Reassociating with the Script reassociateSecurityStore

8-22 Oracle Fusion Middleware Application Security Guide

8.7.3 Specifying a Single Sign-On Solution

This section explains the OPSS Single Sign-On SSO Framework and how to configure an SSO solution using Fusion Middleware Control, in the following sections: ■ The OPSS SSO Framework ■ Configuring an SSO Solution with Fusion Middleware Control ■ OAM Configuration Example

8.7.3.1 The OPSS SSO Framework

The OPSS SSO Framework provides a way to integrate applications in a domain with an SSO solution. Specifically, it provides applications a common set of APIs across SSO products, to handle login, logout and auto login. One of these solutions, the OAM solution, is available out-of-the-box, and it includes the following features: ■ Dynamic authentication - Upon accessing a part of a secured artifact that requires authentication, the application triggers authentication and redirects the user to be authenticated by the appropriate solution. ■ Auto login - A user who has initially accessed an application anonymously registers an account with the application; upon a successful registration, the user is redirected to the authentication URL; the user can also be automatically logged in without being prompted. ■ Global logout - When a user logs out of one application, the logout propagates across to any other application that is enabled by the solution. For a configuration example of an OAM solution, see OAM Configuration Example . An SSO solution must provide a standard way for applications to login and logout users. After successful authentication, the SSO service is responsible to redirect the user to the appropriate URL. It is assumed that the domain where the solution is applied has been configured to allow the Subject to contain the anonymous user and role before login and after logout, and authenticated roles after login. It is also assumed that the SSO provider has implemented a Credential Mapping Service. In the case of the out-of-the-box OAM solution, the provider implements CredentialMapperService that produces the appropriate OAM token. The OPSS SSO framework does not support multi-level authentication. Integration with the desired SSO solution requires a separate installation and appropriate configuration of the solution. For details about recommended solutions, see Part IV, Single Sign-On Configuration .

8.7.3.2 Configuring an SSO Solution with Fusion Middleware Control

To specify the SSO solution used by a domain, proceed as follows:

1. Log in to Fusion Middleware Control and navigate to Domain Security

Security Provider Configuration or Cell Security Security Provider Configuration to display the Security Provider Configuration page.

2. In that page, click the Configure in the Single Sign-On Provider area to display the

Single Sign-On Provider page.

3. In that page, check the box Configure Single Sign-On, to allow entering data for

the provider. All boxes are grayed out until this box is checked.