SSO with WIA not working yet...
Hi,
We are trying to deploy SSO in our PT 5.0.2 portal (running on Windows 2000), but have not been able to get it to work
successfully yet. Microsoft Active Directory 2000 is our user/group source.
The server architecture is as follows:
Server A = Serves as Admin Portal, Portal Server, and Image Server (resides in the DMZ)Server B = Serves as Automation Server (resides inside the firewall)Server C = Serves as Database Server (running SQL Server 2000; resides inside the firewall)Server D = Serves as the Application Server (portlets reside on this server; resides in the DMZ)
All servers reside in the SAME domain.
This is what we have done so far:
1. Installed prerequisite software (i.e. IIS 5.0 and .NET Framework 1.1.4322) on Server C. Successfully installed and
configured the Active Directory Authentication Web Service (i.e. PT Optional Enterprise Web Component) on Server C.
2. Imported the above Web component, ADAWS, into Server A, using the PT Migration Wizard. This automatically created a
"Remote Server" and 2 "Web Services" (namely Authentication Web Service and Profile Web Service) objects on Server A.
3. Created a "Authentication Source - Remote" on Server A. The value in the "Authentication Source Category: " field is
EXACTLY the same as the Active Directory Source Domain. Selected "Authentication and Synchronization" as the Synchronization
setting, and "Full Synchronization."
4. Created a Job and added the above Remote Auth Source as the operation. The JOb ran successfully and imported all users and
groups from Active Directory.
5. Users can successfully login to the portal using the above Remote Auth Source (User ID example: Domain\joe_user).
6. Enabled "Integrated Windows Authentication" ONLY on the "\portal\sso" folder in Internet Services Manager on Server A.
Ensured that the security is set to "Anonymous" on "\portal" and "\portal\bin" folders.
7. Enabled SSO in the Portal, by entering the SSO Secret key in the SSO tab in the PT Admin Applet on Server A.
8. Created a "Authentication Source - SSO" on Server A. Entered the same SSO Secret key entered above and successfully
validated it.
9. Configured SSO integration with Windows Integrated Authentication (WIA) by editing the PTconfig.xml file. The edits are as
follows:
<SSOVendor value="5"/><DefaultAuthSourcePrefix value=""/><CookieDomain value=".companyname.com" />
NOTE: I did not have to edit the "sso.xml" file since the Auth Source category is EXACTLY the same as the Active Directory
Source Domain.
10. Edited the "Authentication Source - Remote" that we created in step 3 above, and changed the setting to
"Synchronization." And then selected the "Authentication Source - SSO" (created in step 8 above) from the "Authentication
Partners: " drop down list.
11. Users can still successfully login to the portal using the Remote Authentication Source after the above change.
12. Server D hosts a remote portlet. It is an IFRAME portlet (written in ASP) that has "href" links to several apps that
reside on Server D. The security on the folder, that contains this portlet, in Internet Services Manager, is set to
"Integrated Windows Authentication." Created a "Remote Server" object for Server D on Server A. Then created a "Web Service -
Remote Portlet" object for the portlet. In the Web Service, I selected the Remote server that I created, and entered only the
remaining path to the portlet (i.e. Portlet URL setting), since PT provided the "http://serverD/" portion. Finally created a
"Portlet" object.
13. users login to the portal using their domain ID (i.e. Domain\joe_user). They are then able to add the portlet to their
page. But when they attempt to click on the links in the portlet they are challenged to enter their user name and password
again.
What step or setting are we missing here? Any help will be sincerely appreciated.
Best regards,Kiran
Hi Rajendrakumar,
You probably haven't updated the ACL properly via STRUSTSS02.
The portal server digitally signs logon tickets as it issues them to the portal users. SAP Systems need to accept the tickets and verify the portal servers digital signature. The following information is important for the SAP System to be able to accept and verify logon tickets:
· The SAP System should only accept logon tickets issued from their designated portal server. Therefore, the identity of the portal server needs to be entered in the SAP Systems Single Sign-On (SSO) access control list (ACL).
· The SAP System needs to be able to verify the portal servers digital signature. The portal server has a self-signed certificate, therefore the SAP System needs access to the portal servers public-key information, which needs to be entered in the SAP Systems certificate list.
Check the following procedure
http://help.sap.com/saphelp_nw70/helpdata/en/78/f1a8490e7011d6999500508b6b8a93/frameset.htm
Regards,
Siddhesh
Similar Messages
-
Hi Experts,
We have setup SSO in our production with OBIEE 11.1.1.6.2 BP1 version and Active directory. All seems to work fine on all browsers. But on MAC OS 10.6.8 when we use Safari 5.1.7 it doesn't work. But when we use the application on MAC OS version 10.7.5 and safari version 6.0.1 and it is working fine. Can anyone please let me know if you have come across the scenario and the solution for this. In windows it works perfectly fine on all browsers. Only this version of MAC and Safari is giving us the trouble.
Thanks in advance for any solution provided.
Regards,
SatyabratJavaScript and Cookies are enabled. my cookies list shows at least 3 associated with hulu. Funny thing is, if I grab the up/down control bar on right side of screen with my mouse, then hulu plays in a somewhat chopped frame by frame. As soon as I let go, the frame freezes yet audio portion continues.
I don't know what a munged Hulu cookie is, however. -
Hi
I am running Nw2004s Portal with ECC5 as BackEnd.
I have Configured the ECC5 for SSO using RZ10 and strustsso2.
The Portal UserIDs are same as those in ECC5 .
The SSO is working fine with ESS in the Portal.
But when i run a BSP iView then it asks for UID,PWD in a PopUp.
I am accessing the Portal with FQDN and in the properties of the System
referred by BSP also maintained FQDN of the backend WebAS.
How to get rid of this Login PopUp for BSP ?
Any Help will be highly appreciated !
Regards,
RajendraHi Rajendrakumar,
You probably haven't updated the ACL properly via STRUSTSS02.
The portal server digitally signs logon tickets as it issues them to the portal users. SAP Systems need to accept the tickets and verify the portal servers digital signature. The following information is important for the SAP System to be able to accept and verify logon tickets:
· The SAP System should only accept logon tickets issued from their designated portal server. Therefore, the identity of the portal server needs to be entered in the SAP Systems Single Sign-On (SSO) access control list (ACL).
· The SAP System needs to be able to verify the portal servers digital signature. The portal server has a self-signed certificate, therefore the SAP System needs access to the portal servers public-key information, which needs to be entered in the SAP Systems certificate list.
Check the following procedure
http://help.sap.com/saphelp_nw70/helpdata/en/78/f1a8490e7011d6999500508b6b8a93/frameset.htm
Regards,
Siddhesh -
We've set up SSL to use with 10g AS Portal (9.0.4). Actually, all we want is to have the SSO sign in securely.
So if I go to https://www.myserver.com:4446/pls/portal I get a portal page. However when I try to login it reverts back to non-SSL. Also, if I go to https://www.myserver.com:4445/pls/orasso the SSO server comes up, but doesnt let me login (no entries in the Enabler Config table) Do I have to run ssodatax? And how can I tell portal to use the SSO through SSL once I fix that?
Im using Oracle 10g AS (9.0.4) on Red Hat 3.0
ThanksHi Tim,
Thank you for the update.
Is this the option you are specifying (i,e) located in Tomcat/conf/server.xml.
Define a SSL Coyote HTTP/1.1 Connector on port 8443
<Connector port="8443"
maxThreads="150" minSpareThreads="25" maxSpareThreads="75"
enableLookups="false" disableUploadTimeout="true"
acceptCount="100" debug="0" scheme="https" secure="true"
clientAuth="false" sslProtocol="TLS" />
So, should we add any parameter called headersize?
Please let us know the parameter that needs to be added.
Thanks.. -
Axis bank net secure with webpin not working on ipad2
Hi,
Axis bank net secure with webpin not working on ipad2
Lt me know how to proceedTry using their App:
https://itunes.apple.com/in/app/axis-bank-mobile-application/id517266358?mt=8 -
Since installing Yosemite, Airplay with Freebox not working
Since installing Yosemite, Airplay with Freebox not working
With Maverick Airplay working wellIf you haven't done so already, try resetting the printing system.
OS X Mavericks: Reset the printing system also Yosemite
Try deleting the printer and scanner and add them back.
Also try Applications/Image Capture to see if it can find the printer and scanner. -
Bootstrap success but Synchronization not worked yet
bootstrap success but Synchronization not worked yet
this is i got in ActiveChgImp.trc
Trace Log Started at Wed Jul 19 12:59:34 EEST 2006
Initialized debug!!
Set retry Count!!
Set Scheduling Interval!!
Initialised src connector
Initialized Src Connector.
TAG FOUND:(INTERFACEDETAILS)
LINE,11:(Package: gsi)
key:(Package)
Value Continuation Not Present
Putting Key into Hash :PACKAGE
LINE,22:(Reader: ActiveChgReader)
key:(Reader)
Value Continuation Not Present
Putting Key into Hash :READER
LINE,31:(SkipErrorToSyncNextChange: false)
key:(SkipErrorToSyncNextChange)
Value Continuation Not Present
Putting Key into Hash :SKIPERRORTOSYNCNEXTCHANGE
LINE,19:(SearchDeltaSize: 500)
key:(SearchDeltaSize)
Value Continuation Not Present
Putting Key into Hash :SEARCHDELTASIZE
SkipErrorToSyncNextchange is set to: false
Search Delta Size set to: 500
Initialized Config Info.
Initialized Provisioning Related Details
Initialized Sync Mode.
Mapping init successful
Initialized Mapping Info.
Initialized Filter Info.
Initialized Execution Cmd.
Initialized Status Attrs.
LDAP URL : (tampro.Twa.com:389 [email protected]
Specifying binary attributes: mpegvideo objectguid objectsid guid usercertificate orclodipcondirlastappliedchgnum
LDAP Connection success
Applied ChangeNum : 1295771Available chg num = 700
Applied ChangeNum : 1295771Available chg num = 1295813
and then run the server but Synchronization not worked yethi,
I used ldapmodify to modify "SkipErrorToSyncNextChange=true",but show errors,following:
LDAP URL : (davidliu:11712 cn=Directory Manager
Specifying binary attributes: mpegvideo objectguid objectsid guid usercertificate orclodipcondirlastappliedchgnum
LDAP Connection success
testsunone:Error in Mapping EngineODIException: DIP_GEN_INITIALIZATION_EXCEPTION
ODIException: DIP_GEN_INITIALIZATION_EXCEPTION
at oracle.ldap.odip.util.DirUtils.getLastChgNum(DirUtils.java:48)
at oracle.ldap.odip.gsi.LDAPReader.initAvailableChgKey(LDAPReader.java:751)
at oracle.ldap.odip.gsi.LDAPReader.initialise(LDAPReader.java:235)
at oracle.ldap.odip.engine.AgentThread.mapInitialise(AgentThread.java:351)
at oracle.ldap.odip.engine.AgentThread.execMapping(AgentThread.java:277)
at oracle.ldap.odip.engine.AgentThread.run(AgentThread.java:165)
testsunone:about to Update exec status
Error in proxy connection : java.lang.NullPointerException
so,according to the Solution of way, I used ldapmodify to fix the following one entrie:
dn: orclODIPAgentName=testsunone,cn=subscriber profile, cn=changelog subscriber, cn=oracle internet directory
changetype: modify
replace: orclaci
orclaci: access to attr = (*) by group="cn=odisgroup,cn=odi,cn=oracle
internet directory" (read,write,search,compare)
orclaci: access to entry by group="cn=odisgroup,cn=odi,cn=oracle
internet directory" (browse,proxy)
but it's looks like not success,also show "DIP_GEN_INITIALIZATION_EXCEPTION" error.
why? anybody can help me,please! thank advance.
I used the oracle portal_wireless_101200 and the SunONE Directory Server 5.2.
Regards.
david -
Wifi connection with 4s not working after installing new software ios6
wifi connection with 4s not working after installing ios 6.
Go to Settings > WiFi > Select your network and hit the right arrow to "Forget Network"
Then go to Settings > General > Reset Network Settings and try connecting again when the phone restarts. -
For the last few weeks I have had constant problems with pages not working. I.E.: I cannot fill in writeable fields, click on buttons... or anything... nothing on the page works. And, this is not exclusive to a particular site. It does seem to be a browser issue, because I can work well in Explorer.
Both the Yahoo! Toolbar extension and the Babylon extension have been reported to cause an issue like that. Disable or uninstall those add-ons.
* https://support.mozilla.com/kb/Troubleshooting+extensions+and+themes -
Applications associated with workstations not working
Hello,
I have onld zen 7.x, on netware.
Applications associated with workstations not working or appearing in one container. Not sure if it every worked. Apps work fine with users.
I am in a bind, since I need to get the app out in the workstation space.
It maybe rights or simple install error with the ZEN from the begining.
thanks for any help or ideas.. Yes I know I need to get to Zen 11.
PhilPhilJannusch,
> Applications associated with workstations not working or appearing in
> one container. Not sure if it every worked. Apps work fine with users.
>
> I am in a bind, since I need to get the app out in the workstation
> space.
Please tell us more as "not working" can mean a lot of things. So:
Are they user or workstation associated?
Are those for whick they do not work (users or workstations) all in the
same container?
In what way do they not work?
Any errors?
Anders Gustafsson (NKP)
The Aaland Islands (N60 E20)
Have an idea for a product enhancement? Please visit:
http://www.novell.com/rms -
How do I fix issue with computer not authorized yet when I go to I-Tunes to authorized it indicated already authorized?
I updated to iOS 5.0.1 days ago and didn't receive that notification until just now...
This time I synced new photos I took yesterday, and it gave me the:
"iTunes Sync: 54 items could not be synced. See iTunes for more information"
Perhaps it kicks off when new items get synced.
I've decided to rent a movie yesterday. Once it gets deleted, I'm curious to see if it jumps to 55 items. -
I am getting frustrated with Apple not working with Flash Player on some of my favorite web sites! Is there another alternative to watching these site options on my I-pad?
Flash is not, and probably never will be, supported on the iPad : http://www.apple.com/hotnews/thoughts-on-flash/ . Plus it would be up to Adobe to make a version of their flash player that works on iOS devices - something which they have never managed to do and which they have now given up on trying to do.
Browser apps such as Skyfire, iSwifter and Puffin 'work' on some sites, but judging by their reviews not all sites. Also some websites, especially news sites, have their own apps in the App Store, so your could try checking there for your sites (and there is the built-in YouTube app). -
i tried for 4 day now to remove a podcast and it has not work yet.
I have tried clicked "remove podcast" on each of the DMLive podcast pages, explaining to them who I was and what my job title was here, but all I got in return was an e-mail that said "have the administrator contact us." As I explained above, there is no admin on this account anymore and whoever was the admin has long since moved on.
Jeremy,
For understandable reasons, just because there is "no admin on this account anymore" does not mean they will take instructions from someone else.
Make clear to Customer Service that you are now the officially responsible party on that account now. -
My original computer that I set up my iPhone 4 with
Does not work.....can I use a new computer to sync
The phone....how do I do this and is there a risk of
Of losing any apps, music etcTry this:
Syncing to a "New" Computer or replacing a "crashed" Hard Drive -
I really need to downgrade to the previos Firefox version just until a couple of add-ons have been upgraded. How easily can I do this without losing my current settings?
There is no guarantee that the add-ons that currently do not work with Firefox 4 will ever be updated, they may have been discontinued.
To downgrade to Firefox 3.6 first uninstall Firefox 4, but do not select the option to "Remove my Firefox personal data". If you select that option it will delete your bookmarks, passwords and other user data.
You can then install the latest version of Firefox 3.6 available from http://www.mozilla.com/en-US/firefox/all-older.html - it will automatically use your current bookmarks, passwords etc.
To avoid possible problems with downgrading, I recommend going to your profile folder and deleting the following files if they exist - extensions.cache, extensions.rdf, extensions.ini, extensions.sqlite and localstore.rdf. Deleting these files will force Firefox to rebuild the list of installed extensions, checking their compatibility, and reset toolbar customizations.
For details of how to find your profile folder see https://support.mozilla.com/kb/Profiles
Maybe you are looking for
-
Exchange Sync works for Mail, Calendar, Contacts - but not for Notes
Hi, I am using an iPhone 3G (16GB). The sync with my account on an Exchange Server (I think 2003) is working just great. Mail, Calendar, Contacts are all in snyc, but there seems to be no way of synchronising the Notes between the iPhone native app a
-
Dear Friends, i am getting error message while loading data in the cube, yesterday i got the same error message while loading ODS the error message is as follows: Value '差旅费 - ERIC BADEN - MEETING WITH E&Y & AYKIM ' (hex. '5DEE65C58D390020002D002
-
Adobe reader 8.1 has stopped working
All of a sudden I cannot open PDF files. Acrobat won't open. I get the message: error 1606. Could not access network location %APPDATA%\ I've tried uninstalling. It will not uninstall, just gives the same message Running Windows 7
-
Hi all, I'm sure this is a 'duh' question. I've been playing around with Netbeans and Forte4J before deciding on JDeveloper. I moved over some tags I had developed using Netbeans. Nothing fancy, just learning excercises mostly. However, there is one
-
Trying to install the last of three purchased Office MAC licenses for a new MacBook Pro. How do I retrieve info to download on to new computer. I can pull it up on my own MacBook but I already have it installed on this one. Thank you.