5 Oracle Access Management

This chapter describes issues associated with Oracle Access Management.

It includes the following topics:

5.1 General Issues and Workarounds

This section describes general issues and workarounds organized by specific Access Manager services. If you do not find a service-related topic (Access Portal, for example), there are no general issues at this time.

5.1.1 General Issues and Workarounds: Access Manager

This topic describes general issues and workarounds for Oracle Access Management Access Manager (Access Manager). It includes the following topics.

5.1.1.1 10G & 32 BIT 11G WebGates Not Supported with SHA1/SHA2 Certificates (Cert Mode)

If Oracle Access Management Access Manager 11.1.2.3.0 server is configured in Cert mode with SHA1/SHA2 certificate, 10g WebGate and 11.1.2.1.0/11.1.2.2.0 (32bit) WebGates are not supported.

5.1.1.2 Login Issue with Active Directory Over SSL

A login issue occurs with Active Directory when using an SSL connection. The current workaround for this is to use a non-SSL port for the ActiveDirectoryAuthenticator.

5.1.1.3 SSO Global Logout Fails With Resource Secured By Public Policy

SSO global logout fails if one of the participating resources is secured by OAM public policy. When Enterprise Content Management PS7 is used with OAM R2PS2 and the OAM ID Asserter is added as the authentication provider in which the action type is defined as an OAM_IDENTITY_ASSERTION token (rather than OAM_REMOTE_USER), SSO global logout fails.

5.1.1.4 Behavior Impact for Non-OIC (Oracle Identity Connect) Clients

When a user is authenticated with any Authentication Scheme using the LDAPNoPasswordModule Authentication Module, an authentication level of "0" is set for the user irrespective of the authentication level defined in the Authentication Scheme.

5.1.1.5 Specify Registered/Allowed Grant Types to Request OAuth Token

The registered/allowed grant types must be specified when an OAuth token is requested.

5.1.1.6 IdmConfigTool Creates Weblogic Authentication Provider With Invalid Configuration

By default, idmConfigTool -configOAM creates a Weblogic Authentication Provider with the following parameters:

  • Static Group Object Class = groupofnames

  • Static Member DN Attribute = member

  • Static Group DNs from Member DN Filter = (&(member=%M)(objectclass=groupofnames))

If your Oracle Unified Directory (OUD) is using groupofuniquenames to define groups and uniquemember to define group members, this must be explicitly changed in the Weblogic Authentication Provider for OUD.

5.1.1.7 OAM 11.1.2.2 WebGate Agents Not Supported with OAM 11.1.2.3 Server

After the OAM server is upgraded to 11.1.2.3, the 11.1.1.6 orapki library is no longer available to insert certificates in OAM 11.1.2.2 WebGate agents.

WORKAROUND: After upgrading to OAM 11.1.2.3, run the following command to convert the wallet to a version compatible with components of 11.1.2.3.

orapki wallet convert [-wallet [wallet]] [-auto_login_only]

5.1.1.8 Access SDK Client Only Needs oamsdk-api.jar

As of this 11.1.2.3.0 release, the Access SDK client only needs to have oamasdk-api.jar in the classpath. This enhancement cause resulted in a documentation change. See Section 5.4.2.1, "Access SDK Documentation Update."

5.1.1.9 Oracle Access Management Console Only Displays 1000 Users in Search

When you search users in the identity store using the Oracle Access Management Console (Configuration -> Administration -> User search), a maximum of 1000 users is displayed even when the result contains more than 1000 users.

5.1.1.10 Anonymous User Must be Defined in Integrated OAM-OAAM Environment

Anonymous must be defined as a user in the default UID when coexistence and Multi-Data Center is enabled in an integrated OAM-OAAM environment.

5.1.1.11 Names of Certain Access Manager Artifacts Will Not Be Localized

Because they are values and not strings that can be translated, the names of Authentication Policies, Authentication Schemes, Authentication Modules and Authentication Plugins will not be localized.

WORKAROUND: These names can be edited.

5.1.1.12 Partial String + Wild Card (*) Doesn't Work with Authorization Rules Search

A partial string paired with a wild card (*) does not work when searching User or Groups in Authorization Rules. A notification error is not thrown when this occurs.

5.1.1.13 Intermittent Issue with OAM and Coherence

Normally when the Coherence server is started in SSL mode, it comes up on port 9095. This issue is encountered if Access Manager finds 9095 in use and starts Coherence on 9096. To alleviate this, make sure that port 9095 is open for the Coherence server.

5.1.1.14 No Error Message Displayed When Login Page is Tunneled for DCC

For an OAM-OAAM integrated environment (using TAP and the DCC to work, the following configurations must be done.

  • Set the DCC app domain "/oam/**" to unprotected.

  • Set "/favicon.ico" as an excluded resource.

5.1.1.15 OAM OTP Mail for SFA Is Not Localized

There is no globalization support for OTP mail in SFA. Although the mail subject and content can be edited in AdaptiveAuthenticationPlugin and AdaptiveAuthenticationModule, it applies to all users.

5.1.1.16 Can't Search GROUP When Active Directory Is Identity Store

If using Active Directory as your identity store, change the group objectclass to "group" rather than the default "groupofuniquenames".

5.1.1.17 DCC Webgate Must be Configured to Tunnel when Using Federation

Detached Credential Collector (DCC) HTTP Reverse Proxy feature has been introduced in the 11.1.2.2.0 release. This new DCC HTTP Reverse Proxy capability is different from the previous DCC for HTTP-Basic/FORM based login, with the latter not working for the Federation SSO flows (IdP or SP mode).

5.1.2 General Issues and Workarounds: Security Token Service

This topic describes general issues and workarounds for Oracle Access Management Security Token Service. There are none currently listed.

5.1.3 General Issues and Workarounds: Identity Federation

This topic describes general issues and workarounds for Oracle Access Management Identity Federation. There are none currently listed.

5.1.4 General Issues and Workarounds: Mobile and Social

This topic describes general issues and workarounds for Oracle Access Management Mobile and Social. There are none currently listed.

5.1.5 General Issues and Workarounds: Access Portal Service

This topic describes general issues and workarounds for Oracle Access Management Access Portal Service. It includes the following topics.

5.1.5.1 Application Can Still Be Delegated When Delegation Is Disabled

When an Administrator unchecks the delegation option using the Oracle Access Management Console, the Application can still be delegated. The workaround is to use the classic ESSO for enabling and disabling the delegation setting.

5.2 Configurations and Workarounds

This section describes configurations and workarounds organized around specific services. The following topics are included:

5.2.1 Configurations and Workarounds: Access Manager

This topic describes configurations and workarounds for Oracle Access Management Access Manager (Access Manager). It includes the following.

5.2.1.1 Enabling ECID Context For Request Tracking

11.1.2.3 WebGate agents can send the execution context identifier (ECID) as a value of 'ECID-context' to the OAM server and receive a response containing the identifier in return. The ECID can help in end to end debugging of requests sent from the WebGate to OAM and returned responses. To enable ECID context set the following user-defined parameter to true in the 11g WebGate profile.

sendECIDResponse=true

5.2.1.2 Create A Server Entry for oam_policy_mgr1

Using the Oracle Access Management Console, create a server entry for the oam_policy_mgr1 node if it is targeted on a different machine than the AdminServer machine. Navigate through Configuration -> server instances from the Launch Pad. The hostname and port should match that of the oam_policy_mgr1 managed server node. Use the SSL Port, if enabled. The oam_policy_mgr1 node should only be started after creation of this server entry.

5.2.2 Configurations and Workarounds: Security Token Service

There are no configurations and workarounds for Oracle Access Management Security Token Service.

5.2.3 Configurations and Workarounds: Identity Federation

This topic describes configurations and workarounds for Oracle Access Management Identity Federation. It includes the following.

5.2.3.1 Enabling Federation with Mobile and Social

After Oracle Access Management is installed and configured with Mobile and Social, the Federation Service should be enabled but is not. To enable the Federation Service:

  1. Login to the Oracle Access Management Console as Administrator.

  2. Navigate through Configuration to access the Available Services.

  3. Disable and re-enable the Mobile and Social Service.

    This action will enable the Federation Service.

5.2.4 Configurations and Workarounds: Mobile and Social

There are no configurations and workarounds for Oracle Access Management Mobile and Social.

5.3 Oracle Access Management Console Issues

This section documents issues that affect the Oracle Access Management Console. It includes the following topics:

5.3.1 WebGate for OHS 12c Should Be Configured as 11g WebGates

A WebGate is available for OHS 12c however the Oracle Access Management Console only lists 10g and 11g options. At this time, 12c WebGates should be configured as you would an 11g WebGate.

5.4 Documentation Errata

Oracle manuals describing and showing Oracle Access Management 11.1.2 and related services, including these Release Notes, incorrectly refer to the OAM Server (the former name of the Access Manager Server). However, in the next release of Oracle 11.1.2 books, the term OAM Server will be replaced by AM Server (Access Manager Server).

This section describes documentation errata for Oracle Access Management-specific manuals. It includes the following titles:

5.4.1 Administrator's Guide for Oracle Access Management

There are no documentation errata for Administrator's Guide for Oracle Access Management.

5.4.2 Developer's Guide for Oracle Access Management

This topic describes modifications made to the Developer's Guide for Oracle Access Management.

5.4.2.1 Access SDK Documentation Update

Due to changes in the oam-java-asdk.zip, the About Installing Access SDK section in chapter 2 of the Developer's Guide for Oracle Access Management has been modified.