设为首页 收藏本站
查看: 878|回复: 0

[经验分享] EBS SSO屏蔽ApplLocalLogin.jsp登录

[复制链接]

尚未签到

发表于 2017-5-23 21:07:45 | 显示全部楼层 |阅读模式
注:以下仅为个人测试及见解
 EBS 版本:11.5.10.2
 背景:SSO单点登录时通过http://<host>.<domain>:<port>/登录EBS,会自动跳转至SSO统一登录界面,
       但Oracle EBS预留了登录后门,http://<host>.<domain>:<port>/OA_HTML/AppsLocalLogin.jsp,
       通过此URL仍然可以绕过SSO统一登录界面,由EBS登录界面进入系统。
 目的:是否可以屏蔽该URL,即使手工输入该URL,也限制只能从SSO统一界面登录EBS。
文档参考:
Applications SSO Login Types (APPS_SSO_LOCAL_LOGIN)
o SSO – Login is only allowed through Single Sign-On. The password is set to ‘EXTERNAL’ after a single sign-on account and an application account are linked.
o LOCAL – Login is only allowed via Oracle E-Business Suite local login. Passwords must be retained in the Oracle E-Business Suite and the account cannot be linked to any Oracle Internet Directory user.
o BOTH – Login can be through both single sign-on and Oracle E-Business Suite. Since changes to the Oracle E-Business Suite password can be synchronized to Oracle Internet Directory, but not vice versa, a user’s Single Sign-On password will not necessarily be synchronized with his Oracle E-Business Suite password.
 
测试步骤:1、将Applications SSO Login Types(英文环境下设置系统预置文件)值设置为“SSO”          2、新建EBS用户TEST1/ABC123
          3、同步至SSO
 测试结果: 1、同步SSO后,fnd_user表中encrypted_user_password与encrypted_foundation_password变更为“EXTERNAL”
            2、输入地址http://<host>.<domain>:<port>/OA_HTML/AppsLocalLogin.jsp,仍然可跳转至EBS登录界面
            3、用TEST1/ABC123登录EBS,失败
            4、通过SSO界面登录,成功(用户名/密码为SSO统一设置用户名/密码)
            5、通过SSO修改用户密码,同步至EBS,fnd_user中密码值为
            6、修改密码后重复步骤4、5,结果一样
            7、密码不为EXTERNAL的用户仍然可以通过输入URL方式从EBS直接登录系统
 
 测试步骤:1、将Applications SSO Login Types(英文环境下设置系统预置文件)值设置恢复为“BOTH”           2、通过SSO将TEST1的密码重置为ABC1234
           3、同步至SSO
 测试结果:1、同步SSO后,fnd_user表中encrypted_user_password与encrypted_foundation_password不再为“EXTERNAL”
           2、输入地址http://<host>.<domain>:<port>/OA_HTML/AppsLocalLogin.jsp,仍然可跳转至EBS登录界面           3、用TEST1/ABC123登录EBS,成功
           4、通过SSO界面登录,成功(用户名/密码为SSO统一设置用户名/密码)
 
另,Matelink上对于R12中SSO登录使用该预置文件一问询的回复
Able To Login Using AppsLocalLogin.jsp Inspite Of Applications SSO Login Types set to SSO [ID 468831.1]
 修改时间 28-NOV-2007     类型 PROBLEM     状态 MODERATED 
  In this Document
  Symptoms
  Cause
  Solution
  References
This document is being delivered to you via Oracle Support's Rapid Visibility (RaV) process, and therefore has not been subject to an independent technical review.
Applies to:
Oracle Applications Technology Stack - Version: 12.0
This problem can occur on any platform.
Symptoms
  On Release 12.0 :
Integrated Oracle E-Business Suite with SSO and OID, provisioning enabled from Applications to OID. Profile option "Applications SSO Login Types" is set to SSO to prevent users from using the local login URL :
  http://<host>.<domain>:<port>/OA_HTML/AppsLocalLogin.jsp
  Users are still able to login using the AppsLocalLogin.jsp inspite of the profile option "Applications SSO Login Types" being set to "SSO".
  EXPECTED BEHAVIOR
It should not allow login using AppsLocalLogin.jsp and display proper error message.

-- Steps To Reproduce:
The issue can be reproduced at will with the following steps:
  1. Create a test user from E-Business Suite and it should also be created in OID.
2. Encrypted_Foundation_Password and Encrypted_User_Password in FND_USER table is set to EXTERNAL.
3. User can login from the SSO login page as expected, but is also able to login successfully using AppsLocalLogin.jsp.
Cause
SSO users are able to create local sessions.

Fix is provided by version SessionMgr.java 120.36.12000000.7 which will be available in 12.0.4.
Solution
-- To implement the solution, please execute the following steps:
Please upgrade to Release 12.0.4 when it is available to download via Oracle Metalink.

1. Please ensure that you have taken a backup of your system before applying the recommended patch.
2. Always advisable to apply the patch in a test environment when available.
3. Retest the issue.
4. Migrate the solution as appropriate to other environments.

运维网声明 1、欢迎大家加入本站运维交流群:群②:261659950 群⑤:202807635 群⑦870801961 群⑧679858003
2、本站所有主题由该帖子作者发表,该帖子作者与运维网享有帖子相关版权
3、所有作品的著作权均归原作者享有,请您和我们一样尊重他人的著作权等合法权益。如果您对作品感到满意,请购买正版
4、禁止制作、复制、发布和传播具有反动、淫秽、色情、暴力、凶杀等内容的信息,一经发现立即删除。若您因此触犯法律,一切后果自负,我们对此不承担任何责任
5、所有资源均系网友上传或者通过网络收集,我们仅提供一个展示、介绍、观摩学习的平台,我们不对其内容的准确性、可靠性、正当性、安全性、合法性等负责,亦不承担任何法律责任
6、所有作品仅供您个人学习、研究或欣赏,不得用于商业或者其他用途,否则,一切后果均由您自己承担,我们对此不承担任何法律责任
7、如涉及侵犯版权等问题,请您及时通知我们,我们将立即采取措施予以解决
8、联系人Email:admin@iyunv.com 网址:www.yunweiku.com

所有资源均系网友上传或者通过网络收集,我们仅提供一个展示、介绍、观摩学习的平台,我们不对其承担任何法律责任,如涉及侵犯版权等问题,请您及时通知我们,我们将立即处理,联系人Email:kefu@iyunv.com,QQ:1061981298 本贴地址:https://www.yunweiku.com/thread-380132-1-1.html 上篇帖子: EBS打Patch通用步骤 下篇帖子: EBS DBA指南笔记2
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

扫码加入运维网微信交流群X

扫码加入运维网微信交流群

扫描二维码加入运维网微信交流群,最新一手资源尽在官方微信交流群!快快加入我们吧...

扫描微信二维码查看详情

客服E-mail:kefu@iyunv.com 客服QQ:1061981298


QQ群⑦:运维网交流群⑦ QQ群⑧:运维网交流群⑧ k8s群:运维网kubernetes交流群


提醒:禁止发布任何违反国家法律、法规的言论与图片等内容;本站内容均来自个人观点与网络等信息,非本站认同之观点.


本站大部分资源是网友从网上搜集分享而来,其版权均归原作者及其网站所有,我们尊重他人的合法权益,如有内容侵犯您的合法权益,请及时与我们联系进行核实删除!



合作伙伴: 青云cloud

快速回复 返回顶部 返回列表