Jabber Directory Integration in hybrid mode

We are running Jabber in cloud/hybrid mode.  Meaning we use WebEx connect cloud for IM/Presence but use our on premise CUCM for voice services.  This works great for the most part.
We recently had Cisco enable "Directory Integration" for our ORG domain.  This allows us to export our users from AD, create a CSV file and then upload this CSV file to Cisco's SFTP server to be imported into Jabber.  Everything is scheduled and requires no user intervention to add/deacitvate users.  We have the import working and are able to get accounts created.  The problem is that enabling Directory Integration has disabled our ability to manually update user profiles and our users ability to upload their contact photo from the Jabber client. 
From the docs it looks like we can specify a webserver that hosts our contact photos.  But this webserver would need to be wide open, no security so that Jabber can access the photos directly.  Seems like there has to be a better solution.  
Anyone else running a hybrid deployment and tackled the contact photos dilemma?

Hi Venkat,
Yes, we installed a Windows 2008 with AD-LDS. Configured CUCM to sync to this AD-LDS and then configured Jabber to use UDS (CUCM 8.6(2) feature). This way Jabber has (indirect) access to the multi-forrest AD data.
Used this document to configure the AD-LDS (https://supportforums.cisco.com/docs/DOC-16356
Regards,
Erik
PS. One thing we learned in this is that you've got to be carefull on selecting the "user-id" field. We initially used "mail" as the user id to make sure all accounts are unique but found out that when using Extension Mobility the user-id input on the phone doesn't accept very long usernames (which you might encounter when integrating based on the mail attribute).

Similar Messages

  • Error -65581 when using 9146 in hybrid mode

    I have a 9146 cRIO Expansion Chassis and I have FPGA code that uses two modules and I'd like to use the scan engine to read the other two modules (ie hybrid mode).  When I try to read scan engine module data, I get error -65581:
    "CompactRIO:  (Hex 0xFFFEFFD3) The bitfile currently running on the CompactRIO chassis is not configured to support using the RIO Scan Interface in this slot. In the LabVIEW Project window, move the module in the slot from under the FPGA target item to under the chassis item, then recompile the bitfile."
    I recompiled my FPGA code and redeployed everything but it did not make a difference.
    Here is a snapshot of my lvproj file:
    I get the error (-65581) whether I read "Analog In" or "PV Read" IO variables.
    Note that my scan engine looks OK from Distributed System Manager:
    I can confirm the FPGA code is running (am blinking the FPGA LED in my FPGA code and can see it blink).  Also, if I switch from "FPGA" to "Scan Engine" mode, I can get the AI Readings to read without an error.
    I'm using the software below on my RIO:
    Thanks in advance!

    Upgraded to cRIO 2013SP1 and still have the exact same errors.  Once I deploy in FPGA mode, the scan engine modules do not update their IO variables (in Distributed System Manager the variable status says "connecting" instead of displaying the current value.  Do you have any other suggestions?
    Is Hybrid mode supported on cRIO 9146 (which is an Expansion Chassis)?

  • Help with Active Directory Integration and kerberos

    Hello,
    I’m encountering a bug preventing me to use Active Directory integration with kerberos :
    Our domain name is CORP.DOMAIN.COM.
    When we request the GC in this domain :
    bash-3.00# nslookup -query=any gc.tcp.corp.domain.com
    Server: 1.2.1.6
    Address: 1.2.1.6#53
    ** server can't find gc.tcp.corp.domain.com: NXDOMAIN
    there is no answer.
    But when we request without corp, we find the servers :
    bash-3.00# nslookup -query=any gc.tcp.domain.com | grep sis
    gc.tcp.domain.com service = 0 100 3268 serveur02.corp.domain.com.
    gc.tcp.domain.com service = 0 100 3268 serveur01.corp.domain.com.
    bash-3.00#
    Is-it possible to add the possibility to enter the domain name where reside the gc.tcp ?
    Thank you.

    Hello
    the domain.com domain exist, but it's not our domain.
    so, when I put domain.com, it search with no result (nothing appends).
    our kdc.conf :
    [kdcdefaults]
    kdc_ports = 88,750
    [realms]
    CORP.DOMAIN.COM = {
    profile = /etc/krb5/krb5.conf
    database_name = /var/krb5/principal
    admin_keytab = /etc/krb5/kadm5.keytab
    acl_file = /etc/krb5/kadm5.acl
    kadmind_port = 749
    max_life = 8h 0m 0s
    max_renewable_life = 7d 0h 0m 0s
    default_principal_flags = +preauth
    krb.conf
    [libdefaults]
    default_realm = CORP.DOMAIN.COM
    default_checksum = rsa-md5
    [realms]
    CORP.DOMAIN.COM = {
    kdc = dc01.corp.domain.com
    kdc = dc02.corp.domain.com
    [domain_realm]
    .corp.domain.com = CORP.DOMAIN.COM
    corp.domain.com = CORP.DOMAIN.COM
    in every domain, I think the GC are in corp.domain.com. but in my company, it's in domain.com...
    Thank you,

  • Active Directory integration: Invalid Token Error in Verification Service

    I'm having problems with Active Directory integration. I'm able to browse users in the task routing slip in JDeveloper. But I'm unable to login to the worklist application.
    Getting an "Invalid Token Error in Verification Service" error. Any pointers?
    <2007-06-12 21:40:36,843> <ERROR> <default.collaxa.cube.services> <PCException::<init>> Identity Service Configuration error.
    <2007-06-12 21:40:36,843> <ERROR> <default.collaxa.cube.services> <PCException::<init>> Identity Service Configuration file has error.
    <2007-06-12 21:40:36,859> <ERROR> <default.collaxa.cube.services> <PCRuntimeException::<init>> Identity Service Configuration error.
    <2007-06-12 21:40:36,859> <ERROR> <default.collaxa.cube.services> <PCRuntimeException::<init>> Identity Service Configuration file has error.
    <2007-06-12 21:40:36,859> <ERROR> <default.collaxa.cube.services> <::> WorkflowService:: VerificationService.destroyContext: invalid token: c9pHcmBFtc4q7/EY3xGAv/6hhfa6Hf5tllCb8ZYKtdSA/8/y0exRcwpjy0vWiWGgBPzuIh5Ur+l+ZHDNe0PKb9KiFScsKAG3JK1y+nIJtC827Rljhn8E+/BoF+ZIN6GFYn/iyo/6Mrlmz02Pg4QtetftO7eHJ01rEV5MmZFTXsg8iV6LQPnkAPjqmmsq+5bVYGGfSFpHX7FXk/0FrSabClKy6DKiwt/1Kp2Ldbj2RY8=
    <2007-06-12 21:40:36,890> <ERROR> <default.collaxa.cube.services> <::> ORABPEL-30503
    <2007-06-12 21:40:36,890> <ERROR> <default.collaxa.cube.services> <::>
    <2007-06-12 21:40:36,890> <ERROR> <default.collaxa.cube.services> <::> Invalid Token Error in Verification Service.
    <2007-06-12 21:40:36,890> <ERROR> <default.collaxa.cube.services> <::> Invalid Token Error in Verification Service. Received invalid token c9pHcmBFtc4q7/EY3xGAv/6hhfa6Hf5tllCb8ZYKtdSA/8/y0exRcwpjy0vWiWGgBPzuIh5Ur+l+ZHDNe0PKb9KiFScsKAG3JK1y+nIJtC827Rljhn8E+/BoF+ZIN6GFYn/iyo/6Mrlmz02Pg4QtetftO7eHJ01rEV5MmZFTXsg8iV6LQPnkAPjqmmsq+5bVYGGfSFpHX7FXk/0FrSabClKy6DKiwt/1Kp2Ldbj2RY8= in destroyContext
    <2007-06-12 21:40:36,890> <ERROR> <default.collaxa.cube.services> <::> Check the underlying exception and correct the error. Contact oracle support if error is not fixable.
    <2007-06-12 21:40:36,890> <ERROR> <default.collaxa.cube.services> <::>
    <2007-06-12 21:40:36,890> <ERROR> <default.collaxa.cube.services> <::>      at oracle.bpel.services.workflow.verification.impl.VerificationService.destroyContext(VerificationService.java:667)
    <2007-06-12 21:40:36,890> <ERROR> <default.collaxa.cube.services> <::>      at oracle.bpel.services.workflow.query.impl.TaskQueryService.destroyWorkflowContext(TaskQueryService.java:161)
    <2007-06-12 21:40:36,890> <ERROR> <default.collaxa.cube.services> <::>      at worklistapp.servlets.Logout.handleRequest(Logout.java:66)
    <2007-06-12 21:40:36,890> <ERROR> <default.collaxa.cube.services> <::>      at worklistapp.servlets.BaseServlet.doGet(BaseServlet.java:142)
    <2007-06-12 21:40:36,890> <ERROR> <default.collaxa.cube.services> <::>      at javax.servlet.http.HttpServlet.service(HttpServlet.java:743)
    <2007-06-12 21:40:36,890> <ERROR> <default.collaxa.cube.services> <::>      at javax.servlet.http.HttpServlet.service(HttpServlet.java:856)
    <2007-06-12 21:40:36,890> <ERROR> <default.collaxa.cube.services> <::>      at com.evermind.server.http.ResourceFilterChain.doFilter(ResourceFilterChain.java:64)
    <2007-06-12 21:40:36,890> <ERROR> <default.collaxa.cube.services> <::>      at oracle.security.jazn.oc4j.JAZNFilter$1.run(JAZNFilter.java:396)
    <2007-06-12 21:40:36,890> <ERROR> <default.collaxa.cube.services> <::>      at java.security.AccessController.doPrivileged(Native Method)
    <2007-06-12 21:40:36,890> <ERROR> <default.collaxa.cube.services> <::>      at javax.security.auth.Subject.doAsPrivileged(Subject.java:517)
    <2007-06-12 21:40:36,890> <ERROR> <default.collaxa.cube.services> <::>      at oracle.security.jazn.oc4j.JAZNFilter.doFilter(JAZNFilter.java:410)
    <2007-06-12 21:40:36,890> <ERROR> <default.collaxa.cube.services> <::>      at com.evermind.server.http.ServletRequestDispatcher.invoke(ServletRequestDispatcher.java:621)
    <2007-06-12 21:40:36,890> <ERROR> <default.collaxa.cube.services> <::>      at com.evermind.server.http.ServletRequestDispatcher.forwardInternal(ServletRequestDispatcher.java:368)
    <2007-06-12 21:40:36,890> <ERROR> <default.collaxa.cube.services> <::>      at com.evermind.server.http.HttpRequestHandler.doProcessRequest(HttpRequestHandler.java:866)
    <2007-06-12 21:40:36,890> <ERROR> <default.collaxa.cube.services> <::>      at com.evermind.server.http.HttpRequestHandler.processRequest(HttpRequestHandler.java:448)
    <2007-06-12 21:40:36,890> <ERROR> <default.collaxa.cube.services> <::>      at com.evermind.server.http.HttpRequestHandler.serveOneRequest(HttpRequestHandler.java:216)
    <2007-06-12 21:40:36,890> <ERROR> <default.collaxa.cube.services> <::>      at com.evermind.server.http.HttpRequestHandler.run(HttpRequestHandler.java:117)
    <2007-06-12 21:40:36,890> <ERROR> <default.collaxa.cube.services> <::>      at com.evermind.server.http.HttpRequestHandler.run(HttpRequestHandler.java:110)
    <2007-06-12 21:40:36,890> <ERROR> <default.collaxa.cube.services> <::>      at oracle.oc4j.network.ServerSocketReadHandler$SafeRunnable.run(ServerSocketReadHandler.java:260)
    <2007-06-12 21:40:36,890> <ERROR> <default.collaxa.cube.services> <::>      at com.evermind.util.ReleasableResourcePooledExecutor$MyWorker.run(ReleasableResourcePooledExecutor.java:303)
    <2007-06-12 21:40:36,890> <ERROR> <default.collaxa.cube.services> <::>      at java.lang.Thread.run(Thread.java:595)
    <2007-06-12 21:40:36,890> <ERROR> <default.collaxa.cube.services> <::> Caused by: BPEL-10555
    <2007-06-12 21:40:36,890> <ERROR> <default.collaxa.cube.services> <::>
    <2007-06-12 21:40:36,890> <ERROR> <default.collaxa.cube.services> <::> Identity Service Configuration error.
    <2007-06-12 21:40:36,890> <ERROR> <default.collaxa.cube.services> <::> Identity Service Configuration file has error.

    Hi Adina,
    thank you for your answer (questions)!
    We use 10.1.3.1 SOA Suite and the default jazn.com Security Provider and what we set at java.naming.security.principal property is oc4jadmin.
    It is interesting, we deployed again out EAR and now it works again! There is not Invalid Token Error exception, but we didn't change almost anything...
    Can we debug it somehow?
    Where does this bug come from?
    Thanks!
    ric

  • Tutorial: Azure Active Directory integration with Igloo Software

    Click reply and tell us what you think:
    Tutorial: Azure Active Directory integration with Igloo Software
    Markus Vilcinskas, Knowledge Engineer, Microsoft Corporation

    Hello
    Can you be little clear, what you have tested with Airwatch MDM cloud?.. which scenarios?.. 
    1) Device Enrollment ?
    2) Access to Airwatch console?
    3) Access to Airwatch self service portal?
    By following the steps We do not get it working at all. by the way some of the steps in this tutorial are unclear and outdated;  
    I finally personally figured out how things should look like, and  make it work but only with Device Enrollment scenarios from the mobile devices itself. not from the pc and browsers or from the Access panel.

  • RT: 9512 modules fault when using hybrid mode

    Hello, I am having an issue with my cRIO hyrbid setup. I am currently using Labview 2010, cRIO 9074, x1 NI 9234, and x3 NI 9512.
    Summary:
    What you are trying to accomplish?
    -I have built two VIs. One that acquired data from an NI 9234. This vi is the one that uses the FPGA due to 51.2kHz sampling frequency needs. The other is to control the motion and encoder reading of three NI 9512s (scan mode). They both work fine separately (on the same FPGA bitfile), but when I copy and paste the VI for the NI 9234 into the VI for the x3 9512s and click run, the motors fault out.
    What steps are necessary to reproduce any problems?
    click run on the attached (prepared program_2VItesting.vi).
    What steps, if any, you have taken to solve any problems and the results of your attempts
    -I have confirmed that if i run the two VIs separately, they work fine. The very first time i combine the two VIs the 9512s work for a second (i.e. the motors move a little). Then it faults. I then used distribution manager to clear the fault and run it again (note: there is no fault code, i just clear the red light on the module by changing to configuration mode then active mode). Every time after the first time the motors do not move at all.
    - I have confirmed that i did correctly setup the hybrid mode based on this kB:
    http://digital.ni.com/public.nsf/allkb/0DB7FEF37C26AF85862575C400531690
    I have attached the vi of the two VIs combined together(prepare program_2VITesting.vi). The top half is the copied and pasted FPGA program (as noted by the open VI reference) and the bottom is the scan mode (as noted by the timed loop). I also attached the seperate VIs (JustDAQ and prepared program) that can both function right now by justing pressing run.
    Am i just missing something simple here?
    Thanks,
    Troy
    Solved!
    Go to Solution.
    Attachments:
    prepared program_2VITESTING.vi ‏1369 KB
    prepared program_ThisWORKS.vi ‏445 KB
    JustDAQ.vi ‏930 KB

    Hello Troy_B,
    Thanks for the post, here is a useful KB describing how to use Scan Engine and FPGA simultaneously. Please take a look at this documentation and make sure you have everything configured correctly for Hybrid Mode.
    http://digital.ni.com/public.nsf/allkb/0DB7FEF37C26AF85862575C400531690
    Note:
    Hybrid Mode has longer compile time because the compiler has to combine the RIO Scan Interface bitfile and the FPGA code into one bitfile.
    The number of DMA FIFO's available for FPGA code is reduced since the scan engine uses 2 DMA FIFO's.
    Here is an example of what your final project should look like with Mod1 in Scan Mode and Mod2 in FPGA Mode:
    Hope this helps!
    Paul-B
    Applications Engineer
    National Instruments

  • How to start / stop Oracle Directory Integration service (Win 2k3 Server)

    I'm running a standard OAS 10.1.2.0.2 instance on Windows Server 2k3, and am having trouble starting and stopping ODISRV instances. Well, at least I think I am, because I can't find any way of telling if they're actually running.
    The System Components in the Application Server Control web page shows the following to be all up and running:
    HTTP_Server
    Internet Directory
    OC4J_SECURITY
    Single Sign-On:orasso
    Management
    Which is backed up by opmnctl:
    opmnctl statusProcesses in Instance:
    ------------------------------------------------+---------
    ias-component | process-type | pid | status
    ------------------------------------------------+---------
    DSA | DSA | N/A | Down
    LogLoader | logloaderd | N/A | Down
    dcm-daemon | dcm-daemon | 1988 | Alive
    OC4J | OC4J_SECURITY | 5008 | Alive
    HTTP_Server | HTTP_Server | 2800 | Alive
    OID | OID | 4956 | Alive
    In the Application Server Control, when I select the Internet Directory instance, and then the Status for Directory Integration, it shows two Directory Integration Servers, which correspond to instances I've previously started using oidctl. However, I cannot see any odisrv processes running. The only relevant processes appear to be 2 x oidldapd, 1 x oidmon, and 2 x opmn.
    When I try to stop these using oidctl, the command returns no errors, but these instances do not go away. There is also only one odisrv log file from a week or so ago that does not appear to get updated. It is very possible that I stuffed the parameters of these instances up when I started them, so they may well be in an invalid statr at the moment.
    So I have the following questions:
    - Is there anyway I can clear all these instances out back to a clean slate to start again?
    - Should I be using opmnctl to start an ODISRV instance, or should I somehow configure it to run under opmnctl startall?
    Thanks,
    Barney

    Once you register the integration server, OIDSRV should auto start using oidmon.
    To cleanup
    -- opmnctl stopall
    -- delete entries from ods.ods_process table, if there are any.
    -- Restart instance using opmnctl

  • Active Directory integration with call manager

    Hi,
    I am facing issues while Integrating the CCM to my Active Directory using AD Plug-in.
    SITE SETUP:
    1. Windows 2003 Parent Domain Controller located remotely with GC.
    2. Windows 2003 Child Domain for the Parent DC located Locally with GC.
    3. Cisco CallManager 4.1.3 sr3b
    My Requirement is to integrate CCM with my Windows 2003 AD.
    My Questions are:
    1. Do I need to Provide the Parent Domain name or the Child Domain name while performing the AD Plug-in Setup?
    2. Does my Call Manager need to have the Forest access of the Active Directory (i.e., Does it perform some modifications in the Parent Domain)?
    3. Does the user account (which is used for Directory Integration) need to have direct members of Schema Admins or thru some other domain admin groups (i.e., Admin user -> Child Domain Admins Groups -> Parent Domain and Schema Admin Groups)?
    Can anyone can help me on this?
    Thanks,
    V.Kumar

    1. Do I need to Provide the Parent Domain name or the Child Domain name while performing the AD Plug-in Setup?
    Use the root domain, in this case the Parent domain.
    Cisco does not recommend having a Cisco Unified CallManager cluster service users in different domains because response times while user data is being retrieved might be less than optimal if domain controllers for all included domains are not local.
    2. Does my Call Manager need to have the Forest access of the Active Directory (i.e., Does it perform some modifications in the Parent Domain)?
    Yes, actually all domains in the forest share the same Schema, which will be modified after running the AD plugin.
    3. Does the user account (which is used for Directory Integration) need to have direct members of Schema Admins or thru some other domain admin groups (i.e., Admin user -> Child Domain Admins Groups -> Parent Domain and Schema Admin Groups)?
    Account should be a member of the Schema Admins group in Active Directory, try the one in parent domain.
    Correct permissions for CCMAdministration and similar example for your setup:
    http://www.cisco.com/en/US/products/sw/voicesw/ps556/products_implementation_design_guide_chapter09186a00806e8c04.html#wp1043057
    HTH

  • Active directory Integration with OBIEE

    Hi all,
    Can any one send me a link for active directory integration with OBIEE.
    I have imported the users succesfully and I was able to login to analytics as an AD user.
    But SSO is not possible. Kindly help me over this.
    Thanks,
    Haree.

    Thanks for reply veeravalli.
    Me too followed the same link and successfully imported all the users from AD into OBIEE and login in is also possible.
    But my requirement is to have Single Sign On ie.., users may log on to their Windows PCs and access Oracle BI EE via a standard web browser with no further authentication required on their part.
    Thanks,
    Haree

  • Active Directory integrated LION with offline Domain Controller

    Hi,
    I have some OS X Lion machine, and all of them joined into the Win2008 AD. There is no any issue when the Domain Controller is reahcable, but when it is not reahcable, or the machine is not in the same network as the DC, then I am not able to login with my AD user.
    In Windows the last credential is stored on the local machines. So if the machine is OFFLINE from the DC, then it is able to let the AD user to login.
    Is there any trick or option how I can implement it with my LION clients? Or there is no way to use AD user when the AD is not reachable?
    Thanks in advance!

    He actually didn't specify much about dynamic updates requirements for old domains, if they don't need secure dynamic updates then a primary zone would work:
    The DNS Server service allows dynamic update to be enabled or disabled on a per-zone basis at each server that is configured to load
    either a standard primary or directory-integrated zone.
    REF: Understanding Dynamic updates
    This post is provided AS IS with no warranties or guarantees, and confers no rights.
    ~~~
    Questo post non fornisce garanzie e non conferisce diritti

  • Active Directory Integrated DNS Zones, replicate only to specific domain controllers

    I have a customer with a fairly large Active Directory forest with many domains that they are trying to consolidate into a single domain which likely take 18 to 24 months according to their timeline.  During this time, they would like all DNS zones
    to be serviced directly from the new domain controllers, meaning, domain A would have replicas of domain B, C, D, E, etc.  Because the environment is complex and some domain controllers in domains other than A are in a very sad state and replication problems
    abound, they would like to avoid replicating all zones forest wide.  
    I've never done this before, or even considered it necessary, is it even possible?  I don't have a ton of time for trial and error, but based on this there seems to be some hope:
    https://technet.microsoft.com/en-us/library/cc753801.aspx?f=255&MSPPError=-2147217396
    Is this telling me how to do what I want to do?
    Thanks
    J
    Joseph M. Durnal MCM: Exchange 2010 MCITP: Enterprise Messaging Administrator, Exchange 2010 MCITP: Enterprise Messaging Administrator, MCITP: Enterprise Administrator

    He actually didn't specify much about dynamic updates requirements for old domains, if they don't need secure dynamic updates then a primary zone would work:
    The DNS Server service allows dynamic update to be enabled or disabled on a per-zone basis at each server that is configured to load
    either a standard primary or directory-integrated zone.
    REF: Understanding Dynamic updates
    This post is provided AS IS with no warranties or guarantees, and confers no rights.
    ~~~
    Questo post non fornisce garanzie e non conferisce diritti

  • Directory Integration Platform Configuration Assistant hanging

    Hi,
    Installing 10gAS (10.1.2.0.2) infrastructure on Linux ES4 (64-bit) - High Availability cluster, node 1.
    The Directory Integration Platform CA is hanging when I retry it, it having previously failed probably due to a Load Balancer config error on my part (I had a timeout set too low (30s) and got "Broken Pipe" error message).
    Having fixed this LB config, hit retry on the CA (still in the OUI) but it is just hanging.
    Tried deleting the /tmp/EM_CONFIG_INSTALL.lk file, as per the install doc, and retrying but no success.
    I am on retry attempt no. 7 and previous attempt (I think attempt no. 4) reported the following in dipca.log:
    oracle.ldap.oidinstall.backend.OIDCAException: Invalid Credentials
    at oracle.ldap.oidinstall.backend.OIDConfiguration.sslbind(OIDConfiguration.java:814)
    at oracle.ldap.oidinstall.backend.OIDConfiguration.<init>(OIDConfiguration.java:144)
    at oracle.ldap.oidinstall.backend.OIDConfigWrapper.configDIP(OIDConfigWrapper.java:463)
    This log has not been written to since this attempt.
    Any ideas?
    Thanks,
    Gavin

    Hi,
    If the SSOCA falis, you may notice a Java Stack Trace. Can you please post the Java Stack Trace too ? It might give a clue about the problem.
    Regards,
    Sandeep

  • Directory Integration Platform Configuration Assistant - Invalid Credential

    O/S: SuSE Enterprise 9
    Situation: During the installer for Oracle Application Server 10g Basic Installation/Portal, I see the following error:
    "Directory Integration Platform Configuration failed. Please see lofile file: /home/oracle/product/10.1.2/OracleAS/infra/ldap/log/dipca.log"
    A review of dipca.log shows the following:
    "oracle.ldap.oidinstall.backend.OIDCAException: Invalid Credentials at oracle.ldap.oidinstall.backend.OIDConfiguration.sslbind(OIDConfiguration.java:787"
    The user authentication method set up on the server was local (/etc/passwd). Could this be my issue? If so, how do I correct it? Any thoughts as to what the issue is?

    You can have the BI, J2EE and webcache in a single midtier. That should not be an issue.
    The password for b2b stored in OID may be out of sync with the password you have set. Please find out what is the password in OID and then reset your b2b schema password with the password stored in OID. The way to locate the b2b password in OID is as follows:
    Login to OID and traverse through the following nodes:
    Entry Management | cn=OracleContext | Products | IAS | IAS
    Infrastructure Database | orclReferenceName | orclResourceName=B2B
    Hope this will resolve your problem,
    Eng

  • Insufficient access rights registering Oracle Directory Integration Server

    Hi all!
    following steps I´ve done to use the Oracle Directory Integration Server.(I´ve installed Oracle 10g infrastructure - OID is running - I´m also able to apply successful with ODM and orcladmin account)
    - oidctl connect=mydb1 server=odisrv instance=1 stop
    - odisrvreg -h localhost -p 389 -D cn=orcladmin,cn=Users,dc=localhost;dc=com -w ,pass
    where pass is the password of orcladmin.
    -> now I get the following error:
    registering..
    Error javax.naming.NoPermissionException [LDAP:error code 50: Insufficient Access Rights]; remaining name 'cn=odisrv+orclhostname=maschine,cn=odi,cn=oracle internet directory' !
    Any idea ??
    Thanks for all help & comments.

    I have gone through the documentation for creating the script. But there is one thing which I am not able to understand i.e. Subscription Parameters.
    Can anyone tell me the use of subscription parameters? What is the role of subscription parameters in Oracle Lite and External Authentication.
    Regards
    Kapil

  • VPN Settings iphone 3G: How to activate "hybrid mode"?

    In the web configuration utility there is an option for "hybrid mode". How can I activate it manually, without using the enterprise deployment? There is no option for this in the CISCO ipsec tab.

    Try these steps...
    -Remove the SIM card.
    -Verify that the SIM card is not damaged or dirty, then reinstall the SIM card.
    -Try turning iPhone off and then on again.
    -Wait approximately two minutes, then see if iPhone detects the SIM card and if it will register on the network.
    -If that doesn't work, try another SIM card for that carrier, if possible, to see if it is detected.
    -If the message still exists, please go to: apple.com/support/iphone/service/faq/ for information on service.
    You may need to restore your phone... http://support.apple.com/kb/ht1414

Maybe you are looking for

  • Payment to vendors though bank transfer

    My customer wants now to change vendors payment through APP with bank transfer instead of Cheque Payment. Please guide

  • AirPort Express and Canon MX310

    Hello I am trying to setup my Canon MX310 via AirPort Express: Today i bought the AirPort Express and everything works fine. But printing does not work at all: I usually connected my printer directly via USB to my iMac. When i did that the first time

  • My mac air keyboard has died? Any ideas?

    My air keyboard has stopped working. My mouse /cursor still moves. Have tried to reboot but cannot enter password to login when I open sign in screen. Help?

  • Freeze while booting from disk

    Hi everyone, long time Mac owner, first time poster. I have a problem.  I have been the proud owner of a macbook pro 13' for a few years now.  Recently I have felt the need to upgrade my laptop to include more memory and a SSD hard drive. Below is th

  • Help..Ipod is corrupted. Says to restore but there is no way

    I just updated my ipod(30GB) with new stuff..and suddenly it froze. I unplugged it..plugged it back in..restarted itunes and when i did a box popped up saying that the ipod is corrupted and i need to restore it. But how can i restore it if itunes isn