| 1 | ## |
|---|
| 2 | ## DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS HEADER. |
|---|
| 3 | ## |
|---|
| 4 | ## Copyright (c) 2006 Sun Microsystems Inc. All Rights Reserved |
|---|
| 5 | ## |
|---|
| 6 | ## The contents of this file are subject to the terms |
|---|
| 7 | ## of the Common Development and Distribution License |
|---|
| 8 | ## (the License). You may not use this file except in |
|---|
| 9 | ## compliance with the License. |
|---|
| 10 | ## |
|---|
| 11 | ## You can obtain a copy of the License at |
|---|
| 12 | ## https://opensso.dev.java.net/public/CDDLv1.0.html or |
|---|
| 13 | ## opensso/legal/CDDLv1.0.txt |
|---|
| 14 | ## See the License for the specific language governing |
|---|
| 15 | ## permission and limitations under the License. |
|---|
| 16 | ## |
|---|
| 17 | ## When distributing Covered Code, include this CDDL |
|---|
| 18 | ## Header Notice in each file and include the License file |
|---|
| 19 | ## at opensso/legal/CDDLv1.0.txt. |
|---|
| 20 | ## If applicable, add the following below the CDDL Header, |
|---|
| 21 | ## with the fields enclosed by brackets [] replaced by |
|---|
| 22 | ## your own identifying information: |
|---|
| 23 | ## "Portions Copyrighted [year] [name of copyright owner]" |
|---|
| 24 | ## |
|---|
| 25 | ## $Id: configure_opends_userstore.ldif,v 1.1.2.2 2009/03/16 01:35:54 inthanga Exp $ |
|---|
| 26 | ## |
|---|
| 27 | ## |
|---|
| 28 | dn: ou=people,dc=opensso,dc=e-taxonomy,dc=eu |
|---|
| 29 | objectClass: top |
|---|
| 30 | objectClass: organizationalUnit |
|---|
| 31 | |
|---|
| 32 | dn: ou=groups,dc=opensso,dc=e-taxonomy,dc=eu |
|---|
| 33 | objectClass: top |
|---|
| 34 | objectClass: organizationalUnit |
|---|
| 35 | |
|---|
| 36 | dn: ou=opensso adminusers,dc=opensso,dc=e-taxonomy,dc=eu |
|---|
| 37 | objectClass: top |
|---|
| 38 | objectClass: organizationalUnit |
|---|
| 39 | |
|---|
| 40 | dn: cn=openssouser,ou=opensso adminusers,dc=opensso,dc=e-taxonomy,dc=eu |
|---|
| 41 | objectclass: inetuser |
|---|
| 42 | objectclass: organizationalperson |
|---|
| 43 | objectclass: person |
|---|
| 44 | objectclass: top |
|---|
| 45 | cn: openssouser |
|---|
| 46 | sn: openssouser |
|---|
| 47 | userPassword: 42eYplcbum5nGQ6kt3XR |
|---|
| 48 | |
|---|
| 49 | dn: cn=openssouser,ou=opensso adminusers,dc=opensso,dc=e-taxonomy,dc=eu |
|---|
| 50 | changetype: modify |
|---|
| 51 | add: ds-privilege-name |
|---|
| 52 | ds-privilege-name: password-reset |
|---|
| 53 | |
|---|
| 54 | dn: cn=ldapuser,ou=opensso adminusers,dc=opensso,dc=e-taxonomy,dc=eu |
|---|
| 55 | objectclass: inetuser |
|---|
| 56 | objectclass: organizationalperson |
|---|
| 57 | objectclass: person |
|---|
| 58 | objectclass: top |
|---|
| 59 | cn: ldapuser |
|---|
| 60 | sn: ldapuser |
|---|
| 61 | userPassword: 7pwe9skhF5OwE4RBWGj8 |
|---|
| 62 | |
|---|
| 63 | dn:dc=opensso,dc=e-taxonomy,dc=eu |
|---|
| 64 | changetype:modify |
|---|
| 65 | add:aci |
|---|
| 66 | aci: (target="ldap:///dc=opensso,dc=e-taxonomy,dc=eu")(targetattr="*")(version 3.0; acl "OpenSSO datastore configuration bind user all rights under the root suffix"; allow (all) userdn = "ldap:///cn=openssouser,ou=opensso adminusers,dc=opensso,dc=e-taxonomy,dc=eu"; ) |
|---|
| 67 | |
|---|
| 68 | dn:dc=opensso,dc=e-taxonomy,dc=eu |
|---|
| 69 | changetype:modify |
|---|
| 70 | add:aci |
|---|
| 71 | aci: (target="ldap:///dc=opensso,dc=e-taxonomy,dc=eu")(targetattr="*")(version 3.0; acl "OpenSSO Authn bind ldap user rights"; allow (read,search) userdn = "ldap:///cn=ldapuser,ou=opensso adminusers,dc=opensso,dc=e-taxonomy,dc=eu"; ) |
|---|
| 72 | |
|---|
| 73 | dn:dc=opensso,dc=e-taxonomy,dc=eu |
|---|
| 74 | changetype:modify |
|---|
| 75 | add:aci |
|---|
| 76 | aci:(targetcontrol = "2.16.840.1.113730.3.4.3")(version 3.0; acl "Allow Persistent Search for the OpenSSO datastore config bind user"; allow (all) userdn = "ldap:///cn=openssouser,ou=opensso adminusers,dc=opensso,dc=e-taxonomy,dc=eu";) |
|---|
| 77 | |
|---|
| 78 | dn:dc=opensso,dc=e-taxonomy,dc=eu |
|---|
| 79 | changetype:modify |
|---|
| 80 | add:aci |
|---|
| 81 | aci: (targetattr = "objectclass || inetuserstatus || iplanet-am-user-login-status || iplanet-am-user-account-life || iplanet-am-session-quota-limit || iplanet-am-user-alias-list || iplanet-am-session-max-session-time || iplanet-am-session-max-idle-time || iplanet-am-session-get-valid-sessions || iplanet-am-session-destroy-sessions || iplanet-am-session-add-session-listener-on-all-sessions || iplanet-am-user-admin-start-dn || iplanet-am-auth-post-login-process-class || iplanet-am-saml-user || iplanet-am-saml-password || iplanet-am-user-federation-info || iplanet-am-user-federation-info-key || ds-pwp-account-disabled || sun-fm-saml2-nameid-info || sun-fm-saml2-nameid-infokey || sunAMAuthInvalidAttemptsData || memberof || member")(targetfilter="(!(userdn=cn=openssouser,ou=opensso adminusers,dc=opensso,dc=e-taxonomy,dc=eu))")(version 3.0; acl "OpenSSO User self modification denied for these attributes"; deny (write) userdn ="ldap:///self";) |
|---|