Setting Oracle Identity Federation System Properties After Upgrade

7-18 Oracle Fusion Middleware Upgrade Guide for Oracle Identity Management java weblogic.WLST oif-upgrade-11.1.1.2.0-11.1.1.5.0.py

7.5.8 Additional Oracle Identity Federation Post-Upgrade Tasks

The following additional post-upgrade tasks should be performed after upgrading to Oracle Identity Federation 11g, in addition to those described in the Oracle Fusion Middleware Upgrade Guide for Oracle Identity Management: ■ If you are have configured Oracle Identity Federation 10g to use the SAML 1.xWS-FED protocol, then after you upgrade to Oracle Identity Federation 11g, you must set a default single sign-on identity provider. For more information, see Configuring Service Providers in the Oracle Fusion Middleware Administrators Guide for Oracle Identity Federation. ■ Export the Identity Provider self-signed certificate to the service provider The procedure you use to perform this task varies, depending on whether your service provider is a 10g or 11g service provider: – If you are using a 10g service provider, then refer to Exporting the IdPs self-signed certificate to the SP in the Oracle Identity Federation Administrators Guide in the Oracle Application Server 10g 10.1.4.0.1 documentation library on the Oracle Technology Network OTN: http:www.oracle.comtechnologydocumentation – If you are using an 11g service provider, then refer to Set Up Single Sign-On for SAML 1.x and WS-Federation in the Oracle Fusion Middleware Administrators Guide for Oracle Identity Federation. ■ If you are using an 11g Identity Provider and a 10g service provider, and you are using the SAML 1.xWS-FED protocol, then you configure the 10g service provider. Specifically, for the 10g service provider, you must change the Signing Certificate Subject DN and Signing Certificate Issuer DN to 11g IdP format, which is of the form CN=host Signing Certificate. For more information, see Configure This Domain as a SourceIdentity Provider in the Oracle Identity Federation Administrators Guide in the Oracle Application Server 10g 10.1.4.0.1 documentation library on the Oracle Technology Network OTN. ■ Enable Send Signed Assertion in Oracle Identity Federation 10g, or disable Require Signed Assertions in Oracle Identity Federation 11g. This task is necessary because in 10g, signed assertions are disabled by default, and in 11g, signed assertions are enabled by default. Depending whether you perform this task in 10g or 11g, refer to one the following: – Configuring Service Providers in the Oracle Fusion Middleware Administrators Guide for Oracle Identity Federation. – Section 6.5.5, Add Assertion Profile in the Oracle Identity Federation Administrators Guide in the Oracle Application Server 10g 10.1.4.0.1 documentation library on the Oracle Technology Network OTN. Upgrading Your Oracle Identity Federation Environment 7-19

7.6 Task 6: Verify the Oracle Identity Federation Upgrade

To verify that your Oracle Internet Directory and Oracle Directory Integration Platform upgrade was successful:

1. Run the Upgrade Assistant again and select Verify Instance on the Specify

Operation page. Follow the instructions on the screen for information on how to verify that specific Oracle Fusion Middleware components are up and running. 2. Use the following URL to verify that Oracle Identity Federation 11g is up and running: http:host:portfedspmetadata For example: http:host42.exmaple.com:7001fedspmetadata Alternatively, you can use Fusion Middleware Control to verify that Oracle Identity Federation and any other Oracle Identity Management components are up and running in the Oracle Fusion Middleware environment. For more information, see Getting Started Using Oracle Enterprise Manager Fusion Middleware Control in the Oracle Fusion Middleware Administrators Guide.