LDAP Group is empty while the LDAP group have 150 users

Hi,
My BOE is mapped to the corporate LDAP, and the LDAP group is already mapped to a BO group.
The problem is that the LDAP Group is empty while the LDAP group have 150 users.
Currently, just after each user login at the first time the user is created under the BO Group.
Is there any way to populate the BO Group automatically?
Best Regards,
DoronS

Hi,
yes there is. Check your LDAP Authentication Tab and select "Create new aliases when the Alias Update occurs"
It should be under your Alias settings.
But please note that you than require 150 licenses. So each users gets a license even if he doesnt use the BOE System but is part of the LDAP Group.
Regards
-Seb.

Similar Messages

  • Active Directory LDAP integration; can not see the XMLP_ groups/roles

    We have configured XMLP 10.1.3.3 to use "LDAP" as the Security model. The LDAP server is Active Directory running under Windows Server 2003.
    It is working to a certain extent:
    Users can log on to the XML Publisher using login/password as defined in AD.
    -When logged in as administrator, groups (roles) are visible in Admin/Roles and Permissions and can have assigned folders and data sources.
    Problems/questions:
    The required roles ("XMLP_ADMIN, etc) can not be seen in Admin/Roles and Permissions. Is this as expected or is it an error?
    -When logging in as a user who is member of the group/role XMLP_ADMIN, I do not get any administrator privileges (I have not tested the other XMLP_* roles defined in AD yet). So all administration has to be done as the local superuser.
    Is there any way to monitor the login process to try and see what goes wrong?
    -Roald
    -Roald

    The problem has been solved, it was self inflicted, typo in the config file:
    <property name="LDAP_PROVIDER_USER_DN" value="Cn=Users;dc=company,dc=com"/>
    (semicolon instead of comma after Users).
    It is a little surprising that this typo lead to problems with group matching, though. It took some time before this part of the config got enough attention.
    -Roald

  • How to send a group email, always to the same group?

    I am trying to send a group message on my Mail app on all devices , iMac and ipone, I have created a group on contacts but it only gives me the names and then I would have to choose each email.  I would like to send an email to the same group of emails, maybe just by tapoping the group name on my Mail app, Is this possible?  Thanks..

    You can't send an email from the Mail app to an address book group, I'm afraid. You will need an app to do that.
    Our MailShot Pro app is unique in helping you create special contacts in your address book that you can use directly from Mail and other compatible apps, as though the feature was built in. You can easily import an address book group into a MailShot group.
    A free version is also available to try, limited to smaller group sizes.
    Peter
    Soluble Apps
    Disclosure: as the developer of MailShot Pro, I may receive a benefit from its sale.

  • Alternating colors with drilldown groups not showing in the primary group.

    Hi all,
    Not sure if it is possible in SSRS but... My alternating colors work in my row groups of the drilldown group, but I also want the primary group (in my screenshot category) to be colored as well. Is this possible at all when my structure is like below?

    Hi Yvanlathem,
    According to your description, you want to set the textbox background color only for the even rows within child group. Right?
    In this scenario, we can put expression into Fill tab in Textbox Properties. We can use IIF() and RowNumber() to make the background color only apply on the even rows. Try the expression below:
    =IIF(RowNumber("Parent Group Name") mod 2=0,"Color1","Color2")
    We have tested in our local environment. It looks like below:
    If you have any question, please feel free to ask.
    Best Regards,
    Simon Hou

  • How can I configure FireFox security setting globally for all users on a PC? Is there something I can do in group policies or throught the registry to insure all users have the same settings?

    Our Bank's core processor has rewritten their product to run in a web browser. Their browser of choice is Firefox 3.6. The specifications from our core processor specify specific security and settings parameters that must be adhered to by all users for their product to run properly. Is there a way to globally configure these settings via the registry or group policies to insure everyone who logs in to a given workstation opens Firefox with the same settings? Thank you for any assistance you can provide - Steve Gish, First Bank Kansas.
    == User Agent ==
    Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)

    You can try:
    *http://kb.mozillazine.org/Locking_preferences

  • How to display group data only when the particular group is clicked

    Hi frnds,
    I want to design my report as follows:
    Data is grouped by country, and for each country it is showing details for that country. I need to find out a way to display all group names first.  E.g.
    Argentina
    Aruba
    Australia
    And on click of particular country name it should display its details below it
    e.g.
    -Argentina
         BBB            Mendoza          123456
    +Aruba
    +Australia
    Has anyone done that before??? Is it possible to achieve it through Crystal Report Designer (2008)?? If yes then how???
    A prompt reply would be appriciated as i need this information urgently.
    Thanx.

    Thanx Jehanzeb,
    The sample u suggested did not solve my problem since it is opening the group data in new window.
    My question is - can we show/hide group data by clicking on that particular group (under that group name).
    e.g.
    ->(initial display - only groups)
    + Australia
    + America
    + Bhutan
    ->(on clicking a group)
    + Australia
    \- America
    abc    xyx    12213213    wqe9090
    dsd    dcv     90eur90e    ifjjdioifdoi
    + Bhutan
    In short, I am looking for on-demand display of records grouped by some field and the expansion of data must be done in the same page.
    Edited by: Kuldeep Chitrakar on Aug 6, 2008 12:44 PM
    Edited by: Kuldeep Chitrakar on Aug 6, 2008 12:45 PM
    Edited by: Kuldeep Chitrakar on Aug 6, 2008 12:46 PM

  • Is possible create in the contacts app, new groups, copy contact from one group to another group, and create in the business group, field to put the pictures of business cards. I think it would be a great idea, no?!

    App Store, Contacts App

    We are only other users here.
    Share the idea with Apple as feedback about the iPad;
    Apple Feedback
    http://www.apple.com/feedback/

  • How to set user/group in BIEE11G by the information stored in DB

    Hi everyone,
    I'm using OBIEE11.1.1.6,
    I'd like to ask are there any way to achive this requirment:
    I have stored user/group information in DB,the format as follow:
    ID USER GROUP
    1 A G1
    2 B G2
    so can we obtain the information from DB,then we set these information into BIEE security?
    i.e we can access BIEE by the USER stored in DB. and the GROUP can be used in BIEE security.
    thank you in advance!

    Hi,
    I am able to open the below link.
    http://www.varanasisaichand.com/2011/09/external-table-authenticationorder-of.html
    Follow the steps:
    Order of Authentication:
    The Oracle BI Server populates session variables using the initialization blocks in the desired order that are specified by the dependency rules defined in the initialization blocks.
    If the server finds the session variable USER, it performs authentication against an LDAP server or an external database table, depending on the configuration of the initialization block with which the USER variable is associated.
    Authentication against the identity store configured in Oracle WebLogic Server Administration Console occurs first, and if that fails, then initialization block authentication occurs.
    If you configure your external table authentication as in OBIEE 10g when the session variable USER is associated to the initialization block and LDAP server fails to get the respective user then the user's will authenticate(Identify store) over database(table).
    Dont forgot to create Catalog group as we do normally in 10g
    In 11g Analytics - Administration- Security - Manage Catalog groups -- (+) to add new groups and set permissions to the catalog folders w.r.t groups/users.
    Please refer this link you will get more information
    http://www.orastudy.com/oradoc/selfstu/fusion/bi.1111/e10543/legacy.htm
    Award points it is useful.
    Thanks,
    satya
    Edited by: Satya Ranki Reddy on May 3, 2012 12:53 PM

  • How does the LDAP authentication process?

    Hi All,
    In SAP KB1384915(https://bosap-support.wdf.sap.corp/sap/support/notes/1384915), BOE client authentication's process is described as follows:
    1. The BOXI SDK calls the login on the BOXI client plugin (passing username & password).
    2. The BOXI client plugin passes the username and password to the third-party authentication server. This may be an LDAP server, or a Windows Active Directory server, or any other server that the BI Platform supports.
    3. The third-party authentication server authenticates the credentials. This generates a security buffer needed by the BOXI server-side authentication plugin.
    4. The SDK passes the security buffer to the CMS, which forwards it to the server-side plugin.
    At this point the handshake process may be finished, or it may continue
    5. This exchange continues until the server-side authentication system indicates that the authentication process has completed.
    Authentication always ends on the server side.
    6. The user has been authenticated. The CMS must verify that the user is a member of a mapped group before the logon process can complete.
    Question about LDAP auth,
    I think that the client plugin doesn't know LDAP server's hostname & portnumber at the time of step2.(BOE server only knows it)
    So I think, the client will access to BOE server to get the LDAP-related informations before the step.
    Would you please tell me whether the following process is correct?
    1. The BOXI SDK calls the login on the BOXI client plugin.
    2. The client plugin gets LDAP-related information (LDAP hostname, portnum, base DN etc) from BOE server.
       At this step, client plugin DOESN'T pass the username&password to BOE Server. Only get informations.
    3. The client plugin passes the username and password to the LDAP server.
    4. The LDAP server authenticates the credentials. This generates a security buffer needed by the BOXI server-side authentication plugin.
    5. The SDK passes the security buffer to the CMS, which forwards it to the server-side plugin.
       At this point the handshake process may be finished, or it may continue
    6. This exchange continues until the server-side authentication system indicates that the authentication process has completed.
       Authentication always ends on the server side.
    7. The user has been authenticated. The CMS must verify that the user is a member of a mapped group before the logon process can complete.
    Thanks&regards,
    Tadashi

    Hi,
    in a BOE Environment the CMS does all of the authentication processes. So i would say that the Client passes the LDAP informations entered by the user to the CMS and the CMS does the authentication on behalf of the client.
    If you need an official Statement, i would recommend you open a Support Message with the SAP Support.
    Otherwise you could monitor the network traffic during the Authentication of the Client. There you should see if the Client communicates directly with the LDAP Host or only with the CMS.
    Regards
    -Seb.

  • How do i use WGM or dcsl to change the primary groups of users, defined by another group?

    i've got a ton of users, whose primary group is "current student". they all belong to the other group "year 13"
    they've left school, so i thought it would be easy to do a search of users with GID equal to or containing the GID for "year 13" (in this case 1121) and then change their primary group to "left school"
    except that doesn't work. i can only search for them in WGM by primary group, it seems. therefore i cannot do any batch operations on a secondary group.
    so. how do i do this? is there a way of scripting dcsl to find users by 'other group' and then change the primary group attribute?
    i'm going to need to be doing a lot of this (changing the other gropus of a school full of students). bit stumped.
    help!

    ok. for some reason neitehr root nor my account (which is part of the open directory admin group) can make changes using dscl.
    when addingremoving users from groups, remember that teh UUID has to be added/removed too
    this is getting there:
    old=year11
    new=year12
    for item in `dscl /LDAPv3/127.0.0.1/ read /Groups/$old GroupMembership | cut -d: -f2`
    do
    echo $item
    UUID=`dsmemberutil getuuid -U $item`
    case "$UUID"
              in
              "There is no uuid for user $item")
                        echo "user $item need personal attention"
                        dscl -u diradmin -P 'somepassword'  /LDAPv3/127.0.0.1 append /Groups/$new GroupMembership $item
                        dscl -u diradmin -P 'somepassword'  /LDAPv3/127.0.0.1 append /Groups/$new GroupMembers $UUID
                        if [ "`dsmemberutil checkmembership -U $item -G $new`" == "user is a member of the group" ]  ; then
                        echo "$item added to $new"
                        dscl -u diradmin -P 'somepassword'  /LDAPv3/127.0.0.1 delete /Groups/$old GroupMembership $item
                        dscl -u diradmin -P 'somepassword'  /LDAPv3/127.0.0.1 delete /Groups/$old GroupMembers $UUID
                                  if [ "`dsmemberutil checkmembership -U $item -G $old`" == "user is a member of the group" ]  ; then
                                  echo "removal of $item from $old failed"
                                  else
                                  echo "removal of $item from $old succeded"
                                  fi
                        else echo "append of $item to $new failed"
                        fi
              esac
    done

  • How to enable the target Group option "Dispaly target Group"  in WebUI

    hello All,
    I am Working on Market Role in CRM 7.0 here when we search for the segment from the Marketing Work center and select any one segment from the search i.e profile set .After that when we click on the graphical Modeler button  on the top . That takes to a view where in we can see icons with target group on the right top in the view when we right click on the icon we get options eg: count,export to file etc here we dont have an option call "Display Target Group" but this option is avaiable in the GUI . How can we get this option on to the webUI can any one help me out in this regards.
    Thanks in advace.
    Regards,
    Kiran Posanapalli.

    I don't think you can get a button like this. You are not supposed to view the content of the target group from within the graphical modeler. You have to see this from the traditional CRM WebClient user interface. There you will see the members of the target group when clicking on the target group name.
    From the graphical modeler the only thing you can do is to right click the target group and export it to a file.

  • How can I get the second group and report totals in Matrix report?

    Hi,
    I have created a matrix report with 2 break Groups.
    Iam getting columns totals for the first group, but not for the second group and the report totals.
    How can I get the second group and report totals for each month?
    Thanks.
    Ram.

    Hi Ram,
    If you want a total at any group-level, go to the particular group in the data model, insert a summary column in the group, and select
    Reset At > appropriate Group Name
    For report level summaries, you must create the summary column outside of all groups.
    Navneet.

  • How to implement the Oracle Group by function in Crystal reports?

    Hi all,
    In SQL, for example we have a group function like:
    select  district,state, country, continent, sum(no.of people) from world.
    Now, How to implement this group function in crystal reports? Please advise.
    Thanks in advance..
    Regards,
    sriram

    Hi Vinay,
    Thanks for the prompt reply.
    In one of our report, we are supposed to perform group by for 14 columns to get sum of 3 columns and there by displaying 17 columns in the report.
    When we tried in crystal reports to implement this oracle group by functionality:
    1. We created 14 groups from the Insert->Group option.
    2. By performing this, we got 14 group sections vertically(one inside the other).
    3. Then we created the sum(15th column),sum(16th column), sum(17th column)  by Insert->Summary option.
    4. We suppresed all the group sections except for the last group.
    5. Then, dragged all the groups to the last group section along with the summary fields.
    This is how, we tried to acheive the oracle group by function in Crystal reports.
    Please advise, whether our approach is right. If not, please suggest the appropriate approach with a bit detailed explanation.
    Thanks,
    Sriram.

  • The LDAP server is unavailable after installing KB2868725

    After installing the KB2868725 Windows Update, a strange LDAPs connection problem occur.
    Context : we have a C# web site (.NET 4.0) that perform an LDAPs Bind operation over LDAPs. The web server is not on the same domain (bind operations are perform again multiple LDAPs Server), and the code work like a charm more than a year.
    So after installing the KB2868725 Windows Update we get a “System.DirectoryServices.Protocols.LdapException: The LDAP server is unavailable.” exception from the same application. When we uninstall the update, the error stop.
    The problem is present ONLY over a SECURE connection.
    We have multiple web server in production and every server where the KB2868725 Windows Update is not installed are working perfectly.
    We build a test application with this simple code, work fine on “non-KB2868725 updated server”:
    void BindLDAP()
    LdapDirectoryIdentifier ldi = new LdapDirectoryIdentifier("example.com", 636, true, false);
    LdapConnection ldapCnn = new LdapConnection(ldi, new NetworkCredential("myUsername", "myPassword"), AuthType.Basic);
    ldapCnn.SessionOptions.VerifyServerCertificate = new VerifyServerCertificateCallback(Validate);
    ldapCnn.Bind();
    private static bool Validate(LdapConnection connection, X509Certificate certificate) { return true; }
    Stack trace:
    System.DirectoryServices.Protocols.LdapException: The LDAP server is unavailable.
    at System.DirectoryServices.Protocols.LdapConnection.Connect()
    at System.DirectoryServices.Protocols.LdapConnection.BindHelper(NetworkCredential newCredential, Boolean needSetCredential)
    Server: Windows Server 2008 R2 Standard, Service Pack 1 (64-bit)
    We tried to change every connections settings, change .NET version (2.0, 3.5 and 4.0), build the test application directly on the server and nothing work.
    If we use others LDAP tool (like http://technet.microsoft.com/en-us/sysinternals/bb963907.aspx) the problem also occur : “The server is not operational.”
    Moreover, if we installed these updates the problem also occur: KB2574819, KB2830477, KB2871997, KB2592687.
    We can’t install any Windows Updates, that’s a problem. We would like to find a solution, please help us ;-)

    Hi,
    The server is configure to get the Windows Update from a WSUS server. Those updates are downloaded from Microsoft. 
    I follow these steps:
    1. Uninstall Windows Update : KB2574819, KB2830477 (KB2857650) and KB2913751;
    2. Perform a LDAP connection test : work perfectly;
    3. Install Update KB2574819;
    4. Perform a LDAP connection test : not working (The LDAP server is unavailable.);
    5. Install Update KB2830477 (KB2857650 is include in KB2830477 update);
    6. Perform a LDAP connection test : not working (The LDAP server is unavailable.);
    7. Install Update KB2913751;
    8. Perform a LDAP connection test : not working (The LDAP server is unavailable.);
    The problem here is we can’t install KB2574819, KB2830477 (KB2857650) and KB2913751 on our productions servers because of the connections problems (install process work fine, is the effects of these Windows Updates).
    Philippe Bernier

  • Error in assigning the tax group

    Dear all,
    i am facing problem KO88 FOR AUC SELTMENT error is "Error in assigning the tax group"
    Error in assigning the tax group
    Message no. FF716
    Diagnosis
    To guarantee a connection between the automatically created tax items, the initiating line items, and the tax information used for reporting, a unique code is assigned to the line items belonging together. An error occurred during this assignment.
    Procedure
    Contact your system administrator.
    Procedure for System Administration
    Create an OSS message
    Please guide me how to sole the problem
    regards
    Raj

    Dear:
                    Please apply OSS note  1292730 . In some instances it happens so that a tax procedure is assigned to company (Check in OY01) that does not use jurisdiction code but you have maintained settings in OBCL you have maintained settings for tax jurisdiction code for the co code. This mismatch may result in this error. Please check and revert back.
    Regards

Maybe you are looking for