User guide
Repository Server Setup
2-37
Note
Ensure that you take sufficient action to protect the administrator password.
For details about securing your data, refer to 'Security Measures' of 'Interstage Single Sign-on' of
'Security Risks' in the Security System Guide.
Role Configuration Entry
This section describes the entry used to register role configuration in the SSO repository. Specify the
role name and role set name in the user information and protection resources.
The role name and role set name must both be unique.
<Role>
The entry used to register a role in the SSO repository is described below.
Object Classes
The role registered in the SSO repository is managed by the following object classes. Specify the
following object classes when registering a role in the SSO repository:
Object class Description
top Basic LDAP object class
ssoRole SSO role information
Attributes
Specify the name of a role as an attribute of the above object classes.
Table 2-5 ssoRole Attributes
Role object class Attribute name Explanation
cn Name ssoRole
ssoAuthType Authentication method
Not used in this version
(1) cn
Description
Specify the name of a role.
The role name specified here is set in the ssoRoleName attribute of user information and the role set
entry.
The following characters are valid:
• Alphanumeric characters
• Space ( ), exclamation mark (!), question mark (?), at symbol (@), Hash (#), dollar sign ($), percent
(%), ampersand (&), left parenthesis ((), right parenthesis ()), left brace ({), right brace (}), left
bracket ([), right bracket (]), hyphen (-), equal sign (=), asterisk (*), slash (/), vertical line (|),
underscore (_), single quotation mark ('), colon (:), period (.), caret (^), back quotation mark (`), tilde
(~)