Can Multiple Webgate/OAM/IdentityStores access one multitenant WLS domain?

Can multiple access points ( web tier + OAM + Identity store) access one application?
The objective here is to have one multi-tenant ADF application accessed by users who are authenthicated by their own enterprise sso and identity store. Authenthicated session should pass the context with list of all enterprise roles that user belongs to which would be used for authorization by the multitenant application. It is assumed here that naming convention for relevant roles is followed by all participating identity stores.
Can Webgate/OAM and accessed WebLogic domain be configured to accomplish this?

OAM can pass as header variables all of the things you mention. For example, you get these by default:
OAM_REMOTE_USER containing the userid of the logged in user (eg "jsmith")
HTTP_OAM_IDENTITY_DOMAIN containing the name of the Identity Store that the logged in user belongs to, as known to the OAM admin console (eg "SunLDAP")
additionally you can define a headervar that contains the user's ldap group membership, and one that contains the user's full DN (or any other attribute and other information).
Of course, any receiving app would need to be configured to consume this information.
Regards,
Colin

Similar Messages

  • HT204053 Can you have multiple apple ids that access one itune account??

    I need to know if I can have multiple Apple Ids attached to one itunes account.  Trying to set facetime up on these separate devices and it keeps failing.  Any help would be appreciated.  I tried to add additional emails, but I all I get is verifying and it never verifies it.

    yes you can still sync all the devices on itunes using one master itunes/appleID account.
    Music:
    If you want to select specific playlists for your kids, DON'T enable iTunes Match on their devices, otherwise they will get ALL the playlists on their devices (learned that the hard way)
    If you have wi-fi synced enabled that should still work.
    Apps:
    I manually select which apps they get on their devices using itunes. It only changes when they re-sync.
    Don't enable AUTO downloads on their devices for Apps or Music purchases.
    Since I also have young kids using these devices:
    I have restrictions setup on their devices. I don't allow them to install/delete apps, nor do I allow them to make any account changes on their devices. This way their devices stay in order and get backed up to icloud. I can easily restore their devices if I needed too.
    Once in a while I will disable the restrictions so I can update all their apps.
    Hope this helps!

  • Can't get OAM 11g Access Tester working

    Hi,
    I've been trying to get the Access Tester (oamtester.jar) from OAM 11g (11.1.1.3) working.
    I can start the tester (java -jar oamtester.jar), but when I try to connect to the OAM server, I either get a "NAP initialization error" or a "challenge_failed"/mismatch error.
    My OAM server is listening on the default port, 14100, and the OAM proxy is listening on 5575, and I've tried connecting to both ports, and get the different errors, depending on which port I try.
    I've tried running the tester on the OAM server machine itself, from a different machine, etc., but get the same errors.
    Can anyone tell me how I can get the tester to work?
    Thanks,
    Jim

    Hi,
    I got the logging in the access tester, and here's what I get when I try to connect to the OAM server:
    Nov 6, 2011 2:16:58 PM ObAAAServiceClient setHostPort
    FINER: ENTRY
    Nov 6, 2011 2:16:58 PM ObAAAServiceClient setHostPort
    FINER: RETURN
    Nov 6, 2011 2:16:58 PM ObAAAServiceClient setHostPort
    FINER: ENTRY
    Nov 6, 2011 2:16:58 PM oracle.security.am.common.nap.util.NAPLogger log
    FINE: There are no entries in given access server list.
    Nov 6, 2011 2:16:58 PM ObAAAServiceClient connect
    FINER: ENTRY
    Nov 6, 2011 2:16:58 PM oracle.security.am.common.nap.ObMessageChannelImpl writeObMessage
    FINE: OpCode = 13 [InitNAP], SeqNo = 0 Message = protocol=NAP version=4 oldest=1
    Nov 6, 2011 2:16:58 PM oracle.security.am.common.nap.ObMessageChannelImpl readMessage
    FINE: Message received from Server: OpCode = 13 [InitNAP], SeqNo = 0 Message = protocol=NAP version=4 oldest=1
    Nov 6, 2011 2:16:58 PM oracle.security.am.common.nap.ObMessageChannelImpl writeObMessage
    FINE: OpCode = 0 [ServerDiagnosticEvent], SeqNo = 0 Message = sts=open
    Nov 6, 2011 2:16:58 PM oracle.security.am.common.nap.ObMessageChannelImpl readMessage
    FINE: Message received from Server: OpCode = 0 [ServerDiagnosticEvent], SeqNo = 0 Message = sts=open
    Nov 6, 2011 2:16:58 PM oracle.security.am.common.nap.ObMessageChannelImpl writeObMessage
    FINE: OpCode = 14 [NAPAuthnChallengeReq], SeqNo = 0 Message = cm=apache1 challenge=f5d58bf93da2331c of=1
    Nov 6, 2011 2:16:58 PM oracle.security.am.common.nap.ObMessageChannelImpl readMessage
    FINE: Message received from Server: OpCode = 14 [NAPAuthnChallengeReq], SeqNo = 0 Message = cm=AccessServerConfigProxy challenge=f5d58bf93da2331c st=ma%3d25%20mi%3d2%20sg%3d1 rt=1
    Nov 6, 2011 2:16:58 PM oracle.security.am.common.nap.ObNap CreateChallengeResponse
    FINEST: Created NAP challenge
    Nov 6, 2011 2:16:58 PM oracle.security.am.common.nap.ObMessageChannelImpl writeObMessage
    FINE: OpCode = 15 [NAPAuthnChallengeResponse], SeqNo = 0 Message = response=2659cf320b28b197d027789ae069efe3
    Nov 6, 2011 2:16:58 PM oracle.security.am.common.nap.ObMessageChannelImpl readMessage
    FINE: Message received from Server: OpCode = 15 [NAPAuthnChallengeResponse], SeqNo = 0 Message = st=ma%3d52%20mi%3d2%20sg%3d1 rt=0
    Nov 6, 2011 2:16:58 PM oracle.security.am.common.nap.ObMessageChannelWrapper initNAP
    SEVERE: Error in receiving hashed server challenge
    Does anyone know why this is happening, and how to get around it?
    Has anyone actually gotten the OAM 11g access tester to work with OAM 11g server via the OAM proxy (on port 5575)?
    Thanks,
    Jim

  • Can multiple orgs be setup for one account?

    Hi,
    Is it possible to have multiple organizations setup for the one account? This is in a sales/campaigns context.
    Thanks.

    If you are referring to linking a customer account to multiple parties I don't think it is possible.

  • How can multiple users edit and access same ACCESS file

    Hello,
    We have 2 access files and multiple users needs to edit and access those files.
    How can I enable mulitple access but only one user can edit rest of users are in read-only mode for one file and multiple access and edit on the another file.

    Hi,
    You should split your database in a front and backend. Then create two seperate front ends which you can distribute. If you need readonly you can opt for two options, setting the attributes of the file to read only or create a front end with read only forms.
    The last one takes a little more work but is safer than setting the attributes to read only because people can change that back themselfs.
    Maurice

  • Can multiple LabVIEW programs simultaneously access the same NI-DAQmx hardware?

    I am developing a test station system that, in essence, runs several
    seperate LabVIEW programs simultaneously on the same computer, each
    controlling a different set of I/O channels on one shared set of NI
    DAQ hardware (analog and digital I/O PCI boards with external signal
    conditioning).
    I have already gotten a system like this running almost flawlessly
    using LabVIEW 6.1, NI-DAQmx 7.1 with traditional channels, and older
    E-series DAQ hardware. So long as two programs do not try to write to
    the same output channel simultaneously, everything works exactly as
    expected--I can even read from the same (named) channel simultaneously
    from more than one program. The only issue I have had is that if
    one
    of the compiled applications is closed (not just stopped, but closed)
    while others are still running, Windows XP (SP1) will bluescreen on a
    driver error. This is undesireable, but acceptable (though if there's
    a fix/workaround, I'd love to hear it).
    I am now building a similar system using mostly the same software
    (with an upgrade to LabVIEW 7.1), and I've noticed that the new
    M-series DAQ hardware seems to offer much more bang for the buck than
    old E-series hardware and its kin.
    My question is this: It appears that I/O on M-series hardware must be
    performed with new mx channels, with traditional channels not being an
    option. I am therefore wondering if I will be able to do this kind of
    multiple simultaneous access with mx channels, or if I must purchase
    the classic hardware and use traditional channels for this somewhat
    unorthodox application.
    (Incidentally, the multiple simultaneous program thing is a
    requirement for this system, as it is the only clean way to run
    multiple
    identical copies of the same complete program that only
    operate on different I/O channels, and re-doing the program from
    scratch is not an option.)

    Dear Anonymous,
    Thank you for contacting National Instruments.
    To address your question, I don't know if multiple simultaneous access with mx channels is possible, but I do not see why it wouldn't be. The best way to find out would be to test it. I don't have your program or hardware, so I'm pointing you to some Compatibility VIs. These are VIs that look exactly like Traditional DAQ VIs except that underneath they call the DAQmx driver instead of the Traditional DAQ driver. If your device works when you substitute these Compatibility VIs in for the Traditional DAQ VIs, then you'll know the M Series boards will work for you.
    Here is the link for information about the Compatibility VIs:
    http://digital.ni.com/softlib.nsf/954feaeea92d90918625674b00658b
    83/9d67f671bcc6850586256e630059308b?OpenDocument
    Let me know if you have any further questions or if this does not resolve your issue.
    Thanks again and have a great day!
    Chad AE
    Applications Engineer - National Instruments

  • Can multiple ringtones be set within one contact entry?

    I'm in the process of updating contacts on my iPhone 4, and am assigning specific ringtones to a few people. I noticed, however, that you can only list one ringtone per contact entry--even though many of my entries have multiple people with different phone numbers (ie: a husband, wife, and kid). I even had to separate my mom and dad in my address book in order to give them each their own ringtone; but I can't list their home phone number in both contact entries, or it just plays the default tone. Is there a way to get around this without having to separate all the "couples?"

    I am going to answer my own question here, I have just found out that by going into the gallery and picking a mp3 that I could "use the tone" as a contact ringtone! - Happy Days!

  • Can multiple tabs be opened in one analysis in OBIEE 11g

    Hyy All, I am not able to open mltiple tabs in one analysis in obiee, Before It, I was using SAP BO, It was possible in there, Please help me out. .

    Hii ChristianBerg,  Thanks for replying..
    First Point by you (- Multiple views inside a view selector within any given analysis), I am adding some more to it that I need "- Multiple views inside a view selector within any given analysis in tabs" :: How can I achieve It? Can you tell provide me any sample report which have multiple sub reports or views? please.. Thanks a lot In Advance.

  • How can multiple footers be placed in one document?

    I have 40 documents, each with between 3 and 25 pages, each with a footer that has a page number and the document title. I want to combine all 40 documents into one pdf but have the pages numbered consecutively rather than have each of the 40 documents begin again at page 1.
    I removed the page numbering from the original documents' footers and turned on page numbering in Acrobat. It numbers properly but the page numbers are below the document titles, which does not look good. I would like to remove the footers completely from the original documents and include the title of each document in the pdf, changing them when necessary and suppressing them when necessary.
    For example:
    Pages 1 - 5: Title 1
    Page 6: Suppress footer
    Page 7 - 15: Title 2
    Page 16: Suppress footer
    and so on, with page numbering consecutive from 1 - 16, etc.
    Can this be done and if so, how?
    Thanks
    Guy Lydig

    When you add headers and footers you can define in the dialog in the blue link "page range options" which pages you want to affect with your settings.

  • Can multiple contacts be added to one converstation?

    I want to know if it is possible to be having an IM conversation with one contact and add another contact to that same conversation.  Thanks in advance.

    Thank you. I appreciate your assist. We have version 7.0. I guess we wait til version 8.0 is purchased by the company.
    Terry B
    Terry Burgett, BBA/MS
    Supervisor Care Specialist
    Dallas Support Team
    214-960-9900
    [email protected]
    "Thank you for all you do!!"

  • HT202213 Can multiple Apple ID's share one computer and music?

    My husband and I want to share music but have 2 separate apple ID's. Is there any way for us to share music?

    The easiest way is for each user to have their own iTunes library in their own Windows user account on that computer.
    To create a new user account:  Start > Control Panel > Add or remove user accounts.  (That is the Windows 7 version; it may look slightly different in another version of Windows.

  • Can't ping, email or access my domain -- on occasion.

    Very weird but I have no idea what is happening. We have two MacBook Pro's one 15 and one 13, both have mobile me and some pop email accounts with our own domains. Also have iphones that connect to the same network, all connecting to Airport Wireless.
    So on occasion I can't access one of my domains (for example mydomain.com). So, when it happens:
    1) I can't access the domain in mail, or entourage (on wife's computer). says: "There may be a problem with the mail server or network. Verify the settings for account “mydomain.com” or try again."
    2) I can't ping mydomain.com
    3) I can't access it via the web browser.
    I know the site is up and running because:
    1) if I turn off wifi on iphone and go through att, email and safari access the domain ok.
    2) I can also go to another domain that is on the same server and the same IP (via web browser, webmail and via ping).
    3) I can also take my computer to the office and access the domains ok.
    So It is as if the airport DNS tables at home get hung up on mydomain.com (perhaps because all the devices checking the same domain for email)? I've rebooted both the computer and Airport, and even cleared DNS cache on my local computer. Still nothing. I have to wait until it just magically starts working again.
    So I'm out of ideas. Any Apple Ninjas out there care to take a guess on what my problem is? Is there a way to reset the router DNS without having to reset the device.
    Thanks in advance for help!
    Message was edited by: vadas

    Go to System Preferences and then head to Sharing. See if there's anything weird there.

  • 1) I have multiple accounts at the iTunes store and none are now associated with my purchases...I think because passwords have been associated with various id's and I can't log in and access those purchases.  I want to get back to being able to use one i

    1) I have multiple accounts at the iTunes store and none are now associated with my purchases...I think because passwords have been associated with various id’s and I can’t log in and access those purchases.  I want to get back to being able to use one id and password and be able to access those purchases.
    2) When I upgraded my iPhone 3gs, to the latest version 5.0.1 (9A405), is when I noticed that i couldn’t update my applications.  There are two names/accounts on the phone and prior to the update there was just the one.  I have tried entering every conceivable password that I have ever used and get the incorrect password error every time. The apps on the iPhone are apparently associated with several/different accounts.  I just want to get everything back to the way it was.  One id and one password with purchases associated with just one account that can be updated on my computer as well as my iPhone.

    Hello sadiepix,
    The following article details several things that can be done to quell iTunes' constant need for authorization.
    iTunes repeatedly prompts to authorize computer to play iTunes Store purchases
    http://support.apple.com/kb/TS1389
    Cheers,
    Allen

  • Can multiple PCs access one remote panel at the same time?

    I've written a program in labview 7.1 to monitor/control a labview application running in the test cell through Remote Panel. I and my coworker can remotely monitor and/or control this labview application individually. But if my coworker has the remote panel displayed on his PC and I try to get the remote panel on my PC, I get a labview error (63) as below:
    "LabVIEW:  Serial port receive buffer overflow.
    LabVIEW:  The network connection was refused by the server."
    My question is: Can multiple PCs access one remote panel at the same time?
    Thanks in advance!
    Y

    Sorry I wasn't clear. The remote panel license is separate from the number of LabVIEW development licenses. Pricing information on remote panel licenses can be found here.

  • Can't access one of multiple iPhoto libraries...

    ... using iphoto 8.1.2, and I have multiple iPhoto libraries.  The one with the most data (24 gb) will not open in iPhoto, even though all data appears ok when I view it in folder structure format.  I just get a blank iPhoto window, a spinning ball, then I force quit.  Somehow iPhoto doesn't know where to "look" anymore. There is a package called iPhoto library which may have inadvertantly become the new default, even though the large one in question was previously the default library.  Worked fine for years, then all of a sudden stopped. Any ideas how to restructure the path?  Many thanks.
    On a MacBook 2.16 GHzIntel Core Duo, 2GB 667 MHz DDR2 SDRAM, version 10.6.8.

    Hold down the option (or alt) key key and launch iPhoto. From the resulting menu select 'Choose Library'
    Does that open it?
    If not then
    Option 1
    Back Up and try rebuild the library: hold down the command and option (or alt) keys while launching iPhoto. Use the resulting dialogue to rebuild. Choose to Rebuild iPhoto Library Database from automatic backup.
    If that fails:
    Option 2
    Download iPhoto Library Manager and use its rebuild function. This will create a new library based on data in the albumdata.xml file. Not everything will be brought over - no slideshows, books or calendars, for instance - but it should get all your albums and keywords back.
    Because this process creates an entirely new library and leaves your old one untouched, it is non-destructive, and if you're not happy with the results you can simply return to your old one. .
    Regards
    TD

Maybe you are looking for

  • Custom Webdynpro text field is taking too long to accept input values

    Dear All,                I hvae created custom web dynpro for PO header fields in SRM. This WD contains a lot of fields. When i try to put cursor on a text field it is taking too long for the cursor to appear in that input text field. There is no pro

  • Error: crash occurred while invoking effect plug-in "Shatter".

    This is URGERNT! Can someone help me?! i dont know what to do! Below are the listed pop-ups that occur.

  • Microsoft Internet Explorer 10 and 11 not working

    Hi Team, Iam currently using windows 7 64-bit operating system and we require internet explorer 10 and 11 for our regular project usage. When I have upgraded the version of IE from 9 to 10 or 11 its not responding and not showing in processes tab of

  • OIM AD Connector Patching

    I need to apply a connector patch for AD connector. I know the patch id also. Please let me know the steps for downloading this patch and applying it to the existing connector. Edited by: 955932 on Oct 10, 2012 11:10 PM

  • Why can I not enter my CS6 after buying a new iMac?

    I leased today an new iMac at the distributor shop adminsystems in Cologne. Mr. Heck, ther owner an the administrator for me wanted to migrate all the data and programms and applications tfrom the old Imac 21,5 " to the new iMac. That would be done b