Oracle IDM Integration with E-Business Suite & Middleware Technologies Session ID#: 14251 Prepared by: Scott Brinker IDM Security Specialist CAP Deepak Sharma Sr. Consultant AST Corporation REMINDER Check in on the COLLABORATE mobile app
Who are we? Scott Brinker 13 Years MDW systems experience / 16 years IT experience 10 Years at the CAP Deepak Sharma More than 8 years in the IT industry Certified in Oracle Identity Governance Suite Certified Oracle SOA Suite Implementation Specialist Several Successful IDM and SOA Implementations
Specialized. Recognized. Preferred. The right partner makes all the difference. Our Services Oracle Partnership Oracle Specialized E-Business Suite Oracle Platinum Partner EBS Financial Management Business Intelligence/EPM Fusion Middleware CRM Managed Services Oracle University Project Advisory Services Pillar Partner SOA Business Intelligence Hyperion Oracle University Approved Education Center Oracle University Reseller Oracle Accelerator Implementer Certified OnDemand Implementer Small Business Strategy Council EBS Supply Chain Management EBS Human Capital Management BI Applications BI Foundation Hyperion Planning Service Oriented Architecture Application Development Framework Database Public Sector Oracle Excellence/Titan Award Winner 2013, 2011 & 2009 2011 Inc. Top Small Company Workplaces 2013, 2012 Inc. 5000 Fastest Growing Companies 2012 Best & Brightest Companies to Work For
The leading organization of board-certified pathologists serves patients, pathologists, and the public by fostering and advocating excellence in the practice of pathology and laboratory medicine worldwide. Have about 260,000 users Employs approximately 600 users CAP leverages the many components IAM Stack OIM, OAM, OID, OVD, OIF, OES SSO Applications at CAP Core Website www.cap.org EBS BIPublisher and BIAnalytics SOA Worklist UCM Been partnering with AST on Series of Security Phases over the past 2 years
Agenda Oracle Identity & Access Management Suite Oracle IAM Capabilities Integration with Oracle Fusion Middleware Components Integration with Oracle E-Business Suite Questions and Answers
Oracle IAM Suite - Overview Access Control Oracle Access Manager Oracle Enterprise Single Sign-On Oracle Identity Federation Oracle Web Services Manager Oracle Adaptive Access Manager Identity Administration Oracle Identity Manager Oracle Identity Analytics Oracle Privileged Accounts Manager Audit & Compliance Directory Services Oracle Virtual Directory Oracle Internet Directory (with Directory Integration Platform) Oracle Unified Directory Oracle Identity & Access Management Suite
Oracle IAM Capabilities Identity and Role administration Industry Leading Provisioning Solution Enterprise Entitlements Solutions Access Management Biometrics Based Access Control Fraud Detection and Risk Analysis Single & Multi-Domain Single Sign On Industry Standard and Regulatory Compliance Federation Support for SAML Base Integration OOB Integration Support with External Systems
Oracle FMW Products IAM Integration Which Products? Universal Content Management Oracle Business Intelligence Hyperion Planning Suite WebCenter Portal WebCenter Sites Oracle SOA Suite
Oracle FMW Products IAM Integration How?
Example IAM Integration - CAP
Oracle FMW Products IAM Integration Implementation Step Create WebLogic Authentication Providers for OAM Adding OAM SSO Provider Configure Security and Policy Stores in OID OAM Policies Install OHS and Configure WebGate To Intercept Requests Configure OHS for Caching Use OHS as Reverse Proxy
Oracle FMW Products IAM Integration Best Practices Migrate Application Policy and Security Stores to LDAP Protect SOA Web-Services Using OAM Enable SSO for Content Server and WebCenter Portal Together Implement OHS Farm For Centralized Control Ensure SSL and Redirect non-ssl to SSL Ensure High Availability Streamline Provisioning Process Use Load Balancer
Oracle E-Business Suite Integration Single Sign On Things To Know Pre-requisite E-Business Suite SSO Requires OID Synchronous user account creation in OID for istore, isupplier and irecruitment Additional Component, E-Business Suite Access Gate is Required Recommendation Deploy Access Gate in an HA Environment Configure Centralized Logout Enable OAM Multi Language Support if Required Enable Self Service Password Changes
Oracle E-Business Suite Integration Single Sign On Implementation Steps Identify WebLogic server which will host E-Business Suite Access Gate and create weblogic domain Install patches - If you are on apps 12.1.1 then apply patch 8919489 & 9824524, for 12.0.6 apply patch 10220779 & 10257580, and for 12.1.2/12.1.3 apply patch 9454600 Configure Primary Identity Store of Oracle Access Manager as Oracle Internet Directory (OID) Install OHS 11g server which will host webgate and also act as proxy server for WebLogic (via mod_wl_ohs), more on mod_wl_ohs Create DBC file for machine hosting WebLogic server java oracle.apps.fnd.security.admindesktop
Oracle E-Business Suite Integration Single Sign On Implementation Steps Use ant -f txkebsauth.xml to deploy EBS Access Gate on weblogic domain. Customize Access Gate Login Page Configure OHS to forward request to WebLogic using mod_wl_ohs Install 10g or 11g Webgate with OHS server Verify Authentication Modules, Schemes, Policies, Application Domain, Public and Protected Resource Configure Profile Option Application Authenticate Agent & Applications SSO Type for EBS R12 Configure EBS-OID synchronization (OID to EBS, EBS to OID or both using option provisiontype) Configure Logout for EBS
Oracle E-Business Suite Integration Single Sign On How?
Oracle E-Business Suite Integration Provisioning Things To Know Types of users in EBS EBS Accounts FND_USER HRMS/Person Record PER_ALL_PEOPLE_F Customer/Vendor Record TCA HZ_PARTIES Types of EBS Connectors e-business Employee Reconciliation e-business User Management Recommendation Should not configure Oracle e-business Employee Reconciliation & Oracle e-business User Management with HRMS both at same time.
Oracle E-Business Suite Integration Provisioning How?
Typical Physical Architecture CAP
References http://oracle.com http://blogs.oracle.com/stevenchan
Please complete the session evaluation Session ID: 14251 We appreciate your feedback and insight You may complete the session evaluation either on paper or online via the mobile app
Thank You. Deepak Sharma dsharma@astcorporation.com Scott Brinker sbrinke@cap.org