2N/A<?
xml version="1.0" encoding="UTF-8"?>
2N/A DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS HEADER. 2N/A Copyright (c) 2009 Sun Microsystems Inc. All Rights Reserved 2N/A The contents of this file are subject to the terms 2N/A of the Common Development and Distribution License 2N/A (the License). You may not use this file except in 2N/A compliance with the License. 2N/A You can obtain a copy of the License at 2N/A See the License for the specific language governing 2N/A permission and limitations under the License. 2N/A When distributing Covered Code, include this CDDL 2N/A Header Notice in each file and include the License file 2N/A If applicable, add the following below the CDDL Header, 2N/A with the fields enclosed by brackets [] replaced by 2N/A your own identifying information: 2N/A "Portions Copyrighted [year] [name of copyright owner]" 2N/A Portions copyright 2011-2014 ForgeRock AS. 2N/A<!
DOCTYPE ServicesConfiguration 2N/A PUBLIC "=//iPlanet//Service Management Services (SMS) 1.0 DTD//EN" 2N/A<
ServicesConfiguration>
2N/A <
Service name="sunEntitlementService" version="1.0">
2N/A <
Schema i18nFileName="" revisionNumber="20">
2N/A <
AttributeSchema name="usenewconsole" 2N/A <
AttributeSchema name="migratedtoentitlementservice" 2N/A <
AttributeSchema name="xacml-privilege-enabled" 2N/A <
Value>false</
Value>
2N/A <
AttributeSchema name="evalThreadSize" 2N/A syntax="number_range" 2N/A rangeStart="0" rangeEnd="200" 2N/A <
AttributeSchema name="searchThreadSize" 2N/A syntax="number_range" 2N/A rangeStart="0" rangeEnd="200" 2N/A <
AttributeSchema name="policyCacheSize" 2N/A syntax="number_range" 2N/A rangeStart="0" rangeEnd="2147483647" 2N/A <
Value>100000</
Value>
2N/A <
AttributeSchema name="indexCacheSize" 2N/A syntax="number_range" 2N/A rangeStart="0" rangeEnd="2147483647" 2N/A <
Value>100000</
Value>
2N/A <!-- entitlement notification, Connection timeout in millisec, 2N/A <
AttributeSchema name="entitlement-notifier-conn-timeout" 2N/A syntax="number_range" 2N/A rangeStart="0" rangeEnd="300000" 2N/A <
AttributeSchema name="entitlement-notifier-retries" 2N/A syntax="number_range" 2N/A rangeStart="0" rangeEnd="50" 2N/A <!-- duration between retries in millisec, max 5 mins --> 2N/A <
AttributeSchema name="entitlement-notifier-duration-between-retries" 2N/A syntax="number_range" 2N/A rangeStart="0" rangeEnd="300000" 2N/A <!-- Privilege change notification 2N/A Connection timeout in millisec, max 5 mins --> 2N/A <
AttributeSchema name="privilege-notifier-conn-timeout" 2N/A syntax="number_range" 2N/A rangeStart="0" rangeEnd="300000" 2N/A <
AttributeSchema name="privilege-notifier-retries" 2N/A syntax="number_range" 2N/A rangeStart="0" rangeEnd="50" <!-- duration between retries in millisec, max 5 mins --> <
AttributeSchema name="privilege-notifier-duration-between-retries" rangeStart="0" rangeEnd="300000" <
AttributeSchema name="privilege-notifier-threadpool-size" rangeStart="0" rangeEnd="20" <
AttributeSchema name="network-monitor-enabled" <
AttributeSchema name="listeners" <
SubSchema name="applicationTypes" inheritance="multiple">
<
SubSchema name="applicationType" inheritance="multiple">
<
AttributeSchema name="applicationClassName" <
AttributeSchema name="actions" <
AttributeSchema name="searchIndexImpl" <
AttributeSchema name="saveIndexImpl" <
AttributeSchema name="resourceComparator" <
AttributeSchema name="nonBooleanActionValues" <
SubSchema name="applications" inheritance="multiple">
<
SubSchema name="application" inheritance="multiple">
<
AttributeSchema name="applicationType" <
AttributeSchema name="description" <
AttributeSchema name="actions" <
AttributeSchema name="resources" <
AttributeSchema name="subjects" <
AttributeSchema name="conditions" <
AttributeSchema name="entitlementCombiner" <
AttributeSchema name="searchIndexImpl" <
AttributeSchema name="saveIndexImpl" <
AttributeSchema name="resourceComparator" <
AttributeSchema name="subjectAttributeNames" <
AttributeSchema name="meta" <
SubSchema name="subjectAttributesCollectors" inheritance="multiple">
<
SubSchema name="OpenSSOSubjectAttributesCollector" inheritance="multiple">
<
AttributeSchema name="class" <
AttributeSchema name="groupMembershipSearchIndexEnabled" <
SubConfiguration name="applicationTypes" id="applicationTypes">
<
SubConfiguration name="iPlanetAMWebAgentService" <
Attribute name="actions" />
<
Value>DELETE=true</
Value>
<
Value>OPTIONS=true</
Value>
<
Value>PATCH=true</
Value>
<
Attribute name="searchIndexImpl" />
<
Attribute name="saveIndexImpl" />
<
Attribute name="resourceComparator" />
<
SubConfiguration name="crestPolicyService" id="applicationType">
<
Attribute name="actions" />
<
Value>CREATE=true</
Value>
<
Value>UPDATE=true</
Value>
<
Value>DELETE=true</
Value>
<
Value>PATCH=true</
Value>
<
Value>ACTION=true</
Value>
<
Value>QUERY=true</
Value>
<
Attribute name="searchIndexImpl" />
<
Attribute name="saveIndexImpl" />
<
Attribute name="resourceComparator" />
<
SubConfiguration name="sunIdentityServerDiscoveryService" <
Attribute name="actions" />
<
Value>LOOKUP=true</
Value>
<
Value>UPDATE=true</
Value>
<
Attribute name="searchIndexImpl" />
<
Attribute name="saveIndexImpl" />
<
Attribute name="resourceComparator" />
<
SubConfiguration name="sunIdentityServerLibertyPPService" <
Attribute name="actions" />
<
Value>QUERY_allow=true</
Value>
<
Value>QUERY_deny=false</
Value>
<
Value>QUERY_interactForValue=false</
Value>
<
Value>QUERY_interactForConsent=false</
Value>
<
Value>MODIFY_allow=true</
Value>
<
Value>MODIFY_deny=false</
Value>
<
Value>MODIFY_interactForValue=false</
Value>
<
Value>MODIFY_interactForConsent=false</
Value>
<
Attribute name="nonBooleanActionValues" />
<
Value>QUERY=deny,allow,interactForValue,interactForConsent</
Value>
<
Value>MODIFY=deny,allow,interactForValue,interactForConsent</
Value>
<
Attribute name="searchIndexImpl" />
<
Attribute name="saveIndexImpl" />
<
Attribute name="resourceComparator" />
<
SubConfiguration name="sunAMDelegationService" <
Attribute name="actions" />
<
Value>MODIFY=true</
Value>
<
Value>DELEGATE=true</
Value>
<
Attribute name="searchIndexImpl" />
<
Attribute name="saveIndexImpl" />
<
Attribute name="resourceComparator" />
<
SubConfiguration name="openProvisioning" <
Attribute name="actions" />
<
Value>CREATE=true</
Value>
<
Value>UPDATE=true</
Value>
<
Value>DELETE=true</
Value>
<
Attribute name="searchIndexImpl" />
<
Attribute name="saveIndexImpl" />
<
Attribute name="resourceComparator" />
<
SubConfiguration name="banking" <
Attribute name="actions" />
<
Value>TRANSFER=true</
Value>
<
Attribute name="searchIndexImpl" />
<
Attribute name="saveIndexImpl" />
<
Attribute name="resourceComparator" />
<
SubConfiguration name="webservices" <
Attribute name="applicationClassName" />
<
Attribute name="searchIndexImpl" />
<
Attribute name="saveIndexImpl" />
<
Attribute name="resourceComparator" />
<
OrganizationConfiguration name="/">
<
SubConfiguration name="registeredApplications" <
SubConfiguration name="iPlanetAMWebAgentService" <
Attribute name="applicationType" />
<
Value>iPlanetAMWebAgentService</
Value>
<
Attribute name="resources" />
<
Attribute name="subjects" />
<
Attribute name="conditions" />
<
Value>daysOfWeek</
Value>
<
Attribute name="entitlementCombiner" />
<
SubConfiguration name="crestPolicyService" id="application">
<
Attribute name="applicationType" />
<
Value>crestPolicyService</
Value>
<
Attribute name="resources" />
<
Attribute name="subjects" />
<
Attribute name="conditions" />
<
Value>daysOfWeek</
Value>
<
Attribute name="entitlementCombiner" />
<
SubConfiguration name="sunIdentityServerDiscoveryService" <
Attribute name="applicationType" />
<
Value>sunIdentityServerDiscoveryService</
Value>
<
Attribute name="resources" />
<
Attribute name="subjects" />
<
Attribute name="conditions" />
<
Value>daysOfWeek</
Value>
<
Attribute name="entitlementCombiner" />
<
SubConfiguration name="sunIdentityServerLibertyPPService" <
Attribute name="applicationType" />
<
Value>sunIdentityServerLibertyPPService</
Value>
<
Attribute name="resources" />
<
Attribute name="subjects" />
<
Attribute name="conditions" />
<
Value>daysOfWeek</
Value>
<
Attribute name="entitlementCombiner" />
<
SubConfiguration name="sunAMDelegationService" <
Attribute name="applicationType" />
<
Value>sunAMDelegationService</
Value>
<
Attribute name="resources" />
<
Attribute name="subjects" />
<
Attribute name="entitlementCombiner" />
<
SubConfiguration name="openProvisioning" <
Attribute name="applicationType" />
<
Value>openProvisioning</
Value>
<
Attribute name="resources" />
<
Attribute name="entitlementCombiner" />
<
SubConfiguration name="paycheck" <
Attribute name="applicationType" />
<
Value>iPlanetAMWebAgentService</
Value>
<
Attribute name="resources" />
<
Attribute name="subjects" />
<
Attribute name="conditions" />
<
Attribute name="entitlementCombiner" />
<
SubConfiguration name="calendar" <
Attribute name="applicationType" />
<
Value>iPlanetAMWebAgentService</
Value>
<
Attribute name="resources" />
<
Attribute name="subjects" />
<
Attribute name="conditions" />
<
Value>daysOfWeek</
Value>
<
Attribute name="entitlementCombiner" />
<
SubConfiguration name="im" <
Attribute name="applicationType" />
<
Value>iPlanetAMWebAgentService</
Value>
<
Attribute name="resources" />
<
Attribute name="subjects" />
<
Attribute name="conditions" />
<
Value>daysOfWeek</
Value>
<
Attribute name="entitlementCombiner" />
<
SubConfiguration name="sunBank" <
Attribute name="applicationType" />
<
Attribute name="resources" />
<
Attribute name="subjects" />
<
Attribute name="conditions" />
<
Value>upperTransferLimit</
Value>
<
Value>lowerTransferLimit</
Value>
<
Value>anyTransferLimit</
Value>
<
Value>daysOfWeek</
Value>
<
Attribute name="entitlementCombiner" />
<
SubConfiguration name="subjectAttributesCollectors" id="subjectAttributesCollectors">
<
SubConfiguration name="OpenSSO" id="OpenSSOSubjectAttributesCollector">
<
Attribute name="class" />
<
Attribute name="groupMembershipSearchIndexEnabled" />
</
OrganizationConfiguration>