Can the Design Console authenticate against the OID?

Can the Design Console authenticate against the OID?
In my setup the users authenticate against the OID server when logging to OIM Web Console.
The OID has a plugin that redirects the authentication request to the Microsoft AD server.
That way the users can login to OIM Web Console using their Microsoft network password.
A small problem is that I have a handful of users that need to use the Design Console, and when they attempt to login it almost always fails at first.
It fails because they forget that the password they have to type on the Design Console login screen actually resides within the OIM Server and as time goes by the password becomes different then the one used to login to the Microsoft network.
So i wondered if it is somehow possible to configure the Design Console to authenticate against my OID server, then it would redirect the authentication request to the Microsoft AD Server and they would not have to bother about what is/was the password stored within the OIM.
Thanks for any thought on the matter.
Adriano.

Design Console always authenticate against the OIM user credentials. I suppose this is due to the factor that this does not behave as an http request over web, so its almost impossible to redirect the login request to some other server(AD/OID etc).
I also did not find this in the Oracle documentation, so I suppose its not possible. The AD Pass Syncwould work but just installing the AD Pass Sync for a handful of users (accessing design console) would not be recommended as it requires an agent to be installed on AD side. You might need to handle the OIM passwords for such users manually.

Similar Messages

  • How to give design console access to the user from OIM GUI - OIM 11g R2

    Hi,
    Could you please let me know if there is any way to give Design Console access to a normal user in OIM 11g R2.
    I tried by giving the access from backend by using DB command and I was able to give the design console access to the user.
    But I need to give design console access to the user from OIM Interface.
    Please let me know how to achieve this functionality.
    Thanks

    I have already used this approach by directly modifying the user record in DB.
    I am looking if it is possible to give Design console access from OIM GUI, the way we use to give in OIM 11g R1.

  • Problem connecting to OIM instance with the Design Console

    Hello,
    I've got questions about how to use the design console to connect to an OIM instance. I'm not the one who has set up the instance and the one who did cannot help me much. He did give me root access on the machine though.
    So first, I'm wondering how do I figure out which port I should connect to. All the doc I can find says that default port is 14000, but I don't understand what it's referring to. I can access to the Web Administration page for Fusion Middleware Control by going to <server_ip>:7001/em. Should I use port 7001? I can figure out that 14000 might not be the correct port because "netstat" does not show anything listening on that port.
    My second question is related to the credentials I should use to login to the console. According to the doc and tutorials I found, the user should be xelsysadm. However the person who has set up the instance does not remember having explicitly set a password for this user. Is it possible to log in to the console using the weblogic admin user?
    I've tried a couple of things, but nothing has worked so far. I always get an error of some some sort. I always get an Invalid Login, except when I log in with the weblogic user and set the following properties in xlconfig.xml:
    ApplicationURL= http://<server_ip>:7001/xlWebApp/loginWorkflowRenderer.do
    java.naming.provider.url= t3://<server_ip>:7001/oim
    With these config, I get this exception:
    javax.naming.NameNotFoundException: While trying to lookup 'ejb.stateful.tcDataBase#com.thortech.xl.ejb.interfaces.tcDataBaseRemote' didn't find subcontext 'stateful'. Resolved 'ejb'
    So that's pretty much where I'm at. I can't find any information that can help me, so any hint would be appreciated.
    Thanks for your time,
    jtellier

    try to login in weblogic console the port will be 7001. if you are able to do this then
    goto->service->security->realim->select user and groups (try to find the correct path)
    create user and then assign administrator groups to this user
    login with this user/password into OIM
    But for design console you don't need any url. if it is configured. go to <IDM_HOME>/designconsole/ and run xlclient.sh
    --nayan                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           

  • OIM11gr2 configure the Design console on Websphere

    Hi All,
    I installed OIM11gr2 with websphere 7 . now i am trying to configure the Design console ,for that i required IBM App Client as per the doc
    http://docs.oracle.com/cd/E37115_01/user.1112/e28523/manage_was_oim.htm#autoId4 ,  can anybody please let me know the link to download latest  IBM App Client.
    Thank You

    Where exactly are you failing ?
    As far as I remember correctly the Design Console installation installation on Linux environments requires a file similar to that of install_server.sh which doesn't comes with the installation media. So in most of the scenarios, the design console is kept on local windows environment. If that doesn't suits you then here is a solution which we did for moving forward.
    - Create a file named install_client.sh by copying the contents of the file from install_server.sh.
    - Open this file and go the the last part, where the jar invocation logic is specified and make the change as following:
    Existing - fi
    $JAVA_HOME/bin/java -cp "*setup_server.jar*:xlhome/install/xlCustom . . . . .
    *Modify To* - fi
    $JAVA_HOME/bin/java -cp "*setup_client.jar*:xlhome/install/xlCustom . . . . .
    Now invoke this sh file to begin installation. Let me know if you hit some issues.
    Thanks
    Sunny

  • Modifying DB connector through the design console

    Hi,
    I have installed the DB connector through the GTC feature in OIM 9.1.0.2. No modifications are required for the reconciliation and it works fine, how ever, I need to attach my own adapter for provisioning of a new user. Is it alright if I go ahead and modify the process definition through the design console, since Oracle documentation and Oracle support asks us not to modify the connector through the design console? Also, can this connector be exported and imported like the rest of the connectors or do I have to create it in every new environment?
    Thanks,
    Supreetha

    It will work but if you redefine the GTC connector any changes will be overwritten.
    On the support side the support for making changes to any artifacts created by GTC has varied by support person and time. It is not officially supported (most of the time).
    Best regards
    /Martin

  • Missing Features Within the Design Console for OIM 11g?

    Hello, I am currently trying to develop an approval workflow for a connector, however, under the process definition section, when I double-click the type I only have access to 'Provisioning', however many unofficial Oracle guides show an additional 'Approval' type. For what I need to do, I am in need of this 'Approval' choice. Is there an extension for the Design Console?
    As far as connectors go, I only have the DBUM connector installed. I am currently using Oracle Identity Manager 11.1.1.3.0.

    You'll want to read through the Upgrade document in the 11.1.1.5 version to know what the differences are in the features of 9.x and 11g or you will be asking many more questions about pieces that don't exist where they used to.
    -Kevin

  • The selected signed file could not be authenticated. The file might have been tampered with or an error might have occured during download. Please verify the MD5 hash value against the Cisco Systems web site

    I am trying to load any 9.0.3 firmware on my UCM 5.0.4.2000-1 server. Every newer firmware I load throws the following error. I have verified the MD5 is correct and also downloaded the file several times with the same result. I can load the same firmware file on another UCM server and it loads fine. Any ideas?
    Thanks in advance!
    Error Message:
    The selected signed file could not be authenticated. The file might have been  tampered with or an error might have occured during download. Please verify the  MD5 hash value against the Cisco Systems web site:  9b:b6:31:09:18:15:e7:c0:97:9f:e6:fe:9a:19:94:99
    Firmware File: cmterm-7970_7971-sccp.9-0-3.cop.sgn
    UCM version: 5.0.4.2000-1

    Thanks for your reply. We have a lab environment where I maintain  UCM 5.0, 5.1, 6.0, 6.1, 7.0, 7.1 and 8.0 servers each running the latest released firmware for our QA testing team. I have downloaded and installed the latest device packages but find that if I try to install any firmware newer then 8.3.1 on either 5.0.4 or 6.0 i start getting MD5 hash authentication errors. It looks like 9.0.3 firmware should work on UCM 5.0 and 6.0 so I am lost as to why I can't seem to update any firmware for any model phone if it is newer then version 8.3.1 on either 5.0 or 6.0. while 5.1 and 6.1 work without issues. Maybe it is just a bug. I mostly wanted to see if anyone else has experienced this or if it is just me.

  • Problem with the agent console created in the ESSO-Logon Manager 64 bits

    Friends,
    When I use the installer that I created in the console ESSO-Logon Manager for 32-bit, this I install it on the client side and when I synchronize with the console-Logon Manager ESSO brings me and I can see the agent all the templates I configured.
    I have a problem with the agent console created in the Logon Manager ESSO-64bit.
    When I use this installer on the client stations and then by the agent does not envision the applications that I have configured in the console.
    This causes you can not do single sign on to applications that I have configured in the client stations
    To generate this installer use the source name: ESSO-LMx64.msi
    Can someone please help me with this problem, this only happens when I use the msi installer on 64-bit client stations.
    Thanks.

    Jackson_Bill wrote:
    What IDE are you using and what platform?Read first.
    Moh Bob wrote:
    I'm using J2ME platform SDK 3.0
    db

  • Since 12/11/2014 Thunderbird 12.1.2 (Oracle ESR) crashed exactly 17 times , always when it the 'To' list searches against the LDAP

    Since 12/11/2014 Thunderbird 12.1.2 (Oracle ESR) crashed exactly 17 times , always when it the 'To' list searches against the LDAP.
    I have tried upgrading it from About > Help. But it never happened after the update download, as it always says some other instance of TB still runs on my computer when ever I Launch TB for the first time after a System Boot.
    Same thing happens in SAFE Mode as well.
    bp-26c9d605-bd89-4f48-90f5-947f72150129
    Thanks,Preeth

    http://kb.mozillazine.org/Profile_in_use

  • Can't access the recovery console after installing the Windows 7 RC

    Hi all,
    I recently installed the Windows 7 RC to give it a go but I've found that it kills my battery life so I decided to go back to vista, however when I press the blue button on start up to access the recovery console I just get a screen that asks me if I want to enter the BIOS or choose another boot location... I used the upgrade option in Windows 7 so I don't see how I could have deleted the partition with the recovery console...
    Is it posible for me to restore my tablet to it's factory settings?

    The install of Win 7 removes the TVT boot manager applet and sets the master boot record to Win 7 partition only.
    The Lenovo supported method of restoring your preload would be thru the use of Recovery CD's.
    You might be able to change the bootable partition from the win 7 partition to the recovery partition, thru some
    3rd party apps.
    Terry
    LESE
    Win 7 beta test

  • Can you change the design to adjust with the size of the browser window?

    I am creating my first site in iWeb, and would like the image in the background to adjust as someone adjusts the size of their browser window.  In other words, no matter what size their window is, the entire page fits.  I would like it to accomodate small to large computers and windows without them having to scroll up/down or sideways.
    Any ideas on how to do that?
    Thanks!

    Thanks Wyodor,
    I apologize, but apparently I typed "background" image instead of just an image.  I have an image on the page that I would like to size to do the same thing.  There are layered images on top of it, and I need those images to remain in the same place because they are hyperlinked images that take them to another page. I have attached a photo of what it looks like here. 
    The agree and disagree buttons are the hyperlinks, and I want them to stay static with the image underneath them.  I know that if I put the larger green image as a background image, to have it dynamic, the agree and disagree buttons would not stay in the correct spot when the browser size is adjusted. Thus, it brings me back to my question (but phrased correctly this time)... is there a way to have the entire site, images and all, be dynamic with the size of the browser? No matter what the size of the browser window, I would like the whole page to show so the hyperlink images stay with the image they are on top of.
    Thanks!

  • Settlement of the Final Balance Payment against the Down Payment Request

    Hi,
    How can I settle the Final Balance of a Vendor in SAP against the Down Payment Made under a PO Based Invoice. For Eg. - I have raised a PO of $10000.00 and made a Down Payment Request and Posted it through the APP for $ 300.00 the final balance under the FBL1N displays as $ 9700-, but the ZP Doc Types for Vendor Payment of Down Payment also appear in the Open Items and Status shown is in RED Colour and not in GREEN Colour and does not appears under the Cleared Items. Under the Cleared Items I am able to view the Original Down Payment Requests which I posted through Transaction F-47.
    I am unable to settle this Final Balance of $9700 against the Down Payment under the Vendor Account on the basis of a PO Based Invoice.
    Can some one please help me urgently on this.
    Thanks in Advance.
    Regards,
    Pankaj.

    Dear,
    The same requirements possible after implement EHP4 Package upgrade.
    Regards,
    Kishore

  • How to edit the Authorisation DB (authenticate-admin, the authenticate-admin-30 or the authenticate-session-owner-or-admin)

    Hi,
    Since i updated to os 10.9, i had to change my script which helps me to create a powerusers group, which has more rights than a normal user. It was no problem to change in the most rules the group key from admin to powerusers. I did this with the help of the security authorizationdb and the plistbuddy command. What I do not understand is why i can't change anything in the authenticate-admin, the authenticate-admin-30 or the authenticate-session-owner-or-admin rule. Anyone has an idea? I used the following command:
    security authorizationdb read authenticate-admin > /tmp/test.plist
    /usr/libexec/PlistBuddy -c "Set :group powerusers" /tmp/test.plist
    security authorizationdb write authenticate-admin < /tmp/test.plist
    The first two lines work ok but it won't write it back into the auth DB. The same command even won't work if i leave away the second line and change nothing in the plist file. Does anyone has tips or ideas how to resolve this? or inputs why it doesn't work?
    Thanks for your help!!

    Thanks for the link. I used it for my script and was able to change the group in a lot of rules from admin to powerusers. For example:
    security authorizationdb read system.preferences > $mod
    /usr/libexec/PlistBuddy -c "Set :group powerusers" $mod
    security authorizationdb write system.preferences < $mod
    This works fine. I could change 25 rules with it. But the rules authenticate-admin, authenticate-admin-30 or authenticate-session-owner-or-admin can't be written back into the authorisation file and I don't know why. I used exactly the same code that I used for the other rules.

  • Why won't the admin console go past the initial splash screen?

    Directory server is version 4.16, console is 4.2. Master server is running under Solaris 8, slave server is running under Solaris 7. Console won't load the directory instance on the Master (a different problem, which is why I'm trying to use a different console). Tried using the console on the slave and I can't get any further than the initial splash screen "Please log in...". Tried using the console on a Red Hat Linux 7.2 machine and I get the exact same result. startconsole -D produces:
    /usr/netscape/server4/bin/base/jre/bin/jre -native -ms8m -mx64m -cp .:/usr/netscape/server4/bin/base/jre/lib/rt.jar:/usr/netscape/server4/bin/base/jre/lib/i18n.jar:./swingall.jar:./ssl.zip:./ldapjdk.jar:./base.jar:./mcc42.jar:./mcc42_en.jar:./nmclf42.jar:./nmclf42_en.jar com.netscape.management.client.console.Console -D -A http://noc2.iu13.k12.pa.us:17718
    Netscape-Console/4.2 B
    RemoteImage: Create RemoteImage cache for sysLoader
    startconsole -f log.txt doesn't work - it won't accept -f as an argument.

    Kevin Myer wrote:
    Directory server is version 4.16, console is 4.2. Master server is
    running under Solaris 8, slave server is running under Solaris 7.
    Console won't load the directory instance on the Master (a different
    problem, which is why I'm trying to use a different console). Tried
    using the console on the slave and I can't get any further than the
    initial splash screen "Please log in...". Tried using the console on
    a Red Hat Linux 7.2 machine and I get the exact same result.
    startconsole -D produces:Try using the "-x nologo" option.

  • Where can I find the Designer column Description in the Repository ?

    I recently posted a question about where to find roles in the data model in Designer (what I was looking for was in ci_business_units (column role_responsibilities). That was a good discussion (and I was happy to find a Designer group).
    Now I am looking for the field "Description", here:
    I looked at all of these tables but couldn't find what I was looking for:
    sdd_folders app
    sdd_folder_members afm
    sdd_folders fol
    sdd_folder_members fms
    ci_modules mds
    ci_general_modules gen
    ci_module_business_units mbu
    ci_business_units bnu
    I also looked for columns like 'DESC%' in the entire d.b. and nothing seemed to be what I'm looking for.

    Hi Wim,
    There is an artikel at the technology blog of Amis "Quick Query to report on Entities and Attibutes in Oracle Designer" https://technology.amis.nl/2006/02/16/quick-query-to-report-on-entities-and-attributes-in-oracle-designer/ In that article they needed the Description of Entities and Attrbiutes which is inside CDI_TEXT. Maybe this is the same for the modules.
    Regards,
    Mark

Maybe you are looking for

  • How to trigger Sequence of processes in BPM

    Hi!  I am trying to implement process sequencing with BPM.Its like i have to trigger a set of processes(say 1,2 &3 ) if certain flag in input msg is set.If the flag is not set then processes (1,2&4 ).       the procecess should occur in a sequence li

  • What I did to my K410 after i bought it (random pics)

    I bought a K410 back in August, and like the PC tinkerer I am, i have been adding on to it for awhile now System befor: Link to image 1 System now: Link to image 2 Pics of my specs/benchmarks/setup: Link to image 3 Link to image 4 Still need to add a

  • F110 - No pymt possible because items with a debit bal.still exist; see job

    hi, I am getting the above error how to rectify the same? Regards,

  • SU10 with CUA

    hi I have implemented CUA and trying to change roles for some users through SU10, which is not hapenning, but when i do the changes through su01 to individual users the effect take place. I am not able to do a Mass User change. Any Suggestions Thanks

  • Nokia email e71

    Hello, Now I have began to use email much more seriously and of course for my old and lovely phone e71 the software support is awful. I want to ask the community a few questions, if I may: What is the latest version of nokia email or nokia messaging?