298
Novell Access Manager 3.1 SP2 Identity Server Guide
n
ov
do
cx (e
n)
16
Ap
ril 20
10
first looks here to determine whether user data is allowed, never allowed, or must be asked for.
If no solution is found in All Trusted Providers, the system examines the permissions
established within the specific service provider.
Owners:
Policies that limit the end user’s ability to modify or query data from his or her own
profile. The settings you specify in the
Owner
group are reflected on the My Profile page in the
User Portal. Portal users have the authority to modify the data items in their profiles. The data
items include Liberty and LDAP attributes for personal identity, employment, and any
customized attributes defined in the Identity Server configuration. Any settings you specify in
the Administration Console override what is displayed in the User Portal. Overrides are
displayed in the
Inherited
column.
If you want the user to have Write permission for a given data item, and that data item is used in
an LDAP Attribute Map, then you must configure the LDAP Attribute Map with Write
permission.
4
On the All Service Policy page, select the policy’s check box, then click
Edit Policy
.
This lets you modify the parent service policy attribute. Any selections you specify on this page
are inherited by child policies.
Query Policy:
Allows the service provider to query for the data on a particular attribute. This
is similar to read access to a particular piece of data.
Modify Policy:
Allows the service provider to modify a particular attribute. This is similar to
write access to a particular piece of data.
Query and Modify:
Allows you to set both options at once.
5
To edit child attributes of the parent, click the policy.
In the following example, child attributes are inheriting Ask Me permission from the parent
Entire Personal Identity
attribute. The
Postal Address
attribute, however, is modified to never
allow permission for sharing.
Содержание ACCESS MANAGER 3.1 SP2 - README 2010
Страница 4: ...4 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Страница 12: ...12 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Страница 158: ...158 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Страница 172: ...172 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Страница 182: ...182 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Страница 290: ...290 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Страница 362: ...362 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Страница 374: ...374 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...