Configuring WebLogic for Single Sign-On
WebLogic supports a variety of LDAP providers (for example, Oracle Internet Directory). See the Tested Configurations documents for the products with which you intend to enable with SSO to determine the supported LDAP providers, and see your LDAP provider documentation for details on adding users and groups to the store. One of the requirements for the web-based applications is that you create groups in the LDAP store and assign each user that requires access to your applications to these groups in WebLogic.
The following groups are created during the initial deployment of Primavera Gateway:
- PrimaveraGatewayProductionAdministrator
- PrimaveraGatewayAdminNoData
- PrimaveraGatewayProductionDeveloper
- PrimaveraGatewayProductionUser
- PrimaveraGatewayUserNoData
The following group was created during the deployment of the Primavera Data Warehouse web-based Configuration Utility:
- PrimaveraAnalyticsProduction
Note:
If you have modified the name of a group in WebLogic, you must also modify the name of the group in your LDAP provider.Also, you must configure SSO providers in the WebLogic security realm. See Creating Single Sign-On Authentication Providers for information on creating authentication providers.
Creating Single Sign-On Authentication Providers
To create SSO authentication providers:
- Log in to the WebLogic Administration Console as an administrative user for either Primavera Gateway or Primavera Analytics.
- In the Change Center pane select Lock & Edit.
- In the Domain Structure pane, select Security Realms.
- Select myrealm in the security realm list.
- In the Settings for myrealm page, select the Providers tab.
- Select New and enter information for a new authenticator provider.
- Select New to enter information for a new authenticator provider.
- In the Name field, enter a name for the provider. For example, PrimaveraAuthenticator.
- In the Type field, select OracleInternetDirectoryAuthenticator.
- In the Common tab, select the newly created provider and set the Control Flag to SUFFICIENT, and click Save.
- In the Provider Specific tab, enter the LDAP information from Oracle Access Manager LDAP store. Ensure you enter information in the following sections: Connection, Users, Groups, Static Groups, Dynamic Groups (optional), and General.
- Click Save.
- In the Domain Structure pane, select Security Realms, myrealm, and Providers.
- Edit all other authenticators and change the Control Flag to SUFFICIENT.
- In the Providers screen, click the Reorder Authentication Providers button and reorder the providers in the following sequence:
- OAMIdentityAsserter
- PrimaveraAuthenticator
- DefaultAuthenticator
- DefaultIdentityAsserter
- Click OK to save your changes
- In the Change Center pane, click Activate Changes.
- Log out of the WebLogic Administration Console.