Log in to Oracle Enterprise Manager. Navigate to the Reports Application Home page see

Administering Oracle Reports Services Using Oracle Enterprise Manager 7-13 ■ Write access . To avoid the security issue of a malicious user potentially overwriting a system file by sending report output to a system directory, you can specify the directories to which Reports Server, Reports Application, or Oracle Reports Runtime is allowed to write. Attempts to write to other directories will return an error. For example, a user may run a report to the following destination on Windows: desname=C:\Temp This would overwrite a system file unless file system access control was enabled to specify write directories that do not include system directories. To define readwrite access to directories for Reports Server, Reports Application, or Oracle Reports Runtime: 1. Log in to Oracle Enterprise Manager. 2. Navigate to the component’s home page see Section 7.3, Viewing the Component Topology .

3. From the Reports menu, select Administration Advanced Configuration.

The Advanced Configuration page displays.

4. In the File System Access Control section, check Enable File System Access

Control , then enter the names of the Read Directories and Write Directories to which Reports Server, Reports Application, or Oracle Reports Runtime should have access. These entries set the read and write sub-elements of the folderaccess element in the configuration file. Read Directories: To avoid the security issue of exposing sensitive content of files, enter the names of the directories from which Reports Server is allowed to read. Separate directory names with a semicolon ;. Write Directories: Enter the names of the directories to which Reports Server is allowed to write. Attempts to write to other folders will return an error.

7.8.6 Enabling and Disabling Single Sign-On

If you plan to take advantage of Oracle Application Server Single Sign-On, you can use Oracle Enterprise Manager to set the SINGLESIGNON parameter in the rwservlet.properties configuration file. SINGLESIGNON=YES by default on installation. For more information about Single Sign-On, refer to Chapter 17, Configuring and Administering OracleAS Single Sign-On . To enable Single Sign-On: 1. Log in to Oracle Enterprise Manager. 2. Navigate to the Reports Application Home page see Section 7.3, Viewing the Component Topology .

3. From the Reports menu, select Administration Advanced Configuration.

The Reports Application Advanced Configuration page displays.

4. In the Reports Security section, check Enable Single Sign-On.

5. Click Apply.

7-14 Publishing Reports to the Web with Oracle Reports Services

7.8.7 Using Oracle Access Manager

Oracle Access Manager is a component of Oracle Fusion Middleware that you can use in place of OracleAS Single Sign-On 10g to implement centralized authentication, policy-based authorizations, delegated administration, and so on. You can use the Oracle Fusion Middleware Upgrade Assistant to upgrade from OracleAS Single Sign-On 10g to Oracle Access Manager 11g. For more information about upgrading to Oracle Access Manager 11g, see the Upgrading Your Oracle Single Sign-On Environment chapter in the Oracle Fusion Middleware Upgrade Guide for Oracle Identity Management.

7.8.8 Managing Credentials

This section explains how to use the oracle Enterprise Manager to manage credentials in a domain credential store.

1. Log in to Oracle Enterprise Manager and navigate to WebLogic Domain

Security Credentials, to display the Credentials page.

2. Use the button Delete to remove a selected item key or map in the table. Note

that deleting a credential map, deletes all keys in it. Similarly, use the button Edit to view or modify the data in a selected item. 3. To display credentials matching a given key name, enter the string to match in the box Credential Key Name, and then click the blue button to the right of it. The result of the query is displayed in the table. 4. To redisplay the list of credentials after examining the results of a query, select WebLogic Domain Security Credentials. To add a new key to a credential map:

1. Click Create Map to display the Create Map dialog.

2. In this dialog, enter the name of the map for the credential being created.

3. Click OK to return to the Credentials page. The new credential map name is

displayed with a folder icon in the table. To add a new key to a credential map:

1. Click Create Key to display the Create Key dialog.

2. In this dialog, select a map from the pull-down list Select Map where the new key

will be inserted, enter a key in the text box Key, select a type from the pull-down list Type the appearance of the dialog changes according to the type selected, enter the required data.

3. Click OK when finished to return to the Credentials page. The new key is shown

under the map icon corresponding to the map you selected. For more information about Reassociating the Credential Store, see Oracle Fusion Middleware Security Guide. Note: In CSF, the Reports Server can access credentials only from the Reports folder, hence you must create credentials under the Reports folder.