Why Oracle Identity Management Integration?

1-2 Oracle Fusion Middleware Administrators Guide for Oracle Directory Integration Platform Directory as the central enterprise directory. Users of that directory can still access Oracle components because Oracle Directory Integration Platform can synchronize the data in Microsoft Active Directory with that in Oracle Internet Directory.

1.2 Oracle Identity Management Installation Options

Oracle Directory Integration Platform can be installed simultaneously with other Oracle Identity Management components or by itself as a standalone instance. To install a standalone Oracle Directory Integration Platform instance, an Oracle Internet Directory component must already be installed. You should install a standalone instance of Oracle Directory Integration Platform under the following circumstances: ■ You need Oracle Directory Integration Platform to be installed in a different application server instance. ■ The applications that you need to provision and synchronize require intensive processing. ■ You need to run multiple instances of Oracle Directory Integration Platform for high availability.

1.3 Synchronization, Provisioning, and the Differences Between Them

Synchronization has to do with directories rather than applications. It ensures the consistency of entries and attributes that are in both Oracle Internet Directory and other connected directories. Provisioning has to do with applications. It notifies them of changes to user or group entries or attributes that the application needs to track. This section contains these topics: ■ Synchronization ■ Provisioning ■ How Synchronization and Provisioning Differ

1.3.1 Synchronization

Synchronization enables you to coordinate changes among Oracle Internet Directory and connected directories. For all directories to both use and provide only the latest See Also: ■ Chapter 10, Synchronizing with Oracle Human Resources ■ Chapter 18, Integrating with Microsoft Active Directory ■ Chapter 20, Integrating with Oracle Directory Server Enterprise Edition Sun Java System Directory Server See: The Oracle Fusion Middleware Installation Guide for Oracle Identity Management for complete information about installing Oracle Directory Integration Platform. Note: Synchronization and Replication are not synonymous. Replication is used for data handling between directories of the same vendor. Introduction to Oracle Identity Management Integration 1-3 data, each directory must be informed of changes made in the other connected directories. Synchronization ensures that changes to directory information—including, but not limited to data updated through provisioning—is kept consistent. Whenever you decide to connect a third-party directory to Oracle Internet Directory, you create a synchronization profile for that specific directory. This profile specifies the format and content of the data to be synchronized between Oracle Internet Directory and the connected directory. To create a synchronization profile, you can use the manageSyncProfiles utility or Oracle Enterprise Manager Fusion Middleware Control.

1.3.2 Provisioning

Provisioning enables you to ensure that an application is notified of directory changes to, for example, user or group information. Such changes can affect whether the application allows a user access to its processes and determines which resources can be used. Use provisioning when you are designing or installing an application has the following requirements: ■ Does not maintain a directory ■ Is LDAP-enabled ■ Can and should allow only authorized users to access its resources When you install an application that you want to provision, you must create a provisioning integration profile for it by using the oidprovtool utility.

1.3.3 How Synchronization and Provisioning Differ

Synchronization and provisioning have important operational differences, as described in Table 1–1 . See Also: Part III, Synchronization Using Oracle Directory Integration Platform See Also: Part IV, Provisioning with the Oracle Directory Integration Platform Table 1–1 Directory Synchronization and Provisioning Integration Distinctions Consideration Directory Synchronization Provisioning Integration The time for action Application deployment time. Directory synchronization is for connected directories requiring synchronization with Oracle Internet Directory. Application design time. Provisioning integration is for application designers developing LDAP-enabled applications. Communication direction Either one-way or two-way—that is, either from Oracle Internet Directory to connected directories, the reverse, or both Either one-way or two-way—that is, either from Oracle Internet Directory to applications, the reverse, or both Type of data Any data in a directory Restricted to provisioned users and groups