Search This Blog

Monday, 4 January 2016

Difference between Oracle Directory Services: OID: OUD: ODSEE: OVD: DIP

If you have just started exploring Identity Management and came across different similar sounding three letter words such as OID, OVD, OUD, blah, blah – and wondering what the heck is the difference between them when they all almost sound similar and all have something to do with directory services – you are not the only one.

Why do we have different similar components offered by same company? Well, each has something different to offer, some brownie features. 

In this article, I will try to highlight main points of all the different products for directory management in 11g of the Fusion Middleware stack offered by Oracle and difference between them.

What is a Directory Service? A directory service is something that provides information about people and resources to a client requesting information. For eg: Phone Book. The information may be a name, a telephone number, an email address, application preferences, group memberships, and so on. The client may be a person and/or application.

As of today, Oracle has 3 different LDAP directories.

a) Oracle Internet Directory (OID)

b) Oracle Directory Server Enterprise Edition (ODSEE)

c) Oracle Unified Directory (OUD).

There’s two other products which are related to directory services:-

d) Directory Integration Platform(DIP)

e) Oracle Virtual Directory (OVD)

Now,  lets see the main points of each component.


Oracle Internet Directory (OID)


a) OID was totally developed by Oracle. 
b) OID is written in Java and C language
c) OID requires an Oracle Enterprise Edition database to be used as physical storage media.
d) Oracle will be releasing security patches and will be enhancing the product as well purely because there are some Oracle products that still require the OID architecture.


Oracle Directory Server Enterprise Edition (ODSEE)


a) ODSEE is SUNs implementation of LDAP. It is a BEST known directory server with proven large deployments in carrier and enterprise environments.
b) ODSEE has got its own embedded database to physically store the LDAP information.
c) It has a directory server and a replication server associated with ODSEE. So we can replicate data from one ODSEE directory to another ODSEE directory as well.
d) ODSEE is now in Maintenance mode from here on. So basically it is still supported but no new features are going to be introduced in this.


Oracle Unified Directory (OUD)


a) OUD is the latest of three LDAP directories. Its is based on the OpenDS standard which was originally developed by SUN.
b) OUD is purely based on Java. A pure Java solution simplifies multiplatform support, deployment, and ongoing maintenance.
c) OUD has an embedded database(Berkeley database) associated with it. It's a small & lightweight but still, it is very fast and robust database to physically hold the LDAP information.
d) OUD can also act as Replication or Proxy servers. Proxy servers can either be used for load balancing or data distribution. 
e) OUD is the preferred (if possible) Directory services, recommended by Oracle for all new development and new deployments.


Directory Integration Platform (DIP)


a) Directory Integration Platform is a product associated with the directory services which is a general-purpose synchronization solution that supports numerous data sources, including OUD 11g.
b) DIP provides the following services for synchronizing identity data from authoritative sources such as LDAP directories and databases:
1) Keeping data and groups synchronized between LDAP directories including OUD 11g, OID, DSEE and Microsoft Active Directory.
2) Keep passwords synchronized between LDAP directories and OUD 11g
3) Synchronizing data between OUD 11g and relational databases
4) Translating attributes and data between OUD 11g and other authoritative sources
c) In 10g, DIP was part of OID architecture. In 11g this has been stripped out and runs as a standalone product that is deployed on a WebLogic server. 
d) There are only five different types of LDAP directories we can synchronize data with using DIP; SUN directories, Active Directory, Novell eDirectory, OpenLDAP, and IBM Tivoli. 
e) Using DIP, we can import information in OID from an Oracle database but can't write it back to database. And it needs to be an Oracle database, not any other database.
f) Most of the things achieved by DIP, can also be done via OIM which is slightly more flexible.


Oracle Virtual Directory (OVD)


a) OVD does not have any available storage media.
b) OVD server is a Java server process that runs outside of WebLogic Domain.
c) OVD is basically a virtual representation of an LDAP directory. Beneath it, we can have AD, OID or OUD or ODSEE or a database. Using adaptors in OVD, we can decide what to connect to.

Sunday, 3 January 2016

Creating Post-Process Event Handler to Create Email-ID in OIM for Users created through Flat File

A Post-Process Event handler are consequent operations related to the current operation taking place. Eg: In our case we want E-Mail ID to be created for the user in OIM as soon as the user is successfully created.

Now to create the post-process event handler we need to implement PostProcessHandler interface.

Below are the 2 ways in which a user can be created in OIM:
1. Using Create option from OIM Identity Console
2. Using Bulk Upload like Flat-File

Now to handle these 2 cases, we use below 2 methods as described by PostProcessHandler interface:

1. public EventResult execute(long l, long l1, Orchestration orchestration)
2. public BulkEventResult execute(long l, long l1,                 BulkOrchestration bulkOrchestration)

Below is the complete code to implement the logic:

package com.iam.oim;

import com.scb.db.DBUtil;

import java.io.Serializable;
import java.sql.Connection;
import java.sql.PreparedStatement;

import java.sql.ResultSet;

import java.util.HashMap;

import oracle.core.ojdl.logging.ODLLogger;

import oracle.iam.platform.Platform;
import oracle.iam.platform.kernel.spi.PostProcessHandler;
import oracle.iam.platform.context.ContextAware;
import oracle.iam.platform.entitymgr.EntityManager;
import oracle.iam.platform.kernel.vo.AbstractGenericOrchestration;
import oracle.iam.platform.kernel.vo.BulkEventResult;
import oracle.iam.platform.kernel.vo.BulkOrchestration;
import oracle.iam.platform.kernel.vo.EventResult;
import oracle.iam.platform.kernel.vo.Orchestration;

public class generateEmailID implements PostProcessHandler{

    private ODLLogger logger = ODLLogger.getODLLogger(Constant.LOGGER_NAME);
    private static final String CLASS_NAME="com.scb.oim.generateEmailID";
    
    /**
     * This method is used to remove any spaces present in the string
     * @param userName
     * @return
     */
    
    private String removeSpaces(String userName){
        userName=userName.replaceAll("-","");
        userName=userName.replaceAll(" ","");
        userName=userName.replaceAll("","");
        return userName;
    }
    
    /**
     * Thsi method is used to fetch the User Details like FirstName, MiddleName, LastName etc.
     * @param parameters
     * @param key
     * @return
     */
    
    private String getParamaterValue(HashMap<String, Serializable> parameters, 
      String key) {
      String value = (parameters.get(key) instanceof ContextAware)
      ? (String) ((ContextAware) parameters.get(key)).getObjectValue()
      : (String) parameters.get(key);
      return value;
    }
    
    /**
     * This method will generate the E-Mail Address based on the logic, like FirstName.LastName@xyz.com or FirstNameMiddleName.LastName@xyz.com
     * @param FN
     * @param MN
     * @param LN
     * @param counter
     * @return
     */
    
    private String generateEmailID(String FN, String MN, String LN, int counter) {
        
        String methodName= "generateEmailID";
        logger.entering(CLASS_NAME, methodName);
        String address = "@xyz.com";
        String emailID = "";
        String count = "";
        
        if(counter > 0){
            count = Integer.toString(counter);
        }
        
        if(MN.equalsIgnoreCase("Null")){
            emailID = ((FN.concat(".")).concat(LN)).concat(count).concat(address);
            logger.info("Generate Email ID: "+emailID);
        }
        else{
            emailID = (((FN.concat(MN)).concat(".")).concat(LN)).concat(count).concat(address);
            logger.info("Generate Email ID: "+emailID);
        }
        logger.exiting(CLASS_NAME, methodName);
        return emailID;
    }
    
    /**
     * This method will check for the uniqueness of the generated Email ID by validting against OIM DB
     * @param email
     * @param Conn
     * @return
     */

    private String checkEmailID(String email, Connection Conn) {
      
      String methodName = "checkEmailID";
      
      logger.entering(CLASS_NAME, methodName);
      String flag =  "Unique";
      int Count = 0;
      PreparedStatement ps = null;
      ResultSet rs = null;
      
      try{
          ps = Conn.prepareStatement(Constant.SQL_SELECT_EMAIL_ID);
          ps.setString(1, email);
          rs = ps.executeQuery();
          
          while(rs.next()){
              Count = rs.getInt(1);
              logger.info("Count: "+Count);
          }
          if(Count>0){
              flag = "Duplicate";
              logger.info("Generated Email ID already exists: "+email);
          }
          else{
              logger.info("Generate Email ID is Unique: "+email);
          }
          logger.exiting(CLASS_NAME, methodName);
          return flag;
      }
        catch (Exception e){
                logger.severe("Exception inside get checkEmailID"+e.getMessage());
        }finally{
                try{
                    if (ps != null){
                            ps.close();
                    }
                    if(rs!=null){
                            rs.close();
                    }
                }catch(Exception e){
                        logger.severe("Exception while closing the ps and rs"+e.getMessage());
                }
        }
      
      return flag;
    }
    
    /**
     * Main Class that executes the PostProcess Event Handler
     * @param parameterHashMap
     * @param targetType
     * @param targetId
     */
    private void executeEvent(HashMap parameterHashMap, String targetType, String targetId) {
        
        Connection oimConnection=DBUtil.getOIMConnection();
        
        if(targetId!=null){
            try{
                    EntityManager mgr = Platform.getService(EntityManager.class);
                    String flag = "Duplicate";
                    int i = 0;
                    
                    //Fetching FirstName, MiddleName and LastName of User to generate Email ID
                    
                    String FirstName = getParamaterValue(parameterHashMap, "First Name");
                    String MiddleName = getParamaterValue(parameterHashMap, "Middle Name");
                    String LastName = getParamaterValue(parameterHashMap, "Last Name");
                    logger.info("First Name: "+FirstName);
                    logger.info("Middle Name: "+MiddleName);
                    logger.info("Last Name: "+LastName);
                   
                    HashMap<String, Object> modParams = new HashMap<String, Object>(); 
                    
                    if((FirstName == null || (FirstName.length() == 0))&&(LastName == null || (LastName.length() == 0))){
                        logger.info("Invalid First Name or Last Name");
                        System.exit(0);
                    }
                    else{
                        
                        if(MiddleName == null || (MiddleName.length() == 0)){
                            MiddleName= "Null";
                            logger.info("Middle Name is NULL!!!!");
                        }
                        
                        FirstName = removeSpaces(FirstName);
                        MiddleName = removeSpaces(MiddleName);
                        LastName = removeSpaces(LastName);
                        
                        
                        
                        String genEmail = generateEmailID(FirstName, MiddleName, LastName, i);
                        
                        //Check if generated Email ID is unique
                        flag = checkEmailID(genEmail, oimConnection);
                        
                        while (flag.equalsIgnoreCase("Duplicate")){
                            i = i+1;
                            genEmail = generateEmailID(FirstName, MiddleName, LastName, i);
                            flag = checkEmailID(genEmail, oimConnection);
                        }
                        if(flag.equalsIgnoreCase("Unique")){
                            modParams.put("Email", genEmail);
                            mgr.modifyEntity(targetType, targetId, modParams);
                            logger.info("USER Modified SUCCESSFULLY WITH EMAIL ID: "+genEmail);
                        }
                    }
                }catch(Exception e){
                    logger.severe("Exception inside executeEvent()"+e.getMessage());
                }finally{
                try{
                    if(oimConnection!=null){
                        oimConnection.close();
                    }
                }catch(Exception e){
                    logger.severe("Exception occured while closing Connection"+e.getMessage());
                }
        }
        }
    
    }
    
    /**
     * This method is called to when a user is created using Identity Console
     * @param l
     * @param l1
     * @param orchestration
     * @return
     */
    
    public EventResult execute(long l, long l1, Orchestration orchestration) {
        
        String methodName = "EventResult()";
        logger.entering(CLASS_NAME, methodName);
        
        HashMap<String, Serializable> parameters = orchestration.getParameters();
    
        logger.info(String.format("Parameters: ", parameters));
        
        String targetType = orchestration.getTarget().getType();
        String entityID = orchestration.getTarget().getEntityId();
        
        logger.info("Target Type: "+targetType);
        logger.info("Entity ID: "+entityID);
        
        try {  
                    executeEvent(parameters,orchestration.getTarget().getType(), orchestration.getTarget().getEntityId());  
                     
               } catch (Exception e) {  
                   e.printStackTrace();  
               }
        logger.exiting(CLASS_NAME, methodName);
        return new EventResult();
    }

    /**
     * This method is called to when a users are created using Flat File or Bulk Upload Utility
     * @param l
     * @param l1
     * @param bulkOrchestration
     * @return
     */
    
    public BulkEventResult execute(long l, long l1,
                                   BulkOrchestration bulkOrchestration) {
                logger.info("Executing BULK operation");  
                HashMap<String, Serializable>[] bulkParameters = bulkOrchestration.getBulkParameters();  
                  
                String[] entityIds = bulkOrchestration.getTarget().getAllEntityId();  
                  
                for (int i = 0; i < bulkParameters.length; i++) {  
            
                    try {  
                       executeEvent(bulkParameters[i],bulkOrchestration.getTarget().getType(), entityIds[i]);  
                    } catch (Exception e) {  
                        e.printStackTrace();  
                    }  
                }  
          
                return new BulkEventResult();  
    }

    public boolean cancel(long l, long l1,
                          AbstractGenericOrchestration abstractGenericOrchestration) {
        return false;
    }

    public void compensate(long l, long l1,
                           AbstractGenericOrchestration abstractGenericOrchestration) {
    }

    public void initialize(HashMap<String, String> hashMap) {
    }
}

In my case I have 2 more files that need to be used to make this code work. I have defined a separate class to establish OIM DB Connection which is as below and the same has been referred from above code:

package com.iam.db;

import java.sql.Connection;

import oracle.iam.platform.Platform;

public class DBUtil {
    public static Connection getOIMConnection() {
        Connection conn = null;

        try {
            conn = Platform.getOperationalDS().getConnection();
            return conn;
        } catch (Exception e) {
            e.printStackTrace();
        }
        return conn;
    }

}

Last class is just to define the final contants and thus I have named it as Constant.java

package com.iam.oim;

public class Constant {
    public static final String LOGGER_NAME = "com.scb.oim.generateEmailID";
    public static final String SQL_SELECT_EMAIL_ID="select count(*) from usr where usr_email = ?";

}

Tuesday, 11 August 2015

Configuring BI Publisher to use OVD as authenticator

This post will show the steps to configure OVD as authenticator for BI Publisher i.e users accounts coming from OVD can login to BI Publisher.

Below steps need to be followed to accomplish the same:

Open the BI Domain console and navigate to Realms-> myrealm->Providers. Below page is displayed(OVD Authenticator will not be listed there as we need to configure the same):


Now click on New to configure OVD Authenticator:


Provide a name for Authenticator and Type as OracleVirtualDirectoryAuthenticator  as displayed in the screenshot above. Click OK to save.

Once the Authenticator is created, we need to provide configuration parameters for the same as below:

Under Configuration->Common, select Control Flag as SUFFICIENT.


Now click on Configuration->Provider Specific to provide the other configuration parameters as below:


Provide the below details and click SAVE to save the configuration:
Host, Port, Principal, Credential, Confirm Credential, check SSL Enabled, User Base DN, User Object Class, Group Base DN, Dynamic Group Name Attribute

RESTART THE ENTIRE BI-DOMAIN.

Once the system is restarted, navigate to Security Realms->myrealm->Users and Groups and search if BISystemUser appear in the list as shown below:


Now navigate to Roles and Policies->Realm Roles->Global Roles->Roles->Admin and click on View Roles Conditions:


Click on Add Conditions, select User from drop-down, click Next. Now enter BISystemUser in User Argument Name and click Add to add it to the conditions list and then click Finish and then click Save on below page to save the changes.


Now the similar thing needs to be done for JMS Module. Navigate to Services->Messaging->JMS Modules


Click on BipJMSResource. Navigate to Security Tab and add the condition for BISystemUser there as below:


Now, open EM console and do the following changes there:

Navigate to Weblogic Domain->bifoundation_domain and select it. From drop-down select Security->Application Roles. In the field Application Stripe, select obi and then click the search image, click the BISystem application role and click Edit Link. Once the user is successfully added, it will appear in the list as below:


Now select Security->Security Provider Configuration from drop-down. Now expand the Identity Store Provider and click on Configure Button and the add the following properties[user.login.attr = cn, PROPERTY_ATTRIBUTE_MAPPING = GUID=sn, username.attr = cn, virtualize = true] and click OK to save the configuration:


Now Restart the entire BI-environment and check the logs of bi_server1 for any possible errors related to Identity Store, else we are good to go.

Now take a user from OVD and try to authenticate into BI Publisher, user should be able to authenticate.

Monday, 10 August 2015

Manually Revoking a Resource Object using Database

Have you ever had a Resource Object stuck in a Pending or Provisioning state that you just couldn't do anything about? This happens a lot when first setting up a Resource Object and running Revoke before you create the Revoke tasks. The status will stay on "Provisioned" but all the tasks inside will say "Cancelled" and there's nothing more you can do to it. If you only allow one instance that user is now stuck.

To revoke a struck Resource Object, first we need to search the Resource Object which user has, along with their statuses and necessary keys required later to revoke the RO. Below is the query:

select oiu.oiu_key, oiu.obi_key, oiu.orc_key, ost.ost_status, obj.obj_name, obj.obj_key,oiu.req_key
from oiu inner join ost on oiu.ost_key = ost.ost_key inner join obi on oiu.obi_key = obi.obi_key

inner join 
obj on obi.obj_key = obj.obj_key where oiu.usr_key=(select usr_key from usr where usr_login='USER ID');

Look at the results and find the line that has the stuck object and save the OIU_KEY and the OBJ_KEY.


Next we need the key for this Object's Revoked status. Each Object has it's own set of Status Codes, so to find the ones for our object above, run this query and replace OBJ_KEY with the OBJ_KEY number from the first query above:

select * from OST where obj_key = 'OBJ_KEY';

Look at the results and find the line where the OST_STATUS is "Revoked" and save the OST_KEY.

Next we will update the Object Instance, and set it's status to the new key. If you want to see the current record in it's bare naked form run this (Replace OIU_KEY with the OIU_KEY from the first query):

select * from oiu where OIU_KEY = 'OIU_KEY';

You will see in the results the OST_KEY column. This is the current status of your Resource Object. This is what we are going to change to the new status. So let's run this query, replacing OST_KEY with the OST_KEY from the second query and OIU_KEY with the OIU_KEY from the first query:

update oiu set ost_key = 'OST_KEY' where oiu_key='OIU_KEY';


Perform a Commit and that's it. Pull up the resource profile for the user in the web console and you should see the status for that resource object is now "Revoked".