With Oracle Fusion Middleware Application Installed

15-26 Oracle Fusion Middleware Application Security Guide

f. Ensure that the parameter Control Flag is set to OPTIONAL initially.

7. In the Change Center, click Activate Changes.

8. DefaultAuthenticator

: Under the Providers tab, select DefaultAuthenticator, which changes its control flag to SUFFICIENT.

9. Reorder

: Under the Providers tab, reorder the providers so that DefaultAuthenticator is first OAMAuthenticator follows DefaultAuthenticator.

10. Oracle Access Manager Authenticator REQUIRED or the Only Authenticator

: Perform the following steps to set user rights for booting Oracle WebLogic Server.

a. Create an Administrators group in the directory server, if one does not already

exist or any other group for which you want boot access. b. Confirm that the LDAP user who boots Oracle WebLogic Server is included in the Administrators or other group.

c. From the WebLogic Administration Console, go to Security Realms, myrealm,

Roles and Policies, Global Roles.

d. Select View Conditions for the Admin Role.

e. Add the group and click Save. 11. Reboot the WebLogic Server.

12. Once the server has started, reset the Authentication Provider parameter Control

Flag to the appropriate value REQUIRED, OPTIONAL, or SUFFICIENT. See Also: Oracle Access Manager Authentication Provider Parameter List on page 16-14 for descriptions and values of the common and provider-specific parameters Note: Do not set the parameter Control Flag to REQUIRED until you have verified that the Authentication Provided is operational and configured correctly. Note: If the Oracle Access Manager Authenticator flag is set to REQUIRED, or if Oracle Access Manager Authenticator is the only Authentication provider, perform the next step to ensure that the LDAP user who boots Oracle WebLogic Server is included in the administrator group that can perform this task. By default the Oracle WebLogic Server Admin Role includes the Administrators group. Note: To provide access to any other group, you must create that group in the directory server and add the user who boots WebLogic Server in that group. Note: The recommended value is REQUIRED. To prevent a known issue, see JAAS Control Flag on page 16-74.