Single Sign-On Setup Task List
The following figure provides the sequence of tasks that are required to successfully configure SSO. Cisco recommends that you complete each task outlined in this flow in the order indicated.

The following table lists the tasks to configure Single Sign-On.
Item |
Task |
||
---|---|---|---|
1 |
Provision a new user account for the OpenAM server to be used for Single Sign-On on the Active Directory (AD) server.
|
||
2 |
Configure client browsers for Single Sign-On. See topics related to third-party software and system requirements for a list of web browsers and supported versions. |
||
3 |
Configure Microsoft Windows Registry for Real-Time Monitoring Tool (RTMT). |
||
4 |
Install Java Runtime Environment (JRE).
|
||
5 |
Import IM and Presence Service certificate into OpenAM. Do this for each IM and Presence Service node that is to use Single Sign-On. |
||
6 |
Install the Apache Tomcat Web Container on the OpenAM Windows server. |
||
7 |
Deploy OpenAM War on Apache Tomcat. |
||
8 |
Set up OpenAM using the GUI Configurator. You access the OpenAM web-based administration interface using a web browser by entering the FQDN of the OpenAM server. |
||
9 |
Set up policies on the OpenAM server. You must follow the policy rules that are defined in the procedure.
|
||
10 |
Configure SSO module instance. A single module instance can be shared by multiple IM and Presence Service nodes for SSO if the same Active Directory domain is used throughout the deployment. |
||
11 |
Configure J2EE agent profile on OpenAM. You must configure an associated J2EE Agent Profile on the OpenAM server for the J2EE Agent of each IM and Presence Service node using SSO. |
||
12 |
Set the OpenAM session timeout to a value that is higher than the session timeout parameter setting for the IM and Presence Service node. |
||
13 |
Import the OpenAM certificate into the tomcat-trust trust store for each IM and Presence Service node using SSO. |
||
14 |
Activate Single Sign-On. Enabling SSO affects service. Cisco highly recommends that you enable SSO during a maintenance window. |
-
Disable Single Sign-On
-
Uninstall OpenAM on Windows
-
Set the debug level
-
Troubleshoot Single Sign-On