Exchange 2013 - Admins can only log into one ECP server

Simple run down of my environment:
• Two AD sites (Site1 and Site2)
• One 2008 R2 domain controller at each site (DC1 w/ FSMOs and DC2) running AD forest function level 2008 R2
• One 2012 Std server with Exchange 2012 Std CU3 at each site (EX1 and EX2) – CAS/MBX on both, No DAG
• Half of mailboxes on each server
Using https://webmail.domain.com for all of our internal and external virtual directories. Adding /OWA or /ECP will get you into the respective site from either internal or external.
All Domain Admin/Exchange Admin (Organization Management) do NOT have mailboxes. Those individuals can log into ECP from https://webmail.domain.com/ecp, or FQDN or IP of EX2 only. If John Smith has no mailbox then he must use:
https://webmail.domain.com/ecp
or
https://ex2.domain.com/ecp
or
https://10.16.109.31/ecp
If EX2 goes offline or they use https://ex1.domain.com/ecp or https://10.16.108.31/ecp then none of the admins can login and they get the following:
Use the following link to open this mailbox with the best performance:
https://webmail.domain.com/owa/auth.owa
X-FEServer: EX2
Date: 2/18/2014 10:37:42 PM
s ECP or the https://webamil.domain.com/ecps ECP.
They can access EMS from either server and run Get-ECPVirtualDirectory and it shows what we would expect:
– https://webmail.domain.com/ecp
– https://webmail.domain.com/ecp
Why can an admin with no mailbox only log into the ECP on EX2? What is forcing the login to EX2 only? How can I move that “forced login” to EX1 if we ever get into a situation where EX2 is having problems? What happened in Active Directory or Exchange that
made EX2 the primary login server for ECP and OWA? My FSMOs are located at Site 1…the same location where EX1 is located. The same server that I cannot log into ECP directly.
~Rick

Any admin that is mail enabled can then only log into the server that hosts his mailbox. Admins without mailboxes can only log into EX2. And again, all admins can log into https://webmail.domain.com/ecp unless one of the servers goes offline
and that's when the problems occur. Nothing obvious or unusual regarding mail flow. Done various internal and external tests and have not seen anything obvious or in the logs.
Yesterday's change that MS Support had me do was to delete the ExternalURL for the ECP virtual directories. No difference. So, my latest update from MS Support that requested me to try today's change...
set-owavirtualdirectory “owa (default web site)” -RedirectToOptimalOWAServer $false
After performing an IIS reset and making sure replication had completed there was no difference. So, I am now forced to wait till Monday for MS to respond if the pattern stays at one email per day.
Has anyone with multiple servers at different AD sites been able to log directly into the either server like I'm trying? I get this problem in my labs and I even had MS, while on the phone, remote in to make sure I was setting it up properly.
The guy on the phone never said if their labs do the same thing cause they don't have multiple AD sites in their labs. In my lab if I have two servers at each site then I can log into both servers at the site, but not the other site. It appears it becomes
site dependent then.
MS has taken numerous logs and they are acting like this is the first time they've seen this. Yet I can reproduce it with no problem time after time. I'll create new VMs and start all over from scratch and make this happen every time I create a new AD/Exchange
environment (it does take me a while to build all those VMs from scratch). No fancy GPOs to AD and no radical changes to the Exchange servers. Other than obvious config changes to make sure email can flow internally and externally, this is pretty much out
of the box.
~Rick

Similar Messages

  • I have qualitynet either wired internet. I buy a card good for a month at a time, I can only log into one device at any one time.  Are there settings I can adjust on my airport express to allow all my devices to connect to wi-fi without having to log out.

    I have qualitynet either wired internet. I buy a card good for a month at a time, I can only log into one device at any one time.  Are there settings I can adjust on my airport express to allow all my devices to connect to wi-fi without having to log out of one devise before using another?

    Some Internet providers that limit access to a single device at a time do so by the device's hardware MAC address. If your ISP is one of those, you may be able to substitute the MAC address of your AirPort Express base station for the computer. I would suggest that you contact them to find out if this is allowable.

  • Exchange 2013 CU3 Databases only activate on one mailbox server

    Hi, guys
    I have two Exchange 2013 CU3 Mailbox servers installed, one DAG, 5 databases, each has one copy. I found that if I activated three databases on Mailboxserver1 or Mailboxserver2, then after a few hours, all databases will  be activated on the mailbox
    server which has three databases activated. All the databases can be activated on Mailboxserver1 or Mailboxserver2, and they work well. I disabled DAC mode for preventing Event 4133 and 4376. And it has the same problem if I enable DAC mode.
    From the event log, I found the log when activate one database on another mailbox server, it is Event 3169:
    Managed availability system failover initiated by Responder=OutlookMapiHttpDeepTestFailover Component=Outlook.
    This caused the database activated on another server.
    And I got the message from SCOM, like this:
    Alert: Health Set unhealthy
    Source: test-mbx - Outlook.Protocol
    Path: test-mbx.contoso.local;test-mbx.contoso.local
    Last modified by: System
    Last modified time: 11/12/2013 5:15:46 AM Alert description: EMSMDB.DoRpc(Logon) step of OutlookRpcDeepTestProbe/DB-01 has failed against test-mbx.contoso.local proxying to test-mbx.contoso.local for [email protected].
    Latency: 00:00:00.0320000
    ActivityContext:
    Outline: [30] EMSMDB.Connect(); [1][FAILED!] EMSMDB.DoRpc(Logon); Likely root cause: Momt
    Details:
    Error: Error returned in LogonCallResult. Error code = WrongServer (0x00000478)
    Log:     Mailbox logon verification
            EMSMDB.Connect()
            Task produced output:
            - TaskStarted = 11/12/2013
    5:15:25 AM
            - TaskFinished = 11/12/2013
    5:15:25 AM
            - ErrorDetails =
            - RespondingRpcClientAccessServerVersion
    = 15.0.712.4012
    Latency = 00:00:00.0303884
            - ActivityContext =
        EMSMDB.Connect() completed successfully.
            EMSMDB.DoRpc(Logon)
            Task produced output:
            - TaskStarted = 11/12/2013
    5:15:25 AM
            - TaskFinished = 11/12/2013
    5:15:25 AM
            - Exception = Microsoft.Exchange.RpcClientAccess.RopExecutionException:
    Error returned in LogonCallResult. Error code = WrongServer (0x00000478)
            - ErrorDetails =
            - Latency = 00:00:00.0018801
            - ActivityContext =
        EMSMDB.DoRpc(Logon) failed.
        Task produced output:
        - TaskStarted = 11/12/2013 5:15:25 AM
        - TaskFinished = 11/12/2013 5:15:25 AM
        - Exception = Microsoft.Exchange.RpcClientAccess.RopExecutionException:
    Error
    States of all monitors within the health set:
    Note: Data may be stale. To get current data, run: Get-ServerHealth -Identity 'test-mbx' -HealthSet 'Outlook.Protocol'
    State               Name                                   
    TargetResource                     HealthSet                    
    AlertValue     ServerComponent    
    NotApplicable       OutlookMapiHttpDeepTestMonitor                                            
    Outlook.Protocol              Unhealthy      None               
    NotApplicable       OutlookRpcDeepTestMonitor                                                 
    Outlook.Protocol              Healthy        None               
    NotApplicable       OutlookRpcSelfTestMonitor                                                 
    Outlook.Protocol              Healthy        None               
    NotApplicable       OutlookMapiHttpSelfTestMonitor                                             Outlook.Protocol             
    Healthy        None               
    NotApplicable       PrivateWorkingSetWarning....cclienta... microsoft.exchange.rpcclientacc... Outlook.Protocol              Healthy       
    None               
    NotApplicable       PrivateWorkingSetError....rpcclienta... microsoft.exchange.rpcclientacc... Outlook.Protocol              Healthy       
    None               
    NotApplicable       ProcessProcessorTimeWarning....ienta... microsoft.exchange.rpcclientacc... Outlook.Protocol              Healthy       
    None               
    NotApplicable       ProcessProcessorTimeError....clienta... microsoft.exchange.rpcclientacc... Outlook.Protocol              Healthy       
    None               
    NotApplicable       ExchangeCrashEventError....pcclienta... microsoft.exchange.rpcclientacc... Outlook.Protocol              Healthy       
    None               
    NotApplicable       LongRunningWatsonWarning....cclienta... microsoft.exchange.rpcclientacc... Outlook.Protocol              Healthy       
    None               
    NotApplicable       LongRunningWerMgrWarning....cclienta... microsoft.exchange.rpcclientacc... Outlook.Protocol              Healthy       
    None                
    This test is a cause that mailbox databases in DAG is doing  failover to another server
    Log Name:      Application
    Source:        MSExchangeRepl
    Date:          12.11.2013 4:49:46
    Event ID:      3169
    Task Category: Service
    Level:         Information
    Keywords:      Classic
    User:          N/A
    Computer:      test-mbx-2
    Description:
    (Active Manager) Database DB-01 was successfully moved from test-mbx.contoso.local to test-mbx-1.contoso.local. Move comment: Managed availability system failover initiated by Responder=OutlookRpcDeepTestFailover Component=Outlook.
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="MSExchangeRepl" />
        <EventID Qualifiers="16388">3169</EventID>
        <Level>4</Level>
        <Task>1</Task>
        <Keywords>0x80000000000000</Keywords>
        <TimeCreated SystemTime="2013-11-12T00:49:46.000000000Z" />
        <EventRecordID>1606248</EventRecordID>
        <Channel>Application</Channel>
        <Computer>test-mbx-2.contoso.local</Computer>
        <Security />
      </System>
      <EventData>
        <Data>DB-01</Data>
        <Data>test-mbx.contoso.local</Data>
        <Data>test-mbx-1.contoso.local</Data>
        <Data>Managed availability system failover initiated by Responder=OutlookRpcDeepTestFailover Component=Outlook.</Data>
      </EventData>
    </Event>
    I don't know why, anyone know what's the problem?
    Thank you.
    Nile Jiang- Please mark the post as answer if it answers your question.
    http://www.usefulshare.com

    Hi,
    After deleting all the health mailboxes and restart
    the Exchange Health Manager service, the health mailboxes are recreated successfullly, but when I check the outlook.protocol health, the OutlookRpcDeepTestMonitor or the OutlookMapiHttpDeepTestMonitor is still unhealthy. How can I fix it?
    [PS] C:\Windows\system32> Get-ServerHealth -Identity 'MAILBOX1' -HealthSet 'Outlook.Protocol' | ft server,state,name,ale
    rtvalue -AutoSize
    Server   state Name                                              AlertValue
    MAILBOX1       OutlookRpcDeepTestMonitor                            Healthy
    MAILBOX1       OutlookMapiHttpDeepTestMonitor                     Unhealthy
    MAILBOX1       OutlookRpcSelfTestMonitor                            Healthy
    MAILBOX1       OutlookMapiHttpSelfTestMonitor                       Healthy
    MAILBOX1       PrivateWorkingSetWarning....cclientaccess.service    Healthy
    MAILBOX1       PrivateWorkingSetError....rpcclientaccess.service    Healthy
    MAILBOX1       ProcessProcessorTimeWarning....ientaccess.service    Healthy
    MAILBOX1       ProcessProcessorTimeError....clientaccess.service    Healthy
    MAILBOX1       ExchangeCrashEventError....pcclientaccess.service    Healthy
    MAILBOX1       LongRunningWatsonWarning....cclientaccess.service    Healthy
    MAILBOX1       LongRunningWerMgrWarning....cclientaccess.service    Healthy
    Nile Jiang- Please mark the post as answer if it answers your question.
    http://www.usefulshare.com

  • Can only log into twitter threw Google, not Fire Fox why ?

    I have stopped using Google, and moved to Fire Fox and Yahoo, and all is great. But I have never been able to log into Twitter on Fire Fox. I have contacted Twitter several times and no help. The only way for me to use Twitter is on Google or my phone.. I would really like to be able to log into Twitter on Fire Fox...
    Also I did an update two days ago, and many of my sites can no longer be loaded, do to update... do I need to reinstall or reupdate ....
    Thanks for the help, Trey Coppland

    If clearing cookies didn't help then it is possible that the cookies.sqlite file that stores the cookies got corrupted.
    *Rename (or delete) <b>cookies.sqlite</b> (cookies.sqlite.old) and delete other present cookies files like <b>cookies.sqlite-journal</b> in the Firefox profile folder in case the file cookies.sqlite got corrupted.
    *http://kb.mozillazine.org/Cookies
    *https://support.mozilla.org/kb/Deleting+cookies
    You can inspect and manage the permissions for the domain in the currently selected tab via these steps:
    *Click the "[[Site Identity Button|Site Identity Button]]" (globe/padlock) on the location bar
    *Click "More Information" to open "Tools > Page Info" with the Security tab selected
    *Go to the Permissions tab (Tools > Page Info > Permissions) to check the permissions for the domain in the currently selected tab
    You can remove all data stored in Firefox from a specific domain via "Forget About This Site" in the right-click context menu of an history entry ("History > Show All History" or "View > Sidebar > History") or via the about:permissions page.
    Using "Forget About This Site" will remove all data stored in Firefox from that domain like bookmarks, cookies, passwords, cache, history, and exceptions, so be cautious and if you have a password or other data from that domain that you do not want to lose then make sure to backup this data or make a note.
    You can't recover from this 'forget' unless you have a backup of the involved files.
    It doesn't have any lasting effect, so if you revisit such a 'forgotten' website then data from that website will be saved once again.

  • My profile on old pc is corrupted. I can only log in locally with another login. I need to copy or back up my firefox bookmarks. how can I do this?

    I have a copy of my old profile on my old laptop but I can no longer log in as myself. I can only log into safe mode on my computer. I need to copy my bookmarks to my new laptop. I copied the profiles folder within the Mozilla folder in my local profile. I need to know how to restore my bookmarks.

    mcioci said: '''''I copied the profiles folder within the Mozilla folder in my local profile.'''''
    That will not work as your new profile folder has a different name and Firefox will not recognize the old profile name.
    *Having your old profile folder within your new profile folder is simply wasting hard drive space.
    *You can copy whatever files you need from the old profile folder to the new profile folder <u>with Firefox closed</u>. '''''In your case''''', you can then delete the old profile folder that is sitting within the new profile folder '''''OR''''' you can cut that old profile folder and paste to a safe backup place outside of the Firefox new profile folder.
    *To open your profile folder you can use the following menu path in Firefox to open a new window with the profile folder: ''Firefox button > Help > Troubleshooting Information > click "Show Folder" to the right of Profile Folder'' (if using the Menu Bar ''Help > Troubleshooting Information > click "Show Folder" to the right of Profile Folder'').
    Bookmarks and History are stored together in a file named '''''places.sqlite'''''. You need to copy that file into your new profile folder and overwrite the existing ''places.sqlite'' <u>with Firefox closed</u> if you have not added new Bookmarks to the new profile and have no new history that you wish to keep in the new profile.
    If you need other information from your old profile see the following for the file names to copy from the old profile to the new profile. Again, if you have added anything in those new profile folders they will be over-written and the new items will be lost.
    *https://support.mozilla.org/en-US/kb/Recovering%20important%20data%20from%20an%20old%20profile#w_your-important-data-and-their-files
    *http://kb.mozillazine.org/Transferring_data_to_a_new_profile_-_Firefox#Suggested_profile_contents_to_transfer

  • Can't log into PowerShell and EAC on Exchange 2013 Server

    I'm not sure why but I my Exchange PowerShell can't log into my Exchange server and I can't access the EAC
    via localhost or the URL. 
    I did notice that I enabled HTTP Proxy in IIS and that I used Application Route Requesting with it but I went ahead
    and reversed all those changes. I also noticed that the physical path for each sub-site in Default Web Site goes to the HTTP Proxy version of that folder instead of the ClientAccess one. I changed each folder to the clientaccess one but that didn't help. I
    did some research on this and I saw that I had to enable the kerbauth in the modules area and I did that to. I restarted IIS and WebRM and that still didn't help. 
    The Exchange Management Shell error: 
    New-PSSession : [exchangeserver.domain.net] Connecting to remote server exchangeserver.domain.net failed with the
    following 
    error message : The client cannot connect to the destination specified in the request. Verify that the service
    on the 
    destination is running and is accepting requests. Consult the logs and documentation for the WS-Management service 
    running on the destination, most commonly IIS or WinRM. If the destination is the WinRM service, run the following 
    command on the destination to analyze and configure the WinRM service: "winrm quickconfig". For more
    information, see 
    the about_Remote_Troubleshooting Help topic. 
    At line:1 char:1 
    + New-PSSession -ConnectionURI "$connectionUri" -ConfigurationName Microsoft.Excha ... 
    + ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    + CategoryInfo : OpenError: (System.Manageme....RemoteRunspace:RemoteRunspace) [New-PSSession], PSRemotin 
    gTransportException 
    + FullyQualifiedErrorId : CannotConnect,PSSessionOpenFailed 
    On the web when I try to access EAC on our URL and not localhost, I get this error: 
    400 
    Bad Request :( 
    The request sent by your browser was not valid 
    On localhost, I just get a page cannot be found.

    Hello
    tip:
    Check Get-owavirtualdirectory | fl and Get-ECPVirtualDirectory | fl and make sure that you using “Form based Authentication” and “Basic Authentication”
    and check Control Panel\All Control Panel Items\Credential Manager for saved password.
    and http://goo.gl/IC5P4S
    sorry my english

  • How to configure the mac mini to allow the clients to access both partitions...the client will only see the one we are logged into at the server???

    if possible??? how do we configure the mac mini to allow the clients to access both partitions...the client will only see the one we are logged into at the server???

    You have to explicitly share directories on external/secondary volumes.
    Use the Server admin app to configure file sharing, and select which directory/directories on the second drive you want to share, then they'll be available to clients.

  • So I just transferred my stuff from my first iPhone I my new one. Now I'm trying to log in to iTunes/apple account but it's not letting me. I can still log into apple on old phone

    So I just transferred my stuff from my first iPhone Ito my new one. Now I'm trying to log in to iTunes/apple account but it's not letting me. I can still log into apple on old phone

    What happens when you try?

  • I changed my email for my apple account online and now i can't log into itunes on my iphone 5 can any one help please?

    i changed my email for my apple account online and now i can't log into itunes on my iphone 5 can any one help please?

    Sign out of your Apple ID on the device and sign in with the new credentials.

  • Multiple users logged into one server, each users printer has a different name, application needs ONE name to print to.

    Multiple users logged into one server, each users printer has a different name, application needs ONE name to print to. 
    I'm NOT in any way a Terminal Services expert and I need help trying to get an application program working in a multi-user environment.
    The issue is that the printer changes for every user that is logged in. The application needs to print NOT to the default printer, but to a "special" printer which is selected in the application... let's call it a label printer to simplify the explanation.
    You have your default regular printer, easy for the application to find that one, and then you have a special printer that labels get printed onto. The application needs to know what printer is the label printer. So we allow the user to select that in the
    application and the selection is stored in a config file in 
    C:\ProgramData\mfgr\prog\setting files
    I don't have access to the application so I can't change how this works.  
    In the "regular" world, selecting the label printer driver to use should be per machine, NOT per user. When a new user logs into a machine, the physical printer doesn't go "poof" and a new printer suddenly appear. Same printer for all
    users.
    Yet in terminal services, the physical machine is "merged" with the virtual machine on the server. And there can be many users logged in at the same time. So each users real machine (and real printer) is injected into the "fake" terminal
    services machine. The name of the printers is made unique for each user. So the printers DO go "poof" and change names depending on the user logged into terminal services.
    So user "A" logs in and sets up the application to print to "LabelPrinterForUserA" (or whatever the name of the printer happens to be), that setting is stored in the ProgramData subfolder, and all is well. Later, user "B" logs
    in, and when they print, the application tries to print to "LabelPrinterForUserA" which doesn't exist for user B or is only accessible by user A. If user B re-configures, that breaks it for user A. 
    SOLUTION 1: The way that /should/ work (in my mind) is that you define one "generic" printer in Terminal Services... call it "Virtual Label printer" and when the user wants to print to it, the print job gets re-directed back to whatever
    physical printer is actually connected to their local workstation. There is a map of virtual printer to actual printer depending on the current user. The application is told once to print to "Virtual Label Printer" for all users.
    SOLUTION 2: Or... there should be some way to make the ProgramData sub folders separate per user. E.g. when user "A" tries to access:
    C:\ProgramData\mfgr\prog\setting files
    they actually get 
    C:\UserData\UserA\AppData\mfgr\prog\setting files
    and user "B" gets
    C:\UserData\UserB\AppData\mfgr\prog\setting files
    So the question I have is: Does either of those solutions exist hidden somewhere in the setup of terminal server? Or is there another way around this issue that I don't know?

    I don't really have a "for sure" answer to this, but because people here can't seem to deal with a question that hasn't been answered I'll provide the best answer I did receive from ServerFault.com user Nathan:
    I can feel your pain with using old software on terminal servers ...the solution I've come up with definitely won't scale as it requires some manual configuration, but I've gotten this method to work with our label printers (which require to be
    printed to an LPT port...yep, that old).
    Share your USB-connected printers to the network on each machine. Then, have the user log in on aunique session for each of them
    (a TS account cannot be shared among computers for this to work) and install a network printer pointing to the USB one they shared. Try to use a DNS name to account for possible DHCP movements.
    After, it should work. Each user can do this since display names can be identical as long as the ports are different (which they are).
    This was clarified by the following series of comments:
    I think you are on to something here, and I originally advised the admin to do this. The problem he ran into is that it setup the printer names in the TS as "printer on usersworkstation"
    and he could not rename it except to change the "printer" to whatever. E.g. the "on userworkstation" remained. I believe there is another way of installing the printer which avoids this, but I can't find it. Ages ago, one used to do NET
    USE LPT2 \\computer\printer password /USER:domain\user /PERSISTENT:YES and then tell the driver to print to LPT2 –  James
    Newton Mar
    17 at 16:21   
    @JamesNewton That's actually the exact method we used. The way around the "network printer" part is to install it as local printer and map it to a TCP/IP port that way. –  Nathan
    C Mar
    17 at 16:28
    You mean in the case where the printers are TCP/IP connected and not local USB / LPT to the users workstation? That makes sense. Wonder if this will work for USB connected printers... –  James
    NewtonMar
    17 at 16:35   
    @JamesNewton You'd share the local printer on the client's PC then on the server connect via TCP/IP to it. You'd need static addresses or use DNS names if DHCP, though. –  Nathan
    C Mar
    17 at 16:51
    Ah. Yes. I see. Looks like the LPT thing should work even with a USB connected printer:superuser.com/questions/182655/… –  James
    Newton Mar
    17 at 17:09   

  • New users can't log into /mydevices or /profilemanager

    Hi all,
    I've got Profile Manager up and running and have deployed about 25 iPads using the current setup.
    My configuration has not changed but all of sudden, new users created today can not log into /mydevices or /profilemanager.  Says the username or password is incorrect, but they're entered properly.  Again, the configuration of the server has NOT changed since users entered (and working) last week.
    Anyone have this issue?  If anyone can shed some light, I'd really appreciate it.
    Apple: Lion Server is buggy as ****.  Profile Manager is buggy as ****.  I've spent hours on the phone with Apple support with one issue after another.  I'm getting sick of the instability and crankiness of Lion Server.  These forums are chalked full of people having such a massive range of issues that I can only draw one conculsion: Lion Server is half baked.
    Please help (again),
    Chris

    I got my problem solved - and here is a few things to note and some steps to resolve the issue.
    1) you do not need to create augmented users - unless you need extra settings for local logins (you most likely won't have users logging into your mav) - if you are using AD that is - if not just create local users
    2) server is buggy - perhaps - but after dealing with this issue for a few days - as much as i want to agree with it i want to say that now it is running very smoothly - and it boils down to order of steps in the install
    4) do not change hostnames once it's set up - that will scre it up even worse
    here is what i woudl suggest to blow it away and reset it up
    1) system pref - users and groups - login options - network account server - edit - unjoin the domain
    2) blow away your open directory and profile manager in command line
    sudo /usr/share/devicemgr/backend/wipeDB.sh
    sudo slapconfig -destroyldapserver
    3) reset apache web config
    sudo /serveradmin command web:command=restoreFactorySettings
    4)make sure your hostname is correct
    5) join domain (if needed)
         on command line veryfiy ad is working by typing
         user "username" where username is username of AD user
    6) if AD set up - check dns search order - make sure no local host (127.0.0.1) is in the list
         system preferences - network - ethernet - advanced -dns - remove 127.0.0.1 if there (only if using AD)
    6) server admin - open directory - settings - change - set up as standalone
    configure yoru ldap server - this will reissue signing authority certificate that you will need if you want to sign your configurations profiles for clients (iOS and Mac)
    7) then configure profile manager
    Reboot after step 2 - step 3, step 6
    if you have a firewall infront of the server there will be aditinal ports required for SCEP
    http://support.apple.com/kb/TS1629
    you will need port 80,443 and 1640
    If you have a reverse proxy you will need to set up a trust to the cetificate on the proxy to the authority configured in the open ldap - different topic - but just tought it was worth mentioning

  • EPM 11.1 Install Problems - Apps not in SS/Can't Log into Wkspce/Install ?

    Hi all...
    Was attempting to do an install w/ separate tablespaces in Oracle. Read install doc and saw this note
    "To use a different database for each product, perform the “Configure Database” task separately for each product.
    In some cases you might want to configure separate databases for products."
    Guess I may have read it wrong but basically, tried running config for an entire app one at a time vs. just running the config database and then performing the remainder of the confg tasks for all apps. Validates okay (except Studio -- connection string doesn't seem to be working although looks okay in the .properties file -- but can fix that later), however now I have the following problems:
    Planning, Reporting and Analysis apps are not showing up in Shared Services nor are there any roles associated with these apps so I can't provision a user for access.
    Can't log into Workspace to see if my apps are are there -- tried using "admin" "password" but get error message "You must supply a valid user name and password to log onto the system". Which makes sense -- there are no roles for these apps and, therefore no users w/ access to these...
    So, first question -- When Oracle says to run the Configure Database task separately for each product, does that mean I was supposed to select only this specific task for each product and then run the config for all products w/ the "configure database" deselected?
    Next question -- Any way to force the app to register to Shared Services? The apps that are not showing in Shared Services do not have any apparent tasks for doing this and some only have a choice between configure database and deploy application server -- don't really want to chose either of these as would think it would get really, really messy (that is, would it deploy a second app server or update the current one?)
    Trying to avoid uninstalling but that may be the only option. However, before I do that wanted to make sure I understood the Oracle note about "Configure Database" (see question above).
    Any thoughts welcome.
    KJ

    So, John...
    Good info on the the EPM Workspace issue. After installing the R&A Migration package, BI Plus and roles were available in Shared Services and I was able to log into Worksapce with both my previously non-working Admin/password account and a test user account. And, as an added bonus, the previous Oracle connection string error I was having w/ Essbase Studio disappeared!
    Unfortunately, Planning and EPMA did not get a boost from that fix so, am currently in the process of uninstalling, which as you noted was not all the clean at all -- actually didn't see any difference after the uninstall from the install, and installing.
    Install appears to be laying down the files (manually deleted the Hyperion directory...) okay. Will have to see how it goes from here. Think I will try the route of doing all the configure database tasks for all the apps first (to keep them in separate tablespaces and instances) and then doing the config for all the apps at one time.
    BTW... Is there a "published" configuration sequence? I read the "Start here" and Install doc from cover to cover before starting the install and config and did not see any specific notes on the order of configuration... Just curious as I have seen several notes that allude to this being in the install doc. Am I just totally missing something?
    KJ

  • I downloaded a movie to the wrong library by accident. now i can't put the movie on my husband's ipod because it says it can only sync to one library at a time. how do i fix this? i don't want to get rid of the old videos, i just want to add new ones

    i really don't know what i did wrong. i logged into itunes using my husband's id, then bought some movies. but for some reason, it downloaded them to my library, not his. now i can't put them on the ipod. is there any way to get them out of my library and into his library? i tried home sharing, but it still won't let me sync them to the ipod

    Copy the movie from the current library to the correct library.
    iDevices can only sync to one library at a time.

  • I can't log into my iTunes account. I logger out a few days ago to trouble shoot because I was trying to redeem some iTunes cards but when i pressed redeem nothing happened. Now when i press sign in and then choose existing Apple ID, nothing happens

    I can't log into my iTunes account on my iPhone 5s. I logged out a few days ago to trouble shoot because I was trying to redeem some iTunes cards but when i pressed redeem nothing happened. I then tried to log back in immediately afterwards. I was unable to do so. After clicking "sign in" at the bottom of the apps main page, it brought up another menu where I clicked "Choose existing Apple ID". After pressing this the menu disappeared and nothing happened. I tried this multiple times and received the same result each time. I tried the other available option of creating a new AP ID to log in with and that one worked perfectly fine. I am clueless as to why the log in for me is either not able to load or just completely blocking me from getting back into my iTunes account on my phone. Not only can I not listen to the music I currently have, but I cannot log in to purchase the new music that I wanted to with my unused iTunes gift cards

    I have the same problem too and tried alot of things like time zone , restarting or changing DNS of wifi connection to 8.8.8.8 still nothing happens .. !!
    iPhone 5s, iOS 8.3

  • Can not log into server computer with any accounts - "You are unable to login to the user account "abcdefg" at this time. Logging in to the account failed because an error occurred."

    I have a Mac mini running the latest version of OS X and Server. Been running fine and flawlessly. However, I had a strange problem with the iCloud preferences panel crashing when I tried to access it, so I rebooted. Now I can not log into the system with any accounts. My master admin account (along with all the others) gives me the error:
    You are unable to login to the user account "abcdefg" at this time. Logging in to the account failed because an error occurred."
    I am able to see the server from other macs and I can log into it using the same account, but it only shows me a few of the shared folders I have access to but NOT to my main directories.
    Rebooting into Command-R and doing a disk utility, I try and repair permission on that drive and get a bunch of errors like:
    ACL found but not expected on Users
    Repaired "Users"
    ACL found but not expected on Users/.localized
    Repaired "Users/.localized"
    ACL found but not expected on Users/Shared
    Repaired "Users/shared"
    ACL found but not expected on Users/Shared/.localized
    Repaired "Users/Shared/.localized"
    Permissions repair complete.
    But rebooting is no joy...same problem. Any idea what is going on or how to repair it? Should I do a time machine restore? Complete new OS X install? Any idea what is causing this or how to salvage it?

    Got everything to re-install and it worked fine...for a few hours. Then I came in to find ALL of my network users deleted. Just GONE. Then found out the Open Directory was trashed and was unable to open, recover or restore from a backup. Looks like I may have a bad drive here.
    I installed a new drive in the system, re-installed and so far (for a couple of hours anyway) the system seems to be working and stable.

Maybe you are looking for

  • Error while running the package .

    guys, i created a transformation file is succesfully completed . when i run the package it is showing the error like immediate run error while creating to run the package on the server <appserverurl>>!cdata(http://localhost/osoft></appserverurl Thank

  • Fresh install with lots of errors

    Good Morning, I just installed oracle XE on a Ubuntu Server 10.04 and I had to fix a problem I never had before. When I tried to connect to the database with sqlplus sqlplus / I got a error saying that ORACLE was'nt running. So, I logged differently:

  • XI Configuration check

    Hello, I am cross checking my configuration with the Readiness_Check_Version3.pdf In one of the test cases on SLDCHECK mentioned below it says "Check if the URL given in this section corresponds to http://<host>:80<sysnr>/sap/xi/engine?type=entry " a

  • Error 1450: library falsly corrupted, can't restore ipod

    every time I start itunes it gives me this error 1450 and starts reimporting all of my music because my library is damaged. If I close itunes and delete both damaged and new libraries and restore it from a backup (identical to one itunes just told me

  • JTable and MouseListener

    Hi, I am using JSDK 1.3. I am seeing some unpredictable behavior when using MouseListener on JTable. Here's the problem: When I click on row in the table, I am expecting that every time there is a click, application would process mouseClicked() event