Identity Store and Policy Store in Oracle Internet Directory Prerequisites for Configuring Oracle Identity Directory Instances

7 Extending the Domain with Oracle Internet Directory 7-1 7 Extending the Domain with Oracle Internet Directory This chapter describes how to extend the domain with Oracle Internet Directory OID in the enterprise deployment. This chapter includes the following topics: ■ Section 7.1, Identity Store and Policy Store in Oracle Internet Directory ■ Section 7.2, Prerequisites for Configuring Oracle Identity Directory Instances ■ Section 7.3, Configuring the Oracle Internet Directory Instances ■ Section 7.4, Post-Configuration Steps ■ Section 7.5, Validating the Oracle Internet Directory Instances ■ Section 7.6, Tuning Oracle Internet Directory ■ Section 7.7, Backing up the Oracle Internet Directory Configuration

7.1 Identity Store and Policy Store in Oracle Internet Directory

You use the Identity Store for storing information about users and groups. You use Policy Store for storing information about security policies and for configuration information. Although you can use a single Oracle Internet Directory instance for storing both the identity and policy information, it is recommended that you use two directory stores. If you intend to separate your identity and policy information, you must create two highly available instances of Oracle Internet Directory. These instances can coexist on the same nodes or can exist on separate nodes. The data, however, must be stored in two separate databases. If policy information must reside in Oracle Internet Directory, you can place identity information into a different directory, such as Active Directory. The procedure for installing and configuring the two instances of Oracle Internet Directory is the same. You must, however, point idstore.mycompany.com at one of the instances and policystore.mycompany.com at the other.

7.2 Prerequisites for Configuring Oracle Identity Directory Instances

Before configuring the Oracle Internet Directory instances on OIDHOST1 and OIDHOST2, ensure that the following tasks have been performed: 1. Synchronize the time on the individual Oracle Internet Directory nodes using Greenwich Mean Time so that there is a discrepancy of no more than 250 seconds between them. 7-2 Oracle Fusion Middleware Enterprise Deployment Guide for Oracle Identity Management 2. Install and upgrade the software on OIDHOST1 and OIDHOST2 as described in Section 4.5.5, Installing Oracle Identity Management. 3. If you plan on provisioning the Oracle Internet Directory instances on shared storage, ensure that the appropriate shared storage volumes are mounted on OIDHOST1 and OIDHOST2 as described in Section 2.4, Shared Storage and Recommended Directory Structure. 4. Ensure that the load balancer is configured.

7.3 Configuring the Oracle Internet Directory Instances