Sun Convergence - allow access with spaces as password

Hi,
We've discovered that Sun Convergence log in as any user when we write space sign without any other signs in password field. It's lok like ldap search (or bind) command fails if only spaces are in password field.
We use:
- Convergence with patch 12 and 10.
- Directory Server 5.2 (not recomennded, but on compatibile list)
We read some threards about similar problem with LDAP auth, but ... thera are not Sun Products. I suspect that problem are in LDAP (implementation Convergence requests).
We have temporary workaround, but ... it very bad. Any people have acces to any known user.
I woonder if some other have similar problem
regards
IT

Oracle does not comment on published reports of alleged Oracle product vulnerabilities. Please refer to Critical Patch Updates and Security Alerts (http://www.oracle.com/technology/deploy/security/alerts.htm) for more details on the policy.
Note: I still recommend you contact support for access to the latest Convergence patch (not yet available on SunSolve) which fixes known product vulnerabilities.

Similar Messages

  • Sun Convergence for user with disabled calendar service

    I have Communication Suite 7 installed with the "Sun Convergence" web interface.
    I create a test user with a disabled calendar service (service package platinum).
    The user test logged in in Sun Convergence web interface and I'm surprised,
    that the calendar for him is available.
    How can I disable the calendar view in Sun Convergence for user with disabled calendar service?
    Thank you.

    petrahu wrote:
    I'm getting the expected result with a service package for mail and calendar,
    e.g. mercury, and setting the status of calendar service to inactive or disabled.The behaviour you are seeing is both "expected" (i.e. as per the current Convergence design) and "unexpected" (i.e. doesn't make sense from a DA service provisioning perspective). It is a real "can-o-worms".
    The problem stems back to the "local.autoprovision" functionality provided at the Calendar Server end (enabled by default):
    http://docs.sun.com/app/docs/doc/819-4654/acajh?l=En&a=view
    "The first time a user logs in, the user's LDAP entry in updated to add calendar service, and a default calendar is created. The user entry must already exist in the LDAP directory. If it does not, an error is returned."
    So even if the calendar service has not been granted at the Delegated Administrator end, the calendar server will "helpfully" add the required objectclasses/attributes when a client (such as Convergence) attempts to login as that user.
    This means Convergence cannot automatically assume a user is not able to access the Calendar service based on the users current objectclass/attribute settings.
    This leads to an existing bug for Convergence:
    Bug#6871400 - "Mail only user is able to access the calendar service"
    I've also created a new Change Request for Calendar Server:
    RFE#6898717 - "local.autoprovision should be disabled by default"
    Please raise this issue with Sun support (log a support request) if you believe the current behaviour is confusing/needs changing (i.e. fix the bug/RFE above).
    Regards,
    Shane.

  • HT4061 iphone is disabled and won't allow access with itunes, i can't get it to open up so i can restore it.  Help please

    can someone please help me. my grandson accidently locked his iphone. i have try to reconnect it with itunes in order to restore it. But it won't do anything except have screen showing ipphone disable connect to itunes when i do itunes says please allow access to iphone. what do i need to do it when i try to open it shows emergencey calls only nothing else will open up. please help me reset his iphone please.

    You have to put the phone into recovery mode before you can restore it. First, turn the phone off. Second, while holding down the home button, connect the phone to the computer, and keep holding down the home button until you see the iTunes logo on the face of the phone (this is recovery mode). Next you should see a message on iTunes on your computer say something like "in order to use this phone you have to restore it from recovery mode.." This will allow you to access your phone! Hope this helps.

  • Apple tv 2 - root password has been changed to non default.   I need to access apple tv 2.   how do i get access with a forgotten password

    apple tv 2 - root password has been changed to non default.   I need to access apple tv 2.   how do i get access with a forgotten password

    Welcome to the Apple Community.
    It depends on which password you are referring to, but generally speaking you can always restore the Apple TV.

  • When I sync my Ipad and Mac I get a message from itunes to allow access with an email address I no longer use and asks for a password I don't know how do I remove the old email

    Whwn I sync my ipad I get a message from itunes to sign into my account but the email used is not my email and I don't have a password for the email it used - how do I get rid of the email address for itunes on the ipad - itunes on the Mac work just fine - but not on the ipad

    Hello Tonchee
    If you are seeing an Apple ID that is not yours, then you have purchased content on your iPad that is tied to that Apple ID. You would need to know that password or remove the content that is associated with that Apple ID.
    Using your Apple ID for Apple services
    http://support.apple.com/kb/ht4895
    Thanks for using Apple Support Communities.
    Regards,
    -Norm G.

  • IPTV 3.4 Allow access to content without password

    Well 3.4 has made up the problems with lack of security in 3.2 only to make it essentially that now enter a password while accessing the server.
    My problem is I want web pages using the plugin to access the sdp files from the download directory without requiring a password as in 3.2 while still maintaning security on the content server configuration. HELP ! What have other done ?
    There is nothing written about configuring apache on CCO
    Desperate for Help and Advice !
    Simon

    Duane - Did you ever get this resolved? If not the fix is to modify the cgi block in the httpd.conf file on the Apache server. This will allow you to restrict access to the server config files on the Content Manager but not require the users to know the admin username/password. Let me know if you need more assistance.
    Thank you,
    Danny

  • Publish RD Gateway and Web Access with One-Time Password (OTP) / Two-factor Authentication WITHOUT ISA/TMG server

    Hi everybody,
    I've been struggeling with this problem for a few weeks now and can't find a way to solve it.
    We have an RD farm (Server 2012) which consists of two Remote Desktop Servers with Connection Broker and Web Access.
    I've recently published a new server, containing RD Gateway and Web Access in our perimeter network.
    Now we've got restrictions that OTP/2FA must be used for the external deployment and we've decided to go for a solution from Gemalto.
    The "program" is called IDConfim and the server is called SA Server (Strong Authentication).
    Also it's important that NO ISA/TMG server is supposed to be used, the OTP/2FA is supposed to work seamless with the Web Access/Gateway.
    After hours discuss we came to a point were their NPS agent setup would be the only way to accomplish our goals.
    The setup is supposed to be like this:
    LAN:
    1 DC (2008 R2)
    RD Farm (2012)
    1 SA Server (2012)
    DMZ:
    RD Gateway/Web Access (2012)
    Were Gateway and Web Access should forward the authentications with NPS to the NPS agent on the SA server.
    When you print your AD account to authenticate you add the 6 digits of OTP which you recieve from you mobile app.
    Initially this seems to work, the Gateway forwards the request to the remote NPS server, BUT only if you write the correct AD password
    (without the OTP extension).
    If you write the correct AD password the authentication is forwarded to out SA Servern and it's beeing rejeced because the password doesn't
    contain the correct OTP extension.
    The problem comes here.
    When you write you AD password along with the OTP extension you get a Windows Security error in the eventlog (On thw Gateway server) like this:
    An account failed to log on.
    Subject:
    Security ID: NULL SID
    Account Name: -
    Account Domain: -
    Logon ID: 0x0
    Logon Type: 3
    Account For Which Logon Failed:
    Security ID: NULL SID
    Account Name: user
    Account Domain: domain
    Failure Information:
    Failure Reason: Unknown username or password.
    Status: 0xc000006d
    Sub Status: 0x0
    Process Information:
    Caller Process ID: 0x0
    Caller Process Name: -
    Network Information:
    Workstation Name: server
    Source Network Address: 192.168.x.x
    Source Port: 63003
    Detailed Authentication Information:
    Logon Process: NtLmSsp
    Authentication Package: NTLM
    Transited Services: -
    Package Name (NTLM only): -
    Key Length: 0
    This event is generated when a logon request fails. It is generated on the computer where access was attempted.
    The Subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.
    The Logon Type field indicates the kind of logon that was requested. The most common types are 2 (interactive) and 3 (network).
    The Process Information fields indicate which account and process on the system requested the logon.
    The Network Information fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.
    The authentication information fields provide detailed information about this specific logon request.
    - Transited services indicate which intermediate services have participated in this logon request.
    - Package name indicates which sub-protocol was used among the NTLM protocols.
    - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
    What i can see it's a NTLM error, but hey?! aren't we supposed to forward all authentication handeling to the remote NPS server?
    The problem is that no matter what i try the above problem stays there.
    Is it not possible to just forward ALL authentication handeling to a remote server?
    The only solution I've found to get it working someday in the future is this:
    "Remote Desktop Pluggable Authentication and Authorization", which is supposed to be introduced in 2012 R2.
    Also this link describes it:
    http://archive.msdn.microsoft.com/Release/ProjectReleases.aspx?ProjectName=rdsdev&ReleaseId=3745
    Please, bring me some answers before my head explodes! :)
    PS, long question = maybe some errors, ask me if something is unclear.

    Hi,
    Based on our experience, if the NTLM error occurs, please check the password.
    Regards,
    Mike
    Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.

  • With the 5s iphone will there be a protective case like otter box that will allow access with the fingerprint?

    I have a 2 year old and have to have a case on my phone.  just wondering if the finger print access will be functional with the protective case.

    You'll need to look on the support site of the manufacturer.

  • HT5306 I do not want to give remote access to anyone but myself as privacy is my friend.  Can this remote desktop software still be for me personally unless I allow access and for my MAC lap top only?  What if I do not update? compatibility issues with wh

    Hello:
    Thank you for the update for remote access for desktops.
    Personally, I do not want to give remote access to anyone but myself as privacy is my friend.  Can this remote desktop software still be for me personally unless I allow access and for my MAC lap top only?  What if I do not update? I do use this lap top in other countries.  compatibility issues with what?

    Apple Remote Desktop is off be default. It has to be enabled for some one to be able to remotely connect to the computer. And then, you still have to have a user name and password on the computer to remotely connect with.
    If you want to see if remote access has is enabled for Apple Remote Desktop; you can find the setting in, Apple Menu, System Prefrences, Sharing. If it's enabled, Remote Management or Screen Sharing will be checked.
    Beucase Apple Remote Desktop Agent is part of the Mac Operating System; even if your not using it, Apple Software Updates will from time to time offer updates for ARD Agent. Software Updates can some times be stacked ontop of each other; so chosing not to install an update, can mean other updates you may want may not be offered. At least until you install the updates those updates require. Also software updates can improve the security of your computer.

  • Every time I change password access control to allow access, it reverts after saving. How do I get the saved change to "take"?

    Outlook keeps asking me to either use the login keychain or to use confidential information connected with my email password. I went into the keychain passwords in KeyChain Access, changed the access control on each of them to allow Outlook access. I saved the changes, but then they all reverted to their previous setting.
    There is an older Keychain Access file in the Control Panel that will not open because it's either "damaged or corrupted". If I delete that, would it make a difference? What can I do to keep my access control changes when they won't stay saved?

    I do not have the disc to reload
    Why not?  You need your system dvds to troubleshoot & to reset/change passwords in view of your current OS listed in your  profile. 
    You can get replacement System Install & Restore CD/DVDs from Apple's Customer Support - in the US, (800) 767-2775 - for a nominal S&H fee. You'll need to have the model and/or serial number of your Mac available.
    If you're not in the US, you may need to go through the regional Apple Store that serves your location to find the contact number. Here's a list of links to all of those - http://store.apple.com/Catalog/US/Images/intlstoreroutingpage.html Another resource:  International Support Phone #s.
    ===============
    I have to have the password, which I cannot remember or find.
    When selecting passwords, make sure it's one that you will NEVER forget AND no one else can figure out. 
    Old school--- > Print it out & keep in a safe place.  A place that ONLY you know about AND never forget.
    New school---> Get a password manager utility.  Highly recommend 1Password which is shareware.  Do a Google search for free password managers.

  • Prime Infrastructure SSH password with space

    Hi,
    We have Prime Infrastructure 1.2 installed and now starting to populate the inventory with the devices list.
    However, it seems like the system does not accept password with space character inside.
    Anyone knows the fix / workaround to make this work?
    Thanks.
    Johannes

    Hi ,
    As Per my understanding there is No workaround ,you can try special characters ,however SPACES are Not allowed
    Thanks
    Afroz

  • How do Sun Convergence Communicate with LDAP?

    Please tell how do sun convergence communicate with LDAP server.what api do these calls use.and where do we can find it.
    Looked at the login page,it is was calling iwc.protocol.iwcp.LOGIN_URL variable.
    login_url was assign as below:
    iwc.protocol.iwcp.LOGIN_URL = iwc.config.session.contextPath + "/svc/iwcp/login.iwc";
    please let us know what is iwcp ?
    And what is contextPath its refering?
    Also please let us know what kind of frame work does convergence uses to communicate with LDAP.
    If possible,advice some documentation to read about this function.
    thanks in advance
    Edited by: testxtest on Jul 14, 2009 12:50 PM

    testxtest wrote:
    Please tell how do sun convergence communicate with LDAP server.Convergence uses the standard LDAP protocol to access data from the LDAP servers.
    what api do these calls use.and where do we can find it.The LDAP protocol technical specifications are defined here:
    http://tools.ietf.org/html/rfc4510
    Looked at the login page,it is was calling iwc.protocol.iwcp.LOGIN_URL variable.
    login_url was assign as below:
    iwc.protocol.iwcp.LOGIN_URL = iwc.config.session.contextPath + "/svc/iwcp/login.iwc";
    please let us know what is iwcp ?What is it you are trying to achieve?
    And what is contextPath its refering?The "contextPath" is the Convergence server URL base for the current session e.g. http://server.aus.sun.com/iwc
    Also please let us know what kind of frame work does convergence uses to communicate with LDAP.The Convergence server uses java ldap-pool libraries.
    If possible,advice some documentation to read about this function.Once again, what is it you are trying to achieve, and most importantly, why?
    Regards,
    Shane.

  • AirPort Utility allows changing Time Capsule disk password with a device password only

    Hello!
    I just noticed that changing disk password is allowed for anyone who has a Time Capsule device password. (AirPort Utility WIndows version)
    I find that illogical.
    Is it a kind of bug or it is intended to be this way?

    Well, lets say that you had friends or other family members that use the Time Capsule for wireless connections.
    And, you have files on the Time Capsule drive that you only want to share with one other person. If you use a disk password, only the person with the disk password will be able to see the files on the drive.
    If you don't set up a disk password, then anyone who is using the Time Capsule wireless will be able to see the files on the drive.
    So, if you want everyone to have access to the files on the drive, then use the device password.
    If you do not want everyone to have access to the files on the drive, then use a disk password

  • Firefox allows access to password protected site even when I have logged out?

    I have developed a website with password protected pages - but Firefox STILL allows access to the protected pages after I have logged out and even if I close and re-open Firefox?
    I have cleared the cache and checked 'Do not remember passwords' IE works OK??
    == This happened ==
    Every time Firefox opened
    == I uploaded and tested the site.

    Did you clear the cookies as well?
    You can also try to clear the "Active logins" : [[Clear Recent History]]

  • Bus Error when accessing A24 space on a VME device with VXI-VISA and VME-MXI-2

    I am trying to access A248 register space on a VME card, but I get a bus error using viIn8 and viOut8 with VXI-VISA on a VXI controller running Win2k across a VXI-MXI-2 <-> VME-MXI-2 link.
    I found the following entry on your site, but I do not if or how it applies to my situation:
    I Cannot Access A24 Space on a VME Bus with a VME-MXI and an AT-MXI-1 on a Windows NT System.
    Product Group: VXI Software
    Product Name: NI-VXI for AT-MXI for Windows NT
    Version/Revision: 1.0
    Problem: With a VME device, bus errors were received when trying to do a VXIin or VXIout to the address in A24 space. The device was successfully edited within the non-VXI device editor portion of VXIedit. Resma
    n acknowledges that the device has a base address of x0000 and has requested 4 MBytes of space in A24 space, but the bus errors were still received.
    Solution: Use VXIedit to insert x4700 into registers A, C, E and 10 of the the VME-MXI. This allows the entire range of VME address spaces (A16, A24 and A32) to be mapped to the MXI bus. You can then access A24 Space.
    Related Links:
    Fixed Version:
    Report Date: 08/01/96
    Last Updated: 07/19/2002
    Document ID: 0O076NGJ

    Hi bnemmers,
    Thank you for contacting National Instruments. First, let me address the KnowledgeBase that you referenced. That KnowledgeBase applies to the VXI-MXI, not the VXI-MXI-2. A similar solution may help, but I will explain that solution last.
    You said that you could not access A24 space on you instrument. Do you have problems accessing A24 space on this particular instrument or on all of your instruments? If you can not access A24 space at all, then there could be a problem with your MXI-2 controller or with its configuration.
    If it is a single instrument that is causing problems, then I suspect there is a problem either with that particular instrument or with the configuration of that particular instrument. If possible, I suggest you test another working instrument in this system. I also suggest you test this instrument in another system that you know is working.
    You mentioned that you are using a VME instrument. If this is the case, then I want to make sure that you have the VME instrument properly configured in Measurement and Automation Explorer. When you add a VME instrument using the "Create new VME Device" option in Measurement and Automation Explorer, you must make sure to add A24 space as a resource in order to communicate in A24 space. When you add this resource, make sure that you select an appropriate range.
    As I mentioned above, it is possible that the MXI-2 interface is not configured properly. It is possible that A24 access is not configured properly and that your device is never even seeing a request to read or write a register. There is a register on the MXI-2 that controls A24 access. This register is called VWR2, Extender A24 Window, and is located at 0xE of the MXI-2's A24/A32 address space. You can read this register using viIn16. If you are using A24 space, then bit 14 should be set to 1 to enable A24 address mapping. Bits 10-8 control the size of the A24 window that is mapped, and bits 7-0 control the base of the A24 window. To make sure that A24 space is enabled and mapped, try writing 0x7800 to this register using viOut16. Assuming that you have opened a VISA session to your VXI-MXI-2 or VME-MXI-2, you would use viOut16(visa session, A24, 0xE, 0x7800). Some of this is explained in the VME-MXI-2 User Manual available at http://digital.ni.com/manuals.nsf/webAdvsearch/68409BFF568BB6118625665F005A0A41?OpenDocument&vid=niwc&node=132100_US.
    I hope this helps. If you are still encountering problems, I suggest you call and talk to an Applications Engineer. Please generate a phone support request at http://www.ni.com/ask. When you do that, you will be given a Service Request Number and a phone number to call. When you call that phone number, you will be routed directly to an Applications Engineer.
    Regards,
    David Shatila
    Applications Engineer
    National Instruments

Maybe you are looking for

  • Using iTunes on external drive with new computer

    My mac died a few weeks ago but I had my iTunes library on an external drive. Trying to point my new mac at this same external drive so that I can get iTunes running again but can't seem to make it work. Is there any way around this without reimporti

  • Exchange server 2010 SP3 UR7 - poison queue

    Hi all, I have an issue, witch should have been resolved in previous URs (UR2) but somehow still present in our installation. we have Exchange 2010 Sp3 UR7 installed, but still transport service crashes when we receive messages with empty FROM and us

  • Existing customer wished to start a new contract

    Hi, After coming to the end of the my initial 18 month contract I looked online and saw lots of great deals that BT offer new customers (6 months free, free homehub, Sainsburys vouchers, etc).  So armed with this and also prices from Talk Talk I phon

  • Display of price, amount, percent is truncated

    Hallo, how to display the numeric(19,6)-fields with all regular digits? In an UDF (on system Form, e.g. SalesOrder-column U_MyPrice ) it looks like 600 600,1 600,12 instead of 600,00 600,10 600,12 for example. Can anybody help me? (PS: I don't want t

  • How does one get a response on DSL connectiveity in my area

    I have contact everyone I know to contact in an effort to get DSL installed in my area. My entire neighborhood has DSL through ATT except the newest phase. Corporate office tells me that Construction and engineering department handles the new connect