Skip to main content

Posts

Showing posts with the label OID

User Role API development with Oracle Platform Security Services

I have recently had a chance to work with Oracle Platform Security Services. OPSS is a combination of application programming interfaces that provide abstraction layer over identity management implementations. Before I go into details with OPSS, let me give you a quick background on the application that started using OPSS recently for user and role management purposes. The project is a custom built Spring based web application. The main purpose of the application is to provide services over our user repository which is Oracle Internet Directory. This application is responsible for providing user and role management. SpringLdap template was heavily used before it was replaced with OPSS through the application to query, and modify OID. The application is deployed to WebLogic Server 10.3.4. The current version of OID is 10.1.4.3 which is at the end of it support life and our client is considering moving away from it. The fact that our client was thinking of migrating away from OI...

Oracle Internet Directory plug-in to remove users from groups

Oracle Internet Directory is an LDAP compliant user directory. To my surprise I  recently found out that it does not remove membership attributes from groups when users get disabled. This is at least true for the version 10.1.4.3. I am not sure if the behavior is different in the 11g version. This became an issue for us because the IT security department wanted to ensure that memberships were removed when users were disabled. Our solution was to basically create a plug-in and register the plug-in with OID. Oracle Identity Management Application Developers Guide located here  provides detailed information on how to extend the behavior of OID. This document has sections for building custom plug-ins and their deployment. I used their JAVA API to build this plug-in. Before I start sharing some code, here is some general information about the plug-in. 1. The plug-in will get executed whenever OID performs a modify operation. 2. The plug-in will determin...

Integrating Oracle WebCenter with Oracle SSO Server 10g

These days I am working with Oracle 10g and 11g products. One of my projects is to stand up a new Oracle 11g WebCenter Spaces Portal that would integrate with the existing Oracle 10g Single Sign On Server which is backed by Oracle Internet Directory. For the integration to be successful, there are few configuration settings that need to be implemented on both of the environments. Here is an overview of the main tasks that need to be completed in order to achieve the integration. Upgrade Oracle 10g Infrastructure tier to supported version (as of this writing, Oracle 11g is certified to work with version 10.1.4.3+). upgrade to 10.1.4.0.1 upgrade to 10.1.4.3 apply interim bug fixing patches Configure Oracle 11g WebLogic authentication providers Configure OIDAuthenticator Configure OSSOIdentityAsserter Re-associate Policy domain with OID create a new jps root node change association Register Oracle 11g WebCenter OHS with Oracle 10g OSSO Server ssoreg.sh Configure mod_o...

WebLogic start up failes after re-associating domain policy and credential store with OID 10.1.4.3

In my current project, I am working on some Oracle products including the new 11g Fusion Middleware components such as Oracle WebCenter, Oracle UCM, etc. The project involves integrated existing Oracle components such as Oracle Single Sign Server and Oracle Internet Directory with Oracle 11g Fusion Middleware applications. By default, Oracle WebCenter Spaces application is configured to use an embedded Ldap store for policy credentials which is not suitable for production environments. One of my tasks was to configure Oracle WebLogic and WebCenter Spaces application so that Policy and Credential Store would be hosted at an external Ldap store, in our case it was Oracle Internet Directory 10.1.4.3. This version of OID in our case was a patched version of OID from 10.1.2.3. We first patched it to version 10.1.4.0.1 and then applied other patches to bring the version to 10.1.4.3 which is the support version of OID by Oracle WebCenter Spaces. We followed the following documentation...