Book Image

Oracle Identity and Access Manager 11g for Administrators

By : Atul Kumar
Book Image

Oracle Identity and Access Manager 11g for Administrators

By: Atul Kumar

Overview of this book

<p>Oracle Identity Management is intended to help organizations quickly and reliably manage information about users on multiple systems and applications. Regulatory Compliance and&nbsp;the&nbsp;desire to expose business applications over&nbsp;the Internet have made Identity and Access management skills&nbsp;particularly&nbsp;desirable in recent times. Oracle Access Manager is&nbsp;a&nbsp;recommended Single Sign-On solution for Fusion Middleware including WebCenter, SOA Suite, Portal, and E-Business Suite; more and more companies&nbsp;are&nbsp;implementing Oracle Access Manager. This book will guide you through the important&nbsp;administrative&nbsp;aspects of Identity Mangement.<br /><br />Oracle Identity and Access Manager 11g for Administrators covers&nbsp;the complete&nbsp;day-to-day task of installing, configuring, and managing Oracle Access Manager and Oracle Identity Manager. This book covers everything an administrator needs during and after&nbsp;an&nbsp;Oracle Identity and Access Management implementation.<br /><br />This book covers all aspects of&nbsp;the&nbsp;Oracle Identity and Access Management life cycle from administrator's point of view. <br /><br />This book starts with&nbsp;an&nbsp;introduction&nbsp;into&nbsp;Oracle’s Identity and Access Management products touching all&nbsp;the&nbsp;products which are part of&nbsp;the&nbsp;Oracle Identity Management Suite. It then covers installation and&nbsp;the&nbsp;configuration of multiple OAM/OIM servers in&nbsp;clusters&nbsp;for resilience and high availability deployment for production deployments, creating Identity and Access Management Schemas, and configuring Identity Manager and Access Manager in detail.&nbsp;The book&nbsp;then dives into&nbsp;the&nbsp;important topic that is Oracle Identity Manager navigation, and covers integrating Oracle Identity Manager with Oracle Internet Directory and Microsoft Active Directory using OIM Connectors. Finally the book covers&nbsp;the&nbsp;important key topic for monitoring that is Logging and Auditing in OIM/OAM and configuring&nbsp;a&nbsp;dedicated database for Auditing.</p>
Table of Contents (21 chapters)
Oracle Identity and Access Manager 11g for Administrators
Credits
About the Author
About the Reviewers
www.PacktPub.com
Preface
9
OIM Navigation: Administration and Design Console
Index

Index

A

B

  • Browse tab /
  • business service tier, OIM
    • core services /
    • API Services /
    • Integration Services /
    • Platform Services /

C

  • .cmd files / Configuring RDA
  • challenge methods, authentication schemes
    • form /
    • basic /
    • X509 /
    • WNA /
    • none /
    • DAP /
    • OAM11g /
  • Coherence Home
    • representation /
  • common environment variables
    • about /
    • Middleware Home /
    • WebLogic Home /
    • Coherence Home /
    • IDAM Oracle Home /
    • Common Oracle Home /
    • SOA Oracle Home /
    • Domain Home /
  • Common Oracle Home
    • representation /
  • components, connector
    • IT Resource Type /
    • process form /
    • resource object /
    • provisioning process /
    • process task /
    • process task adapter /
  • configuration issues, OIM
    • Start/Stop issues /
    • user registration /
    • MDS utility running, errors /
    • OIM design donsole, login error /
  • connector
    • web-based wizards, Cconnector installer /
    • web-based wizards, Deployment Manager /
    • components /
    • transferring, from test to production /
  • connector types, OIM
    • predefined connectors /
    • custom connector, adapter factory used /
    • generic technology connector /
  • Constraint Class, authorization constraints
    • Identify /
    • temporal /
    • IP4 Range /
  • Constraint Type, authorization constraints
    • Allow /
    • Deny /
  • cookies, OAM SSO
    • about /
    • OAM_ID /
    • OAMAuthn /
    • ObSSO /
    • OAM_REQ /
    • OAMRequestContext /
    • OHS_<host-port> /
    • GITO /
  • CrashRecoveryEnabled property /
  • Create button /

D

  • DAP /
  • DataSourceName attribute /
  • data sources
    • in OAM /
    • User Identity store /
    • OAM Policy /
    • Session Data Store /
    • OAM Configuration data store /
    • security key /
    • Java Key Store /
  • data tier, OIM
    • entity data /
    • transactional data /
    • audit data /
  • default IDAM installation
    • stopping /
  • development tools, OIM Design control
    • AdapterFactory /
    • AdapterManager /
    • FormDesigner /
    • ErrorMessageDefinition /
    • ReconciliationRule /
    • Business Rule Definition /
  • directory/ files, Middleware Home
    • Jdkversion* /
    • jrockit_version* /
    • Logs /
    • Modules /
    • Utils /
    • wlserver_version /
    • coherence_version /
    • .home /
    • ocm.rsp /
    • registry.xml /
    • registry.dat /
    • domain-registry.xml /
    • Oracle_IDM1 /
    • Oracle_SOA1 /
    • user_projects /
  • directory content, Domain Home
    • directory content /
    • Bin /
    • bin.sh /
    • Config /
    • config.xml /
    • config /
    • configwconfig /
    • Security /
    • Servers /
    • serversserverName> /
    • serversserverName>oot.properties /
  • Domain Home
    • representation /
    • key files/directories, by OAM server /
    • key files/directories, by OIM server /
    • key files/directories, for OAM server /
    • key files/directories, for OIM server /
  • downloading
    • OAM agent software /
    • 11g WebGates /
    • 10g WebGates /
    • GCC Libraries /

E

  • EBS_TR_User /
  • end_url query parameter /
  • Enterprise Role /
  • eSSO /
  • external interfaces, OIM components
    • SOA /
    • SPML Client /
    • Browser /
    • BI Publisher /
    • OVD Server /
    • OAM Server /

F

  • FMW
    • about /
    • integration, with OAM /
    • integrating, with OAM, for SSO /
    • 11gR1 /
  • FMW-OAM integration, for SSO
    • about /
    • high level integration steps, for OAM /
    • web center-specific tasks /
    • OBIEE specific tasks /
  • Fusion Apps Integration, application domain /
  • Fusion Middleware Control
    • using, for Start/Stop options /

G

  • 10g WebGate forOHS 10g installation, OAM Agents installation
    • steps /
    • provisioning, with OAM 11g /
    • software, installing /
  • 10g WebGate properties, OAM Agent
    • about /
  • 10g WebGates /
  • 11g WebGate forOHS 11g installation, OAM Agents installation
    • steps /
    • 11g WebGate registration, with OAM server /
    • 11g WebGate software, installing /
  • 11g WebGate properties, OAM Agent
    • about /
  • GCC Library
    • downloading /

H

  • High Availability configuration, IDAM installation
    • prerequisites /
    • IDAM configuration, in Active-Active mode /
  • host identifier, OAM policy components
    • about /
    • creating /
    • deleting /
  • Hostname
    • Port /

I

  • IDAM
    • about /
    • installation, steps /
    • installation types /
    • installing /
    • uninstalling /
    • deinstalling /
    • OIM Home, uninstalling /
    • OIM Home, deinstalling /
    • Oracle Common Home, deinstalling /
    • Oracle Common Home, uninstalling /
  • IDAM 11.1.1.3 installation
    • about /
  • IDAM installation
    • points /
    • system requirements, checking /
    • database, installing /
    • Repository Creation Utility, creating /
    • Oracle WebLogic 10.3.3 server, installing /
    • IDAM 11.1.1.3, installing /
    • SOA Suite 11.1.1.2.0 installing /
    • SOA Suite 11.1.1.3.0, upgrading /
    • WebLogic domain, creating /
    • IDAM, configuring /
    • OIM server, configuring /
    • URLs, testing /
    • OIM services, starting /
    • High Availability, installing /
    • High Availability, installing on IDMHOST1 /
    • High Availability, installing on IDMHOST2 /
  • IDAM Oracle Home
    • representation /
  • IDAM server
    • starting /
    • start/stop options /
  • Identity and Access Management 11g /
  • Identity Management 11g /
  • Idle Timeout attribute /
  • IDMDomainAgent, application domain /
  • installation, IDAM
    • steps /
    • database schemas, creating /
    • WebLogic server, installing /
    • Identity and Access Management server, installing /
    • Oracle SOA Suite 11.1.1.2.0, installing /
    • Oracle SOA Suite, updating to 11.1.1.3.0 /
    • domain, creating /
    • configuring /
    • OIM, configuring /
  • installation, OAM Agents
    • provisioning agent /
    • installing agent /
    • key steps /
    • software, downloading /
    • 11g WebGate for OHS 11g, installing /
    • 10g WebGate for OHS 10g, configuring /
    • 10g WebGate for OHS 10g, installing /
  • installation, predefined connectors
    • OIM connector deploying, for Oracle Internet Directory /
    • OIM connector deploying, for Microsoft Active Directory User Management /
    • OIM connector deploying, for Oracle e-Business User Management /
    • preinstallation steps /
    • installation steps /
  • Installation Summary screen /
  • installation types, IDAM
    • about /
    • silent install /
    • interactive install /
    • distributed install /
    • collocated install /
    • single instance install /
    • multiple instance install /
  • installing
    • Design Console /
  • interfaces, OIM
    • OIM Administrative and User Console /
    • OIM Design Console /
    • SPML web services /
  • IT Resource Type, connector components /

J

  • Java Key Store (JKS) format /
  • Java Required File (JRF) /

K

  • Kerberos authentication modules /
  • key components, Oracle E-Business Suite-OAM integration
    • profile option /
    • Oracle HTTP server (OHS) /
    • Web Gate /
    • mod_wl_ohs /
    • Web Logic server /
    • Oracle E-Business Suite Access Gate /

L

M

  • MDS Utilities
    • OIM files, managing /
  • Middleware Home
    • about /
    • directory/ files /
  • mod_oif file /
  • mod_wl_ohs modules /
  • My Oracle Support (MOS) /

N

  • navigation, OIM Design control
    • diagram /
    • MenuBar /
    • ToolBar /
    • Folders /
    • Forms /
    • workspace /
  • Node Manager
    • configuring /
  • Node Manager, configuring as Service
    • about /
    • on Windows /
    • uninstallation, from Windows /
    • Unix/Linux /
  • Node Manager configuration
    • steps /

O

  • OAAM /
  • OAM /
    • overview /
    • architecture /
    • server side component /
    • data sources /
    • server registration /
    • agents, registering /
    • policy components /
    • integrating, with FMW /
    • integrating, with Oracle E-Business Suite /
    • questions /
    • configuration issues /
    • installation issues /
  • OAM-FMW integration
    • about /
    • application, configuring /
    • SSO, providing /
    • security concepts /
  • OAM Administration console
    • accessing /
    • logout /
    • login /
  • OAM Administration console navigation
    • about /
    • console layout /
    • policy configuration /
    • system configuration /
  • OAM Agent
    • properties /
  • OAM Agents
    • installing /
  • OAM agents
    • registering /
  • OAM agents, registering
    • about /
    • OSSO agents /
    • AccessGates /
    • IDMDomainAgent/IAMSuite /
    • ways /
    • OAM server, using /
    • Administration console, using /
    • command line tool, using /
  • OAM agents, registering with OAM server
    • about /
  • OAM Agents installation
    • software, downloading /
    • 11g WebGate for OHS 11g, installing /
  • OAM agent software, downloading
    • 11g WebGates, downloading /
    • 10g WebGates, downloading /
    • GCC Libraries, downloading /
  • OAM agents registration, Administration console used
    • about /
    • 11g/10g WebGates, using /
    • OSSO Agents, creating /
  • OAM agents registration, command line tool used
    • about /
    • Remote Registration utility usages /
    • Remote Registration tool, modes /
  • OAM console
    • URL /
  • OAM Identity Asserter /
  • OAM Key Store /
  • OAM Proxy server /
  • OAM SSO
    • about /
    • Log In request flow /
    • SSO engine settings, accessing /
  • OAM SSO
    • cookies /
  • OAM SSO Log In request flow
    • about /
    • with OAM 10g/11g WebGate /
    • with OSSO agents /
  • OAPM /
  • ODL
  • ODL framework
  • ODL Loggers
  • ODSEE /
  • OES /
  • OIA /
  • OID /
    • using /
  • OIF /
  • OIM /
    • OIM /
    • OAM /
    • OIF /
    • eSSO /
    • OAAM /
    • OES /
    • OIA /
    • OID /
    • ODSEE /
    • OVD /
    • OPSS /
    • OAPM /
    • OWSM /
    • OIN /
    • overview /
    • architecture /
    • components /
    • interface /
    • connector /
    • related passwords, changing /
    • questions /
    • installation issues /
    • configuration issues /
  • OIM, components
    • OIM Server /
    • Design Console /
    • External Interfaces /
    • Remote Manager /
    • Database /
  • OIM-AD connector
    • using /
    • reconciliation, performing /
    • reconciliation, performing for target resource reconciliation /
    • reconciliation, performing for trusted resource reconciliation /
    • provisioning, performing /
  • OIM-EBS User Management connector
    • reconciliation, performing /
  • OIM-OID connector
    • installing /
    • using /
    • reconciliation, performing /
    • provisioning, performing /
  • OIM Administrative and User Console
    • about /
    • user interface, categories /
  • OIM cache
    • purging /
  • OIM configuration
    • managing /
    • managing, MBeans used /
    • system properties, managing /
  • OIM connector deploying, for Microsoft Active Directory User Management
    • steps /
    • preinstallation /
    • installation /
    • IT resource configuration, for Active directory /
    • lookup definition setup, in OIM /
    • OIM-AD connector, using /
  • OIM connector deploying, for Oracle e-Business User Management
    • steps /
    • preinstallation steps /
    • IT resource, configuring /
    • OIM-EBS User Management connector, using /
  • OIM connector deploying, for Oracle Internet Directory
    • about /
    • preinstallation steps /
    • OIM-OID connector, installing /
    • IT Resource, configuring /
    • OIM-OID connector, using /
  • OIM Design control
    • about /
    • installing /
    • navigation /
  • OimFrontEndURL /
  • OIM hostname
    • changing /
  • OIM Password Policy
    • about /
    • creating /
    • associating, to resource /
  • OIN /
  • OPSS /
  • Oracle e-Business Suite
    • IT resource, configuring /
  • Oracle E-Business Suite
    • integrating, with OAM /
  • Oracle E-Business Suite-OAM integration
    • about /
    • key components /
    • request flow /
  • Oracle E-Business Suite R12-OAM SSO
    • high level steps /
  • OracleEntitlementServer (OES) /
  • OSSO /
  • OSSO agent properties, OAM Agent
    • about /
  • OVD /
  • OWSM /

P

  • Policy Configuration tab /
  • policy response, OAM policy components
    • about /
    • header /
    • session /
    • cookie /
  • port number
    • changing /
  • predefined connectors
    • installing /
  • process form, connector components /
  • process management, OIM Design control
    • EmailDefinition /
    • ProcessDefinition /
  • process task, connector components /
  • process task adapter, connector components /
  • properties, OAM Agent
    • configuring, for, 11g WebGate /
    • configuring, for, 10g WebGate /
    • configuring, for, OSSO agent /
  • Protected Resource policy /
  • Providers screen /
  • provisioning
    • about /
    • request-based /
    • policy-based provisioning /
    • direct /
  • provisioning, OIM-AD connector
    • performing /
  • provisioning, OIM-OID connector
    • performing /
    • direct to request-based provisioning, switching to /
    • request-based to direct provisioning, switching to /
    • resources, direct provisioning used /
  • provisioning process, connector components /
  • Proxy tab /
  • Public Resource policy /

R

  • RDA
  • Realm /
  • reconciliation
    • about /
    • trusted source /
    • account reconciliation /
  • reconciliation, OIM-EBS User Management connector
    • performing /
    • e-Business Suite as trusted source, configuring /
    • e-Business Suite as target resource, configuring /
    • e-Business Suite as Trusted Source, configuring /
  • Remote Registration /
    • about /
    • utility usages /
    • In-Band registration mode /
    • Out-of-Band registration mode /
  • Repository Creation Utility (RCU) /
  • resource menagemnt, OIM Design control
    • ITResourcesTypeDefinition /
    • RuleDesigner /
    • ResourceObjects /
  • resource object, connector components /
  • resources, OAM policy components
    • about /
  • resource type, OAM policy components
    • about /
    • HTTP /
    • wl_authen /
    • TokenServiceRP /
    • creating /
    • deleting /
  • RREG
    • using /

S

  • Search tab /
  • security concept, OAM-FMW integration
    • user /
    • groups /
    • application roles /
    • application role configuration, for OBIEE /
    • seeded application roles /
    • identity store /
    • policy store /
    • credential store /
    • web logic server authentication provider /
  • Self-Service Console for unauthenticated users
    • about /
    • Resetting Forgotten password function /
    • Self Register function /
    • Track Self Register Requests function /
    • functions /
    • self profile, managing /
    • request management function /
    • task management function /
  • server registration, OAM
    • about /
    • OAM Server Instance, adding /
  • server side component, Oracle Access Manager
    • Oracle Access Manager Administration Console /
    • Oracle Access Manager Server /
  • session data
    • separate database, configuring /
  • Session Lifetime attribute /
  • session management, OAM
    • user session lifecycle /
  • shutdown order
    • flowchart diagram /
  • Sign Out link /
  • silent installation
    • about /
    • steps /
    • response file, creating /
    • response file, creating for OIM configuration /
    • performing /
  • SOA Oracle Home
    • representation /
  • SPML web service
    • about /
    • addRequest /
    • modifyRequest /
    • deleteRequest /
    • statusRequest /
    • listTargetRequest /
    • suspendRequest /
    • resumeRequest /
    • activeRequest /
    • validateUsername /
    • suggestUsername /
  • start-up order
    • about /
    • flowchart diagram /
  • start/stop options, IDAM server
    • WLST commands, using /
    • Fusion Middleware Control, using /
    • WebLogic console, using /
  • start/stop options, WebLogic Server
    • points /
  • System Configuration tab , OAM Administration Console /

T

  • terminology, OAM policy components
    • about /
    • application domain /
    • resource type /
    • host identifier /
    • resources /
    • authentic modules /
    • policy response /
    • authentication schemes /
    • authentic schemes /
    • authentication policy /
    • authorization policy /

U

  • User Identity store, data sources
    • about /
    • accessing /
    • creating /
    • setting, as primary /
    • important points /
  • user interface, OIM Administrative and User Console
    • Self-Service Console for unauthenticated users /
    • categories /
    • Self-Service Console for authenticated users /
    • Administration Console /
    • Advanced Administration Console /
  • user management, OIM Design control
    • OrganizationalDefaults /
    • PolicyHistory /
    • Roles /
  • userPassword attribute /
  • user session lifecycle
    • active state /
    • inactive state /
    • expired state /
    • settings /
    • Active user sessions /
  • user session lifecycle, settings
    • Session Life Time parameter /
    • Maximum Number of Sessions per User parameter /
    • managing /
    • Idle Timeout /
    • Session Life Time /
    • maximum number of session per user /

W

  • webgate directory /
  • WebLogic console
    • using, for Start/Stop options /
    • Start-up, troubleshooting /
  • WebLogic logging service
  • WebLogic Server
    • overview /
    • diagram /
    • Domain /
    • WebLogic Administration (Admin) Server /
    • WebLogic Managed Server /
    • Node Manager /
    • WebLogic Cluster /
    • WebLogic JDBC Datasource /
  • WebLogic server
    • about /
  • web logic server authentication provider, OAM-FMW integration
    • about /
    • Default Authenticator /
    • JAAS flag /
    • OID configuring, as authentication provider /
    • OAM Identity assertion provider /
  • WLfullclient
    • about /
    • wlfullclient.jar, generating /
    • MDS Utilities /
  • WLST /
  • WLST commands
    • using, for Start/Stop options /
    /
  • workspace, OIM Design control
    • user management /
    • resource management /
    • process management /
    • administration /
    • development tools /

X

  • 9.1.X OIM Connectors /
  • X509 Authentication Modules /