STREAM au format LDIF (LDAP Data Interchange Format). Cet objet et tous ses objets descendants sont copiés. Specifies the distinguished name (DN) of the root of a directory subtree to copy to the LDAP Data Interchange Format (LDIF) stream file. This object, and all descendant objects will be copied.

*ALL
Pour copier l'arborescence complète de l'annuaire. To copy the entire directory tree.
valeur-caractère
Indiquez le nom distinctif du sous-arbre à copier. Un maximum de 50 caractères est autorisé. Specify the subtree distinguished name to be copied. A maximum of 50 characters is allowed.

Copier cn=localhost (LOCALHOST)Copy cn=localhost (LOCALHOST)

Indique si les données situées sous le nom distinctif cn=localhost sont copiées vers le fichier STREAM au format LDIF (LDAP Data Interchange Format). Specifies whether data located under the distinguished name cn=localhost is copied to the LDAP Data Interchange Format (LDIF) stream file.

*NOCOPY
Le contenu de cn=localhost n'est pas copié vers le fichier STREAM LDIF. The contents of cn=localhost are not copied to the LDIF stream file.
*COPY
Le contenu de cn=localhost est copié vers le fichier STREAM LDIF. The contents of cn=localhost are copied to the LDIF stream file.

Copier cn=pwdpolicy (PWDPOLICY)Copy cn=pwdpolicy (PWDPOLICY)

Indique si les données situées sous le nom distinctif cn=pwdpolicy sont copiées vers le fichier STREAM au format LDIF (LDAP Data Interchange Format). Specifies whether data located under the distinguished name cn=pwdpolicy is copied to the LDAP Data Interchange Format (LDIF) stream file.

*NOCOPY
Le contenu de cn=pwdpolicy n'est pas copié vers le fichier STREAM LDIF. The contents of cn=pwdpolicy are not copied to the LDIF stream file.
*COPY
Le contenu de cn=pwdpolicy est copié vers le fichier STREAM LDIF. Cette valeur ne peut être indiquée que lorsque *ALL est utilisé pour le paramètre de DN du sous-arbre (SUBTREE). The contents of cn=pwdpolicy are copied to the LDIF stream file. This can only be specified when *ALL is used for the subtree DN (SUBTREE) parameter.

Copier la réplication imbriquée (NESTRPLC)Copy nested replication (NESTRPLC)

Indique si les contextes de réplication imbriqués sont copiés vers le fichier STREAM au format LDIF (LDAP Data Interchange Format). Par exemple, si un annuaire contient les contextes de réplication o=acme et cn=external users,o=acme, cette option peut servir à copier les données situées sous le nom distinctif o=acme en excluant toutes les entrées situées sous le nom distinctif cn=external users,o=acme. Specifies whether nested replication contexts are copied to the LDAP Data Interchange Format (LDIF) stream file. For example, if a directory contains the replication contexts o=acme and cn=external users,o=acme, this option can be used to copy data under the distinguished name o=acme while excluding all entries under the distinguished name cn=external users,o=acme.

*COPY
Les données des contextes de réplication imbriqués sont copiées vers le fichier STREAM LDIF. Data from nested replication contexts is copied to the LDIF stream file.
*NOCOPY
Les données des contextes de réplication imbriqués ne sont pas copiées vers le fichier STREAM LDIF. Cette valeur ne peut être indiquée que si un DN de sous-arbre (SUBTREE) est indiqué. Data from nested replication contexts is not copied to the LDIF stream file. This can only be specified if a subtree DN (SUBTREE) is specified.

Copier les attributs opérationnels (OPRATR)Copy operational attributes (OPRATR)

Indique si les quatre attributs opérationnels suivants sont copiés vers le fichier STREAM au format LDIF (LDAP Data Interchange Format) : Specifies whether the following four operational attributes are copied to the LDAP Data Interchange Format (LDIF) stream file:

  • creatorsName
  • createTimestamp
  • modifiersName
  • modifyTimestamp.
*COPY
Les attributs opérationnels sont copiés vers le fichier STREAM LDIF. The operational attributes are copied to the LDIF stream file.
*NOCOPY
Les attributs opérationnels ne sont pas copiés vers le fichier STREAM LDIF. The operational attributes are not copied to the LDIF stream file.

Phrase secrète (PASSPHRASE)Passphrase (PASSPHRASE)

Indique la phrase secrète AES (Advanced Encryption Standard) à utiliser pour chiffrer toute information chiffrée stockée dans le fichier STREAM au format LDIF (LDAP Data Interchange Format). Cette phrase secrète doit correspondre à celle utilisée par l'instance de Directory Server qui copiera les informations de ce fichier STREAM LDIF. Elle ne doit être indiquée que si l'instance de Directory Server cible utilise le chiffrement AES pour chiffrer les données. Specifies the Advanced Encryption Standard (AES) passphrase to be used to encrypt any encrypted information stored in the LDAP Data Interchange Format (LDIF) stream file. This passphrase must match the passphrase used by the Directory Server instance that will copy the information from this LDIF stream file. This should only be specified if the target Directory Server instance is using AES encryption to encrypt data.

valeur-caractère
Specify the passphrase. A minimum of 12 characters and maximum of 1016 characters is allowed. The passphrase is case sensitive, therefore characters must be enclosed in apostrophes. Valid characters are:

§#$à¬ç|µéè! 'carat' 'tilde'
" % & ' ( ) * + , - . / ? > = < ; : _
A B C D E F G H I J K L M N O P Q R S T U V W X Y Z
a b c d e f g h i j k l m n o p q r s t u v w x y z
0 1 2 3 4 5 6 7 8 9

Sel de chiffrement (ENCSALT)Encryption salt (ENCSALT)

Indique le sel AES (Advanced Encryption Standard) à utiliser pour chiffrer toute information chiffrée stockée dans le fichier STREAM au format LDIF (LDAP Data Interchange Format). Le sel de chiffrement doit correspondre à celui utilisé par l'instance de Directory Server qui copiera les informations du fichier STREAM LDIF créé par la commande. Il ne doit être indiqué que si l'instance de Directory Server cible utilise le chiffrement AES pour chiffrer les données. Specifies the Advanced Encryption Standard (AES) salt to be used to encrypt any encrypted information stored in the LDAP Data Interchange Format (LDIF) stream file. The encryption salt must match the encryption salt used by the Directory Server instance that will copy the information from the LDIF stream file created by the command. This should only be specified if the target Directory Server instance is using AES encryption to encrypt data.

valeur-caractère
Specify the encryption salt. Exactly 12 characters must be used. The encryption salt is case sensitive, therefore characters must be enclosed in apostrophes. Valid characters are:

§#$à¬ç|µéè! 'carat' 'tilde'
" % & ' ( ) * + , - . / ? > = < ; : _
A B C D E F G H I J K L M N O P Q R S T U V W X Y Z
a b c d e f g h i j k l m n o p q r s t u v w x y z
0 1 2 3 4 5 6 7 8 9

Nom distinctif du filtre (FILTERDN)Filter distinguished name (FILTERDN)

Indique un DN de filtre à utiliser comme filtre pour les classes d'objets et les attributs. Specifies a filter DN to be used as a filter for objectclasses and attributes.

valeur-caractère
Indiquez le nom distinctif du filtre à utiliser pour filtrer les données. Un maximum de 50 caractères est autorisé. Specify the filter distinguished name to be used to filter data. A maximum of 50 characters is allowed.

Commentaires du filtre (FILTERCMT)Filter comments (FILTERCMT)

Indique des commentaires à ajouter dans le fichier LDIF. Specified some comments to be added into the LDIF file.

valeur-caractère
Indique les commentaires. Un maximum de 256 caractères est autorisé. Specifies the comments. A maximum of 256 characters is allowed.

Exporter les entrées supprimées (EXPORTDLT)Export deleted entries (EXPORTDLT)

Indique si les entrées supprimées sont exportées vers le fichier STREAM au format LDIF (LDAP Data Interchange Format). Si le nom distinctif du sous-arbre (SUBTREE) est indiqué avec cette option, il doit être cn=Deleted Objects. Specifies whether the deleted entries are exported to the LDAP Data Interchange Format (LDIF) stream file. If the Subtree distinguished name (SUBTREE) is given along with this option, then the Subtree distinguished name must be cn=Deleted Objects.

*NO
N'exporte pas les entrées supprimées vers le fichier STREAM LDIF. Do not export the deleted entries to the LDIF stream file.
*YES
Exporte les entrées supprimées vers le fichier STREAM LDIF. Export the deleted entries to the LDIF stream file.

Exemples

Exemple 1 : Copie de l'ensemble de l'annuaire QUSRDIR Example 1: Copy Entire QUSRDIR Directory

CPYTOLDIF   INSTANCE(QUSRDIR) LDIFSTMF('/ldap/qusrdir.ldif')

Cette commande copie les entrées de l'annuaire Directory Server de l'instance QUSRDIR vers le fichier STREAM qusrdir.ldif du répertoire ldap. L'utilisateur qui exécute la commande de cette manière doit posséder les droits spéciaux sur tous les objets (*ALLOBJ) et de configuration des E/S système (*IOSYSCFG). This command copies the entries from the Directory Server directory for the QUSRDIR instance to the qusrdir.ldif stream file in the ldap directory. The user running the command this way must have all object (*ALLOBJ) and input/output system configuration (*IOSYSCFG) special authorities.

Exemple 2 : Copie du seul sous-arbre o=ibm Example 2: Copy the o=ibm Subtree Only

CPYTOLDIF   INSTANCE(QUSRDIR) LDIFSTMF('/ldap/ibmsubtree.ldif')
            SUBTREE('o=ibm') ADMIN('cn=admin' 'secret')

Cette commande copie les entrées du sous-arbre o=ibm de l'annuaire Directory Server de l'instance QUSRDIR vers le fichier STREAM ibmsubtree.ldif du répertoire ldap. This command copies the o=ibm subtree entries from the Directory Server directory for the QUSRDIR instance to the ibmsubtree.ldif stream file in the ldap directory.

Exemple 3 : Copie des entrées cn=localhost Example 3: Copy the cn=localhost Entries

CPYTOLDIF   INSTANCE(DOGGIES)
            LDIFSTMF('/ldap/includelocal.ldif')
            SUBTREE(*ALL) LOCALHOST(*COPY)
            ADMIN('cn=fluffy' 'poodle')

Cette commande copie les entrées de l'annuaire Directory Server de l'instance DOGGIES, y compris les entrées de cn=localhost, vers le fichier STREAM includelocal.ldif du répertoire ldap. This command copies the entries from the Directory Server directory for the DOGGIES instance including the entries in cn=localhost to the includelocal.ldif stream file in the ldap directory.

Messages d'erreur

Messages *ESCAPE *ESCAPE Messages

GLD0202
Le nom distinctif (DN) ou le mot de passe de l'administrateur n'est pas correct. Administrator DN or password not correct.
GLD0213
Erreur lors de l'ouverture ou de la création du fichier. Error opening or creating file.
GLD0215
L'instance de serveur d'annuaire &1 est introuvable. Directory server instance &1 not found.
GLD0218
Droits insuffisants, ou nom distinctif et mot de passe incorrects. Not enough authority or incorrect distinguished name and password specified.
GLD022B
Objet &1 introuvable. Cannot find object &1.
GLD0234
Le sous-arbre d'exportation n'est pas un contexte de réplication. Export subtree is not a replication context.
GLD0413
Une erreur d'entrée de liste de validation s'est produite. Validation list entry error occurred.

© Copyright IBM Corp. Texte d'aide reproduit à des fins de formation.