Sun OpenSSO Enterprise 8.0 Deployment Planning Guide

Using the Sample JSP

  1. Install and deploy OpenSSO Enterprise instances on four separate host computers, one instance in each domain.

  2. Locate the sample JSP on the Open SSO instance.

    http://FQDN/opensso/samples/multiprotocol/index.html

  3. Configure OpenSSO Enterprise instance 1 as a SAMLv2 Service Provider named SP1.

    Run the sample JSP to create one hosted SAMLv2 Service Provider and one remote SAMLv2 Identity Provider in the same circle of trust.

  4. Configure OpenSSO Enterprise instance 2 as an ID-FF Service Provider named Service Provider 2.

    Run the sample JSP to create one host ID-FF Service Provider and one remote ID-FF Identity Provider in the same circle of trust.

  5. Configure OpenSSO Enterprise instance 3 as a WS-Federation Service Provider named Service Provider 3.

    Run the sample JSP to created one hosted WS-Federation Service Provider and one remote WS-Federation Identity Provider in one circle of trust.

  6. Configure OpenSSO Enterprise instance 4 as an Identity Provider using the following protocols: IDP, referred as IDP1, IDP2 and IDP3 respectively.

    • SAMLv2 (Identity Provider 1)

    • ID-FF (Identity Provider 2)

    • WS-Federation (Identity Provider 3)

    Run the sample JSP to create three hosted Identity Providers (one each for SAMLv2, ID-FF and WS-Federation), and three remote Service Providers (one each for SAMLv2, ID-FF and WS-Federation) the same circle of trust.

  7. Run single sign-on from Service Provider 1 to Identity Provider 2, then from Service Provider 2 to Identity Provider 2 without logging in again, then Service Provider 3 to Identity Provider 3 without logging in.

  8. Run single logout from Service Provider 1.

    All sessions on Service Provider 2, Service Provider 3, and on all Identity Providers are destroyed.

  9. Run single sign-on again, and then run single Logout from Identity Provider 1.

    All sessions on Service Provider 1, Service Provider 2, Service Provider 3, and on Identity Providers are destroyed.