Oracle Identity Cloud Service Integration with Oracle Identity Manager

Oracle Identity Cloud Service Integration with Oracle Identity Manager

An Oracle Identity Manager (OIM) connector is used to synchronize the users and groups from on-premise OIM to Oracle Identity Cloud Service in a hybrid cloud solution. This integration allows to manage Oracle Identity Cloud Service users directly from OIM and to leverage OIM enterprise governance features, such as Certification and Segregation of Duties with closed loop remediation for a complete identity governance.This post explains steps for Oracle Identity Cloud Service Integration with Oracle Identity Manager using connector.

1.  Register the OIM Application in Oracle Identity Cloud Service

  • Login to Identity Domain as Administrator and click on Applications

Oracle Identity Cloud Service Integration with Oracle Identity Manager21 1024x582 Oracle Identity Cloud Service Integration with Oracle Identity Manager

 

 

 

 

 

 

 

 

 

 

 

  • Click on Add to new Application
  • Select Trusted Application in the next screen

Oracle Identity Cloud Service Integration with Oracle Identity Manager22 Oracle Identity Cloud Service Integration with Oracle Identity Manager

 

 

 

 

 

 

 

 

 

 

  • In the next page, Enter the Application Name and description and Click Next

Oracle Identity Cloud Service Integration with Oracle Identity Manager3 Oracle Identity Cloud Service Integration with Oracle Identity Manager

 

 

 

 

 

 

 

 

 

 

 

  • Select Configure this Application as a Client Now and Select Client Credentials as Grant Types. Also select Grant the client access to Identity Cloud Service Admin APIs and Add User Administrator Group .

Oracle Identity Cloud Service Integration with Oracle Identity Manager4 Oracle Identity Cloud Service Integration with Oracle Identity Manager

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

  • In the Resouces page, click Next

Oracle Identity Cloud Service Integration with Oracle Identity Manager5 Oracle Identity Cloud Service Integration with Oracle Identity Manager

 

 

 

 

 

 

 

 

 

 

 

 

 

  • In the Authorization page, click Finish.

Oracle Identity Cloud Service Integration with Oracle Identity Manager6 Oracle Identity Cloud Service Integration with Oracle Identity Manager

 

 

 

 

 

 

 

 

 

 

 

 

 

  • Application Added message will be displayed. Note down the Client ID and Secret ID and Close

Oracle Identity Cloud Service Integration with Oracle Identity Manager7 Oracle Identity Cloud Service Integration with Oracle Identity Manager

 

 

 

 

 

 

 

 

 

 

 

 

The Client ID and Client Secret is required to Configure the OIM IT Resource  and OIM connector use this to connect to Oracle Identity Cloud Service.

2. Install IDCS Connector in OIM

The steps to install IDCS connector in OIM is explained here.

3. Configure IDCS IT Resource

The steps configure IDCS IT resource is explained here.

4. Import IDCS SSL certificate to OIM Trust Store

1.Export the IDCS https certificate and Copy it to OIM server

2.Import the certificate into the OIM JDK trust store

eg: keytool -import -keystore $JAVA_HOME/jre/lib/security/cacerts -file /app/MiddleWare/idcs.cer -storepass changeit -alias idcs

3.Enter “Yes” when prompted. Certificate was added to keystore message will be displayed.
4.Import the IDCS certificate to OIM Server trust store .
eg: keytool -import -keystore $WL_HOME/server/lib/DemoTrust.jks -file /app/MiddleWare/idcs.cer -storepass   DemoTrustKeyStorePassPhrase -alias idcs

5.Enter “Yes” when prompted. Certificate was added to keystore message will be displayed.

5. Create Form for IDCS Resource Object

  1. Click on Create a SandBox and activate the SandBox.
  2. Click on Form Designer and create a form with below details.

FormName: IDCSForm

Form Tye: Parent Form + Child Tables (Master/Detail)

Resource Type : IDCS User

6. Attach the IDCS Form to Identity Cloud Service Application Instance

  1. Click on Application Instances and and search for “Identity Cloud Service Application Instance
  2. Attach the IDCSForm created earlier to this application instance.
  3. Save the changes and Publish the sand box.

7. Running the IDCS schedulers

  1. Run the IDCS Group Lookup Reconciliation
  2. IDCS Groups will be added to the Lookup.IDCS.Groups lookup.
  3. Run the Catalog Synchronization Job to expose the Identity Cloud Application Instance to users.

8.Testing the Integration

  •  Login to Self Service Console as system Administrator and Click on Request .
  • Select Request for Others

Oracle Identity Cloud Service Integration with Oracle Identity Manager51 1024x390 Oracle Identity Cloud Service Integration with Oracle Identity Manager

 

 

 

 

 

 

 

  • In the next page, Search for the user and add the user to selected list.

Oracle Identity Cloud Service Integration with Oracle Identity Manager61 1024x419 Oracle Identity Cloud Service Integration with Oracle Identity Manager

 

 

 

 

 

 

 

  •  Select SelfRegisteredUsers and Identity Cloud Service Application Instance to the cart

Oracle Identity Cloud Service Integration with Oracle Identity Manager71 Oracle Identity Cloud Service Integration with Oracle Identity Manager

 

 

 

 

 

 

 

 

 

 

  • In the checkout page, enter the details and Submit the request.

Oracle Identity Cloud Service Integration with Oracle Identity Manager8 1024x424 Oracle Identity Cloud Service Integration with Oracle Identity Manager

 

 

 

 

 

 

 

 

 

  • Login to IDCS as Administrator.
  • Click on User and Search for the user

Oracle Identity Cloud Service Integration with Oracle Identity Manager10 300x93 Oracle Identity Cloud Service Integration with Oracle Identity Manager

 

 

 

 

  • Click on the user to view details.

Oracle Identity Cloud Service Integration with Oracle Identity Manager9 Oracle Identity Cloud Service Integration with Oracle Identity Manager

 

 

 

 

 

 

 

 

 

 

 

  • Click on the groups tab to see the assigned group for the user.

Oracle Identity Cloud Service Integration with Oracle Identity Manager11 300x131 Oracle Identity Cloud Service Integration with Oracle Identity Manager

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Leave a Reply

Your email address will not be published. Required fields are marked *

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>