Disabling LDAP Synchronization Oracle Fusion Middleware Online Documentation Library

Enabling LDAP Synchronization 10-9 ■ addPlugin: Adds a plug-in to an existing adapter or at the global level ■ addPluginParam: Add new parameter values to the existing adapter level plug-in or global plug-in ■ createJoinAdapter: Creates a new Join adapter for the Identity Virtualization Library libOVD associated with the given OPSS context ■ createLDAPAdapter: Creates a new LDAP adapter for the Identity Virtualization Library libOVD associated with the given OPSS context ■ deleteAdapter: Deletes an existing adapter for the Identity Virtualization Library libOVD associated with the given OPSS context ■ getAdapterDetails: Displays the details of an existing adapter that is configured for the Identity Virtualization Library libOVD associated with the given OPSS context ■ listAdapters: Lists the name and type of all adapters that are configured for this Identity Virtualization Library libOVD associated with the given OPSS Context ■ modifyLDAPAdapter: Modifies the existing LDAP adapter configuration ■ removeJoinRule: Removes a join rule from a Join adapter configured for this Identity Virtualization Library libOVD associated with the given OPSS Context ■ removeLDAPHost: Removes a remote host from an existing LDAP adapter configuration ■ removePlugin: Removes a plug-in from an existing adapter or at global level ■ removePluginParam: Removes an existing parameter from a configured adapter level plug-in or global plug-in 4. Run help on the individual commands to get usage, such as: helpaddPluginParam The following are examples for updating the AD User Management adapter for the oimLanguages attribute for Multi Language Support MLS: ■ addPluginParam: You can use this command to add oimLanguage param to UserManagement plug-in in AD user adapter, as shown: add PluginParamadapterName=ldap1, pluginName=UserManagement, paramKeys=oimLanguages, paramValues=fr,zh-CN, contextName=oim ■ removePluginParam: You can use this command to remove oimLanguage param from UserManagement plug-in in AD user adapter, as shown: removePluginParamadapterName=ldap1, pluginName=UserManagement, paramKey=oimLanguages, contextName=oim ■ removePluginParam: See Also: Developing Plug-ins in the Oracle Fusion Middleware Developers Guide for Oracle Identity Manager for information about developing plug-ins in Oracle Identity Manager 10-10 Oracle Fusion Middleware Administrators Guide for Oracle Identity Manager You can use this command to remove modifierDNFilter param from Changelog plug-in, as shown: removePluginParamadapterName=CHANGELOG_ldap1, pluginName=Changelog, paramKey=modifierDNFilter, contextName=oim

10.6 Configuring LDAP Authentication When LDAP Synchronization is Enabled

Use the following procedure to be able to use LDAP for authentication when LDAP synchronization is enabled. 1. Add a dynamic group in Oracle Internet Directory OID. a. Create an oimusers.ldif file that defines a dynamic group. The format of the LDIF file should be similar to the following: dn: cn=oimusers, group search base objectclass: orclDynamicGroup objectclass: groupOfUniqueNames labeleduri:ldap:LDAP_HOST:LDAP_PORTUserSearchBase??sub?objectclass=in etOrgPerson For example: dn: cn=oimusers,cn=Groups,dc=us,dc=oracle,dc=com objectclass: orclDynamicGroup objectclass: groupOfUniqueNames labeleduri: ldap:LDAP_HOST:3060cn=Users,dc=us,dc=oracle,dc=com??sub?objectclass=ine tOrgPerson b. Use the ldapadd command to upload the oimusers.ldif file to OID. The command should have the following format: ldapadd -h LDAP_HOST -p LDAP_PORT -D root dn -w password -f oimusers.ldif For example: ldapadd -h LDAP_HOST -p 3060 -D cn=orcladmin -w welcome1 -f oimusers.ldif c. Use the ldapsearch command to validate group members. The command should have the following format: ldapsearch -h LDAP_HOST -p LDAP_PORT -D root dn -w password -b cn=oimusers,groupsearchbase -s base objectclass= See Also: Creating Adapters in Oracle Virtual Directory in the Oracle Fusion Middleware Installation Guide for Oracle Identity Management for detailed information about creating the OVD adapters for Oracle Identity Manager change log and user management Note: This procedure does not enable the following functionality: ■ Forced password changes, including first login, administrator password reset, and expired passwords ■ Forced setting of challenge responses