Externalize Users in 11.1.2

Hello All,
We are working on a POC to upgrade to 11.1.2 and kinda stuck here.
After installing Foundation Services and Essbase on our 2008,64 bit VM , i was able to logon to the EAS console with the user ID admin.
The Essbase server was registered to a different User ID(essadmin) and I was able to add the Essbase server but however when i tried to do the Click on security->Externalize Users, i find that i don't have the option at all.
The only options available are Update Security backup file,Compact Security file and Export Security file.
What are we missing here?

John,
The SS_Security_Client.log does have these entries..Not sure what they mean though :)
[2011-01-11T11:00:53.861-08:00] [EssbaseAdminServices0] [ERROR] [EPMCSS-1002] [oracle.EPMCSS.CSS] [tid: 11] [userId: <anonymous>] [ecid: 0000IpqSw3R7MAk6wznZ6G1DBAWG000006,0] [SRC_CLASS: com.hyperion.css.common.CSSUtils] [APP: EAS#11.1.2.0] [SRC_METHOD: checkValidArgument:107] [arg: error.css.arg.token] Invalid value for error.css.arg.token. Enter a valid value.
[2011-01-11T11:00:53.861-08:00] [EssbaseAdminServices0] [ERROR] [EPMCSS-1014] [oracle.EPMCSS.CSS] [tid: 11] [userId: <anonymous>] [ecid: 0000IpqSw3R7MAk6wznZ6G1DBAWG000006,0] [SRC_CLASS: com.hyperion.css.CSSAbstractAuthenticator$CSSTokenUtils] [APP: EAS#11.1.2.0] [SRC_METHOD: getUserDetails:1022] Invalid token.[[
Error Code: -1
com.hyperion.css.CSSIllegalArgumentException: 26:1002:Invalid value for Token. Enter a valid value.
     at com.hyperion.css.common.CSSUtils.checkValidArgument(CSSUtils.java:107)
     at com.hyperion.css.common.internal.CSSTokenHelper.getTokenDetails(CSSTokenHelper.java:194)
     at com.hyperion.css.CSSAbstractAuthenticator$CSSTokenUtils.getUserDetails(CSSAbstractAuthenticator.java:1018)
     at com.hyperion.css.CSSAbstractAuthenticator.restoreToken(CSSAbstractAuthenticator.java:931)
     at com.hyperion.css.CSSAPIImpl.restoreToken(CSSAPIImpl.java:180)
     at com.hyperion.css.facade.CSSAPIFacade.restoreToken(CSSAPIFacade.java:843)
     at com.hyperion.css.EPMSystem.restoreToken(EPMSystem.java:148)
     at com.hyperion.css.CSSSystem.restoreToken(CSSSystem.java:509)
     at com.essbase.eas.server.CSSLogic.restoreToken(Unknown Source)
     at com.essbase.eas.essbase.server.EssSession.getToken(Unknown Source)
     at com.essbase.eas.essbase.server.ServerCommandListener.connect(Unknown Source)
     at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
     at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:39)
     at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:25)
     at java.lang.reflect.Method.invoke(Method.java:597)
     at com.essbase.eas.framework.server.application.AbstractCommandListener.handleEvent(Unknown Source)
     at com.essbase.eas.framework.server.application.DefaultCommandDispatcher.dispatchEvent(Unknown Source)
     at com.essbase.eas.framework.server.application.DefaultEventController.handleEvent(Unknown Source)
     at com.essbase.eas.framework.server.application.EventDispatcherWorkListener.handleEvent(Unknown Source)
     at com.essbase.eas.framework.server.application.DefaultWorkDispatcher.dispatchEvent(Unknown Source)
     at com.essbase.eas.framework.server.application.DefaultEventController.handleEvent(Unknown Source)
     at com.essbase.eas.framework.server.application.DefaultApplication.generateWorkEvent(Unknown Source)
     at com.essbase.eas.framework.server.application.DefaultServlet.handleRequest(Unknown Source)
     at com.essbase.eas.server.AppManServlet.doPost(Unknown Source)
     at javax.servlet.http.HttpServlet.service(HttpServlet.java:727)
     at javax.servlet.http.HttpServlet.service(HttpServlet.java:820)
     at weblogic.servlet.internal.StubSecurityHelper$ServletServiceAction.run(StubSecurityHelper.java:227)
     at weblogic.servlet.internal.StubSecurityHelper.invokeServlet(StubSecurityHelper.java:125)
     at weblogic.servlet.internal.ServletStubImpl.execute(ServletStubImpl.java:292)
     at weblogic.servlet.internal.ServletStubImpl.execute(ServletStubImpl.java:175)
     at weblogic.servlet.internal.WebAppServletContext$ServletInvocationAction.run(WebAppServletContext.java:3594)
     at weblogic.security.acl.internal.AuthenticatedSubject.doAs(AuthenticatedSubject.java:321)
     at weblogic.security.service.SecurityManager.runAs(SecurityManager.java:121)
     at weblogic.servlet.internal.WebAppServletContext.securedExecute(WebAppServletContext.java:2202)
     at weblogic.servlet.internal.WebAppServletContext.execute(WebAppServletContext.java:2108)
     at weblogic.servlet.internal.ServletRequestImpl.run(ServletRequestImpl.java:1432)
     at weblogic.work.SelfTuningWorkManagerImpl$WorkAdapterImpl.run(SelfTuningWorkManagerImpl.java:516)
     at weblogic.work.ExecuteThread.execute(ExecuteThread.java:201)
     at weblogic.work.ExecuteThread.run(ExecuteThread.java:173)
]]

Similar Messages

  • Externalize users issue

    we are facing issue while externalize users in essbase, not able to get finish button (version 933).
    giving error that there are no users/groups to migrate, but all users & groups there & provisioned.
    (refresh sec from ss option not coming, so tried to do externalize but getting this issue)
    Please help...

    Are you talking about refreshing security from EAS? If you are using 9.3.3 then refreshing essbase security from shared services was removed.
    Cheers
    John
    http://john-goodwin.blogspot.com/

  • Unable to Externalize users to Shared Services

    Hi All,
    I am facing the following issue
    [Sun Jul  6 11:28:17 2008]Local/ESSBASE0///Error(1051429)
    Analytical Services Product Existence Check Fails against the Shared Services Server with Error [Unable to Authenticate.]
    Fatal Error: CSS Initialization Fails
    I have also done the following steps but could not resolve..
    STEP 1:
    a. Shutdown all the Services
    b. Take the backup of the file "Essbase.bak" by copying to another folder.
    c. From Native Folder(ARBORPATH),Rename the "Essbase.bak" file to "Essbase.sec" file.
    d. Reboot the machine where Essbase server is running.
    e. Start the Services and work on the application.
    If the issue still persists then Proceed with STEP 2
    STEP 2:
    Unregister the Analytic Services with Shared Services and then try reconfiguring Analytic Services from Configuration Utility (Especially register with Shared Services) and try working with the application
    If you have any information about how to resolve the above issue, please help.. Thanks.
    Message was edited by:
    637223

    Issue:
    Error 1051429 - Unable to Externalize the Users to HSS.
    Error Log:
    [Sun Jul 6 11:28:17 2008]Local/ESSBASE0///Error (1051429)
    Analytical Services Product Existence Check Fails against the Shared Services Server with Error [Unable to Authenticate.]
    Fatal Error: CSS Initialization Fails
    Environment:
    Win Environment installed – Weblogic 9.1 / HSS / AAS / BI+/ Planning
    Linux Environment Installed – Oracle DB 10 GR2
    Linux Environment Installed – Essbase
    Observation / Research:
    Duplicate entries in Essbase.cfg file.
    ; The following entry specifies the full path to JVM.DLL
    JvmModuleLocation /hyperion/common/JRE/Sun/1.5.0/lib/i386/server/libjvm.so
    ; SharedServicesLocation fatapp2.advtek.com.tw 58080
    ; AuthenticationModule CSS http://fatapp2.advtek.com.tw:58080/interop/framework/getCSSConfigFile
    ; SharedServicesLocation fatapp2.advtek.com.tw 58080
    ; AuthenticationModule CSS http://fatapp2.advtek.com.tw:58080/interop/framework/getCSSConfigFile
    ; SharedServicesLocation fatapp2.advtek.com.tw 58080
    ; AuthenticationModule CSS http://fatapp2.advtek.com.tw:58080/interop/framework/getCSSConfigFile
    SharedServicesLocation fatapp2.advtek.com.tw 58080
    AuthenticationModule CSS http://fatapp2.advtek.com.tw:58080/interop/framework/getCSSConfigFile
    Solution:
    ** Altered the settings of the Essbase.cfg file as below
    ; The following entry specifies the full path to JVM.DLL
    JvmModuleLocation /hyperion/common/JRE/Sun/1.5.0/lib/i386/server/libjvm.so
    SharedServicesLocation fatapp2.advtek.com.tw 58080
    AuthenticationModule CSS http://fatapp2.advtek.com.tw:58080/interop/framework/getCSSConfigFile
    ** Restarted all the Hyperion Services
    ** Logged into HSS, sync the OpenLDAP .
    ** Logged into AAS Console and Externalized all the users in Essbase to HSS
    ** Able to Externalize the users successfully.
    ** Created a sample application and a database and suggested the Customer to work out with the Applications.
    Hope that it works for you :)

  • Externalize users error

    I am trying to migrate Essbase users to Shared Services and I get the following error:
    Error: 1051449: Essbase failed to get group with Error [CSS Error: Invalid Argument: Principal passed is NULL]
    Any ideas?
    Thank you!

    Start Essbase in Foreground.... and capture the error..
    Blow the Security and replace it from Backup which was wormking fine..start all over again for Externalisation
    You can also check for PREUPM/ POSTUPM files in Essbase/Bin..if they are present then Essbase is partially externalised..you can try taking a copy of the PREUPM and rename the PREUPM to Essbase.sec and start essbase..Rexternalise.

  • Converting to Shared Services Security Mode Error (externalize users)

    Error: 1051549: Can not convert Analytic Services to Shared Services mode when Analytic Services is not configured with Shared Services or the initialization process has failed
    I have tried to register ESSbase with SS again and does not work. All services are started....ideas?

    Start Essbase in Foreground.... and capture the error..
    Blow the Security and replace it from Backup which was wormking fine..start all over again for Externalisation
    You can also check for PREUPM/ POSTUPM files in Essbase/Bin..if they are present then Essbase is partially externalised..you can try taking a copy of the PREUPM and rename the PREUPM to Essbase.sec and start essbase..Rexternalise.

  • User and Group Externalization from EAS console Fails!!

    Hi All, I am trying to externalize users and groups from EAS and once its done, all the login Id's (including admin and essadmin) fail. We cant log in into the server anymore because the logins are disabled.
    The shared services is running fine and is talking pretty well with Essbase, but the externalization thing is not working.
    The Essbase is on Linux server and shared services is on windows server and all the products are 9.3.1.
    If any one faced a similar problem or have any idea regarding this issue, please let me know ASAP and would highly appreciate that as we will have to move to production soon.
    Message was edited by:
    user639077

    You might want to Try Re-run the Config utility from the Linux-Essbase server and Re-register the Essbase with HSS.
    Start the Essbase in Foreground and check if it is running
    Now log on to the EAS/AAS with default admin/password if you havent changed it :); add your Essbase server using the Super user/Owner of essbase i mean the id..if you are succesful; i would always create a Test user as before Externalisation i can create users at EAS/AAS and then using Admin id ; i will push the Users/groups to the HSS by Externalising.. let me know if that helped you. GUd Luck..
    Sriram

  • Essbase, shared services, projects, users

    I have installed shared services and cnfigured it
    now installed essbase
    EAS
    Provider services
    and configured in the above mentioned manner
    (DID not start essbase and EAS till now)
    when I log into shared services....i see only bussines rules under projects
    no analytical services under unassigned applications.....
    how can i see essbase server in shared services user management console.......
    it might be a basic funda....i am not getting
    help me in solving this....
    Thanks in advance

    Hi,
    Have you converted essbase from native security mode to shared services security.
    In EAS, right click security and choose "Externalize users"
    Cheers
    John
    http://john-goodwin.blogspot.com/

  • EPM system security externalize

    Hi Masters,
    Recently I have setup EPM system 11.1.2.4 for Essbase on my servers. As you all know this version doesn't support for standalone Essbase security and by default all the users/ groups would be maintained through shared services, I have a stupid doubt here,.... what is the purpose of having the option 'Externalize users' still in EAS? is it like we need to do 'externalize users' as soon as we installed and configured the Essbase and EAS?.
    Please, help me in understanding this point.
    Thanks,
    Siva

    Yes you are correct they are automatically externalized so there is not really point in having the option in EAS anymore, I am sure it will be removed in the future.
    Cheers
    John

  • Externalise Users

    Hi All,
    We are facing some issues while externalizing the users in EAS console, these are the steps we followed ,help us in solving the issue.
    1.We have tried to externalize the users using admin user but after this admin(planning user) became as an Essbase user because of which we were unable to login to planning.
    2.We reverted back to the normal position by replacing the old backup.
    3.Again we created new user in shared services and with the same name we created an Essbase user and tried to externalize with that user, but after that the Essbase administrator became inactive and we were unable to login to both EAS console and Planning.
    4.Again we reverted back.
    I have one concern with exactly which user we need to externalise the user is it a planning or Essbase user.
    Please share any documents or views regarding the externalizing users from Essbase to shared services.
    thanks,
    Anil

    Hi,
    there might be a provisioning problem or not externalized users on essbase,If you already configured planning and essbase successfully and externalized users, then provision user with all access which you want, like essbase and planning with admin access and try to login planning application,refresh security filters and refresh from EAS.
    Kumar: create new user and provide provisioning for planning and essbase as admin access from shared services and externalize user if it successful,refresh from EAS,if not works, otherwise first provide provision for essbase and externlize users then provide provision for planning. then it may work.
    Thanks,
    :-) :-)

  • Externalise users from EAS related query

    Hi,
    In fresh installation when should we go for externalize users (using EAS right click ‘Security’ click Externalize Users). I mean should i go for externalse user:
    1) after installing/configuration of Shared services, essbase client, Essbase server and administration services) .
    2) after installation of Shared services, essbase client, Essbase server, administration services and Planning.
    3) any other suggestion please.
    Version 9.3.1, windows 2003

    Hi,
    Install/configure shared services - check you can log in to shared services
    Install/configure essbase - check you can log into essbase using maxl or esscmd
    Install/configure EAS - Log in to EAS add essbase server, convert to shared services mode.
    Remove essbase server from EAS, add essbase server to EAS but using external authentication ticked..
    Move on to the other products...
    Cheers
    John
    http://john-goodwin.blogspot.com/

  • Externalsise users

    hi,
    i installed/config. shared services, essbase client, essbase server and EAS, i am able to login with MAXL and admin console.
    i externalize users after right click on security, which prompted successful.
    i removed essbase server form EAS and added again (server name, login, pw, re-enter pw) but i can't see options "external authentication ticked"
    then i go to shared services and when i click on any essbase applications at left pane;
    i see errror message " Network error [11004]; unable to locate [hyp931.localdomain] in hosts file.
    version 9.3.1
    windows 2003
    all component on single host.
    please advice did i skip any step?

    How did you register your applications against the hostname? just wondering why the message is "hyp931.localdomain"
    As a test you could update the hosts file and add
    ipaddress hyp931.localdomain
    but put the machine ip
    e.g.
    192.168.1.100 hyp931.localdomain
    restart the services, try it again, if it works then it is something to do with the way it has registered with the hostname.
    Cheers
    John
    http://john-goodwin.blogspot.com/

  • Related to Externalise user from EAS

    Hi,
    i encounter many times with similar problem in different environment;
    It seems, i may be doing something wrong each time; i am trying my steps for externalize users from EAS.
    After connecting EAS,
    1)I right click on 'security' Externalize users.
    2) provide server and it also ask to select- 1) auto , 2) native users login/PW, 3) password
    3) i always select native users and login ID /PW
    then it prompt successfully converted.
    4) I remove essbase server and add again server with similar details but this time my essbase user (user 1) fails to connect with essbase even from ESSCMD.
    but system default user 'admin" is start login if i add credentials in shared services.
    Please help what is wrong and why same problem each time.

    Once you have externlized the users do you see them in Shared services?
    You do know that option sets the password to be the same as the username.
    Cheers
    John
    http://john-goodwin.blogspot.com/

  • User and Group Security Provisioning

    Hi,
    I have a question regarding Group security in Planning. I am using EPM system 11. My basic question is, if I create a new Planning user (interactive user with no default access to dimensions), and assign that user to a Planning group, does the user automatically inherit all the dimension access assigned to that Group? From my experience, it seems that I must explicitly assign each User access to the dimensions they should be able to Read or Write, and that simply adding them to a group that has been given Write access to the Expense Account (for example) does not give a newly added user to that Group Write access.
    A quick note - when creating new Users, I first create and provision them in Shared Services. However, in order to be able to log in with them, I must recreate the user in EAS's User Directory. This seems redundant to make a user twice, but is the only way I am able to successful login with new users, otherwise the Planning login page says "failed to sync with user provisioning". I have not done this same procedure for the Groups I have created (i.e. I have made and provisioned the Groups in Shared Services, but not recreated them in EAS). Is it possible that this is why Users aren't inherittiing the access rights of the Group? I can provide more information if needed, any help or comments are appreciated. Thanks in advance.

    user3x3 wrote:
    1) EAS method is to open EAS, then open the Essbase Server Node, right-click on security, and click Externalize Users. When I do this there is no right-click option to externalize the users, and since it can only be done once and then not reversed I assume the previous administrator already did this. Since this is not availalbe, I must use the second method.
    If you log in with an administrator account you should see the "Externalize Users" option even if you have already externalized.
    I take it you did not configure your system, I take it was documented so you could have a look how it was configured.
    If essbase is on a different server than shared services then maybe the essbase server was not registered with the shared services registry when it was configured, that might the reason why you are getting the shared services error when you try to convert to shared services security, basically it doesn't know where shared services is. If that is the case then it will need to be configured again.
    Cheers
    John
    http://john-goodwin.blogspot.com/

  • Error connecting to Essbase Server when running business rules

    We recently migrated from v9.3 to v11.1.1.3. I have two users with Administrative access who need to run business rules on a native Essbase application, but cannot. They get the message 'Error connecting to Essbase Server'. They get this message when trying to set this execution database. They can't even expand the server to see the list of applications. I have tried deprovisioning them in Shared Services, refreshing security, then adding it all back in and refreshing again, but it doesn't work. My own id has identical access to that which I'm granting them, and I have no problems. I even created a native user with the same access and it works as well. No matter what I do, I cannot get these two users to be able to run their business rules in EAS.
    We also have a Planning application, and the Planning Administrative user has the same issue. However, this user is able to get around it by running rules using the Planning connection rather than the Essbase connection. She has the same issue of not seeing anything under the Essbase Servers when trying to set the execution database though.
    In version 9, we were not using Shared Services for Essbase security. Unfortunately our consultant chose to set it up using Shared Services security when migrating, and according to the documentation, one cannot go back to using Native Essbase security.
    I also tried running the Externalize Users wizard and the three users with issues failed to externalize. My own id did, and the native user I created succeeded.
    Has anyone experienced an issue like this or have any ideas on how to resolve?
    Thanks,
    Sabrina

    Follow up - Oracle has finally resolved this. It's so simple, yet no one thought to check until now. The three users with problems all have mixed case user id's in ldap. They have always logged into EAS with all lower case ids. In version 9, on native security, this was never a problem. But in version 11 using Shared Services (not sure which factor changed it), it doesn't work. The simple solution is to log in with their exact mixed case user ids. It only took Oracle three months and the creation of a bug issue to figure this out for us.
    Sabrina

  • External Authentication issue

    Hi All
    In Shared services I have 'Configured User directories' with the SQl server database. I could connect and get all the users from SQl server . I can see that there are items under User Directories 1.Native Directory 2.SQl server . The serach order is also set. I have restared the Shared services. Now how can i make the use of SQl server users ? .
    From Console I have done the "Externalize users " for Essbase server. I have refreshed the security from shared services.
    Now I should be able to login in console using the SQl server users .. isnt it ? How can I do that ? How can i use the SQl server users to login into EAS and essbase server? . I also provisioned the SQl server user in Shared services and given the Administrator priveleges to Analytic server.
    Please help me.

    Hi,
    1. As you see the newly added "user directory", It must be added properly. But,to re confirm your configuration of SQL server user directory. Do test it ( there is an option to "test" it ,when you go to 'use directory' within shared services.
    2. After you have added, you have told that you have restarted shared services. But ,when you configure a new user directory, I would recommend you to restart shared services along with the other application related services ( like essbase, planning).
    3. Now, if you want to use the users of newly configured User directory, search the user from the directory and assign the roles/preveleges . Then try to login into systems( shared services , planning or essbase ...etc).
    Revert for further clarity.
    Sandeep Reddy Enti
    HCC
    http://hyperionconsultancy.com/

Maybe you are looking for