Authentication Overview Oracle Identity FederationSP Authenticating to Oracle Access Manager

Deploying Oracle Identity Federation 3-21 ■ setting Oracle Identity Federation account information to enable authentication using Fusion Middleware Control ■ updating all existing federation schemes to define the new Oracle Access Manager plugins using Fusion Middleware Control ■ updating all existing federation schemes to define new authentication flows for the new plugins using the Oracle Access Manager console Create the LDAP Entry So that Oracle Identity Federation can authenticate to Oracle Access Manager when using a federation scheme, the LDAP directory must contain an entry to use in validating the Oracle Identity Federation credentials. If no such entry exists, create one that is both searchable based on an identifier and has a password attribute. You use Fusion Middleware Control to set: ■ the identifier ■ passwords ■ the base DN of the entry ■ the entry’s object class ■ the attribute to contain the identifier You can choose: ■ a location for the entry different from the branch where all user records are located ■ an object class different from the user record type Set Up Oracle Identity Federation Account Information To configure Oracle Identity Federation to present credentials when invoking a federation scheme, take these steps: 1. Log in to Fusion Middleware Control and navigate to the Oracle Identity Federation instance.

2. Navigate to SP Integration Modules, then Oracle Access Manager.

3. Check the box to enable Oracle Identity Federation authentication. 4. Enter the username and password of the account to use for Oracle Identity Federation authentication. 5. Enter the Base DN referencing the location where the Oracle Identity Federation account is located. 6. Enter the object class of the LDAP entry to use for Oracle Identity Federation authentication. 7. Enter the LDAP entry attribute that will contain the username and is searchable for example, uid if it is defined in the LDAP entry. Define New Plug-ins Next update the existing federation schemes to include two new plugins used for the authentication operation. Take these steps: 1. Log in to Fusion Middleware Control and navigate to the Oracle Identity Federation instance.

2. Navigate to SP Integration Modules, then Oracle Access Manager.