Previous Topic: Configure Enhanced LDAP Referral Handling

Next Topic: Configure ODBC Storage Options

Configure Support for Large LDAP Policy Stores

Large LDAP policy stores can cause Policy Server User Interface performance issues.

To prevent these problems, you can modify the values of these two registry settings:

Max AdmComm Buffer Size

Specifies the Policy Server User Interface buffer size (specifically, the maximum amount of data, in bytes, that is passed from the Policy Server to the Policy Server User Interface in a single packet).

The Max AdmComm Buffer Size registry setting should be configured at the following registry location:

HKEY_LOCAL_MACHINE\SOFTWARE\Netegrity\SiteMinder\CurrentVersion
\PolicyServ\

The value of this setting must be set very carefully as allocation of a larger buffer results in a decrease in overall performance. The acceptable range of Max AdmComm Buffer Size is 256KB to 2 GB. The default value this is 256KB (also applies when this registry setting does not exist).

SearchTimeout

Specifies the search timeout, in seconds, for LDAP policy stores.

The SearchTimeout registry setting should be configured at the following registry location:

HKEY_LOCAL_MACHINE\SOFTWARE\Netegrity\SiteMinder\CurrentVersion
\LdapPolicyStore\SearchTimeout

The appropriate value for this setting depends upon and can vary according to several factors including network speed, size of the LDAP search query response, the LDAP connection state, load on LDAP server, and so on. The value should be large enough to prevent LDAP timeout when fetching large amounts of policy store data from the LDAP server. The default value is 20 seconds (also applies when this registry setting does not exist).

More information:

Configure the Policy Store Database

Configure a Separate Database for the Key Store

Policy Server Management Console

Management Console--Data Tab Fields and Controls