ldapxacmlwso2-governance-registrywso2-identity-server

How to Seprate wso2 xacml policy in tenent envirnament based on Registry


Our requirement is that i have to separate xacml policy file from default registry called wso2Registry.

so , i am trying to do this scenario using wso2-Governance Registry

but i cant get succeded on this

is anythings other then i have to do to seprate xacml policy based on Tenent so that one tenent cant see other Tenent Xacml policy file not even super tenent


Solution

  • I think your requirement is to isolate the entitlement(XACML) policy. You don't need a separate WSO2 G-Reg instances to do that. In default you it will save the policy at following path for all the tenant, and all the tenants have their own registry space. Therefore any other tenant/ super tenant cannot access them. /_system/governance/repository/identity/entitlement/policy/pap