---
title: Install DS for platform identities
description: Install PingDS as a platform identity repository for PingAM or a shared identity store for PingAM and PingIDM.
component: pingds
version: 7.5
page_id: pingds:install-guide:profile-am-idrepo
canonical_url: https://docs.pingidentity.com/pingds/8.1/install-guide/profile-am-idrepo.html
llms_txt: https://docs.pingidentity.com/pingds/llms.txt
docs_for_agents: https://developer.pingidentity.com/build-with-ai/docs-for-agents.md
revdate: 2024-05-13T16:21:23Z
keywords: ["Identities", "Identity Store", "Install", "LDAP", "Setup &amp; Configuration"]
superseded_by: https://docs.pingidentity.com/pingds/8.1/install-guide/profile-am-idrepo.html
---

# Install DS for platform identities

Use this profile when setting up DS as an identity repository and user data store for AM alone or shared with IDM in a Ping Identity Platform deployment. It includes the additional LDAP schema and indexes required to store the identities:

|   |                                                                                                                                                                                                                                                                                                                                                                       |
| - | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|   | When AM and IDM share multiple DS replicas for identities:- Configure IDM for [failover](https://docs.pingidentity.com/pingidm/7.5/install-guide/external-ds.html#two-ds-active-passive).

- Configure AM to fail over when [connecting to DS replicas](https://docs.pingidentity.com/pingam/7.5/setup/data-stores-opendj.html#ldap_server) in the same order as IDM. |

1. Before proceeding, install the server files.\
   For details, refer to [Unpack files](install-files.html).

2. Run the `setup` command with the `--profile am-identity-store` option:

   ```bash
   $ /path/to/opendj/setup \
    --deploymentId $DEPLOYMENT_ID \
    --deploymentIdPassword password \
    --rootUserDN uid=admin \
    --rootUserPassword str0ngAdm1nPa55word \
    --monitorUserPassword str0ngMon1torPa55word \
    --hostname ds.example.com \
    --adminConnectorPort 4444 \
    --ldapPort 1389 \
    --enableStartTls \
    --ldapsPort 1636 \
    --httpsPort 8443 \
    --replicationPort 8989 \
    --bootstrapReplicationServer rs1.example.com:8989 \
    --bootstrapReplicationServer rs2.example.com:8989 \
    --profile am-identity-store \
    --set am-identity-store/amIdentityStoreAdminPassword:5up35tr0ng \
    --acceptLicense
   ```

   * The deployment ID for installing the server is stored in the environment variable `DEPLOYMENT_ID`. Install all servers in the same deployment with the same deployment ID and deployment ID password. For details, read [Deployment IDs](../security-guide/pki.html#about-deployment-ids).

   * The service account to use in AM when connecting to DS has:

     * Bind DN: `uid=am-identity-bind-account,ou=admins,ou=identities`.

     * Password: The password you set with `am-identity-store/amIdentityStoreAdminPassword`.

   * The base DN for AM identities is `ou=identities`.

     AM and IDM expect exclusive access to the data in each setup profile. *Keep the data separate by using distinct base DNs and domains for each setup profile.* Don't accidentally mix the data by choosing a base DN under another base DN.

   For the full list of profiles and parameters, refer to [Default setup profiles](setup-profiles.html#default-setup-profiles).

3. Finish configuring the server *before you start it*.

   For a list of optional steps at this stage, refer to [Install DS for custom cases](custom-replica.html).

4. Start the server:

   ```bash
   $ /path/to/opendj/bin/start-ds
   ```
