I've been doing some testing with configuring Oauth2 by creating a definition and client under the OpenID Connect and API Protection in ISAM. Everything is working as expected.
From the Advanced Access Control Configuration topics documentation for 9.0.6 I see the following:
When you create policies, policy sets, or API protection definitions you cannot use
them until you publish them to resources. Once policies, policy sets, or API
protection definitions are published, they are enforced during the evaluation of
access requests.
However, I've noticed that it works as expected regardless if I have a "Resource" attached with a published API Protection definition or not. In fact, when I do attach the definition, the only change I can see is it adds the following POP to the junction:
pdadmin sec_master> pop show oauth-pop
Protected object policy: oauth-pop
Description:
Warning: No
Audit level: none
Quality of protection: none
Time of day access: sun, mon, tue, wed, thu, fri, sat, :anytime:local
IP Endpoint Authentication Method Policy
Auth Level: 0 Network: Any Other Network
Am I missing some step somewhere? Looking at this POP it doesn't seem to do anything.
Thanks,
Scott
------------------------------
Scott Reichardt
ISAM 9.0.6
------------------------------