An awareness thing: where do I set this?

I knew it could be set, and that I read the sentence about it with some frequency.

defaultentrylocation Specifies the location of the default entry. Valid values are ldap and local. The default is ldap.

  • ldap - Use the default entry in LDAP for all attribute default values.
  • local - Use the default stanza from local /etc/security/user file for all attribute default values.

I am sure I will not forget it again - but just in case you are using LDAP - with Active Directory or OpenLDAP as the LDAP server AND!! want to continue to have the AIX default user attributes from /etc/security/user - which I do, the place to set it is in /etc/security/ldap/ldap.cfg

