Skip to content

[#1155] Fix typos, unresolved placeholders and dead ForgeRock links in the guides - #1157

Merged
vharseko merged 1 commit into
OpenIdentityPlatform:masterfrom
vharseko:issue-1155-docs-fixes
Oct 1, 2026
Merged

vharseko merged 1 commit into
OpenIdentityPlatform:masterfrom
vharseko:issue-1155-docs-fixes

Conversation

@vharseko

@vharseko vharseko commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

Fixes #1155

Smaller defects in the OpenAM guides, as rendered on https://doc.openidentityplatform.org.

Changes

  • Typo in URL — link:hhttps://… → link:https://… in admin-guide/chap-mobile.adoc.
  • {openam-version} shown literally — subs="attributes+" added to the three console blocks that render the placeholder on the live site (install-guide/chap-install-tools.adoc ×2, dev-guide/chap-client-dev.adoc). A scan of every verbatim block in the guides found no others; the unzip block at line 260 already had subs="attributes".
  • Unterminated example block — the last procedure in getting-started/chap-first-steps.adoc was never closed, so it swallowed the rest of the chapter: the live page shows <p>=== Trying It Out</p> instead of a heading. Closed with ====.
  • Self-service email examples — dropped the stray * markers (leftovers of bold formatting) that were rendered in front of five examples in admin-guide/chap-usr-selfservices.adoc, and put the %link% email bodies there and in reference/chap-config-ref.adoc into literal monospace (`+…+`).
  • Links to ForgeRock — all 16 links to backstage.forgerock.com / forgerock.org are gone:
    • the sample-code KB article (a47487197, ×5) → the openam-samples directory of this repository; the STS sample path in dev-guide/chap-sts.adoc now matches it (openam-source/openam-samples/sts-example-code);
    • the anonymous-access KB article (a97304600) → ACI: Disable Anonymous Access in the OpenDJ Administration Guide;
    • the rest have no Open Identity Platform counterpart and are removed together with their "see …" sentence, or the text is kept without the link (push credentials ×2, CTS affinity, .NET Fedlets, login page timeouts, unsupported versions, security_advisory1/2, the internal javadoc on download.forgerock.org).
    • The ssoadm "trust all certificates" note is removed rather than rewritten: its KB link is dead, and com.iplanet.am.jssproxy.trustAllServerCerts disables both certificate-chain validation (AMX509TrustManager) and host name verification (AMHostnameVerifier) only when the com.sun.identity.protocol handler is installed (through java.protocol.handler.pkgs or opensso.protocol.handler.pkgs), which neither the stock ssoadm script nor the default configuration does. The step above it already documents the correct javax.net.ssl.trustStore option.

Notes

  • %link% was not actually rendered as a link: both the live site and a local render show it as escaped text inside <code>, with no <a href="%link%"> element. The 404 most likely came from a checker that extracts href="…" from page text. The visible defect there was the stray *.
  • http://forgerock.com in the SAML RelayState examples of admin-guide/chap-federation.adoc and www.forgerock.org in the scripting examples are sample values, not links, and are left as they are.
  • reference/chap-config-ref.adoc still says "Use the ForgeRock Backstage website to provision values for the following Simple Notification Service properties". It is not a link, and how Open Identity Platform users obtain SNS credentials needs a separate decision.

Testing

Rendered all 14 changed chapters with Asciidoctor.js, both from origin/master and from this branch:

  • warnings: the only difference is that chap-first-steps.adoc: unterminated example block is gone;
  • HTML: no literal {openam-version} left (the three blocks show 16.1.4), no hhttps, "Trying It Out" is an <h3>, no stray * before the examples, and 16 → 0 hrefs to forgerock.com / forgerock.org.

The full Antora build was not run locally.

…ad ForgeRock links in the guides

- Fix the hhttps typo in the mobile samples link
- Enable attribute substitution in the three console blocks that showed {openam-version} literally
- Close the unterminated example block in Getting Started, which swallowed the "Trying It Out" section
- Drop the stray bold markers around the self-service email examples and keep them as literals
- Replace or remove the links to backstage.forgerock.com and forgerock.org, which no longer serve this content

Fixes OpenIdentityPlatform#1155
@vharseko vharseko added bug documentation Documentation, README, or javadoc labels Sep 30, 2026

@maximthomas maximthomas left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

praise: The fixes land on the actual rendering defects, and the replacement links point at things that exist.

  • getting-started/chap-first-steps.adoc gets the missing ==== closer, so the rest of the chapter no longer renders as <p>=== Trying It Out</p>.
  • The new openam-samples links resolve on master: openam-samples/custom-authentication-module, policy-evaluation-plugin and sts-example-code all exist, and the STS path in dev-guide/chap-sts.adoc now matches the last one.
  • subs="attributes+" is added to exactly the three blocks that showed {openam-version} literally (install-guide/chap-install-tools.adoc:70, :303, and dev-guide/chap-client-dev.adoc).

issue (non-blocking): The description says com.iplanet.am.jssproxy.trustAllServerCerts "only disables host name verification … it does not trust the certificate". That is not what the code does.

openam-documentation/openam-doc-source/src/main/asciidoc/install-guide/chap-install-tools.adoc:151, openam-shared/src/main/java/com/sun/identity/security/keystore/AMX509TrustManager.java:79-81, :123-127, openam-core/src/main/java/com/sun/identity/protocol/https/Https.java:48-50

AMX509TrustManager reads the same property. When it is true, checkServerTrusted returns before any chain validation. Https's static initializer installs that trust manager (through SSLSocketFactoryManager.getSocketFactory()) together with AMHostnameVerifier, so wherever the property has any effect it accepts any server certificate. reference/chap-config-ref.adoc:5428-5429 already documents it that way ("trust whatever certificate is presented without checking"). Removing the NOTE is still right: the stock ssoadm script sets no java.protocol.handler.pkgs, so the property does nothing there. Only the stated reason is wrong, and with a squash merge it would end up in the commit message describing a trust-all switch as harmless. Suggested wording for that bullet:

The `ssoadm` "trust all certificates" note is removed rather than rewritten: its KB link is dead, and
`com.iplanet.am.jssproxy.trustAllServerCerts` disables both certificate-chain validation
(AMX509TrustManager) and host name verification (AMHostnameVerifier) only when the
`com.sun.identity.protocol` handler is installed, which the stock `ssoadm` script does not do.
The step above already documents the correct `javax.net.ssl.trustStore` option.

@vharseko

vharseko commented Oct 1, 2026

Copy link
Copy Markdown
Member Author

The reason given in the description was wrong. When com.iplanet.am.jssproxy.trustAllServerCerts is true, AMX509TrustManager.checkServerTrusted returns before it validates the chain, and Https installs that trust manager together with AMHostnameVerifier. The bullet now reads as you suggested, and also names the two properties that install the handler: java.protocol.handler.pkgs and opensso.protocol.handler.pkgs. Neither is set by the stock ssoadm script, and opensso.protocol.handler.pkgs is empty in the shipped AMConfig.properties / validserverconfig.properties.

The commit message never made this claim, so the branch is unchanged.

@vharseko
vharseko requested a review from maximthomas October 1, 2026 11:39

@maximthomas maximthomas left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The PR is LGTM

@vharseko
vharseko merged commit c9bf539 into OpenIdentityPlatform:master Oct 1, 2026
16 checks passed
@vharseko
vharseko deleted the issue-1155-docs-fixes branch October 1, 2026 12:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug documentation Documentation, README, or javadoc

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Docs: typos, unresolved {openam-version} and %link% placeholders

2 participants