Skip to main content

Configuring Oracle Access Manager(OAM) with Window Native Authentication(WNA) for Windows Single Active Directory Domain

Prerequisites:- A windows active directory domain is installed on a Windows 2008 server. OAM 11g R2 OAM server is installed and a target is protected with OAM deployed on a webserver through a webgate agent.
  1. Login to the Active Directory server and create a user oam for WNA integration.

2. Execute ktpass command to generate a keytab file. The princ parameter needs to be HTTP/hostnameofOAMServer@DomainName. It should map to a user (oam)of AD. 

ktpass -princ HTTP/ -mapuser oam -pass password -out c:\oam.keytab 

3. Once ktpass has been executed successfully you will see that parameter User Logon Name has been modified.

4. On oam server at /etc/ directory krb5.conf file is present. Modify the file for domain name and AD server name. If File is not there please create a file with same name and provide the details as below:
5. After krb5.conf file is modified run the klist command to check the contents of oam.keytab file. Also run kinit command to authenticate to Kerberos server.

klist -k -t -K -e FILE:/app/u01/oam.keytab
kinit –V HTTP/ -k -t /app/u01 /oam.keytab

6. Create new User Identity Store which points to Active Directory(AD) server. It is not mandatory to have AD Server as a user store you can have OVD as a user store with Adapters pointing to AD server or you can have OID as a User Identity Store with Synchronization with AD Server. This AD can be set as default store if needed.
7. Modify the Kerberos Module by browsing to System Configuration --> Access Manager --> Authentication Modules --> Kerberos Authentication Module --> Kerberos. Set required parameters as per your environment configuration.
Parameter Name
Parameter Values
Key Tab file
KRB Config File

8. Go to Policy Configuration --> Application Domains --> ApplicationDomainName --> Protected Resource Policy and change the Authentication Scheme to Kerberos Scheme. This resource is the one which is already protected with OAM through existing deployed webgate.

9.  Login to the machine which Is connected to domain and open IE browser. Open Internet option and select Local Intranet from security tab. Add oam server host name in the Local Intranet sites.

10. Create a test user in Active Directory and login with that user in domain. OAM protected resource page can be accessed without any authentication asked.


    Popular posts from this blog

    Developing Prepopulate Adapter with OIM 11g R2

    1.      Prepopulate Adapter in OIM uses the plugin point oracle.iam.request.plugins.PrePopulationAdapte r. 2.      Write the Java code which returns the value which has to be populated on the form. 3.      This code will implement the plugin point oracle.iam.request.plugins.PrePopulationAdapte r. Code Snippet: - package; import; import java.util.Iterator; import java.util.List; import java.util.logging.Logger; import oracle.iam.identity.exception.NoSuchUserException; import oracle.iam.identity.exception.UserLookupException; import oracle.iam.identity.usermgmt.api.UserManager; import oracle.iam.identity.usermgmt.vo.User; import oracle.iam.platform.Platform; import oracle.iam.platform.authz.exception.AccessDeniedException; import oracle.iam.request.exception.RequestServiceException; import oracle.iam.request.vo.Beneficiary; ...

    Oracle Traffic Director (OTD) configuration

    Download the OTD software and install it on a server by running runInstaller command from <Binaries>/Disk1. Preferred is to configure the OTD as root user because when the administration server is configured as root, then Oracle Traffic Director starts the keepalived daemon automatically when you start instances that are part of a failover group, and stops the daemon when you stop the instances. Set Oracle_Home as the new Installed OTD Home. Run below command to configure the Admin server: <OTD_HOME>/otd/bin/tadm configure-server --port=8989 --user=admin --server-user=root --instance- home= <OTD_HOME> /otd/instance_name/otd_instance1 This command will ask for admin password and will create the admin server. Run Below command to start the admin server: <OTD_HOME> /otd/instance_name/otd_instance1/admin-server/bin/startserv Login to the OTD console on http://<host>:8989 as admin user.  Click New configuration: Click Next and create ne...

    Custom Login Page Protection- OAM 11g R2

    Create a login page with fields having username,password and requestid. Below is the sample login page : <%@page language="java" session="true" contentType="text/html;charset=ISO-8859-1"  %> <% String path = request.getContextPath(); String basePath = request.getScheme()+"://"+request.getServerName()+":"+request. getServerPort()+path+"/"; String requestID = request.getParameter("request_id"); %> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" ""> <html xmlns=""> <font color="blue">Login Page </font><br><br> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"> <title>Implementing css and javascript</title> <meta http-equi...