MS AD in SAP EP SP12 (groups are found but not users)

Hi,
I have a problem with configuring MS AD for SAP EP SP12 (6.40). At the moment, in the portal I cannot logon with my AD users, but I can search for groups in AD. I've tried various different .xml config files, but now I am using the same settings as I did with an existing working SP2 portal.
I've looked at the documentation in http://help.sap.com/saphelp_erp2004/helpdata/en/cc/cdd93f130f9115e10000000a155106/frameset.htm
and if I use the config tool->UME LDAP Data <b>both the connection test and the authentication test works with my samaccountname. </b>
When I trace the authentication test I see the following packets:
1. BIND as my user defined in the settings
2. BIND successful
3. Search with BASEDN: OU=PEOPLE,DC=COMPANY,DC=NET
   Filter: (&(objectclass=User)(samaccountname=dapa))
   Attribute: objectclass
4. Response to search, found user
   Distinguised name: CN=Dagfinn Parnas,OU=Stavanger,OU=PEOPLE,DC=COMPANY,DC=NET
   Attribute: objectClass
   Value:top
   Value: person
   Value: organizationalPerson
   Value: user
5. Bind request with DN: CN=Dagfinn Parnas,OU=Stavanger,OU=PEOPLE,DC=COMPANY,DC=NET and my password
6. Bind successful
When I try to login to the portal, I can see the portal communicates with the AD server and sends the following packets:
1. 1. BIND as my user defined in the settings
2. BIND successful
3. Search with BASEDN: OU=PEOPLE,DC=COMPANY,DC=NET
   Filter: (&(objectclass=User)(samaccountname=dapa))
   Attribute: cn
   Attribute: description
   Attribute: uid
4. Response to search, found user
   Distinguised name: CN=Dagfinn Parnas,OU=Stavanger,OU=PEOPLE,DC=COMPANY,DC=NET
   Attribute: cn
       Value: Dagfinn Parnas
5. No more traffic
So it seems that it finds the correct user, but the portal doesn't do a bind against AD with this user and log me on to the portal afterwards.
<b>Could the problem be that only the cn attribute is sent back (not the description and uid which I asked for as well)?</b>
I tried setting mapping the uniquename to cn also(as described in http://help.sap.com/saphelp_erp2004/helpdata/en/1a/2bee408a63732ae10000000a155106/content.htm), but to no avail.
Some snippets from my config file
[code]
<principal type="account">
                         <nameSpaces>
                              <nameSpace name="com.sap.security.core.usermanagement">
                                   <attributes>
                                        <attribute name="j_user">
                                             <physicalAttribute name="samaccountname"/>
                                        </attribute>
                                        <attribute name="j_password">
                                             <physicalAttribute name="unicodepwd"/>
                                        </attribute>
                                        <attribute name="userid">
                                             <physicalAttribute name="null"/>
                                        </attribute>
                                   </attributes>
                              </nameSpace>
                         </nameSpaces>
                    </principal>
<principal type="user">
                         <nameSpaces>
                              <nameSpace name="com.sap.security.core.usermanagement">
                                   <attributes>
                                        <attribute name="firstname">
                                             <physicalAttribute name="givenname"/>
                                        </attribute>
                                        <attribute name="displayname">
                                             <physicalAttribute name="displayname"/>
                                        </attribute>
                                        <attribute name="lastname">
                                             <physicalAttribute name="sn"/>
                                        </attribute>
                                        <attribute name="fax">
                                             <physicalAttribute name="fax"/>
                                        </attribute>
                                        <attribute name="uniquename">
                                             <physicalAttribute name="samaccountname"/>
                                        </attribute>
                                        <attribute name="loginid">
                                             <physicalAttribute name="null"/>
                                        </attribute>
                                        <attribute name="email">
                                             <physicalAttribute name="mail"/>
                                        </attribute>
                                        <attribute name="mobile">
                                             <physicalAttribute name="mobile"/>
                                        </attribute>
                                        <attribute name="telephone">
                                             <physicalAttribute name="telephone"/>
                                        </attribute>
                                        <attribute name="department">
                                             <physicalAttribute name="ou"/>
                                        </attribute>
                                        <attribute name="description">
                                             <physicalAttribute name="description"/>
                                        </attribute>
                                        <attribute name="streetadress">
                                             <physicalAttribute name="postaladdress"/>
                                        </attribute>
                                        <attribute name="pobox">
                                             <physicalAttribute name="postofficebox"/>
                                        </attribute>
                                        <attribute name="preferredlanguage">
                                             <physicalAttribute name="preferredlanguage"/>
                                        </attribute>                                        
                                   </attributes>
                              </nameSpace>
                              <nameSpace name="com.sap.security.core.usermanagement.relation">
                                   <attributes>
                                        <attribute name="PRINCIPAL_RELATION_PARENT_ATTRIBUTE">
                                             <physicalAttribute name="memberof"/>
                                        </attribute>
                                   </attributes>
                              </nameSpace>
                         <nameSpace name="$usermapping$">
                                      <attributes>
                                           <attribute name="REFERENCE_SYSTEM_USER">
                                                <physicalAttribute name="sapusername"/>
                                           </attribute>
                                      </attributes>
                                 </nameSpace>
                         </nameSpaces>
                    </principal>
[/code]

Got it working by clicking twice the checkbox in front of the field  "Use UME Unique with LDAP unique".
This updated the value from uid to samaccountname (which it should have read from the config xml file allready)

Similar Messages

  • Sap xi SCENARIO source directory working ,but not working target directory

    sap xi SCENARIO source directory working ,but not working target directory..
    plz help me

    Hi,
    Be more specific on the problem you are facing so that the ppl here can help..
    looks like your are trying to file to file scenario and the file is not generating at the target folder ...
    then check the communication logs of the receiver adapter using RWB->CC logs..
    post the error you have received there..
    HTH
    Rajesh

  • Import is not available all other actions are active but not import help?

    Import is not available all other actions are active but not import help? I wish to import bookmarks from internet explorer, I am using windows 7

    Make sure that you do not run Firefox in permanent Private Browsing mode.
    *https://support.mozilla.com/kb/Private+Browsing
    *You enter Private Browsing mode if you select: Tools > Options > Privacy > History: Firefox will: "Never Remember History"
    *To see all History and Cookie settings, choose: Tools > Options > Privacy, choose the setting <b>Firefox will: Use custom settings for history</b>
    * Deselect: [ ] "Permanent Private Browsing mode"

  • Loops are installed, but not in Loop Browser

    Hi All!!
    I have just bought the four (newly packaged) GarageBand Jam Packs. I was so impressed with the demo "song" Victory (Full), that I have decided to use those loops for a project I am working on.
    The "Victory" loops all play in the loop browser (all 137 of them) when I have "Victory (Full)" loaded for playback in GarageBand.
    But.......
    When I start a new project, the Victory loops are not available in the loop browser. This is rather perplexing for me.
    What do I need? I need to find a solution to see these loops and maybe others that are missing (but not missing).
    Thanks in advance for your help.
    Rodger GW

    Yes. The demo song is in D, and I have ensured that I have set the new song to be in D.
    I have also trashed the preferences, trashed the indexes, rebuilt the loop browser by dragging the loop folders from all sources (sources being those defined by the install script), and ensured that the Keyword Browsing is unckecked and I have reset the keyword layout.
    The only thing I have not done is the laborious task of importing each of the 137 Victory files into the the track window then translating each individual part as an Apple Loop. The reason for this is two fold: 1. I am on the lazy side of life and think there should be a quicker way; and 2. I have checked the other files contained in Library -> Audio -> Apple Loops -> Apple -> Jam Pack 4 - Symphony Orchestra are available in the loop browser under the Jam Pack 4 and the Loops Pull Down Menu.
    I am very unsure of the next thing to try.
    Rodger GW
    PS I have even tried to have those loops from the "Victory (Full)" file be selected as favorites. They now reside in Home -> Library -> Audio -> Apple Loops -> User Loops -> SingleFiles, but do not appear in the Favorites tab in the Loop Browser in any new project.
    Thanks in Advance,
    RGW

  • I have ios7.1.2 on my iphone and am trying to upgrade to 8.0.2. I haven't installed 8 yet and when I try and upgrade nothing happens.  It says just the improvements from 8 are available but not the whole ios.  What to do?

    I have ios7.1.2 on my iphone and am trying to upgrade to 8.0.2. I haven't installed 8 yet and when I try and upgrade nothing happens.  It says ios8.0.2  improvements from 8.0.1 are available but not the whole ios.  What to do?

    It sounds like maybe 8.0.1 has downloaded onto your phone but not installed. You can check for it in Settings > General > Usage > Storage, Manage Storage. If it's there you should see it at the top of the list of apps. Swipe to delete it. 8.0.1 was pulled by Apple quickly after it was introduced due to issues and replaced by 8.0.2. Once it's deleted you should be able to download and install 8.0.2.

  • Iphoto allows you to share photos by selecting them and then emailing as an attachment.  I'm not able to do that now, curser isn't appearing in the email address box when I attempt to address my email.  Photos are attaching but not able to include an addr

    iphoto allows you to share photos by selecting them and then emailing as an attachment.  I'm not able to do that now, curser isn't appearing in the email address box when I attempt to address my email.  Photos are attaching but not able to include an address.

    Windows Phone 8.1 is so full of surprises and opens the Windows Phone faithful up to a new world of apps.
    Video editors and
    file managers are just some of the new app categories possible thanks to Windows Phone 8.1. We’ve seen an official video editing app from Microsoft already, but today we finally get Files – the official file manager for Windows Phone.

  • I can not right click "open in new tab" nor open in new window, in my bookmark file.the bookmarks are all there, but I have to open a tab first then left click to open an item. Why can't I right click? The options are there, but not highlighted/clickable.

    I can not right click "open in new tab" nor open in new window, in my bookmark file.the bookmarks are all there, but I have to open a tab first then left click to open an item. Why can't I right click? The options are there, but not highlighted/clickable.

    now it is working?! Go figure. Yeah! Thanks anyway......

  • Billing docs are generated but not account docs

    Hi
    Today I got a ticket which says billing docs are generated but not accounting docs. I went to vf05 and found that it is indeed true. accounting doc was not generated for one of the billing doc. How can I what went wrong and how to solve this.
    Will reward suitably. Plz help.
    Thanks

    Hope SD-FI integration is not properly maintained.
    This can be one of the reason. if the problem is related to GL account determination maintain it in VKOA.
    Assign points if useful
    Regards
    Raghu Ram

  • How do i make the back and forward buttons function? they are visible but not functional.

    I have firefox 8.0.1 and my back and forward button are not working. They are visible but not functioning. I have tried starting in safemode and without any add-ons and the back and forward buttons are still not functioning. What do I need to do to make the buttons functional?

    A possible cause is a problem with the file places.sqlite that stores the bookmarks and the history.
    *http://kb.mozillazine.org/Bookmarks_history_and_toolbar_buttons_not_working_-_Firefox
    *https://support.mozilla.com/kb/Bookmarks+not+saved#w_places-database-file

  • The training tutorials under creative cloud learn are loading but not playing

    The training tutorials in creative cloud learn are loading but not playing, is there a problem with adobe tv?

    Hi sarahhunter1,
    Please try playing video in Google chrome browser.
    Regards,
    Romit Sinha

  • How can I fetch the deliveries which are PGIed but not invoiced.

    Hi
    I want to search for the deliveries for which post goods issue has been done but are not invoiced.
    Kindly guide with you valuable comments.
    Regards,
    Satish.

    Hi,
    Use the T.Code:VF04.
    Goto T.Code:VF04
    Enter the Sold-to-party.
    Select Delivery related tick mark and uncheck all.
    Execute.
    It will give all the deliveries which are PGIed but not invoice.
    Regards,
    Krishna.

  • Safari 4.0.3 running OSX 10.6.1 -  Pages are loading but NOT thumbnails?

    Just upgraded to OSX 10.6.1 running Safari 4.0.3 last week - everything was working BEFORE the upgrade - but now for some reason I have an issue where pages ARE loading including larger banners, text flash animations etc, but if the site contains small thumbnails they are not loading.
    The icon in the web bar spins and spins for ages and then suddenly where the thumbnails should be I get the blue question make as if the links are broken - which there not as this is happening to well know sites such as youtube gettyimages and ebay and its just to the thumbnails?????
    Take ebay for example, the homepage page loads in fine, and if I search for a product - the page with the listing all loads but not the thumbnail images, yet if I click a listing the full page loads without a problem?
    Any advice, I have cleared the cookies and javascript database all to no avail?

    HI,
    Try Safari Maintenance
    Carolyn

  • DAC Task are queued but not running

    Hi Everybody,
    Currently we are running the ETL for only Financials and there are 394 tasks in total out of which 285 have been completed successfully. At times some of the tasks would just get stuck on particular action. For e.g The analyze task after dimension population would remain in the queued status and would never switch to run mode. So we had to abort the ETL and restart it. This action resulted in successful completion of the previously queued task. Now for past two days the ETL is once again stuck (queued but not running).
    For e.g The following task is showing status of running
    51     SIL_InventoryProductDimension_SCDUpdate     Running     2009-03-02 21:09:59.0                    DataWarehouse     DataWarehouse     SILOS          Update Slowly Changing Dimension     Informatica     0     0     -2     CUST R11 5 10
    But if I right click on the details
    I get this
    1     SIL_InventoryProductDimension_SCDUpdate_Full     Running     2009-03-02 17:40:41.0     2009-03-02 21:09:09.0     3 hour(s), 28 min(s), 28 sec(s)     Verifying if workflow still running on Informatica Server 'Oracle_BI_DW_Server'.
    If still running will attach to the workflow.     DataWarehouse     Informatica     0          -2     0
    And the remaining detail tasks for this are in queued status.
    What could be the reason?
    Does it need the Infomartica workflow manager open? It is open currently open but must have been accidently closed in between.
    Informatica services have always been running.
    Thank you very much
    Nilesh
    [excel dashboard|http://www.exceldashboard.org]
    dashboard Software
    [Access Dashboard|http://www.accessdashboards.com]
    [Dashboard Reporting|http://www.reportingdashboard.com]
    Edited by: njethwa on Jan 6, 2010 5:39 PM

    Hi
    This Sometime happens with DAC.We faced the same issue and had an SR open with Siebel for almost 2 weeks,they Couldnt help us out.
    Restart your DAC Server and Do a Dryrun and then run your full ETL .
    The Analyze task would not hang anymore.
    I dot have any logical reason why this happens,but i am guessing it has to do with some java heap memory.So restarting the Server would free up the memory.(i am guessing but not sure).
    But it Works.
    Try it
    Let me know if this helps
    Thanks
    H

  • Podcasts are downloading, but not showing up in Itunes Library !

    Hi guys.... this is d3riving me up the wall !!!
    I'm running Windows XP. I recently had some work done on my computer and had to restore Itunes. Initially, nothing worked, but now the only issue I have is with podcasts.
    I select the episode I want for download and that works OK. Once the download is completed, the episode is nowhere to be found in Itunes. When I look in the 'podcast' folder in the itunes library in Windows, it is not listed.
    I did a search and found these references...
    E:\...\Downloads\Podcasts\Fischer's Brick_PE'S Chess Cast.tmp\
    E:\...\Podcasts\Fischer's Brick_PE'S Chess Cast.tmp\download.mp4 1,310,720
    E:\...\Downloads\Podcasts\Fischer's Brick_PE'S Chess Cast.tmp\Info.plist 1474
    Note 1) Fischer's Brick is the name of the episode of PE'S podcast
    Note 2) 1,310,720 on line 2 and 1474 are the file sizes.
    Note 3'E' I have set Itunes up on my 'E' drive rather than 'C' which I believe is normal. Don't know if that is relevant as 'Songs' Audiobooks seem to work ok with these settings.
    If I select the second line and tell windows to open it in Itunes nothing happens. Actually, what happens is that ITUNES will start playing a song that I downloaded that day!
    Any suggestions would be greatly appreciated
    '   

    It's the iTunes library files which, along with the iTunes Music folder and some other files, are found in the iTunes folder that iTunes uses to know the contents of the Library.
    It sounds like you may have only copied the iTunes Music folder to your new computer, not the entire iTunes folder. Can you confirm whether or not that is the case?
    If that's what happened, repeat the process , making sure the whole iTunes folder goes along for the ride.

  • After loading FF4 the back/forth buttons are visible but not functional. Have tried to reset tool bar etc. no luck. fix please

    After upgrading to the new version everything seems to work well except my back/forth button on the browser are visible but grayed out and not functional. I have tried all of the suggestions in help and am unable to bring them to life. Very frustrating to use a browser with out these functions. I run 4 websites and it is maddening to have to keep reloading the sites just for simple work.
    I have to have these working or will be forced to use another browser. I liked the old FF much better. I can not tolerate this much longer.

    I notice from your system specs that you're running a very old version of Flash. Could you try updating to the latest one which is 10.2.159.1 It also contains a patch to fix a recently discovered [http://www.h-online.com/security/news/item/Adobe-releases-security-update-for-Flash-Player-1228930.html Zero Day exploit]. You can get it from here: http://get.adobe.com/flashplayer/
    Have you experienced any unusual events watching Flash videos lately? It's possible that you may have been a victim of just such an attack. It might be worth doing a malware scan using this well-known scanner from http://www.malwarebytes.org/ The free version is more than adequate to eliminate any current threats.

Maybe you are looking for

  • FLEET Table, Possible Values For Field IS SI UNIT

    Dear experts, While doing analysis on fleet data I realized that for field IS_SI_UNIT (PM: Vehicle Data in SI Unit (e.g. Dimensions)) in table FLEET in two separate systems we have vehicle records set with different entries for this field. In one sys

  • Undeploying war file

    I am trying to undeploy a war file using the iasdeploy removemodule -verbose csa.war command. It says that it finishing deploying, which is odd, and then it still shows up in the IAS registry under the j2ee modules. Is this the correct way to undeplo

  • How can I Revert back to IOS7 from IOS8?

    Hi Folks, Is there a way that I can revert back to IOS7 from IOS8 after install on both iPhone and an IPad? I did not back up either of these devices before doing the upgrade. I know I should always back up before any updates, but I'm hoping the fact

  • Prblem of session

    problem of session: In the jsp page I call such method: session.setAttribute("userId",userId); If the jsp program is run from two or more client and login using different user and call session.getAtytribute("userId") to get value,i find that the late

  • File Properties - Metadata

    Can someone please tell me how I can get file sizes to show in millimetres and not inches in the Metadata File properties window.