This chapter provides information you should review before installing Oracle Identity Management 11g Release 1 (11.1.1) components and Oracle Identity and Access Management 11g Release 1 (11.1.1). It includes the following topics:
Note:
For information about prerequisites for installing the 11g (11.1.1.2.0) version of Oracle Internet Directory (OID), Oracle Virtual Directory (OVD), Oracle Directory Services Manager (ODSM), Oracle Directory Integration Platform (ODIP), and Oracle Identity Federation (OIF) and patching them to 11.1.1.5.0, see Before Installing Oracle Identity Management (11.1.1.5.0).For information about prerequisites for installing the 11g (11.1.1.5.0) version of Oracle Identity Manager (OIM), Oracle Access Manager (OAM), Oracle Adaptive Access Manager (OAAM), Oracle Entitlements Server (OES), and Oracle Identity Navigator (OIN), see Before Installing Oracle Identity and Access Management (11.1.1.5.0).
This section discusses the following topics:
Installing and Configuring Java Access Bridge (Windows Only)
Creating Database Schema Using the Oracle Fusion Middleware Repository Creation Utility (RCU)
Before performing any installation, read the system requirements and certification documentation to ensure that your environment meets the minimum installation requirements for the components you are installing. Both of these documents are available on Oracle Technology Network (OTN).
Oracle Fusion Middleware System Requirements, Prerequisites, and Specifications
The system requirements document covers information such as hardware and software requirements, minimum disk space and memory requirements, and required system libraries, packages, or patches:
http://www.oracle.com/technetwork/middleware/ias/downloads/fusion-requirements-100147.html
Note:
The system requirements document also covers Oracle Universal Installer Startup Requirements.Oracle Fusion Middleware Supported System Configurations
The certification document covers supported installation types, platforms, operating systems, databases, JDKs, and third-party products:
http://www.oracle.com/technetwork/middleware/ias/downloads/fusion-certification-100350.html
If you are installing Oracle Identity Management on a Windows system, you have the option of installing and configuring Java Access Bridge for Section 508 Accessibility. This is only necessary if you require Section 508 Accessibility features:
Download Java Access Bridge from the following Web site:
http://java.sun.com/javase/technologies/accessibility/accessbridge/
Install Java Access Bridge.
Copy access-bridge.jar
and access-1_4.jar
from your installation location to the jre\lib\ext
directory.
Copy the WindowsAccessBridge.dll
, JavaAccessBridge.dll
, and JAWTAccessBridge.dll
files from your installation location to the jre\bin
directory.
Copy the accessibility.properties
file to the jre\lib
directory.
Oracle Directory Integration Platform (ODIP) and Oracle Identity Federation (OIF) are configured with a WebLogic domain. Oracle Internet Directory (OID) and Oracle Virtual Directory (OVD) can be configured with or without a WebLogic domain. For Oracle Identity Management products that require a WebLogic domain, you must configure Node Manager.
You must perform the following steps after installing Oracle WebLogic Server and before installing Oracle Identity Management:
Verify the Oracle WebLogic Server Node Manager utility is stopped. If it is running, kill the process. Use the following commands to identify running process and kill the same:
For example, on UNIX:
1) ps-ef | grep -i nodemanager
This will return the Process Id of the Node Manager Process.
2) kill -9
<Process Id of the Node Manager Process>
On Windows:
Use the Windows Task Manager to identify running Node Manager processes and kill the same.
Determine if the nodemanager.properties
file is present in the WL_HOME
/common/nodemanager/
directory.
If the nodemanager.properties
file is not present, then follow the instructions below:
On UNIX:
Run startNodeManager.sh
(Located at <WL_HOME>/server/bin
directory) to start Node Manager.
On Windows:
Run startNodeManager.cmd
(Located at <WL_HOME>\server\bin
directory) to start Node Manager.
If the nodemanager.properties file does exist, open it and verify that the ListenPort
parameter is included and that it is set. If the ListenPort
parameter is not included or set, edit the nodemanager.properties
file so that it is similar to the following, where NODE_MANAGER_LISTEN_PORT represents the port the Node Manager listens on, such as 5556:
ListenPort=NODE_MANAGER_LISTEN_PORT
You must install an Oracle Database before you can install some Oracle Identity Management components, such as:
Oracle Internet Directory
Oracle Identity Federation, if you want to use an RDBMS data store
For the latest information about supported databases, visit the following Web site:
http://www.oracle.com/technetwork/middleware/ias/downloads/fusion-certification-100350.html
The database must be up and running to install the relevant Oracle Identity Management component. The database does not have to be on the same system where you are installing the Oracle Identity Management component.
The database must also be compatible with Oracle Fusion Middleware Repository Creation Utility (RCU), which is used to create the schemas that Oracle Identity Management components require. For information about RCU requirements, refer to the system requirements document at the following Web site:
http://www.oracle.com/technetwork/middleware/ias/downloads/fusion-requirements-100147.html
Note:
Ensure that the following database parameters are set:'aq_tm_processes' >= 1
'db_cache_size' >= '150994944'
'java_pool_size'>= '125829120'
'shared_pool_size' >= '183500800'
'open_cursors' >= '500
'
If you are installing a new database, be sure to configure your database to use AL32UTF8 character set encoding. If your database does not use the AL32UTF8 character set, you will see the following warning when running RCU: "The database you are connecting is with non-AL32UTF8 character set. Oracle strongly recommends using AL32UTF8 as the database character set." You can ignore this warning and continue using RCU.
You must create and load the appropriate Oracle Fusion Middleware schema in your database before installing the following Oracle Identity Management components and configurations:
Oracle Internet Directory, if you want to use an existing schema rather than create a new one using the Installer during installation.
Note:
When you install Oracle Internet Directory, you have the choice of using an existing schema or creating a new one using the Installer. If you want to use an existing schema, you must create it using the Oracle Fusion Middleware Repository Creation Utility (RCU) before you can install Oracle Internet Directory. If you choose to create a new schema during installation, the Installer creates the appropriate schema for you and you do not need to use the RCU.If you are installing Oracle Internet Directory and your database is not configured as per the requirements in the fusion middleware requirements and prerequisites doc, you would see the following warnings: "Recommended value for Database initialization parameter processes is 500. Choose YES to continue or NO to go back to the same screen and specify different database details." To fix this one can click No and apply the requisite configuration mentioned in the fusion middleware requirements and prerequisites doc - section 8 Repository Creation Utility (RCU) Requirements which can be accessed from the following link:
http://download.oracle.com/docs/html/E18558_01/fusion_requirements.htm#CHDJGECA
Oracle Identity Federation Advanced configurations that use RDBMS for the Federation Store, Session Store, Message Store, or Configuration Store.
You create and load Oracle Fusion Middleware schema in your database using the RCU, which is available in the Oracle Fusion Middleware 11g Release 1 (11.1.1) release media and on the Oracle Technology Network (OTN) Web site. You can access the OTN Web site at:
http://www.oracle.com/technetwork/index.html
Note:
RCU is available only on Linux x86 and Windows x86 platforms. Use the Linux RCU to create schemas on supported UNIX databases. Use Windows RCU to create schemas on supported Windows databases.When you run RCU, create and load only the following schema for the Oracle Identity Management component you are installing—do not select any other schema available in RCU:
For Oracle Internet Directory, select only the Identity Management - Oracle Internet Directory schema
For Oracle Identity Federation, select only the Identity Management - Oracle Identity Federation schema
Note:
When you create schema, be sure to remember the schema owner and password that is shown in RCU. For Oracle Identity Federation, it is of the formPREFIX
_OIF
. You will need to provide this information when configuring Oracle Identity Federation with RDBMS stores.See:
The Oracle Fusion Middleware Repository Creation Utility User's Guide for complete information.This topic describes optional environment-specific tasks you may want to perform before installing Oracle Identity Management 11g Release 1 (11.1.1.5.0). This topic includes the following sections:
Note:
If the environment variableLD_ASSUME_KERNEL
is set, it needs to be unset.If you want to install Oracle Identity Management using symbolic links, you must create them before installation. For example, you could create symbolic links for the installation by executing the following commands:
prompt> mkdir /home/basedir prompt> ln -s /home/basedir /home/linkdir
Then, when you run the Installer to install Oracle Identity Management, you can specify /home/linkdir
as the Oracle Home.
After installation, you cannot create symbolic links to the Oracle Home. Also, you cannot move the Oracle Home to a different location and create a symbolic link to the original Oracle Home.
If you plan to install Oracle Identity Management components on a DHCP server, you must ensure the Installer can resolve host names. This may require editing the /etc/hosts file on UNIX systems, and installing a loopback adapter on Windows systems. The following information provides general examples, you should alter these examples to make them specific to your environment.
Configure the host to resolve host names to the loopback IP address by modifying the /etc/hosts file to contain the following entries. Replace the variables with the appropriate host and domain names:
127.0.0.1 hostname.domainname hostname 127.0.0.1 localhost.localdomain localhost
Confirm the host name resolves to the loopback IP address by executing the following command:
ping hostname.domainname
Install a loopback adapter on the DHCP host and assign it a non routable IP address.
After installing the adapter, add a line to the %SYSTEMROOT%\system32\drivers\etc\hosts file immediately after the localhost line and using the following format, where IP_address represents the local IP address of the loopback adapter:
IP_address hostname.domainname hostname
You can install Oracle Identity Management components on a multihomed system. A multihomed system is associated with multiple IP addresses, typically achieved by having multiple network cards on the system. Each IP address is associated with a host name and you can create aliases for each host name.
The Installer retrieves the fully qualified domain name from the first entry in /etc/hosts file on UNIX, or the %SYSTEMROOT%\system32\drivers\etc\hosts file on Windows. For example, if your file looks like the following, the Installer retrieves myhost1.mycompany.com for configuration:
127.0.0.1 localhost.localdomain localhost 10.222.333.444 myhost1.mycompany.com myhost1 20.222.333.444 devhost2.mycompany.com devhost2
For specific network configuration of a system component, refer to the individual component's documentation listed in "Related Documents"for more information.
This section discusses the following topics:
Installing and Configuring Java Access Bridge (Windows Only)
Obtaining the Latest Oracle WebLogic Server and Oracle Fusion Middleware 11g Software
Installing Oracle WebLogic Server and Creating the Oracle Middleware Home
Creating Database Schema Using the Oracle Fusion Middleware Repository Creation Utility (RCU)
Installing the Latest Version of Oracle SOA Suite (Oracle Identity Manager Users Only)
The Oracle Fusion Middleware Supported System Configurations document provides certification information for Oracle Fusion Middleware, including supported installation types, platforms, operating systems, databases, JDKs, and third-party products related to Oracle Identity and Access Management 11g Release 1 (11.1.1.5.0).
You can access the Oracle Fusion Middleware Supported System Configurations document by searching the Oracle Technology Network (OTN) web site:
http://www.oracle.com/technetwork/middleware/ias/downloads/fusion-certification-100350.html
This topic describes the system requirements for installing Oracle Identity and Access Management 11g Release 1 (11.1.1.5.0) and includes the following sections:
The information in this topic is current at the time of publication. For the most recent information, refer to the Oracle Fusion Middleware System Requirements, Prerequisites, and Specification document, which contains information related to hardware, software, disk space, memory, system library, and patch requirements.
You can access the Oracle Fusion Middleware System Requirements, Prerequisites, and Specification document by searching the Oracle Technology Network (OTN) web site:
When you start the Installer, it checks for the requirements listed in Table 3-1. The Installer will notify you if any requirements are not met.
Table 3-1 Installer Startup Requirements
Category | Minimum or Accepted Value |
---|---|
Platform |
UNIX:
Windows:
|
CPU Speed |
At least 300 MHZ |
Temp Space |
At least 500 MB |
Swap Space |
At least 500 MB |
Monitor |
At least 256 colors |
Table 3-2 lists the minimum memory requirements to install Oracle Identity and Access Management 11g Release 1 (11.1.1):
Table 3-2 Minimum Memory Requirements
Operating System | Minimum Physical Memory | Minimum Available Memory |
---|---|---|
Linux |
2 GB |
1 GB |
UNIX |
2 GB |
1 GB |
Microsoft Windows |
2 GB |
1 GB |
The specific memory requirements for your Oracle Identity and Access Management 11g Release 1 (11.1.1) deployment depends on which components, or combination of components, you install.
If you are installing Oracle Identity and Access Management on a Windows operating system, you have the option of installing and configuring Java Access Bridge for Section 508 Accessibility. This is only necessary if you require Section 508 Accessibility features:
Download Java Access Bridge from the following URL:
http://java.sun.com/javase/technologies/accessibility/accessbridge/
Install Java Access Bridge.
Copy access-bridge.jar
and jaccess-1_4.jar
from your installation location to the jre\lib\ext
directory.
Copy the WindowsAccessBridge.dll
, JavaAccessBridge.dll
, and JAWTAccessBridge.dll
files from your installation location to the jre\bin
directory.
Copy the accessibility.properties
file to the jre\lib
directory.
Refer to the following for more information about the latest Oracle WebLogic Server and Oracle Fusion Middleware 11g software:
For more information on obtaining Oracle Fusion Middleware 11g softwares, see "Obtain the Oracle Fusion Middleware Software" and "Install Oracle WebLogic Server" in the Oracle Fusion Middleware Installation Planning Guide.
For information about downloading Oracle WebLogic Server, see "Product Distribution" in the Oracle Fusion Middleware Installation Guide for Oracle WebLogic Server.
For complete information about patching your Oracle Fusion Middleware 11g to the latest release, refer to the Oracle Fusion Middleware Patching Guide.
Before you can install Oracle Identity and Access Management 11g Release 1 (11.1.1) components, you must install Oracle WebLogic Server and create the Oracle Middleware Home directory.
For more information, see "Install Oracle WebLogic Server" in Oracle Fusion Middleware Installation Planning Guide.
In addition, see Oracle Fusion Middleware Installation Guide for Oracle WebLogic Server for complete information about installing Oracle WebLogic Server.
Oracle WebLogic Server Directory Structure
After you install Oracle WebLogic Server and create a Middleware Home, a home directory, such as wlserver_10.3
, is created for Oracle WebLogic Server under your Middleware Home. This home directory is referred to as WL_HOME.
At the same level as WL_HOME, separate directories are created for the following components associated with Oracle WebLogic Server:
Sun JDK - jdk160_24
Oracle JRockit - jrockit_1.6.0_24
Oracle Coherence 3.6
Note:
Ensure that the JDK version you select is Java SE 6 Update 24 or higher.Note that WebLogic domains are created in a directory named domains
located in the user_projects
directory under your Middleware Home. After you configure any of the Oracle Identity and Access Management products in a WebLogic administration domain, a new directory for the domain is created in the domains
directory. In addition, a directory named applications
is created in the user_projects
directory. This applications
directory contains the applications deployed in the domain.
You must install an Oracle Database before you can install some Oracle Identity and Access Management components. The database must be up and running to install the relevant Oracle Identity and Access Management component. The database does not have to be on the same system where you are installing the Oracle Identity and Access Management component.
The following database versions are supported:
10.2.0.4
11.1.0.7
11.2
Note:
You can locate the most recent information about supported databases by referring to the "Oracle Fusion Middleware Certification" topic in this chapter.Table 3-3 lists the databases requirements for RCU at the time of publication:
Table 3-3 RCU Database Requirements
Category | Minimum or Accepted Value |
---|---|
Version |
Oracle Database 10.2.0.4, 11.1.0.7, or 11.2 (11.1.0.7 or later for non-XE database). Note: When installing the database, you must choose the AL32UTF8 character set. |
Shared Pool Size |
147456 KB |
SGA Maximum Size |
147456 KB |
Block Size |
8 KB |
Processes |
500 |
|
|
Note:
After installing the Oracle 11g database, you must complete the following steps:Log in to the database as the sys
(default) user.
Run the following commands:
alter system set session_cached_cursors=100 scope=spfile;
alter system set processes=500 scope=spfile;
Bounce the database and continue with the installation of Oracle Fusion Middleware Repository Creation Utility (RCU) and loading of schemas.
To identify the patches required for Oracle Identity Manager 11.1.1.5.0 configurations that use Oracle Database 11.1.0.7, refer to the Oracle Identity Manager section of the 11g Release 1 Oracle Fusion Middleware Release Notes.
You must create and load the appropriate Oracle Fusion Middleware schema in your database before installing the following Oracle Identity and Access Management components and configurations:
Oracle Identity Manager
Oracle Access Manager
Oracle Adaptive Access Manager
Oracle Entitlements Server
You create and load Oracle Fusion Middleware schema in your database using the Oracle Fusion Middleware Repository Creation Utility (RCU), which is available on the Oracle Technology Network (OTN) web site. You can access the OTN web site at:
http://www.oracle.com/technetwork/index.html
Note:
RCU is available only on Linux and Windows platforms. Use the Linux RCU to create schemas on supported UNIX databases. Use Windows RCU to create schemas on supported Windows databases. After you extract the contents of thercuHome.zip
file to a directory, you can see the executable file rcu
in the BIN
directory.
For information about launching and running RCU, see the "Launching RCU with a Variety of Methods" and "Running Oracle Fusion Middleware Repository Creation Utility (RCU)" topics in the guide Oracle Fusion Middleware Repository Creation Utility User's Guide. For information about troubleshooting RCU, see the "Troubleshooting Repository Creation Utility" topic in the guide Oracle Fusion Middleware Repository Creation Utility User's Guide.
When you run RCU, create and load only the following schema for the Oracle Identity and Access Management component you are installing—do not select any other schema available in RCU:
For Oracle Identity Manager, select the Identity Management - Oracle Identity Manager schema. The SOA Infrastructure schema, the User Messaging Service schema, and the Metadata Services schema are also selected, by default.
For Oracle Adaptive Access Manager, select the Identity Management - Oracle Adaptive Access Manager schema. By default, the AS Common Schemas - Metadata Services schema is also selected.
For Oracle Adaptive Access Manager with partition schema support, select the Identity Management - Oracle Adaptive Access Manager (Partition Supp...) schema. By default, the AS Common Schemas - Metadata Services schema is also selected.
Note:
For information about Oracle Adaptive Access Manager schema partitions, see OAAM Partition Schema Reference.For Oracle Access Manager, select the Identity Manager - Oracle Access Manager schema. By default, the AS Common Schema - Audit Services schema is also selected.
For Oracle Entitlements Server, select the Identity Management - Oracle Entitlements Server schema. By default, the AS Common Schemas - Metadata Services schema is also selected.
Note:
When you create a schema, be sure to remember the schema owner and password that is shown in RCU.If you are creating schemas on databases with Oracle Database Vault installed, note that statements such as CREATE USER
, ALTER USER
, DROP USER
, CREATE PROFILE
, ALTER PROFILE
, and DROP PROFILE
can only be issued by a user with the DV_ACCTMGR
role. SYSDBA can issue these statements by modifying the Can Maintain Accounts/Profiles rule set only if it is allowed.
See:
The Oracle Fusion Middleware Repository Creation Utility User's Guide for complete information.If you want to reuse an existing database schema, you must upgrade your old database schema to work with Oracle Fusion Middleware 11g products and components.
For information about upgrading your existing database schema, see Oracle Fusion Middleware Upgrade Guide for Oracle Identity Management.
If you are installing Oracle Identity Manager, you must install the latest version of Oracle SOA Suite (11.1.1.5.0).
Follow the instructions in this section to install the latest Oracle SOA Suite software. The installation of Oracle SOA Suite is a prerequisite for configuring Oracle Identity Manager.
Installing the latest version of Oracle SOA Suite 11g involves the following steps:
Obtaining the Latest Oracle WebLogic Server and Oracle SOA Suite Software
Installing Oracle WebLogic Server and Creating the Middleware Home
Refer to the following for more information about the latest Oracle WebLogic Server and Oracle Fusion Middleware 11g software:
You can download the latest Oracle Fusion Middleware 11g software from the Oracle Technology Network (OTN):
http://www.oracle.com/technetwork/index.html
At the time this document was published, the latest release of Oracle Fusion Middleware 11g was 11g Release 1 (11.1.1.5.0), which provides new features and capabilities that supersede those available in Oracle Fusion Middleware 11g Release 1 (11.1.1.1.0) and 11g Release 1 (11.1.1.2.0).
For complete information about patching your Oracle Fusion Middleware 11g to the latest release, refer to the Oracle Fusion Middleware Patching Guide.
Oracle SOA Suite requires Oracle WebLogic Server and a Middleware Home directory. For more information, see "Install Oracle WebLogic Server" in Oracle Fusion Middleware Installation Planning Guide. In addition, see "Running the Installation Program in Graphical Mode" in Oracle Fusion Middleware Installation Guide for Oracle WebLogic Server.
Note:
If you have already created a Middleware Home before installing Oracle Identity and Access Management components, you do not need to create a new Middleware Home again. You must use the same Middleware Home for installing Oracle SOA Suite.Note that only Oracle Identity Manager requires Oracle SOA Suite 11g (11.1.1.5.0). This step is required because Oracle Identity Manager uses process workflows in Oracle SOA Suite to manage request approvals.
Follow the instructions in Table 3-4 to install Oracle SOA Suite. If you need additional help with any of the installation screens, click Help to access the online help.
To start the Oracle SOA Suite installation wizard, you must complete the following steps:
Extract the contents of the soa.zip
(11.1.1.5.0) to a directory, such as soa
.
From your present working directory, move to the Disk1
directory under soa
.
From the Disk1
directory, run runInstaller
(on UNIX) or setup.exe
(on Windows) executable files to launch the Oracle SOA Suite 11.1.1.5.0 installation wizard.
Table 3-4 Installation Flow for Install Only Option
No. | Screen | Description and Action Required |
---|---|---|
1 |
Welcome Screen |
Click Next to continue. |
2 |
Prerequisite Checks Screen |
Click Next to continue. |
3 |
Specify Installation Location Screen |
Specify the Middleware Home and Oracle Home locations. You must specify the location of the same Middleware Home that contains Oracle Identity and Access Management components. For more information about these directories, see "Oracle Fusion Middleware Directory Structure and Concepts" in Oracle Fusion Middleware Installation Planning Guide. Click Next to continue. |
4 |
Specify Security Updates Screen |
Provide your E-mail address to be informed of the latest product issues. Click Next to continue. |
5 |
Installation Summary Screen |
Verify the information on this screen. Click Install to begin the installation. |
6 |
Installation Progress Screen |
If you are installing on a UNIX system, you may be asked to run the Click Next to continue. |
7 |
Installation Complete Screen |
Click Finish to dismiss the installer. |