Extend OAM 11g Password Policy Schema into OUD and Test Force Change password scenario


Steps:
  1. Login into OUD Server
  2. Navigate to /home/oracle/Oracle/Middleware_OUD/asinst_1/OUD/bin
  3. Execute below command
./ldapmodify -h pokuri.demo.com -D "cn=Directory Manager" -w Abcd1234 -p 10389 -f /opt/oracle/Oracle/Middleware_OAM/Oracle_IDM1/oam/server/pswdservice/ldif/OUD_PWDPersonSchema.ldif ā€“v

Note:
- OAM & OUD installed in same machine.

- ā€œOUD_PWDPersonSchema.ldifā€ is the schema file which will come by default with OAM product




Success Message:



4. Login to ODSM console and validate extended schema.



5. Add ā€œoblixorgpersonā€ & ā€œoblixPersonPwdPolicyā€ object classes to user entry



6. Login to OAM console and click on ā€œAuthentication Modulesā€





7. Search and click on ā€œPassword Policy Validation Moduleā€

8. Update Steps as shown below and click on ā€œApplyā€

User Identification Step  
   KEY_IDENTITY_STORE_REF - OUD
   KEY_SEARCH_BASE_URL - ou=People,dc=demo,dc=com

User Authentication step
   KEY_IDENTITY_STORE_REF - OUD
   KEY_PROP_AUTHN_EXCEPTION - true

User Password status Step
   PLUGIN_EXECUTION_MODE - PSWDONLY
   KEY_IDENTITY_STORE_REF - OUD
   URL_ACTION - REDIRECT_POST
   NEW_USERPSWD_BEHAVIOR - FORCECHANGEPASSWORD
   POLICY_SCHEMA - OAM10G
   CHALLENGES_SUPPORTED ā€“ FALSE
   DISABLED_STATUS_SUPPORT - TRUE

     9. Now add ā€œPasswordPolicyValidationSchemaā€ in Application Domain



     10. Restart OAM Service

Testing

  1. Add ā€œobpasswordchangeflagā€ and add value as ā€œtrueā€ which will force the user to change password as soon as user tries to access the OAM protected resource.




2. Access Protected Resource http://pokuri.demo.com:7777/ and enter user credentials


3. Enter current and new passwords



4. Password Reset Success Screen and click on ā€œContinueā€ to land in application welcome page





5. Now check LDAP attribute for change password flag. It will be updated to ā€œfalseā€



Hope this helps some one out there!!

-- Siva Pokuri.

Comments

  1. I really appreciate information shared above. Itā€™s of great help. If someone want to learn Online (Virtual) instructor lead live training in SAIL POINT, kindly contact us http://www.maxmunus.com/contact
    MaxMunus Offer World Class Virtual Instructor led training on SAIL POINT. We have industry expert trainer. We provide Training Material and Software Support. MaxMunus has successfully conducted 100000+ trainings in India, USA, UK, Australlia, Switzerland, Qatar, Saudi Arabia, Bangladesh, Bahrain and UAE etc.
    For Demo Contact us:
    Name : Arunkumar U
    Email : arun@maxmunus.com
    Skype id: training_maxmunus
    Contact No.-+91-9738507310
    Company Website ā€“http://www.maxmunus.com


    ReplyDelete

Post a Comment

Popular Posts