Enabling User Account Lockout

Configuring Oracle Virtual Directory for Integrated Directory Solutions 19-29 ■ Integrating for Use with Oracle Directory Server Enterprise Edition ■ Integrating for Use with Oracle Internet Directory

19.3.1 Overview

Oracle Virtual Directory can be integrated with Oracles Net Services database product. Integrating Oracle Virtual Directory and Net Services enhances and simplifies your name service capabilities by allowing you to leverage service entries stored in an external LDAP repository without any additional synchronization.

19.3.2 Starting the Integration

This section lists the common steps required for all Oracle Virtual Directory-Net Services integrations. Perform the steps in this section first to start the integration, then proceed to a subsequent section specific to Oracle Internet Directory, Microsoft Active Directory, and Oracle Directory Server Enterprise Edition. Different steps are presented depending on whether you are integrating Oracle Virtual Directory with Net Services for use with Oracle Internet Directory, Microsoft Active Directory, or Oracle Directory Server Enterprise Edition. Only perform the steps appropriate for your environment. Perform the following steps to start the Oracle Virtual Directory-Net Services integration process: 1. Create a back-up copy of the ORACLE_HOMEovdeus directory. 2. Create the subschemasubentry plug-in as global server plug-in. Refer to Managing Global Server Plug-ins on page 13-4 for steps on creating server plug-ins.

19.3.3 Integrating for Use with Microsoft Active Directory

Perform the following steps to integrate Oracle Virtual Directory with Net Services for use with Microsoft Active Directory. Perform these only after you have completed the steps in the Starting the Integration section. The procedure for integrating Oracle Virtual Directory with Net Services for use with Microsoft Active Directory includes the following tasks: ■ Configuring Active Directory for the Integration ■ Configuring Oracle Virtual Directory for the Integration

19.3.3.1 Configuring Active Directory for the Integration

Perform the following steps to configure Active Directory for the integration: 1. Make a back-up copy of your Active Directory image. The schema extensions inside of Active Directory are permanent and cannot be canceled. The back-up image enables you to restore all your changes if required. 2. Load the Net Services required schema into Active Directory using the Java classes included in Oracle Virtual Directory by executing the following command. You can use the java executable in the ORACLE_HOMEjdkbin directory. java extendAD -h Active_Directory_Host_Name -p Active_Directory_Port -D Active_Directory_Admin_DN -w Active_Directory_Admin_Password –AD Active_Directory_Domain_DN 19-30 Oracle Fusion Middleware Administrators Guide for Oracle Virtual Directory

19.3.3.2 Configuring Oracle Virtual Directory for the Integration

Perform the following steps to configure Oracle Virtual Directory for the integration:

1. Start the Oracle Virtual Directory server, then start Oracle Directory Services

Manager, and then connect to the Oracle Virtual Directory server.

2. Create two new Local Store Adapters using the following settings. Refer to

Creating Local Store Adapters on page 12-23 for information on creating Local Store Adapters. ■ Use the Local_Storage_Adapter template for each adapter. ■ The Adapter Suffix for a Local Store Adapter must be cn=OracleContext and the Adapter Suffix for the other of the Local Store Adapters must be cn=OracleSchemaVersion. ■ The Database File and Backup File fields for each of the adapters must be unique.

3. Update and load the entries into the Local Store Adapters by extending the Oracle

Virtual Directory schema with the loadOVD.ldif file using the following command. The loadOVD.ldif file contains entries for Oracle Context and schemaversion that Net Services queries. The loadOVD.ldif file is located in the ORACLE_HOME ovdeus directory. ORACLE_HOME binldapmodify -h Oracle_Virtual_Directory_Host –p OVD_Port \ -D bindDN -q -v -a -f loadOVD.ldif

4. Create an LDAP Adapter for Net Services using the following settings and by

entering the Active Directory host information, including host name, non-SSL port number, proxy DN and password, and the appropriate Remote Base and Mapped Namespace. Refer to Creating LDAP Adapters on page 12-3 for information on creating LDAP Adapters. ■ Use the ONames_ActiveDirectory adapter template. ■ Select the BindOnly Pass Through Credential option. 5. Update the Access Control Lists by performing the following steps. If you have customized your ACLs after installing Oracle Virtual Directory, you must adjust the following ACL settings to include your customizations.

a. Create the following ACLs. Refer to

Creating Access Control Lists Using Oracle Directory Services Manager on page 16-1 for information on creating ACLs: Note: An example of a valid Active Directory domain DN is: dc=oracle,dc=com Target DN cn=OracleContext Scope subtree Applies To Entry Grant Browse DN and Return DN Access Public Target DN cn=OracleContext