Configuring Enterprise User Security for Kerberos Authentication
Enterprise User Security Configuration Tasks and Troubleshooting
12-19
■
You have prepared your directory by completing the tasks described in
"Preparing the Directory for Enterprise User Security"
on page 12-5.
■
You have configured your Enterprise User Security objects in the database and
the directory by completing the tasks described in
"Configuring Enterprise User
Security Objects in the Database and the Directory"
on page 12-11.
■
You have configured an SSL instance with no authentication for Oracle Internet
Directory as described in Oracle Internet Directory Administrator's Guide. If you
are using an
ldap.ora
, also ensure that the port number for this SSL with no
authentication instance is listed there as your directory SSL port.
To configure Enterprise User Security for Kerberos authentication, perform the
following tasks:
■
Task 1: Configure the Enterprise Security Manager Console to display the
Kerberos principal name attribute
■
Task 2: (Optional) Configure the Kerberos Principal Name Directory Attribute
for the Identity Management Realm
■
Task 3: Specify the Enterprise User's Kerberos Principal Name in the
krbPrincipalName Attribute
■
Task 4: (Optional) Enable the Enterprise Domain to Accept Kerberos
Authentication
■
Task 5: Connect as a Kerberos-Authenticated Enterprise User
Task 1: Configure the Enterprise Security Manager Console to display the Kerberos principal
name attribute
Use Oracle Internet Directory Self-Service Console to configure the Enterprise
Security Manager Console to display the Kerberos principal name attribute. For
more information about this task, see
"Configuring Enterprise Security Manager
Console for Kerberos-Authenticated Enterprise Users"
on page 2-24.
Task 2: (Optional) Configure the Kerberos Principal Name Directory Attribute for the Identity
Management Realm
Use Enterprise Security Manager Console to enter the directory attribute used to
store the Kerberos principal name for the identity management realm you are using
in the directory. By default Kerberos principal names are stored in the
krbPrincipalName
attribute, but can be changed to correspond to your directory
configuration by changing
orclCommonKrbPrincipalAttribute
in the identity
management realm. For more information about this task, see
"Setting Login Name,
Summary of Contents for Database Advanced Security 10g Release 1
Page 17: ...xvii ...
Page 20: ...xx ...
Page 24: ...xxiv ...
Page 42: ...xlii ...
Page 44: ......
Page 102: ......
Page 124: ......
Page 246: ...Managing Certificates 8 28 Oracle Database Advanced Security Administrator s Guide ...
Page 284: ......
Page 384: ......
Page 414: ...Physical Security D 6 Oracle Database Advanced Security Administrator s Guide ...
Page 518: ...Index 10 ...