Oracle UCM Security Considerations Oracle URM-WNA Redeployment
3.1 Fusion Middleware Security Considerations
This section describes how to configure your Fusion Middleware product to handle authentication and authorization, and other aspects of application security.3.1.1 Oracle UCM Security Considerations
Oracle UCM uses the Oracle WebLogic Server user store to manage user names and passwords, so most user management tasks must be performed with the Oracle WebLogic Server user management tools instead of Oracle UCM’s User Admin applet. User logins must be created on Oracle WebLogic Server and the default Oracle WebLogic Server users should not be used for Oracle URM. Oracle UCM and workflow services use Java Platform Security JPS and the User and Role API. Oracle Internet Directory stores user and group information. When Oracle UCM uses Oracle Internet Directory, the Oracle Internet Directory Authentication provider must be the first provider listed in the security realm configuration. If the Oracle Internet Directory Authentication provider is not listed first for example, it is listed below the Oracle WebLogic Server provider, DefaultAuthenticator, then login authentication fails. You can use the Oracle WebLogic Server Administration Console to change the order in which the configured Authentication providers are called. When you use Oracle Internet Directory, all Oracle UCM administrator and other users must be defined in Oracle Internet Directory. Oracle UCM assigns an administrator role to users defined in the internal Oracle WebLogic Server user store. This is true regardless of whether Oracle Internet Directory is used or not used. However, if you use Oracle Internet Directory and if the OID Authentication provider is not listed first then any request by Oracle UCM to retrieve the roles of the Oracle WebLogic Server defined administrative users will fail. See Managing Security and User Access in the Oracle Fusion Middleware System Administrators Guide for Content Server for more details about security and user accounts. See the Oracle Fusion Middleware Application Security Guide and Oracle Fusion Middleware Securing Oracle WebLogic Server for details about LDAP providers.3.1.2 Oracle URM-WNA Redeployment
For Windows Native Authentication through Kerberos to work with Oracle URM, you must redeploy Oracle URM. First create then save an .xml file for the Oracle URM domain type that includes the following information. Save the file as urm.xml: ?xml version=1.0 encoding=UTF-8? deployment-plan xmlns=http:xmlns.oracle.comweblogicdeployment-plan xmlns:xsi=http:www.w3.org2001XMLSchema-instance xsi:schemaLocation=http:xmlns.oracle.comweblogicdeployment-plan Permissions: Specific permissions are required to perform the tasks described here. For details about the required permissions, see the tasks outlined in later chapters of this manual. In general, users with the Record Administrator role should be able to perform the majority of these tasks. For details about rights and roles, see Chapter 5, Setting Up Security . Setting Up the Software 3-3 http:xmlns.oracle.comweblogicdeployment-plan1.0deployment-plan.xsd global-variables=false application-nameurm.earapplication-name variable-definition variable nameurl-patternname valuevalue variable variable namehttp-onlyname valuefalsevalue variable variable-definition module-override module-nameurm.warmodule-name module-typewarmodule-type module-descriptor external=false root-elementweb-approot-element uriWEB-INFweb.xmluri variable-assignment nameurl-patternname xpathweb-appsecurity-constraint[display-name=UCMConstraint]web-resource-collection[web-res ource-name=idcauth]url-patternxpath operationreplaceoperation variable-assignment module-descriptor module-descriptor external=false root-elementweblogic-web-approot-element uriWEB-INFweblogic.xmluri variable-assignment namehttp-onlyname xpathweblogic-web-appsession-descriptorcookie-http-onlyxpath variable-assignment module-descriptor module-override deployment-plan 1. As administrator, log in to the Oracle WebLogic Server Administration Console.2. Click Deployments in the Domain Structure navigation tree.
3. Click the Control tab then Next until you see the Oracle Universal Records
Management deployment. 4. Select the checkbox to the left of that deployment.5. Click Update.
6. Under the Deployment Plan Path, select Change Path.
7. Navigate to and select the urm.xml file just created.8. Verify that Redeploy this application using the following deployment files is
selected.9. Click Next.
10. Click Finish.
3-4 Oracle Fusion Middleware Setup Guide for Universal Records Management3.1.3 Configuration for External LDAP Authentication Provider
Parts
» Oracle Fusion Middleware Online Documentation Library
» About This Guide About This Product
» Regulatory Needs Litigation Needs Business Needs
» Content Retention Qualities Importance of Content Retention
» Internal and External Retained Content Classified, Unclassified, Declassified Content
» Non-Permanent, Transfer or Accession, and Reviewed Content
» Basic Retention Management Concepts
» Physical Content Management Interaction with Oracle UCM
» Basic Retention Processes Oracle Fusion Middleware Online Documentation Library
» Oracle UCM Security Considerations Oracle URM-WNA Redeployment
» Software Configuration Oracle Fusion Middleware Online Documentation Library
» Retention Setup Checklist Oracle Fusion Middleware Online Documentation Library
» Retention Management Options Oracle Fusion Middleware Online Documentation Library
» Supplemental Markings Classification Security Settings
» Security Classifications Classification Guides
» Security Settings Security Roles and Definitions
» Rights for Roles Security Overview
» System-Wide Configuration Setting Up Physical Content Management
» Creating a Series Creating a Retention Category
» Disposition Types Triggering Events
» Triggers Freezes Configuring Content Triggers, Dispositions, and Freezes
» Configuring the System Interface Overview
» Configuring Reports Configuring PCM
» Individual Page and Action Menus Menus
» Retention Management in an Organization
» Roles Oracle Fusion Middleware Online Documentation Library
» Folder Tasks and Defaults for Predefined Roles
» Chargeback Tasks and Defaults for Predefined Roles
» Security Groups Aliases Security Matrix
» Setting Security Preferences Oracle Fusion Middleware Online Documentation Library
» The Series Tab The Category Tab Folder Tab
» Specifying PCM Barcode Values for Users
» Supplemental Markings Details Supplemental Markings
» Classification Levels About Records Classification
» About Custom Security Custom Security
» PCM Options Oracle Fusion Middleware Online Documentation Library
» Workflow Prerequisites and Process
» Configuration with Desktop Integration Suite About Physical Content Management
» Predefined Location Types Creating or Editing a Location Type
» Viewing Location Type Information Deleting a Location Type Reordering Location Types
» Example: Creating a Location Type
» Predefined Object Types Creating or Editing an Object Type Viewing Object Type Information
» Setting Default Metadata Values for Reservation Items and Offsite Storage
» Configuring Chargeback Processing Storage Space Considerations
» Location Type Object Type Media Type Storage Status
» Creating a Storage Location Batch Creating Storage Locations
» Editing a Storage Location Viewing Information about a Storage Location
» Deleting a Storage Location Blocking a Storage Location
» Example: Creating a Single Storage Location Example: Creating a Batch of Storage Locations
» Retention Schedules and File Plans
» Retention Schedule Hierarchy Planning a Retention Schedule
» Attribute Inheritance Review Status Attributes
» Permanent Status Attributes Disposition Instructions Frozen Folder and Content Status
» Retention Schedule Menus Creating and Navigating Object Levels
» About Record Folders Record Folders
» Retention Period Cutoff Preceding Disposition Action Content or Folder States
» Custom Triggers Global Triggers Custom Direct Triggers
» Creating or Editing a Trigger
» Viewing Trigger Information Viewing Trigger References Deleting a Trigger
» Setting Up Indirect Triggers Deleting an Indirect Trigger Date Entry
» Creating or Editing a Custom Time Period Viewing Period Information
» Viewing Period References Deleting a Custom Period
» Example: Creating a Custom Period
» Creating or Editing Custom Metadata Fields Viewing Custom Metadata Field Information
» About Custom Metadata Example: Creating a Custom Category Metadata Field
» Event Dispositions Time Dispositions
» About Dispositions Category Rule Review Using Workflows
» Preceding Actions Triggering Event Content State Triggering Event
» Classified Records Actions Dispose Actions
» Other Actions Disposition Actions
» Retention Periods Disposition Precedence
» Enabling or Disabling User-Friendly Captions Creating or Editing a Disposition Rule
» Copying a Disposition Rule Viewing Disposition Information Deleting a Disposition Rule
» Event Disposition Simple TimeEvent Disposition Time Disposition
» Architecture Oracle URM and the UCM Adapter
Show more