Troubleshooting LDAP Adapter Creation

Configuring High Availability for Identity Management Components 8-69 3. access.log: This file captures information about processes and clients that access the Oracle Virtual Directory instance.

8.4.6.1 Troubleshooting LDAP Adapter Creation

When creating an LDAP adapter, you specify the host name and port number of LDAP server in the Connection page of adapter creation wizard. If the LDAP server is listening in SSL Server-Only Auth or Mutual Authentication mode, ODSM imports the server certificate into Oracle Virtual Directory’s trust store. However, if you specify the load balancer name that front-ends more than one LDAP server, it imports only one of the LDAP servers certificates. This causes a problem when the Oracle Virtual Directory servers request is routed to the LDAP server, whose certificate is not trusted. To avoid this problem, during LDAP adapter creation, in addition to specifying the load balancer host and port details, specify the host and port details of LDAP servers front-ended by the load balancer, so that certificates of all LDAP servers are imported. After the adapter is created, you can edit adapter settings to remove host and port details of physical LDAP servers, or their weight can be set to zero.

8.5 Oracle Directory Integration Platform High Availability

This section provides an introduction to Oracle Directory Integration Platform and describes how to design and deploy a high availability environment for Oracle Directory Integration Platform and Oracle Directory Services Manager. See Section 8.6, Oracle Directory Services Manager High Availability for more information about Oracle Directory Services Manager. This section includes the following topics: ■ Section 8.5.1, Oracle Directory Integration Platform Component Architecture ■ Section 8.5.2, Oracle Directory Integration Platform High Availability Concepts ■ Section 8.5.3, Oracle Directory Integration Platform and Oracle Directory Services Manager High Availability Configuration Steps ■ Section 8.5.4, Oracle Directory Integration Platform Failover and Expected Behavior ■ Section 8.5.5, Troubleshooting Oracle Directory Integration Platform High Availability

8.5.1 Oracle Directory Integration Platform Component Architecture

Oracle Directory Integration Platform is a J2EE application that enables you to integrate your applications and directories, including third-party LDAP directories, with Oracle Internet Directory. Oracle Directory Integration Platform includes services and interfaces that allow you to deploy synchronization solutions with other enterprise repositories. It can also be used to provide Oracle Internet Directory interoperability with third party metadirectory solutions. Oracle Directory Integration Platform provides two distinct services depending on the type of integration needed: ■ Synchronization through the Oracle Directory Integration Platform Synchronization Service, which keeps connected directories consistent with the central Oracle Internet Directory.