Access policies are not trigger for AD

Hello

I have an automatic supply mechanism based on three components:
1 - managers postprocess on create and update user IOM
2 - postprocess adds users to a role, if the user of the IOM is to have access to AD and adds the user to specific roles additional (one for each ad group) based on the information on the profile of the IOM
3 - access policy are carried out for each specific role and create the AD resource and add groups to the resource.

This process works very well when the user is created but is not always works while refreshing (but sometimes it does). It seems that sometimes the fair access policy is not triggered.

I checked and rechecked the process and everything was fine: the fields to the right were envisaged, the process was running and adding the user to specific roles, but later groups were not added to the resource.

I decided to 'remove' (political access cannot be removed, so I've just configured to be triggered to dummy roles) strategies to access existing and created again exactly as before and it worked... but only for a time. Some time later, the same problem occurred.

This time, I don't have the patience as well (I have 20 roles and access 20 policies). I me roaming on a printout of group access contract and I just decided to change the shape of resources (adding) and deleted the specific group of commissioning and he still added. It worked... but only for a time. Once again, some time after, the same problem occurred.

It is a recurring problem... I don't know what is the cause of the problem, I do not understand why the operations I've run temporarily solved the problem and especially, I do not know how to solve this problem permanently.

Does anyone have the same problem? Any suggestions on how to fix this?

Thanks in advance.

Kind regards

Yes, it's a problem.

but order 1000 sure a problem. It is used by the IOM. Once you've changed 1005 just make sure that you have restarted the server. Hope you did. But, if not just restart and check it out.

Otherwise, you can do a work around.

just for some time to remove this eventhandler for MDS.

2 - postprocess adds users to a role, if the user of the IOM is to have access to AD and adds the user to specific roles additional (one for each ad group) based on the information on the profile of the IOM

Create the rule using the rule designer to add over the different group. and update the access policy if necessary.

Lets see.

I hope it work

Kind regards
Mireille Nayan

Published by: Zaba Nayan on 18 January 2012 04:29

Tags: Fusion Middleware

Similar Questions

  • WebVPN - error: access method is not supported for the capture of WebVPN

    I'm watching a capture of webvpn on the SAA. I start the capture:

    test type webvpn user capture (entering a valid user name)

    Then I connect to the ASA to try to see track with "Using a browser to capture displayed data" as described in the setup guide.

    https:// / admin/capture/test/OCAP

    After login, I get this message in the browser:

    "Error: access method is not supported for WebVPN capture."

    If I stop the capture (capture test) before you try to connect, the error in the browser is:

    "404 not found".

    The/admin/capture/test/OCAP requested URL was not found on this server. "

    Any ideas greatly appreciated. Thank you!

    After some research, I finally found it

    DOC: Webvpn catches are recorded only in zip format


    CSCtg79320

    Symptom:

    WebVPN captures are only saved in zip format.

    Conditions:

    According to the following doc:

    http://www.Cisco.com/en/us/docs/security/ASA/asa82/configuration/guide/WebVPN.html#wp1153077

    WebVPN captures can be recovered in the pcap format using the browser, which is incorrect. The document must be corrected.

    Workaround solution:

    N/A

    Thank you for your time and cooperation

    Portu.

    In case you have any other questions please note all useful messages and mark this question as answered

  • Hi, can someone give me some ideas on what type/brand of usb cameras are not suitable for labview? I need to use with labview and IMAQ Cheers acquisition image vision module

    Hi, can someone give me some ideas on what type/brand of usb cameras are not suitable for labview? I need to use with labview and image acquisition IMAQCheers vision module

    Hi, I use a 1.4MP USB camera with LabView. The brand is ID - a German company.

  • I would like to know what are the characteristics of the trial version of Illustrator are not available for use

    I would like to know what are the characteristics of the trial version of Illustrator are not available for use

    Normally there are no differences in features between the facilities of the trial and will enjoy

  • Why the NDP module says "you are not allowed for this operation?"

    Hello world

    I hope you can help me with this problem!

    I'm playing with the NDP module has a message saying 'you are not allowed for this operation.

    This happens when I try to create a new project and try to open the window to select a project type. It also happens when I go to the ADMIN and add new types of projects?

    Is there a role limiting me or does some other underlying problem?

    Thank you in advance.

    Hello

    I think that you might miss an active project type category.

    Go to Admin-> NDP-> categories of project types.

    You must have at least one category that is active (which is indicated by a green check mark).

    Once at least one is activated, you will need to go to the Cache and rinse the taxonomy of cache (just to be sure, I would empty Admin Data Cache Group as well).

    Then you can go to the Admin and configure your project types.

    Let me know if you have any questions,

    Dmitriy

  • I am trying to improve my Creative Suite 5 to creative cloud but to myself that I have are not eligible for the upgrade, did someone knows why?

    I am trying to improve my Creative Suite 5 to creative cloud but to myself that I have are not eligible for the upgrade, did someone knows why?

    If you have the education version you are not eligible due to the delivery of the HIGH education

  • My license complete creative suite tells me that my trial has expired and now all programs are not available for me. What is going on?

    After 3 years, my suite fully licensed creative returned unexpectedly to a trial. Today it tells me that my trial has expired, and now all of the programs are not available for me. What is going on?

    Trial opens at the launch

  • What type of certificates are not suitable for the signature of the extensions to HTML5?

    It is not clear to me, of the literature exactly what types of certificate are not suitable for the signature of the CC2014 HTML5 extensions.

    I used a Thawte 'Adobe Air' certificate for signing extensions based on Flash. It is now expired. Can I buy the same type and that will work cross-platform for the signature of the extensions to HTML5?

    See http://www.thawte.com/code-signing/content-signing-certificates/adobe-air/index.html

    Thank you

    Hi meeky2,

    Required certificates have not changed for HTML5 extensions, so the same type of certificate that you had before work ('Adobe Air' certificates are very good).

    Note that if you only distribute your HTML5 extension through modules Adobe / Adobe Exchange, then there is no need to use a paid certificate. If you distribute your extension elsewhere, then you should do the same thing as you did with the extensions of the AIR.

    Best regards

    Fraser

  • all rows in the table are not eligible for the specified partition

    SQL > Alter Table ABC
    Exchange 2 Partition P1 with Table XYZ;

    Modified table.

    SQL > Alter Table ABC
    Exchange 2 Partition P2 with Table XYZ;


    P2 Partition Exchange with XYZ Table
    *
    ERROR on line 2:
    ORA-14099: all rows in the table are not eligible for the specified partition

    The exchange partition works fine for the first time. However, if we try to swap the 2nd partition it gives the error.
    How to solve this error?
    How can I find the lines which are not qualified for a specific part. is there a query to find out the same thing?

    >
    Well, exchange of syntax and logic is not clearly as it should (IMHO). There is no element of syntax that tells Oracle we want to Exchange partition data in a table that is not partitioned or not partitioned into partition table data.
    >
    What? Not sure where you got that but maybe it was before you had first cup of coffee? ;)

    An "Exchange", it's just that; an Exchange. Partition data end up in the non-partitioned table and vice versa. It is meaningless and totally obsolete if "we want Exchange partition data in a table that is not partitioned or not partitioned into partition table data".
    >
    It was decided by Oracle not partitioned table control. If the non-partitioned table is empty, it means you want to Exchange data partition in a non-partitioned table. And if not partitioned table is not empty, it means you want to Exchange data in the table that is not partitioned into partition.
    >
    There is no decision to make. The segments are swapped. Oracle doesn't check, know or even care if one or the other or both segments are empty. 'Control' which is carried out (by default except if NO CONTROL is used) only consists of ensuring all the data in the segment intended for the partition belongs to this partition.

    It is what gives the example of John. This can NEVER work if table1 is empty unless p1 is empty at the beginning:
    1 Exchange p1 with table1
    2 Exchange p2 with table1

    As John explains, assuming that no other operations are trying to put the data from p1 P2 which is not possible if p1 actually contains data.

    You can save it for next April 1!

  • ITS Search Application: you are not authorized for this page.

    Hi all

    I'm working on implementing Secure Enterprise Search. I have install the connectivity between PeopleSoft and SES have deployed research definitions and created indexes.
    For example, I have deployed and build and find the HC_HR_COMPANY_DIRECTORY1 of PeopleSoft HCM 9.1 definition.
    When I use the research of the Application of the banner of PeopleSoft to perform a search on a key word, it returns results.
    Now when I click on the link to the result it opens a new window with the error, you are not authorized for this page.

    The url, it tries to open is
    http://myserver/PSP/PS/employee/HRMS/c/c/HR_SRCH_GLOBAL.HR_SRCH_CD.GBL?page=HR_SRCH_CD & action = U & EmplId = K0LB07 & EMPL_RCD = 0 & SESLanguageCd = ENG

    You will notice that the url contains/c/c/that causes the error.
    When a remove here form the url manually, it works fine and I can navigate to the relevant page.

    I saw that the stream has published in ITS contains c/HR_SRCH_GLOBAL.HR_SRCH_CD. GBL? Page = HR_SRCH_CD & etc.
    When you hover over a result link it executes javascript
    OpenCrefInUniNav (' c/HR_SRCH_GLOBAL.HR_SRCH_CD.) GBL? Page = HR_SRCH_CD & Action = U & EMPLID = K0LB07 & EMPL_RCD = 0 & SESLanguageCd = ENG ')
    This prefaced the url with 6 separate parts by / in the base url http://myserver/psp/ps/EMPLOYEE/HRMS/c/ PeopleSoft
    I found this JavaScript function in the HTML PT_COMMON object.

    I don't know that the PT_COMMON.js should not be setting place, so the question should be somewhere in the engine of the application that creates the index feed to HER.
    If the application of create index engine add the c / to the url when you publish the food?

    I run on PeopleTools 8.52.09 and PeopleSoft HCM 9.1 FP2 review Recut.

    Someone at - it an idea how to solve this problem of double/c/c /?

    Concerning

    Halin

    Can make sure you that the local node by default, Portal node (HRMS) Portal and content URL is configured correctly they should end with /psp/ and /psc/

  • Comments operations are not allowed for anonymous users on this virtual machine

    Hello

    After a lot of trying, I finally managed to connect to a virtual machine in VMware Server 2.0.2

    However, I get the error "comments operations are not allowed for anonymous users on this virtual computer" when I try to run notepad.exe. I think that some permissions must be set. So I put comments and guests of user group to be able to administer the object (VM); but still this error comes.

    Can someone help me pls with getting beyond this error.

    Thank you very much.

    This has come up before on this Forum. Be default, Windows does not allow for remote log-ins for accounts without password, which prevents the VIX to perform log-ins comments in this situation.

    You can follow the steps described in the following thread to enable remote log-ins for accounts without password or change the account to have a password.

    http://communities.VMware.com/message/910606

  • What are the optimistic Caches? They are not suitable for OLTP?

    where are the optimistic Caches? I think that they are not suitable for OLTP due its implementation without any concurrency control?

    They are used in situations requiring no concurrency control. For example, session data, transient data, some single-user data and so on.
    The use is based primarily on the Types of businesses.

  • password data are listed for a site, but are not used for the connection

    After updating Firefox (for 36.0.1), listed saved passwords were not being inserted to connections site. After you delete all data saved password, there is no prompt to save the entered password data. I then deleted to recycle bin signons.sqlite, logins.json and signons3.txt, you exit Firefox and hard rebooted my desktop Windows 7 Pro 64-bit computer. Still no prompt to save password entered data. Remember passwords for websites has been checked in all of this, with several attempts to uncheck, OKing, close and restart Firefox, box, OKing, restart Firefox, you log in to a site.

    Another problem is the result of the last update. I can't get my homepage to show the startup of Firefox. The box on the general tab in the Options and the home page is entered. I tried to place the home page two ways: either by manually typing the url in the Options and the other by accessing the url and drag the tab to the Home icon and say yes to make this my home page.

    Ideas for resolution of these issues would be appreciated.

    Update:
    Just got the notice of upgrade to version 37.0.2. Installed upgrading and now no problems! Hope this will help others.

    There are several reasons for something like that. But if the browser
    is now working properly, just keep an eye out for the problem to come back.

  • Why the features are not available for me?

    My desktop version of Firefox, the option shown on this screenshot is disabled: http://screencast.com/t/k7YIzNTC9C7. It is not grayed out on my version of the laptop.

    In addition, I'm not able to select the option "Always Enable" to always enable notifications of certain websites in my browser on my desktop, but I'm able to do on my laptop.

    Both versions are updated to 36.0.4.

    Make sure that you are not Firefox running in permanent private browsing mode (don't remember history).

    • Tools > Options > privacy > Firefox will be: "use the custom settings for history".
    • : Uncheck the [] "always use the private browsing mode.
  • Drivers for Satellite C55-A-1RG are not available for download

    All the links of
    http://www.Toshiba.com.ro/innovation/JSP/supportMyProduct.do?LNG=27&service=se
    for drivers for this model are not available.

    They all give 404 error trying to download.

    No idea where you can get these drivers as it is the laptop is a bit useless without at least some video drivers and wireless.

    Hello

    It seems that the driver could be downloaded again.
    I could download drivers for Satellite series C55 - A.
    I guess there was a temporal server problem that seems to be resolved now.

Maybe you are looking for