Configuring Oracle WebLogic Server Web Services

5-26 Oracle Fusion Middleware System Administrators Guide for Oracle Content Server application-nameibr.earapplication-name variable-definition variable namehttp-onlyname valuefalsevalue variable variable-definition module-override module-nameibr.warmodule-name module-typewarmodule-type module-descriptor external=false root-elementweblogic-web-approot-element uriWEB-INFweblogic.xmluri variable-assignment namehttp-onlyname xpathweblogic-web-appsession-descriptorcookie-http-onlyxpath variable-assignment module-descriptor module-override deployment-plan urm-deployment-plan.xml Use the provided urm-deployment-plan.xml file, or create an .xml file and name it urm-deployment-plan.xml . ?xml version=1.0 encoding=UTF-8? deployment-plan xmlns=http:xmlns.oracle.comweblogicdeployment-plan xmlns:xsi=http:www.w3.org2001XMLSchema-instance xsi:schemaLocation=http:xmlns.oracle.comweblogicdeployment-plan http:xmlns.oracle.comweblogicdeployment-plan1.0deployment-plan.xsd global-variables=false application-nameurm.earapplication-name variable-definition variable namehttp-onlyname valuefalsevalue variable variable-definition module-override module-nameurm.warmodule-name module-typewarmodule-type module-descriptor external=false root-elementweblogic-web-approot-element uriWEB-INFweblogic.xmluri variable-assignment xpathweblogic-web-appsession-descriptorcookie-http-onlyxpath variable-assignment module-descriptor module-override deployment-plan

5.2.4 Configuring Oracle WebLogic Server Web Services

Oracle WebLogic Server Web Services are implemented according to the Web Services for Java EE 1.2 specification, which defines the standard Java EE runtime architecture for implementing Web Services in Java. The specification also describes a standard Managing Security and User Access 5-27 Java EE Web Service packaging format, deployment model, and runtime services, all of which are implemented by Oracle WebLogic Server Web Services. For information on applying OWSM security to Web Services, see Using Oracle Web Service Security Policies in Oracle Fusion Middleware Security WebLogic Web Services for Oracle WebLogic Server. For information on using MTOM with Web Services, see Example of Adding Security to MTOM Web Services in Oracle Fusion Middleware Security WebLogic Web Services for Oracle WebLogic Server.

5.3 User Types, Logins, and Aliases

This section covers the following topics: ■ Section 5.3.1, Introduction to User Login Types ■ Section 5.3.2, Introduction to User Logins and Aliases ■ Section 5.3.3, Managing Logins and Aliases ■ Section 5.3.4, User Information Fields

5.3.1 Introduction to User Login Types

Oracle Content Server software supports the following user login types: ■ Section 5.3.1.1, External Users ■ Section 5.3.1.2, Local Users

5.3.1.1 External Users

External users are defined outside the Oracle Content Server system and authenticated by external security using the Oracle WebLogic Server Administration Console and Oracle Platform Security Services OPSS. Once authenticated, external users can access the Oracle Content Server system through Oracle WebLogic Server. Generally, external users are users in a trusted domain to whom you grant access, but do not manage through the Oracle Content Server system. Their passwords are owned by the Oracle WebLogic Server domain, the network domain, or another provider such as Oracle Internet Directory, although the User Admin applet can be used to set a user password when converting an external user to a local user. Unlike local users, undefined external users are not assigned the guest role. The first time users log in to the Oracle Content Server instance through Oracle WebLogic Server they are added to the Oracle Content Server database, and administrators can view external user information through the Repository Manager. However, external users are not automatically included in user lists, such as the Author field on a content Check In page. If an Override checkbox is selected on a users User Profile page, any user information defined in the Oracle Content Server database overrides the user information derived from the external user base. The Admin User applet only shows users after they have logged in at least one time to an Oracle Content Server instance. All users from the Oracle WebLogic Server user store or other user store outside the Oracle Content Server instance are shown as external users. By default, external security integrations map a limited set of user information user name, password, roles, accounts, and some additional information such as e-mail address from the external user base to the Oracle Content Server system. If you are using LDAP integration, then additional user information, such as e-mail address or user locale, can be mapped from the embedded LDAP server with the Oracle