A web agent instance can be configured using this interface. The properties described only apply if during agent creation, centralized configuration was chosen. If local configuration was selected, the properties related to this agent must be edited in the OpenSSOAgentConfiguration.properites file in the agent installation directory.
The types of configuration available are divided into the following categories:
These properties apply to all applications protected by an agent.
If applicable, select a group from the drop down list to assign this agent to the group. This list consists of previously configured groups.
The password was set when you created the agent profile. However, you can change the password at any time in the future.
The confirmation of the password was performed when you created the agent profile. If you change the password, you must confirm the change.
The Active option is selected when the agent is created. Choose Inactive only if you want to remove the protection the agent provides.
If desired, change the configuration location to whichever of the two options is available: centralized or local. The centralized location allows you to control the configuration in a centralized manner, such as from the Console.
The local option is provided for backward compatibility purposes. If the local configuration option is selected, the agent will use its local configuration in the OpenSSOAgentConfiguration.properites file in the agent installation directory. In addition, the Console will only display the following properties: Password, Password (confirmation), and Status.
When enabled, the agent receives notification messages from the OpenSSO server about configuration changes.
When enabled, notifications help maintain the following agent caches: SSO, policy, and configuration.
When the attribute labeled Enable Notifications is enabled, the URL assigned as a value for this attribute is used by the agent to register notification listeners.
The value of the Universal Resource Identifier (URI). The default value is /amagent.
The interval in minutes for the agent to fetch the agent configuration from OpenSSO. The default value is 60.
The interval in minutes for updating old agent configuration entries, as long as those entries are not currently referenced by any requests. This is part of the hot swapping framework.
When enabled, agent solely enforces authentication (SSO), without enforcing authorization for policies.
The URL of the customized access denied page. If no value is provided, the agent returns an HTTP status of 403 (Forbidden).
The type of debug messages logged. This setting determines the level of the debug log saved locally on the agent host.
When enabled, the log file is rotated at the moment the indicated log file size is reached, as set by the attribute labeled Agent Local Log File Size.
The size, in megabytes, at which the log file is rotated to a new file.
Name of the OpenSSO log file to which each URL access to OpenSSO is recorded.
The URL access logging level setting. This setting refers to URL access as saved to the OpenSSO log file, whose name is specified by the attribute labeled Agent Remote Log Filename.
When enabled, the FQDN default value and the FQDN map values are checked.
The fully qualified host name for users to access resources. This host name is set during agent installation. Do not modify this setting unless necessary.
A mapping to an actual or valid host name. This mapping is from a host name that is not recognized to one that is recognized. This mapping is useful in the following situations: when an IP address or an incorrect URL is entered by the user, or when a virtual host is used for protected resources.
Enter values for the Map Key and the Corresponding Map Values and click Add.
These properties tend to be application specific.
A URL list for which no authentication is performed. For every URL on this list, credentials are not requested for authentication.
When enabled, the not enforced list becomes the enforced list. Therefore, all the URLs listed as values for the attribute labeled Not Enforced URL List are then enforced, while all other URLs are not enforced.
When enabled, the agent fetches profile attributes for URLs on the not enforced list by performing policy evaluation.
The client IP address list. Requests from IP address on this list do not undergo authentication or authorization. Therefore, access is granted for every IP address listed as a value for this attribute. Credentials are not requested for authentication or authorization.
When enabled, browser requests are validated to ensure that they come from the same IP address against which the SSO token was initially issued.
The modes available to fetch additional user profile attributes to be introduced into a request.
A list of mappings from profile attribute names to HTTP header names. These attribute names are populated under specific names for the currently authenticated user.
Enter a profile attribute name value for the Map Key and the HTTP header name for the Corresponding Map Values. Click Add.
The modes available to fetch additional user response attributes to be introduced into a request.
A list of mappings from response attribute names to HTTP header names. These attribute names are populated under specific names for the currently authenticated user. The format of values for this property is as follows: [response_attribute_name]=http_header_name
The modes available to fetch additional user session attributes to be introduced into a request.
A list of mappings from session attribute names to HTTP header names. These attribute names are populated under specific names for the currently authenticated user.
Enter a session attribute name value for the Map Key and the HTTP header name for the Corresponding Map Values. Click Add.
These properties allow you to configure features of the agent related to single sign-on (SSO) and cross domain single sign-on (CDSSO).
The name of the SSO cookie token used between OpenSSO and the agent.
Caution – Changing this property in the agent without correspondingly changing OpenSSO disables the SDK.
When enabled and when the communications channel with the host is secure, the agent marks cookies as secure before sending them.
When enabled, the agent resets cookies in the response before redirecting to OpenSSO for authentication. By default this property is not enabled.
A list of cookies to be included in the redirect response to OpenSSO. This list is only used when the Cookies Reset property is enabled.
When CDSSO is enabled, this list of domains indicates which cookies must be set.
When enabled, cross-domain single sign-on is operative. By default, this property is not enabled.
When enabled, this list indicates which URLs of the available CDSSO controllers can be used by the agent for CDSSO processing. Once you have entered the list of URLs, select a URL and use the buttons to the right of the list to order them accordingly.
These properties configure the OpenSSO services that the agent uses, such as policy service, session service, authentication service, and service management (SM) service.
A list of URLs to OpenSSO authentication. When authentication is required, the agent redirects incoming users to the appropriate authentication service as specified by the URL. Once you have entered the list of URLs, select a URL and use the buttons to the right of the list to order them accordingly.
The timeout period in seconds for an agent connection with the OpenSSO authentication server. The default value is 2 seconds. The error related to this setting is as follows: unable to find active OpenSSO Auth server.
The interval in minutes that the agent polls the primary server to ensure that it is running. The default value is 5.
The list of logout URLs for applications. Once you have entered the list of URLs, select a URL and use the buttons to the right of the list to order them accordingly. Once you have entered the list of URLs, select a URL and use the buttons to the right of the list to order them accordingly.
The list of cookies to be reset upon log out. The format for this list is the same as for the attribute labeled Cookies List for Reset.
The polling interval in minutes to refresh the agent's policy cache. The default value is 3 minutes.
The polling interval in minutes to refresh the agent's SSO cache. The default value is 3 minutes.
The value of the user ID is used by the agent to set the value of the REMOTE_USER server variable. By default, this parameter is set to UserToken.
Used in conjunction with the attribute labeled User ID Parameter, this setting determines from which attribute type the user ID is fetched. The possible values are session and ldap.
When enabled, which is the default setting, the agent caches the policy decision of the resource and all resources from the root of the resource down. To have the agent cache the policy decision for the resource only, which can improve response time, ensure the setting is not enabled.
When enabled, the client host name is obtained through DNS reverse lookup for use in policy evaluation.
The number of seconds used to adjust the time difference between the agent machine and OpenSSO. Clock skew in seconds equals agent time minus OpenSSO time.
These properties do not fit smoothly in other categories.
A combination of the default settings for the locale country code and language code. An underscore, “_”, separates the two locale codes.
The user ID to be used for unauthenticated users.
When enabled, REMOTE_USER processing is performed for anonymous users. This property is associated with the attribute labeled Anonymous User Default Value.
The cookie prefix used in profile attribute headers.
The maximum age in seconds of profile attribute cookie headers.
When enabled, case sensitivity is enforced during both policy evaluation and not-enforced URL evaluation.
When enabled, URLs with special characters are encoded prior to policy evaluation.
When enabled, meaning that “ignore” is enabled, the agent does not send the preferred naming URL as an attribute in the naming request.
When enabled, meaning that “ignore” is enabled, the agent does not ensure that OpenSSO is running before performing a 302 redirect.
When enabled, path information is not stripped from the request URL even if a wild character exists in the not enforced list or policy URLs.
Caution – To prevent a security loop, when this attribute is enabled, ensure that nothing follows the wildcard character “*” in either the not-enforced list or the policy.
When enabled and remote logging fails, resource access is denied.
When enabled, the agent encodes the LDAP header values in the default encoding of the operating system locale. When not enabled, LDAP header values are encoded in UTF-8.
These properties are either custom properties or properties that tend to be used in more-complex or less-common deployments.
When enabled, a load balancer is used for OpenSSO services.
Set this property (as well as the properties labeled as follows: Override Request URL Host, Override Request URL Port, Override Notification URL) to true if the agent is sitting behind an SSL off-loader, load balancer, or proxy.
Set this property (as well as the properties labeled as follows: Override Request URL Protocol, Override Request URL Port, Override Notification URL) to true if the agent is sitting behind an SSL off-loader, load balancer, or proxy.
Set this property (as well as the properties labeled as follows: Override Request URL Protocol, Override Request URL Host, Override Notification URL) to true if the agent is sitting behind an SSL off-loader, load balancer, or proxy.
Set this property (as well as the properties labeled as follows: Override Request URL Protocol, Override Request URL Host, Override Request URL Port) to true if the agent is sitting behind an SSL off-loader, load balancer, or proxy.
When enabled, POST data cache entries are preserved for the time specified by the attribute labeled POST Data Entries Cache Period. This attribute is not applicable to all agents.
The number of minutes a POST cache entry exists before being dropped.
Container Specific: Sun Java System Proxy Server
When enabled, the Sun Java System Proxy Server host name and port number are overridden.
Container Specific: Microsoft IIS Server
Container Specific: Microsoft IIS Server
The DES key for decrypting the basic authentication password in the session.
Container Specific: Microsoft IIS Server
The options available for the loading priority of the agent filter.
Container Specific: Microsoft IIS Server
When enabled and when the Microsoft IIS agent filter is configured for Outlook Web Access (OWA), the agent operates properly. Otherwise, this OWA configuration, does not operate properly.
Container Specific: Microsoft IIS Server
When enabled and when the Microsoft IIS agent filter is configured for Outlook Web Access (OWA), pop up messages from using the Internet Explorer 6 browser are prevented.
Container Specific: Microsoft IIS Server
This property is applicable only when the Microsoft IIS agent filter is configured for Outlook Web Access (OWA). The value for this property is the URL of the local idle session timeout page.
Container Specific: IBM Lotus Domino Server
When enabled, agent checks user existence in the IBM Lotus Domino name database.
Container Specific: IBM Lotus Domino Server
When enabled, agent uses LTPA token. Therefore, enable this property if use of the LTPA token is required by the agent.
Container Specific: IBM Lotus Domino Server
The name of the cookie that contains the LTPA token.
Container Specific: IBM Lotus Domino Server
The configuration name used by the agent to employ the LTPA token mechanism.
Container Specific: IBM Lotus Domino Server
The organization name to which the LTPA token belongs.
A list of custom properties supported by the agent. These are properties created by you.