OAM questions EBS

Hello

I use EBS 12.1.3, I need to use OAM (Oracle Access Manager), the scenario to connect our EBS with Microsoft Active Directory OAM jet, I have a question:

  1. If I do this it means that all users need Microsoft Active Directory ? what happens if I create user does not exist in Microsoft Active Directory?  (how it works in this case of sysadmin).
  2. I can connect as EBS username and password and domain user name and password?
  3. All think about any business module if we opt for this solution as iSupplier? where we create the user name of the provider?
  4. If I have oracle MAF solution connect with EBS, this open solution work list notification URL, in this case no need for username and password?
  5. All account for electronic signature in this case?

Thank you

Hi HaniYS,

My thoughts/personal suggestions are below.

I also suggest you look at the blog of Steven Chan as starting point (it is a great resource with lots of pointers to different areas) - https://blogs.oracle.com/stevenChan/entry/oracle_access_manager_11gr2ps2_certified

1. If I do this mean that all users need Microsoft Active Directory? What happens if I create user does not exist in Microsoft Active Directory?  (sysadmin how it works in this case).

-Please note that you can have different profiles of configuration according to your needs. For Sysadmin, there is a local user and administrator authentication is processed locally within the EBS. You are going to control this optional profile Applications SSO Login Types and will be the connection by using the url AppsLocalLogin.jsp

2. I can connect as EBS username and password and domain user name and password?

-My personal opinion is that this is not a suggested means to keep these two avenues open. How more you open, there are several security issues that you need to worry. However, you can define the profile of the SSO Applications Login Types to the user level to achieve this. But you must use different URLS. AppsLocalLogin.jsp will be for local authentication. The Gateway URL will be your domain user access.

3. all think about any business module if we opt for this solution as iSupplier? where we create the user name of the provider?

-You can implement isupplier and have an external webnode and should be able to configure to manage authentication locally.

4. If I have oracle MAF solution connect with EBS, this open solution work list notification URL, in this case no need for username and password?

-I suggest you examine Oracle E-Business Suite Mobile Apps frequently asked Questions (FAQ) (Doc ID 2064887.1)

Thank you

Chandra

Tags: Oracle Applications

Similar Questions

  • OAM in EBS R12

    What exactly is the OAM and how do I use it in EBS R12.

    It is necessary according to the value of the profile option "SQLNet Access" (FND_SQLNET_ACCESS).

    11.5.10 What's new: run SQL * Net hosts access [ID 291897.1]

    And, yes it is safe but try in a test instance first before promoting at the UAT/PROD.

    Thank you
    Hussein

  • 11g installation OAM-question

    Hello

    I installed OAM 11 g (version: 11.1.1.5.0) with Oracle Database 11g R2 and RCU (Version: 11.1.1.3.3). After you start weblogic admin server, I get the following errors:

    (a) OAMSSA-06251: policy store does not support detected. Required '11.1.1.5.0' but found "11.1.1.3.0".
    (b) could not communicate with one of the configured access server, make sure it is running.

    Update the policy store is anyway? or I need to re-run the installation program?
    Also how to start the access server?

    Asked to clarify the above.

    Thank you

    Srikanth

    The problem is with the installation. If you run Setup again you will run on these issues.

  • Portal Oracle WebLogic with OAM - Question of Architecture

    Hi all

    I have the following customer need.

    Oracle Portal 11.1.1.6 that is deployed on WebLogic Server 10.3.6
    11.1.1.5.0 Oracle Access Manager
    Oracle Internet Directory 11.1.1.6.0

    The customer wants to have Single Sign On for the Oracle Portal Application. It's my understanding of the Architecture.

    Oracle HTTP Server (with WebLogic plugin Proxy) converses with Oracle Portal
    Oracle HTTP Server (ditto above with WebGate) talking to Oracle Access Manager
    Oracle HTTP Server has Oracle Web Cache
    Oracle Access Manager talking about OID
    Oracle Portal talk to with authenticator OID OID

    When I went through the Oracle Portal documents, they provide steps for Oracle Portal that is deployed on Oracle Application Server, but not with WebLogic.

    My questions

    (1) do I configure authenticator OID to myrealm of the WebLogic domain (which hosts the Oracle Portal) to connect to OID?
    (2) at - it something more, that I have to do to integrate Oracle Portal with OID (meaning running pl/sql scripts or one)?
    (3) kindly advice me on the stream Cache Web Oracle, Oracle HTTP Server and Oracle Web Gate to the OAS Portal Oracle?

    Thank you

    Kind regards

    Somerset

    OK - portal will always OID as prerequisite.

    Thank you
    EJ

  • How to fix IWA OAM question?

    Hi all

    I'm running into a problem. I have the following requirements:
    1. I have the configuration of an Oracle based HTTP proxy server reverse with a WebGate installed. Proxy Proxy reverse for several applications running on weblogic and non-weblogic based.
    2. when users and windows domain users go through the proxy, they authenticate with username and password (Basic LDAP scheme). No problem there.
    3. when windows domain users go through the agent, it must be authenticated by using integrated Windows authentication.

    OSH and OSH webgate does not bear IWA. Any idea on how to solve this problem? We do not want to replace the IIS server, because in this case we loose the features of Enterprise Manager of the OHS 11 g.

    Thanks in advance,

    BART.

    OEM can manage IIS http://www.oracle.com/technology/products/oem/pdf/ds_iis.pdf

    There is no way around it with OAM and iWA, you need IIS.

  • OAM: Question of authentication Forms Newbie

    Hey all the...

    I am setting up forms authentication based access to a menu.

    I think I have the process correctly, but I'm missing something.

    My homepage index.html is not protected, I click on a link to access the menu protégé and loading of the form page. I type in my credentials (username, password) - that are the same in the attributes of the form and the authentication scheme and it tries to authenticate to action:/access/dummy.cgi.

    I have read the Administrator's guide and he said to use this file and that it didn't exist, that after authentication, it would continue on the page I had originally linked to. If I do not the user/pass on the second connection type, it takes me to the /access/dummy.cgi and said that the page does not exist.

    So... don't know what to do from here.

    Here's my config authentication scheme:
    name: forms-based authentication scheme
    Level 1
    Challenge the method: form
    parameter of challenge:
    CREDS: user_name password
    Form: / login.html
    Action:/access/dummy.cgi

    SSL required: no
    activate: Yes

    plugins-
    mapping the credentials:
    obMappingBase = %domaine%", obMappingFilter ="(& (& (objectclass = user)(samaccountname=%username%)) (|) ( ! (obuseraccountcontrol=*)) (obuseraccountcontrol = Activated))) ", obdomain ="domain ".
    validate_password:
    ObCredentialPassword = "[password]".

    Any help would be greatly appreciated.

    Thank you.
    -Bryan

    Hi Bryan,.

    "The part that seems out of order is the obMappingBase = %domaine%"*. I don't think the form you also provides the domain value. Try a valid DN searchbase instead, for example obMappingBase = "or is employed, dc is helpdesk, dc = com"* "

    Also, try to change the logging webgate configuration so see you the details of the point of view of the webgate on what you see in the browser.

    -Vinod

  • Suite of Oracle e-Business with OAM and IWA

    Hello

    We are about to implement a sso project to the following prescriptions.

    When users try to access the E-Business Suite, their windows logon is automatically recognized by OAM and they are authenticated by ad of them on target AD systems accounts.

    We plan to design as follows.

    1. users to connect on their machines and access to the eBusiness suite, you will be provided to link.
    2. this link redirects users to an IIS server that is on a separate machine that E-Business suite. WebGate and IWA is installed on the IIS server that allows to recognize the windows of the user connection and authenticates the user through OAM.
    3. after a successful authentication accesses the request without entering passwords.

    The question is whether this application is possible without oSSO side eBusiness suite. And do we need IIS to work as a proxy reverse to the way multi redirect? I couldn't exactly find a best practice for this scenario.

    Any help will be appreciated a lot!

    Thank you
    ECE

    I don't see how you would be able to integrate OAM with EBS, unless you have the oSSO (assuming of course that you are not on the bleeding edge, by 975182.1).

    We run the same configuration and installation in politics OAM redirects. We plant the roots of specific context for each application, then use the OAM strategy to redirect. (for example, http://iwa-server/ebs redirects to https://ebs-server)

    Rule single authorisation for each redirection, then a unique 'policy' in the 'Stratégies' tab for each redirection. Each strategy corresponds to the respective authorization rule.

  • start the Workflow Notification Mailer command line

    Hello

    I use ebs r12 12.1.3 on oul5x64
    I always leave mailer workflow using OAM,
    Question: is there another way to start the sender of the notification using the command line...
    you will need to enter the e-mail server, email account and password.
    Please notify.
    Thanks in advance.
    Kind regards

    Please see this

    http://docs.Oracle.com/CD/A60725_05/HTML/comnls/us/WF/instal17.htm
    Doc 297545.1 (Is there a way to start the Workflow Mailer from the command line?)

    ;) AppsmastI ;)
    Sharing is caring

  • Start the WebLogic, the NodeManager and ManagedWebLogicServer (oam_server1) Server

    DB level - 12.0.1 - Linux x86_64 SP2 SLES11

    Linux x86_64 SP2 SLES11 - application layer

    Fusion MiddleWare - 11.1.2.2

    I am perfectly aware that I can post this in the wrong group. I posted in the SSO group that this group looks like a ghost with no one around town and not a single thread there...

    It is with the intention of integrate OAM with EBS for Single Sign On. (replace 10G SSO)

    I installed all the components for the server of the OAM and got the top and the following documents running on

    http://docs.Oracle.com/CD/E40329_01/install.1112/e49521/install.htm#BABLBHBC

    When the battery starts, I find that I have to open three separate xTerm windows to start the WebLogic, the NodeManager server and the ManagedWebLogicServer (oam_server1). These windows must remain open until you decide to stop servers.

    Is there anyway to start with "nohup" servers so that they run in the background? If someone inadvertently kills the VNC sessions, which means that services that started this particular vnc session is also killed.

    There must be another way to get around this... and I'm looking to see if anyone here can help with suggestions.

    Thank you

    PL see if he can help to Q5 in the FAQ in MOS Doc 1294574.1

  • RCF implementation issues

    recently, we have implemented FRC, some of the menus of responsibility always appears in English and also, output file please share with me if anyone had same kind of question

    EBS:11i
    OS: OEL4
    DB: 10g R2

    Here are the menus of responsibility:

    Simultaneous
    Applications
    Game
    Areas of conflict

    Simultaneous: SDAME
    Manage
    Define
    Work periods
    Rule

    Simultaneous: program
    Define
    Executable
    Types of

    View profile
    System
    Personal

    Application
    Register
    Function
    Menu
    Administer folders
    Currency
    Network test

    Application: Validation
    Set
    Values

    Application: Flexfield: key
    Segments
    Alias
    Inter-validation
    Groups
    Values
    Accounts

    Application: Flexfield: description
    Segments
    Values

    Application: Document
    Define
    Categories
    Assign
    Repositories

    Journal of simultaneous requests.

    Module FNDSCURS: active users
    ---------------------------------------------------------------------------

    Current system time is 03-DEC-2010 02:16:01

    ---------------------------------------------------------------------------


    +-----------------------------
    | Starting the competitor program...
    +-----------------------------


    NLS_LANG and NLS_NUMERIC_CHARACTERS Environment Variables are:
    FRENCH_CANADA CANADIAN. WE8ISO8859P1

    '.,'

    REP-0118: cannot create a temporary file.

    REP-3000: internal error of AU starting Oracle Toolkit.
    REP-3000: internal error of AU starting Oracle Toolkit.

    Builder: release 6.0.8.28.0 - Production on Fri Dec

    (c) Copyright 1999 Oracle Corporation. All rights reserved.

    Hello

    You solved the problem?

    For custom forms/reports, see these docs.

    How to Upgrade 11i forms customized to R12 [ID 563258.1]
    To access the custom after upgrading forms of to R12. [451934.1 ID]
    After the upgrade to 11i to R12 custom forms display blue text fields [759551.1 ID]
    Do not compile EBS R12 reports using Report Builder from gr 10, 2 ID [ID 786794.1] or rwconverter.sh

    Thank you
    Hussein

  • Hi need help to connect to my redhat on vmware with host win xp... Please

    Hello

    I installed my oracle 11.5.10 in redhat4 linux VMware with win xp sp2 as my host OS

    therefore not able to open the Microsoft windows xp browser oracle applications Manager

    I gave a loopback for xp wixn adapter with

    IP 192.168.0.22

    and gateway and dns as 192.168.0.11 - is also the ip address of the linux redhat on vmware

    also I have the default gateway give for redhat linux as 192.168.0.22 - I want to tell the loop back IP address

    I could do a ping to 192.168.0.22 and 192.168.0.11 from the win command prompt

    and linux, I ping the loopback adapter, it is not ping

    .....................
    as an additional comment


    my web apps oracle address

    is
    http://Shiva.HyD.com:8001 is the homepage of opening and not to open the pages of additional connection for OAM and EBS, but when I give the address

    as http://192.168.0.11:8001, then it will open even the login page but won't connect to OAM or EBS


    Help, please


    Shiva

    Salvation;

    Problem solved? You can open login page now?

    Respect of
    HELIOS

  • Headers with OAM 11 GR 2 PS3 question

    Hello

    We are migrating OAM 11 GR 2-OAM 11 GR 2 PS3 from windows to linux. We installed the new configuration of the PS3 and migrated all the OAM configuration details. We have the user profile of authorization policies for applications protected by OAM.

    But while testing the SSO with applications, I found below questions

    1. If any attribute is null in LDAP to the user, R2 returns NOT_FOUND. But in the PS3 display headers as null. Enforcement team has a logic based on NOT_FOUND only. It's a lot of changes on the changes of app to check the value of the attribute of null NOT_FOUND. Is there a workaround for this?

    2. we have values multiple attributes for users in LDAP, in R2, these multivalued attribute values are separated by a colon(:), mais dans la PS3, elle est séparée par une virgule.)  I read the doc - id in metalink 1935703.1 , but it allows to change the comma separator. How this can be changed to the colon?

    Enjoy your entries.

    1. that is a very simple change in coding. Any decent programmer should be able to do this fairly easily.

    2. just follow the instruction and where it says ',' replace with ': '.

  • question of R12 DR eBS

    Hello

    We are in the process of implementation of DR to our Production eBS R12 environment, our Prod is currently as below

    PROD-

    OS: RHEL 5.11

    eBS: 12.1.3

    DB: 11.2.0.4

    Catalog RMAN DB

    OS: RHEL 5.11

    DB: 11.2.0.4

    We use the catalog db to back up our database of PROD and db itself catalogue is supported by rman.

    Now, I am the rest of the document ' Business Continuity for Oracle E-Business release 12.1 Using Oracle 11g Release 2 Physical Standby Database (Doc ID 1070033.1) ' understand the concept and use it as a reference.


    But I have question about the catalog RMAN DB. Apart from BSE synchronized to DR server, I plan to create a catalog rman standby server and will be this synchronization of production so rman.

    Reason I think is so we have our eBS and RMAN catalog getting synchronized production and accident permanently, I simple raise these two databases on the site of the disaster. Thus backup can continue as usual.


    Is this the right approach for RMAN DR database as well? or how your environment is configured if you have the catalog db with eBS?


    Thanks in advance.

    Is this the right approach for RMAN DR database as well? or how your environment is configured if you have the catalog db with eBS?

    --> There is not as the good or bad approach. Given the DR for the catalog database RMAN in my opinion is unnecessary. It's just more maintenance and fees. Instead, I follow below process provided by Oracle in the documentation.

    ***********************************************************************************************************

    Follow these steps when developing a strategy for RMAN backup to the recovery catalog database:
    Run the database catalog of recovery in ARCHIVELOG mode, so that you can do point-in-time recovery if necessary.
    Set the retention policy to REDUNDANCY greater than 1.
    Back up the database on two separate media (for example, disks and tapes).
    Run the BACKUP of DATA PLUS ARCHIVELOG at regular intervals, to a Media Manager if available, or simply to drive.
    Do not use another catalog of recovery as a repository for backups.
    Configure automatic backup of the control file you.

    **************************************************************************************************************************************************************************************

    Ref: http://docs.oracle.com/cd/B28359_01/backup.111/b28270/rcmcatdb.htm#CHDEBDJG

    concerning

    Pravin

  • EBS Apps control Questions?

    Hi all

    I take a few dump exam for master guru of ebs apps?

    Can you check if my answer is good or better or the best?

    Questions.

    1. how it swings (increased capacity) and scalable how can it go?

    All the possible ways.you can add several servers/machines or more of memory, CPU, disks, etc., by server.machine

    2 database, supported programming platforms and access tools.

    All (java, .net, etc.)

    3 operating systems supported.

    All (for example, unix, windows, etc.)

    4 cycle upgrade software (frequency, methods in application and database)

    All (for example you can do it every year, or every month or every 5 years, etc.)

    5. the User Interface (via web, via client software)

    All is supported (web & cleint, etc.).

    6. Security and Audit features (handling and ease of management)

    A lot of safety features and provided, internal and external audit (audit of Db, Db Vault, network, etc.)

    7. backup and recovery

    Backup and restore features are in place and tested (RMAN, Dataguard, etc.)

    8. user query and reporting tools

    There are a lot of built-in avaiable time tools and 3rd parties (ConcurrentManagers, BI, Hyperion, Excel4apps, etc.)

    Please check if my answers will be passing in your standards of knowledge.

    Can also help you improve the answer or what is the best response?

    Thank you very much

    JC

    I hope that "User Interfaces" refers to where the user can input/display the application.

    If this is the case of User Interfaces are OFA, form of Oracle and Web ADI form.

    In R12.2.4 there are other changes in the page as a complement to the pane in the homepage above.

    Reference: https://blogs.oracle.com/stevenChan/entry/usability_improvements_in_release_12

  • Discoverer 11.1.1.7.0 against 12.1.3 with OAM 11.1.2 EBS to request the password for the user with Ondaaah

    Hello

    Oracle has not been able to help me to do this job; 2 open of SR for weeks and no good answer.  They referred me to the people of onlinappsdba and various other public Internet sites.  We run EBS 12.1.3 and Disco 11.1.1.7.0 with 10g SSO and Ondaaah and SSL.  That works very well, users, identity is established through Ondaaah on our corporate network, with zero sign - on.  I'm replacing 10gSSO by OAM 11.1.2.  OAM/OID works very well for EBS and OBIEE, always zero sign - on with the OID 11.1.1.7.0 and AccessGate piece (and a webgate for both).  (Too many servers to SSO support in my view, if something goes wrong, too many places to look.)  For Disco, I created the osso.conf in OAM 11.1.2 installed in a folder on the Disco and bounced of Disco.  This works OK if in OAM authentication method is based authentication forms, with OAM inviting the user to signon, OID and then passes the user name and password through the OID in Active Directory, and connect on Disco invites to indicate the user name, and then gives access to workbooks.  No prompt for password clubbing.  But when I try to activate Ondaaah as an authentication method in the OAM, discoverer invite first the "Oracle Applications" connection for a user name and the EUL.  But Disco then prompts the user a password, that no longer exists in fnd_user. because authentication is external.  Connections fail.  I am also unable to create a private connection; This dialog box Disco also invites a user password.  At the login page of Disco, the user session went to OAM and fact authentication successful via Ondaaah.  I can tell from follow-up to the session through Fiddler.  Transmitted to the disco but Disco missing something and password prompts.  Support OAM at Oracle seems to think that OAM is not send the cookie to Discoverer, although I'm not sure.

    First of all, Ondaaah with Disco should work with OAM, right?  Any thoughts on what might be missing?  I went through the MOS notes a few times, closely followed the tutorial onlinappsdba on it.

    Thank you very much.

    Tom

    The hotfix is described in Note 1616228.1 problem with mod_osso and custom authentication plugins.  Disco can work very well, with zero sign - we and OAM.

Maybe you are looking for

  • L540: password accepted anywhere but the login screen

    Hello! I was happily using the sensor of fingerprint on my L540 for awhile, until what a few months ago, I reinstalled Windows 7 (Professional, x 64). After setting up everything, and by installing drivers Lenovo, I noticed this problem: When I start

  • Satellite A100-599 - question about updating the display driver

    Hello I have a Satellite A100-599 with a NVIDIA 7600go graphics card and I like most of you Bioshock game crashes because of some problems with the graphic card drivers, no pb... Meanwhile, NVIDIA has released some new patches for the Forceware and a

  • "Cannot take the required system, error 2147121300 restore point".

    Run the registry clean up using norton 360 v.6 and got this "unable to make the required system, error 2147121300 restore point. I need help to make the registry cleaning works on this norton 360.

  • EPrint, set up FAILED during installation.

    I'm a very dissatisfied customer at this point. I put one of these exact printers for my (Deskjet 3052 a) neighbor. We both have the SAME computer, even wireless (router and all) and are on the same carrier broadband. Its establishment went great...

  • How recovery a file that will not open

    I just saved a word document last night and this morning the word microsoft says that the path to the file does not exist. How can I find my file?