Portions copyright 2011-2014 ForgeRock AS. <!
DOCTYPE ServicesConfiguration PUBLIC "=//iPlanet//Service Management Services (SMS) 1.0 DTD//EN" <
Service name="sunEntitlementService" version="1.0">
<
Schema i18nFileName="" revisionNumber="20">
<
AttributeSchema name="usenewconsole" <
AttributeSchema name="migratedtoentitlementservice" <
AttributeSchema name="xacml-privilege-enabled" <
AttributeSchema name="evalThreadSize" rangeStart="0" rangeEnd="200" <
AttributeSchema name="searchThreadSize" rangeStart="0" rangeEnd="200" <
AttributeSchema name="policyCacheSize" rangeStart="0" rangeEnd="2147483647" <
AttributeSchema name="indexCacheSize" rangeStart="0" rangeEnd="2147483647" <!-- entitlement notification, Connection timeout in millisec, <
AttributeSchema name="entitlement-notifier-conn-timeout" rangeStart="0" rangeEnd="300000" <
AttributeSchema name="entitlement-notifier-retries" rangeStart="0" rangeEnd="50" <!-- duration between retries in millisec, max 5 mins --> <
AttributeSchema name="entitlement-notifier-duration-between-retries" rangeStart="0" rangeEnd="300000" <!-- Privilege change notification Connection timeout in millisec, max 5 mins --> <
AttributeSchema name="privilege-notifier-conn-timeout" rangeStart="0" rangeEnd="300000" <
AttributeSchema name="privilege-notifier-retries" rangeStart="0" rangeEnd="50" <!-- duration between retries in millisec, max 5 mins --> <
AttributeSchema name="privilege-notifier-duration-between-retries" rangeStart="0" rangeEnd="300000" <
AttributeSchema name="privilege-notifier-threadpool-size" rangeStart="0" rangeEnd="20" <
AttributeSchema name="network-monitor-enabled" <
AttributeSchema name="listeners" <
SubSchema name="applicationTypes" inheritance="multiple">
<
SubSchema name="applicationType" inheritance="multiple">
<
AttributeSchema name="applicationClassName" <
AttributeSchema name="actions" <
AttributeSchema name="searchIndexImpl" <
AttributeSchema name="saveIndexImpl" <
AttributeSchema name="resourceComparator" <
AttributeSchema name="nonBooleanActionValues" <
SubSchema name="applications" inheritance="multiple">
<
SubSchema name="application" inheritance="multiple">
<
AttributeSchema name="applicationType" <
AttributeSchema name="description" <
AttributeSchema name="actions" <
AttributeSchema name="resources" <
AttributeSchema name="subjects" <
AttributeSchema name="conditions" <
AttributeSchema name="entitlementCombiner" <
AttributeSchema name="searchIndexImpl" <
AttributeSchema name="saveIndexImpl" <
AttributeSchema name="resourceComparator" <
AttributeSchema name="subjectAttributeNames" <
AttributeSchema name="meta" <
SubSchema name="subjectAttributesCollectors" inheritance="multiple">
<
SubSchema name="OpenSSOSubjectAttributesCollector" inheritance="multiple">
<
AttributeSchema name="class" <
AttributeSchema name="groupMembershipSearchIndexEnabled" <
SubConfiguration name="applicationTypes" id="applicationTypes">
<
SubConfiguration name="iPlanetAMWebAgentService" <
Attribute name="actions" />
<
Value>DELETE=true</
Value>
<
Value>OPTIONS=true</
Value>
<
Value>PATCH=true</
Value>
<
Attribute name="searchIndexImpl" />
<
Attribute name="saveIndexImpl" />
<
Attribute name="resourceComparator" />
<
SubConfiguration name="crestPolicyService" id="applicationType">
<
Attribute name="actions" />
<
Value>CREATE=true</
Value>
<
Value>UPDATE=true</
Value>
<
Value>DELETE=true</
Value>
<
Value>PATCH=true</
Value>
<
Value>ACTION=true</
Value>
<
Value>QUERY=true</
Value>
<
Attribute name="searchIndexImpl" />
<
Attribute name="saveIndexImpl" />
<
Attribute name="resourceComparator" />
<
SubConfiguration name="sunIdentityServerDiscoveryService" <
Attribute name="actions" />
<
Value>LOOKUP=true</
Value>
<
Value>UPDATE=true</
Value>
<
Attribute name="searchIndexImpl" />
<
Attribute name="saveIndexImpl" />
<
Attribute name="resourceComparator" />
<
SubConfiguration name="sunIdentityServerLibertyPPService" <
Attribute name="actions" />
<
Value>QUERY_allow=true</
Value>
<
Value>QUERY_deny=false</
Value>
<
Value>QUERY_interactForValue=false</
Value>
<
Value>QUERY_interactForConsent=false</
Value>
<
Value>MODIFY_allow=true</
Value>
<
Value>MODIFY_deny=false</
Value>
<
Value>MODIFY_interactForValue=false</
Value>
<
Value>MODIFY_interactForConsent=false</
Value>
<
Attribute name="nonBooleanActionValues" />
<
Value>QUERY=deny,allow,interactForValue,interactForConsent</
Value>
<
Value>MODIFY=deny,allow,interactForValue,interactForConsent</
Value>
<
Attribute name="searchIndexImpl" />
<
Attribute name="saveIndexImpl" />
<
Attribute name="resourceComparator" />
<
SubConfiguration name="sunAMDelegationService" <
Attribute name="actions" />
<
Value>MODIFY=true</
Value>
<
Value>DELEGATE=true</
Value>
<
Attribute name="searchIndexImpl" />
<
Attribute name="saveIndexImpl" />
<
Attribute name="resourceComparator" />
<
SubConfiguration name="openProvisioning" <
Attribute name="actions" />
<
Value>CREATE=true</
Value>
<
Value>UPDATE=true</
Value>
<
Value>DELETE=true</
Value>
<
Attribute name="searchIndexImpl" />
<
Attribute name="saveIndexImpl" />
<
Attribute name="resourceComparator" />
<
SubConfiguration name="banking" <
Attribute name="actions" />
<
Value>TRANSFER=true</
Value>
<
Attribute name="searchIndexImpl" />
<
Attribute name="saveIndexImpl" />
<
Attribute name="resourceComparator" />
<
SubConfiguration name="webservices" <
Attribute name="applicationClassName" />
<
Attribute name="searchIndexImpl" />
<
Attribute name="saveIndexImpl" />
<
Attribute name="resourceComparator" />
<
OrganizationConfiguration name="/">
<
SubConfiguration name="registeredApplications" <
SubConfiguration name="iPlanetAMWebAgentService" <
Attribute name="applicationType" />
<
Value>iPlanetAMWebAgentService</
Value>
<
Attribute name="resources" />
<
Attribute name="subjects" />
<
Attribute name="conditions" />
<!-- <Value>dateRange</Value> <Value>daysOfWeek</Value> <
Attribute name="entitlementCombiner" />
<
Value>DenyOverride</
Value>
<
SubConfiguration name="crestPolicyService" id="application">
<
Attribute name="applicationType" />
<
Value>crestPolicyService</
Value>
<
Attribute name="resources" />
<
Attribute name="subjects" />
<
Attribute name="conditions" />
<!-- <Value>dateRange</Value> <Value>daysOfWeek</Value> <
Attribute name="entitlementCombiner" />
<
Value>DenyOverride</
Value>
<
SubConfiguration name="sunIdentityServerDiscoveryService" <
Attribute name="applicationType" />
<
Value>sunIdentityServerDiscoveryService</
Value>
<
Attribute name="resources" />
<
Attribute name="subjects" />
<
Attribute name="conditions" />
<!-- <Value>dateRange</Value> <Value>daysOfWeek</Value> <
Attribute name="entitlementCombiner" />
<
Value>DenyOverride</
Value>
<
SubConfiguration name="sunIdentityServerLibertyPPService" <
Attribute name="applicationType" />
<
Value>sunIdentityServerLibertyPPService</
Value>
<
Attribute name="resources" />
<
Attribute name="subjects" />
<
Attribute name="conditions" />
<Value>daysOfWeek</Value> <
Attribute name="entitlementCombiner" />
<
Value>DenyOverride</
Value>
<
SubConfiguration name="sunAMDelegationService" <
Attribute name="applicationType" />
<
Value>sunAMDelegationService</
Value>
<
Attribute name="resources" />
<
Attribute name="subjects" />
<
Attribute name="entitlementCombiner" />
<
Value>DenyOverride</
Value>
<
SubConfiguration name="openProvisioning" <
Attribute name="applicationType" />
<
Value>openProvisioning</
Value>
<
Attribute name="resources" />
<
Attribute name="entitlementCombiner" />
<
Value>DenyOverride</
Value>
<
SubConfiguration name="paycheck" <
Attribute name="applicationType" />
<
Value>iPlanetAMWebAgentService</
Value>
<
Attribute name="resources" />
<
Attribute name="subjects" />
<
Attribute name="conditions" />
<
Attribute name="entitlementCombiner" />
<
Value>DenyOverride</
Value>
<
SubConfiguration name="calendar" <
Attribute name="applicationType" />
<
Value>iPlanetAMWebAgentService</
Value>
<
Attribute name="resources" />
<
Attribute name="subjects" />
<
Attribute name="conditions" />
<Value>daysOfWeek</Value> <
Attribute name="entitlementCombiner" />
<
Value>DenyOverride</
Value>
<
SubConfiguration name="im" <
Attribute name="applicationType" />
<
Value>iPlanetAMWebAgentService</
Value>
<
Attribute name="resources" />
<
Attribute name="subjects" />
<
Attribute name="conditions" />
<Value>daysOfWeek</Value> <Value>ipRange</Value> --> <
Attribute name="entitlementCombiner" />
<
Value>DenyOverride</
Value>
<
SubConfiguration name="sunBank" <
Attribute name="applicationType" />
<
Attribute name="resources" />
<
Attribute name="subjects" />
<
Attribute name="conditions" />
<
Value>NumericAttribute</
Value>
<Value>upperTransferLimit</Value> <Value>lowerTransferLimit</Value> <Value>anyTransferLimit</Value> <Value>daysOfWeek</Value> <
Attribute name="entitlementCombiner" />
<
Value>DenyOverride</
Value>
<
SubConfiguration name="subjectAttributesCollectors" id="subjectAttributesCollectors">
<
SubConfiguration name="OpenSSO" id="OpenSSOSubjectAttributesCollector">
<
Attribute name="class" />
<
Attribute name="groupMembershipSearchIndexEnabled" />
</
OrganizationConfiguration>