Resources Tab Creating an Policy Domain for Use with Oracle Web Services Manager

16-66 Oracle Fusion Middleware Application Security Guide

5. Default Authenticator

: Perform the following steps to set up the Default Authenticator for use with the Identity Asserter:

a. Go to Security Realms, Default Realm Name, and click Providers.

b. Click Authentication, Click DefaultAuthenticator to see its configuration

page.

c. Click the Common tab and set the Control Flag to SUFFICIENT.

d. Click Save. 6. Reorder Providers:

a. Click Security Realms, Default Realm Name, Providers.

b. On the Summary page where providers are listed, click the Reorder button

c. On the Reorder Authentication Providers page, select a provider name and

use the arrows beside the list to order the providers as follows: OAM Identity Asserter REQUIRED OID Authenticator SUFFICIENT Default Authenticator SUFFICIENT d. Click OK to save your changes

7. Activate

Changes: In the Change Center, click Activate Changes 8. Reboot Oracle WebLogic Server. 9. Proceed as follows: ■ Successful: Go to Testing the Identity Asserter with Oracle Web Services Manager . ■ Not Successful: Confirm the all providers have the proper specifications for your environment, are in the proper order, and that oamAuthnProvider.jar is in the correct location as described in Installing Components and Files for Authentication Providers and OAM 10g on page 16-4.

16.6.4 Testing the Identity Asserter with Oracle Web Services Manager

To validate the use of the Oracle Access Manager Identity Asserter with Oracle Web Services Manager, you can access the Web service protected by the Identity Asserter and Oracle Web Services Manager policies. If access is granted, the implementation works. If not, see Troubleshooting Tips for OAM Provider Deployments on page 16-69.

16.7 Synchronizing the User and SSO Sessions: SSO Synchronization Filter

In Fusion Middleware 11g, a new component that synchronizes the container user session and SSO session has been introduced. SSO Sync Filter is an Oracle WebLogic system filter implementation that intercepts all requests to the container, acts on protected resource requests, and attempts to synchronize the containers user session with the user identifying header in OSSO Proxy-Remote-User or the user data in the Oracle Access Manager SSO session cookie ObSSOCookie.