Separating AD domains in mulitenant environments

I'm in a multitenant environment.  Some tenants live together in a true cloud infrastructure, where resources are pooled together, and separation is enforced in the virtualization layer, not the physical layer (i.e. shared physical networking infrastructure).  Due to tighter security restrictions, other tenants have a dedicated managed hosting platform with their own hardware at the physical layer (i.e., their own physical switches).  Still other tenants have specialized custom-made arrangements to fit a security model half-way in between having totally separated resources and totally pooled resources.  Everything is in one datacenter.  (Everything is vCenter 5.1 or later so SSO is also used everywhere)
The question is, when is it appropriate to dedicate a separate AD domain to a tenant?
When should I group tenants with different AD domains in a single AD forest, and when should they have a separate forest?

Hello,
This depends on who the tenants are actually. If it is truly multi-tenant then your tenants will have their own AD services that will be completely separate. The only ones that will not be separate from yours are your authentication and authorization for their portal access. Tenants should never have access to SSO, they do not need it to access VMs. THey should not have access to the hosts either.
Now, if they have their own hardware and control everything up and down the stack then they need a separate domain I would think so that auth does not overlap.
This really does depend on whom your tenants are and how separate things are now and the policy you are trying to enforce. Start there then choose how best to do things based on that.
Best regards,
Edward L. Haletky
VMware Communities User Moderator, VMware vExpert 2009, 2010, 2011,2012,2013,2014
Author of the books 'VMWare ESX and ESXi in the Enterprise: Planning Deployment Virtualization Servers', Copyright 2011 Pearson Education. 'VMware vSphere and Virtual Infrastructure Security: Securing the Virtual Environment', Copyright 2009 Pearson Education.
Virtualization and Cloud Security Analyst: The Virtualization Practice, LLC -- vSphere Upgrade Saga -- Virtualization Security Round Table Podcast

Similar Messages

  • Question regarding STP domain separation

    Hi everyone,
    I have the question about separation of STP domain on layer 2 network.
    The following is the example of layer 2 network and the network is within one IP subnet, one VLAN.
    Looped-Area#1-----Cat3750#1-----Layer 2 WAN-----Cat3750#2-----Looped-Area#2
    <--looped---><-------------------No loop exist---------------><---looped-->
    <---------------------------------single VLAN----------------------------->
    There are some Catalyst Switches in each of "Looped-Area#1" and "Looped-Area#2".
    STP is needed to run in the network in order to prevent loop.
    However there is no bridge/switch loop between Cat3750#1 and Cat3750#2, in other words, multiple
    paths does not exist between Cat3750#1 and Cat3750#2 as shown above.
    So I think both Cat3750#1 and Cat3750#2 do not have to participate the STP domain in order to
    calculate STP topology; rather Catalyst Switches in "Looped-Area#1" and Catalyst Switches in
    "Looped-Area#2" should belong to different STP domain. By separating STP domain, I think I can:
    for example, configure "Looped-Area#1" uses PVST+ while "Looped-Area#2" uses RSTP
    avoid to reach STP convergence to whole layer 2 network
    for exmaple, I use one STP domain whole network and STP root and STP secondary root exist in
    "Looped-Area#1".
    And when STP root changes to secondary root, STP convergence occurs and Catalyst Switches in
    "Looped-Area#1" and also in "Looped-Area#2" must wait until STP convergence is completed.
    During STP convergence, traffic does not across Layer 2 WAN, in other words, traffic just
    within "Looped-Area#2" is also affected.
    If I use two STP domain on each "Looped-Area#1" and "Looped-Area#2 and STP root exist each,
    traffic within each area is unaffected by STP convergence occurred on another area.
    I have the following question and concerns about it, could you please advise me?
    To do so what configuration is needed on Catalyst Switches?
    Just configure different "VTP domain name" on Catalyst Switches in each aera?
    Assume that I can create two STP domain, I think BPDU packets are forwarded through whole
    network regardless of differenciation of STP domain because BPDU packet is multicast.
    But BPDU packets from different STP domain are ignored and not processed by Catalyst Switch.
    Also assume that I can create two STP domain, I think if I use PVST+ and RSTP on each area,
    for example, "Looped-Area#1" uses PVST+ and "Looped-Area#2" uses RSTP, 802.1D BPDU packets
    and RSTP BPDU packets are forwarded through whole network regardless of differenciation of
    STP domain and STP type(PVST+ or RSTP) because 802.1D and RSTP BPDU packets are multicast.
    But Catalyst Switches in RSTP does not fall back to legacy STP(PVST+) even through any RSTP
    port receives legacy 802.1D BPDU because PVST+ and RSTP are configured onto different STP domain.
    Is my understanding correct?
    Could you please let me know your advise?
    Your information would be appreciated.
    Best regards,
    Shinichi

    Hi,
    1. There is no "STP domain" concept available for PVSTP+ nor RSTP.
    2. VTP domain has nothing common with STP instances. VTP enables a comfortable VLAN configuration, but once a VLAN is spread (even through multiple VTP domains) STP si running independantly on VTP.
    3. If you are sure "there is no bridge/switch loop between Cat3750#1 and Cat3750#2, in other words, multiple paths does not exist between Cat3750#1 and Cat3750#2", why don't you simply configure
    spanning-tree bpdufilter enable
    on the Cat3750#1 and Cat3750#2 interfaces connected to the Layer 2 WAN?
    See http://www.cisco.com/en/US/docs/switches/lan/catalyst3750/software/release/12.2_46_se/configuration/guide/swstpopt.html#wp1033638
    for details.
    BR,
    Milan

  • Single login for multiple domains

    Can anyone point out a blog or post of a single login for
    multiple domains? For example, let's say I own asite.com and
    bsite.com.
    I want a user who logins to asite.com to also be logged into
    bsite.com if they visit that site. BSite.com is clearly a microsite
    of asite.com but we'd like to continue to use that domain if the
    visitor is on that site instead of redirecting them to keep login
    credentials
    Thanks

    If you're using cookie based login system, I'd imagine you
    could set a cookie to be valid for both of your sites.
    <cfcookie name="myAuthcookie" value="myAuthValue"
    domain=".asite.com;.bsite.com">
    That way both asite.com and bsite.com can read your cookie.
    Note the notation; always include the preceeding dot in the domain
    values. (two dots for top level domains, etc.)
    Strangely CFCOOKIE documentation doesn't mention anything
    about using semicolon separating multiple domains. It did in CF5
    documentation, but not since.

  • WL10.1 domain configuration in silent mode?

    Hi,
    Our existing domain in production is 8.1 and I use the configuration wizard in silent mode to set up domains. This has been an extremely useful tool because I can version control the silent script and also repeatedly and consistently create domains in multiple environments (prod, dev, test).
    We are going to be migrating to 10.1. I have read domain creation strategies in 10.1 documentation and no where is the silent mode domain creation mentioned.
    Has silent mode domain creation using configuration wizard been taken out in 10.1?
    Thanks!

    Hi,
    After installing WL 10.1, there should be a sample silent.xml script inside your WL_HOME dir, you can customize it according to your environment needs.
    Weblogic Consultant

  • MDS VSAN Domain ID

    Hi everybody.
    I have theoretical question that concerns the VSANs. If I can configure up to 254 user VSANs, how can I assign unique Domain ID to each of them, if I have the limitation of 239 domains. Thank you for the attention.
    Cheers,
    Dancho

    You aren't limited to having unique DID if the vsans don't touch. Each vsan is completely unique and vsan X, domain Y is completely different than vsan A, domain Y. Imagine that if the sans are physically separated, then domains do not need to be unique. So, when you logically separate them, they are still separate and can have the same domain.
    If you think about it from an IP network point of view, the vlan A can have the same IP subnet as vlan B if they never attempt to contact each other or route between them.

  • Mail sever, two domains, separate user inboxes

    We have two domains - one for personal emails and one for our company. I want to set up the mail server to keep incoming mail separated by domain and deliver via Imap to separate inboxes. So mail to [email protected] remains separate from mail to [email protected]
    I can do this in my current ail server (Mdaemon/Windows) simply by creating the two domains and setting up the users in those domains (so there's a user nick in each domain with a separate login for that domain.
    I might be missing somehting obvious, but I don't see how to do this in Maountain Lion Server. Any ideas please?

    You're not the only one to have stumbled into this, and OS X Server arguably hasn't been particularly adept nor particularly clear about this, and the newer documentation and newer controls have gotten rather thinner. 
    The 10.6 Mail Service Administration manual describes how to do this, though the specific configuration files may have moved around since 10.6.  (I've become quite fond of the shell locate command here.  That command-line command initializes and accesses a database which makes finding the version-relocated files much easier.)  See the documentation around Mail virtual hosting starting around page 74, followed by the OS X Server-style and Postfix-style aliases, around page 77. 
    There's also the OS X Server 10.8 Workgroup Manager download, which can be useful here.

  • Whiteboard, Polls, Q&A and Powerpoint not working over Federation

    Hi,
    I have a problem with whiteboard, polls, Q&A and Powerpoint sharing over federation, if the federated endpoint is behind a web proxy with HTTPS inspection enabled. Audio, video and desktop sharing works fine.
    Scenario:
    2 Domains which are federated (DomainA and DomainB), all Lync servers are full patched (June 2014)
    2 Users (UserA from DomainA and UserB from DomainB) works with full patched Lync Client 2013. Both Users work on their internal LAN. The client cannot reach the internet directly. Web requests go to through a proxy with HTTPS inspection.
    1. UserA starts a Chat with UserB. UserB accepts.
    2. UserA adds the whiteboard. UserB gets the "Add meeting content" button and accept.
    3. UserA gets the whiteboard, UserB gets a error message "Because of network issues..."
    In this scenario, UserB's Lync client tries to connect to WebConf Edge of DomainA over TCP/443 (HTTPS). Because UserB cannot reach the Internet directly from the inside LAN, the request goes trought the web proxy of DomainB (ProxyB). The web proxy is configured
    with https inspection, so on the WebConfEdge I get requests from the web proxy of DomainB which are also answered by the WebConf Edge. On the pc of UserB I also get the answer, but signed with a certificate of the web proxy which is added as trusted root certificate
    (normal behaviour if https inspection es enabled). On the network trace, as I can see, UserB resets (ACK, RESET) the connection to WebConf Edge directly after receiving the first https response.
    Then I changed the web proxy (ProxyB) to bypass the https inspection for the ip address of the WebConf Edge of DomainA. The same scenario works fine now. It always works fine, if UserB have directly access to web conf edge of Domain A (UserB is in the internet
    and not in the LAN).
    I also could check this vice versa. It depends on which side, the conferencing is hosted. As soon as the other user connects through a web proxy which doesn't bypass the request directly, the user do not get the web conf content.
    Then I tried with other domains and other environments, but all of them had the same issue, as long as the web request from the foreign user goes throug a web proxy. It seems there is no dependency on which product of web proxy will be used, it seems to
    be a dependency on https inspection and all changes the web proxy do in this case with a web request and response.
    I always tested with whiteboard, but the same behaviour is with Q&A and polls and also with Powerpoint (WAC). For Powerpoint it's only because the foreign user do not get the URL from web conf, so the client do not know how to connect to the WAC of DomainA.
    During the tests with several Domains (customers), I see a corrupt "Client Hello" from a specific web proxy. In the list of cipher suites in the "Client Hello", the web proxy added an additional byte (0xFF) at the last TLSCipherSuites
    entry, so the extensions, followed by the ciphersuites list in the "Client Hello" are not readable. So the connection will be reseted directly.
    Because my workaround depends on the web proxy of the foreign side (configure bypass) it's not really a practicable way to make sure, the web conferencing content will work. Is there an other way to solve this issue?
    Regards, Stephan

    Hi,
    From your description, the issue should be the
    https inspection on the web proxy, maybe you should change from the web proxy side.
    You can refer to the link of
    Enabling HTTPS Inspection causes some applications to stop working
    Note: Microsoft is providing this information as a convenience to you. The sites are not controlled by Microsoft. Microsoft cannot make any representations regarding the quality, safety, or suitability of any software or
    information found there. Please make sure that you completely understand the risk before retrieving any suggestions from the above link.
    Best Regards,
    Eason Huang
    Eason Huang
    TechNet Community Support

  • Can 2 vlans have the same subnet?

    I hope the combined genius of the fellow community can answer me this. I am new to Cisco, and I understand VLANs as a physical boundary separating broadcast domains.
    I was wondering if it is possible to divide 1 subnet (192.168.1.0) into two separate VLANS? I have all layer 3 switches in my environment. Making matters worse, there would be no pattern for the IP address assignments into VLAN-A vs. VLAN-B..
    If this is possible, can you please explain the mechanisms for a successful implementation. 

    It mostly depends if/how you want hosts on them to talk one another (or other networks).
    If the answer is "not at all" then you can have as many VLANs as you like using the same subnet. 
    If the answer is "completely" then you have to either a. break your addressing (L3) down to have one set of hosts in subnet A (on vlan a) and the others in subnet b (on VLAN b). or b. have some fancy tricks in place with network address translation (NAT) in place.
    I'll leave the latter solution off as beyond the scope of your question.
    For the former, you would just change your subnet mask - for example, if the classful subnet is a "standard" /24 (255.255.255.0) then split it in two - /25 or 255.255.255.128. Assign hosts in one or the other.
    You have to have some pattern - all networking is based on patterns in some way or another.

  • No transport error while consuming WCF service in a REST way

    Hi,
    Here is a small article on when we usually face No Transport error and how to get rid of it.
    I recently worked on a sample application using “app for Office” (New in Visual Studio 11.0)
    What is “app for Office”?
    An app for Office is basically a webpage that is hosted inside an Office client application. You can use apps to extend the functionality of a document, email message, meeting request, or appointment. Apps
    can run in multiple environments and clients, including rich Office desktop clients, Office Web Apps, mobile browsers, and also on-premises and in the cloud.
    What can an app for Office do?
    An app for Office can do pretty much anything a webpage can do inside the browser, such as the following:
    Provide an interactive UI and custom logic through      JavaScript. (Develop UI using HTML and JavaScript)
    Use JavaScript frameworks such as jQuery.
    Connect to REST endpoints and web services via      HTTP and AJAX.
    Run server-side code or logic, if the page is      implemented using a server-side scripting language such as ASP or PHP.
    As “app for Office” doesn’t have an option to write server side scripting (unlike code behind or in-line coding feature in ASP.NET/MVC) we will have to go for web service or WCF service and consume the service
    using any JavaScript framework like Jquery.
    I wrote a simple WCF service to hook up with server side code and consumed the service using Jquery as follows
    $(document).ready(function () {
    $.ajax({
    type: "GET",
    url: "http://localhost/MyService.svc/rh/data?id=" + $('#sampleType').val(),
    processData: false,
    contentType: "application/json; charset=utf-8",
    dataType: "json",
    crossDomain: true,
    success: function (data) {
    alert(data)
    error: function (xhr, status, error) {
    alert(error);
    I encountered an error saying “No Transport” when I executed the client application.
     I did some investigation on this and found out the root cause that cross-domain request was disabled. But I was really not sure whether it was at my WCF service end or “app for Office” client end. I added
    Client Access policy and Cross-domain-policy xml files to WCF service in order to enable cross-domain request 
    so that service will accept any type requests sent form different domains.
    Client Access policy
    <?xml version="1.0" encoding="utf-8" ?>
    <access-policy>
    <cross-domain-access>
    <policy>
    <allow-from http-request-headers="*">
    <domain uri="*"/>
    </allow-from>
    <grant-to>
    <resource include-subpaths="true" path="/"/>
    </grant-to>
    </policy>
    </cross-domain-access>
    </access-policy>
    Cross-domain-policy
    <?xml version="1.0"?>
    <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
    <cross-domain-policy>
    <allow-http-request-headers-from domain="*" headers="*"/>
    </cross-domain-policy>
    Both the policies should be in different XML files
    But this didn’t solve my problem. After a little bit more investigation I found exactly where and how to enable-cross domain requests.
    Solution
    We need to enable cross-domain requests in environments that do not support cross-domain requests.
    “Cors is equal to true if a browser can create an XMLHttpRequest object and if thatXMLHttpRequest
    object has a withCredentials property. To enable cross-domain requests in environments that do not support cors yet but do allow cross-domain XHRrequests (windows gadget, etc), set $.support.cors = true;”
    You just have to add jQuery.support.cors = true; in your client scripting and it works perfectly fine.
    [Cors- Cross-Origin Resource Sharing]
    A simple example:
    $.support.cors = true;
    $(document).ready(function () {
    $.ajax({
    type: "GET",
    url: "http://localhost/MyService.svc/rh/data?id=" + $('#sampleType').val(),
    processData: false,
    contentType: "application/json; charset=utf-8",
    dataType: "json",
    crossDomain: true,
    success: function (data) {
    alert(data)
    error: function (xhr, status, error) {
    alert(error);
    Hope this will be helpful.
    Thanks

    This is very good technich to resolve the problem. but this is not working in Google chrome or Firfox . can any one help me.

  • Error Code A12E1 and Creative Cloud Update Loop

    Possible Windows Solution - this applies to Windows systems only.
    Problem:
    1) You try to open the Adobe Creative Cloud and receive notification of an update. The options are to Update or Quit. When you click Update, the process starts and then quits with no warning.
    2) You have downloaded the Creative Cloud Manager or any software package installer. When you try to install the program, it quits and gives you a message about Error Code A21E1.
    Possible Cause:
    Due to the recent Cryptolocker virus, many reputable websites have been offering "fixes" to prevent the virus from installing itself. These fixes typically entail making changes to your local security policy, or in domain (office network) environments, making changes to Group Policy that block EXE (executable) files from running if they originate in the C:\Users\{username}\AppData\* folders. You can read more about that stuff HERE and HERE.
    Basically the problem is that the first thing the Adobe Cloud installer does is copy a setup helper to to C:\Users\{username]\AppData\Local\ACCCx2_3_0_322\Set-up.exe. If you or your network administrator have tried to prevent the Cryptolocker virus by putting a blanket stop on allowing EXE files to execute from the AppData folders, this file can't run and, Bob's-your-uncle, you get the Error Code A12E1 message.
    To see if this is the problem you need to check the Windows Event Viewer. You can access it by opening a Run dialog (Win+R) and typing in eventvwr. (If you need help navigating the Event Viewer, check out this YouTube video.) If you see a Windows Application Event 866 "Software RestrictionPolicies" you know this is the reason you can't install anything. If you click on the event, you can see the name and path of the file that is trying to execute.
    If you are like me and applied the Cryptolocker fix in a flurry of prevention activity and forgot if you applied the policy locally or at the group policy level, you can check the "Resultant Set of Policy" management console. Go back to the Run dialog and enter RSOP.MSC to open it. Navigate to Computer Configuration>Windows Settings>Software Restriction Policies and the same one under User Configuration to see if there are modifications. If you find something, right click on a policy object and select Properties to see the name of the GPO it came from.
    Solution:
    While you can tweak the settings to allow Abobe applications to execute, I just dropped the restrictions for now. If you are in a network environment and have an admin - give them the event viewer info and they should be able to set up the exclusion for you.
    In any event - I hope this helps. I hadn't seen anyone else post anything about this possible cause so I thought I should. Best of luck!

    Try http://helpx.adobe.com/creative-cloud/kb/a12e1-error-downloading-creative-cloud.html

  • Anyone tried using LDIF file in the User Profile Synchronization Process?

    Microsoft pushied an article recently talking about using LDIF file in the SharePoint's user profile synchronization. 
    Configure profile synchronization using a Lightweight Directory Interchange Format (LDIF) file (SharePoint Server 2010) http://technet.microsoft.com/en-us/library/ff959234.aspx
    Currently I am unable to obtain the required "Replicate Directory Change" permission set up by the AD admin.  So I thought of exploring this alternative since I still have AD search permission right now.
    So far, I was able to set up the MOSSLDAP-LDIFMA, and use an import.ldif file to add, remove and update user profiles.  However, there are some problems that I can't resolve.  One of key problems is, the LDIF-imported records can't be
    sync'd with login-based records.
    In my environment, when a user login SharePoint via Windows authentication, a new profile would be added, under the account name "domain\username".  Meanwhile, when an LDIF record imported, there will be another profile created under the account
    name "domain:domain\username", or "domain:username".  That is, there would be two profiles for each user.
    Based on my understanding, it is very likely the user profile synchronization is based on the user's account name.  But in document and sample files provided, I can't find out any clue how to prepare the ldif file so that it will update the
    matching records, instead of creating new ones.
    Any help?  Thanks in advance.

    Has anyone managed to get this to work?
    It's nice that Microsoft offers the ability to import user profiles via LDIF into SharePoint, but it is useless if the account name is not correct after the import. I have tried multiple imports from the LDIF to get a user account to show up as  "domain\username" but
    it always ends up as "domain:domain\username", or "domain:username".  or a variation
    of these 2 with a colon separating the domain form the username. i see that multiple people have had the same problem, but unfortunetaly can't seem to find a solution. Also I see Bradley mentions that he was able to import accounts using get-QADUser,
    but he doesnt mention what the accounts import as or if it resolved the domain colon issue.
    Thanks in advance for any help or information anyone can provide.
    cheers,
    Zed

  • Information about Global Usage Code in 10g and 11g

    Hi all,
    While creating TP in 10g in Step 4: Create Trading Partner: Delivery Channel , there is a field Global Usage Code which has values as 'Test' or 'Production'.
    But in case of 11g, i dont see a field for Global Usage Code. If it is not present in the front end, then does B2B 11g picks this value from backend?
    Can someone provide some pointers on this??

    As far as I know, "Global Usage Code" was an indicator field only and used to specify the usage of the delivery channel. If it is set to Test, then the delivery channel is used only for testing purposes. If it is set to Production, then it is used only for production purposes. It has no affect on actual message processing.
    This field is no more available in 11g and such indication is also not required because of Weblogic domain concept as you will have at least different domains for diferen environments (if you are using same installation fo all env)
    Regards,
    Anuj

  • Can't I use a WRT610N as a bridge or AP?

    Inherited this WRT610N from someone, and want to deploy it in a preexisting LAN (172.21.1.x) with a pre-existing DHCP server.
    Can I use the "Internet" port if I assign it static IP on my LAN, and create a new DHCP scope (192.168.1.x) for Wireless clients?
    Solved!
    Go to Solution.

    1. You cannot use the WRT610N as wireless bridge. The WRT won't connect wireless to other access points.
    2. You can set up the WRT the way you have suggested. This will create to separated LANs. Your existing LAN won't be able to access the WRT LAN, but the WRT LAN can access your main LAN.
    3. You can set up the WRT the way you have suggested and turn off NAT on the WRT if your main router is able to NAT additional IP subnets other then its own LAN subnet (i.e. you can tell your main router to NAT 192.168.1.* addresses). WIth NAT disabled on the WRT you have to add a static route for 192.168.1.0/255.255.255.0 to the static IP address of your WRT in your 172.21.1.* network. In addition, computers in your existing LAN should either have the same static route installed or the computers should accept ICMP redirects from your main router. With this setup, the WRT LAN is routed from your main LAN, i.e. computers are able to connect to each other. But it's still a separated broadcast domain which means things like standard Windows workgroup name resolution won't work as that is based on LAN broadcasts.
    4. You can set up the WRT as simple access point and ethernet switch. Leave the internet settings on DHCP. Set a LAN IP address inside your main LAN 172.21.1.*, subnet mask the same as your existing LAN (if possible). Switch off the DHCP server on the WRT. Now connect one of the LAN ports of the WRT to your existing LAN. Do not use the internet port of the WRT. Now you have connected the AP inside the WRT directly into your LAN bypassing all the routing functions of the WRT. You only have a single LAN now and everything can connect to everything else in your LAN.

  • Installing Essbase 11.1.2.1 EPM System Configurator

    Hi,
    I'm installing Essbase on a windows 2008 R2 server.
    After doing the installation following the guide "Rapid deployment of Essbase domain for development environments" and this step by step, i got stuck (some days already) on the setup Shared services and Registry database Connection
    After filling the 3 params SID, User name and Password, I receive the ERROR
    IO ERROR: The network Adapter could not establish the connection.
    I read here that installing and configuring the LOOPBACK Adapter will resolve the problem, It did not for me.
    Can one of you help me out here?
    Many thanks
    Walter

    Is Oracle on the same machine, if it is not can you definitely connect to it from the machines where you are configuring from.
    Are the connection details you entering definitely correct.
    Cheers
    John
    http://john-goodwin.blogspot.com/

  • Transport Authorization Objects

    Hi all,
          Can you please clarify this issue. Is it a good practice to transport authorization objects from Dev to Q/A to Prod or create them separately in all the three environments. I transported the roles but I am not certain about the authorization objects.
    Thank you for your time,
    Ram

    Hi,
    It is a policy decision what will be the source system of your authorizations. From there you can use the transport system to spread the roles over the landscape. To keep everything in sync, use the transport system otherwise in a matter of time you have no idea which is coming from where.
    have fun
    Jan van Roest

Maybe you are looking for

  • Logical statements in Substitutions

    How to write logic in the substitution rules like if ... else Thanks

  • Error when trying to create Dimensions

    Hi, We just installed BPC 5.1. However we are facing issues. As soon as I login and try to create new dimensions I get the following error message: 'Admin Load failed: Exception of type System. OutOfMemoryException was thrown' Any ideas as how to fix

  • Where can I find a list of Adobe Application Manager (AAMInstaller) error codes?

    I'm seeing an error 253 when installing Acrobat and error 81 when installing Illustrator, and can't seem to find documentation anywhere. Mac OS X - 10.9.5

  • Reg: To open a Browse Window Using Form Builder

    Dear All, I am trying to open a browse window using form builder.I am using forms 10g. I have user the following code. Declare l_file_name Varchar2(383); Begin l_file_name := webutil_file.file_open_dialog( ); If   l_file_name Is Not Null Then   If   

  • ABAP /XI Certification

    Hi Guys !! I am intrested fot the ABAP and XI certification. I need some guidelines towords applying. How to apply and where to apply all these info i need. Thanks a Million in advance.