Novell ACCESS MANAGER 3.1 SP2 - POLICY GUIDE 2010 Manual page 167

Hide thumbs Also See for ACCESS MANAGER 3.1 SP2 - POLICY GUIDE 2010:
Table of Contents

Advertisement

Element
<LHSOperand>
<Operator>
<RHSOperand>
<NOT>
<Result>
<ResultOnError>
Policy Action Initiation
A PA trace has the following fields
Description
The enumerative value and parameter list of the left operand. It is the first
value specified for the comparison and has the following format:
<Condition Name(Data ID)>: <Parameter> : <Value>
The Condition Name is the string assigned to the condition type specified
in the policy. The Data ID is a numerical value assigned to the condition
type.
<Parameter>
contains one of the following strings:
when no parameters are specified for the operand,
no-param
followed by a colon, followed by one of the following: the value,
value
, or
hidden-value
information.
hidden-param
followed by a colon, and then
string is used when both the parameter and its value contain
sensitive information.
In the sample CO trace, this is
value
. LdapGroup is the string for the LDAP Group condition. The policy
specified [Current], so no parameters were specified. The groups that the
user belongs to are considered sensitive data, so the log file displays
for the names of the groups.
hidden-value
The display name of the comparison operator.
In the sample CO trace, this is
policy, this is displayed as LDAP Group: Is Member of.
The enumerative value and parameter list of the right operand. It is the
second value specified for the comparison and has the same format as the
<LHSOperand>
.
In the sample CO trace, this is
. The actual policy specifies LDAP Group as the
param:hidden-value
parameter, and the value is the DN of the group.
The string
if the result was negated prior to reporting; otherwise the
NOT
field has no value. This is the If Not option when creating a condition.
In the sample CO trace, this condition result was not negated, therefore
the field is represented by a tilde.
A string followed by a number that specifies the result of the comparison.
See
"Policy Result Values" on page
In the sample CO trace, this is True (69), indicating that the condition
evaluated to True—the user is a member of the specified LDAP group.
A string describing the error that occurred. This is an optional field that
only appears when the condition evaluation results in an error.
The sample CO trace did not result in an error, so it has no string.
when the value contains sensitive
hidden-value
LdapGroup(6645):no-param:hidden-
ldap-group-is-member-of
SelectedLdapGroup(66455):hidden-
169.
Troubleshooting Access Manager Policies 167
no-
. This
. In the

Advertisement

Table of Contents
loading

Table of Contents