How to configure UCM ACL (with WLS & ADProvider)?

Hi all

I have problems to configure ACL. So far, only accounts and the securitygroups define security, ACL has no effect.

So far, that I have configured right
config.cfg-> UseEntitySecurity = true

I was following the script of the user:
Users of the AD: Test1, Test2 (both are members of the two groups in the next line)
Ad groups: TestRole,@TestGroup (RW)
The University Complutense of MADRID SecurityGroup: Test
Role of the Complutense University of MADRID: Testrole
-> Test: TestRole (RWDA)

Point at the Complutense University of MADRID
Account: TestGroup, SG Test
-> The members of the AD Group Testrole should get RWDA and @TestGroup (RW) members should get RW in this element, causing that Test1 and Test2 can point RW (so far works well)

Now when to add Test1 or Test2 with RWD to the user access list, they may not always delete (error, is that "doesn't have sufficient privileges to access content account TestGroup")
If I add Test1 or Test"with R to access of the user list, they can still update

No idea how to do this? I understand the functionality?

I thank in advance

-hk

If your ACL work properly then user would NEED to be in the list of the user, or that they would not all permissions on the content.

You really need to add all the SecurityGroups where you want that ACL is applied to the SpecialAuthGroups configuration variable - see this post useful.

http://blogs.Oracle.com/Kyle/entry/new_security_configuration_flag_ucm_ps3

FOR EXAMPLE
SpecialAuthGroups = Test

Once you have set it up correctly you are right in that you can now control permissions by changing permissions in the access of the user list. giving pernmssions Test1 (RW) through the access of the user list will remove remove permisisons.

Tim

Tags: Fusion Middleware

Similar Questions

  • How to configure the bluetooth with Kyocera android phone connection to share photos, music & video files

    Original title: Windows 8 Configuration bluetooth with Kyocera android phone?

    Configuration of bluetooth of Windows 8 with Kyocera android phone?  I got a laptop with bluetooth Tech. How can I set up a connection and share photos, music & video files?

    Hey GQ - Jon'Jon,.

    Make sure that Bluetooth is enabled on the computer as well as your Kyocera android phone.

    Make sure that the phone is paired with your computer.

    For information about how to configure the Bluetooth with Kyocera android phone connection to share photos, music & video files, it would be better if get you in touch with Kyocera phone support for assistance. Please see the support link:

    http://www.Kyocera-Wireless.com/support/phone/

    Please feel free to respond if you face problems with Windows in the future.

  • How to configure a VM with multiple network cards to see Agent?

    How to configure a VM with multiple network cards to see Agent?

    We can archive this requirement by configuring the subnet used view Agent.

    The subnet determines which view address of Network Agent provides the server instance to connect to view for the client protocol connections. The view on VM officer has more than one NIC

    Follow the procedure below:

    on a display Agent installed VM,

    * Recording of VM session.

    * RUN--> type regedit or type regedit.exe at the command prompt

    * Create a registry entry to configure the subnet.

    For example: is HKLM\Software\VMware, Inc. \VMware VDM\Node Manager\subnet = n.n.n.n/m type - REG_SZ.

    In this example, n.n.n.n is the TCP/IP subnet, and m is the number of bits in the subnet mask.

  • How to configure Oracle Discoverer with EBS R12?

    Dear

    I hope that, by default, only oracle Discoverer is not configured with EBS R 12. How to configure?
    Any help, much appreciated.

    Naya,

    Please refer to the next note, it should be useful:

    Note: 373634.1 - using discoverer 10.1.2 with Oracle E-Business Suite Release 12
    https://MetaLink.Oracle.com/MetaLink/PLSQL/ml2_documents.showDocument?p_database_id=not&P_ID=373634.1

  • How to configure the listener with SSL

    Hi Experts,

    I use 11g R2 EE. I want to configure my database listener so that it can be connected using SSL.

    Can someone provide me guide step by step to configure the listener with SSL (including the portfolio so that comes in the image).

    The command line configurations will be well appreciated.

    Thanks in advance

    Alexander gelin

    The client configuration is the same as the server:

    1. create the portfolio.

    2 creating CSR and copy it in CA.

    3. the CSR signal with your certificate root.

    4 copy signed CRT file and root of public certificate to the client.

    5 configure the sqlnet.ora clients.

    Heavy customers already contains the necessary files. For thin clients, it is necessary to install the full or instant client.

    In SQLDeveloper, connection string should be like:

    jdbc:oracle:oci:@(DESCRIPTION= (ADDRESS_LIST= (ADDRESS= (PROTOCOL=TCPS)(HOST=)(PORT=))) (CONNECT_DATA= (SERVICE_NAME=)) (SECURITY= (MY_WALLET_DIRECTORY=D:\Oracle\client.test.p12)))

  • How to configure vCenter Server with an external smtp server?

    Is it possible to configure vCentere Server with an external smtp server?

    In our environment, we must configure vCenter server to send email alerts when the alarms are triggered. We use the google apps (smtp.gmail.com) server as our official email server.

    I know the steps to do the same?

    You must authenticate external messages. Here is one of this tutorial. http://paulgrevink.WordPress.com/2011/02/06/configuring-vCenter-for-email-with-SMTP-authentication/

  • How to configure jdeveloper 11 with the .dbc files?

    Hi all

    I am a new bie here. 4 jdeveloper 10, I can configure files .dbc to the setting of the project, while 4 jdeveloper 11, it's totally different. I can't find any place to set it up. How to configure the .dbc in jdeveloper 11?

    Kind regards
    Chelsea

    You cannot use jdev 11g for the development of the OFA...
    You must download the patch of jdeveloper on metalink to develop objects of the OFA.

    See this metalink note to find the correct version of jdeveloper, you need to download https://metalink2.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=416708.1

    Prasanna-

  • How to configure a button with alignment fixed points on a logorithmic scale?

    My question is quite simple, but after rooting in the button/gauge proteries, I can't find a way to do what I would like to:

    I would like a simple button with 4 possible values control: 0.0125,0.125,1.25,12.5

    I would like that they also spaced and I want the button to engage only in one of these four values

    I can get it at least to the point of having four values there by placing arbitrary markers (scale-> add the marker), but I can't figure out how to align them, or even if it is the way of Paris to follow on that.

    Thank you!

    See example LV86 attached. Open the Properties dialog box for the button for more information on its configuration.

  • How to configure windows XP with a startup password. MyChild sneak into my computer

    My daughter sneaking into my computer and I want to set up a password for windows XP will not work without it

    Hello

    Set up a password on your user account:

    "How to create and configure user accounts in Windows XP"

    https://support.Microsoft.com/kb/279783/en-us

    You already have an account to use the computer.

    Click Start > Control Panel > user accounts > change an account: select your account > create a password.

    No guarantee that children have a way of finding ways to "crack" passwords.

    You might consider setting up a BIOS password, but how to bypass/reset information is there as...

    See you soon.

  • How to configure SGE2000 ACL?

    Greetings to all Prof. and Violaine here in the community a GOOD DAY!

    Scenario 1.

    The NComputing 1 server address: 192.168.85.216

    The NComputing 2 server address: 192.168.85.215

    I have a VLAN ID created in SGE2000 (Layer 3 Mode) 20. My 2 ncomputing server was a member of VLAN1 (default).

    Issue.

    A. I want to a certain vlan can have access to my ncomputing server, for example VLAN ID 20, must Access Ncomputing Server 2 Ncomputing server1 only and VLAN 25, then other VLAN ID should have no access on the server of Ncomputing.

    B. as the value default all Vlan do not see them each other and I want them to see themselves... as IP 30 VLAN can ping IP 40 VLAN

    How to do this in access list?

    All ideas are welcome and appreciated, if my information to learn more just let me know if I can post more details here...

    Thank you in advance...

    BS,

    Mike

    Hi John,.

    Thank God, quite simple.

    First, you create an ACL being very careful on the fields that you fill in.

    In my example below, I plugged an IP phone on port 1 Gig of my SGE2000P.

    I wanted to access my list to perform all a filter all detect them of ICMP traffic in the port of switch my IP phone that is intended to go to the 192.168.10.0 network.  It was a quick and dirty way to demonstrate whether or not the filter worked.  ICMP blocking would kill any ping I tried to train my PC to the IP phone.

    Look very closely, I put priorities of ACL entry and used reverse subnet masks.

    Note that my second ACL entry is a permit.  the resaon for this is that there is always an invisible rule at the end of the access list (ACL), which is to deny all.

    So my intention of this access list is only to restrict the ICMP goes from 10.1.1.14 to the 192.168.10.0, not no matter what other network traffic...

    Then I bound the ACL to an interface, as filters to access list on ethernet frame infiltration in the switch.

    I applied the ACL to the port 1 Gig and as you can see, the order of rattling and to restrict the ACL called ping appear next to port 1.

    I hope this helps.

    You'd better use the part of the small business community for other questions about your switch.

    Best regards, Dave

  • How to configure ACS 4 with 802. 1 X

    Hay

    How to set up my ACS server to support 802. 1 X with PEAP.in to authenticate the me (PC).

    Thank you initially

    You can skip the part of the certificate.

  • How to configure the FWSM with HSRP support

    Hi all

    We have 2 * 6500 Series switches with each FWSM core installed.

    There are some users of VLANs (each floor) and a lot of servers inside that belong to some other VLANs.

    Basic switches have been configured with redundancy HSRP (active/passive).

    Today, I am picky with FWSM routed mode configuration.

    There is no problem with the default configuration and testing,

    I mean assigning VLANS to FWSM and delete addresses IP of MSFC.

    But unfortunately whenever I have such a configuration, do I lose naturally redundancy between switches.

    In our situation HSRP is a must.

    Is it possible to fix this design in routed mode, with support HSRP. ?

    Thank you

    Erdem.

    Hi Erdem,

    (correct me if I'm wrong, Jon) - If you remove all the Lass you must route all traffic of course the FWSM.

    What we did was to create a transfer network (VLAN) with a SVI and FWSM inside external interface. Now, the default gateway on the FWSM is on the IP address of the SVI. So most of the range is configured on the switch.

    Kind regards

    Jürgen

  • I need help, how to configure virtual machines with PowerCLI IP addresses

    Hi all

    I open this topic because I really need your help.

    I wrote a script that can automatically create 10 VMs on my ESX Server.

    I run the script with PowerCLI.

    I want now to help script, give the ip on the 10 machines created settings.

    I don't know how, can you enlighten me on this subject?

    Is there a script that can do this?

    Thank you very much.

    Isn't the "0.2 | ForEach-Object {"a loop for? IMHO, it is a loop in the PowerShell way.

  • How to configure UCM in webcenter spaces

    Hello

    I installed spaces webcenter and UCM separately and the created i field with spaces and ucm .able to access all services in webcenter/UCM (login).
    What my problem is that I am unable to find content management in web-Center spaces as link http://docs.oracle.com/cd/E21764_01/webcenter.1111/e10149/content_doctf.htm#BDCCCAJG of set-aside. can someone please give some resolution of this. I need to integrate content into web-Centre spaces.

    Concerning
    Shankar

    It is a question for the forum WebCenter Portal. This forum is for WebLogic Portal. You will have better answers in the WebCenter Portal forum.

    WebCenter Portal

    Brad

  • How to configure Airport Extrem with OS El Capitan?

    Hello, I need help to set up airport Extrem with the OS X El Capitan. The system always show the same question:

    You will not be able to administer the old 802.11 g with your Mac OS X El Capitan AirPort base stations.

    Basically, you have three options:

    1. Replace the Express with a newer 802.11n model.
    2. Use a Mac with OS X Lion or earlier version.
    3. Use a Windows XP or Windows 7 PC.

Maybe you are looking for

  • Re: Can I start on my Satellite L650 SD card slot?

    Hello everyone, I just bought a Toshiba Satellite L650 laptop computer and I am satisfied with this laptop. I use Ubuntu 10.10 and his works fine... no problem with built-in hardware like WiFi, Ethernet etc... But now I just tried to boot from an SD

  • Restart of the computer itself.

    My system restarts without warning. He crashes and then restarts. It happens randomly at any time. even in safe mode.If I shut down the system, he's going to restart several times before windows will start up again.There is no external connections or

  • Transfer of Microsoft Office 2007 on my laptop

    I installed 2007 on my laptop and still have the code installation disc and acitivation but my laptop don't have a disk drive how can I transfer across? Can I use a flash drive?

  • Pocket Tunes stopped reading SD Card

    PTunes on my centro was reading my card without problem. The last time I opened the program, no music appeared in the program. I can still read the photos on the sd card of centro. All music files are still on the map, they just do not appear in ptun

  • How to download and reinstall CS5

    I had my computer crash 2 weeks ago and had to get the hard drive replaced. Now, I have to reinstall my adobe creative suite 5. I actually had this happen once before. I remember that I was able to go to a link to adobe and download the software, ado