NT realm works, but appears slow and unconfigurable

Using WLS 6.1sp1 I successfully have authentication working
using the NT realm.
The most simplistic cases work but I'm having trouble with the
more complex cases. BEA does not provide examples on these:
#1. Listing Users/Groups from the console is extrememly SLOW.
Similar to Frank Febbraro's post (5-2-2001), whenever I
click on Security->Users from the console it takes 15-20
minutes to respond. Likewise, the Security-Groups option
never returns (Frank mentions it takes 30 minutes??)
#2. You can specify roles and principles, but not domains.
In the weblogic.xml descriptor I can specify principles or
roles using the <security-role-assignment>. But what I'd
like to do is not limit access to a proper NT group or
weblogic role, but rather an NT domain. That way any user
in the domain that is authenticated can access the resource.
I've heard other developers want this functionality as well.
#3. One domain works, multiple domains do not.
According to the "Managing Security Document"
(http://e-docs.bea.com/wls/docs61/adminguide/cnfgsec.html#1052721)
you can run the weblogic server on various machines,
including a "mutually trusted domain". What is not
stated is how to authenticate using those trusted domains.
For example, logging into the web brower using HTTP
challenge/response may work for the following username:
myusername
But this will not:
mydomain/myusername
nor this:
mytrusteddomain/myusername
And from within the console the Security->Filerealm tab
only allows selection of one realm, not multiple.
Anyone know of any further reading/examples for the NT realm?
Jason

>
Hi Jason,
I'll just dive right in here.
>
#1. Listing Users/Groups from the console is extrememly SLOW.
Similar to Frank Febbraro's post (5-2-2001), whenever I
click on Security->Users from the console it takes 15-20
minutes to respond. Likewise, the Security-Groups option
never returns (Frank mentions it takes 30 minutes??)
Yes. This has been a problem for a lot of users with NTRealms. The speed
issue has something to do with the way the console loads users and
groups. BEA is looking into the issue of why it is a problem for the
console to enumerate through group and user membership.
It is fairly fast, however, when the cachingRealm is simply cleared,
because different calls are being made internally.
So although this is definitely a performance issue with the console, you
should find that there are not performance problems for the "normal"
functioning of your realm -- authentication lookups and the clearning of
the CachingRealm should be reasonably fast.
>
#2. You can specify roles and principles, but not domains.
In the weblogic.xml descriptor I can specify principles or
roles using the <security-role-assignment>. But what I'd
like to do is not limit access to a proper NT group or
weblogic role, but rather an NT domain. That way any user
in the domain that is authenticated can access the resource.
I've heard other developers want this functionality as well.
Right. It is not possible to restrict access to a certain NT domain right
now.
>
#3. One domain works, multiple domains do not.
According to the "Managing Security Document"
(http://e-docs.bea.com/wls/docs61/adminguide/cnfgsec.html#1052721)
you can run the weblogic server on various machines,
including a "mutually trusted domain". What is not
stated is how to authenticate using those trusted domains.
For example, logging into the web brower using HTTP
challenge/response may work for the following username:
myusername
But this will not:
mydomain/myusername
nor this:
mytrusteddomain/myusername
Again, this is unfortunately expected behavior.
If you have 2 NT machines with a trust relationship, and you are using
these machines as the user/group store for WebLogic, there is no easy way
to get WebLogic to differentiate between a user/group on machine#1, versus
a user/group on machine#2. Weblogic views all users and groups,
regardless of where they are found, exactly the same -- exactly equally.
That is why you notice that specifying /mydomain/username or
mytrusteddomain/username both do not work.
>
And from within the console the Security->Filerealm tab
only allows selection of one realm, not multiple.
Right again. (Man, I seem to just be piling on the bad news right now.)
You can only have one "alternate" realm hooked into WebLogic at a time
currently.
I hope this helps answer your questions, even if most of the information
isn't exactly what you wanted to hear...
Cheers,
Joe Jerry

Similar Messages

  • CC 2014 nik efex - My Nik Efex filters are not working in Photoshop CC 2014 - they appear under plug-ins and seem to work, but after running and clicking okay, no new layer appears - seems to have no effect.  The separate menu panel does not appear either

    My Nik Efex filters are not working in Photoshop CC 2014 - they appear under plug-ins and seem to work, but after running and clicking okay, no new layer appears - seems to have no effect.  The separate menu panel does not appear either.  Help with this?

    BINGO !!!!
    Thanks so much Woodsroad. I had the exact same problem with my Dell Windows 7 64 bit with AMD Radeon 6700 Video card.
    All the video tests passed with flying colors.
    The sniffer rename trick fixed the problem.
    Thank goodness for the internet!

  • HP Deskjet D2400 Printer series is working, but very slow

    Problem - HP Deskjet D2400 Printer series is working,  but very slow.  Pause 5-10min before the begin of print and between the sheets   OS-WIN XP SP4

    Hi there bozhk,
    This article should cover the issue you are experiencing. Give the steps outlined a shot and let us know if it helps.
    Best of Luck!
    You can say thanks by clicking the Kudos Star in my post. If my post resolves your problem, please mark it as Accepted Solution so others can benefit too.

  • I installed windows 7 on my macbook pro. all is working but lan adaptor and sound od laptop is not working. please help me or send the link where i can download the these drivers.

    I installed windows 7 on my macbook pro. all is working but lan adaptor and sound od laptop is not working. please help me or send the link where i can download the these drivers.I have lost my resource cd .

    If you are running Lion or Mountain Lion, the drivers are downloaded from within Bootcamp Assistant. If you are running Snow Leopard the drivers are on your Snow Leopard install disk.
    Read the Bootcamp Install Guide for your version of OSx. http://www.apple.com/support/bootcamp/
    Bootcamp questions should be asked in the Bootcamp forum where the Bootcamp gurus hang out https://discussions.apple.com/community/windows_software/boot_camp

  • Auto policy updates from DC1 to DC2 work but break user and admin login in DC2.

    Auto policy updates from DC1 to DC2 work but break user and admin login in DC2.
    Is there any solution to this ?

    You will need to update your transformation rules to match the URL/hosts for dc2.

  • I dropped my iPhone 4 in the sink where it was submerged in water for not even 2 seconds I took it out and put it in a warm room by the radiator and most of it works but no sound and battery length is short and runs out quickly. Any ideals on how to help?

    I dropped my iPhone 4 in the sink where it was submerged in water for not even 2 seconds I took it out and put it in a warm room by the radiator and most of it works but no sound and battery length is short and runs out quickly. Any ideals on how to help?

    $149
    They do not repair .Apple exchange and all returned units are refurbished at The Apple plants in China
    So you get a device that looks like and functions like new
    Are you familiar with the results of water and electricity mixing

  • Can I replace the G5 CP units in my pre intel power mac? I get the 3 flash light and am heating them with a hair dryer. It works but needs fixing and I can't afford a new mac

    Can I replace the G5 CP units in my pre intel power mac? I get the 3 flash light and am heating them with a hair dryer. It works but needs fixing and I can't afford a new mac

    OK, it looks like all but the first G5 1.6 Ghz, & the last 3 G5 Dual Cores will take PC3200 RAM...
    Power Macintosh G5 1.8 (PCI-X) PowerMac7,2   1 Power Macintosh G5 2.0 DP (PCI-X) PowerMac7,2   1 Power Macintosh G5 1.8 DP (PCI-X) PowerMac7,2   1 Power Macintosh G5 1.8 DP (PCI) PowerMac7,3   1 Power Macintosh G5 2.0 DP (PCI-X 2) PowerMac7,3   1 Power Macintosh G5 2.5 DP (PCI-X) PowerMac7,3   1 Power Macintosh G5 1.8 (PCI) PowerMac9,1   1 Power Macintosh G5 2.0 DP (PCI) PowerMac7,3   1 Power Macintosh G5 2.3 DP (PCI-X) PowerMac7,3   1 Power Macintosh G5 2.7 DP (PCI-X) PowerMac7,3

  • My digital editions saying not working but I uninstalled and reinstalled and it is still not working, any ideas?

    My digital editions saying not working but I uninstalled and reinstalled and it is still not working, any ideas?

    Hi imtheozzman, check if your security software is the problem, see : [https://support.mozilla.org/en-US/kb/configure-firewalls-so-firefox-can-access-internet Configure firewalls so that Firefox can access the Internet ]
    thank you

  • Finally got face time to work - but screen freezes and can't continue the call

    finally got face time to work - but screen freezes and can't continue the call - how can I fix this problem?

    Probably a network problem but see here for troubleshooting: http://support.apple.com/kb/TS3367

  • I was working with my Apple IPad 4G suddenly the sound stopped,I flipped the back of device slowly and it started to work but not properly and again stopped working.

    I was working with my Apple IPad 4G suddenly the sound stopped,I flipped the back of device slowly and it started to work but not properly and again stopped working.
    Now it is not working even with fliping, is the problem with hardware or software?
    Is any soloution to solve the problem?

    The Basic Troubleshooting Steps are:
    Restart... Reset... Restore from Backup...  Restore as New...
    Restart / Reset
    http://support.apple.com/kb/ht1430
    Backing up, Updating and Restoring
    http://support.apple.com/kb/HT1414
    If you try all these steps and you still have issues... Then a Visit to an Apple Store or AASP (Authorized Apple Service Provider) is the Next Step...
    Be sure to make an appointment first...

  • Ipod internet will not work. but my computer and other devices work

    It shows that i am connected to the internet, yet it wont load any sites. It will load google. But when i go to click on a site, it'll either pop up as safari cannot open because your ipod touch isnt connected to the internet, or a server issue. Every now and then it will work, but then after a minute it will just go back to its old ways.
    I've tried reconnecting and connecting the wifi on the ipod
    I tried to reset network settings.
    I've turned my modem on and off.
    Again, it may only work for a couple minutes or so, but then itll just go back to its old ways.
    My laptop, phone, and other stuff works on the wifi, I am only having the problem with the ipod.
    Facebook and instagram app works also. but safari isnt

    Does the iOS device connect to other networks? If yes that tend to indicate a problem with your network.
    Does the iOS device see the network?
    Any error messages?
    Do other devices now connect?
    Did the iOS device connect before?
    Try the following to rule out a software problem:                
    - Reset the iOS device. Nothing will be lost
    Reset iOS device: Hold down the On/Off button and the Home button at the same time for at
    least ten seconds, until the Apple logo appears.
    - Power off and then back on your router
    .- Reset network settings: Settings>General>Reset>Reset Network Settings
    - iOS: Troubleshooting Wi-Fi networks and connections
    - Wi-Fi: Unable to connect to an 802.11n Wi-Fi network      
    - iOS: Recommended settings for Wi-Fi routers and access points
    - Restore from backup. See:
    iOS: How to back up
    - Restore to factory settings/new iOS device.
    If still problem and it does not connect to any networks make an appointment at the Genius Bar of an Apple store since it appears you have a hardware problem.
    Apple Retail Store - Genius Bar

  • My iphone 3g sound doesn't work but goes on and off when i'm using headset,

    my iphone 3g sound doesn't work but when i plug in headset, the headset sound goes on and off. I think the speaker has a problem or touches but why does the headset not work but goes off randomly?Pls help me out

    my iphone 3g sound doesn't work but when i plug in headset, the headset sound goes on and off. I think the speaker has a problem or touches but why does the headset not work but goes off randomly?Pls help me out

  • Macbook Pro 10.6.8 constantly drops my wi-fi network and joins Linksys which works but very slow

    My Macbook Pro constantly drops my network and joins Linksys. It connects to the Internet but is painfully slow. Choosing my network again works for a while than goes back to Linksys. Any sugestions?

    Try going to system preferences/network/advanced, airport tab, in the prefered networks pane highlight and drag your net work to the top of the list. See if it then chooses your network as prefered, hope this helps.

  • Firefox does not load a pdf-page shown by a specific link, but goes slow and finally crasches instead. IE10 does work. Link is fro state official side, smhi.se

    I have windows7, just installed and no bugs. As said above, when I try Internet Explorer 10, recently installed, I have no problem looking on this pdf - page.
    The page is found by logging in to smhi.se, the swedish wheater service. I have no problem with the majority of information shown there, just one specific page.
    It can be found by clicking "Väder", then "Is till havs", then down under click "Istjänsten" and then "Senaste iskarta i färg".
    This pdf-document is then loaded very slowly and if I try to navigate on the page it crasches.

    First, after clicking the Firefox button in the upper corner, there is not popping up the square on your solution above!
    I can not select Applications in that menu-line thus.....because I do not have it!
    Instead I get a small square with swedish text. Only thing which resembles me of any action is: Settings (Inställningar), so I chose that and another square shows where strangely enough the same line is about Acrobat is repeated twice. No other settings are repeated twice.....
    So I go to the line for Acrobat and change both lines to Acrobat reader
    Then I save and go out.
    I try again to log into the link I am interested in, but no result, same problem as before.
    Has your swedish people done something strange???
    Best regards // Hans Hällström

  • USB modem in network worked, but accidentaly deleted, and now can't replace it.

    I recently succesfully connected a Nokia 6120 cellphone to use as a 3G modem; the last time I used this was in 2009.
    The USB connection and network place in my network settings "migrated" to its proper place when I upgraded to Lion this year, and when I tried the Nokia again it worked, connected through USB.
    There was a second Nokia network choice on the list in my Network prefs, which I deleted, thinking that it was not necessary. After that deletion, the remaining Nokia setting would not connect the computer to the phone, and of course would provide internet access.
    I tried duplicating the old setting, but now I can't select a USB option when configuring it.
    All my research indicates that this is due to Lion no longer supporting USB modems. However, my Nokia worked just fine, and the old Network via USB setting was still present in Network preferences, and worked just fine until the deletion of one of the Nokia settings.
    Does anyone know of a work-around or a patch that will add USB connectivity to Network preferences in Lion?
    BTW... tried connecting through Bluetooth; I can pair the phone to the computer, but it will not make the modem connetion.
    Would the bluetooth transfer rate be too slow, anyway?
    Thanks in advance
    Glenn

    Found the problem!
    Check this thread:
    https://discussions.apple.com/message/4028119#4028119
    There are, in fact, modem scripts available, and they go into the Library/Modem Scripts folder.
    By deleting the extra configuration, I deleted the old scripts. I downloaded and installed the 3G Nokia scripts from the website shown in the above thread, and my configurations re appeared in Network prefs;
    I went one step further; I connected to the internet using the restored configuration, then selected and deleted (using the - at the bottom of the list) while the connection was working. It got rid of the second configuration but kept the valid one. Hopefully, It will still be available when I attempt to connect again.
    Glenn

Maybe you are looking for