Customizing the LDAP Schema

Third-Party Directory Integration Concepts and Considerations 16-19 the user search context attribute by using the Oracle Internet Directory Self-Service Console.

16.2.8 Select the Group Search Base

The group search context is represented by a multivalued attribute that lists all the containers under which groups exist. Depending on your deployment, either set the group search context value to cover all group entries, or add the container to the group search context attribute by using the Oracle Internet Directory Self-Service Console.

16.2.9 Decide How to Address Security Concerns

There are three main security concerns you need to consider: ■ Access policies—The user and group search bases should be appropriately protected from access by any malicious users. ■ Synchronization—You can configure the Oracle Directory Integration Platform to use SSL when connecting to Oracle Internet Directory and third-party directories. If you do this, then all information exchanged among the directory servers is secure. ■ Password synchronization—Depending on the configuration, passwords can be synchronized. For example, when Oracle Internet Directory is the central enterprise directory, password changes can be communicated to the connected directory. If passwords are to be synchronized, then Oracle recommends that you configure communication between the directories in SSL server authentication mode.

16.2.10 Administering Your Deployment with Oracle Access Manager

To use Oracle Access Manager to administer an Oracle Internet Directory deployment that synchronizes with a third-party directory, you must ensure that synchronized users are visible with Oracle Access Manager.

16.3 Microsoft Active Directory Integration Concepts

This section contains additional considerations for integrating Oracle Internet Directory with Microsoft Active Directory. It contains these topics: ■ Synchronizing from Microsoft Active Directory to Oracle Internet Directory ■ Requirement for Using WebDAV Protocol ■ Windows Native Authentication ■ Oracle Internet Directory Schema Elements for Microsoft Active Directory See Also: Oracle Fusion Middleware Guide to Delegated Administration for Oracle Identity Management for instructions about setting the user search context See Also: Oracle Fusion Middleware Guide to Delegated Administration for Oracle Identity Management for instructions about setting the group search context See Also: Oracle Access Manager Identity and Common Administration Guide for information about how to administer users in Oracle Access Manager