Now you are ready to customize the report. Click Edit from the menu choices You can use the Query Builder to customize the data to include in your report. For

14 Introduction to Single Sign-On in Oracle Fusion Middleware 14-1 14 Introduction to Single Sign-On in Oracle Fusion Middleware The chapter outlines a set of recommended single sign-on solutions for Oracle Fusion Middleware. This chapter includes the following major sections: ■ Choosing the Right SSO Solution for Your Deployment ■ Introduction: OAM Authentication Provider for WebLogic Server ■ Setting Up Debugging in the WebLogic Administration Console

14.1 Choosing the Right SSO Solution for Your Deployment

Oracle Platform Security Services comprise Oracle WebLogic Server’s internal security framework. A WebLogic domain uses a separate software component called an Authentication Provider to store, transport, and provide access to security data. Authentication Providers can use different types of systems to store security data. The Authentication Provider that WebLogic Server installs uses an embedded LDAP server. Oracle Fusion Middleware 11g supports new single sign-on solutions that applications can use to establish and enforce perimeter authentication: ■ Oracle Access Manager solutions ■ Oracle Single Sign-On OSSO solution Customers must carefully choose the solution appropriate to their needs. Selecting the right SSO solution requires careful consideration and depends upon your requirements. This section outlines some general information and guidelines to help you choose the best solution for your needs. Note: Oracle recommends that you consider upgrading to Oracle Access Manager 11g Single Sign on solution to take advantage of additional functionality and architecture. See Also: ■ Oracle Fusion Middleware Security Overview ■ Oracle Fusion Middleware Administrators Guide for Oracle Access Manager with Oracle Security Token Service 14-2 Oracle Fusion Middleware Application Security Guide ■ Development or Small Stand-Alone Environment : Oracle recommends a light-weight SSO solution when deployed applications are not integrated into an enterprise-level single sign-on framework. In such cases, a SAML-based solution that uses the Oracle WebLogic Server SAML Credential Mapping Provider is best. The embedded LDAP server is used as the default user repository. Alternatively, an LDAP Authenticator can be configured to leverage an external LDAP server as a user repository. ■ Enterprise-Level SSO with Oracle Fusion Middleware 11g : Oracle Access Manager supports: – A wide variety of LDAP vendors as the user and group repository and also works with Oracle Virtual Directory – Integration with non-Oracle application server vendors and Web Tier components on a large variety of OS platforms to provide a flexible solution. – Oracle Access Manager 11g supports out-of-the-box integration with Oracle Fusion Middleware applications Oracle Access Manager 11g Release 1 : Oracle recommends Oracle Access Manager 11g whether: – You are new to Oracle Fusion Middleware – You are considering a migration from OSSO – You are considering an enterprise-level SSO solution – You want to implement Identity Propagation with the OAM Token, as described in the Oracle Fusion Middleware Administrators Guide for Oracle Access Manager with Oracle Security Token Service Oracle Access Manager 10g 10.1.4.3: You can continue using this when you have: – Existing Oracle Access Manager 10g implementations – An enterprise-level SSO solution Selecting the right Oracle Access Manager solution 11g versus 10g 10.1.4.3 as your enterprise-level Single-Sign-on solution depends upon your requirements. Refer to product documentation in this chapter and in the respective administration guides to evaluate the release that best meets your overall requirements. ■ Existing OSSO 10g Customers : Oracle Single Sign-On is part of the 10g Oracle Application Server suite. OSSO is an enterprise-level single sign-on solution that works with the OC4J application server in conjunction with Oracle Internet Directory and Oracle HTTP Server 11g. If OSSO is already in place as the enterprise solution for your existing Oracle deployment, Oracle Fusion Middleware continues to support the existing OSSO as a solution. However, Oracle recommends that you consider upgrading to Oracle Access Manager 11g Single Sign on solution, which is a strategic Oracle SSO See Also: Configuring Single Sign-On with Web Browsers and HTTP Clients in Oracle Fusion Middleware Securing Oracle WebLogic Server See Also: Introduction: OAM Authentication Provider for WebLogic Server on page 14-4