
Topics Covered
PingAM Course index
Explore IAM overview, SSO overview, ForgeRock overview, and BackStage overview to understand identity and access management across ForgeRock platforms.
Install ForgeRock AM on Windows using default or custom configurations, compare embedded versus external OpenDJ, configure config store and user store, and connect with Apache Directory Studio for LDAP access.
Explore the PingAM folder structure, including the ds folder and audit logs, and learn how debug logs, user store, config store, and token store support troubleshooting and auditing.
Learn to install Java and Tomcat on Ubuntu Linux for PingAM. Follow practical steps to complete Java and Tomcat installation on a Linux system.
Install PingAM on Linux and configure authentication modules. Learn to set up authentication chains for secure access.
Explore self-service user account recovery by configuring forgot username and forgot password flows. Learn to use security questions, email verification, and customizable email templates to verify identity and reset credentials.
Install and configure the authentication API in Postman, trace authentication flows from browser and Postman, and explore ForgeRock authentication trees and MFA options like HOTP and OTP.
Explore PingAM authentication nodes and trees, deploy via docker, call external APIs with http client nodes, and customize with open source Java nodes and jar deployment.
Examine authentication nodes in PingAM, emphasizing tree structures in the Trees-3 module to illustrate their role within the course.
Explore authentication nodes in PingAM, focusing on the scripted decision node in tree 5 to guide authentication flows.
Master OAuth2 overview and the authorization code grant type, and learn to execute Postman API requests for PingAM authentication.
Explore PingAM authentication flows, including implicit grant and authorization code PKCE grant type, using Postman API to test and configure secure access.
Learn how to analyze the PingAM log folder structure, diagnose issues, and enable or disable audit logging to ensure reliable activity tracking in ForgeRock PingAM.
explore hci customization of the digital interface by branding header, footer, and body; learn prerequisites, download source code, install eclipse or intellij, and deploy a custom xui node using maven.
Explore XUI customization, deployment, and validation for PingAM, and learn how to configure, deploy, and validate PingAM components within ForgeRock.
Begin by building a Java custom node for PingAM, focusing on prerequisites and the download and setup of required software.
Build a Java custom node for PingAM, deploy it, and validate the deployment to ensure proper integration within ForgeRock PingAM.
Build a custom scripted decision node in PingAM to access data from DS and construct the logic that drives access decisions.
Generate a self-signed certificate with keytool and configure it in Tomcat's server.xml to enable https on port 8443. Import the certificate into the truststore to allow ssl connections for applications.
ForgeRock PingAM is an access management tool for authentication and authorization. It's one of the products in the ForgeRock stack. ForgeRock PingAM provides different types of user authentication, such as the Authentication module. Authentication tree, Authentication chains, Federation(SAML2), OpenID Connect(OIDC)/OAuth2, Multifactor Authentication etc..
In this course, we provide end-to-end PingAM installation with multiple containers, the configuration of the authentication module, chains, and tree, Federation(SAML2) configuration, OIDC configuration, OAuth2 Configuration, sample application integration with PingAM, Rest-endpoints configuration in Postman, etc.
ForgeRock mainly provides the following products.
1. PingAM
2. PingDS
3. PingIDM
4. PingIG
ForgeRock products are open source projects until version 13.0, and the naming convention of each product starts with Open. Download the source code with a free subscription and make the changes according to the requirement.
After the 13.0 version, the products are commercial and require a paid subscription to download the source code to customize the source code. And also, the product naming convention changed, like removing the Open keyword. But we can download the software/binary file to practice in the lower environment or personally.
The new product's name is as follows.
1. PingAM (formerly AM - Access Management)
2. PingDS (formerly DS - Directory Services)
3. PingIDM (formerly IDM - Identity Management)
4. PingIG (formerly IG - Identity Gateway)
PingAM - (AM - Access Management)
PingAM originated as OpenSSO, it's created by Sun Microsystems and now owned by Oracle Corporation.
PingAM provides authentication and authorization in multiple ways. Here, summarize and share the PingAM's most important and frequently used features.
Realm
Self Service
Registration
Forgot Username
Forgot Password
Authentication Modules
Authentication Chains
Authentication Nodes(Trees)
Log in with Social - Google, Facebook, LinkedIn, etc...
OAuth2
OIDC
SAML2.0
PingAM - IDP
PingAM - SP
Customization
XUI (User interface)
Java custom node
Scripted Decision Node - Create Script by using JavaScript & Groovy
SAML SP Adapter Script
SAML IDP Adapter Script
OAuth2 Access Token Claims Script
Agents (Java/Web)
Dynamic Client Registration
Audit Logging
Debug Logging
Replication (Multiple Instances)
Policy Configuration
PingAM Rest API