Create the J2EE agent profile with the following settings:
-
Server URL http://www.idp.com:8888/openam
-
Agent URL http://demo.forgerock.com:8080/agentapp
-
Under Global settings change the Agent filter mode from ALL to SSO_ONLY
-
Under Application > Session Attributes Processing change the Session Attribute Fetch Mode from none to HTTP_Header
-
Under Application > Session Attributes Processing > Session Attribute Mappings add UserToken=username and sunIdentityUserPassword=password
-
Under SSO > Cross Domain SSO select the Enabled checkbox. If you have installed OpenAM in the forgerock.com domain you do not need to enable cross domain SSO.

