Example 5: Automatic Account Linking via Attribute Query for a Specific IdP

6-44 Oracle Fusion Middleware Administrators Guide for Oracle Identity Federation

6.18.4 Example 2: Opt-In Mode

In this example, the opt-inopt-out feature is set to Opt-In, the attribute containing the user setting is fedrecordcreation, and the value indicating that the user opted in is agreed. Oracle Identity FederationIdP re-challenges the user for credentials during a federation creation operation only if the fedrecordcreation attribute value of the user is different from agreed. Perform the following steps to configure Oracle Identity FederationSP:

1. Log in to Fusion Middleware Control.

2. Navigate to Administration, then Identity Provider.

3. Select Opt-In as the Opt-InOpt-Out mode.

4. Set the Opt-InOut User Attribute to fedrecordcreation.

5. Set the Opt-InOut Attribute Value to agreed.

6. Apply the changes.

6.18.5 Example 3: Opt-Out Mode

In this example, the feature is set to optout, the attribute containing the user setting is fedrecordcreation and the value indicating that the user opted in is disallowed. Oracle Identity FederationIdP re-challenges the user for credentials during a federation creation operation only if the users fedrecordcreation attribute value equals disallowed. Perform the following steps to configure Oracle Identity FederationSP: 1. Log in to Fusion Middleware Control.

2. Navigate to Administration, then Identity Provider.

3. Select Opt-Out as the Opt-InOpt-Out mode.

4. Set the Opt-InOut User Attribute to fedrecordcreation.

5. Set the Opt-InOut Attribute Value to disallowed.

6. Apply the changes.

6.18.6 Example 4: Opt-In Mode for a Specific IdP

If Oracle Identity FederationIdP needs an Opt-In mode configuration specific to a peer service provider, then the setup information needs to be stored in the SP’s entry in the Federations list. In this example, the opt-inopt-out feature is set to Opt-In, the attribute containing the user setting is fedrecordcreation, and the value indicating that the user opted in is agreed, for an SP referenced by http:sp.com. Oracle Identity FederationIdP re-challenges the user for credentials during a federation creation operation only if the fedrecordcreation attribute value of the user is different from agreed. Perform the following steps to configure Oracle Identity FederationIdP: 1. Log in to Fusion Middleware Control.

2. Navigate to Administration, then Federations.