Engines in Oracle Identity Federation Authenticating with a Repository

Planning Oracle Identity Federation Deployment 2-17 ■ Oracle Identity Federation communicates with the authenticated user Step 2.

2.3.3 Authenticating with an IdM Solution in IdP Mode

In this deployment, the authentication module delegates authentication to the Oracle Single Sign-On IdM solution or Oracle Access Manager to enable Oracle Identity Federation to authenticate in IdP mode. Figure 2–8 Authenticating with an IdM Solution in IdP Mode The flow for a local authentication involving an IdM deployment is as follows: ■ The user accesses Oracle Identity Federation Step 1. ■ Oracle Identity Federation forwards the user to the authentication module for local authentication Step 2. ■ The authentication module redirects the user to the IdM server for authentication Steps 3,4. ■ The IdM server authenticates the user and redirects the user back to the authentication module Steps 5,6. ■ The authentication module forwards the user to Oracle Identity Federation with the user’s identification Step 7. ■ Oracle Identity Federation communicates with the authenticated user Step 8.

2.3.4 Propagating Authentication State to Oracle Access Manager in SP Mode

In this mode, Oracle Identity Federation uses the federation protocols to identify a user, and requests the authentication module to create an authenticated session at Oracle Access Manager so that the user can access the requested resource, which is protected by WebGate for an Oracle Access Manager IdM deployment. The request originates at a peer IdP, and Oracle Identity Federation authenticates in SP mode. 2-18 Oracle Fusion Middleware Administrators Guide for Oracle Identity Federation Figure 2–9 Authenticating with Oracle Access Manager in SP Mode The flow for authenticating a user at a peer provider with Oracle Access Manager is as follows: ■ The user is at the peer IdP Step 1. ■ The IdP redirects the user to Oracle Identity Federation as SP with an authentication assertion Steps 2,3. ■ Oracle Identity Federation processes the assertion, creates a local Oracle Identity Federation session, and forwards the user to the authentication module with the identification Step 4. ■ The authentication module interacts with Oracle Access Manager to create an Oracle Access Manager authenticated session Step 5. ■ The authentication module redirects the user to the protected resource Step 6. ■ WebGate Web Agent grant the user access to the protected resource Step 7.

2.3.5 Propagating Authentication State to Oracle Single Sign-On in SP Mode

In this mode, Oracle Identity Federation uses the federation protocols to identify a user, and requests the authentication module to create an authenticated session at Oracle Single Sign-On so that the user can access the requested resource, which is protected by mod_osso. The request originates at a peer IdP, and Oracle Identity Federation authenticates in SP mode.