<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSO with OpenAM in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/sso-with-openam/m-p/252127#M205257</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I use almost entirely these instructions. When I enter the URL &lt;/SPAN&gt;&lt;A href="http://:/share" rel="nofollow noopener noreferrer"&gt;http://:/share&lt;/A&gt;&lt;SPAN&gt; into the browser address I am redirected to the OpenAM application and I login successfully but steel have this Error 403.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Can anybody help me to resolve this error?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks &lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 18 Apr 2014 09:19:35 GMT</pubDate>
    <dc:creator>ameny</dc:creator>
    <dc:date>2014-04-18T09:19:35Z</dc:date>
    <item>
      <title>SSO with OpenAM</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/sso-with-openam/m-p/252113#M205243</link>
      <description>Hi AllI am using OpenAM as our authentication server and need to get Alfresco and Share community 4.0.d involved in the same architecture.However, I am having serious issues here. Usually when OpenAM (previously OpenSSO) is configured to work with web application we do the following :1. add the Open</description>
      <pubDate>Tue, 05 Jun 2012 21:48:05 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/sso-with-openam/m-p/252113#M205243</guid>
      <dc:creator>smcardle</dc:creator>
      <dc:date>2012-06-05T21:48:05Z</dc:date>
    </item>
    <item>
      <title>Re: SSO with OpenAM</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/sso-with-openam/m-p/252114#M205244</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;These are all really good questions.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;It would be clearly possible to create an OpenAM SSO Authenticator for Alfresco and this would be a great thing, because IAM is still/always a very hot topic for enterprises of all size.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I think it does not exists, because Alfresco can do LDAP, Kerberos and NTLM SSO ootb - and these are systems provisioned by OpenAM then.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;What would be the benefits of an Alfresco &amp;lt;-&amp;gt; OpenAM integration regarding authorization? &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; lothar&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2012 10:35:10 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/sso-with-openam/m-p/252114#M205244</guid>
      <dc:creator>lotharmärkle</dc:creator>
      <dc:date>2012-06-08T10:35:10Z</dc:date>
    </item>
    <item>
      <title>Re: SSO with OpenAM</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/sso-with-openam/m-p/252115#M205245</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I'm also looking for Alfresco integration with OpenAM, preferably using SAML 2.0 protocol.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Any help or suggestions will be greatly appreciated.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;P.S. Benefit of such an integration for me is that in such a case I don't need to pass username/password when talking to Alfresco via the CMIS interface (If I have understood the SSO correctly).&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 09 Jun 2012 01:23:08 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/sso-with-openam/m-p/252115#M205245</guid>
      <dc:creator>medb</dc:creator>
      <dc:date>2012-06-09T01:23:08Z</dc:date>
    </item>
    <item>
      <title>Re: SSO with OpenAM</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/sso-with-openam/m-p/252116#M205246</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;@lothar&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The benefit of this is that We already use OpenAM for all of our other application in the stack.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The problem with LDAP etc is that you still need to login i.e. Share is connected to LDAP but you still get the Share login page. NTLM just means that the browser will pass on the current logged in user for the machine.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;As we don't use the NTLM user/password for our other systems this is out of the equation. For LDAP it's pretty much the same.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;OpenAM can use multiple user stores, including LDAP but this would only authenticate us to the LDAP system&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I think I have found a method for OpenAM integration anyway, just haven't finished configuring yet. This solution uses the Alfresco 4.1.a release where a couple of new SSO classes have been added that can authenticate using either a Cookie or Request Header called SsoUserHeader (or whatever you want to call it in the algfresco-global-properties file.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;OpenAM can be configured such that after authentication the redirect to the application is passed either a custom Cookie or Header, in my case SsoUserHeader containing the uid of the user (Our OpenAM user store is LDAP).&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Looking at the code this would seem to be the way to go. You cannot fool Alfresco by creating a cookie on the client called SsoUserHeader because if going via OpenAM, OpenAM will remove all such cookies and headers and not pass them on to the target application during the redirect, unless otherwise instructed.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;As soon as I have managed to get 4.1.a running and my OpenAM polices configured I will test it out and post the results. I may also write a wiki on how to configure Share with OpenAM.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The other side of the coin is Authorisation. Here I want to create a set of groups in OpenAM for Alfresco, like GROUP_myGroup and have Alfresco use the JEE isUserInRole(…) method to determine if they have privilege to do so, because I don't want to have to also setup Groups and Users&amp;nbsp; and map them in Alfresco as well as the Groups and Users management we have in OpenAM. However, this will be a little more difficult as it will require synchronising the two systems as Alfresco requires these internally for it's Authorisation mechanisms. Initially we will live with the duplication of assigning groups to externally managed users in the Alfresco UI&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Steve&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Jun 2012 05:07:04 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/sso-with-openam/m-p/252116#M205246</guid>
      <dc:creator>smcardle</dc:creator>
      <dc:date>2012-06-12T05:07:04Z</dc:date>
    </item>
    <item>
      <title>Re: SSO with OpenAM</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/sso-with-openam/m-p/252117#M205247</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;@Steve&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;We are also trying to integrate Alfresco community edition with OpenAM but, no luck so far. It would be a great help if you can post some pointers at your convenience.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks in advance,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Gopal&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 17 Jun 2012 00:25:36 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/sso-with-openam/m-p/252117#M205247</guid>
      <dc:creator>gopals</dc:creator>
      <dc:date>2012-06-17T00:25:36Z</dc:date>
    </item>
    <item>
      <title>Re: SSO with OpenAM</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/sso-with-openam/m-p/252118#M205248</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi Gopal&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The good news is that I now have a fully integrated OpenAM Alfresco installation.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;NOTE: This works with Alfresco 4.1.a only as there are new SSO classes defined that are required… It may well be possible to retrofit this to older versions of Alfresco (perhaps an Alfresco DEV can tell us what jars need updating to do this) but I will not be doing this for our installation….&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The OpenAM only integrates with Share in our environment and then the usual Share / Alfresco remote communication takes place.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I don't know how you have setup your OpenAM but we configure the agents to get their configuration from the OpenAM server. If this is the same way you configure this then I can help you out.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I will assume you have installed OpenAM and have the J2EE agent installed and setup correctly (I will not cover this in the following text so you should be at a stage where the OpenAM example J2EE application runs)&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The Share application states everywhere that you should not need to change the web.xml file but for OpenAM /OpenSSO integration this is necessary otherwise there is no way to redirect the login to the OpenAM server.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;1. Configure your OpenAM agent&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; a. Log into OpenAM as the admin user and navigate to "Access Control -&amp;gt; (Your Realm) - where in my case your realm is the top level realm&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; b. Select Policies -&amp;gt; New Policy&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; c. Enter Share as the policy name and then create 2 new URL Policy agent rules&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&lt;SPAN&gt;&amp;nbsp; d. 1st Rule - Name Share ALL - GET &amp;amp; POST selected - Resource Name = &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://" rel="nofollow noopener noreferrer"&gt;http://&lt;/A&gt;&lt;SPAN&gt;&amp;lt;your share server&amp;gt;:&amp;lt;share port&amp;gt;/share/*&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; e. 2nd Rule - Name Share With Parameters - GET &amp;amp; POST selected - Resource Name = &lt;/SPAN&gt;&lt;A href="http://chma-qa115.chelmer.co.nz:8080/share/*?*" rel="nofollow noopener noreferrer"&gt;http://chma-qa115.chelmer.co.nz:8080/share/*?*&lt;/A&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; f. Add a subjects - All Authenticated Users&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; g. Now select Agents -&amp;gt; J2EE - &amp;gt; (your J2EE agent)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; h. Select the Application tab&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; i. Login Processing -&amp;gt; Login Form URI - add /share/page/dologin&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; j. Logout Processing -&amp;gt; Application Logout URL - add Map Key = share - Corresponding Map Value = /share/page/dologout&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; k. Not Enforced URI Processing - Add 2 entries - /share and /share/&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; l. Profile Attributes Processing - Select HTTP_HEADER and add Map Key = uid - Corresponding Map Value = SsoUserHeader (This is what I called my header in the alfresco-global.properties file - see below)&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;# Auth chain&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;authentication.chain=external1:external,alfrescoNtlm1:alfrescoNtlm &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;alfresco.authentication.allowGuestLogin=true&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;# SSO settings&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;external.authentication.enabled=true&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;external.authentication.defaultAdministratorUserNames=admin&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;external.authentication.proxyUserName=&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;external.authentication.proxyHeader=SsoUserHeader&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;NOTE- It does not seem possible to configure SSO where the Guest login has been disabled. There are webscripts used on the Alfresco repository that need guest login.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;That concludes the setup for Alfresco and OpenAM&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;For Share you need to have the following section uncommented in your share-config-custom.xml &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; &amp;lt;config evaluator="string-compare" condition="Remote"&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;remote&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;lt;!–&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;keystore&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;path&amp;gt;alfresco/web-extension/alfresco-system.p12&amp;lt;/path&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;type&amp;gt;pkcs12&amp;lt;/type&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;password&amp;gt;alfresco-system&amp;lt;/password&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/keystore&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;–&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;connector&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;id&amp;gt;alfrescoCookie&amp;lt;/id&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;name&amp;gt;Alfresco Connector&amp;lt;/name&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;description&amp;gt;Connects to an Alfresco instance using cookie-based authentication&amp;lt;/description&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;class&amp;gt;org.alfresco.web.site.servlet.SlingshotAlfrescoConnector&amp;lt;/class&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/connector&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;connector&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;id&amp;gt;alfrescoHeader&amp;lt;/id&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;name&amp;gt;Alfresco Connector&amp;lt;/name&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;description&amp;gt;Connects to an Alfresco instance using header and cookie-based authentication&amp;lt;/description&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;class&amp;gt;org.alfresco.web.site.servlet.SlingshotAlfrescoConnector&amp;lt;/class&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;userHeader&amp;gt;SsoUserHeader&amp;lt;/userHeader&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/connector&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;endpoint&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;id&amp;gt;alfresco&amp;lt;/id&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;name&amp;gt;Alfresco - user access&amp;lt;/name&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;description&amp;gt;Access to Alfresco Repository WebScripts that require user authentication&amp;lt;/description&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;connector-id&amp;gt;alfrescoHeader&amp;lt;/connector-id&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;endpoint-url&amp;gt;&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://" rel="nofollow noopener noreferrer"&gt;http://&lt;/A&gt;&lt;SPAN&gt;&amp;lt;alfresco server&amp;gt;:&amp;lt;alfresco port&amp;gt;/alfresco/wcs&amp;lt;/endpoint-url&amp;gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;identity&amp;gt;user&amp;lt;/identity&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;external-auth&amp;gt;true&amp;lt;/external-auth&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/endpoint&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/remote&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; &amp;lt;/config&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Notice I am not using the SSL cert and in my alfrescoHeader connector I have used SsoUserHeader (as setup in OpenAM) and the endpoint uses the alfrescoHeader connector&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Now you need to add the OpenAM filter to the Share web.xml file&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Add the following filter just before the Share SSO authentication support filter&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;filter&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;filter-name&amp;gt;Agent&amp;lt;/filter-name&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;filter-class&amp;gt;com.sun.identity.agents.filter.AmAgentFilter&amp;lt;/filter-class&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/filter&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Add the following filter mapping to the filter-mapping section&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;filter-mapping&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;filter-name&amp;gt;Agent&amp;lt;/filter-name&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;url-pattern&amp;gt;/*&amp;lt;/url-pattern&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;dispatcher&amp;gt;REQUEST&amp;lt;/dispatcher&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;dispatcher&amp;gt;INCLUDE&amp;lt;/dispatcher&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;dispatcher&amp;gt;FORWARD&amp;lt;/dispatcher&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;dispatcher&amp;gt;ERROR&amp;lt;/dispatcher&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/filter-mapping&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;This makes sure ALL pages go through the OpenAM authentication filter before the Share SSO filter. OpenAM will set the SsoUserHeader to the UID of the currently authenticated user and Share will use this and then perform SSO with the Alfresco Repository&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Now when you select the Share URL you will be redirected to the OpenAM login page to authenticate. OpenAM will set the SsoUserHeader on the request that is forwarded to the Share SSO filter and all should be good.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;You do not need to create your users in Alfresco as the SSO authentication implicitly trusts externally authenticated users and will create a user and a home space in Alfresco for you. The user it creates will have no option for changing password…&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;CAVEAT : Even though I have an authentication chain of external and then alfresco NTLM the alfresco NTLM will never be usable as you cannot bypass the authentication mechanism for OpenAM. What normally would happen is that it will say are you externally authenticated? if not see if your are a user in Alfresco. The second part of this process will not work with this setup as ALL users must be defined in OpenAM.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Because of this, if you want and Alfresco user to login via Share, you will need to make one of your OpenAM users a member of the Alfresco Admin group. If you don't want to do this then no worries as you can always login directly to the Alfresco Repo browser as any internally defined Alfresco user, including the admin user.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I hope this helps you to get your configuration working&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Steve&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jun 2012 22:26:41 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/sso-with-openam/m-p/252118#M205248</guid>
      <dc:creator>smcardle</dc:creator>
      <dc:date>2012-06-18T22:26:41Z</dc:date>
    </item>
    <item>
      <title>Re: SSO with OpenAM</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/sso-with-openam/m-p/252119#M205249</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi Steve,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Firstly, thank you so much for a detailed write up.&amp;nbsp; We have similar OpenAM setup and I am going to execute your steps for integration tomorrow. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks again,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Gopal&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Jun 2012 03:34:23 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/sso-with-openam/m-p/252119#M205249</guid>
      <dc:creator>gopals</dc:creator>
      <dc:date>2012-06-20T03:34:23Z</dc:date>
    </item>
    <item>
      <title>Re: SSO with OpenAM</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/sso-with-openam/m-p/252120#M205250</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Your welcome.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Please post back if it works for you. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Also, if you have any issues I may be able to help you out but you will need to be explicit with regard to your OpenAM configuration.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Steve&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Jun 2012 05:01:09 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/sso-with-openam/m-p/252120#M205250</guid>
      <dc:creator>smcardle</dc:creator>
      <dc:date>2012-06-20T05:01:09Z</dc:date>
    </item>
    <item>
      <title>Re: SSO with OpenAM</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/sso-with-openam/m-p/252121#M205251</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi Gopal,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Were you able to get this working?&amp;nbsp; We have 4.0d and are looking to implement with our SSO solution.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Chris&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Sep 2012 11:57:29 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/sso-with-openam/m-p/252121#M205251</guid>
      <dc:creator>seemach1</dc:creator>
      <dc:date>2012-09-05T11:57:29Z</dc:date>
    </item>
    <item>
      <title>Re: SSO with OpenAM</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/sso-with-openam/m-p/252122#M205252</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I got external SSO with OpenAM working using almost entirely these instructions.&amp;nbsp; Here are some of my observations that I hope will save someone else some time:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;~Error 403: When an Error 403 is thrown, it means that the URL pattern used for the rules (items 'd' and 'e' in smcardles's instructions above) are not formatted correctly.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;~Alfresco Log in: If you see the Alfresco log in screen after successfully authenticating, then there is an error in the share-config-custom.xml or the global properties (most likely share-config-custom.xml.&amp;nbsp; &lt;/SPAN&gt;&lt;BR /&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 15 Jun 2013 18:59:00 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/sso-with-openam/m-p/252122#M205252</guid>
      <dc:creator>bonker2121</dc:creator>
      <dc:date>2013-06-15T18:59:00Z</dc:date>
    </item>
    <item>
      <title>Re: SSO with OpenAM</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/sso-with-openam/m-p/252123#M205253</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hello,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I found this post and thanks for the detailed manual (I hope to try it someday soon) &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://connect.hyland.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;One thing remains unclear: did you solve the issue of Alfresco's use of groups (GROUP_myGroup) in conjunction with OpenAM? Did you settle with groups being replicated from OpenAM (or directly from LDAP, like its OpenDJ) into Alfresco, or did you do something else?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;//Jim Klimov&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 17 Nov 2013 20:15:42 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/sso-with-openam/m-p/252123#M205253</guid>
      <dc:creator>jimklimov</dc:creator>
      <dc:date>2013-11-17T20:15:42Z</dc:date>
    </item>
    <item>
      <title>Re: SSO with OpenAM</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/sso-with-openam/m-p/252124#M205254</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt; I do what you are doing and get the alfresco share login page also can you get me the share-config-custom.xml &amp;amp; global properties and i set these 2 files in tomcat/shared/classes . i wait your response&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Feb 2014 10:57:54 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/sso-with-openam/m-p/252124#M205254</guid>
      <dc:creator>ahmedemad3</dc:creator>
      <dc:date>2014-02-11T10:57:54Z</dc:date>
    </item>
    <item>
      <title>Re: SSO with OpenAM</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/sso-with-openam/m-p/252125#M205255</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I want to use Alfresco 4.2.c with openam. So i use External Authentication.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;These is my log file.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt; 2014-02-12 13:19:58,952&amp;nbsp; DEBUG [app.servlet.AuthenticationHelper] [http-bio-8080-exec-9] Authenticating the current user using session based Ticket information.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; 2014-02-12 13:19:58,952&amp;nbsp; DEBUG [app.servlet.AuthenticationHelper] [http-bio-8080-exec-9] Remote user mapper configured and active. Asking for external user ID.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; 2014-02-12 13:19:58,952&amp;nbsp; DEBUG [app.servlet.DefaultRemoteUserMapper] [http-bio-8080-exec-9] Getting RemoteUser from http request.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; 2014-02-12 13:19:58,952&amp;nbsp; DEBUG [app.servlet.DefaultRemoteUserMapper] [http-bio-8080-exec-9] The remote user id is: null&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; 2014-02-12 13:19:58,952&amp;nbsp; DEBUG [app.servlet.DefaultRemoteUserMapper] [http-bio-8080-exec-9] The header user id is: null&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; 2014-02-12 13:19:58,953&amp;nbsp; DEBUG [app.servlet.DefaultRemoteUserMapper] [http-bio-8080-exec-9] The proxy user name is: null&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; 2014-02-12 13:19:58,953&amp;nbsp; DEBUG [app.servlet.DefaultRemoteUserMapper] [http-bio-8080-exec-9] Returning null&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; 2014-02-12 13:19:58,953&amp;nbsp; DEBUG [app.servlet.AuthenticationHelper] [http-bio-8080-exec-9] No external user ID in request.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; 2014-02-12 13:19:58,953&amp;nbsp; DEBUG [app.servlet.AuthenticationHelper] [http-bio-8080-exec-9] SessionUser is: guest&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; 2014-02-12 13:19:58,954&amp;nbsp; DEBUG [app.servlet.AuthenticationHelper] [http-bio-8080-exec-9] Settings the external authentication flag on the session to false&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; 2014-02-12 13:19:58,954&amp;nbsp; DEBUG [app.servlet.AuthenticationHelper] [http-bio-8080-exec-9] We're not in the portal, getting the login bean.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; 2014-02-12 13:19:58,954&amp;nbsp; DEBUG [app.servlet.AuthenticationHelper] [http-bio-8080-exec-9] Force guest is: false&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; 2014-02-12 13:19:58,954&amp;nbsp; DEBUG [app.servlet.AuthenticationHelper] [http-bio-8080-exec-9] The user is: guest&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; 2014-02-12 13:19:58,954&amp;nbsp; DEBUG [app.servlet.AuthenticationHelper] [http-bio-8080-exec-9] Setting up the request thread.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; 2014-02-12 13:19:58,955&amp;nbsp; DEBUG [app.servlet.AuthenticationHelper] [http-bio-8080-exec-9] The general locale is : en_US&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; 2014-02-12 13:19:58,955&amp;nbsp; DEBUG [app.servlet.AuthenticationHelper] [http-bio-8080-exec-9] The UserPreferencesBean is : org.alfresco.web.bean.users.UserPreferencesBean@307fe1b5&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; 2014-02-12 13:19:58,957&amp;nbsp; DEBUG [app.servlet.AuthenticationHelper] [http-bio-8080-exec-9] The content locale is : en_US&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;If i create a new file test.jsp and add out.print(request.getHeader("ssouser")), i can see my user id.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;With Live HTTP Edit, if i define a HTTP HEADER attribut ssouser, it works.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I don't understand why AuthenticationHelper can't get my Header Attribut.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks for your help&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Feb 2014 12:31:06 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/sso-with-openam/m-p/252125#M205255</guid>
      <dc:creator>davdou79</dc:creator>
      <dc:date>2014-02-12T12:31:06Z</dc:date>
    </item>
    <item>
      <title>Re: SSO with OpenAM</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/sso-with-openam/m-p/252126#M205256</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I have been trying to make a SSO in alfresco with no success. I used OpenAM, and CAS, but it didn't work. can someone help me to integrate SSO in Alfresco.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanx&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Mar 2014 08:38:00 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/sso-with-openam/m-p/252126#M205256</guid>
      <dc:creator>cyr</dc:creator>
      <dc:date>2014-03-28T08:38:00Z</dc:date>
    </item>
    <item>
      <title>Re: SSO with OpenAM</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/sso-with-openam/m-p/252127#M205257</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I use almost entirely these instructions. When I enter the URL &lt;/SPAN&gt;&lt;A href="http://:/share" rel="nofollow noopener noreferrer"&gt;http://:/share&lt;/A&gt;&lt;SPAN&gt; into the browser address I am redirected to the OpenAM application and I login successfully but steel have this Error 403.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Can anybody help me to resolve this error?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks &lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Apr 2014 09:19:35 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/sso-with-openam/m-p/252127#M205257</guid>
      <dc:creator>ameny</dc:creator>
      <dc:date>2014-04-18T09:19:35Z</dc:date>
    </item>
    <item>
      <title>Re: SSO with OpenAM</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/sso-with-openam/m-p/252128#M205258</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Thanks alot smcardle, your steps were very helpful! However, I had problems with step 1.l. The uid didn't work for me. I used the &amp;lt;strong&amp;gt;mail&amp;lt;/strong&amp;gt; attribute instead since that's what we use as the userid in alfresco. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;As for maintaining group memberships, we sync users and groups from ldap into alfresco. &lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Sep 2014 13:41:36 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/sso-with-openam/m-p/252128#M205258</guid>
      <dc:creator>paulm</dc:creator>
      <dc:date>2014-09-25T13:41:36Z</dc:date>
    </item>
    <item>
      <title>Re: SSO with OpenAM</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/sso-with-openam/m-p/252129#M205259</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi ALL,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I setup all necessary changes and athentication working fine with 'admin' user defined in openAM, but getting below error,redirecting to error page (:8080/share/error500.jsp).And in the error screen saying trhee reason below.Please advise.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; You have attempted to access a page that does not exist - check the URL in the address bar.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; You have attempted to access a page that is not accessible to you, such as a private Site dashboard.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; A valid page has been requested but the server was unable to render it due to an internal error - contact your administrator.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Log:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;2014-12-23 09:09:17,700&amp;nbsp; ERROR [alfresco.web.site] [http-bio-8080-exec-5] org.springframework.web.util.NestedServletException: Request processing failed; nested exception is org.springframework.extensions.surf.exception.WebFrameworkServiceException: Unable to process response: A JSONObject text must begin with '{' at character 3&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; org.springframework.extensions.surf.exception.WebFrameworkServiceException: Unable to process response: A JSONObject text must begin with '{' at character 3&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regrads&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Jayendran&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Dec 2014 04:11:47 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/sso-with-openam/m-p/252129#M205259</guid>
      <dc:creator>jainmcs03</dc:creator>
      <dc:date>2014-12-23T04:11:47Z</dc:date>
    </item>
    <item>
      <title>Re: SSO with OpenAM</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/sso-with-openam/m-p/252130#M205260</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi ALL,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Im using Alfresco Community 5.0.c and enabling OpenAM-11.0.0 SSO , user getting uthendicated in openAM but redirect to Alfresco login page. Seeing the same error in log file..&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;2014-12-27 21:17:30,814&amp;nbsp; DEBUG [site.servlet.SSOAuthenticationFilter] [http-bio-8080-exec-7] Repository session timed out - restarting auth process…&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;2014-12-27 21:17:57,141&amp;nbsp; DEBUG [app.servlet.AuthenticationHelper] [http-bio-8080-exec-2] The user is null.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2014-12-27 21:17:57,141&amp;nbsp; DEBUG [app.servlet.AuthenticationHelper] [http-bio-8080-exec-2] The session is not invalidated.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2014-12-27 21:17:57,141&amp;nbsp; DEBUG [app.servlet.AuthenticationHelper] [http-bio-8080-exec-2] Searching for Alfresco auth cookie.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;21:17:58,077 DEBUG [org.alfresco.web.app.servlet.AuthenticationHelper] [http-bio-8080-exec-2] Settings the external authentication flag on the session to false&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Below in my config alfresco-global.properties file.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;### Auth chain SSO settings For HTTPHeader ###&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;authentication.chain=external1:external,alfrescoNtlm1:alfrescoNtlm&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;external.authentication.proxyHeader=SsoUserHeader&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;external.authentication.enabled=true&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;alfresco.authentication.allowGuestLogin=true&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;external.authentication.defaultAdministratorUserNames=admin&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;external.authentication.proxyUserName=&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Please advise.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Jayendran&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 27 Dec 2014 16:21:56 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/sso-with-openam/m-p/252130#M205260</guid>
      <dc:creator>jainmcs03</dc:creator>
      <dc:date>2014-12-27T16:21:56Z</dc:date>
    </item>
    <item>
      <title>Re: SSO with OpenAM</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/sso-with-openam/m-p/252131#M205261</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi ALL&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I got external SSO with OpenAM, it works fine. Now i need some details about SLO(single log out). &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Jayendran&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Jan 2015 15:16:17 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/sso-with-openam/m-p/252131#M205261</guid>
      <dc:creator>jainmcs03</dc:creator>
      <dc:date>2015-01-07T15:16:17Z</dc:date>
    </item>
    <item>
      <title>Re: SSO with OpenAM</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/sso-with-openam/m-p/252132#M205262</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;@Steve&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I got a SSO with openAM successfully as per instructions above, but when i try to logout from the share, its not responding which means redirect not working.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Below the logs for reference, please let me know if we need special handling for logout for share. Thanks,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt; ApplicationFilterChain : Inside doFilter&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ApplicationFilterChain : doFilter : IS_SECURITY_ENABLED : false&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ApplicationFilterChain : printstatement : req.getHeaderNames() org.apache.tomcat.util.http.NamesEnumerator@37e696b6&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ApplicationFilterChain : printstatement : req.getHeaderNames() : host&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ApplicationFilterChain : printstatement : req.getHeaderNames() : connection&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ApplicationFilterChain : printstatement : req.getHeaderNames() : content-length&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ApplicationFilterChain : printstatement : req.getHeaderNames() : origin&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ApplicationFilterChain : printstatement : req.getHeaderNames() : x-requested-with&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ApplicationFilterChain : printstatement : req.getHeaderNames() : alfresco-csrftoken&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ApplicationFilterChain : printstatement : req.getHeaderNames() : user-agent&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ApplicationFilterChain : printstatement : req.getHeaderNames() : content-type&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ApplicationFilterChain : printstatement : req.getHeaderNames() : accept&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ApplicationFilterChain : printstatement : req.getHeaderNames() : referer&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ApplicationFilterChain : printstatement : req.getHeaderNames() : accept-encoding&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ApplicationFilterChain : printstatement : req.getHeaderNames() : accept-language&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ApplicationFilterChain : printstatement : req.getHeaderNames() : cookie&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ApplicationFilterChain : printstatement : req.getAttributeNames() java.util.Collections$2@3b0a366&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ApplicationFilterChain : Inside internalDoFilter&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ApplicationFilterChain : Inside internalDoFilter : value of 'pos' : 0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ApplicationFilterChain : Inside internalDoFilter : value of 'n' : 6&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ApplicationFilterChain : internalDoFilter - filters.toString() : [Lorg.apache.catalina.core.ApplicationFilterConfig;@c312851&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ApplicationFilterChain : internalDoFilter - filterConfig.getFilterName() :Agent Filter&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ApplicationFilterChain : internalDoFilter - filter.getClass():class com.sun.identity.agents.filter.AmAgentFilter&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ApplicationFilterChain : internalDoFilter : IS_SECURITY_ENABLED : false&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ApplicationFilterChain : printstatement : req.getHeaderNames() org.apache.tomcat.util.http.NamesEnumerator@41b77f6e&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ApplicationFilterChain : printstatement : req.getHeaderNames() : host&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ApplicationFilterChain : printstatement : req.getHeaderNames() : connection&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ApplicationFilterChain : printstatement : req.getHeaderNames() : content-length&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ApplicationFilterChain : printstatement : req.getHeaderNames() : origin&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ApplicationFilterChain : printstatement : req.getHeaderNames() : x-requested-with&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ApplicationFilterChain : printstatement : req.getHeaderNames() : alfresco-csrftoken&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ApplicationFilterChain : printstatement : req.getHeaderNames() : user-agent&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ApplicationFilterChain : printstatement : req.getHeaderNames() : content-type&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ApplicationFilterChain : printstatement : req.getHeaderNames() : accept&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ApplicationFilterChain : printstatement : req.getHeaderNames() : referer&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ApplicationFilterChain : printstatement : req.getHeaderNames() : accept-encoding&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ApplicationFilterChain : printstatement : req.getHeaderNames() : accept-language&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ApplicationFilterChain : printstatement : req.getHeaderNames() : cookie&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ApplicationFilterChain : printstatement : req.getAttributeNames() java.util.Collections$2@760f3076&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;AmAgentBaseFilter: doFilter: httpRequest.getHeaderNames()&amp;nbsp; : org.apache.tomcat.util.http.NamesEnumerator@5f36cf87&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;AmAgentBaseFilter: httpRequest.getHeaderName : host&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;AmAgentBaseFilter: httpRequest.getHeaderName : connection&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;AmAgentBaseFilter: httpRequest.getHeaderName : content-length&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;AmAgentBaseFilter: httpRequest.getHeaderName : origin&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;AmAgentBaseFilter: httpRequest.getHeaderName : x-requested-with&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;AmAgentBaseFilter: httpRequest.getHeaderName : alfresco-csrftoken&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;AmAgentBaseFilter: httpRequest.getHeaderName : user-agent&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;AmAgentBaseFilter: httpRequest.getHeaderName : content-type&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;AmAgentBaseFilter: httpRequest.getHeaderName : accept&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;AmAgentBaseFilter: httpRequest.getHeaderName : referer&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;AmAgentBaseFilter: httpRequest.getHeaderName : accept-encoding&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;AmAgentBaseFilter: httpRequest.getHeaderName : accept-language&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;AmAgentBaseFilter: httpRequest.getHeaderName : cookie&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;AmAgentBaseFilter: doFilter: httpRequest.getHeader(SsoUserHeader)&amp;nbsp; : null&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;AmAgentBaseFilter: doFilter : filter.getClass() :class com.sun.identity.agents.filter.AmFilter&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;AmFilter: incoming request =&amp;gt; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;———————————————————–&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;HttpServletRequest: class =&amp;gt; org.apache.catalina.connector.RequestFacade&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Character Encoding&amp;nbsp;&amp;nbsp;&amp;nbsp;: null&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Content Lenght&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;: 0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Content Type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;: application/json&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Locale&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;: en_US&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Accept Locales: &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;en_US&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;en&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Protocol&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;: HTTP/1.1&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Remote Address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;: 10.0.2.2&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Remote Host&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;: 10.0.2.2&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Scheme&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;: http&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Server Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;: madura.scimergent.com&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Server Port&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;: 8080&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Is Secure&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;: false&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Auth Type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;: null&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Context Path&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;: /share&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Cookies:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;JSESSIONID: 6B723091722F67624E85A93240F60C1F&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Alfresco-CSRFToken: ifC6fOgUNX%2bMP7vKvQS7xjPWpddCRMdWTHJ2%2bkXvlcg%3d&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;_alfTest: _alfTest&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;amlbcookie: 01&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;iPlanetDirectoryPro: AQIC5wM2LY4SfcziS59cAnPwKSw5GytkcBgxO5UHlZzV60s.*AAJTSQACMDEAAlNLABQtNzg5MjM2MjEzNzY3NjM3NDczNA..*&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Headers:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;host:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;madura.scimergent.com:8080&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;connection:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;keep-alive&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;content-length:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;origin:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="http://madura.scimergent.com:8080" rel="nofollow noopener noreferrer"&gt;http://madura.scimergent.com:8080&lt;/A&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;x-requested-with:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;XMLHttpRequest&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;alfresco-csrftoken:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;ifC6fOgUNX+MP7vKvQS7xjPWpddCRMdWTHJ2+kXvlcg=&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;user-agent:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;content-type:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;application/json&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;accept:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;*/*&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;referer:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="http://madura.scimergent.com:8080/share/page/user/admin/dashboard" rel="nofollow noopener noreferrer"&gt;http://madura.scimergent.com:8080/share/page/user/admin/dashboard&lt;/A&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;accept-encoding:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;gzip, deflate&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;accept-language:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;en-US,en;q=0.8&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;cookie:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;JSESSIONID=6B723091722F67624E85A93240F60C1F; Alfresco-CSRFToken=ifC6fOgUNX%2bMP7vKvQS7xjPWpddCRMdWTHJ2%2bkXvlcg%3d; _alfTest=_alfTest; amlbcookie=01; iPlanetDirectoryPro=AQIC5wM2LY4SfcziS59cAnPwKSw5GytkcBgxO5UHlZzV60s.*AAJTSQACMDEAAlNLABQtNzg5MjM2MjEzNzY3NjM3NDczNA..*&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Method&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;: POST&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Path Info&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;: /dologout&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Path Trans&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;: /opt/tomcat7Alf/webapps/share/dologout&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Query String&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;: null&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Remote User&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;: null&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Requested Session ID&amp;nbsp;&amp;nbsp;&amp;nbsp;: 6B723091722F67624E85A93240F60C1F&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Request URI&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;: /share/page/dologout&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Servlet Path&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;: /page&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Session&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;: true&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;User Principal&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;: &amp;lt;not queried&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Attributes:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;*** No Attributes ***&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;———————————————————–&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;AmFilter: now processing: XSS Detection Task Handler&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;AmFilter: now processing: Notification Task Handler&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;AmFilter: now processing: FQDN Task Handler&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;AmFilter: now processing: Not Enforced List Task Handler&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;AmFilter: now processing: SSO Task Handler&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;AmFilter: now processing: Application Logout Handler&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;AmAgentBaseFilter: doFilter : result : &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;———————————————————–&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;FilterResult:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Status&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;: REDIRECT&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;ProcessResponse&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;: false&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;RedirectURL&amp;nbsp;&amp;nbsp;&amp;nbsp;: &lt;/SPAN&gt;&lt;A href="http://madura.scimergent.com:8081/OpenAM-11.0.0/UI/Logout?goto=http%3A%2F%2Fmadura.scimergent.com%3A8080%2Fshare" rel="nofollow noopener noreferrer"&gt;http://madura.scimergent.com:8081/OpenAM-11.0.0/UI/Logout?goto=http%3A%2F%2Fmadura.scimergent.com%3A8080%2Fshare&lt;/A&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;RequestURL&amp;nbsp;&amp;nbsp;&amp;nbsp;: null&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;RequestHelper: &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;null&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Data: &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;null&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;———————————————————–&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;AmAgentBaseFilter: doFilter : result.getRequestURL() : null&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;AmAgentBaseFilter: doFilter : result.getRedirectURL() : &lt;/SPAN&gt;&lt;A href="http://madura.scimergent.com:8081/OpenAM-11.0.0/UI/Logout?goto=http%3A%2F%2Fmadura.scimergent.com%3A8080%2Fshare" rel="nofollow noopener noreferrer"&gt;http://madura.scimergent.com:8081/OpenAM-11.0.0/UI/Logout?goto=http%3A%2F%2Fmadura.scimergent.com%3A8080%2Fshare&lt;/A&gt;&lt;BR /&gt;&lt;SPAN&gt;AmAgentBaseFilter: doFilter : result.isNotEnforced() : false&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;AmAgentBaseFilter: doFilter : result.getStatus().getIntValue() : 1&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;…After Redirect….&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Jayendran&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Jan 2015 06:59:34 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/sso-with-openam/m-p/252132#M205262</guid>
      <dc:creator>jainmcs03</dc:creator>
      <dc:date>2015-01-08T06:59:34Z</dc:date>
    </item>
  </channel>
</rss>

