Administering Security for Oracle WebLogic Server
Table of Contents
Show All | Collapse- Title and Copyright Information
- Preface
- 1 Introduction and Roadmap
- 2 Overview of Security Management
- 3 Customizing the Default Security Configuration
- 4 Configuring WebLogic Security Providers
- When Do You Need to Configure a Security Provider?
- Reordering Security Providers
- Enabling Synchronization in Security Policy and Role Modification at Deployment
- Configuring an Authorization Provider
- Configuring the WebLogic Adjudication Provider
- Configuring a Role Mapping Provider
- Configuring the WebLogic Auditing Provider
- Configuring a WebLogic Credential Mapping Provider
- Configuring a PKI Credential Mapping Provider
- Configuring a SAML Credential Mapping Provider for SAML 1.1
- Configuring a SAML 2.0 Credential Mapping Provider for SAML 2.0
- Configuring the Certificate Lookup and Validation Framework
- Configuring a WebLogic Keystore Provider
- 5 Configuring Authentication Providers
- Choosing an Authentication Provider
- Using More Than One Authentication Provider
- Configuring the WebLogic Authentication Provider
- Configuring LDAP Authentication Providers
- LDAP Authentication Providers Included in WebLogic Server
- Requirements for Using an LDAP Authentication Provider
- Configuring an LDAP Authentication Provider: Main Steps
- Accessing Other LDAP Servers
- Enabling an LDAP Authentication Provider for SSL
- Dynamic Groups and WebLogic Server
- Use of GUID and LDAP DN Data in WebLogic Principals
- Configuring Users and Groups in the Oracle Internet Directory and Oracle Virtual Directory Authentication Providers
- Example of Configuring the Oracle Internet Directory Authentication Provider
- Configuring Failover for LDAP Authentication Providers
- Configuring an Authentication Provider for Oracle Unified Directory
- Following Referrals in the Active Directory Authentication Provider
- Improving the Performance of WebLogic and LDAP Authentication Providers
- Configuring RDBMS Authentication Providers
- Configuring a Windows NT Authentication Provider
- Configuring the SAML Authentication Provider
- Configuring the Password Validation Provider
- Configuring Identity Assertion Providers
- How an LDAP X509 Identity Assertion Provider Works
- Configuring an LDAP X509 Identity Assertion Provider: Main Steps
- Configuring a Negotiate Identity Assertion Provider
- Configuring a SAML Identity Assertion Provider for SAML 1.1
- Configuring a SAML 2.0 Identity Assertion Provider for SAML 2.0
- Ordering of Identity Assertion for Servlets
- Configuring Identity Assertion Performance in the Server Cache
- Configuring a User Name Mapper
- Configuring a Custom User Name Mapper
- 6 Configuring Single Sign-On with Microsoft Clients
- Overview of Single Sign-On with Microsoft Clients
- System Requirements for SSO with Microsoft Clients
- Single Sign-On with Microsoft Clients: Main Steps
- Configuring Your Network Domain to Use Kerberos
- Creating a Kerberos Identification for WebLogic Server
- Configuring Microsoft Clients to Use Windows Integrated Authentication
- Creating a JAAS Login File
- Configuring the Identity Assertion Provider
- Using Startup Arguments for Kerberos Authentication with WebLogic Server
- Verifying Configuration of SSO with Microsoft Clients
- 7 Configuring Single Sign-On with Web Browsers and HTTP Clients
- Configuring Single Sign-On Using SAML White Paper
- SAML for Web Single Sign-On Scenario API Example
- Configuring SAML 1.1 Services
- Configuring SAML 2.0 Services
- Configuring SAML 2.0 Services: Main Steps
- Configuring SAML 2.0 General Services
- Configuring an Identity Provider Site for SAML 2.0 Single Sign-On
- Configuring a Service Provider Site for SAML 2.0 Single Sign-On
- Viewing Partner Site, Certificate, and Service Endpoint Information
- Web Application Deployment Considerations for SAML 2.0
- Enabling Debugging for SAML 1.1 and 2.0
- 8 Migrating Security Data
- 9 Managing the RDBMS Security Store
- 10 Managing the Embedded LDAP Server
- 11 Configuring Identity and Trust
- 12 Configuring SSL
- SSL: An Introduction
- One-Way and Two-Way SSL
- Java Secure Socket Extension (JSSE) SSL Implementation Supported
- Setting Up SSL: Main Steps
- Using Host Name Verification
- Specifying a Client Certificate for an Outbound Two-Way SSL Connection
- SSL Debugging
- SSL Session Behavior
- Configuring RMI over IIOP with SSL
- SSL Certificate Validation
- Using JCE Providers with WebLogic Server
- Specifying the Version of the SSL Protocol
- Using the JSSE-Based SSL Implementation
- Using the RSA JSSE Provider in WebLogic Server
- X.509 Certificate Revocation Checking
- Certificate Revocation Checking Overview
- Enabling the Default CR Checking Configuration
- Choosing the CR Checking Methods to Be Used by WebLogic Server
- Failing SSL Certificate Path Validation if Revocation Status Cannot Be Determined
- Using the Online Certificate Status Protocol
- Using Certificate Revocation Lists
- Configuring Certificate Authority Overrides
- 13 Configuring Oracle OPSS Keystore Service
- 14 Configuring Security for a WebLogic Domain
- Important Information Regarding Cross-Domain Security Support
- Enabling Trust Between WebLogic Server Domains
- Using Connection Filters
- Using the Java Authorization Contract for Containers
- Viewing MBean Attributes
- How Passwords Are Protected in WebLogic Server
- Protecting User Accounts
- Configuring a Domain to Use JAAS Authorization
- 15 Configuring JASPIC Security
- 16 Using Compatibility Security
- Running Compatibility Security: Main Steps
- Limited Visibility of Compatibility Security MBeans
- The Default Security Configuration in the CompatibilityRealm
- Configuring a Realm Adapter Authentication Provider
- Configuring the Identity Assertion Provider in the Realm Adapter Authentication Provider
- Configuring a Realm Adapter Auditing Provider
- Protecting User Accounts in Compatibility Security
- Accessing 6.x Security from Compatibility Security
- 17 Security Configuration MBeans
- SSLMBean
- ServerMBean
- EmbeddedLDAPMBean
- RDBMSSecurityStoreMBean
- SecurityMBean
- SecurityConfigurationMBean
- RealmMBean
- WindowsNTAuthenticatorMBean
- CustomDBMSAuthenticatorMBean
- ReadonlySQLAuthenticatorMBean
- SQLAuthenticatorMBean
- DefaultAuditorMBean
- Compatibility Security MBeans
- UserLockoutManagerMBean
- Other Security Provider MBeans