About Federated Identities Identities - Federations

Server Administration 4-25 only those federated identities created with the provider specified. If no Provider ID is specified, the search will be performed over the federated identities created with all trusted providers. ■ Search Value: Enter the value you wish to search for. If no value is specified, all federated identity records will be returned. The search returns a table of federation records. The table columns appearing in the table depend on the default display attributes configured in the search options configuration. Advanced Search Take these steps to perform an advanced search: ■ Enter a Provider ID, or part of one and click Lookup to choose the correct ID from a list of trusted providers. Entering a provider ID in this field will limit the search to only those federated identities created with the provider specified. If no Provider ID is specified, the search will be performed over the federated identities created with all trusted providers. ■ Check Include New and Old Name IDs in Search to include the new and old NameID values in the search for federation records. ■ Use the Operator radio buttons to specify whether the returned records must satisfy all conditions And or records satisfying any conditions Or. ■ Add attribute search conditions by following these steps: – Click Add Attribute. – A pop-up box appears. Use the drop-down list to select a federated identity attribute, and click OK. – The attribute appears as a search option. Select the comparator to use and the value to search for. ■ Click Search. To Manage Records To manage a displayed record, select the corresponding row. Buttons on the page provide these actions: ■ Update - Updates the Name ID of the federated identity by performing a Manage Name ID MNI operation. See Section 4.4.1, About Federated Identities for more details. ■ Delete - Terminates the federated identity by performing a Manage Name ID MNI operation with the Terminate flag set to true, and deletes the record. The functions are available for the SAML 2.0 and Liberty 1.x protocols. See Also: Section 4.4.4, Identities - Search Options Note: The new and old NameID fields are populated only if an update operation was previously performed on a federation record, and if the protocol is enabled. If NameID registration is disabled or if no update operation was ever performed, there is no need to include those fields during a search operation. 4-26 Oracle Fusion Middleware Administrators Guide for Oracle Identity Federation

4.4.3 Identities - Users

Use this page to locate and maintain user records. Simple Search Enter the search value for which you wish to search in the local user entries, and click Search . If no value is specified, all users will be returned.. The search returns a table of user records. The table columns appearing in the table depend on the default display attributes configured in the search option configuration. Advanced Search Take these steps to perform an advanced search: ■ Use the Operator radio buttons to specify whether the returned records must satisfy all conditions And or records satisfying any conditions Or. ■ Add attribute search conditions by following these steps: – Click Add Attributes. – A pop-up box appears. Select a user attribute from the list, and click OK. – The attribute appears as a search condition. Select the comparator to use and the value to search for. – Click Search.

4.4.4 Identities - Search Options

Use this page to configure the attributes used to search for users and federation records. Note: Liberty 1.x support is deprecated. See Also: Section 4.4.4, Identities - Search Options Note: The attributes that appear in this list are those configured in the search options configuration Section 4.4.4, Identities - Search Options . Server Administration 4-27 The page displays two tables: ■ The Federations table shows the attributes available on the Identities - Federation Records tab of the Identities page. It shows: – the attribute’s display name – whether this attribute is a default search attribute in simple searches; in other words, whether a simple search will be performed over this attribute. – whether this attribute is displayed by default in the results from simple and advanced searches. Use the checkboxes to specify which attributes should be available by default for search and display, respectively. Click Apply to save your changes. ■ The Local Users table shows the attributes available on the Identities - Users tab of the Identities page. It shows: – the attribute’s name in the user data store – the attribute’s display name – whether this attribute is a default search attribute in simple searches; in other words, whether a simple search will be performed over this attribute – whether this attribute is displayed by default in the results from simple and advanced searches. Use the checkboxes to specify which attributes should be available by default for search and display, respectively. Click Apply to save your changes. Click Create to add another attribute to the list. Enter the following values: – Attribute Name - The attribute name in the user data store – Display Name – The name that will be displayed when referencing this attribute – Default Search Attribute – Check if this attribute should be searched over in simple searches. 4-28 Oracle Fusion Middleware Administrators Guide for Oracle Identity Federation – Default Display Attribute – Check if this attribute should be displayed in the search results. – Sort On – Check this if search results should be sorted based on the value of this attribute. Select an attribute and click Delete to remove it from the list of attributes available for display and searches. Once you delete an attribute, it is no longer available, but you can add it back to the list using Create. Attributes for Federated Identities The available attributes are: ■ User Name ■ User Description ■ IdP ID ■ IdP Format ■ IdP Qualifier ■ Protocol Version ■ SP Provider ID ■ SP Provider ID Format ■ SP Provider ID Version ■ Provider ID ■ Federation Type The federation type can have these values: – 1 - federation between this server as an IdP and an SP – 2 - federation between this server as an IdP and an Affiliation – 3 - federation between this server as an SP and an IdP – 4 - federation between Oracle Internet Directory server as an Affiliation and an IdP Check Include New and Old Name IDs in Search to include the new and old NameID values in the search operation for federation records. The new and old NameID fields are populated only if an update operation was performed on a federation record, and if the NameID registration protocol is enabled. If the protocol is disabled or if no update operation was ever performed, there is no need to include those fields during a search operation. Attributes for Users Attributes for users need to be added in the Local Users table in the Search Options tab before searches for local users can be performed. However, if the User data store is of type LDAP, the following attributes have already been added: ■ Email Address ■ User ID ■ Last Name ■ First Name