Select the Security Realm Users and Groups. Ensure that all users of external From the WebLogic Domain menu, select Security Security Provider

Securing Oracle Reports Services 15-27 valuecn=groups,dc=us,dc=abc,dc=comvalue values extendedProperty property name=username.attr value=uid propperty name=groupname.attr value=cn serviceInstance 3. Under serviceProviders, add the following: serviceProvider type=IDENTITY_STORE name=idstore.ldap.provider class=oracle.security.jps.internal.idstore.ldap.LdapIdentityStoreProvider serviceProvider descriptionPrototype LDAP-based ID storedescription

15.9.4.2 Configuring External Oracle Internet Directory as Policy Store

To configure an external Oracle Internet Directory as a policy store, modify the DOMAIN_HOMEconfigfmwconfigjps-config-jse.xml file as described in the following procedure.

1. Under jpsContext name=default add the following:

serviceInstanceRef ref=policystore.ldap Comment out the following: --serviceInstanceRef ref=policystore.xml--

2. Under serviceInstances, add the following:

serviceInstance provider=ldap.policystore.provider name=policystore.ldap property value=OID name=policystore.type property name=security.principal value=cn=orcladmin property name=security.credential value=password property value=cn=PRDomain name=oracle.security.jps.farm.name property value=cn=sta796_sa_root name=oracle.security.jps.ldap.root.name property value=ldap:abc.us.com:389 name=ldap.url serviceInstance

3. Under serviceProviders, add the following:

serviceProvider type=POLICY_STORE name=ldap.policystore.provider class=oracle.security.jps.internal.policystore.ldap.LdapPolicyStoreProvider descriptionPrototype LDAP-based ID storedescription serviceProvider

4. Save and restart WLS_REPORTS.

15.10 Forms and Reports Security Recommendations

The following security model is recommended for applications using Reports and Forms. Note: This is just an example. You must replace the example values provided in the entries with your install-specific values. 15-28 Publishing Reports to the Web with Oracle Reports Services If Reports is Using Portal-Based Security ■ It is recommended that Forms and Reports are associated to same Oracle Internet Directory. For more information see, Configuring External Oracle Internet Directory for In-Process Servers , and Configuring External Oracle Internet Directory for Standalone Servers ■ It is recommended that you enable Single Sign-On Perform the following steps to enable Single Sign-On: 1. Log in to Oracle Enterprise Manager. 2. Navigate to the Reports Application page.

3. From the Reports menu, select Administration Advanced Configuration.

The Reports Application Advanced Configuration page is displayed. 4. From the Reports Security window, select the Enable Single Sign-On check box.

5. Click Apply.

If Reports is using JAZN security If Reports is using JPS-based security, by default, an in-process server uses the embedded ID store of WebLogic Server as the ID store and an XML-based Policy store. A standalone server uses JAZN-XML. Forms uses Oracle Internet Directory based authentication for security. In this scenario: ■ It is recommended that you configure Reports to use Oracle Internet Directory-based ID store. Forms and Reports should use the same Oracle Internet Directory. For more information about configuring external Oracle Internet Directory, see, Configuring External Oracle Internet Directory for In-Process Servers , and Configuring External Oracle Internet Directory for Standalone Servers ■ It is recommended that you migrate reports policies from JAZN-XML to JAZN-OID. Forms and Reports should use the same Oracle Internet Directory. ■ It is recommended that you enable Single Sign-On Perform the following steps to enable Single Sign-On: 1. Log in to Oracle Enterprise Manager. 2. Navigate to the Reports Application page.

3. From the Reports menu, select Administration Advanced Configuration.

The Reports Application Advanced Configuration page is displayed. 4. From the Reports Security window, select the Enable Single Sign-On check box.

5. Click Apply.

15.11 Intermediate-level Security for Forms and Reports

Oracle Reports 11g Release 1 11.1.1 provides new security measures for reports run from Oracle Forms Services in non-secure mode: