Working with SAML token message protection policies in JCS-SAAS extension

Hi
I am trying to invoke a fusion apps webservice(Journal import ADF service) , for that I have to use client side policy as:-
oracle/wss11_saml_token_with_message_protection_client_policy.
1) I have imported certificate into my client keystore and cacerts and using them in my client code. I have mode both defaul-keystore.jks and cacerts to JCS file systema and then using them in my client code.
keytool -importcert -trustcacerts -file "C:\Fusion_cloud\JournalImportServiceTester\fap1530\JournalImportSC.cer" -alias journalimportsc -keystore "C:\Fusion_cloud\JournalImportServiceTester\fap1530\default-keystore.jks"
keytool -importcert -trustcacerts -file "C:\Fusion_cloud\JournalImportServiceTester\fap1530\JournalImportSC.cer" -alias finutilsc -keystore "C:\Oracle\Middleware\jdk160_24\jre\lib\security\cacerts"
I am using CLI (Command Line Interface) with JCS SDK to do few administration tasks in JCS, Tried to use to createCredentials in my JCS trial version as below and receiving following error.
1) java -jar %SDK_HOME%/lib/javacloud.jar set-credential -user cloudusername -id inaccenturetrial00450 -si javatrial2180 -dc us2 -key keystore-csf-key -ku owsm -kp welcome1
[ERROR] - Permission denied for system credential oracle.wsm.security , keystore-csf-key
2) java -jar %SDK_HOME%/lib/javacloud.jar set-credential -user cloudusername -id inaccenturetrial00450 -si javatrial2180 -dc us2 -key enc-csf-key -ku orakey -kp welcome1
>>>> Created OK
3) java -jar %SDK_HOME%/lib/javacloud.jar set-credential -user cloudusername -id inaccenturetrial00450 -si javatrial2180 -dc us2 -key sign-csf-key -ku orakey -kp welcome1
[ERROR] - Permission denied for system credential oracle.wsm.security, sign-csf-key
Can you please suggest, how can I setup my JCS-SaaS extension to use this client policy oracle/wss11_saml_token_with_message_protection_client_policy.
Apart from the above are there any steps needs to be done to configure trust between client and server(Fusion Apps Cloud instance).
Thanks in advance
Samy

Hi Samy
Are you trying to propagate identity to an associated FA instance that belong to the same identity domain? If so, You dont need to configure anything.  You can directly use the policy oracle/wss11_saml_token_with_message_protection_client_policy in your client. We have a sample in the SDK that showcases this.
Thanks
Vel

Similar Messages

  • Webmail no longer works with FF4. Message"you have undefined new mail in your inbox " but won't open

    webmail no longer works with FF4. Message"you have undefined new mail in your inbox " but won't open

    webmail no longer works with FF4. Message"you have undefined new mail in your inbox " but won't open

  • HT203175 While trying to use my iTunes library it will suddenly stop working with the erro message Runtime error R6025 pure virtual function call.  HELP!!!

    While trying to use my iTunes library it will suddenly stop working with the error message Runtime error R6025 pure virtual function call.
    Help???

    Just responded to this in another thread (note we used Captivate 7 so it might be a different error).
    We found that when we created files with embedded swf files that existed ABOVE widgets in the timeline, when someone else tried to open our file it broke/we got the runtime error. The original person could still open it for a time, but eventually the cache would clear and they couldn't.
    However, if we ensured swf files are BELOW widgets in the source files, it didn't break. In fact, if we found one that was breaking and got the author to move the swf file on the timeline, it would start working for others.
    STRANGE! Let me know if this works for you to!

  • OWSM 11g: Difference between Message Protection Policies

    Hi all,
    I am using OWSM11g for securing web services. There are two separate policies provided oracle/wss10_message_protection_service_policy and oracle/wss10_x509_token_with_message_protection_client_policy. How does these policies differ in providing message protection?
    Additionally, I have the documentations provided by oracle regarding OWSM11g. In case, there are some addtional resources or tutorials for OWSM 11g which might help me please suggest me the same.
    Thanks in advance.

    Hi,
    In OWSM 10g there was concept of Server Agent and Client agents.The server agents were attached with the service providers and client agents were attached with client consumers.Similarly there are two types of policies available with 11g for service endpoints.One is attached with the service provider endpoint and one is attached with the consumer.
    For e.g- If there is a credit validation webservice which requires the payload to be signed and encrypted,then u attach oracle/wss10_message_protection_service_policy with it and if there is a SOA composite invoking this service,then u attach oracle/wss10_message_protection_client_policy with it.For each of the service side and client side policies some configurations/settings can be modified or overridden.
    Now oracle/wss10_message_protection_service_policy is message integrity and confidentiality service policy implementing WS-1.0 security standards.While oracle/wss10_x509_token_with_message_protection_client_policy is X509 token based authentication with message protection client policy implementing WS-1.0 security standards.
    Hence while implementing security always use the same dual pairs for service and client policies.Currently there are not many samples available but the 'Security and Administrator’s Guide for Web Services' guide is good documentation to start with for configuring security using OWSM 11g.
    Rgds,
    Mandrita

  • Apple ID not working with facetime and messages what to do

    I'm not sure when this issue occurred but I cannt use my facetime and messages at all. My apple ID works with everything else but facetime, messages and oh yeah icloud . I have changed my ID like three times and I also looked at my DSM but nothing. I'm frustrated because I live in Trinidad where there is no apple store to correct this issue. Please help someone!!!!!

    Using FaceTime http://support.apple.com/kb/ht4319
    Troubleshooting FaceTime http://support.apple.com/kb/TS3367
    The Complete Guide to FaceTime + iMessage: Setup, Use, and Troubleshooting
    http://tinyurl.com/a7odey8
    Troubleshooting FaceTime and iMessage activation
    http://support.apple.com/kb/TS4268
    Using FaceTime and iMessage behind a firewall
    http://support.apple.com/kb/HT4245
    iOS: About Messages
    http://support.apple.com/kb/HT3529
    Set up iMessage
    http://www.apple.com/ca/ios/messages/
    Troubleshooting Messages
    http://support.apple.com/kb/TS2755
    Setting Up Multiple iOS Devices for iMessage and Facetime
    http://macmost.com/setting-up-multiple-ios-devices-for-messages-and-facetime.htm l
    FaceTime and iMessage not accepting Apple ID password
    http://www.ilounge.com/index.php/articles/comments/facetime-and-imessage-not-acc epting-apple-id-password/
    Unable to use FaceTime and iMessage with my apple ID
    https://discussions.apple.com/thread/4649373?tstart=90
    For non-Apple devices, check out the TextFree app https://itunes.apple.com/us/app/text-free-textfree-sms-real/id399355755?mt=8
     Cheers, Tom

  • Will it work with my Kaspersky Virus Protection -it keeps exluding that when I want to update my version

    I have been using Firefox for awhile with my Kaspersky Virus Protection - but this time, when I'm ready to update to Firefox 4, it says it will disable that program - is that correct?

    Check with Kaspersky to see if they have an updated version of their extensions available for Firefox 4. <br />
    http://forum.kaspersky.com/

  • My apple ID is not working with Facetime or Messages, but works on the apple site and other applications. Why is this happening?

    My Messages and Facetime applications say my apple ID or password is incorrect when it works for other applications including icloud, and works on the apple id website. I have reinstalled Mountain Lion upon request of an apple advisor but there is still no luck and other apple IDs work on the applications. Why is this happening?

    Yes, you will need to call Apple at this point for further assistance.
    Apple ID: Contacting Apple for help with Apple ID account security

  • Working with MRP Exception Message

    Hi Team,
    In MD04, i am getting exception messages like below.
    20 - Cancel the Process
    15 - Postpone the process
    10 - Bring Process Forward
    I have already read the SDN postings and also the below link.
    What is rescheduling and how does it work - ERP Manufacturing (PP) - SCN Wiki
    But question is, Instead of MRP raises this exception message like "10 - Bring Process forward". This exception message proposes new start date for the planned order.
    Q1: Instead of raises this as exception message, during MRP run, the planned order start date can be directly modified by the system know?
    Q2: On daily basis, How to act on this MD04 exception messages? How the MRP Controller should act on this exception messages? Should the planner need to modify the planned order dates manually as proposed by the exception message?
    Q3: Do w have any mass transaction to act on this exception message?
    Thanks

    But question is, Instead of MRP raises this exception message like "10 - Bring Process forward". This exception message proposes new start date for the planned order.
    Exception message '10' is raised to 'firmed' receipts - not planned receipts. MRP cannot change the firmed receipts (exception - roll-forward periods), hence adjustment in case of this message is out of the question. Rest assured, the planning run does adjust the receipt as much as possible.
    Q1: Instead of raises this as exception message, during MRP run, the planned order start date can be directly modified by the system know?
    Have you seen exception message '10' to a planned order which is not fixed/firmed? System adjusts when possible.
    Q2: On daily basis, How to act on this MD04 exception messages? How the MRP Controller should act on this exception messages? Should the planner need to modify the planned order dates manually as proposed by the exception message?
    This may involve many manual decision from the planners and should not be automated. You can help out a planner through reports, but the decision should not be taken automatically.
    If you find it interesting you can go through responses from Dogboy 49 and myself in the threads shared below:
    Handling of MRP Exception Message
    md04 exception
    Q3: Do w have any mass transaction to act on this exception message?
    No, you may think of developing something using BAPI_MATERIAL_STOCK_REQ_LIST or  MD_STOCK_REQUIREMENTS_LIST_API function modules and providing hyperlinks to the users so that they can directly be inside the corresponding change transaction according to the MRP element.
    However, 10, 20 and 15 all of these three exception messages come due to rescheduling for the firmed receipt elements. In MD07 you can get a collective overview of number of these messages in the exception group 07 (standard).
    Best Regards.
    Rajen

  • 2G phone not working with "Dead iPhone" message

    There's an old 2G iphone my son was using, when the phone part just stopped working; it says "no service".  As far as I can tell, everything else is just fine. I used the sim card in a different phone so it's not the card.  With the phone plugged into computer, the device actually comes up as "Dead iPhone" as well as when looking in phone menu under "about", the same "Dead iPhone" descriptor.  Any suggestions on what to try?

    Where do you see "Dead Iphone?"
    It is likely that you're looking at the name of the iPhone.  You see that because someone wanted to title the bacups that are resident on the computer.
    The status of the service is an entirely separate issue.  Contact your carrier, to make sure the SIM card is active on the network.

  • Working with Air and password protected SQLite

    Hello,
    How can I connect an Air application to an existing password protected SQLite db?
    Thanks

    So, guess this is impossible then ...
    What are my options to develop a secured DB based application on Flex/Air?

  • OEG and OSB - username token with message protection

    Salve,
    I've got a simple example of OEG / OSB integration up and running -
    Scenario 1 - username token validation works fine
    Scenario 2 - username token /message protection has issues.
    I register the web service with OEG and the security policy is auto-generated. I configure as appropriate but get the error -
    No asymmetric key foundERROR12/5/11 1:46 PM signature error: not specified/not specified, key is not found:
    A doc detailing all the steps I took is available at -
    https://docs.google.com/open?id=0B7YrnfO7h717ODI5NGExODAtNjI0Yy00ZGE0LWI3NzQtZTg4YjM2ZDQzOWQ1
    any help --> greatly appreciated.

    Replied offline as forum was down. Issue sorted.
    Many thanks for detailed analysis.

  • AIM not working with messages

    Hello,
    My AIM account has not worked with ichat or messages in the last few months. I called Apple about this over 3 weeks ago and they said their is a glitch in the lion software and aim? However, all of my friends have no problem with their aim accounts working. I have downloaded AIM and everything works. It just does not work in ichat/messages after re-setting the password and re-adding the account. Help!

    Yes,  enabling and disabling the AIM account (sometimes it takes doing it a few times) seems to work.  And I found elsewhere that opening activity monitor and killing off the imagent process (which then automatically relaunches) seems to work as well.  Those workarounds are not permanent solutions for me though.  As soon as the iMac is either restarted or shut down and then turned back on...  Messages seems to be right back at square one with not being able to connect to AIM unless I use the workaround again.  I just hope Apple can figure out what is going on and fix the app before it goes final.

  • Message protection (Encryption) through OWSM in BPEL process 11g

    What is my requirements ?_
    I want to encrypt the messages in BPEl process using OWSM message protection policies
    What is the configuration i am using ?_
    Weblogic Server 10.3.3
    Soa Server 11.1.1.3.0
    Oracle JDeveloper 11.1.1.3.0
    What I have done so far ?_
    (1) Created one Sync BPEl process (CalledAddition) which take two input and add them and give the output
    (2) Created one more Sync BPEL process (CallerProcess) which takes two input and call the above created bpel process
    (CalledAddition) and get the response back as addition of two number.
    Now I want to Add OWSM Message protection policy to Encrypt the message in Main BPEl process(CallerProcess) and the called service (CalledAddition) decrypt the message upon invocation. It is a very simple scenario.
    For this purpose I have done the following OWSM Policy Configuration:
    (1) Created a java keystore as follows
    keytool -genkey -keyalg RSA -keystore test_keystore.jks -storepass welcome1 -alias client_key -keypass welcome1 -dname "CN=Client, OU=WEB AGE, C=US" -keysize 1024 -validity 1460
    (2) Copy the keystore (test_keystore.jks) to location domain/config/fmwconfig.
    (3) Go to EM console/WeblogicDomain/Security/Credential and delete the map oracle.wsm.security and then again created it, with no key inside.
    (4) Go to EM console/WeblogicDomain/Security/SecurityProviderConfiguration and configure the above created keystore as follows:
    (i) Keystore Type=JKS, Keystore Path=./test_keystore.jks, password=welcome1, confirmPassword=welcome1
    (ii) Signature Key:
    Key Alias=client_key, Signature Password=welcome1, confirmPassword=welcome1
    (iii)Encryption Key:
    Crypt Alias=client_key, Crypt Password=welcome1, confirmPassword=welcome1
    (5) Now restart the server (both Weblogic and SOA server)
    (6) Now again go to EM console/WeblogicDomain/Security/Credential and open expand the oracle.wsm.security map, Automatically
    the following keys are made inside it:
    (i) sign-csf-key
    (ii) enc-csf-key
    (iii) keystore-csf-key
    Created one more key inside it explicitly:
    (iv) basic.credentials with username=weblogic and password=welcome1
    (7) Go to EM console/WeblogicDomain/WebServices/Policy and cretaed the following policies:
    oracle/wss11_message_protection_service_policy:
    (i) select policy oracle/wss11_message_protection_service_policy from list and click on create like button. This will create a copy of the policy with different name.
    (ii) Give the new name as oracle/wss11_message_protection_service_policy_Copy ( which is by default)
    (iii) Local Optimization = off and enabled is checked
    (iv) Attachment Attributes …..
    Applies To=Service BIndings and Service Category=Service Clients
    (v) Assertions …..
    Select middle assertion MessageProtection and Advertised=checked and Enforced=checked
    (vi) Configuration....
    Add following Configure properties, if present already edit them as follows:
    (a) name=keystore.enc.csf.key, property set=standard-security-properites, value=enc-csf-key, Type=Optional
    (b) name=keystore.sig.csf.key, property set=standard-security-properites, value=sign-csf-key, Type=Optional
    (c) name=role, property set=standard-security-properites, Default=ultimateReceiver, Type=Optional
    (v) Setting.........
    Done the following setting
    - Message Security/include timestamp=unchecked
    - Message Signing Setting/Include entire body=unchecked (since we need only encryption, no signing of message)
    - Message Encrypt Setting/include entire body=checked
    (vi) Validate and save
    (vi) Thus a new policy is made in domain with name oracle/wss11_message_protection_service_policy_Copy
    Simmilarly create oracle/wss11_message_protection_client_policy:
    (ii) Give the new name as oracle/wss11_message_protection_client_policy_Copy ( which is by default)
    (iv) Attachment Attributes …..
    Applies To=Service BIndings and Service Category=Service Endpoint
    (vi) Configuration....
    Add following Configure properties, if present already edit them as follows:
    (a) name=keystore.recipient.alias, property set=standard-security-properites, value=client_key, Type=Optional
    (b) name=role, property set=standard-security-properites, Default=ultimateReceiver, Type=Optional
    (vi) Thus a new policy is made in domain with name oracle/wss11_message_protection_client_policy_Copy
    Rest of the steps(i,iii and v) are same as described above in case of service policy
    After creating the policies in domain attach them to the bpel process as follows:
    (1) Go to SOA project (CallerProcess) in EM console.
    (2) Click on policy tab
    (3) First attach the client policy (oracle/wss11_message_protection_client_policy_Copy) to the endpoint of the process CallerProcess.
    (4) Then attach the service policy (oracle/wss11_message_protection_serivce_policy_Copy) to the reference in CallerProcess which is calling CalledAddition.
    (5) Now test the process (CallerProcess)
    pass input say 10 and 20 in input
    Upon testing it give the following error_
    Web Service invocation Failed:
    oracle.sysman.emSDK.webservices.wsdlapi.SoapTestException: InvalidSecurity : error in processing the WS-Security security header
    I have made all thing clear. I have gone through several documents but unable to find the solution. If anyone please help me in this case.
    Thanks

    I have followed same steps and getting same errror.
    User 868153, were you able to resolve this issue.
    Appreciate your help.
    Thanks

  • Essbase services abnoraml shutdown with Get token for user

    Hi,
    We are facing essbase services abnormal shutdown, with a .xcp file
    in XCP file showing below given error, for this issue we have added __GETUSERTOKEN TRUE value in our .cfg files but it's not working.
    Exception Log File: /ap01/gema/hyperion/essbase/log00042.xcp
    Current Thread Id: 42949552
    Signal Number: 0x11=Segmentation Violation
    Signal Code: 0x19178024=Unknown
    8:23 PM
    Thread Id 42949552:
    Request Name: Get token for user
    Database Name:
    User Name:
    Start Time: Fri Jun 15 08:20:39 2012
    End Time: Pending
    Please suggest some solutions on this.
    Regards,
    Srinivas

    See if these doc help you
    E-IB: SAML Authentication Failed For Service Operation XXXX. (158,456) error when invoking PS web service with SAML token [ID 1464489.1]
    https://support.oracle.com/CSP/main/article?cmd=show&type=NOT&doctype=PROBLEM&id=1464489.1
    E-IB: Setup and Troubleshooting Guide for SAML Inbound Security [ID 1322740.1]
    https://support.oracle.com/CSP/main/article?cmd=show&type=NOT&doctype=HOWTO&id=1322740.1

  • Trying to get a 3rd Party Router working with BT I...

    Hi,
    I'm trying to move away from the HHub5 on our FTTC BT Infinity connection (40Mb/s). Eventually I settled on a TP-Link WDR 3600 N600 - the flavour which is happy to talk to cable modems and take an OpenWRT install.
    So far I've hooked up a BT OpenReach "white box" modem using the HHub's RJ11 lead, going from the DSL filter into the OpenReach modem's DSL socket.  The modem's DSL LED lights up solid green - which I presume is good?  The TP-Link router is up & running fine with OpenWRT installed, I can connect to it over WiFi and I've hooked up its WAN connection to the OpenReach modem's LAN1 socket (LAN2 is blanked out).
    But whatever I put in the router's PPPoE settings I just can't get an internet connection to come up.  So far I've used '[email protected] (as it's set on the HHub) and a few other suggestions from the forums including 'anything you like' @btinternet.com and @btbroadband.com - nothing seems to get the connection going.
    Is there something I've missed or can anyone suggest a solution?
    Many thanks,
    Steve
    Solved!
    Go to Solution.

    Sorry to answer my own question, but in case it helps anyone in the future:
    I had to put my username in the username AND password fields - same details in both.  I've not seen this written  anywhere online, everyone says to leave the password field blank as it's unused.
    So to recap - this is what got my TP-LINK WDR3600 (OpenWRT based) router working with Infinity: stick [email protected] in the PPPoE usernamd AND password fields.
    Steve

Maybe you are looking for

  • SRM 7.0 PO fields edit

    Hi Guru, I am new to SRM but I have this problem. I have created a Shopping card. When I go to Buyer Professionnal, search for PO number, when I displays I want I want a specific text like 'Hello World' to show up in 'Note to Supplier' field. How can

  • Display Linked Data Source

    I created a Linked Data Source in SharePoint Designer 2010.  Is there any way to display the Link Data Source with a web part outside of SharePoint Designer?  I do not have enough rights to create a web part page in Designer.   Thanks! David L. Crook

  • Thread bottleneck?

    Hi -           We have an application that is loading tens of thousands of xml messages           into a JMS queue backed by Oracle, and committing every 100. MDB's pick up           from that queue and start their own UserTransactions managing from

  • "Could not load iCloud preference pane." after changing password

    I am running a Mac Pro (Mid 2010), OS X Yosemite version 10.10.1. I recently had to change my iTunes (& etc.) password on my iPhone, and since then every so often throughout the day this computer pops up a window saying "this Mac can't connect to iCl

  • SQVI transaction

    Hi, All, We were using the SQVI transaction to make some queries in the system but we had some quesitons. How do we make the query we save able to be accessed by specific or all users? Is there a way to have users be able to run the query without giv