IIQ with Oracle Internet Directory

Does anyone know how to integrate OID (Oracle Internet Directory) with IdentityIQ?

I found that the connection requirements provided in the OID portal do not seem to match the connection parameters available in the IIQ OID connector.

Also, if I have a URL in the following format:

<base_url>:<port>/<endpoint>

how should I configure the Host and Port fields in the OID connector? Should the host contain only the <base_url>, with the port configured separately, and where should the <endpoint> be specified?

Has anyone configured this successfully and can share the correct connection configuration?

IIQ version is 8.5
OID version is 14.1.2.1.0.

Hi @husseinhafez,

Could you confirm what protocol is being used for the URL <base_url>:<port>/<endpoint>?

For example, does the complete URL start with ldap://, ldaps://, or https://?

In short:

  • ldap:// — standard LDAP communication with the OID directory. For the IIQ OID Direct connector, you would configure the OID Host and LDAP listener port.
  • ldaps:// — LDAP over SSL/TLS. You would configure the Host and LDAPS listener port, enable the applicable SSL/TLS configuration, and make sure the OID certificate chain is trusted by the IIQ JVM.
  • https:// — typically indicates an HTTP/web endpoint. If you were given something like https://<host>:<port>/<endpoint>, we should first confirm what that endpoint represents, because the OID Direct connector connects to OID through LDAP/LDAPS rather than an HTTP-style endpoint.

For example, if the actual OID LDAP listener is:

ldap://oid.company.com:3060

the connector would use:

Host: oid.company.com
Port: 3060

The directory base/search DN, such as ou=People,dc=company,dc=com, would then be configured separately in the applicable OID connector settings.

References:

The default ports for Oracle Internet Directory (OID) are 3060 for plain LDAP and 3131 for LDAPS (SSL/TLS). These can be changed during installation, and the installer also picks a different port automatically if the default is already in use. Please confirm the actual ports with your OID administrator.

@husseinhafez Most of the details are already covered above. A few additional points from the connector guide:

  • The /<endpoint> in your URL — this likely maps to the Search DN field under Account Search Scope in the connector config (e.g. ou=People,dc=company,dc=com), not the Host or Port fields.

  • TLS setup — if using LDAPS, import the OID server’s X.509 certificate (and Root CA) into your IIQ JVM truststore via keytool, then enable Use TLS in the connector. If you hit hostname-verification errors, set disableLDAPHostnameVerification=true on the app debug page.

  • Version note — the connector guide lists OID 12C as the supported version. Since you’re on OID 14.1.2.1.0, worth confirming compatibility with SailPoint Support.