8.3.2. Tomcat Agent Profile

Create the J2EE agent profile with the following settings:

  • Server URL http://www.idp.com:8888/openam

  • Agent URL http://demo.forgerock.com:8080/agentapp

  • Under Global settings change the Agent filter mode from ALL to SSO_ONLY

  • Under Application > Session Attributes Processing change the Session Attribute Fetch Mode from none to HTTP_Header

  • Under Application > Session Attributes Processing > Session Attribute Mappings add UserToken=username and sunIdentityUserPassword=password

  • Under SSO > Cross Domain SSO select the Enabled checkbox. If you have installed OpenAM in the forgerock.com domain you do not need to enable cross domain SSO.