# Step 2: Configure the Service Provider — Oracle Access Manager (OAM)

## Configure the Service Provider — Oracle Access Manager (OAM)

Oracle Access Manager (OAM) will be configured through its web-based management console, referred to as the **OAM Console**.\
You can access it via the following URL (example):\
\&#xNAN;**`http://test.public.myvcn.oraclevcn.com:7001/oamconsole`**

{% hint style="info" %}
&#x20;Note: This URL is provided as an example. Use the actual address of your OAM Console depending on your environment.
{% endhint %}

To log in, use the **WebLogic administrator account** (default username: `weblogic`) and the password provided during installation.

***

## **1. Enable Federation Services**

* In the OAM Console, go to **Configuration > Available Services**
* Click the **"Enable Service"** button next to **Identity Federation**
* Make sure the service status changes to **"Enabled"**

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXc2gFYFEI6usY_C9ADk4Os6y8i8xmXFfG0j6y08XoW3962vSnn7xJhGMp942vKfF9RCHkCfJZmTIArY7zERGoz8feL53eWZaaKRHafvBTi4_H5WWFbyHxtO01VJ4QJI1ay2Jd9sSA?key=flYwr8QHc9296S5s6V_SpI0A" alt=""><figcaption></figcaption></figure>

***

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXd_SQ-mHnq651WKqQyunjLI07WgODSFrLBwTk32HMLYDMpOPxN_XmHC2ctUtjZKtK4A5cbAsXecLL2ECvAkAyFGKOIhMC7mSrV22PIXxRyTm47DY31bBKHZtDc0P-Ip0Q1Wn8rJkA?key=flYwr8QHc9296S5s6V_SpI0A" alt=""><figcaption></figcaption></figure>

***

### **2. Configure HTTPS settings**

* Navigate to **Configuration > Settings > Access Manager**
* Update the required HTTPS parameters according to your environment\
  \&#xNAN;*(refer to the relevant configuration screenshot, if available)*

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXdrSX3rIPRgdzhlyE5x4UsvTSqpsxN3Gpg_MjtcosnsJEXTVhMtDCDL-NtTMCG3OGuLufkOSFkBBzmZNFGnMhXQnPpD8zGBfgh-HOtGcxmSJYDTjZPp5izGttP4hoVQqcF650XhTA?key=flYwr8QHc9296S5s6V_SpI0A" alt=""><figcaption></figcaption></figure>

***

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXfvxm8zwAexcKAdUJ4mENyaq_0xrESgKF1TjLGEaJDZiwTa-eyzDogk_OEcgfjX8q2GPp3Jd_5pTZSRmZMAvghU4NdafNKjQTQaSFt9-N5MgOXH8LaGr4dHJ_HieUmvs5CTDNaHVA?key=flYwr8QHc9296S5s6V_SpI0A" alt=""><figcaption></figcaption></figure>

### **3. Configure Federation Settings and Export Metadata**

* Go to **Configuration > Settings > Federation**
* Update the federation parameters as shown in the screenshot
* Click **"Export SAML 2.0 Metadata…"** and save the file

{% hint style="info" %}
This metadata will be imported into **Hideez Enterprise Server (HES)** during Identity Provider (IdP) configuration.
{% endhint %}

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXfsR8X7g-s4Oa8dStERWSvunHKqEh6m80FW48Wry8MnN3_a_c96oWFMRGzrpd61vp-KuYjWkaMSksKyyXp6jAVgOVjgZHImFRtqT8TUpmJZH630U40_2XMIox3Y_7XqXGeBqUejqg?key=flYwr8QHc9296S5s6V_SpI0A" alt=""><figcaption></figcaption></figure>

***

### **4. Create Oracle Internet Directory (OID) Identity Store**

* Navigate to **Configuration > User Identity Stores**

This store will be used to authenticate and authorize users in **Oracle Business Intelligence Enterprise Edition (OBIEE)**.

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXdkWGragVjmIy9rKvcEKUBKjBhbKhzku5lA-Jwoqs6tno905XOJNQzlYo6nr_GfVi1Ub6kOsyNZhrIqFbFovLJUU1xfdailPwJL5mbI_jXXAAve5e0TU6AwyQrw7D6eY-jaAOk6Ig?key=flYwr8QHc9296S5s6V_SpI0A" alt=""><figcaption></figcaption></figure>

* Click **"Create"** and provide the necessary connection details for **Oracle Internet Directory (OID)**

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXdbJFPceyItgZz8KO8DCONSq8dhR72J2Hzs7JvKqNG-8-oHhnON-lGgM-Hir3ti1flINcCVwx99Dn5ZJLrep8ze7oqiBISNSCk8o_cn_Cp9xZ8MunIpGlyPREW94jJJDXJDGCUvcg?key=flYwr8QHc9296S5s6V_SpI0A" alt=""><figcaption></figcaption></figure>

***

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXemYXSTlsbCT5IbQXXHO6ZqMp9kp3V3Y30kwhCiGmyZn8LS3kWvUqS4cNwU8eF50E4Mxqg8fpYhCG8W4JMpdT1CcyStZA9F8xOPx1W0KFfBaDjslYsQWNN3afqO-JAQOiahBoTC?key=flYwr8QHc9296S5s6V_SpI0A" alt=""><figcaption></figcaption></figure>

### **5. Create SAML 2.0 Service Provider**

* Go to **Federation > Service Provider Management**
* Click **"Create"** and fill in the required fields
* Click **"Browse"** and select the **IdP metadata file** downloaded from HES
* Click **"Authentication Scheme and Module"** to finalize the configuration

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXeGU1EllyVXcFXV5gHb3PKesSl_hMSPrGJVtNbZIdo0F3WRbN_R2c_9qlmXw5Va4Y_A6SnY4Fv0Dq_sXdAdSCTmIcia5hqSJYh1vjdgWon21TSmznnaWvwLZPWzhtjQHzHEKdlK?key=flYwr8QHc9296S5s6V_SpI0A" alt=""><figcaption></figcaption></figure>

***

### **6. Create OAM Agent and Application Domain for OBIEE**

* Open an SSH session to the OAM host
* Navigate to the following directory:\
  `$OAM_HOME/idm/oam/server/rreg/input`
* Create a file named `bi_sso.xml` with the required configuration (provided in the next section)

```xml
<OAM11GRegRequest>
    <serverAddress>http://test.public.myvcn.oraclevcn.com:7001</serverAddress>
    <hostIdentifier>TEST_BI_HostId</hostIdentifier>
    <agentName>TEST_BI_OAM</agentName>
    <agentBaseUrl>http://test.public.myvcn.oraclevcn.com:7777</agentBaseUrl>
    <applicationDomain>TEST_BI_OAM</applicationDomain>
	<security>open</security>
	<logOutUrls>
    		<url>/analytics/saw.dll?Logoff</url>
	</logOutUrls>
    <protectedResourcesList>
        		<resource>/aps/SmartView/**</resource>
		<resource>/aps/SmartView/*</resource>
		<resource>/cds/**</resource>
		<resource>/cds/*</resource>
		<resource>/va/**</resource>
		<resource>/va*</resource>
		<resource>/dv/**</resource>
		<resource>/dv*</resource>
		<resource>/mobile/.../*</resource>
		<resource>/mobile/**</resource>
		<resource>/mobile*</resource>
		<resource>/bisearch/**</resource>
		<resource>/bisearch*</resource>
		<resource>/bicomposer/**</resource>
		<resource>/bicomposer*</resource>
		<resource>/mapviewer/mcsadmin/**</resource>
		<resource>/mapviewer/mcsadmin*</resource>
		<resource>/mapviewer/mapadmin/**</resource>
		<resource>/mapviewer/mapadmin*</resource>
		<resource>/mapviewer/console/**</resource>
		<resource>/mapviewer/console*</resource>
		<resource>/mapviewer/**</resource>
		<resource>/mapviewer*</resource>
		<resource>/xmlpserver/**</resource>
		<resource>/xmlpserver*</resource>
		<resource>/bicontent/**</resource>
		<resource>/bicontent*</resource>
		<resource>/analytics/jbips/**</resource>
		<resource>/analytics/jbips*</resource>
		<resource>/analytics/saw.dll/**</resource>
		<resource>/analytics/saw.dll*</resource>
    </protectedResourcesList>
    <publicResourcesList>
        		<resource>/essbase-webservices/**</resource>
		<resource>/essbase-webservices/*</resource>
		<resource>/essbase/agent/**</resource>
		<resource>/essbase/agent/*</resource>
		<resource>/aps/Essbase/**</resource>
		<resource>/aps/Essbase/*</resource>
		<resource>/mapviewer/wmts/**</resource>
		<resource>/mapviewer/wmts/*</resource>
		<resource>/mapviewer/wms/**</resource>
		<resource>/mapviewer/wms/*</resource>
		<resource>/mapviewer/mcserver/**</resource>
		<resource>/mapviewer/mcserver/*</resource>
		<resource>/mapviewer/foi/**</resource>
		<resource>/mapviewer/foi/*</resource>
		<resource>/mapviewer/dataserver/**</resource>
		<resource>/mapviewer/dataserver/*</resource>
		<resource>/aps/JAPI/**</resource>
		<resource>/aps/JAPI/*</resource>
		<resource>/aps/**</resource>
		<resource>/aps/*</resource>
		<resource>/analytics-ws/saw.dll/**</resource>
		<resource>/analytics-ws/saw.dll/*</resource>
		<resource>/analytics/**</resource>
		<resource>/analytics/*</resource>
    </publicResourcesList>
	<excludedResourcesList>
        		<resource>/biservices</resource>
		<resource>/analytics-bi-adf</resource>
		<resource>/xmlpserver/Guest</resource>
		<resource>/xmlpserver/ReportTemplateService.xls</resource>
		<resource>/xmlpserver/report_service</resource>
		<resource>/xmlpserver/services</resource>
		<resource>/analytics/saw.dll/wsdl</resource>
		<resource>/analytics-ws</resource>
		<resource>/ws/.../*</resource>
		<resource>/wsm-pm</resource>
		<resource>/wsm-pm/.../*</resource>
    </excludedResourcesList>
	<protectedAuthnScheme>HidFederationScheme</protectedAuthnScheme>
	<userDefinedParameters>
		<userDefinedParam>
            <name>SSLVerfifyHostname</name>
            <value>false</value>
        </userDefinedParam>
		<userDefinedParam>
            <name>SSLVerifyPeerCert</name>
            <value>false</value>
        </userDefinedParam>
	</userDefinedParameters>
</OAM11GRegRequest>

```

### 7. Register Oracle Access Manager (OAM) in Hideez Enterprise Server (HES)

After you export the **SAML 2.0 metadata** from Oracle Access Manager (OAM), you need to create a corresponding Service Provider (SP) entry in the **Hideez Enterprise Server (HES)** to establish a trust relationship.

Follow these steps:

1. **Log in** to the **Hideez Enterprise Server (HES)** as an administrator.
2. **Navigate** to **Settings > Parameters** in the left panel.
3. **Click** on the **SAML** widget in the right panel.
4. **Click** the **"Add Service Provider"** button.
5. **Upload** the **SAML 2.0 metadata file** that was previously exported from OAM.
6. **Provide** any additional required configuration details if prompted.
7. **Save** the new Service Provider configuration.
