3 Enterprise Single Sign-On

Oracle Enterprise Single Sign-On Suite provides users with unified sign-on and authentication across all their enterprise resources. Unlike Oracle Access Manager that focuses on web access management, Oracle Enterprise Single Sign-On Suite covers also desktops, client-server, custom and host-based mainframe applications. Even if users travel or share workstations, they can enjoy the flexibility of a single log-on that eliminates the need for multiple user names and passwords and helps enforce strong password and authentication policies.

This chapter contains topics related to enterprise single sign-on:

3.1 Enterprise Single Sign-On Synchronization

ESSO Synchronization is a component of Oracle Enterprise Single Sign-On Suite Logon Manager, which handles storage and retrieval of credentials and settings from an external repository such as an LDAP or RDBMS store. This feature lets you synchronize credentials between an end user's local store (on a workstation) and a store in a remote SSO repository (file system share, relational database, or directory server). You configure synchronization through the ESSO-LM administration console.

Table 3-1 shows the supported integrations:

Table 3-1 Oracle Enterprise Single Sign-On Suite Synchronization Manager Integrations

ESSO Synchronization Manager Integrated with Additional Information

Microsoft Active Directory


Microsoft Active Directory Application Mode (ADAM)






3.2 Enterprise Single Sign-On Provisioning Gateway

Oracle Enterprise Single Sign-On Suite Provisioning Gateway (ESSO-PG) enables system administrators to directly distribute, reset, remove, or delete user credentials to an Enterprise Single Sign-On solution without the need for any user involvement.

Here are some examples:

  • An administrator can inject a new user's credentials directly into the user's ESSO-LM account.

  • The administrator can update ESSO-LM simultaneously to reset a password and prevent an application from falling out of synchronization with ESSO-LM.

  • When a user's access to an application is terminated, the administrator can use ESSO-PG to quickly remove the corresponding credentials from the user's ESSO-LM account.

  • When a user leaves the company, the administrator can instantly delete all the user's credentials.

All these operations can be automatically initiated and controlled by industry-leading provisioning systems. ESSO-PG provides an open interface to integrate with other industry-standard or internally-developed provisioning systems, and also provides an interactive interface for administrators to manually provision credentials.

Table 3-2 shows the supported integrations:

Table 3-2 Oracle Enterprise Single Sign-On Suite Provisioning Gateway Integrations

ESSO-PG Integrated with Additional Information

Oracle Identity Manager


Oracle Waveset


IBM Tivoli Identity Manager


Novell Identity Manager


3.3 Enterprise Single Sign-On Authentication Manager

Oracle Enterprise Single Sign-On Suite Authentication Manager (ESSO-AM), an add-on module to Oracle Enterprise Single Sign-on Logon Manager (ESSO-LM), enables an organization to seamlessly provide a strong authentication bridge to all its applications, including smart cards and Entrust authenticators.

Users can employ different authenticators at different times, and application access can be controlled based upon the authenticator used for all authentication events: initial authentication, re-authentication, and forced authentication.

Table 3-3 shows the supported integrations: