Configuring Enterprise User Security for Kerberos Authentication
Enterprise User Security Configuration Tasks and Troubleshooting
12-19
■
You have prepared your directory by completing the tasks described in
"Preparing the Directory for Enterprise User Security"
on page 12-5.
■
You have configured your Enterprise User Security objects in the database and
the directory by completing the tasks described in
"Configuring Enterprise User
Security Objects in the Database and the Directory"
on page 12-11.
■
You have configured an SSL instance with no authentication for Oracle Internet
Directory as described in Oracle Internet Directory Administrator's Guide. If you
are using an
ldap.ora
, also ensure that the port number for this SSL with no
authentication instance is listed there as your directory SSL port.
To configure Enterprise User Security for Kerberos authentication, perform the
following tasks:
■
Task 1: Configure the Enterprise Security Manager Console to display the
Kerberos principal name attribute
■
Task 2: (Optional) Configure the Kerberos Principal Name Directory Attribute
for the Identity Management Realm
■
Task 3: Specify the Enterprise User's Kerberos Principal Name in the
krbPrincipalName Attribute
■
Task 4: (Optional) Enable the Enterprise Domain to Accept Kerberos
Authentication
■
Task 5: Connect as a Kerberos-Authenticated Enterprise User
Task 1: Configure the Enterprise Security Manager Console to display the Kerberos principal
name attribute
Use Oracle Internet Directory Self-Service Console to configure the Enterprise
Security Manager Console to display the Kerberos principal name attribute. For
more information about this task, see
"Configuring Enterprise Security Manager
Console for Kerberos-Authenticated Enterprise Users"
on page 2-24.
Task 2: (Optional) Configure the Kerberos Principal Name Directory Attribute for the Identity
Management Realm
Use Enterprise Security Manager Console to enter the directory attribute used to
store the Kerberos principal name for the identity management realm you are using
in the directory. By default Kerberos principal names are stored in the
krbPrincipalName
attribute, but can be changed to correspond to your directory
configuration by changing
orclCommonKrbPrincipalAttribute
in the identity
management realm. For more information about this task, see
"Setting Login Name,
Содержание Database Advanced Security 10g Release 1
Страница 17: ...xvii ...
Страница 20: ...xx ...
Страница 24: ...xxiv ...
Страница 42: ...xlii ...
Страница 44: ......
Страница 62: ...Oracle Advanced Security Restrictions 1 18 Oracle Database Advanced Security Administrator s Guide ...
Страница 100: ...Duties of an Enterprise User Security Administrator DBA 2 38 Oracle Database Advanced Security Administrator s Guide ...
Страница 102: ......
Страница 116: ...How To Configure Data Encryption and Integrity 3 14 Oracle Database Advanced Security Administrator s Guide ...
Страница 124: ......
Страница 148: ...RSA ACE Server Configuration Checklist 5 24 Oracle Database Advanced Security Administrator s Guide ...
Страница 246: ...Managing Certificates 8 28 Oracle Database Advanced Security Administrator s Guide ...
Страница 254: ...Configuring Oracle Database for External Authentication 9 8 Oracle Database Advanced Security Administrator s Guide ...
Страница 284: ......
Страница 350: ...Troubleshooting Enterprise User Security 12 38 Oracle Database Advanced Security Administrator s Guide ...
Страница 384: ......
Страница 394: ...Data Encryption and Integrity Parameters A 10 Oracle Database Advanced Security Administrator s Guide ...
Страница 414: ...Physical Security D 6 Oracle Database Advanced Security Administrator s Guide ...
Страница 518: ...Index 10 ...