/Management/Replica permissions
Use the /Management/Replica container
object of the protected object space to control the replication of
the master policy database.
High-level controls on this object affect the operation of the policy server and the resource managers in the domain.
| Permission | Operation |
|---|---|
| v (view) | Read the master policy database. |
All Verify Identity Access servers
that maintain a local replica of the policy database must be granted
view (v) permission on the /Management/Replica object.
This group of servers includes all resource managers and the authorization
servers. The replication process requires that these processes be
allowed to view and access entries out of the master policy database.
The Verify Identity Access installation automatically grants read permission to any server that requires access to the master policy database. When a resource manager is configured into the domain, it is automatically added as a member to the ivacld-servers group. This group, by default, is given permission to download the master policy database.