Bi Publisher integration with SSO when users are in separate containers

Hi,
We have bi publisher 10.1.3.4 installed and setup to run with oas 10.1.3.3. Bi publisher as such works fine.
We need to get it integrated with sso and for that we have followed the steps in the bipub admin&ddeveloper guide, security model section:
http://download.oracle.com/docs/cd/E12844_01/doc/bip.1013/e12188/T421739T475591.htm#T434695
In our oid users are devided to 3 containers:
l=emea,dc=oracle,dc=com
l=amer,dc=oracle,dc=com
l=apac,dc=oracle,dc=com
If the "Distinguished Name for Users" in bi security configuration it set to e.g.
l=emea,dc=oracle,dc=com
and the admin user is created in the same container l=emea then login works fine for all users in l=emea container. They can login fine and they have the privileges defined in XMLP groups.
However this means any user in l=apac or l=amer container cannot login.
I've therefore created new admin user cn=bipadmin,dc=oracle,dc=com and change the user search base to be dc=oracle,dc=com. Now as the admin bipadmin user I can login fine and have the privileges as defined in XMLP groups.
Actual end users are in the l=emea, l=amer,l=apac containers and with the end users I can still login but the privileges are missing. So e.g. I can login as cn=xx.yy,l=emea,dc=oracle,dc=com or cn=aa.bb,l=amer,dc=oracle,dc=com but even though I've granted those users admin privileges the admin tab is not visible.
Distinguished name for groups has not changed. It has been the same all the time and the XMLP groups exists there:
cn=cappbb,cn=aitsys,cn=Groups,dc=oracle,dc=com.
But it seems if User search base is changed to higher level than where the users actually are the privileges are no longer found.
Is Bi Publisher supposed to search for users only from the container which is defined in the "Distinguished Name for Users" (in this case dc=oracle,dc=com) or is bi publisher supposed to search the users from all the subgroups also under the "Distinguished Name for Users" path?
If anyone has hit the same issue and has fond resolution please let me know.
Thanks!
Nina

Hi Nina,
User privileges will work fine even though the user search base is pointing at the higher level...
In my application I have defined the User search base as,
Distinguished Name for Users : O=ABC
And my users are under, 1. ABC---> Users ---> US ---> and 2. ABC ---> Vendors...
All users could you able to login along with their privileges...
But in your case, i would want you to recheck,the users group/role mapping...
Also check, if not admin role could you able to atleast import other groups/roles mapped to the user when you login...
I mean any functional roles (other than XMLP*) mapped to the users are imported...
thanks..
regards,
dmaze

Similar Messages

  • Windows network shares disappearing when users are logged on to Mac

    We are having some problems with windows network shares disappearing when users are logged on to Mac computers.
    We have a number of Mac labs that users can logon to using their AD login credentials. Their network shares are saved on a windows file server. The ad plug has been configured on each client Mac as has the LDAP plug-in. It is configured to connect to the Xserve which is running as an OD master. The system preferences for the client Macs are being managed from the Xserve.
    The problem for the users is that they can log into the Mac no problem and they can see their network share appearing on the desktop and in the dock, but for some reason on random Macs and with random users the network share disappears. If they log off and log back in again the network share is still missing. As it happens randomly I can not put my finger on what the problem is.
    Most labs either have Intel iMacs running 10.4.11 or Intel iMacs running 10.5.5
    Any help will be appreciated
    Noel Patterson
    Southern Regional College
    Northern Ireland

    Mike,
    We need to know some basic scoping information to provide any further input.
    1)     
    Is the user prompted that the server will be shutting down?
    2)     
    Does Task Scheduler show that the task ran at the scheduled time?
    3)     
    Are there any errors in %windir%\tasks\schedlgu.txt?
    4)     
    Does the problem still occur if the machine is in its own OU with blocked inheritance?
    Does the problem still occur in a clean boot configuration with MSConfig
    Steps to clean boot machine:
    ================
    Start > Run > Msconfig > Select Services > click "check box", "Hide all microsoft services" > Disable all
    Start > Run > Msconfig > Select startup>  Disable all
    Reboot
    Thanks,
    ankit

  • Oracle E-business Suite 11i(11.5.10.2) integration with SSO/AD.

    Hi,
    Please suggest any note/info on Oracle E-business Suite 11i(11.5.10.2) integration with SSO/AD.
    Thanks

    Hi,
    Please see these docs.
    Integrating Oracle E-Business Suite Release 11i with Oracle Internet Directory and Oracle Single Sign-On [ID 261914.1]
    How to integrate Active Directory with Applicactions 11i , with SSO/OID enable? [ID 437822.1]
    Oracle Application Server with Oracle E-Business Suite Release 11i FAQ [ID 186981.1]
    Thanks,
    Hussein

  • Error in BI publisher integration with OBIEE with SSO

    Hi,
    Whenever we click on BI publisher in OBIEE(More Products-> BI Publisher) which is Sitemider protected we are getting the below error.
    Reporting Login: Login failed. Please contact Administrator for your username/password.
    Even at the BI publisher , at the SSO section below setting are given.
    Single Sing-on Type: CA Siteminder
    Single Sign-off URL: http://[host]:[port]/
    How to get username: HTTP Header
    User Name Parameter : EIN
    How to get user locale: HTTP Header
    User Locale Parameter: LOCALE_LANGUAGE
    When I checked the sawlog, after clicking on BI publisher this is error which we are getting.
    Type: Error
    Severity: 42
    Time: Thu Jun 16 17:42:32 2011
    File: project/websubsystems/xmlpublisherreportingproxy.cpp Line: 87
    Properties: ThreadID-7296;HttpCommand-AdvancedReports;Proxy-605090109;RemoteIP-10.35.25.122;User-605090109;Impersonator-Impersonator
    Location:
    saw.httpserver.request
    saw.rpc.server.responder
    saw.rpc.server
    saw.rpc.server.handleConnection
    saw.rpc.server.dispatch
    saw.threadPool
    saw.threads
    Any other setting needs to be carried out for this BI publsher to work in SSO enabled OBIEE?
    Thanks in advance.

    Hi Kranthi,
    When i go through the 1st link, I have noticed the steps which are written for Enabling "Admin" tab in BI publisher.
    In my case, i am bale to see the Admin tab.
    But the error which i am getting is "Reporting Login: Login failed. Please contact Administrator for your username/password" after clicking on BI publisher in OBIEE which is Siteminder protected.
    I am not getting any error, if i disable the SM.
    In my case, OBIEE is working on IIS & BI publisher on OC4J and OBI version in 10.1.3.4.1.
    Thanks in advance.

  • Unable to view BI Publisher report with SSO configuration enabled

    Hi All,
    Can anybody let us know the configuration of the BI publisher with SSO enabled. We are unable to see any of the BI Publisher reports. without SSO configuration we have integration working perfectly fine with the OBIEE and Publisher.
    We followed the configuration steps to integrate BI Publisher with Oracle SSO. The following are the steps:
    1. deploy analytics.ear as a new application 'analyticsSOAP' in OAS
    2. protect analyticsSOAP in mod_osso.conf file under OAS
    3. change OBIEE Presentation services configuration to use analyticsSOAP/saw.dll
    4. run credstore utility to encrypt password
    5.restart xmlp server
    6.restart http server
    7.restart obiee server
    8. restart obiee presentation service
    Still we have issues when we try to accesses BI Publisher reports by clicking more Products -> BI Publisher or view reports directly on the OBIEE Dashboard
    Thanks in advance.

    configure one more virtual path which is unprotected from site minder. we had similar issue for Marketing and resolved by this virtual path.
    ref:
    http://vaandun-analytics.blogspot.com/2009/11/obi-publisher-with-empty-obi-catalog.html
    Thanks
    Sarathi

  • User pictures are not shown when users are added to person field in custom list

    Hi,
    Recently we have migrated our intranet from SP2010 to SP2013. We upgraded User profile service application, My sites and Intranet site to new environment. We haven't upgraded sites to use SP 2013 templates due to some business decisions. Everything
    is working fine and as expected.
    There are few lists in our environment where we have added users in a persons fields and allowed to show their pictures with details along with name. these user pictures are not being shown on to the page. After looking in picture property I found that "white
    Space" in a picture library name is replace by %2520 instead of %20 (/user%2520photos/profile%2520pictures).
    I tried reproducing problem on a new team site with SP 2010 template and it is reproduced however it is not occurring for a team site with SP 2013 template.
    Any suggestions would be very helpful for resolving this issue. Thanks in advance.
    -Amol Meshe

    We are experiencing the same issue. We get a /User%2520Photos/Profile%2520Pictures/ path anytime we use the people picker field with the option to display picture or the picture and details option.
    EDIT: This is only a problem on the list view. If you open the display form the image shows just fine. I can't see any setting view Edit Page and updating the web part that contains the list data to correct this.
    Michael Allen (.NET and SharePoint 2010 Developer)

  • Gateway failed error when users are trying to loginto the portal

    Hi,
    when the users are trying to log into the portal, the following error msg is displaying. most of the users are facing this problem
    "Connect to SAP gateway failed Connect_PM TYPE=B MSHOST=abcxyz144 GROUP=GP1 R3NAME=GP1 MSSERV=sapmsGP1 PCS=1 LOCATION"
    is the problem from r/3 system or from portal?  if it is from portal, what settings have to be done & if it is r/3 what have to be checked for the particular user to avoid such error message
    reply soon as this is very urgent issue.
    regards
    vv

    this is likely to be missing entries in your services file on the portal server.
    I would expect to see
    sapmsGP1 36xx
    or similar.  You might also want to make sure that you portal server can resolve the DNS name of your R/3 system.  ping abcxyz144 from the portal node to make sure.
    Haydn

  • Tighter Integration with Active Directory User Groups

    I just wrapped up a Jabber deployment with IM&P 9.1(1) and J4W clients 9.1(3).
    The customer asked me if it is on Cisco's roadmap to allow groups in Active Directory to be pulled into the Jabber client.  The primary business case is to allow those in IT to send out IM blasts to the corporation or certain departments.
    Obviously, this would require a significant amount of development and a much tighter integration with Active Directory, but I need to ask anyway.
    Has something like this been identified and placed on any roadmap?
    Thanks,
    Matthew Berry

    Unfortunately this kind of questions cannot be addressed here, roadmap questions need to go thru official channels for an answer.
    You need to reach your SE/AM for this question.
    HTH
    java
    if this helps, please rate
    www.cisco.com/go/pdihelpdesk

  • How do I get Mac Pro with Lion Server to restart at a set time when users are connected?

    I have recently configured a Mac Pro with Lion Server, and have set it to restart automatically every morning at 3am. When I arrive in the morning, I notice that it has not rebooted, usually because it states there are users connected. Is there a way to automatically disconnect users so that the machine will reboot.  No one is ACTIVELY connected at this time of the morning, but may still be logged in somewhere. I did see where I can log out users after a set period of time when using Workgroup Manager to manage a computer or computer group, but I don't use the server to manage all of the computers that have users log in.
    Thanks!

    Well, it doesn't necessarily have to be each and every night, but it was for the sole purpose of preventing sluggishness. We had it set up before, as Snow Leopard Server and it would restart every night. It would occasionally be slow and need rebooting, however a manual reboot was not possible by most people in the store as they did not have credentials to screen share and restart it - which would result in holding down the power button to shut it down.
    The server is used for the sole purpose of logging in about 50 users just so they can customize their experience, as well as saving items to their own home folders.  The store is closed during the night, and there is no reason anyone would be accessing it during the night.

  • BI Publisher Integration with EBS

    I Integrate BI Publisher with EBS security model, and almost everthing works fine.
    I have a EBS user with 2 responsibilities, and 2 reports in BI Publisher.
    I assign to my reports a diferent responsibility (The same for my user).
    When sign in BI Publisher I select a responsibility.
    When I open caltalog I see both reports, and I can execute both.
    If I change my responsibility in "My Account" I can still see and execute both reports.
    I can't see any diference in data results, between responsibilities changes
    How can I fix this?
    Regards,
    Rene

    Great. So you can logon to EBS then click a menu function in EBS to go straight to the analytics "Dashboards" or "Answers" (without another logon). You probably noticed that the link "More Products" - "BI Publisher" on Dashboards is broken. This is not supported following implementation of EBS Single Sign On (ICX_SESSION_COOKIE etc.). See the very latest release notes plus various bugs on mos.
    But yes you can as a workaround set up a normal HTML link in EBS (using javascript:void(window.open('http://host:port/xmlpserver/','_blank') to go to the Publisher logon page with security model EBS Security (uploaded databse configuration file DBC file from EBS). [BTW DBC security works on OC4J but currently bug throws error if deployed with latest WebLogic Server - I assume you are not using WLS?].
    Unfortunately the user will have to enter their EBS user name and password to get into publisher. You now have the problem that when the user runs a report with a data source using answers or logical sql on the jdbc connection to the biserver this will create a RPD session then the init block will fire to authenticate using the connection pool with the pre connect call to validate an icx session cookie that does not exist. I fixed this by creating a default value for session variable ICX_SESSION_COOKIE then called a custom xx version of app_session to handle the case for a user coming in from publisher who is already authenticated so that the FND_GLOBAL call will work required for the security init blocks (LEDGER etc.).

  • IOP 11.1.2.0 integration with Shared Services (User Provisioning)

    In the IOP 11.1.2.0 install guide, the Admin and Admin provisioning roles are provisioned through Shared Services.
    "Provision Integrated Operational Planning Administrator and Integrated Operational Planning
    Provisioning Manager roles for the Integrated Operational Planning instance to the Admin user through
    Oracle's Hyperion® Shared Services Console
    a. Connect to the Oracle's Hyperion® Shared Services Console; for example, http://
    hss_server:hssserver_port/interop.
    b. Log in as the administrator.
    c. Expand User Directories and Native Directory.
    d. Select Users and click Search.
    e. Right-click the Admin user and select Provision.
    f. Expand Default Application Group.
    g. Expand the Integrated Operational Planning instance created.
    h. Highlight IOP Administrator and Provisioning Manager.
    i. Click the right arrow in the middle of the two windows to select the roles.
    j. Click Save, and then click OK."
    The users and groups are defined in Shared Services, per the IOP 11.1.2.0 admin guide (p. 144).
    Is there an IOP user provisioning example in the shared services user's guide, and which version of the guide would I find that in?
    Access priveledges are controlled from the Admin workbench for IOP users, per p.145 of the IOP 11.1.2.00 user's guide.
    Thank you.

    IOP Roles are listed in the 11.1.2 Shared Services User and Role Security Guide, on page 158:
    Integrated Operational Planning Roles
    Table 39 Integrated Operational Planning Roles
    Roles Tasks per Role
    Provisioning Manager Provisions users and groups with Disclosure Management roles
    IOP Administrator Administers Oracle Integrated Operational Planning, Fusion Edition. IOP Administrators can modify models, access
    ACL pages, and perform all Integrated Operational Planning tasks
    IOP User P erforms Oracle Integrated Operational Planning, Fusion Edition actions as a normal user

  • WDA app not launched with SSO when called from portal

    Hi,
    we have configured our systems so that our portal (NW Portal 7.0) is issuing logon tickets and ERP6.0 is receiving them in the backend for single sign-on.
    When launching a SAP GUI for Windows transaction (System admin->Support->SAP Application) to test if the SSO is set up correctly, all goes well and I'm able to call e.g. SU01 with logon tickets from the portal.
    My problem is that when calling a Web Dynpro for ABAP application in the same backend system from the same portal, I get an error "SSO logon not possible; logon tickets not activated on the server" and need to login manually when starting the application.
    When looking at the WDA app URL, I see http://<backend server>.<domain1>.com/... and the portal is sitting on http://<portal server>.<domain2>.com. Could it be a problem if the backend system is in another domain? And if yes, how come the SAP GUI for Windows launch then works (related to an http connection and domain relaxing?)? How to go forward and make it work all right?
    Best regards,
    Mikko

    Hi Navarro,
    Merry Xmas:)
    >>We did the same test with the demo app from you (MS)
    http://msdn.microsoft.com/en-us/library/windows/apps/hh202967(v=vs.105).aspxand it still don't work. (remember to setup
    fast app resume)
    Yes, I can reproduce your issue using the official sample.
    I think this issue is caused by the mechanism of Fast app resume, please refer to the following reference:
    #Fast app resume for Windows Phone 8
    http://msdn.microsoft.com/en-us/library/windows/apps/jj735579(v=vs.105).aspx
    Quote:
    With Fast Resume, when an app is resumed, the system creates a new page instance for the target of the launch point and this page is placed on top of the app’s existing backstack.
    This official sample can also help us to understand how it works:
    https://code.msdn.microsoft.com/windowsapps/Fast-app-resume-backstack-f16baaa6
    We could find that the Application.Launching event will not be triggered if we used Fast app resume, this will affect responding Toast's parameter(Deep Link).
    We are trying to better understand customer views on social support experience, so your participation in this interview project would be greatly appreciated if you have time. Thanks for helping make community forums a great place.
    Click
    HERE to participate the survey.

  • Timeouts of applications integrated with SSO

    Hi,
    We integrated two applications with 10gAS SSO (using SSO SDK), but we have one problem. The timeouts of the applications are different. One of them is 2h and the other one is 15 minutes. The timeout should be counted form the last access time of either of the applications.
    Has anybody had a similar situation? If yes, how did you handle it?
    I am thinking about using a domain cookie that would contain the last access time to the applications. I will have to reset the timestamp in the cookie with each application call...
    But maybe there is a better way to do that?
    Thanks,
    Dmitry

    can you plase check if note Subject: (How To Get Custom Portal Page After Click ''Logout'' Hyperlink )
    Note:312126.1
    work for your issue
    fadi

  • Browser back button not working with ADF Application integrated with SSO

    I have integrated an adf application with Oracle SSO Authentication. Application is running fine.
    Though, while navigating between pages, using browser back button , it is not redirecting the url properly
    Should Redirect it to : http://<hostname>:<port>/<contex-root>/<servlet>/<id>
    Presently Redirecting it to :http://<hostname>:<port>/<contex-root>
    As, directory browsing is not allowed, there is Error 403--Forbidden .
    Can anybody tell what changes needs to be made to make browser back button work.

    In some of the documentation I have read, they have mentioned that using the back button in a browser doesn't work too well with any JSF type of application (not just ADF and Jdeveloper apps).
    http://docs.oracle.com/cd/E15051_01/web.1111/b31974/web_form.htm#CFHHJGJH
    Instead, they suggest using buttons on the form.
    There is a video on using navigation between forms that may be of value: http://www.youtube.com/watch?v=bsPtmRID5XI&feature=plcp
    Stuart
    Edited by: Stuart Fleming on Sep 11, 2012 5:30 AM

  • 10.6.8 Snow Leopard loses HP multi-function scanner connection when users are switched.

    I've got 10.6.8 (Snow Leopard) installed on an iMac with a USB attached HP multi-function printer/scanner/fax.
    I've removed all HP software and got the latest HP drivers from Software Update.
    The software was able to scan appropriately using Preview and Image Capture until my wife signed onto the computer using her id.
    (She switched users and logged into her account on the same iMac.)
    Upon switching back to my user id, there was 'No scanner detected.'  I removed and re-added the printer.  No luck.
    (In fact, upon re-adding the printer, the connection just showed 'USB' instead of 'USB multi-function', and doesn't find a scanner.)
    Rebooting solves the problem (until the next time we switch users).
    Anybody have any ideas?
    Thanks,
    Jimmy

    Is it possible to run the Macgames Realmyst disc on Snow Leopard10.6.8 at 64bit?
    I believe RealMyst is a "pure" is only PowerPC.  So it doesn't matter whether you boot in 32 or 64 bit but it does matter whether you installed Rosetta on your system (optional when you installed your system) to handle the ppc code.  Even with Rosetta there's no guarantees that app will run in 10.6.8.
    Also RealMyst is for OSX.  SheepShaver is for emulating Clasic OS9 so forget about that.

Maybe you are looking for

  • Directions sent from Mavericks 10.9.5 don't show up on iOS 8.3

    I just noticed today while trying to send directions from my Mac (Mavericks 10.9.5) to my iPad (3rd generation, iOS 8.3) that it doesn't show up on notifications nor in the App itself. I've tried: Logging out of iCloud on both devices and logging bac

  • Ipod Nano sync error :  Hard disk write protected

    I have a 2nd gen IPod nano 4 GB. I had Itunes 7.1 installed on my PC when I last synced. A week later my disk crashed and in the new disk I installed Itunes 7.2. When I tried to sync, I get a error message which says " disk is write protected. Please

  • Problem Playing AVI Files From Adobe Classroom In A Book

    Hiya, I just bought the Adobe Classroom In A Book for Premiere Pro CS4.  However, when I try to run Lesson 1, Premiere Pro appears to be having a cow with the AVI file needed for the project.  It tells me that the codec is missing or unavailable.  I'

  • 150009 Error while starting weblogic 7.0 SP 5

    Hi All, We have the following exception when trying to start the weblogic 7.0 SP5. We use Savvion's SBM4.0 deployed on weblogic and have got the followin exception. null javax.naming.CommunicationException. Root exception is java.net.ConnectException

  • Calendar launches but no window

    When launching Calendar, all I get is the menu bar -- no calendar window.  I tried one the suggestion of accessing Calendar via another user on this machine and it worked.  Any ideas on how to get my Calendar window back?