Skip Headers
Oracle® Fusion Middleware Enterprise Single Sign-On Suite Secure Deployment Guide
11g Release 2 (11.1.2.2)

Part Number E37694-01
Go to Documentation Home
Home
Go to Table of Contents
Contents
Go to Feedback page
Contact Us

Go to previous page
Previous
Go to next page
Next
PDF · Mobi · ePub

4 Securing Provisioning Gateway

Provisioning Gateway allows administrators to remotely provision application credentials to Logon Manager users using either the included Provisioning Gateway Web console or by interfacing with Oracle and third-party identity management solutions.

On the server side, Provisioning Gateway runs as two Web applications hosted via Microsoft IIS:

On the end-user side, a plug-in within Logon Manager reads the provisioning instructions stored in the Logon Manager repository during each synchronization event and executes them by adding, modifying, or deleting application credentials from the user's Logon Manager credential store.

4.1 Securing Provisioning Gateway on the Client Side

Provided that Logon Manager has been securely deployed and configured as described in Securing Logon Manager, no extra work is necessary to secure Provisioning Gateway on the client side. This is because the Provisioning Gateway plug-in within Logon Manager uses Logons Manager's synchronization mechanism to interact with the repository, eliminating the need for a dedicated connection. Connection and data security is ensured by Logon Manager's built in encryption mechanisms, provided the repository connection is utilizing SSL.

4.2 Securing Provisioning Gateway on the Server Side

To secure Provisioning Gateway on the server side, you must do the following:

The configuration instructions are provided in the Enterprise Single Sign-On Suite Installation Guide, Enterprise Single Sign-On Suite Administrator's Guide, and standalone Provisioning Gateway documentation, all available on the Oracle Support website.