Friday, November 23, 2012

E-Business Suite R12 integration with Oracle Identity Management 11g

After successful implementations of Oracle SSO 10g with Oracle E-Business Suite 11i and R12, I have now completed an installation and implementation of the Oracle Identity Management and Access Management 11g. This is the Single Sign-On solution of Oracle.
We used the latest version of Oracle Identity Management( Idm) solution, which is currently certified with E-Business Suite R12. This is version IdM 11gR1, to be more precise 11.1.1.5.
Oracle Access Manager (OAM) provides the access management service for authentication and authorization and replaces the Oracle 10g OSSO service.
The current certified implementation requires an Oracle Internet Directory (OID). We have setup the synchronizing process of users from MS Active Directory to Oracle OID. Furthermore, we have setup Oracle provisioning from OID to EBS to create EBS users automatically.
We completed the installation with Kerberos authentication.  With this Windows Native Authentication (WNA) solution,  we created a ‘zero Single Sign-on’ solution. The user is authenticated by Kerberos tickets and user logon into EBS R12 is based on the network credentials.  Users do not need to enter the EBS username and password anymore, because they are already authenticated on the network. A very secure solution and saves a lot on user administration.
Overview of products installed:
- Oracle Identity Management  11g (11.1.1.5)
- Oracle Access Manager 11g (11.1.1.5)
- Oracle EBS Access Gate 11g (1.1.1)
- Oracle Webserver 11g
- Oracle WebGate 11g (11.1.1.5)
- Oracle WebLogic Server (10.3.5)