amAuthLDAP.properties revision 472fc80404c5545ee7bdc88554b8580758ccccda
af84459fbf938e508fd10b01cb8d699c79083813takashi# DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS HEADER.
af84459fbf938e508fd10b01cb8d699c79083813takashi# Copyright (c) 2007 Sun Microsystems Inc. All Rights Reserved
af84459fbf938e508fd10b01cb8d699c79083813takashi# The contents of this file are subject to the terms
af84459fbf938e508fd10b01cb8d699c79083813takashi# of the Common Development and Distribution License
af84459fbf938e508fd10b01cb8d699c79083813takashi# (the License). You may not use this file except in
af84459fbf938e508fd10b01cb8d699c79083813takashi# compliance with the License.
af84459fbf938e508fd10b01cb8d699c79083813takashi# You can obtain a copy of the License at
af84459fbf938e508fd10b01cb8d699c79083813takashi# https://opensso.dev.java.net/public/CDDLv1.0.html or
af84459fbf938e508fd10b01cb8d699c79083813takashi# See the License for the specific language governing
af84459fbf938e508fd10b01cb8d699c79083813takashi# permission and limitations under the License.
af84459fbf938e508fd10b01cb8d699c79083813takashi# When distributing Covered Code, include this CDDL
af84459fbf938e508fd10b01cb8d699c79083813takashi# Header Notice in each file and include the License file
af84459fbf938e508fd10b01cb8d699c79083813takashi# If applicable, add the following below the CDDL Header,
af84459fbf938e508fd10b01cb8d699c79083813takashi# with the fields enclosed by brackets [] replaced by
af84459fbf938e508fd10b01cb8d699c79083813takashi# your own identifying information:
af84459fbf938e508fd10b01cb8d699c79083813takashi# "Portions Copyrighted [year] [name of copyright owner]"
af84459fbf938e508fd10b01cb8d699c79083813takashi# $Id: amAuthLDAP.properties,v 1.8 2010/01/25 22:09:15 qcheng Exp $
af84459fbf938e508fd10b01cb8d699c79083813takashi# Portions Copyrighted 2011 ForgeRock Inc
af84459fbf938e508fd10b01cb8d699c79083813takashi# Portions Copyrighted 2012 Open Source Solution Technology Corporation
af84459fbf938e508fd10b01cb8d699c79083813takashiauthentication=Authentication Modules
af84459fbf938e508fd10b01cb8d699c79083813takashiiplanet-am-auth-ldap-service-description=LDAP
af84459fbf938e508fd10b01cb8d699c79083813takashiLDAPex=Unknown LDAP exception.
af84459fbf938e508fd10b01cb8d699c79083813takashiUPerror=Both user ID and password are required.
af84459fbf938e508fd10b01cb8d699c79083813takashiclasspathError=Class not found. Check the class path.
af84459fbf938e508fd10b01cb8d699c79083813takashiInvalidUP=Invalid user ID and password. Try again.
af84459fbf938e508fd10b01cb8d699c79083813takashiNoUser=User ID not found.
50cb7e2b30597f481fee57bac945190f06ebcc58jortonNoServer=Server cannot be contacted.
50cb7e2b30597f481fee57bac945190f06ebcc58jortonNaming=Naming error has occurred.
50cb7e2b30597f481fee57bac945190f06ebcc58jortonPasswordExp=Password expires in: {0}
50cb7e2b30597f481fee57bac945190f06ebcc58jortonGraceLogins=Your password has expired and you have {0} grace logins remaining.
50cb7e2b30597f481fee57bac945190f06ebcc58jortonTimeBeforeExpiration=Password expires in: {0}
50cb7e2b30597f481fee57bac945190f06ebcc58jortonPasswordReset=Password must be reset.
50cb7e2b30597f481fee57bac945190f06ebcc58jortonPasswdMismatch=The password and the confirm password do not match.
af84459fbf938e508fd10b01cb8d699c79083813takashiPasswordInvalid=Your password does not comply with present password policy.
af84459fbf938e508fd10b01cb8d699c79083813takashiNewPasswordInvalid=Your new password does not comply with present password policy.
af84459fbf938e508fd10b01cb8d699c79083813takashiUPsame=Username and password must be different. Try again.
af84459fbf938e508fd10b01cb8d699c79083813takashiinPwdQual=New password does not meet the password policy requirements.
c04f76acce77126cf88b09350e56ea8c6b4a064enilgunpwdInHist=New password has been used previously.
c04f76acce77126cf88b09350e56ea8c6b4a064enilgunpwdToShort=New password is too short.
c04f76acce77126cf88b09350e56ea8c6b4a064enilgunpwdToYoung=Password has been changed recently, cannot change password.
c04f76acce77126cf88b09350e56ea8c6b4a064enilgunPInvalid=The password you entered is invalid.
c04f76acce77126cf88b09350e56ea8c6b4a064enilgunPasswdSame=The password must be different. Try again.
c04f76acce77126cf88b09350e56ea8c6b4a064enilguna101=Primary LDAP Server
c04f76acce77126cf88b09350e56ea8c6b4a064enilguna101.help=Use this list to set the primary LDAP server used for authentication.
c04f76acce77126cf88b09350e56ea8c6b4a064enilguna101.help.txt=The LDAP authentication module will use this list as the primary server for authentication. A single entry must be in the \
c04f76acce77126cf88b09350e56ea8c6b4a064enilgunformat:<br/><br/><code>ldap_server:port</code><br/><br/>Multiple entries allow associations between OpenAM servers and a LDAP server. \
c04f76acce77126cf88b09350e56ea8c6b4a064enilgunThe format is:<br/><br/><code>local server name | server:port</code><br/><br/>\
c04f76acce77126cf88b09350e56ea8c6b4a064enilgunThe local server name is the full name of the server from the list of servers and sites.
af84459fbf938e508fd10b01cb8d699c79083813takashia102=Secondary LDAP Server
af84459fbf938e508fd10b01cb8d699c79083813takashia102.help=Use this list to set the secondary (failover) LDAP server used for authentication.
af84459fbf938e508fd10b01cb8d699c79083813takashia102.help.txt=If the primary LDAP server fails, the LDAP authentication module will failover to the secondary server. \
af84459fbf938e508fd10b01cb8d699c79083813takashiA single entry must be in the format:<br/><br/><code>ldap_server:port</code><br/><br/>\
af84459fbf938e508fd10b01cb8d699c79083813takashiMultiple entries allow associations between OpenAM servers and a LDAP server. \
af84459fbf938e508fd10b01cb8d699c79083813takashiThe format is:<br/><br/><code>local server name | server:port</code><br/><br/>\
af84459fbf938e508fd10b01cb8d699c79083813takashi<i>NB </i>The local server name is the full name of the server from the list of servers and sites.
af84459fbf938e508fd10b01cb8d699c79083813takashia103=DN to Start User Search
af84459fbf938e508fd10b01cb8d699c79083813takashia103.help=The search for accounts to be authenticated start from this base DN
af84459fbf938e508fd10b01cb8d699c79083813takashia103.help.txt=For a single server just enter the Base DN to be searched. Multiple OpenAM servers can have different base DNs for the search \
af84459fbf938e508fd10b01cb8d699c79083813takashiThe format is as follows:<br/><br/><code>local server name | search DN</code><br/><br/>\
af84459fbf938e508fd10b01cb8d699c79083813takashi<i>NB </i>The local server name is the full name of the server from the list of servers and sites.
af84459fbf938e508fd10b01cb8d699c79083813takashia104=Bind User DN
af84459fbf938e508fd10b01cb8d699c79083813takashia104.help=The DN of an admin user used by the module to authentication to the LDAP server
af84459fbf938e508fd10b01cb8d699c79083813takashia104.help.txt=The LDAP module requires an administration account in order to perform functionality such as password reset.<br/><br/>\
af84459fbf938e508fd10b01cb8d699c79083813takashi<i>NB </i><code>cn=Directory Manager</code> should not be used in production systems.
af84459fbf938e508fd10b01cb8d699c79083813takashia105=Bind User Password
af84459fbf938e508fd10b01cb8d699c79083813takashia105.help=The password of the administration account.
af84459fbf938e508fd10b01cb8d699c79083813takashia106=Attribute Used to Retrieve User Profile
af84459fbf938e508fd10b01cb8d699c79083813takashia106.help=The LDAP module will use this attribute to search of the profile of an authenticated user.
af84459fbf938e508fd10b01cb8d699c79083813takashia106.help.txt=This is the attribute used to find the profile of the authenticated user. Normally this will be the same attribute used to \
af84459fbf938e508fd10b01cb8d699c79083813takashifind the user account. The value will be the name of the user used for authentication.
d0828c8a321dc5e9ea60550f052294669c08cf93jima107=Attributes Used to Search for a User to be Authenticated
af84459fbf938e508fd10b01cb8d699c79083813takashia107.help=The attributes specified in this list form the LDAP search filter.
af84459fbf938e508fd10b01cb8d699c79083813takashia107.help.txt=The default value of uid will form the following search filter of <code>uid=<i>user</i></code>, if there are multiple \
af84459fbf938e508fd10b01cb8d699c79083813takashivalues such as uid and cn, the module will create a search filter as follows <code>(|(uid=<i>user</i>)(cn=<i>user</i>))</code>
af84459fbf938e508fd10b01cb8d699c79083813takashia108=User Search Filter
d0828c8a321dc5e9ea60550f052294669c08cf93jima108.help=This search filter will be appended to the standard user search filter.
cd6c8de3bedcc401ee230159b0439fa20f44488etakashia108.help.txt=This attribute can be used to append a custom search filter to the standard filter. For example: \
cd6c8de3bedcc401ee230159b0439fa20f44488etakashi<code>(objectClass=person)</code>would result in the following user search filter:<br/><br/>\
d0828c8a321dc5e9ea60550f052294669c08cf93jim<code>(&(uid=<i>user</i>)(objectClass=person))</code>
d0828c8a321dc5e9ea60550f052294669c08cf93jima109=Search Scope
cd6c8de3bedcc401ee230159b0439fa20f44488etakashia109.help=The level in the Directory Server that will be searched for a matching user profile.
c04f76acce77126cf88b09350e56ea8c6b4a064enilguna109.help.txt=This attribute controls how the directory is searched.<br/><br/>\
c04f76acce77126cf88b09350e56ea8c6b4a064enilgun<ul><li><code>OBJECT</code>: Only the Base DN is searched.</li>\
c04f76acce77126cf88b09350e56ea8c6b4a064enilgun<li><code>ONELEVEL</code>: Only the single level below (and not the Base DN) is searched</li>\
c04f76acce77126cf88b09350e56ea8c6b4a064enilgun<li><code>SUBTREE</code>: The Base DN and all levels below are searched</li></ul>
c04f76acce77126cf88b09350e56ea8c6b4a064enilguna110=SSL/TLS Access to LDAP Server
c04f76acce77126cf88b09350e56ea8c6b4a064enilguna110.help=Ensures the SSL/TLS will be used to establish connections to the LDAP server.
c04f76acce77126cf88b09350e56ea8c6b4a064enilguna110.help.txt=If this property is enabled; all connections to the LDAP server will be over SSL/TLS. The SSL certificate on the LDAP server \
c04f76acce77126cf88b09350e56ea8c6b4a064enilgunmust be valid or the certificate must be trusted and stored in the OpenAM local certificate file.<br/><br/>\
c04f76acce77126cf88b09350e56ea8c6b4a064enilgun<i>NB </i>Enabling <i>Trust All Server Certificates</i> will bypass the local certificate checking.
c04f76acce77126cf88b09350e56ea8c6b4a064enilguna111=Return User DN to DataStore
c04f76acce77126cf88b09350e56ea8c6b4a064enilguna111.help=Controls whether the DN or the username is returned as the authentication principal.
c04f76acce77126cf88b09350e56ea8c6b4a064enilgun## Note level should have the highest
c04f76acce77126cf88b09350e56ea8c6b4a064enilgun## number for i18N key since it should
af84459fbf938e508fd10b01cb8d699c79083813takashi## be the last attribute when viewed in
af84459fbf938e508fd10b01cb8d699c79083813takashi## the adminconsole
af84459fbf938e508fd10b01cb8d699c79083813takashia500=Authentication Level
af84459fbf938e508fd10b01cb8d699c79083813takashia500.help=The authentication level associated with this module.
af84459fbf938e508fd10b01cb8d699c79083813takashia500.help.txt=Each authentication module has an authentication level that can be used to indicate the level of security \
af84459fbf938e508fd10b01cb8d699c79083813takashiassociated with the module; 0 is the lowest (and the default).
b036ef2952fb6924b308f954b39786443460ddc6rpluema113=LDAP Server Check Interval
af84459fbf938e508fd10b01cb8d699c79083813takashia113.help=The interval of the check used to detect failure in the LDAP server; in minutes.
af84459fbf938e508fd10b01cb8d699c79083813takashia113.help.txt=This is the frequency that the LDAP module will check if the current LDAP server is available. If the server is not \
a114.help=Controls the mapping of local attribute to external attribute for dynamic profile creation.
a114.help.txt=If dynamic profile creation is enabled; this feature allows for a mapping between the attribute/values retrieved from \
the users authenticated profile and the attribute/values that will be provisioned into their matching account in the data store.\
a115.help=Enforced when the user is resetting their password as part of the authentication.
a115.help.txt=If the user needs to reset their password as part of the authentication process, the authentication module can enforce \
a minimum password length. This is separate from any password length controls from the underlying LDAP server. If the external LDAP \
a116.help=Enables support for modern LDAP password policies
a116.help.txt=LDAP Behera Password policies are supported by modern LDAP servers such as OpenDJ. If this functionality is disabled then \
a117.help=Enables a <code>X509TrustManager</code> that trusts all certificates.
a117.help.txt=This feature will allow the LDAP authentication module to connect to LDAP servers protected by self signed or invalid \