f29ab77 Add more LDAP indices

Authored and Committed by cheimes 5 years ago
    Add more LDAP indices
    
    An index is used to optimize an LDAP operation. Without an index, 389-DS
    has to perform a partial or even full table scan. A full database scan can
    easily take 10 seconds or more in a large installation.
    
    * automountMapKey: eq, pres (was: eq)
    * autoMountMapName: eq
    * ipaConfigString: eq
    * ipaEnabledFlag: eq
    * ipaKrbAuthzData: eq, sub
    * accessRuleType: eq
    * hostCategory: eq
    
    automountMapKey and autoMountMapName filters are used for automount.
    
    Installation and service discovery (CA, KRA) use ipaConfigString to find
    active services and CA renewal master.
    
    SSSD filters with ipaEnabledFlag, accessRuleType, and hostCategory to
    find and cache HBAC rules for each host.
    
    ipaKrbAuthzData is used by ipa host-del. The framework performs a
    '*arg*' query, therefore a sub index is required, too.
    
    Partly fixes: https://pagure.io/freeipa/issue/7786
    Fixes: https://pagure.io/freeipa/issue/7787
    Fixes: https://pagure.io/freeipa/issue/7790
    Fixes: https://pagure.io/freeipa/issue/7792
    Signed-off-by: Christian Heimes <cheimes@redhat.com>
    Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com>
    Reviewed-By: Rob Crittenden <rcritten@redhat.com>
    
        
file modified
+50 -0