Extending Domain for Oracle Adaptive Access Manager
12.2 Configuring Oracle Adaptive Access Manager on IDMHOST1
Although OAAM is deployed on servers dedicated to it OAAMHOST1 and OAAMHOST2, the Weblogic domain must first be extended with OAAM on IDMHOST1. This section describes how to configure Oracle Adaptive Access manager on IDMHOST1. This section contains the following topics: ■ Section 12.2.1, Extending Domain for Oracle Adaptive Access Manager ■ Section 12.2.2, Starting Administration Server on IDMHOST1 ■ Section 12.2.3, Creating OAAM Administration User in WebLogic Console ■ Section 12.2.4, Configuring Oracle Adaptive Access Manager on OAAMHOST112.2.1 Extending Domain for Oracle Adaptive Access Manager
Start the configuration wizard by executing the command: MW_HOME oracle_commoncommonbinconfig.sh Then proceed as follows:1. On the Welcome Screen, select Extend an Existing WebLogic Domain. Click Next
2. On the Select a WebLogic Domain screen, using the navigator select the domain home of the Administration Server, for example: ORACLE_ BASE adminIDMDomainaserverIDMDomain. Click Next. 3. On the Select Extension Source screen, select the following: ■ Oracle Adaptive Access Manager - Server ■ Oracle Adaptive Access Manager Admin Server ■ Oracle WSM Policy Manager ■ Oracle Identity Navigator Click Next 4. The Configure RAC Multi Data Sources screen displays the schedulerDS Data Source configured for Oracle Directory Integration Platform and Oracle Directory Services manager ODSM. Do not make any selections or changes on this screen. Click Next. 5. On the Configure JDBC Component Schema screen, select all of the data sources, then select Configure selected data sources as RAC multi data sources. Extending the Domain with Oracle Adaptive Access Manager 12-3 Click Next. 6. On the Configure RAC Multi Data Source Component Schema page Real Applications Cluster Databases only, select all the schemas for your component. Do not select schemas listed for previously configured components. Then enter the following information: If you are using Oracle Database 11.2, replace the vip addresses with the 11.2 SCAN address. Click Next. 7. On the Test Component Schema screen, the configuration wizard attempts to validate the data source. If the data source validation succeeds, click Next. If it fails, click Previous, correct the issue, and try again.8. On the Select Optional Configuration screen, select Managed Server Clusters and
Machines . Click Next 9. When you first enter the Configure Managed Servers screen, the configuration wizard has created a default Managed Server for you. Change the details of the default managed server . Schema Name Service Name Host Names Instance Names Port Schema Owner Password OAAM Admin Schema oaam.mycomp any.com oaamdbhost1-v ip.mycompany. com oaamdb1 1521 EDG_OAAM password oaamdbhost2-v ip.mycompany. com oaamdb2 1521 OAAM Admin MDS Schema oaam.mycomp any.com oaamdbhost1-v ip.mycompany. com oaamdb1 1521 EDG_MDS password oaamdbhost2-v ip.mycompany. com oaamdb2 1521 OAAM Server Schema oaam.mycomp any.com oaamdbhost1-v ip.mycompany. com oaamdb1 1521 EDG_OAAM password oaamdbhost2-v ip.mycompany. com oaamdb2 1521 OWSM MDS Schema oidedg.myco mpany.com oiddbhost1-vi p.mycompany.c om idmdb1 1521 EDG_MDS password oiddbhost2-vi p.mycompany.c om idmdb2 1521 12-4 Oracle Fusion Middleware Enterprise Deployment Guide for Oracle Identity Management For the oaam_server_server1 entry, change the entry to the following values: ■ Name : WLS_OAAM1 ■ Listen Address : OAAMHOST1 ■ Listen Port :14300 ■ SSL Listen Port : 14301 ■ SSL Enabled : Selected. For the second OAAM Server, click Add and supply the following information: ■ Name : WLS_OAAM2 ■ Listen Address : OAAMHOST2 ■ Listen Port : 14300 ■ SSL Listen Port : 14301 ■ SSL Enabled : selected Select the oaam_admin_server1 entry. Change the entry to the following values: ■ Name : WLS_OAAM_ADMIN1 ■ Listen Address : OAAMHOST2 ■ Listen Port :14200 ■ SSL Listen Port : 14201 ■ SSL Enabled : Selected For the OAAM Administration Server, click Add and supply the following information: ■ Name : WLS_OAAM_ADMIN2 ■ Listen Address : OAAMHOST2 ■ Listen Port : 14200 ■ SSL Listen Port : 14201 ■ SSL Enabled - selected Leave all the other fields at the default settings and click Next. 10. On the Configure Clusters screen, create a cluster by clicking Add. ■ Name : cluster_oaam. ■ Cluster Messaging Mode : unicast Create a second cluster by clicking Add. Note: When you first enter this screen the config wizard has created a default Managed Server for you. Change the details of the default Managed Server to reflect the following details. That is, change one entry and add one new entry. Do not change the configuration of any Managed Servers which have already been configured as part of previous application deployments. Extending the Domain with Oracle Adaptive Access Manager 12-5 ■ Name : cluster_oaam_admin ■ Cluster Messaging Mode : unicast Leave all other fields at the default settings and click Next. 11. On the Assign Servers to Clusters screen, associate the Managed Servers with the cluster. Click the cluster name in the right pane. Click the Managed Server under Servers , then click the arrow to assign it to the cluster. The cluster_oaam has the Managed Servers WLS_OAAM1 and WLS_OAAM2 The cluster_oaam_admin has the Managed Servers WLS_OAAM_ADMIN1 and WLS_OAAM_ADMIN2 Click Next. 12. On the Configure Machines screen, create a machine for each host in the topology. Click the tab UNIX if your hosts use a UNIX-based operating system. Otherwise, click the Machines tab. Supply the following information: ■ Name : Name of the host. Best practice is to use the DNS name oaamhost1.mycompany.com. ■ Node Manager Listen Address : The DNS name of the machine oaamhost1.mycompany.com ■ Node Manager Port : A port for Node Manager to use Click Next. 13. On the Assign Servers to Machines screen, indicate which Managed Servers to run on each of the machines you created. Click a machine in the right pane. Click the Managed Servers you want to run on that machine in the left pane. Click the arrow to assign the Managed Servers to the machines. Repeat until all Managed Servers are assigned to machines. For example: oaamhost1 : WLS_OAAM1 and WLS_OAAM_ADMIN1 oaamhost2 :WLS_OAAM2 and WLS_OAAM_ADMIN2 Click Next to continue. 14. On the Configuration Summary screen, click Extend to extend the domain. Note: Do not change the configuration of any clusters which have already been configured as part of previous application deployments. 12-6 Oracle Fusion Middleware Enterprise Deployment Guide for Oracle Identity Management12.2.2 Starting Administration Server on IDMHOST1
Parts
» Oracle Fusion Middleware Online Documentation Library
» What is an Enterprise Deployment? Terminology
» Understanding the Directory Tier
» Architecture Notes Understanding the Application Tier
» Architecture Notes Security Provisions
» Using This Guide Oracle Fusion Middleware Online Documentation Library
» Hardware Resource Planning Oracle Fusion Middleware Online Documentation Library
» Load Balancers Network Prerequisites
» Configuring Virtual Server Names and Ports on the Load Balancer
» Virtual IP Addresses Managing Oracle Fusion Middleware Component Connections
» Firewall and Port Configuration
» Directory Structure Terminology and Environment Variables
» Recommended Locations for the Different Directories
» WebLogic Domain Considerations Real Application Clusters
» Creating Database Services for 11.2.x Databases Database Tuning
» RCU Example Executing the Repository Creation Utility
» Introduction Using this Guide Software Installation Summary
» Installation Installing Oracle HTTP Server
» Installing Oracle Fusion Middleware Components Installing Oracle Fusion Middleware Home
» Installing JRockit Installing Oracle Identity Management
» Upgrading the Oracle Homes for Oracle Identity Management from 11.1.1.2 to 11.1.1.5
» Installing the Oracle SOA Suite
» Installing Oracle Identity and Access Management
» Validating the Installation Backing up the Web Tier Configuration
» Enabling ADMINVHN on IDMHOST1 Running the Configuration Wizard on IDMHOST1 to Create a Domain
» Failing over the Administration Server to IDMHOST2
» Failing the Administration Server Back to IDMHOST1
» Configuring the First Oracle Internet Directory Instance
» Configuring an Additional Oracle Internet Directory Instance
» Registering Oracle Internet Directory with the WebLogic Server Domain
» Extending the Oracle WebLogic Domain with Oracle Directory Integration Platform and ODSM
» Installing and Configuring Oracle Directory Integration Platform and ODSM on IDMHOST2
» Provisioning the Managed Servers in the Managed Server Directory
» Validating Oracle Directory Services Manager Validating Oracle Directory Integration Platform
» Backing Up the Application Tier Configuration
» Configuring the First Oracle Virtual Directory Instance
» Configuring an Additional Oracle Virtual Directory
» Registering Oracle Virtual Directory with the Oracle WebLogic Server Domain
» Creating Policy Store Users and the Policy Container
» Reassociating the Policy and Credential Store
» Extending Directory Schema for Oracle Access Manager
» Creating Users and Groups for Oracle Access Manager
» Creating Users and Groups for Oracle Adaptive Access Manager
» Creating Users and Groups for Oracle Identity Manager
» Creating Users and Groups for Oracle WebLogic Server
» Creating Access Control Lists in Non-Oracle Internet Directory Directories
» Extending Domain with Oracle Access Manager
» Removing IDM Domain Agent Propagating the Domain Changes to the Managed Server Domain Directory
» Changing Oracle Access Manager Security Model
» Configuring Oracle Access Manager by Using the IDM Automation Tool
» Adding the oamadmin Account to Access System Administrators Validating Oracle Access Manager
» Setting up Keystore with the SSL Certificate and Private Key file of the Access Client
» Extending Domain for Oracle Adaptive Access Manager
» Prerequisites Loading Oracle Adaptive Access Manager Seed Data
» Backing Up the Application Tier Configuration Backing Up the Application Tier Configuration
» Prerequisites Enabling Virtual IP Addresses on OIMHOST1 and OIMHOST2
» Extending the Domain to Configure Oracle Identity Manager and Oracle SOA Suite on IDMHOST1
» Propagating the Oracle Identity Manager and SOA Managed Servers to OIMHOST1 and OIMHOST2
» Prerequisites Configuring Oracle Identity Manager to Work with the Oracle Web Tier
» Configuring an IT Resource Instance for Email
» Creating and Importing New Rules
» Tuning Oracle Platform Security Backing Up the Application Tier Configuration
» Prerequisites Oracle Fusion Middleware Online Documentation Library
» Configuring Oracle Identity Federation on OIFHOST1
» Configuring Oracle Identity Federation on OIFHOST2
» Provisioning the Managed Servers on the Local Disk
» Validating Oracle Identity Federation Backing Up the Application Tier Configuration
» Generating Self-Signed Certificates Using the utils.CertGen Utility
» Configuring Node Manager to Use the Custom Keystores
» Starting Node Manager Configuring Managed WebLogic Servers to Use the Custom Keystores
» Configuring Server Migration Targets Click the Migration tab.
» Updating Existing LDAP Users with Required Object Classes
» Integrating Oracle Access Manager with Oracle Identity Manager by Using idmConfigTool
» Updating Oracle Virtual Directory Authenticator Manually Creating CSF Keys
» Managing the Password of the xelsysadm User Validating Integration
» Validating Oracle Adaptive Access Manager
» Prerequisites Creating Oracle Directory Authenticator
» On the Configure Web Server screen, click Yes to automatically update the web
» Validating WebGate Validating the Oracle Access Manager Single Sign-On Setup
» Monitoring Oracle Virtual Directory
» Monitoring Oracle Directory Integration Platform
» Scaling Up the Directory Tier
» Click the SSL tab. Click Advanced. Set Hostname Verification to None. Click Save.
» Click Save. Oracle Fusion Middleware Online Documentation Library
» Patching an Oracle Fusion Middleware Source File Patching Identity Management Components
» Troubleshooting Oracle Internet Directory
» Troubleshooting Oracle Virtual Directory
» Troubleshooting Oracle Directory Integration Platform
» Troubleshooting Oracle Directory Services Manager
Show more