Using OAM 11gR2 for integrating multiple network domains

Using OAM 11gR2 for integrating multiple network domains

This question has been Answered.
Is OAM 11g capable of integrating multiple network domains in the same intra network. ex: abc.domain1.com and xyz.domain2.net. can they be integrated with the same OAM and can SSO be achieved between them. How can we achieve it. Please provide a pointer to the same. I tried searching support, communities. Which point to the 10g version documentation.

IdmSk

Correct Answer
by IdmSk on Oct 18, 2016 1:10 AM
To clarify about OIF- it stands for Oracle Identity Federation product. Since 11gR2 OIF functionality has been merged inside OAM. So if you are using 11gR2PS3 OAM you get the functionality of OIF. OIF provides the functionality for enabling federation in OAM.
To answer your question about    "when all the authentication is maintained by the same User store, policy store will be maintained by the same OAM and with in the intranet n/w"     -the thing is that federation is a framework or a way to federate between two parties. Now this depends on your use cases and requirements and has nothing to do with User store, policy store etc. User store and policy store are required for any OAM configuration.
Now if your requirement is to authenticate applications and you have users defined in a common directory ie User store (OAM will use this user store), then in this scenario where all your applications reside in the same intranet, you do not need OIF or Federation.
Hope this is clear now and please mark the answer as solved if it resolves or answers your question.
Average User Rating: 3 of 5 (1 rating)
Average User Rating
Average User Rating: 3 of 5
(1 rating)
  • 1. Re: Using OAM 11gR2 for integrating multiple network domains

    amey g
    Elite
    Hello Jay,

    Yes its possible. Could you please update exact version of OAM?


    Thanks,
    Amey
  • 2. Re: Using OAM 11gR2 for integrating multiple network domains

    IdmSk
    Apprentice
    OAM, Oracle Access Manager component of Oracle Fusion Middleware provides authentication and authorization to protect resources. These protected resources are the applications which are protected by OAM via policy based mechanisms. These policies defines the resource or the application being protected, - i.e. user has to authenticate before they are granted access to the application. Here the concept of domain is Application domain which you or the admin can define in terms of 1)Resources (the end application being protected) 2) Authentication mechanism 3) Authorization policies 4) Public or Protected and can also make/configure your own Authentication module. Hence your question about using/integrating multiple network domains does not have a bearing. Just make sure your firewall or internal network access is enabled between OAM and the application. In other words location of the application or "the protected resource" is defined in terms of application domain in OAM. Your application domain, say Domain_Apace could be set of applications which are running on Apache web server (irrespective of which network they are on, as long as network connectivity is available). You define policies for authentication and authorization for Domain_Apache applications. So these applications will be protected by OAM via this policy domain. Next you could define another domain, say Domain_WLS which are applications running on the Weblogic servers. You would define policy for this domain and all applications running under Domain_WLS would be protected for authentication and authorization via this policy.
    OAM 11g is now in the latest version of 11gR2PS3. Here is link to 11gRPS3 documentation.  Just FYI, in addition to OAM you would consider other components of Identity Management like Directory, Identity Manager which integrate with OAM to provide you a complete solution.

  • 3. Re: Using OAM 11gR2 for integrating multiple network domains

    Jay...
    Newbie
    Hello SK, Amey,

    Thanks for your response. the current version of OAM is 11gR2PS3. I want to understand one more point here. I believe we do not have to use OIF in between when all the authentication is maintained by the same User store, policy store will be maintained by the same OAM and with in the intranet n/w .. correct?

    Cheers,
    Jay.

  • Correct Answer

    IdmSk
    Apprentice
    To clarify about OIF- it stands for Oracle Identity Federation product. Since 11gR2 OIF functionality has been merged inside OAM. So if you are using 11gR2PS3 OAM you get the functionality of OIF. OIF provides the functionality for enabling federation in OAM.
    To answer your question about    "when all the authentication is maintained by the same User store, policy store will be maintained by the same OAM and with in the intranet n/w"     -the thing is that federation is a framework or a way to federate between two parties. Now this depends on your use cases and requirements and has nothing to do with User store, policy store etc. User store and policy store are required for any OAM configuration.
    Now if your requirement is to authenticate applications and you have users defined in a common directory ie User store (OAM will use this user store), then in this scenario where all your applications reside in the same intranet, you do not need OIF or Federation.
    Hope this is clear now and please mark the answer as solved if it resolves or answers your question.

  • 5. Re: Using OAM 11gR2 for integrating multiple network domains
    Hi SK,

    Thanks for clarifying my doubt.

    Cheers,
    Jay.

Comments

Popular posts from this blog

VMware fix for Invalid manifest and ova file import failed errors

SOAPUI - import certificate

Centrally Managed Users (CMU) - New Feature in Oracle Database 18c