How to setup clients to use authentication to access OID

Hello,
I'd like to perform two tasks with OID:
1) anonymous OID browse for net service entries access to everyone (simple all client configuration - add LDAP naming method and ldap.ora)
2) password protected OID browse for particular net service entries to subset of users (for special clients who has to access restricted Net services)
I check documentation and played a bit and finally can perform task 1) with anonymous binds
Main problem is how to perform task 2). I try to follow guidance from http://download.oracle.com/docs/cd/E11882_01/network.112/e10836/config_concepts.htm#i484232
that I need to put those parameters to sqlnet.ora file:
names.ldap_authenticate_bind = TRUE
wallet_location = location_value
I start playing with Wallet Manager with no success yet.
Question:
1) Maybe somebody knows how to perform tasks above better than I suppose to do with little overhead for admin and end user?
2) Do I need to put all OID Net Service entries to wallets for all clients?
3) Do I need to simply create user in OID with enough privileges to access restricted net service names for browsing and put this user to wallet for all clients?
4) Other ideas?
Configuration:
I setup OID 11.1.1.3.0 on Windows XP 32-bit, import Net Service entries from tnsnames.ora, setup anonymous binding.
Thanks,
Sergiy

Hi
Do you have a radius/tacacs server in your infrastructure. What you want is to authenticate the user on the ASA before they get access to the devices.
Attached is a link to authenticating network access with the ASA
http://www.cisco.com/en/US/docs/security/asa/asa70/configuration/guide/fwaaa.html#wp1043431
HTH
Jon

Similar Messages

  • How many servers Client is using now?

    How many Servers Client is using now?
    Please give me rough idea that how many servers will be there in Sand Box and Golden Box ie Dev-Test-Prod?

    Hi SAP Landscape:
    Landscape is like a server system or like a layout of the servers or some may even call it the architecture of the servers viz. SAP is divided into three different lanscape DEV, QAS and PROD.
    - DEV would have multiple clients for ex: 190- Sandbox, 100- Golden, 180- Unit Test.
    - QAS may again have mutiple clients for ex: 300- Integration Test, 700 to 710 Training.
    - PROD may have something like a 200 Production.
    - SANDBOX for research and development
    These names and numbers are the implementer's discreet on how they want it or they have been using in their previous implementations or how is the client's business scenario.
    Now whatever you do in the Sandbox doesn't affect the other servers or clients. Whenever you think you are satisfied with your configuration and you think you can use it moving forward, you RE-DO it in the golden client (remember, this is a very neat and clean client and you cannot use it for rough usage). As you re-do everything that you had thought was important and usable, you get a transport request pop up upon saving everytime. You save it under a transport request and give your description to it. Thus the configuration is transported to the Unit Test client (180 in this example).
    You don't run any transaction or even use the SAP Easy Access screen on the 100 (golden) client. This is a configuration only client. Now upon a successful tranport by the Basis guy, you have all the configuration in the Testing client, just as it is in the Golden client. The configuration remains in sync between these two clients.
    But in the Testing client you can not even access SPRO (Display IMG) screen. It's a transaction only client where you perform the unit test. Upon a satisfactory unit test, you move the good configuration to the next SERVER (DEV). The incorrect or unsatisfactory configuration is corrected in Golden (may again as well be practised in the sandbox prior to Golden) and accordingly transported back to 180 (Unit Test) until the unit test affected by that particular config is satisfactory.
    The Golden client remains the 'database' (if you wanna call it that) or you may rather call it the 'ultimate' reference client for all the good, complete and final configuration that is being used in the implementation.
    In summary:
    Landscape : is the arrangement for the servers
    IDES : is purely for education purpose and is NOT INCLUDED in the landscape.
    DEVELOPMENT ---> QUALITY -
    > PRODUCTION
    DEVELOPMENT : is where the the consultants do the customization as per the company's requirement.
    QUALITY : is where the core team members and other members test the customization.
    PRODUCTION : is where the live data of the company is recorded.
    A request will flow from Dev->Qual->Prod and not backwards.
    1. Sandbox server: In the initial stages of any implementation project, You are given a sandbox server where you do all the configuration/customization as per the companies business process.
    2. Development Server: - Once the BBP gets signed off, the configuration is done is development server and saved in workbench requests, to be transported to Production server.
    3. Production Server: This is the last/ most refined client where the user will work after project GO LIVE. Any changes/ new develpoment is done is development client and the request is transported to production.
    These three are landscape of any Company. They organised their office in these three way. Developer develop their program in Development server and then transport it to test server. In testing server tester check/test the program and then transport it to Production Server. Later it will deploy to client from production server.
    Presentaion Server- Where SAP GUI have.
    Application Server - Where SAP Installed.
    Database Server - Where Database installed.

  • How to setup osx Firewall to allow incoming access to nginx?

    Hello!
    How to setup osx Firewall to allow incoming access to nginx (any port)?
    Local access is all fine, but when I trying to open http://<myip>:<port> from outside (other device in same network) there are no answer.
    If I turn off Firewall all works fine, but I want to keep my safety.
    Adding "nginx" binary file to Firewall  list doesn't help.

              "Victor" <[email protected]> wrote:
              >
              >Hi,
              >
              >I need to limit access on one JSP to a user. All the
              >other JSP's
              >should be available to averyone all the time. The following
              Victor,
              two ideas:
              1. Once you've seen where jspservlet compiles the jsp to, try adding
              an explicit servlet registration (then an acl for that servlet)
              I'm not sure if it would work, never tried.
              2. If it doesn't, well, you have a servlet class available from
              the jspservlet/jspc process. Move it to servletclasses (or wherever
              you keep other servlets) and register/acl it normally
              

  • How to setup client portal

    How do I setup client portal with user name and password to each clients file for their view and/or adding a pdf or other document?

    Could you put a few more words around the problem you're solving here, and some background?  (The answer to this question can range from a simple Apache directive to a huge content management system, depending on some of those details.)
    How many folks are involved (and what's your likely growth rate)?  (Small numbers of folks can be managed manually, where larger numbers of users means different choices.)
    Are you running Open Directory?  (Apache can be connected into that, and you can manage access from there.)
    Are you looking for a web content management system (CMS) in addition to controlling access to specific documents, or just the authentication?  (Uploading documents generally means keeping track of the associated files and avoiding collisions, which is more complex and can potentially be risky - file uploads can lead to web server breaches, if they're not managed correctly.  In comparision, controlling access and allowing downloads.)
    Web content management systems (which are more common choices for what can be called a "portal") have varying requirements and features.  There's a CMS matrix comparison site available.
    For some of the core features, the 10.6 Web Services manual as a starting point, looking at the Realms-related discussions there, and potentially at WebDAV.  It's also possible to password-protect specific directories using Apache directives; that's the simplest, but it doesn't scale all that well.

  • How to setup Datasource to use data triggers in Data Template

    hi all,
    Pls. let me know the process how to setup dataSourceRef that has to be mentioned in the data template tag for making use of various data triggers?
    I have packaged function which will create a temporary table that I am using in my main query. This whole process should happen in the beforereport trigger.
    can anyone help me in this regard.
    Thanks in advance
    Praneeth
    null

    Yes for triggers use need functions returning boolean value. These functions must reside in a package and you have to define package name as defaultPackage="package_name" in data template.

  • How to disable client cookie using Servlet code

    Hi All,
              I want to disable the client cookie using JSP or servlet code.Is it possible how I can do it.
              Thanks in Advance .

    Hi,
              first of all, the URL rewriting option (URLRewritingEnabled) in the weblogic.xml must be set to true.
              Now, for all first-timer web requests the BEA WLS always uses URL rewriting in addition to cookies to see wether the browser accepts cookies or not.
              I would try to rip of all of the cookies in the header, then flush the response to force the http header to be written.
              I have never tried it and has no idea if it will work, however the teory behind supports the idea.
              This will not work for toggling session tracking mechanism from a session already established with cookies, the session will be lost if attempted to do this without the URL-rewriting enabled on the page.
              - Anders M.

  • How to setup singnet email using other? So desperate.

    Can anyone in Singapore help me. I bought it from shop. How to setup singnet email under add new account> other>......

    Have you tried what is suggested here http://forums.hardwarezone.com.sg/showthread.php?t=3043300 ?
    Incoming : pop.singnet.com.sg
    Outgoing : mail.singnet.com.sg
    Edit: you should also be able to sync email account settings from your computer via iTunes on the device's Info tab (from the iPad manual) :
    You can sync email account settings from Mail on a Mac, and from Microsoft Outlook 2003, 2007, or 2010 or Microsoft Outlook Express on a PC. Account settings are only transferred from your computer to iPad. Changes you make to an email account on iPad don’t affect the account on your computer.
    Message was edited by: King_Penguin

  • How to let SAP user use SSO to access Application in DMZ?

    Hi All,
    Our J2EE application is running on a system in DMZ which can not be connected with LDAP. So I am wondering if it's possible to let SAP user use SSO to access our application.
    After talking with my colleague I think the only way is to import SSO public key to our WebAS and create user in UME and then assign user to the corresponding public key, but anybody know where to download SSP verification file or is it allowed to download and import into another system at all?
    Regards,
    Bin

    Hi,
    Take a look at this example, it uses property nodes to select tha
    active plot and then changes the color of that plot.
    If you want to make the number of plots dynamic you could use a for
    loop and an array of color boxes.
    I hope this helps.
    Regards,
    Juan Carlos
    N.I.
    Attachments:
    Changing_plot_color.vi ‏38 KB

  • How to Setup Allowed Websites using Customization Wizard 11

    I am wondering if it is possible to add a website to the list of allowed websites for Adobe Reader using the Adobe Customization Wizard 11?
    I am referring to the list of Web Sites specifically located under Edit => Preferences => Trust Manager => Internet Access from PDF Files outside the web browser => Change Settings => Web Sites.
    When an allow entry gets created in this list, it is stored in the HKCU registry key at the following location:
         HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\11.0\TrustManager\cDefaultLaunchURLPerms
    as a String Value named "tHostPerms" that contains the following info:  "version:2|sitename:2"
    I would like to setup some of our internal websites to be allowed in this list.  I am using the Adobe Customization Wizard 11 to create a custom transform file so that when I push out Adobe Reader 11 to my clients these settings will already be setup.
    Does anyone know if this can be setup using the Customization Wizard?

    It sounds like you already know how to configure the registry, so follow the suggestion above. Basically do this:
    Set up trust via the UI in an installed application.
    Open the Wizard.
    Go to Registry.
    Drag the registry from the configured app to the new installer (Destination Computer).
    There is a video tutorial of this feature at http://tv.adobe.com/show/acrobat-it-tips-tricks-tutorials/.
    ben

  • How to setup client computer ?

    Server is running 10.4 Tiger server and client 10.4 Tiger.
    I created a computer list in WGM, browsed and added my PowerBook G4 to the list. In WGM, selected the powerbook and clicked on Preferences, Login Items and checked option to allow all user groups. I rebooted the client. But cannot see the user account I created on the server here for login. Am I missing something ? How can I setup PowerBook G4 as the server's client ? Appreciate any help.

    Did you bind the client to the server in the clients /Applications/Utilities/Directory Access application? You need to enable the client to look for the directory through this application. After this is done, the login window on the client will have an "Other..." option where you can type in the user name and password for the account located on the server.
    By the way, you won't be able to see the users list of your servers directory in the Login window on the client, unless you have that option turned on in Workgroup Manager>Preferences>Computer Lists>(computer list the client is in)>Login Window. Then turn on "Show network users".
    Dual-core G5 2.0 GHz   Mac OS X (10.4.4)   2 GB (8x256) Ballistix Memory, 150GB WD Raptor (boot), 160GB OEM drive (media)

  • How to setup bidirectional streams using OEM.

    hi,
    can anyone guide me in setting up bi-directional streams using OEM??
    Thanks in Advance.

    Click on the database --> data Movement --> setup under streams. Follow the steps whether you want schema replication / table replication / etc. You need to populate the host credentials for oracle.

  • OBIEE Security - How to setup SSO-integrated EBS users & mobile access?

    I'm looking for the best approach to solution my company's OBIEE Security requirements, they are:
    1) Create a standard authentication/security process at an enterprise level
    2) Maintain EBS Roles to provide object-level and data-level security in OBIEE
    3) EBS Users must go through the EBS portal to get to OBIEE (ie. single signon integration)
    4) non-EBS users must go through the OBIEE portal
    5) Both EBS and non-EBS users need ability to use the OBIEE iPad mobile application
    So for the EBS users, I've implemented the SSO integration between OBIEE 11.1.1.5.0 and EBS R11 based on the Oracle white paper [ID 1343143.1]. I've also set up an Authorization session init block to read the user's EBS Roles and set up object/data level security.
    For the non-EBS users, I've kept the default identity store (WLS-LDAP) and authentication provider.
    My question is what's the best approach for providing mobile access to the EBS users? Obviously I can't pass an HTML cookie to the iPad for these guys. Assuming these EBS users are in an corporate-LDAP store, I was thinking to setup a dual authentication store that connects to both corporate-ldap(EBS) and the WLS-integrated LDAP(non-EBS).
    Will this work? Does anyone have a better approach they'd like to share?

    Please post the details of the application release, database version and OS.
    We have a customer, who has upgraded to EBS R12 recently. With EBS R12 there comes a responsibility that enables users to directly open embedded BI in EBS. When people do LDAP authentication to EBS, they can directly open the OBIEE inside the EBS. But, when the EBS is SSO (OAM+WNA) integrated, OBIEE SSO in EBS does not work. What is the error?
    It could be related that OAM generated cookies are not recognized by embedded OBIEE.
    Is there a way to do a setup with both OAM SSO enabled to EBS, and EBS-OBIEE SSO is enabled inside EBS ? I do not think there is a single document that covers all the above (I believe you are aware of the individual docs).
    For urgent issue, please always log a SR.
    Thanks,
    Hussein

  • How to setup a physical architecture for MS ACCESS in Solaris

    There isn't any odbc in Solaris platform. How can I access to MS ACCESS files?
    Thanks in advance!

    Hi, here are two solutions from metalink.
    a) Setting up a Sunopsis Agent on the Microsoft Windows system hosting the Access database which will use the ODBC / JDBC bridge for connecting to the Access database. The data may then, for example, be loaded by an Integration Interface into a Database on a Unix system for further processing.
    b) Seting up a Sunopsis Package made up of the following steps (to be executed on an Agent set up on the appropriate Microsoft Windows host)
    - 1. Run the SnpsSQLUnload Tool to extract the data to a Flat File on the Microsoft Windows host
    - 2. Use the SnpsFTP tool to transfer the file to a Unix system
    - 3. Run an Integration Interface from the Unix system file as Source.

  • How to setup AccessGate - OAM 10.1.4

    Hi All,
    How to setup AccessGate to use cluster?
    I read "3.4.4 Modifying an AccessGate" in Access Manager Admin Guide, but no hint in it.
    the tool configureAccessGate only let me fill just one server host name. But the host could be the single point error.
    -h Access Server Host Name
    -p Access Server Port
    Anybody has suggestions?
    Thanks & Regards,
    Justin

    Hi Vinod,
    Below is the content of ObAccessClient.xml. I can see two access servers are set. But the second is never used.
    <?xml version="1.0" encoding="utf-8"?>
    <CompoundList
    xmlns="http://www.oblix.com"
    ListName="ObAccessClient.tmp">
    <SimpleList>
    <NameValPair
    ParamName="id"
    Value="hat"></NameValPair>
    </SimpleList>
    <SimpleList>
    <NameValPair
    ParamName="accessClientPasswd"
    Value="004354474A"></NameValPair>
    </SimpleList>
    <SimpleList>
    <NameValPair
    ParamName="primaryCookieDomain"
    Value=""></NameValPair>
    </SimpleList>
    <SimpleList>
    <NameValPair
    ParamName="preferredHost"
    Value="16.157.68.238"></NameValPair>
    </SimpleList>
    <SimpleList>
    <NameValPair
    ParamName="state"
    Value="Enabled"></NameValPair>
    </SimpleList>
    <SimpleList>
    <NameValPair
    ParamName="maxCacheElems"
    Value="100000"></NameValPair>
    </SimpleList>
    <SimpleList>
    <NameValPair
    ParamName="cacheTimeout"
    Value="1800"></NameValPair>
    </SimpleList>
    <SimpleList>
    <NameValPair
    ParamName="cookieSessionTime"
    Value="3600"></NameValPair>
    </SimpleList>
    <SimpleList>
    <NameValPair
    ParamName="maxConnections"
    Value="10"></NameValPair>
    </SimpleList>
    <SimpleList>
    <NameValPair
    ParamName="maxSessionTime"
    Value="24"></NameValPair>
    </SimpleList>
    <SimpleList>
    <NameValPair
    ParamName="idleSessionTimeout"
    Value="3600"></NameValPair>
    </SimpleList>
    <SimpleList>
    <NameValPair
    ParamName="failoverThreshold"
    Value="2"></NameValPair>
    </SimpleList>
    <SimpleList>
    <NameValPair
    ParamName="aaaTimeoutThreshold"
    Value="-1"></NameValPair>
    </SimpleList>
    <SimpleList>
    <NameValPair
    ParamName="sleepFor"
    Value="60"></NameValPair>
    </SimpleList>
    <SimpleList>
    <NameValPair
    ParamName="debug"
    Value="false"></NameValPair>
    </SimpleList>
    <SimpleList>
    <NameValPair
    ParamName="security"
    Value="open"></NameValPair>
    </SimpleList>
    <SimpleList>
    <NameValPair
    ParamName="state"
    Value="Enabled"></NameValPair>
    </SimpleList>
    <SimpleList>
    <NameValPair
    ParamName="denyOnNotProtected"
    Value="0"></NameValPair>
    </SimpleList>
    <SimpleList>
    <NameValPair
    ParamName="cachePragmaHeader"
    Value="no-cache"></NameValPair>
    </SimpleList>
    <SimpleList>
    <NameValPair
    ParamName="cacheControlHeader"
    Value="no-cache"></NameValPair>
    </SimpleList>
    <SimpleList>
    <NameValPair
    ParamName="ipValidation"
    Value="1"></NameValPair>
    </SimpleList>
    <ValList
    xmlns="http://www.oblix.com"
    ListName="primary_server_list">
    <ValListMember
    Value="primaryServer1"></ValListMember>
    <ValListMember
    Value="primaryServer2"></ValListMember>
    </ValList>
    <ValNameList
    xmlns="http://www.oblix.com"
    ListName="primaryServer1">
    <NameValPair
    ParamName="host"
    Value="sip3.chn.com"></NameValPair>
    <NameValPair
    ParamName="port"
    Value="6080"></NameValPair>
    <NameValPair
    ParamName="numOfConnections"
    Value="5"></NameValPair>
    </ValNameList>
    <ValNameList
    xmlns="http://www.oblix.com"
    ListName="primaryServer2">
    <NameValPair
    ParamName="host"
    Value="sip4.chn.com"></NameValPair>
    <NameValPair
    ParamName="port"
    Value="6080"></NameValPair>
    <NameValPair
    ParamName="numOfConnections"
    Value="5"></NameValPair>
    </ValNameList>
    <ValList
    xmlns="http://www.oblix.com"
    ListName="secondary_server_list"></ValList>
    </CompoundList>

  • How to setup mail client in Data Integrator 11.7 to make use of mail_to()

    How to setup mail client in Data Integrator 11.7 to make use of mail_to() function.
    I am using mail_to() function in one of my job to know the status of source file. If source file is not ready, our DI job should fail and send mail notification with reason for failure.
    But mail_to() function is not sending any mail. I guess I need to set up email client.
    Any one please help to resolve this issue.
    Thanks
    Phani

    From the DI documentation that comes with the installation:
    To use this function, a mail client must be installed and running on the Job
    Server computer that calls the function. The login account for the mail client
    must have the same user name and password as the Data Integrator service.
    The type of client varies by the operating system:
    u2022 If the Job Server is on a computer running the Windows operating
    system, then the mail client must comply with MAPI (message application
    programming interface). In addition, the mail client must be configured as
    the default mail client. For example, Microsoft Outlook is a MAPI-based
    mail client.
    If the Job Server is on a computer running the UNIX operating system,
    then the mail client must be mailx-compliant.
    So:
    Mail client installed and configured and set as default
    Mail client uses the same credentials as the job server service
    Or use another function: smtp_to();
    If still not working or you are not allowed to use an installed mailclient on your box, then try Blat: http://www.blat.net/

Maybe you are looking for