Additional Considerations for Collocated Components High Availability

Configuring High Availability for Identity Management Components 8-111 ■ Oracle Directory Integration Platform: Section 8.5.5, Troubleshooting Oracle Directory Integration Platform High Availability ■ Oracle Directory Services Manager: Section 8.6.6, Troubleshooting Oracle Directory Services Manager ■ Oracle Identity Federation: Section 8.13.5, Troubleshooting Oracle Identity Federation High Availability

8.7.5 Additional Considerations for Collocated Components High Availability

See the sections below for information on additional considerations for the following components in the collocated high availability architectures: ■ Oracle Internet Directory: Section 8.3.7, Additional Oracle Internet Directory High Availability Issues ■ Oracle Directory Services Manager: Section 8.6.7, Additional Considerations for Oracle Directory Services Manager High Availability

8.8 Oracle Access Manager High Availability

This section provides an introduction to Oracle Access Manager 11gR1 and describes how to design and deploy a high availability environment for Oracle Access Manager 11gR1. Oracle Access Manager 11gR1 is the successor product to both Oracle Access Manager 10g access only and Oracle Single Sign-On 10g. Oracle Access Manager 11gR1 provides a single authoritative source for all authentication and authorization services. The core service provided is the checking of valid session tokens, the requesting of credentials if the session token is invalid or missing, and the issuing of session tokens, intercepting resource requests and evaluating access control policies to control access to resources. Oracle Access Manager 11gR1 features a pure Java server while continuing to use Oracle Single Sign-On 10g and Oracle Access Manager 10g agent components. The main new feature for 11gR1 for the agent is the Shared Secret Key Per WebGate SSKPWG feature. Oracle Access Manager provides Single Sign-On features, thus preventing the user from re-logging in every time after authenticating once. It accomplishes this by managing the user session life cycle, which also involves facilitating global logout by orchestrating logout across all relying parties in the valid user session. Oracle Access Manager also ensures that resource access by users is authorized subject to the specified authorization policy. Unlike Oracle Access Manager 10g, Oracle Access Manager 11gR1 no longer has any identity service and is a first class consumer of identity information from other identity management services such as native LDAP and Oracle Identity Manager. Oracle Access Manager 11gR1 is an architecture evolution in the area of Access Management that delivers unified product architecture for enterprise and web Single Sign-On. Components of Oracle Access Manager leverage the Java EE middleware platform with a common underlying data model, shared underlying functionality, consistent semantics with a focus of interoperability and seamless integration. Oracle Access Manager 11gR1 offers co-existence and incremental migration paths for existing Single Sign-On deployments. This section includes the following topics: ■ Section 8.8.1, Oracle Access Manager Component Architecture