Force re-authentication to access certain URLs after authenticated by OAM?

Hi,
I have not came across this requirement, but curious if anyone ever implement this? Or this is possible at all?
Basically, after a user is authenticated by OAM, is it possible to force a re-authentication of each access to certain URLs?
Thanks

Hi ,
I presume that you are looking for a step-up authentication. Yes, Sagar is correct. That is one of the way to do it.
But ideally when you prefer higher authentication for more secured resources, you can challenge the user with KBA question and that is what most of customers use (either Banking applications etc.,). So in that case, OAAM is the best choice for it, where you can configure KBA questions while user first login.
-M

Similar Messages

  • Can not access certain URL

    I can not access my company URL from BB while i can access it from any other device. The below message received,
    The requiered URL could not be retrieved
    Sorry, we couldn't find the web page that you requested. Make sure that you typed the web address correctly, and try again.
    Error Code: 10006

    Hi,
    It seems like with every BB Bold it is giving error code 10006. With the curve it is giving 504 gateway timeout. Only th default browser. if you install any other browser on the phone then it can display the site. When I phone my service provider they say my phone software is not working and I ned to bring it in...this is not true for I tested it on about 10 blackberry bolds and none of them display the site. also not the curve or torch.(Torch is also giving the 10006 error code). When I phone my hosting company they say they cant see anything wrong with the setup of the website. So is blackberry blocking the site or what? I dont know what to do anymore. and the client wants this to display on a blackberry. 
    I see you are from France. Could it be that maybe it does not work in South Africa only? Something on the sa BIS?

  • Can't access certain URLs on servers in LAN

    I'm having a problem with accessing an httpd server running on my PowerBook connected to both my corporate and home LAN.
    I give the iPhone an address like:
    http://192.168.1.188
    And it works fine. However, when I try to access a folder:
    http://192.168.1.188/~mike
    it changes the URL to http://phoenix.local/~mike (phoenix is the name of the machine), and then stalls, and sometimes tells me that it can't access the server.
    I have been to that address on other non-iPhone machines, and the URL works fine.
    Anyone have a clue on what's going on?

    SOLVED:
    You have to put a trailing / if the URL points to a directory. For example:
    http://somewhere.com/folder/
    instead of
    http://somewhere.com/folder

  • Can't access certain things after upgrading to iOS 8.1.2 on iPad

    Just upgraded my iPad to iOS 8.1.2 and now, cannot connect to the App Store, iTunes Store, do an iCloud back up, or even open up Facebook for an app. Password is correct. Surely it does not take 12+ hours to update? What gives? Thanks.

    Hello razmee209.  Thank you for your response.  I spent the better part of yesterday working with Apple Support.  They tried their best, to include backing up photos to my HP laptop, backing up the iPad to iCloud, then resetting the iPad in total.  Same problem.  I restored from the cloud to recover my apps, same problem.
    AT&T installed a new sim card - same problem.  I spent time with AT&T Support yesterday, too.  In both cases, (Apple and AT&T) the support techs who worked with me were extremely polite, courteous and helpful to the best of their abilities, but I think the problem lies deeper, and nobody at Apple is admitting they have a problem with iOS 8, that I'm aware of.
    I didn't have this issue before I upgraded to iOS 8.1.2.
    Everything else with the iPad works fine:  WIFI, Personal Hotspot, email, all my apps, etc.
    In browsing the web for this issue I see that many other folks have the same problem.  I filed a report with Apple this morning, requesting that they contact me, but no word yet.  I was going to go to iPhone 6, and had been considering the iPad Air 2, but I see reports of this problem with those units as well.
    At this point I don't think I'll be spending any more money with Apple, at least not till this issue is resolved.
    Thanks again for your response and suggestions.

  • ISE Guest Access- Redirect to URL after successful logon

    Currently, when guest users attempt to browse they get redirected to the guest portal.  After login, they get a message that they can now access the original URL.  Is there a way to automatically redirect to the URL they were trying to access, or remember the URL after they login?

    ISE guest flow :
    The user associates to the web authentication Service Set Identifier (SSID).
    The user opens the browser.
    The WLC redirects to the guest portal (such as ISE or NGS) as soon as a URL is entered.
    The user authenticates on the portal.
    The guest portal redirects back to the WLC with the credentials entered.
    The WLC authenticates the guest user via RADIUS.
    The WLC redirects back to the original URL

  • Redirect to custom url after successful authentication by OAM

    Hello,
    I need to redirect the user to some custom url instead of original requested url after successful authentication in OAM 11.1.2 (11g release2).
    The requirement in my case is depending upon the user type and the region(one of the user's ldap attributes) it belongs to, it should be redirected to one of the 2 available applications.
    I have tried implementing the same using custom authentication plugin in which I have used RedirectionActionContext class.
    I have also tried setting plugin response as REDIRECT and specifying the custom page url.
    I have also tried changing the "resource_url" parameter in authentication context.
    However, none of above approaches are working.
    Can anybody help me?
    Thanks,
    Purva

    Hello,
    I have exactly the same requirement. Have you solved the problem?
    Thanks,
    Purva

  • Can't access certain sites only on firefox even after reinstalling

    Hi,
    Today I couldn't access certain sites like my university site and google (had to use yahoo to search). I tried restarting FF in safe mode, reseted FF to factory settings, deleted FF and erased all its data and reinstalled FF23.......
    But it still doesn't solve the problem. I have no problems accessing these same sites with another browser. When I access these sites with FF, with by clicking search on my search bar or clicking a bookmark or hyperlink, FF just gives me no response, as if I didn't click anything. If I click to open the link in a new tab, it just displays a blank tab as if I've just pressed Ctrl + T
    Can anyone help me with this please? Thanks.

    Hello ashash, check if your firewall or your security software blocks firefox access for the specific sites.
    thank you

  • Cannot access Grid Control URL after installation

    I have installed Oracle Grid Control 11.1.0.1.0 for Linux x86-64 (64-bit). I can't access below URL
    1. Enterprise Manager Grid Control URL: https://ccoshs02xvoem01.ccosvc.com:7799/em
    2. Admin Server URL: https://ccoshs02xvoem01.ccosvc.com:7101/console
    [oracle@ccoshs02xvoem01 oracle]$ $OMS_HOME/bin/emctl start oms
    Oracle Enterprise Manager 11g Release 1 Grid Control
    Copyright (c) 1996, 2010 Oracle Corporation. All rights reserved.
    Starting WebTier...
    WebTier Successfully Started
    Starting Oracle Management Server...
    Oracle Management Server Already Started
    Oracle Management Server is Up
    [root@ccoshs02xvoem01 ~]# netstat -anp | grep 799
    tcp 0 0 :::7799 :::* LISTEN 26461/httpd.worker
    [root@ccoshs02xvoem01 ~]# netstat -anp | grep 7101
    tcp 0 0 ::ffff:172.30.1.31:7101 :::* LISTEN 18452/java
    tcp 0 0 ::ffff:172.30.1.31:7101 ::ffff:172.30.1.31:53507 ESTABLISHED 18452/java
    tcp 0 0 ::ffff:172.30.1.31:7101 ::ffff:172.30.1.31:54364 ESTABLISHED 18452/java
    tcp 0 0 ::ffff:172.30.1.31:54364 ::ffff:172.30.1.31:7101 ESTABLISHED 22561/emagent
    tcp 0 0 ::ffff:172.30.1.31:53507 ::ffff:172.30.1.31:7101 ESTABLISHED 20994/java
    tcp 0 0 ::ffff:172.30.1.31:53496 ::ffff:172.30.1.31:7101 ESTABLISHED 20994/java
    tcp 0 0 ::ffff:172.30.1.31:53487 ::ffff:172.30.1.31:7101 ESTABLISHED 20994/java
    tcp 0 0 ::ffff:172.30.1.31:7101 ::ffff:172.30.1.31:53496 ESTABLISHED 18452/java
    tcp 0 0 ::ffff:172.30.1.31:7101 ::ffff:172.30.1.31:53487 ESTABLISHED 18452/java
    Please can I know what needs to be done to access Grid Control.

    weblogic.management.ManagementException: Unable to obtain lock on /u01/app/oracle/Middleware/oms11g/user_projects/domains/GCDomain/servers/EMGC_ADMINSERVER/tmp/EMGC_ADMINSERVER.lok. Server may already be running
    at weblogic.management.internal.ServerLocks.getServerLock(ServerLocks.java:159)
    at weblogic.management.internal.ServerLocks.getServerLock(ServerLocks.java:58)
    at weblogic.management.internal.DomainDirectoryService.start(DomainDirectoryService.java:73)
    at weblogic.t3.srvr.ServerServicesManager.startService(ServerServicesManager.java:461)
    at weblogic.t3.srvr.ServerServicesManager.startInStandbyState(ServerServicesManager.java:166)
    at weblogic.t3.srvr.T3Srvr.initializeStandby(T3Srvr.java:749)
    at weblogic.t3.srvr.T3Srvr.startup(T3Srvr.java:488)
    at weblogic.t3.srvr.T3Srvr.run(T3Srvr.java:446)
    at weblogic.Server.main(Server.java:67)
    >
    <Feb 1, 2011 2:49:22 PM GMT> <Notice> <WebLogicServer> <BEA-000365> <Server state changed to FAILED>
    <Feb 1, 2011 2:49:22 PM GMT> <Error> <WebLogicServer> <BEA-000383> <A critical service failed. The server will shut itself down>
    <Feb 1, 2011 2:49:22 PM GMT> <Notice> <WebLogicServer> <BEA-000365> <Server state changed to FORCE_SHUTTING_DOWN>
    Do I need to reboot the server.
    I have restart OMS

  • When I try to access certain listings on ebay they are blocked - I am told this is because it thinks I am in France. I use an English ISP and the problem only happens with Firefox, not (for instance) IE. How can I overcome this?

    When I try to access certain listings on eBay I get the following message:
    "Unfortunately, access to this particular listing or item has been blocked due to a Paris commercial court decision that bans trade of certain authentic perfumes and cosmetic products on eBay because of French selective distribution laws. eBay is appealing this ruling but is nevertheless required to enforce it. We are blocking your viewing in an effort to comply with this court decision. Regrettably, in some cases, we may prevent users from accessing items that are not within the scope of the decision because of limitations on existing technology."
    eBay support told me it is because they think I am in France or because I am using a French ISP. I am in London and am using the British ISP, Bethere. What can I do to convince them that I am in England?
    The URL quoted is just an example. It happens frequently with other listings.

    This is what I get:
    ISP: Be Un Limited
    Organization: Be Un Limited
    Connection: Broadband
    Services: None Detected
    City: Horsham
    Region: West Sussex
    Country: United Kingdom
    It can't be a problem with my ISP or my IP address since it only happens with Firefox. When I try out the same listings with other browsers it doesn't happen. eBay said Firefox must be making it seem as though I am in France. Goodness knows how or why??

  • ISE no redirect to origin URL after guest login

    Hi, is there a possibility to redirect a guest user to the origin URL after he logged in successfully?
    Right now the attached file is what the user sees after login.
    Thanks!

    The first method is local web authentication. In this case, the WLC  redirects the HTTP traffic to an internal or external server where the  user is prompted to authenticate. The WLC then fetches the credentials  (sent back via an HTTP GET request in the case of an external server)  and makes a RADIUS authentication. In the case of a guest user, an  external server (such as Identity Services Engine (ISE) or NAC Guest  Server (NGS)) is required because the portal provides features such as  device registering and self-provisioning. The flow includes these steps:
    The user associates to the web authentication Service Set Identifier (SSID).
    The user opens the browser.
    The WLC redirects to the guest portal (such as ISE or NGS) as soon as a URL is entered.
    The user authenticates on the portal.
    The guest portal redirects back to the WLC with the credentials entered.
    The WLC authenticates the guest user via RADIUS.
    The WLC redirects back to the original URL.
    This  flow includes several redirections. The new approach is to use central  web authentication. This method works with ISE (versions later than 1.1)  and WLC (versions later than 7.2). The flow includes these steps:
    The user associates to the web authentication SSID, which is in fact open+macfiltering and no layer 3 security.
    The user opens the browser.
    The WLC redirects to the guest portal.
    The user authenticates on the portal.
    The  ISE sends a RADIUS Change of Authorization (CoA - UDP Port 1700) to  indicate to the controller that the user is valid, and eventually pushes  RADIUS attributes such as the Access Control List (ACL).
    The user is prompted to retry the original URL.

  • ADF Authorization for ADF Mobile:Configuring Access Control URL for ADF App

    Can someone explain, how to expose weblogic user roles as a Rest Json Api? Basically I want to set up Access Control URL to authorize users on adf mobile.

    Hi Frank,
    This is what I did. Could you please let me know if I am doing it right.
    1. Created an adf application with a simple page and applied security basic http authentication.
    2. Added a rest service implementation in the same application, changed the adf application web.xml as below
    <servlet-mapping> 
       <servlet-name>jersey</servlet-name> 
       <url-pattern>/jersey/*</url-pattern> 
      </servlet-mapping>
    3. When I test the rest service in browser, it asks to log in and returns the user roles. Below is my rest implementation
    @POST
    @Produces(MediaType.APPLICATION_JSON)
    public User getMessag3() throws Exception {
    return new User();}
    the rest service returns the logged in user roles in below json format.
    {"userid":"susant","roles":["SSBAccessGroup","authenticated-role","SSBAccessApp","anonymous-role"],"priviledges":[]}
    Do I need to implement anything on the ADF mobile side or I can just add the rest service url to the authorization tab. Will adf mobile automatically handle sending the http request.
    Actually I just added the rest service url to adfm-applications connections authorization tab and I am getting ACS failed error after log in.
    Thanks

  • Regex expression to block certain URL's.

    Hi,
    I am trying to block certain URL paths within a website. For example I would want to block any request to www.asdf.com/test/input.asp, other request like www.asdf.com should be accepted.
    I tried building a regex to match test/input.asp and the regex test says match succeeded, however after applying it via service policy the URL still works. The following regex has been applied to match test/input.asp
    .+\/test\/input\.asp
    Where could I be wrong?
    Regards

    Hi Karsten,
    The filtering config reads like the following:
    regex Block-test ".+\/test\/input\.asp"
    access-list outside_mpc extended permit ip any host 2.2.2.2
    class-map outside-class
    match access-list outside_mpc
    policy-map type inspect http Block-test
    parameters
    match request uri regex Block-test
      drop-connection log
    policy-map outside-policy
    class outside-class
      inspect http Block-test
    service-policy outside-policy interface outside
    Its not an https connection and the configuration is on the ASA.
    Regards

  • Only show certain fields after a date has passed

    How would I set a recordset to only show certain fields after
    a date has
    passed?
    For example:
    I have a list of classified adverts some which include an
    image which the
    client pays extra for. After a certain time period, say, 1
    year,
    would it be possible to use some kind of IF statement (or
    something) to no
    longer show the image?
    Thanks
    Gary

    scrap that entire post man.
    I'll rewrite it here in a few.
    "crash" <[email protected]> wrote in message
    news:[email protected]...
    >
    OK. I can't be as much help as I was hoping, since I
    just did this in
    > PHP and MySQL. But we can do a bit. My ASP is rusty
    enough I'm just going
    > to give you what I think you should do.
    >
    > You'll need to research how to format dates and most
    importantly strip
    > away the timestamp. In MySQL, you can format the date as
    it comes out of
    > the recordset. I'm not sure if you can do this in
    access, but I would
    > imagine that you can (indeed, it might be the same SQL).
    >
    > <%
    > varToday = Date (should be able to format out timesteamp
    here);
    > varTerm = 365; 'This will be your constant term, defined
    in days, it looks
    > like from archived posts
    >
    > varExpiredDate = varToday = varTerm;
    >
    > Search your recordset via varTerm. ie
    > WHERE datefield < <% varTerm %>
    >
    > You will need to search date formatting in Access to see
    how to strip out
    > the Timestamp from your date, but you should be able to
    do this from your
    > SQL statement, and return just the date, this will be
    compared to your
    > varTerm, which basically states that if your signup date
    is beyond a year
    > from today, your ad will need to be renewed.
    >
    > I"m not very happy with this, but it's all my brain is
    coming up with
    > right now. Gimme a few to review it and I might have
    something more for
    > you.
    >
    > HTH, sorry I couldn't give you code or urls for date
    formatting.
    >
    > Additionally, you will eventually need to build
    somethign that checks
    > images and and dates and then sends an email to your
    customer letting them
    > know their term has expired.
    >
    > OR - You could also add a new field to your database
    which automatically
    > updates an "expire" time in your ad table which
    automatically adds days to
    > the time. If you do this, you don't have to worry about
    stripping
    > timestamps or anyting, and you can just do a simple
    lookup for if Date >=
    > DateExpireField then don't pull image.
    >
    >
    >

  • Can no longer connect to certain shares after upgrading to 10.8.4

    After upgrading to the latest version of Mountain Lion, I can no longer access certain shared volumes. I have one machine running 10.4.11 and I can connect to its hard drive. Another machine on my network runs 10.5.8, and I can now only connect to the built-in hard drive. There are also 2 Firewire drives connected to that (10.5.8) machine that I can no longer connect to.
    When I use "Connect to Server" and enter the AFP address of the 10.5.8 machine, I get a full list of "available" shares, but if I select one of the FireWire volumes, I just get a spinning "rosette" for several minutes and then a failure message. I also have an OS 9 machine that I can no longer connect to on the same network.
    I already read the "Connecting to Legacy Systems" notice and still no joy after following the instructions.
    Can anyone help?
    Thanks!
    Jon

    No NAS other than an Apple one includes native support for AFP. They all use an open source package called Netatalk that is junk. Many years ago Apple deprecated the old security modules that Netatalk uses.
    The easiest solution is to hack up Lion so that it will connect with the old security protocol. Do a search for "lion dhx2" or something like that. Another option is to update your NAS to a version of Netatalk that includes support for DHX2. That is easier said than done. Netatlk isn't as "open" as other open source packages.

  • Firefox 16 freezes for 1 minute when accessing certain webpages, I think they're all using Flash

    I installed Firefox 16.0.1 yesterday. I was running 15 earlier in the day and it was fine. FF 16 however has suddenly started hanging for about a minute when I try to access certain websites. It unfreezes fine after that minute, no crashes or anything, but it's very irritating. From what I can tell it only seems to do it on pages that use Flash. I've got the latest version installed, and it's made no difference. I tried downgrading to FF 15 and it's still the same. Anyone know what's going on?
    Thanks,
    Mark

    Did you try to disable protected mode in the Flash player?
    You can check for problems caused by recent Flash updates and try these:
    *disable a possible RealPlayer Browser Record Plugin extension for Firefox and update the RealPlayer if installed
    *disable protected mode in Flash 11.3 and later
    *disable hardware acceleration in the Flash plugin
    *http://kb.mozillazine.org/Flash#Flash_Player_11.3_Protected_Mode_-_Windows

Maybe you are looking for