Incremental index for UME ADS LDAP

Hi,
We are currently indexing the users in the "ume" repository in order to use a "Who Is Who" type search and using Active Directory as the data source.
The problem is that when we change an attribute in Active Directory, TREX doesn't pick up the modification when running an incremental index, only after a full reindex. This causes the attributes displayed in the search results to be not up to date. This is a problem if we want to schedule an incremental index every night, for example.
For user resources coming from an LDAP, the property modified is missing. Therefore you have to provide an appropriate mapping from LDAP property to User property in UME configuration xml file (see note 1239132). Otherwise changes of user data won't be recognized and updated in the index.
In order to find changes in the resources the crawler is using several properties. The default value contains "Date" which means that "Modified" property of the resource is checked.
This property for the user recource is retrieved from the UME IUser attribute
{com.sap.security.core.usermanagement} LAST_MODIFIED_BY
we set this LAST_MODIFIED_BY in our xml file (dataSourceConfiguration_ads_readonly_db_mailbox_flat_with_krb5v4.xml)
to <attribute name="LAST_MODIFIED_BY"> <physicalAttribute name="whenchanged"/></attribute>
but the incremental index crawler still doesn't notice that a user attribute has been changed in the LDAP.
are we missing something??

HI,
Is there any api to access the ldap attributes.  Can any one provide the code to access the MS ADS?
with regards,
srinivas

Similar Messages

  • Self Registration for UME using LDAP as the datasource

    Hi,
    Am I able to config the self registration when my UME is mapped to LDAP datasource? If yes, how am I going to do this as I'm not able to find the ume.logon.selfreg=TRUE.
    Thanks!

    Hi,
    Isn't this option there in /useradmin ? Go to http://hostname:port/useradmin and click on Configuration. Go to the tab User Admin UI and there select the option for enabling self-registration.
    Also, should be available in configtool under the core ume service.
    Regards,
    Shitij

  • LDAP as data source for UME

    Trying to use a SSL enabled LDAP (Sun) for data source for UME.  It seems that I can't use SSL directly from GRC CUP 5.3. Followed the instructions in saphelp, but when I test the connection, it gives me "Connection test with user path failed". The following is the connection data in UME Config:
    Server Name:  10.56.17.20
    Server Port:     62636
    User:                cn=GMACApp_001,ou=Applications,dc=gm,dc=com
    Password:       <correct one entered>
    User path:        ou=People,dc=gm.dc=com
    Group path:      ou-Groups,dc=gm,dc=com
    Use SSL for LDAP Access is checked
    Use Unique Attribute is not checked
    I can connect to the LDAP using the same credentials with Softerra browser....Any ideas?

    Opened a message with SAP....the response was less than helpful..."we don't support SSL". When I pushed them with the responses I recieved from the forum, the replay was "we have never done this".  There must be a way.  I can't be the only person on the planet that has to connect to a corp LDAP with a secure port!! I have tried the trick of conencting a LDAP as a data source for UME, but with limited success.  Seems when the LDAP + db is enabled, the UME URL is not available (error 503). So that's not working so well either. 
    Any help will be appreciated.

  • How to find the incremental growth of index for last few months

    Hi,
    How to find the incremental growth of index for last few months.
    Thanks,
    Sathis.

    Hi,
    Check the below link, it may help you!
    http://www.rampant-books.com/t_tracking_oracle_database_tables_growth.htm
    Thanks,
    Sankar

  • Crawling fails for UME index

    Dear friends,
               I have setup an index for the ume/users directory. The crawler fails to crawl all entries for ume/users. Do I need to setup my own crawler for the ume or is the standard crawler supposed to work? Can someone, who has got the crawler to work for ume, share his ideas here.
    We are on EP6 SP13.
    Thanks,
      Mandar

    Hi Detlev,
    I have followed the steps described in that help file. The application logs gives me errors as follows
    Error  8/29/05 10:13:55 AM  IndexmanagementService  AbstractTrexIndex: indexing some of the resources failed 
    Error  8/29/05 10:13:55 AM  IndexmanagementService  Indexing document failed. null 
    Error  8/29/05 10:13:55 AM  IndexmanagementService  Indexing document failed. null 
    Error  8/29/05 10:13:55 AM  IndexmanagementService  Indexing document failed. null 
    Error  8/29/05 10:13:55 AM  IndexmanagementService  Indexing document failed. null 
    Error  8/29/05 10:13:55 AM  IndexmanagementService  Indexing document failed. null 
    Error  8/29/05 10:13:55 AM  IndexmanagementService  Indexing document failed. null 
    Error  8/29/05 10:13:55 AM  IndexmanagementService  Indexing document failed. null 
    Error  8/29/05 10:13:55 AM  IndexmanagementService  Indexing document failed. null 
    Error  8/29/05 10:13:55 AM  IndexmanagementService  Indexing document failed. null 
    Error  8/29/05 10:13:55 AM  IndexmanagementService  Indexing document failed. null 
    Error  8/29/05 10:13:55 AM  IndexmanagementService  Indexing document failed. null 
    Error  8/29/05 10:13:54 AM  IndexmanagementService  XIndexing documents failed. AbstractTrexIndex: indexing some of the resources failed Continue crawling... 
    Error  8/29/05 10:13:54 AM  IndexmanagementService  Indexing document failed. null 
    Error  8/29/05 10:13:54 AM  IndexmanagementService  Indexing document failed. null 
    The Crawler does work fine for documents repository. Can you suggest something?
    Thanks,
    Mandar

  • UME with LDAP

    Hi Experts,
    I've installed Portal sneak preview which is 7.0 SP9 in my Desktop and at the moment i'm using Web AS database is the user storage for portal.
    Now wanted to change the user storage to any ldap (for windows) server and wanted to look at the working scenario.
    Now ..
    1. Which is the recommended LDAP server for windows, to the above scenarion
    2. Can i use LDAP is the user storage for sneak preview versions.
    3. Any useful documents to achieve this.
    4. Please remeber i'm on Windows XP.
    Please leave your valuable suggestions
    Thanks,
    Lokesh.

    Hi,
    Hi Experts,
    I've installed Portal sneak preview which is 7.0 SP9 in my Desktop and at the moment i'm using Web AS database is the user storage for portal.
    Now wanted to change the user storage to any ldap (for windows) server and wanted to look at the working scenario.
    Now ..
    1. Which is the recommended LDAP server for windows, to the above scenarion
    I guess on Windows the best choice is ADS. If I get your requirement correctly you want to install a local LDAP Server on your machine correct? I don't know if it is possible to install ADS standalone on Win XP. In general you can use any LDAP Server so you should be able to get it working even with openLDAP if you are fimiliar with the LDAP protocol. I think openLDAP is not supported by SAP so maybe you should try something like SUN Directory Server (You can download a trial from the SUN Website). There is a version for Windows and it works without problems on WIN XP (I've tried a couple of times)
    2. Can i use LDAP is the user storage for sneak preview versions.
    I bet you can. You just have to choose the appropriate XML-File for UME Userstore that supports LDAP as UME and it should work.I've not tried with trial version but I think there are no limitations in the trial version regarding UME configuration.
    3. Any useful documents to achieve this.
    Check these out:
    http://help.sap.com/saphelp_nw70/helpdata/EN/63/14f5b51a6eff429f2d8b2063400e82/frameset.htm
    http://help.sap.com/saphelp_nw70/helpdata/EN/48/d1d13f7fb44c21e10000000a1550b0/frameset.htm
    http://help.sap.com/saphelp_nw70/helpdata/EN/37/cfd93f130f9115e10000000a155106/frameset.htm
    All you have to take care of is to choose the appropriate hierarchy supported by UME to store your user information within your directory (all this is described in the pages linked above)
    4. Please remeber i'm on Windows XP.
    I do
    I hope this helps
    Cheers

  • Automatic upload of roles from ECC to portal (UME with LDAP)

    Hi experts,
    This thread reopen the question asked on the following message : automatic upload of roles from BI to portal
    However, it concerns this time "UME with LDAP".
    Problematic :
    SAP Library 04s tells us that is not yet possible to automate role replication (or role assigment replication) from ABAP Based back-end to Netweaver Portal. Only manual process for initial upload is possible.
    Source = http://help.sap.com/saphelp_nw04s/helpdata/en/41/5e4d40ecf00272e10000000a155106/frameset.htm
    Questions :
    1 - Did anyone ever try to implement such an automatic tool ?
    2 - What if I'm not able to write on the Active Directory ? I am still able, at least, to automate role assignment replication from ABAP Based back-end to Netweaver Portal (ie. UME with LDAP) ? Directly from SAP R/3 to EP through UME, without passing through Active Directory since the group field is not maintained in AD.
    Many thanks for your inputs
    Alexis MARTIN

    Hello,
    As I did not read the previous thread I don't know what exactly you are trying to achieve, but I can tell you about what we have done - as far as it is not too late yet.
    We use the portal with integration to a BI system. In the ABAP stack we have lots of roles with menu items for hundreds of reports. We want the users to see these roles in the portal.
    First we have used the role migration tool of the portal to upload these roles. There is a Java API for executing role uploads from code. You need to create a webservice in the java stack to call this api, and can call the webservice from ABAP.
    However it is just a question of time and role size until this will not work at all. Standard role migration is more or less crap, stability is a problem. It also creates a lot of logs in the PCD and thus fills the database with trash. (After a few OSS messages there is now a program for deleting logs + you can turn of logging.) Also upload of larger roles takes up to an hour, and you alwasy have the problem that your portal roles are not up to date during the day.
    When I got completely fed up, I have implemented an own navigation connector. When you log on to the portal it will connect to the ABAP stack via RFC, load the role, and generate the portal menu from it. It uses caching, but on every logon it checks whether the role has been updated in ABAP since the last time it was loaded. It is up to date, faster then PCD navigation, and you need absoluetely no periodical synching at all. I cant even understand why this is not offered by SAP per standard!
    Drawback is that it will of course only work for the menu items, and only menu items with an "URL-type" are supported. I'm prettry sure however that it would be possible to implement a few other types as well.
    Let me know if you are interested in the solution, I can give you a few additional details: oliverDOTsvisztATwienerbergerDOTcom
    Oliver

  • Change permissions for UME repository

    Dear friends,
           Is it possible to change permissions for the ume repository. By default, it has "Allow" permission for List Children and Read properties. I dont see any options to change permissions under Settings -> permissions. Does anyone here in this forum knows how can I achieve the same? I am actually trying to index the ume repository and the crawler fails. I was wondering if the repository needed to have a full control. So, I am trying to change the permissions.
    We are on EP6 SP13 (all components)
    Any help is appreciated,
    Thanks,
    Mandar

    Hello experts,
    any ideas?
    I need aswell to change the permission in the UME repository...
    Thanks in advance!
    Greets
    Thomas

  • Can I use 2 datasources for UME?

    Hi Experts,
    I want to use 2 datasources for UME, LDAP as primary DS, UME own DB as second DS.
    Actually, i want to do that if it can't find an account in LDAP, the system will try to retrieve this account in UME own DB.
    Can I do that in EP7.0??
    Regards,
    Sidney

    Sidney,
    You can configure UME with max user management/AD servers at a time.
    Its called multi-domain authentication
    It will require a change in the UME xml file.
    You can read more here -
    http://help.sap.com/erp2005_ehp_04/helpdata/en/af/0cfc3f09c2c442e10000000a1550b0/frameset.htm
    Can portal authenticate to multiple domains?
    http://help.sap.com/saphelp_nw70/helpdata/en/63/14f5b51a6eff429f2d8b2063400e82/frameset.htm
    Regards,
    Ritu

  • Configuring Browsing Indexes for Service Search Descriptor Filters

    I am running DSEE 6.1 on Solaris 10.
    I restrict access to the ldap clients (solaris8, 9, and 10) for various users in the Directory by configuring the service search descriptors to use a filter based on specific roles. Each servers profile mentions a role depending on type of server and then users are assigned roles which are nested within specific server type roles:
    NS_LDAP_SERVICE_SEARCH_DESC= passwd:ou=People,dc=example,dc=com?one?nsrole=cn=serverRole,ou=profile,dc=example,dc=com
    NS_LDAP_SERVICE_SEARCH_DESC= group:ou=group,dc=example,dc=com?one
    NS_LDAP_SERVICE_SEARCH_DESC= audit_user:ou=People,dc=example,dc=com?one?nsrole=cn=serverRole,ou=profile,dc=example,dc=com
    NS_LDAP_SERVICE_SEARCH_DESC= shadow:ou=People,dc=example,dc=com?one?nsrole=cn=serverRole,ou=profile,dc=example,dc=com
    NS_LDAP_SERVICE_SEARCH_DESC= user_attr:ou=People,dc=example,dc=com?one?nsrole=cn=serverRole,ou=profile,dc=example,dc=com
    I have noticed in my error logs on the Directory servers messages regarding these filters not being indexed:
    WARNING<20805> - Backend Database - conn=949139 op=1 msgId=2 - search is not indexed base='ou=people,dc=example,dc=com' filter='(nsRole=cn=serverRole,ou=profile,dc=example,dc=com)' scope='one'
    I have also had a few instances where the naming services seems to have stopped altogether. This seems to be timed with when my clients do a refresh of the ldap cache - which is the time that I seed the not indexed messages in the error log.
    I guess that I need to set up Browsing Indexes for these filters
    Can anyone give examples how to do this?
    I guess I will need a vlvBase of ou=people,dc=example,dc=com
    vlvScope of 1
    vlvFilter of nsRole=cn=serverRole,ou=profile,dc=example,dc=com
    I am not sure what I would do for vlvsort attributes though??

    The access logs shows that the attributes to be sorted are uid and cn:
    25/Apr/2008:09:58:21 +1200] conn=171835 op=1 msgId=2 - SRCH base="ou=people,dc=example,dc=com" scope=1 filter="(nsRole=cn=serverRole,ou=profile,dc=example,dc=com)" attrs="cn uid uidNumber gidNumber gecos description homeDirectory loginShell"
    [25/Apr/2008:09:58:21 +1200] conn=171835 op=1 msgId=2 - SORT cn uid (1426)
    [25/Apr/2008:09:58:21 +1200] conn=171835 op=1 msgId=2 - VLV 0:999:0:0 1:1426 (0)
    [25/Apr/2008:09:58:26 +1200] conn=171835 op=1 msgId=2 - RESULT err=0 tag=101 nentries=999 etime=5 notes=U
    So the vlvsort attributes should be cn and uid.

  • ACS can not access ADS-LDAP starting from "DC=..."

    Hi
    I have an ACS v4.2 from which I try to access an ADS LDAP directory. When I use "CN=Users,DC=Domain,DC=com" as the baseDN for the users and the groups everything works as it should. When I change the base DN to "DC=Domain,DC=com" only, then the ACS is not able to find any users or groups. Even when trying to configure the group mappings he claims: "LDAP Server NOT reachable. Please check the configuration.". Using an LDAP browser I don't have any issues accessing the directory from the shorter baseDN.
    Is this a v4.2 related problem or a general ACS problem?
    The point is that I need to find users in different OU's, which are based directly under the domain name, so that I need to search for them starting from "DC=Domain,DC=com". I know that with "Generic LDAP" I can make severeal "Databsae Configurations" to resolve the issue with the OU's. But not with a "RSA SecurID Token and LDAP Group Mapping" setup. There is only possible to have one LDAP group mapping configuration.
    Any input would be greatly appreciated.

    Hi
    We invested a lot of time together with TAC and development. Short answer: No it's not solved. It was an ACS bug. But development didn't realy understand the problem. We went ahead and restructured the ADS.
    The problem we had, is that a LDAP directory of a Windows is not fully accessible. Even if you connect as a Domain Administrator or to the Global Catalog. :-) And that's where the ACS fails. LDAP browsers just read over the unaccessible parts of a LDAP directory and show you all the accessible part. ACS doesn't. He stops and reports the failure. You can see that clearly when sniffing the access of the ACS and the LDAP browser to the directory. Unfortunately the unaccessible part is at the beginning of the ADS LDAP directory. :-(
    Maybe they resolved the problem nowadays. Or if you have a Windows Guru who can help you in making the directory fully accessible I would be interessted in the How-To.
    I wish you best luck with your issue.
    Kind regards
    Roberto

  • Multi-column Index vs One index for each column

    Hello everyone,
    i have one table about 20 000 000 rows, some developers have to generate reports on it and i want to create indexes on this table.
    The table has 34 columns, no primary key, no unique keys.
    The "where..." clause of the reports usually use 8 columns but some reports uses 8 + some other columns.
    can any one help me on what kind of indexes do i have to create?
    1. one index for each column used in "where clause"
    2. one index for 8 columns and some other indexes for other used columns
    3. one index for all columns
    or something else etc...
    br flag

    i have one table about 20 000 000 rows, some developers have to generate reports on it and i want to create indexes on this table.
    The table has 34 columns, no primary key, no unique keys.
    The "where..." clause of the reports usually use 8 columns but some reports uses 8 + some other columns.
    can any one help me on what kind of indexes do i have to create?
    1. one index for each column used in "where clause"
    2. one index for 8 columns and some other indexes for other used columns
    3. one index for all columns
    or something else etc...What's the version of your data base? what kind of database you have, DWH or OTLP? The answer might depend on the type of database as far as bitmap indexes might suit or might not depending if you are runing DWH or OLTP kind of database
    Let me suppose that you are runing OLTP database and you have a where clause with 8 columns.
    1) are all those where clause equalities (where col1 = and col2 =) or there are inequalities?
    2) could you evaluate the most repetitive columns?
    3) could you know the column that could have the best clustering factor (the column which most follow a certain order in the table)
    Based on that I would suggest to create one b-tree index having 8 columns (even though that it seems for me to high) this index should follow the following points:
    1) put the most repetitive column at the leading edge (and compress the index if necessary)
    2) put the columns that are used in equalitity predicate first
    3) put the column having the best clustering factor first
    The most precise index you have the best access you could gain.
    Of course that you have to know that an index access is not always good and a FULL table scan is not always bad.
    Best regards
    Mohamed Houri
    www.hourim.wordpress.com

  • Can Oracle be forced to use the spatial index for sdo_filter in combination with an or clause? Difference between Enterprise and SE?

    We’re seeing the following issue: sql - Can Oracle be forced to use the spatial index for sdo_filter in combination with an or clause? - Stack Overflow (posted by a colleague of mine) and are curious to know if this behaviour is due to a difference between standard and enterprise, or could we doing something else wrong in our DB config.?
    We have also reproduced the issue on the following stacks:
    Oracle SE One 11.2.0.3 (with Spatial enabled)
    Redhat Linux 2.6.32-358.6.2.el6.x86_64 #1 SMP Thu May 16 20:59:36 UTC 2013 x86_64 x86_64 x86_64 GNU/Linux
    11.2.0.3.0 Standard Edition and 11.2.0.4.0 Standard Edition (both with Spatial enabled)
    Microsoft Windows Server 2003R2 Standard x64 Edition
    However, the SQL works fine if we try it on Oracle 11.2.0.3.0 *Enterprise* Edition.
    Any help or advice would be much appreciated.
    Kindest Regards,
    Kevin

    In my experience sdo_filter ALWAYS uses the spatial index, so that's not the problem. Since you did not provide the explain plans, we can't say for sure but I think yhu is right: Standard Edition can't use the bitmap operations, and thus it'll take longer to combine the results of the two queries (because the optimizer will surely split this OR up in two parts, then combine them).
    BTW: when asking questions about queries here, it would be nice if you posted the queries here as well, so that we do not have to check another website in order to see what you are doing. Plus it will probably get you more answers, because not everyone can be bothered to click on that link. It would also have been nice if you had posted your own answer on the other post here as well, because my recommendation would have been to use union all - but since you already found that out for yourself my recommendation would have been a little late.

  • Not able to figure out the table index for Edit table User Properties Dialo

    Studio Edition Version 11.1.1.0.0
    Build JDEVADF_MAIN.D5PRIME_GENERIC_080403.0915.4920
    I'm trying to automate the various features in Jdeveloper dialogs. At one point I got struck with table in Edit Table Dialog.
    Right Click on New -> Database Tier-> Select APPS: Import to offline database Objects. Step 1- Step5 dialogs comes up. Click on Next till finish button comes up. After that one table along with xdf file will be shown in the Jdeveloper Tree Menu. Right click on Table, Go to Properties. Then Select User Properties in the Left Pane. On Right Side table will be shown. I want to know what is the index for this table and also I need to input certain text and select some drop downs from this table.
    Automation Tool: JFCUnit
    Could you please tell how can I put values in some of the fields and select the values from the drop downs.
    Kindly let me know if you need any more Information for the same.

    Hi,
    if you are from Oracle, please use an internal forum. If not, the JDeveloper 11 forum is at: JDeveloper and OC4J 11g Technology Preview
    Frank

  • How to delete the index for the business object BUS0033

    Hi to all experts,
    I'm applying note 1349496 the error here is no records with F4 help for the funds center .
    solution from the note
    Implement the attached program corrections. Then, in the transaction, delete the index for the business object BUS0033, reactivate it, and start the indexing in the indexing mode "Full". The system then displays the data correctly in the F4 search help.
    how to do the second part i have already applied the note .

    any help

Maybe you are looking for

  • Xcelsius 2008 - Known Issues (Application)

    AA: Area Affected PD: Problem Description WA: WorkAround AA: How to recover from an Xcelsius crash PD: If Xcelsius crashes during use, it may leave an orphan Excel process running in the Windows Task Manager. This is most often seen when you can't re

  • Black background affect letters on top

    Hi folks, Still a rookie I am, using Ai (CS6). I've produced a poster I'm fairly happy with, but black background is affecting red and green type on top of the black... Possibly one hint towards a solution is that I have one photo with a transparency

  • CSS Save Error

    Hi everyone, Ever since I installed CS4 and I try to right-click and "Save All" I get a pop-up window stating "UpdateLinks?" and no matter whether I choose yes or no, it is immediately followed by another pop-up that states "file:\\siteabc\www\xyz.cs

  • Timer function in Gigaframe Q80

    Dear Toshiba. I have bought a Gigaframe Q80 (model PA3650E-1ES1). On the packing is the features listed including ''Clock, alarm & timer function''. The manual hold information about how to use the clock and the alarm. But how do I use the timer func

  • Keyboard increment changes from 1 pt by default to 1296 0000 pt

    After placing any file (using File - Place command) the values in the preference dialog box increase dramatically. E.g. Keyboard increment changes from 1 pt by default to 1296 0000 pt and Type Size/Leading from 2 pt to 72 00 pt. In short it is imposs