Navigate to the directory where you extracted the installation files and

Deploying the Oracle Password Filter for Microsoft Active Directory 19-13

12. On the Oracle Password Filter Configuration Parameters page, enter values for the

following parameters: ■ SleepTime : The number of minutes between attempts to synchronize passwords changes between Oracle Internet Directory and Microsoft Active Directory. ■ ConfigSleepTime : The number of minutes between attempts to synchronize configuration changes between Oracle Internet Directory and Microsoft Active Directory. ■ ExcludeListDN : A fully qualified DN containing a list of users whose passwords should not be synchronized. ■ Maximum Retries : Specifies the maximum number of attempts to synchronize a password.

13. Click Next to continue. If you chose Advanced on the Installation Options page,

the Specify Attributes page displays. 19-14 Oracle Fusion Middleware Administrators Guide for Oracle Directory Integration Platform Perform the following steps for advanced installations:

a. On the Specify Attributes page displays, enter values in the Source Attribute

Microsoft Active Directory and Target Attribute Oracle Internet Directory boxes for any attributes that you want to synchronize between the two directories. Also, select a value of true or false from the Binary Attribute Type box to specify whether the source attribute type is binary.

b. Click Next to continue. The Summary page displays and lists the path where

the Oracle Password Filter for Microsoft Active Directory will be installed.

14. On the Summary page, click Next to install the Oracle Password Filter.

15. When prompted whether or not to upload schema extensions to Oracle Internet

Directory, always select No. You do not want to upload schema extensions to Oracle Internet Directory because it comes preloaded with the schema extension attributes required for the Microsoft Active Directory Password filter. The Reboot Domain Controller page displays.

16. On the Reboot Domain Controller page, click Next to restart the computer.

17. Do the following:

For 32-bit systems a. After the computer restarts, log in as an administrator. The remaining configuration tasks for the Oracle Password Filter execute automatically after you log in. For 64-bit systems a. After the computer restarts, log in as an administrator. b. Choose Start Run... and type regedit in the Run dialog box, then click OK. The Registry Editor opens. Deploying the Oracle Password Filter for Microsoft Active Directory 19-15 c. Navigate to the following registry key: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\ orclidmpwf\ADConfig

d. Edit the ResourceFilePath as follows, then click OK.

Change C:\\WINDOWS\\system32\\orclmessages.dll to C:\WINDOWS\sysWOW64\orclmessages.dll e. Close the Registry Editor. The Oracle Password Filter for Microsoft Active Directory is now installed.

19.5.2 Reconfiguring the Oracle Password Filter for Microsoft Active Directory

In most cases, you should not need to reconfigure the Oracle Password Filter following the installation process. However, you can reconfigure the Oracle Password Filter for Microsoft Active Directory by running the Oracle Password Filter for Microsoft Active Directory installation program. To reconfigure the Oracle Password Filter for Microsoft Active Directory:

1. Navigate to the directory where you extracted the installation files and

double-click setup.exe. The Welcome page of the Oracle Password Filter for Microsoft Active Directory configuration program displays, informing you that the installation program will reconfigure the Oracle Password Filter for Microsoft Active Directory.

2. On the Welcome page, click Next. The Microsoft Active Directory Configuration

Parameters page displays. Note: The Microsoft Active Directory and Oracle Internet Directory configuration parameters listed in the following procedure are described in Table 19–1 and Table 19–2 . 19-16 Oracle Fusion Middleware Administrators Guide for Oracle Directory Integration Platform

3. On the Microsoft Active Directory Configuration Parameters page, modify the

following parameters: ■ Domain ■ Base DN ■ Port ■ Host 4. Click Next. The Oracle Internet Directory Configuration Parameters page displays. Deploying the Oracle Password Filter for Microsoft Active Directory 19-17

5. On the Oracle Internet Directory Configuration Parameters page, modify the

following parameters: ■ Base DN ■ Host ■ SSL Port

6. Click Next to continue. The Oracle Password Filter Configuration Parameters page

displays. Note: At the point of reconfiguring, two configuration set entries exist in Oracle Internet Directory and two instances of the Oracle Internet Directory server are running, each instance with one configuration set entry. Enter the SSL port of the second configuration set entry in the SSL Port field. 19-18 Oracle Fusion Middleware Administrators Guide for Oracle Directory Integration Platform

7. On the Oracle Password Filter Configuration Parameters page, modify the

following parameters ■ SleepTime : The number of minutes between attempts to synchronize passwords changes between Oracle Internet Directory and Microsoft Active Directory. ■ ConfigSleepTime : The number of minutes between attempts to synchronize configuration changes between Oracle Internet Directory and Microsoft Active Directory. ■ ExcludeListDN : A fully qualified DN containing a list of users whose passwords should not be synchronized. ■ Maximum Retries : Specifies the maximum number of attempts to synchronize a password.

8. Click Next to continue. The Oracle Password Filter Users page displays.

Deploying the Oracle Password Filter for Microsoft Active Directory 19-19

9. On the Oracle Password Filter Users page, modify the following parameters:

■ Microsoft Active Directory User ■ Microsoft Active Directory User Password ■ Oracle Internet Directory User ■ Oracle Internet Directory User Password

10. Click Next to continue. The Reconfiguration Completed Successfully page

displays.

11. On the Reconfiguration Completed Successfully page, click Finish to reconfigure

the Oracle Password Filter.

19.6 Removing the Oracle Password Filter for Microsoft Active Directory

This section describes how to remove uninstall the Oracle Password Filter for Microsoft Active Directory. To remove the Oracle Password Filter for Microsoft Active Directory: Important: If you have configured both import and export synchronization between Oracle Internet Directory and Microsoft Active Directory, be sure to enter for the User and User Password parameters the same bind DN and password that are specified in the synchronization profile that imports values from Microsoft Active Directory into Oracle Internet Directory. This is necessary to prevent password updates from looping between Oracle Internet Directory and Microsoft Active Directory.