You are on page 1of 12

4/18/2015

SecurityinOracleWebLogic:Realm,SecurityProvider,Authentication,Authorization,UsersOnlineIdentity&AccessManagement

(http://www.onlineappsdba.com)

Find us:

(https://www.facebook.com/k21technologies)

(https://twitter.com/k21technologies)

(https://www.linkedin.com/company/k21technologies)

+1-669-900-5138 | +44-203-372-5553

Security In Oracle WebLogic : Realm, Security Provider,


Authentication, Authorization, Users
Tweet (http://twitter.com/share)

Share

FreeNewsletter

GetLatestUpdates

Posted by "Atul Kumar (http://www.onlineappsdba.com/index.php/author/atul/)" in "security

Youremailhere

(http://www.onlineappsdba.com/index.php/category/security/), weblogic
(http://www.onlineappsdba.com/index.php/category/weblogic/)" on 2008-11-22

Subscribe

(http://onlineappsdba.com/wp-

Make Training Enquiry

Name*
content/uploads/2008/11/weblogic_sec_2.JPG)

Email ID*

Security Providers - are modules that provide security service to application to protect Weblogic resource.

Phone

Types of security providers in WebLogic Server are


Authentication Provider, Authorization Provider, Auditing Providers, Credential Mapping Provider, Identity

Description

Assertion Provider, Principal Validation Provider, Adjudication Providers, Role Mapping Providers, Certificate
Lookup and Validation Providers, Keystore Providers andRealm Adapter providers.
Security Provider Database contains users, groups, security roles, security policies and credentials. This
database can be embedded LDAP server, properties file or physical database.

TOP

Embedded LDAP server- WebLogic Server uses its embedded LDAP server as security provider database to
store users, groups, security roles and security policies.

SUBMIT

Security Realm- Security Realm comprises mechanism of protecting WebLogic Resource. Each Security realm
consists of security providers, users, groups, security roles and security policies. User must be defined in a
security realm in order to access any weblogic resource belonging to that realm. Default realm in Weblogic is

Categories

myrealm.

10gAS

You can configure multiple security realm in a domain but only one realm can be active at a time.

(Http://Www.Onlineappsdba.Com/Index.Ph
11i

(Http://Www.Onlineappsdba.Com/Index.Ph

http://www.onlineappsdba.com/index.php/2008/11/22/securityinoracleweblogicrealmsecurityproviderauthenticationauthorizationusers/

1/12

4/18/2015

SecurityinOracleWebLogic:Realm,SecurityProvider,Authentication,Authorization,UsersOnlineIdentity&AccessManagement

You can configure security realm using WebLogic Console or WLST (WebLogic Scripting Tool) or JMX (Java

1z0108

Management Extension) API.

(Http://Www.Onlineappsdba.Com/Index.Ph
108/)

1z0233

(Http://Www.Onlineappsdba.Com/Index.Ph
233/)
1z0312

(Http://Www.Onlineappsdba.Com/Index.Ph
AD

(Http://Www.Onlineappsdba.Com/Index.Ph
Ad4j

(Http://Www.Onlineappsdba.Com/Index.Ph
Adam

(Http://Www.Onlineappsdba.Com/Index.Ph
(http://onlineappsdba.com/wp-

Adapters

(Http://Www.Onlineappsdba.Com/Index.Ph
Adop

(Http://Www.Onlineappsdba.Com/Index.Ph
Advanced

(Http://Www.Onlineappsdba.Com/Index.Ph
Aia

(Http://Www.Onlineappsdba.Com/Index.Ph
Amberpoint

(Http://Www.Onlineappsdba.Com/Index.Ph
Apache

(Http://Www.Onlineappsdba.Com/Index.Ph

content/uploads/2008/11/weblogic_sec_4.JPG)

Apex

(Http://Www.Onlineappsdba.Com/Index.Ph

Apps

(Http://Www.Onlineappsdba.Com/Index.Ph
AppsASintegration

(Http://Www.Onlineappsdba.Com/Index.Ph
Autoconfig

(Http://Www.Onlineappsdba.Com/Index.Ph
Backup
(http://onlineappsdba.com/wp-

(Http://Www.Onlineappsdba.Com/Index.Ph
Bam

(Http://Www.Onlineappsdba.Com/Index.Ph
Basics

(Http://Www.Onlineappsdba.Com/Index.Ph
BEA

(Http://Www.Onlineappsdba.Com/Index.Ph
Beginners
content/uploads/2008/11/weblogic_sec_5.JPG)
.

(Http://Www.Onlineappsdba.Com/Index.Ph
Blogroll

(Http://Www.Onlineappsdba.Com/Index.Ph
.

BookReview

(Http://Www.Onlineappsdba.Com/Index.Ph
Review/)

http://www.onlineappsdba.com/index.php/2008/11/22/securityinoracleweblogicrealmsecurityproviderauthenticationauthorizationusers/

2/12

4/18/2015

SecurityinOracleWebLogic:Realm,SecurityProvider,Authentication,Authorization,UsersOnlineIdentity&AccessManagement

All Security providers exists within context of realm, some security provider type are compulsory in a security

Bpel

realm while others are optional.

(Http://Www.Onlineappsdba.Com/Index.Ph
BusinessIntelligence

(Http://Www.Onlineappsdba.Com/Index.Ph
Intelligence/)
Calendar

(Http://Www.Onlineappsdba.Com/Index.Ph
Cdc

(Http://Www.Onlineappsdba.Com/Index.Ph
(http://onlineappsdba.com/wp-

Certification

(Http://Www.Onlineappsdba.Com/Index.Ph
Cloning

(Http://Www.Onlineappsdba.Com/Index.Ph
Coherence

(Http://Www.Onlineappsdba.Com/Index.Ph
ConcurrentManager
content/uploads/2008/11/weblogic_sec_3.JPG)

(Http://Www.Onlineappsdba.Com/Index.Ph
Manager/)

ConnectorServer

Authentication Provider - is to prove identity of user or system.

(Http://Www.Onlineappsdba.Com/Index.Ph
Server/)

Auditing Provider - is to provide auditing services. Audit information may be written to LDAP server, Database

ContentServer

or simple file.

(Http://Www.Onlineappsdba.Com/Index.Ph
Server/)

Cpu

Principal is identity assigned to user or group as result of authentication.

(Http://Www.Onlineappsdba.Com/Index.Ph
Customization

Subject - after successful authentication, principal are signed and stored in subject for future use.

(Http://Www.Onlineappsdba.Com/Index.Ph
Database

(Http://Www.Onlineappsdba.Com/Index.Ph
Db_basics

(Http://Www.Onlineappsdba.Com/Index.Ph
DisasterRecovery

(Http://Www.Onlineappsdba.Com/Index.Ph
Recovery/)
Discoverer
(http://onlineappsdba.com/wp-

(Http://Www.Onlineappsdba.Com/Index.Ph
Ecm

(Http://Www.Onlineappsdba.Com/Index.Ph
EPM

(Http://Www.Onlineappsdba.Com/Index.Ph
Esb

(Http://Www.Onlineappsdba.Com/Index.Ph
content/uploads/2008/11/weblogic_sec_11.JPG)
.
LoginModules is part of Authentication Provider and responsible for authenticating users within security
realm and for populating subject with necessary principal (user, group)

Eus

(Http://Www.Onlineappsdba.Com/Index.Ph
Exalogic

(Http://Www.Onlineappsdba.Com/Index.Ph
Fmw

(Http://Www.Onlineappsdba.Com/Index.Ph

http://www.onlineappsdba.com/index.php/2008/11/22/securityinoracleweblogicrealmsecurityproviderauthenticationauthorizationusers/

3/12

4/18/2015

SecurityinOracleWebLogic:Realm,SecurityProvider,Authentication,Authorization,UsersOnlineIdentity&AccessManagement

Authentication- is process to provide credentials (username/password, Certificate..) to provide identity of


user/system. Weblogic support following type of authentication
a) Username/Password- Username and password with or without SSL
b) Certificate Authentication - one way or two way SSL authentication where Server authenticate itself by

Forms

(Http://Www.Onlineappsdba.Com/Index.Ph
Fusion

(Http://Www.Onlineappsdba.Com/Index.Ph
Grc

showing SSL certificate and server can ask client for certificate.

(Http://Www.Onlineappsdba.Com/Index.Ph

c) Digest Authentication- using nonce, timestamp, username and digest

GRCM

d) Perimeter Authentication process of authenticating identity of remote user outside of application server

(Http://Www.Onlineappsdba.Com/Index.Ph

domain.

HA

(Http://Www.Onlineappsdba.Com/Index.Ph
Authorization - is process which determines which user has access on which WebLogic Resources.
WebLogic Resource- is an Object (which represents WebLogic entity) which can be protected. for ex. ear, ejb,
network etc.

Haley

(Http://Www.Onlineappsdba.Com/Index.Ph
HowTo?

Security Policy is kind of ACL(Access Control List) which determines who (user, group, role) has access to

(Http://Www.Onlineappsdba.Com/Index.Ph
To/)

which weblogic resource. WebLogic resource is not protected till you assign security policy to it.

Hyperion

(Http://Www.Onlineappsdba.Com/Index.Ph
Weblogic Server provides SSO with following environments

Identity_manager

- Web Browser and HTTP Client (via SAML)

(Http://Www.Onlineappsdba.Com/Index.Ph

- Desktop client

Idm

More on Single Sign-On with Oracle WebLogic Server coming soon ..

(Http://Www.Onlineappsdba.Com/Index.Ph

Previous in series (http://www.onlineappsdba.com/index.php/2008/11/06/weblogic-server-jdbc-fordatabase-connection-step-by-step/) Next in series

Im

(Http://Www.Onlineappsdba.Com/Index.Ph
Installation

(http://www.onlineappsdba.com/index.php/2009/02/01/deploy-adf-application-to-oracle-weblogic-

(Http://Www.Onlineappsdba.Com/Index.Ph

server/)

Integration

(Http://Www.Onlineappsdba.Com/Index.Ph
Related Posts for Learn WebLogic with Us

InterviewQs

(Http://Www.Onlineappsdba.Com/Index.Ph

Oracle WebLogic Installation Steps


(http://www.onlineappsdba.com/index.php/2008/07/22/oracle-weblogic-installation-steps/)
Domain , Administration & Managed Server, Cluster in Oracle WebLogic

Jboss

(Http://Www.Onlineappsdba.Com/Index.Ph
Jdbc

(Http://Www.Onlineappsdba.Com/Index.Ph

(http://www.onlineappsdba.com/index.php/2008/07/24/domain-administration-managed-

Jdeveloper

server-cluster-in-oracle-weblogic/)

(Http://Www.Onlineappsdba.Com/Index.Ph

Create Domain in Oracle WebLogic

Jdk

(http://www.onlineappsdba.com/index.php/2008/07/28/create-domain-in-oracle-weblogic/)

(Http://Www.Onlineappsdba.Com/Index.Ph

Oracle WebLogic Server Startup/Shutdown

Jobs

(http://www.onlineappsdba.com/index.php/2008/08/03/oracle-weblogic-server-

(Http://Www.Onlineappsdba.Com/Index.Ph

startupshutdown/)

Jrockit

Oracle WebLogic Server 10g R3 10.3 is out now

(Http://Www.Onlineappsdba.Com/Index.Ph

(http://www.onlineappsdba.com/index.php/2008/08/07/oracle-weblogic-server-10g-r3-103released/)
Deploy Application on Oracle WebLogic Server
(http://www.onlineappsdba.com/index.php/2008/08/12/deploy-application-on-oracle-weblogicserver/)

LAF

(Http://Www.Onlineappsdba.Com/Index.Ph
Mail

(Http://Www.Onlineappsdba.Com/Index.Ph
News

(Http://Www.Onlineappsdba.Com/Index.Ph

Cluster Architecture : Oracle WebLogic Server

Oaacg

(http://www.onlineappsdba.com/index.php/2008/08/14/cluster-architecture-oracle-weblogic-

(Http://Www.Onlineappsdba.Com/Index.Ph

http://www.onlineappsdba.com/index.php/2008/11/22/securityinoracleweblogicrealmsecurityproviderauthenticationauthorizationusers/

4/12

4/18/2015

SecurityinOracleWebLogic:Realm,SecurityProvider,Authentication,Authorization,UsersOnlineIdentity&AccessManagement

server/)

Oaam

Start WebLogic Server on Linux on port 80, 443 <= 1024

(Http://Www.Onlineappsdba.Com/Index.Ph

(http://www.onlineappsdba.com/index.php/2008/09/21/start-weblogic-server-on-linux-on-port-

Oam

80-443/)

(Http://Www.Onlineappsdba.Com/Index.Ph

JDBC (Java DataBase Connectivity ) in Oracle WebLogic Overview

Obiee

(http://www.onlineappsdba.com/index.php/2008/11/04/jdbc-java-database-connectivity-in-

(Http://Www.Onlineappsdba.Com/Index.Ph

oracle-weblogic-overview/)
WebLogic Server JDBC for Database connection : Step by Step
(http://www.onlineappsdba.com/index.php/2008/11/06/weblogic-server-jdbc-for-databaseconnection-step-by-step/)

Ocm

(Http://Www.Onlineappsdba.Com/Index.Ph
Ocms

(Http://Www.Onlineappsdba.Com/Index.Ph
Ocs

Security in Oracle WebLogic : Realm, Security Provider, Authentication, Authorization, Users

(Http://Www.Onlineappsdba.Com/Index.Ph

Deploy ADF application to Oracle WebLogic Server

Odi

(http://www.onlineappsdba.com/index.php/2009/02/01/deploy-adf-application-to-oracle-

(Http://Www.Onlineappsdba.Com/Index.Ph

weblogic-server/)

Odq

Node Manager in Oracle WebLogic Server

(Http://Www.Onlineappsdba.Com/Index.Ph

(http://www.onlineappsdba.com/index.php/2009/06/10/node-manager-in-oracle-weblogic-

OEG

server/)

(Http://Www.Onlineappsdba.Com/Index.Ph

Configure Oracle HTTP Server infront of Oracle WebLogic Server mod_wl_ohs

Oem

(http://www.onlineappsdba.com/index.php/2009/09/23/configure-oracle-http-server-infront-oforacle-weblogic-server-mod_wl_ohs/)
How to install weblogic server on 64 bit O.S. (Linux /Solaris) ?
(http://www.onlineappsdba.com/index.php/2009/11/23/how-to-install-weblogic-server-on-64bit-os-linux-solaris/)

(Http://Www.Onlineappsdba.Com/Index.Ph
Oes

(Http://Www.Onlineappsdba.Com/Index.Ph
Ofsaa

(Http://Www.Onlineappsdba.Com/Index.Ph
Ohs

Oracle WebLogic Login Issue : Password is not correct (Password Lock Policy)

(Http://Www.Onlineappsdba.Com/Index.Ph

(http://www.onlineappsdba.com/index.php/2009/12/29/oracle-weblogic-login-issue-password-

Oia

is-not-correct-password-lock-policy/)

(Http://Www.Onlineappsdba.Com/Index.Ph

Oracle WebLogic Server : Node Manager in nutshell

Oid

(http://www.onlineappsdba.com/index.php/2010/01/07/oracle-weblogic-server-node-manager-

(Http://Www.Onlineappsdba.Com/Index.Ph

in-nutshell/)

Oif

Certification : 1Z0-108 Oracle WebLogic Server 10g System Administrator Certified Expert

(Http://Www.Onlineappsdba.Com/Index.Ph

(http://www.onlineappsdba.com/index.php/2010/01/11/certification-1z0-108-oracle-weblogicserver-10g-system-administrator-certified-expert/)
How to integrate WebLogic with Oracle Internet Directory for Login : Authentication
(http://www.onlineappsdba.com/index.php/2010/02/04/how-to-integrate-weblogic-with-oracleinternet-directory-for-login-authentication/)

OIM

(Http://Www.Onlineappsdba.Com/Index.Ph
OMSS

(Http://Www.Onlineappsdba.Com/Index.Ph
OPA

(Http://Www.Onlineappsdba.Com/Index.Ph

opatch, adpatch and now smart update (BSU) to apply weblogic patches

OPAM

(http://www.onlineappsdba.com/index.php/2010/02/23/opatch-adpatch-and-now-smart-

(Http://Www.Onlineappsdba.Com/Index.Ph

update-bsu-to-apply-weblogic-patches/)

OPMN

Disater Recovery documentation for Oracle WebLogic Server 11g (Fusion Middleware)

(Http://Www.Onlineappsdba.Com/Index.Ph

(http://www.onlineappsdba.com/index.php/2010/03/08/disater-recovery-documentation-for-

Orm

oracle-weblogic-server-11g-fusion-middleware/)

(Http://Www.Onlineappsdba.Com/Index.Ph

Authentication Providers in #WebLogic Oracle Access Manager Identity Assertion for Single

Osb

Sign-On and OAM Authenticator

(Http://Www.Onlineappsdba.Com/Index.Ph

(http://www.onlineappsdba.com/index.php/2010/07/05/authentication-providers-in-weblogicoracle-access-manager-identity-assertion-for-single-sign-on-and-oam-authenticator/)

Osr

(Http://Www.Onlineappsdba.Com/Index.Ph

http://www.onlineappsdba.com/index.php/2008/11/22/securityinoracleweblogicrealmsecurityproviderauthenticationauthorizationusers/

5/12

4/18/2015

SecurityinOracleWebLogic:Realm,SecurityProvider,Authentication,Authorization,UsersOnlineIdentity&AccessManagement

Error while starting WebLogic Server : java.lang.NumberFormatException: null

Others

(http://www.onlineappsdba.com/index.php/2010/08/16/error-while-starting-weblogic-server-

(Http://Www.Onlineappsdba.Com/Index.Ph

javalangnumberformatexception-null/)

Oud

#WebLogic startup prompting from username password : boot.properties

(Http://Www.Onlineappsdba.Com/Index.Ph

(http://www.onlineappsdba.com/index.php/2010/08/21/weblogic-startup-prompting-from-

Ovd

username-password-bootproperties/)

(Http://Www.Onlineappsdba.Com/Index.Ph

BEA-000286 : Failed to invoke startup class JRF Startup Class oracle.jrf.wls.JRFStartup


(http://www.onlineappsdba.com/index.php/2011/03/01/bea-000286-failed-to-invoke-startupclass-jrf-startup-class-oraclejrfwlsjrfstartup/)
WebLogic Kerberos (SSO) Authentication Issue : Error 401 Forbidden : No Configuration was

Owsm

(Http://Www.Onlineappsdba.Com/Index.Ph
Patching

(Http://Www.Onlineappsdba.Com/Index.Ph
Peoplesoft

registered that can handle the configuration named com. sun. security. jgss. krb5. accept

(Http://Www.Onlineappsdba.Com/Index.Ph

(http://www.onlineappsdba.com/index.php/2011/03/21/weblogic-kerberos-sso-authentication-

Performance

issue-error-401-forbidden-no-configuration-was-registered-that-can-handle-the-configuration-

(Http://Www.Onlineappsdba.Com/Index.Ph

named-com-sun-security-jgss-krb5-accept/)

Portal

How to reset Lost Oracle WebLogic Password for Fusion Middleware Applications

(Http://Www.Onlineappsdba.Com/Index.Ph

(http://www.onlineappsdba.com/index.php/2011/08/02/how-to-reset-lost-oracle-weblogic-

Printer

password-for-fusion-middleware-applications/)

(Http://Www.Onlineappsdba.Com/Index.Ph

Oracle WebLogic Server Certification : 1Z0-108 Practice Question and Dumps

R12

(http://www.onlineappsdba.com/index.php/2011/08/13/oracle-weblogic-server-certification1z0-108-practice-question-and-dumps/)

(Http://Www.Onlineappsdba.Com/Index.Ph
R12NewFeatures

WebLogic Startup fails with Unable to obtain lock on Server may already be running

(Http://Www.Onlineappsdba.Com/Index.Ph
NewFeatures/)

(http://www.onlineappsdba.com/index.php/2011/08/16/weblogic-startup-fails-with-unable-to-

RAC

obtain-lock-on-server-may-already-be-running/)

(Http://Www.Onlineappsdba.Com/Index.Ph

Oracle Weblogic 12c Launch : Attend online on 1 Dec 2011

Scripts

(http://www.onlineappsdba.com/index.php/2011/11/20/oracle-weblogic-12c-launch-attend-on-

(Http://Www.Onlineappsdba.Com/Index.Ph

1-dec-2011/)

Security

Oracle WebLogic 12c (12.1.1) is now available to download

(Http://Www.Onlineappsdba.Com/Index.Ph

(http://www.onlineappsdba.com/index.php/2011/12/10/oracle-weblogic-12c-1211-is-now-

ServiceRegistry

available-to-download/)
How to Install WebLogic 12C (12.1.1) on Mac

(Http://Www.Onlineappsdba.Com/Index.Ph
Registry/)
Session

(http://www.onlineappsdba.com/index.php/2011/12/11/how-to-install-weblogic-12c-1211-on-

(Http://Www.Onlineappsdba.Com/Index.Ph

mac/)

Siebel

Oracle #WebLogic Server 12c : SE vs EE vs Suite License Options

(Http://Www.Onlineappsdba.Com/Index.Ph

(http://www.onlineappsdba.com/index.php/2012/05/12/oracle-weblogic-server-12c-se-vs-ee-

Soa

vs-suite-license-options/)

(Http://Www.Onlineappsdba.Com/Index.Ph

SSL in WebLogic (CA, KeyStore, Identity & Trust Store) : Things you must know Part I

Solaris

(http://www.onlineappsdba.com/index.php/2013/02/05/ssl-in-weblogic-ca-keystore-identity-

(Http://Www.Onlineappsdba.Com/Index.Ph

trust-store-things-you-must-know-part-i/)

Ssl

SSL in WebLogic Server Part II : Create KeyStore, generate CSR, Import CERT and configure
KeyStore with WebLogic (http://www.onlineappsdba.com/index.php/2013/02/10/ssl-inweblogic-server-part-ii-create-keystore-generate-csr-import-cert-and-configure-keystore-withweblogic/)
WebLogic Admin Server Start-up hanging at Initializing self-tuning thread pool

(Http://Www.Onlineappsdba.Com/Index.Ph
Sso

(Http://Www.Onlineappsdba.Com/Index.Ph
Timesten

(Http://Www.Onlineappsdba.Com/Index.Ph
Trainings

(http://www.onlineappsdba.com/index.php/2013/03/11/weblogic-admin-server-start-up-

(Http://Www.Onlineappsdba.Com/Index.Ph

hanging-at-initializing-self-tuning-thread-pool/)

Troubleshooting

http://www.onlineappsdba.com/index.php/2008/11/22/securityinoracleweblogicrealmsecurityproviderauthenticationauthorizationusers/

6/12

4/18/2015

SecurityinOracleWebLogic:Realm,SecurityProvider,Authentication,Authorization,UsersOnlineIdentity&AccessManagement

Error in WebLogic Clustering : socket MaxMessage Size Exceeded Exception

(Http://Www.Onlineappsdba.Com/Index.Ph

(http://www.onlineappsdba.com/index.php/2013/05/31/error-in-weblogic-clustering-socket-

UCM

maxmessage-size-exceeded-exception/)

(Http://Www.Onlineappsdba.Com/Index.Ph

Changed or New Features in WebLogic 12.1.2


(http://www.onlineappsdba.com/index.php/2013/08/07/changed-or-new-features-in-weblogic12-1-2/)
WebLogic SSL configuration : Inconsistent security configuration Cannot convert identity
certificate (http://www.onlineappsdba.com/index.php/2013/08/08/weblogic-ssl-configuration-

Uddi

(Http://Www.Onlineappsdba.Com/Index.Ph
Uncategorized

(Http://Www.Onlineappsdba.Com/Index.Ph
Unix

(Http://Www.Onlineappsdba.Com/Index.Ph

inconsistent-security-configuration-cannot-convert-identity-certificate/)

Upgrade

Dynamic Cluster in WebLogic 12.1.2 : New Features in WebLogic 12c

(Http://Www.Onlineappsdba.Com/Index.Ph

(http://www.onlineappsdba.com/index.php/2013/08/26/dynamic-cluster-in-weblogic-12-1-2-

Vmware

new-features-in-weblogic-12c/)

(Http://Www.Onlineappsdba.Com/Index.Ph

Identity Propagation between two WebLogic Domains : Cross Domain Security VS Global Trust

Webcache

(http://www.onlineappsdba.com/index.php/2013/11/04/identity-propagation-between-two-

(Http://Www.Onlineappsdba.Com/Index.Ph

weblogic-domains-cross-domain-security-vs-global-trust/)

Webcenter

WebLogic Admin Server Start Up hangs at Log Management BEA-170019 IIOP subsystem

(Http://Www.Onlineappsdba.Com/Index.Ph

enabled (http://www.onlineappsdba.com/index.php/2014/01/15/weblogic-admin-server-startup-hangs-at-log-management-bea-170019-iiop-subsystem-enabled/)
Security:090294 could not get connection javax. net. ssl. SSLKeyException FATAL Alert
BAD_CERTIFICATE A corrupt or unuseable certificate was received
(http://www.onlineappsdba.com/index.php/2014/02/07/security090294-could-not-get-

Webgate

(Http://Www.Onlineappsdba.Com/Index.Ph
Weblogic

(Http://Www.Onlineappsdba.Com/Index.Ph
WindowsAd

connection-javax-net-ssl-sslkeyexception-fatal-alert-bad_certificate-a-corrupt-or-unuseable-

(Http://Www.Onlineappsdba.Com/Index.Ph
Ad/)

certificate-was-received/)

Wlst

WLST connecting to WebLogic Admin Server failed : Bootstrap to [IP:Port] failed. It is likely that the

(Http://Www.Onlineappsdba.Com/Index.Ph

remote side declared peer gone on this JVM

Workflow

(http://www.onlineappsdba.com/index.php/2014/02/18/wlst-connecting-to-weblogic-admin-

(Http://Www.Onlineappsdba.Com/Index.Ph

server-failed-bootstrap-to-ipport-failed-it-is-likely-that-the-remote-side-declared-peer-goneon-this-jvm/)

Archive

September2014
6 Responses to

Security in Oracle WebLogic : Realm, Security Provider, Authentication, Authorization, Users

Luis says:
December 9, 2008 at 12:59 pm (http://www.onlineappsdba.com/index.php/2008/11/22/securityin-oracle-weblogic-realm-security-provider-authentication-authorization-users/#comment24589)
Hello,
I have just installed Oracle BEA Weblogic 10.3 on my Linux machine and everything is working fine.
Now I am wondering how I can integrate Oracle Single Sign On with Weblogic (actually I would like to
know whether this is possible or not) or what is the best solution to implement Single Sign On on a
Weblogic environment.
Thank You
Luis

Reply (/index.php/2008/11/22/security-in-oracle-weblogic-realm-security-providerauthentication-authorization-users/?replytocom=24589#respond)

(Http://Www.Onlineappsdba.Com/Index.Ph
June2014

(Http://Www.Onlineappsdba.Com/Index.Ph
May2014

(Http://Www.Onlineappsdba.Com/Index.Ph
April2014

(Http://Www.Onlineappsdba.Com/Index.Ph
March2014

(Http://Www.Onlineappsdba.Com/Index.Ph
February2014

(Http://Www.Onlineappsdba.Com/Index.Ph
January2014

(Http://Www.Onlineappsdba.Com/Index.Ph
December2013

(Http://Www.Onlineappsdba.Com/Index.Ph
November2013

(Http://Www.Onlineappsdba.Com/Index.Ph

http://www.onlineappsdba.com/index.php/2008/11/22/securityinoracleweblogicrealmsecurityproviderauthenticationauthorizationusers/

7/12

4/18/2015

SecurityinOracleWebLogic:Realm,SecurityProvider,Authentication,Authorization,UsersOnlineIdentity&AccessManagement

Charan says:
June 6, 2009 at 10:48 am (http://www.onlineappsdba.com/index.php/2008/11/22/security-inoracle-weblogic-realm-security-provider-authentication-authorization-users/#comment-70290)
First of all thanks for providing help in WL.
Your tutorials are very good for learners.

October2013

(Http://Www.Onlineappsdba.Com/Index.Ph
September2013

(Http://Www.Onlineappsdba.Com/Index.Ph
August2013

(Http://Www.Onlineappsdba.Com/Index.Ph

could you also provide tutorials on how to install SSL certificates(step-by-step guide) and starting and

July2013

stopping server instances using node manager

(Http://Www.Onlineappsdba.Com/Index.Ph
June2013

Reply (/index.php/2008/11/22/security-in-oracle-weblogic-realm-security-provider-

(Http://Www.Onlineappsdba.Com/Index.Ph

authentication-authorization-users/?replytocom=70290#respond)

May2013

Kanchana Devi says:


July 28, 2009 at 8:54 am (http://www.onlineappsdba.com/index.php/2008/11/22/security-inoracle-weblogic-realm-security-provider-authentication-authorization-users/#comment-75383)
Hi Atul,

(Http://Www.Onlineappsdba.Com/Index.Ph
April2013

(Http://Www.Onlineappsdba.Com/Index.Ph
March2013

(Http://Www.Onlineappsdba.Com/Index.Ph

We are facing a strange issue in Myrealms of staging domain. we have configured the Active directory

February2013

authenticator for provider. in AD we have arround 1300 users. so when we click on myrealms and users

(Http://Www.Onlineappsdba.Com/Index.Ph

and groups tab it takes 8 minutes to display all the users.

January2013

but in Test domain this is not the case, we have only 600+ users and it takes only 3 seconds to display
them all.
so i did lot of test to check if user limitation is there in WL. and found till 990 it displays faster but it
crosses even one user it takes 8 minutes.

(Http://Www.Onlineappsdba.Com/Index.Ph
December2012

(Http://Www.Onlineappsdba.Com/Index.Ph
November2012

(Http://Www.Onlineappsdba.Com/Index.Ph

do you have any comments or suggestion to this.

October2012

as we have arround 10 thousand users in Production and we have to resolve this issue.

(Http://Www.Onlineappsdba.Com/Index.Ph

thanks a lot for your help!!.


-Kanchana

September2012

(Http://Www.Onlineappsdba.Com/Index.Ph
August2012

Reply (/index.php/2008/11/22/security-in-oracle-weblogic-realm-security-provider-

(Http://Www.Onlineappsdba.Com/Index.Ph

authentication-authorization-users/?replytocom=75383#respond)

July2012

(Http://Www.Onlineappsdba.Com/Index.Ph

Jayesh says:

June2012

July 29, 2009 at 12:20 pm (http://www.onlineappsdba.com/index.php/2008/11/22/security-in-

(Http://Www.Onlineappsdba.Com/Index.Ph

oracle-weblogic-realm-security-provider-authentication-authorization-users/#comment-75486)

May2012

Hi Atul,

(Http://Www.Onlineappsdba.Com/Index.Ph
April2012

I have the follwing environment..

(Http://Www.Onlineappsdba.Com/Index.Ph

Oracle ADF Application deployed on oracle weblogic 10g r3 server.

March2012

Implemented ADF authentication and Authorization that uses JAAS.

(Http://Www.Onlineappsdba.Com/Index.Ph

Configured a Active Directory LDAP(i.e. ADAM) as the Security provider.

February2012

(Http://Www.Onlineappsdba.Com/Index.Ph

ADF Authentication and Authorization is working well, when we create user in Weblogic LDAP(embedded

January2012

LDAP server) and assign group to it.

(Http://Www.Onlineappsdba.Com/Index.Ph

The issue I have is as follows:

December2011

(Http://Www.Onlineappsdba.Com/Index.Ph

In my AD LDAP We dont have group stored.

November2011

if i login through any AD LDAP user it is giveing unauthorized error.

(Http://Www.Onlineappsdba.Com/Index.Ph

http://www.onlineappsdba.com/index.php/2008/11/22/securityinoracleweblogicrealmsecurityproviderauthenticationauthorizationusers/

8/12

4/18/2015

SecurityinOracleWebLogic:Realm,SecurityProvider,Authentication,Authorization,UsersOnlineIdentity&AccessManagement

I dont want to have groups in my AD LDAP and get authorized.


Please help in solving this.

October2011

(Http://Www.Onlineappsdba.Com/Index.Ph
September2011

Reply (/index.php/2008/11/22/security-in-oracle-weblogic-realm-security-provider-

(Http://Www.Onlineappsdba.Com/Index.Ph

authentication-authorization-users/?replytocom=75486#respond)

August2011

Paul says:
May 4, 2010 at 3:19 pm (http://www.onlineappsdba.com/index.php/2008/11/22/security-inoracle-weblogic-realm-security-provider-authentication-authorization-users/#comment-99130)
Hi Atul,

(Http://Www.Onlineappsdba.Com/Index.Ph
July2011

(Http://Www.Onlineappsdba.Com/Index.Ph
June2011

(Http://Www.Onlineappsdba.Com/Index.Ph

After the installation of the WebLogic and WebCenter, everything looks working fine. Only one thing I

May2011

dont see on the top of the webCenter Spaces, and that is Administrator menu on the top. I looked at the

(Http://Www.Onlineappsdba.Com/Index.Ph

weblogic admin user group and it is set to default administrator. Any thoughts/idea on this problem?

April2011

The weblogiv version is 10.3.2 & webcenter Spaces version is 11.1.1.2

(Http://Www.Onlineappsdba.Com/Index.Ph

Thanks for your time.

March2011

(Http://Www.Onlineappsdba.Com/Index.Ph

Best Regards,

February2011

Paul.

(Http://Www.Onlineappsdba.Com/Index.Ph
January2011

Reply (/index.php/2008/11/22/security-in-oracle-weblogic-realm-security-provider-

(Http://Www.Onlineappsdba.Com/Index.Ph

authentication-authorization-users/?replytocom=99130#respond)

December2010

Mike says:
February 17, 2012 at 1:16 pm (http://www.onlineappsdba.com/index.php/2008/11/22/security-

(Http://Www.Onlineappsdba.Com/Index.Ph
November2010

(Http://Www.Onlineappsdba.Com/Index.Ph

in-oracle-weblogic-realm-security-provider-authentication-authorization-users/#comment-

October2010

207987)

(Http://Www.Onlineappsdba.Com/Index.Ph

We have some Web Services written in Java that are secured using the WebLogic myrealm security

September2010

realm.

(Http://Www.Onlineappsdba.Com/Index.Ph

Is there a way for the protected Web Service to retrieve the User ID from the credentials used to access
the service?

August2010

(Http://Www.Onlineappsdba.Com/Index.Ph
July2010

Reply (/index.php/2008/11/22/security-in-oracle-weblogic-realm-security-provider-

(Http://Www.Onlineappsdba.Com/Index.Ph

authentication-authorization-users/?replytocom=207987#respond)

June2010

(Http://Www.Onlineappsdba.Com/Index.Ph
Leave a Reply

Name *
Email (will not be published) *
Website

May2010

(Http://Www.Onlineappsdba.Com/Index.Ph
April2010

(Http://Www.Onlineappsdba.Com/Index.Ph
March2010

(Http://Www.Onlineappsdba.Com/Index.Ph
February2010

Comment

(Http://Www.Onlineappsdba.Com/Index.Ph
January2010

(Http://Www.Onlineappsdba.Com/Index.Ph
December2009

(Http://Www.Onlineappsdba.Com/Index.Ph
November2009

(Http://Www.Onlineappsdba.Com/Index.Ph
SUBMIT COMMENT

http://www.onlineappsdba.com/index.php/2008/11/22/securityinoracleweblogicrealmsecurityproviderauthenticationauthorizationusers/

9/12

4/18/2015

SecurityinOracleWebLogic:Realm,SecurityProvider,Authentication,Authorization,UsersOnlineIdentity&AccessManagement

October2009

(Http://Www.Onlineappsdba.Com/Index.Ph
September2009

(Http://Www.Onlineappsdba.Com/Index.Ph
August2009

(Http://Www.Onlineappsdba.Com/Index.Ph
July2009

(Http://Www.Onlineappsdba.Com/Index.Ph
June2009

(Http://Www.Onlineappsdba.Com/Index.Ph
May2009

(Http://Www.Onlineappsdba.Com/Index.Ph
April2009

(Http://Www.Onlineappsdba.Com/Index.Ph
March2009

(Http://Www.Onlineappsdba.Com/Index.Ph
February2009

(Http://Www.Onlineappsdba.Com/Index.Ph
January2009

(Http://Www.Onlineappsdba.Com/Index.Ph
December2008

(Http://Www.Onlineappsdba.Com/Index.Ph
November2008

(Http://Www.Onlineappsdba.Com/Index.Ph
October2008

(Http://Www.Onlineappsdba.Com/Index.Ph
September2008

(Http://Www.Onlineappsdba.Com/Index.Ph
August2008

(Http://Www.Onlineappsdba.Com/Index.Ph
July2008

(Http://Www.Onlineappsdba.Com/Index.Ph
June2008

(Http://Www.Onlineappsdba.Com/Index.Ph
May2008

(Http://Www.Onlineappsdba.Com/Index.Ph
April2008

(Http://Www.Onlineappsdba.Com/Index.Ph
March2008

(Http://Www.Onlineappsdba.Com/Index.Ph
February2008

(Http://Www.Onlineappsdba.Com/Index.Ph
January2008

(Http://Www.Onlineappsdba.Com/Index.Ph
December2007

(Http://Www.Onlineappsdba.Com/Index.Ph
November2007

(Http://Www.Onlineappsdba.Com/Index.Ph

http://www.onlineappsdba.com/index.php/2008/11/22/securityinoracleweblogicrealmsecurityproviderauthenticationauthorizationusers/

10/12

4/18/2015

SecurityinOracleWebLogic:Realm,SecurityProvider,Authentication,Authorization,UsersOnlineIdentity&AccessManagement

October2007

(Http://Www.Onlineappsdba.Com/Index.Ph
September2007

(Http://Www.Onlineappsdba.Com/Index.Ph
August2007

(Http://Www.Onlineappsdba.Com/Index.Ph
July2007

(Http://Www.Onlineappsdba.Com/Index.Ph
June2007

(Http://Www.Onlineappsdba.Com/Index.Ph
May2007

(Http://Www.Onlineappsdba.Com/Index.Ph
April2007

(Http://Www.Onlineappsdba.Com/Index.Ph
March2007

(Http://Www.Onlineappsdba.Com/Index.Ph
February2007

(Http://Www.Onlineappsdba.Com/Index.Ph
January2007

(Http://Www.Onlineappsdba.Com/Index.Ph
December2006

(Http://Www.Onlineappsdba.Com/Index.Ph
November2006

(Http://Www.Onlineappsdba.Com/Index.Ph
October2006

(Http://Www.Onlineappsdba.Com/Index.Ph
September2006

(Http://Www.Onlineappsdba.Com/Index.Ph
August2006

(Http://Www.Onlineappsdba.Com/Index.Ph
July2006

(Http://Www.Onlineappsdba.Com/Index.Ph

Previous Post (http://www.onlineappsdba.com/index.php/2008/11/21/verify-cbo-statsand-database-initalization-parameters-for-11i/)


Next Post (http://www.onlineappsdba.com/index.php/2008/11/24/upgrade-oracleapplication-server-to-10134-10g-r3-patchset-4/)

About k21 technologies

K21 Technologies is among the most experienced Oracle Gold Partner for Identity Access Management service providers. We work with application development
companies and in-house technology division to help achieve significant returns on their IT security investment. Our clientele includes some of the globally renowned
corporate, which speaks of our expertise in our field.
We have the most talented and experienced team that can swiftly deploy security solutions even in complex IT ecosystem. Our clients highly appreciate our timely
implementation, interactive training, on-demand support and community resources.

COMPANY

Client Testinomial (http://k21technologies.com/client-testinomial/)

http://www.onlineappsdba.com/index.php/2008/11/22/securityinoracleweblogicrealmsecurityproviderauthenticationauthorizationusers/

11/12

4/18/2015

SecurityinOracleWebLogic:Realm,SecurityProvider,Authentication,Authorization,UsersOnlineIdentity&AccessManagement

Mission & Values (http://k21technologies.com/mission-values/)


Our Clients (http://k21technologies.com/our-clients/)

SERVICES

Mobile Application Security (http://k21technologies.com/security-in-mobile-application/)


Cloud Application Security (http://k21technologies.com/security-in-cloud-application/)
IAM Implementation (http://k21technologies.com/oracle-identity-access-management-implementation/)
IAM Health Check (http://k21technologies.com/iam-health-check/)
Implementation (http://k21technologies.com/consulting-and-implementation/)
Support (http://k21technologies.com/support/)

PRODUCTS

Training (http://trainings.k21technologies.com/)

RESOURCES

Case Studies (http://k21technologies.com/case-studies/)


User Groups (http://k21technologies.com/user-groups/)
Books (http://k21technologies.com/books/)
Events (http://k21technologies.com/events/)
FRIENDS OF K21 (http://k21technologies.com/friends-of-k21/)
Career (http://k21technologies.com/career/)

CONTACTS

K21 Technologies
8 Magnolia Place, Harrow,
London, HA2 6DS

UK: +44(0)7476444481
USA: +1-888-414-1821

2014,K21Technologies.AllrightsreservedDMCA.com

http://www.onlineappsdba.com/index.php/2008/11/22/securityinoracleweblogicrealmsecurityproviderauthenticationauthorizationusers/

12/12