RADIUS Roles As Reply-Message
Description
Configures the RADIUS service for returning roles in ACCEPT messages. The roles are returned in the ReplyMessage attribute (type 18). Depending on the configuration, each role is returned in a separate attribute or all roles are concatenated and returned in a single attribute (see property Separator).
May be used by
Properties
Return Granted User Roles (
returnGrantedUserRoles) Description
Add the user's granted roles to the list of returned roles. If disabled, only static roles are returned.
Attributes
Boolean
Optional
Default value
true
Static Roles (
staticRoles) Description
Additional static roles that are added to the list of returned roles.
Attributes
String-List
Optional
Suppress Original Reply Message (
suppressOriginalReplyMessage) Description
If this flag is enabled, the original human-readable reply message sent with ACCEPT messages is suppressed. That is, only the roles are returned. If the option is disabled, roles are added as additional attributes after the original message.
Attributes
Boolean
Optional
Default value
true
Separator (
separator) Description
If a separator is defined, all roles are concatenated using the defined separator. The resulting list of roles is returned in a single ReplyMessage attribute. If no separator is defined, each role is returned in a separate ReplyMessage attribute.
For example, assume a user has roles RA, RB and RC. Defining the separator to be "--" results in the ReplyMessage "RA--RB--RC"
Attributes
String
Optional
Length <= 3
Example
;
Example
,
Example
--
YAML Template (with default values)
type: RadiusRolesAsReplyMessageConfiguration
id: RadiusRolesAsReplyMessageConfiguration-xxxxxx
displayName:
comment:
properties:
returnGrantedUserRoles: true
separator:
staticRoles:
suppressOriginalReplyMessage: true