Skip Headers

Oracle® Application Server 10g Security Guide
10g (9.0.4)

Part Number Part No. B10377-01
Go To Documentation Library
Home
Go To Product List
Solution Area
Go To Table Of Contents
Contents
Go To Index
Index

Go to previous page Go to next page


Preface

This document presents basic Web security concepts and describes the Oracle Application Server security framework and how to use it. First, it provides a survey of security issues and requirements that arise when operating private business systems in the public Internet environment. Then it introduces the security features of Oracle Application Server and provides configuration information for setting up a secure middle tier.

This preface contains these topics:

Audience

The Oracle Application Server 10g Security Guide is intended for security administrators, application developers, database administrators, system operators, and other Oracle users who perform the following tasks:

To use this document, you need to have general knowledge of Web server administration, Internet concepts, and networking concepts.

Documentation Accessibility

Our goal is to make Oracle products, services, and supporting documentation accessible, with good usability, to the disabled community. To that end, our documentation includes features that make information available to users of assistive technology. This documentation is available in HTML format, and contains markup to facilitate access by the disabled community. Standards will continue to evolve over time, and Oracle Corporation is actively engaged with other market-leading technology vendors to address technical obstacles so that our documentation can be accessible to all of our customers. For additional information, visit the Oracle Accessibility Program Web site at

http://www.oracle.com/accessibility/

Accessibility of Code Examples in Documentation

JAWS, a Windows screen reader, may not always correctly read the code examples in this document. The conventions for writing code require that closing braces should appear on an otherwise empty line; however, JAWS may not always read a line of text that consists solely of a bracket or brace.

Accessibility of Links to External Web Sites in Documentation

This documentation may contain links to Web sites of other companies or organizations that Oracle Corporation does not own or control. Oracle Corporation neither evaluates nor makes any representations regarding the accessibility of these Web sites.

Organization

This document contains:

Chapter 1, "Oracle Application Server Overview"

This chapter provides a basic overview of Oracle Application Server.

Chapter 2, "Oracle Application Server Security Architecture"

This chapter discusses the Oracle Application Server security framework, including its architecture. It describes each element and how they work together.

Chapter 3, "Oracle Identity Management"

This chapter presents Oracle Application Server deployment options.

Chapter 4, "Recommended Deployment Topologies"

This chapter provides details on the recommended security topologies for Oracle Application Server.

Chapter 5, "Privilege Delegation"

This chapter covers common security considerations for Oracle Application Server administrators.

Appendix A, "Managing PKI Credentials with Oracle Wallet Manager"

This appendix describes Oracle Wallet Manager and managing PKI credentials.

Glossary

This glossary contains terms that are pertinent to Web security and Oracle environments.

Related Documentation

For Oracle Application Server Application Administrators

This section lists common administration tasks and the manuals that describe them.

Task Read...

General administration tasks

Oracle Application Server 10g Administrator's Guide

Managing static content

Oracle HTTP Server Administrator's Guide

Controlling user access to Web content using portals

Oracle Application Server Portal Configuration Guide

Managing Oracle Application Server Web Cache

Oracle Application Server Web Cache Administrator's Guide

Writing and deploying secure OC4J applications

Oracle Application Server Containers for J2EE Security Guide

Managing Oracle Application Server Wireless for security mechanisms

Oracle Application Server Wireless Administrator's Guide

Managing users, passwords, and privileges

Oracle Internet Directory Administrator's Guide

Managing application, resource, and data source security using Oracle Application Server Reports Services

Oracle Application Server Reports Services Publishing Reports to the Web

Managing user access and internalization

Oracle Application Server Personalization Administrator's Guide

Configuring security for Oracle Application Server Workflow

Oracle Workflow Administrator's Guide

Administering SSO

Oracle Application Server Single Sign-On Administrator's Guide

Managing certificate issues

Oracle Application Server Certificate Authority Administrator's Guide

For Oracle Identity Management Infrastructure Administrators

For all tasks pertaining to administering and deploying Oracle Identity Management, see the Oracle Identity Management Concepts and Deployment Planning Guide.

For Oracle Application Server Application Developers

This section lists common development tasks and the manuals that describe them.

Task Go to...

Configuring SSO

Oracle Application Server Single Sign-On Administrator's Guide

Using mod_osso or the Oracle Application Server Single Sign-On SDK to enable applications for SSO

Oracle Application Server Single Sign-On Application Developer's Guide

Configuring Web Services

Oracle Application Server Web Services Developer's Guide

Configuring Syndication Services

Oracle Application Server Syndication Services Developer's and Administrator's Guide

Configuring BC4J

Oracle Business Component for Java Developing Business Components

Using keys and certificates for SSL communication in OC4J

Oracle Application Server Containers for J2EE Servlet Developer's Guide

For Oracle Application Server Application Deployers

This section lists common deployment tasks and the manuals that describe them.

Task Go to...

Configuring SSO

Oracle Application Server Single Sign-On Administrator's Guide

Configuring Forms with HTTP listener, OC4J, SSO, and OID

Oracle Application Server Forms Services Deployment Guide

Configuring security mechanisms in Oracle Application Server Discoverer

Oracle Application Server Discoverer Configuration Guide

See Also:

Oracle Application Server 10g Release Notes in the Oracle Application Server Platform-specific documentation for any security issues that are not addressed here.

For Oracle Application Server Application Users

Component Go to...

Using Oracle Ultra Search

Oracle Ultra Search User's Guide

Using Oracle Application Server ProcessConnect

Oracle Application Server ProcessConnect User's Guide

Setting up the database and PL/SQL to avoid known security problems

Oracle Application Server 10g mod_plsql User's Guide

Guide to Oracle Documentation

For more information, see these Oracle resources. Descriptions of documents have been added to some listings to guide you to where specific security information can be found. Where document titles are self-explanatory, no description is provided.

The Oracle Application Server Documentation Library contains the following documents:

Oracle Application Server Platform-Specific Documentation contains the following documents:

Oracle Database Documentation Library contains the following documents:

Printed documentation is available for sale in the Oracle Store at

http://oraclestore.oracle.com/

To download free release notes, installation documentation, white papers, or other collateral, please visit the Oracle Technology Network (OTN). You must register online before using OTN; registration is free of charge and can be done at:

http://otn.oracle.com/membership/

If you already have a username and password for OTN, then you can go directly to the documentation section of the OTN Web site at

http://otn.oracle.com/documentation/content.html

Conventions

This manual uses the following conventions:

Convention Meaning

.
.
.

Vertical ellipsis points in an example mean that information not directly related to the example has been omitted.

. . .

Horizontal ellipsis points in statements or commands mean that parts of the statement or command not directly related to the example have been omitted

boldface text

Boldface type in text indicates a term defined in the text, the glossary, or in both locations.

italic text

Italicized text indicates placeholders or variables for which you must supply particular values.

[ ]

Brackets enclose optional clauses from which you can choose one or none.


Go to previous page Go to next page
Oracle
Copyright © 2003 Oracle Corporation.

All Rights Reserved.
Go To Documentation Library
Home
Go To Product List
Solution Area
Go To Table Of Contents
Contents
Go To Index
Index