Navigate to Administration, then Authentication Engines, then Oracle SSO. Navigate to Administration, then Authentication Engines, then Oracle SSO. Enter the Oracle Single Sign-On Server Logout URL:

Deploying Oracle Identity Federation 3-7 1. Log in to Fusion Middleware Control and navigate to the Oracle Identity Federation instance.

2. Navigate to Administration, then Service Provider Integration Modules, then

Oracle SSO . 3. Enable the SP Module. 4. Select the authentication mechanism that will be used to locally authenticate users if federated identities are used during Federation SSO and if a federation record needs to be created during the SSO operation. 5. Enter the username attribute that Oracle Identity Federation needs to provide to Oracle SSO. Default is uid. 6. Enter the Oracle Single Sign-On server login URL: http:osso-hostname:osso-portssoauth 7. Enter the Oracle Single Sign-On server logout URL: http:osso-hostname:osso-portssologout

8. Check Logout Enabled.

9. Click Regenerate OSSO Secret to create an encryption key that will be saved in a

file and provided to Oracle Single Sign-On. Save the keystore locally. 10. Save the changes. If Oracle Single Sign-On is integrated as an authentication engine for Oracle Identity Federation and an SP integration module, then the Oracle Single Sign-On authentication engine logout must be disabled, as the SP integration module is managing the logout. To disable the logout for Oracle Single Sign-On authentication engine in Oracle Identity Federation: 1. Log in to Fusion Middleware Control and navigate to the Oracle Identity Federation instance.

2. Navigate to Administration, then Authentication Engines, then Oracle SSO.

3. Disable logout. 4. Save the changes.

3.2.2.5 Configure Oracle Single Sign-On

This part of the setup requires setup on the Oracle Single Sign-On server, and partner configuration. To set up Oracle Single Sign-On: See Also: Section 5.16, Configuring SP Integration Modules See Also: Section 5.15, Configuring Authentication Engines Note: A partner application is an Oracle Application Server-based application or a non-Oracle application that delegates the authentication function to the Oracle Single Sign-On server. A partner application is responsible for determining whether a user authenticated by Oracle Single Sign-On is authorized to use the application.