---
title: "Step-by-Step Setup"
canonical: "https://sesame-software-documentation.refined.site/space/bandr/372113410/Step-by-Step%20Setup"
format: markdown
---
## **🔹 Step 1: Install Java 17**

### ⚙️ **For Windows:**

- Download and install OpenJDK 17 from:
  - [Azul Zulu](https://www.azul.com/downloads/)
  - [Eclipse Adoptium](https://adoptium.net/)
- Verify installation by running in Command Prompt:

`java -version`

### **For Linux:**

**Ubuntu/Debian:**

`sudo apt update`

`sudo apt install openjdk-17-jdk`

**CentOS/RHEL:**

`sudo yum install java-17-openjdk-devel`

Verify installation:

`java -version`

---

## **🔹 Step 2: Extract the BandR Zip File**

### ⚙️ **For Windows:**

- Right-click the BandR zip file and choose "Extract All."
- Locate the extracted `BandR` directory containing:
  - `application.properties`: Configuration file.
  - `bandr.jar`: Executable JAR.
  - `README.txt`: Additional instructions.

### ⚙️ **For Linux:**

`unzip BandR.zip`

`cd BandR`

---

## **🔹 Step 3: Select Your Database Dialect**

Choose one supported dialect:

- **Microsoft SQL Server**
- **PostgreSQL**
- **Oracle (Requires JVM Settings:** `-Doracle.jdbc.J2EE13Compliant=true` **)**

---

## **🔹 Step 4: Update the application.properties File**

Open `application.properties` and configure the following sections.

### ⚙️ **Hikari (JDBC) Properties**

Update these properties to match your database configuration.

- **jdbc-url:** Replace `{host}` and `{port}` with your database details.
  - **SQL Server:**

`spring.datasource.hikari.jdbc-url=jdbc:sqlserver://{host}:{port};databaseName=RJBANDR;encrypt=true;trustServerCertificate=true;`

- **PostgreSQL:**

`spring.datasource.hikari.jdbc-url=jdbc:postgresql://{host}:{port}/RJBANDR`

- **Oracle:**

`spring.datasource.hikari.jdbc-url=jdbc:oracle:thin:@{host}:{port}/RJBANDR`

- **driver-class-name:**
  - SQL Server: `com.microsoft.sqlserver.jdbc.SQLServerDriver`
  - PostgreSQL: `org.postgresql.Driver`
  - Oracle: `oracle.jdbc.driver.OracleDriver`
- **username:**

`spring.datasource.hikari.username=<your-database-username>`

- **password:** *(You can encrypt this, see Section C below)*

`spring.datasource.hikari.password=<your-database-password>`

- **schema:**

`spring.datasource.hikari.schema=<your-database-schema>`

- **catalog:** (default is `RJBANDR`)

`spring.datasource.hikari.catalog=RJBANDR`

### ⚙️ **JPA Properties**

Set these properties to match your selected database platform.

- **database-platform:**
  - SQL Server:

`spring.jpa.database-platform=org.hibernate.dialect.SQLServerDialect`

- PostgreSQL:

`spring.jpa.database-platform=org.hibernate.dialect.PostgreSQLDialect`

- Oracle:

`spring.jpa.database-platform=org.hibernate.dialect.OracleDialect`

- **generate-ddl:**

`spring.jpa.hibernate.ddl-auto=update`

- **show-sql:**

`spring.jpa.show-sql=true`

### ⚙️ **Encrypt Sensitive Properties with Jasypt**

To secure sensitive values, use **Jasypt encryption**.

#### **Step 1: Encrypt a Value**

Run the following command to encrypt your sensitive value:

`jasypt encrypt input="your_password" password="Sesame2!3" algorithm=PBEWITHHMACSHA512ANDAES_256`

You will get an encrypted output like:

`abcDEF1234567890==`

Wrap the result in `ENC()` in your properties file:

`spring.datasource.hikari.password=ENC(abcDEF1234567890==)`

#### **Step 2: Pass the Encryption Password at Runtime**

- **Windows Command Prompt:**

`java -Djasypt.encryptor.password=Sesame2!3 -jar bandr.jar --spring.config.location=file:"C:\\path\\to\\QA\\application.properties"`

- **Linux Terminal:**

`java -Djasypt.encryptor.password=Sesame2!3 -jar bandr.jar --spring.config.location=file:$(pwd)/application.properties`

#### **Step 3: Repeat for Other Sensitive Fields**

You can encrypt additional sensitive values like LDAP passwords, API keys, etc.

🗒️ **Note:** Always store your encryption password securely (avoid placing it in the properties file).

---

## **🔹 Step 5: Prepare Your Database**

- Create a database matching your configured catalog name (default: `RJBANDR`).
- Grant necessary permissions to your specified database user.
- Verify that the user has privileges to create tables, insert, update, and delete records.

‌

---

## **🔹 Step 6: Run the Application**

### ⚙️ **For Windows:**

Navigate to the directory containing `bandr.jar` and execute:

`java -jar bandr.jar --spring.config.location=file:"C:\\path\\to\\QA\\application.properties"`

### ⚙️ **For Linux:**

`java -jar bandr.jar --spring.config.location=file:$(pwd)/application.properties`

**Important Notes:**

- Enclose paths with spaces in quotes.
- Ensure you are using Java 17.
- Make sure port 8080 is available and not used by another application.

---

## **🔹 Step 7: Access the BandR UI**

Once the application starts, navigate to:

`http://localhost:8080/admin/dashboard`

Verify the application is running and the UI is accessible.

---

## **🔹 Step 8: Configure SSO (Microsoft Entra)**

### ⚙️ **App Registration**

- Register a new application in Microsoft Entra (Azure AD).
- Reference:[ Baeldung Guide](https://www.baeldung.com/spring-boot-azuread-authenticate-users)

### ⚙️ **App Details**

- Record endpoints and client details from the app registration.

### ⚙️ **Create Client Secret**

- Under "Certificates & Secrets," create a new client secret.

### ⚙️ **BandR System Properties for SSO**

Add these properties to your environment or as JVM arguments:

`SESAME_AUTH_METHOD=sso`

`SESAME_OAUTH2_REGISTRATION_ID=<registrationId>`

`SESAME_OAUTH2_CLIENT_ID=<clientId>`

`SESAME_OAUTH2_CLIENT_SECRET=<clientSecret>`

`SESAME_OAUTH2_AUTH_URI=<authUri>`

`SESAME_OAUTH2_TOKEN_URI=<tokenUri>`

`SESAME_OAUTH2_JWK_SET_URI=https://login.microsoftonline.com/common/discovery/v2.0/keys`

`SESAME_OAUTH2_USERNAME_ATT=<userNameAttribute>`

`SESAME_OAUTH2_CLIENT_NAME=<clientName>`

### ⚙️ **Alternative: application.properties**

`rj.auth-method=sso`

`rj.oauth2.registrationId=<registrationId>`

`rj.oauth2.clientId=<clientId>`

`rj.oauth2.clientSecret=<clientSecret>`

`rj.oauth2.authorizationUri=<authUri>`

`rj.oauth2.tokenUri=<tokenUri>`

`rj.oauth2.jwkSetUri=<jwkSetUri>`

`rj.oauth2.userNameAttributeName=<userNameAttribute>`

`rj.oauth2.clientName=<clientName>`

### ⚙️ **Group / Role Mappings**

- Configure token claims in the Azure AD App's "Token Configuration."

---

## **🔹 Step 9: Configure SAML Login (Optional)**

### ⚙️ **References**

- [Spring Boot and SAML](https://developer.okta.com/blog/2022/08/05/spring-boot-saml)
- [Spring Security Samples](https://github.com/spring-projects/spring-security-samples/tree/main/servlet/spring-boot/java/saml2)
- [Baeldung SAML Guide](https://www.baeldung.com/spring-security-saml)

### ⚙️ **Get Started**

- Use Okta or another SAML provider.
- Set up your SAML application and obtain metadata.

### ⚙️ **SAML System Properties**

`SESAME_SAML_KEY_LOCATION=file:/path/to/private.key`

`SESAME_SAML_CERT_LOCATION=file:/path/to/certificate.crt`

`SESAME_SAML_METADATA_URI=file:/path/to/metadata.xml`

### ⚙️ **Activate SAML Profile**

Run the application with the SAML profile:

`java -jar -Dspring.profiles.active=saml bandr.jar`

### ⚙️ **Example application.properties Configuration**

`spring:`

`  security:`

`    saml2:`

`      relyingparty:`

`        registration:`

`          okta:`

`            signing:`

`              credentials:`

- `private-key-location: ${SESAME_SAML_KEY_LOCATION}`

`                  certificate-location: ${SESAME_SAML_CERT_LOCATION}`

`            assertingparty:`

`              metadata-uri: ${SESAME_SAML_METADATA_URI}`

---

## **🔹 Step 10: Configure LDAP (Optional)**

### ⚙️ **LDAP Properties**

`rj.ldap.userDnPatterns=`

`rj.ldap.userSearchBase=`

`rj.ldap.userSearchFilter=`

`rj.ldap.groupSearchBase=`

`rj.ldap.groupSearchFilter=(uniqueMember={0})`

`rj.ldap.groupRoleAttribute=cn`

`rj.ldap.groupSearchSubtree=true`

`rj.ldap.ldapAuthoritiesPopulator=`

`rj.ldap.passwordEncoder=sha256`

### ⚙️ **Password encoder options:**

- `ldapsha`
- `bcrypt`
- `noop`
- `pbkdf2`
- `scrypt`
- `sha256`

---

## **🔹 Step 11: Configure Binary (BLOB) Storage (Optional)**

By default, BandR stores Salesforce base64 file data as BLOBs in the database. This step is optional — configure it only if you want to redirect binary storage to the local filesystem or Amazon S3.

### **Property Reference**

| Setting | Value |
| --- | --- |
| **Property** | `rj.binary.storage` |
| **Environment Variable** | `SESAME_BINARY_STORAGE` |
| **Default** | `db` |

### **Storage Options**

- `db` *(default)* — Stores binary data as a BLOB in the BandR database. No additional configuration required.
- `fs` — Stores files on the local filesystem under the `rj.user-dir` location:

`{rj.user-dir}/backupId/objectName/brId/lastThreeOfObjectId/objectId`

- `s3` — Stores files in Amazon S3:

`/bucketName/backupId/objectName/brId/lastThreeOfObjectId/objectId`

### **application.properties**

`rj.binary.storage=db`

### **Environment Variable**

`SESAME_BINARY_STORAGE=db`

---

For further guidance on Steps 8, 9, or 10, see our next article [Configuring Spring Profiles for Authentication (LDAP, SSO, SAML)](https://sesamesoftware.atlassian.net/wiki/x/AQAnK).  
For more help, see `README.txt` or contact support.

---

‌