Logout for 11g WebGate and OAM 11g

16-2 Oracle Fusion Middleware Application Security Guide

16.1.1.1 About Oracle Access Manager 10g Installation and Setup

This topic provides a brief installation and setup overview if you are new to Oracle Access Manager. Access Servers : For the Oracle Access Manager Authentication Provider, you need two Access Servers for WebGates or AccessGates: one primary server and one secondary server. Currently, only one secondary Access Server is supported. Installing Access Servers includes: ■ Adding an Access Server configuration profile in the Access System Console for the primary server. Ensure that the Access Management Service is On also known as Policy Manager API Support Mode. ■ Adding a secondary Access Server configuration profile with the Access Management Service On. ■ Installing the primary Access Server instance. ■ Installing the secondary Access Server instance. WebGateAccessGate : Whether you need a WebGate or an AccessGate depends on your use of the Oracle Access Manager Authentication Provider. For instance, the: ■ Identity Asserter for Single Sign-On : Requires a separate WebGate and configuration profile for each application to define perimeter authentication. Ensure that the Access Management Service is On. ■ Authenticator or Oracle Web Services Manager : Requires a separate AccessGate and configuration profile for each application. Ensure that the Access Management Service is On. About OAM 10g WebGateAccessGate Profiles and Policy Domains This topic introduces the WebGateAccessGate profiles, policy domains, and the methods you can use the create these. While there are subtle differences between WebGates and AccessGates, these terms are often used interchangeably. In the Access System Console, the configuration profile for WebGates or AccessGates is known as an AccessGate profile. The Policy Manager is where an Oracle Access Manager policy domain is created. Access System Console Method : Enables users with specific Oracle Access Manager administration rights to enter information and set parameters directly in Oracle Access Manager. This method is required if you are using the Authenticator, or if you have Oracle Web Services Manager policies protecting Web services. OAMCfgTool Method : Application administrators who are implementing the Identity Asserter for single sign-on, can use OAMCfgTool to create a new WebGate profile for a fresh Web Tier. Required parameters are provisioned using values for your environment specified on the command line. Default values are accepted for non-required parameters; the Access Management Service is set to On. After creating a profile, values can be modified in the Access System Console. Each AccessGate profile must include the following parameters; those marked with an asterisk, , are provisioned with OAMCfgTool: ■ AccessGate Name —A unique name without spaces. With OAMCfgTool the name is derived from the app_domain value, appended with _AG. See Also: Requirements for the Provider with Oracle Access Manager on page 14-12