| # PIP Engine Definition |
| # |
| xacml.pip.engines=ldap1 |
| |
| ldap1.classname=org.apache.openaz.xacml.std.pip.engines.ldap.LDAPEngine |
| ldap1.name=LDAP PIP |
| ldap1.description=The LDAP containing the seven seas sample LDIF data. |
| ldap1.issuer=org.apache.openaz:xacml:test:ldap |
| ldap1.java.naming.factory.initial=com.sun.jndi.ldap.LdapCtxFactory |
| # |
| # NOTE: You will have to setup a local LDAP server and load the data\apache-ds-tutorial.ldif before |
| # this example will work. |
| # |
| #ldap1.java.naming.provider.url=ldap://localhost:10389 |
| ldap1.java.naming.provider.url=ldap://xacml-pip.research.att.com:10389 |
| #ldap.java.naming.security.principal= |
| #ldap.java.naming.security.credentials= |
| ldap1.scope=subtree |
| |
| ldap1.resolvers=dn,ship |
| |
| ldap1.resolver.dn.classname=org.apache.openaz.xacml.std.pip.engines.ldap.ConfigurableLDAPResolver |
| ldap1.resolver.dn.name=Domain Names |
| ldap1.resolver.dn.description=Find all the dn's for the subject id |
| ldap1.resolver.dn.base=o=sevenseas |
| ldap1.resolver.dn.base.parameters= |
| ldap1.resolver.dn.filter=(|(uid=${uid})(mail=${uid})) |
| ldap1.resolver.dn.filter.parameters=uid |
| ldap1.resolver.dn.filter.parameters.uid.id=urn:oasis:names:tc:xacml:1.0:subject:subject-id |
| ldap1.resolver.dn.filter.parameters.uid.datatype=http://www.w3.org/2001/XMLSchema#string |
| ldap1.resolver.dn.filter.parameters.uid.category=urn:oasis:names:tc:xacml:1.0:subject-category:access-subject |
| #ldap1.resolver.dn.filter.parameters.uid.issuer=org.apache.openaz:xacml:test:ldap |
| ldap1.resolver.dn.filter.view=dn |
| ldap1.resolver.dn.filter.view.dn.id=org.apache.openaz:xacml:test:ldap:subject:dn |
| ldap1.resolver.dn.filter.view.dn.datatype=http://www.w3.org/2001/XMLSchema#string |
| ldap1.resolver.dn.filter.view.dn.category=urn:oasis:names:tc:xacml:3.0:attribute-category:resource |
| ldap1.resolver.dn.filter.view.dn.issuer=org.apache.openaz:xacml:test:ldap |
| |
| ldap1.resolver.ship.classname=org.apache.openaz.xacml.std.pip.engines.ldap.ConfigurableLDAPResolver |
| ldap1.resolver.ship.name=Ship Resolver |
| ldap1.resolver.ship.description=This resolves a subject's dn to a ship. |
| ldap1.resolver.ship.base=o=sevenseas |
| ldap1.resolver.ship.base.parameters= |
| ldap1.resolver.ship.filter=uniquemember=${dn} |
| ldap1.resolver.ship.filter.parameters=dn |
| ldap1.resolver.ship.filter.parameters.dn.id=org.apache.openaz:xacml:test:ldap:subject:dn |
| ldap1.resolver.ship.filter.parameters.dn.datatype=http://www.w3.org/2001/XMLSchema#string |
| ldap1.resolver.ship.filter.parameters.dn.category=urn:oasis:names:tc:xacml:3.0:attribute-category:resource |
| ldap1.resolver.ship.filter.parameters.dn.issuer=org.apache.openaz:xacml:test:ldap |
| ldap1.resolver.ship.filter.view=cn |
| ldap1.resolver.ship.filter.view.cn.id=org.apache.openaz:xacml:test:ldap:subject:ship |
| ldap1.resolver.ship.filter.view.cn.datatype=http://www.w3.org/2001/XMLSchema#string |
| ldap1.resolver.ship.filter.view.cn.category=urn:oasis:names:tc:xacml:3.0:attribute-category:resource |
| ldap1.resolver.ship.filter.view.cn.issuer=org.apache.openaz:xacml:test:ldap |
| |