How to setup OID to synchronize with 2nd AD server

Hi there,
We are currently using OAS 10g (10.1.2.0.2)
We have configured OID to synchronize 1 way with 1 AD domain server on Global catalog port.
Now I have a 2nd AD domain server which we need to pull in the user accounts and synchronize any changes to these accounts into the same OID.
I have created a new integration profile in ODM to synchronzie accounts from 2nd domain server.
I have successfully pulled in the AD user accounts from the 2nd AD domain into OID by bootstrapping using the properties file method(only this method works, the usual bootstrap command without properties file doesnt work at all).
But after pulling in the AD accounts from 2nd domain server, the synchronization profile for the 2nd AD domain doesnt synchronize any changes in user account nor any new user created at 2nd domain end.
Have checked the synchronization profile trace file but could not find any thing wrong.
The new integration profile which was created for the 2nd AD domain is using the same "Connected Direcotory URL" as all the other profiles that we have for the 1st AD domain.
Can someone advise what is wrong with my OID synchronization process for the 2nd AD domain?
Any help to point me in the right direction would be appreciated.
(running out of time!).
Cheers
Jim

Thanks for your relpy.
Do I require a separate AD admin account on the 2nd AD server in order to perform the ldapbind? or can I use the same AD admin account from the 1st AD server which I'm currently using on OID to sync with the 1st AD server?
Cheers
Peng Soon

Similar Messages

  • How to use JavaMail 1.4 with Oracle Application Server 10g (9.0.4.0.0)

    Hi all,
    I'd like to know if it's possible and how to use JavaMail 1.4 with Oracle Application Server 10g (9.0.4.0.0), Windows version.
    With the following code, I can see that the mail.jar used by the server is the one included in the jdk installation :
    // I'm testing InternetAddress.class because I want to use commons-email-1.2.jar that requires mail.jar 1.4 (or higher) and activation.jar 1.1 (or higher)
    // and I know that inside the commons-email-1.2.jar file, I need to call the InternetAddress.validate() method that throws a java.lang.NoSuchMethodError: javax.mail.internet.InternetAddress.validate()V if it is used with mail.jar 1.2.
    Class cls = javax.mail.internet.InternetAddress.class;
    java.security.ProtectionDomain pDomain = cls.getProtectionDomain();
    java.security.CodeSource cSource = pDomain.getCodeSource();
    java.net.URL location = cSource.getLocation();
    System.out.println(location.toString());
    This code returns : file:/C:/oracle/app/jdk/jre/lib/ext/mail.jar and this mail.jar file has an implementation version number: 1.2
    - I've tried to include my own mail.jar (1.4.2) and activation.jar (1.1.1) files in the war file that I deploy, but it doesn't work (the server still uses the same mail.jar 1.2)
    - I've tried to put the mail.jar (1.4.2) and activation.jar (1.1.1) files in the applib directory of my OC4J instance, but it doesn't work (the server still uses the same mail.jar 1.2)
    - I know that a patch exists : I've read the following document: How to Make Libraries such as mail.jar and activation.jar Swappable ? [ID 552432.1]
    This article talks about the Patch 6514136, but this patch only applies to : Oracle Containers for J2EE - Version: 10.1.3.3.0
    Can you please help me ?
    Thanks in advance for your answers,
    Laurent

    I strongly suggest to upgrade to AS 10.1.3 to get this.
    Think of future support of AS 9.0.4. You will get not critical patch updates anymore.
    --olaf                                                                                                                                                                                                                                                                                                               

  • How to setup microsoft outlook 2011 with exchange server 2007

    How to setup microsoft outlook 2011 for Mac with Exchange server 2007?

    The folks who set up the Exchange Server should be happy to help you.

  • How to setup IVR in SPA9000 with SPA400

    I had setup SPA9000 with SPA400, I can make outgoing and incomming calls, Incomming call can be transfer by press extentions,But i want to know how to setup IVR, for example, if someone call, system should give greetings and advice to choose extension with the name.Inaddition to that I want to put music on hold.Can some please help me out.

    I can do you one better and teach you how to use the support pages at linksys:
    1) Go to http://www.linksys.com
    2) Click on "Support", then "Technical Support"
    3) Click on "Choose a product"
    4) Under "voice over ip" (the second row, in the middle) select "IP PBX" from the dropdown
    5) In the dropdown to the left, select "SPA9000" from the dropdown
    6) Under "Downloads" click on "Click here"
    7) Then select the version number from the dropdown (if you got your device after 2006, it's most certainly a V2)
    8) Now you can download the wizard, the user guide and the ivr manual (auto attendant quickinstall)
    Or, the quicker way if you know what device you're interested in
    1) Go to http://www.linksys.com
    2) Click on "Support", then "Technical Support"
    3) Under "Enter Model Number" type spa9000 and click OK
    4) Continue at point 6) from the list above
    There are two essential pieces to tracking down a problem with your VoIP equipment:
    The configuration of every device involved
    SIP protocol traces
    And don't forget: there's no such thing as giving too much information when describing a problem.

  • How to setup a newtork HD with my iMac

    Hello to the forum,
    I want to setup an ethernet HD with my home network so to be able to have access to files from both my iMac and mac mini.
    I am using Snow Leopard 10.6.8
    I have the following HD. https://discussions.apple.com/community/desktop_computers/post!input.jspa?contai nerType=14&container=2034
    This HD has also the option to setup multiple RAID modes. Does anyone knows if I can manage and setup its Raid by using Disk Utility instead of WD software? What do I have to do in order to set it up properly ?
    Thanks in advance.

    What software will you use to access movies from your iPad wirelessly? Apple doesn't provide software to do this.
    Your Ethernet drive should come with a manual with setup instructions.
    The drive will usually be attached to your router via Gigabit ethernet.
    Here is the link to the WD support page for your drive.
    The Quick install guide will answer some of your questions.

  • Synchronize with  External NTP server.

    Dear All Good morning,
    Environment:
    SunOS CSF-2 5.10 Generic_138888-03 sun4u sparc SUNW, Sun-Fire-V245 system.
    Sun Cluster 3-2 Two node.
    Question:
    How to Synchronize Cluster timing with external NTP server/device? If external NTP device is down will have any impact in the cluster setup?

    epmuneer wrote:
    Question:
    How to Synchronize Cluster timing with external NTP server/device?The configuration for NTP on Solaris Cluster is explained here:
    [http://docs.sun.com/app/docs/doc/820-4676/cacbdgeg?l=en&a=view|http://docs.sun.com/app/docs/doc/820-4676/cacbdgeg?l=en&a=view]
    and
    [http://docs.sun.com/app/docs/doc/820-4677/cbhijhbh?l=en&a=view|http://docs.sun.com/app/docs/doc/820-4677/cbhijhbh?l=en&a=view]
    If external NTP device is down will have any impact in the cluster setup?You should configure the cluster nodes as peers as well as getting the time from the external NTP server.
    If the external NTP server fails, then time will drift, but at least the cluster nodes keep themselves in sync to have a consistent view.
    Regards
    Thorsten

  • How to setup the sync between two new ACS server

    Hey
    I setup one acs v5.3 in one server in NYC and another acs v5.3 in SJC,
    I want to make the acs.nyc as primary and acs.sjc as the secondary, how do i setup it up ?
    thanks,
    Yang

    make sure that each box has a unique license
    On the box that will be the secondary do the following
    Go to System Administration > Operations > Local Operations > Deployment Operations
    Enter IP address of Primary Instance and admin username / password and then press "Register to Primary"
    Regisration process takes a little time since also involves copying the database from the primary and then restarting the secondary with the new database. You can monitor the progress of this on the primary at
    System Administration > Operations > Distributed System Management

  • How to Setup Historical DSC Database on a standalone Server

    Hey @all,
    I am looking for documentation how to setup a standalone server for the DSC Module(Ver. 8) Historical Database.
    My aim is to log all data to this server. The Server will be running Win2K.
    Do I have to install the complete Labview 8 software and the DSC Module?
    Does a walkthrough exist how to setup a DSC server?
    Thx!
    Carsten  

    After installing the runtime you should only have to reboot the computer in order to get the citadel service running.  At the point, for citadel purposes, this machine will behave as though you had the DSC development system installed.  The 8.0 runtime has no setup requirements...it should only need to be installed.  Unlike previous versions, 8.0 requires you to build your application into an executable and the runtime should be invisible to you once you install it.  If this is not the case, please post about it so it can be looked at.
    If you have specific questions, please post them and I will either try and help you find the answers, get them posted, or answer them myself.
    Regards,
    Robert

  • [OBPM 10gR3]How to configer a hybrid directory with Oracle LDAP Server

    Hey, guys,
    Does anyone have experience on configering a hybrid directory with Oracle LDAP Server? How to config the mapping conf file for Oracle LDAP in the directory of \OraBPMwlHome\conf?
    Here is my conf file. But I got some LDAP mapping errors. It's really weird OBPM doesn't support Oracle's self LDAP, at least it does not provide the conf file.
    -----------errors------------
    Exception [javax.naming.OperationNotSupportedException: [LDAP: error code 53 - Function Not Implemented]; remaining name '']. Reason: [LDAP: error code 53 - Function Not Implemented] fuego.directory.DirectoryRuntimeException: Exception [javax.naming.OperationNotSupportedException: [LDAP: error code 53 - Function Not Implemented]; remaining name '']. at fuego.directory.DirectoryRuntimeException.wrapException(DirectoryRuntimeException.java:85) at fuego.directory.hybrid.ldap.JNDIQueryExecutor.select(JNDIQueryExecutor.java:203) at fuego.directory.hybrid.ldap.JNDIQueryExecutor.selectAllFromView(JNDIQueryExecutor.java:84) at fuego.directory.hybrid.ldap.JNDIQueryExecutor.selectAllFromView(JNDIQueryExecutor.java:64) at fuego.directory.hybrid.ldap.Repository.selectAllFromView(Repository.java:54) at fuego.directory.hybrid.ldap.LDAPPollingEventGenerator.buildCurrentProxies(LDAPPollingEventGenerator.java:98) at fuego.directory.provider.notifiers.BasePollingEventGenerator.generateEvents(BasePollingEventGenerator.java:41) at fuego.directory.hybrid.HybridMultipleEventGenerator.generateEvents(HybridMultipleEventGenerator.java:43) at fuego.directory.provider.notifiers.DirectoryNotifier.notifyChanges(DirectoryNotifier.java:403) at fuego.server.service.DirectoryListener.updateEngineFromDirectoryImpl(DirectoryListener.java:309) at fuego.server.service.DirectoryListener$DirectoryPollingItem.execute(DirectoryListener.java:351) at fuego.server.execution.DefaultEngineExecution$AtomicExecutionTA.runTransaction(DefaultEngineExecution.java:304) at fuego.transaction.TransactionAction.startBaseTransaction(TransactionAction.java:470) at fuego.transaction.TransactionAction.startTransaction(TransactionAction.java:551) at fuego.transaction.TransactionAction.start(TransactionAction.java:212) at fuego.server.execution.DefaultEngineExecution.executeImmediate(DefaultEngineExecution.java:123) at fuego.server.execution.DefaultEngineExecution.executeAutomaticWork(DefaultEngineExecution.java:62) at fuego.server.execution.EngineExecution.executeAutomaticWork(EngineExecution.java:42) at fuego.ejbengine.ejb.EngineStartupBean.executeItem(EngineStartupBean.java:192) at fuego.ejbengine.ejb.EngineStartupBean.updateFromDirectory(EngineStartupBean.java:172) at fuego.ejbengine.ejb.engine_startup_bpmengine_wodkyx_ELOImpl.updateFromDirectory(engine_startup_bpmengine_wodkyx_ELOImpl.java:365) at fuego.ejbengine.servlet.SchedulerServlet$DirectoryPollingTask.runImpl(SchedulerServlet.java:269) at fuego.ejbengine.servlet.SchedulerServlet$ScheduledTask.run(SchedulerServlet.java:208) at java.util.TimerThread.mainLoop(Timer.java:512) at java.util.TimerThread.run(Timer.java:462) Caused by: javax.naming.OperationNotSupportedException: [LDAP: error code 53 - Function Not Implemented]; remaining name '' at com.sun.jndi.ldap.LdapCtx.mapErrorCode(LdapCtx.java:3078) at com.sun.jndi.ldap.LdapCtx.processReturnCode(LdapCtx.java:2951) at com.sun.jndi.ldap.LdapCtx.processReturnCode(LdapCtx.java:2758) at com.sun.jndi.ldap.LdapCtx.searchAux(LdapCtx.java:1812) at com.sun.jndi.ldap.LdapCtx.c_search(LdapCtx.java:1735) at com.sun.jndi.toolkit.ctx.ComponentDirContext.p_search(ComponentDirContext.java:368) at com.sun.jndi.toolkit.ctx.PartialCompositeDirContext.search(PartialCompositeDirContext.java:338) at com.sun.jndi.toolkit.ctx.PartialCompositeDirContext.search(PartialCompositeDirContext.java:321) at javax.naming.directory.InitialDirContext.search(InitialDirContext.java:248) at fuego.jndi.FaultTolerantDirContext.search(FaultTolerantDirContext.java:867) at fuego.directory.hybrid.ldap.JNDIQueryExecutor.select(JNDIQueryExecutor.java:190) ... 23 more
    -----------mapping conf file for Oracle LDAP---------
    <?xml version="1.0" encoding="UTF-8"?>
    <?fuego version="6.1 ALPHA" application="albpmenterprise"?>
    <!-- This file contains the propper attribute mapping for the FDI Generic Ldap Provider using Oracle Directory Service.          
    * Preference for group object
              <preference id="assignedParticipants.containsId" value="true"/>
              This preference is useful to speed up the provider and it can only be used if the assignedParticipant value is the dn of the user and the dn contains the participant id
              <preference id="assignedParticipants.containsId" value="true"/>
              This preference is useful to speed up the provider and it can only be used if the assignedGroup value is the dn of the group and the dn contains the group id
              <preference id="modifyTimeStamp.suffix" value="Z"/>
              This preference is useful when the suffix mofidyTimeStamp format of your ldap is not .OZ.
    -->
    <config>
         <object id="person">
              <object-filter>
                   <![CDATA[
                        (objectclass=inetOrgPerson)
                   ]]>
              </object-filter>
              <relative-dn>
                   <!-- the relative dn for person -->
              </relative-dn>
              <attribute id="id" value="uid"/>
              <attribute id="lastName" value="sn"/>
              <attribute id="firstName" value="givenname"/>
              <attribute id="accountLock" value="orclIsEnabled">
                   <attribute-comparator operation="EQUALS" compareTo="ENABLED"/>
                   <filter>
                        <![CDATA[
                             ($accountLock=ENABLED)
                        ]]>
                   </filter>
              </attribute>
              <attribute id="facsimileTelephoneNumber" value="facsimileTelephoneNumber"/>
              <attribute id="displayName" value="displayName"/>
              <attribute id="mail" value="mail"/>
              <attribute id="telephoneNumber" value="telephoneNumber"/>
              <attribute id="employeeId" value="employeeNumber"/>
              <attribute id="thumbnailPhoto" value="jpegPhoto"/>
              <attribute id="manager" value="manager"/>
              <attribute id="modifyTimeStamp" value="modifytimestamp"/>
         </object>
         <object id="group">
              <object-filter>
                   <![CDATA[
                        (objectclass=orclGroup)
                   ]]>
              </object-filter>
              <relative-dn>
                   <!-- the relative dn for group -->
    </relative-dn>
              <attribute id="id" value="dn"/>
              <attribute id="modifyTimeStamp" value="modifytimestamp"/>
              <attribute id="displayName" value="displayName"/>
              <attribute id="name" value="cn"/>
              <attribute id="description" value="description"/>
              <attribute id="assignedParticipants" value="uniquemember"/>
              <!--attribute id="assignedGroups" value="memberOf"/-->
              <attribute id="ou" value="uniquemember"/>
         </object>
         <object id="ou">
              <object-filter>
                   <![CDATA[
                        (objectclass=domain)
                   ]]>
              </object-filter>
              <relative-dn>
                   <!-- the relative dn for ous -->
    </relative-dn>
              <attribute id="name" value="orclsubscriberfullname"/>
              <attribute id="description" value="description"/>
         </object>
    </config>
    Edited by: Lemonice on 2009-3-30 上午2:08
    Edited by: Lemonice on 2009-3-30 下午7:01
    Edited by: Lemonice on 2009-3-30 下午8:43

    Hi,
    in my case, I am trying to configure the OBPM directory using ALUI and its native LDAP service.
    Now, I found that the first name and the last name in BPM are retrieved from the ALUI display name : provided we enter the display name in the format %first name% + %last name% we get them into BPM. But the display name is not always in this format...
    In addition, it's the portal telephone number information which is retrieved into BPM Telephone and Fax numbers.
    And, the email adress remains blank
    I have installed the latest patch for OBPM (Version: 10.3.1.0.0 Build: #97172)
    Would you have any documentation about creating a Profile Web Service in ALUI and specifying which LDAP attributes to map to which ALUI properties in the Profile Source ?
    Thanks !
    Edited by: vVince on May 6, 2009 3:46 PM

  • How to get Messages to work with a proxy server?

    at work we use a proxy server.
    some icloud programs work, but Messages does not.
    any idea how to get this to work through a proxy server?
    thanks.

    Hi,
    Now I feel really silly.
    I remember the pane looking like this though:-
    As there used to be two iChat forums here at Apple Support Communities  and the older iChat 2.1 one has disappeared I am not sure how many threads might be available for scrutiny on this matter.
    AS I said I don't ever recall someone reporting that they got it  to work.
    During early version of iChat it was found that the AIM server would accept a login on almost any port.
    It became popular to suggest port 443  as this was a well known port known to be open on most routers "out-of-the-box" and likely to be open in campus situations where students may not have any control over what ports were open.
    An AIM Login can also do "Direct IMs" for which is switches to port 5190 on the UDP Protocol.
    At this point the chat is peer to peer.
    It does this if you send a pic in the Chat or send a file.
    It uses port 5190 for this no matter what is used for the Login.
    7:27 PM      Thursday; May 9, 2013
      iMac 2.5Ghz 5i 2011 (Mountain Lion 10.8.3)
     G4/1GhzDual MDD (Leopard 10.5.8)
     MacBookPro 2Gb (Snow Leopard 10.6.8)
     Mac OS X (10.6.8),
     Couple of iPhones and an iPad
    "Limit the Logs to the Bits above Binary Images."  No, Seriously

  • How to setup Cintiq 12wx along with dual monitors (3 displays total)

    I’m considering purchasing a Wacom Cintiq 12wx.  I currently run the latest LR and Photoshop CS5 with two NEC P221W monitors (which I keep color-calibrated) on Windows 7, set up with my desktop extended across both displays.  They are both running at their native 1680 x 1050 resolution (and I want to keep them that way).  My video card is a GeForce 8800 GT.  Dell XPS 630i.
    I want to run the 12wx (whose resolution is 1024 x 1280) in addition to the above setup.  The best advice I can find so far on the web is to get another (cheaper) NVidia card to run it.  Sounds right to me.  My question (assuming this is the way to go): how should/can the Windows desktop/monitor setup be configured to handle this?
    My desired Lightroom result is:
    * grid/develop view of image on my main NEC
    * image only on the second NEC (F11) – this is what I have so far
    * editable view of the image on the Cintiq
    My desired Photoshop result is:
    * editable image view only (well, mostly) on my main NEC
    * tool panels etc. on the second NEC (configured via Workspace) – this is what I have so far
    * editable view of the image on the Cintiq
    Has anyone done this, if so how?  Also, I’m hoping I can color-calibrate the Cintiq as well as the two NECs, thoughts?
    Thanks.

    Thank you Grant for the quick response. Well, it seems I don't know what I'm doing.
    So, Mac Pro doesn't have any video INPUTS just Outputs. CHECK.
    That is correct I have a six-input-port-selector with one input (SWITCH C2G). CHECK.
    What I want is to be able to toggle through the inputs from the HDMI Switch C2G. That way I can use all my devices (Mac Pro, Xbox, PS3, Cable Box) with these monitors.
    Since the Switch C2G only has one OUTPUT Slot, I'm thinking I just need to connect the monitors to the Switch C2G Output slot by using a 2 to 1 HDMI Adapter, but wouldn't I lose the true potential of these monitors by not connecting them directly to the Mac Pro?
    Currently, I have the monitors hooked up with Thunderbolt/Mini Display Adapters to the Mac. So I guess I would just have to run just one HDMI with Thunderbolt/Mini Display from the Mac to the Switch C2G, and connect the other devices to the Switch as well.
    Jeez. Am I right? 
    What If I get an HDMI Switch with 2 Outputs instead of getting the 2 to 1 HDMI Adapter or perhaps a 4 to 2 Adapter. Heck. I'm not sure what to do here.
    I would really appreciate anyones help.
    Thank you.

  • How to setup an ikev2 VPN with public key authentica​tion with your BB10 device

    This setup will allow you to run a VPN between your BB10.2 (and probably BB10.1) device and a debian linux computer (I am running the testing stream).  You will need to tweak this config (and possibly install strongswan server on your LAN's gateway) to get access to network resources, or access the internet via the VPN.  I have created this setup with the intention of accessing files/services on the debian computer only.
    1.  Install strongswan on your debian machine(I have v4.6.4 installed, I think the current testing version is v5.1.  If you install v5+, some lines in the config may be obsolete), and install any other extra packages you are prompted to install: 
    apt-get install strongswan strongswan-ikev1 strongswan-ikev2 strongswan-starter openssl ipsec-tools
    2.  Generate certificates on your debian server in any, starting with a certificate authority.  Edit the C= O= CN= fields to whatever you want:
    ipsec pki --gen --outform pem > caKey.pem
    ipsec pki --self --in caKey.pem --dn "C=CA, O=none, CN=Certificate-Auth" --san="Certificate-Auth" --ca --outform pem > caCert.pem
    Generate a server keypair (again, editing the same fields as I indicated above.  The CN= field should be lan ip address of your strongswan server.  I would also put this as the address in --san=, or you can specify your hostname(if you have one, i.e. mydomainname.com):
    ipsec pki --gen --outform pem > serverKey.pem
    ipsec pki --pub --in serverKey.pem | ipsec pki --issue --cacert caCert.pem --cakey caKey.pem --dn "C=CA, O=none, CN=192.168.1.100" --san="192.168.1.100" --flag serverAuth --outform pem > serverCert.pem
    Generate a keypair for your BB10 device (choose a CN=, and use it in the --san field @your server lan ip or hostname:
    ipsec pki --gen --outform pem > userKey.pem
    ipsec pki --pub --in userKey.pem | ipsec pki --issue --cacert caCert.pem --cakey caKey.pem --dn "C=CA, O=none, CN=bb10" --san "[email protected]"  --flag serverAuth --outform pem > userCert.pem
    3.  After generating your keys, package the client keys for your BB10 device(you will be asked to create a password): openssl pkcs12 -export -in userCert.pem -inkey userKey.pem -out bb10.pfx
    Copy the bb10.pfx file, and serverCert.pem to your BB10 device and import the certificates into the certificate store(Open Settings --> Security and Privacy --> Certificates --> Import)
    4. Move the certificates into the appropriate folders on your debian server: 
    mv caKey.pem /etc/ipsec.d/private
    mv caCert.pem /etc/ipsec.d/cacerts
    mv serverKey.pem /etc/ipsec.d/private
    mv serverCert.pem /etc/ipsec.d/certs
    5. Enable ip forwarding on your debian machine:
    edit /etc/sysctl.conf - change the following value as follows:
    net.ipv4.ip_forward=1
    Close the file and save changes.  To enable changes, type:  sysctl -p /etc/sysctl.conf
    6.  Edit config files:
              ipsec.secrets:
    : RSA serverKey.pem
            ipsec.conf:
    config setup
            strictcrlpolicy=no
            uniqueids=yes
    conn %default
            ikelifetime=60m
            keylife=20m
            rekeymargin=3m
            keyingtries=1
            keyexchange=ikev2
            leftfirewall=yes
            dpddelay=30
            dpdtimeout=120
            dpdaction=clear
    conn bb10
            mobike=yes
            ike=aes256-sha1-sha1-modp1024!
            esp=aes256-sha1!
            left=%defaultroute
            leftid="C=CA, O=none, CN=192.168.1.100"
            leftcert=serverCert.pem
            right=%any
            rightsourceip=10.10.0.1
            rightid="C=CA, O=none, CN=bb10"
            rightauth=pubkey
            leftauth=pubkey
            pfs=yes
            auto=add
    7. Start the ipsec service on your debian machine: service ipsec stop; service ipsec start
    8. Set up the VPN connection on your blackberry: Settings -->Network Connections --> VPN --> Add.
    a) Profile Name:  Give your VPN a name
    b) Server Address:  Enter your server's address
    c) Gateway Type: Generic IKEv2 VPN Server
    d) Authentication Type: PKI
    e) Authentication ID Type:  Identity Certificate Distinguished Name
    f) Client Certificate: The client certificate you imported should show up in the dropdown
    g) Gateway Auth Type: PKI
    h) Gateway Auth ID Type: Identity Certificate Distinguished Name
    i) Gateway CA Certificate:  Find the certificate authority you imported.  If you used the same name as I did above when creating the certificate, if will be called "Certificate-Auth".
    j) Perfect forward secrecy : ON
    k) Change IKE Lifetime to 3600
    l) Change IPSEC lifetime to 1200
    You can leave everything else on default settings.  Save your VPN profile.
    9. Connect to your VPN.  You should now be able to ping both ways between your blackberry and debian host.  Using the above configuration, your blackberry device will have the ip address of 10.10.0.1.

    There have been numerous bb10 updates (now 10.2.1.2977) since I first posted this mini how-to-I am not sure if it was the bb10 updates, or updates to strongswan (now v5.2.0) or my linux kernel (v3.15.3), though I am now able to use stronger hash and elliptic curve key exchange.  I am using sha384 in my example, though have also got it working with sha512.  Give it a try:
    Simply use the same process I detailed before, though change the following lines in ipsec.conf:
    ike=aes256-sha1-sha1-modp1024!
    esp=aes256-sha1!
    to
    ike=aes256-sha384-ecp521
    esp=aes256-sha384-ecp521
    Be sure to restart strongswan after you change these lines in the config.
    After this is done, change 'Automatically determine algorithm' to off in the VPN profile settings of your VPN connection profile on your blackberry.  I'm not sure why it doesn't work automatically.  State the following in this section:
    IKE DH Group:  21
    IKE CIpher: AES (256-bit key)
    IKE Hash: SHA384
    IKE PRF: HMAC-SHA384
    IPSec DH Group: 21
    IPSec Cipher: AES (256-bit key)
    IPSec Hash: SHA384

  • HT2497 how to setup airport to work with IPV6

    How can I setup my AE to work with IPV6 that was launch last night in the east coast? Or there is no need for me to do anything on my AE because it will setup itself automatically?
    Thanks,
    TCFL

    IPv6 service comes in a variety of "flavors" so it would be difficult to provide you with exact configuration settings for your AirPort router.
    I would first check with your ISP to see if they have implemented IPv6 service. If they have, they should provide you with what requirements must be satisfied to use IPv6.

  • How to setup Glashfish 2.1 with sun crypto hardware inside T2 processor

    Dear Expert,
    I had setup comm 7 at guest os (ldom guest) on sun fire t5240 , All running well (mail,calender,im) , I also read
    http://wikis.sun.com/display/BluePrints/Taking%20Advantage%20of%20Wire-Speed%20Cryptography
    Does any body have guide step by step How to integrated glasshfish with sun    Cryptography hardware ?
    thanks
    Hadi

    singautara,
    SLIM is trying to tell you that SUSE 9.x will just not work.
    Period.
    SUSE 9.x is for Intel and AMD chips and the computers that use them. Your Ultra-60 does not have x86 compatible components in it.
    It does not have a BIOS. It has an OpenBootProm .
    The last distribution ever ported by SUSE to Sun's SPARC cpu architecture was something like version 7.3. That is from 5 years ago !
    What's wrong with the Operating Environment that was developed by the same company that manufactured your computer?
    Use the SunOS on the Sun system !
    http://sunsolve.sun.com/handbook_pub/Software/
    Tell you what ...
    Find the "Related Documentation" link at this page in the Sun System Handbook and research what sort of system you have.
    http://sunsolve.sun.com/handbook_pub/Systems/U60/U60.html

  • How to setup discoverer to work with portal in future

    Hi,
    I have to setup the environment for a discoverer 10g R2 based reporting application.
    The application is supposed to display reports on the portal that is hosted on Oracle 10g AS.
    I started with installation of Oracle 10g R2 DB server. I have the Oracle BI suite 10g , Oracle 10g AS, Oracle 10g Portal etc with me.
    Can someone guide me as to how should I proceed in the installation step-wise so as the repoting application can be hooked on to the AS and displayed in portal.
    The slight catch here is there is a separate team working on developing the portal.
    I need to know what is to be done so that there is a smooth merger of discoverer with the portal.
    Thanks
    Goga

    Hi
    The interaction between Discoverer and Portal takes place after you have installed the full-blown application server. Stand-alone Discoverer cannot be made to hook into Portal.
    When you install the full application server you need an infrastructure database. You either do this manually by inserting the repository components into an existing database or you use the seeded database that comes with the install. Personally, I prefer the seeded approach.
    After you have installed the infrastructure you run the installer a second time and install the middle tier. While you can install the infrastructure and middle components onto the same machine, performance is better if you use different machines. However, if you are only trying to test things out, doing all of this on one machine would be ok.
    After you have got your middle tier components installed (Discoverer and Portal), make sure they are working. For Discoverer you will need to have an EUL. For Portal you only need to be able to connect to it.
    Next, and only now comes the link between Discoverer and Portal. All you need to do is tell Portal that the link is to be enabled. This is called creating a portlet provider.
    To create a portlet provider for Discoverer follow this workflow:
    1. Connect to Portal as Portal user
    2. On the top right, click the Administer tab
    3. You will see three further tabs, this time on the left, called Portal, Portlets and Database
    4. Click the Portlets tab
    5. Locate the Remote Providers box on the top right hand side
    6. Click Register a Provider
    7. In Provider Information enter the following:
    a) a name - for example Discoverer
    b) a Display name - for example Discoverer
    c) Timeout - for example 30 seconds
    d) Timeout message - for example Please try again later
    e) In implementation Stype select Web
    f) Click the Next button
    8. In General Properties enter the following:
    a) In URL type http://hostname:port/discoverer/portletprovider
    Eg. http://server1.learndiscoverer.com:7778/discoverer/portletprovider
    You may need to omit the port on some systems so that it would look like this:
    http://server1.learndiscoverer.com/discoverer/portletprovider
    Note: type discoverer/portletprovider as stated
    If you do need a port and are unsure as to which port number to enter follow this workflow:
    i) Launch a second browser window
    ii) Type http://hosntame:1811 (or whatever is the AS Control port on your system) and press Enter
    iii) In username enter ias_admin and the associated password
    iv) When authenticated, you will see the Farm for your infrastructure and mid tier
    v) Cick on the mid tier instance (you may need to enter your ias_admin username and password again)
    vi) Click the Ports link alongside the word Home at the top of the screen
    vii) Note the port number for your HTTP Server Listen(non-SSL) port
    viii) Close AS Control and go back to the portlet provider setup
    b) Check the box Web provider in same cookie domain as the portal
    c) Leave other defaults as they are and scroll down to section called User/Session Information
    d) In User/Session Information check User and specify that the frequency should be Once per user session
    e) Click the Next button
    8. In Grant Access leave this alone and click the Finish button
    9. If you get a warning about the cookie domain click the OK button
    10. Exit Portal
    You have now successfully created a portlet provider for Discoverer
    To test that this is working enter one og these in your browser window:
    If using ports:
    http://hostname:port/discoverer/portletprovider
    If not using ports:
    http://hostname/discoverer/portletprovider
    The system should respond with Congratulations! You have successfully reached your Provider's Test Page
    Does this help?
    Regards
    Michael

Maybe you are looking for