integrating open am with liferay portal

Integrating OpenAM with Liferay Portal 2013 Integrating OpenAM with Liferay Portal on Tomcat Liferay Portal and OpenAM both require a minimum 1.6 JVM. Make sure that your JAVA_HOME environment variable is correctly set to point to your Java 6 installation. For OpenSSO to work correctly with Liferay Portal, both servers need to be running in the same domain. To solve this issue while running both servers on a single machine, edit the hosts file (/etc/hosts or %SystemRoot%system32driversetc) and add/update your localhost entry: localhost where is your actual domain. Install Liferay Portal : Liferay Portal is an open source portal. Liferay comes in two editions, Enterprise Edition (EE) and Community Edition (CE). Installation consisted of: 1.Unzip to a directory. This will create a liferay-portal-5.2.3 folder. On Linux/MacOS, you will need to add execute permissions to all of the shell scripts in the bin directory: chmod +x *.sh 2.In liferay-portal-5.2.3/tomcat-6.0.18/bin/, executing (or startup.bat) will start Tomcat, and deploy Liferay Portal. 3.Open a browser to, and you will see the Liferay login page. You can login with [email protected]/test . Install OpenSSO/OpenAM : Created by Prabhakaran Page 1

Upload: prabakaranbrick

Post on 15-Dec-2014




3 download




Page 1: Integrating open am with liferay portal

Integrating OpenAM with Liferay Portal 2013

Integrating OpenAM with Liferay Portal on Tomcat

Liferay Portal and OpenAM both require a minimum 1.6 JVM. Make sure that your JAVA_HOME environment variable is correctly set to point to your Java 6 installation.

For OpenSSO to work correctly with Liferay Portal, both servers need to be running in the same domain. To solve this issue while running both servers on a single machine, edit the hosts file (/etc/hosts or %SystemRoot%system32driversetc) and add/update your localhost entry: localhost

where is your actual domain.

Install Liferay Portal :

Liferay Portal is an open source portal. Liferay comes in two editions, Enterprise Edition (EE) and Community Edition (CE).

Installation consisted of:

1.Unzip to a directory. This will create a liferay-portal-5.2.3 folder.

On Linux/MacOS, you will need to add execute permissions to all of the shell scripts in the bin directory: chmod +x *.sh

2.In liferay-portal-5.2.3/tomcat-6.0.18/bin/, executing (or startup.bat) will start Tomcat, and deploy Liferay Portal.

3.Open a browser to, and you will see the Liferay login page. You can login with [email protected]/test.

Install OpenSSO/OpenAM :

OpenSSO is an open source access management and federation server platform. Announced by Sun Microsystems in July 2005, OpenSSO was based on Sun Java System Access Manager, and was the core of Sun’s commercial access management and federation product, OpenSSO Enterprise (formerly Sun Access Manager and Sun Federation Manager). Oracle completed their acquisition of Sun Microsystems in February 2010 and announced that OpenSSO would no longer be their strategic product. OpenSSO will continue to be developed and supported by ForgeRock under the name of OpenAM. from ForgeRock -

Created by Prabhakaran Page 1

Page 2: Integrating open am with liferay portal

Integrating OpenAM with Liferay Portal 2013

As OpenAM also requires a servlet container, Download the latest Tomcat (6.0.29).

Installation of the Tomcat server consisted of:

1.Unzip apache-tomcat-6.0.29 zip file. This will create an apache-tomcat-6.0.29 folder.

2.As both Liferay Portal and OpenAM will be running on the same machine, to update the ports that the OpenAM Tomcat server was using.

Edit apache-tomcat-6.0.29/conf/server.xml. change all of the ports from 8xxx to 9xxx. For example, 8080 to 9080, 8443 to 9443, etc.

On Linux/MacOS, you will need to add execute permissions to all of the shell scripts in the bin directory: chmod +x *.sh

3.Edit (or catalina.bat) and add the following line to the start of the file, after the comment block listing the various Environment Variable Prequisites:

Linux/MacOS: JAVA_OPTS="$JAVA_OPTS -Xmx1024m -XX:MaxPermSize=256m"

Windows: set JAVA_OPTS="%JAVA_OPTS% -Xmx1024m -XX:MaxPermSize=256m"

Installation of OpenAM consisted of:

To Deploy OpenAM

The openam-server-10.1.0-Xpress.war file contains all OpenAM server components and samples. How you deploy the .war file depends on your web application container.

1. Deploy the .war file on your container.

For example, copy the file to deploy on Apache Tomcat webapps directory.

2. After Tomcat has deployed OpenAM, you will see the exploded war file as apache-tomcat-6.0.29/webapps/openam

3. Open a browser to, which should redirect you to, to complete the OpenAM configuration..

Created by Prabhakaran Page 2

Page 3: Integrating open am with liferay portal

Integrating OpenAM with Liferay Portal 2013

4. You should see the OpenAM configuration options page. Under Custom Configuration click Create New Configuration. Enter the following

Default User Password — password

5. Server Settings — default entries are ok

Created by Prabhakaran Page 3

Page 4: Integrating open am with liferay portal

Integrating OpenAM with Liferay Portal 2013

6. Configuration Data Store Settings — select First Instance, select OpenAM as Configuration Data Store, leave other entries

7. User Data Store Settings — select OpenAM User Data Store

Created by Prabhakaran Page 4

Page 5: Integrating open am with liferay portal

Integrating OpenAM with Liferay Portal 2013

8. Site Configuration — select No

9. Default Policy Agent User — policy01 (password/password)

Created by Prabhakaran Page 5

Page 6: Integrating open am with liferay portal

Integrating OpenAM with Liferay Portal 2013

10. Configurator Summary Details – click Create Configuration. This will create the configuration for your OpenAM server under ~/opensso (or c:Documents and Settings{username}opensso).

11. When this completes, in the Configuration Complete dialog, click Proceed to Login, which should now redirect you to amAdmin as the username, password as the password, and click Log In. You should now see the OpenAM Console.

Created by Prabhakaran Page 6

Page 7: Integrating open am with liferay portal

Integrating OpenAM with Liferay Portal 2013

Additional OpenAM Configuration

To get OpenAM to work correctly with Liferay, you need to set Encode Cookie Value to Yes. This will prevent infinite redirection between Liferay and OpenAM on login.

1.In the OpenAM Console, select the Configuration tab.

Created by Prabhakaran Page 7

Page 8: Integrating open am with liferay portal

Integrating OpenAM with Liferay Portal 2013

2.Select the Servers and Sites tab.

3.Click Default Server Settings.

4.Select the Security tab.

Created by Prabhakaran Page 8

Page 9: Integrating open am with liferay portal

Integrating OpenAM with Liferay Portal 2013

5.In the Cookie section, select the Yes checkbox beside Encode Cookie Value.

6.Click Save.

Before updating Liferay to use OpenAM, I recommend adding the default Liferay user, [email protected], to OpenAM.

1.In the OpenAM Console, select the Access Control tab and Click the / (Top Level Realm) realm.

Created by Prabhakaran Page 9

Page 10: Integrating open am with liferay portal

Integrating OpenAM with Liferay Portal 2013

2. Select the Subjects tab.

Created by Prabhakaran Page 10

Page 11: Integrating open am with liferay portal

Integrating OpenAM with Liferay Portal 2013

3.Click New…

Setup the default Liferay user:

ID — joebloggs

First Name — Joe

Last Name — Bloggs

Full Name — Joe Bloggs

Password — password

Click OK to create the user.

4.Click Joe Bloggs to add the email address. Enter [email protected] for the Email Address, and click Save.

Created by Prabhakaran Page 11

Page 12: Integrating open am with liferay portal

Integrating OpenAM with Liferay Portal 2013

Integrate Liferay Portal with OpenAM

Now you are ready to update Liferay Portal to integrate with OpenAM for authentication

1.If Liferay is running, shut it down (bin/shutdown).

2.Create a new file, called, in your Liferay directory, under liferay-portal-5.2.3/tomcat-6.0.18/webapps/ROOT/WEB-INF/classes/.

3.Edit this file, and add the following properties:

Created by Prabhakaran Page 12

Page 13: Integrating open am with liferay portal

Integrating OpenAM with Liferay Portal 2013

4.Start Liferay (bin/startup).

5.Once Liferay has started, open a browser to, and you should be redirected to the OpenAM login page

Enter joebloggs for the User Name, and password for the Password. Click Log In.

You will be authenticated against OpenAM, and redirected to Liferay.

Created by Prabhakaran Page 13

Page 14: Integrating open am with liferay portal

Integrating OpenAM with Liferay Portal 2013

Now that Liferay is using OpenAM for authentication, if you create a new user in OpenAM, that user will also be created in Liferay on the first log in. That newly created user in Liferay will only have the basic information filled in – First Name, Last Name, Screenname, Email Address – and will have the default Roles, Groups, and Organizations assigned.






Created by Prabhakaran Page 14