Possible outdated information
PLEASE NOTE: This page may be out of date and could contain inaccuracies. In future it may be significantly revised or removed altogether.
Using the ssoadm command
Have you ever been frustrated by the ssoadm command. You know how to change a setting in the GUI, but how can you set the property on the command line? This document tells you how!
Updating a global attribute using
First you need to determine the setting you want to change, in this example lets decide we want to change the maximum session time.
Is it a global attribute?
If the attribute is a global attribute then it is shown under the Configuration tab and not under the Access Control tab.
If we login to the OpenAM console and navigate to the Configuration >> Global >> Session service we see the following service defaults.
Dynamic attributes shown under the configuration tab are the default values for this service. If you have not associated a service with a realm then these are the values that will be used by OpenAM.
So we want to change the default
Maximum Session Time attribute value to 240. To use the ssoadm command to do this we need to know the internal name of the attribute within OpenAM. This is a simple process, if you know how.
Find the correct service
In the console we can see that this service is called
Session so we can use that as our starting point. We need to find the following information before we can run the
- The name of the service where the attribute is stored.
- The name of the attribute we want to update.
What does OPENAM_DEPLOY_DIR mean?
Replace this with the path to where you have deployed OpenAM. For example:
Firstly lets match the name of the service in the console to the service's properties file. The property file will lead us to the information we required.
This determines that the name of the service definition file is
amSession. The OpenAM service definition files are stored in the same directory as the properties files.
Find the correct attribute
Now we have found the correct service to search, we need to find the specific attribute. Search the property file for the attribute name;
Maximum Session Time in our example.
Now you need to find the name of the attribute, run another grep command.
The attribute name is
iplanet-am-session-max-session-time. The final piece of information we need is the name of the service, time for another
So this means the service name is
iPlanetAMSessionService and armed with this information we can run the
ssoadm command as usual.
What does the -t flag mean?
This tells ssoadm the section of the service definition the attribute resides; from the console we have
organization (means realm) and
Updating a realm attribute using
If we wanted to perform exactly the same action on the same attribute, but at the realm level then you need to perform the same steps as shown above to determine the name of the service and the name of the attribute. The
ssoadm command you run is different.
This will set the attribute on the Session service in the
test sub-realm. The
/ indicates the
test sub-realm is directly beneath the top-level realm.