Develop Possible Causes Process Flow of Analysis

23-12 Oracle Fusion Middleware Developers Guide for Oracle Adaptive Access Manager AnswerSolution : No, URL must be an exact match and query parameters, such as anything after a ? are not considered part of the URL, so they would have to be trapped with a condition, and not included as part of the URL.

23.4 Knowledge-Based Authentication

Prompt a User with Two Challenge Questions QuestionProblem : I would like to prompt a user with two challenge questions when they attempt to logon from a new device. How can this be achieved given that the questions are randomly picked, raising the possibility that the same question may be displayed twice? AnswerSolution : The OAAM one question at a time flow is by design. It is better security practice to present one question and only show the next question once the user has successfully answered the challenge. This protects the questions from being harvested for use in a phishing exercise. As well, OAAM allows users to have multiple attempts at a question which entails keeping track of how many wrong answers they have entered. If there were more than one question displayed at a time it would be difficult to maintain and possibly confusing to end users. If you want to challenge a user with more than one question you should do so by presenting them in separate sequential screens. OAAM does not support authentication of more than one question at a time.

23.5 Virtual Authentication Devices

Accessible Versions of the Virtual Authentication Devices QuestionProblem : Users who access using assistive techniques need to use the accessible versions of the virtual authentication devices. How do I enable these versions? AnswerSolution : Accessible versions of the TextPad, QuestionPad, KeyPad and PinPad are not enabled by default. If accessible versions are needed in a deployment, they can be enabled using the Properties Editor in OAAM Admin or using the Oracle Adaptive Access Manager extensions shared library. The accessible versions of the virtual authentication devices contain tabbing, directions and ALT text necessary for navigation via the screen reader and other assistive technologies. You will need to modify bharosa_server.properties. To enable these versions, set the is ADA compliant flag to true. For native integration the property to control the virtual authentication device is desertref.authentipad.isADACompliant For Oracle Adaptive Access Manager out-of-the-box, the property to control the virtual authentication device is bharosa.uio.default.authentipad.is_ada_compliant Visible Text Input or Password Non-Visible Input Setting QuestionProblem : How can I configure QuestionPad so that challenge answers can be enter as non-visible text?