WSO2 Identity Server PAP and PDP separation

307 Views Asked by At

I am trying to figure how do I deploy/config WSO2 IS PAP and PDP separately so that the servers have specific role. WSO2 comes up with one full package. Once I separate I would like to know how do I publish policies from PAP to PDP.

Thanks Raj

1

There are 1 best solutions below

0
On

Currently, You can not remove PDP or PAP functions from an WSO2 Identity Server instance completely. But you can disable PDP function using entitlement.properies file. But this would not remove management UI from the instance. However you can do the logic separation. Say you can run one instances as PAP and several other instances as PDP... Then your PAP instance can be used to create policies. And you can register PDP instances as the policy subscribers using the policy publisher management UI. Here you need to provide the PDP server url, user name (admin) and password (admin). So you can register one subscriber for each PDP instances. Using policy administration UI of the PAP, you can use publish option to publish policies to selected subscribers. More details on policy publishing can be found at here