Sync User with Shared Services

I noticed that if I provision a user in shared services the user can not log into planning until I restart planning. Is there a way to do this without restarting planning? This also seems to happen with EPM.
I know this happens with essbase but you can put a few commands in the essbase.cfg file and it can either sync on a time basis or when a user logs into the system.

I am not sure what version you are using, but I will assume 9.3.1
If so you shouldn't need to restart the planning server, once you have set them up in HSS the user should be able to log into planning, once the newly created user logs into planning the user is also created on the essbase (EAS) side as a planning user.
If you set up a new user and then log into the planning app as an admin user, select a form and click assign access, then click add access, can you see the user in the list ?
Cheers

Similar Messages

  • Essbase security sync issue with Shared Services v 11.1.2.2

    Hi,
    We are using Essbase version 11.1.2 (ESB11.1.2.2.102B025) and shared services version 11.1.2.2.300.6001 (Drop 6)
    Foundation Services is on a cluster evironment, windows 2008 64 bit.
    Essbase is on Unix Sun Solaris.
    We encounter an issue in which each time a new user is added to a group.
    The user will not have immediate access to Essbas. Currently the only time the
    user will have access is when we restart essbase.
    Is there a way to sync users from Shared Services without restarting Essbase?
    Anyone has experience on this problem and may know what and where to look?
    This is the error the user get, even though the group has access to essbase cube and the user
    has been added to the group.
    [Thu Jun 27 16:22:18 2013]Local/ESSBASE0///79/Error(1055126)
    This user has no application access set. Please contact your system administrator
    [Thu Jun 27 16:22:18 2013]Local/ESSBASE0///79/Error(1054067)
    Internal error
    [Thu Jun 27 16:22:18 2013]Local/ESSBASE0///79/Error(1051293)
    Login fails due to invalid login credentials
    [Thu Jun 27 16:22:18 2013]Local/ESSBASE0///79/Warning(1051003)
    Error 1051293 processing request [Login] - disconnecting
    There is no issue if we provision the user directly to the cube, e.g. without using group.
    Please advise. Thanks.

    You shouldn't have to restart Essbase as it should automatically sync, there may be additional information in SharedServices_Security_Client.log though it is probably worth logging with Oracle.
    Cheers
    John
    http://john-goodwin.blogspot.com/

  • Performance Scorecard - unable to sync security with Shared Services

    Hi all,
    after successful installation of HPS we have provisioned users in Shared Services console for using HPS application. Now we need to sync HPS application with HSS. We have logged as "admin" to run this sync but we are missing Administration menu.
    Could anyone give us an advice how to fix it?
    Thanks,
    Vladino

    Hi Amith,
    Before configuring EAS with Shared Services, please verify following:-
    1- Installaed relational database repository (SQL Server, Oracle, DB2).
    2- Create a database called hypdb in database repository.
    3- Create user called hypuser with valide password who has access on this database.
    4- Also ensure service related to database repository is running.
    Now try to configure EAS with SS. Hope it will help you.
    Atul K,

  • Regarding issue with externalizing users to shared services

    Hello,
    I was working today on externalizing users to shared services through EAS Console & it went successful. But then I saw that the users were already externalized & there was already an application group existing in shared services. So now there are two application groups both clone of each other, i.e. if I provision any user with one application, the clone of that application is also provisioned through that user.
    The bigger problem is somehow the connect bet'n both SS & Essbase Services is lost & the users created in SS are not getting reflected in EAS, even after refreshing the securities on EAS... & then I tried to restart all the services again open LDAP, SS, IS, Essbase & Admin Services.... I am getting error while opening Essbase services, they are not getting started??? Please help me resolve this error...
    Thanks.

    Hi,
    What version are you installing and what O/S is it for ?
    If it is windows it is definitely an executable you are running and you are not trying execute one of the patches?
    Cheers
    John
    http://john-goodwin.blogspot.com/

  • Unable to Externalize users to Shared Services

    Hi All,
    I am facing the following issue
    [Sun Jul  6 11:28:17 2008]Local/ESSBASE0///Error(1051429)
    Analytical Services Product Existence Check Fails against the Shared Services Server with Error [Unable to Authenticate.]
    Fatal Error: CSS Initialization Fails
    I have also done the following steps but could not resolve..
    STEP 1:
    a. Shutdown all the Services
    b. Take the backup of the file "Essbase.bak" by copying to another folder.
    c. From Native Folder(ARBORPATH),Rename the "Essbase.bak" file to "Essbase.sec" file.
    d. Reboot the machine where Essbase server is running.
    e. Start the Services and work on the application.
    If the issue still persists then Proceed with STEP 2
    STEP 2:
    Unregister the Analytic Services with Shared Services and then try reconfiguring Analytic Services from Configuration Utility (Especially register with Shared Services) and try working with the application
    If you have any information about how to resolve the above issue, please help.. Thanks.
    Message was edited by:
    637223

    Issue:
    Error 1051429 - Unable to Externalize the Users to HSS.
    Error Log:
    [Sun Jul 6 11:28:17 2008]Local/ESSBASE0///Error (1051429)
    Analytical Services Product Existence Check Fails against the Shared Services Server with Error [Unable to Authenticate.]
    Fatal Error: CSS Initialization Fails
    Environment:
    Win Environment installed – Weblogic 9.1 / HSS / AAS / BI+/ Planning
    Linux Environment Installed – Oracle DB 10 GR2
    Linux Environment Installed – Essbase
    Observation / Research:
    Duplicate entries in Essbase.cfg file.
    ; The following entry specifies the full path to JVM.DLL
    JvmModuleLocation /hyperion/common/JRE/Sun/1.5.0/lib/i386/server/libjvm.so
    ; SharedServicesLocation fatapp2.advtek.com.tw 58080
    ; AuthenticationModule CSS http://fatapp2.advtek.com.tw:58080/interop/framework/getCSSConfigFile
    ; SharedServicesLocation fatapp2.advtek.com.tw 58080
    ; AuthenticationModule CSS http://fatapp2.advtek.com.tw:58080/interop/framework/getCSSConfigFile
    ; SharedServicesLocation fatapp2.advtek.com.tw 58080
    ; AuthenticationModule CSS http://fatapp2.advtek.com.tw:58080/interop/framework/getCSSConfigFile
    SharedServicesLocation fatapp2.advtek.com.tw 58080
    AuthenticationModule CSS http://fatapp2.advtek.com.tw:58080/interop/framework/getCSSConfigFile
    Solution:
    ** Altered the settings of the Essbase.cfg file as below
    ; The following entry specifies the full path to JVM.DLL
    JvmModuleLocation /hyperion/common/JRE/Sun/1.5.0/lib/i386/server/libjvm.so
    SharedServicesLocation fatapp2.advtek.com.tw 58080
    AuthenticationModule CSS http://fatapp2.advtek.com.tw:58080/interop/framework/getCSSConfigFile
    ** Restarted all the Hyperion Services
    ** Logged into HSS, sync the OpenLDAP .
    ** Logged into AAS Console and Externalized all the users in Essbase to HSS
    ** Able to Externalize the users successfully.
    ** Created a sample application and a database and suggested the Customer to work out with the Applications.
    Hope that it works for you :)

  • Corporate User Accounts - Shared Services - Planning

    Hello,
    I have a question related to corporate user accounts.
    Suppose there is a corporate ID that was given access to planning, had the required provisioning in shared services and had the dimensional level security applied. Now this user no more works for the organization and so the corporate ID is no more active.
    What will happen in shared services and planning. Will it still have a record of that account and we will need to manually clear it everytime situation like this is encountered or since it is a corporate ID shared servicies and planning know for itself that this ID is no more active and valid.
    I would appreciate if someone could clear this doubt.
    Thanks in advance.
    ~ Adella
    Edited by: Adella on Sep 22, 2011 10:43 AM

    In theory if the ad account is no more then the provisioning is removed, now in the past there has been problems where if you don't deprovision a user first before they get deleted from the ad then the user still exists in certain tables and becomes stale.
    Sometimes utilities like provsionusers and updateusers would sync up to shared services and remove any stale users, sometimes they had to be manually removed.
    I have not actually tested or seen what happens with the latest version to see if it actually manages to clean up all stale users without any issues.
    Cheers
    John
    http://john-goodwin.blogspot.com/

  • Register with shared services - failed

    I am trying to install EPM 11.1.1.2 and I get this error for the point "register with shared services" for every item except Essbase.
    Shared Services is running, I can connect to the Web App on localhost:28080/interop and manage users and groups but it seems that registering things with it just does not go through.
    any ideas? has someone had the same problem and solved it?
    thank you in advance for your support.
    Micha Roon

    Hi,
    Glad to hear you think the installation was a piece of cake!!
    I think you may get this error when configuring a product selecting "perform first time configuration".
    Are you using a single repository for all your products?
    Could you maybe recreate new databases, including shared services and try again?
    Seb
    www.capiotech.com

  • Grant the Essbase application permission to user in Shared Services

    Hi,
    We got a problem in granting the Essbase permission to user using Shared Services. We are using Hyperion 9.3.1.
    (1) We created an Essbase application + database through Essbase Administration Console, say TBC.Sales.
    (2) Provision the Essbase "Server Access" + Essbase Application "Read" roles to a user.
    (3) In Essbase Admin Console, we "Refresh Security from Shared Services".
    However, the user still cannot see the Essbase Database in SmartView. Does anyone know how to fix the problem?

    The problem is fixed with Essbase 9.3.1.3.0.5.

  • Unable to register Hyperion Reporting and Analysis with Shared Services

    Hello everybody,
    I'm trying to install and configure Foundation Services in order to schedule Brio Query documents execution and distribution.
    IBM DB2 Express has been installed and configured.
    Shared Services have been installed and configured.
    Reporting and Analysis - System 9 Services have been installed and not yet configured.
    Reporting and Analysis - System 9 UI Services have been installed and not yet configured.
    When proceeding with Hyperion Reporting and Analysis configuration in registering with Shared Services, provided with the same host, port, user profile and password used for configuring Shared Services, I get the following message:
    "An unknown CSS error occured.
    Please check that the information entered is correct."
    Messages from configtool.log file:
    "(Aug 21, 2008, 09:32:32 AM), com.hyperion.cis.config.CmsRegistrationUtil, DEBUG, Getting CSS instance
    (Aug 21, 2008, 09:32:32 AM), com.hyperion.cis.config.CmsRegistrationUtil, DEBUG, URL for CSS.xml = https://itblq001.wincor-nixdorf.com:58080/interop/framework/getCSSConfigFile
    (Aug 21, 2008, 09:32:32 AM), com.hyperion.cis.config.CmsRegistrationUtil, DEBUG, Authenticate LStoppa user to CSS.
    (Aug 21, 2008, 09:32:32 AM), com.hyperion.cis.config.CmsRegistrationUtil, ERROR, Failed to authenticate user = LStoppa"
    I can't understand what's happening. May you help me?
    Thank you for every hints.
    Regards
    Lucia

    The service runs until I try to confirm the registration while configuring HRA. Then it stops.
    Apologies for the simple question, as I am trying to make the whole Hyperion System 9 running with little knowledge of it: how do I log to shared services?
    Thanks

  • Issue with shared services - Need Urgent Help please!!

    Hello Experts
    One of my customer has installed a new instance of oracle and copied all the schemas and data over to the new instance.
    Now when they bring up shared services, have lost all our provisioning. None of the projects are recognized by shared serices and gets the following error when we try to bring up a user
    'xxxxx' is not a recognized Shared Services project. Please contact your adminstrator
    Is there something we need to do to restore Shared Services to its original state?
    Thanks in advance.
    Regards,
    Sonu
    Edited by: 637223 on Jan 20, 2009 2:19 AM

    hi,
    I doubt that "creating a new instance of oracle and copied all the schemas and data over to the new instance" will register the project with shared service and thats why giving error. Because when you install shared service, it asks you about the database name (oracle in your case) to register with. So even if you overwrite that database by new instance it gives error.
    Have you tried the configuration utilty ? Over there you can provide the new database instanse as your database and configure your shared service. Remember that you need to do a complete configuration of shared service , analytic administration services and analytic services. After configuring, Restart the system.....it should work.
    Hope this helps!
    Regards,
    James

  • Essbase not registering with Shared Services in 11.1.2.1

    During configuration Essbase is is failing on Register with Shared Services. The configuration was pretty straight forward and all defaults. I ran the diagnostic tool and it came back with connection refused. Essbase is the first (other than Shared Services connection) that I have attempted to configure on this box
    We are running an all Windows environment with four separate servers. Shared Services is running on a separate box, connection to the SQL server is working, passwords are correct, username is correct, database is correct, there are no firewalls in place and I can get to Shared Services and workspace, services are running...
    Any ideas?

    This is what is in the log:
    [2011-06-08T07:52:39.239-04:00] [EPMCFG] [ERROR] [EPMCFG-01020] [oracle.EPMCFG] [tid: 19] [ecid: 0000J1j69ueFS8A_n_G7yZ1Dvq96000003,0] [SRC_CLASS: com.hyperion.config.wizard.impl.RunAllTasks] Error: [[
    EPMCSS-00301: Failed to authenticate user. Invalid credentials. Enter valid credentials.
         at com.hyperion.css.facade.impl.CSSAbstractAuthenticator$CSSTokenUtils.getTokenString(CSSAbstractAuthenticator.java:956)
         at com.hyperion.css.facade.impl.CSSAbstractAuthenticator.addToken(CSSAbstractAuthenticator.java:397)
         at com.hyperion.css.facade.impl.CSSAbstractAuthenticator.authenticateTrustedUser(CSSAbstractAuthenticator.java:497)
         at com.hyperion.css.facade.impl.CSSAbstractAuthenticator.authenticateProxyUser(CSSAbstractAuthenticator.java:332)
         at com.hyperion.css.facade.impl.CSSAPIImpl.authenticateProxyUser(CSSAPIImpl.java:186)
         at com.hyperion.css.facade.CSSAPIFacade.authenticateProxyUser(CSSAPIFacade.java:146)
         at com.hyperion.cis.config.CmsRegistrationUtil.<init>(CmsRegistrationUtil.java:107)
         at com.hyperion.config.wizard.impl.RunAllTasks.executeHubRegistrationTask(RunAllTasks.java:656)
         at com.hyperion.config.wizard.impl.RunAllTasks.execute(RunAllTasks.java:515)
         at com.hyperion.config.wizard.impl.RunnAllTasksState.run(RunnAllTasksState.java:90)
         at java.lang.Thread.run(Thread.java:619)
    Nested Exception:
    EPMCSS-00301: Failed to authenticate user. Invalid credentials. Enter valid credentials.
         at com.hyperion.css.common.internal.CipherUtil.encrypt2(CipherUtil.java:318)
         at com.hyperion.css.common.internal.CipherUtil.encryptToken(CipherUtil.java:165)
         at com.hyperion.css.facade.impl.CSSTokenHelper.getToken(CSSTokenHelper.java:169)
         at com.hyperion.css.facade.impl.CSSAbstractAuthenticator$CSSTokenUtils.getTokenString(CSSAbstractAuthenticator.java:954)
         at com.hyperion.css.facade.impl.CSSAbstractAuthenticator.addToken(CSSAbstractAuthenticator.java:397)
         at com.hyperion.css.facade.impl.CSSAbstractAuthenticator.authenticateTrustedUser(CSSAbstractAuthenticator.java:497)
         at com.hyperion.css.facade.impl.CSSAbstractAuthenticator.authenticateProxyUser(CSSAbstractAuthenticator.java:332)
         at com.hyperion.css.facade.impl.CSSAPIImpl.authenticateProxyUser(CSSAPIImpl.java:186)
         at com.hyperion.css.facade.CSSAPIFacade.authenticateProxyUser(CSSAPIFacade.java:146)
         at com.hyperion.cis.config.CmsRegistrationUtil.<init>(CmsRegistrationUtil.java:107)
         at com.hyperion.config.wizard.impl.RunAllTasks.executeHubRegistrationTask(RunAllTasks.java:656)
         at com.hyperion.config.wizard.impl.RunAllTasks.execute(RunAllTasks.java:515)
         at com.hyperion.config.wizard.impl.RunnAllTasksState.run(RunnAllTasksState.java:90)
         at java.lang.Thread.run(Thread.java:619)
    I do not have external user directories defined in Shared Services yet.... I cant even get into Shared Services because a "Failed to authenticate user. Invalid credentials." message. I checked my credentials and they cant be wrong cause I copied and pasted them.

  • Urgent: Error in registering HFM with Shared Services while configuration.

    Hi,
    I am installing HFM 11.1.2 on a 64-bit Server 2008 platform with my Foundation Services server is on different
    Machine. I have installed installed HFM client, Web Application and Services on both the server.
    But i have configured "Deploy to Application Server" on Foundation Server to have a single domain.
    All other configurations are done on the HFM Server only.
    But during to Deployment to application server my "Register with shared services" part fails.
    My foundation services are running. Do i require to Configure DCOM on foundation server also.
    Please suggest me some ways to solve this problem.
    Regards,
    Arvind

    Johan,
    you are right, now the user are given with dba priv ,
    now i am getting the below error,
    (Nov 11, 2008, 05:30:03 AM), com.hyperion.cis.config.wizard.RunAllTasksWizardAction, ERROR, Error:
    com.hyperion.cis.config.ProcessingException
    at com.hyperion.ess.EASDBConfigurator.configure(EASDBConfigurator.java:252)
    at com.hyperion.cis.config.wizard.RunAllTasksWizardAction.executeDBConfigTask(RunAllTasksWizardAction.java:282)
    at com.hyperion.cis.config.wizard.RunAllTasksWizardAction.execute(RunAllTasksWizardAction.java:151)
    at com.installshield.wizard.RunnableWizardBeanContext.run(Unknown Source)
    Please let me know your suggestions.
    Thanks,
    bhavani

  • Users in Shared Services

    Can someone tell me if there is a SQL table somewhere that stores the listing of users in Shared Services?
    Where would that data be stored?

    so John, you say that there is no chance to retrieve those users from relational-tables before v.11.1.2, right? is it possible in 11.1.2?
    actually i also need a scheduled report to see all users in HSS hence we're using same HSS with another project-team and both teams need such a kind of control report: "which users are able to see our project, who are in the other project... etc."
    i think, i should use CSSExport utility for creating such a scheduled report?
    do you have any suggestion?
    rgds,
    ozmo

  • MSAD Configuration with Shared Services

    Hi,
    I have just sucessfully configured MSAD to the HFM SS but 1 concern is that anyone with the domain suer login is able to login to shared service although limited function are available. Is there anyway to control other users except my users to login?
    I do not want to use Native to create user as it will means another set of password to rememberr for the users, would prefer they use their normal domain accoutn to login.
    Thanks

    In addition to other comments, users can only make changes in Shared Services if they have Shared services roles assigned. Also, we use MSAD with both local and AD groups, and as long as you know the effective rights, it works out fine either way. The Shared services roles are listed below (Security Administrator's Guide pp 135-136):
    Administrator: Provides control over all products that integrate with Shared Services. It enables more
    control over security than any other Hyperion product roles and should therefore be
    assigned sparingly. Administrators can perform all administrative tasks in User
    Management Console and can provision themselves.
    This role grants broad access to all applications registered with Shared Services. The
    Administrator role is, by default, assigned to the admin Native Directory user, which is
    the only user available after you deploy Shared Services.
    Directory Manager: Creates and manages users and groups within Native Directory.
    Do not assign to Directory Managers the Provisioning Manager role because combining
    these roles allows Directory Managers to provision themselves.
    The recommended practice is to grant one user the Directory Manager role and another
    user the Provisioning Manager role.
    LCM Manager: Runs the Artifact Life-Cycle Management utility to promote artifacts or data across product environments and operating systems
    Project Manager: Creates and manages projects within Shared Services
    Create Integrations: Creates Shared Services data integrations (the process of moving data between
    applications) using a wizard.
    For Oracle's Enterprise Performance Management Architect, creates and executes data
    synchronizations.
    Run Integrations: Views and runs Shared Services data integrations.
    For Performance Management Architect, executes data synchronizations.
    Dimension Editor ( includes Dimension Viewer and Interactive Editor):
    Creates and manages import profiles for dimension creation. Also, creates and manages
    dimensions manually within the Performance Management Architect user interface or the
    Classic Application Administration option.
    Required to access Classic Application Administration options for Financial Management
    and Planning using Web navigation.
    Dimension Viewer can read or view dimensions. This role automatically maps to the
    Dimension Reader access on dimensions.
    Interactive Editor can modify members within a dimension, and grants dimension writer
    access to all dimensions. Does not allow users to delete dimensions.
    Note: Dimension Viewer and Interactive Editor roles are reserved for future use.
    Application Creator (includes Analytic Services Application Creator, Financial Management Application Creator, Planning Application Creator,  External Application Creator): Creates and deploys Performance Management Architect applications. Users with this
    role can create applications, but can change only the dimensions to which they have
    access permissions.
    Required, in addition to the Dimension Editor role, for Financial Management and
    Planning users to be able to navigate to their product’s Classic Application Administration
    options.
    When a user with Application Creator role deploys an application from Performance
    Management Architect, that user automatically becomes the application administrator
    and provisioning manager for that application.
    The Application Creator can create all applications.
    The Analytic Services Application Creator can create Generic applications.
    The Financial Management Application Creator can create Consolidation applications
    and Performance Management Architect Generic applications. To create applications,
    the user must also be a member of the Application Creators group specified in Financial
    Management Configuration Utility.
    The Planning Application Creator can create Planning applications and Performance
    Management Architect Generic applications.
    The External Application Creator can create external views and export application views
    but cannot export the library.
    Note: External Application Creator role is reserved for future use.

  • Register with Shared Services Failing in 11.1.1.3

    Hi,
    We installed 11.1.1.3 in Linux operating system and the application server is Websphere 6.1.After Installation and Configuration of EPM products we Externalized users from EAS Console and configured Active Directory in Shared Services and now want to migrate users of Existing Production environment to new Environment.For that created a new testgroup in Shared Services under Native Directory and when I am refreshing it's displaying an error as shown below:
    Essbase failed to get roles list for [ESB:Analytic Server] from Shared Services Server with Error [32:1062:Failed to connect to the user directory [msadServer]
    Can anyone suggest on this.
    Any help is appreciated...

    This usually happens when the application exists in Essbase but does not exist in Shared Services.
    To resolve this you need to go into the AAS console, right click on the Sample application and select the 'REGISTER' option.
    This will register the application with Shared Services. You should then see the application listed in Shared Services under the Analytic Server project.
    You will need to make sure that the list of applications in the Analytic Server matches the list of applications under the project in Shared Services. If you have any other applications missing then please register those as well.
    HTH-
    Jasmine.

Maybe you are looking for