Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@
information: "Portions copyright [year] [name of copyright owner]".

Copyright 2017 ForgeRock AS.
Portions Copyright 2024-2025 3A Systems LLC.
Portions Copyright 2024-2026 3A Systems LLC.
////

:figure-caption!:
Expand Down Expand Up @@ -2051,7 +2051,7 @@ One-time passwords are valid for five minutes after they are generated by defaul

[NOTE]
======
You may also also need to configure the login page session timeouts in OpenAM. For more information, see link:https://backstage.forgerock.com/knowledge/kb/article/a23597700[How do I configure login page session timeouts in OpenAM (All versions)?, window=\_blank]
You may also need to configure the login page session timeouts in OpenAM.
======
+
`ssoadm` attribute: `sunAMAuthHOTPPasswordValidityDuration`
Expand Down Expand Up @@ -4430,9 +4430,6 @@ For detailed information about the available properties, see xref:../reference/c
Push Notification Service::
Configures how OpenAM sends push notifications to registered devices, including endpoints, and access credentials.

+
For information on provisioning the credentials required by the Push Notification Service, see link:https://backstage.forgerock.com/knowledge/kb/article/a47604373[How do I set up AM/OpenAM Push Notification Service credentials, window=\_blank] in the __ForgeRock Knowledge Base__.

+
For detailed information about the available properties, see xref:../reference/chap-config-ref.adoc#push-notification-service-configuration["Push Notification Service"] in the __Reference__.

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@
information: "Portions copyright [year] [name of copyright owner]".

Copyright 2017 ForgeRock AS.
Portions Copyright 2024-2025 3A Systems LLC.
Portions Copyright 2024-2026 3A Systems LLC.
////

:figure-caption!:
Expand Down Expand Up @@ -107,7 +107,7 @@ Furthermore, OpenAM REST APIs are built on an underlying common REST framework d
[#get-mobile-sample-apps]
=== Getting Source Code for Sample Mobile Applications

Source code for the sample mobile applications is available in sample repositories on the link:hhttps://github.com/OpenIdentityPlatform/[GitHub, window=\_blank]. Get local clones of one or more of the following repositories so that you can try these sample applications on your system:
Source code for the sample mobile applications is available in sample repositories on the link:https://github.com/OpenIdentityPlatform/[GitHub, window=\_blank]. Get local clones of one or more of the following repositories so that you can try these sample applications on your system:

* link:https://github.com/OpenIdentityPlatform/mobile-samples-android-openam-apps[OpenAM OAuth2.0 Android sample app, window=\_blank]

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -276,16 +276,13 @@ Default: 900 seconds.

.. In the Outgoing Email Subject field, enter the Subject line of your email in the New Value field, and then click Add.
+
The subject line format is `lang|subject-text`, where `lang` is the ISO-639 language code, such as `en` for English, `fr` for French, and others. For example, the subject line values could be: *`en|Registration Email`
* and *`fr|Inscription E-mail`
*.
The subject line format is `lang|subject-text`, where `lang` is the ISO-639 language code, such as `en` for English, `fr` for French, and others. For example, the subject line values could be: `en|Registration Email` and `fr|Inscription E-mail`.

.. In the Outgoing Email Body field, enter the text of your email in the New Value field, and then click Add.
+
The email body text format is `lang|email-text`, where `lang` is the ISO-639 language code. Note that email body text must be all on one line and can contain any HTML tags within the body of the text.
+
For example, the email body text could be: *`en|Thank you for registration to our site! Click <a href="%link%">here</a> to register to the site.`
*
For example, the email body text could be: `+en|Thank you for registration to our site! Click <a href="%link%">here</a> to register to the site.+`


. In the Valid Creation Attributes field, enter the user attributes the user can set during the user self-registration. The attributes are based on the OpenAM identity repository.
Expand Down Expand Up @@ -337,15 +334,13 @@ Default: 900 seconds.

.. In the Outgoing Email Subject field, enter the subject line of your email in the New Value field, and then click Add.
+
The subject line format is `lang|subject-text`, where `lang` is the ISO-639 language code, such as `en` for English, `fr` for French, and others. For example, the subject line value could be: *`en|Forgotten Password Email`
*.
The subject line format is `lang|subject-text`, where `lang` is the ISO-639 language code, such as `en` for English, `fr` for French, and others. For example, the subject line value could be: `en|Forgotten Password Email`.

.. In the Outgoing Email Body field, enter the text of your email in the New Value field, and then click Add.
+
The email body text format is `lang|email-text`, where `lang` is the ISO-639 language code. Note that email body text must be all on one line and can contain any HTML tags within the body of the text.
+
For example, the email body text could be: *`en|Thank you for request! Click <a href="%link%">here</a> to reset your password.`
*
For example, the email body text could be: `+en|Thank you for request! Click <a href="%link%">here</a> to reset your password.+`


. Under Advanced Configuration, change the default Forgotten Password Confirmation Email URL for your deployment. The default is: `\http://openam.example.com:8080/openam/XUI/#passwordReset/`.
Expand Down Expand Up @@ -385,8 +380,7 @@ Default: 900 seconds.

.. In the Outgoing Email Subject field, enter the subject line of your email in the New Value field, and then click Add.
+
The subject Line format is `lang|subject-text`, where `lang` is the ISO 639 language code, such as `en` for English, `fr` for French, and others. For example, the subject line value could be: *`en|Forgotten username email`
*.
The subject Line format is `lang|subject-text`, where `lang` is the ISO 639 language code, such as `en` for English, `fr` for French, and others. For example, the subject line value could be: `en|Forgotten username email`.

.. In the Outgoing Email Body field, enter the text of your email in the New Value field, and then click Add.
+
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -9055,7 +9055,7 @@ The sample web application deploys in your container to show you the client SDK
. Deploy the .war in your Java web application container such as Apache Tomcat or JBoss.
+

[source, console]
[source, console, subs="attributes+"]
----
$ cp ExampleClientSDK-WAR-{openam-version}.war /path/to/tomcat/webapps/client.war
----
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -499,7 +499,7 @@ This section shows how to customize authentication with a sample custom authenti

The sample authentication module prompts for a user name and password to authenticate the user, and handles error conditions. The sample shows how you integrate an authentication module into OpenAM such that you can configure the module through OpenAM console, and also localize the user interface.

For information on downloading and building OpenAM sample source code, see link:https://backstage.forgerock.com/knowledge/kb/article/a47487197[How do I access and build the sample code provided for OpenAM 12.x, 13.x and AM (All versions)?, window=\_blank] in the __Knowledge Base__.
The OpenAM sample source code is in the link:https://github.com/OpenIdentityPlatform/OpenAM/tree/master/openam-samples[openam-samples, window=\_blank] directory of the OpenAM source code on GitHub.
--
Get a local clone so that you can try the sample on your system. In the sources, you find the following files under the `/path/to/openam-source/openam-samples/custom-authentication-module` directory:

Expand Down Expand Up @@ -1068,7 +1068,7 @@ Build the module with Apache Maven, and install the module in OpenAM.

After you successfully build the module, you find the `.jar` file in the `target/` directory of the project.

For information on downloading and building OpenAM sample source code, see link:https://backstage.forgerock.com/knowledge/kb/article/a47487197[How do I access and build the sample code provided for OpenAM 12.x, 13.x and AM (All versions)?, window=\_blank] in the __Knowledge Base__.
The OpenAM sample source code is in the link:https://github.com/OpenIdentityPlatform/OpenAM/tree/master/openam-samples[openam-samples, window=\_blank] directory of the OpenAM source code on GitHub.


[#installing-sample-auth-module]
Expand Down Expand Up @@ -1363,7 +1363,7 @@ This section shows how to build and use a custom policy plugin that implements a

The OpenAM policy framework lets you build plugins that extend subject conditions, environment conditions, and resource attributes.

For information on downloading and building OpenAM sample source code, see link:https://backstage.forgerock.com/knowledge/kb/article/a47487197[How do I access and build the sample code provided for OpenAM 12.x, 13.x and AM (All versions)?, window=\_blank] in the __Knowledge Base__.
The OpenAM sample source code is in the link:https://github.com/OpenIdentityPlatform/OpenAM/tree/master/openam-samples[openam-samples, window=\_blank] directory of the OpenAM source code on GitHub.

Get a local clone so that you can try the sample on your system. In the sources, you find the following files under the `/path/to/openam-source/openam-samples/policy-evaluation-plugin` directory:
--
Expand Down Expand Up @@ -1412,7 +1412,7 @@ Follow the steps in this procedure to build the sample plugin:

. If you have not already done so, download and build the samples.
+
For information on downloading and building OpenAM sample source code, see link:https://backstage.forgerock.com/knowledge/kb/article/a47487197[How do I access and build the sample code provided for OpenAM 12.x, 13.x and AM (All versions)?, window=\_blank] in the __Knowledge Base__.
The OpenAM sample source code is in the link:https://github.com/OpenIdentityPlatform/OpenAM/tree/master/openam-samples[openam-samples, window=\_blank] directory of the OpenAM source code on GitHub.

. Check out the `master` branch of the OpenAM source.

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1287,10 +1287,6 @@ The following settings define settings for access to certificates and private ke

Other sections in this guide explain how to configure a Fedlet for signing and encryption including how to work with the keystores that these settings reference, and how to specify public key certificates in standard SAML v2.0 metadata. When working with a Java Fedlet, see the section on xref:#fedlet-signing-encryption["Enabling Signing and Encryption in a Fedlet"].

[TIP]
======
Although this section focuses on Java Fedlets, if you are working with a .NET Fedlet see link:https://backstage.forgerock.com/knowledge/kb/article/a99870342[How do I use Fedlets in .NET applications in OpenAM (All versions)?, window=\_blank] in the __ForgeRock Knowledge Base__.
======

`com.sun.identity.saml.xmlsig.keystore`::
This sets the path to the keystore file that holds public key certificates of IDPs and key pairs for the Fedlet.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -46,11 +46,11 @@ Several sections in this chapter reference STS code examples. The following proc

. If you have not already done so, download and build the STS samples.
+
For information on downloading and building OpenAM sample source code, see link:https://backstage.forgerock.com/knowledge/kb/article/a47487197[How do I access and build the sample code provided for OpenAM 12.x, 13.x and AM (All versions)?, window=\_blank] in the __Knowledge Base__.
The OpenAM sample source code is in the link:https://github.com/OpenIdentityPlatform/OpenAM/tree/master/openam-samples[openam-samples, window=\_blank] directory of the OpenAM source code on GitHub.

. Check out the `master` branch of the OpenAM source.
+
You can find the STS code examples under `/path/to/openam-samples-external/sts-example-code`.
You can find the STS code examples under `/path/to/openam-source/openam-samples/sts-example-code`.

====

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@
information: "Portions copyright [year] [name of copyright owner]".

Copyright 2017 ForgeRock AS.
Portions Copyright 2024-2025 3A Systems LLC.
Portions Copyright 2024-2026 3A Systems LLC.
////

:figure-caption!:
Expand Down Expand Up @@ -323,6 +323,8 @@ Run the image:
docker run -it --name apache_agent -p 8000:80 -h www.example.com --shm-size 2G --network openam-quickstart apache_agent
----

====


[#try-it-out]
=== Trying It Out
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@
information: "Portions copyright [year] [name of copyright owner]".

Copyright 2017 ForgeRock AS.
Portions Copyright 2024-2025 3A Systems LLC.
Portions Copyright 2024-2026 3A Systems LLC.
////

:figure-caption!:
Expand Down Expand Up @@ -53,8 +53,6 @@ Active/passive deployments are slightly simpler to deploy. Active/passive deploy
+
Affinity deployments allow you to spread requests to the CTS token store across multiple directory master instances. Affinity deployments are a good fit for deployments with many OpenAM servers.
+
For more information on CTS affinity deployments, see link:https://backstage.forgerock.com/knowledge/kb/article/a94140799[Best practice for using Core Token Service (CTS) Affinity based load balancing in AM (All versions) and OpenAM 13.5.1, window=\_top] in the __ForgeRock Knowledge Base__.
+
Do not deploy CTS token stores behind a load balancer. Instead, specify connections to the directory server instances that comprise the CTS token store by using the Connection String(s) property in the CTS configuration.

+
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -67,7 +67,7 @@ $ mkdir -p /path/to/openam-tools/admin
. Unpack the tools:
+

[source, console]
[source, console, subs="attributes+"]
----
$ cd /path/to/openam-tools/admin
$ unzip ~/Downloads/openam/SSOAdminTools-{openam-version}.zip
Expand Down Expand Up @@ -149,12 +149,6 @@ $ tail -2 /path/to/openam-tools/admin/openam/bin/ssoadm
-D"javax.net.ssl.trustStore=/path/to/tomcat/conf/keystore.jks" \
com.sun.identity.cli.CommandManager "$@"
----
+

[NOTE]
======
In non-production environments, you can configure the `ssoadm` command to trust all server certificates. For more information, see link:https://backstage.forgerock.com/knowledge/kb/book/b88592244#trust[Q. How do I configure ssoadm to trust all certificates?, window=\_top] in the __ForgeRock Knowledge Base__.
======

. (Optional) If you use IBM Java, add `-D"amCryptoDescriptor.provider=IBMJCE"` and `-D"amKeyGenDescriptor.provider=IBMJCE"` options to the `ssoadm` or `ssoadm.bat` script before using the script.
+
Expand Down Expand Up @@ -306,7 +300,7 @@ DS_DIRMGRPASSWD=password
When the OpenAM server `.war` file is deployed and running, you can configure it by using the tool with the properties file.
+

[source, console]
[source, console, subs="attributes+"]
----
$ java -jar openam-configurator-tool-{openam-version}.jar --file config.properties
Checking license acceptance...License terms accepted.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1118,7 +1118,7 @@ $ ./ldapsearch --hostname openam.example.com --port 1389 --bindDN "cn=Directory
. Repeat these steps for all appropriate OpenDJ instances.

====
For additional information, see link:https://backstage.forgerock.com/knowledge/kb/article/a97304600[How do I prevent anonymous access in DS/OpenDJ (All version), window=\_blank] in the __ForgeRock Knowledge Base__.
For additional information, see link:https://doc.openidentityplatform.org/opendj/admin-guide/chap-privileges-acis#access-control-disable-anonymous[ACI: Disable Anonymous Access, window=\_blank] in the OpenDJ __Administration Guide__.



Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -3297,7 +3297,6 @@ Use the ForgeRock Backstage website to provision values for the following Simple

* SNS Client Region

For information on provisioning the credentials required by the Push Notification Service, see link:https://backstage.forgerock.com/knowledge/kb/article/a47604373[How do I set up AM/OpenAM Push Notification Service credentials, window=\_blank] in the __BackStage Help Knowledge Base__.
--
`ssoadm` service name: `PushNotificationService`

Expand Down Expand Up @@ -4330,7 +4329,7 @@ Outgoing Email Body::
Customizes the user self-registration email body text.

+
Default: `en|<h2>Click on this <a href="%link%">link </a> to register.</h2>`
Default: `+en|<h2>Click on this <a href="%link%">link </a> to register.</h2>+`

+
`ssoadm` attribute: `selfServiceUserRegistrationEmailBody`
Expand Down Expand Up @@ -4455,7 +4454,7 @@ Outgoing Email Body::
Customizes the forgotten password email body text.

+
Default: `en|<h2>Click on this <a href="%link%"> link</a> to reset your password.</h2>`
Default: `+en|<h2>Click on this <a href="%link%"> link</a> to reset your password.</h2>+`

+
`ssoadm` attribute: `selfServiceForgottenPasswordEmailBody`
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -974,7 +974,7 @@ Accessible as an option to the Discovery Service for a specific user. To edit an
[#console-web-services-jsp-endpoints]
=== Web Services Console JSP Endpoints

Web services include endpoints in the `console/webservices` subdirectory. You can use them to define legacy options for services, such as the Liberty Identity Federation Framework (ID-FF). As such, these endpoints may be less essential to your implementation of OpenAM. For more information, see the link:http://www.forgerock.org/security_advisory2.html[OpenAM Wiki on Web Services, window=\_blank].
Web services include endpoints in the `console/webservices` subdirectory. You can use them to define legacy options for services, such as the Liberty Identity Federation Framework (ID-FF). As such, these endpoints may be less essential to your implementation of OpenAM.
--

`WSAuthNServices.jsp`::
Expand Down Expand Up @@ -1038,7 +1038,7 @@ This simple endpoint includes a redirection of the ServiceURI, and specifies Ope
This endpoint is called with the `PWResetInvalidURLViewBean` class, when a module servlet gets an invalid URL.

`PWResetQuestion.jsp`::
Starts the password reset process by prompting for the User ID. For more information on the process, see the method for the associated `PWResetQuestionModel`, available from the link:http://download.forgerock.org/downloads/openam/javadocs/internal/com/sun/identity/password/ui/model/PWResetQuestionModel.html[Interface PWResetQuestionModel specification page, window=\_blank].
Starts the password reset process by prompting for the User ID. For more information on the process, see the methods of the associated `com.sun.identity.password.ui.model.PWResetQuestionModel` interface.

`PWResetSuccess.jsp`::
Specifies the endpoint that is called when an account password is successfully reset.
Expand Down Expand Up @@ -1236,7 +1236,7 @@ Used with the servlet named `GatewayServlet`. Associated with the `Gateway.java`
The associated `.java` file is associated with session failover.

`/sessionservice, /profileservice, /policyservice, /namingservice, /loggingservice, /authservice, /notificationservice`::
All of these endpoints are associated with link:http://www.forgerock.org/security_advisory1.html[OpenAM Security Advisory #201203, window=\_blank]. As suggested in the advisory, if you are using OpenAM version 9.5.4 or 10.0.0, you should be sure to apply the updates required to upgrade your systems to versions 9.5.5 or 10.0.1 (or higher).
All of these endpoints are associated with OpenAM Security Advisory #201203. As suggested in the advisory, if you are using OpenAM version 9.5.4 or 10.0.0, you should be sure to apply the updates required to upgrade your systems to versions 9.5.5 or 10.0.1 (or higher).

`/jaxrpc/*, /identityservices/*`::
These endpoints provide information on configured web services, including the port name, status, URL, and implementation class. Both endpoints show the same data. The IdentityServices servlet name points to the following description: "Web Service Endpoint - Identity Services".
Expand Down
Loading
Loading