Modes of Operation Configuring Oracle Identity Federation

Additional Server Configuration 6-45

3. Select the service provider and click Update.

4. Click the Oracle Identity Federation Settings tab.

5. Expand the Identity ProviderAuthority Settings section.

6. Select Opt-In as the Opt-InOpt-Out mode.

7. Set the Opt-InOut User Attribute to fedrecordcreation.

8. Set the Opt-InOut Attribute Value to agreed.

9. Apply the changes.

6.19 Bypassing User Mapping During Assertion Processing

With this feature Oracle Identity Federation, when acting as a service provider, does not attempt to locate a user based on the information contained in the assertion; instead the content of the assertion is passed directly back to the SP Integration module, which implements the user mapping flow. If Oracle Identity FederationSP is configured to bypass mapping that is, to not map the principal identified in the assertion to a local user, Oracle Identity Federation does the following: ■ creates an Oracle Identity Federation session for the anonymous user, specified in the Oracle Identity Federation administration console in the service provider section. This is required as the server needs to be aware of the user being authenticated at the server and at peer providers for example, at the logout operations. Thus, setting the Anonymous User ID in the Oracle Identity Federation pages for Fusion Middleware Control is mandatory. ■ passes the NameID, attributes, and other information back to the SP Integration module, as specified in Section 10.4.2.3, Implementing the Service , under the heading Oracle Identity Federation Assertion Processing.

6.19.1 Configuring Oracle Identity Federation

To configure Oracle Identity Federation to map or not map the incoming assertion to a user record: 1. Log in to Fusion Middleware Control.

2. Navigate to Administration, then Service Provider, then Common.

3. Check Map assertion to User Account to configure Oracle Identity Federation to

map incoming assertions to user records; uncheck it to not map the assertion. 4. Apply the changes.

6.20 Overriding NameID Mapping Per Partner

On a per-partner basis, an Oracle Identity Federation administrator can override the mapping of NameID formats to local user directory attributes. To configure this feature at the command line take these steps: 1. Set up the script environment as described in Chapter 9, Oracle Identity Federation Command-Line Tools. 2. Invoke the WLST shell using java weblogic.WLST.