My Oracle Support Banner

OAM/OAAM/OIM: How to Retrieve/Use Email from LDAP for OTP (instead of User Entering Explicitly During OTP Registration) (Doc ID 2479516.1)

Last updated on JANUARY 24, 2019

Applies to:

Oracle Adaptive Access Manager - Version 11.1.2.0.0 and later
Oracle Access Manager - Version 11.1.2.0.0 and later
Information in this document applies to any platform.

Goal

We have integrated OAM/OAAM/OIM. Our users get created in back-end OVD/OID via OIM workflow (with approvals).


Our security policy does not allow users to set their own email address. We need to enable OTP on first login so that user enters username and then system determines user has never registered before and generates OTP, sends it to email address retrieved from user's LDAP (OID/OVD) object, user receives email and enters OTP into the prompt; upon successful authentication, the user is prompted to enter challenge questions/answers. Currently, OAAM forces user to set a dedicated email for OTP, which we cannot allow.

Is the user email stored in LDAP available to the com.bharosa.io.manager.user.DefaultContactInfoManager?

What is the recommended approach?

Can an LDAP pool available to OAAM be reused within a custom implementation of the DefaultContactInfoManager class?

Solution

To view full details, sign in with your My Oracle Support account.

Don't have a My Oracle Support account? Click to get started!


In this Document
Goal
Solution

My Oracle Support provides customers with access to over a million knowledge articles and a vibrant support community of peers and Oracle experts.