1-2Exercise 2: Install Oracle Identity Analytics 11gR1 .... Exercise 2: Install Oracle Identity Analytics 11gR1Exercise 2: Install Oracle Identity Analytics 11gR1 In this exercise, you c
Trang 1Oracle Identity Analytics 11gR1:
AdministrationActivity Guide
D68340GC20
Edition 2.0
December 2010
D71224
Trang 2Copyright © 2010, Oracle and/or its affiliates All rights reserved.
Disclaimer
This document contains proprietary information and is protected by copyright and other intellectual property laws You may copy and print this document solely for your own use in an Oracle training course The document may not be modified or altered
in any way Except where your use constitutes "fair use" under copyright law, you may not use, share, download, upload, copy, print, display, perform, reproduce, publish, license, post, transmit, or distribute this document in whole or in part without the express authorization of Oracle.
The information contained in this document is subject to change without notice If you find any problems in the document, please report them in writing to: Oracle University,
500 Oracle Parkway, Redwood Shores, California 94065 USA This document is not warranted to be error-free.
Restricted Rights Notice
If this documentation is delivered to the United States Government or anyone using the documentation on behalf of the United States Government, the following notice is applicable:
U.S GOVERNMENT RIGHTS The U.S Government’s rights to use, modify, reproduce, release, perform, display, or disclose these training materials are restricted by the terms of the applicable Oracle license agreement and/or the applicable U.S Government contract
Trang 3Table of Contents
About This Course Preface-xi
Course Goals Preface-xiTopics Not Covered Preface-xiiHow Prepared Are You? Preface-xiiiHow to Use Course Materials Preface-xivConventions Preface-xvIcons Preface-xvTypographical Conventions Preface-xviAdditional Conventions Preface-xvi
Installing Oracle Identity Analytics 11gR1 1-1
Objectives 1-1Exercise 1: Examine Your Practice System 1-2Preparation 1-2Task – Examine Your Practice System 1-2Exercise 2: Install Oracle Identity Analytics 11gR1 1-4Task 1 – Copy and Unzip the Oracle Identity Analytics 11.1.1.3 Software 1-4Task 2 – Import the Oracle Identity Analytics Schema to the MySQL Database 1-4Task 3 – Configure the WAR File 1-5Task 4 – Prepare the Oracle Identity Analytics Environment 1-6Task 5 - Verify the Preinstallation Steps 1-7Task 6 – Deploy the Oracle Identity Analytics Application on GlassFish 1-10Exercise Summary 1-12
Building the Identity Warehouse 2-1
Objectives 2-1Exercise 1: Import Users 2-2Preparation 2-2Task 1 – Copy the Sample Feed Files to the Appropriate Directories2-2
Task 2 – Configure Import Options 2-3
Trang 4Task 3 – Create a New Provisioning Server 2-3Task 4 – Schedule an Import Job to Import the Sample Feed 2-4Task 5 – Verify User Import 2-5Exercise 2: Configure Metadata 2-6Preparation 2-6Task 1 – Define Resource Type Metadata 2-6Task 2 – Define Attribute Categories 2-7Task 3 – Define Attributes 2-7Exercise 3: Set Up Business Structures 2-10Task 1 – Import Sample Business Structures 2-10Task 2 – Create a Business Structure Rule 2-11Task 3 – Assign Users to a Business Structure Using Rules 2-12Task 4 – Assign Users to a Business Structure Using the Console 2-13
Exercise 4: Import Accounts 2-14Task 1 – Import Accounts From Sample Files 2-14Task 2 – Verify Accounts Import 2-15Exercise 5: Configure an Application 2-16Task 1 – Create an Application 2-16Task 2 – Assign Users to an Application 2-17Exercise 6: Import Roles 2-19Preparation 2-19Task 1 – Import Roles 2-19Task 2 – Verify Role Import 2-20Exercise 7: Import Policies 2-21Task 1 – Import Active Directory Policy 2-21Task 2 – Import DB2 Policy 2-23Task 3 – Import LDAP Policy 2-23Task 4 – Import Oracle Policy 2-24Exercise 8: Manage Resource Data 2-26Task 1 – Configure Glossary, Data Owner, and Classification 2-26Exercise Summary 2-28
Configuring Oracle Identity Analytics Security 3-1
Objectives 3-1Exercise 1: Configure Oracle Identity Analytics Security 3-2Task 1 – Configure Creation and Correlation of Oracle Identity Analytics Users 3-2Task 2 – Create a Role 3-3Task 3 – Create a User 3-4Task 4 – Create a Proxy Assignment 3-4Exercise 2: Configure LDAP Authentication 3-6Task 1 – Configure the ldap.properties File 3-6
Trang 5Objectives 4-1Exercise 1: Configure Identity Certification 4-2Task 1 – Create an Email Template 4-2Task 2 – Configure Email Settings 4-3Task 3 – Configure Logging (Optional) 4-4Task 4 – Configure Certifications 4-4Exercise 2: Create Data Owner and User Entitlement Certifications 4-6Task 1 – Create a Data Owner Certification 4-6Task 2 – Create a User Entitlement Certification 4-7Exercise 3: Complete Certifications 4-9Task 1 – Complete User Certification 4-9Task 2 – Complete Transferred User Certification 4-11Task 3 – Complete Data Owner Certification 4-11Exercise 4: Perform Remediation Validation 4-13Task 1 – Configure Remediation 4-13Task 2 – Perform Remediation Validation 4-13Exercise Summary 4-15
Performing Identity Audits 5-1
Objectives 5-1Exercise 1: Configure Identity Audit 5-2Task – Configure Email Settings 5-2Exercise 2: Create an Audit Rule and Policy 5-4Task 1 – Create an Audit Rule 5-4Task 2 – Create an Audit Policy 5-5Exercise 3: Perform an Audit Scan 5-6Task 1 – Run a Policy Scan 5-6Task 2 – Close Violations 5-7Exercise 4: Perform an Identity Audit 5-8Exercise 4: Perform an Identity Audit – Solution 5-9Exercise Summary 5-11
Performing Role Engineering 6-1
Objectives 6-1Exercise 1: Perform Role Engineering 6-2Task 1 – Configure Logging (Optional) 6-2Task 2 – Perform a Role Mining Task 6-2Task 3 – Configure Role Mining Results 6-4Task 4 – Perform Entitlement Discovery 6-6Exercise Summary 6-8
Performing Role Management 7-1
Objectives 7-1Exercise 1: Configure Role and Rule Workflows 7-2Task 1 – Configure Email Template 7-2Task 2 – Configure Role Modification Workflow 7-2Task 3 – Configure Role Membership Rule Modification Workflow
Trang 67-4Exercise 2: Perform Role Modification and Approval 7-5Task 1 – Modify Candidate Role 7-5Task 2 – Approve Role Modification Request 7-6Exercise 3: Perform Role Consolidation 7-7Task 1 – Analyze Role Consolidation by Role Membership 7-7Task 2 – Analyze Role Consolidation by Entitlements 7-7Exercise 4: Configure Role Management Auto-Provisioning Rules 7-9Task 1 – Create Role Auto-Provisioning Rules 7-9Task 2 – Approve Modified Rule 7-10Task 3 – Run the Modified Rule 7-10Task 4 – Configure Rule Trigger Schedule 7-11Exercise 5: Configure Role SoD 7-13Task 1 – Create a Role SoD Policy and Rule 7-13Task 2 – Run an SoD Check 7-14Task 3 – Configure a Role Exclusion 7-14Exercise 6: Configure Event Listeners 7-16Task 1 – Configure Logging (Optional) 7-16Task 2 – Create Event Listener 7-16Task 3 – Trigger Event Listener 7-18Exercise Summary 7-20
Generating Reports 8-1
Objectives 8-1Exercise 1: Generate Reports 8-2Task 1 – Copy jrxml Files 8-2Task 2 – Run a Report 8-2Task 3 – Schedule a Report 8-3Exercise 2: Upload a Custom Report 8-4Task 1 – Modify a Custom Report 8-4Task 2 – Run a Custom Report 8-5Exercise Summary 8-6
Working with the Solaris Sandbox A-1
Objectives A-1Start, Log In to, and Log Out of Solaris Sandbox Zones A-2Overview of Solaris OS Zones A-2Solaris Sandbox Zones A-2Zone Management Commands in the Solaris Sandbox A-3Start Servers A-4Start the MySQL Server A-4Start the GlassFish Application Server A-4Start the Directory Server Instance A-4
Trang 7Bring the Solaris Sandbox to the Starting Point for Performing a PracticeA-8
Run the Firefox Browser from the Zones A-9
Trang 9About This Course
This course provides you with the opportunity to learn about Oracle Identity Analytics 11gR1 (OIA) software Oracle Identity Analytics provides
comprehensive role lifecycle management and identity compliance capabilities to streamline operations, enhance compliance, and reduce costs The Oracle Identity Analytics course will provide you with an entry point into Oracle Identity Analytics and cover the necessary concepts for implementing and managing a role-based access control solution
Practices will acquaint you with the components of Oracle Identity Analytics, including the identity warehouse, reports, and workflows You will also learn to perform identity certifications, audits, role engineering, and role management
Course Goals
After completing this course, you should be able to:
Trang 10Topics Not Covered
Topics Not Covered
This course does not cover the following topics:
Trang 11How Prepared Are You?
How Prepared Are You?
To be sure you are prepared to take this course, can you answer yes to the following questions?
Trang 12How to Use Course Materials
How to Use Course Materials
To enable you to succeed in this course, these course materials use a learning module that is composed of the following components:
● Goals – You should be able to accomplish the goals after finishing this
course and meeting all of its objectives
● Objectives – You should be able to meet the objectives after completing a
portion of the instructional content Objectives support goals and can support other high-level objectives
● Lecture – The instructor will present information specific to the objective
of the module This information will help you obtain the knowledge and skills necessary to succeed with the activities
● Activities – The activities take on various forms, such as an exercise,
self-check, discussion, and demonstration Activities are used to facilitate mastery of an objective
Trang 13Additional resources – Indicates other references that provide additional
information about the topics described in the module
Discussion – Indicates that a smallgroup or class discussion on the current topic
is recommended at this time
Note – Indicates additional information that can help you but is not crucial to
your understanding of the concept being described You should be able to understand the concept or complete the task without this information Examples
of notational information include keyword shortcuts and minor system adjustments
Caution – Indicates that there is a risk of personal injury from a nonelectrical
hazard, or risk of irreversible damage to data, software, or the operating system
A caution indicates the possibility of a hazard (as opposed to certainty) that might happen, depending on the action of the user
Trang 14Typographical Conventions
Courier is used for the names of commands, files, directories, programming code, and onscreen computer output For example:
Use ls -al to list all files
system% You have mail
Courier bold is used for characters and numbers that you enter For example:
To list the files in this directory, enter:
# ls
Courier italics is used for variables and command-line placeholders that are replaced with a real name or value For example:
To delete a file, use the rm filename command.
as part of an activity For example:
Enter chmod a+rwx filename to grant read, write, and execute rights for
filename to world, group, and users.
Palatino italics is used for book titles, new words or terms, or words that you want to emphasize For example:
Read Chapter 6 in the User’s Guide.
Additional Conventions
A Courier backslash \ at the end of a command line is known as a line continuation character in UNIX This means that the next line in the text actually belongs to the previous line, and you should enter the entire command on one line You do not need to enter the line continuation character For example:
# cd /glassfish/domains/domain1/applications/j2ee-\
modules/rbacx/WEB-INF
Trang 15Lab 1
Installing Oracle Identity Analytics 11gR1
Objectives
After completing this practice, you should be able to:
Trang 16Exercise 1: Examine Your Practice System
Exercise 1: Examine Your Practice System
The practice environment in this course uses the Solaris Sandbox environment Appendix A provides a detailed description of the Solaris Sandbox and how it is used
The Solaris Sandbox for this course contains all the software that you need to run the practices and includes the following:
you perform these practices
Oracle Identity Analytics data
Identity Analytics application is deployed
software you will learn about in this course
Preparation
The values needed for this exercise are listed in Table 1-1
Task – Examine Your Practice System
Complete the following steps to examine the practice environment for your machine:
1 Start the Virtual Box From the Linux desktop menu bar, select Applications
> System Tools > Sun VirtualBox
2 If the License dialog box appears, scroll to the bottom of the text, and then click I Agree
Table 1-1 Practice Variables Variable Value Description
ROOTUSER root Superuser name
ROOTPWD cangetin Superuser password
Trang 17Exercise 1: Examine Your Practice System
5 Do not do anything while the text login screens proceed Wait until the GUI login screen appears Log in as the root user on your student machine
6 From the Launch menu, select Preferences > Desktop Preferences >
Keyboard > Behavior
The Keyboard Behavior dialog box appears
7 Verify that the Key Presses Repeat When Key is Held Down check box is deselected
Note – Under some conditions, remotely-displayed practice systems are subject
to false key press repeats, even when users do not keep a key pressed down Disabling key presses eliminates this problem in most cases If this is a local PC (that is, not accessing the desktop by VNC nor NetSupport), then deselecting this check box is not necessary Deselecting the repeat key will affect how you edit command line history (for example, cursor left will not repeat)
8 Click Close
9 Open a terminal window From the Launch menu, select Applications > Utilities > Terminal
The command prompt within the global zone is global #
After you log in to your practice system, you are in the global zone
10 From the global zone, prepare the zones to run the practices by typing the following command:
Note – From this point forward in the practices, the command-line prompt is
abbreviated in examples to # rather than showing the full command-line prompt,
Trang 18Exercise 2: Install Oracle Identity Analytics 11gR1
Exercise 2: Install Oracle Identity Analytics 11gR1
In this exercise, you complete the following tasks:
Task 1 – Copy and Unzip the Oracle Identity Analytics 11.1.1.3 Software
In this task, you will copy the Oracle Identity Analytics zip file to the installation location and unzip the file
1 Log in to zone01 if required
2 Unzip the software file into its own directory
# cd /
# mkdir OIA_11gR1
# cd /OIA_11gR1
# unzip /opt/ses/software/OIA/OIA_11gR1.zip
Task 2 – Import the Oracle Identity Analytics Schema
to the MySQL Database
In this task, you will import the Oracle Identity Analytics schema into the MySQL database
1 Copy the my.cnf file to the /etc directory This file contains configuration settings for the MySQL database
# cp /opt/ses/shared/labfiles/my.cnf /etc
2 Start MySQL
# /etc/init.d/mysql start
Trang 19Exercise 2: Install Oracle Identity Analytics 11gR1
On line 17, add a space after the dashes so it reads, “ Indexes” Save and close the script
4 Import the Oracle Identity Analytics schema to MySQL
# mysql < rbacx-11.1.1.3.0_mysql_schema.sql
# mysql <
migrate-rbacx-11.1.1.3.0To11.1.11.3.1-mysql.sql
Neither mysql script should have any response No news is good news
5 Verify that the rbacx database was created
# mysql mysql> show databases;
The information_schema, mysql, rbacx, and test databases should appear in the terminal window
6 Verify that the rbacxservice user was created You should see an entry for rbacxservice in the output
mysql> select user from mysql.user\G;
mysql> quit;
Task 3 – Configure the WAR File
1 Unpack the WAR file to a staging directory
# mkdir /OIA_11gR1/staging
# cd /OIA_11gR1/staging
# jar -xvf /rbacx.war
2 Set the RBACX_HOME environment variable
the vi editor or the gedit editor
RBACX_HOME=/OIA_11gR1 export RBACX_HOME
Caution – Verify that you have spelled the environment variable name,
might lead to errors when starting the Oracle Identity Analytics Web application later in this exercise
# source /.profile
Trang 20Exercise 2: Install Oracle Identity Analytics 11gR1
# echo $RBACX_HOME
The output should be /OIA_11gR1
3 Edit the /OIA_11gR1/staging/WEB-INF/log4j.properties file by locating on line 10 “log4j.appender.file.file” and editing the value as follows:
Note – This course uses the \ character at the ends of lines in example commands
to indicate line continuation When you see a command in multiple lines, each ending with the \ character, enter the command on a single line, without pressing Enter Do not enter the \ character when entering the command
5 Copy the jasper-jdt.jar file to INF/lib/ This is needed for the GlassFish application server
Trang 21Exercise 2: Install Oracle Identity Analytics 11gR1
3 Edit the /OIA_11gR1/conf/iam.properties file
/OIA_11gR1/sample
4 Create the rbacx.log file
# mkdir /OIA_11gR1/logs
# touch /OIA_11gR1/logs/rbacx.log
Task 5 - Verify the Preinstallation Steps
In this task, you will verify that you have performed the preinstallation steps correctly
Caution – Be sure to perform all the steps in this task Failure to perform Oracle
Identity Analytics preinstallation correctly might lead to deployment problems in the next task
1 Verify that the MySQL daemon is active
# ps -ef | grep mysql
Output similar to the following should appear in the terminal window:
root 2743 2078 0 Feb 02 pts/4 0:00 /bin/sh /bin/mysqld_safe user=root
root 2821 2743 0 Feb 02 pts/4 0:16 /mysql-5.1.30-solaris10-i386/bin/mysqld
basedir=/mysql-5.1.30-solaris10-i386 root 3101 2092 0 16:28:30 pts/4 0:00 grep mysql
If the MySQL daemon is not active, start the daemon:
# /etc/init.d/mysql start
2 Verify that you imported the Oracle Identity Analytics schema into the database
# mysql mysql> show databases;
Trang 22Exercise 2: Install Oracle Identity Analytics 11gR1
3 Verify that the log4j.properties file was modified correctly
# grep appender.file.file /OIA_11gR1/staging/ \
# jar -tf /OIA_11gR1/rbacx.war | grep weka
The output in the terminal window should indicate the presence of the INF/lib/weka3-5-6-5.jar file If the file is not present, follow the steps in Task 3 to include the weka3-5-6-5.jar file in the rbacx.war file and to repack the rbacx.war file
WEB-5 Verify that the jasper-jdt.jar file was incorporated into the rbacx.war file
# jar -tf /OIA_11gR1/rbacx.war | grep jasper-jdt
Output in the terminal window should indicate the presence of the
in Task 3 to include the jasper-jdt.jar file in the rbacx.war file and
to repack the rbacx.war file
6 Verify that the jdbc.properties file was modified correctly
# grep jdbc.url /OIA_11gR1/conf/jdbc.properties
Output similar to the following should appear in the terminal window:jdbc.url=jdbc:mysql://localhost:3306/rbacx
If the output from the grep command differs, follow the steps in Task 4 to modify the jdbc.properties file
7 Verify that the MySQL configuration file my.cnf ignores case for table names
# grep lower_case /etc/my.cnf
Output should say:
lower_case_table_names=1where 1 means true
Trang 23Exercise 2: Install Oracle Identity Analytics 11gR1
8 Verify that the iam.properties file was modified correctly
# grep Location /OIA_11gR1/conf/iam.properties
Output similar to the following should appear in the terminal window:
com.vaau.rbacx.iam.file.import.completeLocation=/OIA_11gR1/sample/import/complete
com.vaau.rbacx.iam.file.import.schemaLocation=/OIA_11gR1/sample/import/schema
com.vaau.rbacx.iam.file.import.dropLocation=/OIA_11gR1/sample/import/in
com.vaau.rbacx.etl.import.dropLocation=/OIA_11gR1/sample/import/etl/in
com.vaau.rbacx.etl.import.graphsLocation=/OIA_11gR1/sample/import/etl/graphs
com.vaau.rbacx.etl.import.completeLocation=/OIA_11gR1/sample/import/etl/complete
com.vaau.rbacx.etl.import.outputLocation=/OIA_11gR1/sample/import/in
com.vaau.rbacx.iam.file.export.dropLocation=/OIA_11gR1/sample/export/etl/in
com.vaau.rbacx.iam.file.export.schemaLocation=/OIA_11gR1/sample/export/schema
com.vaau.rbacx.etl.export.dropLocation=/OIA_11gR1/sample/export/etl/in
com.vaau.rbacx.etl.export.graphsLocation=/OIA_11gR1/sample/export/etl/graphs
com.vaau.rbacx.etl.export.completeLocation=/OIA_11gR1/sample/export/etl/complete
com.vaau.rbacx.etl.export.outputLocation=/OIA_11gR1/sample/export/out
If the output from the grep command differs, follow the steps in Task 4 to modify the iam.properties file
9 Verify the presence of the rbacx.log file
Trang 24Exercise 2: Install Oracle Identity Analytics 11gR1
Task 6 – Deploy the Oracle Identity Analytics Application on GlassFish
In this task, you will deploy the Oracle Identity Analytics war file from the previous task to the GlassFish application server
1 Start the GlassFish application server
# asadmin start-domain domain1
Note – Make sure that you are using the proper asadmin command from the
/glassfish/bin directory by using the which asadmin command
2 Launch a browser within zone01
# firefox &
Note – Running Firefox from the Launch menu will run it in the global zone
Make sure to start Firefox from the command line in zone01 It may start and try
to unsuccessfully load a home page If so, just click the Stop icon
3 Navigate to the following URL to open the GlassFish administration console
http://localhost:4848
4 Log in as follows:
User Name: admin Password: adminadmin
If you are prompted to register the software, click Never Register
Note – Increasing the max heap size to 1024 MB improves the performance of
the GlassFish application server on systems with more than 4 GB RAM If your system does not have 4 GB RAM or if you have problems with low free RAM memory, keep the max heap size setting to 512 MB and skip steps 5 through 8, resume with step 9
5 Under Common Tasks on the extreme left, select Application Server > JVM Settings > JVM Options
6 Increase the max Java heap size by changing the JVM option
Trang 25Exercise 2: Install Oracle Identity Analytics 11gR1
# asadmin stop-domain domain1
# asadmin start-domain domain1
9 Return to the GlassFish Administration console Under Common Tasks, navigate to Applications > Web Applications
10 Click Deploy and complete the form as follows:
Type: Web Application (.war)
Location (Local packaged): /OIA_11gR1/rbacx.war Application Name: rbacx
Context Root: rbacx
Status: selectRun Verifier: deselectPrecompile JSPs: deselect
11 Click OK The rbacx application should appear under Deployed Web Applications
12 Click Launch or open http://localhost:8080/rbacx
13 Log in as follows:
Username: rbacxadmin Password: password
The Oracle Identity Analytics administration console should appear
Note – Check the /OIA_11gR1/logs/rbacx.log file if any problems
occur
Trang 26Exercise Summary
Exercise Summary
Discussion – Take a few minutes to discuss what experiences, issues, or
discoveries you had during the practice exercise
Trang 28Exercise 1: Import Users
Exercise 1: Import Users
In this exercise, you complete the following tasks:
Trang 29Exercise 1: Import Users
Task 2 – Configure Import Options
1 In a terminal window, change to the following directory:
# cd /OIA_11gR1/conf
2 Configure the option for dropping orphan accounts
com.vaau.rbacx.iam.correlation.dropOrphanAccounts=false
3 View the Failed Import Notification email settings
# cd /glassfish/domains/domain1/applications/\
j2ee-modules/rbacx/WEB-INF/
Note – Whenever you see lines in command examples ending in “\” in these
practices, enter them as a single command in your terminal session Do not enter the “\” as part of the command
line 403 and 407-414 to view the settings No changes are required In
a production system, you would set your email values here
Task 3 – Create a New Provisioning Server
In this task, you will create a new Provisioning Server for importing data into Oracle Identity Analytics The type of Provisioning Server you will use is from a file
1 Log in to the Oracle Identity Analytics console as rbacxadmin
2 In the Oracle Identity Analytics console, navigate to Administration >
Configuration (This takes a minute the first time.)
Trang 30Exercise 1: Import Users
3 Click Provisioning Servers
4 Click New Provisioning Server Connection next to the green plus icon
5 For Type of Provisioning Server Connection, select File, and then click Next
6 Complete the form as follows:
Connection Name: File Server Import Drop Location: /OIA_11gR1/sample/import/in
Import Complete Location:
/OIA_11gR1/sample/import/complete
Import Schema Location: /OIA_11gR1/sample/import/schema
Export Drop Location: <leave blank>
Export Schema Location: <leave blank>
2 Click Schedule Job next to the green plus icon
3 On the Import tab, select Import Users
4 Under Connection Name, select File Server and click Next
5 For the new import job, complete the form as follows:
Name: user_feed01 Description: sample user feed
Run the job now: Select
Note – You can deselect this option if you choose to run the job at a later time
6 Click Finish
7 The Job Status Progress Details window will blink and flash several times before it starts Close the Job Status window when the import job is
Trang 31Exercise 1: Import Users
Task 5 – Verify User Import
In this task, you will verify that the user import was successful and view a sample user
1 Navigate to Administration > Auditing & Events
2 Click the Import/Export Logs subtab and look for an entry in the logs with the Description "Users import from file: users01.csv" The result should be Successful
3 Select the audit entry (to the left of BATCH) and click View Details and to view the exceptions if any When you are done looking at the import log, click Back
4 Navigate to Identity Warehouse > Users When you go to a menu item for the very first time, it takes a minute to load
5 Search for cg14655, and click the User Name link Verify that user data is present for Christopher Green, Services Manager, under the General and Custom Properties tabs, and note the relationship map diagram showing Amy Anderson (his boss) and his reports (Andrew, Aidan, and so on)
Trang 32Exercise 2: Configure Metadata
Exercise 2: Configure Metadata
In this exercise, you complete the following tasks:
Preparation
Use the values in Table 2-2 for this exercise Ask your instructor for any additional values that are not provided
Task 1 – Define Resource Type Metadata
In this task, you will define the resource type metadata by importing the data from a sql file You will also manually create a resource type and define metadata for that resource
1 Import the metadata.sql file
# cd /opt/ses/shared/labfiles/metadata
# mysql -D rbacx < metadata.sql
2 In the Oracle Identity Analytics console, navigate to Administration > Configuration
3 Click the Resource Types tab You should see a list of resources in the left pane
4 Click New Resource Type (next to the green plus) and complete the New Resource Type form as follows:
Trang 33Exercise 2: Configure Metadata
Task 2 – Define Attribute Categories
In this task, you will define an attribute category for the Telegance resource type
1 Select the Telegance Resource Type created in the previous task
2 Click New Attribute Category and complete the form as follows:
Attribute Category Name: General
Category Order: 1
3 Click Save
Task 3 – Define Attributes
In this task, you will define the attributes for the attribute category created in the previous task
1 Define the appID attribute:
Category
2 Define the profileName attribute:
Category
Trang 34Exercise 2: Configure Metadata
3 Define the securitySetting attribute:
Category
Trang 35Exercise 2: Configure Metadata
Note – You do not need to create the name, endpoint, domain, and
Other attributes need to be defined in the metadata
Trang 36Exercise 3: Set Up Business Structures
Exercise 3: Set Up Business Structures
In this exercise, you complete the following tasks:
Task 1 – Import Sample Business Structures
The ability to import business structures is a new feature in Oracle Identity Analytics 11gR1 In this task, you will import business structures into the Oracle Identity Analytics Identity Warehouse The resulting business structures should appear as shown in the following screenshot
1 In a terminal window, change to the import directory
# cd /OIA_11gR1/sample/import
Trang 37Exercise 3: Set Up Business Structures
2 Copy the sample user feed and schema files to the corresponding
5 Click Schedule Job
6 Click Import Business Structure
7 Select File Server and click Next
8 Complete the form as follows:
Name: BU_import
Description: Business Structure import
Run Job Now: Select
9 Click Finish
10 The Job Status Progress Details window will blink several times before it starts It should import 69 records Close the Job Status window when the import job finishes
Task 2 – Create a Business Structure Rule
Using rules, you can simplify the task of assigning users to business structures In this task, you will create a rule to assign users to one of the business structures created in the previous task
1 Navigate to Identity Warehouse > Business Structures
2 Click Rules and click New Rule
3 Complete the form as follows:
Rule Name: BU_Services
Description: Assign users to Services BU
Trang 38Exercise 3: Set Up Business Structures
9 Add Amy Anderson as the Rule Owner
3 For the BU_Services rule, click Preview
4 For Selection Strategy, choose All Users from the drop-down menu and click Next
5 On the Summary page, click Preview The status bar will update when all users are scanned
6 Under Job Name, click the resulting scan You should see the 58 users that met the rule condition These users will be added to the business structure upon running the rule
Trang 39Exercise 3: Set Up Business Structures
7 Click Apply to add the 58 users to the Services business structure (You may have to scroll to the extreme right of the page to access the Apply button.)
Note – Alternatively, you can click Run instead of Preview and schedule to run
the rule later on a periodic or one-time schedule
Task 4 – Assign Users to a Business Structure Using the Console
You can also assign users to business structures manually through the console In this task, you will assign users whose manager is Amy Anderson to the Anderson Amy business structure
1 Navigate to Identity Warehouse > Business Structures
2 In the left pane, under Business Structures, click the Hierarchy tab, expand the Reporting Structure, and expand Anderson Scott
3 Select the Anderson Amy business structure and click the Users tab
is not sorted alphabetically.)
Hughes, and Linda Murdock—appear on the Users tab These users are now members of the Amy Anderson business structure
Trang 40Exercise 4: Import Accounts
Exercise 4: Import Accounts
In this exercise, you complete the following tasks:
Task 1 – Import Accounts From Sample Files
In this task, you will import the sample accounts feed into the Oracle Identity Analytics Identity Warehouse
1 In a terminal window, change to the following directory:
3 Log in to the Oracle Identity Analytics console if necessary
4 Navigate to Administration > Configuration
5 Click Import/Export
6 Click Schedule Job
7 Click Import Accounts
8 For the Data Selection Source, select File Server and click Next
9 Select all 11 Resource Types listed and click Next
10 For the new import job, complete the form as follows:
Name: accounts_import1 Description: accounts import
Run the job now: Select
11 Click Finish
12 Close the Job Status window when the import job is finished It should have imported 539 accounts