What changes are needed to have iDS 5.1 support SHA instead of SSHA as the default ?

We have an application that ONLY supports SHA passwords
and when we upgraded from iDS 4.16 to iDS 5.1 it doesnt
work any more. Looking further, iDS 4.16 supported SHA
as the default for password storage and iDS 5.1 supports the more secure SSHA as its default.
Is there a way that we can specify what accounts use
SHA versus SSHA ? If not, how do you configure iDS 5.1
to support SHA as its default ?

Hello, I read your response and I have a slightly different problem. I have set up a LDAP on Iplanet 5.1 and imported users from our old 4.x directory. When I did this everyone was added with their existing SHA hashed password.
Now any new users that we have been adding have been loaded to the directory whit an SSHA hased password. This has caused a problem with some of our applications that require an SHA hashed password.
I know where I can reset the default password hashing for the LDAP, but is there a way I can convert the passwords for the few hundred users that we entered before figuring this out from the SSHA hashed password to the SHA hashed password? I tried to do this via an LDIF import and when the LDIF file contained a userpassword value that began with {SSHA}, that is the way it was imported.
Is there a way to have the IPlanet LDAP do this? Or write a simple program to do this? We don't want to have each one of these users have to enter a new password and then have the LDAP server encrypt it, we would rather just take the existing SSHA hashed password and convert it to an SHA hashed password. Is this possible?
Any help would be greatly appreciated.
Thanks

Similar Messages

  • What licenses are needed to have CUCM not in demo but for LAB

    I am trying to build a lab with new versions of CUCM 9.1
    I do not want to use demo versions for 60 days nor request a temp license for 6 months.
    what is the minimum licenses i will need to have CUCM in full production mode for Lab somulation and with the least cost?

    Hi.
    If you are a Cisco partner, you can obtain an NFR kit at a reasonable price.
    Check the following link.
    http://www.cisco.com/web/AP/partners/promotions/nfr/index_nz.html
    HTH
    Regards
    Carlo
    Please rate all helpful posts
    "The more you help the more you learn"

  • What changes are needed in Server Operating system using OPC with Labview

    I am a novice trying to connect Labview into KepwareEX OPC server. I am using MS Windos XP on both sides. at first I could see no OPC server I checked with the Kepware and they suggested me to fix the DCOM configuration on the Server. at last I saw the OPC Server and their client connected to it.
    When I try to assign a Datasocket connected to a control on Front panel in to OPC. System Browses and see the OPC server but after selecting the tag. when I run the software, connection Lamp gets red and this Error comes up ""Can't connect to OPC server. Registery Access denied" . the Kepware  quick client is working OK. and Labview got connected when I tested it on the same server. I think there is something wrong with Server OS configuration cause I can not See the Labview OPC Server too, which is installed but I am not using it, Can anybody help me ?

    Hello:
         When you try creating a new I/O server and when you select OPC, you should be able to see the list of OPC servers installed in the system. You can select LabVIEW OPC and select a I/O item from the configure OPC client instance.
    From what I understand you are able to connect from LabVIEW just fine. Are you able to use server explorer and connect to kepware? The following tutorial will step you through using OPC servers with LabVIEW.
    http://zone.ni.com/devzone/cda/tut/p/id/3742
    DSC is LabVIEW add-on for developing your HMI/SCADA or high-channel-count data-logging applications. With the DSC Module, you can interactively develop a distributed monitoring and control system with tags ranging from a few dozen to tens of thousands. The following link has a TCP modbus presentation that you will find useful.
    http://www.ni.com/labview/labviewdsc/upgrade.htm
    Please let us know the steps you are following to configure the OPC connections and post some snapshots. This will help in better understanding.
    Thanks and hope this helps
    Regards
    Avi Harjani

  • What changes are required for OSS note 456507

    Hi All,
    PLease advise me what changes are required for OSS note 456507 (Assign the function groups QOWK or ORFC in the authorization object S_RFC to tRFC/qRFC users).
    I’m thinking of just going with the following additions to Role
    AAAB – Cross Application Auth Objects
    S_RFC
    Activity – 16
    Name of RFC - *
    Type of RFC - *
    But wanted to check what the implications of doing such a thing were, are there any negative points that you can think of opening up the access as above, as opposed to what was suggested in the OSS note?
    Your advice would be greatly appreciated.
    Thanks in Advance.
    Regards,
    Sandhya.

    Hello Sandhya,
    S_RFC is needed in case of making any RFC calls.
    Normally it is needed  for users that are mentioned in RFC destinations.
    As such mostly these users are system/communication users or super users.
    Without giving access to function groups through S_RFC successful RFC call can´not be done.
    Now the value of field name of RFC can be * but only for those users which are really global super users. In case you need this authorization for any selective functionality as in you case only for function groups QOWK or ORFC then you should try to  restrict the access. Negatiity is only that in case of * the authorization access increases but for system or super users you dont need to worry too much really because with system/communication users no one can login and the super users will have sap_all generally. Also their passwords will be a well kept secret so that a miususe can not be made.
    By global super users I mean users which are used for various types of activites.
    Please award points accordingly.
    Regards.
    Ruchit.

  • I have had creative suite premium installed on my computer for a long time, but now it states that my computers configuration has changed and needs to be reactivated, but it cannot be activated by internet, and the phone number states that adobe no longer

    I have had creative suite premium installed on my computer for a long time, but now it states that my computers configuration has changed and needs to be reactivated, but it cannot be activated by internet, and the phone number states that adobe no longer activates by phone. What is the solution to continue to use my program that I have had working on this computer for a long time?

    You do not state which version... if CS2 read next
    CS2 (and earlier) Activation Server replacement software
    http://helpx.adobe.com/x-productkb/policy-pricing/creative-suite-2-activation-end-life.htm l
    When you install the special version of PPro2 on a Win7 or Win8 computer, you MAY need to right click the program icon and select WinXP compatibility from the option popup... AND Vista problems https://forums.adobe.com/thread/416347
    If not CS2, read next
    This is an open forum, not Adobe support... you need Adobe staff to help
    Adobe contact information - http://helpx.adobe.com/contact.html
    -Select your product and what you need help with
    -Click on the blue box "Still need help? Contact us"

  • How do I determine what xtras are needed?

    From the searching I have done it appears that xtras equired are mostly trial-and-error.
    Is there an efficient way to determine what xtras are needed for each lindividual movie?
    My programs are divided into a series of sequential movies.  At the end of each movie
    there is a goto statement to launch the next movie.  Does that require me to determine
    xtras for each separate movie? 
    In a perfect world there would be a way for Director to search a  folder for and present an aggregate list of all xtras required for that set of movies.
    If no such method exists, what is the recommended hunt and peck system?

    Thanks for the response, rduane.  But I refer to the procedures as a bit random for the reasons you mentioned in your explanation.  For example, you stated that, "Director will normally add all of the Xtras that you need to each movie as you build it".  And, yes, I know that it does add some automatically.  But, if Director really does "add all of the xtras that you need to each movie as it is built", how could I ever jump to one that is missing a needed xtra?  If it needs it, why wasn't it added when it was built?
    So, that's the reason I mentioned "trial and error", and "hunt and peck".  The system is not reliable in its handling of xtras, or which ones are needed where.  I am familiar with workarounds such as going to each movie and selecting Modify>Movies>Xtras to see which ones Director has added,  But that is all it tells you.  It does not tell you if it has added all the xtras "needed".  And when the error message comes up, it does name the missing xtra, but not which movie needs it.  So, one has to go find the named xtra and copy it over to the Xtras folder. 
    At least, that's what I do to fix it.  But I asked the question because I wanted to know if Xtras handling itself is unreliable, or if I'm doing something incorrectly.
    Dewey-+

  • While doing ODI migration what things are needed to be setup in Topology?

    While doing ODI migration what things are needed to be setup in Topology manager ?
    1.Like in Toplogy in file we hive file paths.
    2. In Planning we set Logical schema .
    Not sure about other things.
    Hoping some can can help!!!!!!!!!!!!!!!11

    Lots of things are defined in the topology manager - below is a simplified list
    1) Physiccal Schemas the actual connection information / details related to any technology you plan to use in your ODI integration interfaces
    2) Logical schema, abstracted version of the Physical schema which allows greater flexibility ad reuse across environments
    3) Contexts - how you asssociate logical and physical schemas
    4) Agents - manage the execution of ODI jobs
    When you talk about migration, do you mean moving ODI objects between seperate environments such as Dev and Prod? If so you will need to ensure that all the technologies you use in Dev are present in Prod. The physical layer has been set up with all the correct connection details. Your logical scemas has been set up matching your configuration in the dev environment and you have used the contexts to associate the logical and physical layers as per your dev configuration.

  • What commands are needed to configure authentication?

    I'm running the JaasAcn Sample from a DOS prompt on a Win XP client and am getting 'authentication failed'. My Active Directory Realm is AD.COURSEWIZARD.COM and the KDC FQDN is ad.ad.coursewizard.com. It succeeds when I run the 'Sample' locally on the AD server. If I set 'isInitiator=false' in jaas.conf, it succeeds no matter what I enter for username & password. It seems that I need to configure an SPN.
    When setting an SPN, are you declaring that a particular AD user account is associated with a remote service that will be requesting authentication?
    Do I have to also use the 'ktpass' command, even though I'm using a Win client?
    If I use ktpass, but am just testing with a PC on the Inet, should I just use my IP address for domain since I don't have a FQDN?
    Do I need to move the keytab file, created by ktpass, to the client and configure it to use it?
    Does the ADS need to have a krb5.conf or krb5.init file? I don't see one under '../drivers/etc/'.
    What commands are needed in order to configure the server, and client, to authenticate successfully?
    Cheers

    Sorry, I haven't seen a nice JGSS for Windows guide yet.
    Back to your questions:
    1. When setting an SPN, are you declaring that a particular AD user account is associated with a remote service that will be requesting authentication?
    IMHO, setspn creates a service-like alias for a normal AD account, so that GSS style server program can use it as a NT_HOSTBASED_SERVICE name.
    2. Do I have to also use the 'ktpass' command, even though I'm using a Win client?
    ktpass is used at the server side, what you use at client side is unrelated.
    3. If I use ktpass, but am just testing with a PC on the Inet, should I just use my IP address for domain since I don't have a FQDN?
    Porbably not. Anyway, AD works fine with a DNS. If you haven't one, config the AD server as a DNS server.
    4. Do I need to move the keytab file, created by ktpass, to the client and configure it to use it?
    No, keytab is used at server side. The client side uses the native credentials cached in LSA after you login to Windows as an AD account.
    5. Does the ADS need to have a krb5.conf or krb5.init file? I don't see one under '../drivers/etc/'.
    Yes, Java needs the file for both client and server JGSS programs. Normally it should be inside the WINDOWS directory. Somethign weird woun happen if you uses Terminal Services or else. Add -Dsun.security.krb5.debug=true to the Java command line will show you when Java tries to look for this file.
    6. What commands are needed in order to configure the server, and client, to authenticate successfully?
    You need setspn.exe and ktpass.exe on the server to create the SPN and the keytab file. No tools are necessary on the client side, but MS's kerbtray.exe and klist.exe (attention: MS's klist, not Java's) are nice. BTW, a nice network sniffer (say, Wireshark) is also useful.
    I'm not an expert on all these questions, but I cannott resist the temptation to give an answer to each of them.

  • What skills are needed to manage Exalogic?

    Hi there
    Please let me know if I should be directing this question to another Forum and which Forum it should be.
    We are thinking of purchasing Exalogic with a view to having a private Cloud.
    What skills are needed or teams in order to manage Exalogic in-house?
    I've used google but not really found the answers other than a couple of Oracle docs which suggest sys admins teams, network teams, etc could all have a hand in the management as they currently exist.
    However, Management are wondering if a new team needs to be formed and what skills that team should have.
    As we already have Exadata under the DBA team they are wondering if the skills the DBAs have will also apply for Exalogic.
    Thanks.

    Others are welcome to jump in!
    Thanks and stay tuned to for results next week<a href="https://www.sdn.sap.comhttp://www.sdn.sap.comhttp://www.sdn.sap.com/irj/sdn/developerareas/technology">The Technology HomePage</a> for tally and scores

  • Camileo P10 - What tools are needed?

    Hi,
    first i wanted to ask what codec is needed to edit the footage shot with a Camileo P10. I wanted to edit the videos with Adobe After Effects but it went all **** on the files, stating something about preblems with the audio and played the video chopped and muted. Didnt have any problems, even corrupted video files worked better than the sh** this camera pushes out of its sd-slot.
    NO, I dont want to convert the files.
    NO, I dont need workarounds.
    NO, I wont buy another Toshiba cam.
    NO, I dont need links from old threads that lead me nowhere.
    All i wanna hear is what Codec is needed, since it has to be an error with that. Plays fine with VLC, but not with WMP, winamp, quicktime, anything else.
    Alternatively you can suggest some tools i should use. I'd prefer a sledgehammer, but maybe a buzz saw is fine too. unfortunately i can't make a video of destroying the cam. you should know why.

    Hello
    > btw, i figured it out by myself
    Can you also post how you have fixed it by yourself? I think this would be interesting for other users.
    Furthermore I dont understand your problem. Here its an user to user forum where you can talk with people like you and me. That means there is no warranty that you will get an answer to your question. Not all questions can be answered from users so sometimes its advisable to contact an official authorized service provider. The guys can provide really professional help.
    And I doubt that other manufactures have a better support. From my experience I can say that Im satisfied with this forum and my authorized service provider and as you can read here, this can confirm many other users as well.
    Last but not least the focuses here in forum are notebooks because its a Computer Systems Support Forum as you see under the Toshiba Logo. Do you know what this mean? It means that the most discussions and users are looking in notebook and software section only.
    Anyway, Im glad to hear that the problem is fixed. :)

  • What wires are needed to connect to a projector

    What wires are needed to connect a macbook to a projector

    A VGA or HDMI cable (Perferably HDMI). But you need mini-displayport connectors to the specific cables.

  • HT1386 Switching from a pc to a Mac. What steps are needed to get my iPhone and iPad to work with my new Mac?

    What steps are needed when upgrading from a pc to a Mac?

    Copy everything from your old computer to your new one.

  • WHAT PARTS ARE NEEDED TO SHOW MY MAC 10.8.4 OVER TV-.

    WHAT PARTS ARE NEEDED TO SHOW MY MAC 10.8.4 OVER TV….

    About AirPlay Mirroring in OS X Mountain Lion
    You need:
    An AirPlay-enabled device such as http://store.apple.com/us/ipod/ipod-accessories/apple-tv
    A suitable TV monitor
    A network
    HDMI cable
    A compatible Mac:
    iMac (Mid 2011 or newer)
    Mac mini (Mid 2011 or newer)
    MacBook Air (Mid 2011 or newer)
    MacBook Pro (Early 2011 or newer)
    Or, depending on the model Mac you intend to use: a Thunderbolt or MiniDP or DVI to HDMI adapter for a wired connection to your TV or AVR

  • I want to know what changes is iTunes going to do to my Calendar or Contacts, before I apply the syncronization.

    I use an iPhone 5 with iOS 6.1.4. I sync with iTunes 10.7.0.21 on a Win XP sp3 Computer.
    I sync always manually. I have configured iTunes to "warn when any of data on my computer is going to be changed".
    When I press "SYNC" iTunes warns that "7%, for example, of my Calendar is going to be changed".
    But it doesn't say WHICH Calendars records is going to change.
    How can I know what changes are going to be applied ?
    And how can I decide which changes to accept and which not ?
    Or, at least, is there a log file to see what changes have been applied, in order to correct any mistakes ?
    Thanks,
    George Skarpas

    I'd imagine they should be filed under the artist name in your My Documents>My Music>iTunes>iTunes Music folder, so try there first maybe.

  • I am subscribed to Photoshop only and I want to know if I can change my subscription to have your new offer of Lightroom and Photoshop together for the same price I am paying for Photoshop alone?

    I am subscribed to Photoshop only and I want to know if I can change my subscription to have your new offer of Lightroom and Photoshop together for the same price that I am paying for Photoshop alone?

    Contact sales support by web chat. They can cancel your current subscription and transfer you to the new one if you are within certain criteria. Otherwise you may need to wait until your subscription runs out and then sign up later.
    Mylenium

Maybe you are looking for

  • FKK_EBS_TOI_COPA Mass activity in FS-CD

    HI, For SAP FS-CD project, We want to posting documents into FS-CD by generating the IDOC through LSMW in Delayed Status (With out posting) and will be posted using Mass Run FKK_EBS_TOI_COPA. What is the standard process of posting throguh IDOC. when

  • Parameters of NFS in Solaris 10 and Oracle Linux 6 with ZFS Storage 7420 in cluster without database

    Hello, I have ZFS 7420 in cluster and OS Solaris 10 and Oracle Linux 6 without DB and I need mount share NFS in this OS and I do not know which parameters are the best for this. Wich are the best parameters to mount share NFS in Solaris 10 or Oracle

  • Adding color backgroun to text created

    Is there a way to add a color background to text I created. I am able to add text and then able to add a color background separately, but when I add it , I can't see the text? thank you! Susan

  • Is it possible to get this o/p in a query

    Hello All, is it possible to write a query for the output SQL> select * from emp1; EMPNO EMPNAME 100 AAA 222 BBB 333 CCC 444 DDD SQL> select * from bank; BANKID BANKNAME 1 ICICI 2 HDFC 3 SBI 4 SBH SQL> select * from emp1_bank; EMPNO BANKID 100 1 100

  • Brand new to PS and need help already. Is catalog the same as album?

    I received Elements7 as a gift several months ago. I loaded it onto my computer, and an album was created, but I never learned to use the program. I now have the Classroom in a Book, and am at a standstill at the very beginning. It says to go to the