Generating a token request (WS-Trust)-HELP

Hello. I'm trying to make a web service client to consume a service with security. The first thing I need to do is generate a token request using WS-Trust and then sign it. Send this token request to the STS and then receive a token signed by the STS. Which libraries I can use to do this? Does anyone have an example to take to help?
Thanks.
Francisco.

What identifiers are configured in the ADFS RP trust?  Most likely there is an audience/realm mismatch between ADFS and the application's settings.  It's not uncommon to be off by one character, missing a trailing slash, http instead of https,
etc.
Steve Kradel, Zetetic LLC

Similar Messages

  • System is not generating a spool request for Dep.?

    Hi,
    When I am running a test run with 'planned posting run' system is not giving me any error but when I am executing it in a "repeat run" system comes up with a message
    "!! This processing can only be carried out as background processing !!
    But when I go to (Jobs Overview screen) see the spool request system is not generating the spool request and Please help me out what's wrong is happening and what shall I do.
    It is a new company code for the first time we are running the dep.
    Thanks in advance...
    Regards
    Nitin

    Dear Nitin,
    Refer Following threads
    fiscal year change has not yet
    AFAB - Not posting
    AFAB - Not posting
    Regards
    Saurabh

  • Problem Generating a certificate request

    I have a couple of Windows 2003 R2 SP2 servers hosting several instances of ADAM.  I am using certreq to generate the certificate requests for these servers so I can use SSL in connecting to ADAM but I am getting an error.  This is the request.inf I am using (pretty much straight from an MS article...) to generate the request...
    ;----------------- request.inf -----------------
    [Version]
    Signature="$Windows NT$
    [NewRequest]
    Subject = "CN=servername.childdomain.rootdomain.com" ; replace with the FQDN of the DC
    KeySpec = 1
    KeyLength = 1024
    ; Can be 1024, 2048, 4096, 8192, or 16384.
    ; Larger key sizes are more secure, but have
    ; a greater impact on performance.
    Exportable = TRUE
    MachineKeySet = TRUE
    SMIME = False
    PrivateKeyArchive = FALSE
    UserProtected = FALSE
    UseExistingKeySet = FALSE
    ProviderName = "Microsoft RSA SChannel Cryptographic Provider"
    ProviderType = 12
    RequestType = PKCS10
    KeyUsage = 0xa0
    [EnhancedKeyUsageExtension]
    OID=1.3.6.1.5.5.7.3.1 ; this is for Server Authentication
    I am using this command....  certreq -new request.inf request.req
    After hitting enter, it sits there for about 10 seconds and gives me this error back...
    Certificate Request Processor: Access is denied.  0x80070005 (WIN32: 5)
    [RequestAttributes]
    I have searched on this error and have not found much of anything on it.  This process seems to work fine on other servers that I have, but these two servers both generate this error.  Both servers are clean builds and only have ADAM installed on them.  I am a local admin on both servers so it doesn't appear that there should be any permission issues as implied by the error message. 
    Anyone have any ideas?
    Thanks!

    Hello Bryan,
    First of all, please make sure that the CA certificate is added into the Trusted Root certificate store on the servers. If the certificate web enrollment is enabled, please check how a certificate request works on that two server generate the error.
    Meanwhile, please verify the security permission on the MachineKeys directory:
    1.    Open Windows Explorer, and find the MachineKeys directory in the following location:
    Drive:\Documents and Settings\all users\Application Data\Microsoft\Crypto\RSA\MachineKeys
    2.    Right-click the directory, and click Properties.
    3.    Click the Security tab, and ensure that the full control permission for the Administrators
    How to: Change the Security Permissions for the MachineKeys Directory
    http://msdn.microsoft.com/en-us/library/bb909654.aspx
    Hope it helps.

  • SharePoint Provider-hosted Apps - Expired OAuth Client Secret - Token Request failed

    Hi everyone,
    in the past days, we have encountered authentication problems with our provider-hosted SharePoint apps.
    The apps are not deployed through the Office Store, but through the specific organizational app-catalog of the SharePoint tenant of our customers.
    Because the apps are provider-hosted, we had to register the OAuth client id and client secret properties of the app for accessing SharePoint resources from our app through the /_layouts/15/appregnew.aspx page.
    Now, the OAuth client secret of our app seems to be expired and this causes the app to stop working.
    The exception stacktrace is:
    "Token request failed. at Microsoft.IdentityModel.S2S.Protocols.OAuth2.OAuth2S2SClient.Issue(String securityTokenServiceUrl, OAuth2AccessTokenRequest oauth2Request) at OurProjectName.TokenHelper.GetAccessToken(String refreshToken, String targetPrincipalName,
    String targetHost, String targetRealm) at OurProjectName.TokenHelper.GetAccessToken(SharePointContextToken contextToken, String targetHost) at OurProjectName.TokenHelper.GetClientContextWithContextToken(String targetUrl, String contextTokenString, String appHostUrl)"
    We have already found this article regarding replacing expired client secret in SharePoint apps: http://msdn.microsoft.com/en-us/library/office/dn726681(v=office.15).aspx
    We have followed the provided steps, generated a new client secret and added it to the web.config file. The old client secret still stays in the file as "SecondaryClientSecret". Then, we executed the PowerShell script in order to register the new
    client secret in our SharePoint tenant. Afterwards, the authentication works as expected. 
    The question is, whether we really have to do the steps for ALL of our customers if the client secret expires again? If the client secret is expired, do we have to execute the PowerShell script on all of our customers' tenants?
    Maybe there is something we failed to notice...
    Thanks for your help. Feel free to ask for further information if something is missing.
    Best regards,
    Dustin

    Hi Utilitas,
    There is no easy way to batch updating Client Secret for each tenant. You may need to execute
    the PowerShell script to update it as the above you post.
    Best Regards,
    Zhengyu Guo
    TechNet Community Support
    Please remember to mark the replies as answers if they help and unmark
    them if they provide no help. If you have feedback for TechNet Subscriber Support, contact [email protected]
    Zhengyu Guo
    TechNet Community Support

  • How can I generate product's Request Code ( indesign cs6)

    Have installed on my machine without Internet a cannot fond how to generate Product's request code to activate online. I just ahave a window asking me to connect but I cant. Any tips? thx in advance

    Nobody here can help with activation issues. You’ll need to contact Adobe directly.

  • Can we generate a transport request in SCAT transaction?

    Hi Everyone,
    Is it possible to generate a transport request in SCAT transaction.
    I am using a test case to update some tables. Can I generate a transport request so that I can move the changes to the table (like table maitainance) across systems?
    Thanks in advance.

    Hi,
    Please check this link which has very good article for beginner.
    http://www.thespot4sap.com/Articles/CATT.asp
    For more information, please check this links.
    http://help.sap.com/saphelp_47x200/helpdata/en/ae/410b37233f7c6fe10000009b38f936/content.htm
    http://help.sap.com/printdocu/core/Print46c/en/data/pdf/BCCATTOL/BCCATTOL.pdf
    http://help.sap.com/printdocu/core/Print46c/en/data/pdf/BCCATTOL/CACATTOL.pdf
    https://www.sdn.sap.com/irj/sdn/weblogs?blog=/pub/u/37984. [original link is broken] [original link is broken]
    Hope this will help to start with.
    Regards,
    Raj.

  • Generate new License Request from ELM

    Hello everyone,
    I am having a problem generating a new License Request from ELM.
    It was required to me by Cisco Licensing in order for them to provide me a new License file.
    Here are the steps that I made in generating a new License Request from ELM. (See attached file ELMaccess, LR1 & LR2)
    I first accessed the ELM under CUCM administration.
    Select License tab> Other Fulfillment Options> Generate License Request> Save to my computer
    I received a .txt file (lic_req_201.....) and that certain file was the one I sent to Cisco Licensing.
    Cisco Licensing replied:
    "It is still the same license request that you have here, just regenerated. What is needed is an entirely new and different ELM License request."
    I am not really certain for what kind of License Request file that he wanted, or maybe there is a different procedure in doing this?
    Can someone help on this?
    If I am missing something or if there is another procedure on generating a new License Request kindly guide me.
    Thank you so much.
    Kind regards,
    Art
    Network Engineer
    Net Pacific Philippines
    CCNA R&S
    CSCO12379161       

    Hi mkchandak,
    Thank you for your response!
    Yes we did, we actually at first generated a license request, submitted it to licensing and they provided us a license file. Now, upon the installation of the license file we received this error message "Insufficient Licenses".
    We went back to cisco Licensing, a new engineer assigned to us, provided all the details he requires, our license case was approved by their Product Manager and now he requests for a "Newly Generated License Request".
    I followed the same steps in generating a new License Request:
    I accessed the ELM under CUCM administration.
    Select License tab> Other Fulfillment Options> Generate License Request> Save to my computer
    I received a .txt file (lic_req_201.....) and that certain file was the one I sent to Cisco Licensing.
    Cisco Licensing replied:
    "It is still the same license request that you have here, just regenerated. What is needed is an entirely new and different ELM License request."
    So maybe he is referring to something other than the License Request that I have provided.
    Maybe there is a different procedure in generating a "fresh and newly generated License Request"
    If you know a step-by-step procedure in achieving this, please guide me.
    Any help would be greatly appreciated.
    Thanks again!
    Cheers,
    Art
    Network Engineer
    Net Pacific Philippines
    CCNA R&S
    CSCO12379161

  • Can i get script for the standard program 'Generate cycle count requests'

    Actually we have huge records available in *'Cycle count open requests listing'* report and its because of the *'Generate cycle count requests'* program created many records on particular date in mtl_cycle_count_entries table. Can anyone help to provide the script or the logic on what basis the Generate cycle count requests' program retrieving data

    Make sure that toolbars like the "Navigation Toolbar" and the "Bookmarks Toolbar" are visible: "View > Toolbars"
    *Open the Customize window via "View > Toolbars > Customize"
    *Check that the "Bookmarks Toolbar items" is on the Bookmarks Toolbar
    *If the "Bookmarks Toolbar items" is not on the Bookmarks Toolbar then drag it back from the toolbar palette in the customize window to the Bookmarks Toolbar
    **If other missing items are in the toolbar palette then drag them back from the Customize window on the toolbar
    *If you do not see an item on a toolbar and in the toolbar palette then click the "Restore Default Set" button to restore the default toolbar set up
    If the menu bar is hidden then press the F10 key or hold down the Alt key to make the menu bar appear.
    Make sure that toolbars like the "Navigation Toolbar" and the "Bookmarks Toolbar" are visible: "View > Toolbars"
    *Open the Customize window via "View > Toolbars > Customize"
    *Check that the "Bookmarks Toolbar items" is on the Bookmarks Toolbar
    *If the "Bookmarks Toolbar items" is not on the Bookmarks Toolbar then drag it back from the toolbar palette in the customize window to the Bookmarks Toolbar
    **If other missing items are in the toolbar palette then drag them back from the Customize window on the toolbar
    *If you do not see an item on a toolbar and in the toolbar palette then click the "Restore Default Set" button to restore the default toolbar set up

  • Generate xml-rpc request using xsd

    Hi All,
    I have one xsd file . I want to generate xml-rpc request file using this xsd file. If any body have any tools for that , can you please share this name with me. It's great help for me...
    Thank You,
    Pattanaik

    That's an interesting question. I thought it would be obvious that xmlbeans or "normal" xml-rpc packages would handle this.
    It turns out this doesn't seem to be true.
    Are you saying that you're trying to pass an object to a method and you want to deserialize the object into a java object of a type that is defined via an XSD? If this is the case you can use xmlbeans to do the xsd<->java mapping, then use just about any xml-rpc service to do the actual RPC mechanism.
    It's interesting that these two technologies haven't converged though...

  • Can I generate a transport request in SCAT transaction?

    Hi Everyone,
    I am using a test case to update some tables. Can I generate a transport request so that I can move the changes to the table (like table maitainance) across systems?
    Thanks in advance.

    Hi,
    Please check this link which has very good article for beginner.
    http://www.thespot4sap.com/Articles/CATT.asp
    For more information, please check this links.
    http://help.sap.com/saphelp_47x200/helpdata/en/ae/410b37233f7c6fe10000009b38f936/content.htm
    http://help.sap.com/printdocu/core/Print46c/en/data/pdf/BCCATTOL/BCCATTOL.pdf
    http://help.sap.com/printdocu/core/Print46c/en/data/pdf/BCCATTOL/CACATTOL.pdf
    https://www.sdn.sap.com/irj/sdn/weblogs?blog=/pub/u/37984. [original link is broken] [original link is broken]
    Hope this will help to start with.
    Regards,
    Raj.

  • Request for technical help? Report generation?

    I am developing a Inventory system for RealTech Trading,Ethiopia. But i am am facing difficulty to generate useful and important reports
    i here by request any body who knows how to generate reports for java applications to help me.
    this is Abiy Legesse form Ethiopia

    What have you tried so far?

  • How to generate a certificate request with more than one OU?

    We're using Sun Java System Web Server 6.1 SP4. The Corp. has it's own CA and organize their certificates in a hierarchical rule with more then one organization unit (OU) in a chain.
    So what we need is generate a certificate requeste with more than one OU, but the Web Server wizard has only one text field for it. We've already tried to fill in this field the complete chain of OUs like "ou=orgX, ou=deptY, ou=secZ" and didn't work either.
    Thank's in advance,
    Jeff!

    Do you have tried with the command line "certutil" ?
    #<SERVER-ROOT>/bin/https/admin/bin/certutil

  • Can we generate a dummy request from a backend process?

    I would want to generate a dummy request from a backend process since I need to use the 'process instanace key' which will be associated with it. The 'process instance key' is vital for my requirement since we need to trigger a process task in OIM.
    Is it possible to create a 'dummy' request?

    Hi,
    You can use HTTP Binding for that... Have a look at Biemond's blog...
    http://biemond.blogspot.com.au/2010/05/http-binding-in-soa-suite-11g-ps2.html
    Cheers,
    Vlad

  • Submitting an image file for indexing generates the tokens "IMAGE" and "1"

    This is a problem because the user is able to submit any file through a web interface, and we want to determine when there is zero output from the indexing process so we can warn the user that the file they submitted has no indexable content.
    I'd rather keep the detection algorithm simple: currently it checks to see whether any tokens were indexed for the record the user just edited, and IF there were NO tokens, the user is warned that the file they submitted contains no indexable words. But if ctxhx.exe generates the string "Image 1" when someone gives it (for example) a jpeg file, that's not going to work.
    So my questions are these: How do I prevent ctxhx from generating any tokens when someone gives it an image file? And if that's not possible, how can I include logic in a batch file to detect an image file and prevent ctxhx from handling it? (Since the files are renamed without extensions when indexed, I can't determine file type from extensions). I know there's a command-line program called TestForPDF.exe, which I found at http://www.oracle.com/technology/products/text/htdocs/altfilters.htm; is there a similar program (perhaps TestForImage.exe), or instructions for creating such a program?

    I finally resorted to using the "format column" feature of the context index. The code in my front-end looks at the extension of the file submitted by the user, and sets the value of the format column to "IGNORE" before it tries to resync the index. It seems a bit kludgy, but it works.

  • I have bought a Seagate Backup Plus 1TB drive, first time I have selected Mac Windows option which excludes Time Machine to work on it, but now I want to go back and select Only Mac option to activate my Time Machine application. I request you to help me

    I have bought a Seagate Backup Plus 1TB drive, first time during plug-in, I have selected Mac Windows option which excludes Time Machine to work on it, but now I want to go back and select Only Mac option to activate my Time Machine application.
    I request you to help me with the procedure of the same?

    IMPORTANT - This will reformat your Seagate drive and hence wipe it.  If there is anything on your Seagate drive you want to keep, save it somewhere else FIRST.
    Plug the drive in.
    In Finder select Applications > Utilities > Disc Utilities.
    Select the external drive, select Partition option, give it a name (I call mine Mac Backup), select Mac OS Extended (Journaled) as the Format and under the drop down menu "Partition Layout" select the number of partitions you want (so if you want the drive to just be for Time Machine, select 1 Partition, if you want part of the drive to be for Time Machine and the rest for something else, select 2 partitions and so on).  Click apply and the Disc Utility will partition and reformat your drive ready to use.
    When this is complete, open Time Machine in System Preferences. Use  Select Disc to select the drive (or if you have multiple partitions, the partition of the drive) you want and you are good to go.
    This may be a long way round, but it gives you the option to partition your disc which you may want.

Maybe you are looking for

  • ? regarding resetting password in Airport Wireless Network.

    ? regarding resetting password in Airport Wireless Network. I am using comcast cable and have a netgear wireless router to access the internet. In my airport network preferrences I have a network name and a password which is working well on my brand

  • ISE 1.1.3.124 secondary node not reachable after registration

    G'day All, I'm constantly seeing that the sync and replication status for my secondary admin/monitor node in the primary node as node not reachable. The secondary still thinks it is in standalone mode. When I run the ISE diag tool connectivity tests

  • Swing: Look and Feel

    I've found this page with a nice look and feel: https://substance.dev.java.net/docs/skins.html#CremeSkin But I can't use it. I import this: import org.jvnet.substance.skin.SubstanceCremeLookAndFeel; And do this: UIManager.setLookAndFeel(new Substance

  • PDF Files Size after Scan

    I have a Canon MX892 (made for personal use) all in one printer in my home, when I scanned a 21 page document it turned out to be 14 meg in size.  I scanned this same document from my office which has Konica C54 all in one printer (made for business

  • Adjustment Brush not Working

    in the Develop module my adjustment brush is not working, all the other sliders work, what is wrong?