Application Delivery Management
Application Modernization & Connectivity
CyberRes by OpenText
IT Operations Management
<DataSource(uri.oidp.xml.config.01.2011)>:
Id: idm_idv
DisplayName: IDM eDir
m_Class: com.novell.oidp.source.ldap.LDAPSource
Subordinate Element: LDAPSource
<AssertionAttributeMaps(uri.oidp.xml.config.01.2011)>:
<AssertionAttributeMap(uri.oidp.xml.config.01.2011)>:
Id: saml2-attr-map
DisplayName: SAML2 Attribute Map
<AssertionAttributeMapEntry(uri.oidp.xml.config.01.2011)>:
Friendly Name: SAML IDP to Identity Vault mapping attribute
Local Name: saml2-mapping-attr
Saml Name: cn
Remote Name Format: urn:oasis:names:tc:SAML:2.0:attrname-format:basic
<AttributeGroup(uri.oidp.xml.config.01.2011)>:
nId: 1
Display Name: IDM Attributes
Description: Attributes needed by IDM
<AttributeGroupEntry(uri.oidp.xml.config.01.2011)>:
Local Name: Surname
Display Name: Last Name
<AttributeGroupEntry(uri.oidp.xml.config.01.2011)>:
Local Name: givenName
Display Name: First Name
<AttributeGroupEntry(uri.oidp.xml.config.01.2011)>:
Local Name: userDN
Display Name: Distinguished name
<AttributeGroupEntry(uri.oidp.xml.config.01.2011)>:
Local Name: userCN
Display Name: userCN
<AttributeGroupEntry(uri.oidp.xml.config.01.2011)>:
Local Name: initials
Display Name: initials
<AttributeGroupEntry(uri.oidp.xml.config.01.2011)>:
Local Name: mail
Display Name: mail
<AttributeGroupEntry(uri.oidp.xml.config.01.2011)>:
Local Name: nrfMemberOf
Display Name: nrfMemberOf
<AttributeGroupEntry(uri.oidp.xml.config.01.2011)>:
Local Name: srvprvPreferredLocale
Display Name: srvprvPreferredLocale
<AttributeGroupEntry(uri.oidp.xml.config.01.2011)>:
Local Name: cacheable
Display Name: cacheable
<AuthMethod(uri.oidp.xml.config.01.2011)>:
Id: saml2-method
DisplayName: SAML2 Method
Class Ref Id: saml2-class
Type: USER_AUTHENTICATE
Enabled: true
<AuthContract(uri.oidp.xml.config.01.2011)>:
Id: saml2-contract
DisplayName: SAML2 User Login
Enabled: true
Base URL: idm:login:user:saml2
Show Password Expired UI: false
Check Trust Levels: true
Remote Contracts: false
Trust Level: 2
Timeout: 10
Endless Loop Detection Window (millis): 2000
Endless Loop Detection Threshold: 5
<ContractExecutableList(uri.oidp.xml.config.01.2011)>:
<ContractExecutableReference(uri.oidp.xml.config.01.2011)>:
Ref Id: saml2-method
<AuthCards(uri.oidp.xml.config.01.2011)>:
<AuthCard(uri.oidp.xml.config.01.2011)>:
Id: eIDPLogin
Endpoint Url: null
Endpoint Type(s):
UserAgent Type(s):
Group Ref Id: null
Show: true
Authentication Required: true
<ImageSetList(uri.oidp.xml.config.01.2011)>:
<ImageSetReference(uri.oidp.xml.config.01.2011)>:
Ref Id: ospImageRef
<Protocols(uri.oidp.xml.config.01.2011)>:
Require Signed Authn Requests: false
Require Signed Assertions: false
Sign Authn Requests: false
Use IDP Publishing: false
Use IDP Discovery: false
Single Logout Method: false
IDP Publish Domain: null
IDP Service Domain: null
SP Service Domain: null
Assertion TTL: 5
<UserLookups(uri.oidp.xml.config.01.2011)>:
<UserLookup(uri.oidp.xml.config.01.2011)>:
Id: saml2-user-lookup
DisplayName: Map SAML IDP user
Matching Expression: =(saml2-mapping-attr,saml2-mapping-attr)
<LocalizedStringList(uri.oidp.xml.config.01.2011)>:
Decorator: SecondaryNamingAttrDisplayName
<LocalizedString(uri.oidp.xml.config.01.2011)>:
Locale: *
Text: Email
<Logout(uri.oidp.xml.config.01.2011)>:
<RedirectUrl(uri.oidp.xml.config.01.2011)>:
Url: https://www.acme.com/IDMProv/logout.do
returnParamName: target
final: false
<RedirectUrl(uri.oidp.xml.config.01.2011)>:
Url: http://localhost:8180/sspr/public/Logout
returnParamName: logoutURL
final: false
<RedirectUrl(uri.oidp.xml.config.01.2011)>:
Url: https://www.acme.com/nidp/jsp/logoutSuccess.jsp
final: true
hasFinal:
*[osp-conf]
2015-12-15T16:15:11.549-0500
Event:
Message:
OAuth configuration properties:
com.netiq.idm.osp.as.admins-container-dn: ou=ServiceAccounts,o=acme
com.netiq.idm.osp.as.duplicate-resolution-naming-attr: mail
com.netiq.idm.osp.as.naming-attr: cn
com.netiq.idm.osp.as.scope: 2
com.netiq.idm.osp.as.users-container-dn: ou=Active,ou=People,o=acme
com.netiq.idm.osp.auth.pwd.expire.show: ********
com.netiq.idm.osp.auth.pwd.expire.url: ********
com.netiq.idm.osp.clients: [XML Node]
com.netiq.idm.osp.forgotten-pwd-url: https://www.acme.com/IDMProv/jsps/pwdmgt/ForgotPassword.jsp
com.netiq.idm.osp.ldap.admin-dn: cn=admin,o=acme
com.netiq.idm.osp.ldap.admin-pwd: ********
com.netiq.idm.osp.ldap.host: 10.1.1.4
com.netiq.idm.osp.ldap.port: 636
com.netiq.idm.osp.ldap.use-ssl: true
com.netiq.idm.osp.localhost-auto-add: false
com.netiq.idm.osp.login.method: saml2
com.netiq.idm.osp.login.saml2.enabled: true
com.netiq.idm.osp.login.saml2.mapping-attr: cn
com.netiq.idm.osp.login.saml2.metadata-url: https://www.acme.com/nidp/saml2/metadata
com.netiq.idm.osp.logout-urls:
<RedirectUrl xmlns="uri.oidp.xml.config.01.2011" returnParamName="target">https://www.acme.com/IDMProv/logout.do</RedirectUrl><RedirectUrl xmlns="uri.oidp.xml.config.01.2011" returnParamName="logoutURL">http://localhost:8180/sspr/public/Logout</RedirectUrl><RedirectUrl xmlns="uri.oidp.xml.config.01.2011" final="true">https://www.acme.com/nidp/jsp/logoutSuccess.jsp</RedirectUrl>
com.netiq.idm.osp.oauth-key-alias: osp
com.netiq.idm.osp.oauth-key.pwd: ********
com.netiq.idm.osp.oauth-keystore.file: /opt/netiq/idm/apps/osp_sspr/osp/osp.jks
com.netiq.idm.osp.oauth-keystore.pwd: ********
com.netiq.idm.osp.oauth-truststore.file: /opt/netiq/idm/apps/jre8/lib/security/cacerts
com.netiq.idm.osp.oauth-truststore.pwd: ********
com.netiq.idm.osp.oauth.accessTokenTTL: 120
com.netiq.idm.osp.oauth.refreshTokenTTL: 2592000
com.netiq.idm.osp.oauth.sessionTokenRevocationTTL: 172800
com.netiq.idm.osp.sessionTTL: 1200
com.netiq.idm.osp.ssl-keystore.file: /opt/netiq/idm/apps/osp_sspr/osp/osp.jks
com.netiq.idm.osp.ssl-keystore.pwd: ********
com.netiq.idm.osp.tenant.additional-hosts:
<AdditionalHosts xmlns="uri.osp.xml.config.01.2011">
<Host>169.254.186.36</Host>
</AdditionalHosts>
com.netiq.idm.osp.tenant.host: www.acme.com
com.netiq.idm.osp.tenant.port: 8443
com.netiq.idm.osp.tenant.protocol: https
com.netiq.idm.osp.url.host: https://www.acme.com:8443
com.netiq.idm.pwdmgt.provider: ********
com.netiq.idm.osp.logout-urls:
<RedirectUrl xmlns="uri.oidp.xml.config.01.2011" returnParamName="target">https://www.acme.com/IDMProv/logout.do</RedirectUrl><RedirectUrl xmlns="uri.oidp.xml.config.01.2011" returnParamName="logoutURL">http://localhost:8180/sspr/public/Logout</RedirectUrl><RedirectUrl xmlns="uri.oidp.xml.config.01.2011" final="true">https://www.acme.com/nidp/jsp/logoutSuccess.jsp</RedirectUrl>
[OSP]
Time: 2015-12-15T17:02:38.188-0500
Level: TRACE
Java Execution:
Class: com.novell.oidp.source.ldap.LDAPSource
Method: <init>
Line Number: -1
Thread: localhost-startStop-1
Message: LDAPSource Configuration:
<LDAPSource(uri.oidp.xml.config.01.2011)>:
Admin User Name: cn=admin,o=acme
Directory Type: 1
Operation Timeout: 15000
Idle Connection Timeout: 10000
Install SAML Method: false
Rebind Allowed: true
Max Waiting Per Replica: -1
<LDAPReplica(uri.oidp.xml.config.01.2011)>:
Id: idvReplica0
DisplayName: IDM Replica One
Ip Address: 10.1.1.42
Do SSL: true
Maximum Connections: 31
Port: 636