Popular Posts

Getting Started with OAuth2Client on iOS
Custom Solutions
In creating a proof-of-concept iOS app that uses OAuth2 to consume the Google APIs, I began with the OAuth2Client project by the folks at nxtbgthng GmbH. This project is one of oldest and most ac...
Databases, ACID Compliance, NoSQL, and More
NoSQL has been in the media for the last couple years as one of the new marketing buzzwords and you may be wondering exactly what it is, what it can do, and how it can fit into your current infrastruc...
Oracle Identity Manager Basics: Creating a Custom Adapter in OIM 11g
Identity Management
Oracle Identity Manager Basics: Creating a Custom Adapter in OIM 11g The purpose of this entry is to explain how to create a custom adapter in OIM.  The adapter will write to an external file.&n...


  • Home
    Home This is where you can find all the blog posts throughout the site.
  • Categories
    Categories Displays a list of categories from this blog.
  • Tags
    Tags Displays a list of tags that has been used in the blog.
  • Bloggers
    Bloggers Search for your favorite blogger from this site.
  • Login
Recent blog posts

Posted by on in Data Center
One often overlooked aspect of relocating your data center is the impact the move will have on your end-users and their applications. While the underlying technology is important, your clients are interacting with their applications on a daily basis. If we take a top down approach to data center migration, and start by understanding your application level and then working our way down through the interfaces to the Server/Storage and finally the network, we can uncover the true effect the move will have on your end-user clients.  With many of our customers, we find there are conflicting lists of applications and...
Hits: 130
Within RSA IMG (formerly Aveksa) workflows you can assign many resources to complete an approval and/or manual fulfillment activity. The following screenshot shows an example of resource assigned to an approval activity. The following screenshot shows an example of resource assigned to a manual fulfillment activity.     There is, on occasion, the need to update the resource assignments, due to some type of personnel turnover  - whether the person leaves the enterprise or transfers into another role. When this happens, you find yourself having to edit the workflow. NOTE: In RSA IMG 6.9 the notion to configure “Other…Owners” for any...
Hits: 254
IDMWORKS Recognized for Expertise in Selling, Deploying and Supporting Oracle Identity and Access Management Solutions August 12, 2015 – IDMWORKS today announced that it has achieved Platinum partner status in Oracle PartnerNetwork (OPN). By attaining Platinum level membership, Oracle has recognized IDMWORKS for its in-depth expertise and excellence in delivering identity and access management solutions and for uniquely addressing the challenges of joint customers. IDMWORKS has established its depth and breadth of the expertise across key Oracle solution areas, including the Oracle Identity and Access Management Suite, the Oracle Mobile Security Suite Plus, Oracle Enterprise Single Sign-On Authentication Manager, Oracle Directory...
Tagged in: Oracle
Hits: 186
I ran into an issue where I couldn't determine why a certain ACI was not working as expected in Oracle Unified Directory 11gR2.  After doing some research, I stumbled onto Effective Rights Control (ERC) within OUD.  Effective Rights Control forces OUD to output the ACI that is affecting an entry's permissions.   Here is the Oracle document on Searching Using the Get Effective Rights Control (http://docs.oracle.com/cd/E29407_01/admin.111200/e22648/managing_data.htm#solTO-SEARCH-USING-THE-GET-EFFECTIVE-RIGHTS-CONTROL)   The following command will display a description of the access permissions for an entry for the categories of add, delete, read, write, and proxy.  This command doesn't get down to the individual attribute level, but...
Hits: 223
From time to time we run across requirements where there is some attribute that is used to hold a value that can vary greatly across the enterprise from one object to another, usually users.  Most commonly it is for things like job codes, departments, locations or various entities under a corporate umbrella. Typically in those situations we find that the requirements call for some values to be permitted through the system while others are not or that various values will need to have additional logic applied to them compared to others. Now this may not sound like a difficult requirement to...
Hits: 239
Problem: So maybe my pain will help someone else.  I recently encountered an issue when combining OAM, Unsolicited Login and SSL.  I had configured everything properly in a test environment so that Unsolicited Login worked properly over HTTP.  Testing verified everything worked properly.  As soon as we switched to using our HTTPS-only endpoints everything broke. This scenario should only occur if you are in an HTTPS-only environment for a reason to be described below. It turned out that somehow, despite specifying our successurl as: <input type="hidden" name="successurl" value="https://myserver.example.com/application"> OAM translated that value as http://myserver.example.com/application. As such we saw the following in...
Hits: 406
As an IdentityIQ implementation becomes more mature, there will inevitably be more applications connected. Depending on how the roles are set up, this will have one major consequence: provisioning the roles will take longer. The way IIQ will attempt to provision the roles, out of the box, is serially. It will run through each application being provisioned one at a time, waiting for a response from the target, before it moves on to the next operation. Oftentimes, this will be no issue as many roles will still fly through, assuming everything goes right. There are many cases though (admin roles and...
Hits: 366
Below are a list of Operating systems that the RSA IMG application will install on. The RSA IMG will also install on a RHEL 6U6 os version, there is only one place that you will have to modify so that the installation script will perform the install. SUSE Linux Enterprise Server 11SP3RHEL 5u8 RHEL 5u9 RHEL 5u10 RHEL 6 RHEL 6u1RHEL 6u2 RHEL 6u3 RHEL 6u4 RHEL 6u5 How to correct the version issue when installing V6.9.1 on a RedHat OS version 6.6 Description of the error: When installing aveksa version 6.9.1 on a redhat os version 6.6 I had to...
Hits: 346

Posted by on in Access Management
So I ran into an issue with OAM 11gR2PS2 where I needed to modify the retry limit for the authentication scheme.  Previous versions of OAM used a system level value that you could define in oam-config.xml (per https://support.oracle.com/epmos/faces/DocumentDisplay?id=1360866.1).  When I tried that for PS2, I still saw the default 5 retries.   I then stumbled onto an article talking about someone exhibiting the behavior I desired when they didn't want it (https://support.oracle.com/epmos/faces/DocumentDisplay?id=1570598.1)   As a result, in my authentication scheme, I added OverrideRetryLimit=1 into my Challenge Parameters.  Once you click apply, the value takes effect.     The benefit to this modification, and...
Hits: 446
NetIQ has released a beta version of their Designer for IDM tool on the Mac OS.  For years Designer has only been supported on Windows and Linux but with this release NetIQ has officially taken that last step to add Mac support.  If you have a Mac and want to use Designer on your native OS without having to use a VM or dual-boot system, you can download the BETA version at the link below: Beta Designer for Mac OS You will need to register an account to download the required files if you do not already have one. If you...
Hits: 685
Our previous blog about creating custom review reports within RSA IMG (formerly Aveksa) focused on leveraging certain views, namely pv_users, pv_reviews, pv_review_component, and pv_unified_entitlment. (http://www.idmworks.com/blog/entry/creating-a-custom-aveksa-review-report). A few things to consider when writing custom reports, or modifying those that are supplied by RSA: 1.     What are the questions that need answering in this report? 2.     Are the views documented in the “Public Database Schema Reference” guide sufficient to answer these questions? 3.     Will I need to further reverse engineer the RSA IMG relational database to get the level of details, or necessary information to build this report?   Let’s examine each aspect:...
Hits: 498
We always receive requests for custom functionality here at IdentityForge. Sometimes meeting these needs are easy, other times it requires us to change our outlook.  On occasion we get a request that we know will benefit our other customers as well, no matter what industry or space they reside in.  A recent request boiled down to some very simple improvements on our end that for some of our clients would enable huge boulders to be moved.  We have this large financial client in Asia and they came to us requesting help with a laundry list of hurdles and game stoppers. The...
Hits: 369
If you’ve ever attended an IAM seminar or conference you’ve heard the scary statistics about failure rates for IAM projects, which are known to be as high as 70%. A major contributing factor to this in most organizations is the state of Active Directory. Since AD is the heart of user account information and access granted via groups, it is the natural starting point for any IAM rollout. However, orphaned accounts and groups, miscategorized employees and a lack of clear ownership over groups can lead to the wrong people having the wrong access.  IDMWORKS & STEALTHbits are co-presenting the webinar Getting Ahead of...
Hits: 422
When encountering issues with the Courion Access Assurance Suite Office 365 Account Management Module (AMM) or the Password Management Module (PMM), typically one of the following two errors will be captured in the Ticketing table and the microsoft-office365pmm.log - The user name or password is incorrect. Verify your user name, and then type your password again.       - Unable to authenticate your credentials. Make sure that your user name is in the format: <username>@<domain>. If this issue persists, contact Support.”   These are Office 365 specific errors and the likely causes are below:   1.      The user name or...
Hits: 475
  A feature of Oracle Mobile Security Suite is the integration with its Secure Mobile Mail app. It works great out of the box, but most customers want to customize it.   During a recent implementation, we found ways to customize this app including new logos and a custom bundle identifier (a necessary step for signing with your own cert). Here's how you do it:   1) Unzip the ipa from Oracle: unzip bmtouchdown_c14n_3_6_1_596_15159-unsigned.ipa   2) Go into the extracted Payload directory, right click on MyTouchDown and select Show Package Contents.   3) Make your modifications (edit info.plist to change bundle id, update png image...
Hits: 409
IDMWORKS and NetIQ recently co-sponsored the healthcare technology webinar “Seamless Integration for EHR Governance with NetIQ.” In case you missed it, here are the highlights from IDMWORKS CTO Chad Cromwell’s presentation: Why Has Identity Management Become a Priority for Healthcare Organizations? 1.       Regulations HIPPA privacy and other security statutes require more audit requirements and an increase in users that are required to access multiple systems. This is driving the need to streamline the user provisioning process. 2.       Automation Automating the provisioning increases the efficiency, improves service and decreases the security administration to perform these time consuming tasks.   Meaningful Use and...
Hits: 444
During a recent OMSS project, we found we were having issues with kerberos authentication. We tried the typical things such as turning up logging, etc. However we found that the Access Server logs weren't showing us everything we needed to see to troubleshoot the issue with kerberos. After some research and experimentation, we found a way to increase the log level just for the kerberos library used by OMSS (Heimdal, http://www.h5l.org/).  First, find the krb5.conf file located at $OMSS_HOME/msas/conf/krb5.conf. Find the following section:   [logging]   krb5 = STDERR   Replace the krb5 option with the following: krb5: logging = FILE:/tmp/krb.log  ...
Hits: 499
One concept common in medium-to-large software development projects is the separation of data-access code into layers. This has the benefits of separating concerns, easing testing, and simplifying dependencies. While the Go programming language has several ORMs in various stages of development to assist with this concept, most pull you further away from the database driver implementation, making it harder to leverage features specific to the underlying database (e.g. array and JSON column types in Postgres). With that in mind, in this post we'll discuss a simple strategy for separating data access in a Go project. The desired characteristics are: Models are...
Hits: 553
Oracle introduced their Mobile Security Suite last year and over the past few months we’ve had a chance to work with this exciting new product. One key piece of this product is the containerization tool, which containerizes and signs app to enable the secure tunnel, authentication through the secure container, encryption, etc.  Recently we had an issue when we tried to containerize an iOS app developed with the new Swift language. After we containerized and signed the app, we saw this error when running the app on the device itself: Error: /private/var/mobile/Containers/Bundle/Application/1291513D-A7C0-46FF-91B6-39F41B8C3A82/Directory.app/Frameworks/libswiftCore.dylib not valid: 0xe8008018: The identity used to sign the...
Hits: 682
Introduction The following guide will walk you through all of the steps necessary to create a series of REST activities in a custom ServiceNow workflow. We'll be using JSONPlaceholder as a REST API for the examples. This is a simple public JSON API that supports all of the various HTTP verbs and mocks the results. One of the endpoints supplied by the REST API is for managing hypothetical blog posts. The general workflow we'll be creating is this: Request a list of posts Store the ID of the first post Request a single post matching the stored ID Store the Title...
Hits: 1048


Contact Us

Please fill in all required fields.