Oracle Single Sign-On to Oracle Access Manager Migration Rob Otto – Oracle Consulting Services UK 1.

Slides:



Advertisements
Similar presentations
The following is intended to outline our general product direction
Advertisements

Ljubomir Ivaniš CPU d.o.o.
Oracle IDM at First National Bank
Module 6: Configuring Windows XP Professional to Operate in a Microsoft Network.
A Java Architecture for the Internet of Things Noel Poore, Architect Pete St. Pierre, Product Manager Java Platform Group, Internet of Things September.
5 Copyright © 2006, Oracle. All rights reserved. Securing Grid Control.
Report Distribution Report Distribution in PeopleTools 8.4 Doug Ostler & Eric Knapp 7264.
EM 12c Cloud Control Architecture.
Architecting a Complete Solution for the Cloud Economy Delivering Standards-Based Access Control Marc Chanliau Oracle Identity Management Bernard Diwakar.
Access and Identity Management for Enterprise Portals Rohit Gupta Director, Identity Management Product Management Oracle Corporation.
Microsoft ® Application Virtualization 4.5 Infrastructure Planning and Design Series.
Active Directory and Windows Security Integration with Oracle Database Alex Keh Principal Product Manager, Windows and.NET Oracle.
ORACLE APPLICATION SERVER BY PHANINDER SURAPANENI CIS 764.
© 2008 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Automates Infrastructure Outsourcing.
Microsoft ® Application Virtualization 4.6 Infrastructure Planning and Design Published: September 2008 Updated: February 2010.
Oracle Confidential – Internal/Restricted/Highly RestrictedCopyright © 2014, Oracle and/or its affiliates. All rights reserved. | Oracle Identity Management.
Virtual techdays INDIA │ august 2010 Secure Collaboration: All You Need to Know about Extending Active Directory Rights Management Services (AD RMS)
Matt Steele Senior Program Manager Microsoft Corporation SESSION CODE: SIA326.
Week #10 Objectives: Remote Access and Mobile Computing Configure Mobile Computer and Device Settings Configure Remote Desktop and Remote Assistance for.
TAM STE Series 2008 © 2008 IBM Corporation WebSEAL SSO, Session 108/2008 TAM STE Series WebSEAL SSO, Session 1 Presented by: Andrew Quap.
Chapter 12: Additional Active Directory Server Roles
Hands-On Microsoft Windows Server 2008 Chapter 1 Introduction to Windows Server 2008.
Copyright 2007, Information Builders. Slide 1 WebFOCUS Authentication Mark Nesson, Vashti Ragoonath Information Builders Summit 2008 User Conference June.
Oracle Application Express (Oracle APEX)
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
Oracle Application Server 10g (9.0.4) Recommended Topologies Pavana Jain.
Timothy Heeney| Microsoft Corporation. Discuss the purpose of Identity Federation Explain how to implement Identity Federation Explain how Identity Federation.
1Copyright © 2012, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide 8 Reporting from Contract.
Hands-On Microsoft Windows Server 2008 Chapter 1 Introduction to Windows Server 2008.
MCSE Guide to Microsoft Exchange Server 2003 Administration Chapter Four Configuring Outlook and Outlook Web Access.
Technology Overview. Agenda What’s New and Better in Windows Server 2003? Why Upgrade to Windows Server 2003 ?  From Windows NT 4.0  From Windows 2000.
Christopher Chapman | MCT Content PM, Microsoft Learning, PDG Planning, Microsoft.
Oracle Application Express 3.0 Joel R. Kallman Software Development Manager.
Configuring and Troubleshooting Identity and Access Solutions with Windows Server® 2008 Active Directory®
Module 8 Configuring Mobile Computing and Remote Access in Windows® 7.
Configuring and Troubleshooting Identity and Access Solutions with Windows Server® 2008 Active Directory®
Philadelphia Area SharePoint User Group Building Customer/Partner Extranets Designing a Secure Extranet with Sharepoint 2007 Russ Basiura RJB Technical.
1Copyright © 2012, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide 8 Contract Management.
Brent Mosher Senior Sales Consultant Applications Technology Oracle Corporation.
ArcGIS Server and Portal for ArcGIS An Introduction to Security
SURENDER SARA 10GAS Building Corporate KPI’s
Using AS 10g with EBS What are the Benefits of Integrating AS 10g with Oracle Applications?
© Copyright 2009 Sysgem AG, 8002 Zurich, Switzerland Sysgem Products Sysgem Enterprise Manager (SEM)  Identity & Access Management  System Management.
Simplify and Strengthen Security with Oracle Application Server Allan L Haensgen Senior Principal Instructor Oracle Corporation Session id:
TWSd - Security Workshop Part I of III T302 Tuesday, 4/20/2010 TWS Distributed & Mainframe User Education April 18-21, 2010  Carefree Resort  Carefree,
Module 11: Implementing ISA Server 2004 Enterprise Edition.
Portal for ArcGIS An Introduction
1 Introduction to Microsoft Windows 2000 Windows 2000 Overview Windows 2000 Architecture Overview Windows 2000 Directory Services Overview Logging On to.
Empowering people-centric IT Unified device management Access and information protection Desktop Virtualization Hybrid Identity.
Access and Information Protection Product Overview Andrew McMurray Technical Evangelist – Windows
Workforce Scheduling Release 5.0 for Windows Implementation Overview OWS Development Team.
Industry specific cover image Girish Jashnani What’s new in R12 – A technology perspective Jan 17 th 2007.
Module 11: Designing an Active Directory Federation Services Implementation in Windows Server 2008.
Getting to Know Oracle Business Intelligence Oracle BI Enterprise Edition 11g Installation, Upgrade, Monitoring Limor Fledel Oracle Business Intelligence.
ALL INFORMATION PRESENTED AS WELL AS ALL SESSIONS ARE MICROSOFT CONFIDENTIAL AND UNDER YOUR NON-DISCLOSURE AGREEMENT (NDA) AND\OR TECHNOLOGY PREVIEW.
Introducing Novell ® Identity Manager 4 Insert Presenter's Name (16pt) Insert Presenter's Title (14pt) Insert Company/ (14pt)
©2010 Check Point Software Technologies Ltd. | [Unrestricted] For everyone Endpoint Security VPN R75 (SecureClient Next Generation)
BE-com.eu Brussel, 26 april 2016 EXCHANGE 2010 HYBRID (IN THE EXCHANGE 2016 WORLD)
Agenda  Microsoft Directory Synchronization Tool  Active Directory Federation Server  ADFS Proxy  Hybrid Features – LAB.
Active Directory Domain Services (AD DS). Identity and Access (IDA) – An IDA infrastructure should: Store information about users, groups, computers and.
Michael Mast Senior Architect Applications Technology Oracle Corporation.
Short Customer Presentation September The Company  Storgrid delivers a secure software platform for creating secure file sync and sharing solutions.
Oracle Java Cloud Service Oracle Develop July 2013.
Protect your data Enable your users Desktop Virtualization Information protection Mobile device & application management Identity and Access Management.
Copyright © 2014, Oracle and/or its affiliates. All rights reserved. | Daddy, what's a middle wear? An incredibly oversimplified explanation of what Middleware.
JD Edwards Support and Oracle Cloud Infrastructure: A Successful Path to Oracle Cloud
SharePoint Online Hybrid – Configure Outbound Search
Active Directory and Windows Security Integration with Oracle Database
Developing for Windows Azure
Presentation transcript:

Oracle Single Sign-On to Oracle Access Manager Migration Rob Otto – Oracle Consulting Services UK 1

The following is intended to outline our general product direction The following is intended to outline our general product direction. It is intended for information purposes only, and may not be incorporated into any contract. It is not a commitment to deliver any material, code, or functionality, and should not be relied upon in making purchasing decisions. The development, release, and timing of any features or functionality described for Oracle’s products remain at the sole discretion of Oracle. 2 2 2

Agenda Access Management introduction Oracle Access Manager 11gR2 Overview Oracle SSO v OAM 11gR2 OAM 11gR2- Migration and Coexistence with OSSO Q&A 3

<Insert Picture Here> Access Management Introduction 4 4

Platform Security Services Identity Management Portfolio – 11gR2 Modern, Innovative & Integrated Governance Password Reset Privileged Accounts Access Request Roles Based Provisioning Role Mining Attestation Separation of Duties Access Web Single Sign-on Federation Mobile, Social & Cloud External Authorization SOA Security Integrated ESSO Token Services Fraud Detection Directory LDAP Storage Virtual Directory Meta Directory Platform Security Services 5

Taking a Platform Approach Building on Components of Fusion Middleware WebCenter ADF Workflow SOA User Interface Coherence CAF Customization Performance Fusion Middleware 6

Oracle Access Management Comprehensive security for applications, data, and web services End-to-end authentication, single sign-on, and fine grained application protection Innovative anomaly detection, transaction security, and multi-factor authentication Extensive 3rd party integrations Access Management Authentication Single Sign-On Federation Fraud Prevention Authorization & Entitlements Web Services Security Secure Token Services 7

Adaptive Access Manager Oracle Access Management Suite Plus Entitlements Server Adaptive Access Manager Entitlements Management Fine Grained Authorization Risk-based Authentication Real-time Fraud Prevention Access Manager Identity Federation Secure Token Services Web Access Control Single Sign-On Partner SSO & Identity Federation Fedlet SP integration Security Token Management Identity Propagation 8

Oracle Access Management Blueprint Architecture

<Insert Picture Here> Oracle Access Manager 11gR2 Overview 10 10

Oracle Access Manager 11g Objectives Provide foundation for Access Management Suite Converge OAM, OSSO, and OpenSSO Provide new and advanced functionality to customers Tighten integrations 11

Oracle Access Manager 11g Key Features Benefits Modular Architecture Separated admin and runtime server to enable independent operations Secure Policy Model Access is denied by default until policies are created to allow access Simplified Install & Config One package to install and one series of steps to configure a simple working environment Session Management Allows admin tracking and termination of user sessions Diagnostics & Monitoring Allows administrators to monitor key operational metrics in real-time Central Agent Management Administration console provides a holistic view of all agents and shows the server they are connected to Backwards Compatibility Compatible with 10g webgates and 10g mod_osso Windows Native AuthN Enables Windows desktop to web single sign-on Improved Utilities Remote registration utility, remote access tester, and WLST cmds for policy operations 12

Oracle Access Manager 11g Architecture – Runtime Server Protocol Compatibility Framework Credential Collector SSO Engine AuthN Service AuthZ Service OAM Server Session Management Identity Provider Token Processing Partner & Trust Policy Service Configuration Service Coherence Distributed Cache Oracle Platform Security Services 13

Oracle Access Manager 11g Administration Console Integrated Security Administration, Agent Administration 14

Access Manager 11gR2 Deployment Overview 15 15

Access Manager 11gR2 Deployment Detail External Client Internet Firewall (Web Tier) Protected Load Balancer WebHosts Web Hosts OHS OHS WebGate WebGate Firewall (App Tier) AppHosts IAM Hosts IDMHosts WLS WLS_OAM Admin Server Admin Server WLS_ODSM AccessGate OAM Admin Console Admin Console ODSM EM Firewall (Data Tier) LDAP Hosts DB Hosts RAC OVD OID Metadata DB (OAM, OID, Schema) 16

Access Manager 11gR2 Installation and Configuration Installation process OAM 11g installs using Oracle Universal Installer (OUI) The installation process copies all the software bits to the host machine OUI does not perform product configuration Configuration process requires 2 steps Database schema configuration using Repository Creation Utility (RCU) Product configuration and deployment using WebLogic Configuration Wizard Oracle Support Note 340.1 provides a good starting point 17 17

Oracle Access Manager 11g Windows Native Authentication SPNEGO based credential validation for true Windows desktop to web single sign-on Allows single sign-on for WebGate and Oracle SSO protected applications simultaneously Does not need IIS based solution for WebGate WebGates and Oracle SSO protected applications need not run on Windows platform Can be enabled for a subset of protected applications Internal vs External websites 18

Oracle Access Manager 11g Windows Native Authentication - Setup Basic steps are as follows: Edit /etc/krb5.conf file Create Service Principal Name Obtain Kerberos Ticket Set-up OAM Kerberos AuthN Module Configure Kerberos AuthN Scheme for WNA Register AD as OAM User Store Verify OAM configuration (oam-config.xml) Enable Kerberos in Web Browser Test See OAM Admin Guide, Chapter 7 (link here) 19

<Insert Picture Here> Oracle SSO v OAM 11gR2 20 20

Oracle Access Manager Sample Oracle SSO Architecture Deployed Application Oracle HTTP Server MOD_OSSO agent Authentication Local User Store End User Authentication Decisions OC4J Application Server LDAP Authentication User Authentication Oracle Single Sign-On Server User Data User Synchronization Enterprise User Store Oracle Internet Directory Directory Integration Platform or Oracle Identity Manager Enterprise User Store Oracle Confidential – For Internal Use Only 21

Oracle Access Manager Key differences v OSSO OAM 11gR2 OSSO SSO, policy-based AuthN & AuthZ SSO and simple AuthN only WebLogic Server-based OC4J-based 3rd-Party LDAP server support Dependence on OID Support for OSSO, OAM 10g, OAM 11g and OpenSSO agents via PCL Support for only OSSO agents (mod_osso) Server-based session management Sessions via client cookies only Cross-domain SSO is native Single network domain only Native password policy (R2+) OIDDAS for password policy Integration with OIM (optional) for User Self-Service OIDDAS for user self-service

OAM 11gR2- Migration and Coexistence with OSSO <Insert Picture Here> OAM 11gR2- Migration and Coexistence with OSSO 23 23

Oracle Access Manager 11g OSSO 10g Upgrade Facilitated through AS Upgrade Assistant Process: Install OAM 11g Run Upgrade Assistant pointing to Oracle AS Single-On 10.1.4.3 Two modes: Retain Ports: no changes required on partner sites Change Ports: partner sites need new osso.conf which is generated by the Upgrade Assistant See Support Migration Advisor (note 343.1) and upgrade viewlet (note 1230123.1)

Co-existence: OAM11g & SSO 10g Supports OracleAS SSO 10g Release (10.1.2.0.2) through OracleAS SSO 10g Release (10.1.4.3.0) Co-existence requires same back-end user identity store: Oracle Internet Directory (OID) 25 25

Co-existence: OAM11g & SSO 10g mod_osso redirects requests to the 11g OAM Server for authentication through a proxy. mod_wl replaces mod_oc4j. mod_wl enables SSO to work without any changes on the OHS Without Proxy 26

Co-existence: SSO between Partner Applications App1 upgraded to OAM11g User accessing App1 OAM sets the SSO cookie and updates session information accordingly. The cookie includes a flag indicating that an OSSO cookie must also exist for this cookie to be valid. 27 27

Q & A

29 29