Missing roles in Shared Services 9.3.1

We are going through an install of 9.3.1 at a clients site. Planning is working correctly with shared services, but Financial Reporting is throwing this error found in SharedServices_security.log:
2008-05-02 11:53:50,718 [ExecuteThread: '13' for queue: 'weblogic.kernel.Default'] WARN com.hyperion.css.spi.impl.nv.NativeProvider.getHierarchicalRoleTree(Ljava.util.Map;Ljava.lang.String;Lcom.hyperion.css.common.CSSRoleNode;Ljava.lang.String;Lcom.hyperion.css.spi.util.jndi.CSSDirContext;Ljava.util.Locale;Ljava.util.ResourceBundle;)V(Optimized Method) - Exception getting Child Roles in hierarchy due to Illegal or invalid id.dflt passed in. Please check the argument.
When attempting to connect from Financial Reporting Studio or Workspace we get an error stating:
"You are not authorized to use this functionality. Contact your administrator."
We are running WebLogic 8.1 service pack 4 on Windows Enterprise server 2003 sp1.
If anyone has seen or worked through this error, please respond.

Got resolution on the error. Look for css-9_3_1.dll in HYPERION_HOME\common\css\9.3.1\bin on the server where Financial Reporting is installed. This dll enables FR to communicate with NTLM. Oracle support stated that "This dll is not included in the PATH by default because nobody uses NTLM anymore." When I asked them why it was not documented despite the fact that NTLM continues to be listed prominently as a supported authentication repository, they had no reply. Watch for this one to bite you!!!

Similar Messages

  • Task List Access Manager Role in Shared Services

    Hi
    The documentation says this role "Assigns task lists and tasks to other users". I have assigned this role to a group (in Shared Services), I have given that group Manage and Assign access to the Task List (in Planning), and have even done a security Refresh.
    Yet, when I go in as a user who is in that group, I do not see the Assign Access button in Manage Task Lists.
    Is this a bug or have I missed a step?
    We are on 11.1.2.1
    Thanks!

    Hi,
    Have you tried generating a provisioning report in Shared Services, have a read of :- http://download.oracle.com/docs/cd/E10530_01/doc/epm.931/html_cas_help/provrep.htm
    If that doesn't suit your requirements then you could always have a look at using CSSImportExportUtility to export provisioning to a csv file. The utility is located in hyperion\common\utilities and has a pdf on instructions how to use it.
    Cheers
    John
    http://john-goodwin.blogspot.com/

  • Essbase Application Doesn't show up in Selected Roles in shared services

    Hello all,
    I have few essbase applications which donot show up in the"Selected roles" column in Shared services though the user has been provisioned with the application. Infact the provisioned users can access the application based on the provisioning, but just that I as an administrator donot see it there in the selected roles department. Again this is only in "Selected roles" column meaning I can see it in the "Available roles" column. The application has been registered in EAS and I have also refreshed the security in EAS. We are on 11.1.1.4. Any ideas anyone?
    Thanks,
    Ted.
    Edited by: Teddd on Jan 10, 2013 9:43 AM

    Working with Oracle on it, they think it is a bug.

  • HFM roles in shared services

    We have several users that need to be able to consolidate and translate without all other admin functions.  Have tried to create a group and individually provision users with consolidate all but does not give consolidation ability unless given app admin.
    How do we give them only the ability to consolidate and translate?

    Try the FM Forum - https://forums.oracle.com/community/developer/english/business_intelligence/performance_management_applications/financial_consolidation
    FM HSS Roles - http://docs.oracle.com/cd/E40248_01/epm.1112/hss_security_user_role/frameset.htm?apas05.html
    Cheers
    John
    http://john-goodwin.blogspot.com/

  • Shared Services 11.1.2 + Provisioned Roles for Business Rules not reflectin

    Hi,
    I have provisioned users to have 'Basic' role in shared services for Business rules. We are using Calc manager + classic planning app. However users are unable to see the business rules associated with the forms due to which the rules dont run on save. Is there a intermediary step which I am overlooking?
    Regards,
    N

    Please ignore this question. I guess i posted in the wrong place. Not sure how to remove the thread

  • Reg: Hyperion Upgradation from 7.1.x to 9.3.x and Shared Services...

    Hi Everybody,
    New to this forum and i want to know about upgrading the essbase from 7.1.x to 9.3.x...As i gone through PDF, it is mentioning as upgrading of 9.3.x from earlier versions prior to release 9.2.x cannot be done directly...Here comes with the migration/upgradation topic wherein... Can we go ahead and install essbase 9.3.x on new box and migrate app's / db's from 7.1.x old box?
    One more thing is like...if we are using External authentication using LDAP in 7.1.x version for security....will it be mandatory to implement shared services separately in system 9 or continue with native security mode without installing shared services...I have only essbase and no other tools implemented...
    Hope u guys understand my queries!...If any body can explain on these two aspects...will be of great help to me...
    Thanks for the help in advance!!

    Hi,
    You will have to migrate the Essbase server from 7.1.2 to 9.3.1
    The steps you will follow are as below: --
    1. Configure Essbase on new environment, 9.3.1 by using the same user as on 7.1.2 [THIS IS AN IMPORTANT STEP, TO MIGRATE SECURITY]
    1. Take data exports of all application/databases in old environment
    2. Take backups of all Essbase objects, including essbase.sec in old environment. Take security file backup after stopping Essbase 7.1.2
    3. Create the applications/databases with same name in new environment 9.3.1
    4. Copy the outlines and open outline in EAS in 9.3.1 and save them again.
    5. Copy all objects, rules, reports, calc for all applications.
    6. Stop essbase, Eas in new environment and copy security file from old environment to new environment Take backup of Essbase.sec on new environment
    7. Start Essbase 9.3.1
    8. Validate all databases using Esscmd "validate" command
    9. Reimport all data and run default calc on all applications.
    10. Now, you have the security in new Essbase server, as in old environment
    11. Externalize the security in EAS.
    Caution: When you migrate to Shared Services, Essbase users and groups are converted to equivalent roles
    in Shared Services. Shared Services creates a superuser with the user ID named “admin,” which
    is read-only. If Essbase contains a user ID named “admin”, that user ID cannot be migrated to
    Shared Services. Before migrating, change the “admin” user ID (for example, from “admin” to
    “asadmin”).
    It is not compulsory to use shared services with Essbase 9.3.1, if you have Essbase only.
    but since it the way to go, you will have to migrate your essbase security to shared services.
    Let me know if it helps, by defining the reply as answered, Helpful or correct.
    Cheers
    RS

  • Shared Services Delegated Admin

    Hi,
    I am trying to create a delegated administrator role in Shared Services for HFM. I have created the delegated list in Shared Services and assigned a manager to the group. However when I log-in as that user I am only able to view the groups I have assigned to the delegated list, I am not able to provision users to those groups.
    Any ideas on what needs to be done so that group manager can provision users to the groups?

    You want to look at the Hyperion Security Administration Guide to understand Shared Service, Provisioning and External Authentication.
    http://download.oracle.com/docs/cd/E10530_01/doc/epm.931/hyp_security_guide.pdf
    Brian Chow

  • IC WebClient Shared Services Business Roles

    Dear All
    I have a question regarding the some of the IC Webclient Shared Services roles provided by SAP.
    I know that as of CRM 7.0 EHP 1.0 SAP provides separate roles for Accounting Interaction Center, Employee Interaction center and ITDS- IT HelpDesk Role along with a  Shared Services Agent Role.
    I want to know that  is it recommended to combine the Accounting Interaction Center, Employee Interaction Center and IT HelDesk role into one role or the opporsite way of using separte roles for separate functions.
    Thanks
    Tarang

    Hello
    Well...it depends.
    If you want your agents to handle all types of calls and you don't have a big-big company with many employees and a big support desk, the best option (due to maintenance reasons) is keeping everything in a single business role with a multi account identification profile.
    On the other hand, if you have agents with separate and independent account, IT and employee tasks and your business processes are different depending on who is on the phone, you need three different business roles.
    So, to summarize, it depends on your project needs and your company size.
    Regards
    Joaquin

  • Shared Services: Role Assignment

    When I try to assign the privilege of "Server Access" from Shared Services to a user, clicking on
    Essbase:servername:1 -> Essbase:servername:1 the tree does not open, but opens Default Application Group -> Essbase:servername:1.
    If I add the privilege of "Server Access" by:
    Default Application Group -> Essbase:servername:1 -> Administrator -> Create/Delete Application -> Server Access
    user can't access to Essbase from Excel.
    in addition Essbase can not see the users created through Shared Services. Only the admin user is displayed.

    I faced the same issue with the server access role. If I provision an Essbase Application role , the User can access the particular application. However the user can access the application by just provisioning the Application Role anyway. Then why is there such a role called Server Access? I am using 11.1.2.0 version.

  • Hyperion Shared Services Import security files where to define roles-11.1.2

    Hi,
    I want to create the shared services security import file. Do anyone knows where to define the group or user roles for it. Earlier we have to changes in CSImportexport.
    Now in version 11.1.2.1 things are different.
    Do anyone knows about it.
    Thanks!!!!

    Thanks for the reply.
    I am taking export only first and this is what i got from export, if you see below under role id there are some codes generated internally, if I have to give any group different roles like planner, application creator, interactive user... where in csv file I can define those.
    #provisioning     
    project_name ----------     application_name     -----role_id     --------------------------------------------------------------------------------------------- product_typ--------user_id-------     user_provider     
    Default Application Group---     CPSPlan-----     native://DN=cn=HP:0003,ou=HP,ou=Roles,dc=css,dc=hyperion,dc=com?ROLE--     HP-11.1.2.0-------     admin--------Native Directory     
    Default Application Group---     CPSPlan-----     native://DN=cn=HUB:2,ou=HUB,ou=Roles,dc=css,dc=hyperion,dc=com?ROLE---     HUB-11.1.2.0-----     admin--------Native Directory     
    Default Application Group---     CPSPlan-----     native://DN=cn=HP:0001,ou=HP,ou=Roles,dc=css,dc=hyperion,dc=com?ROLE--     HP-11.1.2.0-------     devusr-------Native Directory     
    Default Application Group---     CPSPlan-----     native://DN=cn=HP:0001,ou=HP,ou=Roles,dc=css,dc=hyperion,dc=com?ROLE--     HP-11.1.2.0-------     OMBUsr-----     Native Directory     
    Default Application Group---     CPSPlan------native://DN=cn=HP:0003,ou=HP,ou=Roles,dc=css,dc=hyperion,dc=com?ROLE--HP-11.1.2.0-------     processadmin-----     Native Directory     
    Regards.

  • All external users are missing in Shared services.

    Hi All,
    We are on Hyperion System 11.1.2.. Today all of a sudden in production users are not able to log in. So logged in as admin (native user) to see whats going on. Surprised to see that all the groups are empty and all the users are removed from all groups. So when tried to add back its unable to find the external users.
    So some thing is wrong with external users.
    Any suggestions on how to fix or any one experienced similar issues?

    Got this same error in Shared Services 11.1.1.3 Was due to an Active Directory Domain Controller being decommissioned Here is a fix you might try, It basically refreshes your user database connection
    Log into Shared Services
    Click on “Administration” on the “Shared Services” toolbar
    Click “Configure User Directories
    Check the Radio button next to “Active Directory” (or the db your are experiencing the error) and then click “Edit”
    The next screen displays the connection info for “Active Directory”(or the db your are experiencing the error), nothing to change here, just click “Finish” and the connection refresh should start
    Re-start All Services
    Verify that you can now look up an external user without error

  • 'register with shared services' option missing while configuring eas

    I am facing some issues while configuring a new epm system:
    While configuring eas 11.1.2.0, I am not getting the option' Register with Shared Services'. but otherwise, the configuration is successful. As a result, I don't see the Business Rules option in Shared Services/Application Groups. But we are able to use eas console and do see business rules node in eas console.
    How do I get configurator to show this option?
    I was able to configure and register all other Hyperion applications.
    Thanks,
    Edited by: 784749 on Mar 28, 2012 12:35 PM
    Edited by: 784749 on Mar 28, 2012 12:59 PM

    One way is to use the registry tool though make sure you backup the shared services database before running the utility.
    It is located in <MIDDLEWARE_HOME>/user_projects/<instancename>/bin
    to change the status for EAS for HSS then run the following
    epmsys_registry updateproperty BUSINESS_RULES_PRODUCT/system_tasks_configuration/@hubRegistration Pending
    Now if you run the configurator again it should let you select just Essbase Administration Services, you dont need to select the child components.
    It should then registry with Shared Services.
    Cheers
    John
    http://john-goodwin.blogspot.com/

  • Analytic Server Application missing from Project in Shared Services

    Slowly rebuilding my trashed development server. However I cannot access the Essbase server via EAS without getting a network error 10061
    I noticed in my Projects list I do NOT have the server value for the Analytic Server project.
    Do I reregister with Shared Services on Analytic Services? If so I tried that to no avail...
    Looking for ideas.
    JTS

    Hi John,
    Did the following:
    1. Stop all services (this is development so all Hyperion products are on one box)
    2. Renamed essbase.sec to essbase.secold
    3. Made copy of essbase.bak_preUPM and then renamed the copy to essbase.sec
    4. In configuration utility, selected Essbase Server and register with Shared Services and Analytic Server services
    5. Started the hypservice
    6. Went to Shared Services. Application is not under project grouping Analytic Server
    This was a really hosed server and I have been putting it back piece by piece. In the error logs it is as clear as day. It cannot find the application Analytic server.
    Any other way to trigger this to work? What if I took the AAS database from production, restored it then registered?
    JTS

  • Hyperion Shared Services -- External user containers getting missed out .

    Hi All ,
    In my hyperion enviornment user authentication is done through native directory and also through External directories configured to LDAP - OIDM . Frequently the external containers are getting disappeared from the shared services console. But when i restart the services its getting back some time. Some times it take some time to reflect back. I dont understand why this is happening.Quick hep is appreciated.
    Thanks,
    roshi

    It was network problem

  • New group in Shared Services does not come up in projects?

    Hi All,
    I'm working on a system that has externalized security, and we use Hyperion Shared Services to add users to groups and assign filters to groups.
    I have just added a new group in the analkytic server in shared services, I have also provisioned it to have filter access of a particular DB.
    When I go to the projects folder and check the list of groups under the application, to look for this group so I could assign the filter, I dont find the group listed.
    Does anyone know what I am missing out on.
    Thanks in advance.
    Anindyo

    Hi John,
    I tried to delete the group and create a new group again:
    searched for the group, right clicked on it and clicked on Provision.
    Then I expanded the Analytic server tree to the left, selected server Access, and moved it using the arrow button.
    Then I expanded the DB name, there were "Provisioning Manager", "Application Manager" and "My Role".
    I expanded the Tree of "My Role" and found "Calc", "Filter" and "Read".
    I expanded the tree "Filter", and found Start/Stop Application.
    I selected "Filter" (not Start/Stop Application) and moved it to the second list on the right using the Arrow button.
    Then I clicked on the save button.
    Now I expanded the Projects Folder:
    Clicked on the DB to which I provisioned this group.
    It showed the list of users and groups to the right.
    I selected groups in the drop down.
    Clicked on refresh, but the new group does not appear.
    Please let me know if I missed out on anything.
    Thanks for the response,
    Regard,
    Anindyo

Maybe you are looking for