SSO to ITS error

Good day,
I have a problem when trying to connect to ITS via SSO. This has all been set up and it works fine. Problem arises when I deactivate my user's password (delete the password) on the R/3 end and whenever I try to log to the ITS via SSO, an error message "USER_HAS_NO_PASSWORD" appears.
Could this be a configuration setting that needs to be set up?
ITS: release 6200 patchlevel 1022 patchno 63326 build 16160160
Resolved: Partially resolved by following Note 1068459.
Message was edited by:
        E. Blueprint Basis
Message was edited by:
        E. Blueprint Basis

Found the cause of the problem in OSS Note 1068459.

Similar Messages

  • SSO between ITS 620 R/3 and EP

    Hi,
    I need to use ITS 620 for R/3 4.7 and EP 6.0 for ess/mss implementation
    I have to configure SSO between R/3 and EP.
    Do I also need to configure SSO between ITS and R/3 , ITS and EP also for this?
    If yes can any one tell me the steps in configuring SSO between ITS and R/3, ITS and EP ?
    advance thanks,
    PK

    UPDATE:
    I have installed a portal (SAp netweaver 7.0 Java stack) and have connected it to a ECC6.0 SR3 backend and I needed only to configure the SSO between portal and backend abap instance, and all worked fine. There was no need to configure the SSO between the integrated ITS and abap instance.
    About the error  message mentioned in my previous forum entry:
    I did not only do the steps for SSO between portal and backend as described in the blog "Configuring the Business Package for Employee Self-Service (ESS)", but I also did all the additional steps as mentioned in "10 golden rules of SSO".
    After that the error message "SSO logon not possible; logon tickets not activated on the server" did not appear anymore. (Instead a screen that asks for username and password always appears with the warning "No switch to HTTPS occurred, so it is not secure to send a password". But I think that's ok.)

  • Configure SSO for ITS to R/3 using SNC/Kerberos

    Our R/3 systems had been configured for SSO using SNC and Kerberos for awhile now.  We now have a requirement to configure SSO between ITS and R/3.  Since our R/3 env. has been using kerberos library, we won't be able to use SAP Cryptographic library.  I had modified the registry, environment and services in itsadmin to point to the kerberos library and principal names for agate and r/3 servers as described in SNC User Guide; also, I updated table SNCSYSACL with the Agate SNC name.  That seems to work fine.  From the trace file, it recognized GSS-API library for Kerberos and the SNC name for Agate.  However, when I tried to logon to R/3 from ITS, I still am being prompted with the logon screen to enter my SAP account/password.
    I found several whitepapers and documentations stating that ITS does support Kerberos for SSO but I couldn't find any procedure on how to implement it.  Following is the error I'm getting from the sapbasis.trc file but I can't find any document on this error:
    =====================================================
    [Thr 5284] SncInit(): Initializing Secure Network Communication (SNC)
    [Thr 5284]       PC with Windows NT (mt,ascii,SAP_UC/size_t/void* = 8/32/32)
    [Thr 5284] SncInit(): Trying environment variable SNC_LIB as a
          gssapi library name: "C:\WINNT\system32\gsskrb5.dll".
    [Thr 5284]   File "C:\WINNT\system32\gsskrb5.dll" dynamically loaded as GSS-API v2 library.
    [Thr 5284]   The internal Adapter for the loaded GSS-API mechanism identifies as:
      Internal SNC-Adapter (Rev 1.0) to Kerberos 5/GSS-API v2
    [Thr 2888] Sun Jan 15 22:44:59 2006
    [Thr 2888] <<- ERROR: SncSetParam()==SNCERR_PARAM_DENIED
    [Thr 2888] *** WARNING => NO Domain! domain==NULL means: No domain at all within the cookie. [sapss1_loctr 333]
    [Thr 2888] Sun Jan 15 22:45:29 2006
    [Thr 2888] *** WARNING => NO Domain! domain==NULL means: No domain at all within the cookie. [sapss1_loctr 333]
    =====================================================
    Does anyone know what am I missing?  Any help is greatly appreciated.
    Thank you!
    Diem

    Hi Markus,
    I also just installed/configured PAS for LDAP authentication using the "PAS for External Authentication Mechanisms" documentation.  I think the domain problem probably due to not having the external authentication mechanism install (in this case - PAS).  Does that sound right to you?
    I tried both options for ~extid_type parameter = "LD" and "UN".  I added the DN information to table USREXTID when ~extid_type="LD" but both options gave me error of "LDAP authentication failed".  I increased the trace level for sapextaut.trc but I don't see enough detail information.  Following are the errors/data from the trace file.  Can you please let me know how I can tell what string is being passed for authentication? 
    I'm quite sure the LDAP host and port data is correct since we've been using the same information for the SAP LDAP connector and we've been using our LDAP connector between MS AD and R/3 for a long time without any problem. 
    To logon to R/3 through ITS, I entered the AD account (CN attribute in AD) when I got the errors.
    Thank you very much for all your help.
    Diem Tran
    Trace:
    =====================================================
    2006-01-18T01:39:30.734 p001688 t4992 s0158B4E8 [sapextauth,  437]: W sapextauth: PAS session begins...
    2006-01-18T01:39:30.734 p001688 t4992 s0158B4E8 [sapextauth,  456]:     sapextauth: SncNameR3 is:    "p:na1adm/[email protected]"
    2006-01-18T01:39:30.734 p001688 t4992 s0158B4E8 [sapextauth,  462]:     sapextauth: SncNameAGate is: "p:[email protected]"
    2006-01-18T01:39:30.750 p001688 t4992 s0158B4E8 [sapextauth,  468]:     sapextauth: SNC_LIB is:      "C:\WINNT\system32\gsskrb5.dll"
    2006-01-18T01:39:30.750 p001688 t4992 s0158B4E8 [sapextauth,  568]:     sapextauth: XGatConnectSession leaving....
    2006-01-18T01:39:30.750 p001688 t4992 s0158B4E8 [sapextauth,  616]:     sapextauth: XGatHandleLogin called....
    2006-01-18T01:39:30.750 p001688 t4992 s0158B4E8 [sapextauth,  976]:     sapextauth: Entering XGatHandleLogin with LDAP...
    2006-01-18T01:39:30.750 p001688 t4992 s0158B4E8 [sapextauth,  993]: W Either ~login or ~password missing, returning XGDKRCloginrequired.
    2006-01-18T01:39:50.281 p001688 t4992 s00000000 [sapextauth,  398]:     sapextauth: XGatEventOpenSession called...
    2006-01-18T01:39:50.281 p001688 t4992 s0158B4E8 [sapextauth,  616]:     sapextauth: XGatHandleLogin called....
    2006-01-18T01:39:50.281 p001688 t4992 s0158B4E8 [sapextauth,  976]:     sapextauth: Entering XGatHandleLogin with LDAP...
    2006-01-18T01:39:50.296 p001688 t4992 s0158B4E8 [sapextauth, 1059]:     sapextauth: LDAP port ist 389
    2006-01-18T01:39:50.296 p001688 t4992 s0158B4E8 [sapextauth, 1261]: E sapextauth: LDAP authentication failed.
    2006-01-18T01:39:50.296 p001688 t4992 s0158B4E8 [sapextauth, 1277]: E sapextauth: Wrong try for user Tran_Diem
    2006-01-18T01:39:59.140 p001688 t4992 s00000000 [sapextauth,  398]:     sapextauth: XGatEventOpenSession called...
    2006-01-18T01:39:59.156 p001688 t4992 s0158B4E8 [sapextauth,  616]:     sapextauth: XGatHandleLogin called....
    2006-01-18T01:39:59.156 p001688 t4992 s0158B4E8 [sapextauth,  976]:     sapextauth: Entering XGatHandleLogin with LDAP...
    2006-01-18T01:39:59.156 p001688 t4992 s0158B4E8 [sapextauth, 1059]:     sapextauth: LDAP port ist 389
    2006-01-18T01:39:59.156 p001688 t4992 s0158B4E8 [sapextauth, 1261]: E sapextauth: LDAP authentication failed.
    2006-01-18T01:39:59.156 p001688 t4992 s0158B4E8 [sapextauth, 1277]: E sapextauth: Wrong try for user Tran_Diem
    =======================================================

  • User assgined to a group, SSO to ITS is not working

    We had our security group add a ESS-User group.  We imported 500 users and assigned them to that group.  When logging into EP, we are getting access to the correct tabs, but ITS is requiring us to login. 
    But when logging in as a user that is not assigned to this group, the SSo to ITS is working. 
    What setup step are we missing?  Are we supposed to configure something in Visual Administrator.

    Hi Dena,
    A logon trace might provide the cause of the problem. See SAP note 495911 for starting.
    Thanks and regards,
    Dieter

  • HT201413 Whenever i try to sync my ipod a message keeps coming up saying "1 or more items could not be synced", apparently its error -69. Please help, i've tried rebooting my laptop, installing the latest itunes and turning off the wifi but nothing seems

    Whenever i try to sync my ipod a message keeps coming up saying "1 or more items could not be synced", apparently its error -69. Please help, i've tried rebooting my laptop, installing the latest itunes and turning off the wifi but nothing seems to work.

    Are you using security software on your PC? If yes, try to disable the software or check the settings. More info here: http://support.apple.com/kb/TS3125

  • Blank page n 500 ITS error(sessionlocking)when clicking on workitem in UWL

    hi,
    We have recently upgraded our system from NW 7 SP 10 to NW 7 SP 15. After this , when a manger wants to approve a particular travel expense request or leave request, a blank screen opens and then after some time, we hit a 500 ITS error with Session-Locking. The iviews related to these workitems are all WD iviews.
    Our server is MY SQL. We have set the property idleStart in CBS, VA to false. We have checked for ABAP dump. There is no dump regarding this in the back-end.
    Can anyone please help.
    This is very urgent .
    regards,
    pinki

    hi gurus,
    Can anyone pelase help me out !!
    This is very urgent........
    regards,
    pinki

  • TS3682 i plug in my iphone 4 and i loss all contact... i try to backup restore but its error say not enough space.  please help me. i want only my contact backup restore not everything. so i dont know how can i do ?

    i plug in my iphone 4 and i loss all contact... i try to backup restore but its error say not enough space.  please help me. i want only my contact backup restore not everything. so i dont know how can i do ?

    Try to connect in recovery mode to restore, without using the latest backup, explained here:
    iOS: Unable to update or restore

  • Hi guys i have an ipad 2 4.3.5. i cannot downgrade to 4.3.3 nor upgrade it to 5.1.1 nor to ios 6. in the first 2 its error 3194 in ios 6 after some time it shows network error everytime. tried a lot. even used my friend's pc. wat shall i do????

    hi guys i have an ipad 2 4.3.5. i cannot downgrade to 4.3.3 nor upgrade it to 5.1.1 nor to ios 6. in the first 2 its error 3194 in ios 6 after some time it shows network error everytime. tried a lot. even used my friend's pc. wat shall i do????

    No. You can not. The only thing you can do is update to the durrent version. iOS 6. Shut off your antivirus and firewall software during the update process. It can interfere. If you are using Kaspersky, you may need to remove it entirely.

  • SSO to ITS via EP6

    Ok all knowing people, I have this working in EP5 but, can't get it working in EP6.
    Our Portal:
    EP6 SP2 Pack3 Hotfix7.  Working like a champ.  However, SSO to our ITS box will not work.
    I have downloaded and am using the SAP application integrator.  After creating the ITS System I make an Iview with com.sap.portal.appintergrator.sap with the generic component selection. 
    Url template is HTTPS://its.server.net/scripts/wgate/webgui/! ?<authentication>
    Template fraction for user mapping:
        login=<mappeduser>&password=<mappedpassword>
    After I run the Iview I get a runtime error.
    "Unable to process template https://its.server.net/scripts/wgate/webgui/! ?<authentication> because authentication is an invalid terminal property of the context."
    Am I going in the wrong direction?  Do you know of anyone that is running a webgui within an Iview with SSO?

    Hi,
    you have to create a "SAP Transaction iView" instead of using the app integrator.
    ==> right click on the desired folder in the PCD ==> choose "New" and "iView" ==> choose "SAP Transaction iView" ==> enter the ID info ==> choose the GUI type ("SAP Gui for HTML in your case) ==> select your SAP system and enter the desired transaction code ==> save
    Regards,
    Michael

  • SSO Login page Error : Unexpected errors (WWC-41400)

    Hi,
    I downloaded the zip file ssosdk.zip from download section of OTN for SSO and followed the steps in the Install document. All the process went through without any error. But when i tried to access my login URL, i am getting this error :Unexpected errors (WWC-41400)
    .Even if i try to login using my ORCLADMIN username and its password i am getting the same error and remains in the same page.
    while configuring the partner application i did not encounter any error. Kindly suggest me how to proceed further.
    Vijay

    This also happened to me after I run ssodatan to change the logon_url port.
    Can anyone provide some help with this?!

  • SSO To ITS not working

    Hi Experts,
    Here is the issue:
    I have 2 Internal Portals SP and EP.
    1.If I open SP Portal from Internet Explorer, SSO Tickets are getting generated and I am able to Login using SSO to SP - ITS machines.
    2.If I open EP Portal from Internet Explorer and In the same Browser If I open SP Portal,now I am unable to Login using SSO to SP - ITS Machines.It is showing logon screen.
    The Issue might be SSO Tickets generated by EP Portal do not subsequently allow SSO to SP ITS Machines.
    Could you please let me know where exactly goes wrong,and where should I make changes to rectify this issue.
    Any help would be highly appreciated.Thankx in advance.
    Regards,
    Karthick

    Hi Karthick,
    This blog might be interesting for troubleshooting.
    /people/dennis.kleymeonov/blog/2005/09/15/connecting-sap-systems-to-enterprise-portal-with-sso
    You might also get more information with the hints given in SAP note 495911.
    Thanks and regards,
    Dieter

  • SSO Login Page Error

    Can anyone solve this issue??
    We are developing ASP.Net application with oracle 10g Application server for single sign-on.
    we need to map the IIS URL(eg /private/*), redirecting to Oracle Application server,authenticate it and get the result back
    to IIS.
    As of Oracle Document we installed and configured proxy plugin and SSO plugin in IIS,and registered a partner application
    using ossoreg.jar command and it was successfully redirecting to the Single Sign-on login page
    but the problem is, after I click Login button it gives "page not found" error
    and the URL read as "http://<host.domain>:<port>//sso/auth"
    A normal login through SSO doesnt give any error...
    Do we need to change some config in policy.properties configuration file??
    Please reply, if anyone identified the problem.
    Regards
    Guhan

    Hi,
    I have triued the same thing here ... linking to a protected url on an IIS server. Initially I had similar problems. Check your plugin.conf file and make sure your login server file is defined correctly ... no " and use the Windows path conventions.
    Also, I thought I had directed the config file (osso.conf) to be in the directory i had created but it showed up in oracle_home/apache/apache/conf/osso. You may need to move it.

  • SSO between ITS and EP

    We are implementing ESS MSS on 4.7 , ITS 4.7 with EP 6.0
    Can some one point me as to how to configure the SSO between these various landscapes. I Think we would require SSO between EP and ITS for ESS in MSS services.
    regards
    Sam
    Message was edited by:
            sameer chilama

    Hi Sameer,
    All the information you are looking for is in the help.sap.com
    http://help.sap.com/saphelp_nw04/helpdata/en/89/6eb8e1af2f11d5993700508b6b8b11/frameset.htm
    This help guide is really very clear and thorough.
    Regards
    Daniel

  • SSO - integrated ITS - SRM 5(EBP)

    Hi all,
    I am just wondering if we need Java stack in order to set up Single sign on for SRM/EBP shopping cart (bbpstart).
    We are on SRM Server 5.5 with integrated ITS. We don't have Portal. We currently have SSO implemented on all Gui interfaces for all SAP systems via Active directory.
    What is the correct documentation for my case?
    Thanks a lot and looking forward to hearing from any good instruction,
    Kev

    Hi,
        If your password field is already pre filled with some value due to which you are unable to enter the password then you need to maintain the foll parameers in RZ10:
    The foll tasks need to carried out preferably by a BASIS person after which you need to restart the SRM server for changes to be effective:-
    1.Select the instance profile in RZ10 and  goto Extended maintainence.
    2.login/create_sso2_ticket  = 2
       login/accept_sso2_ticket   = 1
    Also check if the values for the SRM server are properly maintained in the table TWPURLSVR.
    HTH.
    BR,
    Disha.
    Pls reward points for useful answers.

  • SSO and ITS

    Hello,
    We are trying to setup SSO for SAP System. Our architecture looks like this:
    3rd party logon mechanism(via web) --> ITS --> Web Dispatcher --> WAS (BSP's)
    We did extensive research and found that ITS might enable us to do that. But we are not clear if SNC is a must (Which we don't want to do). The documenation is not clear. The current URL without SSO points to Web Dispatcher which get us the bsp pages from the WAS.
    Following is what we want to achieve:
    1. Users will logon to the 3rd party logon mechanism via web(software is installed with APACHE 2.0)
    2. once users are authenticated we need to pass the ID via HTTP header or any other method available to logon to SAP BSP Pages.
    Currently users can logon to 3rd party software which redirects to the BSP application and requests user id and password.
    We are wondering if anyone has done this sort of setup.
    Thanks,

    Hi
    For SSO concept visit (You can also find usage in EP)
    https://www.sdn.sap.com/irj/sdn/go/portal/prtroot/docs/library/uuid/90277dbd-0401-0010-33a1-ac2c7e3a5659
    <b>Usage across portal:</b>
    Normally Portal provides you a page which has content from different backend applications. Portal actually provides single point of entry to these applications which reside outside Portal. Now with Single SingOn feature user does not have to logon to backend application again. That means when he clicks a link on Portal which points to Backend application, he does not have to enter user and password again for that application.
    for more info
    sso
    Some fundas related to SSO with portal
    What is meant by "SSO across multiple domains"
    some usefull blog
    Step-By-Step Guide to implement Application Integrator
    Hope that helps

Maybe you are looking for

  • Help setting up Aiport Express with a non BT broadband service

    Just bought a MacBook with Airport Express and am having trouble connecting to the net. I've got a green light on my Express unit but when I try to configure it I can't see a Connect Using PPPoA setting which my ISP says I need, they claim the PPPoE

  • Video signal

    please my hp proliant server's monitor is displayin no video signal, what can i do?

  • How do I cancel a download (that is in progress) from the app store?

    I have a "Xcode for snow leopard" download that I obviously don't need anymore. I want it to be gone from the app store, but I don't want to download all the 4.9GB to my harddrive. How can I cancel it?

  • Export DataGrid to Excel. (Need Help @_@)

    Hi Guys..      im newbie flex developer, i just want to ask how im going to export may data to excel??

  • 6.0.1 Update

    I have downloaded the latest update for FCP (6.0.4) and installed it but I cannot seem to get FCP to recognize that it has been updated. When I launch, it is still showing the old version. Ideas?