Unable to Externalize users to Shared Services

Hi All,
I am facing the following issue
[Sun Jul  6 11:28:17 2008]Local/ESSBASE0///Error(1051429)
Analytical Services Product Existence Check Fails against the Shared Services Server with Error [Unable to Authenticate.]
Fatal Error: CSS Initialization Fails
I have also done the following steps but could not resolve..
STEP 1:
a. Shutdown all the Services
b. Take the backup of the file "Essbase.bak" by copying to another folder.
c. From Native Folder(ARBORPATH),Rename the "Essbase.bak" file to "Essbase.sec" file.
d. Reboot the machine where Essbase server is running.
e. Start the Services and work on the application.
If the issue still persists then Proceed with STEP 2
STEP 2:
Unregister the Analytic Services with Shared Services and then try reconfiguring Analytic Services from Configuration Utility (Especially register with Shared Services) and try working with the application
If you have any information about how to resolve the above issue, please help.. Thanks.
Message was edited by:
637223

Issue:
Error 1051429 - Unable to Externalize the Users to HSS.
Error Log:
[Sun Jul 6 11:28:17 2008]Local/ESSBASE0///Error (1051429)
Analytical Services Product Existence Check Fails against the Shared Services Server with Error [Unable to Authenticate.]
Fatal Error: CSS Initialization Fails
Environment:
Win Environment installed – Weblogic 9.1 / HSS / AAS / BI+/ Planning
Linux Environment Installed – Oracle DB 10 GR2
Linux Environment Installed – Essbase
Observation / Research:
Duplicate entries in Essbase.cfg file.
; The following entry specifies the full path to JVM.DLL
JvmModuleLocation /hyperion/common/JRE/Sun/1.5.0/lib/i386/server/libjvm.so
; SharedServicesLocation fatapp2.advtek.com.tw 58080
; AuthenticationModule CSS http://fatapp2.advtek.com.tw:58080/interop/framework/getCSSConfigFile
; SharedServicesLocation fatapp2.advtek.com.tw 58080
; AuthenticationModule CSS http://fatapp2.advtek.com.tw:58080/interop/framework/getCSSConfigFile
; SharedServicesLocation fatapp2.advtek.com.tw 58080
; AuthenticationModule CSS http://fatapp2.advtek.com.tw:58080/interop/framework/getCSSConfigFile
SharedServicesLocation fatapp2.advtek.com.tw 58080
AuthenticationModule CSS http://fatapp2.advtek.com.tw:58080/interop/framework/getCSSConfigFile
Solution:
** Altered the settings of the Essbase.cfg file as below
; The following entry specifies the full path to JVM.DLL
JvmModuleLocation /hyperion/common/JRE/Sun/1.5.0/lib/i386/server/libjvm.so
SharedServicesLocation fatapp2.advtek.com.tw 58080
AuthenticationModule CSS http://fatapp2.advtek.com.tw:58080/interop/framework/getCSSConfigFile
** Restarted all the Hyperion Services
** Logged into HSS, sync the OpenLDAP .
** Logged into AAS Console and Externalized all the users in Essbase to HSS
** Able to Externalize the users successfully.
** Created a sample application and a database and suggested the Customer to work out with the Applications.
Hope that it works for you :)

Similar Messages

  • Administration Users from Shared Services...

    Dear Experts,
    Am using OEPM 11.1.1.2
    I have one basic question on Shared Services Users...As we are using the default login of Essbase administration services after installation and configuration to
    login to the server and this is already changed to Shared Services Security during Configuration..
    My question is can we be able to create user related to EAS from Shared Services or still we need to use the same default 'admin'? If so,
    In any case if i want to provide one user with only "create/delete applications" for Essbase....i will go and do it in Shared Services.....
    but if i want to modify something in Essbase...i still need to use EAS for modifying the application/Database information
    How can i create multiple users in EAS?
    One More, i don't see any project for Essbase Administration Services like Essbase, APS created in Shared Services after the applications have moved to Shared Services Security Mode...Is this correct? Please clarify
    Moreover, in my case userid "admin" is used for all the Application groups in Shared Services...So if i change the password for this "ID", will it reflect to all the application groups who are privileged to...
    Thanks

    My question is can we be able to create user related to EAS from Shared Services or still we need to use the same default 'admin'? If so,
    In any case if i want to provide one user with only "create/delete applications" for Essbase....i will go and do it in Shared Services.....
    but if i want to modify something in Essbase...i still need to use EAS for modifying the application/Database information
    How can i create multiple users in EAS?
    One More, i don't see any project for Essbase Administration Services like Essbase, APS created in Shared Services after the applications have moved to Shared Services Security Mode...Is this correct? Please clarify
    Moreover, in my case userid "admin" is used for all the Application groups in Shared Services...So if i change the password for this "ID", will it reflect to all the application groups who are privileged to...
    Firstly, Shared services is a centralized User management console for all hyperion applications. Once you externalize your security to shared services, You can create as many users as you want in shared services and assign him access to Essbase. How ever, You will have to go to EAS and do a "refresh security from shared services" for changes made to users in shared services to reflect in Essbase.
    For projects to appear under shared services project list, you will have to register each product with the shared services.
    If the same admin ID is used for all applications, Yes, the password change will reflect to all applications he has access to.
    -Nra

  • Unable to start User Profile Sync Service

    Hi,
    I am currently facing some issues with starting the User Profile Sync Service on my SP2013 farm.. I was wondering if someone could help me out a bit.
    I have successfully installed the SP2013 farm on a environment that has access to our AD etc. and I have also
    restored the database from SP2007 and converted it to Claims authentication etc. The one thing I can’t get to work is to enable the User Profile Sync Service on the server. I have checked quite a bit of TechNet blogs and other sites and tried almost everything
    suggested but it still fails. I’ve also recreated the farm from scratch yesterday again but no luck still
    L.
    The below is what I have done:
    Farm Admin account – spadmin2013 is local admin on all SP Farm servers (2 WFE and 2 APP Servers) and has log on locally rights as well on security policy. On the SQL DB it has dbo permissions on the Sync, Profile and Social DB’s.
    Farm Service account – spservice-s is a managed farm account that is used to run the various services of the farm (used during the config wizard part).
    From within the Admin Control Panel I have verified the managed accounts and it is indeed spadmin2013 which owns the User Profile Sync Service (not the application itself). When I try to start the service it tries to do that for 5-10 minutes and then fails
    and goes back to stop and I do not see any error. I have created a custom service application with new database that runs on spadmin2013/spfarm/ldap accounts etc. I can see from the Windows services – FIM and FIMSync service try to start using the spadmin2013
    and then go back to disabled. I have also tried giving the spadmin2013 rights to replicate the AD as few blogs suggested that. I am not sure where this is going wrong or what is missing. I had successfully got this to work and still can get it to work on my
    first SP2013 server which is a standalone – running SQL, SP app and WFE on the same box.
    In fact I also tried to activate this service first before I joined my 3 other servers to the farm and had no luck. I am kinda lost here as to what is going on! 

    Right. i ran a new log as suggested. I have also cleared the config cache and created a Powershell profile as suggested in this link - http://blogs.msdn.com/b/bryanbolling/archive/2014/01/02/unable-to-start-user-profile-synchronization-service.aspx
    I checked the ULS Logs and i can see the below error -
    ILM Configuration: Validating account.
    ILM Configuration: Validating the system groups
    ILM Configuration: Setting up WMI
    ILM Configuration: Setting required permissions
    ILM Configuration: Create install config file
    ILM Configuration: Update source project
    ILM Configuration: Changing service account credentials
    ILM Configuration: Setting policy for service account
    Updating SPPersistedObject UserProfileApplication Name=User Profile Sync Service. Version: 63903 Ensure: False, HashCode: 55647834, Id: ef1ec55c-aa15-4cb7-a9fe-498382a88b4e, Stack:
    at Microsoft.Office.Server.Administration.UserProfileApplication.Update()
    at Microsoft.Office.Server.Administration.UserProfileApplication.SetupSynchronizationService(ProfileSynchronizationServiceInstance profileSyncInstance)
    at Microsoft.Office.Server.Administration.ProfileSynchronizationSetupJob.Execute(SPJobState state)
    at Microsoft.SharePoint.Administration.SPTimerJobInvokeInternal.Invoke(SPJobDefinition jd, Guid targetInstanceId, Boolean isTimerService, Int32& result)
    at Microsoft.SharePoint.Administration.SPTimerJobInvoke.Invoke(TimerJobExecuteData& data, Int32& result)
    SQL connection time: 131.92704 for Data Source=SPSQLAGL;Initial Catalog="Sync DB";Integrated Security=True;Enlist=False;Pooling=True;Min Pool Size=0;Max Pool Size=100;Connect Timeout=15;Application Name="SharePoint[OWSTIMER][1][Sync DB]"
    ILM Configuration: Configuring database
    ILM Configuration: Error 'ERR_CONFIG_DB'
    UserProfileApplication.SynchronizeMIIS: Failed to configure MIIS post database, will attempt during next rerun. Exception: System.Configuration.ConfigurationErrorsException: ERR_CONFIG_DB
    at Microsoft.Office.Server.UserProfiles.Synchronization.ILMPostSetupConfiguration.ValidateConfigurationResult(UInt32 result)
    at Microsoft.Office.Server.UserProfiles.Synchronization.ILMPostSetupConfiguration.ConfigureMiisStage2()
    at Microsoft.Office.Server.Administration.UserProfileApplication.SetupSynchronizationService(ProfileSynchronizationServiceInstance profileSyncInstance).
    UserProfileApplication.SynchronizeMIIS: End setup for 'User Profile Sync Service'.
    Updating SPPersistedObject ProfileSynchronizationSetupJob Name=ProfileSynchronizationSetupJob. Version: 63899 Ensure: False, HashCode: 36296732, Id: 7aeb377f-8bd1-453d-b6be-6a373eaf350d, Stack:
    at Microsoft.SharePoint.Administration.SPJobDefinition.Update()
    at Microsoft.Office.Server.Administration.ProfileSynchronizationSetupJob.Execute(SPJobState state)
    at Microsoft.SharePoint.Administration.SPTimerJobInvokeInternal.Invoke(SPJobDefinition jd, Guid targetInstanceId, Boolean isTimerService, Int32& result)
    at Microsoft.SharePoint.Administration.SPTimerJobInvoke.Invoke(TimerJobExecuteData& data, Int32& result)
    Leaving Monitored Scope (Timer Job ProfileSynchronizationSetupJob). Execution Time=6041.65717333333
    Name=Timer Job User Profile Sync Service_ProfileSynchronizationJob
    Updating SPPersistedObject ProfileSynchronizationSetupJob Name=ProfileSynchronizationSetupJob. Version: -1 Ensure: False, HashCode: 13918585, Id: 21e01df1-8772-487d-bd56-f699b3912bda, Stack:
    at Microsoft.SharePoint.Administration.SPJobDefinition.Update()
    at Microsoft.Office.Server.Administration.UserProfileApplication.StartSynchronizationServiceSetupTimer(String strSyncMachineAddress)
    at Microsoft.Office.Server.Administration.UserProfileApplication.SynchronizeMIIS()
    at Microsoft.Office.Server.Administration.ILMProfileSynchronizationJob.Execute()
    at Microsoft.Office.Server.Administration.UserProfileApplicationJob.Execute(SPJobState jobState)
    at Microsoft.SharePoint.Administration.SPTimerJobInvokeInternal.Invoke(SPJobDefinition jd, Guid targetInstanceId, Boolean isTimerService, Int32& result)
    at Microsoft.SharePoint.Administration.SPTimerJobInvoke.Invoke(TimerJobExecuteData& data, Int32& result)
    Updating SPPersistedObject ProfileSynchronizationSetupJob Name=ProfileSynchronizationSetupJob. Version: 63913 Ensure: False, HashCode: 13918585, Id: 21e01df1-8772-487d-bd56-f699b3912bda, Stack:
    at Microsoft.SharePoint.Administration.SPJobDefinition.Update()
    at Microsoft.Office.Server.Administration.UserProfileApplication.StartSynchronizationServiceSetupTimer(String strSyncMachineAddress)
    at Microsoft.Office.Server.Administration.UserProfileApplication.SynchronizeMIIS()
    at Microsoft.Office.Server.Administration.ILMProfileSynchronizationJob.Execute()
    at Microsoft.Office.Server.Administration.UserProfileApplicationJob.Execute(SPJobState jobState)
    at Microsoft.SharePoint.Administration.SPTimerJobInvokeInternal.Invoke(SPJobDefinition jd, Guid targetInstanceId, Boolean isTimerService, Int32& result)
    at Microsoft.SharePoint.Administration.SPTimerJobInvoke.Invoke(TimerJobExecuteData& data, Int32& result)
    I have verified the spadmin2013 does have dbo permissions and also is part of security & sysadmin in sql server. I run SQL 2012 with SP1

  • Grant the Essbase application permission to user in Shared Services

    Hi,
    We got a problem in granting the Essbase permission to user using Shared Services. We are using Hyperion 9.3.1.
    (1) We created an Essbase application + database through Essbase Administration Console, say TBC.Sales.
    (2) Provision the Essbase "Server Access" + Essbase Application "Read" roles to a user.
    (3) In Essbase Admin Console, we "Refresh Security from Shared Services".
    However, the user still cannot see the Essbase Database in SmartView. Does anyone know how to fix the problem?

    The problem is fixed with Essbase 9.3.1.3.0.5.

  • Exclude a user from Shared Services LCM export

    How do I exclude a specific user from the Shared Services LCM export?  In the migration definition file I am trying to specify something like the following:
    pattern="*" and pattern<>"lcm_admin"

    What exactly you want to try after/by exporting users from Shared services?
    Regards,
    Santy.

  • How to Generate a Report for a list of Users in Shared Services.

    I am using Hyperion 9.3.1 version.
    I have around 120 (MSAD) users in shared services and now i want to generate a report which tells what all access is given to a particular application for these users. Can anyone let me know the steps how to acheive this.
    Regards,
    Vijay Krishna.

    Hi,
    Have you tried generating a provisioning report in Shared Services, have a read of :- http://download.oracle.com/docs/cd/E10530_01/doc/epm.931/html_cas_help/provrep.htm
    If that doesn't suit your requirements then you could always have a look at using CSSImportExportUtility to export provisioning to a csv file. The utility is located in hyperion\common\utilities and has a pdf on instructions how to use it.
    Cheers
    John
    http://john-goodwin.blogspot.com/

  • Users in Shared Services

    Can someone tell me if there is a SQL table somewhere that stores the listing of users in Shared Services?
    Where would that data be stored?

    so John, you say that there is no chance to retrieve those users from relational-tables before v.11.1.2, right? is it possible in 11.1.2?
    actually i also need a scheduled report to see all users in HSS hence we're using same HSS with another project-team and both teams need such a kind of control report: "which users are able to see our project, who are in the other project... etc."
    i think, i should use CSSExport utility for creating such a scheduled report?
    do you have any suggestion?
    rgds,
    ozmo

  • No Users in Shared Services

    I cannot search users in shared Services .users for HSF :(
    can any one assist me

    Open ur services console
    select Share services >clik " log on" > > my account > provide ur user name and password this would help

  • Regarding issue with externalizing users to shared services

    Hello,
    I was working today on externalizing users to shared services through EAS Console & it went successful. But then I saw that the users were already externalized & there was already an application group existing in shared services. So now there are two application groups both clone of each other, i.e. if I provision any user with one application, the clone of that application is also provisioned through that user.
    The bigger problem is somehow the connect bet'n both SS & Essbase Services is lost & the users created in SS are not getting reflected in EAS, even after refreshing the securities on EAS... & then I tried to restart all the services again open LDAP, SS, IS, Essbase & Admin Services.... I am getting error while opening Essbase services, they are not getting started??? Please help me resolve this error...
    Thanks.

    Hi,
    What version are you installing and what O/S is it for ?
    If it is windows it is definitely an executable you are running and you are not trying execute one of the patches?
    Cheers
    John
    http://john-goodwin.blogspot.com/

  • Sync User with Shared Services

    I noticed that if I provision a user in shared services the user can not log into planning until I restart planning. Is there a way to do this without restarting planning? This also seems to happen with EPM.
    I know this happens with essbase but you can put a few commands in the essbase.cfg file and it can either sync on a time basis or when a user logs into the system.

    I am not sure what version you are using, but I will assume 9.3.1
    If so you shouldn't need to restart the planning server, once you have set them up in HSS the user should be able to log into planning, once the newly created user logs into planning the user is also created on the essbase (EAS) side as a planning user.
    If you set up a new user and then log into the planning app as an admin user, select a form and click assign access, then click add access, can you see the user in the list ?
    Cheers

  • Externalise users to Shared Services fails

    I recently tried to Externalise users to Shared Services. However, when I attempted to do this, I received the following error:
    [Thu Nov 13 15:29:12 2008]Local/ESSBASE0///Error(1051449)
    Analytical Services failed to get group with Error com/hyperion/css/spi/util/CSSGroupComparator
    I tried to Externalise again and then I received this error:
    [Thu Nov 13 15:33:20 2008]Local/ESSBASE0///Error(1051449)
    Analytical Services failed to get group with Error [CSS Error: Invalid Argument: Principal passed is NULL]
    And also, now whenever I tried to add a new user to Essbase thats authenticated externally, I receive this error:
    [Fri Nov 28 16:56:20 2008]Local/ESSBASE0///Error(1051223)
    Single Sign On function call [css_getUser] failed with error [CSS Error: Invalid Argument: Principal passed is NULL]
    Note, it did partially succeed in externalising to shared services, as the Essbase Cubes & Project to appear.
    Does anyone have any ideas on how to resolve these errors and successfully externalise to shared services?
    Edited by: user2062993 on 30/11/2008 19:32

    I have a similar situation at my end.
    reconfigure EAS console as from the configuration utility or mere editing the properties of the administration server will do.
    I tried editing the properties in the administration server but it dint help so should i go and reconfigure the EAS from the configuration utility .

  • Performance Scorecard - unable to sync security with Shared Services

    Hi all,
    after successful installation of HPS we have provisioned users in Shared Services console for using HPS application. Now we need to sync HPS application with HSS. We have logged as "admin" to run this sync but we are missing Administration menu.
    Could anyone give us an advice how to fix it?
    Thanks,
    Vladino

    Hi Amith,
    Before configuring EAS with Shared Services, please verify following:-
    1- Installaed relational database repository (SQL Server, Oracle, DB2).
    2- Create a database called hypdb in database repository.
    3- Create user called hypuser with valide password who has access on this database.
    4- Also ensure service related to database repository is running.
    Now try to configure EAS with SS. Hope it will help you.
    Atul K,

  • Maxl statement create user to shared services

    <p>when you create a user in shared services, you can specify afirst name, last name, and email address into textboxes.</p><p> </p><p>now, when you create a user with maxl, can you specify to placea first name, last name, and email address into those textboxes? ican only seem to add a comment into the description textbox.</p>

    <p>actually, you can't even insert text in the description textbox.the comment code with maxl statement is only for maxl and notshared services.</p>

  • Automate deletion of user in Shared Services

    Hi
    How can I automate the deletion of terminated users that are both externally authenticated(through MASD) as well as native in Shared services.
    Thank you
    Namita

    Will that key word in the user's description? Then yes you can filter those users in Shared Services.
    Check http://otndnld.oracle.co.jp/document/products/epm/111200/E-17236/epm.1112/epm_security_api/client/com/hyperion/css/common/UserSearchFilter.html
    Regards
    Celvin
    http://www.orahyplabs.com

  • Cannot externalize security to shared services

    After installing brand new essbase 11 and migrating applications from essbase 7, we have cannot externalize security.
    Only some applications get created under essbase in shared services Application Group folder.
    EAS console gets the following error (each time app name is different):
    Error: 1051419: Essbase Application [Spnd_CYF] Registration Fails against the Shared Services Server with Error [Shared Services is not initialized. Please retry the operation. If problem persists, please check the database configuration. Registeration failed: error.UnableToCreateFolder.Shared Services is not initialized. Please retry the operation. If problem persists, please check the database configuration. Registeration failed: error.UnableToCreateFolder.]
    SharedServices_Metadata.log gets the following:
    2010-01-06 13:34:30,057 [http-28080-Processor2] ERROR com.hyperion.eie.common.cms.CMSFacade - org.apache.slide.common.ServiceAccessException: Service org.apache.slide.store.impl.rdbms.JDBCStore@ad97f5 access error : [Hyperion][Oracle JDBC Driver]No more data available to read.
    2010-01-06 13:34:36,767 [http-28080-Processor2] ERROR com.hyperion.eie.common.cms.CMSFacade - org.apache.slide.common.ServiceAccessException: Service org.apache.slide.store.impl.rdbms.JDBCStore@ad97f5 access error : [Hyperion][Oracle JDBC Driver]No more data available to read.
    2010-01-06 13:34:36,767 [http-28080-Processor2] ERROR com.hyperion.eie.common.cms.registry.sync.SyncESBAPPInstances - Error parsing Registeration file CARRIER_HQ03ESSDEV3_1.instance: error.UnableToGetModelContent
    2010-01-06 13:34:36,767 [http-28080-Processor2] ERROR com.hyperion.eie.common.cms.registry.sync.CMSRegistryHelper - Sync operation failed for APPLICATION component: CARRIER: Error parsing Registeration file CARRIER_HQ03ESSDEV3_1.instance: error.UnableToGetModelContent
    2010-01-06 13:34:43,290 [Load EAP] ERROR com.hyperion.eie.common.cms.CMSFacade - org.apache.slide.common.ServiceAccessException: Service org.apache.slide.store.impl.rdbms.JDBCStore@ad97f5 access error : [Hyperion][Oracle JDBC Driver]No more data available to read.
    2010-01-06 13:37:35,659 [http-28080-Processor5] ERROR com.hyperion.eie.common.cms.CMSFacade - org.apache.slide.common.ServiceAccessException: Service org.apache.slide.store.impl.rdbms.JDBCStore@ad97f5 access error : [Hyperion][Oracle JDBC Driver]No more data available to read.
    2010-01-06 13:37:42,213 [http-28080-Processor5] ERROR com.hyperion.eie.common.cms.CMSFacade - org.apache.slide.common.ServiceAccessException: Service org.apache.slide.store.impl.rdbms.JDBCStore@ad97f5 access error : [Hyperion][Oracle JDBC Driver]No more data available to read.
    2010-01-06 13:37:48,845 [http-28080-Processor5] ERROR com.hyperion.eie.common.cms.CMSFacade - org.apache.slide.common.ServiceAccessException: Service org.apache.slide.store.impl.rdbms.JDBCStore@ad97f5 access error : [Hyperion][Oracle JDBC Driver]No more data available to read.
    2010-01-06 13:37:48,845 [http-28080-Processor5] ERROR com.hyperion.eie.common.cms.CMSFacade - com.hyperion.eie.common.cms.CMSException: error.UnableToCreateFolder
    2010-01-06 13:37:48,845 [http-28080-Processor5] ERROR com.hyperion.eie.modelmgmt.action.register1Action - Unable to create folder in /files/Products/ESBAPP-11.1.1.
    2010-01-06 13:37:48,845 [http-28080-Processor5] ERROR com.hyperion.eie.modelmgmt.action.register1Action - com.hyperion.eie.common.cms.CMSException: error.UnableToCreateFolder

    Forget this thread. I am able to rectify the issue. We forgot to give access to temp folder of EAS Console.

Maybe you are looking for

  • Open Sales order data

    Hi,    Can any one please help on identifying the table used for retrieving Open sales order data for a particular period, My requirement is to take the Volume of open sales order for Data migration volume assessment   Please help on this Thanks Raje

  • Hierarchical Query Sort help needed in 9i (9.2.0.6)

    Hello all, hope you guys are far away from IKE (it hit us pretty bad last weekend), anyway come to point My requirement is data sorted by name is such a way after parent show its childs (if exists) i.e first sort parents and then by childs within par

  • Unable to find Form.UDFFormUID property in B1 SDK 8.81

    Hello Experts, I'm quite new to SAP SDK and I have a little question for you: I know there should be a UDFFormUID property in the Form object of UI API, from B1 SDK 2007 and 8.8 also, as it is said for example in this thread: Form UDFFormUID new prop

  • I went over to iTunes Match and have lost about two thirds of my music collection. Can anyone help me get it back?

    I recently decided to pay for iTunes Match to save memory space on my two iphones, where I have an extensive music collection, which was synced with an iPad and several MacBooks and a desktop. However I am really horrified that in so doing I seem to

  • Syncing itouch memory over to iPad.

    recently I acquired an iPad for festivus and quickly realized that while I was able to successfully sync up my apps from itouch, it failed to carry over the memory of said apps. for example, high scores, specific app settings, user profile, you get t