Example 3: Complex Automatic Account Linking through LDAPSQLQuery Example 4: Automatic Account Linking through LDAPSQL Query and NameID Mapping

Additional Server Configuration 6-43 ■ Example 3: Opt-Out Mode ■ Example 4: Opt-In Mode for a Specific IdP

6.18.1 Modes of Operation

Oracle Identity FederationIdP can implement this feature in three modes: 1. Off - The Opt-inOpt-out functionality is not exercised 2. Opt-In - If the user attribute for opt-inopt-out equals the value set by the administrator, Oracle Identity FederationIdP does not force the user to re-authenticate for Federation SSO operations; otherwise it forces re-authentication. 3. Opt-Out - If the user attribute for opt-inopt-out equals the value set by the administrator, then Oracle Identity FederationIdP forces the user to re-authenticate for Federation SSO operations; otherwise it does not force re-authentication.

6.18.2 Configuring Oracle Identity Federation

To configure Oracle Identity Federation to use Opt-InOpt-Out: 1. Log in to Fusion Middleware Control.

2. Navigate to Administration, then Identity Provider.

3. Select the Opt-InOpt-Out mode:

■ Off: indicates that the Opt-inOpt-out feature is not exercised ■ Opt-In: indicates that the Opt-in mode is active ■ Opt-Out: indicates that the Opt-out mode is active 4. If the mode is set to Opt-In or Opt-Out, then enter the Opt-InOut user attribute that references the attribute to retrieve from the user record. Its value is compared against the value set by the administrator. 5. If the mode is set to Opt-In or Opt-Out, then enter the Opt-InOut attribute value holding the value set by the administrator and used to compare against the user attribute.

6.18.3 Example 1: Off Mode

In this example, the opt-inopt-out feature is turned off so that the user is never re-challenged for credentials when a federation record is created on Oracle Identity FederationIdP. Perform the following steps to configure Oracle Identity FederationSP: 1. Log in to Fusion Middleware Control.

2. Navigate to Administration, then Identity Provider.

3. Select Off as the Opt-InOpt-Out mode. 4. Apply the changes. 6-44 Oracle Fusion Middleware Administrators Guide for Oracle Identity Federation

6.18.4 Example 2: Opt-In Mode

In this example, the opt-inopt-out feature is set to Opt-In, the attribute containing the user setting is fedrecordcreation, and the value indicating that the user opted in is agreed. Oracle Identity FederationIdP re-challenges the user for credentials during a federation creation operation only if the fedrecordcreation attribute value of the user is different from agreed. Perform the following steps to configure Oracle Identity FederationSP:

1. Log in to Fusion Middleware Control.

2. Navigate to Administration, then Identity Provider.

3. Select Opt-In as the Opt-InOpt-Out mode.

4. Set the Opt-InOut User Attribute to fedrecordcreation.

5. Set the Opt-InOut Attribute Value to agreed.

6. Apply the changes.

6.18.5 Example 3: Opt-Out Mode

In this example, the feature is set to optout, the attribute containing the user setting is fedrecordcreation and the value indicating that the user opted in is disallowed. Oracle Identity FederationIdP re-challenges the user for credentials during a federation creation operation only if the users fedrecordcreation attribute value equals disallowed. Perform the following steps to configure Oracle Identity FederationSP: 1. Log in to Fusion Middleware Control.

2. Navigate to Administration, then Identity Provider.

3. Select Opt-Out as the Opt-InOpt-Out mode.

4. Set the Opt-InOut User Attribute to fedrecordcreation.

5. Set the Opt-InOut Attribute Value to disallowed.

6. Apply the changes.

6.18.6 Example 4: Opt-In Mode for a Specific IdP

If Oracle Identity FederationIdP needs an Opt-In mode configuration specific to a peer service provider, then the setup information needs to be stored in the SP’s entry in the Federations list. In this example, the opt-inopt-out feature is set to Opt-In, the attribute containing the user setting is fedrecordcreation, and the value indicating that the user opted in is agreed, for an SP referenced by http:sp.com. Oracle Identity FederationIdP re-challenges the user for credentials during a federation creation operation only if the fedrecordcreation attribute value of the user is different from agreed. Perform the following steps to configure Oracle Identity FederationIdP: 1. Log in to Fusion Middleware Control.

2. Navigate to Administration, then Federations.