Does AD member group count has a critical limit in OAM?

Hi,
I’m using Oracle Access Manager 10g (10.1.4.0.1) to setup an SSO system. The user base is an instance of Microsoft Active Directory 2003. I’m authorizing a particular URL (which is defined as a Policy Domain in OAM) for the users based on user groups defined in the Active Directory.
I&rsquo;ll explain my problem using this example. Suppose the URL I&rsquo;ve setup is http://www.example.com/test. Therefore, &lsquo;/test&rsquo; is defined as a Policy Domain in OAM. Within this policy domain, I have two (enabled) authorization rules namely, Rule-A (allows access to the AD group, Group-A) and Rule-B (allows access to the AD group, Group-B). Then, under &lsquo;Default Rules&rsquo; I have defined the authorization expression as, <strong>Rule-A | Rule-B</strong>.
In the AD, Group-A has 500 member groups and Group-B has 1900 member groups. (User accounts are members of these sub-groups). Let us suppose that there is a user account called User-A as a member of a sub-group under Group-A, and User-B under Group-B likewise. My problem is, that when access is tested for the above URL through the &lsquo;<strong>OAM Access Tester</strong>&rsquo;, User-A is authorized but User-B is shown as &ldquo;Inconclusive&rdquo;. Is this related to some member group count limitation in OAM? I would be really grateful if anybody can help me.
By the way please note that, I&rsquo;ve already changed the value of the parameter &ldquo;<strong>maxForRangedMemberRetrieval</strong>&rdquo; to 1500 in \IdentityServer_install_dir\identity\oblix\apps\common\bin\globalparams.xml, as suggested in OAM documentation.
Regards,
Asanka Gallege.
Edited by: ASGALK on Nov 6, 2008 11:30 AM

Originally Posted by dkitzen
Hi Thomas,
Thanx for the quick reply.
Is it posible to edit the LDAP request in ZCM, like explained below?
To perform a search where the result might exceed this number of objects, the client (ZCM) must specify the paged search control. This is to group the returned results in groups that are no larger than the MaxPageSize value.
Greetings,
Dennis.
Not that I'm aware of, you need to increase the MaxPageSize value of your AD.
Thomas

Similar Messages

  • Number Range RF_Beleg has reached critical limit

    Hi
    While doing the customer clearing in AR , I got the error as "Number Range RF_Beleg has reached critical limit ". Can anybody suggest me how to fix this error.it looks some allocated number range has exhausted.
    Thanks
    SN

    Hi Sathya,
           You may have to follow the following steps:
    i) You may know the document type of the document that generates this error, say DZ, Pls goto <b>OBA7</b> and note the Number Range defined for the same.
    ii) Having noted the Number Range, goto <b>FBN1</b>. Click on the <b>Change Status Button.</b>
    iii)  Locate the Co Code, Fiscal Year and the Number Range (That u got from Step i). Select that line and change the current number to zero.
    iv) Come back to the main screen of FBN1. Again click onto the <b>Change Interval Button</b>. Select the same record as in iii) and change the From & To Numbers. <b>The defined numbers should not overlap with any other number range for any other document type.</b>
    v)Save it.
    Try posting again.
    Hope this helps.

  • Does using personas / themes count towards my download limit?

    Does using personas or themes count towards my download limit?

    Only downloading a file (theme or persona) does account to your download limit.
    Once you've download a persona (or theme) then using doesn't account for extra download quota.
    Additional Personas are not stored on your computer,so if you switch a persona then the new persona needs to be re-downloaded from the (getpersonas) server.
    A theme is stored on your computer, so switching themes requires no extra download.

  • How do I know which group and group counter used to create current estimate

    Is there a way to know, if for a given set of materials, what groups and groups counters have been used to create the current cost estimate. Or for a given comboniation of material, group and group counter has been used to create a current cost estimate. I can look each up through displaying the cost estimate but I am looking for a quick way since the number of materials are in 100s.
    I was wondering if there is a table I could look up to get the info.
    Any help would be much appreciated.
    Regards

    The name of the table that needs to be used is KEKO. I figured it out so I thought I would share
    Edited by: NIK83 on Mar 7, 2011 10:16 PM

  • Group and group counter used to create cost estimate

    I am creating a custom report and would like to know what table do I have to use if for a given material  the program has to pick Group, Group counter and the task list type that were used in creating the cost estimate for that material. Any help in this regards is much appreciated.
    Regards,

    The name of the table that needs to be used is KEKO. I figured it out so I thought I would share
    Edited by: NIK83 on Mar 7, 2011 10:16 PM

  • Tasl list group and group counter

    hi,
    i have one requirement . I have give internal number range to the task list. so my need to to create task list with one group and several group counter. But what is happening is when i run LSMW for that. seperate group numbers has been generated for each task list. is there any way to get the same group number with different counters using LSMW>

    hi
    since you have given internal number range for task list system will try to create task list with different group numbers .if you want the same group number with different group counter then i think you have to use the task list with external number and use the number created before
    regards
    thyagarajan

  • My broadband has 2MB download limit I need a counter to see how much I use.

    My broadband has 2MB download limit I need a counter to see how much I use. Please recommend one that I can start counting at the start of the month and be able to see how many MB I have downloaded at the end of the month to be able to work out what amount I need to pay for.

    Oops I mean a 2GB/month allowance. And I found Intego Content Barrier does it.

  • My mom updated her iPhone to iOS7, and now she has my contacts. Does this mean that she has access to all of my photos as well? How can she 'unlink' our phones? Or, is there anyway that I can get my stuff to disappear from her phone? Thanks

    My mom updated her iPhone to iOS7, and now she has my contacts. Does this mean that she has access to all of my photos as well? How can she 'unlink' our phones? Or, is there anyway that I can get my stuff to disappear from her phone? We share iTunes account so I think we are both on the same iCloud.

    Welcome to the Apple Community.
    If you are using the same ID as a primary iCloud login, then yes she can see your photos in photostream if you have it enabled.
    You can use the same ID for iTunes so you can share all your purchases, but you need different ID's for iCloud.
    Unfortunately, the mess caused by sharing the ID, will need to be sorted manually, once you both have your own ID's.

  • Error : Period dimension 'Period' is missing a Base Time Period member 'Jun' that has been deleted since the last deployment. Base Time Period members cannot be deleted once the dimension is deployed

    HI,
    I am using V11.1.2.2 Hyperion Planning. I am currently getting an error:
    Error : Period dimension 'Period' is missing a Base Time Period member 'Jun' that has been deleted since the last deployment. Base Time Period members cannot be deleted once the dimension is deployed
    This is what i got when i tried to add alternate hierarchy to my shared dimension. I tried to delete it and it messed up.
    NOw it wont deploy my application.
    Can any one suggest.
    Thanks in advance
    Cheers,
    XXX

    EPMA!!!!! EPMA!!!!
    I'm playing around with it to write a blog post and it is crazy. Only possible workaround (till now i'm not able to figure out a solution to it) is to copy the application and deploy it as a new one. Take copy of all objects (forms, tasklist etc). Delete the corrupted application and rename the new one to old.
    Regards
    Celvin
    http://www.orahyplabs.com

  • Does anyone know whether BT has a mail server that...

    Does anyone know whether BT has a mail server, other than mail.btinternet.com, that supports only POP3/SMTP and not IMAP?  For those interested, the background is as follows.
    I've been trying to get my iPad Mail client to connect to mail.btinternet.com using POP3/SMTP.  When you try to set up an email account on the iPad in the normal way, you are not given the choice of using POP or IMAP.  The Mail client appears to query mail.btinternet.com and, if it determines that the server supports IMAP, it then proceeds to set up a connection using IMAP.  Now, I know a workaround to force the Mail client to connect using POP3/SMTP.  That is not the problem.  The problem is that Mail client does not appear to work properly with POP3/SMTP, and I suspect this is because some of the Mail client code, under the covers, still believes it is using IMAP.
    For example, having setup an email account that uses POP3/SMTP, if I try to create a local mailbox/folder on the iPad Mail client, the operation fails with the message "Unable to Create Mailbox The mailbox couldn't be created on the server".  So I ask myself, why is the Mail client trying to create a mailbox/folder on the server?  The conclusion I have come to is that the Mail client still thinks it is using IMAP.
    I suspect that there are defects in the iPad Mail client code.  But, to test this, it would be good to experiment by setting up a connection to a mail server that supports only POP3/SMTP and not IMAP and then see whether the Mail client behaves any differently.  Hence my initial request.
    Solved!
    Go to Solution.

    Both my wife and I use the Outlook mail client on Windows for our "serious" email and we are very happy with Outlook.
    The iPad is actually my wife's and she bought it for other reasons, such as to Facetime friends and relations, install the Kindle app and read Kindle books, use the BBC iPlayer app, and so on.  But I have set up a separate btinternet email address for her to use on the iPad and she intends to give that email address only to certain close relations.  But, so far, we have found that the iPad Mail client is just not usable with POP/SMTP, and she doesn't really want or need to use IMAP.
    Edit:  Sorry, forgot your specific question.  No, it doesn't create the folder/mailbox locally.  It fails completely.

  • Variant "_$$audit-event-count" has not been declared in the current scope.

    I migrated my bpel process manager from Version 2.1.2 [oc4j linux] to 10.1.2.0.0 [using jboss as application server].
    The orabpel schema for 10.1.2.0.0 seems to be a bit different.
    I installed the new schema and then dumped all the data from my previous schema. I also successfully deployed the 2.1.2 processes onto 10.1.2 version.
    I can initiate a new instance of the process, however , the previously completed instances or not completed instances fail with the following error,
    16:28:06,061 INFO [STDOUT] <2006-01-31 16:28:06,061> <ERROR> <default.collaxa.cube> <BaseCubeSessionBean::logError> Error while invoking bean "instance manager": Variant not found.
    The variant "_$$audit-event-count" has not been declared in the current scope. All variants must be declared in the scope before being accessed.
    Any advice is greatly appreciated. Thanks.

    JScript is JavaScript.
    Ah, now there's part of the confusion :)
    If you're asking about a Windows Script Host (WSH) script, you don't have to declare stdin because it's part of the host.
    Ok... So if I understand you correctly, I'm actually programming in J(ava)Script on windows for WSH. Simply trying to call ReadLine fails as well, as it is not defined according to the compiler.
    Be specific: What are you trying to do? Tell what you want to do, not
    how you think it needs to be done.
    which brings me to my current issue: attempting to ReadLine() (in order to get the program to pause for a moment, from
    this example)
    I know I put up a pretty big wall of text back there, sorry about that.
    EDIT: Well, I think I've learned
    about J*script. It sounds like JScript and Javascript are more just versions of ECMAScript.

  • Group and Group counter in Routing

    Hi all,
    what is group and group counter in routing , how these are used in routing , please explain.
    Regards,
    Joseph.

    Dear Joseph,
    1.Each routing is stored against a group and group counter no.
    2.When we create routing without respect to any material and only by giving the plant,the set of operations gets saved under one
    group counter and group no.
    4.Many materials can be assigned to this same group and group counter no,so that the routing is valid for all the materials included.
    5.When you create a routing for material specific,the set of operation gets saved in a group no and group counter no as 01,when
    you create another routing with another set of operations for the same material,plant and task list combination now the group no
    remains same and the group counter gets saved under 02.
    6.This data can be further helpful in assigning the routing data in the production version,.
    Check and revert
    Regards
    S Mangalraj

  • My tv does not have hdmi, it has componet. Is there an adapter for apple tv to go from hdmi to componet?

    my tv does not have hdmi, it has componet. Is there an adapter for apple tv to go from hdmi to componet?

    It could be that it's too old. I have the same problem. Apple has a HDMI to DVI adapter, if you have a DVI input, which is how I connect my Apple TV. But if not here's an adapter for you.
    http://www.google.com/m/products/catalog?q=hdmi+to+component&oe=UTF-8&hl=en&clie nt=safari&um=1&ie=UTF-8&tbm=shop&cid=17067353230121565849&sa=X&ei=mSIKT_zoIY3egg eCwuD1Dw&ved=0CDAQ8wIwAA

  • Whenever I update my apps sometimes it takes me to my brothers account that we used to share and it does that when his card has no money buti have my own and it takes me to his .

    It only does this when his account has money yet his account is deleted off both my iPhone and iPad

    If apps were downloaded on his ID, only his ID can update them.

  • Oracle.apps.xdo.XDOException: Group G_EMP has incorrect  Query Source : Q1

    All,
    I am trying to create some reports using XML data Template in BI publisher. But when I just create a simple data template, I keep getting the error message as mentioned below.
    [111907_101025922][][STATEMENT] Template parsing completed...
    [111907_101026625][][STATEMENT] Start process Data
    [111907_101026625][][STATEMENT] Process Data ...
    [111907_101026625][][STATEMENT] Writing Data ...
    [111907_101026625][][EVENT] Data Generation Completed...
    [111907_101026625][][EVENT] Total Data Generation Time 1.0 seconds
    [111907_102628031][][STATEMENT] Setting data definition:Sample_Data_Template type:oracle.apps.xdo.servlet.data.bind.AdvancedQueryBoundValue11
    [111907_102629516][][STATEMENT] Logger.init(): *** DEBUG MODE IS ON. ***
    [111907_102629516][][STATEMENT] Logger.init(): LogDir=C:\Program Files\Java\jdk1.5.0_13\xmldebug
    [111907_102629516][][STATEMENT] Template parsing started...
    [111907_102629516][][STATEMENT] Data Template ......
    [111907_102629516][][STATEMENT] oracle.xml.parser.v2.XMLDocument@1ab4586
    [111907_102629516][][STATEMENT] Inside dataQueryParser...
    [111907_102629516][][STATEMENT] Inside dataStructureParser...
    [111907_102629516][][STATEMENT] Group ...report
    [111907_102629516][][EXCEPTION] oracle.apps.xdo.XDOException: Group G_EMP has incorrect Query Source : Q1
         at oracle.apps.xdo.dataengine.DataTemplateParser.groupParser(Unknown Source)
         at oracle.apps.xdo.dataengine.DataTemplateParser.groupParser(Unknown Source)
         at oracle.apps.xdo.dataengine.DataTemplateParser.dataStructureParser(Unknown Source)
         at oracle.apps.xdo.dataengine.DataTemplateParser.templateParser(Unknown Source)
         at oracle.apps.xdo.dataengine.XMLPGEN.setDataTemplate(Unknown Source)
         at oracle.apps.xdo.dataengine.DataProcessor.setDataTemplate(Unknown Source)
         at oracle.apps.xdo.servlet.data.bind.AdvancedQueryBoundValue11.callDataProcessor(AdvancedQueryBoundValue11.java:117)
         at oracle.apps.xdo.servlet.data.bind.AdvancedQueryBoundValue11.getValue(AdvancedQueryBoundValue11.java:101)
         at oracle.apps.xdo.servlet.ReportContextImplV11.getReportXMLData(ReportContextImplV11.java:389)
         at oracle.apps.xdo.servlet.CoreProcessor.process(CoreProcessor.java:132)
         at oracle.apps.xdo.servlet.CoreProcessor.generateDocument(CoreProcessor.java:62)
         at oracle.apps.xdo.servlet.ReportImpl.renderBodyHTTP(ReportImpl.java:638)
         at oracle.apps.xdo.servlet.ReportImpl.renderReportBodyHTTP(ReportImpl.java:237)
         at oracle.apps.xdo.servlet.XDOServlet.writeReport(XDOServlet.java:279)
         at oracle.apps.xdo.servlet.XDOServlet.writeReport(XDOServlet.java:266)
         at oracle.apps.xdo.servlet.XDOServlet.doGet(XDOServlet.java:199)
         at oracle.apps.xdo.servlet.XDOServlet.doPost(XDOServlet.java:222)
         at javax.servlet.http.HttpServlet.service(HttpServlet.java:763)
         at javax.servlet.http.HttpServlet.service(HttpServlet.java:856)
         at com.evermind.server.http.ResourceFilterChain.doFilter(ResourceFilterChain.java:64)
         at oracle.apps.xdo.servlet.security.SecurityFilter.doFilter(SecurityFilter.java:65)
         at com.evermind.server.http.ServletRequestDispatcher.invoke(ServletRequestDispatcher.java:621)
         at com.evermind.server.http.ServletRequestDispatcher.forwardInternal(ServletRequestDispatcher.java:368)
         at com.evermind.server.http.HttpRequestHandler.doProcessRequest(HttpRequestHandler.java:866)
         at com.evermind.server.http.HttpRequestHandler.processRequest(HttpRequestHandler.java:448)
         at com.evermind.server.http.HttpRequestHandler.serveOneRequest(HttpRequestHandler.java:216)
         at com.evermind.server.http.HttpRequestHandler.run(HttpRequestHandler.java:117)
         at com.evermind.server.http.HttpRequestHandler.run(HttpRequestHandler.java:110)
         at oracle.oc4j.network.ServerSocketReadHandler$SafeRunnable.run(ServerSocketReadHandler.java:260)
         at com.evermind.util.ReleasableResourcePooledExecutor$MyWorker.run(ReleasableResourcePooledExecutor.java:303)
         at java.lang.Thread.run(Thread.java:595)
    Could any one of you please help me out :)
    Thanks,

    Hi King,
    Find below the data template I am using. I have defined a Q1 in my data template. Let me know where I am going wrong.
    Thanks,
    Ram
    <dataTemplate name="Emp" dataSourceRef="EBS">
         <dataQuery>
              <sqlstatment name="Q1" dataSourceRef="EBS">
                   <![CDATA[ SELECT empno, empname FROM APPS.EMP ]]>
              </sqlstatment>
         </dataQuery>
         <dataStructure>
              <group name="G_EMP" source="Q1">
                   <element name="empno" value="empno"/>
                   <element name="empname" value="empname"/>
              </group>
         </dataStructure>
    </dataTemplate>

Maybe you are looking for

  • Is it safe to enable "write changes into XMP"?

    I am evaluating the LR4 beta using my existing tree of master photos. (Have to put the thing under a realistic load, or there is no test.) If I make a change to a photo with XMP writing enabled in the catalog settings, will LR3 be able to cope with t

  • Audio coming from only one field

    Hello, I just did a mic'ed interview with my little camera. I was wearing headphones and noticed audio coming from only the left side, but there was nothing I could do about it that I was aware of. Anyway, now that this thing is in Final Cut Express,

  • Extension Manager errors

    I've lost the ability to open my extensions manager. The error first read "extension manager in use" and after re boot now reads "could not find preferences file -created a new preferences file" but it still will not open. Also lost the ability to sy

  • How to replace faulty Flex 7510 WLC on HA

    Hi guys, I have a faulty secondary 7510 controller (on HA) and going to replace with a new one. How do I go about this? What steps should I take? Anyone done this before? Thanks in advance.

  • User Exit for EDI

    Hi friends, I have a doubt here. I need to do an enhancement.I need to put Billing Block on Sales Orders coming through EDI to SAP.I am using EXIT_SAPLVEDC_003. Is it the correct EXIT for Inbound EDI Orders ? Will this EXIT trigger for Inbound EDI Or