Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@
information: "Portions copyright [year] [name of copyright owner]".

Copyright 2017 ForgeRock AS.
Portions Copyright 2024-2025 3A Systems LLC.
Portions Copyright 2024-2026 3A Systems LLC.
////

:figure-caption!:
Expand Down Expand Up @@ -225,7 +225,7 @@ When installing the policy agent with the `--custom-install` option, the system
[#configure-web-policy-agent]
=== Configuring Web Policy Agent Properties

When you create a web policy agent profile and install the agent, you can choose to store the agent configuration centrally and configure the agent through OpenAM console. Alternatively, you can choose to store the agent configuration locally and configure the agent by changing values in the properties file. For information on the properties used in a centralized configuration, and the corresponding properties for use in a local configuration file where applicable, see link:../../../openam-web-policy-agents/web-users-guide/#configure-web-policy-agent[Configuring Web Policy Agent Properties, window=\_blank] in the __OpenAM Web Policy Agent User's Guide__.
When you create a web policy agent profile and install the agent, you can choose to store the agent configuration centrally and configure the agent through OpenAM console. Alternatively, you can choose to store the agent configuration locally and configure the agent by changing values in the properties file. For information on the properties used in a centralized configuration, and the corresponding properties for use in a local configuration file where applicable, see xref:../web-users-guide/chap-web-agents.adoc#configure-web-policy-agent[Configuring Web Policy Agent Properties] in the __OpenAM Web Policy Agent User's Guide__.


[#configure-j2ee-policy-agent]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2137,7 +2137,7 @@ The following procedure applies when OpenAM is configured as an IdP in one domai

. Install the policy agent.
+
The basic process for installing policy agents is available in the link:../../../openam-web-policy-agents/web-users-guide/#web-users-guide[Web Policy Agent User's Guide, window=\_blank] and the link:../../../openam-jee-policy-agents/jee-users-guide/#jee-users-guide[Java EE Policy Agent User's Guide, window=\_blank].
The basic process for installing policy agents is available in the xref:../web-users-guide/index.adoc[Web Policy Agent User's Guide] and the xref:../jee-users-guide/index.adoc[Java EE Policy Agent User's Guide].

. Replace the given OpenAM Login URL and OpenAM Logout URLs with SAML v2.0 URLs described in xref:#using-saml2-sso-slo["JSP Pages for SSO and SLO"].
+
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@
information: "Portions copyright [year] [name of copyright owner]".

Copyright 2017 ForgeRock AS.
Portions Copyright 2024-2025 3A Systems LLC.
Portions Copyright 2024-2026 3A Systems LLC.
////

:figure-caption!:
Expand Down Expand Up @@ -735,7 +735,7 @@ This example pulls everything together (except security considerations), using O

. On the OpenAM server that will be configured as an OAuth 2.0 client, set up an OpenAM policy agent and policy in the Top Level Realm, `/`, to protect resources.
+
See the link:../../../openam-web-policy-agents/web-users-guide/#web-users-guide[Web Policy Agent User's Guide, window=\_blank] or the link:../../../openam-jee-policy-agents/jee-users-guide/#jee-users-guide[Java EE Policy Agent User's Guide, window=\_blank] for instructions on installing a policy agent. This example relies on the Apache Tomcat Java EE policy agent, configured to protect resources in Apache Tomcat (Tomcat) at `\http://www.example.com:8080/`.
See the xref:../web-users-guide/index.adoc[Web Policy Agent User's Guide] or the xref:../jee-users-guide/index.adoc[Java EE Policy Agent User's Guide] for instructions on installing a policy agent. This example relies on the Apache Tomcat Java EE policy agent, configured to protect resources in Apache Tomcat (Tomcat) at `\http://www.example.com:8080/`.
+
The policies for this example protect the Tomcat examples under `\http://www.example.com:8080/examples/`, allowing GET and POST operations by all authenticated users. For more information, see xref:chap-authz-policy.adoc#chap-authz-policy["Defining Authorization Policies"].
+
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@
information: "Portions copyright [year] [name of copyright owner]".

Copyright 2017 ForgeRock AS.
Portions Copyright 2024 3A Systems LLC.
Portions Copyright 2024-2026 3A Systems LLC.
////

:figure-caption!:
Expand Down Expand Up @@ -132,11 +132,11 @@ Now that you have read about the SSO process, you should be able to set it up on

. Install OpenAM as described in the xref:../install-guide/index.adoc[Installation Guide]. This procedure uses a Server URL of `\http://openam.example.net:8080/openam`.

. Install the appropriate policy agent, as described in the link:../../../openam-web-policy-agents/web-users-guide/#web-users-guide[OpenAM Web Policy Agent User's Guide, window=\_blank] or the link:../../../openam-jee-policy-agents/jee-users-guide/#jee-users-guide[OpenAM Java EE Policy Agent User's Guide, window=\_blank]. This procedure uses an agent URL of `\http://app.example.net:80`, and an agent name of `webagent1`.
. Install the appropriate policy agent, as described in the xref:../web-users-guide/index.adoc[OpenAM Web Policy Agent User's Guide] or the xref:../jee-users-guide/index.adoc[OpenAM Java EE Policy Agent User's Guide]. This procedure uses an agent URL of `\http://app.example.net:80`, and an agent name of `webagent1`.

. Make sure that both URLs are configured with IP addresses, as described in xref:../install-guide/chap-install-core.adoc#chap-install-core["Installing OpenAM Core Services"] in the __Installation Guide__.

. Return to the OpenAM server on `\http://openam.example.net:8080/openam`. Log in as the administrative user, normally `amadmin`. To activate and configure the agent, follow the procedure described in the link:../../../openam-web-policy-agents/web-users-guide/#web-users-guide[OpenAM Web Policy Agent User's Guide, window=\_blank] or the link:../../../openam-jee-policy-agents/jee-users-guide/#jee-users-guide[OpenAM Java EE Policy Agent User's Guide, window=\_blank].
. Return to the OpenAM server on `\http://openam.example.net:8080/openam`. Log in as the administrative user, normally `amadmin`. To activate and configure the agent, follow the procedure described in the xref:../web-users-guide/index.adoc[OpenAM Web Policy Agent User's Guide] or the xref:../jee-users-guide/index.adoc[OpenAM Java EE Policy Agent User's Guide].

. Now you can configure SSO Only mode. In the OpenAM console, click Realms > __Realm Name__ > Agents > `webagent1`. Scroll down to SSO Only Mode and activate the Enabled box.

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@
information: "Portions copyright [year] [name of copyright owner]".

Copyright 2017 ForgeRock AS.
Portions Copyright 2024-2025 3A Systems LLC.
Portions Copyright 2024-2026 3A Systems LLC.
////

:figure-caption!:
Expand Down Expand Up @@ -97,9 +97,9 @@ OpenAM also supports standards-based access policies defined using the eXtensibl

In the first chapter of the guide you installed a web policy agent to enforce OpenAM's authorization decisions on Apache HTTP Server. That web policy agent is only one of many policy agents that work with OpenAM. xref:../admin-guide/chap-agents.adoc#chap-agents["Configuring Policy Agent Profiles"] in the __Administration Guide__ describes policy agents for different web servers, for a variety of Java EE web application containers, for protecting SOAP-based web services, and for OAuth 2.0 clients.

For details about web policy agents also see the link:../../../openam-web-policy-agents/web-users-guide/#web-users-guide[Web Policy Agent User's Guide, window=\_blank].
For details about web policy agents also see the xref:../web-users-guide/index.adoc[Web Policy Agent User's Guide].

For details about Java EE policy agents also see the link:../../../openam-jee-policy-agents/jee-users-guide/#jee-users-guide[Java EE Policy Agent User's Guide, window=\_blank].
For details about Java EE policy agents also see the xref:../jee-users-guide/index.adoc[Java EE Policy Agent User's Guide].

Furthermore link:https://github.com/OpenIdentityPlatform/OpenIG[OpenIG Identity Gateway, window=\_blank] works with applications where you want to protect access, but you cannot install a policy agent. For example, you might have a web application running in a server for which no policy agent has been developed. Or you might be protecting an application where you simply cannot install a policy agent. In that case, OpenIG functions as a flexible reverse proxy with standard SAML v2.0 capabilities. For details see the link:https://doc.openidentityplatform.org/openig/[OpenIG documentation, window=\_blank].

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@
information: "Portions copyright [year] [name of copyright owner]".

Copyright 2017 ForgeRock AS.
Portions Copyright 2024-2025 3A Systems LLC.
Portions Copyright 2024-2026 3A Systems LLC.
////

:figure-caption!:
Expand All @@ -23,7 +23,7 @@
[#chap-uninstall]
== Removing OpenAM Software

This chapter shows you how to uninstall OpenAM core software. See the link:../../../openam-web-policy-agents/web-users-guide/#web-users-guide[OpenAM Web Policy Agent User's Guide, window=\_blank], or the link:../../../openam-jee-policy-agents/jee-users-guide/#jee-users-guide[OpenAM Java EE Policy Agent User's Guide, window=\_blank] for instructions on removing OpenAM agents.
This chapter shows you how to uninstall OpenAM core software. See the xref:../web-users-guide/index.adoc[OpenAM Web Policy Agent User's Guide], or the xref:../jee-users-guide/index.adoc[OpenAM Java EE Policy Agent User's Guide] for instructions on removing OpenAM agents.

[#uninstall-OpenAM-core]
.To Remove OpenAM Core Software
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@
information: "Portions copyright [year] [name of copyright owner]".

Copyright 2017 ForgeRock AS.
Portions Copyright 2024-2025 3A Systems LLC.
Portions Copyright 2024-2026 3A Systems LLC.
////

:figure-caption!:
Expand All @@ -28,7 +28,7 @@ This chapter covers installation of the policy agent for Apache Tomcat.
[#before-tomcat-agent-install]
=== Before You Install

Make sure OpenAM is installed and running, and that you can contact OpenAM from the system running the policy agent. Next, create a profile for your policy agent as described in xref:../jee-users-guide/chap-jee-agent-config.adoc#create-agent-profiles[Creating Agent Profiles]. To protect resources with the agent, create at least one policy as described in link:../../../openam/admin-guide/chap-cdsso[Configuring Policies, window=\_blank] in the __OpenAM Administration Guide__. Consider creating a simple policy, such as a policy that allows only authenticated users to access your resources in order to test your policy agent after installation.
Make sure OpenAM is installed and running, and that you can contact OpenAM from the system running the policy agent. Next, create a profile for your policy agent as described in xref:../jee-users-guide/chap-jee-agent-config.adoc#create-agent-profiles[Creating Agent Profiles]. To protect resources with the agent, create at least one policy as described in xref:../admin-guide/chap-authz-policy.adoc#configure-policies-with-console[Configuring Policies] in the __OpenAM Administration Guide__. Consider creating a simple policy, such as a policy that allows only authenticated users to access your resources in order to test your policy agent after installation.

You must install Apache Tomcat before you install the policy agent, and you must stop the server during installation.

Expand Down Expand Up @@ -149,11 +149,11 @@ com.iplanet.am.server.port=8080
com.iplanet.am.services.deploymentDescriptor=/openam
----

Adjust configuration parameters to your needs according to xref:./chap-jee-agent-config.adoc#configure-j2ee-policy-agent[Configuring Java EE Policy Agent Properties]
Adjust configuration parameters to your needs according to xref:chap-jee-agent-config.adoc#configure-j2ee-policy-agent[Configuring Java EE Policy Agent Properties]

[NOTE]
======
If the agent is in a different domain than the server, refer to the __Administration Guide__ procedure, link:../../../openam/admin-guide/chap-cdsso[Configuring Cross-Domain Single Sign On, window=\_blank].
If the agent is in a different domain than the server, refer to the __Administration Guide__ procedure, xref:../admin-guide/chap-cdsso.adoc#chap-cdsso[Configuring Cross-Domain Single Sign-On].
======

--
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@
information: "Portions copyright [year] [name of copyright owner]".

Copyright 2017 ForgeRock AS.
Portions Copyright 2024-2025 3A Systems LLC.
Portions Copyright 2024-2026 3A Systems LLC.
////

:figure-caption!:
Expand Down Expand Up @@ -140,7 +140,7 @@ You can create a policy agent profile in OpenAM using the `ssoadm` command-line

The following procedure demonstrates creating a policy agent profile using the `ssoadm` command:

. Make sure the `ssoadm` command is installed. See link:../../../openam/13/install-guide/#install-openam-admin-tools["To Set Up Administration Tools", window=\_blank] in the __OpenAM Installation Guide__.
. Make sure the `ssoadm` command is installed. See xref:../install-guide/chap-install-tools.adoc#install-openam-admin-tools[To Set Up Administration Tools] in the __OpenAM Installation Guide__.

. Determine the list of properties to set in the agent profile.
+
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@
information: "Portions copyright [year] [name of copyright owner]".

Copyright 2017 ForgeRock AS.
Portions Copyright 2024 3A Systems LLC.
Portions Copyright 2024-2026 3A Systems LLC.
////

:figure-caption!:
Expand Down Expand Up @@ -79,7 +79,7 @@ For example, you can set URI patterns with wildcards in the OpenAM console using
/css/-*-
/*.jsp?locale=*
----
For more information on wildcard usage, see link:../../../openam/13/admin-guide/#wildcard-syntax[Wildcard Usage, window=\_blank].
For more information on wildcard usage, see xref:../admin-guide/chap-authz-policy.adoc#policy-patterns-wildcards[Specifying Resource Patterns with Wildcards].

The Java EE policy agent also supports a Not-Enforced Client IP List, which specifies the client IP addresses that can be excluded from authentication and authorization. This property lets administrators access the web site from a certain IP address, or gives a search engine access to the web resources.

Expand Down Expand Up @@ -147,6 +147,6 @@ OpenAM's CDSSO solves this cross-domain problem and is best implemented in envir

The Java EE policy agent works with an OpenAM component called a `CDCServlet` that generates a self-submitting form containing the valid session token from one domain. The form gets auto-submitted to the policy agent endpoint via a POST operation. The policy agent processes the request and extracts the session ID, which is again validated by OpenAM. If validation is successful, the policy agent sets the cookie in alternate domain. The client can then access a resource in that domain.

For more details, see link:../../../openam/13/admin-guide/#chap-cdsso[Configuring Cross Domain Single Sign-On, window=\_blank].
For more details, see xref:../admin-guide/chap-cdsso.adoc#chap-cdsso[Configuring Cross-Domain Single Sign-On].


Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@
information: "Portions copyright [year] [name of copyright owner]".

Copyright 2017 ForgeRock AS.
Portions Copyright 2024-2025 3A Systems LLC.
Portions Copyright 2024-2026 3A Systems LLC.
////

:figure-caption!:
Expand All @@ -28,7 +28,7 @@ This chapter covers installation of the policy agent for Jetty.
[#before-jetty-agent-install]
=== Before You Install

Make sure OpenAM is installed and running, and that you can contact OpenAM from the system running the policy agent. Next, create a profile for your policy agent as described in xref:../jee-users-guide/chap-jee-agent-config.adoc#create-agent-profiles[Creating Agent Profiles]. To protect resources with the agent, create at least one policy as described in link:../../../openam/13/admin-guide/#chap-authz-policy[Configuring Policies, window=\_blank] in the __OpenAM Administration Guide__. Consider creating a simple policy, such as a policy that allows only authenticated users to access your resources in order to test your policy agent after installation.
Make sure OpenAM is installed and running, and that you can contact OpenAM from the system running the policy agent. Next, create a profile for your policy agent as described in xref:../jee-users-guide/chap-jee-agent-config.adoc#create-agent-profiles[Creating Agent Profiles]. To protect resources with the agent, create at least one policy as described in xref:../admin-guide/chap-authz-policy.adoc#configure-policies-with-console[Configuring Policies] in the __OpenAM Administration Guide__. Consider creating a simple policy, such as a policy that allows only authenticated users to access your resources in order to test your policy agent after installation.

You must install Jetty before you install the policy agent, and you must stop the server during installation.

Expand Down Expand Up @@ -143,11 +143,11 @@ com.iplanet.am.server.port=8080
com.iplanet.am.services.deploymentDescriptor=/openam
----

Adjust configuration parameters to your needs according to xref:./chap-jee-agent-config.adoc#configure-j2ee-policy-agent[Configuring Java EE Policy Agent Properties]
Adjust configuration parameters to your needs according to xref:chap-jee-agent-config.adoc#configure-j2ee-policy-agent[Configuring Java EE Policy Agent Properties]

[NOTE]
======
If the agent is in a different domain than the server, refer to the __Administration Guide__ procedure, link:../../../openam/admin-guide/chap-cdsso[Configuring Cross-Domain Single Sign On, window=\_blank].
If the agent is in a different domain than the server, refer to the __Administration Guide__ procedure, xref:../admin-guide/chap-cdsso.adoc#chap-cdsso[Configuring Cross-Domain Single Sign-On].
======
--
. If your policy agent configuration is not in the top-level realm (/), then you must edit config/OpenSSOAgentBootstrap.properties to identify the sub-realm that has your policy agent configuration. Find com.sun.identity.agents.config.organization.name and change the "/" to the path to your policy agent profile. This allows the policy agent to properly identify itself to the OpenAM server.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@
information: "Portions copyright [year] [name of copyright owner]".

Copyright 2017 ForgeRock AS.
Portions Copyright 2024 3A Systems LLC.
Portions Copyright 2024-2026 3A Systems LLC.
////

:figure-caption!:
Expand All @@ -35,7 +35,7 @@ After setting up the container where you run OpenAM to use HTTPS, get the certif

Copy the certificate file to the system where you plan to install the policy agent. Import the certificate into a trust store that you will use during policy agent installation. If you import the certificate into the default trust store for the Java platform, then the `agentadmin` command can recognize it without additional configuration.

Export and import of self-signed certificates is demonstrated in the __Administration Guide__ chapter on link:../../../openam/13/admin-guide/#chap-certs-keystores[Managing Certificates, window=\_blank].
Export and import of self-signed certificates is demonstrated in the __Administration Guide__ chapter on xref:../admin-guide/chap-certs-keystores.adoc#chap-certs-keystores[Managing Certificates and Keystores].

--

Expand Down
Loading
Loading