This user guide describes various configuration and management options available with entitlement management.
Left hand menu has been separated in to three main management categories. i.e. PAP (Policy Administrator Point), PDP (Policy Decision Policy) and PEP (Policy Enforcement Point)
Figure 1: Entitlement Management
Policy Administration Point provides various operations in policy management. Following are the list of them
The defined policies can be search using the Search Policy option. Here you can provide regular expression of the policy identifier or else some attribute value that is contain in the policy
Figure 2: Policy administration
There are five different ways that you can add policy in to PAPFigure 3: Select Policy Creation Wizard
Figure 4: Simple Policy Creation Wizard UI
Figure 5: Basic Policy Creation Wizard UI
Figure 6: Standard Policy Creation Wizard UI
Figure 7: Creating a policy set
Figure 8: Import a policy or Policy Set from file system or registry
The defined policy can be published using policy publishers to any Policy store. You can create a policy in PAP and then can publish to registered subscribers. By default, there are two publisher, i.e PDP publisher and Carbon Basic Auth Publisher. There is one registered subscriber for PDP publisher. You can use 'Add Subscriber' to define more subscriber. Subscribers can be search by providing regular expression and You can view the status of subscribers
Figure 9: Publishing a policy
This shows the actual PDP policy store. You can view, order and enable PDP policies from here. Also you can configure the global policy combining algorithm for PDP policies. The defined policies can be search using the Search Policy option. Here you can provide regular expression of the policy identifier
Figure 10: PDP Policy View
This editor provides the UI for view the PDP extension points. You can reinitialize extensions, clear decision cache and attribute cache using this UI
Figure 11: PDP extension
You can evaluate the PDP engine using this editor. You can create XACML 3.0 request and do the evaluation.
Figure 12: Evaluate the defined entitlement policy
This UI can be used to locate defined policy. Following options can be configured in the search query.
Figure 13: Search
External References: