OAM-OIF - multiple identity providers

I have this scenario as discussed in this document....
http://fusionsecurity.blogspot.com/2011/12/multiple-identity-providers-with-oracle.html
Has anyone implemented this solution? The document does not contain much details. Oracle says its a limitation in the product and may be addressed in the future. Has anyone successfully implemented a workaround that is being suggested in the document or maybe had another workaround?

Hi Tamim,
Hope this helps.
I have worked with an application integration with OAM 11gR1 where default authN scheme is WNA. I remember applying patch BP04 for OAM 11.1.1.5 and modifying oam-config.xml for WNA fallback to work for external users.
Once applied, if a user is not logged on to a Windows domain,  OAM will fallback to Basic authN scheme presenting a popup to enter credentials.
To enable form based authN for non domain (external) users, I have created a separate DNS entry and protected it with a FORM based authN scheme in OAM. You need to configure original app URL as the authN success URL for this domain.
You can consider this solution as an alternative to your approach in which case you just need to write a database authN plugin and configure an additional application domain.
Regards,
Phani

Similar Messages

  • How do I print multiple identical small images on the same sheet of paper?

    I would like to know how I can produce multiple identical small images (10mm x 10mm) on the same sheet of paper?
    I used to be able to do this in older versions of Adobe Photoshop.
    Thank you.

      Try using picture package. There is an option to print 10 copies on a single sheet.
    1. Select your photo in Organizer
    2. Click File >> Print
    3. Choose picture package in section 4 of the print dialog
    4. Select layout in section 5 and choose fill page with first photo
    5. Click print button
      Click to view image

  • Multiple LDAP Providers?

    Is it possible to have multiple LDAP providers configured within one UCM instance?
    Users from A.DOMAIN.COM and users from B.DOMAIN.COM can authenticate with and share one UCM? This is of course not taking into consideration how security would be set up behind the scenes.. this is more of a 'what if...' question. We would want the users authenticating against their domain accounts in their respective domains.
    If it makes any difference, A & B are Active Directory domains in a two-way trusted relationship that belong to the common DOMAIN.COM forest.
    Thanks

    Hey Peter,
    This use case can be handled. If you notice in the documentation for security
    [Seen Here|http://download.oracle.com/docs/cd/E10316_01/cs/cs_doc_10/admin/users_security/wwhelp/wwhimpl/common/html/wwhelp.htm?context=managing_security_10&file=page_7_17.htm]
    You can set up additional LDAP providers. In this documentation, they are referencing fail-over, however, this will work for your case, with various users are in LDAP B vs LDAP A.
    Keep in mind that you need to set the provider priority to be different than your first provider, such as priority 1, then priority 2 and that all users will hit the first provider first if they have never logged in, however, their last success log in with X provider will be saved so all subsequent requests will go to the proper ldap provider.
    -AJ LaVenture
    Software Consultant
    www.fishbowlsolutions.com

  • Regarding Identity Providers in OBIEE 11g

    Hi Guys,
    can anyone help me..
    what are identity providers and wat is the use of them??
    thanks in advance

    I think it is expected behavior. Try out saving as html and then saving it as pdf.
    If helps mark

  • About multiple identity plug-in in SES11.1.2.2

    hi Experts,
    I have a question on identity plug-in for ses11.1.2.2, if multiple identity plug-in are activited/started, does this mean SES will check the identity from all these identity plug-in? for example:
    Can I have this senario: user1 belongs to AD, user2 belongs to OID? both user1 and user2 can log in with SES when AD and OID plug-in are activied.
    Best regards

    hi sbuchta,
    I want to double confirm your answer.
    If this is the requirement:
    1. Customer has an AD as backend authentication system.
    2. Customer is using WCC(UCM) which uses that AD as authentication provider.
    3. Customer uses SES to search UCM and NTFS(NTFS has ACL enabled)
    In this scenario, the only option is to use fed search solution(1 SES instance for searching NTFS with AD plugin, another SES instance for searching UCM with StellentIdentityPlugin)?
    Best regards

  • Does WRT54GP2 work with multiple ViOP providers ?

    My question is, Does WRT54GP2 router work with multiple ViOP providers ? Can I use it with a ViOP provider other then Vonage ?
    Thanks, John

    Yes you definately can , all you need is a VOIP adapter that supports SIP . It's a standard protocol and is supported by all routers and VOIP providers

  • Help Sumitting multiple identical forms????

    I have a JSP page where i include my page navigation as another JSP on the top and bottom of the page... since the previous and next links are submits of form I get a javascript error... how can i include multiple identical forms to one jsp page////

    I believe the OP is talking about the "Merge Comments?" pop-up that i'm getting as well.
    I can't figure out how to stop it from prompting people to do this... it's causing quite a lot of confusion!!
    I attached a screen shot of it so we can get rid of any ambiguity =P
    Thanks,
    Alice

  • Publication for Deski report with multiple data providers

    Hi,
    Has anyone been able to get a publication working that uses a Deski report with multiple data providers as the source? I'm trying to get a publication working that uses dynamic recipients and personalization. When I try to schedule the publication, I get the error "Object not found". 
    Thanks,
    Debbie

    Debbie,
    That's standard.
    It's useful for emulating outer joins in reports.
    Say you've got a sales report where you want to display all 12 months of the year in a crosstab whatever month you run in.
    We're only in May at the moment though. With one data provider (SALES), you'll get a crosstab with just up to May for your months.
    If you create a separate data provider called MONTHS to return the months in the current year, you will then have a merged dimension of YearMonth in both.
    In your crosstab if you just use YearMonth you'll get just the five months. If you qualify it with its data provider name (in our case MONTHS), you'll see the full twelve months shown.
    I hope that clears it up for your.
    Regards,
    Mark

  • Why filter causes multiple identical images in gridview to display in literoom 4.3?

    I have not been able to find why multiple identical images are displaying in gridview when filters are applied.  There is only one image in the folder.  This obviously makes it difficult to apply images to keywords.
    I simply can't find the reason.  Neither is there anything in help on this issue. 

    BenMarkus
    Third request for help regarding the problem detailed below.
    Mar 16, 2013 1:44 PM in reply to Community Help
    Report
    I am in the process of organizing my Literoom images and filter displays
    MULTIPLE IDENTICAL IMAGES, under METADATA STATUS changed. .
    Computer info - Literoom 4.3, windows 7, some 55,000 images on the hardrive, one
    catalog used.
    When I go to folders, and click on J drive which holds these images, they all
    come up if filter is off of course. Now using metadata I search on a date, a
    camera, lense, etc. But I just want to find all of my images on a particular
    day. I can find those with no problem. My problem is that I may have 2 or more
    identical images display in grid and view as well as film strip. Looking up
    metadate status I find that these images are CHANGED. I understand that status,
    but there is no way that these multiple images would result from my work.
    I searched for multiple files located in multiple folders - NOT THE CASE. What
    is creating those multiple files, they are identical as to date, how they look,
    etc?
    If I go to CATALOG, and work with the all the images there, found at the top of
    course, I get the same functionality, BUT THE MULTIPLE IMAGES ARE ABSENT.
    I can't find the reason for this in any help. I would appreciate very much some
    one telling me why this is takes place. It makes it difficult to keyword on
    images on a certain date, because of the multiple files.
    Filters are a powerful tool for organizing collections and keywords - my problem
    is not using filters, but understanding why multiple images.
    Further investigation this problem is found in any place - Catalog, or folder. 
    Believe me this is a PROBLEM.  I need to find a live person somewhere in the
    vast ocean of helps that can answer this question.  I don't have a problem
    understanding how to use it, I JUST WANT TO KNOW WHY MULTIPLE IMAGES.
    Can you or someone in Adobe answer my question.  I just want an answer.  Say I
    payed my money why can't it work properly.
    Ben Lamfers

  • Error while creating multiple identity realms

    Hi,
    I am trying the tutorial for creating multiple identity realms posted on
    http://www.oracle.com/technology/obe/obe_as_10g/im/realm_mng/realm.htm
    While executing "STEP 12" to enter the following values:
    -User Search Base,
    -User Creation Base,
    -Group Search Base,
    -Group Creation Base
    I get the following error:
    Identity Management Realm Modification Error!
    Cannot Modify Identity Management Realm : [LDAP: error code 20 - Attribute Or Value Exists]
    For some reason this step just doesnt seem to work. I am using OCS 10.1.1 on Solaris10
    Can anyone please help me resolve this issue.
    Thanks.

    Hi. It is a "feature" of SRM.
    I asked SAP about it and did not get a good response.
    If you enter Asset A, it will copy the internal order number from that asset into the cart. You can not see the internal order in the web, but you can see it in BBP_PD.
    If you then change the asset to asset B, it will not refresh the internal order number.
    This means you get internal order A on asset B.
    It happens any time you change asset number, so if you copy a line then change you will get this problem.
    We ended up using the BBP_DOC_CHANGE_BADI to RFC into R/3 and update the internal order number.
    Regards,
    Dave.

  • Multiple application providers problem

    we want to allow multiple applicatin providers to load applets, one after the other, but not to be able to modify/delete what an applet from a previous provier. we think if each provider can simply have their own key, allowing them to be the only one to modify/delete their own specific applet (and no other applet) then that will work.
    we read about delegation management (and security domains), but we can't find cards that support that.
    1) do any cards support this?
    2) is there another way, perhaps by either
    a) telling the card manager to allow loading of applets, but once loaded to not ever allow modification/deletion of them OR
    b) writing our own loader with a custom key to the card manager such that no other loader can install/delete applets but out own loader.

    Aspects Software Ltd. (www.aspectssoftware.com) GlobalPlatform Java Card product "OS755" supports Application Provider Security Domains and Delegated Management.
    They also have an IDE "Developer" that helps you develop the Security Domains and your applets.

  • Alternatives to Entourage that have its Multiple Identity feature?

    I access all my mail through Microsoft Entourage. I use this mail client because of it's "Switch Identity" feature, meaning I can have entirely separate inboxes, folder lists, etc for each email address if necessary.
    I'll always want to access email through a dedicated client rather than a web browser, and would only ever change from Entourage to another client if it also had a multiple identity feature.
    Does anyone know of any Mac OS X email clients other than Entourage that have this feature and would run on my machine?
    There's a long list of clients listed here, but it isn't obvious (to me anyway) which if any have a multiple identity feature other than Entourage.
    Many thanks.

    BDAqua - thanks for your reply.
    Just so I'm clear - what I'm talking about isn't multiple accounts, but multiple identities - i.e. an entirely separate list of inboxes, folders, etc for each group of email accounts, with a *different default send address for each identity*, as per Entourage. With Entourage, to change Identity, you effectively have to log out of the program, select a different Identity, and then log back in, in order to switch. This is similar to logging in & out of the Mac OS itself.
    I've hardly ever used Apple's Mail. Given that I'm running Mac OS X 10.4.11, my version of Mail is 2.1.3. Assuming that Mail does in fact have a Multiple Identity feature, does 2.1.3 have this feature, or would I have to use a newer version of Mail?
    This question also raises a few similar ones in my mind:
    Is 2.1.3 the latest version of Mail that will run on Tiger?
    What are the latest versions of Mail that will run on Leopard & Snow Leopard?
    Given that my Mac can't run Snow Leopard but can run Leopard, would I have to upgrade to Leopard in order to run a version of Mail that has the Multiple Identity feature?
    If there is a version of Mail that has a Multiple Identity feature and will run on my Mac, how do I access the feature? I've searched the Mail Help, but can only see references to setting up multiple accounts - there's no mention of multiple identities.
    As for Thunderbird - I'd heard the name at some point but had no idea what it was. It looks like it's the Mozilla project's mail client, and as such should be of as high a standard as Firefox. If I'm unable to get Apple's Mail to work in the way I'd like, I may give Thunderbird a try.
    My reason for wanting to switch to something other than Entourage is simply that it's far too big, complex & slow (on my machine at least) for my requirements. It's akin to me driving a Ferrari when all I need is a Ford Fiesta Mark IV (which is actually the car I drive!).
    Many thanks.

  • Multiple authentication providers for the same identity store?

    We are on WebLogic Server 11g PS5 and in the middle of configuring the authentication providers.
    Turns out we an Active Directory instance where we have two distinct User Base DNs we would like to use, without overlap, but they share the Group Base DN.
    What is the best practice to configure this? I think we could use the parent DN, but that would basically include the whole of the directory for users and groups, will that impact performance?

    Hi Alexandre,
    You might find this helpful - http://download.oracle.com/docs/cd/E10761_01/doc/oam.1014/b32420/v2authen.htm#BABJCHEJ. The text "suppose the user requests a resource that is protected by a form-based authentication scheme that redirects the user to a form with several options for logging in. When the user selects a login method on the form, he or she is again redirected, this time to a form containing a certificate-based authentication scheme." suggests that what you want to achieve is possible. If you do get this configured and working the way you want, can you please share with the forum?
    -Vinod

  • Multiple identical Applications files??

    I opened to my Applications in my finder the other day and discovered this;
    I have multiple app files and they are identical.  They each are the same size file.
    How were they created?  Do I delete the copies? How do I avoid this in the future?
    Thanks for any help you can give me.
    Frank

    They're aliases. You can just delete them.
    (115980)

  • MyFitnessPal creating multiple identical data points in Health app.  Why?

    I am using MyFitnessPal to sync with the Health app.  I logged my breakfast this morning using myfitnesspal.com which syncs with the MyFitnessPal app.  In many instances (carbohydrates, fat, protein, etc.) multiple data points were created with the exact same value (i.e. there were 6 data points saying 13g fat, adding up to 78g of fat so far today, which is wrong).
    Has anyone else experienced this and what did you do to fix it?
    I have an iPhone 5, using myfitnesspal.com and the MyFitnessPal app, which syncs to the Health app.

    Same problem with the Garmin Connect app... In the Health app, there are 5 identical entries for number of steps every hour, so Health shows me with 5x the number of steps I've actually taken (according to the vivosmart and hence the Garmin Connect app). There are also multiple entries for active calories (although all showing being shared at 12:00am), also using Garmin Connect as the source... apparently, today I've exerted over 12,000 calories!
    I've also got MyFitnessPal, and from what I can tell, it appears to be tracking correctly.

Maybe you are looking for