Accéder au contenu principal

Configuring Oracle Cloud as the Service Provider with SimpleSAMLphp as IDP

In order to establish SSO between enteprise backend and Oracle Public Cloud, it's possible to use SimpleSAMLphp (Federation tool) as an in-house Identity Provider, and setup Oracle Cloud as the Service Povider.
Cf official documentation Managing Single Sign-On about the concept.
SSO relies on SAML 2.0 standard.

Tasks

At the Identity Server (IDP) level

  • Install Apache and PHP 5.3 +
  • Install SimpleSAMLphp
  • Just Follow documentation and yum install php53-mcrypt  instead php-mcrypt if linux complains about it.
  • Test with a simple SP provided with SimplePHPphp.
  • Don't forget to un-comment the example-userpass !
  • Export the metadata in a XML file

At the Cloud Service level

  • Import the previous metadata file
  • Accept default values and don't change anything.
  • At the IDP server level: 
    • Follow documentation Servive Provider Quickstart
      • Update the config/authsources.php with infos provided in the parameter pages (entity Id)
      • EntityID value must be the same value as Provider Id
      • Let's stay in http (vs https) mode for demo purpose
  • Test the SSO (cf output below)
  • enable it, only if test is ok.
Output Display after SSO test


Login page after enabling SSO


SimpleSAMLphp login page

Commentaires

Posts les plus consultés de ce blog

Oracle Documents Cloud Service - Using Upload File REST API

If the Upload File sample given in ODCS documentation is used "as is", we get a http 400 error. The syntax is strict and every blank line must be empty (no space character for instance). If we cust and paste the sample, there are residual space characters which must be removed. So, use this pattern instead: -----1234567890 Content-Disposition: form-data; name="jsonInputParameters" { "parentID": " " } -----1234567890 Content-Disposition: form-data; name="primaryFile"; filename="example.txt" Content-Type: text/plain Hello World! -----1234567890-- instead the original one: -----1234567890 Content-Disposition: form-data; name="jsonInputParameters" { "parentID":"FB4CD874EF94CD2CC1B60B72T0000000000100000001" } -----1234567890 Content-Disposition: form-data; name="primaryFile"; filename="example.txt" Content-Type: text/plain -----1234567890-- Tests can be...

Activating OmniPortlet with Oracle WebCenter

in a fresh install of Oracle WebCenter, the OmniPortlet is deployed but not registered as a portlet producer. As mentioned in the documentation, it’s needed to do some extra setup either with the Fusion Middleware Control or with a WLST script. This post explains how to use the first option. Let’s suppose that the administration port is : 7001. Use a web browser for connecting to the Fusion Middleware control (Remark: it’s not the WebLogic console !) http:<hostname>:7001/em Connect as weblogic (or an account with administrative privileges) Choose Register Producer option in the WebCenter menu In the URL endpoint field, enter: http://<hostname>:7001/portalTools/omniPortlet/providers/omniPortlet In most of case, it will be useful to restart all webCenter, in order to see the new portlet displayed in the catalog (under Portlets folder) In order to  see the already registered portlets, choose Service Configuration