Contained WithinFind More DocumentationFeatured Support Resources | Download this book in PDF (1704 KB)
Appendix B Access Manager User LDAP EntriesA Sun JavaTM System Access Manager deployment that stores users in an LDAP directory other than Sun Java System Directory Server must add the following object classes and attributes to the directory schema: For example, if you have configured a generic LDAPv3 repository plug-in or a Microsoft® Active Directory plug-in for a realm, you must create and add the user schema to the datastore. You must perform this operation manually, because pre-populated LDIF files are not currently available to use. Object Classesiplanet-am-session-service Object ClassSupported by: Access Manager Definition: Contains session service related attributes. Superior Class: top Object Class Type: auxiliary Required Attributes: none Allowed Attributes: iplanet-am-user-service Object ClassSupported by: Access Manager Definition: Contains the Access Manager attributes necessary to manage user accounts. Superior Class: top Object Class Type: auxiliary Required Attributes: none Allowed Attributes: iplanet-am-managed-person Object ClassSupported by: Access Manager Definition: Contains Access Manager attributes used to manage users. Superior Class: top Object Class Type: auxiliary Required Attributes: none Allowed Attributes: sunAMAuthAccountLockout Object ClassSupported by: Access Manager Definition: Contains Access Manager attributes used to manage invalid login attempts and user lock out. Superior Class: top Object Class Type: auxiliary Required Attributes: none Allowed Attributes: inetUser Object ClassSupported by: Sun One Directory Server Definition: Auxiliary class that has to be present in an entry for delivery of subscriber services. Superior Class: top Object Class Type: auxiliary Required Attributes: none Allowed Attributes: iplanet-am-saml-service Object ClassSupported by: Access Manager Definition: Contains SAML service related attributes. Superior Class: top Object Class Type: auxiliary Required Attributes: none Allowed Attributes: sunIdentityServerDiscoveryService Object ClassSupported by: Access Manager Definition: Contains Discovery Service related attributes. Superior Class: top Object Class Type: auxiliary Required Attributes: none Allowed Attributes: sunIdentityServerLibertyPPService Object ClassSupported by: Access Manager Definition: Contains session service related personal profile (PP) attributes. Superior Class: top Object Class Type: auxiliary Required Attributes: none Allowed Attributes: Attributesiplanet-am-session-service Object Class Attributesiplanet-am-session-max-session-timeSyntax: string Description: Specifies the maximum session service Time iplanet-am-session-max-idle-timeSyntax: string Description: Specifies the maximum session idle time. iplanet-am-session-max-caching-timeSyntax: string Description: Specifies the maximum session caching time. iplanet-am-session-quota-limitSyntax: string Description: Specifies the session quota constraints. iplanet-am-session-service-statusSyntax: string Description: Specifies the maximum session service status. iplanet-am-session-get-valid-sessionsSyntax: string Description: Specifies the get valid sessions. iplanet-am-session-destroy-sessionsSyntax: string Description: Specifies destroy session. iplanet-am-session-add-session-listener-on-all-sessionsSyntax: string Description: Specifies add session listener on all sessions. iplanet-am-user-service Object Class Attributesiplanet-am-user-admin-start-dnSupported by: Access Manager Syntax: dn, single-valued Description: Specifies the starting point node (DN) displayed in the starting view of the Access Manager Console when this administrator logs in. iplanet-am-user-alias-listSyntax: string Description: Specifies the user alias names list. iplanet-am-user-auth-configSyntax: string Description: Specifies the user authentication configuration. sunIdentityMSISDNNumberSyntax: string Description: Specifies the user Mobile Station Integrated Services Digital Network (MSISDN) number. iplanet-am-user-failure-urlSyntax: string Description: Specifies the redirection URL for a failed user authentication. iplanet-am-user-success-urlSyntax: string Description: Specifies the redirection URL for a successful user authentication. iplanet-am-user-login-statusSyntax: string, single-valued Description: Specifies the user login status:
iplanet-am-user-password-reset-force-resetSyntax: string Description: Specifies the Password Reset Force Reset password. iplanet-am-user-password-reset-optionsSupported by: Access Manager Syntax: string, single-valued Description: Specifies options used by the Access Manager password reset module. iplanet-am-user-password-reset-question-answerSupported by: Access Manager Syntax: string, single-valued Description: Specifies the password question and answer used to prompt a user who has forgotten the password. The format is question answer. iplanet-am-user-service-statusSupported by: Access Manager Syntax: dn, single-valued Description: Specifies the status of the user for various services. iplanet-am-user-federation-info-keySyntax: string Description: Specifies the user Federation information key. iplanet-am-user-federation-infoSyntax: string Description: Specifies user Federation information. iplanet-am-managed-person Object Class Attributesiplanet-am-modifiable-bySupported by: Access Manager Syntax: dn, multi-valued Description: Specifies the role-dn of the administrator who has access rights to modify this user entry. By default, the value is set to the role-dn of the administrator who created the account. iplanet-am-role-aci-descriptionSupported by: Access Manager Syntax: string, multi-valued Description: Specifies the description of the ACI that belongs to this role. iplanet-am-static-group-dnSupported by: Access Manager Syntax: dn, multi-valued Description: Defines the DNs for the static groups that this user belongs to. iplanet-am-user-account-lifeSyntax: date string, single-valued Description: Specifies the account expiration date in the following format: yyyy/mm/dd hh:mm:ss sunAMAuthAccountLockout Object Class AttributessunAMAuthInvalidAttemptsDataSyntax: string Description: Specifies XML data for invalid login attempts. inetUser Object Class AttributesinetUserStatusSyntax: string Possible values: "active", "inactive", or "deleted" Description: Specifies the status of a user. iplanet-am-saml-service Object Class Attributesiplanet-am-saml-userSyntax: string Description: Specifies the SAML user ID. iplanet-am-saml-passwordSyntax: string Description: Specifies the SAML user password. sunIdentityServerDiscoveryService Object Class AttributessunIdentityServerDynamicDiscoEntriesSyntax: string Description: Specifies the dynamic disco entries. sunIdentityServerLibertyPPService Object Class AttributessunIdentityServerPPCommonNameCNSyntax: string Description: Specifies the Liberty PP common name. sunIdentityServerPPCommonNameAltCNSyntax: string Description: Specifies the Liberty PP alternate common name. sunIdentityServerPPCommonNameFNSyntax: string Description: Specifies the Liberty PP common name first name. sunIdentityServerPPCommonNameSNSyntax: string Description: Specifies the Liberty PP common name surname. sunIdentityServerPPCommonNamePTSyntax: string Description: Specifies the Liberty PP common name first name personal title. sunIdentityServerPPCommonNameMNSyntax: string Description: Specifies the Liberty PP common name middle name. sunIdentityServerPPInformalNameSyntax: string Description: Specifies the Liberty PP informal name. sunIdentityServerPPLegalIdentityLegalNameSyntax: string Description: Specifies the Liberty PP legal name. sunIdentityServerPPLegalIdentityDOBSyntax: string Description: Specifies the Liberty PP date of birth. sunIdentityServerPPLegalIdentityMaritalStatusSyntax: string Description: Specifies the Liberty PP marital status. sunIdentityServerPPLegalIdentityGenderSyntax: string Description: Specifies the Liberty PP gender. sunIdentityServerPPLegalIdentityAltIDTypeSyntax: string Description: Specifies the Liberty PP alternate identity type. sunIdentityServerPPLegalIdentityAltIDValueSyntax: string Description: Specifies the Liberty PP alternate identity value. sunIdentityServerPPLegalIdentityVATIDTypeSyntax: string Description: Specifies the Liberty PP legal identity VATID type. sunIdentityServerPPLegalIdentityVATIDValueSyntax: string Description: Specifies the Liberty PP legal identity VATID value. sunIdentityServerPPEmploymentIdentityJobTitleSyntax: string Description: Specifies the Liberty PP job title. sunIdentityServerPPEmploymentIdentityOrgSyntax: string Description: Specifies the Liberty PP employment organization. sunIdentityServerPPEmploymentIdentityAltOSyntax: string Description: Specifies the Liberty PP alternate employment organization. sunIdentityServerPPAddressCardSyntax: string Description: Specifies the Liberty PP address card. sunIdentityServerPPMsgContactSyntax: string Description: Specifies the Liberty PP message contact. sunIdentityServerPPFacadeMugShotSyntax: string Description: Specifies the Liberty PP façade mug shot. sunIdentityServerPPFacadeWebSiteSyntax: string Description: Specifies the Liberty PP façade website. sunIdentityServerPPFacadeNamePronouncedSyntax: string Description: Specifies the Liberty PP façade name pronounced. sunIdentityServerPPFacadeGreetSoundSyntax: string Description: Specifies the Liberty PP façade greet sound. sunIdentityServerPPFacadeGreetMeSoundSyntax: string Description: Specifies the Liberty PP façade greet me sound. sunIdentityServerPPDemographicsDisplayLanguageSyntax: string Description: Specifies the Liberty PP demographics display language. sunIdentityServerPPDemographicsLanguageSyntax: string Description: Specifies the Liberty PP demographics language. sunIdentityServerPPDemographicsBirthdaySyntax: string Description: Specifies the Liberty PP demographics birthday. sunIdentityServerPPDemographicsAgeSyntax: string Description: Specifies the Liberty PP demographics age. sunIdentityServerPPDemographicsTimeZoneSyntax: string Description: Specifies the Liberty PP demographics time zone. sunIdentityServerPPSignKeySyntax: string Description: Specifies the Liberty PP signing key. sunIdentityServerPPEncryptKeySyntax: string Description: Specifies the Liberty PP encryption key. sunIdentityServerPPEmergencyContactSyntax: string Description: Specifies the Liberty PP emergency contact. |