Web Policy Agent

A web agent instance can be configured using this interface. The properties described only apply if during agent creation, centralized configuration was chosen. If local configuration was selected, the properties related to this agent must be edited in the OpenSSOAgentConfiguration.properites file in the agent installation directory.

The types of configuration available are divided into the following categories:

Global

These properties apply to all applications protected by an agent.

Group

If applicable, select a group from the drop down list to assign this agent to the group. This list consists of previously configured groups.

Password

The password was set when you created the agent profile. However, you can change the password at any time in the future.

Password Confirm

The confirmation of the password was performed when you created the agent profile. If you change the password, you must confirm the change.

Status

The Active option is selected when the agent is created. Choose Inactive only if you want to remove the protection the agent provides.

Location of Agent Configuration Repository

If desired, change the configuration location to whichever of the two options is available: centralized or local. The centralized location allows you to control the configuration in a centralized manner, such as from the Console.

The local option is provided for backward compatibility purposes. If the local configuration option is selected, the agent will use its local configuration in the OpenSSOAgentConfiguration.properites file in the agent installation directory. In addition, the Console will only display the following properties: Password, Password (confirmation), and Status.

Agent Configuration Change Notification

When enabled, the agent receives notification messages from the OpenSSO server about configuration changes.

Enable Notifications

When enabled, notifications help maintain the following agent caches: SSO, policy, and configuration.

Agent Notification URL

When the attribute labeled Enable Notifications is enabled, the URL assigned as a value for this attribute is used by the agent to register notification listeners.

Agent Deployment URI Prefix

The value of the Universal Resource Identifier (URI). The default value is /amagent.

Configuration Reload Interval

The interval in minutes for the agent to fetch the agent configuration from OpenSSO. The default value is 60.

Configuration Cleanup Interval

The interval in minutes for updating old agent configuration entries, as long as those entries are not currently referenced by any requests. This is part of the hot swapping framework.

SSO Only Mode

When enabled, agent solely enforces authentication (SSO), without enforcing authorization for policies.

Resources Access Denied URL

The URL of the customized access denied page. If no value is provided, the agent returns an HTTP status of 403 (Forbidden).

Agent Debug Level

The type of debug messages logged. This setting determines the level of the debug log saved locally on the agent host.

Agent Local Log File Rotation

When enabled, the log file is rotated at the moment the indicated log file size is reached, as set by the attribute labeled Agent Local Log File Size.

Agent Local Log File Size

The size, in megabytes, at which the log file is rotated to a new file.

Agent Remote Log Filename

Name of the OpenSSO log file to which each URL access to OpenSSO is recorded.

URL Access Remote Logging Type

The URL access logging level setting. This setting refers to URL access as saved to the OpenSSO log file, whose name is specified by the attribute labeled Agent Remote Log Filename.

FQDN Check

When enabled, the FQDN default value and the FQDN map values are checked.

FQDN Default

The fully qualified host name for users to access resources. This host name is set during agent installation. Do not modify this setting unless necessary.

FQDN Virtual Host Map

A mapping to an actual or valid host name. This mapping is from a host name that is not recognized to one that is recognized. This mapping is useful in the following situations: when an IP address or an incorrect URL is entered by the user, or when a virtual host is used for protected resources.

Enter values for the Map Key and the Corresponding Map Values and click Add.

Application

These properties tend to be application specific.

Not Enforced URL List

A URL list for which no authentication is performed. For every URL on this list, credentials are not requested for authentication.

Invert Check for Not Enforced URL List

When enabled, the not enforced list becomes the enforced list. Therefore, all the URLs listed as values for the attribute labeled Not Enforced URL List are then enforced, while all other URLs are not enforced.

Fetch Attributes for Notenforced URLs

When enabled, the agent fetches profile attributes for URLs on the not enforced list by performing policy evaluation.

Not Enforced Client IP List

The client IP address list. Requests from IP address on this list do not undergo authentication or authorization. Therefore, access is granted for every IP address listed as a value for this attribute. Credentials are not requested for authentication or authorization.

Client IP Validation

When enabled, browser requests are validated to ensure that they come from the same IP address against which the SSO token was initially issued.

Profile Attributes Fetch Mode

The modes available to fetch additional user profile attributes to be introduced into a request.

Profile Attributes Map

A list of mappings from profile attribute names to HTTP header names. These attribute names are populated under specific names for the currently authenticated user.

Enter a profile attribute name value for the Map Key and the HTTP header name for the Corresponding Map Values. Click Add.

Response Attributes Fetch Mode

The modes available to fetch additional user response attributes to be introduced into a request.

Response Attributes Map

A list of mappings from response attribute names to HTTP header names. These attribute names are populated under specific names for the currently authenticated user. The format of values for this property is as follows: [response_attribute_name]=http_header_name

Session Attributes Fetch Mode

The modes available to fetch additional user session attributes to be introduced into a request.

Session Attributes Map

A list of mappings from session attribute names to HTTP header names. These attribute names are populated under specific names for the currently authenticated user.

Enter a session attribute name value for the Map Key and the HTTP header name for the Corresponding Map Values. Click Add.

SSO

These properties allow you to configure features of the agent related to single sign-on (SSO) and cross domain single sign-on (CDSSO).

Cookie Name

The name of the SSO cookie token used between OpenSSO and the agent.


Caution – Changing this property in the agent without correspondingly changing OpenSSO disables the SDK.


Cookie Security

When enabled and when the communications channel with the host is secure, the agent marks cookies as secure before sending them.

Cookies Reset

When enabled, the agent resets cookies in the response before redirecting to OpenSSO for authentication. By default this property is not enabled.

Cookies List for Reset

A list of cookies to be included in the redirect response to OpenSSO. This list is only used when the Cookies Reset property is enabled.

Cookies Domain List

When CDSSO is enabled, this list of domains indicates which cookies must be set.

CDSSO

When enabled, cross-domain single sign-on is operative. By default, this property is not enabled.

CDSSO Servlet URL List

When enabled, this list indicates which URLs of the available CDSSO controllers can be used by the agent for CDSSO processing. Once you have entered the list of URLs, select a URL and use the buttons to the right of the list to order them accordingly.

OpenSSO Services

These properties configure the OpenSSO services that the agent uses, such as policy service, session service, authentication service, and service management (SM) service.

OpenSSO Login URL

A list of URLs to OpenSSO authentication. When authentication is required, the agent redirects incoming users to the appropriate authentication service as specified by the URL. Once you have entered the list of URLs, select a URL and use the buttons to the right of the list to order them accordingly.

Agent Connection Timeout:

The timeout period in seconds for an agent connection with the OpenSSO authentication server. The default value is 2 seconds. The error related to this setting is as follows: unable to find active OpenSSO Auth server.

Polling Period for Primary Server

The interval in minutes that the agent polls the primary server to ensure that it is running. The default value is 5.

Logout URL List

The list of logout URLs for applications. Once you have entered the list of URLs, select a URL and use the buttons to the right of the list to order them accordingly. Once you have entered the list of URLs, select a URL and use the buttons to the right of the list to order them accordingly.

Logout Cookies List for Reset

The list of cookies to be reset upon log out. The format for this list is the same as for the attribute labeled Cookies List for Reset.

Policy Cache Polling Period

The polling interval in minutes to refresh the agent's policy cache. The default value is 3 minutes.

SSO Cache Polling Period

The polling interval in minutes to refresh the agent's SSO cache. The default value is 3 minutes.

User ID Parameter

The value of the user ID is used by the agent to set the value of the REMOTE_USER server variable. By default, this parameter is set to UserToken.

User ID Parameter Type

Used in conjunction with the attribute labeled User ID Parameter, this setting determines from which attribute type the user ID is fetched. The possible values are session and ldap.

Fetch Policies from Root Resource

When enabled, which is the default setting, the agent caches the policy decision of the resource and all resources from the root of the resource down. To have the agent cache the policy decision for the resource only, which can improve response time, ensure the setting is not enabled.

Retrieve Client Hostname

When enabled, the client host name is obtained through DNS reverse lookup for use in policy evaluation.

Policy Clock Skew

The number of seconds used to adjust the time difference between the agent machine and OpenSSO. Clock skew in seconds equals agent time minus OpenSSO time.

Miscellaneous

These properties do not fit smoothly in other categories.

Agent Locale

A combination of the default settings for the locale country code and language code. An underscore, “_”, separates the two locale codes.

Anonymous User Default Value

The user ID to be used for unauthenticated users.

Anonymous User

When enabled, REMOTE_USER processing is performed for anonymous users. This property is associated with the attribute labeled Anonymous User Default Value.

Profile Attributes Cookie Prefix

The cookie prefix used in profile attribute headers.

Profile Attributes Cookie Maxage

The maximum age in seconds of profile attribute cookie headers.

URL Comparison Case Sensitivity Check

When enabled, case sensitivity is enforced during both policy evaluation and not-enforced URL evaluation.

Encode URL's Special Characters

When enabled, URLs with special characters are encoded prior to policy evaluation.

Ignore Preferred Naming URL in Naming Request

When enabled, meaning that “ignore” is enabled, the agent does not send the preferred naming URL as an attribute in the naming request.

Ignore Server Check

When enabled, meaning that “ignore” is enabled, the agent does not ensure that OpenSSO is running before performing a 302 redirect.

Ignore Path Info in Request URL

When enabled, path information is not stripped from the request URL even if a wild character exists in the not enforced list or policy URLs.


Caution – To prevent a security loop, when this attribute is enabled, ensure that nothing follows the wildcard character “*” in either the not-enforced list or the policy.


Deny Resource Access on Remote Log Failure

When enabled and remote logging fails, resource access is denied.

Native Encoding of Profile Attributes

When enabled, the agent encodes the LDAP header values in the default encoding of the operating system locale. When not enabled, LDAP header values are encoded in UTF-8.

Advanced

These properties are either custom properties or properties that tend to be used in more-complex or less-common deployments.

Load Balancer Setup

When enabled, a load balancer is used for OpenSSO services.

Override Request URL Protocol

Set this property (as well as the properties labeled as follows: Override Request URL Host, Override Request URL Port, Override Notification URL) to true if the agent is sitting behind an SSL off-loader, load balancer, or proxy.

Override Request URL Host

Set this property (as well as the properties labeled as follows: Override Request URL Protocol, Override Request URL Port, Override Notification URL) to true if the agent is sitting behind an SSL off-loader, load balancer, or proxy.

Override Request URL Port

Set this property (as well as the properties labeled as follows: Override Request URL Protocol, Override Request URL Host, Override Notification URL) to true if the agent is sitting behind an SSL off-loader, load balancer, or proxy.

Override Notification URL

Set this property (as well as the properties labeled as follows: Override Request URL Protocol, Override Request URL Host, Override Request URL Port) to true if the agent is sitting behind an SSL off-loader, load balancer, or proxy.

POST Data Preservation

When enabled, POST data cache entries are preserved for the time specified by the attribute labeled POST Data Entries Cache Period. This attribute is not applicable to all agents.

POST Data Entries Cache Period

The number of minutes a POST cache entry exists before being dropped.

Override Proxy Server's Host and Port

Container Specific: Sun Java System Proxy Server

When enabled, the Sun Java System Proxy Server host name and port number are overridden.

Authentication Type

Container Specific: Microsoft IIS Server

Replay Password Key

Container Specific: Microsoft IIS Server

The DES key for decrypting the basic authentication password in the session.

Filter Priority

Container Specific: Microsoft IIS Server

The options available for the loading priority of the agent filter.

Filter configured with OWA

Container Specific: Microsoft IIS Server

When enabled and when the Microsoft IIS agent filter is configured for Outlook Web Access (OWA), the agent operates properly. Otherwise, this OWA configuration, does not operate properly.

Change URL Protocol to https

Container Specific: Microsoft IIS Server

When enabled and when the Microsoft IIS agent filter is configured for Outlook Web Access (OWA), pop up messages from using the Internet Explorer 6 browser are prevented.

Idle Session Timeout Page URL

Container Specific: Microsoft IIS Server

This property is applicable only when the Microsoft IIS agent filter is configured for Outlook Web Access (OWA). The value for this property is the URL of the local idle session timeout page.

Check User in Domino Database

Container Specific: IBM Lotus Domino Server

When enabled, agent checks user existence in the IBM Lotus Domino name database.

Use LTPA token

Container Specific: IBM Lotus Domino Server

When enabled, agent uses LTPA token. Therefore, enable this property if use of the LTPA token is required by the agent.

LTPA Token Cookie Name

Container Specific: IBM Lotus Domino Server

The name of the cookie that contains the LTPA token.

LTPA Token Configuration Name

Container Specific: IBM Lotus Domino Server

The configuration name used by the agent to employ the LTPA token mechanism.

LTPA Token Organization Name

Container Specific: IBM Lotus Domino Server

The organization name to which the LTPA token belongs.

Custom Properties

A list of custom properties supported by the agent. These are properties created by you.