Contained WithinFind More DocumentationFeatured Support Resources | Descargar este libro en PDF (538 KB)
Chapter 1 Sun Java System Federation Manager 7.0 Release NotesThe Sun Java™ System Federation Manager 7.0 Release Notes contain important information about the release of Sun Java System Federation Manager, version 7.0. Features, known issues and limitations, and other information are addressed. Read this document before you install and use this release. The Federation Manager 7.0 Release Notes contain the following sections: Revision HistoryThe following table shows the Federation Manager 7.0 Release Notes revision history. Table 1–1 Revision History
Related Third-Party Web SitesThird-party URLs are referenced in this document and provide additional, related information. Note – Sun Microsystems is not responsible for the availability of third-party Web sites mentioned in this document. Sun does not endorse and is not responsible or liable for any content, advertising, products, or other materials that are available on or through such sites or resources. Sun will not be responsible or liable for any actual or alleged damage or loss caused by or in connection with the use of or reliance on any such content, goods, or services that are available on or through such sites or resources. About Sun Java System Federation Manager 7.0Sun Java System Federation Manager 7.0 is the first product to focus on quickly establishing and extending services. Federation Manager 7.0 is a first-generation product that accelerates the introduction of new, revenue-generating services by organizing hub-and-spoke partner networks into secure and trusted domains. Federation Manager allows companies to act as spokes (or service providers) by providing extensible, easy-to-deploy federation solutions. Key features of Federation Manager include:
Hardware and Software RequirementsThe following sections describe hardware and software requirements for this release of Federation Manager. If you have questions about support for other versions of these components, contact your Sun Microsystems technical representative. Data StoresFederation Manager configuration data, user authentication data and user federation data can be managed and retrieved from a database of the following type:
Note – Federation Manager does not come with a user administration system. Platforms and Operating SystemsYou can install Federation Manager on the following platforms running the applicable operating systems. Table 1–2 Operating Systems
Supported Web ContainersFederation Manager can be deployed in the following web containers. CPU and memory requirements are based on the needs of the web container. Table 1–3 Supported Web Containers
Known Issues and LimitationsThis section describes known issues and workarounds, if available, at the time of the release. Issues relevant to all supported operating systems and web containers are collected in this section. Installation and DeploymentThe following issues are related to the installation of Federation Manager and its deployment on the supported web containers.
Error 404-Not Found When Deploying federation.war on WebLogic 8.1 Application Server Under WindowsThe root cause is that Federation Manager can not find the right authentication module XML file due to the use of an incorrect file separator. This problem happens with JDK 1.4.x only. WORKAROUND: Run the following command to add the proper separator before the final start command in the startWeblogic.bat script:
Federation Manager installation error on Linux if Application Server 8 is installed by JES4 (6434059)Federation Manager is based on Access Manager 6.3. Thus, the shared components are conflict with those in JES4 (which includes Access Manager 7.0). WORKAROUND: The following procedure will install Federation Manager correctly.
Escape special characters in silent install file and sample XML files (6431990)Special characters must be escaped (preceded with a back slash) in the silent installation file. Also, after installation, if you want to run the Liberty SSO or SPI samples, you need to edit the metadata XML files and escape the special characters before loading them using the amadmin command line tool. WORKAROUND: Replace & with \&, or a space with \ . For example, rather than defining the INST_ORGANIZATION parameter in the silent installation file as INST_ORGANIZATION=dc=a b & c, use INST_ORGANIZATION=dc=a\ b\ \&\ c. Update the Java Web Services Developer Pack packages before installing on Solaris 9/10. (6334913)A fresh installation of the Solaris Operating System v.9/10 contains older versions of the following packages:
These older versions are numbered 7.x. The newer versions installed by the Federation Manager installer are numbered 1.2.x. Because of this numbering convention, the newer packages will not be installed. Thus, the Java Web Services Developer Pack (JWSDP) packages need to be manually updated prior to installing Federation Manager. If this is not done, the installation might be successful, but a user will not be able to login to the Console due to a java.lang.NoClassDefFoundError exception. Note – The package timestamp can be used to verify which package is older. WORKAROUND: Before installing Federation Manager, use pkginfo -l to check that the shared packages are the supported version as stated in the Sun Java System Federation Manager 7.0 User’s Guide. If an older package is found, remove it manually using pkgrm. The installer will deploy the correct packages. fmwar does not prompt for a JAVA_HOME value. (6333234)fmwar checks for the java file in the /usr/bin/ directory. If that file is present, fmwar assumes all Java components are present which is not always the case. WORKAROUND: Set the JAVA_HOME environment variable to the location of the latest installed release of Java. SUNWjhrt is not installed when JAVA_HOME is not set. (6324701)SUNWjhrt is a shared package that performs an internal check for one of the following versions of Java before the package can be installed:
If none of these versions is found, the installation script will abort, causing Federation Manager installation to fail. WORKAROUND: Install the SUNWj3rt package bundled with the Federation Manager binary. Change to the directory where the Federation Manager binary was unpacked and run the following command from within the common directory: pkgadd -d . SUNWj3rt Alternately, you can download the Java Development Kit (JDK) version 1.5 from the Sun Developer Network and install the SUNWj5rt package from that binary. After installing the correct package, rerun fmsetup to install Federation Manager. Installation fails if space is used in INST_ORGANIZATION property value (6324192)Installation will fail if a space is used between individual components of the root distinguished name (DN). For example, the DN dc=sun, dc=com would cause the installation to fail. dc=sun,dc=com is acceptable. WORKAROUND: Remove any typed space(s) between individual components of the root DN. Stock ticker sample does not work on WebSphere Application Server (6322964)The web service sample does not work when Federation Manager is deployed on WebSphere Application Server. This sample simulates a stock ticker and is located in the /FederationManager-base/SUNWam/fm/samples/liberty/webservices/stockticker directory. WORKAROUND: Copy /usr/share/lib/jax-qname.jar to the classpath in websphere_install_root/WebSphere/AppServer/config/cells/cell-name/nodes/node-name/servers/server-instance/server.xml. For example:
ConfigurationThe following issues are related to configuring Federation Manager.
Exception thrown when transferring configuration data to Sun Java System Directory Server on Solaris 8 (6324142)Service configuration data cannot be migrated from flat file to Directory Server when Directory Server is running on Solaris 8. WORKAROUND: On Solaris 8, before running the fmff2ds migration script, install patch 110165-05. Unable to use default ldapmodify in Solaris 8 against Microsoft Active Directory (6328437)The default version of ldapmodify included with Solaris 8 (Sparc) will not run against Active Directory on a Windows 2000 Advanced Server. WORKAROUND: Before running the fmff2ds script against Active Directory, upgrade your ldapmodify by downloading the Directory Server Resource Kit from http://www.sun.com/download/products.xml?id=3f74a0db. amadmin throws exception when Federation Manager is deployed on BEA WebLogic Server (6320391)After amadmin loads meta data, it uses Remote Procedure Calls (RPC) to send notifications to the server. With WebLogic Server, use jaxrpc 1.0. WORKAROUND: Change the Makefile to bundle the jaxrpc 1.0 jars. Take the following steps after installing with fmsetup:
FederationThe following issues are related to the federation features of Federation Manager. ambulkfed script refers to wrong paths on Linux (6435835)The ambulkfed script federates LDAP users in bulk with remote providers. WORKAROUND: Change the following lines in the ambulkfed script: gettext=/usr/bin/gettext ECHO=/usr/bin/echo RM=/usr/bin/rm to gettext=/bin/gettext ECHO=/bin/echo RM=/bin/rm Single Sign-On Using Artifact Fails when Federation Manager is Deployed in WebSphere Application Server 5.1.1.3 (6431994)WebSphere Application Server 5.1.1.3 bundles an older version of javax.xml.namespace.QName which does not have the getPrefix method. WORKAROUND: After installing Federation Manager, copy fm_staging_dir/web-src/WEB-INF/lib/jax-qname.jar to websphere_install_root/AppServer/lib/qname.jar Web Browser Artifact Profile fails when Federation Manager is Deployed in WebSphere Application Server (6320498)When Federation Manager is deployed in WebSphere Application Server, federation using the Web Browser Artifact Profile fails when the service provider attempts to send an artifact back to the identity provider. WORKAROUND: You must override WebSphere's default SOAP factory by doing the following:
Federation fails when Federation Manager is deployed in WebSphere Application Server and using Secure Sockets Layer (6322995)User federation between an identity provider and a service provider fails when Federation Manager is deployed in WebSphere Application Server and using Secure Sockets Layer (SSL). WORKAROUND: You must find the Java Development Kit (JDK) 1.4 or above and modify WebSphere's server.xml file as described below. server.xml is located in websphere-base/WebSphere/AppServer/config/cells/cell-name/nodes/node-name/servers/server-instance/. The cell-name/node-name/server-instance variables identify the name of the cell/node/server in which Federation Manager is deployed. For example, /opt/WebSphere/AppServer/config/cells/moonriver/nodes/moonriver/servers/server1/server.xml.
Federation fails when Federation Manager is deployed in BEA WebLogic Server and using Secure Sockets Layer (6324673)User federation between an identity provider and a service provider fails when using SSL and Federation Manager is deployed in WebLogic Server. WORKAROUND: Modify the startWebLogic.sh script by adding the following:
Redistributable FilesSun Java System Federation Manager 7 does not contain any files that you can redistribute to non-licensed users of the product. How to Report Problems and Provide FeedbackIf you have problems with Federation Manager, contact Sun customer support using one of the following mechanisms:
So that we can best assist you in resolving problems, please have the following information available when you contact support:
Sun Welcomes Your FeedbackSun Microsystems is interested in improving its documentation and welcomes your comments and suggestions. To share your thoughts, go to http://docs.sun.com and click the Send Comments link at the top or bottom of the page. In the online form provided, include the document title and part number. The part number is a seven-digit or nine-digit number that can be found on the title page of the book or at the top of the document. For example, the title of this book is Sun Java System Federation Manager 7 Release Notes, and the part number is 819–2400. Additional Sun ResourcesFor product downloads, professional services, patches, support, and additional developer information, go to the following locations: If you have technical questions about any Sun products, contact Sun Support and Services. |
||||||||||||||||||||||||||||||