policy-trigger

Use the policy-trigger stanza entry to define the external authorization service.

Description

Define the external authorization service.

Options

Usage: Required when we are configuring OAuth EAS authentication.

Default value

None.

Example:

The following example is an operation-based trigger with a user-defined action group of Printer and the actions rxT in that group. To specify the primary action group, specify only :rxT. The primary action group can be represented with an empty action group name or the string primary can be used explicitly. All lowercase letters are required if primary is used explicitly. Any policy-trigger that does not contain a colon (:) character is considered to be a POP attribute name.

The following example is for a POP attribute trigger called webseal_pop_trigger. When a POP that contains a reference to this string is encountered, the appropriate external authorization service is called to take part in the access decision.

In order for the above POP attribute trigger to work, POP configuration must first be completed by the secure domain administrator, by using the pdadmin pop commands.

The following is an example configuration for the OAuth EAS, where the file oauth_eas.conf contains the [oauth-eas] stanza and the corresponding [tfim-cluster:<cluster>] stanza. This example is entered as one line in the WebSEAL configuration file:

Parent topic: [aznapi-external-authzn-services] stanza