<Insert Picture Here> PeopleTools Security, What's New in PeopleTools 8.50 Tom Lenz & Sushma Patel Principal Support Engineer Oracle PeopleTools Global Customer Support
The following is intended to outline our general product direction. It is intended for information purposes only, and may not be incorporated into any contract. It is not a commitment to deliver any material, code, or functionality, and should not be relied upon in making purchasing decisions. The development, release, and timing of any features or functionality described for Oracle s products remains at the sole discretion of Oracle.
Agenda We will cover changes to PeopleTools Security in PT 8.50. <Insert Picture Here> Password Controls Dynamic Role Rules USER_PROFILE Message LDAP Authentication PeopleSoft Pluggable Encryption Technology (PET)
Password Controls
Password Controls
Password Control Solutions When unlocking a User Profile, the password MUST be changed Addresses a Security Vulnerability issue and is working as designed in 8.48.19 and 8.49.15. (Doc 790523.1) Password expire not showing for new users Bug 1664486000, resolved in PT 8.50. (Doc 657175.1) Password expires for users every time Bug1607397000, resolved in PT 8.49. Email ID needs to be defined for the user. (Doc 652630.1)
Password Control Solutions E-SEC: Can Password Controls be User Specific? (Doc 611621.1) E-SEC: How to Setup Password Controls in PeopleTools 8.1x, 8.2x, 8.4x. 8.5x (Doc 609930.1) E-LDAP: Can PeopleSoft Password Controls be Used with LDAP Authentication? (Doc 612048.1)
Agenda We will cover changes to PeopleTools Security in PT 8.50. <Insert Picture Here> Password Controls Dynamic Role Rules USER_PROFILE Message LDAP Authentication PeopleSoft Pluggable Encryption Technology (PET)
Dynamic Role Rules
Dynamic Role Rules
Dynamic Role Rules
Dynamic Role Rules
Dynamic Role Rules
Dynamic Role Rules
Dynamic Role Rule Solutions There are no new reported issues in PT 8.48 to 8.50 for Dynamic Role Rules Dynamic Role Rule Solutions: E-SEC: How to get Dynamic Role Rules to work on PT 8.4x and 8.1x (Doc ID 620659.1) E-SEC: Dynamic Roles test works fine, but does not execute the rules (Doc ID 616199.1) E-SEC: Troubleshooting Dynamic Role Rules on PeopleTools (Doc ID 612882.1) E-SEC: Enhancement to Improve Performance of Dynamic Role Rules (Doc ID 649245.1) E-AE/SEC: How to Schedule Dyn Role Rules using Recurrence Definitions (Doc ID 615876.1) E-LDAP: How to get LDAP Dynamic Role Rules to work in 8.4x (Doc ID 617419.1) Integration Broker Performance and Tuning Solutions: E-IB: Domain failover for Integration (Doc ID 615241.1) E-IB: Questions about Gateway Load Balancing and Domain Failover (Doc ID 643865.1) E-IB: Messaging problems when running multiple PUBSUB domains (Doc ID 659103.1) E-IB: Integration Broker Recommended PUB/SUB settings (Doc ID 615694.1)
Agenda We will cover changes to PeopleTools Security in PT 8.50. <Insert Picture Here> Password Controls Dynamic Role Rules USER_PROFILE Message LDAP Authentication PeopleSoft Pluggable Encryption Technology (PET)
USER_PROFILE Message
USER_PROFILE Message
USER_PROFILE Message
USER_PROFILE Solutions Permission Lists on the General tab of the User Profile get updated, EMPLID gets removed from the PSOPRDEFN table but not from PSOPRALIAS BUG 1509197000, resolved in PT 8.49. (Doc 648620.1) When a OPRID gets locked in the publishing DB the message does not update the subscribing DB BUG 1628650000, resolved in PT 8.50. (Doc 653266.1)
Agenda We will cover changes to PeopleTools Security in PT 8.50. <Insert Picture Here> Password Controls Dynamic Role Rules USER_PROFILE Message LDAP Authentication PeopleSoft Pluggable Encryption Technology (PET)
LDAP Authentication
LDAP Authentication
LDAP Authentication
LDAP Authentication
LDAP Authentication
LDAP Authentication with SSL PeopleTools uses Java Naming and Directory Interface (JNDI) libraries only. JNDI requires no added installation as it is part of the standard PeopleTools installation. No More Cert7.db or Oracle Wallet Manager PT 8.50 How to Setup SSL for LDAP Authentication (Doc 979094.1)
LDAP Authentication with SSL
LDAP Solutions LDAP Red Paper with Troubleshooting Tips for PeopleTools 8.x (Doc 641301.1) PT 8.50 App Server Logs All LDAP Search attempts (Doc 1050132.1) PT 8.50 Error Loading the JAVA VM Library (Doc 975469.1) PT 8.50 How to Setup SSL for LDAP Authentication (Doc 979094.1) LDAP SSL performance issues with App Server on Windows (Doc 640663.1) LDAP Authentication Login Performance with Active Directory (Doc 619825.1) Cache Directory Schema Fails with DSNAMEAT Field Error (Doc 621228.1) Cache Directory Schema Fails at LDAPSCHEMA.MAIN. step02 (Doc 623318.1) Can LDAP be Setup for Failover or Load Balancing? (Doc 611763.1) User Profile is Updated on Every Logon via LDAP (Doc 635278.1)
Agenda We will cover changes to PeopleTools Security in PT 8.50. <Insert Picture Here> Password Controls Dynamic Role Rules USER_PROFILE Message LDAP Authentication PeopleSoft Pluggable Encryption Technology (PET)
Pluggable Encryption Technology
Pluggable Encryption Technology
Pluggable Encryption Technology
PET Solutions What is PeopleSoft Pluggable Encryption Technology (PET)? (Doc 645892.1) Information on Best Security Practices to Attain PCI Standards (PET) (Doc 656475.1) Pluggable Encryption PGP Error Algorithm Requires a Signer. (211,513) (Doc 658450.1)
Other Security Issues/Solutions Looping GetCertificate Request in App Server Log Causes Account Lockout (Doc 781591.1) Query Access List Cache Executes when LDAP Users are Updated or Created (Doc 873919.1) PT 8.4x Troubleshooting SYSAUDIT Security Report Errors SEC-XX (Doc 636885.1) Red Paper on Securing Your PeopleSoft Application Environment (Doc 620422.1)
Questions? Comments? Suggestions? Stray Thoughts? Ask now or forever be logging Service Requests with Global Customer Support