| config | attribute set of attribute set of any value | Desired values for the package's declared config artifacts. |
| credentials | attribute set of submodule | Opaque references for the package's declared credentials. |
| database.maxBytes | signed integer | Maximum LMDB database size in bytes. |
| enable | boolean | Enable the package-owned OpenLDAP server. |
| listenUrls | non-empty list of string matching (ldap|ldaps|ldapi)://[^[:space:]]* | LDAP, LDAPS, or local-domain listener URLs passed to slapd. |
| rootDn | string matching [A-Za-z][^[:cntrl:]]* | Directory administrator distinguished name for the primary database. |
| rootPassword | submodule | Opaque reference to the directory administrator password. |
| suffix | string matching [A-Za-z][^[:cntrl:]]* | Distinguished-name suffix served by the primary directory database. |
| tls.certificate | submodule | Opaque credential reference for the LDAP server certificate. |
| tls.enable | boolean | Enable TLS configuration and permit LDAPS listeners. |
| tls.privateKey | submodule | Opaque credential reference for the LDAP server private key. |
| tls.trustedCa | submodule | Opaque credential reference for the trusted client certificate authority bundle. |
| tls.verifyClient | one of ["never","allow","try","demand"] | Client-certificate verification policy applied to TLS sessions. |