OIM 11.1.1.5 Ldapsync OID and Password Management

Hello All,
I have the following setup:
- OIM 11.1.1.5
- Ldapsync
- OID 11.1.1.2 (patched to 11.1.1.5)
I'm trying to validate to following password management scenario:
1. End user connects to OIM web console
2. Reset its own password
Expected:
a. The password is updated in OIM ( OK )
b. The password is updated in OID via ldapsync ( OK )
c. The OID attribute pwdReset is updated from 1 to 0 ( NOK )
OBS: pwdreset | If the value is 1, the user must reset the password at the next login.
Problem:
Ldapsync updated the password on OID as expected but the attribute pwdReset was not updated.
Thanks for shedding any light
Adr.

Hello jtellier,
No solution yet, it is still in my list though, but with low priority.
I'll be happy to hear from you in case you find something.
Good luck
Adr

Similar Messages

  • Client Security Solution--and Password Manager--no longer autoruns

    My T61 was working wonderfully until recent installation of antispyware, antivirus programs.
    Prior to that, on boot, I could always see a brief CSS splash screen, and, more importantly, Password Manager would always kick in automatically, to load password data or to ask if I wanted it to remember something.
    Now, although Password Manager remains an icon in the system tray, it not only does not detect need for input, hotkeys do nothing, despite being marked enabled.
    I downloaded CSS 8.1 from the website (although this was still installed), and ran the "Repair", but still no joy.
    Your help is greatly appreciated.

    Thanks again--as you suggested, a thread well worth reviewing.
    In my case, I opted for the Rescue and Recovery Quick Restore--albeit with much fear and trepidation, since, unlike the roughly equivalent MS System Restore, this feature does not tell the user the date of the restore point that is being recreated.
    As it turned out, this took me back to a point when Norton Internet Security was only partially removed--which created the added anxiety of (a) inability to connect to the Internet through Explorer or Outlook 2007 and (b) inability to launch any Office 2007 program!  (That last caused yet another twist, since the instructions I had previously followed to completely removed Norton were now saved as .docx files....)  Although Norton Internet Security was still present on the desktop, and ccApp.exe was obviously running (and unable to shut itself down on Restart), Add/Remove Programs (the first step in the removal process) would not work--"the module is missing."
    Fortunately, I was able to download the Symantec Removal Tool through another computer onto a USB drive, copy the program to the T61, and run it there.  (Note that although Explorer would not load fully, Internet access of a sort was still available as witness System Update and Microsoft Update downloading without difficulty--though MS could not complete installing updates for Office 2007 with Norton still in the picture.  This matters because the Removal Tool accesses the net.)
    Once Removal had done its thing, Explorer, Office 2007, and Password Manager again worked as before.
    Sadly, I still don't know what the necessary ingredients for CSS/Password Manager are--there ought to be a listing of what files these otherwise excellent programs require.  And I'm not sure what approach to firewall, antivirus, and antispyware I ought to take, given the possibility that the programs I replaced Norton Internet Security with caused CSS/Password Manager grief.
    Sigh.

  • Additional software functionalities: To-Do and passwords management???

    I just activated my iphone and find it amazing for the functionalities advertised by apple but quite deficient in basic tools other phones offer pretty much as standard nowadays. I am referring to the ability to manage a list of to do items, prioritise them and tick them off when done. Where is it?
    Furthermore, is there any add-on software that allows passwords management in a secure environment?
    Thanks for any help you can send my duirection!!!
    Marco

    I totally agree. I think my iPhone is brilliant. Does pretty much what I want. (I know others have mentioned lack of MMS or 3G) but this isn't an issue for me.
    However I was surprised at the lack of a "to do" list, which I more or less expected as part of the calendar function, and something that I used all the time on my previous phone.
    Given so much has been made in leopard regarding to do's and notes in Mail and integration with iCal. I'm surprised at this omission on iPhone.
    I also would beg Apple to add this as part of a future update.

  • Firefox3 and Password Manager

    I've been waiting to upgrade to Firefox3 untill the Password Manager worked with it.
    Today System Update promised me such a feature.  I installed Firefox3, downloaded the patch
    to make Password Manager work with it, installed it and hoped.  Vain hope . . . 
    When I tried to login to the Lenovo Community it didn't fill in my name or password.  I can access
    the Password Manager from within Firefox3, and it shows this address as one of its sites.
    Also, after it didn't fill in the responses for me, it didn't ask me if I wanted to save them.
    Apparently I rushed to judgement.
    Bob Stockler
    G41 - 2886-5TU - Mobile Pentium 4 532 - 3.06 Gh
    2 Gb RAM - 80 Gb Toshiba 5400rpm HDD - Win XP Pro

    Bob, thanks for your update.  Based on your success, I attempted to download FF3 again and finally achieved success this morning.  The method I had to go though was as follows:
    Disabled the ThinkVantage Password Manager 2.0 add-on within FF2
    Unintalled FF2
    Tried to install CSS Patch for FF3 provided by Lenovo on 8/6/08 found here, but received feedback that patch had already been installed, which is a true statement:CSS Patch for FF3
    Installed FF3 (3.0.3)
    Noted that the ThinkVantage Password Manager 2.0 add-on was greyed out and could not be enabled - I thought the patch was supposed to address this!!
    Had to work through this process found at: Password Manager incompatible with Firefox 3
    Find tvtpwm_moz_xpi.xpi in Client Security Solution install directory (C:\Program Files\Lenovo\Client Security Solution)
    Open it using your fav zip program (I used 7-Zip)
    Change install.rdf and update <em:maxVersion>2.0+</em:maxVersion> to <em:maxVersion>3.0+</em:maxVersion>
    Open chrome/tvtpwm.jar
    Edit content/tvtpwm.js and replace window.addEventListener("load", onLoad, true); with following:
    window.addEventListener("load", function () { gBrowser.addEventListener("load", onLoad, true); }, false);
    Install tvtpwm_moz_xpi.xpi. Go to Firefox's 'File' menu, select 'Open File', navigate to your directory containing the file (in my case, it's 'C:\Program Files\Lenovo\Client Security Solution'), and select it. This will bring up the "Add-ons" installer. Click install and restart Firefox when prompted.
    So far, I have had no issues with auto population of username/password.  I went through this exact same process multiple times in the past without success.  Now, I am wondering if the latest rev. of FF3 (3.0.3) has allowed for better stability with the password manager.  I still do not understand what the CSS Patch for FF3 was supposed to ever do.  In my opinion, it should have performed what I had to perform manually above.
    Question:  When I look at my add-ons, the ThinkVantage Password Manager still shows "2.0".  It works fine, but should this have changed to 3.0?
    Message Edited by Kaz on 10-23-2008 01:27 PM
    Message Edited by Kaz on 10-23-2008 01:28 PM
    Message Edited by Kaz on 10-23-2008 01:33 PM
    T60, 8744-5BU: 2.0 GHz T7200, 4 GB RAM, 15.4" WSXGA+, 1680x1050 ATI Mobility Radeon X1400, Win 7 Ultimate w/SP1 - 64-bit

  • "Message Center" and "Password Manager" stay on top after Boot-Sequence

    Hello,
    when I boot my system the "Password Manager" and "Message Center" start automatically. The windows used to disappear after the start sequence, but do not any more.
    Both the Info-Window (Password Manager) and the empty  Message Window (Messsage Center) stay on top of the desktop.
    It's absolutely annoying clicking both windows away each morning....
    Is there any help?
    Regards - Oliver

    Hello,
    when I boot my system the "Password Manager" and "Message Center" start automatically. The windows used to disappear after the start sequence, but do not any more.
    Both the Info-Window (Password Manager) and the empty  Message Window (Messsage Center) stay on top of the desktop.
    It's absolutely annoying clicking both windows away each morning....
    Is there any help?
    Regards - Oliver

  • Oracle Forms 11g SSO with OID and IAM

    What versions of OID and Access Manager are required to get an Oracle Forms and Reports 11.1.1.2 application
    on Weblogic 10.3.2 configured for Oracle SSO using OID authentication?
    We want the OID to store and authenticate Users for username and password logins to the database, then
    ultimately by user Certificate authentication in OID. I have OID 11.1.1.2 installed and SSO enabled for Forms
    in Enterprise Manager.
    Is Access Manager required for Forms SSO with OID authentication to work or just to allow user interaction
    for registration and Password reset?
    Things mention OAM 10.4.3 and others talk about IAM 11g for Forms 11.1.1.2 SSO to work with OID.
    We did this back in Oracle Forms and OID 10g with JSP and LDAP to setup users but I understand 11g is
    different and IAM can help or is required for this type of SSO to work.
    Any help?
    Edited by: Kirch on Apr 30, 2013 7:39 AM

    Hi,
    According to Oracle's certification matrix found at http://www.oracle.com/technetwork/middleware/downloads/fmw-11gr1certmatrix.xls, Oracle Forms 11.1.1.2 is not supported to use any Oracle Access Manager (OAM) version. OAM is a component of IAM. It is only supported with Oracle SSO 10.1.4.x. The best solution would be to upgrade the Forms and Reports environment to either 11gR2 (11.1.2.1) or to the latest 11gR1 patchset 11.1.1.7. Both versions are compatible with OAM 11.1.1.7.0 and OID 11.1.1.7.0 where only Forms 11gR2 (11.1.2.1) is compatible with OAM 11.1.2.0 and OID 11.1.1.7.0. That would be the best solution as we have ran into configuration problems in the past with using Oracle SSO 10.1.4.x.
    Since OID 11.1.1.2.0 is already installed, you should be able to patch it up to 11.1.1.7.0.
    For user authentication in OID, it is required to have OAM or Oracle SSO as both products use WebGate or mod_osso agents for authentication and authorization. For purposes of allowing end users to register accounts and password reset, you will either need to also install another IAM component called Oracle Identity Manager (OIM) or create a customized SSO login page that can be coded to perform these actions. I believe there are some examples available on the Internet.
    Thanks,
    Scott
    http://pitss.com/us

  • Password Manager and IE9 RC

    Hello, Installed the latest version of Client Security Solution and Password Manager does not work at all. I'm using IE9 RC 64 bit but also tried it out on Firefox and does not work. I'm running Win 7 64bit. 
    When I went to update my software Lenovo did recommend a patch for Password Manager 64 bit but nothing's working. Is there a fix/workaround to get it working in a 64 bit environment? 
    Thanks John

    Hello mate,
    Have you activated the TPM chip in the bios ?
    Knowledge is of two kinds. We know a subject ourselves, or we know where we can find information on it.
    ThinkPad T510 4313-CTO Windows 8 x64 - Intel Core i7-620M - NVIDIA NVS 3100M - 8GB RAM - 240GB SSD- Intel Centrino Ultimate-N 6300 - Gobi 2000.
    ThinkPad Helix 3697-CTO Windows 8.1 x64 - Intel Core i7-3667U - Intel HD Graphics 4000 - 8GB RAM- 256GB SSD - Intel Centrino Advanced-N 6205 - Ericsson C5621gw

  • What is the best way update similar OID and OAM LDAP attributes via OIM?

    Our environment uses OIM provisioning to an OID LDAP which is used by OAM.
    For legacy purposes, we need to populate both the Oracle "orcl*" attributes and OAM "ob*" in cases where they have the same or similar usage.
    Example: When a user is disabled in OIM we need to set orclisenabled="false" and obUserAccountControl="DEACTIVATED" in OID
    What is the best way to accomplish this in OIM? My initial thought was to write a custom adapter, similar to the out-of-the-box OID Modify User adapter, which supports modifying multiple attributes.
    Is there a better way?

    You can create two tasks which will modify two attributes of OID.
    On Disable user task, call task1 and on Success of task1, call Task2 (using Task to Generate Feature).
    You can make use of OOTB connector only.

  • I am trying to build a basic TCL skeleton script that reads a remote SNMP OID and displays the value on the screen.

    I am trying to build a basic TCL skeleton script that reads a remote SNMP OID and displays the value on the screen.
    I don't want it to be an EEM Event, I just want to run it from the (tcl)# prompt.
    So I guess I'm asking if you can use cli_exec and other commands in the "namespace import ::cisco::eem::*" in a normal non-EEM script - can I do that?
    This is the error I get:
    OTN.159(tcl)#source flash:TCL_SNMP_Remote_Read.tcl
    invalid command name "::cisco::eem::event_register_none"             ^
    % Invalid input detected at '^' marker.
    What am I missing?
    =================  TCL_SNMP_Remote_Read.tcl  ==============================
    ::cisco::eem::event_register_none
    namespace import ::cisco::eem::*
    namespace import ::cisco::lib::*
    if [catch {cli_open} RESULT]
        { error $RESULT $errorInfo }
        else { array set cli1 $RESULT }
    if [catch {cli_exec $cli1(fd) "snmp get v2c 192.168.1.100 public timeout 1 oid 1.3.6.1.2.1.1.1.0" } RESULT]
           { error $RESULT $errorInfo  }
           else { set SnmpSysDesc $RESULT }
    if [catch {cli_close $cli1(fd) $cli1(tty_id)} RESULT] {
                error $RESULT $errorInfo
    puts $SnmpSysDesc
    =========================================================================
    In the sho-run config I have:
    event manager directory user policy "flash:/"
    event manager session cli username "cisco"
    Any help to get me started would be greatly appreciated!
    Tim

    If you don't want an EEM policy, then don't use any of the EEM constructs.  Instead, all you need is this:
    set output [exec "snmp get v2c 192.168.1.100 public timeout 1 oid 1.3.6.1.2.1.1.1.0"]puts $output

  • How can we get ADFSecurity work when used in OC4J, OID and OAM?

    I am getting error in http server log "mod_oc4j: Response status=499 and reason=Oracle SSO, but failed to get mod_osso global context."
    But I am not using Oracle SSO and my client doesn't want to use it either, I am using OAM SSO(CoreIDSSO) in my configuration. Please read the details below.
    I am using ADFSecurity in an app that is protected by OAM. To migrate ADFSecurity permissions from
    system-jazn-data.xml to OID, I used JAZNMigrationTool to populate OID with Grantees and Permissions. OAM gives login page, and authentication works fine.
    But ADFSecurity is not working. ADFComponent Delete button is enabled even for roles that dont have permissions for the iterator delete.
    - The app works fine when I use without OAM. ADF Security permissions work fine.
    - The app works fine when used with OAM, but with ADFSecurity disabled (enforce=false).
    - When I enforce ADFSecurity alongwith OAM, ADFSecurity is not working.
    In the doc "Oracle Containers for J2EE Security Guide b28957", there is a mention of use of CoreIDPrincipal for permissions. Our OID Permissions entries show
    LDAPRealmRole for attribute orcljaznprincipal. I am not sure if this could be the reason.
    We have configured AccessServerSDK for the SOA instance and have policy for the urls in the policy manager. We have entries in orion-application.xml, orion-web.xml and system-jazn-data.xml as per the documentations.
    How can we get ADFSecurity work when used with OID and OAM?

    Have you been able to successfully integrate OAS with OAM & OID? We have similar requriement and so far we have not been able to get it working.
    We have application specific roles which we map to OID roles using orion-application.xml.
    Any pointers to achieve this would be greatly appreciated.
    thanks,
    Dipal

  • Creating a new context in OID and extending DIT

    I am developing a portal. I need to create a new context in the OID and extend the DIT so that i can store Subscriber information in it. Please help me with the procedure, and sample schema.
    thanks in advance,
    udai.

    Hello JB-Baby
    You can't create a subfolder in Sent. Mail does this automatically for each account you set up. If you wish to organise messages you send by some criteria or other, why not consider a Smart Mailbox?
    I assume by your second question you mean can you change the columns in the message viewer? Yes you can. You select View -> Columns and check the ones you want. You can adjust the order of the columns by dragging the titles around in the message viewer.
    If you didn't mean this, maybe you could explain what you are after in a little more detail.

  • Link b/w orclIsEnabled on OID and portal API calls wwsec_api.activate_user

    Hi Folks,
    I am just curious about the account status on OID and access on portal user profiles.
    Is account activation or deactivation in OAS portal (using wwsec_api.activate_portal_user/ deactivate_portal_user calls) related to the OID enable/ disable of an account using orclIsEnabled field?
    i think the portal api calls control the portal access in the wwsec_person$ tables. but does it also reflect on to the orclIsEnabled field?
    any guidance will be highly appreciated!
    AMN

    I'm not 100% positive but I do not think the portal account activation/deactivation calls change the orclIsEnabled attribute in OID since there are times when a user in OID may still be enabled for SSO purposes but that same user may be deactivated as a portal user.

  • OID and Oracle Forms in 9iAS Release 2

    Whenever I bring up a first form in 9iAS forms over the web scenario, I am forced to log into the database through a pop up login box in IE. This is so even though I have a perfectly valid "userid=user/pwd@database" value in the URL. I have tried moving the userid value to the formsweb.cfg group and it helps not a whit. Once I log on everything works hunkydory. I am figuring there is some issue with OID. Is this a valid assumption?
    How, exactly, does the OID and forms over the web interact. Do I need to create an OID user that has resource access to the database and then use that id in the userid variable in the URL? If so, how do I do this. Please feel free to be specific as if you were talking to an idiot or a small child...type very slowly and enunciate as you go. Not being able to log in from the formsweb.cfg and the URL is an irritant, not a showstopper, but it is a big irritant.

    AS with all the downloads on otn this is a full version with no
    time limit. But you are under the OTN license which says that
    you have to purchase the product if you are developing
    production applications with it. Its free for evaluation and
    personal education purposes.

  • Allowed set of characters for user name and password in OIM 11g

    Hi,
    Can anyone provide us quickly what is the characters (no.s,alpahbets,special symbols) that are supported for username and password field in OIM 11.1.1.5 ?
    Thanks,
    Karthik

    Read it , it is general for OIM 11g
    http://docs.oracle.com/cd/E14571_01/relnotes.1111/e10132/oim.htm#CHDFFDGH

  • Differences between OID and OUD

    Hello gurus,
    What are the differences between OID and OUD.
    Why Oracle release two LDAP directories. Please let me know.

    These two are two LDAP directories.
    Where OID is database dependent and OUD is not.

Maybe you are looking for

  • Face Time:  blue star vs. camera in contacts????

    I have an iPad2 and a MacBook Pro.  Both with the latests systems (iPad 6.1.3, MacBook Mountain Lion).  When I Facetime my daughter's iPod, there's a blue camera with a star in it next to her name, Messagin and Facetime work with her iPod (different

  • Hi i need help with getting my homework for school

    im in a nine week class that ends tommorw and need help go\etting my program working properly these are the requirements ofr the assignments: Modify the Inventory Program by adding a button to the GUI that allows the user to move to the first item, t

  • Cannot print more than one copy! Any ideas?

    My wife came home with a HP 5400dn officejet pro the other night from Staples. After setting the thing up with a successful test page, I tried a real print job. So far so good. Then I tried to use the duplex function but wait, where is the option to

  • Using "Keychain Access" as a Password Manager

    Hello All, While searching for a secure, trustworthy password manager I started wondering why I couldn't just use Keychain Access built into the Mac OS. I've tried others and they're all nice in their own way but why not use what's already there? Any

  • My email says I have four new emails, but only have three marked as unread?

    My email says I have four new emails, but only have three marked as unread? I've tried turning "badge app icon" off and on, as well as deactivating and reactivating account and still having same problems.