How to see a shared services user in EAS Console?
Hii, I have externalized security for Essbase through shared services, now I created a new user in HSS & provisioned it with Filter, Write option in HSS. Now I refresh the security & want to see the user reflected in EAS console, I want this because I want to create essbase filters on that user. So if I am able to see that user in EAS Console, I can assign different filters to it. Can I do that?
Make sure you've done this if you have a problem: Re: Oracle EPM System Rel. 11.1.1.2 - Assign Essbase Filter in Shared Services
Follow John Goodwin's steps in this post: Unable to assign filters in Shared Services
Note Glenn's comment about sometimes having to assign the filters through MaxL because of issues although I think John's answer in the first post should help a lot.
Regards,
Cameron Lackpour
Similar Messages
-
Could any one tell me that How can i create the service User ie j2ee SID
hi all,
In the implementation of SPNego Authentication schem in my portal system.
i want to create the service user ie .j2ee-<SID>.
<b>could any one tell me that How can i create the service User ie j2ee-<SID> in my visual administrator??</b>.
any help will be highly Appretiated .
thanks and regards.
vinit soni.Vineet,
the user management tab opens in Read Only mode - thats why the button is coming as disabled. There is a button for switching into Edit mode - it looks like a pen / pencil on the top bar. Click on that - your "Create User" button would be enabled.
Also regarding creation of Service User via code level you can see <a href="https://www.sdn.sap.com/irj/sdn/thread?messageID=1057074">THIS</a> thread. And <a href="http://HERE">http://help.sap.com/saphelp_nw04/helpdata/en/f9/e3162ec55f4df6922d161f3785012a/frameset.htm</a>HERE[/url] is the SAP Help documentation on required permission settings.
Regards,
Shubhadip
Message was edited by:
Shubhadip Ghosh
Message was edited by:
Shubhadip Ghosh -
How to enter into shared services in system 9
how to login into shared services
Hello,
I'm new with Hyperion and would like to ask something. I installed Hyperion Shared Services 9.3.1 in my desktop (inside consist of Windows XP Professional Service Pack 3, 1 GB RAM, Oracle Database 10g (10.2.0.1) Standard Edition, Oracle Application Server 10g).
I read from Hyperion Shared Services security guide in Chapter 3 about User Management Console that we can launch User Management Console in 3 ways:
1. Using a browser and connecting to the User Management Console URL
2. On Windows, navigating Start > All Programs > Hyperion > Foundation Services > User Management Console
3. From a Hyperion product interface
I tried to connect using URL : http://<localhost>/58080/interop and http://<localhost>/58080/interop/ and http://<localhost>/58080/interop/index.jsp but failed (where I changed <localhost> to my computer name). When I installed Shared Services, there are no point to choose port or create username.
There are no User Management Console in Foundation Services either.
How to start and stop Shared Services then and how do I know Shared Services has already run?
Thanks. -
IOP 11.1.2.0 integration with Shared Services (User Provisioning)
In the IOP 11.1.2.0 install guide, the Admin and Admin provisioning roles are provisioned through Shared Services.
"Provision Integrated Operational Planning Administrator and Integrated Operational Planning
Provisioning Manager roles for the Integrated Operational Planning instance to the Admin user through
Oracle's Hyperion® Shared Services Console
a. Connect to the Oracle's Hyperion® Shared Services Console; for example, http://
hss_server:hssserver_port/interop.
b. Log in as the administrator.
c. Expand User Directories and Native Directory.
d. Select Users and click Search.
e. Right-click the Admin user and select Provision.
f. Expand Default Application Group.
g. Expand the Integrated Operational Planning instance created.
h. Highlight IOP Administrator and Provisioning Manager.
i. Click the right arrow in the middle of the two windows to select the roles.
j. Click Save, and then click OK."
The users and groups are defined in Shared Services, per the IOP 11.1.2.0 admin guide (p. 144).
Is there an IOP user provisioning example in the shared services user's guide, and which version of the guide would I find that in?
Access priveledges are controlled from the Admin workbench for IOP users, per p.145 of the IOP 11.1.2.00 user's guide.
Thank you.IOP Roles are listed in the 11.1.2 Shared Services User and Role Security Guide, on page 158:
Integrated Operational Planning Roles
Table 39 Integrated Operational Planning Roles
Roles Tasks per Role
Provisioning Manager Provisions users and groups with Disclosure Management roles
IOP Administrator Administers Oracle Integrated Operational Planning, Fusion Edition. IOP Administrators can modify models, access
ACL pages, and perform all Integrated Operational Planning tasks
IOP User P erforms Oracle Integrated Operational Planning, Fusion Edition actions as a normal user -
Hi All,
I want to export shared services users for a particular application.
Is there any way for this?
ThanksYes, you can export / import the provisioning for a particular application.
By default the utility export all Users / Groups and provisioning for all applications.
To export provisioning for a particular application you need to modify the below parameters in CSS Import Export properties file.
export.provisioning.all=false
export.provisioning.apps=(<Project Name>:<Application Name>)(<Project Name 1>:<Application Name 1>)
Hope this helps you...
Kind regards,
Manmohan Sharma -
Hyperion Shared Services user Management Guide
Hi ,
Can any one share the Hyperion Shared Services User Management Guide.
Regards
naveenHi,
For 9.3.1 Try - http://download.oracle.com/docs/cd/E10530_01/doc/epm.931/html_cas_help/toc.htm
11.1 - http://download.oracle.com/docs/cd/E12825_01/epm.111/epm_security_11111/cas_help.htm
Cheers
John
http://john-goodwin.blogspot.com/ -
Hi All,
We need to migrate Shared services users and groups from 9.3.1 to 11.1.2.2 version. Any help would be appreciated. Can we use CSS import export utility?
Thanks in advance!!Hi John, In my another environment I have to migrate the users and groups from Hyperion HSS 11.1.1.2 to Hyperion shared services 11.1.2.2. I am using LCM for that, when I export the users and gropus from 11.1.1.2, it exports fine but when i import it to my 11.1.2.2 using LCM, I am getting the below errors.
Error when I try to import the groups:
ErrorEPMIE-00051: Failed to perform operation on role. Could not locate role matching filter {0} and filter attribute {1}. Please ensure that a role exists matching the filter with filter attribute.
EPMIE-00024: Failed to import all of the membership info for group test group. Invalid group members encountered. Please ensure the validity of members and its existence in their respective providers.
Errors when i try to import the users:
ErrorEPMIE-00051: Failed to perform operation on role. Could not locate role matching filter {0} and filter attribute {1}. Please ensure that a role exists matching the filter with filter attribute.
EPMIE-00020: Failed to update user 04668162 during import. Invalid identity for user. Please ensure that the user is available in the system with the identity specified in the import file.
Any idea?
Thanks in advance. -
What is the "admin" user in EAS Console?
I am still relatively new to Planning and Essbase. I am trying to figure out the relevance of "admin" user in the Essbase Administration Console. My colleague and I have seen several instances of this admin user in EAS console but it doesn't appear to represent a "live" user. We have also seen references to "admin@native directory" in the Essbase and EssbaseODL logs. In the last couple of days, we were unable to run a script that automatically backs up a database because this admin user was performing a spreadsheet operation. We were able to successfully force the admin account off via the console but we know for a fact that no one else is logged in.
Below are excerpts from the Essbase log. Please see the text in red.
Any insight on this would be greatly appreciated.
Thanks!
Essbase.log
Fri*Oct*18*07:15:08*2013*Local*ESSBASE0***3092*Info*(1051164)*Received login request from *[::1]
Fri*Oct*18*07:15:08*2013*Local*ESSBASE0***3092*Info*(1051187)*Logging in user *[EPM11hypplan@AD]* from *[::1]
Fri*Oct*18*07:15:08*2013*Local*ESSBASE0***3096*Info*(1051001)*Received client request: *List Connected Users *(from user *[EPM11hypplan@AD]*)
Fri*Oct*18*07:15:08*2013*Local*ESSBASE0***2100*Info*(1051001)*Received client request: *Logout User *(from user *[EPM11hypplan@AD]*)
Fri*Oct*18*07:15:08*2013*Local*ESSBASE0***2100*Info*(1051037)*Logging out user *[admin@Native Directory]*, active for *63 *minutes
Fri*Oct*18*07:15:08*2013*Local*ESSBASE0***3020*Info*(1051001)*Received client request: *Logout User *(from user *[EPM11hypplan@AD]*)
Fri*Oct*18*07:15:08*2013*Local*ESSBASE0***3020*Error*(1013291)*Failed to logout user *[admin@Native Directory]*: user has requests running
Fri*Oct*18*07:15:08*2013*Local*ESSBASE0***3020*Warning*(1051003)*Error *1013291 *processing request *[Logout User]* - disconnecting
Fri*Oct*18*07:15:08*2013*Local*ESSBASE0***3360*Info*(1051001)*Received client request: *Logout User *(from user *[EPM11hypplan@AD]*)
Fri*Oct*18*07:15:08*2013*Local*ESSBASE0***3360*Error*(1013291)*Failed to logout user *[admin@Native Directory]*: user has requests running
Fri*Oct*18*07:15:08*2013*Local*ESSBASE0***3360*Warning*(1051003)*Error *1013291 *processing request *[Logout User]* - disconnecting
Fri*Oct*18*07:15:08*2013*Local*ESSBASE0***3092*Info*(1051001)*Received client request: *Logout User *(from user *[EPM11hypplan@AD]*)
Fri*Oct*18*07:15:08*2013*Local*ESSBASE0***3092*Info*(1013220)*Supervisor *[EPM11hypplan@AD]* has forced user *[admin@Native Directory]* to logout
Fri*Oct*18*07:15:08*2013*Local*ESSBASE0***3092*Info*(1051037)*Logging out user *[admin@Native Directory]*, active for *48 *minutes
Fri*Oct*18*07:15:08*2013*Local*ESSBASE0***3096*Info*(1051001)*Received client request: *Logout User *(from user *[EPM11hypplan@AD]*)
Fri*Oct*18*07:15:08*2013*Local*ESSBASE0***3096*Info*(1013220)*Supervisor *[EPM11hypplan@AD]* has forced user *[admin@Native Directory]* to logout
Fri*Oct*18*07:15:08*2013*Local*ESSBASE0***3096*Info*(1051037)*Logging out user *[admin@Native Directory]*, active for *28 *minutes
Fri*Oct*18*07:15:08*2013*Local*ESSBASE0***2100*Info*(1051001)*Received client request: *Logout User *(from user *[EPM11hypplan@AD]*)
Fri*Oct*18*07:15:08*2013*Local*ESSBASE0***2100*Error*(1051020)*Cannot log yourself out!
Fri*Oct*18*07:15:08*2013*Local*ESSBASE0***2100*Warning*(1051003)*Error *1051020 *processing request *[Logout User]* - disconnecting
Fri*Oct*18*07:15:08*2013*Local*ESSBASE0***3020*Info*(1051001)*Received client request: *Select Application/Database *(from user *[EPM11hypplan@AD]*)
Fri*Oct*18*07:15:08*2013*Local*ESSBASE0***3020*Info*(1051009)*Setting application *FinPlan *active for user *[EPM11hypplan@AD]
Fri*Oct*18*07:15:08*2013*Local*ESSBASE0***3360*Info*(1051001)*Received client request: *Get Application State *(from user *[EPM11hypplan@AD]*)
Fri*Oct*18*07:15:08*2013*Local*ESSBASE0***3092*Info*(1051001)*Received client request: *Set Application State *(from user *[EPM11hypplan@AD]*)
Fri*Oct*18*07:15:08*2013*Local*ESSBASE0***3096*Info*(1051001)*Received client request: *List Objects *(from user *[EPM11hypplan@AD]*)
Fri*Oct*18*07:16:33*2013*Local*ESSBASE0***2100*Error*(1051021)*You have been logged out due to inactivity or explicitly by the administrator.
Fri*Oct*18*07:16:33*2013*Local*ESSBASE0***2100*Warning*(1051003)*Error *-1 *processing request *[List Substitution Variables]* - disconnecting
Fri*Oct*18*07:16:33*2013*Local*ESSBASE0***3020*Info*(1051001)*Received client request: *Logout *(from user *[admin@Native Directory]*)
Fri*Oct*18*07:16:33*2013*Local*ESSBASE0***3020*Info*(1051037)*Logging out user *[admin@Native Directory]*, active for *49 *minutes
Fri*Oct*18*07:16:33*2013*Local*ESSBASE0***3360*Info*(1051001)*Received client request: *Logout *(from user *[admin@Native Directory]*)
Fri*Oct*18*07:16:33*2013*Local*ESSBASE0***3360*Info*(1051037)*Logging out user *[admin@Native Directory]*, active for *2 *minutes
Fri*Oct*18*07:16:33*2013*Local*ESSBASE0***3092*Info*(1051164)*Received login request from *[::ffff:10.112.14.74]Admin user is a administrator user or a super user in essbase .Admin user has full permission to access the entire system which includes all users and groups.Admin user has the rights to create users Perform dataloads,write and execute calculations,delete users
In your log i can see admin user was active and doing some operations. EPM11hypplan user has forced admin user logout of server.I guess you have set up EPM11hypplan user which has same privilege of admin user to run process.Also check if any particular job process is run via admin id .
More info refer the below url
http://docs.oracle.com/cd/E17236_01/epm.1112/esb_dbag/frameset.htm?dsenative.html
Thanks,
Sreekumar Hariharan -
Shared Services User Reports - for HFM Users
Does anyone have some good material or knowledge they can share with me today regarding the following Shared Services topics?
1. What might cause a run of the Users By Group report to fail? After about 15 mins bombs out and receive the following error: "User not found with identity = ntlm:SID=S-1-5-21-787380144-986785343-375376054-10174?USER(-2147216700). Then gives much more detail on error.
2. How to remove users that appear under admin role but not in default?
3. For audit (TODAY), ideally should produce a report of HFM users – including dates (when added, when security /provisioning was changed for them) – is there a report or combo of reports that will provide this information?
Any help or a point in the right direction is hugely appreciated.
Thank you!Ok - just some pointers, so use as suits.
1: this looks like it is not seeing your AD/NTLM user. You see a similar SID if in Properties of any file share where the connection to the domain is not available, or the user no longer exists. Remember, if a user ID in NTLM or AD has been changed, Shared Services does not recognise this, and stores the original SID, so you need to remove and reprovision the user.
2. The cleanest INHO is to do a CSS Import/Export and 'clean' the file. RTFM :)
3. There are some reports in Shared Services, but see if this is of use - especially the Security Matrix, (http://www.epmmaestro.com/dnn/Products/EPMWebSymphony/tabid/56/Default.aspx)
Good luck -
Shared Services Users Disappear from Groups
We have Native Groups in Shared Services that we added users from our MSAD directory to. Yesterday we found that the groups no longer have these users in them and IT did say they did some moves in the directory over the weekend. But I'm wondering if that would really cause SS to drop all the users from the groups like this.
Basically, no one is able to log in although we are testing adding users back to the groups and think that's working.
I just don't want to have to re-create our groups anytime our MSAD is updated.
I'd appreciate any help in understanding this better,
PaulOur MSAD administrators moved some OU's around one day and it caused a lot of problems for us since our Shared Services MSAD configuration setting for "User DN" had all the OU's hard coded or what have you. I had to change them to the same that the AD folks had changed them to, then restart everything.
So on the native side I can see how if they moved OU's around that could throw off what you had done. There's a utility which I've been too scared to use (probably harmless but I can't afford any mishaps) which tells Shared Services to search for MSAD changes and to force them through Shared Services, which is probably a nice thing to do once in a while especially when MSAD OU's are moved around. SS does not automatically poll for that type of change but you should be able to automate this.
There's an updatenativedir utility that you can read up on which might help. Don't forget to do backups first of all the security-related databases & files, etc. first.
Perhaps someone reading this is comfortable running UPDATENATIVEDIR and can help provide better guidance, if that's the issue here.
Karen -
How to enable Kerberos - Shared Services and Workspace
Hi All
I'm trying to enable Kerberos SPNEGO with WebSphere 6.1.0.31. I've protected the urls.....and i can see the handshake happening in the trace logs.....
Shared Services SSO is working fine if i use the option of Get Remote user info from http header.....
But workspace doesn't seem to accept any of the options given $REMOTE_USER$, $HTTP_USER$.
Can some please let me know how to do this....? Or is there a way to change the header information?Thanks john For ur reply ..i have seen these documents long ago ..i am asking about Shared services and workspace architecture and how these are functioning and where we can find out communication error and slow login issue with workspce and shared services.. How authentication is log on ..is there any machanisam they are using for authencation ...We are using OpenLadp ...
Ex :1.Per suppose log on to workspace that request goes to shared services directory and it will check whether that user is exists or not on Shared services tables ...here what kind of alogirtham using to aunthenticate user...How we can diagonse this process taking to much time,,,is there any specific logs related this (If logs are exsits how we can find out)...
2.Once authencation done successfully and responce send to workspace and populate workspace home page...then i click on application button (FM application) and it's taki ng to much time to load HFM page.To this where we need to look whta excatly problem? what are logs file helpful to us to diagonse.. -
Shared Services User Directory
Hi Gurus,
I was wondering if there is a way of hiding the groups from the Microsoft Active Directory.
For example,
we want the users from Active directory, but when we check the properties of the users in shared services, it shows the user belonging to a lot of groups that are not hyperion-related. Is there a way to make sure that we see the user to be under only the native directory groups.
ThanksIn my production environment, i have a user "john"
When i look at the user's properties in shared services, the user is under only hyperion-related groups.
However, we have secondary environment, which we just imported the active directory, and on this one, the same user is under several more groups that are not related to hyperion, for example the user is under CITRIX group, and all other different ones.
Is it possible for us to filter so that the users will show only under the hyperion related groups -
Shared services user/admin guide
Is there any pdf doc for shared services admin/user guide,,
I tried searching for it but couldnt find it..
i can see a help option when I work with SS which gives goo d help ...but is there any pdf doc to go through before I really start working on SS??
Please let me knowYou want to look at the Hyperion Security Administration Guide to understand Shared Service, Provisioning and External Authentication.
http://download.oracle.com/docs/cd/E10530_01/doc/epm.931/hyp_security_guide.pdf
Brian Chow -
Shared Services Users are not Visiable in Planning Application
Hi All,
We are using Hyperion 11.1.3 version
Problem: We Created Users in Shared Services but those users are not visible in Planning
can you suggest me
VijayHi John,
After giving all the Planning provisions to users, they are not visiable while assigining access to Dimensions Members,
I selected Account Dimension Lower member and clicked on Assing Access button on the top, it opened a popup window where I could not see any users in it....
can you suggest me what should I do???
Vijay -
How to install the shared services
i installed the system9.3.1 but i dont know how to install the shared sevices could you please help me on this.
thanks
subbu.Hi,
Kindly see installation doc of Shared Services from this URL: - http://download.oracle.com/docs/cd/E10530_01/doc/nav/portal_1.htm
Regards,
Atul
Maybe you are looking for
-
Can No Longer Install WinXP on My Machine
Opened my rig this afternoon and it went into continuous loop reboot. Safe mode was inaccessible and reinstallation of XP Pro was impossible. Called Microsoft and they have no actual fix for the problem. The problem seems to have something to do w
-
Adobe 8 Professional won't print as pdf
I've installed, and re-installed the program but cannot make the pdf be the print driver in Adobe or as a printer. I'm using Windows 7 and a 64 bit processor---and wonder if there's something I need to repair/change or just switch to pdf creater to
-
How do I alter print settings in e print and i pad print
My new printer is a 3050A
-
Sending order data to an external system using scp sftp (osm 631.221)
Hello There, I need to come up with a means of sending some order data to an external system via SCP or SFTP. I was looking at an automated task that would fire off some Java to package the data, create the file and send it. I then have to write anot
-
i orderd a ipad2 with engraving to day when will it stop processing