Silent installation with different LDAP server

I am trying to do a silent install of iAS 6.0 SP2 and it fails at the
ACL, directory server stage (steps 10/11).
I am trying to install iAS without installing the LDAP server component
as I already have a directory server installed.
The error message I am getting is as follows:
10. ERROR: Register_NASA: Unable to find or execute programs
/train/iplanet/ias/ias/bin/.ldapmodify
or /shared/bin/ldapmodify
... skipping this step ...
Changing ownership of iAS files to imm:imm .....
Done.
Start registering System/StaticServlet...
Start registering Bootstrap EJB...
javax.naming.NameNotFoundException
at java.lang.Throwable.fillInStackTrace(Native Method)
at java.lang.Throwable.fillInStackTrace(Compiled Code)
at java.lang.Throwable.(Compiled Code)
at java.lang.Exception.(Compiled Code)
at javax.naming.NamingException.(NamingException.java:114)
at javax.naming.NameNotFoundException.(NameNotFoundException.java:48)
at com.netscape.server.jndi.RootContext.resolveCtx(Unknown Source)
at com.netscape.server.jndi.RootContext.bind(Unknown Source)
at com.netscape.server.jndi.RootContext.bind(Unknown Source)
at javax.naming.InitialContext.bind(InitialContext.java:371)
at com.netscape.server.deployment.EjbReg.deployToNaming(Unknown Source)
at com.netscape.server.deployment.EjbReg.registerEjbJar(Compiled Code)
at com.netscape.server.deployment.EjbReg.registerEjbJar(Compiled Code)
at com.netscape.server.deployment.EjbReg.run(Compiled Code)
at com.netscape.server.deployment.EjbReg.main(Unknown Source)
Start registering iAS 60 Fortune Application...
It looks like all the required ldap files - .ldapmodify, .ldapsearch
etc. are not getting copied to the installed ias bin directory
(/train/iplanet/ias/ias/bin) from the source directory
(/train/software/ias/Solaris/iAS/nas) as I have not selected the
Directory server during the iAS install.
My install.inf has the following values for the components to be
installed -
Components= WEBCONNECTOR,WEBLESS,iAS-AT,iAS-DT,iAS_BASE
What does iAS-DT stand for?
Any workarounds?
Thanks.
Ranga

Hi Ranga,
iAS-DT is (iPlanet Application Server Deployment Tool).its a GUI for
deployment of J2EE application. You can use existing directory server
but you have to spacify directory server at the time of installation .
If you need more help please send your install.inf and userinput.log
file
Deepak
Dev support
Ranga T S wrote:
I am trying to do a silent install of iAS 6.0 SP2 and it fails at the
ACL, directory server stage (steps 10/11).
I am trying to install iAS without installing the LDAP server
component as I already have a directory server installed.
The error message I am getting is as follows:
10. ERROR: Register_NASA: Unable to find or execute programs
/train/iplanet/ias/ias/bin/.ldapmodify
or /shared/bin/ldapmodify
... skipping this step ...
Changing ownership of iAS files to imm:imm .....
Done.
Start registering System/StaticServlet...
Start registering Bootstrap EJB...
javax.naming.NameNotFoundException
at java.lang.Throwable.fillInStackTrace(Native Method)
at java.lang.Throwable.fillInStackTrace(Compiled Code)
at java.lang.Throwable.(Compiled Code)
at java.lang.Exception.(Compiled Code)
at javax.naming.NamingException.(NamingException.java:114)
at javax.naming.NameNotFoundException.(NameNotFoundException.java:48)
at com.netscape.server.jndi.RootContext.resolveCtx(Unknown Source)
at com.netscape.server.jndi.RootContext.bind(Unknown Source)
at com.netscape.server.jndi.RootContext.bind(Unknown Source)
at javax.naming.InitialContext.bind(InitialContext.java:371)
at com.netscape.server.deployment.EjbReg.deployToNaming(Unknown Source)
at com.netscape.server.deployment.EjbReg.registerEjbJar(Compiled Code)
at com.netscape.server.deployment.EjbReg.registerEjbJar(Compiled Code)
at com.netscape.server.deployment.EjbReg.run(Compiled Code)
at com.netscape.server.deployment.EjbReg.main(Unknown Source)
Start registering iAS 60 Fortune Application...
It looks like all the required ldap files - .ldapmodify, .ldapsearch
etc. are not getting copied to the installed ias bin directory
(/train/iplanet/ias/ias/bin) from the source directory
(/train/software/ias/Solaris/iAS/nas) as I have not selected the
Directory server during the iAS install.
My install.inf has the following values for the components to be
installed -
Components= WEBCONNECTOR,WEBLESS,iAS-AT,iAS-DT,iAS_BASE
What does iAS-DT stand for?
Any workarounds?
Thanks.
Ranga

Similar Messages

  • JAZN-LDAP: Make use of different LDAP Server

    Hi,
    I am trying to make use of a different LDAP Server (other than OID)-- With OID i am able to authenticate users.
    Now i need to make use of a different LDAP Server (For ex: SunONe Directory Server).. I have tried specifying the LDAP URL location of the new LDAP Server in the Orion-Application.xml as below
    <jazn provider="LDAP" location="ldap://ldaphost:ldapport" />
    But I see that the application is still defaulting to the OID and not making use of the LDAPserver specified above.
    Also, i see that I am unable to modify the LDAP URL Location
    In Step2 of Deploying an Application :
    Deploy Application: User Manager : I have selected the option "Use JAZN LDAP User Manager"
    But the LDAP Location is non-editable and which defaults to the OID location as the one below
    LDAP Location ldap://OIDLDAPURL:PORT
    Could ne1 throw some light on the issue i am facing..
    Thanks
    John

    See Configuring External LDAP Providers @:
    http://matrix.csustan.edu/docs/oracle/oas/web.1012/b14013/ldap3rdparty.htm
    Here are a few gotchas for active directory:
    -if you plan to use the membership of the AD user to AD roles, set in orion-application:
    <jazn provider="XML">
    <property name="custom.ldap.provider" value="true"/>
    <property name="role.mapping.dynamic" value="true"/>
    </jazn>
    in web.xml you should also define
    <security-role>
    <role-name>ldap-role-to-which-ldap-user-belongs-that-is-entitled to-acces-the-resource</role-name>
    </security-role>
    If you run the application in the embedded OC4J it seems it takes this hint from other file that you can determine looking at trace you can make appear with option:
    -Djazn.debug.log.enable=true (in jvm start command)
    When running in embedded OC4J the application is called: current-workspace-app
    Good Luck

  • Problem with NW04s SR2 installation with MS SQL Server 2000 SP4

    I’m struggling with the NW04s installation with MS SQL Server 2000.
    The installation stops at the step “Create/modify database schema SAPJ2EDB”.
    The following error/info from log file,
    INFO       2007-06-06 12:02:33 [iaxxgenimp.cpp:632]
               showDialog()
    Execute step doConfiguration of component |NW_Onehost|ind|ind|ind|ind|0|0|NW_Onehost_System|ind|ind|ind|ind|1|0|NW_CreateDBandLoad|ind|ind|ind|ind|10|0|NW_CreateDB|ind|ind|ind|ind|0|0|NW_MSS_DB|ind|ind|ind|ind|2|0|NW_MSS_SRVCFG|ind|ind|ind|ind|6|0.
    INFO       2007-06-06 12:02:35 [iaxxgenimp.cpp:632]
               showDialog()
    Execute step doTempdb of component |NW_Onehost|ind|ind|ind|ind|0|0|NW_Onehost_System|ind|ind|ind|ind|1|0|NW_CreateDBandLoad|ind|ind|ind|ind|10|0|NW_CreateDB|ind|ind|ind|ind|0|0|NW_MSS_DB|ind|ind|ind|ind|2|0|MssDowntimeConfig|ind|ind|ind|ind|7|0.
    INFO       2007-06-06 12:02:36 [iaxxgenimp.cpp:632]
               showDialog()
    Execute step doSwitch of component |NW_Onehost|ind|ind|ind|ind|0|0|NW_Onehost_System|ind|ind|ind|ind|1|0|NW_CreateDBandLoad|ind|ind|ind|ind|10|0|NW_CreateDB|ind|ind|ind|ind|0|0|NW_MSS_DB|ind|ind|ind|ind|2|0|MssDowntimeConfig|ind|ind|ind|ind|7|0.
    INFO       2007-06-06 12:02:36 [iaxxgenimp.cpp:632]
               showDialog()
    Execute step doTempDBAnalyze of component |NW_Onehost|ind|ind|ind|ind|0|0|NW_Onehost_System|ind|ind|ind|ind|1|0|NW_CreateDBandLoad|ind|ind|ind|ind|10|0|NW_CreateDB|ind|ind|ind|ind|0|0|NW_MSS_DB|ind|ind|ind|ind|2|0|MssDowntimeConfig|ind|ind|ind|ind|7|0.
    INFO       2007-06-06 12:02:37 [iaxxgenimp.cpp:632]
               showDialog()
    Execute step doTempDBBeforeRestart of component |NW_Onehost|ind|ind|ind|ind|0|0|NW_Onehost_System|ind|ind|ind|ind|1|0|NW_CreateDBandLoad|ind|ind|ind|ind|10|0|NW_CreateDB|ind|ind|ind|ind|0|0|NW_MSS_DB|ind|ind|ind|ind|2|0|MssDowntimeConfig|ind|ind|ind|ind|7|0.
    INFO       2007-06-06 12:02:38 [iaxxgenimp.cpp:632]
               showDialog()
    Execute step doRestartServer of component |NW_Onehost|ind|ind|ind|ind|0|0|NW_Onehost_System|ind|ind|ind|ind|1|0|NW_CreateDBandLoad|ind|ind|ind|ind|10|0|NW_CreateDB|ind|ind|ind|ind|0|0|NW_MSS_DB|ind|ind|ind|ind|2|0|MssDowntimeConfig|ind|ind|ind|ind|7|0.
    INFO       2007-06-06 12:02:58 [ianxbservi.cpp:697]
               CIaNtServices::stop(const map<iastring,iastring>&)
    The service 'MSSQLSERVER' stopped successfully on host 'GBCZ672C'.
    INFO       2007-06-06 12:03:10 [ianxbservi.cpp:632]
               CIaNtServices::start(const map<iastring,iastring>&)
    The service 'MSSQLSERVER' started successfully on host 'GBCZ672C'.
    INFO       2007-06-06 12:03:21 [ianxbservi.cpp:632]
               CIaNtServices::start(const map<iastring,iastring>&)
    The service 'SQLSERVERAGENT' started successfully on host 'GBCZ672C'.
    INFO       2007-06-06 12:03:21 [iaxxgenimp.cpp:632]
               showDialog()
    Execute step doTempDBAfterRestart of component |NW_Onehost|ind|ind|ind|ind|0|0|NW_Onehost_System|ind|ind|ind|ind|1|0|NW_CreateDBandLoad|ind|ind|ind|ind|10|0|NW_CreateDB|ind|ind|ind|ind|0|0|NW_MSS_DB|ind|ind|ind|ind|2|0|MssDowntimeConfig|ind|ind|ind|ind|7|0.
    INFO       2007-06-06 12:03:22 [iaxxgenimp.cpp:632]
               showDialog()
    Execute step doChangeTempSetNewSize of component |NW_Onehost|ind|ind|ind|ind|0|0|NW_Onehost_System|ind|ind|ind|ind|1|0|NW_CreateDBandLoad|ind|ind|ind|ind|10|0|NW_CreateDB|ind|ind|ind|ind|0|0|NW_MSS_DB|ind|ind|ind|ind|2|0|MssDowntimeConfig|ind|ind|ind|ind|7|0.
    INFO       2007-06-06 12:03:39 [iaxxgenimp.cpp:632]
               showDialog()
    Execute step CheckParameters of component |NW_Onehost|ind|ind|ind|ind|0|0|NW_Onehost_System|ind|ind|ind|ind|1|0|NW_CreateDBandLoad|ind|ind|ind|ind|10|0|NW_CreateDB|ind|ind|ind|ind|0|0|NW_MSS_DB|ind|ind|ind|ind|2|0|MssSchemaCreate|ind|ind|ind|ind|9|0.
    INFO       2007-06-06 12:03:39 [iaxxgenimp.cpp:632]
               showDialog()
    Execute step CreateDirectories of component |NW_Onehost|ind|ind|ind|ind|0|0|NW_Onehost_System|ind|ind|ind|ind|1|0|NW_CreateDBandLoad|ind|ind|ind|ind|10|0|NW_CreateDB|ind|ind|ind|ind|0|0|NW_MSS_DB|ind|ind|ind|ind|2|0|MssSchemaCreate|ind|ind|ind|ind|9|0.
    INFO       2007-06-06 12:03:40 [iaxxgenimp.cpp:632]
               showDialog()
    Execute step CreateDatabase of component |NW_Onehost|ind|ind|ind|ind|0|0|NW_Onehost_System|ind|ind|ind|ind|1|0|NW_CreateDBandLoad|ind|ind|ind|ind|10|0|NW_CreateDB|ind|ind|ind|ind|0|0|NW_MSS_DB|ind|ind|ind|ind|2|0|MssSchemaCreate|ind|ind|ind|ind|9|0.
    ERROR      2007-06-06 12:03:40 [iaxxgenimp.cpp:731]
               showDialog()
    FCO-00011  The step CreateDatabase with step key |NW_Onehost|ind|ind|ind|ind|0|0|NW_Onehost_System|ind|ind|ind|ind|1|0|NW_CreateDBandLoad|ind|ind|ind|ind|10|0|NW_CreateDB|ind|ind|ind|ind|0|0|NW_MSS_DB|ind|ind|ind|ind|2|0|MssSchemaCreate|ind|ind|ind|ind|9|0|CreateDatabase was executed with status ERROR .
    ERROR      2007-06-06 12:03:40
               lib=iamodmssql module=CIaNtMssDmo
    MDB-05053  Errors when executing sql command: <p nr="0"/> If this message is displayed as a warning - it can be ignored. If this is an error - call your SAP support.
    INFO       2007-06-06 12:04:04 [iaxxgenimp.cpp:774]
               showDialog()
    An error occured and the user decided to retry the current step: "|NW_Onehost|ind|ind|ind|ind|0|0|NW_Onehost_System|ind|ind|ind|ind|1|0|NW_CreateDBandLoad|ind|ind|ind|ind|10|0|NW_CreateDB|ind|ind|ind|ind|0|0|NW_MSS_DB|ind|ind|ind|ind|2|0|MssSchemaCreate|ind|ind|ind|ind|9|0|CreateDatabase".
    ERROR      2007-06-06 12:04:05 [iaxxgenimp.cpp:731]
               showDialog()
    FCO-00011  The step CreateDatabase with step key |NW_Onehost|ind|ind|ind|ind|0|0|NW_Onehost_System|ind|ind|ind|ind|1|0|NW_CreateDBandLoad|ind|ind|ind|ind|10|0|NW_CreateDB|ind|ind|ind|ind|0|0|NW_MSS_DB|ind|ind|ind|ind|2|0|MssSchemaCreate|ind|ind|ind|ind|9|0|CreateDatabase was executed with status ERROR .
    Please let me know if you can help or if there is any other way around.
    Many Thanks in advance.
    Ritin Jain

    Hi All,
    I was not able to solve the problem with MS SQL 2000, but I was able to resolve the issue with MS SQL 2005.
    You have to chhose the following settings while instalation,
    Service Account - Select one of the following options:
    1) Use the built-in System account for each service and choose Local system or Network Service.
    2) Use a domain user account, and enter the user name and password.
    Under Start services at the end of setup make sure that SQL Server and SQL Server Agent are selected.
    Authentication Mode      
    1) Select Mixed Mode (Windows Authentication and SQL Server Authentication).
    This mode is required for a Java or ABAP+Java system.
    If you choose this mode, you have to set the password for the sa login.
    Note: The password for the sa login must comply with the Windows password policy.
    Collation Settings      
    1) Select SQL collations (used for compatibility with previous versions of SQL Server).
    2) From the drop-down list select Binary order based on code point comparison, for use with the 850 (Multilingual) Character Set.
    I hope this helps!

  • [OBPM 10gR3]How to configer a hybrid directory with Oracle LDAP Server

    Hey, guys,
    Does anyone have experience on configering a hybrid directory with Oracle LDAP Server? How to config the mapping conf file for Oracle LDAP in the directory of \OraBPMwlHome\conf?
    Here is my conf file. But I got some LDAP mapping errors. It's really weird OBPM doesn't support Oracle's self LDAP, at least it does not provide the conf file.
    -----------errors------------
    Exception [javax.naming.OperationNotSupportedException: [LDAP: error code 53 - Function Not Implemented]; remaining name '']. Reason: [LDAP: error code 53 - Function Not Implemented] fuego.directory.DirectoryRuntimeException: Exception [javax.naming.OperationNotSupportedException: [LDAP: error code 53 - Function Not Implemented]; remaining name '']. at fuego.directory.DirectoryRuntimeException.wrapException(DirectoryRuntimeException.java:85) at fuego.directory.hybrid.ldap.JNDIQueryExecutor.select(JNDIQueryExecutor.java:203) at fuego.directory.hybrid.ldap.JNDIQueryExecutor.selectAllFromView(JNDIQueryExecutor.java:84) at fuego.directory.hybrid.ldap.JNDIQueryExecutor.selectAllFromView(JNDIQueryExecutor.java:64) at fuego.directory.hybrid.ldap.Repository.selectAllFromView(Repository.java:54) at fuego.directory.hybrid.ldap.LDAPPollingEventGenerator.buildCurrentProxies(LDAPPollingEventGenerator.java:98) at fuego.directory.provider.notifiers.BasePollingEventGenerator.generateEvents(BasePollingEventGenerator.java:41) at fuego.directory.hybrid.HybridMultipleEventGenerator.generateEvents(HybridMultipleEventGenerator.java:43) at fuego.directory.provider.notifiers.DirectoryNotifier.notifyChanges(DirectoryNotifier.java:403) at fuego.server.service.DirectoryListener.updateEngineFromDirectoryImpl(DirectoryListener.java:309) at fuego.server.service.DirectoryListener$DirectoryPollingItem.execute(DirectoryListener.java:351) at fuego.server.execution.DefaultEngineExecution$AtomicExecutionTA.runTransaction(DefaultEngineExecution.java:304) at fuego.transaction.TransactionAction.startBaseTransaction(TransactionAction.java:470) at fuego.transaction.TransactionAction.startTransaction(TransactionAction.java:551) at fuego.transaction.TransactionAction.start(TransactionAction.java:212) at fuego.server.execution.DefaultEngineExecution.executeImmediate(DefaultEngineExecution.java:123) at fuego.server.execution.DefaultEngineExecution.executeAutomaticWork(DefaultEngineExecution.java:62) at fuego.server.execution.EngineExecution.executeAutomaticWork(EngineExecution.java:42) at fuego.ejbengine.ejb.EngineStartupBean.executeItem(EngineStartupBean.java:192) at fuego.ejbengine.ejb.EngineStartupBean.updateFromDirectory(EngineStartupBean.java:172) at fuego.ejbengine.ejb.engine_startup_bpmengine_wodkyx_ELOImpl.updateFromDirectory(engine_startup_bpmengine_wodkyx_ELOImpl.java:365) at fuego.ejbengine.servlet.SchedulerServlet$DirectoryPollingTask.runImpl(SchedulerServlet.java:269) at fuego.ejbengine.servlet.SchedulerServlet$ScheduledTask.run(SchedulerServlet.java:208) at java.util.TimerThread.mainLoop(Timer.java:512) at java.util.TimerThread.run(Timer.java:462) Caused by: javax.naming.OperationNotSupportedException: [LDAP: error code 53 - Function Not Implemented]; remaining name '' at com.sun.jndi.ldap.LdapCtx.mapErrorCode(LdapCtx.java:3078) at com.sun.jndi.ldap.LdapCtx.processReturnCode(LdapCtx.java:2951) at com.sun.jndi.ldap.LdapCtx.processReturnCode(LdapCtx.java:2758) at com.sun.jndi.ldap.LdapCtx.searchAux(LdapCtx.java:1812) at com.sun.jndi.ldap.LdapCtx.c_search(LdapCtx.java:1735) at com.sun.jndi.toolkit.ctx.ComponentDirContext.p_search(ComponentDirContext.java:368) at com.sun.jndi.toolkit.ctx.PartialCompositeDirContext.search(PartialCompositeDirContext.java:338) at com.sun.jndi.toolkit.ctx.PartialCompositeDirContext.search(PartialCompositeDirContext.java:321) at javax.naming.directory.InitialDirContext.search(InitialDirContext.java:248) at fuego.jndi.FaultTolerantDirContext.search(FaultTolerantDirContext.java:867) at fuego.directory.hybrid.ldap.JNDIQueryExecutor.select(JNDIQueryExecutor.java:190) ... 23 more
    -----------mapping conf file for Oracle LDAP---------
    <?xml version="1.0" encoding="UTF-8"?>
    <?fuego version="6.1 ALPHA" application="albpmenterprise"?>
    <!-- This file contains the propper attribute mapping for the FDI Generic Ldap Provider using Oracle Directory Service.          
    * Preference for group object
              <preference id="assignedParticipants.containsId" value="true"/>
              This preference is useful to speed up the provider and it can only be used if the assignedParticipant value is the dn of the user and the dn contains the participant id
              <preference id="assignedParticipants.containsId" value="true"/>
              This preference is useful to speed up the provider and it can only be used if the assignedGroup value is the dn of the group and the dn contains the group id
              <preference id="modifyTimeStamp.suffix" value="Z"/>
              This preference is useful when the suffix mofidyTimeStamp format of your ldap is not .OZ.
    -->
    <config>
         <object id="person">
              <object-filter>
                   <![CDATA[
                        (objectclass=inetOrgPerson)
                   ]]>
              </object-filter>
              <relative-dn>
                   <!-- the relative dn for person -->
              </relative-dn>
              <attribute id="id" value="uid"/>
              <attribute id="lastName" value="sn"/>
              <attribute id="firstName" value="givenname"/>
              <attribute id="accountLock" value="orclIsEnabled">
                   <attribute-comparator operation="EQUALS" compareTo="ENABLED"/>
                   <filter>
                        <![CDATA[
                             ($accountLock=ENABLED)
                        ]]>
                   </filter>
              </attribute>
              <attribute id="facsimileTelephoneNumber" value="facsimileTelephoneNumber"/>
              <attribute id="displayName" value="displayName"/>
              <attribute id="mail" value="mail"/>
              <attribute id="telephoneNumber" value="telephoneNumber"/>
              <attribute id="employeeId" value="employeeNumber"/>
              <attribute id="thumbnailPhoto" value="jpegPhoto"/>
              <attribute id="manager" value="manager"/>
              <attribute id="modifyTimeStamp" value="modifytimestamp"/>
         </object>
         <object id="group">
              <object-filter>
                   <![CDATA[
                        (objectclass=orclGroup)
                   ]]>
              </object-filter>
              <relative-dn>
                   <!-- the relative dn for group -->
    </relative-dn>
              <attribute id="id" value="dn"/>
              <attribute id="modifyTimeStamp" value="modifytimestamp"/>
              <attribute id="displayName" value="displayName"/>
              <attribute id="name" value="cn"/>
              <attribute id="description" value="description"/>
              <attribute id="assignedParticipants" value="uniquemember"/>
              <!--attribute id="assignedGroups" value="memberOf"/-->
              <attribute id="ou" value="uniquemember"/>
         </object>
         <object id="ou">
              <object-filter>
                   <![CDATA[
                        (objectclass=domain)
                   ]]>
              </object-filter>
              <relative-dn>
                   <!-- the relative dn for ous -->
    </relative-dn>
              <attribute id="name" value="orclsubscriberfullname"/>
              <attribute id="description" value="description"/>
         </object>
    </config>
    Edited by: Lemonice on 2009-3-30 上午2:08
    Edited by: Lemonice on 2009-3-30 下午7:01
    Edited by: Lemonice on 2009-3-30 下午8:43

    Hi,
    in my case, I am trying to configure the OBPM directory using ALUI and its native LDAP service.
    Now, I found that the first name and the last name in BPM are retrieved from the ALUI display name : provided we enter the display name in the format %first name% + %last name% we get them into BPM. But the display name is not always in this format...
    In addition, it's the portal telephone number information which is retrieved into BPM Telephone and Fax numbers.
    And, the email adress remains blank
    I have installed the latest patch for OBPM (Version: 10.3.1.0.0 Build: #97172)
    Would you have any documentation about creating a Profile Web Service in ALUI and specifying which LDAP attributes to map to which ALUI properties in the Profile Source ?
    Thanks !
    Edited by: vVince on May 6, 2009 3:46 PM

  • OpenLDAP authentication provider with CA LDAP server

    Hi,
    I am trying to get authentication to work using an OpenLDAP AP connecting to CA LDAP server (formerly eTrust LDAP server). I am at the point where the bind is successful, the user account is authenticated in LDAP, but I am unable to retrieve the group information.
    Here is the error for the group lookup:
    ####<Apr 8, 2013 9:48:33 AM CDT> <Debug> <SecurityAtn> <EPMDOWCS8> <ms1> <[ACTIVE] ExecuteThread: '6' for queue: 'weblogic.kernel.Default (self-tuning)'> <<WLS Kernel>> <> <01f9ee928bc01ecd:275c5c34:13dea1201e3:-7ffd-000000000000021d> <1365432513554> <BEA-000000> <[Security:090278]Error listing member groups myACID>
    This is the final error, presumably because the group lookup failed:
    ####<Apr 8, 2013 9:48:33 AM CDT> <Debug> <SecurityAtn> <EPMDOWCS8> <ms1> <[ACTIVE] ExecuteThread: '6' for queue: 'weblogic.kernel.Default (self-tuning)'> <<WLS Kernel>> <> <01f9ee928bc01ecd:275c5c34:13dea1201e3:-7ffd-000000000000021d> <1365432513554> <BEA-000000> <javax.security.auth.login.FailedLoginException: [Security:090302]Authentication Failed: User myACID denied
         at weblogic.security.providers.authentication.LDAPAtnLoginModuleImpl.login(LDAPAtnLoginModuleImpl.java:229)
         at com.bea.common.security.internal.service.LoginModuleWrapper$1.run(LoginModuleWrapper.java:110)
         at com.bea.common.security.internal.service.LoginModuleWrapper.login(LoginModuleWrapper.java:106)
         at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
         at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:39)
         at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:25)
         at java.lang.reflect.Method.invoke(Method.java:597)
         at javax.security.auth.login.LoginContext.invoke(LoginContext.java:769)
         at javax.security.auth.login.LoginContext.access$000(LoginContext.java:186)
         at javax.security.auth.login.LoginContext$4.run(LoginContext.java:684)
         at javax.security.auth.login.LoginContext.invokePriv(LoginContext.java:680)
         at javax.security.auth.login.LoginContext.login(LoginContext.java:579)
         at com.bea.common.security.internal.service.JAASLoginServiceImpl.login(JAASLoginServiceImpl.java:113)
    The CA LDAP server is pointed to a Top Secret database, so the attribute names are atypical as far as directory services objects are concerned. I've tried modifying the group and static group information to search both groups and profiles, but both fail. I've also tried omitting the static group information, and specifying dynamic group info, but that failed as well.
    Here is the search it is running:
    (&(memberOf=tssacid=myACID,tssadmingrp=acids,host=ourdevsysid,o=our.ORG)(objectclass=tssprofile))
    Here the is the group based DN: tssadmingrp=profiles,host=ourdevsysid,o=our.org
    The group search scope is subtree. I tried unlimited, and a limited of 2 levels.
    If I execute the filtered search using a third party tool (JXplorer), I receive this error:
    javax.naming.NamingException: [LDAP: error code 80 - LDP2900E Unknown attribute, , in filter string]; remaining name 'tssadmingrp=profiles,host=ourdevsysid,o=our.org'
         at com.sun.jndi.ldap.LdapCtx.mapErrorCode(LdapCtx.java:3085)
         at com.sun.jndi.ldap.LdapCtx.processReturnCode(LdapCtx.java:2987)
         at com.sun.jndi.ldap.LdapCtx.processReturnCode(LdapCtx.java:2794)
         at com.sun.jndi.ldap.LdapCtx.searchAux(LdapCtx.java:1826)
         at com.sun.jndi.ldap.LdapCtx.c_search(LdapCtx.java:1749)
         at com.sun.jndi.toolkit.ctx.ComponentDirContext.p_search(ComponentDirContext.java:368)
         at com.sun.jndi.toolkit.ctx.PartialCompositeDirContext.search(PartialCompositeDirContext.java:338)
         at javax.naming.directory.InitialDirContext.search(InitialDirContext.java:257)
         at com.ca.commons.jndi.JNDIOps.rawSearch(JNDIOps.java:1192)
         at com.ca.commons.jndi.JNDIOps.rawSearchSubTree(JNDIOps.java:1039)
         at com.ca.commons.naming.DXOps.rawSearchSubTree(DXOps.java:343)
         at com.ca.commons.jndi.JNDIOps.searchSubTree(JNDIOps.java:1030)
         at com.ca.directory.jxplorer.broker.JNDIDataBroker.unthreadedSearch(JNDIDataBroker.java:772)
         at com.ca.directory.jxplorer.broker.DataBroker.doSearchQuery(DataBroker.java:485)
         at com.ca.directory.jxplorer.broker.DataBroker.processRequest(DataBroker.java:253)
         at com.ca.directory.jxplorer.broker.JNDIDataBroker.processRequest(JNDIDataBroker.java:376)
         at com.ca.directory.jxplorer.broker.DataBroker.processQueue(DataBroker.java:200)
         at com.ca.directory.jxplorer.broker.JNDIDataBroker.processQueue(JNDIDataBroker.java:883)
         at com.ca.directory.jxplorer.broker.DataBroker.run(DataBroker.java:165)
         at java.lang.Thread.run(Thread.java:662)
    When I execute that same search in JXplorer directly on one of the profile objects (e.g. tssprofile=@oneofourprofiles,tssadmingrp=profiles,host=a12sysid,o=tgslc.org), it runs successfully.
    Here is an old post. Seems the op encountered the same problem I did.
    authentication provider for CA eTrust LDAP server
    Anyone work with these technologies in a past life?
    Thanks,
    Rob

    Are you able to see the users in weblogic?Not for this AP. I have a ReadOnly SQL authenticator as well. I am able to see users for that, and for the Default Authenticator.
    Have you assigned admin roles to the user in weblogic?No. I do not intend to do that, and I don't believe I am required to do that.
    is the group base dn properly configured?Yes.

  • Getting iCal 3 to work with an LDAP server

    I've managed to set up Directory Utility with a third-party LDAP server (part of Communigate Pro) so that Directory will look up people.
    However I expected that once I did this, iCal would consult the LDAP server to do autocompletion when adding attendees to events. It doesn't.
    I thought maybe I could use Address Book's Directories Group to facilitate adding attendees. Both the LDAP server configured through Mail and the LDAP Directory Service configured through Directory Utility are visible here--but even though I can look people up, I can't drag any of the resulting names into the Attendees list in iCal.
    It seems I first have to drag them into a local Group; only then can I drag them into Attendee lists in iCal.
    Finally, iCal has a feature called the Address Panel which I thought might make use of an LDAP server configured through Directory Utility, but it hasn't worked for me. The Panel says "Open Directory Lookup" near the top of the window, which suggests it might not be intended to function with any old LDAP implementation.
    Any suggestions?
    By the way, I have the LDAP server's entry in Directory Utility as RFC 2307 with an empty searchbase for all mappings. However I haven't modified any of the mappings themselves.
    Thanks.

    iCal 3 looks for certain specific LDAP attributes which are (somewhat) unique to Open Directory.
    Some information on mimicking Open Directory can be found at http://wiki.expertmx.com/doku.php?id=applecalendarserver

  • Silent Installation with JRE 1.6_04

    Hi All,
    We are creating a batch file silent installation of Sun JRE. I am able to uninstall JRE and Install JRE. However I have issue while setting the parameters such as AUTOUPDATECHECK=0 SSL_V2_COMPATIBLE_HELLO=1 while installing.
    Has anyone tried this ?
    I use below batch file to install JRE
    jre-6u4-windows-i586-p.exe /s ADDLOCAL=jrecore IEXPLORER=0 MOZILLA=0 JAVAUPDATE=0 AUTOUPDATECHECK=0 SSL_V2_COMPATIBLE_HELLO=1
    Has anyone succesful with all the parameters?
    Rajesh Alex

    After long time I found solution to this issue.... I want to share to all
    (Silent installation wont work with JRE 1.604 and I had to set the SSLV2 client to true for SSL)
    There is 2 levels of settings for JRE 1.6 either at user level (Policy) or at System level
    User Level
    C:\Documents and Settings\ralex\<User Application Data Folder>\Sun\Java\Deployment\deployment.properties
    deployment.security.SSLv2Hello=true
    System Level
    <Windows Directory>\Sun\Java\Deployment\deployment.config
    To set this at System level , we have to create 2 files under
    1 C:<Windows Directory>\Sun\Java\Deployment\deployment.config
    a) deployment.config
    deployment.system.config=file:///C:/WINDOWS/Sun/Java/Deployment/deployment.properties
    deployment.system.config.mandatory=true
    b) deployment.properties file
    2 Delete the deployment.properties file under C:\Documents and Settings
    We have repackaged JRE Install .exe and after installation the script will do the above changes...
    Rajesh Alex
    Message was edited by:
    Alex(AlexysCorp)
    Message was edited by:
    Alex(AlexysCorp)

  • One Planning server configured with different BI server

    Hello Everyone,
    I have a Planning server configured with BI workspace (Hyperion 9.3.1). There are 5 Planning applications already running smoothly.
    Can I have another BI server pointing to the same Planning server? Now I want one more Planning application on the same Planning server but different BI server.
    If its possible, won't it affect the other applications already present in the Planning server?
    Is it possible. Your prompt response would be appreciated.
    Thanks

    Hi All,
    Thank you very much for the response....Had not been keeping well, so was unable to follow the forum....
    The fact is the current BI server is on 9.3.1 and Planning server is also on 9.3.1, in which I have 5 apps that are running smoothly....
    I have one more instance of Hyperion Planning application which is on version 3.5.1 and I need to upgrade it to 9.3.1. It would have been a smooth process if I would have just migrated it in the current set up. But we have a constraint here. The BI server is loaded and hence I can't have one more application configured on it. And also the apps belong to different departments. So they want a distinct BI server for this one single app.
    So, I have been asked to use a different BI server for workspace and reporting needs, and the existing Planning server(which is 9.3.1) for the Planning application.
    Kindly suggest me what should be my approach.
    Thanks

  • How can portal use two different LDAP Server in UME

    Hi,
    My question is Can UME in portal be configured for multiple LDAP sources.Currently i have a setting in portal
    as follows:
    Server Name : Abcd
    port : 1234
    user : CN=" ",Ou=" ",Ou=" ",Dc=AD,Dc=my company,Dc=com
    password :
    user path : DC=AD,Dc=My company,Dc=Com
    group Path : same as user path
    I want to configure one more LDAP server to my portal UME,how can give values for that in above sttings.I even want these current settings to be enabled.
    Do anyone have idea on this.
    Thanks and Regards
    Rani A

    Hi again ,
    I know it can be done. But how urgent is this for you.
    I can get back to you in couple of days, me lil busy today.
    cheers,
    Anu...

  • Silent Installation without MTS Transaction Server

    Hi,
    is there away to do a silent installation of the Oracle 9.x client without being prompted for the MTS port ?
    We need to install "oracle.networking.netcltprod" and "oracle.winprod" and it seems impossible to bypass the MTS screen.
    Thanks for any hint.
    Michael

    Hi,
    is there away to do a silent installation of the Oracle 9.x client without being prompted for the MTS port ?
    We need to install "oracle.networking.netcltprod" and "oracle.winprod" and it seems impossible to bypass the MTS screen.
    Thanks for any hint.
    Michael

  • Coldfusion 8 installation with Latest Wamp Server

    Hello Guys
    I need a very basic tutorial i am very new.....
    How can i setup Coldfusion 8 with WampServer so that i can access My Sql database
    N.B.  Please i need it quickly
    Smin Rana

    You should absolutely have your WAMP system running when you install ColdFusion. The web server connector option (and screen) is presented to a user during installation, so you may need to reinstall CF8.
    In brief, CF can be installed as a standalone web server (one that runs only on port 8500) or it can be tied in (connected) to your existing web server, be it IIS, Apache, etc. I think that most CF developers want CF tied into their system. I know that I prefer not to have to type or include or deal with port numbers in my URLs!
    Here's a test: start the ColdFusion web service (since you're on Windows this should be easy to do from the 'Services' panel -- and CF may already be running, depending on your install options). Then open your browser and go to http://localhost:8500/CFIDE/administrator. If you see the administrator page, you've got CF running.
    If it is running on port 8500, you can still connect to your MySQL databases and use CF. However, it's just not connected to Apache. You can manually connect CF to Apache but it isn't an easy thing to do, per se. It might be worth uninstalling CF and reinstalling using the tutorial link I posted previously.
    When you get a chance, let me know if CF is running on port 8500 (above).

  • MySAP ERP 2004 Installation with MS SQL server database

    Hi all,
    I m trying to perform the DB instance of mySAP ERP 2004 on a MS SQL Server, but during the process of SAPSSEXEC
    the my MS SQL server stops and I the SAPSSEXEC.log files ends up with a fatal error:DB connection failed.
    I stoped and restart the installation but the same error repeats. Can anybody try to help me out in this regard.
    Thanks
    Yogi

    Hi Yogi
    I am facing the same problem as you:
    I have been installing ECC5 SR1. The Centrale Instance installation happened very well.
    The problem is with The Database installation. At the phase 16 of 29, Database load, the R3load jobs take more than 21 hours and often finish with the following sql error message in the log files:
    <i>(DB) ERROR: DDL statement failed
    (CREATE UNIQUE  INDEX [DD03L~1] ON [DD03L] ( [TABNAME] , [AS4LOCAL] , [POSITION] , [AS4VERS]  ) )
    DbSlExecute: rc = 99
      (SQL error 21)</i>
    I am working on :
    - Windows 2003 server
    - The DB is on
    Microsoft SQL Server  2000 - 8.00.2039 (Intel X86) 
    I come all the way to read that you have solved the same problem. Can you help me please.
    Thanks.
    Belehego

  • PS CS 4 - silent installation with deploymentFile. Exitcode 1

    I have created the install.xml and the remove.xml with setup.exe --record=1.
    I have placed those files into Adobe CS4 folder, where the setup.exe file is.
    I have created the application.xml.override file with following parameters:
    ---------------application.xml.override file --------------------------------
    <?xml version="1.0" encoding="utf-8"?>
    <Configuration>
    <Payload>
    <Data key="Registration">Suppress</Data>
    <Data key="EULA">-1</Data>
    <Data key="Updates">Suppress</Data>
    </Payload>
    </Configuration>
    ---------------/ application.xml.override file --------------------------------
    I have tried to place this file into different folders, but everytime when i try to run:
    setup.exe --mode=silent --deploymentFile="install.xml"
    it begun adobe setup, and after some seconds it ends adobe setup with exit code = 1.
    Exitcode: 1 = Unable to parse command line
    Any suggestions..??
    Best regards.

    Tai Lao wrote:
    What Christoph is trying to tell you is that you actually need to mount that disk image by double clicking on the icon of the dmg file.  The contents of the disk image is what you need to install, not the dmg file itself.
    Thank you so much! I could not understand what Chris meant about that dmg file. I took your advice and double clicked on the icon of the dmg file, trying to install the extract plus filter, but I got this message (see screenshot)
    Next, I tried to open the dmg file > English > goodies > filters, but they're still grayed out (see screenshot)
    Having got my first MacBook Pro in July of 2009, I am still a fairly new, first-time mac user. So you guys may have to spell things out for me, please?

  • Issues with an LDAP server configured using DHCP instead of static.

    Can anyone tell me if there is a known issue using a DHCP address instead of a static IP address to build a 10.4 MAC server that will is a LDAP master?
    I have an LDAP master that is running 10.4 that has user account issues. Random users will suddenly not be able to authenticate against the server. I have been told this is because the server was originally built using a DHCP address and then migrated to a static IP. Being a UNIX geek this does not seem to make a lot of sense to me but I am new to MAC..... So?

    It absolutely could be the cause of the issue. Open Directory uses Kerberos (among other things) for authentication. Kerberos is VERY VERY VERY particular about DNS... and if your OD master changed the IP address, it could cause these problems. I wouldn't expect that it would ever work, but perhaps some days the IP is the same as it was during initial setup.
    Do a 'sudo changeip -checkhostname' from the server and see if it says everything is okay. If not, you definitely have things you need to fix. Frankly, with DHCP on the server you are 100% guaranteed to have problems at some point.

  • Problems with Adobe Premiere Elements 10 silent installation with SCCM 2007

    Hi, i have some issues when i try to install Premiere Elements 10 from Config Manager.
    I have followed these instructions:
    http://www.appdeploy.com/packages/detail.asp?id=2331
    If i try this commandoline:
    setup.exe" /L1033 /S /V“SERIALNUMBER=xxxx-xxxx-xxxx-xxxx-xxxx-xxxx COUNTRY=xxx /qn" it works when i run this locally, but not from Config manager, i get an exit code 1203.
    Can someone tell me what i can change in the MSI, so i can use the MSI installer?

    Well, if i use this commandoline: oem.exe /UL1033 /V"SERIALNUMBER=xxxx-xxxx-xxxx-xxxx-xxxx-xxxx"
    i get this error:
    program for advertisement "XXXXXX" failed ("xxxxxx" - "Per-system unattended"). A failure exit code of 255 was returned.
    User context: NT-MYNDIGHET\SYSTEM
    Possible cause: Systems Management Server (SMS) determines status for each program it executes. If SMS cannot find or correlate any installation status Management Information Format (MIF) files for the program, it uses the program's exit code to determine status. An exit code of 255 is considered a failure.
    Solution: For more information on the exit code, refer to the documentation for the program you are distributing.

Maybe you are looking for

  • How can I adjust just the ringer volume on an iPhone 4s

    I have the ringer turned way up because I'm in a noisy work environment, but that also increases the volume for the key click, game sounds, etc.  is there a way to only affect the ringer volume?

  • How to restore data (contacts mainly) after synchronising with wrong options

    Hi I hope someone can help me? It seems I must have changed the settings of synchronisation with PC Suite, because it suddenly deleted quite a bunch of contacts from my phone! Before (unfortunately long ago) I know I synchronised by combining both th

  • Dim Screen, freezing, mouse issues

    My macbook just started doing all of this today, with no prior warning. First, the mouse would stop working for no reason. i would unplug it and plug it back in, and it would work for anywhere from 2 to 10 minutes, then just quit again. a few hours l

  • Connecting Ethernet cable causes shutdown

    Our 17" iMac suddenly shutdown and refused to start up - makes the start sound but shuts down after a few seconds. Managed to get it going by removing all cables and resetting SMU. Then connected to network thru Airport. The moment I reinsert the Eth

  • T-code for Asset balances

    Dear All , Can somebody tell me what is the <b>t-code for Asset balances</b> . Actually I want to do the BDC recording for that . Thanks in advance Regards Prabhat