OpenSSOAgentConfiguration.template revision 20d6346411620e69843780ad0526325cd7ad94ee
7cb226ec344f3996906c015ef58749c5565b2a05Evan Hunt#
7cb226ec344f3996906c015ef58749c5565b2a05Evan Hunt# DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS HEADER.
7cb226ec344f3996906c015ef58749c5565b2a05Evan Hunt#
7cb226ec344f3996906c015ef58749c5565b2a05Evan Hunt# Copyright (c) 2008 Sun Microsystems Inc. All Rights Reserved
7cb226ec344f3996906c015ef58749c5565b2a05Evan Hunt#
7cb226ec344f3996906c015ef58749c5565b2a05Evan Hunt# The contents of this file are subject to the terms
5095e72ac3c0f1e16c246b56e8277614571bf132Mark Andrews# of the Common Development and Distribution License
5095e72ac3c0f1e16c246b56e8277614571bf132Mark Andrews# (the License). You may not use this file except in
5095e72ac3c0f1e16c246b56e8277614571bf132Mark Andrews# compliance with the License.
653cad790b4dc6c1330f634150a8941b75ed761eMark Andrews#
653cad790b4dc6c1330f634150a8941b75ed761eMark Andrews# You can obtain a copy of the License at
cb240b0676186ba4668946c98730879f14a195faFrancis Dupont# https://opensso.dev.java.net/public/CDDLv1.0.html or
cb240b0676186ba4668946c98730879f14a195faFrancis Dupont# opensso/legal/CDDLv1.0.txt
cb240b0676186ba4668946c98730879f14a195faFrancis Dupont# See the License for the specific language governing
e41de66a124e6e564428360c2f76e5f1ae6c6f06Francis Dupont# permission and limitations under the License.
e41de66a124e6e564428360c2f76e5f1ae6c6f06Francis Dupont#
e41de66a124e6e564428360c2f76e5f1ae6c6f06Francis Dupont# When distributing Covered Code, include this CDDL
cbf59e5887d69fca6fe86a1ee5fcc82dded14babMark Andrews# Header Notice in each file and include the License file
cbf59e5887d69fca6fe86a1ee5fcc82dded14babMark Andrews# at opensso/legal/CDDLv1.0.txt.
cbf59e5887d69fca6fe86a1ee5fcc82dded14babMark Andrews# If applicable, add the following below the CDDL Header,
9e102ef9697f0b0d0607fe24bc3ac00286936dd4Francis Dupont# with the fields enclosed by brackets [] replaced by
9e102ef9697f0b0d0607fe24bc3ac00286936dd4Francis Dupont# your own identifying information:
9e102ef9697f0b0d0607fe24bc3ac00286936dd4Francis Dupont# "Portions Copyrighted [year] [name of copyright owner]"
ed53ec0b06825bcc6ba54e10e0174e2de93e595dMark Andrews#
ed53ec0b06825bcc6ba54e10e0174e2de93e595dMark Andrews# $Id: OpenSSOAgentConfiguration.template,v 1.2 2009/10/15 23:36:49 leiming Exp $
ed53ec0b06825bcc6ba54e10e0174e2de93e595dMark Andrews#
61bcc232038f0a2cb77ed6269675fdc288f5ec98Evan Hunt# Portions Copyrighted 2013-2014 ForgeRock AS.
61bcc232038f0a2cb77ed6269675fdc288f5ec98Evan Hunt
61bcc232038f0a2cb77ed6269675fdc288f5ec98Evan Hunt#------------------------------------------------------------------------------
61bcc232038f0a2cb77ed6269675fdc288f5ec98Evan Hunt# Configuration Property File
61bcc232038f0a2cb77ed6269675fdc288f5ec98Evan Hunt#
0e095727ffcae21cbf8b97942d8779094b22983bMark Andrews# OpenAM Policy Agent for:
0e095727ffcae21cbf8b97942d8779094b22983bMark Andrews# IBM Websphere 6.1
0e095727ffcae21cbf8b97942d8779094b22983bMark Andrews#
0e095727ffcae21cbf8b97942d8779094b22983bMark Andrews# Version: ${project.version}
26b49e84597ab3ebaa9ae1eb0fe01befa46a8107Mark Andrews#------------------------------------------------------------------------------
26b49e84597ab3ebaa9ae1eb0fe01befa46a8107Mark Andrews#
26b49e84597ab3ebaa9ae1eb0fe01befa46a8107Mark Andrews# THIS FILE PROVIDES THE CONFIGURATION SETTINGS NECESSARY FOR THE AGENT
26b49e84597ab3ebaa9ae1eb0fe01befa46a8107Mark Andrews# TO FUNCTION CORRECTLY. PLEASE REFER TO THE DOCUMENTATION BEFORE
2415f36f79e168a46c59cdedf0d6d3146efa5196Mark Andrews# MODIFYING ANY OF THE VALUES IN THIS FILE.
2415f36f79e168a46c59cdedf0d6d3146efa5196Mark Andrews#
2415f36f79e168a46c59cdedf0d6d3146efa5196Mark Andrews# Note:
cf4ceeee5fee2ebdca74f82514c14fd50939f85bMark Andrews# Data present in this file provides the necessary configuration
cf4ceeee5fee2ebdca74f82514c14fd50939f85bMark Andrews# settings needed by Agent to work correctly. Invalid configuration
cf4ceeee5fee2ebdca74f82514c14fd50939f85bMark Andrews# data present in this file can lead to malfunction of the Agent, the
4f587beb8eb70f198346333bce5b89df3ac5c88eMark Andrews# application, and the Application Server.
4f587beb8eb70f198346333bce5b89df3ac5c88eMark Andrews#
4f587beb8eb70f198346333bce5b89df3ac5c88eMark Andrews# WARNING: The contents of this file are classified as an UNSTABLE
649452635065426fcc08b99b351db904939a6580Mark Andrews# interface by Sun Microsystems, Inc. As such, they are subject to
649452635065426fcc08b99b351db904939a6580Mark Andrews# significant, incompatible changes in any future release of the
649452635065426fcc08b99b351db904939a6580Mark Andrews# software.
0874abad14e3e9ecfc3dc1a1a2b9969f2f027724Mark Andrews#
0874abad14e3e9ecfc3dc1a1a2b9969f2f027724Mark Andrews# INVALID CONFIGURATION SETTINGS MAY RESULT IN MALFUNCTION OF THE ENTIRE
0874abad14e3e9ecfc3dc1a1a2b9969f2f027724Mark Andrews# SYSTEM.
19f4b069dcade77da4ce9b6de2fa6d22062bef4fMark Andrews#------------------------------------------------------------------------------
19f4b069dcade77da4ce9b6de2fa6d22062bef4fMark Andrews
19f4b069dcade77da4ce9b6de2fa6d22062bef4fMark Andrews#------------------------------------------------------------------------------
2d96b63d311a5252c8583eb30a56b1fc58172419Mark Andrews# General Notes about the Agent Configuration
2d96b63d311a5252c8583eb30a56b1fc58172419Mark Andrews# -------------------------------------------
2d96b63d311a5252c8583eb30a56b1fc58172419Mark Andrews#
422009fe5b15e31e7f5d09212bd1480121a1464eEvan Hunt# HOT-SWAP MECHANISM:
422009fe5b15e31e7f5d09212bd1480121a1464eEvan Hunt# Certain property keys in this configuration are hot-swap enabled.
422009fe5b15e31e7f5d09212bd1480121a1464eEvan Hunt# The value for these keys when altered are dynamically loaded by the
422009fe5b15e31e7f5d09212bd1480121a1464eEvan Hunt# Agent such that it is not necessary to restart the Application
422009fe5b15e31e7f5d09212bd1480121a1464eEvan Hunt# Server in order for these changes to take effect. However, in cases
215ef83bbed20727813a52ddcdbcd1455856638bMark Andrews# where the key is explicitly identified as not enabled for hot-swap
215ef83bbed20727813a52ddcdbcd1455856638bMark Andrews# or in cases when the hot-swap mechanism is disabled on the system,
215ef83bbed20727813a52ddcdbcd1455856638bMark Andrews# the Application Server must be restarted for the changes to take
fea04b0ffeaa83716937f1728ff6742722cec91aMark Andrews# effect. Please refer to the Agent documentation to further learn
fea04b0ffeaa83716937f1728ff6742722cec91aMark Andrews# about hot-swap configuration of the Agent.
fea04b0ffeaa83716937f1728ff6742722cec91aMark Andrews#
f02b5d87a561ba669bd368a8a6422f364f7702ecEvan Hunt# LIST CONSTRUCTS:
f02b5d87a561ba669bd368a8a6422f364f7702ecEvan Hunt# Certain property keys in this configuration are specified as lists.
9a859983d7059a6eb9c877c1d2ac6a3a5b7170f7Evan Hunt# A list construct is defined as follows:
9a859983d7059a6eb9c877c1d2ac6a3a5b7170f7Evan Hunt#
9a859983d7059a6eb9c877c1d2ac6a3a5b7170f7Evan Hunt# Format:
9a859983d7059a6eb9c877c1d2ac6a3a5b7170f7Evan Hunt# <key>[<index>]=<value>
9a859983d7059a6eb9c877c1d2ac6a3a5b7170f7Evan Hunt#
9a859983d7059a6eb9c877c1d2ac6a3a5b7170f7Evan Hunt# Where:
9a859983d7059a6eb9c877c1d2ac6a3a5b7170f7Evan Hunt# key : is the configuration key
9a859983d7059a6eb9c877c1d2ac6a3a5b7170f7Evan Hunt# index : is a positive number starting from 0 that increments by 1
9a859983d7059a6eb9c877c1d2ac6a3a5b7170f7Evan Hunt# for every value specified in this list.
9a859983d7059a6eb9c877c1d2ac6a3a5b7170f7Evan Hunt# value : is one of the values specified in this list.
9a859983d7059a6eb9c877c1d2ac6a3a5b7170f7Evan Hunt#
9a859983d7059a6eb9c877c1d2ac6a3a5b7170f7Evan Hunt# Notes:
eff7f78bc65f30efd87a398e66084ddab72799d3Mark Andrews# - Please refer the Agent documentation for full details on usage.
eff7f78bc65f30efd87a398e66084ddab72799d3Mark Andrews#
eff7f78bc65f30efd87a398e66084ddab72799d3Mark Andrews# Example:
61271cdee65f3313e98f382b07e6674861d9020aEvan Hunt# com.sun.identity.agents.config.example[0] = value0
61271cdee65f3313e98f382b07e6674861d9020aEvan Hunt# com.sun.identity.agents.config.example[1] = value1
61271cdee65f3313e98f382b07e6674861d9020aEvan Hunt# com.sun.identity.agents.config.example[2] = value2
61271cdee65f3313e98f382b07e6674861d9020aEvan Hunt#
c2f051aaaab60dbac4bc754f09d594846d99fb89Evan Hunt# MAP CONSTRUCTS:
c2f051aaaab60dbac4bc754f09d594846d99fb89Evan Hunt# Certain property keys in this configuration are specified as Maps.
32babe43eb479d2ae8736f9985a84d1b9d95a33aScott Mann# A Map construct is defined as follows:
32babe43eb479d2ae8736f9985a84d1b9d95a33aScott Mann#
d57f1ade2da01c70d1043b1f912dbef5ee6817edMark Andrews# Format:
35efe74edbdae034447a5bf73c78d8243e50b0b8Mark Andrews# <key>[<name>]=<value>
f385bac3b918aac3e33d2a8219e1b78f1c7f276eEvan Hunt#
f385bac3b918aac3e33d2a8219e1b78f1c7f276eEvan Hunt# Where:
f385bac3b918aac3e33d2a8219e1b78f1c7f276eEvan Hunt# key : is the configuration key
11c282d8a4c87618538cfc89c9004666dc841036Francis Dupont# name : is a string that forms the lookup key as available in the
11c282d8a4c87618538cfc89c9004666dc841036Francis Dupont# Map
020a733707d308258768c9d677b5839edb647ec8Evan Hunt# value : is the value associated with the name in the Map
020a733707d308258768c9d677b5839edb647ec8Evan Hunt#
d54394cbefb7b0ed7bdf9aafaec4ece06578c26bFrancis Dupont# Notes:
d54394cbefb7b0ed7bdf9aafaec4ece06578c26bFrancis Dupont# - Please refer the Agent documentation for full details on usage.
d54394cbefb7b0ed7bdf9aafaec4ece06578c26bFrancis Dupont#
70c7f4fb4fc589b04a68d67479d34eecd99c1991Evan Hunt# Example:
70c7f4fb4fc589b04a68d67479d34eecd99c1991Evan Hunt# com.sun.identity.agents.config.example[AL] = ALABAMA
70c7f4fb4fc589b04a68d67479d34eecd99c1991Evan Hunt# com.sun.identity.agents.config.example[AK] = ALASKA
70c7f4fb4fc589b04a68d67479d34eecd99c1991Evan Hunt# com.sun.identity.agents.config.example[AZ] = ARIZONA
624664e50406f63108ddc7bad47dbac87ac74261Francis Dupont#
624664e50406f63108ddc7bad47dbac87ac74261Francis Dupont# APPLICATION SPECIFIC/GLOBAL CONFIGURATION:
35efe74edbdae034447a5bf73c78d8243e50b0b8Mark Andrews# Certain property keys in this configuration can be specified per
c1ced49662181d2fb2343ed7bde71d170f0d1119Mark Andrews# protected application. This implies that the Agent will use
c1ced49662181d2fb2343ed7bde71d170f0d1119Mark Andrews# different values of the same configuration key for different
ba88bcf08b965f65c07735efa2f675b8cbeb735aMark Andrews# applications as defined in this configuration file. Properties
ba88bcf08b965f65c07735efa2f675b8cbeb735aMark Andrews# which are not specified per protected applications are called Global
ba88bcf08b965f65c07735efa2f675b8cbeb735aMark Andrews# properties. Application specific properties are defined as follows:
ba88bcf08b965f65c07735efa2f675b8cbeb735aMark Andrews#
21d349b612e253bea438f3340b2f293b032ed848Mark Andrews# Format:
88c63fe9c78e60e5e521d095d6e983c211902904Mark Andrews# <key>[<appname>]=<value>
88c63fe9c78e60e5e521d095d6e983c211902904Mark Andrews#
88c63fe9c78e60e5e521d095d6e983c211902904Mark Andrews# Where:
4c05f9a6a3d0fe27d5fad1599b10500e21c705feMark Andrews# key : is the configuration key
d31740ce282bcf0a27e17dec49a3ff9ddd26e814Scott Mann# appname : is the Application name to which this configuration
d31740ce282bcf0a27e17dec49a3ff9ddd26e814Scott Mann# belongs. The application name is the context path of
d31740ce282bcf0a27e17dec49a3ff9ddd26e814Scott Mann# the application without the leading forward slash
d31740ce282bcf0a27e17dec49a3ff9ddd26e814Scott Mann# character. In case when the application has been
664917bedafa65dee4349c84324a31731aa1e228Francis Dupont# deployed at the root-context of the server, the
664917bedafa65dee4349c84324a31731aa1e228Francis Dupont# application name should be specified as
664917bedafa65dee4349c84324a31731aa1e228Francis Dupont# 'DefaultWebApp'.
be789bc7eb6f683979cd1405a06284ee00cda366Mark Andrews# value : the value that will be used by the Agent when
17bc56e321574b43c5837d1741e9157c8f2fcd91Francis Dupont# protecting the application identified by the given
d3e3d7846dd5895960dcdcb1012b4be23388f81cMark Andrews# application name.
d3e3d7846dd5895960dcdcb1012b4be23388f81cMark Andrews#
d3e3d7846dd5895960dcdcb1012b4be23388f81cMark Andrews# Notes:
ef421f66f47224a42073deaf087378c5d0c9952eEvan Hunt# - When an application specific configuration is not present, the
ef421f66f47224a42073deaf087378c5d0c9952eEvan Hunt# Agent uses different mechanisms to identify a default value. There
ef421f66f47224a42073deaf087378c5d0c9952eEvan Hunt# could be configurations where the default value is used as the
ef421f66f47224a42073deaf087378c5d0c9952eEvan Hunt# value specified for the same key without any application specific
ef421f66f47224a42073deaf087378c5d0c9952eEvan Hunt# suffix '[<appname>]'. For example, if the following configuration
ef421f66f47224a42073deaf087378c5d0c9952eEvan Hunt# keys are present:
7cc5632595476c20f1c0683eff35baa370dd65bbEvan Hunt#
7cc5632595476c20f1c0683eff35baa370dd65bbEvan Hunt# com.sun.identity.agents.config.example[Portal] = value1
7cc5632595476c20f1c0683eff35baa370dd65bbEvan Hunt# com.sun.identity.agents.config.example[DefaultWebApp] = value2
7cc5632595476c20f1c0683eff35baa370dd65bbEvan Hunt# com.sun.identity.agents.config.example = value3
2f09e7c3fc25c0e5028593a24531d636845c3e42Mark Andrews#
2f09e7c3fc25c0e5028593a24531d636845c3e42Mark Andrews# then, for applications other than the ones deployed on the root
2f09e7c3fc25c0e5028593a24531d636845c3e42Mark Andrews# context and the context '/Portal', the value of this key will
4f07b2b00cf52582b2ee9b55aabe7eb5066e57e7Mark Andrews# default to 'value3'.
4f07b2b00cf52582b2ee9b55aabe7eb5066e57e7Mark Andrews#
4f07b2b00cf52582b2ee9b55aabe7eb5066e57e7Mark Andrews# - Application Specific configuration properties must follow the
4f07b2b00cf52582b2ee9b55aabe7eb5066e57e7Mark Andrews# rules and syntax of the MAP construct of configuration entries as
ddd40390be246189f10dc18782914b295befb139Mark Andrews# defined above.
0e507dbb816575e6220fe309e8ada68897ffcdbeMark Andrews#
ddd40390be246189f10dc18782914b295befb139Mark Andrews# Example:
fd5d7b4b1cf3b11ff248a361e5b2c56ca7372225Mark Andrews# com.sun.identity.agents.config.example[Portal] = value1
ddd40390be246189f10dc18782914b295befb139Mark Andrews# com.sun.identity.agents.config.example[BankApp] = value2
5715e1c6f6b549e95b312f1529efd849f7c9503fMark Andrews# com.sun.identity.agents.config.example[DefaultWebApp] = value3
5715e1c6f6b549e95b312f1529efd849f7c9503fMark Andrews#------------------------------------------------------------------------------
ddd40390be246189f10dc18782914b295befb139Mark Andrews
b795de862ba8e75f3b9c56abb9553c28255c8567Mark Andrews#
b795de862ba8e75f3b9c56abb9553c28255c8567Mark Andrews# FILTER OPERATION MODE
c12904ec531fb210066bafc33bde74d43889caacMark Andrews# Specifies the mode of operation of the Filter. Valid value is one of:
c12904ec531fb210066bafc33bde74d43889caacMark Andrews# NONE, SSO_ONLY, URL_POLICY, J2EE_POLICY, ALL. This property can also be
0a92db42c6be6a158cd41ff863831a8d2d257935Mark Andrews# specified as an application specific property. However, the global
0a92db42c6be6a158cd41ff863831a8d2d257935Mark Andrews# property must always be present.
17c98e7adddf82b73f478e89213fd10148a53100Mark Andrews# WARNING:
17c98e7adddf82b73f478e89213fd10148a53100Mark Andrews# WHEN THIS PROPERTY IS SET TO 'NONE', THE AGENT WILL GRANT ACCESS TO
17c98e7adddf82b73f478e89213fd10148a53100Mark Andrews# ALL PROTECTED RESOURCES. THIS MODE OF OPERATION SHOULD NOT BE USED
699e00089fb1a6eb31d7bd1c96bf973608953159Mark Andrews# IN DEPLOYED PRODUCTION SYSTEMS AT ANY TIME AS IT CAN RESULT IN
699e00089fb1a6eb31d7bd1c96bf973608953159Mark Andrews# UNAUTHORIZED ACCESS TO PROTECTED SYSTEM RESOURCES. THIS MODE OF
6883a918f790147fd98e21b2c3d3d479320f3ed5Mark Andrews# OPERATION IS PROVIDED ONLY TO FACILITATE TROUBLESHOOTING OF THE
6883a918f790147fd98e21b2c3d3d479320f3ed5Mark Andrews# APPLICATION IN A WELL CONTROLLED DEVELOPMENT AND TEST ENVIRONMENT
6883a918f790147fd98e21b2c3d3d479320f3ed5Mark Andrews# AND SHOULD NOT BE USED IN ANY OTHER ENVIRONMENT.
e01f55daa4b611190a11a40299007e5e55018854Mark Andrews# Hot-Swap Enabled: No
e01f55daa4b611190a11a40299007e5e55018854Mark Andrews# Example:
e01f55daa4b611190a11a40299007e5e55018854Mark Andrews# com.sun.identity.agents.config.filter.mode = ALL
4c577cbd1efc14156751e5b2ced7a866871a2f1aMark Andrews# com.sun.identity.agents.config.filter.mode[BankApp] = URL_POLICY
4c577cbd1efc14156751e5b2ced7a866871a2f1aMark Andrews#
4c577cbd1efc14156751e5b2ced7a866871a2f1aMark Andrewscom.sun.identity.agents.config.filter.mode = ALL
2ba2a6e4be2eae3a1db1a657ceee15aa62799c7fMark Andrews
2ba2a6e4be2eae3a1db1a657ceee15aa62799c7fMark Andrews#
2ba2a6e4be2eae3a1db1a657ceee15aa62799c7fMark Andrews# USER MAPPING PROPERTIES
30aaec21221ca5d8715d1ff1ce92fbdf98bb6652Mark Andrews# - user.mapping.mode: Specifies the mechanism by which the user-ID
30aaec21221ca5d8715d1ff1ce92fbdf98bb6652Mark Andrews# to be used on the protected server for the authenticated user is
30aaec21221ca5d8715d1ff1ce92fbdf98bb6652Mark Andrews# determined by the Agent. Value of this is one of: USER_ID,
30aaec21221ca5d8715d1ff1ce92fbdf98bb6652Mark Andrews# PROFILE_ATTRIBUTE, HTTP_HEADER, SESSION_PROPERTY.
17a0bbda335ffc9af34be1000f500c622008458cMark Andrews# - user.attribute.name: Specifies the name of the profile attribute,
17a0bbda335ffc9af34be1000f500c622008458cMark Andrews# or HTTP header, or Session property which contains the user-ID to
17a0bbda335ffc9af34be1000f500c622008458cMark Andrews# be used on the protected server for the authenticated user. This
17a0bbda335ffc9af34be1000f500c622008458cMark Andrews# property is not used if the value of user.mapping.mode is set to
b32e391602b3655c90c2ded10376dbfa4ec8a074Evan Hunt# USER_ID.
b32e391602b3655c90c2ded10376dbfa4ec8a074Evan Hunt# - user.principal: A flag that indicates that the principal of the
b32e391602b3655c90c2ded10376dbfa4ec8a074Evan Hunt# authenticated user be used instead of just the user-ID for
b32e391602b3655c90c2ded10376dbfa4ec8a074Evan Hunt# authenticating the user on the protected server. This property is
e3fbbde8fc2e7d6e50583926d34e25a7b638e5adMichael Graff# applicable if the user.mapping.mode is set to USER_ID.
52d44117c825de42dd8bba00885cfb004770c79eMichael Graff# - user.token: Specifies a session property name which contains the
1d5981dd3f7ae31703b7b4e3aa776bc8302ff78dEvan Hunt# user-ID of the authenticated user in session. This property is used
1d5981dd3f7ae31703b7b4e3aa776bc8302ff78dEvan Hunt# when the user.mapping.mode is set to USER_ID and the user.principal
1d5981dd3f7ae31703b7b4e3aa776bc8302ff78dEvan Hunt# flag is set to false.
1d5981dd3f7ae31703b7b4e3aa776bc8302ff78dEvan Hunt# Hot-Swap Enabled: Yes
aae88005f26209d969328703a09170e8af3faff3Mark Andrews# Examples:
57b403c1e9cd8f814c7dbf1808f6cd8d2efb7aeaScott Mann# com.sun.identity.agents.config.user.mapping.mode = PROFILE_ATTRIBUTE
57b403c1e9cd8f814c7dbf1808f6cd8d2efb7aeaScott Mann# com.sun.identity.agents.config.user.attribute.name = employeenumber
29bd52e4ee3fa047474d5d5b405d1e09c800a6f4Evan Hunt#
29bd52e4ee3fa047474d5d5b405d1e09c800a6f4Evan Huntcom.sun.identity.agents.config.user.mapping.mode = USER_ID
b1b42b03b774d77ddfd38e5e0a5c0a3ed1944b89Mark Andrewscom.sun.identity.agents.config.user.attribute.name = employeenumber
b1b42b03b774d77ddfd38e5e0a5c0a3ed1944b89Mark Andrewscom.sun.identity.agents.config.user.principal = false
b1b42b03b774d77ddfd38e5e0a5c0a3ed1944b89Mark Andrewscom.sun.identity.agents.config.user.token = UserToken
2870e5fb54c4a7e3980307b191c7e6ae649119bcEvan Hunt
c5fa3706950224af3f5ae6d22944b1b8298d4eddMark Andrews#
c5fa3706950224af3f5ae6d22944b1b8298d4eddMark Andrews# CLIENT IDENTIFICATION PROPERTIES
4d205bf79b4abacfef41c9f01ee63938deba2f31Mark Andrews# - client.ip.header: Specifies a HTTP header name that holds the IP
74b7355f1ee4a914aa09a6c6493aae64c588b026Mark Andrews# address of the client. May be left blank if not used.
4d205bf79b4abacfef41c9f01ee63938deba2f31Mark Andrews# - client.hostname.header: Specifies a HTTP header name that holds the
5cfe4bcb0afd71f6bc1cc2dab37a9ad6181c13f9Mark Andrews# Hostname of the client. May be left blank if not used.
5cfe4bcb0afd71f6bc1cc2dab37a9ad6181c13f9Mark Andrews# Hot-Swap Enabled: Yes
5cfe4bcb0afd71f6bc1cc2dab37a9ad6181c13f9Mark Andrews# Example:
5b79d154014f87b6c54b1ec2d3912c35b02042a1Mark Andrews# com.sun.identity.agents.config.client.ip.header = X-Proxy-Client-IP
5b79d154014f87b6c54b1ec2d3912c35b02042a1Mark Andrews# com.sun.identity.agents.config.client.hostname.header = X-Proxy-Client-Host
a8e5a5918355d883f24e4f137c13cd53841679a9Mark Andrews#
a8e5a5918355d883f24e4f137c13cd53841679a9Mark Andrewscom.sun.identity.agents.config.client.ip.header =
a8e5a5918355d883f24e4f137c13cd53841679a9Mark Andrewscom.sun.identity.agents.config.client.hostname.header =
69496e55a787f8d800c826d2405d8f38e4c52b86Mark Andrews
69496e55a787f8d800c826d2405d8f38e4c52b86Mark Andrews#
c1ee8bb4ba3e9ab1463403ed685729631de406b1Mark Andrews# CONFIGURATION RELOAD INTERVAL
c1ee8bb4ba3e9ab1463403ed685729631de406b1Mark Andrews# Specifies the interval in seconds between configuration reloads. When
c1ee8bb4ba3e9ab1463403ed685729631de406b1Mark Andrews# set to 0, the hot-swap mechanism will be disabled.
16cc4a1f56d0f9a300419da7e75e3b72169e608aMark Andrews# Hot-Swap Enabled: Yes
63d9e735c402ff883d86b22484742d11623745dbMark Andrews#
16cc4a1f56d0f9a300419da7e75e3b72169e608aMark Andrewscom.sun.identity.agents.config.load.interval = 3600
16cc4a1f56d0f9a300419da7e75e3b72169e608aMark Andrews
000a8970f840a0c27c5cc404826853c4674362acMark Andrews#
000a8970f840a0c27c5cc404826853c4674362acMark Andrews# LOCALE IDENTIFICATION PROPERTIES
000a8970f840a0c27c5cc404826853c4674362acMark Andrews# - locale.language: Specifies the language code for identifying the Locale
000a8970f840a0c27c5cc404826853c4674362acMark Andrews# of operation.
000a8970f840a0c27c5cc404826853c4674362acMark Andrews# - locale.country: Specifies the country code for identifying the Locale of
000a8970f840a0c27c5cc404826853c4674362acMark Andrews# operation.
903b3c84e2428160b2921364335363bb33452dabEvan Hunt# Hot-Swap Enabled: No
903b3c84e2428160b2921364335363bb33452dabEvan Hunt#
903b3c84e2428160b2921364335363bb33452dabEvan Huntcom.sun.identity.agents.config.locale.language = en
1fba20bd0b3501f4c7e751e239e0992bf92443bfMark Andrewscom.sun.identity.agents.config.locale.country = US
1fba20bd0b3501f4c7e751e239e0992bf92443bfMark Andrews
e02c1d738bd326beceabbe4a04692ea0282225edMark Andrews#
e02c1d738bd326beceabbe4a04692ea0282225edMark Andrews# AUDIT LOG PROPERTIES
e02c1d738bd326beceabbe4a04692ea0282225edMark Andrews# - audit.accesstype: Specifies the access type which will be logged by the
87708bde16713bc02ff2598f4a82f98c699a2f2dMark Andrews# Agent. Valid value is one of: LOG_NONE, LOG_ALLOW, LOG_DENY, LOG_BOTH.
87708bde16713bc02ff2598f4a82f98c699a2f2dMark Andrews# - log.disposition: Specifies the audit log mode that the Agent will use
38b84a1fcfdbda4d1d0fdca409004ae83be2ace8Mark Andrews# when writing audit log messages. Valid value is one of: LOCAL, REMOTE,
a04b5f679428cefefedebe93718c0401e36f947dMark Andrews# ALL.
38b84a1fcfdbda4d1d0fdca409004ae83be2ace8Mark Andrews# - remote.logfile: Specifies the file name to be used on the remote server
38b84a1fcfdbda4d1d0fdca409004ae83be2ace8Mark Andrews# if the log.disposition is set to REMOTE or ALL.
433e06a25cdd92d665abda3e64c2c65f4a3f9b21Mark Andrews# - local.log.rotate: A flag that indicates if the rotation of audit log
433e06a25cdd92d665abda3e64c2c65f4a3f9b21Mark Andrews# local file is enabled or disabled.
433e06a25cdd92d665abda3e64c2c65f4a3f9b21Mark Andrews# - local.log.size: The size in bytes of the local audit log file, beyond
433e06a25cdd92d665abda3e64c2c65f4a3f9b21Mark Andrews# which the Agent should rotate the log file.
8a743600ddfcd97adbbd83f8e9f546ce7d365acbEvan Hunt# Hot-Swap Enabled: Yes
8a743600ddfcd97adbbd83f8e9f546ce7d365acbEvan Hunt#
8a743600ddfcd97adbbd83f8e9f546ce7d365acbEvan Huntcom.sun.identity.agents.config.audit.accesstype = LOG_NONE
8a743600ddfcd97adbbd83f8e9f546ce7d365acbEvan Huntcom.sun.identity.agents.config.log.disposition = REMOTE
8a743600ddfcd97adbbd83f8e9f546ce7d365acbEvan Huntcom.sun.identity.agents.config.remote.logfile = @AUDIT_LOG_FILENAME@
8a743600ddfcd97adbbd83f8e9f546ce7d365acbEvan Huntcom.sun.identity.agents.config.local.log.rotate = false
dc4fa197dd1031b3c966e5ee9d69a0f49ae1d9ceMark Andrewscom.sun.identity.agents.config.local.log.size = 52428800
dc4fa197dd1031b3c966e5ee9d69a0f49ae1d9ceMark Andrews
3916872f379457fe344afb02398a009701c5016aEvan Hunt#
a04b5f679428cefefedebe93718c0401e36f947dMark Andrews# WEB SERVICE PROCESSING PROPERTIES
3916872f379457fe344afb02398a009701c5016aEvan Hunt# - webservice.enable: A flag that specifies if Web Service processing is
3916872f379457fe344afb02398a009701c5016aEvan Hunt# enabled or disabled.
3916872f379457fe344afb02398a009701c5016aEvan Hunt# - webservice.endpoint: A list of Web Application end points that represent
161429fc059b0eeb84fb506bca4f9f5857a9c091Mark Andrews# Web Services.
161429fc059b0eeb84fb506bca4f9f5857a9c091Mark Andrews# - webservice.process.get.enable: A flag that indicates if the processing
161429fc059b0eeb84fb506bca4f9f5857a9c091Mark Andrews# of HTTP GET requests for Web Service endpoints is enabled or disabled.
79bf7c874bb5a01b5b5db44af10b4ae24c89b93eEvan Hunt# - webservice.authenticator: An implementation class that can be used to
79bf7c874bb5a01b5b5db44af10b4ae24c89b93eEvan Hunt# authenticate web-service requests.
79bf7c874bb5a01b5b5db44af10b4ae24c89b93eEvan Hunt# - webservice.internalerror.content: The name of file that contains content
79bf7c874bb5a01b5b5db44af10b4ae24c89b93eEvan Hunt# used by the Agent to generate an internal error fault for clients.
d9ad0a55bb198caecf13c79f7e9a402fba8e68ebEvan Hunt# - webservice.autherror.content: The name of file that contains content
d9ad0a55bb198caecf13c79f7e9a402fba8e68ebEvan Hunt# used by the Agent to generate an authorization error fault for clients.
d9ad0a55bb198caecf13c79f7e9a402fba8e68ebEvan Hunt# - webservice.responseprocessor: An implementation class that is used to do
d9ad0a55bb198caecf13c79f7e9a402fba8e68ebEvan Hunt# web-service response processing.
d9ad0a55bb198caecf13c79f7e9a402fba8e68ebEvan Hunt# Hot-Swap Enabled: Yes
d9ad0a55bb198caecf13c79f7e9a402fba8e68ebEvan Hunt#
d9ad0a55bb198caecf13c79f7e9a402fba8e68ebEvan Huntcom.sun.identity.agents.config.webservice.enable = false
d9ad0a55bb198caecf13c79f7e9a402fba8e68ebEvan Huntcom.sun.identity.agents.config.webservice.endpoint[0] =
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrewscom.sun.identity.agents.config.webservice.process.get.enable = true
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrewscom.sun.identity.agents.config.webservice.authenticator =
7a54dadeb565d746ef8b3fc77dc76455d836dd30Mark Andrewscom.sun.identity.agents.config.webservice.internalerror.content = WSInternalErrorContent.txt
7a54dadeb565d746ef8b3fc77dc76455d836dd30Mark Andrewscom.sun.identity.agents.config.webservice.autherror.content = WSAuthErrorContent.txt
7a54dadeb565d746ef8b3fc77dc76455d836dd30Mark Andrewscom.sun.identity.agents.config.webservice.responseprocessor =
643935ac110cdd977759ac9b85a5795646ccc6cfMark Andrews
643935ac110cdd977759ac9b85a5795646ccc6cfMark Andrews#
643935ac110cdd977759ac9b85a5795646ccc6cfMark Andrews# ACCESS DENIED URI
79344b9710d6ab498769c5fb1889910c592c6d8bMark Andrews# An application specific (MAP) property that specifies the URI used by
79344b9710d6ab498769c5fb1889910c592c6d8bMark Andrews# the Agent to block unauthorized access requests. May be left unspecified
79344b9710d6ab498769c5fb1889910c592c6d8bMark Andrews# if not available. A global value can also be specified.
179e028b35ff89a9d493398285c40dc89b08963bMark Andrews# Example:
179e028b35ff89a9d493398285c40dc89b08963bMark Andrews# com.sun.identity.agents.config.access.denied.uri[BankApp] = /BankApp/accessdenied.html
179e028b35ff89a9d493398285c40dc89b08963bMark Andrews# com.sun.identity.agents.config.access.denied.uri = /accessdenied.html
c2170a4bd022e20d7dd75e56f9ccff8e7cbbb356Mark Andrews# Hot-Swap Enabled: Yes
c2170a4bd022e20d7dd75e56f9ccff8e7cbbb356Mark Andrews#
c2170a4bd022e20d7dd75e56f9ccff8e7cbbb356Mark Andrewscom.sun.identity.agents.config.access.denied.uri[] =
c2170a4bd022e20d7dd75e56f9ccff8e7cbbb356Mark Andrews
82f77687abd21349fa7c7f51e71fdc0c7367d2e2Mark Andrews#
82f77687abd21349fa7c7f51e71fdc0c7367d2e2Mark Andrews# FORM LOGIN PROCESSING PROPERTIES
0ece47f7c1cf03718726d9dff183b02fa35115e6Mark Andrews# - login.form: A LIST property used by the Agent to identify login
0ece47f7c1cf03718726d9dff183b02fa35115e6Mark Andrews# request and take appropriate action. Each entry should be the
0ece47f7c1cf03718726d9dff183b02fa35115e6Mark Andrews# absolute URI of the resource specified in the web.xml deployment
1f512cd06b4aefb86e767197751879840ba3f56bMark Andrews# descriptor of the protected application in the element
1f512cd06b4aefb86e767197751879840ba3f56bMark Andrews# form-login-page.
1f512cd06b4aefb86e767197751879840ba3f56bMark Andrews# - login.error.uri: A LIST property used by the Agent to identify
584ad7dedd0928a59830f82d82ae696bf6f4e705Evan Hunt# error page request and take appropriate action. Each entry should
584ad7dedd0928a59830f82d82ae696bf6f4e705Evan Hunt# be the absolute URI of the resource specified in the web.xml
584ad7dedd0928a59830f82d82ae696bf6f4e705Evan Hunt# deployment descriptor of the protected application in the element
584ad7dedd0928a59830f82d82ae696bf6f4e705Evan Hunt# form-error-page.
71bd858d8ed62672e7c23999dc7c02fd16a55089Evan Hunt# - login.use.internal: A flag that specifies if the Agent should use
71bd858d8ed62672e7c23999dc7c02fd16a55089Evan Hunt# internal content for handling form login requests.
71bd858d8ed62672e7c23999dc7c02fd16a55089Evan Hunt# - login.content.file: Specifies the name or complete path of the file
71bd858d8ed62672e7c23999dc7c02fd16a55089Evan Hunt# that will be used by the Agent for handling form login requests if
71bd858d8ed62672e7c23999dc7c02fd16a55089Evan Hunt# the login.use.internal flag is set to true.
71bd858d8ed62672e7c23999dc7c02fd16a55089Evan Hunt# Hot-Swap Enabled: Yes
71bd858d8ed62672e7c23999dc7c02fd16a55089Evan Hunt# Examples:
71bd858d8ed62672e7c23999dc7c02fd16a55089Evan Hunt# com.sun.identity.agents.config.login.form[0] = /BankApp/jsp/login.jsp
71bd858d8ed62672e7c23999dc7c02fd16a55089Evan Hunt# com.sun.identity.agents.config.login.error.uri[0] = /BankApp/jsp/error.jsp
71bd858d8ed62672e7c23999dc7c02fd16a55089Evan Hunt#
71bd858d8ed62672e7c23999dc7c02fd16a55089Evan Huntcom.sun.identity.agents.config.login.form[0] =
71bd858d8ed62672e7c23999dc7c02fd16a55089Evan Huntcom.sun.identity.agents.config.login.error.uri[0] =
71bd858d8ed62672e7c23999dc7c02fd16a55089Evan Huntcom.sun.identity.agents.config.login.use.internal = true
71bd858d8ed62672e7c23999dc7c02fd16a55089Evan Huntcom.sun.identity.agents.config.login.content.file = FormLoginContent.txt
71bd858d8ed62672e7c23999dc7c02fd16a55089Evan Hunt
71bd858d8ed62672e7c23999dc7c02fd16a55089Evan Hunt#
71bd858d8ed62672e7c23999dc7c02fd16a55089Evan Hunt# LOCAL AUTHENTICATION PROCESSING PROPERTIES
71bd858d8ed62672e7c23999dc7c02fd16a55089Evan Hunt# - auth.handler: A MAP property that specifies application
71bd858d8ed62672e7c23999dc7c02fd16a55089Evan Hunt# specific Authentication Handler to be used by the the
71bd858d8ed62672e7c23999dc7c02fd16a55089Evan Hunt# Agent in order to authenticate the logged on user with the
71bd858d8ed62672e7c23999dc7c02fd16a55089Evan Hunt# Application server for the particular application.
71bd858d8ed62672e7c23999dc7c02fd16a55089Evan Hunt# - logout.handler: A MAP property that specifies the application
ffa806a2948ef93a8e90e8272bb9053d87a2346eMark Andrews# specific Logout Handler to be used by the Agent in order to logout
ffa806a2948ef93a8e90e8272bb9053d87a2346eMark Andrews# the logged on user within the Application server for the
ffa806a2948ef93a8e90e8272bb9053d87a2346eMark Andrews# particular application.
ffa806a2948ef93a8e90e8272bb9053d87a2346eMark Andrews# - verification.handler: A MAP property that specifies the application
bbedadf76ab670b01887fb9b41097120ea4fdf14Evan Hunt# specific local verification handler used by the agent to validate
bbedadf76ab670b01887fb9b41097120ea4fdf14Evan Hunt# the user credentials with the local repository.
8d8f0b465959b799cb0d29ed694dc50ea7a73202Mark Andrews# Hot-Swap Enabled: Yes
8d8f0b465959b799cb0d29ed694dc50ea7a73202Mark Andrews# Example:
8d8f0b465959b799cb0d29ed694dc50ea7a73202Mark Andrews# com.sun.identity.agents.config.auth.handler[BankApp] = BankAuthHandler
7659fdb3aab0a96e10aac67669b6c8d79faef44fjohnd# com.sun.identity.agents.config.logout.handler[BankApp] = BankLogoutHandler
7659fdb3aab0a96e10aac67669b6c8d79faef44fjohnd# com.sun.identity.agents.config.verification.handler[BankApp] = BankVerificationHandler
858c4a86c12fdaf90d8d24a6535c7e0f89d0a962johnd#
858c4a86c12fdaf90d8d24a6535c7e0f89d0a962johndcom.sun.identity.agents.config.auth.handler[] =
9f9b7f0e8d455b1c88e51ddcefdbf19b472e1ef2Mark Andrewscom.sun.identity.agents.config.logout.handler[] =
9f9b7f0e8d455b1c88e51ddcefdbf19b472e1ef2Mark Andrewscom.sun.identity.agents.config.verification.handler[] =
9f9b7f0e8d455b1c88e51ddcefdbf19b472e1ef2Mark Andrews
9f9b7f0e8d455b1c88e51ddcefdbf19b472e1ef2Mark Andrews#
9f9b7f0e8d455b1c88e51ddcefdbf19b472e1ef2Mark Andrews# HTTP SESSION BINDING
9f9b7f0e8d455b1c88e51ddcefdbf19b472e1ef2Mark Andrews# Its default value is false so the agent will not invalidate http session,
9f9b7f0e8d455b1c88e51ddcefdbf19b472e1ef2Mark Andrews# and session data will be maintained.
e334405421979688f2d838805ac67ee47bd62976Mark Andrews# If its value is true, then the agent will invalidate the http session when
e334405421979688f2d838805ac67ee47bd62976Mark Andrews# the agent identifies that login has failed, user does not have SSO session
8aee18709f238406719768b8a6b843a15c5075f8Mark Andrews# or pincipal user name does not match SSO user name.
8aee18709f238406719768b8a6b843a15c5075f8Mark Andrews# Hot-Swap Enabled: Yes
8aee18709f238406719768b8a6b843a15c5075f8Mark Andrewscom.sun.identity.agents.config.httpsession.binding = false
e78c2b856b9bfbf713fe805224f345f8e8f84e4aEvan Hunt
e78c2b856b9bfbf713fe805224f345f8e8f84e4aEvan Hunt#
e78c2b856b9bfbf713fe805224f345f8e8f84e4aEvan Hunt# GOTO PARAMETER NAME
e78c2b856b9bfbf713fe805224f345f8e8f84e4aEvan Hunt# This property has been deprecated.
c0a76b3c0b42a110e14eb56103973944900400c4Mark Andrews# Specifies the goto Parameter name to be used by the Agent when
c0a76b3c0b42a110e14eb56103973944900400c4Mark Andrews# redirecting the user to the appropriate authentication service. The
82f0630bae09598209cc37c1db00ff4356efee27Mark Andrews# value of this parameter is used by the authentication service to
82f0630bae09598209cc37c1db00ff4356efee27Mark Andrews# redirect the user to the original requested destination.
82f0630bae09598209cc37c1db00ff4356efee27Mark Andrews# Valid Values:
36fc19f9397ac2469d5432e5eb6ff8774cf60676Mark Andrews# A string value that represents the goto parameter name.
b44b120c66d9c36f1648f18d169bb4daf4b921afMark Andrews# Hot-Swap Enabled: Yes
c656722ea789f512132d5df9a613bea5717dbe3aMark Andrews#
020120e3c72d67a86ce3fd2542b43b269a1e9233Mark Andrewscom.sun.identity.agents.config.redirect.param = goto
97664670d0e45ec865da407112fceb892133eaf3Mark Andrews
97664670d0e45ec865da407112fceb892133eaf3Mark Andrews#
97664670d0e45ec865da407112fceb892133eaf3Mark Andrews# LOGIN URL
c656722ea789f512132d5df9a613bea5717dbe3aMark Andrews# Specifies the login URLs to be used by the Agent to redirect
b5b934a0bb46aded1552a17473652b5a7f4a3274Evan Hunt# incoming users without sufficient credentials to the OpenAM
b5b934a0bb46aded1552a17473652b5a7f4a3274Evan Hunt# authentication service.
b5b934a0bb46aded1552a17473652b5a7f4a3274Evan Hunt# Hot-Swap Enabled: Yes
b5b934a0bb46aded1552a17473652b5a7f4a3274Evan Hunt#
5af195d1dbe4c266a47264111a9293069041209dMark Andrewscom.sun.identity.agents.config.login.url[0] = @AM_SERVICES_PROTO@://@AM_SERVICES_HOST@:@AM_SERVICES_PORT@@AM_SERVICES_DEPLOY_URI@/UI/Login
5af195d1dbe4c266a47264111a9293069041209dMark Andrews
5af195d1dbe4c266a47264111a9293069041209dMark Andrews#
5af195d1dbe4c266a47264111a9293069041209dMark Andrews# LOGOUT URL
5af195d1dbe4c266a47264111a9293069041209dMark Andrews# Specifies the logout URLs to be used by the Agent to log out
5a636f9951e0a6968498d588a57cb01161d2a109Mark Andrews# the authenticated users from the OpenAM authentication service.
5a636f9951e0a6968498d588a57cb01161d2a109Mark Andrews# Hot-Swap Enabled: Yes
8eb30f8dd3c1170406f4f2307964e4c0994494beEvan Hunt#
8eb30f8dd3c1170406f4f2307964e4c0994494beEvan Huntcom.sun.identity.agents.config.logout.url[0] = @AM_SERVICES_PROTO@://@AM_SERVICES_HOST@:@AM_SERVICES_PORT@@AM_SERVICES_DEPLOY_URI@/UI/Logout
8eb30f8dd3c1170406f4f2307964e4c0994494beEvan Hunt
8eb30f8dd3c1170406f4f2307964e4c0994494beEvan Hunt#
d48730a446ffffa8d75462a4abefce030425fa64Mark Andrews# LOGIN URL, LOGOUT URL, or CDSSO URLs PROPERTIES
d48730a446ffffa8d75462a4abefce030425fa64Mark Andrews# - login.url.prioritized: specifies if the failover sequence for Login URLs
d48730a446ffffa8d75462a4abefce030425fa64Mark Andrews# or CDSSO URLs should be prioritized as defined in the list with the lowest
d48730a446ffffa8d75462a4abefce030425fa64Mark Andrews# index having the highest priority.
7ffe86618c91097b73cde82fb535180dbd5f8e91Mark Andrews# - login.url.probe.enabled: specifies if agent will check the availability
7ffe86618c91097b73cde82fb535180dbd5f8e91Mark Andrews# of these urls before redirecting to them.
7ffe86618c91097b73cde82fb535180dbd5f8e91Mark Andrews# Default value is true for backward compability, but suggests to set it
d48730a446ffffa8d75462a4abefce030425fa64Mark Andrews# to false (server will not be checked) in production deployment where agent
380c874925f684847d9278b909cf511cb5b0289aShawn Routhier# often can not access login url directly.
380c874925f684847d9278b909cf511cb5b0289aShawn Routhier# - login.url.probe.timeout: this is the connect timeout value in milliseconds
380c874925f684847d9278b909cf511cb5b0289aShawn Routhier# when login.url.probe.enabled is set to true (or server will be checked).
7ffe86618c91097b73cde82fb535180dbd5f8e91Mark Andrews# - logout.url.prioritized: specifies if the failover sequence for Logout
7ffe86618c91097b73cde82fb535180dbd5f8e91Mark Andrews# URLs should be prioritized as defined in the list with the lowest
380c874925f684847d9278b909cf511cb5b0289aShawn Routhier# index having the highest priority.
a27b3757fdd8976ce05e37f391ad9e7ac4638e5dMark Andrews# - logout.url.probe.enabled: specifies if agent will check the availability
a27b3757fdd8976ce05e37f391ad9e7ac4638e5dMark Andrews# of these urls before redirecting to them.
a27b3757fdd8976ce05e37f391ad9e7ac4638e5dMark Andrews# Default value is true for backward compability, but suggests to set it
7ffe86618c91097b73cde82fb535180dbd5f8e91Mark Andrews# to false (server will not be checked) in production deployment where agent
7ffe86618c91097b73cde82fb535180dbd5f8e91Mark Andrews# often can not access logout url directly.
7ffe86618c91097b73cde82fb535180dbd5f8e91Mark Andrews# - logout.url.probe.timeout: this is the connect timeout value in milliseconds
a27b3757fdd8976ce05e37f391ad9e7ac4638e5dMark Andrews# when logout.url.probe.enabled is set to true (or server will be checked).
c9c2ffe729bf24a7fd0f0a234a4a84e67621d414Mark Andrews# Hot-Swap Enabled: Yes
c9c2ffe729bf24a7fd0f0a234a4a84e67621d414Mark Andrews#
c9c2ffe729bf24a7fd0f0a234a4a84e67621d414Mark Andrewscom.sun.identity.agents.config.login.url.prioritized = true
7bce3361868c7c00929e0c1b64a45f24a714972fMark Andrewscom.sun.identity.agents.config.login.url.probe.enabled = true
7bce3361868c7c00929e0c1b64a45f24a714972fMark Andrewscom.sun.identity.agents.config.login.url.probe.timeout = 2000
7bce3361868c7c00929e0c1b64a45f24a714972fMark Andrewscom.sun.identity.agents.config.logout.url.prioritized = true
7bce3361868c7c00929e0c1b64a45f24a714972fMark Andrewscom.sun.identity.agents.config.logout.url.probe.enabled = true
7bce3361868c7c00929e0c1b64a45f24a714972fMark Andrewscom.sun.identity.agents.config.logout.url.probe.timeout = 2000
2015023399657c36e9dcc8b5dc35ce20dfc876f0Mark Andrews
2015023399657c36e9dcc8b5dc35ce20dfc876f0Mark Andrews#
2015023399657c36e9dcc8b5dc35ce20dfc876f0Mark Andrews# AGENT SERVER PROPERTIES
b2c8cc4f2d61f0593300a5851e26e7ddb30b7e10Mark Andrews# - agent.host: The host name identifying the Agent protected server to
b2c8cc4f2d61f0593300a5851e26e7ddb30b7e10Mark Andrews# the client browsers if different from the actual host name. May be
ed83fa75f5657ab2394a701f7ccc169dd9ef48fcMark Andrews# left blank if not used.
ed83fa75f5657ab2394a701f7ccc169dd9ef48fcMark Andrews# - agent.port: The port number identifying the Agent protected server
ed83fa75f5657ab2394a701f7ccc169dd9ef48fcMark Andrews# listening port to the client browsers if different from the actual
9eba1cf5e5420aeded5ed380d9942269fbde90f1Mark Andrews# listening port. May be left blank if not used.
c470afc7ac0040f1bf7553ce8183b7a1d1726211Mark Andrews# - agent.protocol: The protocol being used (http/https) by the client
c470afc7ac0040f1bf7553ce8183b7a1d1726211Mark Andrews# browsers to communicate with the Agent protected server if different
506a2177bfafa4321cf1ba27ff4a1d09bac69e14Mark Andrews# from the actual protocol used by the server.
506a2177bfafa4321cf1ba27ff4a1d09bac69e14Mark Andrews# Hot-Swap Enabled: Yes
506a2177bfafa4321cf1ba27ff4a1d09bac69e14Mark Andrews#
082f42dcf2f38509a8c842013548f680a6ad06f3Mark Andrewscom.sun.identity.agents.config.agent.host =
082f42dcf2f38509a8c842013548f680a6ad06f3Mark Andrewscom.sun.identity.agents.config.agent.port =
082f42dcf2f38509a8c842013548f680a6ad06f3Mark Andrewscom.sun.identity.agents.config.agent.protocol =
c75523bcb30c2b8426ee7cb226d9b429c337325bMark Andrews
c75523bcb30c2b8426ee7cb226d9b429c337325bMark Andrews#
c75523bcb30c2b8426ee7cb226d9b429c337325bMark Andrews# LOGIN ATTEMPT LIMIT
c75523bcb30c2b8426ee7cb226d9b429c337325bMark Andrews# Specifies the number of login attempts that a user can make without
c75523bcb30c2b8426ee7cb226d9b429c337325bMark Andrews# success using a single browser session which will trigger the
c75523bcb30c2b8426ee7cb226d9b429c337325bMark Andrews# blocking of the user request. Setting this value to 0 disables this
70ba55161bbecab6b58ad4d2203741e9b57951bcMark Andrews# feature.
70ba55161bbecab6b58ad4d2203741e9b57951bcMark Andrews# Hot-Swap Enabled: Yes
70ba55161bbecab6b58ad4d2203741e9b57951bcMark Andrews#
70ba55161bbecab6b58ad4d2203741e9b57951bcMark Andrewscom.sun.identity.agents.config.login.attempt.limit = 0
ad9107efaaae2407cf11bf0c55407d8daed2e2d4Mark Andrews
ad9107efaaae2407cf11bf0c55407d8daed2e2d4Mark Andrews# SSO Cache Enable Flag:
3f9f14055b85c2dda341b341de0e65d4639542c5Mark Andrews# This property specifies if the SSO Cache is active for the agent. This cache
3f9f14055b85c2dda341b341de0e65d4639542c5Mark Andrews# is used through public APIs exposed by the agent SDK.
75f48cecb3289c6d23a45127da65f18937160341Mark Andrews# Valid Values: true, false
75f48cecb3289c6d23a45127da65f18937160341Mark Andrews# Hot-Swap Enabled: Yes
75f48cecb3289c6d23a45127da65f18937160341Mark Andrewscom.sun.identity.agents.config.amsso.cache.enable = true
8fb412590e03dcf9de775dad1eb7acf320b575edMark Andrews
8fb412590e03dcf9de775dad1eb7acf320b575edMark Andrews#
8fb412590e03dcf9de775dad1eb7acf320b575edMark Andrews# COOKIE RESET PROCESSING PROPERTIES
8fb412590e03dcf9de775dad1eb7acf320b575edMark Andrews# - cookie.reset.enable: A flag that specifies if cookie reset processing
1b42401954a8770d82a168ae1ac06ce66862fd25Mark Andrews# is enabled or disabled.
1b42401954a8770d82a168ae1ac06ce66862fd25Mark Andrews# - cookie.reset.name: A list of cookie names that will be reset by the
1b42401954a8770d82a168ae1ac06ce66862fd25Mark Andrews# Agent if cookie reset processing is enabled.
240a7dc59d6bc135ed298436b59dc86c84928ca2Mark Andrews# - cookie.reset.domain: A MAP property with the key being the cookie name
240a7dc59d6bc135ed298436b59dc86c84928ca2Mark Andrews# specified in cookie.reset.name property and the value being the domain
240a7dc59d6bc135ed298436b59dc86c84928ca2Mark Andrews# of this cookie to be used when a reset event occurs.
240a7dc59d6bc135ed298436b59dc86c84928ca2Mark Andrews# - cookie.reset.path: A MAP property with the key being the cookie name
e588bfe68951d3a88f56640fdc7e43d8623642f4Mark Andrews# specified in cookie.reset.name property and the value being the path
e588bfe68951d3a88f56640fdc7e43d8623642f4Mark Andrews# of this cookie to be used when a reset event occurs.
e588bfe68951d3a88f56640fdc7e43d8623642f4Mark Andrews# Hot-Swap Enabled: Yes
c656722ea789f512132d5df9a613bea5717dbe3aMark Andrews#
02a211f4c4d86f283f9c94bc7e5ab07b547e49f4Mark Andrewscom.sun.identity.agents.config.cookie.reset.enable = true
02a211f4c4d86f283f9c94bc7e5ab07b547e49f4Mark Andrewscom.sun.identity.agents.config.cookie.reset.name[0] = LtpaToken
02a211f4c4d86f283f9c94bc7e5ab07b547e49f4Mark Andrewscom.sun.identity.agents.config.cookie.reset.name[1] = LtpaToken2
c656722ea789f512132d5df9a613bea5717dbe3aMark Andrewscom.sun.identity.agents.config.cookie.reset.domain[] =
17be07ab818846dffb79e898da888a29c919bb02Mark Andrewscom.sun.identity.agents.config.cookie.reset.path[] =
17be07ab818846dffb79e898da888a29c919bb02Mark Andrews
17be07ab818846dffb79e898da888a29c919bb02Mark Andrews#
ffa806a2948ef93a8e90e8272bb9053d87a2346eMark Andrews# CDSSO PROCESSING PROPERTIES
ffa806a2948ef93a8e90e8272bb9053d87a2346eMark Andrews# - cdsso.enable: A flag that specifies if CDSSO processing is
20599f3d0e20fe6e253f59f043f3bef5d6635de6Mark Andrews# enabled or disabled.
20599f3d0e20fe6e253f59f043f3bef5d6635de6Mark Andrews# - cdsso.redirect.uri: An intermediate URI that is used by the
20599f3d0e20fe6e253f59f043f3bef5d6635de6Mark Andrews# Agent for processing CDSSO requests.
38abdbf816fac8386d6f5259d5d6bdfb1b4b3d05Mark Andrews# - cdsso.cdcservlet.url: A LIST of URLs of the available CDSSO controllers
38abdbf816fac8386d6f5259d5d6bdfb1b4b3d05Mark Andrews# that may be used by the Agent for CDSSO processing.
38abdbf816fac8386d6f5259d5d6bdfb1b4b3d05Mark Andrews# - cdsso.clock.skew: Specifies a time in seconds to be used by the
38abdbf816fac8386d6f5259d5d6bdfb1b4b3d05Mark Andrews# Agent to determine the validity of the CDSSO AuthnResponse assertion.
38abdbf816fac8386d6f5259d5d6bdfb1b4b3d05Mark Andrews# - cdsso.trusted.id.providers: This property specifies the OpenAM
c6f4972c745f8903aba6dcca41f17a44c473db66Mark Andrews# Server/ID providers that should be trusted by the agent, when evaluating
c6f4972c745f8903aba6dcca41f17a44c473db66Mark Andrews# the CDC Liberty Responses. Used when a Load Balancer/Firewall is between
c6f4972c745f8903aba6dcca41f17a44c473db66Mark Andrews# the agent & server.
c6f4972c745f8903aba6dcca41f17a44c473db66Mark Andrews# - cdsso.secure.enable: A flag that specifies if the SSO Token cookie
c6f4972c745f8903aba6dcca41f17a44c473db66Mark Andrews# set by the agent in the different domains in CDSSO mode will be marked
f94ec08c17d60ee519a4f46b6dbb3519989e5b9cMark Andrews# secure. When the property is set to true the SSO Token cookie will only
f94ec08c17d60ee519a4f46b6dbb3519989e5b9cMark Andrews# be transmitted if the communications channel with the host is a secure one.
f94ec08c17d60ee519a4f46b6dbb3519989e5b9cMark Andrews# - cdsso.domain: This property specifies the domains for which cookies have
8bc194b266a17f89e6c54469d4dfbb408070f39eMark Andrews# to be set in a CDSSO scenario. If this property is left blank then the
8bc194b266a17f89e6c54469d4dfbb408070f39eMark Andrews# fully qualified cookie domain for the agent server will be used for
8bc194b266a17f89e6c54469d4dfbb408070f39eMark Andrews# setting the cookie domain. In such case it is a host cookie instead of
03952196946fc638af7f20a9b59cfd2f15de01acFrancis Dupont# a domain cookie.
03952196946fc638af7f20a9b59cfd2f15de01acFrancis Dupont# Example:
03952196946fc638af7f20a9b59cfd2f15de01acFrancis Dupont# com.sun.identity.agents.config.cdsso.domain[0] = .sun.com
7c681d075027f3389c31d261e1a71473c42ac73bMark Andrews# Hot-Swap Enabled: Yes
7c681d075027f3389c31d261e1a71473c42ac73bMark Andrews#
7c681d075027f3389c31d261e1a71473c42ac73bMark Andrewscom.sun.identity.agents.config.cdsso.enable = false
da45cdaf79df00578c5bd2be9a9083a1bf95a4feMark Andrewscom.sun.identity.agents.config.cdsso.redirect.uri = @AGENT_APP_URI@/sunwCDSSORedirectURI
c73d8c1b72ddc3330cfc21e2070dffabca324bf7Mark Andrewscom.sun.identity.agents.config.cdsso.cdcservlet.url[0] = @AM_SERVICES_PROTO@://@AM_SERVICES_HOST@:@AM_SERVICES_PORT@@AM_SERVICES_DEPLOY_URI@/cdcservlet
c73d8c1b72ddc3330cfc21e2070dffabca324bf7Mark Andrewscom.sun.identity.agents.config.cdsso.clock.skew = 0
c73d8c1b72ddc3330cfc21e2070dffabca324bf7Mark Andrewscom.sun.identity.agents.config.cdsso.trusted.id.provider[0] = @AM_SERVICES_PROTO@://@AM_SERVICES_HOST@:@AM_SERVICES_PORT@@AM_SERVICES_DEPLOY_URI@/cdcservlet
c73d8c1b72ddc3330cfc21e2070dffabca324bf7Mark Andrewscom.sun.identity.agents.config.cdsso.secure.enable = false
c73d8c1b72ddc3330cfc21e2070dffabca324bf7Mark Andrews#com.sun.identity.agents.config.cdsso.domain[0] =
c73d8c1b72ddc3330cfc21e2070dffabca324bf7Mark Andrews
27fe1966c948ba0c1c9d0d831ea3d8bf32d052acTatuya JINMEI 神明達哉#
27fe1966c948ba0c1c9d0d831ea3d8bf32d052acTatuya JINMEI 神明達哉# LOGOUT PROCESSING PROPERTIES
27fe1966c948ba0c1c9d0d831ea3d8bf32d052acTatuya JINMEI 神明達哉# - logout.application.handler: An application specific (MAP) property
27fe1966c948ba0c1c9d0d831ea3d8bf32d052acTatuya JINMEI 神明達哉# that identifies a handler to be used for logout processing.
27fe1966c948ba0c1c9d0d831ea3d8bf32d052acTatuya JINMEI 神明達哉# - logout.uri: An application specific (MAP) property that identifies
27fe1966c948ba0c1c9d0d831ea3d8bf32d052acTatuya JINMEI 神明達哉# a request URI which indicates a logout event.
27fe1966c948ba0c1c9d0d831ea3d8bf32d052acTatuya JINMEI 神明達哉# - logout.request.param: An application specific (MAP) property that
27fe1966c948ba0c1c9d0d831ea3d8bf32d052acTatuya JINMEI 神明達哉# identifies a parameter which when present in the HTTP request
27fe1966c948ba0c1c9d0d831ea3d8bf32d052acTatuya JINMEI 神明達哉# indicates a logout event.
27fe1966c948ba0c1c9d0d831ea3d8bf32d052acTatuya JINMEI 神明達哉# - logout.introspect.enabled: A flag that when set allows the Agent
27fe1966c948ba0c1c9d0d831ea3d8bf32d052acTatuya JINMEI 神明達哉# to search HTTP request body to locate logout parameter.
27fe1966c948ba0c1c9d0d831ea3d8bf32d052acTatuya JINMEI 神明達哉# - logout.entry.uri: An application specific (MAP) property that identifies
27fe1966c948ba0c1c9d0d831ea3d8bf32d052acTatuya JINMEI 神明達哉# a URI to be used as an entry point after successful logout and
27fe1966c948ba0c1c9d0d831ea3d8bf32d052acTatuya JINMEI 神明達哉# subsequent successful authentication if applicable.
27fe1966c948ba0c1c9d0d831ea3d8bf32d052acTatuya JINMEI 神明達哉# Hot-Swap Enabled: Yes
27fe1966c948ba0c1c9d0d831ea3d8bf32d052acTatuya JINMEI 神明達哉#
27fe1966c948ba0c1c9d0d831ea3d8bf32d052acTatuya JINMEI 神明達哉com.sun.identity.agents.config.logout.application.handler[] =
cfd262045c23cadb8415f0111f56995258f17361Evan Huntcom.sun.identity.agents.config.logout.uri[ibm/console] = /ibm/console/logout.do
cfd262045c23cadb8415f0111f56995258f17361Evan Huntcom.sun.identity.agents.config.logout.request.param[] =
cfd262045c23cadb8415f0111f56995258f17361Evan Huntcom.sun.identity.agents.config.logout.introspect.enabled = false
cfd262045c23cadb8415f0111f56995258f17361Evan Huntcom.sun.identity.agents.config.logout.entry.uri[] =
cfd262045c23cadb8415f0111f56995258f17361Evan Hunt
cfd262045c23cadb8415f0111f56995258f17361Evan Hunt#
cfd262045c23cadb8415f0111f56995258f17361Evan Hunt# FQDN PROCESSING PROPERTIES
cfd262045c23cadb8415f0111f56995258f17361Evan Hunt# - fqdn.check.enable: A flag that indicates if FQDN checking is enabled
cfd262045c23cadb8415f0111f56995258f17361Evan Hunt# or not.
cfd262045c23cadb8415f0111f56995258f17361Evan Hunt# - fqdn.default: A hostname that represents the default FQDN to be
cfd262045c23cadb8415f0111f56995258f17361Evan Hunt# used by the Agent when necessary.
cfd262045c23cadb8415f0111f56995258f17361Evan Hunt# - fqdn.mapping: A MAP property that specifies a mapping from an invalid
4b6cb8d09e75ce9f04b2e40bd9d2e449c09b0c1fMark Andrews# FQDN entry specified as the key to a valid FQDN entry specified as
4b6cb8d09e75ce9f04b2e40bd9d2e449c09b0c1fMark Andrews# its value.
4b6cb8d09e75ce9f04b2e40bd9d2e449c09b0c1fMark Andrews# Hot-Swap Enabled: Yes
712b976a0633806b7140b17354a9398300f616b9Mark Andrews# Examples of fqdn.mapping:
712b976a0633806b7140b17354a9398300f616b9Mark Andrews# com.sun.identity.agents.config.fqdn.mapping[myserver]=myserver.mydomain.com
712b976a0633806b7140b17354a9398300f616b9Mark Andrews#
f0835301386ff7026fd0097198d4b42f2f8d0867Mark Andrewscom.sun.identity.agents.config.fqdn.check.enable = true
f0835301386ff7026fd0097198d4b42f2f8d0867Mark Andrewscom.sun.identity.agents.config.fqdn.default = @AGENT_HOST@
f0835301386ff7026fd0097198d4b42f2f8d0867Mark Andrewscom.sun.identity.agents.config.fqdn.mapping[] =
f0835301386ff7026fd0097198d4b42f2f8d0867Mark Andrews
f0835301386ff7026fd0097198d4b42f2f8d0867Mark Andrews#
cb933b69ff357100768d0b33b88e4ee986b128f2Evan Hunt# LEGACY USER AGENT PROCESSING PROPERTIES
cb933b69ff357100768d0b33b88e4ee986b128f2Evan Hunt# These three properties have been deprecated:
cb933b69ff357100768d0b33b88e4ee986b128f2Evan Hunt# - legacy.support.enable: A flag that specifies if legacy user agent
f1f39b7e07b2665073d976c4d27e30988552b873Tatuya JINMEI 神明達哉# support is enabled or disabled.
9eba1cf5e5420aeded5ed380d9942269fbde90f1Mark Andrews# - legacy.user.agent: A LIST of user agent header values that identify
f1f39b7e07b2665073d976c4d27e30988552b873Tatuya JINMEI 神明達哉# legacy browsers. Entries in this list can have wild card character '*'.
f1f39b7e07b2665073d976c4d27e30988552b873Tatuya JINMEI 神明達哉# - legacy.redirect.uri: An intermediate URI used by the Agent to
f1f39b7e07b2665073d976c4d27e30988552b873Tatuya JINMEI 神明達哉# redirect legacy user agent requests.
f1f39b7e07b2665073d976c4d27e30988552b873Tatuya JINMEI 神明達哉# Hot-Swap Enabled: Yes
86dcc4005887f91d23d970d4574a8f6afa7e28d2Evan Hunt#
86dcc4005887f91d23d970d4574a8f6afa7e28d2Evan Huntcom.sun.identity.agents.config.legacy.support.enable = false
86dcc4005887f91d23d970d4574a8f6afa7e28d2Evan Huntcom.sun.identity.agents.config.legacy.user.agent[0] = Mozilla/4.7*
86dcc4005887f91d23d970d4574a8f6afa7e28d2Evan Huntcom.sun.identity.agents.config.legacy.redirect.uri = @AGENT_APP_URI@/sunwLegacySupportURI
86dcc4005887f91d23d970d4574a8f6afa7e28d2Evan Hunt
86dcc4005887f91d23d970d4574a8f6afa7e28d2Evan Hunt#
86dcc4005887f91d23d970d4574a8f6afa7e28d2Evan Hunt# CUSTOM RESPONSE HEADERS
86dcc4005887f91d23d970d4574a8f6afa7e28d2Evan Hunt# A MAP property that specifies the custom headers that are set by
86dcc4005887f91d23d970d4574a8f6afa7e28d2Evan Hunt# the Agent on the client browser. The key is the header name and the
86dcc4005887f91d23d970d4574a8f6afa7e28d2Evan Hunt# value represents the header value.
86dcc4005887f91d23d970d4574a8f6afa7e28d2Evan Hunt# Hot-Swap Enabled: Yes
c656722ea789f512132d5df9a613bea5717dbe3aMark Andrews# Example:
bf9b852c3eaf2c9847f926751b57a06f1ae3d72aEvan Hunt# com.sun.identity.agents.config.response.header[Cache-Control] = no-cache
bf9b852c3eaf2c9847f926751b57a06f1ae3d72aEvan Hunt#
bf9b852c3eaf2c9847f926751b57a06f1ae3d72aEvan Huntcom.sun.identity.agents.config.response.header[] =
bf9b852c3eaf2c9847f926751b57a06f1ae3d72aEvan Hunt
bf9b852c3eaf2c9847f926751b57a06f1ae3d72aEvan Hunt#
bf9b852c3eaf2c9847f926751b57a06f1ae3d72aEvan Hunt# REDIRECT ATTEMPT LIMIT
bf9b852c3eaf2c9847f926751b57a06f1ae3d72aEvan Hunt# Specifies the number of successive single point redirects that a
bf9b852c3eaf2c9847f926751b57a06f1ae3d72aEvan Hunt# user can make using a single browser session which will trigger the
ff5864ef42c3bc55e9be20434d1f7de2f6794894Mark Andrews# blocking of the user request. When set to 0 this feature is disabled.
ff5864ef42c3bc55e9be20434d1f7de2f6794894Mark Andrews# Hot-Swap Enabled: Yes
ff5864ef42c3bc55e9be20434d1f7de2f6794894Mark Andrews#
f3792d4bda1273fe82f9d0a13f141923e41d4537Tatuya JINMEI 神明達哉com.sun.identity.agents.config.redirect.attempt.limit = 0
f3792d4bda1273fe82f9d0a13f141923e41d4537Tatuya JINMEI 神明達哉
45d9b38097eb7b43e7e0d5d20c2d0903c7224ebdMark Andrews#
ddd40390be246189f10dc18782914b295befb139Mark Andrews# PORT CHECK PROCESSING PROPERTIES
810656a187f2c358323bbf679f792f19a46a7973Mark Andrews# - port.check.enable: A flag that indicates if port check functionality
810656a187f2c358323bbf679f792f19a46a7973Mark Andrews# is enabled or disabled.
810656a187f2c358323bbf679f792f19a46a7973Mark Andrews# - port.check.file: Specifies the name or complete path of a file that
bf13e709db49bb19e0c2e73f0a964fe9d7bea4dfMark Andrews# has the necessary content needed to handle requests that need port
bf13e709db49bb19e0c2e73f0a964fe9d7bea4dfMark Andrews# correction.
bf13e709db49bb19e0c2e73f0a964fe9d7bea4dfMark Andrews# - port.check.setting: A MAP of port versus protocol entries with the
bf13e709db49bb19e0c2e73f0a964fe9d7bea4dfMark Andrews# key being the listening port number and value being the listening
bdc1d1b1bfad04bbae3fdf974e49e392951fb911Mark Andrews# protocol to be used by the Agent to identify requests with invalid
43888c231579e5b021beeadd7265cda302ea1efeMark Andrews# port numbers.
43888c231579e5b021beeadd7265cda302ea1efeMark Andrews# Hot-Swap Enabled: Yes
b7ba273d32232dfadaea5af384f1e6f36c915249Mark Andrews# Example of port.check.setting:
c52235e52ee12e4d15f808ac06608584257f6479Mark Andrews# com.sun.identity.agents.config.port.check.setting[80] = http
4a8dc5f8efcc8bc3033a9383f958d1de22c844f4Mark Andrews# com.sun.identity.agents.config.port.check.setting[443] = https
0627874ff86b2d5c9d6d90ea9fde8111dc97654bMark Andrews#
4a8dc5f8efcc8bc3033a9383f958d1de22c844f4Mark Andrewscom.sun.identity.agents.config.port.check.enable = false
48dfee71508886d86fe8fb12f91961b5daf3141dMark Andrewscom.sun.identity.agents.config.port.check.file = PortCheckContent.txt
48dfee71508886d86fe8fb12f91961b5daf3141dMark Andrewscom.sun.identity.agents.config.port.check.setting[@AGENT_PREF_PORT@] = @AGENT_PREF_PROTO@
48dfee71508886d86fe8fb12f91961b5daf3141dMark Andrews
718c4becc5711be71e23202a87f3aaea1aedde79Mark Andrews#
718c4becc5711be71e23202a87f3aaea1aedde79Mark Andrews# NOT-ENFORCED URI PROCESSING PROPERTIES
718c4becc5711be71e23202a87f3aaea1aedde79Mark Andrews# - notenforced.uri: A LIST of URIs for which protection is not enforced
081b36ff9588e4d67a1a3095f5333a2b223482f7Mark Andrews# by the Agent.
081b36ff9588e4d67a1a3095f5333a2b223482f7Mark Andrews# - notenforced.uri.invert: A flag that specifies if the list of URIs
43c770b9987375e9e0efa19617b22e8e6a748a63Mark Andrews# specified by the property notenforced.uri should be inverted. When
43c770b9987375e9e0efa19617b22e8e6a748a63Mark Andrews# set to true, it indicates that the URIs specified should be enforced
9a56f03c4c63c3729ebfcff9f99b9394c6004a20Mark Andrews# and all other URIs should be not enforced by the Agent. Entries in
9a56f03c4c63c3729ebfcff9f99b9394c6004a20Mark Andrews# this list can have wild card character '*'.
9a56f03c4c63c3729ebfcff9f99b9394c6004a20Mark Andrews# - notenforced.uri.cache.enable: A flag that specifies if the caching of
02181a6c7420e8f3c083d0d20e0e65a78ea25d0fMark Andrews# of not-enforced URI list evaluation results is enabled or disabled.
02181a6c7420e8f3c083d0d20e0e65a78ea25d0fMark Andrews# - notenforced.uri.cache.size: The size of the cache to be used if
02181a6c7420e8f3c083d0d20e0e65a78ea25d0fMark Andrews# caching of not-enforced URI list evaluation results is enabled.
e24ccb512c110d181e01f977196e518b0e72e451Mark Andrews# - notenforced.refresh.session.idletime: A flag that specifies if the OpenAM
e24ccb512c110d181e01f977196e518b0e72e451Mark Andrews# session idle time is reset or not when accessing the not enforced URIs.
e24ccb512c110d181e01f977196e518b0e72e451Mark Andrews# Hot-Swap Enabled: Yes
63af1a646a006867dbd99dc0aa74559d832a420fMark Andrews# Example of notenforced.uri:
63af1a646a006867dbd99dc0aa74559d832a420fMark Andrews# com.sun.identity.agents.config.notenforced.uri[0]=*.gif
b7bc86a4d3d78fae33577682cea7d1449abb7b33Mark Andrews# com.sun.identity.agents.config.notenforced.uri[1]=/public/*
b7bc86a4d3d78fae33577682cea7d1449abb7b33Mark Andrews# com.sun.identity.agents.config.notenforced.uri[2]=/images/*
b7bc86a4d3d78fae33577682cea7d1449abb7b33Mark Andrews#
675cc80975eb7d15e0d9f1d5f424baafaf189fdeMark Andrewscom.sun.identity.agents.config.notenforced.uri[0] =
675cc80975eb7d15e0d9f1d5f424baafaf189fdeMark Andrewscom.sun.identity.agents.config.notenforced.uri.invert = false
675cc80975eb7d15e0d9f1d5f424baafaf189fdeMark Andrewscom.sun.identity.agents.config.notenforced.uri.cache.enable = true
a20996ab6ff2be473b85470fddd2380a3e180e7bMark Andrewscom.sun.identity.agents.config.notenforced.uri.cache.size = 1000
a20996ab6ff2be473b85470fddd2380a3e180e7bMark Andrewscom.sun.identity.agents.config.notenforced.refresh.session.idletime = false
80852eb5a8df5f3d70efb764e00f8f09efc5730cMark Andrews
a27bbd21cf07371fc71e7ade75c3d78a5b98b7f9Mark Andrews#
a27bbd21cf07371fc71e7ade75c3d78a5b98b7f9Mark Andrews# NOT-ENFORCED CLIENT IP PROCESSING PROPERTIES
29f0da7fb84ea8010175769baecd12ab20903bb4Mark Andrews# - notenforced.ip: A LIST of client IP addresses for which protection is
29f0da7fb84ea8010175769baecd12ab20903bb4Mark Andrews# not enforced by the Agent.
29f0da7fb84ea8010175769baecd12ab20903bb4Mark Andrews# - notenforced.ip.invert: A flag that specifies if the list of client IP
b00de53de2e37154d9046d481734cfb9a8573204Mark Andrews# addresses specified by the property notenforced.ip should be inverted.
b00de53de2e37154d9046d481734cfb9a8573204Mark Andrews# When set to true, it indicates that the client IP addresses specified
b00de53de2e37154d9046d481734cfb9a8573204Mark Andrews# should be enforced and all other client IPs should be not enforced by
249dcf3932668693a53c2790b97f5170efb233e1Mark Andrews# the Agent. Entries in this list can have wild card character '*'.
ead77b9ad4821433ad45ef1de2c072b7c8f94f48Mark Andrews# - notenforced.ip.cache.enable: A flag that specifies if the caching of
8e22c73f3ea64337926151b53245f61342fa52faMark Andrews# of not-enforced IP list evaluation results is enabled or disabled.
8e22c73f3ea64337926151b53245f61342fa52faMark Andrews# - notenforced.ip.cache.size: The size of the cache to be used if
8e22c73f3ea64337926151b53245f61342fa52faMark Andrews# caching of not-enforced IP list evaluation results is enabled.
e27d55e3ee06b6edcf625b8920a5c809da7f0b98Mark Andrews# Hot-Swap Enabled: Yes
e27d55e3ee06b6edcf625b8920a5c809da7f0b98Mark Andrews# Example of notenforced.ip:
e27d55e3ee06b6edcf625b8920a5c809da7f0b98Mark Andrews# com.sun.identity.agents.config.notenforced.ip[0]=192.18.145.*
e27d55e3ee06b6edcf625b8920a5c809da7f0b98Mark Andrews# com.sun.identity.agents.config.notenforced.ip[1]=192.18.146.123
e27d55e3ee06b6edcf625b8920a5c809da7f0b98Mark Andrews#
7d9be933d7f4504cd0355ced1fb7fbd137e455b7Mark Andrewscom.sun.identity.agents.config.notenforced.ip[0] =
7d9be933d7f4504cd0355ced1fb7fbd137e455b7Mark Andrewscom.sun.identity.agents.config.notenforced.ip.invert = false
7d9be933d7f4504cd0355ced1fb7fbd137e455b7Mark Andrewscom.sun.identity.agents.config.notenforced.ip.cache.enable = true
5ae2eac4c16bdbbef032544bd9fc86f47e7bdc2cMark Andrewscom.sun.identity.agents.config.notenforced.ip.cache.size = 1000
5ae2eac4c16bdbbef032544bd9fc86f47e7bdc2cMark Andrews
5b02fc32d693bb811199308a40143df0adf818c1Mark Andrews#
5b02fc32d693bb811199308a40143df0adf818c1Mark Andrews# COMMON ATTRIBUTE FETCH PROCESSING PROPERTIES
b667946fa548bf8cb93029458ec130be6365419fMark Andrews# - attribute.cookie.separator: A character that will be used to separate
c656722ea789f512132d5df9a613bea5717dbe3aMark Andrews# multiple values of the same attribute when it is being set as a cookie.
b667946fa548bf8cb93029458ec130be6365419fMark Andrews# - attribute.cookie.encode: A flag that indicates if the value of the
c656722ea789f512132d5df9a613bea5717dbe3aMark Andrews# attribute should be URL encoded before being set as a cookie.
d8624c1f19777853aa96cb797759743c82480f70Mark Andrews# - attribute.date.format: The format of date attribute values to be used
d8624c1f19777853aa96cb797759743c82480f70Mark Andrews# when the attribute is being set as HTTP header. This format is based
c656722ea789f512132d5df9a613bea5717dbe3aMark Andrews# on the definition as provided in java.text.SimpleDateFormat.
98744b51112090a3fb7abcf858cb0657c13609ccMark Andrews# Hot-Swap Enabled: Yes
98744b51112090a3fb7abcf858cb0657c13609ccMark Andrews#
8d31dd9ab62d91b5f23ac687657c966d44074a3fMark Andrewscom.sun.identity.agents.config.attribute.cookie.separator = |
8d31dd9ab62d91b5f23ac687657c966d44074a3fMark Andrewscom.sun.identity.agents.config.attribute.date.format = EEE, d MMM yyyy hh:mm:ss z
c656722ea789f512132d5df9a613bea5717dbe3aMark Andrewscom.sun.identity.agents.config.attribute.cookie.encode = true
6d5840017831db1eee3be47236ff5044449a0256Mark Andrews
6d5840017831db1eee3be47236ff5044449a0256Mark Andrews#
6d5840017831db1eee3be47236ff5044449a0256Mark Andrews# PROFILE ATTRIBUTE PROCESSING PROPERTIES
3ec79bbc03fc5378a6cb37b276807cd40b5332aaMark Andrews# - profile.attribute.fetch.mode: The mode of fetching profile attributes.
3ec79bbc03fc5378a6cb37b276807cd40b5332aaMark Andrews# This value is one of: NONE, HTTP_HEADER, REQUEST_ATTRIBUTE, HTTP_COOKIE
3ec79bbc03fc5378a6cb37b276807cd40b5332aaMark Andrews# - profile.attribute.mapping: A MAP that specifies the profile attributes to
dc64df4479df5e7cb3ed1dead21888b5af98f67eMark Andrews# be populated under specific names for the currently authenticated user.
dc64df4479df5e7cb3ed1dead21888b5af98f67eMark Andrews# The key is the profile attribute name and the value is the name under
778a01b1aa76273d4a28c7559a509edc7a00ec95Mark Andrews# which that attribute will be made available.
778a01b1aa76273d4a28c7559a509edc7a00ec95Mark Andrews# Hot-Swap Enabled: Yes
778a01b1aa76273d4a28c7559a509edc7a00ec95Mark Andrews# Example of profile.attribute.mapping:
44f175a90a855326725439b2f1178f0dcca8f67dMark Andrews# com.sun.identity.agents.config.profile.attribute.mapping[cn]=CUSTOM-Common-Name
44f175a90a855326725439b2f1178f0dcca8f67dMark Andrews# com.sun.identity.agents.config.profile.attribute.mapping[mail]=CUSTOM-Email
21991bd14e8b59000dfc2acf2ce614596cf28cbaMark Andrews#
21991bd14e8b59000dfc2acf2ce614596cf28cbaMark Andrewscom.sun.identity.agents.config.profile.attribute.fetch.mode = NONE
21991bd14e8b59000dfc2acf2ce614596cf28cbaMark Andrewscom.sun.identity.agents.config.profile.attribute.mapping[] =
b335299322e50f045f10e4636262cd2f8d407a8bMark Andrews
b335299322e50f045f10e4636262cd2f8d407a8bMark Andrews#
b335299322e50f045f10e4636262cd2f8d407a8bMark Andrews# SESSION ATTRIBUTE PROCESSING PROPERTIES
ff5c52617eecd06161344c99987a866691592e4aMark Andrews# - session.attribute.fetch.mode: The mode of fetching session attributes.
e12030c433a08b9e9678717ec5e8092c9e4da72cMark Andrews# This value is one of: NONE, HTTP_HEADER, REQUEST_ATTRIBUTE, HTTP_COOKIE
e12030c433a08b9e9678717ec5e8092c9e4da72cMark Andrews# - session.attribute.mapping: A MAP that specifies the session attributes to
e18c62b1dab6bf82530a94c00e2320e542f40c3fMark Andrews# be populated under specific names for the currently authenticated user.
e18c62b1dab6bf82530a94c00e2320e542f40c3fMark Andrews# The key is the session attribute name and the value is the name under
5c40acf2156bbc258fc290f38cf8d5e12d085bedMark Andrews# which that attribute will be made available.
5c40acf2156bbc258fc290f38cf8d5e12d085bedMark Andrews# Hot-Swap Enabled: Yes
5c40acf2156bbc258fc290f38cf8d5e12d085bedMark Andrews# Example of session.attribute.mapping:
5c40acf2156bbc258fc290f38cf8d5e12d085bedMark Andrews# com.sun.identity.agents.config.session.attribute.mapping[UserToken]=CUSTOM-userid
5c40acf2156bbc258fc290f38cf8d5e12d085bedMark Andrews#
5c40acf2156bbc258fc290f38cf8d5e12d085bedMark Andrewscom.sun.identity.agents.config.session.attribute.fetch.mode = NONE
8b7d3aeda264513ca83961fb752703cc3c85451dMark Andrewscom.sun.identity.agents.config.session.attribute.mapping[] =
8b7d3aeda264513ca83961fb752703cc3c85451dMark Andrews
8b7d3aeda264513ca83961fb752703cc3c85451dMark Andrews#
9eba1cf5e5420aeded5ed380d9942269fbde90f1Mark Andrews# RESPONSE ATTRIBUTE PROCESSING PROPERTIES
f083a44415365f6464f8bd35f439dc13ee0b684fMark Andrews# - response.attribute.fetch.mode: The mode of fetching policy response
f083a44415365f6464f8bd35f439dc13ee0b684fMark Andrews# attributes. This value is one of: NONE, HTTP_HEADER, REQUEST_ATTRIBUTE,
108300f7f14315b7fa72a04f009dcb4d0839f207Mark Andrews# HTTP_COOKIE
108300f7f14315b7fa72a04f009dcb4d0839f207Mark Andrews# - response.attribute.mapping: A MAP that specifies the policy response
108300f7f14315b7fa72a04f009dcb4d0839f207Mark Andrews# attributes to be populated under specific names for the currently
2fca4a3321c0137a0bcaa4692564b249ae26322eMark Andrews# authenticated user. The key is the policy response attribute name and
2fca4a3321c0137a0bcaa4692564b249ae26322eMark Andrews# the value is the name under which that attribute will be made available.
2fca4a3321c0137a0bcaa4692564b249ae26322eMark Andrews# Hot-Swap Enabled: Yes
121f783b6660f2cb49829bdc51eb522fd327437eMark Andrews#
121f783b6660f2cb49829bdc51eb522fd327437eMark Andrewscom.sun.identity.agents.config.response.attribute.fetch.mode = NONE
121f783b6660f2cb49829bdc51eb522fd327437eMark Andrewscom.sun.identity.agents.config.response.attribute.mapping[] =
707d9fbd86a15a7112936473a31191dc09ca642cMark Andrews
707d9fbd86a15a7112936473a31191dc09ca642cMark Andrews#
707d9fbd86a15a7112936473a31191dc09ca642cMark Andrews# BYPASS PRINCIPAL LIST
bb9298e0088e8a636ea59f5b435f7c5b536c8017Mark Andrews# This property specifies a list of principals that is bypassed by the
bb9298e0088e8a636ea59f5b435f7c5b536c8017Mark Andrews# Agent for authentication and search purposes.
bb9298e0088e8a636ea59f5b435f7c5b536c8017Mark Andrews# Hot-Swap Enabled: Yes
1df2b7edfecd7cb7edc08ae9ec43d008cfbe7d34Mark Andrews# Example:
1df2b7edfecd7cb7edc08ae9ec43d008cfbe7d34Mark Andrews# com.sun.identity.agents.config.bypass.principal[0] = guest
1df2b7edfecd7cb7edc08ae9ec43d008cfbe7d34Mark Andrews# com.sun.identity.agents.config.bypass.principal[1] = testuser
fd95cc0da9563aa85ac67462433b6a2b6ac0db9fMark Andrews#
fd95cc0da9563aa85ac67462433b6a2b6ac0db9fMark Andrewscom.sun.identity.agents.config.bypass.principal[0] =
fd95cc0da9563aa85ac67462433b6a2b6ac0db9fMark Andrews
bb6d33103e672d21429ae1837ce10d91f2419800Mark Andrews#
bb6d33103e672d21429ae1837ce10d91f2419800Mark Andrews# PRIVILEGED ATTRIBUTE PROCESSING PROPERTIES
bb6d33103e672d21429ae1837ce10d91f2419800Mark Andrews# - default.privileged.attribute: A list of privileged attributes that will
cc6d67469cf390842adf1bd35dd2b21fc3b7df18Mark Andrews# be granted to all users who have a valid OpenAM session.
cc6d67469cf390842adf1bd35dd2b21fc3b7df18Mark Andrews# - privileged.attribute.type: A list of privileged attribute types that will
cc6d67469cf390842adf1bd35dd2b21fc3b7df18Mark Andrews# be fetched for each user.
1e9848fb2b4573711c02696dc4ee6540de4c81f6Mark Andrews# - privileged.attribute.tolowercase : A MAP property that specifies if the
1e9848fb2b4573711c02696dc4ee6540de4c81f6Mark Andrews# privileged attribute types should be converted to lowercase.
1e9848fb2b4573711c02696dc4ee6540de4c81f6Mark Andrews# - privileged.session.attribute: A list of session property names which
1e9848fb2b4573711c02696dc4ee6540de4c81f6Mark Andrews# hold privileged attributes for the authenticated user.
9eba1cf5e5420aeded5ed380d9942269fbde90f1Mark Andrews# - privileged.attribute.mapping.enable: A flag to specify whether
c45d848e2a5898975a14a6311a406f45028a45b0Tatuya JINMEI 神明達哉# a mapping from an attibute's original value to another value is
c45d848e2a5898975a14a6311a406f45028a45b0Tatuya JINMEI 神明達哉# enabled. This mapping may be necessary to satisfy container-specific
7dc38ccd52efe59c8fef8e73f9313080652a1c4aShawn Routhier# restrictions on character set being used in certain configuration files.
7dc38ccd52efe59c8fef8e73f9313080652a1c4aShawn Routhier# - privileged.attribute.mapping: A map property that specifies the above
7dc38ccd52efe59c8fef8e73f9313080652a1c4aShawn Routhier# mentioned mapping; Note that if a key contains "=" or ":", then these
7dc38ccd52efe59c8fef8e73f9313080652a1c4aShawn Routhier# special character needs to be escaped by "\".
ce164dbd9c97331a54994748df3ba72c35920946Tatuya JINMEI 神明達哉#
ce164dbd9c97331a54994748df3ba72c35920946Tatuya JINMEI 神明達哉# Hot-Swap Enabled: Yes
ce164dbd9c97331a54994748df3ba72c35920946Tatuya JINMEI 神明達哉# Examples:
ce164dbd9c97331a54994748df3ba72c35920946Tatuya JINMEI 神明達哉# com.sun.identity.agents.config.default.privileged.attribute[0] = AUTHENTICATED_USERS
c6217b2899ea2bca7f5870ea5dbb3e46fbb72391Mark Andrews# com.sun.identity.agents.config.privileged.attribute.type[0] = Group
86077a2e87bcf2b13cbe2ecfeb17502cc2c12b04Mark Andrews# com.sun.identity.agents.config.privileged.attribute.tolowercase[Group] = false
b8d036c434d68e358c95bcb7268b5c310ed0579cMark Andrews# com.sun.identity.agents.config.privileged.session.attribute[0] = UserToken
b8d036c434d68e358c95bcb7268b5c310ed0579cMark Andrews# com.sun.identity.agents.config.privileged.attribute.mapping.enable=true
b8d036c434d68e358c95bcb7268b5c310ed0579cMark Andrews# com.sun.identity.agents.config.privileged.attribute.mapping[id\=manager,ou\=group,dc\=openam,dc\=forgerock,dc\=org] = am_manager_role
003fd2f720f79404b62d49f6dfe7aa1257f03b08Mark Andrews# com.sun.identity.agents.config.privileged.attribute.mapping[id\=employee,ou\=group,dc\=openam,dc\=forgerock,dc\=org] = am_employee_role
003fd2f720f79404b62d49f6dfe7aa1257f03b08Mark Andrews
003fd2f720f79404b62d49f6dfe7aa1257f03b08Mark Andrewscom.sun.identity.agents.config.default.privileged.attribute[0] = AUTHENTICATED_USERS
003fd2f720f79404b62d49f6dfe7aa1257f03b08Mark Andrewscom.sun.identity.agents.config.privileged.attribute.type[0] = Group
a80d26914afece7324158918e8d74c7c8384a0dfMark Andrewscom.sun.identity.agents.config.privileged.attribute.type[1] = Role
a80d26914afece7324158918e8d74c7c8384a0dfMark Andrewscom.sun.identity.agents.config.privileged.attribute.tolowercase[Group] = false
a80d26914afece7324158918e8d74c7c8384a0dfMark Andrewscom.sun.identity.agents.config.privileged.attribute.tolowercase[Role] = false
c19f322914f380404b613fbb31f5ac2582098f9dMark Andrewscom.sun.identity.agents.config.privileged.session.attribute[0] =
c19f322914f380404b613fbb31f5ac2582098f9dMark Andrewscom.sun.identity.agents.config.privileged.attribute.mapping.enable = true
c19f322914f380404b613fbb31f5ac2582098f9dMark Andrewscom.sun.identity.agents.config.privileged.attribute.mapping[] =
ff9301990d83dedca3806a16b4c9693f16d6e8b1Mark Andrews
ff9301990d83dedca3806a16b4c9693f16d6e8b1Mark Andrews#
fa2cb8d61d8699709b9fc14ed4f47bb63507b2a5Mark Andrews# SSO TOKEN COOKIE NAME
fa2cb8d61d8699709b9fc14ed4f47bb63507b2a5Mark Andrews# The name of the SSO Token cookie used between the OpenAM server and
fa2cb8d61d8699709b9fc14ed4f47bb63507b2a5Mark Andrews# the Agent.
08fb52ec8c3923e501c7f8d74c524cced52551f9Mark Andrews# Hot-Swap Enabled: No
08fb52ec8c3923e501c7f8d74c524cced52551f9Mark Andrewscom.iplanet.am.cookie.name=iPlanetDirectoryPro
08fb52ec8c3923e501c7f8d74c524cced52551f9Mark Andrews
64c43af4f464b4ead99c3d2a561f0013fd26308cMark Andrews#
64c43af4f464b4ead99c3d2a561f0013fd26308cMark Andrews# SESSION CLIENT PROPERTIES
64c43af4f464b4ead99c3d2a561f0013fd26308cMark Andrews# - com.iplanet.am.session.client.polling.enable: A flag that specifies if
c5259c013bba297cb0d38b85bd1c83fc26ef268cMark Andrews# the session client must use polling for updating session information
c5259c013bba297cb0d38b85bd1c83fc26ef268cMark Andrews# and not depend upon server notifications.
c5259c013bba297cb0d38b85bd1c83fc26ef268cMark Andrews# - com.iplanet.am.session.client.polling.period: Specifies the time in
c5259c013bba297cb0d38b85bd1c83fc26ef268cMark Andrews# seconds after which the session client will request update of cached
c5259c013bba297cb0d38b85bd1c83fc26ef268cMark Andrews# session information from the server.
ce0a4906ad27a8743e4f59e8ea06433640d78e54Mark Andrews#
22c4126ba51175af1453cd2254c303c6f65a766cMark Andrews# Note: the notification url to be used by the Agent to receive session
22c4126ba51175af1453cd2254c303c6f65a766cMark Andrews# notifications is com.sun.identity.client.notification.url
637a4234fab5dacacfa0d4fb8b41290b634b252fMark Andrews# Hot-Swap Enabled: No
b1003ace6f6e15ffa212c7982c80845f549e6cefMark Andrews#
b1003ace6f6e15ffa212c7982c80845f549e6cefMark Andrewscom.iplanet.am.session.client.polling.enable=false
637a4234fab5dacacfa0d4fb8b41290b634b252fMark Andrewscom.iplanet.am.session.client.polling.period=180
92348098ebe7ef4c26bfe2204a7364fa18735afcMark Andrews
92348098ebe7ef4c26bfe2204a7364fa18735afcMark Andrews#
637a4234fab5dacacfa0d4fb8b41290b634b252fMark Andrews# ENCRYPTION PROVIDER
d1a5fdc34a3d7caabead7bbf0cbf6fa7d89f0910Mark Andrews# Specifies the encryption provider implementation to be used by the Agent.
d1a5fdc34a3d7caabead7bbf0cbf6fa7d89f0910Mark Andrews# Hot-Swap Enabled: No
5e95cf76e46d93d6b6c2e3cd1aca4c1ab33f827eMark Andrews#
2e20dea9fc0a84217c7debdef8b4b6c6f04d3998Mark Andrewscom.iplanet.security.encryptor=com.iplanet.services.util.JCEEncryption
2e20dea9fc0a84217c7debdef8b4b6c6f04d3998Mark Andrews
13396661f46572d7b94703a25721aad040fbd91aMark Andrews#
13396661f46572d7b94703a25721aad040fbd91aMark Andrews# USER DATA CACHE PROPERTIES
13396661f46572d7b94703a25721aad040fbd91aMark Andrews# - com.sun.identity.idm.remote.notification.enabled: A flag that is used to
64f8608ed6b7f42a4a7d358fade2c82dfd1e9c01Mark Andrews# enable/disable the notifications for amsdk and IdRepo Caches. If set to
64f8608ed6b7f42a4a7d358fade2c82dfd1e9c01Mark Andrews# true notifications are enabled and disabled if set to false.
0cae66577c69c89086cd065bb297690072b471b4Mark Andrews# - com.iplanet.am.sdk.remote.pollingTime: Cache update time in minutes for
0cae66577c69c89086cd065bb297690072b471b4Mark Andrews# user management data. If set to '0' no updates happen. This property
d3cbd6b05c16c6e0e86c1651bda3b3ee06574d62Mark Andrews# takes effect only if no notification url is provided by
d3cbd6b05c16c6e0e86c1651bda3b3ee06574d62Mark Andrews# 'com.sun.identity.client.notification.url' or if notifications are
d3cbd6b05c16c6e0e86c1651bda3b3ee06574d62Mark Andrews# disabled. (i.e., com.sun.identity.idm.remote.notification.enabled=false)
139cedabf9242add24d8326e216e451dd2d5a935Tatuya JINMEI 神明達哉# Hot-Swap Enabled: No
3a28f0dc73549d8c59ad18898540892c7eed957bTatuya JINMEI 神明達哉#
139cedabf9242add24d8326e216e451dd2d5a935Tatuya JINMEI 神明達哉com.sun.identity.idm.remote.notification.enabled=true
8ac908b38a2fd9b780ae3a27ff26932a17823ae0Mark Andrewscom.iplanet.am.sdk.remote.pollingTime=1
8ac908b38a2fd9b780ae3a27ff26932a17823ae0Mark Andrews
8ac908b38a2fd9b780ae3a27ff26932a17823ae0Mark Andrews#
0b24b2d3c423560a0a4cd9a4476b9a2dcafb7ea3Evan Hunt# SERVICE DATA CACHE PROPERTIES
0b24b2d3c423560a0a4cd9a4476b9a2dcafb7ea3Evan Hunt# - com.sun.identity.sm.notification.enabled: A flag that is used to
0b24b2d3c423560a0a4cd9a4476b9a2dcafb7ea3Evan Hunt# enable/disable the notifications for service management caches. If set to
dcfca6f18d5069155ae50025aaeead0cc8c04730Evan Hunt# true notifications are enabled and disabled if set to false.
dcfca6f18d5069155ae50025aaeead0cc8c04730Evan Hunt# - com.sun.identity.sm.cacheTime: Cache update time in minutes for service
ebaf977ecfe6b26ba4482e00d1fd78914a1e17ebMark Andrews# configuration data. If set to '0' no updates happen. This property
ebaf977ecfe6b26ba4482e00d1fd78914a1e17ebMark Andrews# takes effect only if no notification url is provided by
ebaf977ecfe6b26ba4482e00d1fd78914a1e17ebMark Andrews# 'com.sun.identity.client.notification.url' or if notifications are
140cf92b3bbff9da00a782c8afe27f5fa63bd7f7Evan Hunt# disabled. (i.e., com.sun.identity.sm.notification.enabled=false).
19a62c240d4bac66eabc96139bc4a773250495ccFrancis Dupont# Hot-Swap Enabled: No
fd3a3783538312dc8f61a85ce4d3720f43b912c0Mark Andrews#
fd3a3783538312dc8f61a85ce4d3720f43b912c0Mark Andrewscom.sun.identity.sm.notification.enabled=true
fd3a3783538312dc8f61a85ce4d3720f43b912c0Mark Andrewscom.sun.identity.sm.cacheTime=1
0185a9358cb8324f44e114c6fd3cbbc4b9c507e4Francis Dupont
8a198fa776a09beb4dabf40b73a54d9c7bd70ac9Evan Hunt#
8a198fa776a09beb4dabf40b73a54d9c7bd70ac9Evan Hunt# AUTHENTICATION SERVICE PROPERTIES
8a198fa776a09beb4dabf40b73a54d9c7bd70ac9Evan Hunt# Server protocol, host and port to be used by Authentication Service.
8a198fa776a09beb4dabf40b73a54d9c7bd70ac9Evan Hunt# Hot-Swap Enabled: No
8a198fa776a09beb4dabf40b73a54d9c7bd70ac9Evan Hunt#
ce0a4906ad27a8743e4f59e8ea06433640d78e54Mark Andrewscom.iplanet.am.server.protocol=@AM_SERVICES_PROTO@
8a198fa776a09beb4dabf40b73a54d9c7bd70ac9Evan Huntcom.iplanet.am.server.host=@AM_SERVICES_HOST@
8a198fa776a09beb4dabf40b73a54d9c7bd70ac9Evan Huntcom.iplanet.am.server.port=@AM_SERVICES_PORT@
0185a9358cb8324f44e114c6fd3cbbc4b9c507e4Francis Dupont
e11a0c114cdaf8f7e7832e9f1a011138248093a6Evan Hunt#
e11a0c114cdaf8f7e7832e9f1a011138248093a6Evan Hunt# POLICY CLIENT PROPERTIES
0185a9358cb8324f44e114c6fd3cbbc4b9c507e4Francis Dupont# - com.sun.identity.agents.notification.enabled: A flag that specifies
b47d410f8409294863f214542a05c92cbe86cf04Evan Hunt# if notifications are enabled or disabled for remote policy client.
0185a9358cb8324f44e114c6fd3cbbc4b9c507e4Francis Dupont# - com.sun.identity.agents.polling.interval: The duration in minutes
6ff7cd9fa57e8f8092c08df8f9ceccbffb6b19c9Francis Dupont# after which the cached entries are refreshed by remote policy client.
6ff7cd9fa57e8f8092c08df8f9ceccbffb6b19c9Francis Dupont# - com.sun.identity.policy.client.cacheMode: The mode of caching to be
0185a9358cb8324f44e114c6fd3cbbc4b9c507e4Francis Dupont# used by remote policy client. Valid value is one of: subtree, self.
f77148e02902a96bddd5948e594bd4be2efe67ffFrancis Dupont# Cache mode subtree is recommended for a small number of policy rules
f77148e02902a96bddd5948e594bd4be2efe67ffFrancis Dupont# In all other cases, cacheMode self is recommended.
0185a9358cb8324f44e114c6fd3cbbc4b9c507e4Francis Dupont# - com.sun.identity.policy.client.booleanActionValues : boolean action
0185a9358cb8324f44e114c6fd3cbbc4b9c507e4Francis Dupont# values for policy action names.
a91029a00e83e3933046cc9354357bccaa66c272Francis Dupont# format : serviceName|actionName|trueValue|falseValue
a91029a00e83e3933046cc9354357bccaa66c272Francis Dupont# - com.sun.identity.policy.client.resourceComparators: Resource Comparators
a91029a00e83e3933046cc9354357bccaa66c272Francis Dupont# to be used for different service names.
05b1ab91a62c09b052cdd9641355671997430d15Evan Hunt# - com.sun.identity.policy.client.clockSkew: Specifies time in seconds
05b1ab91a62c09b052cdd9641355671997430d15Evan Hunt# which is allowed to accommodate the time difference between the
05b1ab91a62c09b052cdd9641355671997430d15Evan Hunt# OpenAM server machine and the remote policy client machine.
03e5afa4c09d57f85a007149999619e87f501138Evan Hunt#
03e5afa4c09d57f85a007149999619e87f501138Evan Hunt# Note: the Notification URL for remote policy client is set by the
03e5afa4c09d57f85a007149999619e87f501138Evan Hunt# property com.sun.identity.client.notification.url.
03e5afa4c09d57f85a007149999619e87f501138Evan Hunt# Hot-Swap Enabled: No
03e5afa4c09d57f85a007149999619e87f501138Evan Hunt#
03e5afa4c09d57f85a007149999619e87f501138Evan Huntcom.sun.identity.agents.notification.enabled=true
03e5afa4c09d57f85a007149999619e87f501138Evan Huntcom.sun.identity.agents.polling.interval=3
0f66aced2640d964aeb6db41210711ba0640d7f2Evan Huntcom.sun.identity.policy.client.cacheMode=subtree
0f66aced2640d964aeb6db41210711ba0640d7f2Evan Huntcom.sun.identity.policy.client.booleanActionValues=iPlanetAMWebAgentService|GET|allow|deny:iPlanetAMWebAgentService|POST|allow|deny
0f66aced2640d964aeb6db41210711ba0640d7f2Evan Huntcom.sun.identity.policy.client.resourceComparators=serviceType=iPlanetAMWebAgentService|class=com.sun.identity.policy.plugins.HttpURLResourceName|wildcard=*|delimiter=/|caseSensitive=false
0f66aced2640d964aeb6db41210711ba0640d7f2Evan Huntcom.sun.identity.policy.client.clockSkew=10
0f66aced2640d964aeb6db41210711ba0640d7f2Evan Hunt
0f66aced2640d964aeb6db41210711ba0640d7f2Evan Hunt#
0f66aced2640d964aeb6db41210711ba0640d7f2Evan Hunt# URL POLICY ENVIRONMENT VARIABLE PROPERTIES
0f66aced2640d964aeb6db41210711ba0640d7f2Evan Hunt# - com.sun.identity.agents.config.policy.env.get.param: A list of HTTP GET
0f66aced2640d964aeb6db41210711ba0640d7f2Evan Hunt# request parameters whose names and values will be set in the environment
0f66aced2640d964aeb6db41210711ba0640d7f2Evan Hunt# map for URL policy evaluation at OpenAM Enterprise server. The key in the map is in the
8ebf67b7f0aeea7ef8c6e034c57a1dc57a7b216aEvan Hunt# format of GET.<parameter-name>, the map value is a set of string values
8ebf67b7f0aeea7ef8c6e034c57a1dc57a7b216aEvan Hunt# of the parameter.
8ebf67b7f0aeea7ef8c6e034c57a1dc57a7b216aEvan Hunt# - com.sun.identity.agents.config.policy.env.post.param: A list of HTTP POST
7c25b5f311a5a97ba3e9323956507f551c9b3b53Shawn Routhier# request parameters whose names and values will be set in the environment
9eba1cf5e5420aeded5ed380d9942269fbde90f1Mark Andrews# map for URL policy evaluation at OpenAM Enterprise server. The key in the map is in the
7c25b5f311a5a97ba3e9323956507f551c9b3b53Shawn Routhier# format of POST.<parameter-name>, the map value is a set of string values
597642c0baaf66172ca44104ed5a18957a969748Evan Hunt# of the parameter.
597642c0baaf66172ca44104ed5a18957a969748Evan Hunt# - com.sun.identity.agents.config.policy.env.jsession.param: A list of
597642c0baaf66172ca44104ed5a18957a969748Evan Hunt# HTTP SESSION attributes whose names and values will be set in the
597642c0baaf66172ca44104ed5a18957a969748Evan Hunt# environment map for URL policy evaluation at OpenAM Enterprise server. The key in the
597642c0baaf66172ca44104ed5a18957a969748Evan Hunt# map is in the format of JSESSION.<parameter-name>, the map value is a
d3a6cd7c7e13707d0c26e1af0e026dd6c22c5e99Evan Hunt# set that contains the string value of the parameter.
d3a6cd7c7e13707d0c26e1af0e026dd6c22c5e99Evan Hunt# Hot-Swap Enabled: Yes
d3a6cd7c7e13707d0c26e1af0e026dd6c22c5e99Evan Hunt#
845bb3195a4f50d438ec0fcd5d79593010314319Evan Hunt# Examples:
845bb3195a4f50d438ec0fcd5d79593010314319Evan Hunt# com.sun.identity.agents.config.policy.env.get.param[0]=name
845bb3195a4f50d438ec0fcd5d79593010314319Evan Hunt# com.sun.identity.agents.config.policy.env.get.param[1]=phonenumber
d8680445d6212d5552ea8a22fd2f9951b11c4b10Tatuya JINMEI 神明達哉# com.sun.identity.agents.config.policy.env.jsession.param[0]=cardnumber
d8680445d6212d5552ea8a22fd2f9951b11c4b10Tatuya JINMEI 神明達哉# Assuming HTTP GET request parameters "name" and "phonenumber" have their
d8680445d6212d5552ea8a22fd2f9951b11c4b10Tatuya JINMEI 神明達哉# values as "bob" and "1-800-123-4567" respectively. There is a HTTP Session
9ead684875ab0ab5fdb8b5dd837a88f7dbd0e01dEvan Hunt# attribute "cardnumber" with its value as "12345678".
9ead684875ab0ab5fdb8b5dd837a88f7dbd0e01dEvan Hunt# In the map, the following will be set:
687b6322fb189c41c3672226a59461cc5c24c087Evan Hunt# GET.name => [bob]
687b6322fb189c41c3672226a59461cc5c24c087Evan Hunt# GET.phonenumber => [1-800-123-4567]
687b6322fb189c41c3672226a59461cc5c24c087Evan Hunt# JSESSION.cardnumber => [12345678]
57fb4f7bbec88bc6431a39d4a10f82c265798b1fMark Andrews#
57fb4f7bbec88bc6431a39d4a10f82c265798b1fMark Andrewscom.sun.identity.agents.config.policy.env.get.param[0]=
57fb4f7bbec88bc6431a39d4a10f82c265798b1fMark Andrewscom.sun.identity.agents.config.policy.env.post.param[0]=
57fb4f7bbec88bc6431a39d4a10f82c265798b1fMark Andrewscom.sun.identity.agents.config.policy.env.jsession.param[0]=
5b77627c09dea9a65a70d2a0b95a22ff75b3ac04Mark Andrews
5b77627c09dea9a65a70d2a0b95a22ff75b3ac04Mark Andrews# AGENT NOTIFICATION URL PROPERTY
5b77627c09dea9a65a70d2a0b95a22ff75b3ac04Mark Andrews# -com.sun.identity.client.notification.url: URL for agent to receive
288486df9df0c5a39b3c3d625c7f133d9a8e69fbMark Andrews# notifications from the OpenAM server for session, policy, and
288486df9df0c5a39b3c3d625c7f133d9a8e69fbMark Andrews# configuration changes.
5773d3c007c0c065f83480aa17e61bea728221f9Mark Andrews# Hot-Swap Enabled: No
5773d3c007c0c065f83480aa17e61bea728221f9Mark Andrews#
5773d3c007c0c065f83480aa17e61bea728221f9Mark Andrewscom.sun.identity.client.notification.url=@AGENT_PREF_PROTO@://@AGENT_HOST@:@AGENT_PREF_PORT@@AGENT_APP_URI@/notification
85c5ed3577655f4f710f0af5ee93edd71c336055Evan Hunt
85c5ed3577655f4f710f0af5ee93edd71c336055Evan Hunt#
85c5ed3577655f4f710f0af5ee93edd71c336055Evan Hunt# DEBUG SERVICE PROPERTY
0faf1492c711ddb063efda9f3f03b7afa938cff8Francis Dupont# - com.iplanet.services.debug.level: Specifies the debug level to be used.
0faf1492c711ddb063efda9f3f03b7afa938cff8Francis Dupont# The value is one of: off, error, warning, message.
0faf1492c711ddb063efda9f3f03b7afa938cff8Francis Dupont# Hot-Swap Enabled: Yes
0faf1492c711ddb063efda9f3f03b7afa938cff8Francis Dupont#
0faf1492c711ddb063efda9f3f03b7afa938cff8Francis Dupontcom.iplanet.services.debug.level=@DEBUG_LEVEL@
bd31f734eec1884bd14024a232eb3ad3b0b86489Evan Hunt
bd31f734eec1884bd14024a232eb3ad3b0b86489Evan Hunt#
c656722ea789f512132d5df9a613bea5717dbe3aMark Andrews# IGNORE REQUEST URL PATH INFO
1361014b02f11cf8de8725d1770a3dccbc1c8975Evan Hunt# The path info will be stripped from the request URL while doing Not Enforced
1361014b02f11cf8de8725d1770a3dccbc1c8975Evan Hunt# List check and url policy evaluation if the value is set to true.
ce0a4906ad27a8743e4f59e8ea06433640d78e54Mark Andrews#
40ad4ed01be1cace49a62214d11ef1309b3029a0Evan Hunt# Hot-Swap Enabled: Yes
40ad4ed01be1cace49a62214d11ef1309b3029a0Evan Hunt#
b09559fd36c5081ffaf58ab64bdef170c1a720f1Evan Huntcom.sun.identity.agents.config.ignore.path.info = false
b09559fd36c5081ffaf58ab64bdef170c1a720f1Evan Hunt