My Oracle Support Banner

WebLogic Server Support Pattern: Investigating Domain Trust Issues (Doc ID 1332288.1)

Last updated on SEPTEMBER 04, 2020

Applies to:

Oracle WebLogic Server - Version 10.0 and later
Information in this document applies to any platform.

Purpose

Problem Description

Intercommunication between two WebLogic Server domains results in a security exception.

NOTE: Examples of exceptions can be found in this document.

Why does trust need to be set between WLS domains?

During intercommunication between two WebLogic Server domains, caller identity (or kernel identity) is propagated from one domain to another domain. Since the subject is already authenticated in the calling domain, there is no need to authenticate the subject again in the second domain (server). To establish this kind of relationship, trust must be set between domains. EJB, JMS invocation from one server to another server, use of run-as for servlet or run-as-identity principal for EJBs from one server to another server are some examples of where trust needs to be set between domains. This is a requirement for interoperability between two domains. If there is no transaction context propagation requirement between two domains, there is no need to set the trust between the domains.

Troubleshooting Steps

To view full details, sign in with your My Oracle Support account.

Don't have a My Oracle Support account? Click to get started!


In this Document
Purpose
 Problem Description
 Why does trust need to be set between WLS domains?
Troubleshooting Steps
 How is trust set between WLS 10.0.x and 10.3.x domains?
 Global Trust
 Cross-Domain Security
 How is trust set between WLS 10.x and 9.2.x (or 8.1.x) domains?
 Default Trust Relationships
 What is the default trust relationship between two WLS 10.x domains?
 What is the default trust relationship between WLS 9.x and/or 10.x domains?
 What is the default trust relationship between WLS 6.x/7.x/8.1.x and 10.x (or 9.x) domains?
 Problem Troubleshooting
 Problem - between 8.1.x and 10.3.x domains
 Problem - between 10.3.4 domains
 Problem - error during the discovery of the Managed Server
 Need further help?

My Oracle Support provides customers with access to over a million knowledge articles and a vibrant support community of peers and Oracle experts.