10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Extended<br />

attributes<br />

in<br />

the<br />

token<br />

that<br />

do<br />

not<br />

match<br />

an<br />

entry<br />

in<br />

[cdsso-incoming-attributes]<br />

are<br />

preserved<br />

(extracted).<br />

The<br />

order<br />

of<br />

the<br />

entries<br />

in<br />

the<br />

stanza<br />

is<br />

important.<br />

The<br />

first<br />

entry<br />

that<br />

matches<br />

an<br />

attribute<br />

name<br />

is<br />

used.<br />

Other<br />

entries<br />

are<br />

ignored.<br />

For<br />

example,<br />

if<br />

you<br />

want<br />

to<br />

extract<br />

the<br />

attribute<br />

named<br />

my_special_attr1<br />

but<br />

want<br />

to<br />

ignore<br />

all<br />

other<br />

entries<br />

with<br />

the<br />

prefix<br />

my_special_attr_,<br />

the<br />

stanza<br />

entries<br />

should<br />

be:<br />

[cdsso-incoming-attributes]<br />

my_special_attr1<br />

=<br />

preserve<br />

my_special_attr_*<br />

=<br />

refresh<br />

Using<br />

the<br />

examples<br />

shown<br />

above<br />

in<br />

“Specify<br />

extended<br />

attributes<br />

to<br />

add<br />

to<br />

token”<br />

on<br />

page<br />

253,<br />

the<br />

entries<br />

in<br />

the<br />

<strong>WebSEAL</strong><br />

configuration<br />

file<br />

<strong>for</strong><br />

a<br />

server<br />

that<br />

operates<br />

in<br />

the<br />

example2.com<br />

domain<br />

could<br />

be:<br />

[cdsso-incoming-attributes]<br />

job_category<br />

=<br />

preserve<br />

my_cdas_attr_1<br />

=<br />

preserve<br />

my_cdas_attr_*<br />

=<br />

refresh<br />

In<br />

this<br />

example,<br />

the<br />

attributes<br />

job_category<br />

and<br />

my_cdas_attr_1<br />

are<br />

extracted<br />

from<br />

the<br />

token.<br />

The<br />

remainder<br />

of<br />

the<br />

attributes<br />

with<br />

the<br />

prefix<br />

my_cdas_attr_<br />

are<br />

ignored.<br />

Chapter<br />

9.<br />

Client<br />

single<br />

sign-on<br />

solutions<br />

255

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!