Navigate to SP Integration Modules, then Oracle Access Manager. Navigate to SP Integration Modules, then Oracle Access Manager.

3-22 Oracle Fusion Middleware Administrators Guide for Oracle Identity Federation

3. Select and click Update for all the federation schemes that were created in Oracle

Access Manager. 4. Enter the Oracle Access Manager administrator credentials to enable administrative update operations to be performed on the Oracle Access Manager server.

5. Click Configure Oracle Access Manager.

This updates the schemes with two new plugins: ■ a credential_mapping plugin used to locate the Oracle Identity Federation account. ■ a validate_password plugin used to validate the password provided by Oracle Identity Federation against the one from the Oracle Identity Federation account. Define New Authentication Flows Due to Access Server limitations, you cannot use Fusion Middleware Control to create new authentication flows to uptake the new plugins created in the previous step; instead, you must use the Oracle Access Manager console to create those objects. For each federation scheme you updated, perform these actions: 1. Log in to the Oracle Access Manager console as administrator. 2. Navigate to the Access System Console, then Access System Configuration, then Authentication Management. 3. Select the federation scheme you wish to update. 4. Click the Steps tab.

5. Click Add to add a new step.

6. Enter a name for the step in the Step Name field. 7. In the Available Plugins table, perform these steps in order:

a. Select the second credential_mapping plugin and click add.

b. Select the validate_password plugin and click add.

c. Select the first credential_mapping plugin and click add.

8. Click Save.

9. Click the Authentication Flow tab.

10. Click Modify.

11. Select the new step as the Initiating Step. 12. Select Stop for On Success Next Step. 13. Select Stop for On Failure Next Step.

14. Click Save.

15. Click the Steps tab.

16. Select the old step. Click Delete.

Note: The order is important. Deploying Oracle Identity Federation 3-23

3.2.5.3 Enabling Authentication when Creating New Federation Schemes

This configuration supports the following scenario: ■ Oracle Identity Federation is already deployed and integrated with Oracle Access Manager, or Oracle Identity Federation is deployed but not yet integrated with Oracle Access Manager. ■ Oracle Identity Federation is not configured for authentication to Oracle Access Manager. ■ No federation schemes have been created in Access server. The tasks include: ■ creating the account in the LDAP directory used for Oracle Identity Federation authentication ■ setting information about the Oracle Identity Federation account, and any Oracle Identity FederationOracle Access Manager integration which might involve creating new authentication schemes, in Fusion Middleware Control. ■ creating new federation schemes using Fusion Middleware Control Create the LDAP Account So that Oracle Identity Federation can authenticate to Oracle Access Manager when using a federation scheme, the LDAP directory must contain an entry to use in validating the Oracle Identity Federation credentials. If no such entry exists, you must create one that is both searchable based on an identifier and has a password attribute. You use Fusion Middleware Control to set: ■ the identifier ■ passwords ■ the base DN of the entry ■ the entry’s object class ■ the attribute to contain the identifier You can choose: ■ a location for the entry different from the branch where all user records are located ■ an object class different from the user record type Set Up Oracle Identity Federation Account Information To configure Oracle Identity Federation to present credentials when invoking a federation scheme, take these steps: 1. Log in to Fusion Middleware Control and navigate to the Oracle Identity Federation instance.

2. Navigate to SP Integration Modules, then Oracle Access Manager.

3. Enable Oracle Identity Federation authentication. 4. Enter the username and password of the account to use for Oracle Identity Federation authentication. 5. Enter the Base DN referencing the location where the Oracle Identity Federation account is located. 6. Enter the object class of the LDAP entry to use for Oracle Identity Federation authentication.