WL 6.1 LDAPRealm -- Can't see users, groups through console

I'm having some troubles setting up an LDAPRealm correctly. I've been
searching through the ng, and have read the cnfgsec.html doc closely
several times, but must be missing something. Here is the situation:
Running WLS 6.1 on Win2k. What I want to do is create an LDAPRealm for
authentication. Right now I have Iplanet/Netscape Directory server
6.01 with the default schema. I have set up an LDAPRealm through the
console.
ie Security -> Configure a new LDAP Realm V1 (Deprecated)... uses
class weblogic.security.ldaprealmv1.LDAPRealm. Filled out the
appropriate user groups entries:
Group DN:ou=topologymanagement,o=netscaperoot
Group Name Attribute: cn
Uncheck Group is Context
Group Username attribute:groupOfUniqueNames
User Auth: bind
User Password Attribute: userPassword
User DN: ou=SpecialUsers
Username attribute: uid
Then created the appropriate caching realm. The resulting related
changes to config.xml are as follows:
<LDAPRealm AuthProtocol="simple"
Credential="eNcRyPtEdPaSsWoRd"
GroupDN="ou=topologymanagement,o=netscaperoot"
GroupIsContext="false" GroupNameAttribute="ou"
GroupUsernameAttribute="groupOfUniqueNames"
LDAPURL="ldap://machineName:389"
Name="MyLDAP Realm V1 (Deprecated)" Notes="hi"
Principal="Directory Manager" UserDN="ou=SpecialUsers"
UserNameAttribute="uid" UserPasswordAttribute="userPassword"/>
Now, I bounce the weblogic server and it comes up no complaints. But
when I go to the console, to Security->Groups (mydomain> Realms>
wl_default_realm> Groups is the title), I do not see any of the groups
listed in the Directory server. Same for the users. Checking the
directory server logs, I see the following each time I start the
console:
[22/May/2002:15:34:12 -0400] conn=0 op=20 SRCH base="cn=config"
scope=0 filter="(|(objectClass=*)(objectClass=ldapsubentry))"
attrs="nsslapd-accesslog nsslapd-accesslog-list"
[22/May/2002:15:34:12 -0400] conn=0 op=20 RESULT err=0 tag=101
nentries=1 etime=0
So it looks like it is connecting. Any suggestions, tips or pointers
would be greatly appreciated. Does anybody have a doc of a simple walk
through setting up LDAP realms? I've been unable to find a tutorial.
I've read Weblogics docs, but I need an example to look at to put all
the pieces together. Thanks for the help
-k

i got ldapv1 able to work with this following config.
" <LDAPRealm AuthProtocol="simple" Credential="{3DES}nJfj4lzp6IM="
GroupDN="o=abc.com,ou=Groups" GroupIsContext="false"
GroupUsernameAttribute="uniquemember"
LDAPURL="ldap://localhost:389"
Name="MyLDAP Realm V1 (Deprecated)"
Principal="uid=admin, ou=Administrators,ou=TopologyManagement,
o=NetscapeRoot"
UserAuthentication="bind" UserDN="o=abc.com,ou=people"
UserNameAttribute="uid"/>
thx
kiran
kj" <[email protected]> wrote in message
news:[email protected]...
I'm having some troubles setting up an LDAPRealm correctly. I've been
searching through the ng, and have read the cnfgsec.html doc closely
several times, but must be missing something. Here is the situation:
Running WLS 6.1 on Win2k. What I want to do is create an LDAPRealm for
authentication. Right now I have Iplanet/Netscape Directory server
6.01 with the default schema. I have set up an LDAPRealm through the
console.
ie Security -> Configure a new LDAP Realm V1 (Deprecated)... uses
class weblogic.security.ldaprealmv1.LDAPRealm. Filled out the
appropriate user groups entries:
Group DN:ou=topologymanagement,o=netscaperoot
Group Name Attribute: cn
Uncheck Group is Context
Group Username attribute:groupOfUniqueNames
User Auth: bind
User Password Attribute: userPassword
User DN: ou=SpecialUsers
Username attribute: uid
Then created the appropriate caching realm. The resulting related
changes to config.xml are as follows:
<LDAPRealm AuthProtocol="simple"
Credential="eNcRyPtEdPaSsWoRd"
GroupDN="ou=topologymanagement,o=netscaperoot"
GroupIsContext="false" GroupNameAttribute="ou"
GroupUsernameAttribute="groupOfUniqueNames"
LDAPURL="ldap://machineName:389"
Name="MyLDAP Realm V1 (Deprecated)" Notes="hi"
Principal="Directory Manager" UserDN="ou=SpecialUsers"
UserNameAttribute="uid" UserPasswordAttribute="userPassword"/>
Now, I bounce the weblogic server and it comes up no complaints. But
when I go to the console, to Security->Groups (mydomain> Realms>
wl_default_realm> Groups is the title), I do not see any of the groups
listed in the Directory server. Same for the users. Checking the
directory server logs, I see the following each time I start the
console:
[22/May/2002:15:34:12 -0400] conn=0 op=20 SRCH base="cn=config"
scope=0 filter="(|(objectClass=*)(objectClass=ldapsubentry))"
attrs="nsslapd-accesslog nsslapd-accesslog-list"
[22/May/2002:15:34:12 -0400] conn=0 op=20 RESULT err=0 tag=101
nentries=1 etime=0
So it looks like it is connecting. Any suggestions, tips or pointers
would be greatly appreciated. Does anybody have a doc of a simple walk
through setting up LDAP realms? I've been unable to find a tutorial.
I've read Weblogics docs, but I need an example to look at to put all
the pieces together. Thanks for the help
-k

Similar Messages

  • HT4798 I'm seeing the above problem, how can i open "Users&Groups" if i can't login?

    I'm seeing the above problem, how can i open "Users&Groups" if i can't login?

    If the system is associated with an Apple ID, and you know that account password, the Apple ID can be used to reset your user account password.
    Otherwise, boot into Recovery by holding down the key combination command-R at startup. Release the keys when you see a gray screen with a spinning dial.
    When the OS X Utilities screen appears, select Utilities ▹ Terminal from the menu bar.
    In the Terminal window, type this:
    resetpassword
    That's one word with no spaces. Then press return. A Reset Password window opens.
    Select your boot volume if not already selected.
    Select your username from the menu labeled Select the user account if not already selected.
    Follow the prompts to reset the password. It's safest to choose a password that includes only the characters a-z, A-Z, and 0-9.
    Select  ▹ Restart from the menu bar.
    You should now be able to log in with the new password, but you won't be able to unlock the Keychain. If you've forgotten the Keychain password (which is ordinarily the same as your login password), there's no way to recover it. You’ll need to reset your keychain in the preferences of the Keychain Access application.

  • Can't access Users & Groups in System Preferences :(

    I can't access Users & Groups in System Preferences please help thanks

    Check the following:
    First, do you see the "User and Group" icon?
    If not, open the "presentation" menu and look under the "personalize" option to see if the icon is uncheck.
    Second, try to set a new account and see if you can access it from that account.
    Repair disk permission

  • I can't see the group ripper in premiere pro after 2014.1 update, and 2014.2 did not fix.

    Please someone help me fix this I am literally going crazy as I have to edit in my notebook and am constantly hooking it up to different monitors, which calls for a different workspace most of the time. Thanks in advance.
    To be clear I can not see the group ripper and therefore have to reset my workspace every time I want to redock an undocked panel group.

    Click on the name and drag.

  • I can't see pdf files through safari

    i can not see pdf files through safari

    I had the same problem after making Adobe the reader for pdf. Fixed it by
    1) removing the Adobe plug-in from the Internet Plug-Ins file in the Library.
    2) restarting Safari.
    Back to normal.
    Bob

  • Provide Rights to User Group through SDK

    hello all,
    Please help me to provide some rights or role to the User Group through using Business Objects SDK classes not using
    setting in CMC.
    please help me.
    Thanks,
    Prashant Joshi

    Hi Prashant,
    There are few samples available.
    The JSP sample below shows setting advanced rights on a user group for root folder using Enterprise SDK.
    https://boc.sdn.sap.com/node/18903
    Another sample in set_Rights folder in sample collection at following link. Similar to above samples but it sets rights on a user not a user group and also shows how to set permissions on subfolders.
    https://boc.sdn.sap.com/node/3211
    Tks
    Aasavari

  • Can only see User Management in Admin Tools

    I configured an LDAP realm and included the required admin group to access
    the Administration Tools. However, the only thing I can see in
    Administration Tools is User Management. Why is that?

    Wendy,
    Would it be possible for you to send us a file from your LDAP directory
    server? Please forward this information to the support case you have open.
    In the \iPlanet\Servers\slapd-yourhost\config directory.
    Send the dse.ldif file.
    Basically what we want to do is to compare the user and group dn values
    specified in the vlvBase lines with your config.xml. Also grab the
    string that starts with creatorsname ... look for something like
    creatorsName:
    uid=admin,ou=administrators,ou=topologymanagement,o=netscaperoot
    The principal value in the config.xml will be the creatorsName string.
    Set the principal string in config.xml should be something like
    Principal="uid=admin,ou=Administrators,ou=TopologyManagement,o=NetscapeRoot"
    unless your iPlanet schema has been changed.
    So, in the config.xml LDAPRealm definition explicitly set Group is context.
    GroupIsContext="false"
    Set the AuthProtocol to simple.
    Your config.xml LDAPRealm definition should have 13 fields and look
    something like:
    <LDAPRealm
    AuthProtocol="simple"
    Credential="password"
    GroupDN="o=beasys.com, ou=Groups"
    GroupIsContext="false"
    GroupNameAttribute="cn"
    GroupUsernameAttribute="uniquemember"
    LDAPURL="ldap://myhost.beasys.com:389"
    Name="myLdapRealmV1"
    Principal="uid=admin,ou=Administrators,ou=TopologyManagement,o=NetscapeRoot"
    SSLEnable="false"
    UserAuthentication="bind"
    UserDN="o=beasys.com, ou=People"
    UserNameAttribute="uid"/>
    -- Jim
    Wendy Kajiyama wrote:
    Hi,
    iPlanet 5.0, no service pack.
    I got the user and group DN from our Network Admin.
    "Jim Litton" <[email protected]> wrote in message
    news:[email protected]...
    Wendy,
    Can you also supply the vendor and version number of your directory
    server?
    I was looking at your config.xml from your support case and I am
    unfamiliar with the user DN and group DN strings you are using.
    Where did you find the syntax for those strings? Is that particular
    string syntax documented somewhere on the LDAP vendors site?
    Jim Litton
    Developer Relations
    Ture Hoefner wrote:
    Hello Wendy,
    I suspect a configuration problem in the LDAPRealm, but it is possible
    that you have a P13N-only license. That is probably a long-shot because
    I
    don't know if we sell those any more. You are using Portal 7.0, right?
    I can try to help... can you answer these questions:
    * which version?
    * After you log into as "administrator" (who is a member of
    "SystemAdministrator"), can you access the Group Management tools and
    see
    the "SystemAdministrator" group and the list of users who belong to that
    group?
    * Do the all of the users and groups that you see match what you have
    in
    your LDAP server?
    "Wendy Kajiyama" <[email protected]> wrote in message
    news:[email protected]...
    Hi Ture,
    Thanks for your reply. Unfortunately, after contacting support and
    receiving the patch for LDAP I am still having the problem of not being
    able
    to see the icons in Admin Tools.
    Any other ideas?
    Thanks,
    wendy
    "Ture Hoefner" <replyto@newsgroup> wrote in message
    news:[email protected]...
    Hi Wendy,
    Which version?
    After you log into as "administrator" (who is a member of
    "SystemAdministrator"), can you access the Group Management tools and
    see
    the "SystemAdministrator" group and the list of users who belong to
    that
    group? Does it match what you have in your LDAP server? If you cannot
    list
    members of groups in your Portal JSP admin tool then contact support
    and
    ask
    for the patch that fully enables WLS's LDAPRealm for use with Portal
    (it
    is
    CR070870 for Portal 4.0, I don't know if there is a patch for 7.0, or
    if
    it
    is included in a SP for 7.0...)
    If you are able to list the users in a group then make sure you have
    the
    group "SystemAdministrator", not "SystemAdministrators".
    I've used delegated portal administration with LDAPRealm for 7.0 so I
    know
    it works. I suspect a configuration issue. I will try to help you
    figure
    it out.
    "Wendy Kajiyama" <[email protected]> wrote in message
    news:[email protected]...
    yup, i set up LDAP to have the required administrator groups and log
    in
    the
    admin tools as administrator which is a user in the
    SystemAdministrator
    group.
    "kurt c" <[email protected]> wrote in message
    news:[email protected]...
    could this not be a permissions issue? are you logged in as
    'administrator'?
    "Wendy Kajiyama" <[email protected]> wrote:
    I checked to see if ebusiness.jar was in my application and it's
    there.
    Any
    other ideas?
    Thanks!
    wendy
    "Peter Laird" <[email protected]> wrote in message
    news:[email protected]...
    Wendy,
    You may be seeing CR081150, which is a bug report regarding the
    removal
    of
    ebusiness.jar
    from your application. If you remove this JAR, the admin tool
    fails
    to
    load certain
    EJBs which cause it to only display more than the user tool. The
    workaround is
    to put ebusiness.jar back into your applicaiton. If this is
    unacceptable,
    contact
    Support and they will work with you.
    Cheers,
    PJL
    "Wendy Kajiyama" <[email protected]> wrote:
    I configured an LDAP realm and included the required admin group
    to
    access
    the Administration Tools. However, the only thing I can see in
    Administration Tools is User Management. Why is that?

  • Sending form via email - can't see user responses in returned PDF

    I created a form in Form Central.  I chose "save as PDF form" and saved it on my computer.  I attached this form to an email and asked employees to fill out and send back to me as a pdf.  When people email me back their filled in form, I can only see the responses when I click on each individual box.  When I print the form, the responses do not print.
    Would appreciate help since I distributed the forms to the company, and realized there was a problem as responses started to come in today (I only tested it on my computer and had no issues)
    I would appreciate any help you can give.  Especially:
    Why is this happening? 
    How do I prevent this in the future?
    Is there anything I can do to resolve the issue, without having to send out an updated form?
    Christine

    The users filling out your PDF are not using Adobe Acrobat or the Free Adobe Reader to fill out your form - FormsCentral forms have to be filled out in Adobe Reader or Acrobat.
    Also, make sure that you are also using Adobe Reader or Adobe Acrobat to view those PDFs.
    The way to resolve this is to instruct your users to use Adobe Reader to fill out the form.
    This FAQ touches on the issue, but mostly related to the Submit button not working, however the issues you describe are caused by not using Adobe Reader or Acrobat as well: http://forums.adobe.com/docs/DOC-2653
    Thanks,
    Josh

  • Can't see /Users/home/Library in Finder

    I can see /Users/home/Library in xterm, but not finder, why?
    iMac - Lion

    Because it's invisible. To make it permanently visible:
    Open the Terminal application in your Utilities folder and paste the following:
    chflags nohidden ~/Library
    Press RETURN.

  • Can't see Users after binding with Active Directory

    Hi,
    I have a clean install of Mountain Lion Server and I have bound it with Windows 2003 Servers Active Directory. All is working, but I can't see the Ad users in Server app so that I can't edit it.
    I can see it only over Directory Utility.
    Can anybody help me that I can see the AD Users in Server app so that I can edit it.
    And knows anybody how to change the AD users home folder so that I can have it on my Mountain Lion server?

    Try the following user tip:
    Troubleshooting issues with iTunes for Windows updates

  • Can't "see" User account name in the GUI anymore ...

    Hello Community
        Using WS2012 I created user account in AD.  I right clicked a user account and chose "Move".
        The problem is my finger slipped and hit other keys.
        Now I can't see the user account anymore.
        When I run the following command:
            get-aduser -filter 'Name -like "user1"'  I get the results below:
                DistinguishedName : CN=user1,DC=<DomainName>,DC=<SomeName>,DC=us
        The problem is how can I "see" what folder name, OU or the group's name that user1 resides at in
    the GUI?
        Thank you
        Shabeaut

    If I understand well, you were able to get the user DN. Based on the name, the user account should be directly under your domain (Not under an OU or a Container). So, use ADUC and select your domain. Once done, you should be able to see the user account.
    This posting is provided AS IS with no warranties or guarantees , and confers no rights.
    Ahmed MALEK
    My Website Link
    My Linkedin Profile
    My MVP Profile

  • Can't open Users & Groups preference pane?

    I am only user on my MBA. I was going to add wife as another user, but each time I try open User and Groups in System Preferences I get:
    Preference Error
    Could not load Users & Groups preference pane.
    I found this post on the same issue. I also recently upgraded to Mountain Lion from Snow Leopard. I tried to follow the suggestion to open via Terminal app by entering /System/Library/PreferencePanes/Accounts.prefPane, but only got response that it is a directory.
    Armando

    1. You have a corrupt user picture.
    2. Read this whole message before doing anything. If you're not sure you understand it, STOP. Get someone with more experience to help you; e.g., by making a "Genius" appointment at an Apple Store.
    3. Back up all data if you haven’t already done so. Before proceeding, you must be sure you can restore your system to the state it’s in now. If you don't have backups, or you don't know how to restore from them without being able to log in, STOP.
    4. Triple-click anywhere in the line below on this page to select it:
    /System/Library/CoreServices/Directory Utility.app
    Rght-click or control-click the highlighted text and select
    Services ▹ Open
    from the contextual menu.* The application Directory Utility will open.
    5. In the Directory Utility window, click the lock icon and authenticate. Select the Directory Editor tool in the toolbar. Select Users from the Viewing menu in the toolbar, if not already selected. Select your user account in the list. On the right is a list of properties and values. Select the property "JPEGPhoto" and delete it by clicking the minus-sign icondirectly below the property list. There are two such icons in the window. You want the one on the right, not the one on the left.
    CAUTION: Do not click the minus-sign icon on the left, below the user list.
    Then click the Save button in the lower right corner of the window. Quit Directory Utility.
    6. Try again to open Users & Groups. If it still doesn't work, repeat the above steps with any other users you created. You'll need to reset the user pictures. Don't use the same ones.
    7. Besides the users you created, there are many other items in the user list, representing built-in accounts. Don't change those accounts.
    8. CAUTION: There is no "undo" in Directory Utility. If you make a mistake and delete something in the Directory Editor that should not have been deleted, restore your whole system from a backup and start over. I have no other help to offer in that case.
    *If you don't see the contextual menu item, copy the selected text to the Clipboard (command-C). Open a TextEdit window and paste into it (command-V). Select the line you just pasted and continue as above.

  • Macbook can't see time capsule through airport utility; powerbook can.

    This question probably applies to Airport Extremes as well as Time Capsules, but I happened to see it with a new TC.
    My Time Capsule came in yesterday. My plan was to bridge it into my existing network to serve 802.11n over 5ghz. I did the initial setup using a 12" powerbook and it worked fine. I set the Time Capsule in bridge mode and for 802.11n 5ghz, plugged it into my network, and reset. The light on the TC turned green and all looked like it was working. At least, until I tried to connect through my Macbook Pro.
    I installed the Airport Utility software that came with the TC, rebooted, then launched Airport Utility -- and it couldn't find any devices. It can, however, see the Airport's wireless network. After a reboot of the TC, it can also connect to the Airport's wireless network. I can get to the internet and the local network, but cannot see the Airport through Airport Utility and cannot see the Time Capsule disk. It's as if Bonjour is being blocked between my laptop and the Airport. This happens whether I'm connected to the TC wirelessly or wired.
    I've tried restoring to factory defaults and starting over (I still can't see the TC, even after a hard reset) and I've tried a hard reset of the TC (I had to, actually -- it hung during startup several times). In each case, the powerbook can see it, but the macbook can't. I'm out of things to try. If I can't get this resolved soon, I'm going to have to return the TC, since it's useless if I can't access the disk.
    I was planning on upgrading the two computers to Leopard over the weekend, then use the TC for Time Machine for both computers, but if it's not working for Tiger I'm worried that it won't work for Leopard, either.
    Is there any variable anyone knows of that blocks a computer from seeing an base station through the Airport Utility? A non-obvious firewall setting, perhaps, or something that could be blocking Bonjour? Does Airport detection even use Bonjour, or am I on the wrong track?
    Thanks

    An update: I can see the Airport configuration of the TC through my Macbook if I pick File->Configure Other... on the Airport Utility, and then put in the IP address. Which leads me to believe that it's a Bonjour issue, but I haven't figured out more than that.
    Of course, the TC is still useless for Time Machine if I can't get to the disk, so the problem remains.

  • Can't see calander group's or add a new group in ical 5.0 (lion)

    Help.
    Can't add a new group or see my groups when i click on calander in Lion version of ical. Any idea's why?
    Thanks

    Info taken from other discussion threads on Win not recognizing iPhone:
    NOT SEEN IN ITUNES:
    Windows 7 uses a MTP driver instead of the USBAAPL by default, and what you need is an 'Apple Mobile Device USB Driver' which you might not have in 'Universal Serial Bus Controllers' (check it and see).
    Update the driver by expanding 'Portable Devices' from the list, right click Apple iPhone/iPhone and select 'Update Driver Software'. Then select 'Browse My computer...'
    C:\Program Files\Common Files\Apple\Mobile Device Support\Drivers - then hit 'Next'.
    NOT SEEN AS CAMERA:
    Open Device Manager: Right click on My Computer and select Properties from the drop down menu. This will open System Properties as shown below. System Properties opens on the General tab so you will need to click on the Hardware tab.
    Remove iPhone USB Driver: called Apple Mobile Device USB Driver. We want to remove this driver by expanding the list of USB drivers which can be done by clicking the + next to Universal Serial Bus controllers. Now right click on Apple Mobile Device USB Driver and select Uninstall from the drop down menu. A confirmation will require you confirm you want to remove the iPhone USB driver.Click the OK button on the pop up confirmation window which will remove the driver.
    Reinstall iPhone Driver: Once the driver has been removed you should unplug the iPhone from the USB cable. To reinstall the iPhone USB driver plug it back into the USB cable and the reinstalling of the driver will start automatically. There will be numerous pop up messages displayed near the system clock in the lower right corner of your Windows desktop. Once you see the pop up message confirming that your new device is ready to use everything should be working properly again.
    Verify iPhone Camera Detected: Open My Computer now to verify that the iPhone is displayed and you can click on it as you previously were able to do.

  • How can  we see the desktop through a java frame by using JNI?

    How to make a java frame transparent( so that we can see the desktop through it) by JNI? I have seen some code to take a snapshot of the desktop. But is there any code so that the desktop is fully or partially visible through a frame?
    laks

    Please take your time to write full words: "you" instead of "u", "your" instead of "ur". It makes your posts a lot easier to read, especially for those of us who don't have English as their native language.
    You can not really "modify" the behaviour of a method by using a proxy, but you can create a proxy, direct all but one method to the original method and provide a separate implementation for the target method.
    This way you'll have two objects with the same interface (not only in the Java sense, but all methods look the same), but differing behaviour: the original object and the proxy.
    Now if you pass around the proxy instead of the original object, then it'll look as if you changed the behaviour of your object.

Maybe you are looking for

  • How do I use my Time Capsule for backup without making it my router?

    I've always used my Time Capsule as my internet router (paired with my Time Warner modem) and I've also used it to back up my computer.   I just got a new modem, it was a nightmare to set up, and it's supposed to have very fast internet.  It's a Time

  • Installation of Arch (64) in VirtualBox, issues with Xorg

    Hi friends, I want to install Arch (64) in VirtualBox, recent versions both. I did the main installation procedure. But now I want to install X. I did "pacman -S xorg", and "Xorg -configure", and copied the newly created xorg-file to /etc/X11. It cor

  • Hard disc not visable on desktop IMAC

    I used a firewire cable to transfer data from imac OS 9.2 to my new macmini. With the result a floating FW icon for hours, some noise at start. I unplugged the cable and now my hard disk is not working/displaying on my imac. So also no reinstall poss

  • Shift-Arrow in Curves adjustment layer CS6

    In previous verions of Photoshop, when I made a curves adjustment layer, selected the midpoint, then did a shift-arrow adjusstment, it was always in increments of 10. Now in CS6, it is 12 on my machine, 13 and 14 on the two other machines in the offi

  • Has there been any indication that a Service Pack 3 will be released?

    There have been a number of cumulative updates. In the past, there was some caution expressed regarding not applying CUs unless there was a specific issue that the CU addressed. It has been a year since the last Service Pack. The CUs have included qu