Select the assertion template to be edited as described in Click the Configurations tab.

Managing Web Service Policies 7-13 Figure 7–7 Edit Configure Property Window Displayed When Displayed in a Policy

8. Edit the Configuration properties and click OK.

Note that you can edit only the Description, Value, and Default properties. The Content Type property setting defined in the assertion template cannot be changed, and is not displayed. For details about these properties, see Editing the Configuration Properties on page 7-11.

9. When you are done, click Save to save the policy.

Adding an OR Group to a Policy You can create an OR group, consisting of one or more assertions, enabling a single policy to accept multiple types of security tokens. A client can enforce any one of the policies that are defined in the OR group. For more information, see Defining Multiple Policy Alternatives OR Groups on page 3-9. You can add only one OR group to a policy. Once you have generated an OR Group, the Add OR Group button is greyed out. You can add an OR group from the Create Policy page, the Copy Policy page, or the Edit Policy Detail page. To add an OR group to a policy: 1. Navigate to the Create Policy page, the Create Like page, or the Edit Policy Detail page.

2. In the Assertion List section, click Add OR Group.

3. In the Add OR Group dialog, enter the name of the first assertion in the group, and select an assertion template from the Assertion Template list.

4. Click OK.

The assertion is added under the OR Group. 5. To add additional assertions to the OR group: a. Ensure that an assertion within the OR group is currently selected.

b. Click Add.

c. In the Add Assertion dialog, enter the name of the assertion in the group, and select an assertion template from the Assertion Template list.

d. Click OK.

6. To configure the assertions, see Configuring Assertions on page 7-14. The policy attribute values for attachTo and category limit the assertions that are valid within the current policy. All assertions within an OR group must be