Skip Headers
Oracle® Collaboration Suite Integration with Microsoft Active Directory
Release 2 (9.0.4) for Solaris

Part Number B15610-01
Go to Documentation Home
Home
Go to Book List
Book List
Go to Index
Index
Go to Master Index
Master Index
Go to Feedback page
Feedback

Go to next page
Next
View PDF

Contents

Title and Copyright Information

Send Us Your Comments

Preface

Audience
Organization
Related Documentation
Conventions
Documentation Accessibility

1 Upgrading the Oracle Application Server

Oracle Internet Directory-Specific Preupgrade Tasks
Backing Up the Oracle Internet Directory
Preparing to Upgrade the Metadata Repository Database
Setting the Environment for Upgrading the Metadata Repository
Loading the DBMS_IAS_UPGRADE Package
Upgrading the Metadata Repository Container
Removing Invalid Packages From the Database
Executing mrc.pl for New Schema Creation and Oracle Internet Directory Entry Update
Resolving Errors
Upgrading the Identity Management Services
Upgrading Identity Management
Identity Management Configuration Overview
Understanding the Identity Management Upgrade Processes
The Identity Management Upgrade Process
Using Oracle Universal Installer to Upgrade Identity Management
Upgrading a Non-Distributed Identity Management Configuration
Upgrading a Distributed Identity Management Configuration
Performing an Oracle Internet Directory Multi-Master Replication Upgrade
Upgrading Oracle Internet Directory on One Replica
Upgrading Oracle Internet Directory on Multiple Replicas Simultaneously
Upgrading Oracle Internet Directory v. 9.2.0.x to Release 2 (9.0.4)
Performing Infrastructure Post-Upgrade Tasks
Completing the Oracle Internet Directory Upgrade
Applying Patches for Portal 9.0.2.2.14 and 9.0.2.3
Reconfigure the OracleAS Portal Instances for the Oracle Internet Directory Server
Refreshing the Delegated Administration Services (DAS) URL Cache
Recommended Performance Enhancement Tasks
Completing the Oracle Application Server Single Sign-On Upgrade
Re-configuring the Oracle Application Server Single Sign-On Middle Tier
Configuring Third-party Authentication
Installing Customized Pages in the Upgraded Server
Converting External Application IDs
Setting Up OracleAS Single Sign-On Replication
Upgrading the OracleAS Single Sign-On Server with a Customized Middle Tier
Troubleshooting Wireless Voice Authentication
Installing Languages in the OracleAS Single Sign-On Server
Re-Registering OracleAS Portal with the Upgraded OracleAS Single Sign-On Server
Re-Registering mod_osso with the Upgraded OracleAS Single Sign-On Server
Using an Upgraded Identity Management Configuration with Oracle9iAS Discoverer Release 2 (9.0.2)
Completing the Oracle Application Server Wireless Upgrade
Upgrading Wireless User Accounts in Oracle Internet Directory
Adding Unique Constraint on the orclWirelessAccountNumber Attribute in Oracle Internet Directory
Disabling Oracle Application Server Wireless Upgrade Triggers in the Infrastructure Repository
Activating All Oracle Application Server Wireless Release 2 (9.0.4) Features
Assigning Change Password Privilege to OracleAS Wireless
Specifying URL Query Parameters for Wireless Services That Use the HTTP Adapter
Decommissioning the Release 2 (9.0.2) Oracle Home
Deinstalling Oracle9iAS Release 2 (9.0.2) and Deleting the Source Oracle Home
Relocating Data, Control, and Log Files
Validating the Identity Management Upgrade
Executing the utlrp.sql Utility
Checking for Invalid Database Objects
Testing Oracle Application Server Single Sign-On Connectivity

2 Integration with the Microsoft Windows Environment

Overview of Integration with the Microsoft Windows Environments
Components for Integrating with the Microsoft Windows Environment
Methods for Tracking Changes in Microsoft Active Directory
Configuration Information Set During Installation of the Active Directory Connector
Synchronization Profiles
Mapping Rules
Access Controls
Information Required During Setup
Information Required in a Multiple-Domain Microsoft Active Directory Environment
Information Required for Synchronizing from Microsoft Active Directory to Oracle Internet Directory
Information Required for Synchronizing from Oracle Internet Directory to Microsoft Active Directory
Directory Information Tree Setup for Integration with Microsoft Active Directory
Planning the Directory Information Tree
Configuring the Directory Information Tree
The Directory Information Tree in a Multiple-Domain Active Directory Environment
Tools for Configuring the Active Directory Connector
High-Level Configuration Requirements
Deployments with Oracle Internet Directory as the Central Directory
Deployments with Microsoft Active Directory as the Central Directory
Planning the Integration with Microsoft Active Directory
Configuring the Active Directory Connector
Summary of Active Directory Connector Configuration Scenarios
Synchronization Scenarios with Single-Domain Microsoft Active Directory Environments
Synchronization Scenarios with Multiple-Domain Microsoft Active Directory Environments
About Scenario Examples
About the Information You Must Add to the Active Directory Connector
About the adprofilecfg.sh Tool
Tasks Common to Various Scenarios
Task 1: Verify the Microsoft Active Directory Information to be Configured into the Active Directory Synchronization Profiles
Task 2: Configure the Information Related to the Microsoft Active Directory Environment
Task 3: Start the Oracle Directory Integration and Provisioning Server as You Would for Synchronization
Synchronization Between a Single-Domain Microsoft Active Directory and Oracle Internet Directory
Scenario 1: One-Way Synchronization from Microsoft Active Directory to Oracle Internet Directory
Scenario 2: One-Way Synchronization from Oracle Internet Directory to Microsoft Active Directory
Scenario 3: Two-Way Synchronization Between Oracle Internet Directory and Microsoft Active Directory
Synchronization Between a Multiple-Domain Microsoft Active Directory and Oracle Internet Directory
Scenario 4: One-Way Synchronization from Microsoft Active Directory to Oracle Internet Directory when Global Catalog Is Configured in the Microsoft Active Directory Environment
Scenario 5: One-Way Synchronization from Microsoft Active Directory to Oracle Internet Directory when Global Catalog is not Configured in the Microsoft Active Directory Environment
Scenario 6: One-Way Synchronization from Oracle Internet Directory to Microsoft Active Directory
Configuring The Active Directory External Authentication Plug-in
Installing Active Directory External Authentication Plug-ins
Enabling the Active Directory External Authentication Plug-ins
Customizing the Active Directory Connector
Creating and Customizing a Synchronization Profile
Customizing Mapping Rules
Domain-Level Mapping
Attribute-Level Mapping
How to Customize the Mapping Rules
Customizing the Search Filter to Get Information from Microsoft Active Directory
Running the Active Directory Connector in SSL Mode
Synchronizing Passwords
Synchronizing Passwords from Oracle Internet Directory to Microsoft Active Directory
Synchronizing Passwords from Microsoft Active Directory to Oracle Internet Directory
Customizing ACLs
Customizing the LDAP Schema
Migrating Data Between Directories
Managing Integration with Microsoft Windows
Typical Management Tasks
Managing the Active Directory External Authentication Plug-in
Deleting the Active Directory External Authentication Plug-in
Disabling the Active Directory External Authentication Plug-ins
Re-enabling the Active Directory External Authentication Plug-ins
Integration with Microsoft Windows NT 4.0
Installing and Configuring Windows NT External Authentication and Auto-Provisioning Plug-ins
Troubleshooting Integration with Microsoft Windows
Troubleshooting Synchronization with Active Directory Connector
Debugging the Microsoft Active Directory External Authentication Plug-in
Sample LDIF Files Required for Integration with Microsoft Windows
grantrole.ldif
multidomaindit.ldif
renameprofile.ldif

3 Windows Native Authentication

Overview of Windows Native Authentication
How Windows Native Authentication Works
System Requirements
Configuring Windows Native Authentication
Verify That Microsoft Active Directory Is Set Up and Working
Install Oracle Internet Directory and OracleAS Single Sign-On
Synchronize Oracle Internet Directory with Microsoft Active Directory
Configure Oracle Internet Directory to Use Windows Authentication Plugin
Verify That Synchronization and the Authentication Plugin Are Working
Configure the Single Sign-On Server
Set Up a Kerberos Service Account for the Single Sign-On Server
Configure the Single Sign-On Server to Use the Sun JAAS Login Module
Configure the Single Sign-On Server as a Secured Application
Configure the End User Browser
Internet Explorer 5.0 and Greater
Internet Explorer 6.0 Only
Reconfigure Local Accounts
Fallback Authentication
Login Scenarios

Index