Do I have to run DNS service?

I'm wondering if I have to use the DNS service on OS X Server. I understand what DNS is but I'm admittedly in over my head with DNS and how to operate it properly on the server. We always have connection issues with various services within our office network that we don't experience anywhere else (ie: when we take the same laptop out of the office and use it on another network). I'm convinced it's the DNS setup on our server, which I'm sure has gotten messed up from all the poking around. But do we even need to be running this service?
The services we use on the server are VPN, iCal, File Sharing, and Blogs/Wikis. We have an airport extreme that serves DHCP router and our ISP supplied modem serves as our internet gateway and generic firewall (default settings).
Some examples of random access/connection problems we have within our office that we don't have elsewhere:
-email/web host access problems (new sub domains often do not appear unless we kill/reboot the DNS service)
-screensharing via iChat never works within our office network (not sure if that's DNS related or not, just another one of those things that never works within the office, but works fine when we take laptops outside of the office).
Any of this DNS related? Even if it's not, do I have to have DNS service running on our server?
Thanks!!

Bogus or buggy DNS can certainly cause issues, and so can a bad Ethernet cable or WiFi interference. Could be a misconfigured network. Could be somebody's corrupted the DNS configuration. Which of these might be the trigger in this case is difficult to say.
And no, you don't need to be running local DNS. But you do need access to DNS servers somewhere upstream of your clients, and your local boxes certainly can operate with either Bonjour (mDNS) or static IP assignments. Or with your own local DNS.
What the next step depends on your intent and your budget. If you want to learn and manage DNS, then Cricket Liu's DNS and BIND book is a good resource for learning. (And the CutEdge Systems DNS Enabler package -- though with a few weirdnesses aside -- has a more capable interface.) If you have somewhat more budget and less desire to learn DNS, then getting somebody in to verify and reconfigure (and secure) DNS is a valid approach.

Similar Messages

  • Running DNS service for SCAN in the openfiler VM

    Grid version     : 11.2.0.3
    Guest OS     : Oracle Enterprise Linux 6.3
    Host OS          : Windows 7 (64-bit ) with 16gb Physical RAM
    Hypervisor : Virtual Box 4.2.6
    Openfiler version : 2.99
    Using virtualBox, I am setting up a 2-node RAC node on Oracle Linux.
    I have a 3rd VM which runs openfiler ( NAS )
    For using SCAN feauture, I would like to run a DNS service as mentioned in the article below
    http://www.oracle-base.com/articles/linux/dns-configuration-for-scan.php
    I don't want to run the DNS service in any of the two RAC nodes. Instead of creating a separate VM just for the DNS , I am thinking of running it in the Openfiler VM.
    Openfiler is running in a Linux Distro called rPath. I am not sure if the packages mentioned in the above oracle-base.com article is available in this distro. Has anyone run a similair DNS service in the Openfiler OS ?

    I doubt it.  OpenFiler is a "stripped-down" OS.
    But Wait ! A Google search returned this : http://www.denbraber.org/?p=4
    Hemant K Chitale
    Edited by: Hemant K Chitale on Apr 22, 2013 5:10 PM

  • Do I need to run DNS on a colo server being accessed remotely via VPN?

    My Mac Mini Server is located in a colo site. We generally use it for Web, email and a couple of application-specific services. It has a dedicated IP address. We have a separate DNS service we use to point to the domains on the server located remotely from the server. Forward and reverse lookups work fine from the server, even though the local DNS service is turned off.
    However, we now have a couple of things we want to access remotely on the server via VPN (for example, some files via AFP). The firewall blocks remote AFP requests (using the built-in firewall, not a separate box). We can connect via VPN without problems. However, AFP does not work. If I allow AFP in the firewall and try to connect, no problems at all.
    Since the Mini is located by itself and will never likely have anything connected to a "local network" (never running DHCP, etc.), there generally doesn't seem to be a need to run DNS on the server.
    I suspect the problem is that when you VPN into the server you are on its "local network", whatever that means, so the DNS does not resolve since the local DNS service is not running. However, I am not positive of this.
    Must we run local DNS? Does it have to mirror the remote DNS that we currently reference? Can we somehow "reference" the local DNS from VPN clients trying to access local services?
    I hope this question makes some sense.

    Bear with me please....
    The Mac Mini is in a data center on a shelf, getting a direct connection to the Internet via ethernet with a fixed IP address (under the covers, I suspect that the data center is using some sort of router or switch, but I am not paying for a hardware firewall or other gateway). There is no local network for the Mini. It is not running DHCP, not handing out NAT addresses, etc. DNS is currently off. Rather than using the local DNS, the Mini is resolving its DNS needs with a DNS server located at another site, over the Internet. This seems to work fine (i.e., changeip confirms it is working and services seem to work).
    I am currently using the software firewall built into SLS.
    I want to turn on VPN so that remotely located computers can access services on the Mini without having to make the services visible through the firewall.
    I am able to connect devices via VPN with little difficulty (iPhones, Macs, etc.). However, when I try to access services (let's use AFP as an example), I cannot access them UNLESS they are allowed through the firewall. This tells me that I am not seeing the services through the VPN, but rather through the Internet directly.
    What I meant by "local network" is that the VPN allocates local IP addresses when devices log into the VPN service (10.0.x.x). There is no DHCP allocating these addresses, just VPN.
    My question is: why can I not see the services on the Mini blocked by the firewall when successfully logged into VPN on the server? Isn't the whole point of the VPN to gain access to services behind the firewall?
    I am guessing (with no particular information to support my thesis) that somehow without DNS running on the Mini, VPN clients are unable to access services on the Mini. I do not know for sure, however, if this is the problem. If it IS a problem, then the question is whether I should completely copy the DNS entries from the remote DNS server to the Mini and start the service. Will that solve the issue? Create conflicts with the DNS (since it is now located on both a remote service and on the Mini)? It certainly will create a maintenance headache since now I will have to maintain the DNS in both places.
    I am hesitant to migrate all of my DNS services to the Mini (because I will also have to go to the domain registrars to change where they point, etc.) to eliminate the remote one. And I am not sure it will solve this problem anyway.
    Sorry for all of the typing!

  • I have DHCPand DNS services in a router and I want to install domain controller

    Hello
    I have a sonic wall router managing the DHCP and DNS services for a my network and wanna keep it doing this.
    I have a computer running windows server 2012 standard and installed active directory along with DNS. I also went to the DNS manager of these server and forwarded the DNS addresses of my router.  For some reason I'm not able to join a client computer
    into the DC.
    I got this error:
    An Active directory domain controller (AD DC) for the domain "mydomain.ca"  could not be contacted.
    Is it possible to configure active directory using the DNS and DHCP services of my router? or Am I doing something wrong?
    Can somebody helping me with this matter?
    Thanks.

    Hello,
    if the DNS server on your router is able to provide all required zones, SRV records and options that the DCs require there is no problem using 3rd party DNS servers.
    But I would recommend that you u se the DC as DNS server also and just run the installation during the promotion process.
    All clients MUST use the domain internal DNS servers on the NIC NONE else otherwise you will run into trouble. Internet access will be done via the FORWARDERS on the DNS server properties in the DNS management console on the Windows Server.
    Best regards
    Meinolf Weber
    MVP, MCP, MCTS
    Microsoft MVP - Directory Services
    My Blog: http://blogs.msmvps.com/MWeber
    Disclaimer: This posting is provided AS IS with no warranties or guarantees and confers no rights.
    Twitter:  

  • I have installed the itunes but is not installing the Apple Mobile Device service it always that i try to install the itunes i have the same problem the error that appears is that the installer can run the service but the service is never installed

    Hi i have a problem I try to update my iphone but i can not do it, because every time that i try to install itunes appear an error that can start the Apple Mobile Deviece, and I could see that this service is never installed so that's why the installer can make run the services, does anybody know why this happen? My OS is windows 7, and I'm getting mad because i can update my music in my iphone thanks.

    Hello Skip Grantham,
    Thanks for using Apple Support Communities.
    it may be necessary to remove all traces of iTunes and related software components from your computer before reinstalling iTunes.
    For more information on this, take a look at:
    iTunes 11.1.4 for Windows: Unable to install or open
    http://support.apple.com/kb/TS5376
    Check for .dll files
    Go to C:\Program Files (x86)\iTunes and C:\Program Files\iTunes and look for .dll files.
    If you find QTMovie.DLL, or any other .dll files, move them to the desktop.
    Reboot your computer.
    Note: Depending on your operating system, you may only have one of the listed paths.
    Uninstall and reinstall iTunes
    Uninstall iTunes and all of its related components.
    Reboot your computer. If you can't uninstall a piece of Apple software, try using the Microsoft Program Install and Uninstall Utility.
    Re-download and reinstall iTunes 11.1.4.
    Best of luck,
    Mario

  • Newie Mail server and running other services

    We have a small office network of 6 macs that connect to a Panther server, this server provides DNS and file sharing and thats about it a Filemaker Sever and Retrospect Server. I doesn't suffer from heavy use
    I have been using a a separate mac to run Quickmail server 1 (os9) and I need to upgrade it as some of the mail protocols are out of date.
    We have a static IP address assigned to our mail gateway by our service provider.
    My question or advice
    Should I just start using OS X server to run mail services
    or
    Upgrade Quickmail and continue running it separately on a new mac mini (or similar)
    My concerns are at the moment any problem with email locally can be solved pretty much without effecting the other server or the network.
    Thanks

    The basic setup is prety simple...
    Replace following with your own equivalents...
    Domain name: woopee.com (the domain name after the "@" in your emails)
    Host name: mail.woopee.com (the hostname your MX record points to. Does not need to match server hostname. This will be the hostname mail server uses when communicating with other servers)
    Local Host Aliases: woopee.com (a list of the domains you want to accept mail for. Probably just same as Domain name?)
    Local network: 192.168.10.0/24 (LAN IP range for local users. Used to bypass authentication when they send mail out)
    Server Admin-> Mail-> General...
    Tick:Enable POP
    Tick:Enable IMAP
    Tick:Enable SMTP, Allow incoming mail, Enter Domain name & Host name (from above).
    Mail-> Relay
    Tick: Accept SMTP relays... Enter localhost IP: 127.0.0.1/32 and Local network (from above).
    Tick: Use these junk mail rejection servers. Add: zen.spamhaus.org
    Mail->Filters
    Tick: scan for junk mail. Minimum score: 5 (can be reduced later)
    Junk mail should be: Delivered (will just tag and forward to recipient)
    Tick: Attach subject tag: * Junkmail *
    Tick: Scan email for viruses
    Infected messages should be: Deleted
    Tick: update junk mail & virus database: 1 time per day
    Mail->Advanced->Security
    SMTP: none (this prevents smtp authentication from anyone outside your Local network)
    IMAP: Tick: Clear, Plain, Cram-md5 (or leave all unticked if only using pop accounts)
    POP: Tick: APOP
    Mail->Advanced->Hosting
    Local Host Aliases: Add: localhost & woopee.com (separate entries, see Local host aliases, above)
    That's it (I think ...although I cannot guarantee I have not missed something). There will be no problem setting this up and seeing it going whilst still using the existing mail server. Set up client accounts to send and receive from new server and you can send mail around internally to test. Last thing would be to change your firewall port-forwarding for SMTP from existing server to new one.
    Watch the mail.log in Console for any errors & do plenty tests.
    Ensure users have mail enabled in Workgroup Manager.
    There are plenty mods available beyond this. Have a good read through the mail services manual (I know its a bit confusing at times) and you should see where the above settings fit in.
    Lots of stuff on the forum here which you can search for. Spam filtering in particular can be made far more effective but requires editing of the underlying unix configuration files - again, plenty of previous discussions about that on forum. Meantime, the zen.spamhaus.org RBL will filter out a great many spammers.
    -david

  • Windows Server 2008 R2 DNS service issue with BitLocker

    I recently installed BitLocker on a Windows Server 2008 Platform. I did not encrypt the boot partition because the server hardware BIOS did not have the necessary requirements to encrypt the system drive.
    The Server roles are ADSM, DC and File Server. For DC operation I am also running the DNS service.
    When I installed the DNS role I was prompted to install the Log files on a different volume than the OS. I did this, but unfortunately, it was the same volume that was encrypted.
    Since I could not encrypt the system disk, the encrypted volume must be unlocked via password in order to mount. Here in lise my problem.
    When I do a full reboot of the server, I get to the point in the boot process where my mouse is visible and operational (this would be just before the Windows OS logo displays, I believe), then the server reboots. On the next boot up I am given the diagonstics
    and recovery dialog because the OS failed to boot.
    I believe the failure is the DNS service trying to launch, but because the log files are on the encrypted drive and it has not been unlocked, the system sees this as a security problem and reboots
    Does this make sense? If it does, is there a way to boot 2008 R2 with the DNS service disabled, say with the original install disk in recovery mode?
    Any help would be greatly appreciated as this system cannot be booted in its current state.
    Peter C. Hesse Network/Systems Administrator

    Hi,
    I believe you mean the Active Directory Logs not the DNS logs, because these are necessary to startup a domain controller, because the AD database depends on these logs.
    So if you have AD logs on a different partition and that is encrypted with Bitlocker you could probably automatically unlock it.
    So you did not encrypt OS partition because the server does not have a TPM fully compliant chip ?
    manage-bde /?
    manage-bde -autounlock -enable Driveletter:
    But you have to be able to boot server normal mode I am not sure if the command can be used in DSRM mode.
    Below are some links that might help:
    http://social.technet.microsoft.com/Forums/windowsserver/en-US/c52ffc7d-f822-4b61-b633-46f8e04eac80/bitlocker-for-domain-controller
    Hope this helps.
    Regards,
    Calin

  • Non-ISP DDNS with Apple DHCP and DNS Services

    I have two questions about Dynamic DNS (DDNS) as it applies to Apple's DNS and DHCP services within my home network. I am not talking about DDNS in the context of making my external-facing router available by a domain name on the Internet using the dynamically-assigned IP from my ISP.
    Starting with Snow Leopard Server, I attempted to use Apple's DNS and DHCP services (I have the firmware-based DHCP service in my router turned off.) The difficulty I immediately faced was that Apple's DHCP implementation didn't update the DNS service as IPs were handed out to DHCP clients. Because of this, it wasn't possible to access hosts by their hostname, since getting a DHCP-assigned dynamic IP at boot-up didn't do anything to automagically register the hostname-to-IP mapping in DNS. Manually registering the hostname in DNS was pointless, becuase over time the client IP address can and did change. I could create static IP assignments based on the MAC address, but doing that for all of the devices on my home network sort of defeated the purpose of using dynamic IPs.
    The only solution I eventually found was to go out and get an open source DHCP server, compile it for my Mac, install it, and configure it. After doing this, everything worked great; every time a new host or other device was booted it got a dynamic IP through DHCP, and then the DHCP server automatically updated Apple's DNS serive with the hostname and assigned IP. I could immediately access every device on my network by hostname. As IP addresses changed over time, the hostname-to-IP mapping in DNS was automatically updated.
    Except, Apple's point upgrades kept breaking my non-Apple DHCP install. Every time I applied software updates to my server I had to go back and re-finagle DHCP to get it to automatically start and run. By the time Lion Server came out, I drank the Kool-Aid and went back to Apple's DHCP implementation. I was disappointed that it still didn't seem able to update DNS with hostnames as it assigned IPs, but I was so tired of mucking about at the command prompt to fix DHCP every time Software Updates broke it, I just lived with the inconvenience of not being able to access devices on my network by hostname.
    I'm sorry to say this, but Windows Server has had this capability since at least server 2003. In fact, until I dumped my Windows Server and switched to Snow Leopard Server, I was running Microsoft's DNS and DHCP services on Server 2003 and they did exactly what I'm describing brilliantly.
    Can anyone offer any advice here? Does Mountain Lion's implementation of DHCP allow for DDNS updates to the DNS service? If not, how are other people handling this? Should I go back to running Windows Server for my DNS and DHCP services? My Netgear WNDR3700 router appears to have the standard, substandard DHCP server in firmware as most home routers, and no facility for DNS at all--much less the ability to update an on-site DNS sever with IP addresess it hands out. In fact, the only appliance I know of that does this is the InfoBlox my employer uses, but that's too expensive for a home solution.
    As a Post Script, I'll add that I've been VERY unhappy that I lost the ability to bind Windows clients to Open Directory under Lion Server. Since I'm starting to see articles that say this capability hasn't been added back to Mountain Lion Server, I'm seriously considering implementing a Windows Server AD master and establishing a "magic triangle" or "golden triangle". If I end up having to do that, I wonder if I might as well just go back to using Microsoft's DNS and DHCP services.

    Hi,
    Whether to move your DHCP to another server depends on the workload of your server. If there are too many clients on the network, you should move your DHCP to another server.
    Did the record which owned by the machine generate before you configure the DnsUpdateProxy group? You can try to regenerate the record and check the result.
    For more detailed information, you can view the link below.
    DNS best practices
    http://technet.microsoft.com/en-us/library/cc778439(v=ws.10).aspx
    Using DNS servers with DHCP
    http://technet.microsoft.com/en-us/library/cc787034(v=ws.10).aspx
    DNS registration changes for Windows Server 2003 based DHCP Servers
    http://technet.microsoft.com/en-us/library/ee441167(v=ws.10).aspx
    Hope this helps.
    Steven Lee
    TechNet Community Support

  • Is a Dynamic DNS Service included in my FiOS Bundle?

    I have the FiOS TV, Phone & Internet Bundle (internet upgraded for $5 extra for faster speeds) and switched from Cable.
    I know that Cable provided all of their Boost internet premium speed customers with a bundle of goodies, including a Dynamic DNS service.
    Does Verizon offer Dynamic DNS service included as well?
    If not, which is easiest to use (I have a Mac running OS X 10.5.7)
    I noticed that my FiOS Router Firmware has Dynamic DNS section, but it's very unclear as to if it is meant for a Verizon specific service or a third party service.
    Please advise; thanks! 
    --> Screenshot of Verizon Router Firmware screen - click here. 
    Message Edited by FireFish on 06-02-2009 01:22 AM
    Message Edited by FireFish on 06-02-2009 01:22 AM

    That screen you captured is where you would enter your dyndns.org account info and thereby get dynamic dns running on your setup.
    It's not really accurate to say the service is 'included' in the bundle, it's just that the router is capable of talking with this 3rd party service - most routers can do so nowadays.

  • DNS Service DOWN ! Someone plz explain to me why !

    Hi,
    Please, can someone explain to me why i receive this message :
    Server Server_Name BorderManager X.X.X.X DNS (Domain Name Service)
    SVCDOWN
    at 10:20:34
    And when i check the status of the DNS at the proxy console all my DNS
    are
    up and running ???
    What's going here ? And then i get the message that the DNS service is
    back
    online..
    Thanks in advance. !!!
    K. Chabot

    One thing that i forgot to say, we use a software called What's Up tomonitor all our servers, Pix, router, etc....
    Everytime i load named.nlm on a server and than i start monitoring it,
    what's up is always telling me that the service is down after a while,
    but
    in fact the service is up. I'm wondering if named doesn't refresh or
    do
    something that what's up could interpret as a down and re-up again.
    Any thought about this ?
    By the way, i did roll back to 5.53 for the tcp like you suggested, @
    first,
    i got a fatal warning that a critical error happened and i couldn't
    access
    any nic card bind to tcp without an error, so i just re-initialize the
    interface and reboot the server. It's now working, and i hope for a
    long
    long time !
    Did you have any issues regarding the tcpip 5.93 with border manager
    3.6 ?
    Isn't novell gonna patch this in the next service pack or do we need
    to back
    it up before any future service pack ?
    Again Craig, thanks a lot for your help !
    K. Chabot
    "K. Chabot" <[email protected]> wrote in message
    news:AR77b.22112$[email protected]..
    > Named i mean.
    >
    > "K. Chabot" <[email protected]> wrote in message
    > news:6R77b.22111$[email protected]..
    > > Yes Names was running on that server.
    > >
    > > "Craig Johnson" <[email protected]> wrote in message
    > > news:[email protected]..
    > > > Are you trying to run NAMED on that server by any chance?
    > > >
    > > > Craig Johnson
    > > > Novell Support Connection SysOp
    > > > *** For a current patch list, tips, handy files and books on
    > > > BorderManager, go to http://nscsysop.hypermart.net ***
    > > >
    > >
    > >
    >
    >

  • I have to run network diagnostics everytime I login.

    I have to run network diagnostics every time I login or wake my iMac. All other devices work fine. This has been going on for months. Any suggestions on fixing this?

    Hi, this has worked for a few...
    Make a New Location, Using network locations in Mac OS X ...
    http://support.apple.com/kb/HT2712
    old... http://docs.info.apple.com/article.html?artnum=106653
    Make a New Location, Using network locations in Mac OS X ...
    http://support.apple.com/kb/HT2712
    10.7…
    System Preferences>Network, top of window>Locations>Edit Locations, little plus icon, give it a name.
    10.5.x/10.6.x/10.7.x instructions...
    System Preferences>Network, click on the little gear at the bottom next to the + & - icons, (unlock lock first if locked), choose Set Service Order.
    The interface that connects to the Internet should be dragged to the top of the list.
    Instead of joining your Network from the list, click the WiFi icon at the top, and click join other network. Fill in everything as needed.
    For 10.5/10.6, System Preferences>Network, unlock the lock if need be, highlight the Interface you use to connect to Internet, click on the advanced button, click on the DNS tab, click on the little plus icon, then add these numbers...
    208.67.222.222
    208.67.220.220
    Click OK.
    Also, turn off IPv6:
    System Preferences » Network » AirPort » TCP/IP tab » Configure IPv6
    Or whatever Interface you use.

  • Compatible Dynamic DNS Services

    Does anyone know about ANY FREE Dynamic DNS service compatible with the Dynamic Global Hostname settings in Airport Extreme (MC340LL/A A1354)?
    My registar/hosting (DreamHost) doesn't allow dynamic dns updates, except through local shell or perl scripts, or APIs on the web server — as far as I know. Dyndns.com only allows it with Custom DNS Zones, which are not free. And I would rather not use those silly update clients.
    Oh, and I'm not willing to pay $99/yr for a MobileMe account just to have my home.owndomain.com pointed to my dynamic IP. Ain't gonna happen!
    Thanks in advance!

    Hi, Tesserax. Thanks for the welcome!
    I've been using DynDNS with a D-Link router, but it got replaced.
    Their words:
    <!-- Note on DynDNS Free and DynDNS Pro: We currently do not support the AirPort or Time Capsule devices on our Free and Pro Dynamic DNS services. You must use Custom DNS with your own domain name for this to work properly. If you're intent on using our DynDNS Free or DynDNS Pro devices with an AirPort or Time Capsule, you must use one of our DynDNS.com Update Clients.
    Setup Your Custom DNS Zone for Updates
    The AirPort Extreme, AirPort Express and Time Capsule devices do NOT use the DynDNS HTTP Update API [IETF Draft] to dynamically update DNS servers. Instead, these devices use the DNS Update [RFC 2136] protocol combined with TSIG security [RFC 2845]." -->
    Which means it CAN be done, but only with Custom DNS. First, I think $29.95 for just a pointer is a little expensive; second, I would have to move my DNS services from my hosting. Too much ado, so I'm looking for an alternative — without success so far. I just want something that uses DNS Update protocol and TSIG security.
    Meanwhile, I set up an API from my hosting and a perl script running on the boot to check if DNS is pointing to the right IP. It just works, clean and simple. But it's not a built-in solution and I cannot take advantage of wide area Bonjour, for example.
    So, if does anyone know about it — a free dynamic dns service that uses DNS Update protocol and TSIG security —, please let me know.
    Thanks,
    Gui

  • This copy of Microsoft Office 2013 cannot be used on a computer running Terminal Services" error message when you try to open the Click-to-Run version of an Office 2013 program or suite on a terminal server

    Hi All,
    I have Citrix VDI (Virtual Desktop Infrastructure) Implemented
    in my company and installed few Applications on App Server lets say.... MS Office 2013, filzialla, putty, etc...
    I assigned these apps to the users through CITRIX STUDIO, when I try to use these apps. on VDI everything is working fine only when i tried to open Word, Excel or Powerpoing, outlook it throws error as 
    ""This copy of Microsoft Office 2013 cannot be used on a computer running Terminal Services" error message when you try to open the Click-to-Run version of an Office 2013 program or suite on
    a terminal server"" and apps gets closed.
    Please help me on this ASAP.
    Thanks & Regards,
    Sachin Shinde

    Hi,
    As mentioned in ths article below, run for Office 365 products on to a Remote Desktop Session Host server is not supported. You can install Office products for Office 365 to a virtual desktop, but the virtual desktop must be assigned to a single user.
    http://technet.microsoft.com/en-us/library/jj219423(v=office.15).aspx
    Regards,
    Melon Chen
    TechNet Community Support

  • How to run business services as dynamically generated Subject?

    Hi experts,
    I have configured a business service which puts a message on a JMS queue in a weblogic container other than ALSB's weblogic container.The queue is configured with a security policy [say a 'MessagePublisher' role], so that only users with role of 'MessagePublisher' can send message to that queue.
    We have different partners SFTPing messages(xml/csv/excel format) to us, of which only few of them would have a role of 'Message Publisher'. I have configured a proxy to read these files from a directory, however sender of some of these messages may not have a role of 'Message Publisher'.
    I am expecting the senders' credentials to be appended to the message by some process on SFTP server. How can I generate a 'Subject' within a proxy using these credentials and do a run as on the business service, so that only users with the role of 'MessagePublisher' succeed in sending message to the queue.
    I probably can configure my business service to run as a user account who has the relevant role, but I do not want to hard code the UserAccount within business service and obtain a user account using sender's credentials.
    Is ALSB not supposed to be used as suggested above?Would highly appreciate any thoughts on this..
    Regards.

    The JMS business service can use only a static service account. I think this has an undesirable implication that the business service cannot be invoked as a dynamically generated subject.
    Only way I know of to enforce role based access control in this scenario is to have an extra proxy service in front of JMS business service. Enforce access control over this extra proxy service.
    To invoke this extra proxy service with credentials embedded embedded in the message, I think you need to look at "custom authentication" option under message level security. I am not sure how this would work. May be someone here can explain that.

  • I have "chatted" with customer service 5 different times. I was sent here. I have activated Photoshop Elements 9 on two different iMacs. They are both dead and I am unable to get it to activate on my newest computer. iMac. Can anybody help me?

    I have "chatted" with customer service 5 different times. I was sent here. I have activated Photoshop Elements 9 on two different iMacs. They are both dead and I am unable to get it to activate on my newest computer. iMac. Can anybody help me?

    Unfortunately, only adobe can help you with that, as most people here are just posters such as your self and don't work for adobe.
    If you go here and use the Chat now button (bottom of page), they should get you up and running by resetting your activations.
    http://helpx.adobe.com/x-productkb/policy-pricing/activation-deactivation-products.html

Maybe you are looking for

  • ***** in the output AT END stmt

    I am getting ***** in the output, if I use the at end stmt. Can anybody tell me the reason and teh solution??

  • 2010 Mac Mini power cord loose? and Abode flash player bad??

    Just received new 2010 Mac Mini 2 days ago. It looks different and better features than old Mini I had. I am happy with newer Mini. Problem: The power cord loose and not good plug in. Need replace newer the power cord. Who I should contact to or go a

  • CLASSIFIACTION_DESTINATION - What roles must the user have?

    Hi all, I have created the CLASSIFICATION_DESTINATION in PI 7.1. Now I want to publish a service from ERP. I get always the same error: Error during cache update for classification system meta data/values Invalid Response code (401). Server          

  • Project Setting for H.264-AAC

    Ok, I think I overcomplicated things when I ask which file type or codec renders the fastest... I'll ask an easy one... What "Project Settings" will I use if I'm planning to edit a .mp4 file with (H.264 video AAC audio) for it to be recognized as 'na

  • Solaris 8 hotkeys quit working

    I have added hotkeys (in CDE hotkey editor), and have found that they will occasionally quit working. I can delete and re-add the very same hotkey and it will work. Has anyone seen anything like this & know what could be causing the problem? thanks,