Refresh Security from shared services fails.

Hello all,
On our environment I went into shared services with admin rights and changed the native directory password. And from then on I have not been able to refresh the security of essbase server in EAS. I get the following error,
Essbase failed to get roles list for [ESB:Analytic Servers:Servername:1] from Shared Services Server with Error [32:1062:Failed to connect to the user directory [Native Directoy].]
Also I would like to know if native directory password means the password "password" which comes as default for the username admin. Am new to essbase and was under the impression that native directory password means the password "password" which came as default for the username admin. Please help, this is a production issue which started only because I changed the native directory password and now I need to get it fixed.
Thanks.
Edited by: Teddd on Jan 6, 2013 4:07 PM

Please confirm the version of the Shared Services (HSS) and Essbase, EAS server.
Also let me know, if the HSS, ESSBASE & EAS installed on the same box ?
If they are on the different servers, ensure that there is no network communication issues.. (try performing telnet on the port from each other servers)
E.g Open command prompt - telnet servername port (telnet HSS_SERVER 28080), hit enter.. if it shows the blank screen .. it is successful and there is no communication issues.
Also you could try..
On EAS server, add the below in windows registry under EAS... and restart the machine..
ESS_CSS_JVM_OPTION1 = -Dcom.hyperion.css.socketTimeout=60000
if you are not comfortable updating the registry contact you admin and ensure to take the backup before editing...

Similar Messages

  • Error from EAS - "refreshing security from Shared Services failed"

    Hi,
    I was using Native only security in HSS for Essbase 11.1.1.3 and EAS allowed me to Refresh security from Shared Services. (Essbase security was already externalized to HSS.)
    However, after I added "MS Active Directory", and provisioned a MSAD user to a native Planning group, EAS errors out with "refreshing security from Shared Services failed" .
    I checked Essbase security and that MSAD user is not added to Essbase.
    From Essbase Log I see:
    Essbase failed to get roles list for [ESB:Analytic Servers:servername:1] from Shared Services Server with Error [32:1062:Failed to connect to the user directory [ HSS'sMSADname].
    I then tried to remove MSAD from our H Shared Services and see if this problem goes away. However, MSAD still shows on the left panel menu in H Shared Services. How can I get rid of MSAD?
    Any suggestions?
    Edited by: user643332 on May 12, 2010 12:05 AM

    Hi,
    Are you sure you have removed it from shared services, you may have just disabled it.
    You must restart the shared services application server to apply any changes made.
    Cheers
    John
    http://john-goodwin.blogspot.com/

  • Refresh security from Shared Services fails - System11

    Hi All,
    WHen refreshing the Essbase security from Shared Services in System 11 we get the following error:
    Error 1051522: Essbase failed to get group's member tree with Error [CSS Error: Unknown error: Could not get exception message from exception object]
    We see the same error in the Essbase log.
    In the Shared Service Security CLient.log we get the following warnings:
    2009-03-03 16:12:58,294 WARN [Thread-108] CSS dll either not found in java.library.path or can't be loaded[Root Cause: D:\Hyperion\common\CSS\9.5.0.0\bin\css-9_5_0.dll: Can't load IA 32-bit .dll on a AMD 64-bit platform ] com.hyperion.css.spi.impl.ntlm.NTLMTrustedDomain.<clinit>(Unknown Source)
    2009-03-03 16:12:58,294 WARN [Thread-108] Error initializing trusted domains or the workstation name.[Root Cause: getNtTrustedDomains ] com.hyperion.css.spi.impl.ntlm.NTLMTrustedDomain.<clinit>(Unknown Source)
    Has anyone come across this?
    Thanks for your help.
    Seb

    Hi Seb,
    I take it you are using NTLM as your external authentication.
    The error message means that it can't see css-9_5_0.dll in the path, if you are on windows make sure the path contains <drive>:\Hyperion\common\CSS\9.5.0.0\bin\
    If it doesn't update the environment variables, not sure if you need to reboot it may pick it up straight away, you can check by going to a command prompt and running echo %path%
    Cheers
    John
    http://john-goodwin.blogspot.com/

  • EAS Console - Not getting the option "Refresh security from Shared Services"

    Hi,
    In EAS Console 11.1.2.2, I am not getting the option "Refresh security from Shared Services" when I right click on Security (under Essbase Servers).
    However, I can see this option via EAS Console 11.1.1.3 (current existing version).
    Could you please let me know how can I get this option in EAS Console 11.1.2.2? Is this by any chance related to the option "Externalize Users"?
    Thanks in advance.

    Thanks a lot join for this information and your kind support .
    One more question:
    The owner of the Planning application is user 'hypadmin'.
    I can see the SIDs of user 5001 a little different in both the versions. Is this ok?
    Hyperion Planning 11.1.1.3 (Existing Environment)
    USER_ID     SID ROLE SYNC_PSWD OFFLINE_ENABLED HUB_ROLES
    50001          native://DN=cn=0fa19f8241602600:3b78a0e0:130926693d2:-78ba,ou=People,dc=css,dc=hyperion,dc=com?USER 3 2 0 5019
    Hyperion Planning 11.1.2.2 (New Environment)
    USER_ID     SID ROLE SYNC_PSWD OFFLINE_ENABLED HUB_ROLES
    50001           native://nvid=54aec0428a3ba591:-44b7ca9b:13f03c114d2:-5d99?USER 3 2  4507
    I have not yet performed "Externalize Users" yet in the new environment (11.1.2.2) throgh EAS Console. Is it required in the newer version 11.1.2.2?

  • Essbase EAS - Refresh Security from Shared Services

    Hi All,
    Just went live with Essbase. We are using MSAD Groups in Shared Services for our users. I noticed that if we add a new user to a provisioned group, they don't automatically get access to Essbase. I believe I have to select 'Refresh Security From Shared Services' in EAS. I am nervous about doing this with users in the system as I don't want to accidentally boot them out. Is there any risk? Reports stopped? Users forced to logout? Smartview implications?
    I feel like I did it before and disrupted some users during development but I am not sure.
    Much Appreciated,
    Mike

    Thx. I just did it and it didn't seem to disrupt anything. I tested with a user with a smartview open, a report running and a WA dashboard on screen. It did mention that after refreshing the essbase server would be disconnected and i would have to reconnect but it didn't actually boot me out or disrupt any process.
    I guess it's okay to do on a live production system. ?
    Thx,
    Mike

  • Refresh Security from shared services.

    Hi
    When ever there are any changes in the security at shared services(LDAP) , I am doing a refresh security from shared services(@EAS)
    -in order to get these changes from shared services.
    Which is taking 30 minutes refresh ever time in our systems.
    Is there any other way to make quickone?
    Version - 11.1.1.3
    Thanks

    strange? We are still on 931 (Essbase on 9.3.1.6) and refreshing security is not necessary at all any more. It is even deprecated functionality. I always though that 11 did not have it too.^^^The end (or most of the end) of Essbase.sec came in a late patch of 9.3.1. It isn't there yet in 11.1.1.3, I think. It is in 11.1.2. There was not a lot of fanfare about the change although it's there in the patch notes.
    Regards,
    Cameron Lackpour

  • Refreshig security from shared services

    let us assume that we are creating 5 users in shared services and provisioning them with different privileges. when refreshing these users security from shared services to essbase , i need to refresh the security of only one particular user role, how can i do that?

    if using 9.3.1 later version u can use Shared servicves patch whcih will automatically update the security
    or esle right clik on EAS security > refresh security from shared services > all users or currecnt users
    which will update ur security
    Refresh each user or group individually using MAXL command:
    alter user username sync security with all application;
    alter group groupname sync security with all application;

  • Error migrating Security from Shared Services.

    Hi,
    I was using Hyperion Planning 9.3.1's in Import/ Export utility in D:\Hyperion\common\utilities\CSSImportExportUtility\cssimportexport\importexport\CSSExport.bat. I'm trying to export Security from Shared Services into xml format. I get the following error message:
    Malformed \uxxxx encoding
    Anyone with similar experiences? Hyperion's impexp.pdf makes the steps so complicated!!

    Answering my own question:
    Since I am in Windows, I was using backslashes in my paths when I updated file:
    importexport.properties
    The error went away after I changed the backslashes to forward slashes in all paths.

  • Security from shared services

    Hi all:
    Essbase has been activated the security of users using shared services, but do not want to use more, according to documentation that is not possible.
    how to do it? , or should be reinstalled essbase to cancel the utility?
    thanks

    So the first error is because the user can't be migrated -- this sort of makes sense.
    Have you tried creating a dummy user, like TestUser1, in Shared Services, and then provision him to Essbase server access, and maybe read access to Sample.Basic? Does that work? I would leave out all group membership just to prove that you can do that.
    If that works, have you tried creating a simple group (groups can have multiple levels of inheritance which can be really powerful but can get SNAFU'd as you are seeing) in Shared Services and assigned it to Sample.Basic? If that works, create another native user like TestUser2 and assign him to that group.
    I guess I'm getting at an incremenatlist approach to see what breaks. If nothing works, then I would go for the scorched earth policy and try again with Essbase.sec -- you won't have much to lose.
    Regards,
    Cameron Lackpour

  • Essbase Refresh security from SS failed

    Hi,
    we are getting the error while refresh security from shared services from Essbasse....
    "Refreshing security from Shared Services failed"
    In essbase error log can see below.....
    Error(1051522)...Analytical Services failed to get group's member tree with Error [Failed to create an initial directory context for MSAD]
    Please help.
    Thanks.

    Thx. I just did it and it didn't seem to disrupt anything. I tested with a user with a smartview open, a report running and a WA dashboard on screen. It did mention that after refreshing the essbase server would be disconnected and i would have to reconnect but it didn't actually boot me out or disrupt any process.
    I guess it's okay to do on a live production system. ?
    Thx,
    Mike

  • Administration Users from Shared Services...

    Dear Experts,
    Am using OEPM 11.1.1.2
    I have one basic question on Shared Services Users...As we are using the default login of Essbase administration services after installation and configuration to
    login to the server and this is already changed to Shared Services Security during Configuration..
    My question is can we be able to create user related to EAS from Shared Services or still we need to use the same default 'admin'? If so,
    In any case if i want to provide one user with only "create/delete applications" for Essbase....i will go and do it in Shared Services.....
    but if i want to modify something in Essbase...i still need to use EAS for modifying the application/Database information
    How can i create multiple users in EAS?
    One More, i don't see any project for Essbase Administration Services like Essbase, APS created in Shared Services after the applications have moved to Shared Services Security Mode...Is this correct? Please clarify
    Moreover, in my case userid "admin" is used for all the Application groups in Shared Services...So if i change the password for this "ID", will it reflect to all the application groups who are privileged to...
    Thanks

    My question is can we be able to create user related to EAS from Shared Services or still we need to use the same default 'admin'? If so,
    In any case if i want to provide one user with only "create/delete applications" for Essbase....i will go and do it in Shared Services.....
    but if i want to modify something in Essbase...i still need to use EAS for modifying the application/Database information
    How can i create multiple users in EAS?
    One More, i don't see any project for Essbase Administration Services like Essbase, APS created in Shared Services after the applications have moved to Shared Services Security Mode...Is this correct? Please clarify
    Moreover, in my case userid "admin" is used for all the Application groups in Shared Services...So if i change the password for this "ID", will it reflect to all the application groups who are privileged to...
    Firstly, Shared services is a centralized User management console for all hyperion applications. Once you externalize your security to shared services, You can create as many users as you want in shared services and assign him access to Essbase. How ever, You will have to go to EAS and do a "refresh security from shared services" for changes made to users in shared services to reflect in Essbase.
    For projects to appear under shared services project list, you will have to register each product with the shared services.
    If the same admin ID is used for all applications, Yes, the password change will reflect to all applications he has access to.
    -Nra

  • Security Refresh of Shared Services Failing 11.1.1.3

    I executed a manual refresh of SS security in EAS after provisioning a new externally authenticated user and the refresh failed. I researched the issue in the log files, and the automatic daily refresh I have set to run via the config file has been failing since the last recycle of services (complete stop and start of services from reliable scripts).
    Oracle suggested I stop and restart certain services including a longer pause between SS and EAS/Essbase to resynch Essbase and Shared Services. This did not work, neither did a complete stop, reboot, restart.
    I'm approaching desperation, I cannot provision new users in a production environment...
    There are no other symptoms. All users are externally authenticated in the AD, and they are not experiencing any login problems at all. Users have changed their p/w even locked out their accounts and and had them unlocked.
    I'm attaching some log file snippets. I would greatly appreciate your insight.
    Failure message:
    Essbase failed to get roles list for [ESB:Analytic Servers:CORPESS:1] from Shared Services Server with Error [32:1062:Failed to connect to the user directory [Cabot2, Cabot].]
    From SharedServices_Security_Client.log after services restarted:
    2010-09-23 07:12:19,531 INFO [main] Got native directory location from Registry:corpfs.cabotog.com:28089 com.hyperion.css.registry.RegistryManager.getNativeProviderLocationFromRegistry(Unknown Source)
    2010-09-23 07:12:19,531 INFO [main] URL constructed out of values in Registry database:ldap://corpfs.cabotog.com:28089/dc=css,dc=hyperion,dc=com com.hyperion.css.common.configuration.CSSConfigurationImplXML.initConfiguration(Unknown Source)
    2010-09-23 07:12:21,062 ERROR [Thread-3] 27:1062:Failed to connect to the user directory Cabot2.[Root Cause: [LDAP: error code 32 - 0000208D: NameErr: DSID-031001CD, problem 2001 (NO_OBJECT), data 0, best match of:
         'OU=Corp,DC=cabotog,DC=com'
    ] ] com.hyperion.css.spi.util.jndi.pool.JNDIConnectionPool.getBorrowObject(Unknown Source)
    2010-09-23 07:12:21,062 ERROR [Thread-4] 27:1062:Failed to connect to the user directory Cabot.[Root Cause: [LDAP: error code 32 - 0000208D: NameErr: DSID-031001CD, problem 2001 (NO_OBJECT), data 0, best match of:
         'OU=Corp,DC=cabotog,DC=com'
    ] ] com.hyperion.css.spi.util.jndi.pool.JNDIConnectionPool.getBorrowObject(Unknown Source)
    2010-09-23 07:12:21,062 ERROR [Thread-3] 60:1101:JNDI error.[Root Cause: 27:1062:Failed to connect to the user directory Cabot2. ] com.hyperion.css.spi.impl.msad.JNDIHelper.getURLContext(Unknown Source)
    2010-09-23 07:12:21,062 ERROR [Thread-4] 60:1101:JNDI error.[Root Cause: 27:1062:Failed to connect to the user directory Cabot. ] com.hyperion.css.spi.impl.msad.JNDIHelper.getURLContext(Unknown Source)
    2010-09-23 07:12:21,062 WARN [Thread-3] Failed to update Cache for provider Cabot2[Root Cause: 60:1101:JNDI error. ] com.hyperion.css.spi.impl.msad.MSADCacheUpdater.refreshProviderCache(Unknown Source)
    2010-09-23 07:12:21,062 WARN [Thread-4] Failed to update Cache for provider Cabot[Root Cause: 60:1101:JNDI error. ] com.hyperion.css.spi.impl.msad.MSADCacheUpdater.refreshProviderCache(Unknown Source)

    We are using 11.1.1.3. We had the same issue you described. External users could login to all applications, but all security refreshes failed (in both EAS and Planning) with the failure error in your original post. The patch our consultant applied was "Shared Services Service Fix 11.1.1.3.06" per Oracle support. The following entries in our SS client log are what prompted Oracle's remedy (after several weeks of escalation):
    2010-09-24 15:01:38,110 ERROR [Thread-54] 27:1112:Failed to connect to <ldapserver> at <portnumber>. com.hyperion.css.spi.impl.ldap.LDAPProvider.isAvailable(Unknown Source)
    2010-09-24 15:01:38,110 ERROR [Thread-54] The folowing providers are not initialized, check configuration [ED] com.hyperion.css.spi.CSSManager.pingConfiguredProviders(Unknown Source)
    2010-09-24 15:01:38,110 ERROR [Thread-54] 32:1062:Failed to connect to the user directory <ldapdirectory>. com.hyperion.css.spi.CSSManager.pingConfiguredProviders(Unknown Source)
    2010-09-24 15:01:38,110 DEBUG [Thread-54] getRolesListForEntries() failed : [43842 ms]
    Edited by: 799357 on Oct 4, 2010 12:33 PM
    Edited by: 799357 on Oct 4, 2010 12:38 PM

  • Error with Active Directory Synchnorisation from Shared Services to Essbase

    Have recently installed HS9 v 9.3.1
    In Shared Services i have created both native and MSAD users. Everything works fine with the native users (Planning,EAS etc...)
    MSAD user directory has been configured & tested -ok on Workspace.
    The MSAD users have been provisioned and can access Workspace & Shared services without any issue.
    However, when accessing Planning, the following error is displayed in the Essbase server log:
    Tue Mar 18 15:12:39 2008]Local/ESSBASE0///Info(1051001)
    Received client request: Create External User With Type (from user [hyperion])
    [Tue Mar 18 15:12:39 2008]Local/ESSBASE0///Error(1051205)
    Single Sign On function call [css_getUser] failed
    [Tue Mar 18 15:12:39 2008]Local/ESSBASE0///Warning(1051003)
    Error 1051205 processing request [Create External User With Type] - disconnecting
    [Tue Mar 18 15:12:39 2008]Local/ESSBASE0///Info(1051001)
    Received client request: Set Application FrontEnd Type (from user [hyperion])
    [Tue Mar 18 15:12:39 2008]Local/ESSBASE0///Info(1051001)
    Received client request: Get Security Mode (from user [hyperion])
    [Tue Mar 18 15:12:39 2008]Local/ESSBASE0///Info(1051001)
    Received client request: Set Application Id For Planning (from user [hyperion])
    [Tue Mar 18 15:12:39 2008]Local/ESSBASE0///Info(1051001)
    Received client request: Get Security Mode (from user [hyperion])
    [Tue Mar 18 15:12:39 2008]Local/ESSBASE0///Info(1051001)
    Received client request: Get Security Mode (from user [hyperion])
    [Tue Mar 18 15:12:39 2008]Local/ESSBASE0///Info(1051001)
    Received client request: Re-Sync User/Group with Single application (from user [hyperion])
    [Tue Mar 18 15:12:39 2008]Local/ESSBASE0///Info(1051590)
    Synchronization started for user/group [MSADUser]
    [Tue Mar 18 15:12:39 2008]Local/ESSBASE0///Info(1051591)
    Synchronization completed for user/group [MSADUser]
    [Tue Mar 18 15:12:39 2008]Local/ESSBASE0///Error(1051013)
    User/group MSADUser does not exist
    [Tue Mar 18 15:12:39 2008]Local/ESSBASE0///Warning(1051003)
    Error 1051013 processing request [Re-Sync User/Group with Single application] - disconnecting
    ---------- When accessing through XL Addin, the foll is displayed:
    [Tue Mar 18 16:49:09 2008]Local/ESSBASE0///Error(1051012)
    User MSADUser does not exist
    [Tue Mar 18 16:49:09 2008]Local/ESSBASE0///Warning(1051003)
    Error 1051012 processing request [Login] - disconnecting
    Thanks !!!

    Hardcode IP addresses instead of the server names in the essbase.cfg file and the Shared Services CSS.XML file for the Shared Services server references.
    Restart SS/Essbase, provision an MSAD user, then do a Refresh from Shared Services in AAS.
    Verify your MSAD userID then shows up as an Essbase user in AAS(Display User list for the Essbase server)
    As long as the MSAD users show up in the user list, they should be working.

  • Security in shared services

    Hi
    In essbase we can load the securityfilters using HAL or MAXL , and in planning you can load the security file using importsecurity .cmd file, How about in shared services how can you load the bulk user security file. Is provisionusers.cmd will be helpful for this. I appreciate if any one keep some input for this.
    Thanks

    Hi,
    There's an import/export utility in the $HYPERION_HOME\common\utilities folder which allows you to bulk upload/export users and provisioning from shared services.
    This will allow you to do the bulk upload and do basic provisioning and assign your users to groups etc. However I don't think it's possible to assign Essbase filters to the users/groups.
    In Planning you can use the importSecurity.exe to assign access in planning then when you do a planning refresh this will create and assign the correct filters to your users in the background.
    Gee

  • Register with Shared Services Failing in 11.1.1.3

    Hi,
    We installed 11.1.1.3 in Linux operating system and the application server is Websphere 6.1.After Installation and Configuration of EPM products we Externalized users from EAS Console and configured Active Directory in Shared Services and now want to migrate users of Existing Production environment to new Environment.For that created a new testgroup in Shared Services under Native Directory and when I am refreshing it's displaying an error as shown below:
    Essbase failed to get roles list for [ESB:Analytic Server] from Shared Services Server with Error [32:1062:Failed to connect to the user directory [msadServer]
    Can anyone suggest on this.
    Any help is appreciated...

    This usually happens when the application exists in Essbase but does not exist in Shared Services.
    To resolve this you need to go into the AAS console, right click on the Sample application and select the 'REGISTER' option.
    This will register the application with Shared Services. You should then see the application listed in Shared Services under the Analytic Server project.
    You will need to make sure that the list of applications in the Analytic Server matches the list of applications under the project in Shared Services. If you have any other applications missing then please register those as well.
    HTH-
    Jasmine.

Maybe you are looking for

  • Tiger mail application not working

    This might not be the right place to post, but looking for information on the Tiger mail app. Been having trouble using the mail app with Wi-Fi, ethernet connections at hotels. For some reason it won't work. Is there a way around the issue or is it d

  • Business scenario configuration

    Dear all How to configure in SAP system for the following scenario 1. Client manufactures a huge material where generally it will be make-to-order with assembly or with out assembly and finished product will deliver to the customer site as per the PO

  • How to get each frame Info in SWF ?

    Hi,all. I met a problem with SWF decomplie. If you have edited the fla files, store lots of frames which contains some shape information like pixels color, position and ect When you want to get that information in SWF, or rather, each frame informati

  • Returning Nano to Apple for refurbishment

    My son's Nano is pretty beat up because the silicone cover we have for it provided no protection for the screen and I'd like to send it to Apple to have it refurbished. It is no longer under warranty, so I realize I will have to pay for this. I can't

  • FLV after publishing issue

    All of the students in my class are having the same issue with our embedded videos. We are creating tutorials in Captivate and many of us have embedded video. After publishing the captivate file we are getting this connection issue. Our instructor is