Configuring Liberty Web Services
299
n
ov
do
cx (e
n)
16
Ap
ril 20
10
If you click the
Postal Address
attribute, you can see that all of its child attributes have
inherited the
Never Allow
setting. You can specify different permission attributes for
Address
Type
(for example), but the inherited policy still overrides changes made at the child level, as
shown below.
The interface allows these changes in order to simplify switching between configurations if, for
example, you want to remove an inherited policy.
Inherited:
Specifies the settings inherited from the parent attribute policy, when you view a
child attribute. In the User Portal, settings displayed under
Inherited
are not modifiable by the
user. At the top-level policy in the User Portal, the values are inherited from the settings in the
Administration Console. Thereafter, inheritance can come from the service policy or the parent
data item’s policy.
Ask Me:
Specifies that the service provider requests from the user what action to take.
Always Allow:
Specifies that the identity provider always allows the attribute data to be sent to
the service provider.
Never Allow:
Specifies that the identity provider never allows the attribute data to be sent to
the service provider.
When a request for data is received, the Identity Server examines policies to determine what
action to take. For example, if a service provider requires a postal address for the user, the
Identity Server performs the following actions:
Checks the settings specified in
All Service Providers
.
If no solution is found, checks for the policy settings configured for the service provider.
6
Click
OK
until the Web Service Provider page is displayed.
7
Click
OK
, then update the Identity Server as prompted.
Summary of Contents for ACCESS MANAGER 3.1 SP2 - README 2010
Page 4: ...4 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 12: ...12 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 158: ...158 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 172: ...172 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 182: ...182 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 290: ...290 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 362: ...362 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 374: ...374 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...