Using oc4j Jaas with external user-base

Hi,
Im evaluating the possibility of migrating my application from BEA Weblogic 7.00 to Oracle9iAS. I Use OC4j 9.0.3 for the migration proof.
My Weblogic application uses a LoginModule, written by us which access our existing user-base (stored in an rdbms).
We use proprietary Principal classes and update the Subject when a login 'transaction' is committed.
Our EJB code (which is the resource we want to protect) includes role definitions and the specific weblogic deployment-descriptors includes mapping between the roles defined in the ejb dd and the principal names we return with the login-module.
I have some questions:
1. How can i perform a similar mapping (propriatary principal names to ejb roles), do i have to declare all those principals in jazn.data?, where do I have to declare them?
2. Can i disregard the UserManager concept?
3. Do i have to implement a LoginContext on my own?
4. Do I need to explicitly call LoginCOntext.login in my login code or is it automatically done (please elaborate)?
5. Do i have to keep using RealmLoginManager along with my LoginModule?
6. Where is the preferable place for putting the login module (application’s ear file?)
7. Can i use any LoginModule which simply implements the JAAS LoginModule interface?, are there any specific oracle behavior/requirement i should know about?
8. What is the class name for the JAZN class which serves as the default LoginContext?
Note: I dont want to integrate with OID or manage the user-base using Oracles JAZN-XML, i want to simply integrate with my own existing user authentication data and use it for authorizing calls to EJBS.
Thanks in advanced,
Yuval.

sorry for delay in repsonding.
I only use my LDAP directory to manage poeple and groups but not organisational units.
When a user logs in using BPM, you view the details for a person in process administrator or view a groups members etc that information is then stored in the bpm database. That information is refreshed whenever the directory service is polled. The frequency of this is determined by the value of 'Directory Polling Interval' set under the Other tab of your engine.
I don't belive the user passwords etc are stored in the bpm database only meta information about people and groups and therefore your directory service must be available whenever a user tries to login to workspace etc.
Hope that helps,
Mike.

Similar Messages

  • Using a workflow to share documents with external users

    I'm trying to create a workflow that will share documents with external users. Those external users don't have SharePoint logons.
    One approach might be to send an email using a 2010 workflow. However there doesn't appear to be the ability to attach a document to that email.
    The other approach could be to use the Share function of SharePoint 2013 but can this be triggered using a workflow? If so how?
    Please note: I'm using SharePoint Online
    Thanks in Advance,
    Mark E.
    Learning SharePoint

    Hi Mark,
    You can use external sharing option in SharePoint Online. Below links might help:
    https://support.office.com/en-gb/article/Manage-external-sharing-for-your-SharePoint-online-environment-c8a462eb-0723-4b0b-8d0a-70feafe4be85
    https://support.office.com/en-in/article/Manage-sharing-with-external-users-in-Office-365-Small-Business-2951a85f-c970-4375-aa4f-6b0d7035fe35?ui=en-US&rs=en-IN&ad=IN
    http://www.adrit.de/Blog/Post/25/External-sharing-with-Office-365---Part-2--How-to-share-SharePoint-content-with-external-users-
    Best Regards,
    Brij K
    http://bloggerbrij.blogspot.co.uk/

  • Using windows vista with two users and I can only open books with adobe digital editions on one account?

    using windows vista with two users and I can only open books with adobe digital edition

    You must authorize the second computer with the same Adobe ID.
    There are sometimes issues with this registration: if you have them ....
    Sometimes ADE gets its registration/activation confused and in a semi-authorized state.
    Uninstalling and reinstalling does not help.
    Unfortunately, it often then gives misleading error messages about what is wrong.
    A common incorrect message informs you that the ID is already in use on another computer and cannot be reused.
    This can often be resolved by completely removing any authorization using ctrl-shift-D to the Library screen on ADE (cmd-shift-D if on Mac).
    Restart ADE, and then reauthorize with your (old) Adobe ID.

  • Is it possible to list information , that i have shared(i.e documents, sites etc) with external user.

    Hi,
    Is it possible to list information , that i have shared(i.e documents, sites etc) with external user. 

    Hi
    We have two version of SharePoint, one the online version and the other on-premise installation
    In online version, we can invite external users(liveID and google users) to have access to site and documents. This feature is provided by ADFS server already configured OOB in online version
    Onpremise version does not have by default the feature to share with external users or customers. we have to extend the site and provide different identity providers.The identity provider can be Active directory,SQL server,Claims,ADFS server which
    will support liveID
    http://technet.microsoft.com/en-us/library/cc261698(v=office.14).aspx  
    Thanks
    Whenever you see a reply and if you think is helpful,Vote As Helpful! And whenever you see a reply being an answer to the question of the thread, click Mark As Answer

  • Using KM APIs with Anonymous user

    Dear SDNites,
    I have gone thorough one of the SAP notes on possible CM scenarios with anonymous users. It says the the supported scenarios are Search, browse and download.
    My question is that can we use KM apis in these areas with anonymous users?  I got some documentation on KM Indexmanagement APIs for searching with TREX, which requires authenticated user. I am wondering is there any way to use those APIs with anonymous user access.
    Thanks a lot in advance.
    Regards
    Pavan

    Hi Pavan,
    if you access the KM via Web Service you'll find parameters in each service to send username and password.
    If you browse the KM reposiroties via http you may need to do an authentication first. If your portal accepts basic authentication (as it does by default) you may call the KM explorer iView with some URL like:
    http://<username>:<password>@<hostname>.<domain>:<port>/<path to KM iView>
    If this does not work, maybe you need to use a client that supports basic authentication (digest). This may be e.g. the OpenSourcer library [HttpClient|http://hc.apache.org/] from the Apache project.
    See [RFC2617|http://www.faqs.org/rfcs/rfc2617.html] for more details on Basic Authentication and Basic Authentication (digest).
    If you have some more questions, please come back.
    Carsten

  • "Use RAW files with external editor" greyed out for Photoshop CS2?

    I've just upgraded from iPhoto 5, and the "Use RAW files with external editor" option in the advanced preferences is greyed out when I select Photoshop CS2 as my external editor (back in the General pane).
    It works fine when Preview.app is selected. I can understand that pre-CS2 Photoshop wouldn't be available, but CS2 is capable of editing RAW images.
    Has anyone been able to get iPhoto 6 to send a RAW image to Photoshop CS2 using this preference? I've written an Applescript to do it in iPhoto 5, but I'd rather use something cleaner...
    15" PowerBook G4   Mac OS X (10.4.4)  

    Works great with Photoshop Elements, opens with Camera Raw. The issue is you can't save it so that iPhoto gets the changes.
    You have to save it and then re-import. I tried all permutations of saving it in originals and modified folders in the library. No luck. The only thing I didn't try is to save it as a jpeg over the top of the full sized one iPhoto created on import.

  • Hi everyone, to use the portal with many users using the same portal user?

    I have an another question is possible to use the portal with many users using the same portal user with diferent roles in the same time?
    thanks

    Hi Israel,
    It is possible to have same user logged in through differnt terminals or browser windows. However if there are say 10 roles assigned to that user, all 10 will be visible in all the windows. However you may open and work on different roles.. in the different windows.
    Note that the real time collaboration features shall not be available if the same user logs in multiple times.
    Hope this is useful.
    Regards,
    Anagha

  • Need help with external user authentication

    Hello,
    I need some help to set up an external user authentication in Oracle DB 10g. Using the documentation at
    http://www.oracle-base.com/articles/misc/OsAuthentication.php
    I added the user alex to my linux system and checked the parameter os_authent_prefix:
    SQL> show parameter os_authent_prefix
    NAME TYPE VALUE
    os_authent_prefix string ops$
    SQL>
    I created the oracle user alex using
    CREATE USER alex IDENTIFIED EXTERNALLY;
    as well as
    CREATE USER ops$alex IDENTIFIED EXTERNALLY;
    The parameters in the sqlnet.ora are set to
    NAMES.DIRECTORY_PATH = (TNSNAMES, HOSTNAME, EZCONNECT)
    SQLNET.AUTHENTICATION_SERVICES = (ALL)
    Being the local user alex on the linux server I can login:
    $ sqlplus /
    SQL*Plus: Release 10.2.0.1.0 - Production on Tue Aug 30 08:56:26 2011
    Copyright (c) 1982, 2005, Oracle. All rights reserved.
    Connected to:
    Oracle Database 10g Release 10.2.0.1.0 - 64bit Production
    SQL>
    Now using a Windows Client:
    C:\>sqlplus alex@<netservicename>
    SQL*Plus: Release 10.2.0.1.0 - Production on Di Aug 30 10:31:37 2011
    Copyright (c) 1982, 2005, Oracle. All rights reserved.
    Kennwort eingeben:
    ERROR:
    ORA-01017: invalid username/password; logon denied
    - So, what's wrong?
    - Do I always have to create oracle users with the prefix "ops$" to the local username? How do these users login - with or without the prefix 'ops$'?
    - I read that kerberos authentication is only available through oracle advanced security addon. What about authentication through ldap?

    Obviously it doesn't work from any remote system.
    For this to happen the parameter remote_os_authent would have been set to true.
    Warning: this poses a security risk.
    As far as I know you should have been logged in as alex on the client, and using sqlplus /
    However, from 10g onwards Oracle comes with Oracle Wallet, which stores the password encrypted outside the database in a file, called wallet, and which is accessible from anywhere.
    You would better use that.
    Sybrand Bakker
    Senior Oracle DBA

  • Public SharePoint Online Site with External User Portal

    Hello Everyone,<o:p></o:p>
    My company switched over to Office 365 a few months ago, and now would like to start using our Public SharePoint site to share information (documents
    pertaining to their orders/drawings/etc.) with our customers (external users).<o:p></o:p>
    <o:p> </o:p>
    I have seen documentation on how to share documents with individual users, but we were looking to do something a little bit different. We would ultimately
    like to have a public site with generic company information (like hours, about us,directions etc.) that anyone can see.
    We would also like to use SharePoint as almost an "FTP type" service where we could post documents and share them with individual
    external
    users. HOWEVER, instead of sharing individual documents, we were wondering if there was a way that an external user (that we have granted
    access) could sign into the public SharePoint site, and then see information that ONLY pertains to them.
    I have been doing some research on this, and I haven't seen that anyone else has tried this. Has anyone had any luck? Or would you have suggestions on how to make
    this work? I had originally posted this question on the Office 365 SharePoint forum, and they suggested posting this question here. Any help would be appreciated. Thanks!

    Hi,
    did you finally manage to get what you requested here above ? Indeed, I am also struggling to set up the same (public website with individual content sharing with external authentified user).
    For external user, I am quite sure that we need to go through MS ID creation (I have created some test users using https://login.live.com).
    Our public website is done and (almost) working. I have then created a sub-site for the same, this one to manage permission based on authentified user
    But I am stuck when trying to assign a document library with relavant permission.
    Would be great to share our feedback and I have searched a lto on the web and did not find any satisfying answer to this design (If there is any... here is my doubt...)
    Thanks in advance
    stef

  • Problem: Using iTunes 6 with multiple user accounts in XP

    I recently installed iTunes 6.0.0.18 as an upgrade in Windows XP Professional. After installing the software and a restart, I attempted to use iTunes with success as the Administrator. However as another user, iTunes when launched will prompt the user with the user license agreement. When the user accepts the agreement, iTunes never opens, however I have noticed that the hard drive where the music files are located is continually accessed. When logging out an "End Task" message pops up stating that Quicktime Helper Files are still being used.
    After the problem arose I attempted twice to completely uninstall iTunes, restart, cleanup the directories, reinstall, and then give all users full control permissions in both the directory structure of iTunes and the registry, with the exact same results.
    Currently I have no fix for this problem, but I suspect that it is an issue with the software (iTunes 6.0.0.18). I have since downgraded back to iTunes 5.0.1.4 and am not having any issues.

    Hello B,
    So I finally had time to download the latest version of iTunes (ver. 6.0.1.3) and install it (logged on as the Administrator account). Please note that during the install I did get an error message that stated something to the effect that "a program tried to access memory location XXXX which is "READ" only." I believe this to be the new memory lock "virus" deterrent system that Intel has recently introduced with the latest 64-bit processors and motherboards, (which I have) but I am only guessing. In any case the installer finished in the background without incident.
    After installing iTunes I launched it as the Administrator, and everything work just fine. I then logged off and logged in as my user account and attempted to run iTunes. I got the license agreement window, clicked "Accept" and nothing happened, but again I noticed that the Network card and my NAS were being accessed. I launched "services.msc" to check, as you suggested, to see if my QuickTime service had started. Much to my surprise the service was not listed. So I figured, well if there is such a service that needs to be launched then perhaps launching QuickTime would start this service, (still baffled to why the service is not listed in Windows Services). I launched QuickTime, and while leaving QuickTime open I then attempted to launch iTunes. Much to my surprise it started! I then closed both apps and have attempted to start iTunes several times since with success. A crazy fluke but, the steps listed above seemed to work for me. I can only hope that it helps others out who may be experiencing the same issue.
    So it seems that my issue has been resolved. Thank you for all your time and efforts on this matter, I do appreciate it.
    Jamie

  • Using the GT70 with external monitor and lid closed

    I wasn't sure where to post this question.
    I have several laptops and use external monitors. I close the lid on the laptops and the display continues to work.
    On the GT70, the system shuts down. It won't allow me to use the external keyboard and mouse or display the session.
    Any suggestions if there is a configuration option to allow the GT70 to continue to function with external monitor and lid closed.

    Yup. This is a windows setting. You need to go into your control panel -> power options -> "Choose when the computer sleeps" and "Choose what closing the lid does"
    That should solve the problem. I currently have my GT70 hooked up to a 42" TV and I can close the lid and it stays on and the TV continues displaying as well. No problems. =]

  • Regarding issue with externalizing users to shared services

    Hello,
    I was working today on externalizing users to shared services through EAS Console & it went successful. But then I saw that the users were already externalized & there was already an application group existing in shared services. So now there are two application groups both clone of each other, i.e. if I provision any user with one application, the clone of that application is also provisioned through that user.
    The bigger problem is somehow the connect bet'n both SS & Essbase Services is lost & the users created in SS are not getting reflected in EAS, even after refreshing the securities on EAS... & then I tried to restart all the services again open LDAP, SS, IS, Essbase & Admin Services.... I am getting error while opening Essbase services, they are not getting started??? Please help me resolve this error...
    Thanks.

    Hi,
    What version are you installing and what O/S is it for ?
    If it is windows it is definitely an executable you are running and you are not trying execute one of the patches?
    Cheers
    John
    http://john-goodwin.blogspot.com/

  • How to use iPod Shuffle with external Speakers

    I tried using iPod Shuffle but its not working with external speakers.
    Please let me know if there is any way i can use it in External Speakers

    http://manuals.info.apple.com/MANUALS/1000/MA1550/en_US/iPod_shuffle_4thgen_User _Guide.pdf

  • When using time machine with external hardrive to backup, some music items from iTunes and some photos from iPhoto do not transfer to backup hardrive.  What am I ding wrong?  Using latest version of mountain lion.

    When I use time machine with my external harddrive to back up computer, some music from iTunes library, and some photos from iPhoto library are missing when I check backup disk.  I am using latest version of mountain lion.  Am I doing something wrong?

    First, Time Machine doesn't completely back up the iPhoto library while iPhoto is running. Make sure you quit iPhoto after making any changes to allow a backup to take place.
    This simple procedure will clear your Time Machine settings, including both overt and hidden exclusions. If you have a long exclusion list that can't be recreated easily, you may prefer a more complicated procedure that preserves the exclusion list. In that case, ask for instructions. Otherwise, do as follows.
    Triple-click the line below to select it:
    /Library/Preferences/com.apple.TimeMachine.plist
    Right-click or control-click the highlighted line and select
    Services ▹ Reveal
    from the contextual menu. A Finder window should open with a file selected. Copy it to the Desktop. Then move it (the original, not the copy) to the Trash. You'll be prompted for your administrator password. Reboot, recreate your settings in the Time Machine preference pane, and run a backup to test. If TM now performs as expected, delete the file you copied to the Desktop.

  • Major problems using DV cam with external drive connected. HELP

    I am running Final Cut Pro 5.0.4 and Quicktime Pro 7.0.4 and I want to use one of my external Firewire drives as my scratch disk, and when I connect my Canon GL2 FCP either crashes if it is open, or hangs when trying tro start uo if external hard drives are connected. As I need to use an external to capture to I really need to resolve this A.S.A.P.
    Thanks in advance for your reading and replying to my post,
    Sebastian

    firewire external hd is a perfectly acceptable medium for capturing footage. it works pretty flawlessly and has little issues or problems
    This type of blanket statement really can't be supported in my view.
    There are issues with single bus firewire captures.
    And many cams, including Canons, don't play well with firewire hard drives on the same bus.
    Glad it works for you, but that's doesn't mean it works for everyone.
    You might want to take a peak at this:
    http://www.adamwilt.com/Tidbits.html#FireWireFrustrations

Maybe you are looking for