Click Add to add a new step.

Deploying Oracle Identity Federation 3-23

3.2.5.3 Enabling Authentication when Creating New Federation Schemes

This configuration supports the following scenario: ■ Oracle Identity Federation is already deployed and integrated with Oracle Access Manager, or Oracle Identity Federation is deployed but not yet integrated with Oracle Access Manager. ■ Oracle Identity Federation is not configured for authentication to Oracle Access Manager. ■ No federation schemes have been created in Access server. The tasks include: ■ creating the account in the LDAP directory used for Oracle Identity Federation authentication ■ setting information about the Oracle Identity Federation account, and any Oracle Identity FederationOracle Access Manager integration which might involve creating new authentication schemes, in Fusion Middleware Control. ■ creating new federation schemes using Fusion Middleware Control Create the LDAP Account So that Oracle Identity Federation can authenticate to Oracle Access Manager when using a federation scheme, the LDAP directory must contain an entry to use in validating the Oracle Identity Federation credentials. If no such entry exists, you must create one that is both searchable based on an identifier and has a password attribute. You use Fusion Middleware Control to set: ■ the identifier ■ passwords ■ the base DN of the entry ■ the entry’s object class ■ the attribute to contain the identifier You can choose: ■ a location for the entry different from the branch where all user records are located ■ an object class different from the user record type Set Up Oracle Identity Federation Account Information To configure Oracle Identity Federation to present credentials when invoking a federation scheme, take these steps: 1. Log in to Fusion Middleware Control and navigate to the Oracle Identity Federation instance.

2. Navigate to SP Integration Modules, then Oracle Access Manager.

3. Enable Oracle Identity Federation authentication. 4. Enter the username and password of the account to use for Oracle Identity Federation authentication. 5. Enter the Base DN referencing the location where the Oracle Identity Federation account is located. 6. Enter the object class of the LDAP entry to use for Oracle Identity Federation authentication.