Changing Oracle Access Manager Security Model

Extending the Domain with Oracle Access Manager 11g 11-9 SetHandler weblogic-handler WebLogicHost ADMINVHN WeblogicPort 7001 Location Location oamconsole SetHandler weblogic-handler WebLogicHost ADMINVHN WebLogicPort 7001 Location VirtualHost Restart the Oracle HTTP Server, as described in Section 20.1, Starting and Stopping Oracle Identity Management Components.

11.5.4 Validating Accessibility

Attempt to access the Oracle Access Manager application using the URL: https:sso.mycompany.comoam The Oracle Access Manager screen is displayed. A message saying Action Failed appears on the screen. You can ignore the message because all you are testing is that the Oracle Access Manager server can be accessed through the Load Balancer. Attempt to Access the OAM console at: http:admin.mycompany.comoamconsole

11.6 Configuring Oracle Access Manager

This section contains the following topics: ■ Section 11.6.1, Changing Oracle Access Manager Security Model ■ Section 11.6.2, Configuring Oracle Access Manager by Using the IDM Automation Tool ■ Section 11.6.3, Configuring Oracle Access Manager for Multidirectory Support ■ Section 11.6.4, Validating the Configuration

11.6.1 Changing Oracle Access Manager Security Model

By default, Oracle Access Manager is configured to use the Open security model. Many applications require a different security model with a higher level of security. If you want to change the security model, proceed as follows: Log in to the OAM console at: http:admin.mycompany.comoamconsole as the WebLogic administration user. Then perform the following steps:

1. Click the System Configuration tab.

2. Expand Server Instances under the Common Configuration section.

3. Click an Oracle Access Manager server, for example, WLS_OAM1, then select

Open from the Actions menu.

4. Change the mode to the required security model, for example, Simple.

11-10 Oracle Fusion Middleware Enterprise Deployment Guide for Oracle Identity Management

5. Click Apply.

6. The Confirm Edit dialog appears: OAM Server instance wls_oam1 might be in use, are you sure you want to edit it? Select Yes. 7. Repeat for each Oracle Access Manager server.

8. Click Access Manager Settings located in the Access Manager Settings section.

9. Select Open from the Actions menu. The access manager settings are displayed.

10. If you have changed the security mode to Simple, supply a global passphrase. If you have changed the security mode to Cert Mode Configuration, provide the keystore details.

11. Click Apply.

12. Click the System Configuration tab.

13. Expand Access Manager Settings - SSO Agents.

14. Click OAM Agents and select Open from the Actions menu.

15. In the Search window, click Search.

16. Click IAMSuiteAgent in the search results. The Agent Properties are displayed.

17. Set the Security value to the new security model. Click Apply. 18. Restart the managed servers WLS_OAM1 and WLS_OAM2 as described in Section 20.1, Starting and Stopping Oracle Identity Management Components.

11.6.2 Configuring Oracle Access Manager by Using the IDM Automation Tool