Nsure Idntity Manager & Oracle Internet Directory Michel Bluteau Field Corporate Strategist Nsure Identity Management Novell Québec
© 12 mai 2004 Novell Inc, Confidential & Proprietary 2 Driver for Oracle 10g OID Required privileges for driver Mandatory Classes for –OID –Enterprise User –Enterprise Role Required ACLs for the changelog
© 12 mai 2004 Novell Inc, Confidential & Proprietary 3 Oracle Internet Directory OID is an application that runs off Oracle OID clients use LDAP OID uses Oracle Net to communicate with Database servers
© 12 mai 2004 Novell Inc, Confidential & Proprietary 4 Oracle Internet Directory Oracle Directory Manager
© 12 mai 2004 Novell Inc, Confidential & Proprietary 5 Oracle Internet Directory Oracle Directory Manager
© 12 mai 2004 Novell Inc, Confidential & Proprietary 6 Oracle Internet Directory Communication
© 12 mai 2004 Novell Inc, Confidential & Proprietary 7 Oracle Advanced Security Uses OID for -Storing the password for a centralized user that can have access to more than one Database server -Centrally store and assign privileges -Integration of VPD(Virtual Private Database) and Row Label Security -With 10g, synchro of attributes userPassword(SSO) and orclPassword(DB) -OID can leverage RAS and RAC for high availability in a Oracle bubble(many DB servers)
© 12 mai 2004 Novell Inc, Confidential & Proprietary 8 Driver for Oracle OID bi-directional sync for data uni-directional sync for the password –From eDirectory to OID No customization required(versus JDBC)
© 12 mai 2004 Novell Inc, Confidential & Proprietary 9 Driver User: Select cn=orcladmin
© 12 mai 2004 Novell Inc, Confidential & Proprietary 10 Choose Create Like, create meta
© 12 mai 2004 Novell Inc, Confidential & Proprietary 11 Modify cn, sn, uid and userPassword
© 12 mai 2004 Novell Inc, Confidential & Proprietary 12 Result: cn=meta
© 12 mai 2004 Novell Inc, Confidential & Proprietary 13 Under cn=OracleContext, cn=Groups
© 12 mai 2004 Novell Inc, Confidential & Proprietary 14 Add to cn=OracleSuperAdminGroup
© 12 mai 2004 Novell Inc, Confidential & Proprietary 15 Add to cn=OracleUserSecurityAdmin
© 12 mai 2004 Novell Inc, Confidential & Proprietary 16 Add to cn=Common User Attributes
© 12 mai 2004 Novell Inc, Confidential & Proprietary 17 Add to cn=OracleContextAdmins
© 12 mai 2004 Novell Inc, Confidential & Proprietary 18 Add to required DAS groups
© 12 mai 2004 Novell Inc, Confidential & Proprietary 19 After adding meta to groups - meta can create users and groups via oidadmin - but cannot do so via LDAP with ldapadd or the DirXML driver See: east.oracle.com/docs/cd/B10464_02/manage.904/b1 2118/priv_de3.htm
© 12 mai 2004 Novell Inc, Confidential & Proprietary 20 After adding meta to groups - Provide meta with the required ACLs for cn=Users and cn=Groups (under dc=novl,dc=ca). See: east.oracle.com/docs/cd/B10464_02/manage.904/b1 2118/access2.htm# http://download- east.oracle.com/docs/cd/B10464_02/manage.904/b1 2118/access2.htm#
© 12 mai 2004 Novell Inc, Confidential & Proprietary 21 After adding meta to groups
© 12 mai 2004 Novell Inc, Confidential & Proprietary 22 After adding meta to groups
© 12 mai 2004 Novell Inc, Confidential & Proprietary 23 Required privileges for changelog The ACLs for changelog MUST be modified in order to allow meta access to the changelog
© 12 mai 2004 Novell Inc, Confidential & Proprietary 24 Under Access Control Management
© 12 mai 2004 Novell Inc, Confidential & Proprietary 25 Add meta, via Create Like
© 12 mai 2004 Novell Inc, Confidential & Proprietary 26 Add meta, via Create Like
© 12 mai 2004 Novell Inc, Confidential & Proprietary 27 Add meta, via Create Like
© 12 mai 2004 Novell Inc, Confidential & Proprietary 28 Add meta, via Create Like
© 12 mai 2004 Novell Inc, Confidential & Proprietary 29 Add meta, résultat
© 12 mai 2004 Novell Inc, Confidential & Proprietary 30 Classes required for OID - User requires the following classes: inetOrgPerson orclUserV2 orclUser(optional) - Group(dynamicGroup) requires the following classes: groupOfUniqueNames orclGroup the displayname attribute is mandatory
© 12 mai 2004 Novell Inc, Confidential & Proprietary 31
© 12 mai 2004 Novell Inc, Confidential & Proprietary 32 Classes required for OID
© 12 mai 2004 Novell Inc, Confidential & Proprietary 33 Classes required for OID
© 12 mai 2004 Novell Inc, Confidential & Proprietary 34 Classes required for OID