In Keystores, select an option that includes Custom Identity. In the Identity section, fill in properties as follows:

8-4 Oracle Fusion Middleware Administrators Guide for Oracle Identity Federation Configuring Oracle WebLogic Server and Section 8.1.2.2, Configuring Keystore Passwords in Oracle Identity Federation . ■ Set up Oracle Identity Federation to use its own identity and trust keystores. This approach is described in Section 8.1.2.3, Alternative Way to Configure Oracle Identity Federation as SSL Client . Topics in this section include: ■ Configuring Oracle WebLogic Server ■ Configuring Keystore Passwords in Oracle Identity Federation ■ Alternative Way to Configure Oracle Identity Federation as SSL Client ■ Connecting to an LDAP Server over SSL ■ Ensuring that Fusion Middleware Control can Manage an Oracle Identity Federation Target

8.1.2.1 Configuring Oracle WebLogic Server

Some SSL servers might require authentication of the client performed during the SSL handshake. This operation is typically done by having the SSL client present an SSL Client certificate to the SSL server. This section describes how to configure Oracle WebLogic Server and Oracle Identity Federation to present a Client SSL certificate when it is requested by an SSL server. This requires: ■ setting up trust for the CA that issued the SSL server certificates ■ obtaining a certificate for the Oracle Identity Federation SSL client. Take these steps to achieve this:

1. Log in to the Oracle WebLogic Server administration console and navigate to

Environment , then Servers.

2. Select the server for which you want to set up SSL.

3. Go to the Keystores tab, and click Lock Edit.

4. In Keystores, select an option that includes Custom Identity and the Trust

Keystore type you wish to configure. 5. In the Identity section, fill in properties as follows: ■ Custom Identity Keystore: location of keystore with SSL private key and certificate ■ Custom Identity Keystore type: identity keystore type ■ Custom Identity Keystore Passphrase: storepassword

6. In the Trust section, fill in the properties with the Trust Keystore information.

7. Click Save, then click Activate Changes.

8. Restart the server.

8.1.2.2 Configuring Keystore Passwords in Oracle Identity Federation

If Oracle Identity Federation needs to connect to a remote provider and provide an SSL client certificate, you must configure the identity and trust keystore passwords in Oracle Identity Federation setup, not in Oracle WebLogic Server. Follow these steps: