Projects dropped from shared services when creating an essbase application

When we try to create an essbase application via EAS - there is an error message Unable to createExternalUser. then when we log in to shared services - there are no projects available.
This is for version 9.3.1.0

Hi Cameron,
many thanks for your answer.
Well let me explain a little bit further:
I created an own security module which manages the whole security in Essbase. I get the grants from a corporate system and then just apply them by some definitions natively in Essbase using filters etc.
To make sure the grants on the server are exactly the same as the grants that get delivered to me, I export the complete security in Essbase using MaxL and import it to a relational DB. I then check whether there are any grants which shouldn't be there and vice versa.
If now an admin user creates an application, he gets an additional application manager grant for this application. He does not loose his admin permissions.
Now in my check this application manager grant pops up as this grant is not in the corporate system but created Essbase internally when a application is created.
If I export the complete security this application manager grant is there.
I would like to get rid of these errors in my check. Also it makes no sense that an admin user gets an Application Manager grant because he already has that permission as an admin user.
I already searched the documentations but didn't find a setting to disable this behaviour of Essbase.
Btw. Essbase version is 11.1.1.3.
Maybe someone of you guys know if there is any chance to do this - if not, I have to find another solution.
Thanks and kind regards,
Thomas

Similar Messages

  • EAS Console - Not getting the option "Refresh security from Shared Services"

    Hi,
    In EAS Console 11.1.2.2, I am not getting the option "Refresh security from Shared Services" when I right click on Security (under Essbase Servers).
    However, I can see this option via EAS Console 11.1.1.3 (current existing version).
    Could you please let me know how can I get this option in EAS Console 11.1.2.2? Is this by any chance related to the option "Externalize Users"?
    Thanks in advance.

    Thanks a lot join for this information and your kind support .
    One more question:
    The owner of the Planning application is user 'hypadmin'.
    I can see the SIDs of user 5001 a little different in both the versions. Is this ok?
    Hyperion Planning 11.1.1.3 (Existing Environment)
    USER_ID     SID ROLE SYNC_PSWD OFFLINE_ENABLED HUB_ROLES
    50001          native://DN=cn=0fa19f8241602600:3b78a0e0:130926693d2:-78ba,ou=People,dc=css,dc=hyperion,dc=com?USER 3 2 0 5019
    Hyperion Planning 11.1.2.2 (New Environment)
    USER_ID     SID ROLE SYNC_PSWD OFFLINE_ENABLED HUB_ROLES
    50001           native://nvid=54aec0428a3ba591:-44b7ca9b:13f03c114d2:-5d99?USER 3 2  4507
    I have not yet performed "Externalize Users" yet in the new environment (11.1.2.2) throgh EAS Console. Is it required in the newer version 11.1.2.2?

  • Error with Active Directory Synchnorisation from Shared Services to Essbase

    Have recently installed HS9 v 9.3.1
    In Shared Services i have created both native and MSAD users. Everything works fine with the native users (Planning,EAS etc...)
    MSAD user directory has been configured & tested -ok on Workspace.
    The MSAD users have been provisioned and can access Workspace & Shared services without any issue.
    However, when accessing Planning, the following error is displayed in the Essbase server log:
    Tue Mar 18 15:12:39 2008]Local/ESSBASE0///Info(1051001)
    Received client request: Create External User With Type (from user [hyperion])
    [Tue Mar 18 15:12:39 2008]Local/ESSBASE0///Error(1051205)
    Single Sign On function call [css_getUser] failed
    [Tue Mar 18 15:12:39 2008]Local/ESSBASE0///Warning(1051003)
    Error 1051205 processing request [Create External User With Type] - disconnecting
    [Tue Mar 18 15:12:39 2008]Local/ESSBASE0///Info(1051001)
    Received client request: Set Application FrontEnd Type (from user [hyperion])
    [Tue Mar 18 15:12:39 2008]Local/ESSBASE0///Info(1051001)
    Received client request: Get Security Mode (from user [hyperion])
    [Tue Mar 18 15:12:39 2008]Local/ESSBASE0///Info(1051001)
    Received client request: Set Application Id For Planning (from user [hyperion])
    [Tue Mar 18 15:12:39 2008]Local/ESSBASE0///Info(1051001)
    Received client request: Get Security Mode (from user [hyperion])
    [Tue Mar 18 15:12:39 2008]Local/ESSBASE0///Info(1051001)
    Received client request: Get Security Mode (from user [hyperion])
    [Tue Mar 18 15:12:39 2008]Local/ESSBASE0///Info(1051001)
    Received client request: Re-Sync User/Group with Single application (from user [hyperion])
    [Tue Mar 18 15:12:39 2008]Local/ESSBASE0///Info(1051590)
    Synchronization started for user/group [MSADUser]
    [Tue Mar 18 15:12:39 2008]Local/ESSBASE0///Info(1051591)
    Synchronization completed for user/group [MSADUser]
    [Tue Mar 18 15:12:39 2008]Local/ESSBASE0///Error(1051013)
    User/group MSADUser does not exist
    [Tue Mar 18 15:12:39 2008]Local/ESSBASE0///Warning(1051003)
    Error 1051013 processing request [Re-Sync User/Group with Single application] - disconnecting
    ---------- When accessing through XL Addin, the foll is displayed:
    [Tue Mar 18 16:49:09 2008]Local/ESSBASE0///Error(1051012)
    User MSADUser does not exist
    [Tue Mar 18 16:49:09 2008]Local/ESSBASE0///Warning(1051003)
    Error 1051012 processing request [Login] - disconnecting
    Thanks !!!

    Hardcode IP addresses instead of the server names in the essbase.cfg file and the Shared Services CSS.XML file for the Shared Services server references.
    Restart SS/Essbase, provision an MSAD user, then do a Refresh from Shared Services in AAS.
    Verify your MSAD userID then shows up as an Essbase user in AAS(Display User list for the Essbase server)
    As long as the MSAD users show up in the user list, they should be working.

  • Refreshig security from shared services

    let us assume that we are creating 5 users in shared services and provisioning them with different privileges. when refreshing these users security from shared services to essbase , i need to refresh the security of only one particular user role, how can i do that?

    if using 9.3.1 later version u can use Shared servicves patch whcih will automatically update the security
    or esle right clik on EAS security > refresh security from shared services > all users or currecnt users
    which will update ur security
    Refresh each user or group individually using MAXL command:
    alter user username sync security with all application;
    alter group groupname sync security with all application;

  • How to deregister epm instances from shared services

    Hi All,
    I had Hyperion EPM 11.1.2.1 on Windows Server A and repsitories on Oracle Database B.
    I freshly installed Hyperion EPM 11.1.2.1 on Windows Server C and configured it with repositories on Oracle Database D (which are exact replica of repositories on Oracle Database B).
    Now what I'm stuck with is that shared services on Windows Server C is still configured with Essbase/Planning instance of Windows Server A as well. This is creating problems for me when I try to access calculation manager on Windows Server C and I see Essbase/Planning applications from Essbase instance of Windows Server A.
    Is there anyway I can deregister the entire epm instance of Windows Server A from shared services on Windows Server C?
    I don't want any connections between EPM on Windows C and EPM on Windows A because soon windows server A will be retired.
    Any help will be much appreciated.
    Best regards,
    Jayant Sahewal

    Removing instances in 11.1.2.1 is not so easy, it is not until 11.1.2.3 that there is an option to remove an instance, in 11.1.2.1 you really have to uninstall products to remove them from the registry, then also try applying the registry cleaner patch to see if it helps, if it doesn't then look at the epmsys_registry utility to delete entries from the registry.
    Cheers
    John
    http://john-goodwin.blogspot.com/

  • Unregister Essbase/EAS from Shared services

    Hi Is it possible to unregister essbase, EAS from shared services? if so can some one please guide me unregister. we are on EPM 11.1.1.3
    Thanks

    Hi,
    I've a similar issue with my customer.
    In fact we have an an application with several databases and end users have read access on one, write acces on another and finally calculation accesses (but only on few calc scripts) on the last database.
    SO, in shared security mode we can't reach all these requirements, beacause access are granted at the Essbase application level.
    Therefore, the only solution I've found to put Essbase in stand-alone mode is to drop the essbase.sec file and recreate the essbase applications thanks to EAS or maxl commands.
    For EAS I've found a topic on this forum, and the solution is to edit the olapadmin.properties file on the installation path of EAS server and to swith the value HUBProvisionEnabled=true at false.
    You have to stop and start the services to do that but it works. And when started, you can use the EAS default login.
    Edited by: Eric_M on May 2, 2011 6:02 AM

  • Administration Users from Shared Services...

    Dear Experts,
    Am using OEPM 11.1.1.2
    I have one basic question on Shared Services Users...As we are using the default login of Essbase administration services after installation and configuration to
    login to the server and this is already changed to Shared Services Security during Configuration..
    My question is can we be able to create user related to EAS from Shared Services or still we need to use the same default 'admin'? If so,
    In any case if i want to provide one user with only "create/delete applications" for Essbase....i will go and do it in Shared Services.....
    but if i want to modify something in Essbase...i still need to use EAS for modifying the application/Database information
    How can i create multiple users in EAS?
    One More, i don't see any project for Essbase Administration Services like Essbase, APS created in Shared Services after the applications have moved to Shared Services Security Mode...Is this correct? Please clarify
    Moreover, in my case userid "admin" is used for all the Application groups in Shared Services...So if i change the password for this "ID", will it reflect to all the application groups who are privileged to...
    Thanks

    My question is can we be able to create user related to EAS from Shared Services or still we need to use the same default 'admin'? If so,
    In any case if i want to provide one user with only "create/delete applications" for Essbase....i will go and do it in Shared Services.....
    but if i want to modify something in Essbase...i still need to use EAS for modifying the application/Database information
    How can i create multiple users in EAS?
    One More, i don't see any project for Essbase Administration Services like Essbase, APS created in Shared Services after the applications have moved to Shared Services Security Mode...Is this correct? Please clarify
    Moreover, in my case userid "admin" is used for all the Application groups in Shared Services...So if i change the password for this "ID", will it reflect to all the application groups who are privileged to...
    Firstly, Shared services is a centralized User management console for all hyperion applications. Once you externalize your security to shared services, You can create as many users as you want in shared services and assign him access to Essbase. How ever, You will have to go to EAS and do a "refresh security from shared services" for changes made to users in shared services to reflect in Essbase.
    For projects to appear under shared services project list, you will have to register each product with the shared services.
    If the same admin ID is used for all applications, Yes, the password change will reflect to all applications he has access to.
    -Nra

  • Assign Analytic Servers under Projects folder in Shared Services

    Hello experts,
    The problem is that: we are migrating dev environment to a new test environment. All is done, but when I try to assign "Administrator" role for Essbase server to an especific user, I can't see "Analytic Servers" option under Projects folder in Shared Services (where is Essbase server in dev environment).
    How can I assign that role if I can't see Essbase server in Shared Services? Can I assign it? How?
    Thanks for your time!
    Best Regards
    Edited by: user1654709 on 31-ago-2012 10:37

    Hi,
    You can do the following:
    1. Launch the MaxL Prompt and connect to Essbase Server using the Administrative user
    2. Execute the following:
    alter system resync sss;
    alter application all reregister;
    If the Essbase security is externalized, the above commands will execute successfully. If Essbase is not registered to Shared Services, then you execute the following command:
    MAXL> display system security mode;
    +.....If it is 1 then run the alter command:+
    MAXL> alter system set sss_mode <ENFORCE-PWD-SPEC>;
    Please read http://docs.oracle.com/cd/E17236_01/epm.1112/esb_tech_ref.pdf page 671 regarding <ENFORCE-PWD-SPEC> option to decide (depending on number of users on the system) what "password option" is best for you.
    After successful, externalization of security, then execute again the following:
    MAXL>alter system resync sss;
    MAXL>alter application all reregister;
    Hope it helps....
    KosuruS
    Edited by: KosuruS on Sep 6, 2012 12:02 PM
    Edited by: KosuruS on Sep 6, 2012 12:03 PM

  • Refresh security from Shared Services fails - System11

    Hi All,
    WHen refreshing the Essbase security from Shared Services in System 11 we get the following error:
    Error 1051522: Essbase failed to get group's member tree with Error [CSS Error: Unknown error: Could not get exception message from exception object]
    We see the same error in the Essbase log.
    In the Shared Service Security CLient.log we get the following warnings:
    2009-03-03 16:12:58,294 WARN [Thread-108] CSS dll either not found in java.library.path or can't be loaded[Root Cause: D:\Hyperion\common\CSS\9.5.0.0\bin\css-9_5_0.dll: Can't load IA 32-bit .dll on a AMD 64-bit platform ] com.hyperion.css.spi.impl.ntlm.NTLMTrustedDomain.<clinit>(Unknown Source)
    2009-03-03 16:12:58,294 WARN [Thread-108] Error initializing trusted domains or the workstation name.[Root Cause: getNtTrustedDomains ] com.hyperion.css.spi.impl.ntlm.NTLMTrustedDomain.<clinit>(Unknown Source)
    Has anyone come across this?
    Thanks for your help.
    Seb

    Hi Seb,
    I take it you are using NTLM as your external authentication.
    The error message means that it can't see css-9_5_0.dll in the path, if you are on windows make sure the path contains <drive>:\Hyperion\common\CSS\9.5.0.0\bin\
    If it doesn't update the environment variables, not sure if you need to reboot it may pick it up straight away, you can check by going to a command prompt and running echo %path%
    Cheers
    John
    http://john-goodwin.blogspot.com/

  • Problem with Business Rules access from Shared Services

    Hello,
    When trying to access Business Rules from Shared Services (expand Business Rules and click on the application) I get the "Refer to the Security Guide to configure security permissions for this application" message, but the user is fully provisioned for Business Rules. It happens even logged on as admin. Access from Administration Services works fine. The version Hyperion system 9 (9.3.0.1). What is wrong? Help, please.
    Thanks,
    Timur

    You can't access Business Rules from Shared Services. This is no different from any other application - Planning, Essbase, etc. You can provision users to the application roles, but you can't actually do anything with the application, other than security, in Shared Services. You use Admin Services to maintain Business Rules.

  • Error migrating Security from Shared Services.

    Hi,
    I was using Hyperion Planning 9.3.1's in Import/ Export utility in D:\Hyperion\common\utilities\CSSImportExportUtility\cssimportexport\importexport\CSSExport.bat. I'm trying to export Security from Shared Services into xml format. I get the following error message:
    Malformed \uxxxx encoding
    Anyone with similar experiences? Hyperion's impexp.pdf makes the steps so complicated!!

    Answering my own question:
    Since I am in Windows, I was using backslashes in my paths when I updated file:
    importexport.properties
    The error went away after I changed the backslashes to forward slashes in all paths.

  • Refresh Security from shared services.

    Hi
    When ever there are any changes in the security at shared services(LDAP) , I am doing a refresh security from shared services(@EAS)
    -in order to get these changes from shared services.
    Which is taking 30 minutes refresh ever time in our systems.
    Is there any other way to make quickone?
    Version - 11.1.1.3
    Thanks

    strange? We are still on 931 (Essbase on 9.3.1.6) and refreshing security is not necessary at all any more. It is even deprecated functionality. I always though that 11 did not have it too.^^^The end (or most of the end) of Essbase.sec came in a late patch of 9.3.1. It isn't there yet in 11.1.1.3, I think. It is in 11.1.2. There was not a lot of fanfare about the change although it's there in the patch notes.
    Regards,
    Cameron Lackpour

  • How to sync user for planning from Shared Services

    Hi ..
    Can anybody please let me know how to sync users for planning from shared services.
    Thank you.

    You need to expand on your question.
    But the basic concept is you create or connect (for LDAP) users in Shared Services. You also create groups as required for these users. Then in shared services you provision those user to Planning applications (directly or indirectly through groups)
    Then in Planning you will see users or groups. And in planning you connect them to either members in dimensions or to objects like Forms, Task lists, Business Rules.
    There is therefore no such thing as synching Shared Services with Planning.
    Note: the 2 steps mentioned above can be done in batch through load utilities.
    Please expand you question if necessary

  • Error from EAS - "refreshing security from Shared Services failed"

    Hi,
    I was using Native only security in HSS for Essbase 11.1.1.3 and EAS allowed me to Refresh security from Shared Services. (Essbase security was already externalized to HSS.)
    However, after I added "MS Active Directory", and provisioned a MSAD user to a native Planning group, EAS errors out with "refreshing security from Shared Services failed" .
    I checked Essbase security and that MSAD user is not added to Essbase.
    From Essbase Log I see:
    Essbase failed to get roles list for [ESB:Analytic Servers:servername:1] from Shared Services Server with Error [32:1062:Failed to connect to the user directory [ HSS'sMSADname].
    I then tried to remove MSAD from our H Shared Services and see if this problem goes away. However, MSAD still shows on the left panel menu in H Shared Services. How can I get rid of MSAD?
    Any suggestions?
    Edited by: user643332 on May 12, 2010 12:05 AM

    Hi,
    Are you sure you have removed it from shared services, you may have just disabled it.
    You must restart the shared services application server to apply any changes made.
    Cheers
    John
    http://john-goodwin.blogspot.com/

  • Exclude a user from Shared Services LCM export

    How do I exclude a specific user from the Shared Services LCM export?  In the migration definition file I am trying to specify something like the following:
    pattern="*" and pattern<>"lcm_admin"

    What exactly you want to try after/by exporting users from Shared services?
    Regards,
    Santy.

Maybe you are looking for

  • What is the text suffice for verizon applie iphone

    What is the text/email suffice for sending a text via email for the verizon network using and applie Iphone?

  • Mediawiki, mysql, php? problems [SOLVED]

    On Sunday my Arch install that is hosted by Slicehost became unresponsive to them so they had to do an emergency reboot. After it came back up my install of mediawiki was (and still is) only returning a blank page (at least in Firefox). After some di

  • WAD : Create specific command in the WAD.

    Hello, Is it possible to create specific command in oder to manage parameter not available in the standard command list. For example : user want to be able to change Charts axis value with a command button If someone can provide sample code to call W

  • Simple frame around pictures

    Hi, I'm trying to simply place a thin border around either a block of text or photo so they stand out as boxed on a white background.  Can anyone help. Thanks

  • Code synchronization across the cluster

    Do the App Servers take care of synchronizing webapp java code across multiple nodes of a cluster. or does synchronizing work only on a single JVM Thanks, Sunil.