Regarding sso confrigaution

Hi All,
i have just migrated from obiee10 to obiee11g.
since i configured sso in 10g so it also got configured in obiee11g.
the problem is that it showing sign out button after sign in in any application.
previously in 10 it was not coming but in obiee11g it is coming.

Hi All,
i have just migrated from obiee10 to obiee11g.
since i configured sso in 10g so it also got configured in obiee11g.
the problem is that it showing sign out button after sign in in any application.
previously in 10 it was not coming but in obiee11g it is coming.

Similar Messages

  • Regarding SSO setting

    hi all,
    Can you suggest me how to make SSO setting for IDM,EP and ABAP?
    Do we need to make SSO setting for below combination of systems.
    1) IDM - EP
    2) IDM - ABAP
    3) EP - ABAP
    or SSO setting for Just IDM -EP and IDM- ABAP is enough
    please confirm.
    regards

    >
    Bastian Kromer wrote:
    > usually your IDM will be configured to manage identities of the EP and your ABAP Systems. Then you can use SSO for the Portal itself (mostly by using Kerberos authentification);
    yes, I agree. Using Kerberos authentication allows Active Directory domain to be used as authentication server.
    > and SSO for ABAP Systems by enabling ticket (certification-) exchange from EP to the ABAP backend.
    If you want SSO for SAP GUI logon to ABAP systems, then SSO2 ticket trust for SSO is not sufficient. Instead, a lot of companies configure SNC authentication to ABAP systems, also using Kerberos - then the user logged onto workstation is authenticated to ABAP systems as well as Poral and other web enabled SAP applications. Obviously, if your Portal application communicates with ABAP system then SSO2 ticket trust method is also required.

  • REGARDING SSO

    Hi Experts,
       our data source is ABAP we need to configure SSO if we r giving SAP-ALL permissions to backend user then it is working fine otherwise its not working fine how to solve this problem what permissions a backend user should have plz mention clearly na....
      due to this SAP-ALL permission to the backend user at front end it is automatically showing system administration,user adiministration,content administration how to achieve this ??
    plz solve this issue......
    waiting for u r response .....
    Regards,
    Shilpa

    Hi,
    yes our requirement is to create transaction iview ....
    i created a system object and specified all the properties....
    1.connector
    2.WAS properties
    3.ITS properties
    4. user management
    5.create system alias
    now i need to configure SSO
    i downloaded the certificate from systemadministration -> keystore administration
    verify.der
    and
    exported the certificate in ECC6.0
    whaen iam giving the perm,issions for the user at backend level SAP-all it is working fine without any errors
    when iam taking that permission na.... its  not working fine it is showing error when i tested the connection
    now , tell me na how to solve this issue.......
    plz waiting for u r response....
    Regars,
    Shilpa

  • Regarding IBots confrigaution in obiee11g

    Hi All,
    I have some question on ibots in obiee 11g.
    1. I want to send user a dashboard page with attachment and also in mail body both.
    since what i know we can send page in attachment or in body, so please suggest.
    2. while sending report in mail i want to show in subject current date.
    how can we do that.
    please suggest.
    Regards
    Manoj Kr. Pandey

    Hi,
    You can send it as an attachment to retain original formating.
    You can refer variiables in subjec line, usethe current date variable name in subject like:@{biServer.variables.variablename}
    Regards,
    Dpka

  • Need Help regarding SSO token validation machanisim

    Hi all,
    We are using Oracle CRM on demand with our own web app(struts) using Applet(web link). We are using SSO for all verification. Currently for each call to weblink, we need to verify SSO token with oracle on demand in our action class. We want to cut down the SSO verification hit to CRM server. Can we have a some way to achieve this?
    Once a user logs in crm, crm will send a SSO token. Once user clicks our weblink first time, a SSO token verification will be happen in our server and authenticate to use our app. Then next all subsequent requests form this same user wouldn't go to SSO verification again as it is already done in login time. We will allow user to access our app based on the SSO expire time.
    How can we achieve this? Appreciate your gr8 help.
    Thanks
    Suman

    what are you going to do stop insert/update upon commit?
    -- use on-insert trigger
    if allowed_to_insert then
    insert_record;
    end if;
    -- use on-update trigger
    if allowed_to_update then
    update_record;
    end if;
    if when entering data, you might want to check set_block_property

  • SSO from Microsoft to SAP portal

    Hi guys,
    I am stacked in something regarding SSO, the problem here is that I have to create and ASP.net application able to create the SAPLogOnTicket and bypass the SAP portal logon screen and everytime I am using may application I have not to log in again in the SAP Portal.
    Anyone who have an answer or a working example, please let me know.
    Thanks in advance,
    Armando

    Hi Armando,
    if your application is extranet application (you access it from internet) then you need to use citrix to    log in to the portal without asking for username and password.
    if the application is accessible from the intranet then you need to identify the application in the portal landscape system. for more information on this subject you can read the following useful help:
      [Click Here|http://help.sap.com/saphelp_nw2004s/helpdata/en/ec/0fe43d19734b5ae10000000a11405a/frameset.htm]
    Regards,

  • SSO with AD to DB

    Hi Tim,
    I have question regarding SSO to database (MSSQL).
    I read most of posts here but no solution found. I configure SSO to infoview from your white paper and this works with no problem.
    To enable SSO to database:
    - in CMC  => "Cache security context (required for SSO to database)" in enabled
    - in krb5.ini  => "forwardable = true" in entered
    - we created SPN => MSSQLSvc/MSCompName.domain.com:1434 BOXISSO (boxisso is "kerberos user")
    - in desiger => "use SSO when refreshing reports at view time"
    In infoview I gen an error "Login failed to for user NT AUTHORITY/ANONYMOUS LOGON..."
    On database are users authenticated with user boxisso or with their ad names? (what are privileges on mssql side needed?)
    Thank you for reply!
    Regards,
    Gregor

    Is the SIA running under a delegated service account (delegation to any service enabled)? Is the SQL DB integrated with AD? and enabled for kerberos? You should verify the latter with Microsoft.
    Also try enabling this on the servers (reporting and SQL) http://support.microsoft.com/kb/262177
    Regards,
    Tim

  • SSO and ABAP Web Services

    I am opening this thread on behalf of my colleague Bala regarding SSO and ABAP Web Services.
    We have gone through single sign on options and found several options are available within 5.0.
    We would like to know the options available for SAP ABAP web services access from a Non-SAP system with user authorization but without Portal/ITS installation.
    Also I would like to avoid any hard coding of user id in Non-SAP system .
    Could you provide any information.
    Thanks,
    Bala

    We have gone through single sign on options and found several options are available within 5.0.
    Tell me what are the several options and what is your Non-SAP system?
    without Portal/ITS installation.
    ITS is now an integral part of ECC 5.0 system. So would not need a seperate installation, unlike earlier versions.
    AB

  • RDP SSO?

    I need a little information regarding SSO in use with Remote Desktop services.
    In searching for RD Services SSO I get these articles about getting the RDWeb SSO and using SSO with RemoteApp. But there is never any mention of RDP itself.
    My people want to be able to load up MSTSC or an .rdp file, put in the server address and connect via RDP with no prompt for credentials.  I am not seeing anything on the web on how to do this.
    We are running Windows 2012 R2 RDS.

    Hi Thomas,
    Thank you for posting in Windows Server Forum.
    To take advantage of the new Web SSO feature, the client must be running Remote Desktop Connection (RDC) 8.1 for better feature and functionality.
    In order for Web SSO to work:
    a. The connection in RemoteApp and Desktop Connections must have an ID. By default, it is set to the Fully Qualified Domain Name (FQDN) of the RD Connection Broker server in case of RD Connection Broker mode. In RD Session mode, it is set to the FQDN of
    the RD Web Access server.
    b. RemoteApp programs must be digitally signed using a Server Authentication certificate [Secure Sockets Layer (SSL) certificate]. The certificate Enhanced Key Usage section must contain ‘Server Authentication (1.3.6.1.5.5.7.3.1)’. More details about the
    types of certificates used to digitally sign RemoteApp programs can be found here.
    c. Client operating systems must trust the certificate with which the RemoteApp programs are signed.
    In addition, need to add the server name under GPO setting “Allow delegating default credentials”. Please check
    this article
    for information. For mstsc to run without credential prompt, we can also edit the rdp file “PromptCredentialOnce:i:0” and see the result. 
    For more information you can refer below article.
    Step by Step Customizing RD Web Access 2012 R2 – Part 1
    Hope it helps!
    Thanks.
    Dharmesh Solanki

  • App Server SSO LDAP on 11g

    We are currently running App Server using OID & SSO version 10.1.2.3 in a high availability environment. We have a project to migrate these applications to new hardware and are considering installing Fusion Middleware App Server 11g (on Linux 64bit). Does anyone have any comments or concerns regarding SSO or OID on App Server 11g?

    Take a look at this thread The Future of Oracle Single Sign-On 10g (10.1.4.3) ????
    You can have OID 11g in your FMW installation but you will have to maintain a separate instance for SSO 10g patched up to 10.1.4.3.

  • Partner Application in release 2

    Hello,
    I have to create a new PL/SQL partner application in the release 902.
    Where is the new sso sdk for the new Portal release?
    In the new pdk seems that it is the same of the 309 release (ssosdk307_032101 or ssosdk307)...
    And the pl/sql example code in the Oracle9 iAS Single Sign-On Application Developers Guide is not working...
    Can someone give me some feedback?
    Thank you and regards,
    Lorenzo.

    Lorenzo,
    Did you get any feedback on this posting? I'm also working with Release 2 (9.0.2) and is just about to start implementing the Java SSO SDK. The latest release of SSO SDK I've found is 307. According to the documentation this version supports SSO server 3.0.6 to 3.0.8, thus not Release 2. Please reply if you have any news regarding SSO SDK for Release 2.
    Best Regards,
    Rikard

  • Timeout of one session destroys the other

    Hi folks,
    I got a strange problem regarding sso and session lifew time, which drives me crasy.
    Well, I got two web apps which use FORM authentication which I like to use with sso enabled.
    sso seems to work fine for my two web-apps App-A and App-B, but when I close App-B, it happens that I have to login to App-A again, after a while.
    It looks as if the session times out even if I continue to work with the application.
    Once again. If I do the following steps:
    1. Starting App-A and login
    2. Starting App-B from App-A (it is linked there)
    3. Closing the browser window ([X] -Button) of App-B
    4. Going on to use App-A
    Than, after a while, I fall back to the login form of App-A, suddenly. The timespan until I have to login again seems to be the timeout of App-B
    How the hell can this be?!?

    OK, this is a very old thread and many things have changed since then.
    In the simplest case, you can just add a bit more logic for the third slider and expand on the above example by tst. Should be trivial. Have you tried?
    If you have LabVIEW 8.0 or higher, you could wrap the entire thing in an Xcontrol. This has the advantage that there will be no visible code on the diagram and the limits are even enforced if you change the sliders in edit mode.
    Maybe you don't need any of this. You could just have a control with three sliders, then sort the three outputs before handing them off to the rest of the code (See attached, LabVIEW 7.0).
    LabVIEW Champion . Do more with less code and in less time .
    Attachments:
    3sliders.vi ‏34 KB

  • T440P - Win 8.1 Fingerprint Single Sign on Issue

    Hi,
    I just bought the T440P laptop, and for some reason it never updated to win 8.1 pro from the CDs that were provided. So I installed Win 8.1 x64 Enterperise with Update (provided by my company). I downloaded all the drivers for win 8,1 x64 from the website and installed them. The issue that i am facing is while following the single-sign on guide i have checked (ticked) everything but when the system boots it asks for my fingerprint (power - on password) and then stops at windows login and asks for it again. Why isnt the single sign on working?
    Below images show the settings in the fingerprint Manager Pro 8.01.26(x64). Any help will be apprecaited.
    Also the guide says to click the power-on tick over the enrolled finger print. I cannot find this option, is it even possible to power on the machine (T440P) with the fingerprint with win 8.1 x64 ?
    Thanks,
    Usama

    Hi,
      Using kerberos authentication, users when logged in to windows environment need not enter any user name or password for logging into portal. Check these links for configurations.
    http://help.sap.com/saphelp_nw2004s/helpdata/en/a4/385bef3bd14241b9c4f36bd779537d/frameset.htm
    Regarding SSO between windows and portal
    How To Identify which SSO(Windows Authentication ) is Implemented
    Regards,
    Harini S

  • Cannot re-authenticate in the same session.

    I get this error when I call the Java server code sample that was included in the AFCS download.  I am calling the getAuthToken function on the AccountManager object.  This error only occurs when I open another tab in my browser and try to get another token.  We have wrapped the Java sample in a LiveCycle process and the channel is setup as follows:
    var ro:RemoteObject = new RemoteObject( "myDestination" );
    var cs:ChannelSet = new ChannelSet();
    cs.addChannel(new AMFChannel("remoting-amf", "http:myServer:8080/remoting/messagebroker/amf"));
    ro.setCredentials( "Administrator", "password" );
    If I remove the setCredentials when I do not already have the browser open the I get a different error.  If I remove the setCredentials when I try to open another tab I do NOT get the error mentioned above.
    So what is it about the setCredentials that is making this work only the first time and not when I try to open another tab in my browser?
    Thanks in advance for any help.
    -chris   

    Looks like this is a fairly common problem when using Flex remoting and LiveCycle. I found one explanation here:http://michael.omnicypher.com/2009/01/authentication-with-flex-remoting-in.html but you can look for more.
    I am not familiar with remoting used this way so I can't really help with that.
    Regarding SSO, I would say yes and no. The purpose of external authentication is to leverage your authentication system and user database and give you a way to manage what privileges / permission your users will have once they enter a room.
    So, in that sense yes, external authentication is a mechanism to do single-sign-on between your main web application and an LCCS room.

  • Where is LogOn Ticket implemented in WS consumption (header/envelope)???

    Hi
    Just a short technical question regarding sso:
    Does someone know where the SAP Logon Ticket is transmitted within the HTTP Protokol?
    I want to consume a 3rd party web service and now I am wondering if the LogOn Ticket is transmitted within the header or the Envelope of the communication?
    Can someone help me out?
    Thanks,
    Minima
    P.S:  It would really help if someone could send me a link to some proper documentation of that issue.

    Hi,
    SAP provides a Web Server filter that can be used for an authentication by means of http header varaible and a dynamic link library for verifying SSO tickets in 3rd party software which can be used to provide support for SAP Logon Tickets in Java applications.
    Please go through these links:
    Single Sign-On of Windows-based Web Service Clients using SAP Logon Tickets
    https://www.sdn.sap.com/irj/sdn/go/portal/prtroot/docs/library/uuid/5bc7e899-0e01-0010-cca9-84f45118dd17
    https://www.sdn.sap.com/irj/sdn/go/portal/prtroot/docs/library/uuid/ae399f0d-0301-0010-cebf-bb13f430af55
    https://www.sdn.sap.com/irj/sdn/go/portal/prtroot/docs/library/uuid/47d0cd90-0201-0010-4c86-f81b1c812e50
    https://www.sdn.sap.com/irj/sdn/go/portal/prtroot/docs/library/uuid/4f209cf3-0201-0010-1db5-d2e33048b6c8
    Hope it helps.
    Regards,
    Mona
    Edited by: Mona Kapur on Jan 21, 2008 8:11 PM

Maybe you are looking for

  • IDE Configuration

    My motherboard is a K7T Turbo version 3 (MS6330). I'm running WinXP Pro with an AMD XP2400 processor if it's relevant. I have two HD's, CD burner, DVD burner, DVD Rom and an LS-120. I also have a Maxtor PCI IDE card installed. What would be the best

  • Index is Missing in DB02

    Dear All, I just check in DB02 that there is one secondary Index is missing on Production server. Database object for VBAK is inconsistent: (Secondary indexes)   Indexes: Inconsistent with DDIC source   ABAP Dictionary Database Index does not exist I

  • [as2] Class is not working

    Hi. I have two levels one for "movie1.swf" the other "movie2.swf", movie1 is on level 0, movie2 is on level 1. I made a class "MySound", a class that extends the Sound class. The problem is that I tried to use MySound class on movie2 and is not worki

  • "Backup" as opposed to "Sync"

    I have probably been using my Apple TV in the "wrong" fashion for the last two years. I've purchased 99% of my content on the Apple TV rather than on my iTunes platform on my PC, and I now want to backup selected TV Shows to my pc. The only way I've

  • Need to provide effort estimate for an implementation project.

    Hi All, I am working on an RFP and need to give effort estimates related to SD module. I need guidance for you experts in this case. The RFP is from an Indian client. The SD implementaion looks preety vanilla stuff as they have not mentioned any sale