New Features of OID in Fusion Middleware 11g
New Features of OID in Fusion Middleware 11g
New Features of OID in Fusion Middleware 11g
Enhanced Logging: The new orcltraceconndn and orcltraceconnip instancespecific configuration attributes allow you to specify logging based on a connection
distinguished name (DN) and IP address, respectively.
Restricting Binding to the Server. The new bindAuthPriv attribute allows you
to specify the users who can bind to Oracle Internet Directory server.
DIT View: You can create a DIT view, which is a virtual view or name space that
shows entries from a different or source DIT.
LDAP Replication Filter: Oracle Internet Directory server and the replication
server support filtering of specific entries based on an LDAP filter string configured
with theorclEntryExclusionFilter attribute in the replication agreement.
The new optional catalog command IOT option causes an Index Organized
Table (IOT) to be created for the specified attribute without creating an
additional index. The IOT option improves both read and write performance for
a normal LDAP operation and reduces the storage as well.
Shared Entry Cache: The entry cache now resides in shared memory, so
multiple Oracle Internet Directory server instances on the same host can share a
cache. If the host is part of a cluster, all hosts are notified to remove an entry when
it changes on one host. Not all search types are cached, only those that benefit
from the performance improvement. Attributes for configuring the cache now
reside in the DSA configuration entry..
DIT Masking: You can now restrict the DIT content that is exposed in an Oracle
Internet Directory server instance. This enables you to present different views of
the DIT to different users, depending on which instance they connect to.
Security Enhancements
o
Support for more SHA-2 variants: Several variants of the SHA-2 hashing
algorithm are now available for protecting user passwords
SSO Integration: You can configure ODSM to use Oracle Access Manager
11g or Oracle Access Manager 10g for single sign on.
Unlocking locked accounts: You can list and unlock locked accounts
from ODSM..
Configurable session timeout: You can control the length of time before an
inactive session times out.
LDAP Protocol Features
o
Support for the "+" option: You can use this option to return
operational attributes on a search..
Groups Features
o
Oracle Directory Services Manager: The old graphical user interface for
managing directories, Oracle Directory Manager, has been replaced by this webbased administration tool. Use it to manage Oracle Internet Directory and Oracle
Virtual Directory. You can invoke it directly or from Oracle Enterprise Manager
Fusion Middleware Control.
Improved Replication Manageability: You can set up and manage LDAPbased replication by using the replication wizard in Oracle Enterprise Manager
Fusion Middleware Control. A separate Replication page enables you to adjust
attributes that control the replication server.
Sizing and Tuning Wizard: You can obtain recommendations for tuning and
sizing by running the Sizing and Tuning wizard in Oracle Enterprise Manager Fusion
Middleware Control.