Leave a Comment:
25 comments
Great article.
Is this for the 10g UCM or the soon to be announced 11g? 11g has a different security model than 10g because of the new WLS layer.
Either way, you should also check out our Advanced User Security Mapping tool which provides the kind of integration you outlined here with a web based admin UI and the ability to connect and map to AD, LDAP, OID etc.
let me know what you think!
Reply@ billycripe,
Thanks a lot for AUSM link (though I need to check demo)
This is for 10g UCM , I am waiting on 11g UCM (I think its releasing in next 2 weeks).
ReplyDear Atul
We need to integrate EBS 12.1.1 with UCM. We have no roadmap to do this except standard oracle document which is not very comprehensive. Can you guide us or share docs/case studies?
Ashok
Reply@ Ashok,
This is done using application extension framework (AXF) check
http://www.oracle.com/products/middleware/content-management/docs/ipm-ebs-solution-datasheet.pdf
and
http://download.oracle.com/docs/cd/E14571_01/doc.1111/e15865/toc.htm
ReplyHi
I was configuring LDAP provider for Active Directory.
I am getting the following error :
Unable to load provider class for activeDirectory. Unable to instantiate java class code for ‘ldap.ActiveDirectoryLdapProvider’ at location ‘ldap.ActiveDirectoryLdapProvider’.
ReplyHi,
how can we configure ldap in ucm 11g using providers in weblogic.
ReplyHi Atul,
i have configured the novell provider in weblogic server and i can see the list of users and groups from eDirectory in users and groups.But when i try to login with any user from eDirectory then it fails.What could be the cause of it.Do i need to map group from eDirectory to some role(s) in weblogic to make it work.Please guide me in this regard how to make this integration work.
ReplyWhat application you are using and as what role ?
Yes, you would need user to group/role mapping for any application URL (update application name and version i.e. 10g or 11g)
ReplyHi Atul,
The application is universal content management -content server 11g and when i see the role for this application in admin console then it shows none roles.
Next scenario,lets say i have two groups in eDirectory IT,Finance and have some users that have different permissions for these groups.Now,do i have to map these groups to some roles in weblogic and also in content server.
Reply@ Muhammed
Check this chapter
http://download.oracle.com/docs/cd/E14571_01/doc.1111/e10792/c03_security.htm
ReplyHi Atul,
I would like to connect the ldap server using secure port 636. What are all the prerequisites for this?
Do we have to install the same secure cert in both ldap server and ucm server? Please let me know.
@ Charles,
Is this UCM 10g or 11g ?
I am assuming ldap is configured with one way ssl (and not two way ssl) which means ldap server will show certificate where as clients (ucm in this case) are not required to show certificates.
Depending on UCM 10g or 11g you provide ldap ssl port and tell UCM that this is ldaps (ssl) port.
ReplyThanks for yor reply Atul.
I am using UCM 10g.
I have gone through the following article about installing secure cert in Domain controllers
http://support.microsoft.com/?kbid=321051
To establish the trusted connection to a DC, we need to export the cert from DC and install it in the UCM and configure the provider to use port 636. Am i correct?
Reply@ Charles, AD by default runs on non-ssl 389 and ssl 636 port.
First use 389 and that should work.
If that works then change create another provider with port 636 and see if that works (I don’t think any cert required at UCM side as AD by default is not configured in two way ssl .
ReplyHi Atul,
I want to integrate UCM,SES and ActiveDirectory together.
Can you give me a hint how do this ?
Now I have a problem, because when I add new security provider into Weblogic server (ECM) I got error in SES when I run crawler.
Error:
Thread-2 EQP-60303: Exiting saxthread due to errors
Thread-2 EQP-80330: Unrecognized QName :Envelope oracle.search.sdk.crawler.PluginException oracle.search.plugin.rss.SAXThread:checkNamespace:200 oracle.search.plugin.rss.SAXThread:startElement:218 oracle.xml.parser.v2.NonValidatingParser:parseElement:1296 oracle.xml.parser.v2.NonValidatingParser:parseRootElement:340 oracle.xml.parser.v2.NonValidatingParser:parseDocument:307 oracle.xml.parser.v2.XMLParser:parse:212 oracle.xml.jaxp.JXSAXParser:parse:292 oracle.search.plugin.rss.SAXThread:run:159 java.lang.Thread:run:595
Thanks …
Reply@ john,
What is version of UCM and SES ?
Do you have an option to put OID (Oracle Internet Directory – LDAP server from Oracle) between UCM/SES and AD ?
ReplySorry, I forgot it …
UCM – 11.1.1.5.0
SES – 11.1.2.0.0
Active Directory – Microsoft Windows Server 2003
On SES – Identity management Setup: Active Directory
– Source: Oracle Content Server
on ECM – component: SESCrawlerExport
– WebLogic – Security Realms – Security Provider – to Active directory
With this configuration I got error (see above).
Thanks, John
Replywe have followed all the step shown above, but we get the following error:
Connection State: N/A
Connection Error: Unable to load provider class for AD_LDAP. Unable to instantiate java class code for ‘ldap.ActiveDirectoryLdapUserProvider’ at location ‘ldap.ActiveDirectoryLdapUserProvider’.
Last Activity Date: None
Hi Atul,
You have mentioned the below statement in your article.
“This integration process i.e. Active Directory as LDAP Provider is different from direct AD integration”
I think in my application it is done through direct AD integration. But I don’t know how they have done it. Is there any article or documentation how to configure directly.
Please help.
Thanks,
Selvam S.
@Selvam,
Did you look at link mentioned under Reference section in above post ?
ReplyHi Atul,
Can we integrate UCM 11 G with AD in similar way as you have mentioned here. We don’t need to create a weblogic provider. We can just create a Content Server LDAP provider that should be OK right?
Regards,
Ramesh
@ Ramesh,
I don’t think that will be supported/certified solution.
You should create authentication provider in WebLogic for AD . That is quite simple solution
Step to add provider is http://download.oracle.com/docs/cd/E21764_01/doc.1111/e15483/idm_integration.htm#BABCHCED
Change from OID to AD (ignore OAM10g/11g steps)
ReplyHi Atul
I’m getting below error while starting UCM after changing the configuration as per above document.
Please help me to sort out this issue
<general exception
intradoc.data.DataException: !csProviderClassLoadError,RCA_AD
at intradoc.provider.Provider.createClass(Provider.java:126)
at intradoc.provider.Provider.init(Provider.java:68)
at intradoc.server.IdcSystemLoader.loadProviders(IdcSystemLoader.java:2369)
I have followed the above steps to establish ldap connection for our Ebs intergration but still not able to login using ldap password
Reply