Configuring general settings for a realm
The following table describes realm settings on the General tab that you need to configure:
Field | Action |
---|---|
Realm ID | Enter a realm name. The value that you enter must satisfy the following requirements:
|
Application Domain(s) | Enter comma-separated domain names of applications integrated with BMC Helix SSO. Each value in the application domain is a host of an application URL of a tenant. For example, if the URL for the Mid Tier application is http://tenant1.midtier.company.com/arsys, the host will be tenant1.midtier.company.com. Ensure that all applications of a tenant have a corresponding value in the application domain string. For example, consider that you created realm1 for a tenant that has two applications with the following URLs:
In this scenario, for realm1, the application domain value will be a comma-separated string of tenant1.midtier.company.com and tenant1.dwp.company.com. You can define the application domain by using one of the following patterns:
Example: <hostname>.calbro.bmc.com is a fully qualified domain name. calbro is a subdomain of bmc.com bmc is a subdomain of com com is the parent domain. Important:
|
(Optional) Tenant | Enter a tenant name of the integrated applications. Important: You can associate a realm with only one application tenant. (Version 22.3.01 and later) If you select the Invalidate Sessions On Tenant Change check box, all tokens and sessions of users who are logged in within this realm are invalidated when the is tenant changes. |
(Optional) After Logout URL | Enter the URL to which a user is redirected after the user logs out from BMC Helix SSO. |
(Optional) Single Log Out | Select this check box to enable the single logout option for end users. When the single logout experience is enabled, if an end user clicks the logout URL in one application, the user is automatically logged out from the BMC Helix SSO server and, as a result, from all applications belonging to the user's realm. When the single logout experience is disabled, if an end user clicks the logout URL in one application, the user is still logged in to BMC Helix SSO server if the user is simultaneously logged in to at least one application. The BMC Helix SSO agent maintains a cache. Therefore, for applications that are open in other browser tabs, single log out occurs after a short delay. For an enhanced single logout experience for users, see Configuring-BMC-Helix-SSO-to-support-immediate-logout-from-all-applications. |
Session Quota | For security reasons, you might need to configure the number of active sessions or simultaneous logins for a particular realm. You can also decide whether to invalidate an older session or not allow the user to log in to a new session and display an error message. In this field, you can enter the number of active sessions or simultaneous logins for a particular user. Enter one of the following values:
Important: If you select the Automatically invalidate oldest session on reaching quota check box, and if a user exceeds the number of logins, the user can log in, but will get logged out from the oldest session. If you do not select this option, the user cannot log in to any session beyond the entered value and the following error message is displayed: Exceeded session quota limit. |
The following Action Request System server details fields are available if the Fetch AR user info option is selected for the tenant:
Field name | Description |
---|---|
AR API URL | Enter the URL of the Action Request System server (AR System server) API. |
AR Integration User Name | Enter the user name to be used to access the AR System server. Important:
|
AR Integration User Password | Enter the password for the specified user name to access the AR System server. |