Defining Nodes for PeopleSoft-Only Single Signon

Defining General Node Properties for PeopleSoft-Only Single Signon

Access the Node Definitions page (PeopleTools, and then Portal, and then Portal Node Definitions).

This example illustrates the fields and controls on the Portal Nodes Definitions - Node Definitions page for the default local node.

Portal Nodes Definitions page - Node Definitions for default local node

The following example shows the Nodes - Node Definitions page for a remote PeopleSoft node participating in single signon as defined on the local database:

Important:

The node name that you define for a remote PeopleSoft node to participate in single signon must be the same name as the default local node name on the participant’s local database.

This example illustrates the fields and controls on the Portal Nodes Definitions - Node Definitions page for a remote PeopleSoft node.

Portal Nodes Definitions page - Node Definitions for remote node

The fields and controls required for single signon are described in the following table. Note that your business and system requirements may warrant additional configuration of this page.

Field or Control Description

Description

Enter a description for the node.

Node Type

Select PIA from the drop-down list.

The Node Type for local and remote PeopleSoft nodes participating in single signon must be PIA.

Authentication Option

Determines how nodes in a single signon configuration authenticate other nodes in the same configuration. The valid options for single signon are:

  • Password: Indicates that each node in the single signon configuration authenticates other nodes by way of knowing the password for each node. For example, if there are three nodes (A, B, and C), the password for node A needs to be specified in its node definition on nodes A, B, and C.

  • Certificate: Indicates that a digital certificate authenticates each node in the single signon configuration. For certificate authentication, you need to have the following in the key store in the database for each node:

    • Certificate for each node.

      Note:For SSO, avoid using certificate key size 4096 due to browser limitation.

    • Root certificate for the CA that issued the certificate.

    Important: For single signon, the alias for the certificate of a node needs to be the same as the node name. Also, you must request and set up your digital certificates before you set the authentication option to certificate authentication.

While the option None, which signifies no authentication between nodes, is included in the drop-down list, it is not a valid option for single signon nodes.

Default Local Node

When defining the default local node on the local database, select the Default Local Node option.

Indicates that the current node represents the database you’re signed in to. The default local node is used specifically for setting up single signon. The options you set for single signon should be made on the default local node.

Node Password

  • Default local node definition.

    Enter a password for the node. The value you enter is limited to 88 characters.

  • Remote PeopleSoft node definitions.

    Enter the password for the single signon participant’s default local node, as provided by the participant.

Note: You must reboot the application server and the web server after you define or change this value.

Create Node Password

The Create Node Password button appears only on the definition for the default local node.

Oracle recommends that customers use strong, complex passwords and make use of the maximum number of characters. This button provides a convenient method to fulfill the requirements for a more secure password.

  1. Click the button to create a 32-character strong, random password.

  2. Click OK on the informational message.

  3. Save the page to see a message with the generated password in clear text.

    It is important that you save the password displayed in the message, because it is required to configure remote nodes for single signon.

Default User ID

  • Default local node definition.

    Enter or select a default user ID to associate with the node.

  • Remote PeopleSoft node definitions.

    Enter or select the default user ID defined for the single signon participant’s default local node, as provided by the participant.

Create CheckTokenID

The Create CheckTokenID button appears only:

  • On the definition for the default local node.

  • When the Authentication Option type is Password or Certificate.

Click the button to create a system-generated check tokenID for use in conjunction with single signon among PeopleSoft systems.

When you click the button, the system populates the Check TokenID field with the generated value.

Check TokenID

  • Default local node definition:

    This field displays the check token ID value generated after clicking the Create CheckTokenID button. This ID is used in conjunction with single signon among PeopleSoft systems.

    Alternatively, you can create a custom ID up to 256 characters.

    Copy the value in the field before saving the page. You must provide this value to other PeopleSoft partners/nodes participating in single-signon, as they must define this value on their database on the remote node definition that represents your database.

  • Remote PeopleSoft node definitions.

    On definitions for remote PeopleSoft nodes participating in single signon, enter the value provided by your single signon partner.

After you save the page the field becomes masked, regardless of whether a value is defined in the field or not.

Note: You must reboot the application server and the web server after you define or change this value.

Defining Portal Node Properties for PeopleSoft-Only Single Signon

Access the Nodes - Portal page (PeopleTools, and then Portal, and then Portal Node Definitions and click the Portal tab).

The following example shows the Nodes - Portal page for the local default node.

This example illustrates the fields and controls on the Nodes - Portal page for a default local node.

Nodes - Portal page (Default local node)

The fields and controls required for single signon are described in the following table. Note that your business and system requirements may warrant additional configuration of this page.

Note:

References to “remote PeopleSoft nodes” in the descriptions refer to remote node definitions that you must define for each PeopleSoft system participating in single signon.

Field or Control Description

Tools Release

  • Default local node definition.

    When defining properties for the default local node, enter the Tools release version installed on the local database. On most browsers, you can press CTRL + J to locate the PeopleTools release installed on the database.

  • Remote PeopleSoft node definitions.

    When defining properties for remote PeopleSoft nodes, enter the Tools release version installed on the single signon participant’s database.

Content URI Text

  • Default local node definition.

    When defining properties for the default local node, enter the URI of the pscontent servlet for the local database.

  • Remote PeopleSoft node definitions.

    When defining properties for remote PeopleSoft nodes, enter the URI of the pscontent servlet (psc) for the single signon participant’s default local node.

Portal URI Text

  • Default local node definition.

    When defining properties for the default local node, enter the URI of the portal servlet (psp) for the local database.

  • Remote PeopleSoft node definitions.

    When defining properties for remote PeopleSoft nodes, enter the URI of the portal servlet (psp) for the single signon participant’s default local node.