---
title: Install DS for AM CTS
description: Install PingDS as a CTS token store for PingAM, with options for managing token expiration using PingAM or PingDS.
component: pingds
version: 7.5
page_id: pingds:install-guide:profile-am-cts
canonical_url: https://docs.pingidentity.com/pingds/8.1/install-guide/profile-am-cts.html
llms_txt: https://docs.pingidentity.com/pingds/llms.txt
docs_for_agents: https://developer.pingidentity.com/build-with-ai/docs-for-agents.md
revdate: 2023-12-19T09:00:59Z
keywords: ["CTS Store (Sessions &amp; Tokens)", "Install", "LDAP", "Setup &amp; Configuration"]
superseded_by: https://docs.pingidentity.com/pingds/8.1/install-guide/profile-am-cts.html
---

# Install DS for AM CTS

1. Before proceeding, install the server files.\
   For details, refer to [Unpack files](install-files.html).

2. Run the appropriate `setup` command with the `--profile am-cts` option.

   |   |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
   | - | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
   |   | Installation settings depend on AM token expiration and session capability requirements. Letting DS expire tokens is efficient, but affects sending AM notifications about session expiration and timeouts to AM policy agents.- Learn about AM token expiration options in [Manage expired CTS tokens](https://docs.pingidentity.com/pingam/7.5/cts/cts-reaper.html).

   - Learn about the mechanism DS uses to expire tokens in [Entry expiration](../config-guide/import-export.html#backend-ttl). |

   1. AM reaper manages all token expiration (AM default):

      ```bash
      $ /path/to/opendj/setup \
       --deploymentId $DEPLOYMENT_ID \
       --deploymentIdPassword password \
       --rootUserDN uid=admin \
       --rootUserPassword str0ngAdm1nPa55word \
       --monitorUserPassword str0ngMon1torPa55word \
       --hostname ds.example.com \
       --adminConnectorPort 4444 \
       --ldapPort 1389 \
       --enableStartTls \
       --ldapsPort 1636 \
       --httpsPort 8443 \
       --replicationPort 8989 \
       --bootstrapReplicationServer rs1.example.com:8989 \
       --bootstrapReplicationServer rs2.example.com:8989 \
       --profile am-cts \
       --set am-cts/amCtsAdminPassword:5up35tr0ng \
       --acceptLicense
      ```

   2. AM reaper manages only SESSION token expiration:

      ```bash
      $ /path/to/opendj/setup \
       --deploymentId $DEPLOYMENT_ID \
       --deploymentIdPassword password \
       --rootUserDN uid=admin \
       --rootUserPassword str0ngAdm1nPa55word \
       --monitorUserPassword str0ngMon1torPa55word \
       --hostname ds.example.com \
       --adminConnectorPort 4444 \
       --ldapPort 1389 \
       --enableStartTls \
       --ldapsPort 1636 \
       --httpsPort 8443 \
       --replicationPort 8989 \
       --bootstrapReplicationServer rs1.example.com:8989 \
       --bootstrapReplicationServer rs2.example.com:8989 \
       --profile am-cts \
       --set am-cts/amCtsAdminPassword:5up35tr0ng \
       --set am-cts/tokenExpirationPolicy:am-sessions-only \
       --acceptLicense
      ```

   3. DS manages all token expiration:

      ```bash
      $ /path/to/opendj/setup \
       --deploymentId $DEPLOYMENT_ID \
       --deploymentIdPassword password \
       --rootUserDN uid=admin \
       --rootUserPassword str0ngAdm1nPa55word \
       --monitorUserPassword str0ngMon1torPa55word \
       --hostname ds.example.com \
       --adminConnectorPort 4444 \
       --ldapPort 1389 \
       --enableStartTls \
       --ldapsPort 1636 \
       --httpsPort 8443 \
       --replicationPort 8989 \
       --bootstrapReplicationServer rs1.example.com:8989 \
       --bootstrapReplicationServer rs2.example.com:8989 \
       --profile am-cts \
       --set am-cts/amCtsAdminPassword:5up35tr0ng \
       --set am-cts/tokenExpirationPolicy:ds \
       --acceptLicense
      ```

   In the preceding example commands:

   * The deployment ID for installing the server is stored in the environment variable `DEPLOYMENT_ID`. Install all servers in the same deployment with the same deployment ID and deployment ID password. For details, read [Deployment IDs](../security-guide/pki.html#about-deployment-ids).

   * The service account to use in AM when connecting to DS has:

     * Bind DN: `uid=openam_cts,ou=admins,ou=famrecords,ou=openam-session,ou=tokens`.

     * Password: The password you set with `am-cts/amCtsAdminPassword`.

   * The base DN for AM CTS tokens is `ou=famrecords,ou=openam-session,ou=tokens`.

     AM and IDM expect exclusive access to the data in each setup profile. *Keep the data separate by using distinct base DNs and domains for each setup profile.* Don't accidentally mix the data by choosing a base DN under another base DN.

   * The `am-cts` profile excludes the base DN from change number indexing.

   For the full list of profiles and parameters, refer to [Default setup profiles](setup-profiles.html#default-setup-profiles).

3. Finish configuring the server *before you start it*.

   For a list of optional steps at this stage, refer to [Install DS for custom cases](custom-replica.html).

4. Start the server:

   ```bash
   $ /path/to/opendj/bin/start-ds
   ```
