Oracle Adaptive Access Manager Topologies Oracle Identity Manager Topologies

11 Upgrading Oracle Single Sign-On Environment 11-1 11 Upgrading Oracle Single Sign-On Environment This chapter describes how to upgrade your existing Oracle Single Sign-On 10g Release 2 10.1.2.3 or Oracle Single Sign-On 10g Release 2 10.1.4.3 to Oracle Access Manager 11g Release 1 11.1.1.5.0. This chapter contains the following sections: ■ Overview ■ Upgrade Scenarios ■ Task 1: Decide Upon an Oracle Access Manager Topology ■ Task 2: If Necessary, Upgrade the Oracle Database ■ Task 3: Use Repository Creation Utility to Create 11g Oracle Access Manager Schemas ■ Task 4: Install and Configure the Oracle Access Manager Middle Tier ■ Task 5: Upgrade Oracle Access Manager Middle Tier Using Upgrade Assistant ■ Task 6: Complete Any Required Oracle Access Manager Post-Upgrade Tasks ■ Task 7: Verify the Oracle Access Manager Upgrade Before performing any installation or upgrade, you should read the system requirements and certification documentation to ensure that your environment meets the minimum installation requirements for the products you are installing. For more information, refer to System Requirements and Prerequisites in the Oracle Fusion Middleware Installation Planning Guide.

11.1 Overview

You can use Oracle Fusion Middleware Upgrade Assistant to upgrade the following: ■ Oracle Single Sign-On 10g configurations and artifacts ■ Partner metadata stored by Oracle Single Sign-On 10g Server ■ Partners registered with Oracle Single Sign-On 10g Server Note: On AIX platforms, ensure that you have patched your Oracle Internet Directory 10g 10.1.4.0.1 to Oracle Internet Directory 10.1.4.3.0 before upgrading to Oracle Access Manager 11g. 11-2 Oracle Fusion Middleware Upgrade Guide for Oracle Identity Management After you complete the upgrade, Oracle Internet Directory becomes the primary identity store for Oracle Access Manager 11g. The following components are not upgraded to the Oracle Access Manager 11g environment when you run Upgrade Assistant to upgrade from Oracle Single Sign-On 10g: ■ Oracle Single Sign-On 10g with Window Native Authentication integration. For more information, see Configuring Oracle Access Manager to use Windows Native Authentication in the Oracle Fusion Middleware Integration Guide for Oracle Access Manager. ■ Logging configuration. For more information see Logging Component Event Messages in the Oracle Fusion Middleware Administrators Guide for Oracle Access Manager. ■ Oracle Single Sign-On 10g with Oracle Identity Federation integration. For more information see Integrating Oracle Identity Federation in the Oracle Fusion Middleware Integration Guide for Oracle Access Manager. ■ Custom authentication. ■ X509 configurations. For more information see the Oracle Fusion Middleware Administrators Guide for Oracle Access Manager. ■ External Application ■ Pstore ■ Multirealm Configuration

11.2 Upgrade Scenarios

Before you upgrade Oracle Single Sign-On 10g to Oracle Access Manager 11g, you must consider your Oracle Single Sign-On 10g infrastructure Figure 11–1 and depending on the functionality you choose to retain, you must select one of the following scenarios: ■ Oracle Delegated Administration Services Required After Upgrading from Oracle Single Sign-On to Oracle Access Manager ■ Oracle Delegated Administration Services Required, but Oracle Single Sign-On Admin Not Required After Upgrading from Oracle Single Sign-On to Oracle Access Manager 11g ■ Oracle Delegated Administration Services Not Required After Upgrading from Oracle Single Sign-On to Oracle Access Manager Oracle Single Sign-On 10g Infrastructure Before Upgrade Figure 11–1 illustrates the Oracle Single Sign-On 10g topology, which is the starting point for upgrading to Oracle Access Manager 11g. Upgrading Oracle Single Sign-On Environment 11-3 Figure 11–1 Oracle Single Sign-On 10g Infrastructure The topology comprises the following: ■ Partner applications in a JEE container front-ended by Oracle HTTP Server to communicate with the Oracle Single Sign-On infrastructure ■ Oracle Identity Management infrastructure that includes the Oracle HTTP Server 10g front-ending the Oracle Delegated Administration Services application and the Oracle Single Sign-On Server The Oracle Single Sign-On endpoint, which consists of a host name and a port number, represents the URL that Oracle Single Sign-On users can use to access the Oracle Single Sign-On Server and the Oracle Delegated Administration Services application. An example Oracle Single Sign-On endpoint is host.domain.com:port. Oracle Delegated Administration Services Required After Upgrading from Oracle Single Sign-On to Oracle Access Manager Use this upgrade scenario if you want to continue to use the Oracle Delegated Administration Services application and the Oracle Single Sign-On Admin tool after upgrading from Oracle Single Sign-On 10g to Oracle Access Manager 11g. Figure 11–2 illustrates the scenario. Note the following points when using this upgrade scenario: ■ Use this scenario if you are using Oracle Portal, Oracle Forms, Oracle Reports, or Oracle Discoverer partner applications because you require Oracle Delegated Administration Services and Oracle Single Sign-On Admin. Upgrade all partner applications at once. ■ The Oracle Delegated Administration Services application runs on a new port. Note: This example is used in this section to illustrate different upgrade scenarios and their Oracle Single Sign-On endpoints. 11-4 Oracle Fusion Middleware Upgrade Guide for Oracle Identity Management ■ Any Oracle Delegated Administration Services requests from partner applications, such as Oracle Portal, arrive at the Oracle HTTP Server 11g and redirected to Oracle HTTP Server 10g, which front-ends the Oracle Delegated Administration Services 10g application. The Oracle HTTP Server 11g front-ends Oracle Access Manager 11g. Such requests are redirected to Oracle HTTP Server 10g port, which front-ends the Oracle Delegated Administration Services 10g application. ■ You are using the same OHS 10g port that front-ended Oracle Single Sign-On 10g as the new port for Oracle Access Manager 11g. Therefore, the Oracle Single Sign-On 10g server goes down. ■ The Oracle Single Sign-On-Oracle Delegated Administration Services endpoint same_host.domain.com:same_port remains the same for all the partner applications. ■ After you perform the upgrade, Oracle Internet Directory is selected as the user identity store automatically. Note: You must reregister Oracle Delegated Administration Services and Oracle Single Sign-On Admin with Oracle Access Manager 11g because their port is changed.