Sun OpenSSO Enterprise 8.0 Technical Overview
    
A
 
 access control, OpenSSO Enterprise ( Index Term Link )
 
 access logs ( Index Term Link )
 
 Access Manager Repository Plug-in, identity repository plug-in ( Index Term Link )
 
 account locking
  and authentication ( Index Term Link )
  memory locking ( Index Term Link )
  physical locking ( Index Term Link )
 
 action, policy ( Index Term Link )
 
 Active Directory authentication ( Index Term Link )
 
 active session time, policy ( Index Term Link )
 
 agents
  See policy agent
  See security agent
 
 amLogging.xml ( Index Term Link )
 
 Anonymous authentication ( Index Term Link )
 
 API, SAML v2 ( Index Term Link )
 
 application programming interfaces, See API
 
 architecture
  client/server ( Index Term Link )
  Discovery Service ( Index Term Link )
  federation ( Index Term Link )
  Identity Web Services ( Index Term Link )
  plug-ins ( Index Term Link )
  SAML v1.x ( Index Term Link )
  sample deployment 1 ( Index Term Link )
  sample deployment 2 ( Index Term Link )
  web services security ( Index Term Link )
  web services security deployment ( Index Term Link )
 
 auditing, See logging
 
 authentication chain, policy ( Index Term Link )
 
 authentication chaining ( Index Term Link )
 
 authentication configuration service ( Index Term Link )
 
 authentication context, overview ( Index Term Link )
 
 authentication data ( Index Term Link ) ( Index Term Link )
 
 authentication level, policy ( Index Term Link )
 
 authentication level-based authentication ( Index Term Link )
 
 authentication module instance, policy ( Index Term Link )
 
 authentication modules ( Index Term Link ) ( Index Term Link )
  Active Directory ( Index Term Link )
  Anonymous ( Index Term Link )
  Certificate ( Index Term Link )
  Data Store ( Index Term Link )
  Federation ( Index Term Link )
  HTTP Basic ( Index Term Link )
  JDBC ( Index Term Link )
  Membership ( Index Term Link )
  MSISDN ( Index Term Link )
  RADIUS ( Index Term Link )
  SafeWord ( Index Term Link )
  SAML ( Index Term Link )
  SecurID ( Index Term Link )
  UNIX ( Index Term Link )
  Windows Desktop SSO ( Index Term Link )
  Windows NT ( Index Term Link )
 
 Authentication Service
  account locking ( Index Term Link )
  authentication chaining ( Index Term Link )
  authentication configuration service ( Index Term Link )
  authentication level-based authentication ( Index Term Link )
  authentication type configurations ( Index Term Link )
  configuration ( Index Term Link )
  core authentication module ( Index Term Link )
  description ( Index Term Link )
  distributed authentication user interface ( Index Term Link )
  features ( Index Term Link )
  FQDN name mapping ( Index Term Link )
  JAAS shared state ( Index Term Link )
  login URLs ( Index Term Link )
  module-based authentication ( Index Term Link )
  modules ( Index Term Link )
  or Authentication Web Service (Liberty) ( Index Term Link )
  organization-based authentication ( Index Term Link )
  overview ( Index Term Link )
  persistent cookie ( Index Term Link )
  process ( Index Term Link )
  programming interfaces ( Index Term Link )
  realm-based authentication ( Index Term Link )
  realm configuration ( Index Term Link )
  redirection URLs ( Index Term Link )
  role-based authentication ( Index Term Link )
  security ( Index Term Link )
  service-based authentication ( Index Term Link )
  session upgrade ( Index Term Link )
  SPI ( Index Term Link )
  user-based authentication ( Index Term Link )
  user interface ( Index Term Link )
 
 authentication services
  Authentication Service (non-Liberty) ( Index Term Link )
  Authentication Web Service (Liberty) ( Index Term Link )
 
 authentication type configurations ( Index Term Link )
 
 Authentication Web Service ( Index Term Link )
  description ( Index Term Link )
  intefaces ( Index Term Link )
  or Authentication Service (non-Liberty) ( Index Term Link )
 
 authorization
  See Policy Service
  and XACML ( Index Term Link )
  overview ( Index Term Link )
 
 auto-federation ( Index Term Link )
    
B
 
 basic user session ( Index Term Link )
  initial HTTP request ( Index Term Link )
 
 bootstrap file ( Index Term Link )
 
 bulk federation ( Index Term Link )
    
C
 
 CDSSO, See cross-domain single sign-on
 
 centralized agent configuration ( Index Term Link )
 
 centralized configuration data, bootstrap file ( Index Term Link )
 
 Certificate authentication ( Index Term Link )
 
 circle of trust
  definition ( Index Term Link ) ( Index Term Link )
 
 Client Detection Service, in authentication ( Index Term Link )
 
 Client SDK ( Index Term Link )
 
 Client SDK samples ( Index Term Link )
 
 command line interface ( Index Term Link )
 
 common domain ( Index Term Link ) ( Index Term Link )
  reader service ( Index Term Link )
  writer service ( Index Term Link )
 
 common domain cookie ( Index Term Link )
 
 Common Federation Configuration ( Index Term Link )
 
 Common Tasks Wizard ( Index Term Link )
 
 components, OpenSSO Enterprise ( Index Term Link )
 
 conditions, policy ( Index Term Link )
 
 configuration, Authentication Service ( Index Term Link )
 
 configuration data ( Index Term Link )
 
 configuration data store ( Index Term Link )
  bootstrap file ( Index Term Link )
 
 configuration files, description ( Index Term Link )
 
 cookies
  and sessions ( Index Term Link )
  common domain ( Index Term Link )
 
 core authentication module ( Index Term Link )
 
 core services
  Authentication Service ( Index Term Link )
  Federation Services ( Index Term Link )
  Identity Repository Service ( Index Term Link )
  identity web services ( Index Term Link )
  Logging Service ( Index Term Link )
  OpenSSO Enterprise ( Index Term Link )
  Policy Service ( Index Term Link )
  Security Token Service ( Index Term Link )
  Session Service ( Index Term Link )
  Web Services Security ( Index Term Link )
  web services stack ( Index Term Link )
 
 cross-domain single sign-on
  definition ( Index Term Link ) ( Index Term Link )
  process ( Index Term Link )
 
 cross domain single sign on
  proprietary ( Index Term Link )
  SAML v2 ( Index Term Link )
 
 current session properties, policy ( Index Term Link )
    
D
 
 data
  authentication ( Index Term Link )
  configuration ( Index Term Link )
  identity ( Index Term Link )
  types ( Index Term Link )
 
 data services
  interfaces ( Index Term Link )
  Liberty Personal Profile Service ( Index Term Link )
 
 Data Store authentication ( Index Term Link )
 
 data stores ( Index Term Link ) ( Index Term Link )
 
 definition, OpenSSO Enterprise ( Index Term Link )
 
 definitions
  circle of trust ( Index Term Link )
  federation ( Index Term Link )
  identity ( Index Term Link )
  identity federation ( Index Term Link )
  identity provider ( Index Term Link )
  principal ( Index Term Link )
  provider ( Index Term Link )
  provider federation ( Index Term Link )
  service provider ( Index Term Link )
  trust ( Index Term Link )
 
 deployment ( Index Term Link )
 
 Discovery Service ( Index Term Link )
  architecture ( Index Term Link )
  description ( Index Term Link )
  intefaces ( Index Term Link )
  overview ( Index Term Link )
  process ( Index Term Link )
 
 distributed authentication
  definition ( Index Term Link )
  in authentication ( Index Term Link )
 
 documentation ( Index Term Link )
  OpenSSO Enterprise ( Index Term Link )
  related products ( Index Term Link )
 
 DTD
  configuration files ( Index Term Link )
  modification of ( Index Term Link )
 
 dynamic identity provider proxying, Liberty ID-FF ( Index Term Link )
    
E
 
 error logs ( Index Term Link )
    
F
 
 failover, configuration data store ( Index Term Link )
 
 features
  Authentication Service ( Index Term Link )
  OpenSSO Enterprise ( Index Term Link )
 
 federated identity ( Index Term Link )
 
 federation ( Index Term Link )
  architecture ( Index Term Link )
  common domain ( Index Term Link )
  definition ( Index Term Link )
  identity federation and single sign-on ( Index Term Link )
  options ( Index Term Link )
  overview ( Index Term Link )
  SPI ( Index Term Link )
 
 Federation authentication ( Index Term Link )
 
 federation management, OpenSSO Enterprise ( Index Term Link )
 
 federation options
  Liberty ID-FF ( Index Term Link )
  SAML v1.x ( Index Term Link ) ( Index Term Link )
  SAML v2 ( Index Term Link ) ( Index Term Link )
 
 Federation Services, description ( Index Term Link )
 
 federationmanagement, key features ( Index Term Link )
 
 Fedlet ( Index Term Link )
  overview ( Index Term Link )
 
 flat files, logging ( Index Term Link )
 
 FQDN name mapping, and authentication ( Index Term Link )
 
 functions, OpenSSO Enterprise ( Index Term Link )
    
G
 
 General Policy Service ( Index Term Link )
 
 global logout, Liberty ID-FF ( Index Term Link )
 
 global services ( Index Term Link )
  Common Federation Configuration ( Index Term Link )
  Liberty ID-FF Service Configuration ( Index Term Link )
  Liberty ID-WSF Security Service ( Index Term Link ) ( Index Term Link )
  Multi-Federation Protocol ( Index Term Link )
  Password Reset ( Index Term Link )
  Policy Configuration ( Index Term Link )
  SAML v2 Service Configuration ( Index Term Link ) ( Index Term Link )
  Security Token Service ( Index Term Link )
  Session ( Index Term Link )
  User ( Index Term Link )
    
H
 
 HTTP Basic authentication ( Index Term Link )
 
 HTTP request, and authentication ( Index Term Link )
 
 HTTP security agent ( Index Term Link )
    
I
 
 identifiers, Liberty ID-FF ( Index Term Link )
 
 identity, definition ( Index Term Link )
 
 identity-based web service ( Index Term Link )
 
 identity data ( Index Term Link )
 
 identity federation ( Index Term Link ) ( Index Term Link )
  definition ( Index Term Link )
 
 Identity Manager, and OpenSSO Enterprise ( Index Term Link )
 
 identity providers, definition ( Index Term Link )
 
 Identity Repository Service
  See identity data
  description ( Index Term Link )
 
 identity repository service, plug-in ( Index Term Link )
 
 Identity Web Services ( Index Term Link )
  architecture ( Index Term Link )
 
 identity web services
  description ( Index Term Link )
  OpenSSO Enterprise ( Index Term Link )
 
 Identity Web Services
  overview ( Index Term Link )
  REST ( Index Term Link )
  SOAP and WSDL ( Index Term Link )
  styles ( Index Term Link )
 
 information tree, See configuration data
 
 installation and configuration ( Index Term Link )
 
 interfaces
  Authentication Service ( Index Term Link )
  Logging Service ( Index Term Link )
  Policy Service ( Index Term Link )
  Security Token Service ( Index Term Link )
  SOAP Binding Service ( Index Term Link )
  web services security ( Index Term Link )
  XACML ( Index Term Link )
 
 introduction, OpenSSO Enterprise ( Index Term Link )
 
 IP address/DNS names, policy ( Index Term Link )
    
J
 
 JAAS framework, and authentication ( Index Term Link )
 
 JAAS shared state, and authentication ( Index Term Link )
 
 Java Community Process, See JCP
 
 JavaServer Pages, See JSP
 
 JCP, specifications ( Index Term Link )
 
 JDBC ( Index Term Link )
 
 JDBC authentication ( Index Term Link )
 
 JSP, SAML v2 ( Index Term Link )
 
 JSR 196 specifications ( Index Term Link )
    
L
 
 LDAP authentication ( Index Term Link )
 
 LDAP filter, policy ( Index Term Link )
 
 LDAPv3, identity repository plug-in ( Index Term Link )
 
 legacy mode, OpenSSO Enterprise ( Index Term Link )
 
 Liberty Alliance Project
  specifications ( Index Term Link ) ( Index Term Link )
 
 Liberty Alliance Project Identity Federation Framework, See Liberty ID-FF
 
 Liberty ID-FF ( Index Term Link )
  and single sign-on ( Index Term Link )
  auto-federation ( Index Term Link )
  bulk federation ( Index Term Link )
  convergence with SAML ( Index Term Link )
  dynamic identity provider proxying ( Index Term Link )
  federation option ( Index Term Link )
  global logout ( Index Term Link )
  identifiers and name registration ( Index Term Link )
  pre-login process ( Index Term Link )
  process ( Index Term Link )
  SAML v1.x comparison ( Index Term Link )
 
 Liberty ID-FF Service Configuration ( Index Term Link )
 
 Liberty ID-WSF Security Service ( Index Term Link )
 
 Liberty Personal Profile Service ( Index Term Link )
  description ( Index Term Link )
 
 local identity ( Index Term Link )
 
 log reading, customize ( Index Term Link )
 
 logging
  access logs ( Index Term Link )
  amLogging.xmll ( Index Term Link )
  component log files ( Index Term Link )
  error logs ( Index Term Link )
  flat files ( Index Term Link )
  log reading ( Index Term Link )
  overview ( Index Term Link )
  process ( Index Term Link )
  recorded events ( Index Term Link )
  relational databases ( Index Term Link )
  remote logging ( Index Term Link )
  secure logging ( Index Term Link )
 
 Logging Service
  description ( Index Term Link )
  programming interfaces ( Index Term Link )
 
 login URLs, and authentication ( Index Term Link )
    
M
 
 Membership authentication ( Index Term Link )
 
 memory locking, and authentication ( Index Term Link )
 
 message level security ( Index Term Link )
 
 module-based authentication ( Index Term Link )
 
 MSISDN authentication ( Index Term Link )
 
 Multi-Federation Protocol ( Index Term Link )
 
 multi-federation protocol hub, overview ( Index Term Link )
    
N
 
 name registration, Liberty ID-FF ( Index Term Link )
 
 Naming Service, and session validation ( Index Term Link )
    
O
 
 OpenSSO Enterprise
  access control ( Index Term Link )
  architecture ( Index Term Link )
  components ( Index Term Link )
  core services ( Index Term Link )
  definition ( Index Term Link )
  features ( Index Term Link )
  federation management ( Index Term Link )
  functions ( Index Term Link )
  identity web services ( Index Term Link )
  introduction ( Index Term Link )
  legacy mode ( Index Term Link )
  overview ( Index Term Link )
  process ( Index Term Link )
  web services security ( Index Term Link )
 
 Oracle Access Manager, and OpenSSO Enterprise ( Index Term Link )
 
 organization-based authentication ( Index Term Link )
 
 overview
  authentication and authentication context ( Index Term Link )
  Authentication Service ( Index Term Link )
  Discovery Service ( Index Term Link )
  HTTP security agent ( Index Term Link )
  Liberty Personal Profile Service ( Index Term Link )
  message level security ( Index Term Link )
  OpenSSO Enterprise ( Index Term Link )
  policy agent ( Index Term Link )
  Policy Service ( Index Term Link )
  security agent ( Index Term Link )
  session service ( Index Term Link )
  SOAP security agent ( Index Term Link )
  transport level security ( Index Term Link )
  XACML ( Index Term Link )
    
P
 
 Password Reset ( Index Term Link ) ( Index Term Link )
 
 PDP, in SAML ( Index Term Link )
 
 persistent cookie, and authentication ( Index Term Link )
 
 physical locking, and authentication ( Index Term Link )
 
 plug-ins
  Access Manager Repository Plug-in ( Index Term Link )
  authentication
   See authentication modules
  identity repository service ( Index Term Link )
  LDAPv3 ( Index Term Link )
  policy response providers ( Index Term Link )
  Policy Service ( Index Term Link )
  service configuration ( Index Term Link )
 
 policy ( Index Term Link )
  and XACML ( Index Term Link )
  conditions ( Index Term Link )
  definition ( Index Term Link )
  General Policy Service ( Index Term Link )
  Policy Configuration Service ( Index Term Link )
  rule ( Index Term Link )
  subject ( Index Term Link )
 
 Policy Administration Point, definition ( Index Term Link )
 
 policy agent, overview ( Index Term Link )
 
 policy agents ( Index Term Link )
 
 Policy Configuration ( Index Term Link )
 
 Policy Configuration Service ( Index Term Link )
 
 Policy Decision Point
  and XACML ( Index Term Link )
  definition ( Index Term Link )
 
 Policy Enforcement Point
  and XACML ( Index Term Link )
  definition ( Index Term Link )
 
 policy evaluation, process ( Index Term Link )
 
 Policy Service
  definition ( Index Term Link )
  description ( Index Term Link )
  overview ( Index Term Link )
  plug-in ( Index Term Link )
  policy ( Index Term Link )
  policy evaluation ( Index Term Link )
  policy response provider plug-in ( Index Term Link )
  programming interfaces ( Index Term Link )
  referral ( Index Term Link )
  XACML ( Index Term Link )
 
 policy types ( Index Term Link )
 
 pre-login process, Liberty ID-FF ( Index Term Link )
 
 principal, definition ( Index Term Link )
 
 process
  See OpenSSO Enterprise
  Discovery Service ( Index Term Link )
  Liberty ID-FF ( Index Term Link )
  SOAP Binding Service ( Index Term Link )
 
 programming interfaces
  Authentication Web Service ( Index Term Link )
  data services ( Index Term Link )
  Discovery Service ( Index Term Link )
 
 provider federation, definition ( Index Term Link )
 
 providers ( Index Term Link )
    
R
 
 RADIUS authentication ( Index Term Link )
 
 reader service ( Index Term Link )
 
 realm authentication, policy ( Index Term Link )
 
 realm-based authentication ( Index Term Link )
 
 realm configuration, authentication ( Index Term Link )
 
 realms ( Index Term Link )
  and access control ( Index Term Link )
 
 redirection URLs, and authentication ( Index Term Link )
 
 referral ( Index Term Link )
 
 relational databases, logging ( Index Term Link )
 
 remote logging ( Index Term Link )
 
 RequestHandler interface ( Index Term Link )
 
 resource, policy ( Index Term Link )
 
 resource offering ( Index Term Link )
 
 REST ( Index Term Link )
  Identity Web Services ( Index Term Link )
 
 role-based authentication ( Index Term Link )
 
 rule, policy ( Index Term Link )
    
S
 
 SafeWord authentication ( Index Term Link )
 
 SAML, convergence with Liberty ID-FF ( Index Term Link )
 
 SAML authentication ( Index Term Link )
 
 SAML v1.x
  architecture ( Index Term Link )
  federation ( Index Term Link )
  federation option ( Index Term Link )
  Liberty ID-FF comparison ( Index Term Link )
 
 SAML v2 ( Index Term Link )
  administration ( Index Term Link )
  API ( Index Term Link )
  basic configuration ( Index Term Link )
  features ( Index Term Link )
  federation ( Index Term Link )
  federation option ( Index Term Link )
  JSP ( Index Term Link )
  SPI ( Index Term Link )
 
 SAML v2 Service Configuration ( Index Term Link ) ( Index Term Link )
 
 sample deployment 1 ( Index Term Link )
 
 sample deployment 2 ( Index Term Link )
 
 samples
  Client SDK ( Index Term Link )
  command line interface ( Index Term Link )
  server ( Index Term Link )
 
 secure attribute exchange, overview ( Index Term Link )
 
 secure logging ( Index Term Link )
 
 SecurID authentication ( Index Term Link )
 
 security, and authentication ( Index Term Link )
 
 security agent
  HTTP security agent ( Index Term Link )
  overview ( Index Term Link )
  SOAP security agent ( Index Term Link )
 
 security agents ( Index Term Link )
 
 Security Token Service ( Index Term Link ) ( Index Term Link )
  and Web Services Security ( Index Term Link )
  architecture ( Index Term Link )
  description ( Index Term Link )
  global service ( Index Term Link )
  programming interfaces ( Index Term Link )
  supported tokens ( Index Term Link )
 
 server samples ( Index Term Link )
 
 service-based authentication ( Index Term Link )
 
 service configuration plug-in ( Index Term Link )
 
 service files, configuration data ( Index Term Link )
 
 Service Management Service ( Index Term Link )
 
 service provider interface, See SPI
 
 service provider interfaces, See SPI
 
 service providers, definition ( Index Term Link )
 
 session
  See user session
  basic user session ( Index Term Link )
  initial HTTP request ( Index Term Link )
 
 session failover tools ( Index Term Link )
 
 Session Global Service ( Index Term Link )
 
 session ID, See session token
 
 session object, See session data structure
 
 Session Service, description ( Index Term Link )
 
 session service, overview ( Index Term Link )
 
 session termination ( Index Term Link )
 
 session token ( Index Term Link )
 
 session upgrade, and authentication ( Index Term Link )
 
 session validation, process ( Index Term Link )
 
 single sign-on ( Index Term Link )
  definition ( Index Term Link ) ( Index Term Link )
  process ( Index Term Link )
 
 single sign—on, and Liberty ID-FF ( Index Term Link )
 
 SiteMinder, and OpenSSO Enterprise ( Index Term Link )
 
 SOAP and WSDL, Identity Web Services ( Index Term Link )
 
 SOAP Binding Service ( Index Term Link )
  description ( Index Term Link )
  process ( Index Term Link )
  programming interfaces ( Index Term Link )
 
 SOAP security agent ( Index Term Link )
 
 SOAPReceiver, SOAP Binding Service process ( Index Term Link )
 
 SOAPReceiver servlet ( Index Term Link )
 
 specifications
  JCP ( Index Term Link )
  Liberty Alliance Project ( Index Term Link )
  web services security ( Index Term Link )
  WS-* ( Index Term Link )
 
 SPI ( Index Term Link )
  Authentication Service ( Index Term Link )
  federation ( Index Term Link )
  SAML v2 ( Index Term Link )
 
 SSO, See single sign-on
 
 ssoadm command line ( Index Term Link )
 
 ssoAdminTools.zip ( Index Term Link )
 
 ssoSessionTools.zip ( Index Term Link )
 
 subject, policy ( Index Term Link )
    
T
 
 time, policy ( Index Term Link )
 
 tokens, specifications ( Index Term Link )
 
 transport level security ( Index Term Link )
 
 trust, definition ( Index Term Link )
 
 trust agreements ( Index Term Link ) ( Index Term Link )
    
U
 
 UNIX authentication ( Index Term Link )
 
 user authentication, process ( Index Term Link )
 
 user-based authentication ( Index Term Link )
 
 User Global Service ( Index Term Link )
 
 user session
  cookies ( Index Term Link )
  definition ( Index Term Link )
  logging results ( Index Term Link )
  policy evaluation ( Index Term Link )
  session data structure ( Index Term Link )
  session termination ( Index Term Link )
  session token ( Index Term Link )
  session validation ( Index Term Link )
  user authentication ( Index Term Link )
    
V
 
 value, policy ( Index Term Link )
 
 virtual federation proxy, overview ( Index Term Link )
    
W
 
 Web Services Description Language, See WSDL
 
 web services security ( Index Term Link )
  architecture ( Index Term Link )
  deployment architecture ( Index Term Link )
 
 Web Services Security, description ( Index Term Link )
 
 web services security
  OpenSSO Enterprise ( Index Term Link )
  programming interfaces ( Index Term Link )
  specifications ( Index Term Link )
 
 web services stack ( Index Term Link )
  architecture ( Index Term Link )
  definition ( Index Term Link )
  included services ( Index Term Link )
  process ( Index Term Link )
  with Authentication Web Service ( Index Term Link )
  with Liberty ID-FF ( Index Term Link )
  with SAML v2 ( Index Term Link )
 
 Windows Desktop SSO authentication ( Index Term Link )
 
 Windows NT authentication ( Index Term Link )
 
 writer service ( Index Term Link )
 
 WS-*, specifications ( Index Term Link )
 
 WS-Federation ( Index Term Link )
 
 WS-Security specifications ( Index Term Link )
 
 WS-Trust specifications ( Index Term Link )
 
 WSDL ( Index Term Link ) ( Index Term Link )
    
X
 
 XACML
  and authorization ( Index Term Link )
  programming interfaces ( Index Term Link )
 
 XML
  configuration files ( Index Term Link )
  service files ( Index Term Link )