Oracle Access Manager (11g OAM) Request Flow

Posted by Unknown on Sunday, April 17, 2011

Oracle Access Manager Request Flow:
  1. The user tries to access an application (resource) protected by Oracle Access Manager 11gR1 using his web browser.
  2. The Oracle Access Manager agent  intercepts the request and tries to ascertain if the user has an authenticated session. Since this is the user’s first access, the user is redirected to the Oracle Access Manager 11gR1 Access Server for authentication.
  3. Access Server’s credential collector component displays a Login Form as defined in authentication scheme. The user submits his credentials to the Access Server.
  4. OAM validates the user’s credentials against user directory and generates a security token. The user is redirected to the resource he tried to access in Step 1.
Oracle Access Manager Session revalidate request flow:
  1. The Oracle Access Manager agent intercepts the request and extracts the security token (cookie).
  2. The Oracle Access Manager agent then makes a back channel call to the Access Server (OAP over TCP) to validate the session and authorize the request.
  3. Oracle Access Manager authenticates the user from the LDAP repository.
  4. Access server verifies the user’s permissions against the configured policy for the web resource.
  5. Access server responds to the WebGate request indicating that access is allowed.
  6. The Oracle Access Manager agent allows the request to go through.
  7. The user is now able to access the web resource he tried to access in Step 1.
Posted in 11g IDM | Leave a comment

Oracle Access Manager 11gR1 Architecture

Oracle Access Manager 11gR1 architecture:

  • User agents: These include web browsers, Java applications, and Web services applications. The user agents access the Access Server and the administration and configuration tools using HTTP.
  • Protected resources: A protected resource is an application or web page to which access is restricted. Access to protected resources is controlled by WebGates or Custom Agents.
  • Administration and configuration tools: Oracle Access Manager can be administered and configured by the Oracle Access Manager console, the Oracle Enterprise Manager Fusion Middleware Control and the Oracle Enterprise Manager Grid Control, and the WebLogic Scripting Tool (WLST).

More Here


{ 0 comments... read them below or add one }

Post a Comment