OpenSSO

Overview FAQ

  1. What is OpenSSO?
  2. Why would Sun open source this proprietary code?
  3. What are the benefits of open-sourcing software?
  4. What are the benefits of OpenSSO??
  5. What are the objectives of the OpenSSO project?
  6. What comprises OpenSSO?
  7. How large is the OpenSSO community?
  8. What is available on the OpenSSO project site?
  9. What license is used for the OpenSSO code base?
  10. Is there any cost for using the OpenSSO source code?
  11. What am I allowed to do with the OpenSSO source code?
  12. If I build the code, can I call it Access Manager?
  13. Do I need to register to download the OpenSSO source code?
  14. How do I participate in the OpenSSO project?
  15. Where do I start?
  16. Can I get support on OpenSSO?

Q: What is OpenSSO?

The Open Web Single Sign-On Project, referred to as OpenSSO, is an open development effort based on the source code for Sun JavaTM System Access Manager and Sun Java System Federation Manager, two identity and federation products offered by Sun Microsystems, Inc. The goal of OpenSSO is to provide an extensible foundation for an identity services infrastructure in the public domain, facilitating single sign-on (SSO) for web applications hosted on web and application servers.

Q: Why would Sun open source this proprietary code?

The official Sun Microsystems answer to this question can be found on the Sun web site. In short, Sun's goal is to improve developer access to SSO technology so that it can become a ubiquitous part of web security infrastructure. OpenSSO gives developers the freedom to secure their internal web infrastructure using SSO technology without adding software licensing costs to their budgets.

Q: What are the benefits of open-sourcing software?

Open-sourcing software:

  • Allows developers to cooperate freely across time and distance with a minimum of legal restrictions.
  • Increases code quality and security.
  • Reduces deployment costs.
  • Increases the capacity for customization.
  • Encourages reusable software.
  • Enables a community where skill and merit matter.

Q: What are the benefits of OpenSSO?

The availability of free, open source code that provides identity-based authentication and single sign-on capabilities will lead to broad adoption of the technology in the Java community. The modules available in OpenSSO comprise an identity service that allows for user authentication and single sign-on within a domain. Developers can freely incorporate this identity service into the web or J2EE-based applications or services they provide.

Q: What are the objectives of the OpenSSO project?

The objectives of the OpenSSO project are:

  • To provide open access to an identity infrastructure source code.
  • To enable innovation to build the next generation of open network identity services.
  • To establish open XML-based file formats and language-independent component application programming interfaces (APIs).

Q: What comprises OpenSSO?

Sun Microsystems will provide the source for the following modules to the Java developer community on a free right-to-use basis:

  • Session Management
  • Policy
  • Console
  • Administration tools
  • Federation
  • Web Services
  • Policy agents

Q: How large is the OpenSSO community?

The OpenSSO project, for all intents and purposes, went live in July, 2006. As of June, 2007, there were 400 project members.

Q: What is available on the OpenSSO site?

The OpenSSO site contains the source code, nightly builds, the governance proposal, the contributor agreement, documentation, forums, mailing lists, and links to relevant information. In addition, it contains instructions on how to become involved. Check out the navigation bar on the left for more specifics.

Q: What license is used for the OpenSSO code base?

The OpenSSO code will be released under the Common Development and Distribution License (CDDL). Information about this license can be found at http://www.sun.com/cddl/ and http://www.opensource.org/licenses/cddl1.php.

Q: Is there any cost for using the OpenSSO source code?

No. The OpenSSO source code is free to use, free to modify and free to redistribute.

Q: What am I allowed to do with the OpenSSO source code?

You can view, modify, build, use, and redistribute the OpenSSO source code. Each of the binary downloads have their own licenses with different rights and restrictions. Please refer to the Licensing page for information about the license terms associated with the source code and binaries.

Q: If I build the code, can I call it Access Manager?

No. Access Manager, Federation Manager and Federated Access Manager are trademarks of Sun Microsystems. You can not call what you build, or any modifications thereof, by any of these names. You can call it anything that is not already trademarked.

Q: Do I need to register to download the OpenSSO source code?

You do not need to register as a user on the java.net site in order to download the source code for OpenSSO. Nor do you need to register as a member of the OpenSSO project.

Q: How do I participate in the OpenSSO project?

The OpenSSO project follows a simple governance structure.

  • Decisions are made in public discussion groups.
  • Decisions are made by consensus, rather than voting.
  • Decisions are made transparently and any member of the project may voice their concerns.
Everyone is welcome to join the OpenSSO community and make contributions. OpenSSO members follow the code of conduct and abide by the governance process. OpenSSO members may play one or more of the following roles:
  • User
  • Contributor
  • Committer
  • Module Owner
  • Project Manager
See the Governance for more details.

Q: Where do I start?

The best place to start is the OpenSSO home page where you can find links to the nightly builds, discussion groups, documentation, downloads, source code, white papers, and more. You can find answers to questions regarding CVS and how the OpenSSO tree works here. You can find answers to technical questions regarding the source code here.

Q: Can I get support on OpenSSO?

Yes and no. Sun Microsystems sells support for OpenSSO Enterprise and OpenSSO Express, productized releases that are built from the OpenSSO source code. There are also mailing lists and community forums where you can freely post questions and receive help from members of the OpenSSO community on nightly builds and the OpenSSO source code itself.