Essbase Refresh security from SS failed

Hi,
we are getting the error while refresh security from shared services from Essbasse....
"Refreshing security from Shared Services failed"
In essbase error log can see below.....
Error(1051522)...Analytical Services failed to get group's member tree with Error [Failed to create an initial directory context for MSAD]
Please help.
Thanks.

Thx. I just did it and it didn't seem to disrupt anything. I tested with a user with a smartview open, a report running and a WA dashboard on screen. It did mention that after refreshing the essbase server would be disconnected and i would have to reconnect but it didn't actually boot me out or disrupt any process.
I guess it's okay to do on a live production system. ?
Thx,
Mike

Similar Messages

  • Error from EAS - "refreshing security from Shared Services failed"

    Hi,
    I was using Native only security in HSS for Essbase 11.1.1.3 and EAS allowed me to Refresh security from Shared Services. (Essbase security was already externalized to HSS.)
    However, after I added "MS Active Directory", and provisioned a MSAD user to a native Planning group, EAS errors out with "refreshing security from Shared Services failed" .
    I checked Essbase security and that MSAD user is not added to Essbase.
    From Essbase Log I see:
    Essbase failed to get roles list for [ESB:Analytic Servers:servername:1] from Shared Services Server with Error [32:1062:Failed to connect to the user directory [ HSS'sMSADname].
    I then tried to remove MSAD from our H Shared Services and see if this problem goes away. However, MSAD still shows on the left panel menu in H Shared Services. How can I get rid of MSAD?
    Any suggestions?
    Edited by: user643332 on May 12, 2010 12:05 AM

    Hi,
    Are you sure you have removed it from shared services, you may have just disabled it.
    You must restart the shared services application server to apply any changes made.
    Cheers
    John
    http://john-goodwin.blogspot.com/

  • Essbase EAS - Refresh Security from Shared Services

    Hi All,
    Just went live with Essbase. We are using MSAD Groups in Shared Services for our users. I noticed that if we add a new user to a provisioned group, they don't automatically get access to Essbase. I believe I have to select 'Refresh Security From Shared Services' in EAS. I am nervous about doing this with users in the system as I don't want to accidentally boot them out. Is there any risk? Reports stopped? Users forced to logout? Smartview implications?
    I feel like I did it before and disrupted some users during development but I am not sure.
    Much Appreciated,
    Mike

    Thx. I just did it and it didn't seem to disrupt anything. I tested with a user with a smartview open, a report running and a WA dashboard on screen. It did mention that after refreshing the essbase server would be disconnected and i would have to reconnect but it didn't actually boot me out or disrupt any process.
    I guess it's okay to do on a live production system. ?
    Thx,
    Mike

  • EAS Console - Not getting the option "Refresh security from Shared Services"

    Hi,
    In EAS Console 11.1.2.2, I am not getting the option "Refresh security from Shared Services" when I right click on Security (under Essbase Servers).
    However, I can see this option via EAS Console 11.1.1.3 (current existing version).
    Could you please let me know how can I get this option in EAS Console 11.1.2.2? Is this by any chance related to the option "Externalize Users"?
    Thanks in advance.

    Thanks a lot join for this information and your kind support .
    One more question:
    The owner of the Planning application is user 'hypadmin'.
    I can see the SIDs of user 5001 a little different in both the versions. Is this ok?
    Hyperion Planning 11.1.1.3 (Existing Environment)
    USER_ID     SID ROLE SYNC_PSWD OFFLINE_ENABLED HUB_ROLES
    50001          native://DN=cn=0fa19f8241602600:3b78a0e0:130926693d2:-78ba,ou=People,dc=css,dc=hyperion,dc=com?USER 3 2 0 5019
    Hyperion Planning 11.1.2.2 (New Environment)
    USER_ID     SID ROLE SYNC_PSWD OFFLINE_ENABLED HUB_ROLES
    50001           native://nvid=54aec0428a3ba591:-44b7ca9b:13f03c114d2:-5d99?USER 3 2  4507
    I have not yet performed "Externalize Users" yet in the new environment (11.1.2.2) throgh EAS Console. Is it required in the newer version 11.1.2.2?

  • Refresh Security from shared services.

    Hi
    When ever there are any changes in the security at shared services(LDAP) , I am doing a refresh security from shared services(@EAS)
    -in order to get these changes from shared services.
    Which is taking 30 minutes refresh ever time in our systems.
    Is there any other way to make quickone?
    Version - 11.1.1.3
    Thanks

    strange? We are still on 931 (Essbase on 9.3.1.6) and refreshing security is not necessary at all any more. It is even deprecated functionality. I always though that 11 did not have it too.^^^The end (or most of the end) of Essbase.sec came in a late patch of 9.3.1. It isn't there yet in 11.1.1.3, I think. It is in 11.1.2. There was not a lot of fanfare about the change although it's there in the patch notes.
    Regards,
    Cameron Lackpour

  • Refresh security from Shared Services fails - System11

    Hi All,
    WHen refreshing the Essbase security from Shared Services in System 11 we get the following error:
    Error 1051522: Essbase failed to get group's member tree with Error [CSS Error: Unknown error: Could not get exception message from exception object]
    We see the same error in the Essbase log.
    In the Shared Service Security CLient.log we get the following warnings:
    2009-03-03 16:12:58,294 WARN [Thread-108] CSS dll either not found in java.library.path or can't be loaded[Root Cause: D:\Hyperion\common\CSS\9.5.0.0\bin\css-9_5_0.dll: Can't load IA 32-bit .dll on a AMD 64-bit platform ] com.hyperion.css.spi.impl.ntlm.NTLMTrustedDomain.<clinit>(Unknown Source)
    2009-03-03 16:12:58,294 WARN [Thread-108] Error initializing trusted domains or the workstation name.[Root Cause: getNtTrustedDomains ] com.hyperion.css.spi.impl.ntlm.NTLMTrustedDomain.<clinit>(Unknown Source)
    Has anyone come across this?
    Thanks for your help.
    Seb

    Hi Seb,
    I take it you are using NTLM as your external authentication.
    The error message means that it can't see css-9_5_0.dll in the path, if you are on windows make sure the path contains <drive>:\Hyperion\common\CSS\9.5.0.0\bin\
    If it doesn't update the environment variables, not sure if you need to reboot it may pick it up straight away, you can check by going to a command prompt and running echo %path%
    Cheers
    John
    http://john-goodwin.blogspot.com/

  • WCS Refresh Config from Controller Fails

    Have been able to refresh config from controller successfully in the past, but now it only works on 1 of 4 controllers. Receive error "Failed (see logs)". Any idea why this would fail, and/or where I can find these logs? All controllers are reachable.

    For what it's worth, it is generally recommended that the WCS be at a MORE recent or same revision level (in terms of date, not version numbering, per se) as the controllers.
    Have you upgraded the controllers prior to the WCS? It is my understanding that upgrading in the wrong order (i.e.: Upgrading the WLC/WiSM before the WCS is upgraded) might cause problems.
    Just a thought.
    - John

  • Refresh Security from shared services fails.

    Hello all,
    On our environment I went into shared services with admin rights and changed the native directory password. And from then on I have not been able to refresh the security of essbase server in EAS. I get the following error,
    Essbase failed to get roles list for [ESB:Analytic Servers:Servername:1] from Shared Services Server with Error [32:1062:Failed to connect to the user directory [Native Directoy].]
    Also I would like to know if native directory password means the password "password" which comes as default for the username admin. Am new to essbase and was under the impression that native directory password means the password "password" which came as default for the username admin. Please help, this is a production issue which started only because I changed the native directory password and now I need to get it fixed.
    Thanks.
    Edited by: Teddd on Jan 6, 2013 4:07 PM

    Please confirm the version of the Shared Services (HSS) and Essbase, EAS server.
    Also let me know, if the HSS, ESSBASE & EAS installed on the same box ?
    If they are on the different servers, ensure that there is no network communication issues.. (try performing telnet on the port from each other servers)
    E.g Open command prompt - telnet servername port (telnet HSS_SERVER 28080), hit enter.. if it shows the blank screen .. it is successful and there is no communication issues.
    Also you could try..
    On EAS server, add the below in windows registry under EAS... and restart the machine..
    ESS_CSS_JVM_OPTION1 = -Dcom.hyperion.css.socketTimeout=60000
    if you are not comfortable updating the registry contact you admin and ensure to take the backup before editing...

  • Error from sample JAX-WS security from documentation: Failed to get token

    I am trying example 2-1 for the server and 2-3 for the client and i am using WLS 10.3.5:
    http://docs.oracle.com/cd/E21764_01/web.1111/e13713/message.htm#CDEBIJEJ
    i get some errors when trying to compile/generate the source listed, but i work around those.
    and i hardcode some values ( like username/password, keystore locations, etc).
    i can deploy the web service successfully and execute the client.
    I have some debugging turned on, so i see that the messages are being successfully encrypted and decrypted.
    However, i get an exception back from the server:
    [java] Exception in thread "main" javax.xml.ws.soap.SOAPFaultException: Failed to get token for tokenType: http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-x509-token-profile-1.0#X509v3
    [java]      at com.sun.xml.ws.fault.SOAP11Fault.getProtocolException(SOAP11Fault.java:197)
    [java]      at com.sun.xml.ws.fault.SOAPFaultBuilder.createException(SOAPFaultBuilder.java:122)
    [java]      at com.sun.xml.ws.client.sei.SyncMethodHandler.invoke(SyncMethodHandler.java:125)
    [java]      at com.sun.xml.ws.client.sei.SyncMethodHandler.invoke(SyncMethodHandler.java:95)
    [java]      at com.sun.xml.ws.client.sei.SEIStub.invoke(SEIStub.java:136)
    [java]      at $Proxy30.echo(Unknown Source)
    [java]      at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
    [java]      at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:39)
    [java]      at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:25)
    [java]      at java.lang.reflect.Method.invoke(Method.java:597)
    [java]      at weblogic.wsee.jaxws.spi.ClientInstanceInvocationHandler.invoke(ClientInstanceInvocationHandler.java:84)
    [java]      at $Proxy31.echo(Unknown Source)
    [java]      at wssp12.wss10.Test.main(Unknown Source)
    For the Service:
    I have used exactly the same policies from the example.
    i did have to comment out the @WLHTTPTransport clause ( the error gives me the impression it is no longer supported )
    For the client:
    The generated port no longer takes just string for the wsdl url, so i don't pass in a url at all. i let it use the URL from the client gen process. I also hard coded a username/password i created.
    any thoughts?
    These examples don't mention anything about Secure Token Server ( although, i see it mentioned later down the page after other examples ). Do these examples require an STS be configured? or is that unrelated to my exception?
    Thanks for the help!!!
    Follow up:
    i added the following ( which i think should take care of the STS part i was asking about):
    61 String sts="https://TESTUESR0:7002/UsernameTokenPlainX509SignAndEncrypt/simpleSecureService";
    62 requestContext.put(weblogic.wsee.jaxrpc.WLStub.WST_STS_ENDPOINT_ON_WSSC,sts);
    but this made no difference.
    Edited by: user733322 on Feb 17, 2012 7:38 AM

    DTC was running on remote computer. The problem was it was no longer accepting transactions from remote servers. This was in SSIS so I had to turn to "Transaction Supported" for all Data Flow Transactions.
    Greg Hanson

  • Refreshig security from shared services

    let us assume that we are creating 5 users in shared services and provisioning them with different privileges. when refreshing these users security from shared services to essbase , i need to refresh the security of only one particular user role, how can i do that?

    if using 9.3.1 later version u can use Shared servicves patch whcih will automatically update the security
    or esle right clik on EAS security > refresh security from shared services > all users or currecnt users
    which will update ur security
    Refresh each user or group individually using MAXL command:
    alter user username sync security with all application;
    alter group groupname sync security with all application;

  • Refresh Security using MaxL command

    Hi All,
    When trying to refresh security from shared services using the below maxl command:
    alter user 'henkej03' sync security with all application;
    getting the below error:
    [Fri Mar  6 09:06:00 2009]Local/ESSBASE0///Info(1051590)
    Synchronization started for user/group [hypadmin]
    [Fri Mar  6 09:06:00 2009]Local/ESSBASE0///Error(1051514)
    Analytical Services failed to get roles for users and groups for applications during refresh/login sync/user sync from Shared Services Server with Error [CSS Error: Internal Error. Function getmultiUGmultipAppRoleList]
    [Fri Mar  6 09:06:00 2009]Local/ESSBASE0///Warning(1051003)
    Error 1051514 processing request [Set User/Group List] - disconnecting
    Can anyone help me on the above.
    Thanks in advance,
    Raja

    Thanks guys...
    but my HSS and LDAP was up and running, I think there was temporary problem in network ... today I got error...
    ERROR - 1051514 - Analytical Services failed to get roles for users and group
    s for applications during refresh/login sync/user sync from Shared Services Serv
    er with Error [Cannot find application with ID ESBAPP:bopelim1_AHQLUBNT118_2].
    tried to use "resync all.." but failed...
    Checked in HSS and app was not registerd..to HSS :) .. so regiseted with HSS and User was refreshed succesfully !
    In case you encounter the "ERROR - 1051514", check if the app is registered to HSS or not?
    have a nice time !!!
    SD

  • Unable to refresh security

    Hi All,
    i am having a problem in refreshing security.
    I am getting following error message :
    "Failed to create security filters for Username1, UserName2"
    UserName1 and UserName2 are no longer in our company.
    I removed both users in SQL repositories from following tables
    HSP_USER_PREFS
    HSP_MRU_MEMBERS
    HSP_USERSINGROUP
    hsp_users
    hsp_object
    did anyone face this type of error.
    thanks in advance.

    Hi Jake,
    thanks for the reply.
    I tried sync Native directory.
    as it didn't work I also tried running Updatenativedir.bat utility in planning.
    I am now getting following error message:
    D:\Hyperion\common\utilities\SyncOpenLdapUtility\UpdateNativeDir\updateNativedir
    updateNativeDir -cssLocation http://ftlqbihss01:58080/interop/framework/getCSSC
    onfigfile -nodelete
    java.io.IOException: Property data cannot be loaded from cache.
    at com.hyperion.css.common.configuration.CSSConfigurationImplXML.process
    Streams(Unknown Source)
    at com.hyperion.css.common.configuration.CSSConfigurationImplXML.<init>(
    Unknown Source)
    at com.hyperion.css.common.configuration.CSSConfigurationManager.getConf
    iguration(Unknown Source)
    at com.hyperion.css.CSSAPIImpl.initialize(Unknown Source)
    at com.hyperion.css.utils.sync.CSSMigrationUtility.sync(Unknown Source)
    at com.hyperion.css.utils.sync.CSSMigrationUtility.main(Unknown Source)
    Update Native Directory operation aborted : com.hyperion.css.common.configuratio
    n.CSSConfigurationException: Cannot configure the system. Please check the confi
    guration. Error Code: 9
    NestedException:
    java.io.IOException: Property data cannot be loaded from cache.
    can you please help me in resolving the issue.

  • Essbase BSO cube from EPMA

    Dear all,
    I have an essbase BSO cube. The cube is refreshed from EPMA.
    It was working fine. But after making some changes (add members), the deployment was being aborted with the following message.
    Error.
    Failed to deploy Essbase cube.
    Caused by: Failed to build Essbase cube dimension: (XX_MONTHS) .
    Caused by: Cannot end stream build. Essbase Error(1007083): Dimension build failed. Error code [1060056]. Check the server log file and the dimension build error file for possible additional info.
    Failed to deploy Essbase cube.
    Caused by: Failed to build Essbase cube dimension: (XX_MONTHS) .
    Caused by: Cannot end stream build. Essbase Error(1007083): Dimension build failed. Error code [1060056]. Check the server log file and the dimension build error file for possible additional info.
    \\Error Updating Dimension MA_MONTHS
    \\Error Initializing Rule File Information.
    Kindly help.
    Thanks and Regards,

    Error 1060056 usually tells you that generation or level with the same name already exists. So check whether you have same member names across/within the dimension.
    Regards
    Celvin

  • Data import from EBS failed via FDMEE in fdm . Getting error message as "Error connecting to AIF URL.

    FDM Data import from EBS failed via FDMEE after roll back the 11.1.2.3.500 patch . Getting below error message in ERPI Adapter log.
    *** clsGetFinData.fExecuteDataRule @ 2/18/2015 5:36:17 AM ***
    PeriodKey = 5/31/2013 12:00:00 AM
    PriorPeriodKey = 4/30/2013 12:00:00 AM
    Rule Name = 6001
    Execution Mode = FULLREFRESH
    System.Runtime.InteropServices.COMException (0x80040209): Error connecting to AIF URL.
    at Oracle.Erpi.ErpiFdmCommon.ExecuteRule(String userName, String ssoToken, String ruleName, String executionMode, String priorPeriodKey, String periodKey, String& loadId)
    at fdmERPIfinE1.clsGetFinData.fExecuteDataRule(String strERPIUserID, String strDataRuleName, String strExecutionMode, String strPeriodKey, String strPriorPeriodKey)
    Any help Please?
    Thanks

    Hi
    Getting this error in ErpiIntergrator0.log . ODI session ID were not generated in ODI / FDMEE. If I import from FDMEE its importing data from EBS.
    <[ServletContext@809342788[app:AIF module:aif path:/aif spec-version:2.5 version:11.1.2.0]] Servlet failed with Exception
    java.lang.RuntimeException
    at com.hyperion.aif.servlet.FDMRuleServlet.doPost(FDMRuleServlet.java:76)
    at javax.servlet.http.HttpServlet.service(HttpServlet.java:727)
    at javax.servlet.http.HttpServlet.service(HttpServlet.java:820)
    at weblogic.servlet.internal.StubSecurityHelper$ServletServiceAction.run(StubSecurityHelper.java:227)
    at weblogic.servlet.internal.StubSecurityHelper.invokeServlet(StubSecurityHelper.java:125)
    at weblogic.servlet.internal.ServletStubImpl.execute(ServletStubImpl.java:301)
    at weblogic.servlet.internal.TailFilter.doFilter(TailFilter.java:27)
    at weblogic.servlet.internal.FilterChainImpl.doFilter(FilterChainImpl.java:57)
    at oracle.security.jps.ee.http.JpsAbsFilter$1.run(JpsAbsFilter.java:119)
    at oracle.security.jps.util.JpsSubject.doAsPrivileged(JpsSubject.java:324)
    at oracle.security.jps.ee.util.JpsPlatformUtil.runJaasMode(JpsPlatformUtil.java:460)
    at oracle.security.jps.ee.http.JpsAbsFilter.runJaasMode(JpsAbsFilter.java:103)
    at oracle.security.jps.ee.http.JpsAbsFilter.doFilter(JpsAbsFilter.java:171)
    at oracle.security.jps.ee.http.JpsFilter.doFilter(JpsFilter.java:71)
    at weblogic.servlet.internal.FilterChainImpl.doFilter(FilterChainImpl.java:57)
    at oracle.dms.servlet.DMSServletFilter.doFilter(DMSServletFilter.java:163)
    at weblogic.servlet.internal.FilterChainImpl.doFilter(FilterChainImpl.java:57)
    at weblogic.servlet.internal.RequestEventsFilter.doFilter(RequestEventsFilter.java:27)
    at weblogic.servlet.internal.FilterChainImpl.doFilter(FilterChainImpl.java:57)
    at weblogic.servlet.internal.WebAppServletContext$ServletInvocationAction.wrapRun(WebAppServletContext.java:3730)
    at weblogic.servlet.internal.WebAppServletContext$ServletInvocationAction.run(WebAppServletContext.java:3696)
    at weblogic.security.service.SecurityManager.runAs(SecurityManager.java:120)
    at weblogic.servlet.internal.WebAppServletContext.securedExecute(WebAppServletContext.java:2273)
    at weblogic.servlet.internal.WebAppServletContext.execute(WebAppServletContext.java:2179)
    at weblogic.servlet.internal.ServletRequestImpl.run(ServletRequestImpl.java:1490)
    at weblogic.work.ExecuteThread.execute(ExecuteThread.java:256)
    at weblogic.work.ExecuteThread.run(ExecuteThread.java:221)

  • WPA/WPA2 secured wireless connection fails for two minurtes for every hour of use.

    Hello.
    I have a brand new ThinkPad T500 2055-A16 with Windows Vista Business. I have a WiFi connection problem. It is not a signal strength problem, as it doesn't work even if I place the computer right next to the access point with no other wireless equipment near by.
    None of my other computers experience this problem. I even bought another ThinkPad T500 2055-A16 at the same time as this one, and that does not have the problem either. The problem is when I connect to a network using WPA2-PSK or WPA-PSK. The connection works fine for half an hour, an hour or two hours, but then without warning, the connection is lost and it is not possible to reconnect for half a minute, a minute or two minutes. The exact times vary. When I switch the network to use WEP or no encryption, everything works fine. But I don't like to use no encryption and I cannot use WEP because I have other computers in my home which does not support WEP.
    I had this problem right from the beginning the first time I used the computer. I have tried many things like disabling power management or IPv6 and other things suggested by my ISP, but it did not change anything, so I switched them back to their default value. I have also tried to update the driver for the Intel(R) WiFi Link 5100 AGN card, but that didn't help the problem. The problem became slightly less annoying when I uninstalled Access Connections, because Vista would then reconnect as soon as it could, whereas I in Access Connections would have to continuously press the connect button until it succeeded. But the problem is still a real pain.
    Some pieces from the Windows Event Viewer, which I think looks interesting (these occur regularly at exactly the same timestamps as when the connection is lost):
     Profile match: Success
     Pre-Association: Success
     Association: Success
     Security and Authentication: Fail
    0x00048005 and 0x0003800b
    Result of diagnosis: Problem found
     Issue referred to: L2Sec Helper Class
    I also see the following message on my access point's log, which also occur at exactly the times when the connection is lost:
    1x:00216b4d7ee6:logout
    (The number match the MAC address of my computer)
    The only other message which is logged on my Access Point when all log options are enabled is "Time initialized by NTP server".
    How can I solve this problem so that I can have undisrupted wireless Internet access?

    Edit: Actually my other ThinkPad T500 2055-A16 also fails in the same way, but my ThinkPad SL500 2746-9BG and my Medion laptops works fine, also running Vista.

Maybe you are looking for

  • Notification details edit in work manager 6.2

    Hello Experts, There is no WorkCenter field in Notification edit. WorkCenter exists in transaction and object property, so i easily added WorkCenter to NotificationEdit Screen ,  but it does not replicate  when i deploy and run on client. Please sugg

  • Creating bookmarks in LabVIEW

    Is there a way to create a bookmark in LabVIEW? I have a kludge thats a dummy VI named Bookmark.vi. I've written a script so that I can push my F1 key, and the script sends keystrokes to use LabVIEW's "Find" ability to zoom right to wherever I place

  • Submit Cancelled Dialog and Submiting by Email

    Hello, I've googled this one pretty carefully and have found similar issues but never a solution I could get to fix the behaviour. I am using LiveCycle Designer ES (8.2) and have created a simple form. The goal is to use some of the collected informa

  • BLOB error: invalid arguments in call

    I created a table with 3 columns: PICID(Number), Pic(BLOB) and User(Varchar2[20]). I am using SQL Developer to create a new row and put a picture into the Pic column. When I try to save it, I get this: One error savings changes to table "PICS": Row 1

  • What does this icon mean? (Can't find on this website) (3rd gen)

    It is on a 3rd generation iPod. It looks like the dock connector cord (iPod/wide end) and an arrow. Looks like this: http://img402.imageshack.us/img402/1695/9a811ap4.jpg Thanks