Friday, May 20, 2011

Steps to Configure the Cross Domain Security Between WebLogic Server Domains

Cross Domain Security establishes trust between domains such that principals in a Subject from one WebLogic Server domain can make calls in another domain.
WebLogic Server establishes a security role for cross-domain users, and uses the WebLogic Credential Mapping security provider in each domain to store the credentials to be used by the cross-domain users.  

Configuration and use of cross-domain security is described in the following sections:
  • Configuring Cross-Domain Security
  • Configuring Cross-Domain User
  • Configure a Credential Mapping for Cross-Domain Security
Configuring Cross-Domain Security

1. If you have not already done so, in the Change Center of the Administration Console, click "Lock & Edit"
2. In the left pane, click on the domain name.

3. In the right pane, Select Security > General tab.

4. Check the Cross Domain Security Enabled.

5. Click Save and in the Change Center of the Administration Console, click "Activate Changes".
 

Configuring Cross-Domain User

1In the left pane, click on the security realms
 
2. In the right pane, click on myrealm
3. Add new user "cross-domain" under Users and Groups > Users tab.
 
4. Click on the "cross-domain" user to add this user to "CrossDomainConnectors" group and click on Groups tab. Move the "CrossDomainConnectors" from available list to chosen list.
5. Click Save to save all the changes for "cross-domain" user.

Configuring Credential Mapping for Cross-Domain Security

1In the left pane, click on the security realms
 
2. In the right pane, click on myrealm
 
3. Click new under Credential Mappings > Default tab.
 
4. Check "User cross-domain protocol" and In the Remote Domain field, enter the name of the remote domain that needs to interact with the local domain. Click next once done.
 
5. On the Create a New Security Credential Map Entry page, enter the following.
-- Local User: User configured in the local domain if not Automatically populated.
-- Remote User: User configured in the remote domain [base_domain2] that is authorized to interact with the local domain.
-- Remote Password: The password for the remote user.
6. Click Finish.
 
That's it. Now your Cross Domain Security Between WebLogic Server Domains should be enabled. 

Please leave your valuable comments.

89 comments:

Anonymous said...

Are you sure this works? I have spent two days now on wls 10.3.5 and it is not working at all. Here is what I am getting on remote domain:



My client is accessing a jsp page on local domain. In the process, he is getting authenticated and I have made sure that user "cross-domain" is used for this purpose (though I know this defeats the purpose). After this, the jsp I ma invoking is making a call to remote domain, and this call is failing with the above error.

Anonymous said...

error is:

java.lang.SecurityException: [Security:090398]Invalid Subject: principals=[cross-domain, CrossDomainConnectors].
java.lang.SecurityException: [Security:090398]Invalid Subject: principals=[cross-domain, CrossDomainConnectors]
at weblogic.security.service.SecurityServiceManager.seal(SecurityServiceManager.java:833)
at weblogic.security.service.SecurityServiceManager.getSealedSubjectFromWire(SecurityServiceManager.java:522)
at weblogic.rjvm.MsgAbbrevInputStream.getSubject(MsgAbbrevInputStream.java:352)
at weblogic.rmi.internal.BasicServerRef.acceptRequest(BasicServerRef.java:953)
at weblogic.rmi.internal.BasicServerRef.dispatch(BasicServerRef.java:351)
Truncated. see log file for complete stacktrace

Sunil Nandargi said...

I am sure this works. I have got it working with the steps in this Post.

Flo said...

Hi, i am using global trust at the moment. This works, but is not "wanted" by platform heads. We have to use CDS. We implemented it right the way you did (and changed the Global trust PW to different values), but got an error saying sth about user anonymous is not permitted to do that operation.... However the software Vendor told me to sync the global trust Passwords. Is Cross Dom Sec depending on the synced Global Trust PW or is it independent?

Imran Mirza said...

Do we need to do these steps in both domains? or just at the consumer domain that is trying to use JMS service?

Anonymous said...

I think that what you wrote was actually very logical.
But, consider this, what if you added a little content?
I ain't suggesting your content is not good, however what if you added a post title that makes people desire more? I mean "Steps to Configure the Cross Domain Security Between WebLogic Server Domains" is kinda boring. You might glance at Yahoo's home page and watch how they create post titles to
get viewers to open the links. You might try adding a
video or a related pic or two to grab readers excited about
everything've got to say. Just my opinion, it might make your blog a little bit more interesting.

my site ... 65352

Anonymous said...

Attractive component of content. I simply stumbled upon your site and in accession
capital to claim that I get actually loved
account your weblog posts. Any way I'll be subscribing for your augment and even I success you get entry to constantly quickly.

Here is my weblog - free web hosting site directory

Anonymous said...

When someone writes an article he/she retains
the idea of a user in his/her mind that how a user can understand it.
Thus that's why this post is outstdanding. Thanks!

Feel free to visit my website cccam free server

Anonymous said...

I'm curious to find out what blog platform you are working with? I'm having some minor security issues
with my latest blog and I'd like to find something more safeguarded. Do you have any recommendations?

Feel free to surf to my homepage: Best sat Box card share

Anonymous said...

Asking questions are actually fastidious thing if you are not understanding something completely, however this piece of
writing provides fastidious understanding yet.


Also visit my website cardshare

Anonymous said...

Pretty component to content. I simply stumbled upon your weblog and in accession capital to
claim that I get actually loved account your blog posts.
Any way I will be subscribing on your feeds or even I fulfillment you get
entry to consistently quickly.

my weblog :: how to test cccam server

Anonymous said...

I tend not to leave a comment, but after reading a
bunch of comments on this page "Steps to Configure the Cross Domain Security Between WebLogic Server Domains".
I do have a few questions for you if it's allright. Is it just me or do some of these remarks come across as if they are coming from brain dead folks? :-P And, if you are posting at other online sites, I would like to keep up with anything fresh you have to post. Could you make a list of all of your public pages like your Facebook page, twitter feed, or linkedin profile?

my weblog - raspberry ketones reviews

Anonymous said...

Incredible infοrmatiοn іn this aгtісlе.
I'm Carla from Clarion, United States and I am so glad to have seen this blog. By the way, I'd lοve tο get in contаct with уou.

Will you make sure you drop me а e-mai?

Lοok at my ωeb blog ... blogspot.com

Anonymous said...

Hello! Someone in my Myspace group shared this website with us so I came to check it out.
I'm definitely loving the information. I'm book-marking and will be tweeting
this to my followers! Wonderful blog and excellent design
and style.

Also visit my homepage; Idrotherapy Anti Aging

Anonymous said...

Fantastic post however , I was wanting to know if you could write a litte more on this topic?
I'd be very grateful if you could elaborate a little bit further. Thanks!

my site: Asphalt Driveway Mn

Anonymous said...

Wow that was unusual. I just wrote an extremely long
comment but after I clicked submit my comment didn't appear. Grrrr... well I'm not writing all that over again.
Anyhow, just wanted to say great blog!

Also visit my page: Slim Helper Diet Patches

Anonymous said...

Appreciating the persistence you put into your blog
and in depth information you provide. It's awesome to come across a blog every once in a while that isn't the same unwanted rehashed information.
Excellent read! I've bookmarked your site and I'm including your RSS feeds
to my Google account.

Also visit my web site :: Raspberry Ketone Reviews

Anonymous said...

Wow, this piece of writing is pleasant, my
sister is analyzing such things, so I am going to convey her.



Also visit my weblog: Dermajuvinate review

Anonymous said...

Appreciate the recommendation. Will try it out.

My web-site: Buy green tone pro

Anonymous said...

Hi there to all, how is everything, I think every one is getting more from this web page, and your views are good
for new viewers.

Here is my blog post Buy swiss rose

Anonymous said...

Hey I am so happy I found your site, I really found you by accident, while
I was looking on Aol for something else, Anyhow I am here
now and would just like to say thanks for a remarkable post and a all round entertaining blog (I also
love the theme/design), I don’t have time
to browse it all at the moment but I have saved it and also added in your RSS feeds, so when I
have time I will be back to read much more, Please do keep up
the great b.

My website ... Anatomy X5 Review

Anonymous said...

I every time spent my half an hour to read this webpage's content all the time along with a cup of coffee.

Feel free to surf to my page: Abercrombie Paris

Anonymous said...

Hi there! I understand this is somewhat off-topic however I had
to ask. Does running a well-established website like yours
take a massive amount work? I am completely new to operating a blog but I do write in my diary every day.
I'd like to start a blog so I can easily share my personal experience and feelings online. Please let me know if you have any kind of ideas or tips for brand new aspiring blog owners. Appreciate it!

Feel free to surf to my weblog - acai ultra lean review

Anonymous said...

Pretty! This was an incredibly wonderful article.
Many thanks for supplying these details.

Here is my web site: Power Pump XL

Anonymous said...

My brother recommended I would possibly like this blog.

He was totally right. This submit truly made my day. You cann't imagine simply how so much time I had spent for this information! Thanks!

Look at my blog :: www.wsmisports.com

Anonymous said...

Thanks for one's marvelous posting! I quite enjoyed reading it, you may be a great author.I will remember to bookmark your blog and definitely will come back in the foreseeable future. I want to encourage one to continue your great writing, have a nice afternoon!

Also visit my page; Louis Vuitton Outlet

Anonymous said...

I'm not sure where you're getting your info, but good topic.
I needs to spend some time learning much more or understanding more.
Thanks for magnificent info I was looking for this
information for my mission.

Also visit my site ... raspberry ketone ultra slim

Anonymous said...

This is a topic that is close to my heart.
.. Thank you! Where are your contact details though?


Feel free to visit my page ... raspberry ketone reviews

Anonymous said...

I know this web site presents quality depending content and extra stuff, is there any other website which presents these
kinds of stuff in quality?

Feel free to surf to my weblog ... Oakley Holbrook

Anonymous said...

I rarely leave a response, but i did some searching and wound up here "Steps to Configure the Cross Domain Security Between WebLogic Server Domains".
And I do have a few questions for you if
it's allright. Could it be only me or does it give the impression like a few of these remarks appear as if they are coming from brain dead visitors? :-P And, if you are posting on additional places, I would like to keep up with anything fresh you have to post. Would you list of all of your shared sites like your twitter feed, Facebook page or linkedin profile?

Feel free to visit my web page; Cheap NFL Jerseys

Anonymous said...

Hello there! Do you know if they make any plugins to
help with Search Engine Optimization? I'm trying to get my blog to rank for some targeted keywords but I'm not
seeing very good results. If you know of any please share.
Kudos!

my page click for source

Anonymous said...

I think that everything typed was actually very reasonable.
However, think about this, suppose you were
to write a awesome headline? I mean, I don't wish to tell you how to run your blog, however suppose you added a title to possibly get a person's attention?

I mean "Steps to Configure the Cross Domain Security Between WebLogic Server Domains" is a
little boring. You might glance at Yahoo's front page and watch how they write news titles to grab viewers to open the links. You might add a related video or a related pic or two to grab people excited about what you've written.

Just my opinion, it would make your website a little bit more interesting.


Feel free to visit my web-site ... Chaussures De Foot Pas Cher

Anonymous said...

Hey! I know this is kinda off topic but I was wondering which blog platform are you using for this site?

I'm getting sick and tired of Wordpress because I've had problems with
hackers and I'm looking at alternatives for another platform. I would be awesome if you could point me in the direction of a good platform.

Here is my web page :: Christian Louboutin Sale

Anonymous said...

Good post. I will be experiencing a few of these issues as well.
.

Also visit my webpage; Michael Kors Outlet - -

shrikant K said...

Hi,
I am also trying to achieve cross domain security, but facing some issue, thus seek your help.
Basically we have 2 weblogic instances (10.3.6) and exactly followed the same steps as explained for setting up cross domain security. I have 2 FORM based web applications and are deployed in each of these domain. Requirement is, when we navigate from one application to another using URL then control should directly navigate to home page of another application (as if both applications deployed in the same domain). But control is navigating to login page. I am not passing any user credentials though this URL.
Any clue will be much helpful

Unknown said...

Thank you for the setup steps, it works.

Anonymous said...

Webitech provide reliable and cheap hosting packages is all one considers when it comes to web hosting, we bring it to you. We guarantee you 99.98% uptime along with free domains. We offer you greatest and fair deals on FTP accounts, data storage and email services on the hosting packages. Our hosting packages our suitable for all kind of business as well as for personal use.
Web Hosting in Pakistan

Anonymous said...

Webitechpk.com Best Leading Web Hosting Company in Pakistan. Corporate cheap hosting services plans. We have both Linux and windows based business servers….
Web Hosting in Pakistan

Anonymous said...

For the first time in Pakistan, create your own website without worrying about costs. We provide professional quality web hosting completely free! WebITech is one of top best web hosting provider in Pakistan along with big cities, Karachi, Lahore, and Islamabad.….
Web Hosting in Pakistan

Anonymous said...

WebITech provide Best web hosting in Pakistan. You can also buy cheap reseller hosting in Pakistan. WebITech Provide domain registration, dedicated servers and reseller program. Webitech is a Cheap Hosting and Domain provider in Pakistan, We Deal in Web hosting, reseller, Domains and VPS in Pakistan…
Web Hosting in Pakistan

john smith said...

It would also help if the systems can automatically notify the authorities of trouble the moment it’s detected. Sydney CCTV systems

Unknown said...

Brilliant Content I like the way you describe your point in the content.do visit our blog for more health related content.health vania

Instagram Downloader said...

I am so grateful for your article. Much thanks.
Instagram Downloader Follower

Rashid Awan said...

I am grateful for your article
Pc SoftBox

Unknown said...

I am so grateful for your article. Much thanks.
Best Wirless Mouse

Wiral Eyes said...

I am so grateful for your article. Much thanks.
IMessag

Rafail said...

I am grateful for your article. Thanks
https://medium.com/@keen2learng/how-to-grow-instagram-followers-for-business-e066cbee19e0

Marcus Unger said...

Really helpful article. Great share
BUY INSTA FOLLOWERS

Anonymous said...

Really helpful article. Great share
VoVo Gifts

Unknown said...

Thank you for your helpful post. nice article.
packagingcompany

Unknown said...

Really helpful article. Great share
BWM - WIRELESS MOUSE

Unknown said...

Thank you for your helpful post. nice article.
packagingcompany

kuch bhi said...

Really helpful article. Great share
Vixari Tripod

Unknown said...

Thanks for this list. I have check all of these websites all are in working condition. and I can get many of the backlinks for my website.thanks packagingcompany

Unknown said...

I am really happy to say it’s an interesting post to read . I learn new information from your article , you are doing a great job . Keep it up. And must visit our site.Packaging Company

MainMuzammil said...

I am so grateful for your article. Much thanks.
how-to-download-instagram-video-on-pc


Unknown said...

Great blog. It was fun working on the project. Thanks to you for sharing the idea. I now know a thing or two more than I did before this. I am looking forward to adding more features to it soon. please visit our site.Packaging Company

Zubair Ahmad said...

Thats the Good work for all. Thanks.
Guardrail

Rashid Awan said...

I am so grateful for your article. Much thanks.
Pcsoftbox

Unknown said...

I am so grateful for your article. Much thanks.
Super Mario 63

Unknown said...

Very nice information! I really appreciate your effort. Very well! Thanks for sharing. Read more

Unknown said...

Nice working and info about nature we can't know but I think now we get something special. I love where your mind is going with the possibilities of bookmarking from the learning perspective.It also got me thinking about what it may do for us as the head of the class
Packaging Company

STARS HIDE said...

Really helpful article. Great share
Cake display fridge

kuch bhi said...

Really helpful article. Great share
Brokers Forex

MainMuzammil said...

"get Twitter followers

get Twitter followers

get Twitter followers

get Twitter followers

get Twitter followers"

Rafail said...

Thanks for this comlete list. I have check all of these websites, all are in working
and I get many of the backlinks for my website. Thanks...
getting real twitter followers

get real twitter followers

buy Twitter followers

real followers for twitter

real twitter followers

twitter real followers

Latest News said...

I am so grateful for your article. Much thanks.
stair platform

Latest News said...


I am so grateful for your article. Much thanks.
stairs and stairways

STARS HIDE said...

I am so grateful for your article. Much thanks.
windows 7 professional iso

Shaheryar said...

About Best Wireless Mouses Review:
Best Wireless Mouses is an incredible platform that claims to provide extensive reviews of the best wireless mouses. You can read reviews, check prices, and get to know about the solutions of your queries regarding wireless mouses.

Best wireless mouses
Wireless Mouses
Incredible Mouses

Zubair Ahmad said...

"Thanks for this complete list. I have check all of these websites, all are in working
and I get many of the backlinks for my website. Thanks...

SocialSteeze Reviews reverbnation

Social Steeze Review disqus

SocialSteeze Reviews dreamwidth

Social Steeze Reviews visual

Social Steeze Reviews ask

Latest News said...

I am so grateful for your article. Much thanks.
vista home premium.iso

Zubair Ahmad said...

"Thanks for this complete list. I have check all of these websites, all are in working
and I get many of the backlinks for my website. Thanks...

SocialSteeze Reviews buzzon

SocialSteeze Reviews storeboard

SocialSteeze Reviews codepen

SocialSteeze Review codecademy

awais chaudhry said...

Really helpful article. Great share

moby picture

weheartit

forms powwows

my foilo

github

gifyu

3gfycat

instructable

trello

tribber

awais chaudhry said...

Really helpful article. Great share

folkd

splice

edocr

seeking alpha

quora

tupalo

3Ddocracy

colour lovers

codepen

manageb


Unknown said...

Really helpful article. Great share

Photoshop Creative

Colour Lovers

500Px

Public Lab

Xoolit

Promo DJ

Torgi RU

It's My URL's

ManoZaidimai

Webes Tools

awais chaudhry said...



Really helpful article. Great share

codeademy

creative market

yellowbot

genius

trover

mindmakers

1880bets

able2knows

codepen

catchafire

awais chaudhry said...



Really helpful article. Great share

suncoastflatlanders

forum statcounter

forums spry

guildwork

lavida forum

awais chaudhry said...

Really helpful article. Great share

spreaker

mobypicture

weheartit

github

toyota

forums.powwows

gust

gifyu

gfycat

trello


jimmycharlis said...

Really helpful article. Great share

subsetgames

desktopnexus

shortest.sctiveboard

galvano.xobor

forum.elster

myfolio

brooklynne

forum.gamevil

coalitionguild

trackandfieldnews

Valencia home theater seating said...
This comment has been removed by the author.
jimmycharlis said...

Really helpful article. Great share

womensbeautyoffers

jimmycharlis said...

Really helpful article. Great share

getsatisfaction

facts of the day said...
This comment has been removed by the author.
facts of the day said...

Is your job required relocation in the UK? Are you currently living in Farnham? You need not worry about the moving task anymore. Man and van Farnham will completely handle this move efficiently in which you will get stress-free moving experience with us. We provide nationwide house removal services at cheap rates. Our services are extraordinary in which you really need not feel worried about anything. Our great team members will definitely take care of the whole move brilliantly. We also provide you surety that complete items will move from one place to another securely without any hesitation. For any type of query, you can frequently get our valued assistance in this regard. Our customer support team is always available to guide you.
Man and Van Guildford
Man and Van Guildford
Man and Van Woking
Man and Van Farnham
Man and Van Crawley
Man and Van Redhill
Phone number
020 8648 4433
079 8380 5143
Gmail: info@daddyremovals.com
Address: London UK

Sophia James said...

WoW Nicely written and describe with images, you should also read on News Engine about Best Computer Monitoring Softwares

jimu jee said...

I was reading your article and wondered if you had considered creating an ebook on this subject.
offshoreservers.net

Waqas Malik said...

https://goodwebsiteguide.blogspot.com/2014/11/online-marketing-jargon-buster.html#comment-form

Anonymous said...

Designing packaging is an essential component of any profitable company. Businesses may make their products stand out from the competition and boost sales by using efficient packaging design approaches. Businesses wishing to leave a lasting impression on clients might consider using personalised soap boxes. Custom soap boxes can be utilised to produce striking designs that will grab attention and increase sales with the appropriate strategy.