Sun Java System Access Manager 7 2005Q4 Technical Overview
    
A
 
 access control realm
  definition of ( Index Term Link )
  realm mode ( Index Term Link )
  when to use ( Index Term Link )
 
 access logs ( Index Term Link )
 
 Access Manager information tree
  access control realm ( Index Term Link )
  and identity repository ( Index Term Link )
  how realm data is stored ( Index Term Link )
  what it does ( Index Term Link )
 
 account federation ( Index Term Link )
 
 account linking termination ( Index Term Link )
 
 account locking ( Index Term Link )
  memory locking ( Index Term Link )
  physical locking ( Index Term Link )
 
 Active Directory authentication module type ( Index Term Link )
 
 affiliation federation ( Index Term Link )
 
 agent, See policy agent
 
 amLogging.xml ( Index Term Link )
 
 amSDK
  identity repository plug-in ( Index Term Link ) ( Index Term Link )
 
 Anonymous authentication module type ( Index Term Link )
 
 architecture
  access control realms ( Index Term Link )
  changes in this release ( Index Term Link )
  framework layer ( Index Term Link )
  overview ( Index Term Link )
  plug-ins layer ( Index Term Link )
 
 assertion, in SAML ( Index Term Link )
 
 auditing, See logging
 
 authentication, See Authentication Service
 
 authentication chaining ( Index Term Link )
 
 authentication context ( Index Term Link )
 
 authentication domain ( Index Term Link )
 
 authentication module types ( Index Term Link )
  Active Directory ( Index Term Link )
  Anonymous ( Index Term Link )
  Certificate ( Index Term Link )
  HTTP Basic ( Index Term Link )
  JDBC ( Index Term Link )
  Membership ( Index Term Link )
  MSISDN ( Index Term Link )
  RADIUS ( Index Term Link )
  SecurID ( Index Term Link )
  UNIX ( Index Term Link )
  Windows Desktop Single Sign-On ( Index Term Link )
  Windows NT ( Index Term Link )
 
 Authentication Service
  account locking ( Index Term Link )
  authentication chaining ( Index Term Link )
  authentication framework ( Index Term Link )
  authentication level-based authentication ( Index Term Link )
  authentication plug-in ( Index Term Link )
  client detection ( Index Term Link )
  configuration service ( Index Term Link )
  core component ( Index Term Link )
  core component descriptions ( Index Term Link )
  definition of ( Index Term Link )
  distributed authentication user interface ( Index Term Link ) ( Index Term Link )
  FQDN name mapping ( Index Term Link )
  general authentication service ( Index Term Link )
  JAAS shared state ( Index Term Link )
  module-based authentication ( Index Term Link )
  organization-based authentication ( Index Term Link )
  plug-in modules ( Index Term Link )
  presentation layer ( Index Term Link )
  process flow illustrated ( Index Term Link )
  redirection URLs ( Index Term Link )
  role-based authentication ( Index Term Link )
  service-based authentication ( Index Term Link )
  session upgrade ( Index Term Link )
  user-based authentication ( Index Term Link )
  user's view of ( Index Term Link )
  validation plug-in ( Index Term Link )
  web service, brief description ( Index Term Link )
 
 Authentication Web Service ( Index Term Link )
 
 authorization, See Policy Service
    
B
 
 basic user session, as a type of user session ( Index Term Link )
    
C
 
 CDSSO, See cross-domain single sign-on
 
 Certificate authentication module type ( Index Term Link )
 
 circle of trust ( Index Term Link )
 
 client APIs, brief description ( Index Term Link )
 
 Client Detection Service
  core component descriptions ( Index Term Link )
  in authentication ( Index Term Link )
  in authentication process flow ( Index Term Link )
 
 components, See core components
 
 condition, in policy ( Index Term Link )
 
 cookies, used in sessions ( Index Term Link )
 
 core components
  Authentication Service ( Index Term Link )
  in Access Manager, brief descriptions ( Index Term Link )
 
 cross-domain single sign-on
  as a type of user session ( Index Term Link )
  definition of ( Index Term Link )
  process flow illustrated ( Index Term Link )
  user session ( Index Term Link )
    
D
 
 data structure ( Index Term Link )
 
 delegation plug-in
  brief description ( Index Term Link )
  defining privileges ( Index Term Link )
 
 Discovery Service ( Index Term Link )
 
 distributed authentication
  definition of ( Index Term Link ) ( Index Term Link )
  process flow illustrated ( Index Term Link )
 
 documentation
  related Access Manager books ( Index Term Link )
  related Sun JES books ( Index Term Link )
 
 DTD
  caution, modifying DTD files ( Index Term Link )
  files used in Access Manager ( Index Term Link )
 
 dynamic identity provider proxying ( Index Term Link )
    
E
 
 error logs ( Index Term Link )
    
F
 
 federated identity ( Index Term Link )
 
 federation, See identity federation
 
 flat file format, logging ( Index Term Link )
 
 FQDN name mapping, definition of ( Index Term Link )
 
 framework layer
  Access Manager architecture ( Index Term Link )
  authentication ( Index Term Link )
  identity repository management ( Index Term Link )
  policy framework ( Index Term Link )
    
G
 
 general policy service ( Index Term Link )
    
H
 
 HTTP Basic authentication module type ( Index Term Link )
    
I
 
 identity federation ( Index Term Link )
  See also Liberty Alliance Project
  Access Manager frameworks ( Index Term Link )
  account federation ( Index Term Link )
  authentication domain ( Index Term Link )
  brief description of ( Index Term Link )
  circle of trust ( Index Term Link )
  core component descriptions ( Index Term Link )
  definition of ( Index Term Link )
  protocols flow ( Index Term Link )
  SAML specifications ( Index Term Link )
  web service, brief description ( Index Term Link )
  web service consumer ( Index Term Link )
  web service provider ( Index Term Link )
  web services framework (ID-WSF) ( Index Term Link )
 
 identity federation framework (ID-FF) ( Index Term Link )
 
 identity provider introduction ( Index Term Link )
 
 identity repository management
  framework ( Index Term Link )
  identity repository management plug-in ( Index Term Link )
 
 information tree, See Access Manager information tree
 
 Interaction Service ( Index Term Link )
    
J
 
 JAAS shared state, in authentication ( Index Term Link )
 
 JDBC ( Index Term Link )
 
 JDBC authentication module type ( Index Term Link )
    
L
 
 LDAP authentication module type ( Index Term Link )
 
 legacy mode ( Index Term Link )
 
 Liberty Alliance Project
  See also identity federation
  circle of trust ( Index Term Link )
  definition of ( Index Term Link )
  Liberty Alliance frameworks ( Index Term Link )
 
 local identity ( Index Term Link )
 
 log reading ( Index Term Link )
 
 logging
  access logs ( Index Term Link )
  amLogging.xmll ( Index Term Link )
  brief description of ( Index Term Link )
  component log filenames ( Index Term Link )
  core component descriptions ( Index Term Link )
  error logs ( Index Term Link )
  flat file format ( Index Term Link ) ( Index Term Link )
  log files directory ( Index Term Link )
  log reading ( Index Term Link )
  overview of ( Index Term Link )
  process flow illustrated ( Index Term Link )
  recorded events ( Index Term Link )
  relation database format ( Index Term Link )
  remote logging ( Index Term Link )
  secure logging ( Index Term Link )
    
M
 
 Membership authentication module type ( Index Term Link )
 
 Metadata Service ( Index Term Link )
 
 MSISDN authentication module type ( Index Term Link )
    
N
 
 name identifier mapping protocol ( Index Term Link )
 
 name registration ( Index Term Link )
 
 Naming Service
  core component descriptions ( Index Term Link )
  in session validation process flow ( Index Term Link )
 
 normal policy ( Index Term Link )
    
O
 
 OASIS ( Index Term Link )
 
 one-time federation ( Index Term Link )
 
 opt-in account linking ( Index Term Link )
    
P
 
 PDP
  See policy decision point
  in SAML ( Index Term Link )
 
 PEP, See policy enforcement point (PEP)
 
 persistent cookie, definition of ( Index Term Link )
 
 Platform Service, core component descriptions ( Index Term Link )
 
 plug-ins
  amSDK ( Index Term Link ) ( Index Term Link )
  Authentication Service ( Index Term Link )
  delegation ( Index Term Link ) ( Index Term Link )
  identity repository management ( Index Term Link )
  plug-ins architecture ( Index Term Link )
  policy response providers ( Index Term Link )
  Policy Service ( Index Term Link )
  service configuration ( Index Term Link ) ( Index Term Link )
 
 policy
  condition ( Index Term Link )
  definition of ( Index Term Link )
  normal policy ( Index Term Link )
  policy rule ( Index Term Link )
  referral policy ( Index Term Link )
  subject ( Index Term Link )
  types of policies ( Index Term Link )
 
 policy administrator ( Index Term Link )
 
 policy agent
  brief description ( Index Term Link )
  definition of ( Index Term Link )
  PEPs and PDPs ( Index Term Link )
 
 policy configuration service ( Index Term Link )
 
 policy decision point (PDP), definition of ( Index Term Link )
 
 policy enforcement point, definition of ( Index Term Link )
 
 policy organization administrator ( Index Term Link )
 
 Policy Service
  access control realm and policies ( Index Term Link )
  authorization, definition of ( Index Term Link )
  core component descriptions ( Index Term Link )
  definition of ( Index Term Link )
  general Policy Service ( Index Term Link )
  normal policy ( Index Term Link )
  policy, definition of ( Index Term Link )
  Policy Configuration Service ( Index Term Link )
  policy evaluation ( Index Term Link )
  policy plug-in ( Index Term Link )
  policy response provider plug-in ( Index Term Link )
  referral policy ( Index Term Link )
  types of policies ( Index Term Link )
  web service, brief description ( Index Term Link )
 
 privileges, and delegation plug-in ( Index Term Link )
    
R
 
 RADIUS authentication module type ( Index Term Link )
 
 realm, See access control realm
 
 realm administrator ( Index Term Link )
 
 redirection URLs ( Index Term Link )
 
 relational database format, logging ( Index Term Link )
 
 remote logging ( Index Term Link )
 
 reverse HTTP bindings ( Index Term Link )
 
 roles, and delegation plug-in ( Index Term Link )
 
 rule, in policy ( Index Term Link )
    
S
 
 SafeWord authentication module type ( Index Term Link )
 
 SAML ( Index Term Link )
  about SAML specifications ( Index Term Link )
  assertion ( Index Term Link )
  definition of ( Index Term Link )
  SAML Service ( Index Term Link )
  web service, brief description ( Index Term Link )
 
 SAML authentication module type, authentication module ( Index Term Link )
 
 SAML Service
  core component descriptions ( Index Term Link )
  overview of ( Index Term Link )
 
 secure logging ( Index Term Link )
 
 SecurID, authentication module ( Index Term Link )
 
 security mechanisms, in identity federation ( Index Term Link )
 
 service configuration plug-ins ( Index Term Link ) ( Index Term Link )
 
 Service Management Service ( Index Term Link )
 
 services ( Index Term Link )
  Access Manager web services ( Index Term Link )
  authentication ( Index Term Link )
  identity federation ( Index Term Link )
  Identity Repository Management Service ( Index Term Link )
  logging ( Index Term Link )
  policy ( Index Term Link )
  services that power Access Manager ( Index Term Link )
 
 session, See user session
 
 session data structure ( Index Term Link )
 
 session ID, See session token
 
 session management, See User Session Management
 
 Session Service, See User Session Management
 
 session token ( Index Term Link )
 
 session upgrade, definition of ( Index Term Link )
 
 single sign-on
  as a type of user session ( Index Term Link )
  definition of ( Index Term Link )
  process flow illustrated ( Index Term Link )
  user session ( Index Term Link )
 
 single sign-on and federation protocol ( Index Term Link )
 
 single sign-out protocol ( Index Term Link )
 
 SOAP Binding ( Index Term Link )
 
 SSO, See single sign-on (SSO)
 
 subject, in policy ( Index Term Link )
 
 subrealm administrator ( Index Term Link )
 
 Sun Java System Directory Server
  as an identity repository ( Index Term Link )
  legacy mode ( Index Term Link )
    
T
 
 trusted authority ( Index Term Link )
    
U
 
 UNIX authentication module type ( Index Term Link )
 
 user authentication, See Authentication Service
 
 user session
  basic user session ( Index Term Link )
  cookies ( Index Term Link )
  definition of ( Index Term Link )
  initial HTTP request ( Index Term Link )
  session data structure ( Index Term Link )
  session token ( Index Term Link )
 
 User Session Management
  basic user session, brief description ( Index Term Link )
  core component descriptions ( Index Term Link )
  cross-domain SSO, brief description ( Index Term Link )
  definition of ( Index Term Link )
  overview of ( Index Term Link )
  session termination ( Index Term Link )
  session validation ( Index Term Link )
  single-sign on, brief description ( Index Term Link )
  user sessions, types of ( Index Term Link ) ( Index Term Link )
  web service, brief description ( Index Term Link )
    
V
 
 validation plug-in, in authentication ( Index Term Link )
    
W
 
 web service consume ( Index Term Link )
 
 web service provider ( Index Term Link )
 
 web services, definition of ( Index Term Link )
 
 Windows Desktop Single Sign-On authentication module type ( Index Term Link )
 
 Windows NT authentication module type ( Index Term Link )
    
X
 
 XML, files used in Access Manager ( Index Term Link )