Ensure that the parameter Control Flag is set to OPTIONAL initially. Create an Administrators group in the directory server, if one does not already

15-32 Oracle Fusion Middleware Application Security Guide

a. Click Security Realms, Default Realm Name, and click Providers.

b. Click Authentication, click New, and then enter a name and select a type: Name: OAM Identity Asserter Type: OAMIdentityAsserter OK c. In the Authentication Providers table, click the newly added authenticator.

d. On the Common tab, set the Control Flag to REQUIRED, and click Save.

e. Click the Common tab, specify ObSSOCookie as the chosen Active Type for

the 10g custom AccessGate, and click Save.

f. Click the Provider Specific tab and configure these parameters:

Primary Access Server: Specify the host and part. For example: abcd:7777 Access Gate Name: The name of the OAM Agent registration protecting the application. For example: AG1 Access Gate Password: The AccessGate password, if any, that was specified in during provisioning. Save.

4. OID Authenticator

: Perform the following steps to add this provider.

a. Click Security Realms, Default Realm Name, and click Providers

b. Click New, enter a name, and select a type: Name: OID Authenticator Type: OracleInternetDirectoryAuthenticator Click OK. c. In the Authentication Providers table, click the newly added authenticator.

d. On the Settings page, click the Common tab, set the Control Flag to

SUFFICIENT , and then click Save.

e. Click the Provider Specific tab and specify the following required settings

using values for your own environment: Host: Your LDAP host. For example: localhost Port: Your LDAP host listening port. For example: 6050 Principal: LDAP administrative user. For example: cn=orcladmin Credential: LDAP administrative user password. User Base DN: Same searchbase as in Oracle Access Manager. All Users Filter: For example: uid=objectclass=person User Name Attribute: Set as the default attribute for username in the LDAP directory. For example: uid Group Base DN: The group searchbase same as User Base DN Note: Do not set the All Groups filter as the default works fine as is.