ESAM
- Last Updated: September 10, 2026
- 3 minute read
- OpenEdge
- Version 12.8
- Documentation
External Security Administration Manager (ESAM) is an OpenEdge security control service that operates externally to the OpenEdge installation. ESAM centralizes governance and applies security policies without requiring code changes.
Platform availability
ESAM is only available on 64-bit Linux and 64-bit Windows platforms.
Roles and responsibilities
To effectively use ESAM, organizations can assign roles with defined responsibilities:
-
System Administrators—Install OpenEdge and configure secure installations.
-
OpenEdge ESAM Administrators(Optionally)—Manage runtime environments, set ESAM policies, and monitor audit logs to support security objectives.
ESAM installation trust states
- Service-registered mode
An installation is connected to ESAM and successfully validated against its ESAM registration record. An installation is considered Service-Registered when:
- ESAM is available.
- The installation is registered with ESAM.
- The installation identity information matches the ESAM registration record.
- The OpenEdge root installation path
(
DLC) matches the registered installation.
In this state:
- ESAM policies are evaluated and enforced.
- Security-sensitive operations can rely on ESAM trust validation.
- OpenEdge operates as a verified ESAM-managed installation.
- Client-anonymous mode
Client-anonymous mode is a fallback operating state used when OpenEdge cannot establish the registration trust relationship required for ESAM-managed operation. A client-anonymous installation typically occurs when:
- Registration metadata cannot be found.
- Required ESAM files are missing or corrupted.
- Installation identity information cannot be validated.
- Permissions prevent access to ESAM registration artifacts.
In client-anonymous mode:- ESAM registration validation is unavailable.
- Policy evaluation that depends on installation registration cannot be performed.
- OpenEdge falls back to internal behavior that preserves application availability.
- Security capabilities may be reduced compared to a Service-Registered installation.
| Mode | Registration trust | Validated | Result |
|---|---|---|---|
| Service-registered | Yes | Yes | Trusted ESAM-managed operation |
| Client-anonymous | No | No | Fallback operation with no policy execution. |
For more information, see Valid uses of client-anonymous mode
Installation
When you install OpenEdge, the ESAM installer runs automatically in silent mode. ESAM is a fixed and absolute file system space that can apply root and group authorities to protect OpenEdge installation artifacts and the integrity of the OpenEdge root install path, also known as DLC.
As the name implies, ESAM installs in a fixed directory, external to DLC, based on the operating system:
- Linux:
/etc/openedge.d - Windows:
C:\Windows\System32\openedge.d
| Directory | Description |
|---|---|
| audit | Contains the audit log file (oesec.log), which records administrative actions and policy violations. This log is essential for security monitoring and supports forensic analysis in the event of breaches or misconfiguration. Additional logs track ESAM registrations and migration activities. Access is restricted to System Administrators. |
| bin | Contains the validation script, (valdlc.{bat|exe}),
which verifies the integrity of the OpenEdge root installation path,
DLC. Accessible to users.
|
| conf | Contains:
|
| install | Contains uninstall scripts, a resources subdirectory used for uninstalling, and other related files. |
| lib | Contains libraries to support ESAM. |
| Release |
Contains GUID install specific directory. ESAM uses the GUID details to make the right policy decisions for a specific installation. If ESAM does not have a valid GUID, ESAM reverts to client-anonymous to help troubleshoot. |
| sbin | Contains setdlc.{bat|exe}—Register or unregister
the OpenEdge root install path (DLC)
with ESAM. Without this script, installations cannot be securely linked to
ESAM, leaving them exposed to unauthorized changes. Access is restricted to OpenEdge ESAM Administrators and System Administrators. |
Backup dlc.ver
The dlc.ver file is required for OpenEdge registration. You cannot register or unregister an OpenEdge installation without this file. If dlc.ver is deleted or corrupted, registration fails unless you restore a backup. Access is limited to System Administrators. The directory is based on the operating system:
- Linux:DLC/install/verify
- Windows: DLC\install\verify
OpenEdge recommends creating a backup in a secure location in case you need to manually re-register an ESAM-managed OpenEdge installation. If this file is missing, ESAM reverts to client-anonymous mode.
For more information, see ESAM loads in client-anonymous mode unexpectedly.
Upgrade ESAM
During OpenEdge installations, the OpenEdge installer updates ESAM to the latest version while preserving existing configurations. Each upgrade adds a Release directory to openedge.d.