OpenAMIdPInstallDebianLenny: configure_opends_userstore.ldif

File configure_opends_userstore.ldif, 3.8 kB (added by l.suhrbier, 2 years ago)
Line 
1##
2##   DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS HEADER.
3##
4##   Copyright (c) 2006 Sun Microsystems Inc. All Rights Reserved
5##
6##   The contents of this file are subject to the terms
7##   of the Common Development and Distribution License
8##   (the License). You may not use this file except in
9##   compliance with the License.
10##
11##   You can obtain a copy of the License at
12##   https://opensso.dev.java.net/public/CDDLv1.0.html or
13##   opensso/legal/CDDLv1.0.txt
14##   See the License for the specific language governing
15##   permission and limitations under the License.
16##
17##   When distributing Covered Code, include this CDDL
18##   Header Notice in each file and include the License file
19##   at opensso/legal/CDDLv1.0.txt.
20##   If applicable, add the following below the CDDL Header,
21##   with the fields enclosed by brackets [] replaced by
22##   your own identifying information:
23##   "Portions Copyrighted [year] [name of copyright owner]"
24##
25##   $Id: configure_opends_userstore.ldif,v 1.1.2.2 2009/03/16 01:35:54 inthanga Exp $
26##
27##
28dn: ou=people,dc=opensso,dc=e-taxonomy,dc=eu
29objectClass: top
30objectClass: organizationalUnit
31
32dn: ou=groups,dc=opensso,dc=e-taxonomy,dc=eu
33objectClass: top
34objectClass: organizationalUnit
35
36dn: ou=opensso adminusers,dc=opensso,dc=e-taxonomy,dc=eu
37objectClass: top
38objectClass: organizationalUnit
39
40dn: cn=openssouser,ou=opensso adminusers,dc=opensso,dc=e-taxonomy,dc=eu
41objectclass: inetuser
42objectclass: organizationalperson
43objectclass: person
44objectclass: top
45cn: openssouser
46sn: openssouser
47userPassword: 42eYplcbum5nGQ6kt3XR
48
49dn: cn=openssouser,ou=opensso adminusers,dc=opensso,dc=e-taxonomy,dc=eu
50changetype: modify
51add: ds-privilege-name
52ds-privilege-name: password-reset
53
54dn: cn=ldapuser,ou=opensso adminusers,dc=opensso,dc=e-taxonomy,dc=eu
55objectclass: inetuser
56objectclass: organizationalperson
57objectclass: person
58objectclass: top
59cn: ldapuser
60sn: ldapuser
61userPassword: 7pwe9skhF5OwE4RBWGj8
62
63dn:dc=opensso,dc=e-taxonomy,dc=eu
64changetype:modify
65add:aci
66aci: (target="ldap:///dc=opensso,dc=e-taxonomy,dc=eu")(targetattr="*")(version 3.0; acl "OpenSSO datastore configuration bind  user all rights under the root suffix"; allow (all) userdn = "ldap:///cn=openssouser,ou=opensso adminusers,dc=opensso,dc=e-taxonomy,dc=eu"; )
67
68dn:dc=opensso,dc=e-taxonomy,dc=eu
69changetype:modify
70add:aci
71aci: (target="ldap:///dc=opensso,dc=e-taxonomy,dc=eu")(targetattr="*")(version 3.0; acl "OpenSSO Authn bind ldap user rights"; allow (read,search) userdn = "ldap:///cn=ldapuser,ou=opensso adminusers,dc=opensso,dc=e-taxonomy,dc=eu"; )
72
73dn:dc=opensso,dc=e-taxonomy,dc=eu
74changetype:modify
75add:aci
76aci:(targetcontrol = "2.16.840.1.113730.3.4.3")(version 3.0; acl "Allow Persistent Search for the OpenSSO datastore config bind user"; allow (all) userdn = "ldap:///cn=openssouser,ou=opensso adminusers,dc=opensso,dc=e-taxonomy,dc=eu";)
77
78dn:dc=opensso,dc=e-taxonomy,dc=eu
79changetype:modify
80add:aci
81aci: (targetattr = "objectclass || inetuserstatus || iplanet-am-user-login-status || iplanet-am-user-account-life || iplanet-am-session-quota-limit || iplanet-am-user-alias-list ||  iplanet-am-session-max-session-time || iplanet-am-session-max-idle-time || iplanet-am-session-get-valid-sessions || iplanet-am-session-destroy-sessions || iplanet-am-session-add-session-listener-on-all-sessions || iplanet-am-user-admin-start-dn || iplanet-am-auth-post-login-process-class || iplanet-am-saml-user || iplanet-am-saml-password || iplanet-am-user-federation-info || iplanet-am-user-federation-info-key || ds-pwp-account-disabled || sun-fm-saml2-nameid-info || sun-fm-saml2-nameid-infokey || sunAMAuthInvalidAttemptsData || memberof || member")(targetfilter="(!(userdn=cn=openssouser,ou=opensso adminusers,dc=opensso,dc=e-taxonomy,dc=eu))")(version 3.0; acl "OpenSSO User self modification denied for these attributes"; deny (write) userdn ="ldap:///self";)