Sun OpenSSO Enterprise 8.0 Administration Guide
    
A
 
 access control ( Index Term Link )
 
 account lockout
  memory ( Index Term Link )
  physical ( Index Term Link )
 
 Administration service ( Index Term Link )
 
 administrator interface ( Index Term Link )
 
 advice message ( Index Term Link )
 
 affiliate entity ( Index Term Link )
 
 agent profiles, and realm ( Index Term Link )
 
 agents ( Index Term Link )
 
 amadmin ( Index Term Link )
 
 AMAgent.properties ( Index Term Link )
 
 amldapuser ( Index Term Link )
 
 arg login URL parameter ( Index Term Link )
 
 attribute federation, See auto-federation
 
 Attribute Mapper ( Index Term Link )
 
 attributes
  Authentication Web Service ( Index Term Link )
  Discovery Service ( Index Term Link )
  Liberty Personal Profile Service ( Index Term Link )
  non-default federation ( Index Term Link )
  SOAP Binding Service ( Index Term Link )
 
 audience for this guide ( Index Term Link )
 
 authentication
  account lockout
   memory ( Index Term Link )
   physical ( Index Term Link )
  and realm ( Index Term Link )
  authentication types ( Index Term Link )
  FQDN mapping ( Index Term Link )
  login URLs ( Index Term Link )
   authentication level ( Index Term Link )
   realm ( Index Term Link )
   service ( Index Term Link )
   user ( Index Term Link )
  methods
   resource ( Index Term Link )
  multiple LDAP configurations ( Index Term Link )
  persistent cookies ( Index Term Link )
  realm
   redirection URLs ( Index Term Link )
  realm values ( Index Term Link )
  redirection URLs
   authentication level-based ( Index Term Link )
   service ( Index Term Link )
   user ( Index Term Link )
  session upgrade ( Index Term Link )
  types
   authentication level ( Index Term Link )
   module ( Index Term Link )
   realm ( Index Term Link )
   role ( Index Term Link )
   service ( Index Term Link )
   user ( Index Term Link )
  user interface
   login URL ( Index Term Link )
 
 authentication chains ( Index Term Link )
  create ( Index Term Link )
 
 authentication level authentication login URLs ( Index Term Link )
 
 authentication level authentication type ( Index Term Link )
  configuring ( Index Term Link )
 
 authentication level-based redirection URLs ( Index Term Link )
 
 authentication modules ( Index Term Link )
  configure ( Index Term Link )
  Core ( Index Term Link )
  global values ( Index Term Link )
 
 authentication properties, Core ( Index Term Link )
 
 authentication types ( Index Term Link )
  authentication level ( Index Term Link )
   configuring ( Index Term Link )
  module ( Index Term Link )
   configuring ( Index Term Link )
  realm ( Index Term Link )
   configuring ( Index Term Link )
  role ( Index Term Link )
  role-based
   configuring ( Index Term Link )
  service ( Index Term Link )
   configuring ( Index Term Link )
  user ( Index Term Link )
   configuring ( Index Term Link )
 
 Authentication Web Service, attribute ( Index Term Link )
 
 authlevel login URL parameter ( Index Term Link )
 
 Authorizer ( Index Term Link )
 
 auto-creation ( Index Term Link )
 
 auto-federation ( Index Term Link )
  ID-FF ( Index Term Link )
  SAMLv2 ( Index Term Link )
    
B
 
 backup, configuration data ( Index Term Link )
 
 basic authentication ( Index Term Link )
 
 bootstrapping discovery service ( Index Term Link )
 
 bootstrapping Discovery Service ( Index Term Link )
 
 bulk federation ( Index Term Link )
    
C
 
 change host name ( Index Term Link )
 
 circle of trust ( Index Term Link )
  add providers ( Index Term Link )
  create ( Index Term Link ) ( Index Term Link )
  delete ( Index Term Link )
  modify ( Index Term Link )
 
 conditions ( Index Term Link )
  advice messages ( Index Term Link )
  Authentication by Module Chain ( Index Term Link )
  Authentication by Module Instance ( Index Term Link )
  Authentication Level ( Index Term Link )
  IP Address/DNS Name ( Index Term Link )
 
 Conditions
  LDAP Filter ( Index Term Link )
 
 conditions
  session property ( Index Term Link )
 
 Conditions
  Time ( Index Term Link )
 
 configuration data, backup and restore ( Index Term Link )
 
 console ( Index Term Link )
  administrator interface ( Index Term Link )
  legacy support ( Index Term Link )
  user interface ( Index Term Link )
   login URL ( Index Term Link )
 
 containers ( Index Term Link )
 
 Containers ( Index Term Link )
  Creating ( Index Term Link )
  Deleting ( Index Term Link )
 
 Core authentication module ( Index Term Link )
 
 create entities, with ssoadm ( Index Term Link )
 
 create policy ( Index Term Link )
 
 Current Sessions
  Interface ( Index Term Link )
  Session Management
   Terminating a Session ( Index Term Link )
  Session Management Window ( Index Term Link )
    
D
 
 data stores, and realm ( Index Term Link )
 
 debug files ( Index Term Link )
 
 Directory Management ( Index Term Link )
 
 Discovery Service ( Index Term Link )
  attributes ( Index Term Link )
 
 discovery service, bootstrapping ( Index Term Link )
 
 Discovery Service
  bootstrapping ( Index Term Link )
  resource offerings ( Index Term Link )
 
 documentation
  collections ( Index Term Link )
  OpenSSO Enterprise ( Index Term Link )
  related product ( Index Term Link )
 
 domain login URL parameter ( Index Term Link )
 
 dynamic identity provider proxying ( Index Term Link )
    
E
 
 enable auto-creation ( Index Term Link )
 
 entities
  create ( Index Term Link )
  creating with ssoadm ( Index Term Link )
 
 entity
  affiliate ( Index Term Link )
  provider ( Index Term Link )
    
F
 
 federation
  auto-federation ( Index Term Link )
  bulk federation ( Index Term Link )
  configure global logout ( Index Term Link )
  configure pre-login ( Index Term Link )
  dynamic identity provider proxying ( Index Term Link )
  entities
   creating with ssoadm ( Index Term Link )
  entities and circles of trust ( Index Term Link )
  identity provider metadata sample ( Index Term Link )
  metadata ( Index Term Link )
  non-default attributes ( Index Term Link )
  pre-login URL ( Index Term Link )
  service provider metadata sample ( Index Term Link )
 
 Federation Operations, Finding an Identity Provider for Authentication ( Index Term Link )
 
 forceAuth login URL parameter ( Index Term Link )
 
 FQDN mapping, and authentication ( Index Term Link )
    
G
 
 global logout, configure ( Index Term Link )
 
 Globalization Settings ( Index Term Link )
 
 goto login URL parameter ( Index Term Link )
 
 gotoOnFail login URL parameter ( Index Term Link )
 
 group, subjects ( Index Term Link )
 
 Group Containers ( Index Term Link )
  Creating ( Index Term Link )
  Deleting ( Index Term Link )
 
 Groups ( Index Term Link )
  Adding to a Policy ( Index Term Link )
  Create a Managed Group ( Index Term Link )
  Membership by Filter ( Index Term Link )
  Membership by Subscription ( Index Term Link )
    
H
 
 host name, change ( Index Term Link )
    
I
 
 ID-FF, auto-federation ( Index Term Link )
 
 ID-FF writer service URL ( Index Term Link )
 
 ID—FF Identity Provider Introduction service, configuring ( Index Term Link )
 
 identities ( Index Term Link )
 
 Identity Management ( Index Term Link )
  Containers ( Index Term Link )
   Creating ( Index Term Link )
   Deleting ( Index Term Link )
  Group Containers ( Index Term Link )
   Creating ( Index Term Link )
   Deleting ( Index Term Link )
  Groups ( Index Term Link )
   Adding to a Policy ( Index Term Link )
   Create a Managed Group ( Index Term Link )
   Membership by Filter ( Index Term Link )
   Membership by Subscription ( Index Term Link )
  Organizations ( Index Term Link )
   Adding to a Policy ( Index Term Link )
   Creating ( Index Term Link )
   Deleting ( Index Term Link )
  People Containers ( Index Term Link )
   Creating ( Index Term Link )
   Deleting ( Index Term Link )
  Roles ( Index Term Link )
   Adding to a Policy ( Index Term Link )
   Adding Users to ( Index Term Link )
   Creating ( Index Term Link )
   Removing Users from ( Index Term Link )
  Users ( Index Term Link )
   Adding to a Policy ( Index Term Link )
   Adding to Services, Roles and Groups ( Index Term Link )
   Creating ( Index Term Link )
 
 identity provider, metadata sample ( Index Term Link )
 
 IDP Discovery Server, SAMLv2 ( Index Term Link )
 
 idpMNIPOST.jsp ( Index Term Link )
 
 idpMNIRedirect.jsp ( Index Term Link )
 
 idpMNIRequestInit.jsp ( Index Term Link )
 
 IDTokenN login URL parameter ( Index Term Link )
 
 interfaces
  Authorizer ( Index Term Link )
  ResourceIDMapper ( Index Term Link )
 
 iPSPCookie login URL parameter ( Index Term Link )
    
J
 
 JSP
  idpMNIPOST.jsp ( Index Term Link )
  idpMNIRedirect.jsp ( Index Term Link )
  idpMNIRequestInit.jsp ( Index Term Link )
  spMNIPOST.jsp ( Index Term Link )
  spMNIRedirect.jsp ( Index Term Link )
  spMNIRequestInit.jsp ( Index Term Link )
    
L
 
 LDAP authentication, multiple configurations ( Index Term Link )
 
 LDAPv3–compliant directory ( Index Term Link )
 
 legacy support ( Index Term Link )
 
 Liberty Personal Profile Service, attributes ( Index Term Link )
 
 libIDPDiscoveryConfig.properties ( Index Term Link )
 
 load balancing ( Index Term Link )
 
 locale login URL parameter ( Index Term Link )
 
 login URL parameters ( Index Term Link )
 
 login URLs
  and authentication ( Index Term Link )
  authentication level ( Index Term Link )
  realm authentication ( Index Term Link )
  service ( Index Term Link )
  user ( Index Term Link )
    
M
 
 Managing OpenSSO Enterprise Objects ( Index Term Link )
 
 memory account lockout ( Index Term Link )
 
 metadata
  federation ( Index Term Link )
  identity provider sample ( Index Term Link )
  managing with ssoadm ( Index Term Link )
  service provider sample ( Index Term Link )
 
 methods
  authentication
   resource ( Index Term Link )
 
 module authentication type ( Index Term Link )
  configuring ( Index Term Link )
 
 module login URL parameter ( Index Term Link )
    
N
 
 name identifiers ( Index Term Link )
 
 naming service, and policy ( Index Term Link )
 
 non-default federation attributes ( Index Term Link )
    
O
 
 org login URL parameter ( Index Term Link )
 
 Organizations ( Index Term Link )
  Adding to a Policy ( Index Term Link )
  Creating ( Index Term Link )
  Deleting ( Index Term Link )
 
 overview
  authentication
   login URL ( Index Term Link )
  auto-creation ( Index Term Link )
  auto-federation ( Index Term Link )
  bulk federation ( Index Term Link )
  dynamic identity provider proxying ( Index Term Link )
  policy agents ( Index Term Link )
  policy process ( Index Term Link )
  pre-login URL ( Index Term Link )
    
P
 
 parameters, pre-login URL ( Index Term Link )
 
 password, change ( Index Term Link )
 
 Password Reset ( Index Term Link )
 
 People Containers ( Index Term Link )
  Creating ( Index Term Link )
  Deleting ( Index Term Link )
 
 PersistAMCookie login URL parameter ( Index Term Link )
 
 persistent cookies, and authentication ( Index Term Link )
 
 persistent name identifier ( Index Term Link )
 
 physical account lockout ( Index Term Link )
 
 policies
  conditions ( Index Term Link )
   advice messages ( Index Term Link )
 
 policy ( Index Term Link )
  and naming service ( Index Term Link )
  and realm ( Index Term Link )
  create ( Index Term Link )
   console ( Index Term Link )
   referral ( Index Term Link )
   ssoadm ( Index Term Link )
  creating ( Index Term Link )
  modify ( Index Term Link )
  policy types ( Index Term Link )
  referral ( Index Term Link )
   modify ( Index Term Link ) ( Index Term Link )
   referrals ( Index Term Link )
   rules ( Index Term Link )
  resource authentication ( Index Term Link )
  rules ( Index Term Link )
  subjects ( Index Term Link )
 
 policy agents
  overview ( Index Term Link )
  process ( Index Term Link )
 
 Policy Configuration service ( Index Term Link )
 
 policy types ( Index Term Link )
 
 pre-login, configure ( Index Term Link )
 
 pre-login URL ( Index Term Link )
  configure ( Index Term Link )
  parameters ( Index Term Link )
 
 prerequisites for this guide ( Index Term Link )
 
 privileges
  and realm ( Index Term Link )
  upgrade ( Index Term Link )
 
 procedures
  store resource offerings ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
 
 provider entity ( Index Term Link )
    
Q
 
 query parameter ( Index Term Link )
    
R
 
 reader service URL ( Index Term Link )
 
 realm authentication login URLs ( Index Term Link )
 
 realm authentication redirection URLs ( Index Term Link )
 
 realm authentication type ( Index Term Link )
  configuring ( Index Term Link )
 
 realm login URL parameter ( Index Term Link )
 
 realms ( Index Term Link )
  adding service ( Index Term Link )
  agent profiles ( Index Term Link )
  authentication ( Index Term Link )
  creating ( Index Term Link )
  data stores ( Index Term Link )
  general properties ( Index Term Link )
  modifying ( Index Term Link )
  modifying service ( Index Term Link )
  policy ( Index Term Link )
  privileges ( Index Term Link )
   upgrade ( Index Term Link )
  services ( Index Term Link )
  subject ( Index Term Link )
  subjects ( Index Term Link )
   group ( Index Term Link )
   user ( Index Term Link )
 
 redirection URLs
  authentication level-based ( Index Term Link )
  realm ( Index Term Link )
  service ( Index Term Link )
  user ( Index Term Link )
 
 referral, create ( Index Term Link )
 
 referral policy ( Index Term Link )
 
 referrals, create ( Index Term Link )
 
 related guides ( Index Term Link )
 
 request handler ( Index Term Link )
 
 resource authentication ( Index Term Link )
 
 resource offering, for bootstrapping ( Index Term Link )
 
 resource offerings
  as dynamic attributes ( Index Term Link )
  as user attributes ( Index Term Link )
  storing ( Index Term Link )
 
 resource offerings for bootstrapping ( Index Term Link )
 
 ResourceID Mapper ( Index Term Link )
 
 restore, configuration data ( Index Term Link )
 
 role authentication type ( Index Term Link )
 
 role-based authentication type, configuring ( Index Term Link )
 
 role login URL parameter ( Index Term Link )
 
 Roles ( Index Term Link )
  Adding to a Policy ( Index Term Link )
  Adding Users to ( Index Term Link )
  Creating ( Index Term Link )
  Removing Users from ( Index Term Link )
 
 rules ( Index Term Link )
    
S
 
 SAML ( Index Term Link )
  Attributes ( Index Term Link )
  site identifiers
   configure ( Index Term Link )
  target URL ( Index Term Link )
  trusted partner
   configure step 1 ( Index Term Link )
   configure step 2 ( Index Term Link )
 
 SAML v2 Plug-in for Federation Services, and AMAgent.properties ( Index Term Link )
 
 SAMLv2
  auto-federation ( Index Term Link )
  IDP Discovery Service ( Index Term Link )
 
 SAMLv2 IDP Discovery service
  configuring
   URLs ( Index Term Link )
 
 SAMLv2 reader service URL ( Index Term Link )
 
 SAMLv2 writer service URL ( Index Term Link )
 
 Secure Socket Layer/Transport Layer Security, See SSL/TLS
 
 security
  SOAP binding ( Index Term Link )
  XML encryption ( Index Term Link )
  XML signing ( Index Term Link )
 
 service authentication login URLs ( Index Term Link )
 
 service authentication redirection URLs ( Index Term Link )
 
 service authentication type ( Index Term Link )
  configuring ( Index Term Link )
 
 service login URL parameter ( Index Term Link )
 
 service provider, metadata sample ( Index Term Link )
 
 services
  adding to realm ( Index Term Link )
  and realm ( Index Term Link )
  Discovery Service ( Index Term Link )
  Globalization Settings ( Index Term Link )
  modifying properties ( Index Term Link )
  Password Reset ( Index Term Link )
  Policy Configuration ( Index Term Link )
  Session ( Index Term Link )
  User ( Index Term Link )
 
 Session service ( Index Term Link )
 
 session upgrade, and authentication ( Index Term Link )
 
 single sign-on, See SSO
 
 single sign-on with transient name identifier ( Index Term Link )
 
 site identifiers ( Index Term Link )
 
 SOAP binding ( Index Term Link )
  basic authentication ( Index Term Link )
  SSL/TLS ( Index Term Link )
  SSL/TLS client authentication ( Index Term Link )
  SSL/TLS server authentication ( Index Term Link )
 
 SOAP Binding Service
  attributes ( Index Term Link )
  request handler ( Index Term Link )
 
 special users
  amadmin ( Index Term Link )
  amldapuser ( Index Term Link )
  UrlAccessAgent ( Index Term Link )
 
 spMNIPOST.jsp ( Index Term Link )
 
 spMNIRedirect.jsp ( Index Term Link )
 
 spMNIRequestInit.jsp ( Index Term Link )
 
 SSL/TLS ( Index Term Link )
  client authentication ( Index Term Link )
  server authentication ( Index Term Link )
 
 SSO, use cases ( Index Term Link )
 
 SSO without service provider user account ( Index Term Link )
 
 ssoadm, See do-bulk-fed-data
 
 ssoadm
  and metadata ( Index Term Link )
  create entities ( Index Term Link )
 
 subject, and realm ( Index Term Link )
 
 subjects ( Index Term Link ) ( Index Term Link )
  group ( Index Term Link )
  user ( Index Term Link )
    
T
 
 target URLs ( Index Term Link )
 
 Terminating a Session ( Index Term Link )
 
 transient name identifier ( Index Term Link )
 
 trusted partners ( Index Term Link )
    
U
 
 UrlAccessAgent ( Index Term Link )
 
 use cases
  access control ( Index Term Link )
  agents ( Index Term Link )
  basic authentication ( Index Term Link )
  enable auto-creation ( Index Term Link )
  load balancing ( Index Term Link )
  single sign-on with transient name identifier ( Index Term Link )
  single sign-on without service provider user account ( Index Term Link )
  SSL/TLS ( Index Term Link )
  using non-default federation attributes ( Index Term Link )
 
 user, subjects ( Index Term Link )
 
 user authentication login URLs ( Index Term Link )
 
 user authentication redirection URLs ( Index Term Link )
 
 user authentication type ( Index Term Link )
  configuring ( Index Term Link )
 
 user interface ( Index Term Link )
 
 user interface login URL ( Index Term Link )
 
 user login URL parameter ( Index Term Link )
 
 User service ( Index Term Link )
 
 Users ( Index Term Link )
  Adding to a Policy ( Index Term Link )
  Adding to Services, Roles, and Groups ( Index Term Link )
  Creating ( Index Term Link )
    
X
 
 XML encryption ( Index Term Link )
 
 XML signing ( Index Term Link )