HFM Access Security info thru API or Database?

In HFM running in the system 9 enviornment - is there a way to access the security info thru an API or Database. This is info that typically is availiable in the security extract and contains info like
!FILE_FORMAT=2.0
!VERSION=9.30
!FILE_FORMAT=2.0
!VERSION=9.30
!USERS_AND_GROUPS
!ROLE_ACCESS
etc.
Thanks in advance for any insight.

There is an item not really discussed in this thread which is OpenLDAP. Shared Services uses a product called OpenLDAP for certain tasks such as a repository for the Native Groups and Users. Additionally, if you have users tied in through a 3rd party sourch such as Active Directory, certain key information is found here.
For instance, when you look at the Security Access tables in HFM, you will notice that it does not reference the usernames by username rather by a unique ID key. This ID key translates back to the information in Shared Services OpenLDAP database.
This had the potential to causes issues when trying to make a development environment due to the fact the unique id's (SIDs) could be different for the exact same user. In order to retain security information between two different environments without having to redo the security, you have to synchronize the shared service databases to ensure the SID data was the same.
Shared Services has an import/export utility which helps with this task; however, the old versions would not export the SID!!! (whoops). Fortunately, the newer versions of this utility do infact export the SID values if you request it to do so.
In regards to the subject of this thread, you can get at the security information a few ways :
#1 - There is a Java API for Shared Services. I've tried to make use of it; however, I've found it a bit more complicated than I would like so I do not use this method.
#2 - Using the Application Client DLL's. There are vb samples of how to get basic information such as group membership, etc, etc if you have the SDK.
#3 - Database direct. As pointed out previously there are unique tables for each application which hold this data; however, you will also need to interface with OpenLdap to x-ref the SID values to readable usernames/groups. In regards to this, I was pondering making a utility to do this for people if there was an interest. I need the data as I do a quarterly user audit and I would prefer to automate this as much as possible.....
Edited by: beyerch on Feb 11, 2009 12:35 PM

Similar Messages

  • Mac being unable to sever connections and I can't access secure databases

    Recently my university library underwent a security rehaul, since then I have been unable to access secure databases to do research for papers and the like. After resetting my browser, emptying my cache, and shutting down my computer, I am unable to sever my old connection to the library page.
    The weird thing was I was in a chat with a librarian at the school at the time, and it never signed off even when my computer was shut down...
    What do?

    This will tell you if your apps are compatible:
    http://roaringapps.com/apps:table
    Thanks ... Ken

  • (264361962) Q ADVC-27 How do you pass the security info to access the EJB?

    Q<ADVC-27> How do you pass the security info to access the EJB?
    A<ADVC-27> Authentication for web service users must occur at the web layer. This
    means providing appropriate web resource definitions and restrictions in the web.xml
    file for your project. The most common and useful form of security for application
    interaction is via client-side certificates. Then the client identity is transmitted
    to the EJB is the same way as in regular J2EE environments. There is a complete description
    on security on e-docs:
    http://edocs.bea.com/workshop/docs70/help/guide/security/ovwSecurity.html
    Adam

    You need to ask Apple to reset your security questions. To do this, click here and pick a method; if that page doesn't list one for your country or you're unable to call, fill out and submit this form.
    (119093)

  • Error while accessing secure store

    Hi Team,
    We are on EP 7.0 on SQL server 2005 . Iam facing one problem , in sometimemy IRJ pOrtal site stops giving error " Java iView Runtime " .At this time what happens that in my usr/sap drive , the sap folder is not shown as shared its share goes away and that time when i connect to visual admin tool the authentication fails and that time config tool gives error
    #1.5#00188B417A01007E0160B338000008FC00045DE876A4C303#1229152911187#com.sap.engine.services.dbpool.spi.ManagedConnectionFactoryImpl##com.sap.engine.services.dbpool.spi.ManagedConnectionFactoryImpl#Guest#2####f168def0c8c411dd9a2100188b417a01#SAPEngine_Application_Thread[impl:3]_29##0#0#Error##Plain###ManagedConnectionFactoryImpl.createManagedConnection(): SQLException occured while creating ManagedConnection: com.sap.sql.log.OpenSQLException: Error while accessing secure store: File "
    musaprd
    sapmnt
    PWC
    SYS
    global
    security
    data
    SecStore.properties" does not exist although it should..#
    #1.5#00188B417A010085015AAAF5000008FC00045DE876A4C207#1229152911187#com.sap.sql.connect.OpenSQLDataSourceImpl##com.sap.sql.connect.OpenSQLDataSourceImpl#Guest#2####09e36ed0c8c711dd93b200188b417a01#SAPEngine_Application_Thread[impl:3]_39##0#0#Error#1#/System/Database/sql/connect#Java#com.sap.sql_0019##Exception of type com.sap.sql.log.OpenSQLException caught: Error while accessing secure store: File
    When i check in this path SecStore.properties is there , also i have checked the permissions .....................please revert the reason of this error  . 
    Main part of this all is that after taking a reboot everything becomes fine , this happens every few days .
    Please revert to this .
    Regards,
    Somya

    Hi,
    This error crops up when the the folder usr/sap folder sharing is lost .  We  have recently faced this problem this is Windows OS level problem you can ask your OS admin. Applying a security patch will do.
    Regards,
    Vamshi.

  • Issue with updating Security Info on my Microsoft ID

    I am stuck in a vicious circle trying to sort an issue with my Microsoft account.
    I need to remove an old, defunct, email address and add a load of new security info however, depending on whether the date format on the page I keep being directed to is UK or US, either the updates haven’t happened or they won’t
    be happening until next month – which seems ridiculous!
    I’m trying to sign up for a Windows Store developer account to publish a Windows 8 app. I’m using my MSDN subscription to register for this (for free) but there is a step I can’t get past because it insists on sending a code to
    my old email address – to which I have no access. It is picking up this address from my Microsoft Account Security info – however, I updated this info weeks ago. This is the screen I see (I’ve blurred out some of it as it seemed foolish to publish all my security
    info J
    It says my old address will be removed on 03/04/2013 and my new info added on that same date. Does anyone know if this is UK date format 3<sup>rd</sup> April – in which case it’s a long wait or a US date 4<sup>th</sup>
    March in which case it didn’t happen? I’ve tried phoning 5000 and the Microsoft Customer support lines but neither of them have a clue where to start. They just keep asking me if I’ve forgotten my password – which I haven’t.
    Does anyone know how I can resolve this? My only option at the moment is to wait until 3<sup>rd</sup> of April and see if anything changes – which is not ideal.
    Cheers,
    Rob

    Hello,
    The Microsoft account forum has been retired and all account related questions must now be asked online
    here.
    Select the issue you need help with and fill out the requested details on the next page.
    You need to be signed in with a Microsoft account to access the form. If you are unable to access your primary account, you can use an alternate account (if you have one) or create a new one at
    https://signup.live.com
    You can read further information about blocked accounts
    here.
    Karl
    When you see answers and helpful posts, please click Vote As Helpful, Propose As Answer, and/or Mark As Answer.
    My Blog: Unlock PowerShell
    My Book:
    Windows PowerShell 2.0 Bible
    My E-mail: -join ('6F6C646B61726C406F75746C6F6F6B2E636F6D'-split'(?<=\G.{2})'|%{if($_){[char][int]"0x$_"}})

  • Security problem in oracle 9i Database Configuration Assistant

    Inside the tool Oracle 9i Database Configuration Assistant there is an option by which you can make a "copy" of your Database. This "copy" is called a template and you don4t need any password or aunthentication to do it, you just need the tool to be installed in your server. Once you have a template, you can bring it anywhere and recreate the original database (including data). Again, you don't need any password or aunthentication to do it, further more, in the last step of this process you can change the password of any user (inluding SYS, SYSTEM or another DBA user). The thing about this is that anyone with access to the computer where the database is can make a template of it, take this template to another computer and recreate my database having FULL access to it (structure, data, code ...). And everything without needing any password!!!. I really thing that it is a big problem. Is there any way of preventing this operation?. How can I safely protect my database?. I thought about unistalling the product, but someone can re-install it and everything would be the same. Can someone give me an answer?
    Thanks for everything.
    Pablo Cuenca

    You must protect your database from casual browsing at the OS level. This is not a security hole, per se, since this is a known issue with any and all software. Database Configuration Assistant is not needed for this since one may copy the database without it.

  • Insecurity of Keychain Access: "secure" notes visible during authentication

    Sorry if this has been discussed before, but I'm not keen on wading through 137 pages of discussions.
    I recently discovered Keychain Access' ability to create "secure notes," and thought this would be a wonderful way to keep my serial numbers, bank accounts, and other sensitive information secure.
    However, I just tried to actually decrypt this information for the first time, and was rather shocked. When you attempt to open a secure note, and select the "show note" checkbox that prompts the "Deny / Allow Once / Always Allow" dialog box, the dialog box contains the "secure" information from the note!
    In my example, which you can see here (http://www.justinreese.com/media/images/secure_bbedit.png), the entire text of the note is included in the dialog, previous to any password authentication. Of course, because I'm reusing the login keychain, I understand that it's already been decrypted upon logging in; however, I was under the impression that using Keychain Access to store secure notes and other passwords offered a secondary level of protection, and that even if someone were able to compromise my system while I was logged in, at least that sensitive data would remain secure (the way a dedication application such as Wallet or Yojimbo would do it).
    So... is this a bug, an oversight, or simply my own poor planning in using the login keychain to store secure information?
    Thanks to all.
    17" Powerbook G4/1.5Ghz   Mac OS X (10.4.6)   Stock + 1GB of RAM
    17" Powerbook G4/1.5Ghz   Mac OS X (10.4.6)   Stock except 1.5GB of RAM

    My suspicion is that when you created the note, in the "name" field, you used "paste" intending to paste "BBEdit 8 Registration". However, if the clipboard at the time had contained multiple lines, the "Name:" field would then contain the entire contents (Owner Name, Email Address, etc), although it might not be immediately apparent since the main "Keychain Access" window would only display the first line. However, when asking for authentication, the full "Name" is displayed. This scenario is easy enough to replicate.
    The odd thing is that even if the "Name:" is subsequently edited to remove the extra lines, the "authentication dialogue" seems to continue to ask for authentication using the "old" name... it's probably being cached somewhere but I haven't been able to track it down.
    So in this case, I would call this "user error" for putting "secure" info in an "insecure" field in the first place, but there is definitely some sort of bug / oversight / slopiness in that the authentication dialogue doesn't update - so in effect it is asking you to authenticate for one thing, when in reality it is authenticating something that might have a completely different name. That sort of thing might open up "spoofing" opportunities, but for a user's personal keychain, I would suspect that anyone that can get close enough to do something with it would have opportunities to do far worse. Still, it can't be a good thing...

  • Export security-Info from planning to flat file

    <p>In planning there's the possibility of <b><span style=" color: #008000;">importing</span></b> security information (assignedaccess) by the utility ImportSecurity.exe.</p><p> </p><p>Is there the possibility of <b><span style=" color:#ff0000;">exporting</span></b> this information (e.g. access todimensions or forms) from planning to flat file.</p><p> </p><p>Note: In shared services there's another utility for import andexport of provisioning information (command-line tool) but thisdoesn't comprise import/export of security info of anapplication.</p><p> </p><p>Regards</p><p>Geri</p>

    Hello Geri,<BR><BR>Currently, Planning 3.5.1 does not have any utility to export security out of planning. <BR><BR>What you can do is this that generated PDF files through the application itself and then convert it in to text files and so on to load security via importsecurity.exe. <BR><BR><BR>Thanks,<BR>Scorpio<BR><BR><BR><BR>

  • Unable to update my macbook, access macbook info/preferences, or adjust volume

    Unable to update my macbook, access macbook info/preferences, or adjust volume

    Hello Terence,
    Thanks for your reply.
    So if iPhoto is installed through some other account in my Mac and I'm using it the other person can't access my iPhoto library...right?
    I don't want to give anyone access to my library or system hard drive, So can you please let me know how to check what has been shared with others from a mac. (also the hard drive)
    As this is my Mac which I've bought but for 1st 10 days one of my friend used it using his apple ID
    So I want my Mac fully secured from now onwards.
    Regards,
    Sri

  • Howto proces SOAP Header with security info

    My incoming Soap messages contain security info in the soapenv:Header part.
    However, I only need the contents of the Body element.
    If I do NOT handle the Soap Message, then an Exception is thrown: something like: 'Do not know how to handle MustUnderstand'.
    So something must be done with the Security info in the header, but I do not know how. Do I have to remove the header completely in the Soap handler, after checking the singning? If somebody can point me to some examples of Soap header processing for this case it would be helpful.
    kind regs.
    Harry

    Hi Harry
    The header in Soap Messages is optional. Is is used to carry security information, that is security on the level of the Soap message. So when the header of an incoming Soap message is 'handled', the header is of no use any longer and can (must) be discarded. Indeed discarded, because the rest of the handlers don't expect a header in the Soap message. They extract the 'contents' from the body of the Soap message, and deliver that to you backend system.
    I will describe the header handling in the webservice: to get access to the Soap message in your code, you have to write a 'handler' Class. This Class should implement the Handler Interface or extend the abstract GenericHandler Class. To handle only the incoming Soap messages, the 'Requests', the method 'handleRequest' should be implemented. This handleRequest method has 1 parameter (mc) with type MessageContext. This parameter contains the original Soap message in Object format. You can access the original header information via:
    SOAPMessageContext smc = (SOAPMessageContext)mc;
    SOAPMessage message = smc.getMessage();
    SOAPPart part = message.getSOAPPart();
    SOAPEnvelope envelope = part.getEnvelope();
    SOAPHeader header = envelope.getHeader();
    With: Iterator iterator = header.getChildElements();
    you can navigate through the header elements and do whatever you like. If you decide that security info in this header does not match the contents of the body for instance, you can issue an Exception and log it.
    After processing the header you have to discard it with:
    header.detachNode(); and let your handleRequest method return 'true'.
    The rest of the webservice processing takes the contents from the body element, and delivers that to your application.
    To let you webservice make use of your Handler, you have to name it in the web-services.xml as follows:
    <webservices>
    <handler-chains>
    <handler-chain name="myChain">
    <handler class-name="a.b.c.MyHandler" />
    </handler-chain>
    </handler-chains>
    <web-service name="MyService">
    <operations>
    <operation ... handler-chain="myChain" .... />
    </operations>
    When the webservice 'MyService' gets a request, the handler 'MyHandler' is automatically invoked. you can have more handlers in a chain. Also you can declare more chains in your <webservices> section and refer to them from the <operation> elements.
    Items of interest:
    javax.xml.rpc.handler.soap.*
    javax.xml.rpc.handler.*
    javax.xml.namespace.*
    javax.xml.soap.*
    May be this of use for you :).

  • HT5312 security question, and email for Send reset security info

    hello,
    i forgot answer for my security question, but my email for Send reset security info email to j•••••@poczta.onet.pl is not current
    please help me .what can i do?

    We can't help you here, we don't even have access to (legitly) Directory Services.
    Please check with AST.
    Check the AppleCare number for your country here:
    http://support.apple.com/kb/HE57
    Call them up, and let them know you would like to be transferred to the Account Security Team.

  • When downloading an ap, it asks for security info required

    when i goto download an ap, it asks for my apple id and password.  Then it pops a screen upsaying Security Info Required.  to help ensure the security of your apple id, you must confirm your password and answer your security questions.  What gives?

    Humm... This appears to be the answer:
    http://news.cnet.com/8301-13579_3-57413072-37/apple-ios-users-face-tighter-secur ity-to-access-accounts/
    Bob

  • Im trying to reset my security codes but when i click send reset security info it doesn't send

    Help!

    Hey Winklestoo,
    Thanks for the question. If you are having issues with the security questions associated with your Apple ID, follow these steps:
    If you forgot the answers to your Apple ID security questions
    http://support.apple.com/kb/HT6170
    Reset your security questions
    1. Go to My Apple ID (appleid.apple.com).
    2. Select “Manage your Apple ID” and sign in.
    3. Select “Password and Security” on the left side of the page.
    4. If you have only one security question, you can change the question and answer now.
    5. If you have more than one security question:
              - Select “Send reset security info email to [your rescue email address].” If you don't see this link or don't have access to your rescue address, contact Apple Support as described in the next section.
              - Your rescue address will receive a reset email from Apple. Follow its instructions to reset your security questions and set up new questions and answers. Didn't receive the email?
    After resetting your security questions, consider turning on two-step verification. With two-step verification, you don't need security questions to secure your account or verify your identity.
    If you can't reset your security questions
    Contact Apple Support in either of these circumstances:
              - You don't see the link to send a reset email, which means you don't have a rescue address.
              - You see the link to send a reset email, but you don't have access to email at the rescue address.
    A temporary support PIN isn't usually required, but Apple may ask you to generate a PIN if your identity needs to be verified.
    Thanks,
    Matt M.

  • How do I change the email that the security info sends to

    I have recently bought a $20 gift card for iTunes and if I try to buy a Game it comes up with the security questions and I don't know them.
    I tried to reset the questions but it's sending them to a email I don't have access to.
    So I need to reset my email that the security info sends to but I don't know how
    Any help?

    You cannot and need to ask Apple to reset your security questions; ways of contacting them include phoning AppleCare and asking for the Account Security team, clicking here and picking a method for your country, and filling out and submitting this form.
    They wouldn't be security questions if they could be bypassed without Apple verifying your identity.
    (104761)

  • Safari crashes when accessing secure websites

    Hi, all you Discussion-eers!
    I downloaded the new Safari for Windows Beta today, since I thought that it would be really neat to have the opportunity to actually use that nice web browser on a Windows platform.
    It can successfully launch and load a good deal of websites for me.
    What isn't working quite so well, however, is accessing secure pages, like logging into the Discussions, or logging into accounts on other websites.
    When I attempt to access any secure website, it either:
    - Promptly closes the browser on its own, without any errors
    - "Encounters a problem and needs to close"
    - Completely freezes up while loading the page, to the point where I cannot close the program by clicking the "x" on the program window. (I must end it through Task Manager)
    - Displays this error message when attempting to load the webpage.
    I have tried completely deleting all program/installer files off the computer (hopefully, at least), and installing another copy of SafariSetup, as well as restarting, to no avail.
    Any ideas as to what's causing this? I currently use IE (Internet Explorer) 6 for accessing websites.
    If you need, I'd be happy to provide any other info about my issue that might help.
    Thanks in advance!
    -Kylene

    Good to know it's not just me than. Started happening to me at the same time as everyone else too. Did the usual: messed about with Safaris preferences files, reset Safari, repaired permissions, installed latest (for my system) security update 2007-008, restarted and then repaired permissions again and voila.....still crashing.
    Old youtube pages in Safrari history still loaded but couldn't navigate from them.
    Using Firefox now which seems to be fine.
    Would be intersting to know what's happened though.

Maybe you are looking for

  • MS Access and Date

    I have a MS Access table which contains a Date tag on each record. I want to retrieve records based on: Today - 1 month or Today - 2 weeks etc. Can anyone tell me the syntax? Thanks

  • How to run the program in the applet

    I have installed the JDK 1.3 and succesfully compiled my first Java application (appropriately named HelloWorld.java). I could compile the source file also.But i am getting an error when i am trying to run the program in the applet iam getting an err

  • Please could anybody tell me how to stop the rainbow wheel from turning

    i sem to have a start up disk full prob but no other mac as target mode, just PC and an external hard disk thanks it is becomeming alarmingly urgent

  • Adding cost center on OKB9 with cost element company code with valuation ar

    hi , can anybody help me out with the Adding cost center on OKB9 with cost element company code with valuation area configuration. i have to do this configuration but do not know the detailed steps for that one. Good points will be awarded.

  • Lightroom CC 2015 HDR merge not importing into Catalog

    When I use the new HDR merge in LR CC 2015, the new xxxxx-HDR.dng image is created but not imported into the catalog. All of the demo videos I've watched show the image being immediately imported into the catalog and visible on the filmstrip. Suggest