Deploying Oracle Identity Federation with Oracle Access Manager 11g

3-20 Oracle Fusion Middleware Administrators Guide for Oracle Identity Federation

3.2.5.1 Authentication Overview

This authentication operation occurs when Oracle Identity Federation uses an Oracle Access Manager federation authentication scheme, through the AccessGate installed on the machine hosting Oracle Identity Federation, to create a user session. The operation ensures that the module invoking the scheme is indeed the Oracle Identity Federation server and that no other process is trying to use the scheme. Operational Flow The deployment and run-time flow are as follows: 1. Using Fusion Middleware Control, the Oracle Identity Federation administrator createsupdates the existing Oracle Access Manager federation schemes to add two new plugins 2. Using Fusion Middleware Control, the Oracle Identity Federation administrator provides the necessary credentials to OIF 3. At runtime, Oracle Identity Federation passes the credentials along with the data used to create the Oracle Access Manager user session 4. The Oracle Access Manager server validates the Oracle Identity Federation credentials against the LDAP user repository 5. After the Oracle Identity Federation credentials are validated, an Oracle Access Manager user session is created Customizing the LDAP Account The administrator can customize the LDAP account used to validate the Oracle Identity Federation credentials to select: ■ the location of the entry that is, location different from the users branch ■ the object class of the entry Servers Authorized to Invoke Authentication For security reasons, the Oracle Identity Federation username can be set in the credential_mapping plugin of the federation scheme. This ensures that only the user corresponding to that account can be used when invoking this scheme. This feature is optional, but enabling it ensures that only authorized Oracle Identity Federation servers invoke the federation authentication schemes.

3.2.5.2 Enabling Authentication with Existing Federation Schemes

In this scenario: ■ Oracle Identity Federation is already deployed and integrated with Oracle Access Manager ■ Oracle Identity Federation is not configured for authentication to Oracle Access Manager ■ no federation schemes created in the Access server are configured for Oracle Identity Federation authentication to Oracle Access Manager The configuration involves: ■ creating an account in the LDAP directory to use for Oracle Identity Federation authentication