10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Indicates<br />

whether<br />

default<br />

policy<br />

overrides<br />

user<br />

level<br />

policy<br />

during<br />

LDAP<br />

searches.<br />

When<br />

this<br />

stanza<br />

entry<br />

is<br />

set<br />

to<br />

yes,<br />

only<br />

the<br />

default<br />

policy<br />

is<br />

checked.<br />

Valid<br />

values<br />

are:<br />

yes|true<br />

User<br />

policy<br />

support<br />

is<br />

disabled<br />

and<br />

only<br />

the<br />

global<br />

(default)<br />

policy<br />

is<br />

checked.<br />

This<br />

option<br />

allows<br />

the<br />

user<br />

policy<br />

to<br />

be<br />

ignored,<br />

even<br />

when<br />

it<br />

is<br />

specified.<br />

no|false<br />

User<br />

policy<br />

support<br />

is<br />

enabled.<br />

When<br />

a<br />

user<br />

policy<br />

is<br />

specified<br />

by<br />

the<br />

administrator,<br />

it<br />

overrides<br />

the<br />

global<br />

policy.<br />

This<br />

stanza<br />

entry<br />

is<br />

optional.<br />

By<br />

default,<br />

the<br />

value<br />

is<br />

not<br />

specified<br />

during<br />

<strong>WebSEAL</strong><br />

configuration.<br />

When<br />

the<br />

value<br />

is<br />

not<br />

specified,<br />

the<br />

default<br />

behavior<br />

is<br />

enable<br />

user<br />

policy<br />

support.<br />

This<br />

is<br />

equivalent<br />

to<br />

setting<br />

this<br />

stanza<br />

entry<br />

to<br />

no.<br />

Example:<br />

default-policy-override-support<br />

=<br />

yes<br />

user-and-group-in-same-suffix<br />

=<br />

{yes|true|no|false}<br />

Indicates<br />

whether<br />

the<br />

groups,<br />

in<br />

which<br />

a<br />

user<br />

is<br />

a<br />

member,<br />

are<br />

defined<br />

in<br />

the<br />

same<br />

LDAP<br />

suffix<br />

as<br />

the<br />

user<br />

definition.<br />

When<br />

a<br />

user<br />

is<br />

authenticated,<br />

the<br />

groups<br />

in<br />

which<br />

the<br />

user<br />

is<br />

a<br />

member<br />

must<br />

be<br />

determined<br />

in<br />

order<br />

to<br />

build<br />

a<br />

credential.<br />

Normally,<br />

all<br />

LDAP<br />

suffixes<br />

are<br />

searched<br />

to<br />

locate<br />

the<br />

groups<br />

of<br />

which<br />

the<br />

user<br />

is<br />

a<br />

member.<br />

Valid<br />

values<br />

are:<br />

yes|true<br />

The<br />

groups<br />

are<br />

assumed<br />

to<br />

be<br />

defined<br />

in<br />

same<br />

LDAP<br />

suffix<br />

as<br />

the<br />

user<br />

definition.<br />

Only<br />

that<br />

suffix<br />

is<br />

searched<br />

<strong>for</strong><br />

group<br />

membership.<br />

This<br />

behavior<br />

can<br />

improve<br />

the<br />

per<strong>for</strong>mance<br />

of<br />

group<br />

lookup<br />

because<br />

only<br />

a<br />

single<br />

suffix<br />

is<br />

searched<br />

<strong>for</strong><br />

group<br />

membership.<br />

This<br />

option<br />

should<br />

only<br />

be<br />

specified<br />

if<br />

group<br />

definitions<br />

are<br />

restricted<br />

to<br />

the<br />

same<br />

suffix<br />

as<br />

the<br />

user<br />

definition.<br />

no|false<br />

The<br />

groups<br />

might<br />

be<br />

defined<br />

in<br />

any<br />

LDAP<br />

suffix.<br />

This<br />

stanza<br />

entry<br />

is<br />

optional.<br />

The<br />

value<br />

is<br />

not<br />

specified<br />

by<br />

default<br />

during<br />

<strong>WebSEAL</strong><br />

configuration.<br />

When<br />

the<br />

value<br />

is<br />

not<br />

specified,<br />

the<br />

default<br />

value<br />

is<br />

no.<br />

Example:<br />

user-and-group-in-same-suffix<br />

=<br />

yes<br />

See<br />

also<br />

the<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

<strong>for</strong><br />

e-<strong>business</strong><br />

Per<strong>for</strong>mance<br />

Tuning<br />

Guide.<br />

Appendix<br />

A.<br />

<strong>WebSEAL</strong><br />

configuration<br />

file<br />

reference<br />

399

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!