Why is security user required for Tux Domain?

I have to add a user in Weblogic Security Realm with user name equal to the Tuxedo
Remote Domain name. Otherwise the service request from Tuxedo to WTC is rejected
"Failed to get user identity".
In WTC Local WLS Domain "AIRCORE-WLS"... Security=None
In the Remote Tuxedo Domain "AIRCORE-TUX" DMCONFIG... SECURITY=NONE
So why is Weblogic trying to authenticate the remote TDOM as a user?
####<Feb 18, 2003 6:43:28 PM CST> <Debug> <WTC> <EA-LAWSTUC-W2K> <aircoreserver>
<ExecuteThread: '11' for queue: 'default'> <kernel identity> <> <180046> <]/rdsession(0)/dispatch/15/Failed
to get user identity: javax.security.auth.login.FailedLoginException: Authentication
Failed: User AIRCORE-TUX javax.security.auth.login.LoginException: Identity Assertion
Failed: User AIRCORE-TUX does not exist>
After creating user "AIRCORE-TUX" in Security/Realms/myrealm/users, service request
works.
####<Feb 18, 2003 6:49:11 PM CST> <Debug> <WTC> <EA-LAWSTUC-W2K> <aircoreserver>
<ExecuteThread: '1' for queue: 'default'> <kernel identity> <> <180046> <[InvokeInfo/setTargetSubject/(principals=[AIRCORE-TUX])>

Carl,
Carl Lawstuen wrote:
>
I have to add a user in Weblogic Security Realm with user name equal to the Tuxedo
Remote Domain name. Otherwise the service request from Tuxedo to WTC is rejected
"Failed to get user identity".This is WTC need to get correct user credential to access WLS EJB. You
either add users to WLS or you add remote domain id (access point id) as
user to WLS depends on your configuration and release of Tuxedo the
request came from.
>
In WTC Local WLS Domain "AIRCORE-WLS"... Security=None
In the Remote Tuxedo Domain "AIRCORE-TUX" DMCONFIG... SECURITY=NONEThis SECURITY is not for ACL or user credential, this is for
authenticating the TDOMAIN session. It is done at session
negotiation/establishing time. This has something to do with connection
principal but has nothing to do with ordinary user. Since you set it to
NONE then there is no session authentication being done.
>
So why is Weblogic trying to authenticate the remote TDOM as a user?As I mentioned before WTC needs user credential to access WLS properly.
>
####<Feb 18, 2003 6:43:28 PM CST> <Debug> <WTC> <EA-LAWSTUC-W2K> <aircoreserver>
<ExecuteThread: '11' for queue: 'default'> <kernel identity> <> <180046> <]/rdsession(0)/dispatch/15/Failed
to get user identity: javax.security.auth.login.FailedLoginException: Authentication
Failed: User AIRCORE-TUX javax.security.auth.login.LoginException: Identity Assertion
Failed: User AIRCORE-TUX does not exist>
After creating user "AIRCORE-TUX" in Security/Realms/myrealm/users, service request
works.As I mentioned before depends on your configuration and Tuxedo releases
you have to use access point id (domain id/connection principal) or real
user. Once you have this in place it should work fine.
>
####<Feb 18, 2003 6:49:11 PM CST> <Debug> <WTC> <EA-LAWSTUC-W2K> <aircoreserver>
<ExecuteThread: '1' for queue: 'default'> <kernel identity> <> <180046> <[InvokeInfo/setTargetSubject/(principals=[AIRCORE-TUX])>Regards,
Honghsi

Similar Messages

  • Why Data Sort is required for Merge Join Transformation

    hi,
    In my understanding Merge Join works very similar to T SQL joins. But I am trying to understand why Sort is a compulsory requirement? I have looked into following article but not helpful
    http://technet.microsoft.com/en-us/library/ms137653(v=sql.105).aspx
    aamertaimor
    aamertaimor

    Merge Join is going to walk through two sets in the order that you gave in your input or using the Sort transformation. So, it loads one record from one input and one record from the second input.  If the keys match, it will output the row with information
    from both inputs.  If the left input has a value that is less than the value in right input, then either the row from the left input is sent out with no right input information (if there is an outer join) or if the join is an inner join, the
    Merge Join component will get the next row from Left input.  If the right input has a value that is less than the value that in the left input, then if there is a full outer join, output the right input with no left input information otherwise, get the
    next row from the right input.
    Here is the beauty, SSIS only needs to retain a couple rows in memory.
    What if Microsoft decided that there is no requirement for sorting?  Then in order for the Merge join to work is that it would load all of the rows from one input into memory and then the Merge Join would look up the row in memory.  That means
    a large amount of memory would be needed.
    By the way, if you want Merge Join behavior without the sort, use a Lookup component.
    Russel Loski, MCT, MCSE Data Platform/Business Intelligence. Twitter: @sqlmovers; blog: www.sqlmovers.com

  • Why is my password required for printing?

    Hi everyone,
    I just got a brand new Mac Pro and I’m a bit puzzled about some of the security loops it makes me jump through. I didn’t mess much with the security settings, besides having to fix some permissions to share files with my MacBook, so I feel I’m unlikely to have caused this behavior.
    I was thus surprised (and annoyed) when I attempted to print and was asked each time to enter my password. The printer is connected to a Windows XP machine on a home network. I regularly use this printer with my MacBook and never have to enter any password. I must admit that there’s a chance I may have been asked for my password the first time I printed, and decided to store it in my keychain, and this could explain why I’m never asked for it. I just don’t remember.
    Nevertheless, my question is whether it is standard for a new Mac Pro to ask me for my password when printing on such a setup. Is the only remedy to this to include the password in the keychain?
    By the way, storing passwords for printers, web sites, etc., in a keychain is pretty unsafe unless access to my computer is password-protected, right?
    Comments and suggestions will be greatly appreciated.

    Hiya, Jon99 from Midwest,
    I am surprised that printing asks you for your password. I have printed for a long time BOTH on USB AND wirelessly via my WPA2 hidden network. Never has the printer asked me for a password! On a PC, I would suspect a virus, but I have not heard of that for a Mac (there only about 40 as opposed to 10's of thousands on PC's).
    The only explanation, I would be able to think of is if it a shared network printer because yours "belongs" to another machine (PC); so it maybe that it is not your mac asking for a password to print, but your mac asks you to access your (hopefully) secure PC. And, yes, you probably stored your password on your macbook keychain. why don't you try and print again, and check the "details" of what keychain actually wants (it's 3/4 down the window and click on details).
    Mac only normally asks for passwords for installation of programs, maybe in mail receiving/sending problems, or airport or similar.

  • Minimum set of ACLs / security access required for getting MBeanHome and Runtime MBeans

    Hi,
    Where can I get information regarding the "minimum set" of ACLs and security access/permission
    required for
    a) Accessing weblogic.management.MBeanHome [Local and Admin interfaces] and RemoteMBeanServer
    interfaces
    b) Use MBeanHome and RemoteMBeanServer interface to look up MBeans [especially
    Runtime MBeans] for Cluster, Server instances, EJBs, JDBC, Execute Queues, etc?
    Any help or hint is appreciated!
    Regards,
    DKV

    "DKV" <[email protected]> wrote in message
    news:3f4e8429$[email protected]..
    >
    Hi,
    Where can I get information regarding the "minimum set" of ACLs andsecurity access/permission
    required for
    I believe this was answered in the management jmx newsgroup.

  • Why XL line cards required for OTV?

    According to Cisco's website, there are specific types of line cards required to support OTV on N7K (N7K-8 port 10GbE with XL options, or N7K-48 port 10/100/1000 Module with XL option).
    Q1: Do I have to use the physical ports on those line cards to make OTV related interfaces? Can I use logical interfaces, and use physical ports on those line cards for non-OTV connectivity, such as used as a layer 2 access port?
    Q2: Since OTV feature is enabled globally, why the requirements for specific line cards in the first place? What the features/services provided by the line cards for OTV operations?
    Thanks.

    Has anyone seen design docs that suggest using 10-Gig ports for the OTV interfaces? I know the Q&A indicates support for all M1 line cards (not F1 or F2), but I'm wondering if there's any clearly defined design reason for not using the 1-G line cards for this (such as the N7K-M148GS-11L). 
    I'm basically asking if it would be recommended (for a system with no additional open 10-G ports) to purchase another 10-G blade (such as the N7K-M108X2-12L at $27), or could we do the job with spare ports on an existing 1-G card?  I've been through several docs, and while none of them indicate 10-G connectivity is mandatory, I'm hoping for a reason why Cisco might be pushing/recommending this for any size of OTV deployment.
    Thank you.

  • Why can the users in one child domain logon to computers in a different child domain in Server 2012 R2?

    I have setup a test system. It has a domain with 2 child domains.  DomainA.xyz.com has users and workstations. DomainB.xyz.com is a resource domain and has servers.  wyx.com is for IT administration.
    Users in domainA can logon to the domainB computers.  I searched to find out why it was so.  I found a "NT AUTHORITY\INTERACTIVE" entry in the local users group that enables this.
    This is rather confusing.  1.  When a user enters his credentials, he is not logged on and therefore would not be "INTERACTIVE" at that time.  2.  If everybody that signs on a computer is interactive, then does that mean
    everyone in the forest can sign on?
    So my issue is: Can I delete the "INTERACTIVE" entry in the local users group and not cause any problems?  I want to protect the resource domain from users signing on to them and give them access to the resources they need.

    Hi,
    The Interactive group includes all users that have logged on locally.
    In addition, it is not recommended to remove the
    interactive group from the local user group since it would cause all kinds of problems. For more detailed information, please refer to the similar thread and link below:
    Interactive
    group
    Staring
    at a blank desktop, due to Interactive missing from Users group
    Best regards,
    Susie

  • OBIEE 11.1.1.6 Help needed to resolve a user requirement for an analysis

    Hi all,
    I need to create a pivot table like this:
    Show a calculated measure VALUE / QUANTITY by dimension1 (on rows) and year & month (on columns). Add a grand total on year. Add a calculated item that shows the difference between grand total on year and last month shown. That is:
    ----------2012-------------------------------------------------------------+
    ----------JANUARY---FEBRUARY--MARCH-----APRIL-----Total 2012+Diff------+
    + (dim1) + 205+ 212+ 209+ 211+ 210+ 1+
    Obviously it's easy to do if I don't take the additional calculated item into account.
    But when it comes for having it specified, I'm in trouble:
    I can put year and month on columns and create a total on year (and it works) but I don't know how to create the diff calculated item...
    or...
    I can create two calculated items, one for the grand total (but I don't exactly know how to define the rule), the other one defined as LAST month - grand total (but I get an error if I try to use a calculated item in a calculated item).
    Any help or suggestion is welcome.
    Version is 11.1.1.6.
    Thanks!
    Cristina

    Must be the "hang at exit" problem.<br /><br />
    #Stop the Firefox process:
    #*[http://kb.mozillazine.org/Kill_application Mozillazine - Kill application]
    #*Windows 7 users click [http://www.techrepublic.com/blog/window-on-windows/reap-the-benefits-of-windows-7s-task-manager/2576 here]
    #*Mac users: http://techheavy.com/2011/02/the-mac-task-manager/
    #Why Firefox may hang:
    #*[http://support.mozilla.com/en-US/kb/Firefox+hangs Firefox hangs] (see Hang at exit)
    #*[http://kb.mozillazine.org/Firefox_hangs Firefox hangs (Mozillazine)] (see Hang at exit and Closing Firefox properly)
    #*[https://support.mozilla.com/en-US/kb/Firefox+is+already+running+but+is+not+responding Firefox is already running but is not responding]
    #Use Firefox Safe Mode to find a problem with an Extension or Plugin:
    #*Don't check anything when entering Safe Mode, just continue
    #*If the problem does not occur in Safe Mode it is probably and Extension or Plugin causing the problem
    #*See:
    #**[[Safe Mode]] and [http://kb.mozillazine.org/Safe_Mode Safe Mode (Mozillazine)]
    #**[http://support.mozilla.com/en-US/kb/Troubleshooting+extensions+and+themes Troubleshooting extensions and themes]
    #**[http://support.mozilla.com/en-US/kb/Troubleshooting+plugins Troubleshooting plugins]
    #**[http://support.mozilla.com/en-US/kb/Basic+Troubleshooting Basic Troubleshooting]
    '''If this reply solves your problem, please click "Solved It" next to this reply when <u>signed-in</u> to the forum.'''

  • Security - SM30 required for visualizing IMG TABLE / SPRO

    Hi!
    Is there a possibility to visualize IMG tables (for example T16FS), through SPRO without having SM30 transaction?
    It's a security policy where I work that most of the users can't have assigned SM30, but this interferes with visualizing of tables in SPRO.
    Would you help me, please?
    Thanks a lot!

    Julieta,
    I think if you know the table name , you can find the table entries through SE16 also. SM30 is not always needed. SM30 is needed only if you want to make some entry in sometables and for SPRO tables entry through SM30 is not possible.
    I could see the entries of T16FS through SE16
    If you want to see IMG tables through SPRO, you shoudl really knwo the SPRO path.If you ask any consultant belonging to that module, he should be able to guide you very well.
    Hope thsi helps you

  • Requirement for network domain

    We have a few customers who are using peer-to-peer networks, or just several PC's networked together, without a domain or MS Active Directory.  We feel that this is not the best setup, and there have been several problems that result from it.  But the customers are trying to minimize their cost, and do not want to create a full network.  Does SAP have any documentation that addresses this issue?  I have not been able to find any.
    Thanks for your help.
    Marcia

    Hi,
    Server configured as Workgroup is just okay, the problem is file security. You could  put passwords to all your
    sharedocs or dont share any from networks.
    What is your goal with regards to your network? I might suggest.
    Thanks.
    Clint

  • Why is the user agreement for Flash Player in Arabic? Most of us can't read Arabic.

    While awaiting the latest install of Flash Player, I decided to check out the user agreement:
    It opens showing a page in Arabic
    It is 304 pages long
    There is no obvious link to a table of contents
    There is no question asking what language is preferred
    I wonder whether or not this is so incompetently done that a reasonable jury would find that no user could be reasonably expected to have read or agreed to anything.
    //The link goes to page 1 of the 304 page "Personal Computer Software License Agreement", which is in Arabic. After I had worked with it and found the table of languages, the next time I opened the document, it went to the last page I had open-- page 87, which is in English (United States).  I do not ask for it to detect my language, merely offer me a choice.

    When I click that link, it goes (as it should from a U.S. IP Address) to the hyperlinked page 87, which is where the English portion begins.
    Your browser or International settings may prevent it from doing so, but I have nine machines that ALL parse the link the same way.

  • Multiple S-users required for OSS integration to SAP

    Dear all
    My client handles the IT support for 4 companies.  Each of these companies have their own SAP systems & therefore each company have their own S-number.
    Currently, I can assign one S-number in the global settings & then I can assign one S-number per user. 
    The problem however is that each user can post an OSS message for any of the 4 companies & therefore need to be able to specify which S-user should be used at the time of sending the message to SAP.
    Any ideas???

    Dear Danell,
    I am not sure whether you have configured the Standard Support Desk Scenario or the Support Desk Scenario for VAR's ASP's and AHP's.
    I would request you to kindly visit the URL : http://service.sap.com/solutionmanager
    This URL contains an separate section on VAR's / ASP's and AHP's with detailed Subsections for Setup / FAQ's and Documentation.
    Hope that the information in this section helps.
    Regards
    Amit

  • Why is email address required for digital sig?

    Hi, all.  Thanks, in advance, for any help :-)
    We have created an application in LiveCycle and have incorporated digital signatures to allow applicants to sign the various forms within the application, including W-4 and I-9.  Here is the next question....
    By default, the digital signature cannot be created without entering an email address.  The problem there, is that we have some applicants who do not have an email address (yes, there are still humans on the planet who don't have an email address :-).  Is there a way to get around this?  That can't be the only legally valid personal information that can be used to create a digital sig?  Can we offer an option if they don't have an email address?  We don't want to instruct them to enter bogus information.
    Thanks,
    Michelle

    Michelle
    When Acrobat is used to create a digital certificate, it is creating a self-signed certificate that conforms to the X509 certificate standard.  I haven't read the X509 spec from start to finish, but I would assue that the standard dictates that the e-mail (which is part of the "Subject" section of a certificate) is mandatory.
    See http://en.wikipedia.org/wiki/X.509 for a bit more info on digital certificates
    As for your statement "That can't be the only legally valid personal information that can be used to create a digital sig?", I don't believe there is anything legally binding or valid about a self-signed certificate as anyone can create one with any information they want.
    Regards
    Steve

  • Why is Domain required for an identity in the FIM Service?

    I have a scenario where FIM is managing identity, but not all identities have an Active Directory account. I have a flag in the FIM Portal (Service) that indicates if a particular
    user is entitled to an AD account or not. My provisioning setup adds or removes the AD account as appropriate. To support FIM Portal activities for those that do have AD accounts, I populate AccountName, Domain, and ObjectSID in the FIM Service from their
    corresponding attributes in AD.
    What I have noticed is that it does not seem possible to null out or delete the Domain attribute for a user in the FIM Service. I can delete the attributes for both AccountName
    and ObjectSID without issues.
    When attempting to remove the Domain attribute for a user I get the following in the event logs:
    Microsoft.ResourceManagement.WebServices.Exceptions.UnwillingToPerformException: Other ---> System.Data.SqlClient.SqlException: Procedure or function 'GetDomainConfigurationIdentifiersFromDomain'
    expects parameter '@domainName', which was not supplied.
    I assume that something internal to the FIM Service is trying to do some magic with validating the domain name and the domain configuration. I did found a post saying, “Yeah,
    you have to populate Domain”:
    http://social.technet.microsoft.com/Forums/en-US/f207caa9-3a6f-4f2d-8461-a83777280803/fim-service-ma-export-failedmodificationviawebservices-error?forum=ilm2
    My question is why is Domain required for a user? It is obviously needed for users that have AD accounts an must authenticate with the Portal, but in the case where a user
    does not have an account (and therefore does not have a domain), it feels odd to store the incorrect data for the user. It also looks weird when you bring up list of users in the portal and see domain values for users that do not have accounts. In this particular
    case, the client has many domains and does have the Domain and AccountName attributes displayed on the user search results page.

    Hi Henry,
    Using another domain attribute and workflow to maintain the actual Domain and DomainConfiguration is a good suggestion, thanks.
    My original question still stands however... Why is Domain required in the FIM Service?
    It is sounding like the answer is "It is not really required on it's own, but there is an internal process that requires it if there is a value for DomainContext set (and there is some magic that sets DomainContext, so you have to manually clear it.)"
    Since DomainContext is automatically set when a client writes a value to Domain. I would suggest that it is a bug that DomainContext is not automatically cleared when Domain is cleared.
    I poked around a bit and the bug can be fixed by changing the stored procedure definition to allow null parameters. In the FIM Service database the stored procedure [fim].[GetDomainConfigurationIdentifiersFromDomain] has a parameter declaration of "@domainName
    NVARCHAR(448)". If this is changed to "@domainName NVARCHAR(448) = null" the problem appears to be solved.
    Making this change would of course be totally unsupported, but perhaps it can be included in a future product update.
    For now I will use Henry's workaround, or just live with potential out of date Domain data.
     Thanks

  • WHY  PGA  IS  REQUIRED  FOR  EVERY USER  ?

    Good Morning Everyone ;
    I have a question  about PGA.
    WHY  PGA IS REQUIRED FOR  EVERY USER ?
    What i got from google ..
    Even though the parse information for SQL or PL/SQL may already be available in library cache of shared pool,
    the value upon which the user want to execute the select or update statement cannot be shared.
    I cant realize it   Can anyone show clear  example , if  possible ?
    DB Version is  10.2.0.4.0
    OS : oracle linux 5.5
    Thanks in advance ..

    Thanks aman and heok.
    My Question :
    Your explanation is clear. I think i am getting little bit confused.
    Could you please clarify little more ?
    >> session 1 :
    user is HR
    SQL>select * from tab1  ORDER BY name;
    >> session 2 :
    user is scott
    SQL>select * from tab1 where ORDER BY name;
    >> session 3 :
    user is USER1
    SQL>select * from TAB1 where ORDER BY name;
    >> session 4 :
    user is USER2
    SQL>select * from TAB1 where ORDER BY name;
    IS this right aman ?
    Already sql statements are avail in SGA ,Even though all above users needs same information.
    Oracle does sorting operation in PGA. If PGA exceeds , oracle will use temporary tablespace .
    Thanks heok and aman.

  • IE 11 Enhanced Security improperly enabled for one user in domain

    I'm running a small network with two domain controllers which use Server 2008 R2 Standard. The clients all run Windows 7 with the latest updates. Today one user suddenly started having their browser always start in Enhanced Security mode on the Windows
    7 clients! This happens for any client in the domain, but it does not happen when then user logs into the terminal server for the domain. I use roaming profiles and redirected folders. I have separate profiles for the Terminal server from those used for the
    local computers. I have restored the user's profile to last week when the problem was not happening, but it did not help. It does not happen for any other user in the network, even if the user logs in on the same computer. So there is something in the user's
    environment that is causing the problem. I have reset IE 11 to default and it still comes up in with Enhanced Security for that user on the Windows 7 clients. I've searched the internet for this problem without success.

    So I figured this out. I think that it is a mis-feature in Server 2008. The particular user is a member of the Backup Operators security group on the domain. Recently they did a backup on the server and then this problem started.
    It appears that even though they are not a server administrator or a domain administrator, the Enhance Security settings got put into their roaming profile and when they logged into their workstation, the settings got applied to IE on their workstation.
    If I turned of Enhance Security on the server for only users, the problem still happened for this user, even though they are only a Backup Operator, not an administrator. If I turned off Enhanced security on the server for administrators, logged in and out
    of the server as this user, then the problem went away.
    So it seems that Backup Operators are viewed as "administrators" by Enhanced Security and if you use roaming profiles for such users, Enhanced Security will be enabled for such users on their workstations. Yuck.
    Easiest solution is probably to have a separate user account for the backup role on the server.

Maybe you are looking for

  • Oracle11g: how I change character set to AL32UTF8?

    Hi, a software is requiring to have a database with AL32UTF8 character set. For what I understand I have an instance of db with nls_language=american I tried: SQL> alter database character set AL32UTF8; alter database character set AL32UTF8 ERROR at

  • Custom component: porting from lc 8.0 to lc 8.2

    hello i developed a java pojo custom component for lc 8.0, essentially it connected to a db and returned a complex object. Now the environment has been upgraded to lc 8.2 . I've loaded my processes (which include my custom component) on the new envir

  • Error record

    Hi, Consider that i have 1000 records in flat file. In that the 501th record is error record. Then how will the updation happens in session method and call transaction method? What happens to the record from 502 - 1000. And what will happen to the 50

  • Portal iview xml files

    Hi, Mayby anybody here knows where do the portal iviews xml files are saved in the server? Thanks. Promise to award points... Ruthie.

  • UDF Settings Change By Themselves

    Hello, We have had cases where it seems like our UDF setting change by itself.  We have tried to set our UDF so that the same UDF's appear for each user.  The way we made this change is in the UDF Settings is we created a category called Hidden.  We