OWLCS install - trying to use with my Active Directory

Experts,
I'm new to OWLCS but am very familiar with the Oracle Fusion Middleware 11g Stack. My end goal is to integrate OWLCS with WebCenter Spaces 11g (11.1.1.3). I have a Dev Environment where I have installed OWLCS (11.1.1.2) following the steps outlined in the Installation Guide, Oracle® WebLogic Communication Services Installation Guide 11g Release 1 (11.1.1) E13808-01.
I followed the instructions to setup an All-in-One Managed Server. I have an Admin server (owcs_AdminServer) and managed server (wlcs_server1) defined and started. I've also followed the instructions to update my Realm to "mycompany.com" and also remembered to update the /etc/hosts file with "mycompany.com".
I followed the remainder of the guide to test the installation with an Oracle Communicator Client.... I added test users using launch_sash, I successfully connected and saw my presence change and was able to communicat with another test user.
That was fine for testing... but, I need this connected to our LDAP (Active Directory) and then eventually to integrate with WebCenter Spaces. This is where I get lost...
I started following the Admin Guide, Configure Authentication Provider for OWLCS, in Section 5. But I'm confused over what type of authentication that is needed? Do I setup for Digest Authentication?
Being not quite sure, I started to follow the steps 5.7.4 Steps for Configuring Digest Authentication. First, I could not change my LDAP provider to store unecrypted passwords so I didn't change anything to the existing LDAP.
In 5.7.4.2 Reconfigure the DefaultAuthenticator Provider, I followed steps to change the DefaultAuthentication flag to "sufficient".
Next, I followed 5.7.4.3 and created an LDAP authentication provider for my Active Directory LDAP server. I checked my Users and Groups after restarting the Admin server and I can see my users and groups in the MyRealm Security Realm .
Here is where I need help... My LDAP admin is telling me that our LDAP cannot pass unencrypted passwords... so what are my options?
Do I really have to setup DigestAuthentication? What is the Credential Attribute Name that Active Directory LDAP users use?
Do I have to create a new Digest Authenticator?
I also have a few questions regarding the settings to Oracle Communicator but will wait until the above is resolved. I have some confusion on the settings on Oracle Communicator once the above is working. And then next, getting it to work with WebCenter Spaces.
Thanks in advance,
Phil

Hi Phil,
Integration with Active Directory is not supported for OWLCS. We support LDAP integration with Oracle Internet Directory (OID) only.
Please refer to section 5.12 in the Admin Guide at:
http://download.oracle.com/docs/cd/E14571_01/doc.1111/e13806/securityoverview.htm#CJAJEFHF
There are several steps which need to be followed carefully to configure OWLCS with OID, including installing Static Verifier and modifying OWLCS server instance.
Please also keep in mind that OWLCS is not available for production use; it is limited to development, testing, and non-production use only. It is not licensable at this time for middleware customers.

Similar Messages

  • SAP IDM with MS Active Directory (OU names in Arabic)

    Dear Gurus,
    With SAP IDM , we need to integrate with MS Active directory such a way that SAP IDM only fetches users who have “SAP” in one of the AD field. That means do not read entire AD but only fetches users in SAP who have “SAP” tagged in one of the AD field.
    Is it possible ? We tried that in SAP LDAP connector but its not possible in LDAP connector in SAP as LDAP connector is reading through all the users in our CUA system.
    Question is it possible through SAP IDM that we use some thing (maybe  BAPI) to restrict users and do not read all users but only users having “SAP” in one of the AD field.
    Also note that our AD has some OU's name in Arabic.
    Regards,

    If you want to filter this in the ADS Initial Load job then you can modify the repository LDAP Filter:
    (&(objectclass=person)(orgUnit=SAP))
    Replace orgUnit=SAP with your your attribute and tag.
    Br,
    Chris

  • OracleApps HRMS-R12.1.3 Integration with MS Active Directory (win 2008 R2)

    Dear Friends,
    we are using Oracle Apps R12.1.3 and the Microsoft Active Directory : Windows 2008 R2
    we have the following requirement:
    (1)From Oracle Apps to Active Directory.
    -Employee master information needs to be interfaced to Active Directory on a regular interval which should be updated in the active directory.
    (2)From Active Directory to Oracle system.
    -Whenever new email address for an employee is created in Active directory, the information needs to flow to Oracle HRMS.
    Please let us know the method to achieve with minimal latest oracle softwares?
    can it be done over coding from oracle apps without new softwares?
    Is Oracle Apps R12.1.3 certified with Windows 2008 R2 Active Directory?
    Regards,
    DB

    user564706 wrote:
    Dear Friends,
    we are using Oracle Apps R12.1.3 and the Microsoft Active Directory : Windows 2008 R2
    we have the following requirement:
    (1)From Oracle Apps to Active Directory.
    -Employee master information needs to be interfaced to Active Directory on a regular interval which should be updated in the active directory.
    (2)From Active Directory to Oracle system.
    -Whenever new email address for an employee is created in Active directory, the information needs to flow to Oracle HRMS.
    Please let us know the method to achieve with minimal latest oracle softwares?
    can it be done over coding from oracle apps without new softwares?
    Is Oracle Apps R12.1.3 certified with Windows 2008 R2 Active Directory?
    Regards,
    DBPlease update your original thread(s) instead of creating new one(s) -- Integrate Oracle Apps R12 with Microsoft Active Directory
    Thanks,
    Hussein

  • Portal Integration with Microsoft Active Directory

    We are working on a project to integrate Oracle9iAS Portal with Microsoft Active Directory. I am wondering if anyone has any experience with this and hence suggestions. Particularly, I'm wondering if its possible and how to use Active Directory to manage the Portal user accounts and group relationships?

    Please note that we finally got this working. For Active Directories sake, I would suggest using userPrincipalName or sAMAccountName as the Unique Attribute. Also, note that Active Directory uses OUs for organization, not CNs, so the search base should be either just the DN of the domain or an OU in the domain. Also, be sure to specify the full DN of the Bind DN as in CN=Administrator,CN=Users,DN=domain,DN=com

  • SSO All SAP solution with windows Active directory

    Dear Experts,
    We have multiple sap solution like
    SAP ERP EHP7
    SAP BW
    SAPBO
    SAP EES/MMS
    SAP Solution Manager
    And all solutions based on Operating system AIX and database is DB2
    We want to configure SSO ( using windows 2012 active directory users ) with all above systems and it's clients.
    Kindly guide me how to achieve SSO using Windows 2013 active directory users.
    DO we need LDAP between Active directory and all servers ?
    we need additional SAP license
    please guide me
    Regards

    Hello
    You can use SAP Single Sign-on 2.0 solution by SAP to integrate all your systems with SSO. The solution contains all what is required for configuring SSO in SAP ABAP and Java Systems. To know more, you may refer:
    1. SAP NetWeaver Single Sign-On 2.0 – SAP Help Portal Page
    2. Implementing SAP NetWeaver Single Sign-On 2.0 Based on Kerberos Tokens 1/4 - YouTube
    3.Implementing SAP NetWeaver Single Sign-On 2.0 Based on Kerberos Tokens 2/4 - YouTube
    4.  Implementing SAP NetWeaver Single Sign-On 2.0 Based on Kerberos Tokens 3/4 - YouTube
    5. Implementing SAP NetWeaver Single Sign-On 2.0 Based on Kerberos Tokens 4/4 - YouTube
    You will have to buy license for SAP Single Sign-on 2.0.
    Regards,
    Tapan

  • 802.1x PEAP Machine Authentication with MS Active Directory

    802.1x PEAP Machine and User Authentication with MS Active Directory:
    I have a simple pilot-text environment, with
    - Microsoft XP Client,
    - Cisco 2960 Switch,
    - ACS Solution Engine (4.1.4)
    - MS Active Directory on Win 2003 Server
    The Remote Agent (at 4.1.4) is on the same server as the MS AD.
    User Authentication works correctly, but Machine Authentication fails.
    Failed machine authenticaton is reported in the "Failed Attempts" log of the ACS SE.
    The Remote Agent shows an error:
    See Attachment.
    Without Port-Security the XP workstation is able to log on to the domain.
    Many thanks for any indication.
    Regards,
    Stephan Imhof

    Is host/TestClientMan.Test.local the name of the machine? What does the AAA tell for you the reason it fails?

  • Hello all...is there a way to activate(on startup) /deactivate(on logoff) CS6 Suite using a script, Active Directory Login Script or central Management Tool?

    hello all...is there a way to activate(on startup) /deactivate(on logoff) CS6 Suite using a script, Active Directory Login Script or central Management Tool?

    The long answer is: No. this is Adobe's secret sauce and you cannot manage it using other tools.
    Mylenium

  • Flash 10 install issues and use with PowerPoint

    Hi feeling really frustrated now and I'm keeping my fingers crossed for a quick solution.
    I'm running Windows 7, Flash 10.0.32.18 (now the Beta 10.1 in desperation) and I haven't had to reinstall flash on start up until last night so that was an unfortunate down turn of events for me and not even the reason for searching the forums.
    My issue started as I stood in front of one of my classes (I work in a College) with PowerPoint 2007 and a lesson ready to go and the Flash images that had always worked refused to be anything other than a still image with no interaction.
    Unfortunately when I upgraded to Windows 7 I carried out a clean install and reinstalled Office along with the latest versions of Flash, Shockwave etc. I say unfortunately because I now have no way of knowing where the problem lie. On asking, Microsoft are adamant that it is an Adobe issue and the forum would seem to back this up.
    On investigation I found that when looking at a slide the object was identified as a Flash object but I can't view any properties, also 'insert a shockwave flash object' is not available in the control toolbox. This would indicate that Flash is not installed even though viewing flash on the internet has not been an issue.
    The last issue that may help toward a solution is that when trying to view an .swf file I'm informed that I need to have FlashPlayer installed (I have) and when trying to use a third party flash player such as SWF Opener it also asks me to install flash.
    Like everyone else here I've installed, uninstalled all Flash etc. more times than I care to remember now.
    I'm not that technically minded when it comes to the nitty gritty of software operation and programming, I just like things to work.
    Please help as the most important thing I use my laptop for I now can't!!!!

    gm377!!!!
    Yeahhhhhhhhhhhh!
    Talk about famous 3 words, It's All Fixed is what I love to hear ! Well good for you, bet you are glad
    that is done and as I like to say when all of the ducks are in a row, FP is a piece of cake! It is always
    the ducks that cause the problems.
    You asked about the dates in manage add ons, as far as SFO is concerned and FP 10 it is more exact
    to look at Add/Remove, the screen shot I have shows Adobe Flash Player 10 Plug in and the date is
    11/18/09 probably when you did one of the Un/In stalls or the beta and it logged the correct version
    there in Add/Remove. However in the 1st screen shot of add ons, SFO is not even listed, probably due
    to the Uninstall and Reinstall actions. I have noticed Windows updates are listed in my Add/Remove, not
    when I install them, but when Microsoft issued them and maybe Adobe does the same thing. Then I have
    XP3/IE6, so you have differences there too. In my add on for example, no dates are shown and when I
    updated my SFO Active X (I can do that with IE6:-) I know when I did it. Even though you had Shockwave
    Flash Object listed you did not have the Flash10c.ocx which is the ActiveX CONTROL, the engine if you will
    that Flash Player 10 works together with so all Flash websites, youtube, etc need. Think of having a gas pedal
    and no gas in the tank, everything works together:-) The plug in you installed today was the Flash10c.ocx, the
    gas. Go look.
    Hey are the slides working now too?
    Ok, I'll take a Christmas card
    Well thanks for the "star" and appreciation and the best to you!
    eidnolb
    (I had some problems with fitting sentences and links on the posts today, that's the reason for the half sentences & funny looking paragraphs)
    Message was edited by: eidnolb to add a comment

  • How to deploy EUS  using OVD with existing active directory ?

    Hi,
    I am new in Oracle FMW and want to explore more into it,
    I have existing MS active directory with users and group policies defined there  and I need to implement the solution for  all users  to authenticate in oracle Database (11gR2) via AD.
    and after searching reading some docs I came to know that It can be done by  "EUS deployment using AD and OVD".
    Now I am bit confused for where to start Please guide me . My env is as follows
    I have existing MS AD server (win2003) and oracle Database 11gR2 on HP unix..So Do I need another server (Win2003/2008) to install OVD or can I install OVD on existing AD server.
    What exactly software required to install OVD as I have downloded software from e delivery site "Oracle Identity and Access Management 11g (11.1.1.7.0)"  
    Is it same or do i need to download other one?

    Check this:
    Installing and Configuring Oracle Virtual Directory
    OIM Image: OID and OVD 11g Basic Install Steps
    Oracle® Fusion Middleware
    Middleware Technologies : Installing Oracle Virtual Directory

  • Win7 C5180 No paper profiles installed to to use with Photoshop printing

    Reinstalled C5180 from a download for Win 7.  Now I cannot access the Printer  profiles for Advanced and Premium Plus Photo papers made for the C5180, C6180, C8180 , which had previously been available with the initial installation of my C5180 in XP.  I used them with Photoshop  for correct Color Management.  
     How can I find and install them? I still have the original CD but do not like to use this in case it interferes with the new software downloaded for Win7. Any suggestions?

    Hello,
    1. Maybe you have to activate/deactivate, so please have a look there:
    http://helpx.adobe.com/x-productkb/policy-pricing/activation-deactivation-products.html
    2, Sometimes, we know in the meantime, the "opm.db file" is the culprit. In this case you should delete it.
    3. Did you already try "uninstalling and re-installing"?
    Be careful with (de)installing aso. by (de)installing by your own resources. As much as I regret it and as strange as it may seem I fear it's a challenge for Adobe's Creative Cloud Cleaner Tool.
    Sometimes - for whatever reasons - CC doesn't "want" to work. In this case you should CC completely delete and reinstall by help of Adobe Creative Cloud Cleaner Tool. (A try to uninstall by own resources is not enough!)
    I quote: ... helps resolve installation problems for Adobe Creative Cloud and Adobe Creative Suite (CS3-CS6) applications. The tool removes installation records for prerelease installations of Creative Cloud or Creative Suite applications. It does not affect existing installations of previous versions of Creative Cloud or Creative Suite applications.
    Please use: http://helpx.adobe.com/creative-suite/kb/cs5-cleaner-tool-installation-problems.html    and follow the prescribed sequence of operations
    4.If necessary and for further questions click through http://helpx.adobe.com/contact.html  and if "open" please use chat, I had the best experiences.
    Good luck!
    Hans-Günter

  • Installing hardware to use with tmobil

    would like software for i phone black 8g to use with tmobil?

    There is no software to install, you simply insert the SIM card and (if necessary) modify the connection settings.
    If you are referring to T-Mobile USA, they are not a supported carrier and no one here can assist you.
    All of this assumes your device is either carrier locked to Tmobil or is an unlocked device.

  • SSO (single sign on) on NetWeaver 7.0 Enterprise Portal based on spnego with Microsoft Active Directory

    Hi,
    we are using SAP Netweaver Enterprise Portal 7.0 (SP25) based on Windows 2008 R2/Oracle 11g.
    When we setup the Portal, we used the UME of the ECC - ABAP.
    The portal is used internally only.
    Now we want to provide SSO.
    User authenticate against Windows Active Directory (Windows 2003).
    We thought SSO via spnego would be the best solution.
    Any better alternates, we should use?
    We are following the SAP documentation:
    SAP-Bibliothek - Benutzerauthentifizierung und Single Sign-On
    We still want to create users in ABAP and assign them the portal roles. LDAP access should only have read access, to verify the security token from Active Directory.
    When we setup the portal from scratch using ABAP as its UME, in the system configuration, LDAP can't be selected/add as data source.
    In case we understand the documentation correctly, we would now need to add LDAP via the configtool for read access.
    What is not clear to us, when we active now LDAP via config tool, if we would now lose the ABAP connection.
    Is there a tutorial for SSO Netweaver 7.0 EP, like for EP 7.3, available?
    In 7.3 SSO is pretty simple to get it running, thanks to the many tutorials here and on the internet.
    Thanks for your help.
    Best regards
    Carlos Behlau

    Hi,
    I was able to generate the key via ktab program.
    But when I am enable SSO, nothing is happening when I try to log-on via SSO to the portal.
    I installed WebDiag tool on the portal server and ran trace.
    The users are located in domain: company.com of activate directory.
    The Java AS are located in domain: sap.company.com of activate directory.
    The sap.company.com domain acts as child of company.com.
    When I check the WebDiag trace, I see for the SPNegoLoginModule - the entry "... no key (etype: 23) for realm sap.company.com available ..."
    I would except company.com as realm key, as the keytabs have been generated on the domain controller of company.com.
    Is it possible to get SSO with child domain running?
    Based on the statement of the network folks, child and father domain having a trust.
    Thanks for your help.
    Best regards
    Carlos

  • Unable to login with an Active Directory account on 10.6.7

    I just got a Mac Airbook and I'm trying to connect with my AD account. I was able to bind my computer to the domain succesfully but when I try and logon with my AD account I get the shakes. I verified my binding with the green light next to "Network Account Server". I asked some admins who have older macs and they guided me through the settings but it still doesn't work for me. The only thing that shows up in the logs when I attempt to login is "Active Directory could not find GUID for DOMAIN\domain to update admin group". And yes, my local user is different than my AD user.
    Any ideas?

    Not for me. Some things mount others do not. Plus you can't use links from e-mails or save to from applications. It makes most applications completely unuse-able for me. It looks like I'm going to have to run almost everything over Parallels. Kind of of lame that Mac can't get this fixed.

  • Oracle VDI 3.3 Directory access with Windows2008 Active Directory

    Hi
    can some body help me to solve this issue?
    I install oracle VDI 3.3 and I configure Windows2008 Active Directory for authentification.
    I made some test in command line
    kinit -v user
    and I received the message "Authenticated to Kerberos v5"
    but when I tried to create a company to do another configuration I receive the following error:
    Unable to Connect to User Directory
    Failed to connect, no servers available.
    BR

    I am in the same situation and have tried everything. I am using VDI 3.4 and able to authenticate using knit command but cannot setup up my company.
    AD is 2011 Small Business Server and the domain is domain.local
    Any help would be appreciated. Thanks

  • HT201358 Can ARD3 work with the Active Directory setup on a Windows machine and without the need of Open Directory

    We need the 'Golden Triangle' setup to work with ARD3 running on a Mac server with client Mac details retrieved from a Windows Active Directory. In this system, the ARD3 will be used to install packages from a Mac OS X server, where the client Mac list is gathered directly from a Windows Active Directory, which is already in place.
    So, please guide me whether Apple Remote Desktop 3 is capable of getting client machine details from an Active Directory without the need of re-creating the client Mac list in the Mac server running ARD3.
    If ARD3 can not be used in this case, do you recommend any other tools that can resolve our issue.
    Thank you in advance.
    Sudheesh.

    ARD cannot directly obtain client information from Active Directory, no. It may be possible to create a script that would get such information and be able to put it into ARD, but I wouldn't begin to know how to write such a script. You may also be able to bind your OS X Server to ARD and create groups there. This article is obsolete for 10.6 or later but may provide some clues as to how to proceed:
    http://support.apple.com/kb/TA24276
    There are a number of third-party systems that can manage Macs that may be able to draw information from AD, such as Casper, LANDesk, and others. Which if any would meet your needs depends on many factors including how many devices you need to manage, whether you're looking for a cross-platform tool, your budget, etc. This is a difficult issue to address in a forum like this since there are so many variables to be considered.
    Regards.

Maybe you are looking for

  • Link to an iTunes song?

    Is there a way to post a link from my blog to specific songs in iTunes...some times I want to be able to send people on my blog over to hear the sample of a song I'm blogging about, and who knows, maybe my reco's will lead to sale & make the stock go

  • Web searches are being done using yahoo and not google. I tried the fixes given but they don't work. I want to use Google by default

    only by clicking on mozilla firefox start page can i get a google search. the initial screen always uses yahoo

  • Android 5.0 and ISE

    Hi, Anybody tried ISE Native Supplicant Provisioning with Android 5.0? I have ISE 1.3 in production and I can do NSP on iPad iOS 8.0.2 and Nexus 7 Android KitKat 4.4.4 but the Cisco Network Setup Assistant app. doesn't work with Nexus 5 Android Lolli

  • Logic for this senerio -- UDF

    Hi XI Gurus,                       I hav to create a UDF.This is an IDOC - XI - FILE seerio. In  this senerio is I have an IDOc whose 7th segment contains a field. This field can store values in between 0 - 9. On the other hand I have a file structur

  • How to Retrieve a List of Business Objects using DI Server?

    In DI Server (and DI-API) I could not find how I can get a list of business objects, for instance ServiceCall objects. and more - say i need the list with a filter on customer code and call status?