Expand the WebLogic Domain icon in the Navigation tree in the left pane.

2-6 Oracle Fusion Middleware Administrators Guide for Oracle Adaptive Access Manager

3. Select OAAM domain and right-click and select the menu option Security, and

then the option Credentials in the submenu. 4. Check if there is a map with the name oaam. If not, click the Create Map option and enter the Map Name as oaam. Click OK to save the map.

5. Click oaam to select the map and then click Create Key.

6. In the pop-up dialog make sure Select Map is oaam.

7. Enter: ■ Key Name : DESede_db_key_alias if the key is database-related or DESede_config_key_alias if it is configurationapplication related. Make sure there are no typos or spaces. ■ Type : Generic. ■ Credential Value : encoded value of the symmetric key

8. Enter a description in the Description field.

9. Click OK to save the secret key to the Credential Store Framework.

10. Make sure you back up the alias and the secret key. The backup is required if you must recreate the domain and point the domain to the existing Oracle Adaptive Access Manager database. 2.4.7 Setting Up Oracle Adaptive Access Manager Database Credentials in the Credential Store Framework To set up the Oracle Adaptive Access Manager database credentials in the Credential Store Framework: 1. Log in to Fusion Middleware Control at http:weblogic_admin_server:portem using the Web browser and use the WebLogic Administrator credentials to log in.

2. Expand the WebLogic Domain icon in the Navigation tree in the left pane.

3. Select the OAAM domain and right-click and select the menu option Security and

then the option Credentials in the submenu. 4. Check to see whether there is a map with the name oaam. If not click the Create Map option and enter the Map Name as oaam. Click OK to save the map. 5. Click oaam to select the map and then click Create Key. OAAM Servers automatically generate the secret key if you start them after domain creation. You can choose to use those auto-generated secret keys if you do not want to use different secret keys.

6. In the pop-up dialog make sure Select Map is oaam.

7. Enter the following: ■ Key : oaam_db_key. Make sure there are no typos and spaces. ■ Type : Password ■ UserName : database user name of OAAM Note: If you lose the secret key, all the existing data in the Oracle Adaptive Access Manager database becomes unusable since many important administrative operations involve encrypted data. Setting Up the Oracle Adaptive Access Manager Environment for the First Time 2-7 ■ Password : database password of OAAM 8. Enter the description.

9. Click OK to save the secret key to the Credential Store Framework.

2.4.8 Backing Up Secret Keys and Database and Configuration Keys

You must back up the secret keys used. You may need these keys, if you have to recreate the Oracle Adaptive Access Manager 11g domain. Make sure you note the secret key and the alias name. 1. Log in to Oracle Enterprise Manager.

2. Expand the WebLogic Domain on the left pane, and select OAAM domain.

3. From the OAAM Domain, select Security, and then Credentials.

4. Expand oaam and select the symmetric key related entries associated with the

Type Generic. 5. Click Edit. 6. Go to the Credentials section then copy the symmetric key related entries and note the key name. 7. Repeat the above steps to back-up database and configuration keys.

2.5 Creating OAAM Users

Before you can access the Oracle Adaptive Access Manager Administration Console, you must create users. Creating these users allows you to use OAAM. The user can be created in the WebLogic Administration Console. Details for creating an administration user in the WebLogic Administration Console are provided below. If you want to take care of user and group creation in the external LDAP store, see Creating Users and Groups for Oracle Adaptive Access Manager in the Oracle Fusion Middleware Enterprise Deployment Guide for Oracle Identity Management. You create a user as follows:

1. Log in to the Oracle WebLogic Administration Console for your WebLogic

administration domain.

2. In the left pane, select Security Realms.

3. On the Summary of Security Realms page select the name of the realm for

example, myrealm.

4. On the Settings for Realm Name page select Users and Groups Users.

5. Click New and provide the required information to create a user, such as user1,

in the security realm.

6. Click the newly created user, user1.

7. Click the Groups tab.

Note: If you delete and recreate the Oracle Adaptive Access Manager 11g domain, make sure you use the backed-up secret keys when setting the encryption keys so that the existing data in the Oracle Adaptive Access Manager database can be decrypted properly.