5.3 Recommended Installation Scenarios and Server Setup

When you perform a standalone installation, you should install the components in a specific order and on specific servers. The installation programs for some components require information about previously installed components.

This section helps you determine installation order and server types, according to specific scenarios for auditing and reporting.

5.3.1 Send Events to an Auditing Service without Reporting in Identity Manager

In this scenario, you plan to use Sentinel to audit events that occur in Identity Manager. You have no plans for generating reports in Identity Manager. Install the components in the following order:

  1. Sentinel Log Management for IGA

  2. Identity Vault

  3. Identity Manager engine, drivers, and iManager plug-ins

  4. (Optional) iManager

  5. Designer

  6. Tomcat and PostgreSQL

  7. OSP

  8. SSPR

  9. Identity Applications

  10. (Optional) Analyzer

5.3.2 Send Events to Identity Manager and Generate Reports

In this scenario, you plan to use the Sentinel Log Management for IGA that ships with Identity Manager to audit Identity Manager. You might also generate reports for those events. Install the components in the following order:

  1. Identity Vault

  2. Sentinel Log Management for IGA

  3. Identity Manager engine, drivers, and iManager plug-ins

  4. (Optional) iManager

  5. Designer

  6. Tomcat and PostgreSQL

  7. OSP

  8. SSPR

  9. Identity Applications

  10. Identity Reporting

  11. (Optional) Analyzer

5.3.3 Send Events to an External Service Before Pushing Events to Identity Manager

In this scenario, you plan to use a service such as Sentinel to audit Identity Manager. Install the components in the following order:

  1. External auditing service, such as Sentinel

  2. Identity Vault

  3. Identity Manager engine, drivers, and iManager plug-ins

  4. (Optional) iManager

  5. Designer

  6. Tomcat and PostgreSQL

  7. OSP

  8. SSPR

  9. Identity Applications

  10. Identity Reporting

  11. (Optional) Analyzer

5.3.4 Recommended Server Setup

In a typical production environment, you might install Identity Manager on seven or more servers, as well as on client workstations. For example:

Computer setup

Component setup

Servers 1 and 2 (two-server directory replica)

  • Identity Vault

  • Identity Manager Engine

Servers 3 and 4 (two-server cluster)

  • Identity applications

  • iManager

  • One SSO Provider

  • Remote Loader

  • Self Service Password Reset

Server 5 (or a cluster of servers)

Identity Manager databases:

  • Identity applications

  • Identity Reporting

Server 6 (not in a cluster)

Identity Reporting

Server 7

Sentinel Log Management for IGA

Client workstations (1+)

  • Designer

  • iManager Workstation

  • Internet browsers that access the identity applications and reporting

5.3.5 Selecting an Operating System Platform for Identity Manager

You can install the Identity Manager components on a variety of operating system platforms. The following table helps you determine which servers you might want to use for your identity management solution.

Platform

Component

Open Enterprise Server (OES)

Identity applications

Identity Manager engine

Identity Reporting

Identity Vault

iManager (server)

One SSO Provider

PostgreSQL

Remote Loader

Self Service Password Reset

Tomcat

NOTE:You cannot use the integrated installation process on a system running Open Enterprise Server 11 SP3 or Open Enterprise Server 2015 SP1.

openSUSE

Analyzer

Designer

iManager Workstation (client)

Red Hat Linux Server (RHEL)

Identity applications

Identity Manager engine

Identity Reporting

Identity Vault

iManager (server)

One SSO Provider

PostgreSQL

Remote Loader

Self Service Password Reset

Sentinel Log Management for IGA

Tomcat

SUSE Linux Enterprise Desktop (SLED)

Designer

SUSE Linux Enterprise Server (SLES)

Analyzer

Designer

Identity applications

Identity Manager engine

Identity Reporting

Identity Vault

iManager (server)

One SSO Provider

PostgreSQL

Remote Loader

Self Service Password Reset

Sentinel Log Management for IGA

Tomcat

Windows desktop

Designer

iManager Workstation (client)

Browser access to the identity applications and Identity Reporting

Windows Server

Analyzer

Designer

Identity applications

Identity Manager engine

Identity Reporting

Identity Vault

iManager (server)

.NET Remote Loader

One SSO Provider

PostgreSQL

Remote Loader

Self Service Password Reset

Tomcat

For more information about system requirements and prerequisites, see the following sections: