Oracle OAM Federation behind SSL proxy
Losen, Stephen C. (scl)
scl at eservices.virginia.edu
Thu Dec 22 06:53:48 EST 2016
Hi folks,
Shot in the dark here. Our Enterprise IT folks are moving toward SAML/Shibboleth authentication for Oracle Enterprise Business Suite (EBS). They are setting up Oracle Access Manager (OAM) which has SAML support. I am the Shibboleth IDP admin and know next to nothing about OAM, other than it is a SAML SP. The plan is to put the OAM web server behind a F5 BigIP that terminates SSL. As a first cut the Oracle DBAs tested OAM by accessing it directly (via VPN) without going through the F5. They provided me with the OAM SP metadata, which I installed on the IDP. The URLs in this metadata are all "private" and refer directly to the OAM server, not the F5 virtual server. Testing was successful. However, now we want to put OAM behind the F5. Naturally OAM must be "aware" of this and must redirect the browser to the "public" URL for the F5 virtual server. Also the SP metadata must contain these public URLs. Our Oracle DBAs are stumped at the moment and do not know how to configure OAM to do this. When testing using the F5 virtual server, OAM sends redirects to the internal "private" URL instead of the F5 public URL. The generated SP metadata has private URLs. Putting OAM behind a proxy must be a fairly common situation that is supported somehow. Is this an OAM config? Or perhaps a WebLogic config?
For the time being we will probably abandon the proxy and connect directly to OAM, and configure SSL on the OAM server. But we definitely need the F5 proxy eventually.
Steve Losen
University of Virginia
More information about the users
mailing list