Documentation Home
> Sun Java System Access Manager 7 2005Q4 Administration Guide
Sun Java System Access Manager 7 2005Q4 Administration Guide
Book Information
Index
A
B
C
D
E
F
G
I
J
L
M
N
O
P
R
S
T
U
V
W
X
Preface
Part I Access Manager Configuration
Chapter 1 Access Manager 7 2005Q4 Configuration Scripts
Access Manager 7 2005Q4 Installation Overview
Access Manager amconfig Script Operations
Access Manager Sample Configuration Script Input File
Deployment Mode Variable
Access Manager Configuration Variables
Web Container Configuration Variables
Sun Java System Web Server 6.1 SP5
Sun Java System Application Server 8.1
BEA WebLogic Server 8.1
IBM WebSphere 5.1
Directory Server Configuration Variables
Access Manager amconfig Script
Access Manager Deployment Scenarios
Deploying Additional Instances of Access Manager
Deploying an Additional Access Manager Instance
To Deploy an Additional Access Manager Instance
To Update the Platform Server List
Configuring and Reconfiguring an Instance of Access Manager
To Configure or Reconfigure an Instance of Access Manager
Uninstalling Access Manager
To Uninstall an Instance of Access Manager
Uninstalling All Access Manager Instances
To Completely Remove Access Manager 7 2005Q4 From a System
Example Configuration Script Input File
Chapter 2 Installing and Configuring Third-Party Web Containers
Installing and Configuring BEA WebLogic 8.1
To Install and Configure WebLogic 8.1
Installing and Configuring IBM WebSphere 5.1
To Install and Configure WebSphere 5.1
Using Java ES to Install Directory Server and Access Manager
To Install Directory Server
Configuring Access Manager
To Configure Access Manager
Creating the Configuration Script Input File
BEA WebLogic and IBM WebSphere
BEA WebLogic only
IBM WebSphere only
Running the Configuration Script
Restarting the Web Container
Chapter 3 Configuring Access Manager in SSL Mode
Configuring Access Manager With a Secure Sun Java Enterprise System Web Server
To Configure a Secure Web Server
Configuring Access Manager with a Secure Sun Java System Application Server
Setting Up Application Server 6.2 With SSL
To Secure the Application Server Instance
Configuring Application Server 8.1 With SSL
Configuring Access Manager in SSL Mode
To Configure Access Manager in SSL Mode
Configuring AMSDK with a Secure BEA WebLogic Server
To Configure a Secure WebLogic Instance
Configuring AMSDK with a Secure IBM WebSphere Application Server
To Configure a Secure WebSphere Instance
Configuring Access Manager to Directory Server in SSL Mode
Configuring Directory Server in SSL Mode
Connecting Access Manager to the SSL-enabled Directory Server
To Connect Access Manager to Directory Server
Part II Access Control
Chapter 4 The Access Manager Console
Administration View
Realms Mode Console
Legacy Mode Console
Legacy Mode 6.3 Console
User Profile View
Chapter 5 Managing Realms
Creating and Managing Realms
To Create a New Realm
General Properties
Authentication
Services
To Add a Service to a Realm
Privileges
Chapter 6 Data Stores
LDAPv3 Data Store
To Create a New LDAPv3 Data Store
LDAPv3 Repository Plug-in Attributes
Primary LDAP Server
LDAP Bind DN
LDAP Bind Password
LDAP Bind Password (confirm)
LDAP Organization DN
Enable LDAP SSL
LDAP Connection Pool Minimum Size
LDAP Connection Pool Maximum Size
Maximum Results Returned from Search
Search Timeout
LDAP Follows Referral
LDAPv3 Repository Plugin Class Name
Attribute Name Mapping
LDAPv3 Plugin Supported Types and Operations
LDAP Users Search Attribute
LDAP Users Search Filter
LDAP User Object Class
LDAP User Attributes
LDAP Groups Search Attribute
LDAP Groups Search Filter
LDAP Groups Container Naming Attribute
LDAP Groups Container Value
LDAP Groups Object Class
LDAP Groups Attributes
Attribute Name for Group Membership
Attribute Name of Group Member
Attribute Name of Group Member URL
LDAP People Container Naming Attribute
LDAP People Container Value
LDAP Agents Search Attribute
LDAP Agents Container Naming Attribute
LDAP Agents Container Value
LDAP Agents Search Filter
LDAP Agents Object Class
LDAP Agents Attributes
Persistent Search Base DN
Persistent Search Maximum Idle Time Before Restart
Maximum Number of Retries After Error Codes
The Delay Time Between Retries
LDAPException Error Codes to Retry On
AMSDK Repository Plug-in
To Create a New AMSDK Repository Plugin
Chapter 7 Managing Authentication
Configuring Authentication
Authentication Module Types
Core
Active Directory
Anonymous
Certificate
HTTP Basic
JDBC
LDAP
Membership
MSISDN
RADIUS
Configuring RADIUS with Sun Java System Application Server
SafeWord
Configuring SafeWord with Sun Java System Application Server
SAML
SecurID
UNIX
Windows Desktop SSO
Known Restriction with Internet Explorer
Configuring Windows Desktop SSO
To Create a User in the Windows 2000 Domain Controller
To Set Up Internet Explorer
Windows NT
Installing the Samba Client
Authentication Module Instances
To Create a New Authentication Module Instance
Authentication Chaining
To Create a New Authentication Chain
Authentication Types
How Authentication Types Determine Access
URL Redirection
Realm-based Authentication
Realm-based Authentication Login URLs
Realm-based Authentication Redirection URLs
Successful realm-based Authentication Redirection URLs
Failed Realm-based Authentication Redirection URLs
To Configure Realm-Based Authentication
To Configure The Realms’s Authentication Attributes
Organization-based Authentication
Organization-based Authentication Login URLs
Organization-based Authentication Redirection URLs
Successful Organization-based Authentication Redirection URLs
Failed Organization-based Authentication Redirection URLs
To Configure Organization-Based Authentication
To Configure The Organizations’s Authentication Attributes
Role-based Authentication
Role-based Authentication Login URLs
Role-based Authentication Redirection URLs
Successful Role-based Authentication Redirection URLs
Failed Role-based Authentication Redirection URLs
To Configure Role-Based Authentication
Service-based Authentication
Service-based Authentication Login URLs
Service-based Authentication Redirection URLs
Successful Service-based Authentication Redirection URLs
Failed Service-based Authentication Redirection URLs
To Configure Service-Based Authentication
User-based Authentication
User-based Authentication Login URLs
User Alias List Attribute
User-based Authentication Redirection URLs
Successful User-based Authentication Redirection URLs
Failed User-based Authentication Redirection URLs
To Configure User-Based Authentication
Authentication Level-based Authentication
Authentication Level-based Authentication Login URLs
Authentication Level-based Authentication Redirection URLs
Successful Authentication Level-based Authentication Redirection URLs
Failed Authentication Level-based Authentication Redirection URLs
Module-based Authentication
Module-based Authentication Login URLs
Module-based Authentication Redirection URLs
Successful Module-based Authentication Redirection URLs
Failed Module-based Authentication Redirection URLs
The User Interface Login URL
Login URL Parameters
goto Parameter
gotoOnFail Parameter
realm Parameter
org Parameter
user Parameter
role Parameter
locale Parameter
module Parameter
service Parameter
arg Parameter
authlevel Parameter
domain Parameter
iPSPCookie Parameter
IDTokenN Parameters
Account Locking
Physical Locking
Memory Locking
Authentication Service Failover
Fully Qualified Domain Name Mapping
Possible Uses For FQDN Mapping
Persistent Cookie
To Enable Persistent Cookies
Multi-LDAP Authentication Module Configuration In Legacy Mode
To Add An Additional LDAP Configuration
Session Upgrade
Validation Plug-in Interface
To Write and Configure a Validation Plug-in
JAAS Shared State
Enabling JAAS Shared State
JAAS Shared State Store Option
Chapter 8 Managing Policies
Overview
Policy Management Feature
URL Policy Agent Service
Policy Agents
The Policy Agent Process
Policy Types
Normal Policy
Rules
Subjects
Access Manager Roles Versus LDAP Roles
Nested Roles
Conditions
Response Providers
Policy Advices
Referral Policy
Rules
Referrals
Policy Definition Type Document
Policy Element
Rule Element
ServiceName Element
ResourceName Element
AttributeValuePair Element
Attribute Element
Value Element
Subjects Element
Subject Element
Referrals Element
Referral Element
Conditions Element
Condition Element
Adding a Policy Enabled Service
To Add a New Policy Enabled Service
Creating Policies
To Create Policies with amadmin
To Create a Normal Policy With the Access Manager Console
To Create a Referral Policy With the Access Manager Console
Creating Policies for Peer Realms and Sub Realms
To Create a Policy for a Sub Realm
Managing Policies
Modifying a Normal Policy
To Add or Modify a Rule to a Normal Policy
To Add or Modify a Subject to a Normal Policy
To Add a Condition to a Normal Policy
To Add a Response Provider to a Normal Policy
Modifying a Referral Policy
To Add or Modify a Rule to a Referral Policy
To Add or Modify Referrals to a Policy
To Add a Response Provider to a Referral Policy
Policy Configuration Service
Subjects Result Time To Live
Dynamic Attributes
amldapuser Definition
Adding Policy Configuration Services
Resource—Based Authentication
Limitations
To Configure Resource—based Authentication
Chapter 9 Managing Subjects
User
To Create or Modify a User
To Add a User to Roles and Groups
To Add Services to an Identity
Agents
To Create or Modify an Agent
Creating a Unique Policy Agent Identity
To Create a Unique Policy Agent Identity
Filtered Role
To Create a Filtered Role
Roles
To Create or Modify a Role
To Add Users to a Role or Group
Groups
To Create or Modify a Group
Part III Directory Management and Default Services
Chapter 10 Directory Management
Managing Directory Objects
Organizations
To Create an Organization
To Delete an Organization
To Add an Organization to a Policy
Containers
To Create a Container
To Delete a Container
Group Containers
To Create a Group Container
To Delete a Group Container
Groups
To Create a Static Group
To Add or Remove Members to a Static Group
To Create a Dynamic Group
To Add or Remove Members to a Dynamic Group
To Add a Group to a Policy
People Containers
Create a People Container
To Delete a People Container
Users
To Create a User
To Edit the User Profile
To Add a User to Roles and Groups
To Add a User to a Policy
Roles
To Create a Static Role
To Add Users to a Static Role
To Create a Dynamic Role
To Remove Users from a Role
To Add a Role to a Policy
Chapter 11 Current Sessions
The Current Sessions Interface
Session Management
Session Information
Terminating a Session
To Terminate a Session
Chapter 12 Password Reset Service
Registering the Password Reset Service
To Register Password Reset for Users in a Different Realm
Configuring the Password Reset Service
To Configure the Service
Password Reset Lockout
Memory Lockout
Physical Lockout
Password Reset for End Users
Customizing Password Reset
To Customize Password Reset
Resetting Forgotten Passwords
To Reset Forgotten Passwords
Password Policies
Chapter 13 Logging Service
Log Files
Access Manager Service Logs
Session Logs
Console Logs
Authentication Logs
Federation Logs
Policy Logs
Agent Logs
SAML Logs
amAdmin Logs
Logging Features
Secure Logging
To Enable Secure Logging
Command Line Logging
Logging Properties
Remote Logging
To Enable Remote Logging
Error and Access Logs
Debug Files
Debug Levels
Debug Output Files
Using Debug Files
Multiple Access Manager Instances And Debug Files
Part IV Command Line Reference
Chapter 14 The amadmin Command Line Tool
The amadmin Command Line Executable
The amadmin Syntax
amadmin Options
--runasdn (-u)
--password (-w)
--locale (-l)
--continue (-c)
--session (-m)
--debug (-d)
--verbose (-v)
--data (-t)
--schema (-s)
--deleteservice (-r)
--serviceName
--help (-h)
--version (-n)
Using amadmin for Federation Management
Loading the Liberty meta compliance XML into Directory Server
--runasdn (-u)
--password (-w)
--passwordfile (-f)
--entityname (-e)
--import (-g)
Exporting an Entity to an XML File (Without XML Digital Signing)
--runasdn (-u)
--password (-w)
--passwordfile (-f)
--entityname (--e)
--export (-o)
Exporting an Entity to an XML File (With XML Digital Signing)
--runasdn (-u)
--password (-w)
--passwordfile (-f)
--entityname (--e)
--exportwithsig (-o)
Using amadmin for Resource Bundles
Add resource bundle.
Get resource strings.
Remove resource bundle.
Chapter 15 The ampassword Command Line Tool
The ampassword Command Line Executable
To Run ampassword with Access Manager in SSL mode
Chapter 16 The bak2am Command Line Tool
The bak2am Command Line Executable
The bak2am Syntax
bak2am Options
--gzip backup-name
--tar backup-name
--verbose
--directory
--help
--version
Chapter 17 The am2bak Command Line Tool
The am2bak Command Line Executable
The am2bak Syntax
am2bak Options
--verbose (-v)
--backup backup-name (-k)
--location (-l)
--config (-c)
--debug (-b)
--log (-g)
--cert (-t)
--ds (-d)
--all (-a)
--help (-h)
--version (-n)
To Run the Backup Procedure
Chapter 18 The amserver Command Line Tool
The amserver Command Line Executable
amserver Syntax
start
stop
Chapter 19 The VerifyArchive Command Line Tool
The VerifyArchive Command Line Executable
VerifyArchive Syntax
VerifyArchive Options
logName
path
uname
password
Chapter 20 The amsecuridd Helper
The amsecuridd Helper Command Line Executable
amsecuridd Syntax
amsecuridd Options
verbose (-v)
configure portnumber (-c portnm)
Running the amsecuridd helper
Required Libraries
Part V Appendixes
Appendix A AMConfig.properties File
About the AMConfig.properties File
Access Manager Console
Access Manager Server Installation
am.util
amSDK
Application Server Installation
Authentication
Certificate Database
Cookies
Debugging
Directory Server Installation
Event Connection
Global Services Management
Helper Daemons
Identity Federation
JSS Proxy
LDAP Connection
Liberty Alliance Interactions
Logging Service
Logging Properties You Can Add to AMConfig.properties
Naming Service
Notification Service
Policy Agents
Policy Client API
Profile Service
Replication
SAML Service
Security
Session Service
SMTP
Statistics Service
Appendix B serverconfig.xml File
Overview
Proxy User
Admin User
server-config Definition Type Document
iPlanetDataAccessLayer Element
ServerGroup Element
Server Element
User Element
DirDN Element
DirPassword Element
BaseDN Element
MiscConfig Element
Failover Or Multimaster Configuration
Appendix C Log File Reference
Appendix D Error Codes
Access Manager Console Errors
Authentication Error Codes
Policy Error Codes
amadmin Error Codes
© 2010, Oracle Corporation and/or its affiliates