User is not able to Login from external supplier, using the WSS (ICH)

Hi Gurus,
The user is not able to login to the server externally from url.
dev_icm is giving below warnings:
[Thr 11052] IcmWatchDogThread: watchdog started
[Thr 11309] ** WARNING => HttpPlugInInit: Parameter icm/HTTPS/trust_client_with_issuer or icm/HTTPS/trust_client_with_subject not set  => do
not trust any intermediary*
X.509 cert data will be removed from header [http_plg_mt. 720]
[Thr 11309] =================================================
[Thr 11309] = SSL Initialization  on  IBM RS/6000 with AIX
[Thr 11309] =   (700_REL,May  3 2008,mt,ascii-uc,SAP_UC/size_t/void* = 16/64/64)
[Thr 11309]   profile param "ssl/ssl_lib" = "/usr/sap/SCA/SYS/exe/run/libsapcrypto.o"
           resulting Filename = "/usr/sap/SCA/SYS/exe/run/libsapcrypto.o"
[Thr 11309] =   found SAPCRYPTOLIB  5.5.5C pl16  (Jun 10 2004) MT-safe
[Thr 11309] =   current UserID: "scaadm",  env-var USER="scaadm"
[Thr 11309] =   using SECUDIR=/usr/sap/SCA/DVEBMGS41/sec
[Thr 11309] =  secudessl_Create_SSL_CTX():  PSE "/usr/sap/SCA/DVEBMGS41/sec/SAPSSLA.pse" not found,
[Thr 11309] =      using PSE "/usr/sap/SCA/DVEBMGS41/sec/SAPSSLC.pse" as fallback
[Thr 11309] = Success -- SapCryptoLib SSL ready!
[Thr 11309] =================================================
HTTPS (SSL) settings are as below, i think which means that no ssl certifiacts are required.
icm/HTTPS/verify_client        = 0
Kindly help urgently.
regards,
MJ

this is SCM system.
SSL CA's are set.
what should be value of the parameters?
icm/HTTPS/trust_ client_with_ issuer or
icm/HTTPS/trust_ client_with_ subject
http and https ssl conections are correctly set.
I think the SAPSSLA. pse" not found, is not the problem as the parameter icm/HTTPS/verify_ client = 0 is set, it means that no ssl certifiacts are required.
problem is coming when the system is being accessed from externally using other secure domain name.
the system is being accessed ok from web urs which is internal, but not external.
for example in strust tcode  the domain name is *abc.com, which is running fine when accessing the system internally.
but when the user is accessing this sytem from other secure login from *xyz.com, which is also the same companys domain, then the user not able to login, its showing errir.

Similar Messages

  • I was charged no my credit card for the app store and i am not able to login, i tried to use the forget password options but it isnt going through

    i was charged no my credit card for the app store registeration and i am not able to login, i tried to use the forget password options but it isnt going through
    Apple id : [email protected]

    If the old ID is yours, and if your current ID was created by editing the details of this old ID (rather than being an entirely new ID), go to https://appleid.apple.com, click Manage my Apple ID and sign in with your current iCloud ID.  Click edit next to the primary email account, change it back to your old email address and save the change.  Then edit the name of the account to change it back to your old email address.  You can now use your current password to turn off Find My iDevice, even though it prompts you for the password for your old account ID. Then save any photo stream photos that you wish to keep to your camera roll.  When finished go to Settings>iCloud, tap Delete Account and choose Delete from My iDevice when prompted (your iCloud data will still be in iCloud).  Next, go back to https://appleid.apple.com and change your primary email address and iCloud ID name back to the way it was.  Now you can go to Settings>iCloud and sign in with your current iCloud ID and password.

  • After upgraded 9.2 DB, all users are not able to login (Except Guest).

    After completed the DB upgrade from 8.1.7.4 to 9.2.0, all users are not able to login the oraclemypage.home. This is except the Guest account.For example, I use the sysadmin account to login the oraclemypage.home. It shows "Your login is invalid. Please login again."
    Moreover, I do the following query.
    SQL> select fnd_web_sec.validate_login('SYSADMIN','SYSADMIN') from
    dual;
    FND_WEB_SEC.VALIDATE_LOGIN('SYSADMIN','SYSADMIN')
    N
    If I guery the Guest account, the result is "Y".
    Also, all users can access via dev60cgi/f60cgi to open E-business 11.5.7 application. Are there any missing script / process I need to do?
    Thanks,
    Matthew

    Hi Arun,
    What message u get on the apache logs / jserv logs when u get the error ?
    Since the log cumulate a giga byte, I clean up the log and test again. It seems no error message.Whats your platform?
    HP-UX 11.11To which version (5 digit) u upgraded DB ?
    Oracle9i Enterprise Edition Release 9.2.0.6.0 - 64bit Production
    I found a note 225074.1 that talks of a similar issue where users are ablt to login to forms but not php. this is for AIX. review the note.
    I had checked this previously. Part of this document already tried which suggested by Oracle Support.what is the end_date for all of these users in fnd_user table ? if all users for some reason is end_dated , then fnd_web_sec will show 'N"
    All users are normal. For those I tested without end_dated, I can access via f60cgi too.whats the session_cookie_domain set to in icx_parameters table? Set to NULL and try bouncing apache once.
    This set to ".mycompany.com". You mean that I set the session_cookie_domain to NULL and restart Apache, right? Why I need to set it NULL?

  • Webapplication users are not able to login

    Hi
    I am having windows 2012 domain controller. One web application running in this domain controller. Users in the domain all have access to web application. After giving the username and password it will allow the user to login to application. But the thing
    is some users are not able to login to application, at the same time same users able to login to systems with user id.
    Web application is integrated with AD for authentication. Removing the user not able to login, creating again, after that particular user able to login to that application.
    Please give me some suggestion...

    That might be due to the fact that these users have too many group membership. Read that: http://support.microsoft.com/kb/327825/en-us
    You can get more details in the Security logs of the server.
    Microsoft made some improvements here by introducing KDC Resource SID Compression: http://social.technet.microsoft.com/wiki/contents/articles/20886.kdc-resource-sid-compression.aspx
    This posting is provided "AS IS" with no warranties or guarantees , and confers no rights.
    Get Active Directory User Last Logon
    Create an Active Directory test domain similar to the production one
    Management of test accounts in an Active Directory production domain - Part I
    Management of test accounts in an Active Directory production domain - Part II
    Management of test accounts in an Active Directory production domain - Part III
    Reset Active Directory user password

  • I am not able to download from i tunes store the free games to my ipod, does anyone know

    i am not able to download from i tunes store the free games to my ipod, does anyone know

    mine does the same thing like I tried to download kik and when I went to select apps to sync in my ipod menu it showed up all grey

  • I am not able to login to i cloud using my apple id

    I am not able to login to i cloud using my apple id.

    That's too bad.  Try entering the correct login credentials.

  • Users are not able to login to BPM worklist application from one of the AD.

    Hi ,
    We are using FMW11g ( 11.1.1.6.0) and configured 2 AD's.( AD-1 & AD-2). We are able to see users from both AD's in the weblogic admin console. Users present in AD-1 are able to login to BPM worklist application without any issue but users from AD-2 are not able to login to BPM application. Could any one please answer 1) Can we configure 2 AD's to FMW11g ? 2) If "YES" , what configuration needs to change to users login from AD-2.
    Please let me know if any more information need.
    Regard's
    Naveen

    Hi
    NO. You CANNOT use more than One Security Provider for a BPM Workspace Application. Only the top most first Security Provider will work. In your case you have 2 ADs security providers and only users from top most can login. Yes, you can see the Users from both and infact all the Security Providers that are configured. It is the limitation of the bpm workspace application and its corresponding security framework.
    Out of box, if you use default AD Configuration then there is nothing you can do. Only the first top most will work. If you really really want you need to use totally custom authentication provider where you will write your own code for authentication. Remember this development is pure weblogic security related one and you need to have good understanding of internal weblogic security. I would not recommend this.
    Here is one old post. This old post has 2 other old posts worth visiting to get more details:
    Re: Use multiple ActiveDirectory as authenticator provider
    Re: oracle soa and active directory integration (Different requirement/usecase)
    Thanks
    Ravi Jegga

  • SIM user is not able to login with hand held device

    SIM user of particular store is not able to login with handhel device but able to login with terminal.
    Please tell me whether it is configuration issue or data issue.

    You can check whether password is expired or not. Is it same login details used for SIM GUI? If so, are you able to login to GUI.

  • Not able to login from microsoft account's generat...

    I had created a skype id using my hotmail account. The skype name automatically generated as live:***
    I am able to login to skype on any device when I signin using Microsoft account and enter details of my hotmail account.
    Problem: Why am I not able to login using the automatically generated skype name (live:***), on any device or browser. Whenever I try logging in using this skype name I get an error that please check your skype name and enter password and login again.
    Please help!

    Hi,
    I presume you have implemented the solution provided in the KBA 1204539
    Two things you might try:
    - Use the IP address as CMS name. If that works, then you have a problem with your resolution. You need to check your client DNS settings and suffix.
    - Make sure that there is communication between CMS server and client. If you use requestport parameter, you need to verify with your network admin that the range indicated is opened between server and client.
    - Use the requestport parameter for Input FRS as well
    You can check more details in the section "Working with Firewalls" (page 450) http://help.sap.com/businessobject/product_guides/boexir31SP3/en/xi31_sp3_bip_admin_en.pdf
    I presume that your LiveOffice is working because you are connecting to QaaWs and your connection to the Web Application server is fine. The problem are the other ports.
    Regards,
    Julian

  • Recently cerated Open Directory user accounts not able to login.

    Hello Everyone,
    I recently updated our companies Maverick server to version 3.2.1 and now some of my users are unable to login to our Open Directory server. Our server is currently running OS X 10.9.5 Build 13F34. The server log out put is the following when a user attempts to login to Open Directory.
    12/8/14 11:35:46.995 AM kdc[3049]: AS-REQ [email protected] from 192.168.15.95:59274 for krbtgt/[email protected]
    12/8/14 11:35:47.003 AM kdc[3049]: AS-REQ [email protected] from 192.168.15.95:59274 for krbtgt/[email protected]
    12/8/14 11:35:47.004 AM kdc[3049]: Need to use PA-ENC-TIMESTAMP/PA-PK-AS-REQ
    12/8/14 11:35:47.011 AM kdc[3049]: AS-REQ [email protected] from 192.168.15.95:50783 for krbtgt/[email protected]
    12/8/14 11:35:47.016 AM kdc[3049]: AS-REQ [email protected] from 192.168.15.95:50783 for krbtgt/[email protected]
    12/8/14 11:35:47.017 AM kdc[3049]: Client sent patypes: ENC-TS
    12/8/14 11:35:47.017 AM kdc[3049]: ENC-TS pre-authentication succeeded -- [email protected]
    12/8/14 11:35:47.019 AM kdc[3049]: Client supported enctypes: aes256-cts-hmac-sha1-96, aes128-cts-hmac-sha1-96, des3-cbc-sha1, arcfour-hmac-md5, using aes256-cts-hmac-sha1-96/aes256-cts-hmac-sha1-96
    12/8/14 11:35:47.019 AM kdc[3049]: Requested flags: forwardable
    12/8/14 11:35:47.282 AM kdc[3049]: TGS-REQ [email protected] from 192.168.15.95:50911 for host/[email protected] [canonicalize, forwardable]
    12/8/14 11:35:47.283 AM kdc[3049]: Searching referral for mbpe-0c4de9abba49.local
    12/8/14 11:35:47.284 AM kdc[3049]: Server not found in database: krbtgt/[email protected]: no such entry found in hdb
    12/8/14 11:35:47.285 AM kdc[3049]: Failed building TGS-REP to 192.168.15.95:50911
    12/8/14 11:35:47.289 AM kdc[3049]: TGS-REQ [email protected] from 192.168.15.95:64376 for krbtgt/[email protected] [forwardable]
    12/8/14 11:35:47.290 AM kdc[3049]: Server not found in database: krbtgt/[email protected]: no such entry found in hdb
    12/8/14 11:35:47.290 AM kdc[3049]: Failed building TGS-REP to 192.168.15.95:64376
    Note: I have rebuild Open Directory and still see the message above when users attempt to login. Also, I have not changed the name of the server, all server certificates are valid and for some reason time machine restores is not working. I have tried to restore the server back to June and it made the issue worse.
    Any help would be appreciated.

    Thank you for you reply Linc. Unfortunately I tried this already and it did not fix my issue. I checked the Open directory startup log and found a possible issue with the domain name in the startup file and the signing certificate. The domain name has a $ and it can find the signing certifiate with a public key. Please take a look below and let me know what you think?
    12/8/14 11:02:42.961 PM kdc[13708]: AS-REQ [email protected] from 127.0.0.1:63580 for krbtgt/[email protected]
    12/8/14 11:02:42.975 PM kdc[13708]: UNKNOWN -- [email protected]: no such entry found in hdb
    12/8/14 11:02:43.082 PM kdc[13708]: AS-REQ [email protected] from 127.0.0.1:52257 for krbtgt/[email protected]
    12/8/14 11:02:43.093 PM kdc[13708]: UNKNOWN -- [email protected]: no such entry found in hdb
    12/8/14 11:02:43.621 PM kdc[13708]: AS-REQ [email protected] from 127.0.0.1:64357 for krbtgt/[email protected]
    12/8/14 11:02:43.633 PM kdc[13708]: UNKNOWN -- [email protected]: no such entry found in hdb
    12/8/14 11:02:43.893 PM kdc[13708]: AS-REQ [email protected] from 127.0.0.1:64619 for krbtgt/[email protected]
    12/8/14 11:02:43.904 PM kdc[13708]: UNKNOWN -- [email protected]: no such entry found in hdb
    12/8/14 11:02:44.191 PM kdc[13708]: AS-REQ [email protected] from 127.0.0.1:61095 for krbtgt/[email protected]
    12/8/14 11:02:44.210 PM kdc[13708]: UNKNOWN -- [email protected]: no such entry found in hdb
    12/8/14 11:02:44.560 PM kdc[13708]: AS-REQ [email protected] from 127.0.0.1:52115 for krbtgt/[email protected]
    12/8/14 11:02:44.576 PM kdc[13708]: UNKNOWN -- [email protected]: no such entry found in hdb
    12/8/14 11:02:45.016 PM UserEventAgent[18]: Registered Workstation service - wdpmosx [68:5b:35:ca:f7:4b]._workstation._tcp.
    12/8/14 11:02:45.193 PM kdc[13708]: AS-REQ [email protected] from 127.0.0.1:54745 for krbtgt/[email protected]
    12/8/14 11:02:45.208 PM kdc[13708]: UNKNOWN -- [email protected]: no such entry found in hdb
    12/8/14 11:02:45.554 PM kdc[13723]: label: WDPMOSX.XYZ.ORG
    12/8/14 11:02:45.554 PM kdc[13723]: dbname: od:/LDAPv3/ldapi://%2Fvar%2Frun%2Fldapi
    12/8/14 11:02:45.554 PM kdc[13723]: mkey_file: /var/db/krb5kdc/m_key.WDPMOSX.XYZ.ORG
    12/8/14 11:02:45.555 PM kdc[13723]: acl_file: /var/db/krb5kdc/acl_file.WDPMOSX.XYZ.ORG
    12/8/14 11:02:45.568 PM kdc[13723]: PKINIT: failed to find a signing certifiate with a public key
    12/8/14 11:02:45.618 PM kdc[13723]: KDC started
    Thanks again.

  • Users are not able to login to portal

    Hi,
    In our NWDI server, none of the users able to login. I can able to login to Visual administrator and checked the user status which is unlocked.
    It is not showing any error messages even.
    Any suggestions?
    Regards,
    Kalainila B

    Have you renewed your portal certificate recently? We had an strange issue, once you putted the user and the correct answer it simply disappeared and the screen was showing the login screen ....
    The problem was that when we recreated the ticket in the visual admin we had made a mistake and the SAPLogonTicketpair was written with one capital letter in wrong place. The result: nobody can log in, even with the SAP* user.
    The solution was simple, regenerate the portal certificate with the correct name .....

  • Macbook Pro not able to burn from External DVD drive

    Hi there,
    I just bought a Samsung SE-208DB external drive for my 2011 Macbook Pro 8,1 13inch and at first the drive was detected by my Macbook Pro and I was able ot burn a disk but now when I plug in the device, it powers on for a bit then powers off to were I can't eject the disk anymore.Then sometimes it works just fine. I am using an external USB hub with AC plug power so I am confident power to the USb isn't an issue. I just wanted to know are Macbook Pro known to have issues with external drives?
    And for those wondering why I don't just use the internal DVD on my Macbook Pro, I replaced it with an SSD for dedicated Windows 7 operating system.
    Any ideas on how to approached this problem? Should I just get another brand of external DVD drive. I know I can't get Apples as for some strange reason, Apple makes those only compatible with Macs that didn't come with DVD drives like the Macbook Air.
    Thanks

    Ok I solved it.
    The problem is that the drive uses too much power from the usb port.
    You can use one of those cables with on one end two usb plugs and on the other end a mini usb. Connect the coresponding usb for power to an iphone charger or any 5v/1amp charger.
    Or you can do what I did. I used a usb hub. In one usb port I connected my iphone charger and the drive to another usb port on the hub.
    I have just burned my first succesful disc.
    Regards

  • Users are not able to login

    HI,
    I m able to login as root and it is working fine but if i login through a normal user ,it is logging and after sometime (few seconds) displays the desktop screen and comes back to the login screen.
    I have created a new user and tried to login the same probelm exist.
    Please help me out to solve this issue.
    Thanks & Regards
    M.sundaramoorthy
    9880590534

    It's queer, how about trying these ways:
    1. Restart the CDE daemon: /etc/init.d/dtlogin stop then start;
    2. Check if there's any enviroment different between root & other users??

  • I am not able to login to my applet as the login dialog does not take the focu

    In the login dialog of the applet it does allow the user to enter the password in to the field. Password field does not takes the focus. I tried with JTextfield and it is also having the same problem.
    == This happened ==
    Every time Firefox opened
    == When in installed 3.5.9 version. It is ok with 3.0 version

    Can you use the Tab key?
    See also [[Pressing Tab key does not select menus or buttons]]
    http://kb.mozillazine.org/accessibility.tabfocus

  • Users are not able to subscribe to RSS feed using Outlook express

    Hi,
    I have implemented RSS in one of my project .
    My project is an intranet site.
    In my project i use the rss.cfm for subscribing to the
    content.
    users are able to subscribe using IE7 & firefox but when
    users try to subscribe using Outlook 2007 or outlook 2003 . they
    are not able to subscribe.
    is there any way so that users can subscribe by their outlook
    as well ??
    Thanks & Regards,
    Prashant Gupta

    Hi rollerskatie,
    i tried the www.feedvalidator.org however it return the
    status "server returned timeout." .
    while i am able to subscribe to feed using the IE &
    firefox.
    my project site is an
    Intranet site.
    I am not able to understand this behaviour , why i am able to
    subscribe using the IE and firefox and not able to subscribe using
    the outlook.
    Thanks
    Prashant Gupta

Maybe you are looking for