|
||||||||||
|
Configure
your "Enterprise Role" for group authentication Now we will configure our new Enterprise Role to include a group of users in OID. Create a new group in OID using the DAS web application and assign two users to this group. Watch a viewlet to see how to create a group using DAS Now we will map the Enterprise Role to the new user group in OID. Start the Enterprise Security Manager. Example # esm At the login screen enter the super user name (cn=orcladmin), password, FQDN and port number for the OID server.
On the ESM screen, drill down through "Realms -> <your domain name> -> Enterprise Domain -> OracleDefualtDomain -> Enterprise Roles". Highlight the new Enterprise Role name. Select the "Database Global Role" tab and then click the "Add" button. From the "Users" tab, click on the "Add" button.
On the screen that follows drill down in the DIT to the "Groups" container that has the new group we created at the beginning of this section. With the "Groups" container highlighted the "Selection" field should be automatically populated with the full DN of the "Groups" container. In the "Search Criteria" section check the box for "Include Subtrees". In the "Show Names Containing" field, enter the name of the group you want to map to your new Enterprise Role. Click the "Search Now" button. Highlight the name of the group that is returned in the search results. Click the "OK" button.
Back at the "Enterprise Security Manager" screen click the "Apply" button.
Now we need to test our user connections with the database. Since nlewis and pneedham are both part of the MyDBApp group, and this group has been mapped to the "dbaccessentrole" Enterprise Role, both users should be able to connect to the database.
Watch a viewlet to see how its done.
|
||||||||||