<?xml version="1.0" encoding="ISO-8859-1"?>

<!--
 DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS HEADER.

 Copyright (c) 2006 Sun Microsystems Inc. All Rights Reserved

 The contents of this file are subject to the terms
 of the Common Development and Distribution License
 (the License). You may not use this file except in
 compliance with the License.

 You can obtain a copy of the License at
 https://opensso.dev.java.net/public/CDDLv1.0.html or
 opensso/legal/CDDLv1.0.txt
 See the License for the specific language governing
 permission and limitations under the License.

 When distributing Covered Code, include this CDDL
 Header Notice in each file and include the License file
 at opensso/legal/CDDLv1.0.txt.
 If applicable, add the following below the CDDL Header,
 with the fields enclosed by brackets [] replaced by
 your own identifying information:
 "Portions Copyrighted [year] [name of copyright owner]"

 $Id: defaultDelegationPoliciesForAmSDK.xml,v 1.3 2009/08/19 05:40:40 veiming Exp $
-->

                                                                                
<!DOCTYPE Policies
    PUBLIC "-//iPlanet//OpenSSO 2005Q4 Admin CLI DTD//EN"    "jar://com/sun/identity/policy/policyAdmin.dtd">
                                                                                
<Policies>

<Policy name="@SM_ROOT_SUFFIX_HAT@^^PolicyAdmin1"
    referralPolicy="false" active="true" >
    <Rule name="delegation-rule1">
        <ServiceName name="sunAMDelegationService" />
        <ResourceName name="sms://*@SM_CONFIG_ROOT_SUFFIX@/iPlanetAMPolicy*Service/*" />
        <AttributeValuePair>
            <Attribute name="MODIFY" />
            <Value>allow</Value>
        </AttributeValuePair>
        <AttributeValuePair>
            <Attribute name="DELEGATE" />
            <Value>allow</Value>
        </AttributeValuePair>
        <AttributeValuePair>
            <Attribute name="READ" />
            <Value>allow</Value>
        </AttributeValuePair>
    </Rule>
    <Subjects name="Subjects" description="">
        <Subject name="delegation-subject" type="AMIdentitySubject" includeType="inclusive">
            <AttributeValuePair>
                <Attribute name="Values"/>
                <Value>id=Top-level Policy Admin Role,ou=role,@SM_CONFIG_ROOT_SUFFIX@,amsdkdn=cn=Top-level Policy Admin Role,@ROOT_SUFFIX@</Value>
            </AttributeValuePair>
        </Subject>
    </Subjects>
</Policy>

<Policy name="@SM_ROOT_SUFFIX_HAT@^^PolicyAdmin2"
    referralPolicy="false" active="true" >
    <Rule name="delegation-rule1">
        <ServiceName name="sunAMDelegationService" />
        <ResourceName name="sms://*@SM_CONFIG_ROOT_SUFFIX@/sunAMRealmService/*" />
            <AttributeValuePair>
                <Attribute name="READ" />
                <Value>allow</Value>
            </AttributeValuePair>
    </Rule>
    <Subjects name="Subjects" description="">
        <Subject name="delegation-subject" type="AMIdentitySubject" includeType="inclusive">
            <AttributeValuePair>
                <Attribute name="Values"/>
                <Value>id=Top-level Policy Admin Role,ou=role,@SM_CONFIG_ROOT_SUFFIX@,amsdkdn=cn=Top-level Policy Admin Role,@ROOT_SUFFIX@</Value>
            </AttributeValuePair>
        </Subject>
    </Subjects>
</Policy>

<Policy name="@SM_ROOT_SUFFIX_HAT@^^PolicyAdmin3"
    referralPolicy="false" active="true" >
    <Rule name="delegation-rule1">
        <ServiceName name="sunAMDelegationService" />
        <ResourceName name="sms://*@SM_CONFIG_ROOT_SUFFIX@/sunIdentityRepositoryService/*" />
        <AttributeValuePair>
            <Attribute name="READ" />
            <Value>allow</Value>
        </AttributeValuePair>
    </Rule>
    <Subjects name="Subjects" description="">
        <Subject name="delegation-subject" type="AMIdentitySubject" includeType="inclusive">
            <AttributeValuePair>
                <Attribute name="Values"/>
                <Value>id=Top-level Policy Admin Role,ou=role,@SM_CONFIG_ROOT_SUFFIX@,amsdkdn=cn=Top-level Policy Admin Role,@ROOT_SUFFIX@</Value>
            </AttributeValuePair>
        </Subject>
    </Subjects>
</Policy>

</Policies>
