MSAD in OBIEE 11.1.1.7.140715 access

Hi all

I recently patched one of OBIEE 11.1.1.7.140715 environmental OBIEE. Everything went well, I can able to connect without any problems.

In my existing configuration MSAD, I added a few parameters to get the list of users in the ad group, that I couldn't connect to Analytics. I changed the password to the user configured MSAD and in the console EM change the password to BISystemUser and rebooted. After that, I couldn't access analytics with any AD as well as native users.

I'm not able to see users AD including "BisystemUser" of the logic of the Web. Looks like its corrupt. Please suggest me in this situation.

I will delete the existing configuration of MSAD and reconfigure newly, is this will help?

Journal of NQServer:

[2015 06-24 T 21: 16:00.000 - 05:00] [OracleBIServerComponent] [ERROR: 1] [] [] [ecid: 00iTxTLHkaEFc515zv8DyW0001c4000000, 0:13006:6] [tid: 928] oracle.bi.security.service.SecurityServiceException: SecurityService::validateSystemUserCredentialsThe system user could not be authenticated.

[2015 06-24 T 21: 16:00.000 - 05:00] [OracleBIServerComponent] [ERROR: 1] [] [] [ecid: 00iTxTLHkaEFc515zv8DyW0001c4000000, 0:13006:6] [tid: 928] [nQSError: 43126] failed authentication: username/password invalid.

Journal of bi_server1-diagnostic:

Caused by: javax.security.auth.login.FailedLoginException: [Security: 090303] authentication failure: User BISystemUser weblogic.security.providers.authentication.LDAPAtnDelegateException: [Security: 090294] could not get connection

at weblogic.security.providers.authentication.LDAPAtnLoginModuleImpl.login(LDAPAtnLoginModuleImpl.java:251)

to com.bea.common.security.internal.service.LoginModuleWrapper$ 1.run(LoginModuleWrapper.java:110)

at java.security.AccessController.doPrivileged (Native Method)

at com.bea.common.security.internal.service.LoginModuleWrapper.login(LoginModuleWrapper.java:106)

at sun.reflect.GeneratedMethodAccessor334.invoke (unknown Source)

at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:25)

at java.lang.reflect.Method.invoke(Method.java:597)

at javax.security.auth.login.LoginContext.invoke(LoginContext.java:769)

to javax.security.auth.login.LoginContext.access$ 000 (LoginContext.java:186)

to javax.security.auth.login.LoginContext$ 4.run(LoginContext.java:683)

at java.security.AccessController.doPrivileged (Native Method)

at javax.security.auth.login.LoginContext.invokePriv(LoginContext.java:680)

at javax.security.auth.login.LoginContext.login(LoginContext.java:579)

at com.bea.common.security.internal.service.JAASLoginServiceImpl.login(JAASLoginServiceImpl.java:113)

at sun.reflect.GeneratedMethodAccessor336.invoke (unknown Source)

at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:25)

at java.lang.reflect.Method.invoke(Method.java:597)

to com.bea.common.security.internal.utils.Delegator$ ProxyInvocationHandler.invoke (Delegator.java:57)

to $Proxy36.login (Unknown Source)

to weblogic.security.service.internal.WLSJAASLoginServiceImpl$ ServiceImpl.login (WLSJAASLoginServiceImpl.java:89)

at com.bea.common.security.internal.service.JAASAuthenticationServiceImpl.authenticate(JAASAuthenticationServiceImpl.java:82)

at sun.reflect.GeneratedMethodAccessor338.invoke (unknown Source)

at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:25)

at java.lang.reflect.Method.invoke(Method.java:597)

to com.bea.common.security.internal.utils.Delegator$ ProxyInvocationHandler.invoke (Delegator.java:57)

to $Proxy54.authenticate (Unknown Source)

at weblogic.security.service.WLSJAASAuthenticationServiceWrapper.authenticate(WLSJAASAuthenticationServiceWrapper.java:40)

at weblogic.security.service.PrincipalAuthenticator.authenticate(PrincipalAuthenticator.java:348)

at weblogic.security.services.Authentication.doLogin(Authentication.java:133)

at weblogic.security.services.Authentication.login(Authentication.java:74)

at weblogic.security.services.Authentication.login(Authentication.java:51)

at oracle.security.jps.wls.jaas.module.authentication.WlsUserAuthenticator.authenticate(WlsUserAuthenticator.java:56)

... 64 more

]]

[2015 06-24 T 21: 24:16.460 - 05:00] [bi_server1] [ERROR] [OWS-04115] [oracle.webservices.service] [tid: [ASSETS].] {[ExecuteThread: '1' for the queue: "(self-adjusting) weblogic.kernel.Default"] [userId: < anonymous >] [ecid: 0000Ks_82RlFc515zv8DyW1LYcSd000002, 0:40] [APP: OracleRTD #11.1.1] an error for the port: {}http://www.sigmadynamics.com/schema/services/RpcService} RpcPort: oracle.fabric.common.PolicyEnforcementException: FailedAuthentication: the security token cannot be authenticated..

[2015 06-24 T 21: 24:16.460 - 05:00] [bi_server1] [ERROR] [WSM-00279] [oracle.wsm.resources.security] [tid: RTD_Worker_358] [username: < anonymous >] [ecid: 0000Ks_82RlFc515zv8DyW1LYcSd000002, 0] [APP: 11.1.1 # OracleRTD] [WSM_POLICY_NAME: oracle/wss_username_token_client_policy] the following error Message is received on the client side of the service:-[[ ]]

FailedAuthentication: The security token cannot be authenticated.

Client-side policy is: -.

Oracle/wss_username_token_client_policy.

The service url endpoint is: -.

http://xx.XX.78.12:9704/ws/CPP .

Keystore properties: -.

{}.

Properties are in the context of the message (partial list): -.

{javax.xml.ws.security.auth.username = BISystemUser, javax.xml.rpc.security.auth.username is BISystemUser}.

PolicyReference OverrideProperty:

[]

Policy configuration properties (some of them can be replaced by properties in the message context or PolicyReference, about the order of precedence of the properties, see documentation);

{key = basic.credentials - csf = ultimateReceiver role}.

Other related information: -.

{oracle.integration.platform.common.subject = Subject: NULL}

}.

]]

[2015-06 - 24 T 21: 24:16.460 - 05:00] [bi_server1] [ERROR] [] [oracle.webservices.jaxws] [tid: RTD_Worker_358] [username: < anonymous >] [ecid: 0000Ks_82RlFc515zv8DyW1LYcSd000002, 0] [APP: OracleRTD #11.1.1] error when calling endpoint "http://xx.xx.78.12:9704/ws/CPP" of the customer. Client-side policies: [oracle/wss_username_token_client_policy]

Thank you

Hi all

I solved the problem by reconfiguring the directory AD.

Thank you

PC

Tags: Business Intelligence

Similar Questions

  • A specific account of MSAD with very low performance

    We have a specific account of MSAD EPM that takes forever to connect and access a form of planning to run a report.  If the same user uses our native directory IDs test meeting he is as fast as all other MSAD accounts.

    If another account MSAD uses his work station that they may have no problem (so not a problem of workstation)

    We dropped and he added to security groups, updated filters and reviewed its MSAD configuration to ensure that it is no different.

    Looking for other avenues or the tools to use to determine why this person has problems.

    JTS

    Had to share this desire

    Finally figured out what was the problem after sniffing through our network.  It's a preference of the workspace for the Accessibility Mode.  It has been verified for this user (File/Preferences/general/accessibility Mode)

    The speed of the system unchecked once was normal for other users

    Always small things

    JTS

  • Review of best design OBIEE

    Our project has sales and billing information stored next to the Oracle and we want to have some users access to the sales and billing related reports through OBIEE dashboard? Sales user should access the sales reports, billing users need to access the billing reports and users having the rights to display the two types of reports can see both of them.

    In addition, forced specific region must be applied. I want to say in a region can consult data on this area alone.

    At the highest level, what is the correct way of data modeling? Can you please let me know how to do this with the security of the external table?

    Hello

    The following link should help you http://obieeblog.wordpress.com/2009/06/18/OBIEE-Security-Enforcement-%E2%80%93-External-Database-table-Authorization/

    Or search this forum of authentication to the external table

    Good luck

    Daan Bakboord
    http://obibb.WordPress.com

  • Percentage of elapsed time

    I have build an analysis and I want to know what percent of the time between two dates is elapsed.

    I use the following formula:

    (TimestampDiff (SQL_TSI_DAY, 'Project'. "" Date of actual start»(, CURRENT_DATE) / TimestampDiff (SQL_TSI_DAY, 'Project'. " «Effective Start Date", «Project"» Date of actual end")) * 100

    I checked the first part returns with precision the number of days elapsed since the start date and the second part returns with precision the number of days between the start and end dates.

    My problem is that when dividing it by this one, I always zero. In fact, any time I divide a number any of the latter I get zero. It is not possible to generate a denominator use this function? I am able to multiply the two but I can't divide one by the other.

    Can someone help me understand a formula to determine what percentage of my time elapsed between my start and end date?

    Example:

    Start date: 15/12/13
    End date: 31/08/2015

    447 days elapsed between the date of beginning and today (12/03/15). The duration of the project is 624 days. I expect my analysis to 72% back, but instead, I am 0.00

    I use OBIEE 11.1.1.7.140715


    I solved the problem. I had to RIDE my TimestampDiffs as FLOAT.

  • The Mobile BI App designer not no projection in analytical URL but appearing in the mobile URL

    Hi all

    I am new to using the Mobile App Designer. When I connect to OBIEE (http://localhost:9704 / Analytics /) I see the mobile option app but when I click on the option, the window to create a new application does not appear.

    If I look at the mobile OBIEE (http://localhost:9704 / mobile /) it works fine and I am able to see the phone to create or window of Tablet, but the application will not be saved. I checked the permissions in folders and permissions to my account, but they all seem fine.

    We are on the latest version of OBIEE 11.1.1.7.140715 and patch: 18794832 BI Mobile App Designer. Double, I checked the read me and followed the instructions according to the patch. Any ideas?

    Thank you

    Mark

    Update, question relates to IE10, does not work with the compatibility view on. This must be turned off. Confirmed with the Support of Oracle to organise a fix to be put in place. Have to downgrade to IE9 or wait for a fix because IE11 is the same problem.

  • coreapplication_obips1

    Hello
    We have installed OBIEE 11 g in our machines (Linux). When we see the situation to help
    opmnctl status
    command, all services are alive except coreapplication_obips1. It's showing out of service. Please let us know how

    Could if it you please let me know how to start this service. And what's the use of this service.

    "Error log: operation of the Mbean access denied."

    Thank you
    Gram

    check...

    http://bihyperionobiee.blogspot.in/2013/03/OBIEE-11.html
    http://obiee1000.blogspot.in/2012/04/OBIEE-111160-coreapplication-doesn' ANSI.org/access/access_t.html

  • Installation issues - multi development environment - User

    Hello
    I have some difficulty to get the multi development environment - user works correctly.

    Our server OBIEE (11g) is on some sort of linux machine, I don't have access to directly (practices of strict security to the company). I can connect to enterprise manager, however. We use the tool of administration remotely from a Windows jumpbox.

    We have a Windows jump box that is the only way to connect to the server in OBIEE, that I do not have access to Port 9703 is open between these machines so that communicate with the server in OBIEE administration tool. It works very well from the Windows machine with respect to the edition of the standard in online mode and see the changes in the responses. Any user who wants to be able to use the administration tool must be first Office remote access to the jumpbox. So all development occurs only from this machine, very probably several users at the same time.

    After you open the online repository, I copied it to a local directory on the Windows computer. Then, I opened this depot offline and created projects (I've added BM and matter to a project, which is the right way?). Then I set up a folder shared on the Windows computer network and stressed the administration tool this directory and copied the repository to the shared directory.

    I can go to file-> multi-user-> Checkout and select a project, make changes, compare the changes, merge them and publish them. However, none of these changes aren't being propagated to the server. I'm fairly certain that the 'master' repository is changed only in the windows box, and nothing is propagated to the OBIEE server on the Linux machine.

    I guess my question is, if I'm unable to set up a shared folder on the real server (due to security policies), is implemented things MÜDE to do something? Is there a way I can set up so that the shared folder is on the Windows machine, and it updates the real repository sat on the Linux OBIEE server machine? I really want to refrain from someone go to Enterprise Manager each time just to load the new file to the repository.

    Thank you.

    Hello

    You will need to configure a script that does the following:

    -Stop the services on the Linux server
    -Copy the fender - of your shared windows folder to the folder on the server Linux
    -Restart the services

    Whenever you have checked in your changes, you must run the script to put your changes online.

    Good luck!

    Randall

  • Cannot access the direct application of database reports in the dashboard

    Hi all

    I added a new user to the DPR OBIEE. When I tried to access a report created using direct, database application in the dashboard sound up the following error:

    State: HY000. Code: 10058. [NQODBC] [SQL_STATE: HY000] [nQSError: 10058] A general error occurred. [nQSError: 13017] User or group did not Direct database access privilege to access the database "Oracle Data Warehouse". Please check the permissions of a user/group in the Administration Oracle BI tool. (HY000)

    (1) the newly created user belongs to any group.

    ' (2) in Presentation Services-> settings-> Administration-> manage privileges ' gave the permission of * "Perform direct database requests" * also.

    Help, please... Thanks in advance... :)

    Kind regards
    LonaD.

    Hi Lona,

    Open, click OBIEE administration tool to manage-> Security-> user.
    Double-click the user who must have the permission of direct execution of the database application. In the drop-down list, select 'allow '. Hope this will solve your problem.

    Thank you
    Lolita

  • Hyperion Essbase "Excel Add-Ins" are not connected.

    HELLO Experts!

    I M using Hyperion 9.3.0 and external authentication (MSAD) for users.

    I put in "Server Access" service in the analytical server and "read" permission for Essbase App.

    But while I m connect via "Excel add in" with this user, there is an error message "failed to connect due to invalid credentials".

    Please any one suugest me the solution.

    Thank you
    Vivek

    Published by: Jeremy Vivek on June 8, 2010 18:39

    Published by: Jeremy Vivek on June 8, 2010 18:42

    Hi Vivek,

    You don't need to restart the service.

    you just need to synchronize the user using the sequence of commands maxl.

    change the resync sss system; --> This command synchronizes all users, groups.
    change the group Security with all applications of synchronization ;--> this can be used to synchronize the group individually
    change user Security with all applications of synchronization ;--> this can be used to synchronize the user required individually

    use the command according to the needs and try to connect again.

    -Krish

  • MSAD password change will reflect in obiee 11g?

    Hi gurus,

    I'm integrating MSAD to be the primary authenticator in obiee 11g. I was wondering if I change my password in the AD, I'll be able to connect with the changed password or would I need to refresh something on the end OBIEE to pick up this new password? I have to enable SSO for whom? I couldn't find relevant documents.

    Thank you

    Dan

    Yes. No change required to the side bi.

    I referred to the AD integration, make sure that that does not change frequently

  • OBIEE 11.1.1.7.0 works is not after you have configured to use authentication MSAD (Active Directory)

    Hi all

    I'm trying to configure OBIEE 11 g to use the MSAD (Active Directory) authentication. I followed the instructions of Configuration Oracle BI with Oracle Internet Directory , but after a restart all services, I do not get connect OBIEE. I've hearded that there is a bug in this version (11.1.1.7.0) when you rearrange the suppliers and put the new (that you created) as the frist, followed by DefaultAuthenticator and DefaultIdentityAsserter providers.

    Someone had this problem? How to resolve that? Is there a URL or DocID teach how this is set correctly?

    Thanks in advance,

    Concerning

    is even if you have 10 k + users it will show only 1000, this is the limitation, but you can still find the users from the top by clicking on customize the table, it options you give the criteria in filter and view display, you can select the column by which you can search for example: by using the name or description, or Provider(AD or Default) in this path , you can search for specific users you want to see or Alvaro * so it will give u the list whose name start with Alvaro

    I hope it helps brand if not

  • OBIEE 11g &amp; MSAD

    I installed MSAD with WebLogic and am able to see all users by following the steps described in the guide to security. I can connect to answers with my users "weblogic" who installed the system, but when I try a user it fails. What should I bring on groups of MSAD as well and then assign them to roles or can I assign a role directly to a user to operate; or do I have to do in order to get the user to connect?

    J.A.M,

    Here is the answer you are looking for,
    http://bimetrics.WordPress.com/2011/08/12/integrating-MS-Active-Directory-with-OBIEE-11g-in-WebLogic-Server/

    The section on password BISystemUser by doing the same for the user to BISystemUser weblogic and the BISystemUser AD (which could actually be any arbitrary name if you wanted to) the user doesn't actually take place.

    Work through the steps listed in this blog post for your environment and your problems should be solved and your weblogic users and AD username should be able to connect successfully on Analytics portal.

    Take note of her virtualize = true attribute.

    In addition, make sure your Application roles through the command console of Fusion EM BIConsumer application role includes the main "authenticated role." This will ensure that all users who actually authenticate via AD or weblogic LDAP are allowed in the Analytics portal.

    Please give the points. I'm starving for points.

    See you soon,.
    Christian

    Published by: Christian screen-Sep 14, 2011 12:53 AM

  • Configuration of Active Directory in OBIEE 11g

    Hello gurus,

    We have two sets of different users in our ad server on the same host and accessible with the same account system

    1. employees

    2. the Contracting Parties

    From now on, the OBIEE 11 g weblogic system is configured to allow access only to the employees of the advertising tree.

    All employees and contractors are assigned to the same set of user AD groups.

    Currently, we create entrepreneurs as independent users in the administration console and we manually assign groups.

    However, we are having the similar configuration for entrepreneurs (ie., as employees thro AD)

    I copy - paste the authentication provider specific of the OBIEE config.xml and created a new for entrepreneurs with a new user base

    UserBase DN: OR = contractors, DC = abc, DC = com

    All other attributes are exactly the same between the two suppliers of employees and entrepreneurs including the service account in MSAD

    The problem is that I am able to see users contractor under users and groups in the weblogic console, but not able to connect in OBIEE users of the contractor.

    As these groups are already part of the existing installation program (Employees), I did any changes in EM to App role - installation of groups.

    I see also that under users and groups get duplicated because they come from several suppliers. Can we get specific groups they come from different trees of a single AD server.

    If not, can anyone suggest if we can specify multiple trees as Userbase DN of the single AD server in weblogic provider configuration?

    Can someone let me know if I am missing measures?

    Thank you

    Shravan

    You need to restart the battery.  I know that weblogic doesn't make you - but you need from my experience.

    Also is it all as well you can reverse the AD autour configuration.  The path of least resistance we have Weblogic dial has for a complete list of users and a complete list of groups - it don't trim it down by the group as you do above and then create several connections AD.  So just have a tree for all users, where it contains the contractor and the employees.  And another tree for all ad groups.  Then have Announces create 2 groups - one for employees and a contractor.

    Users would be something like - DN: CN = Users, DC = abc, DC = com

    The groups would be something like - DN: CN = Groups, DC = abc, DC = com

    -What makes the wider AD connection.  I stopped adding several sources from AD of the group.  She only source with a global list of users and groups.

    This way you only download duplicates.  Its Announces responsibility to people is the right group so you can correctly set the EM group.  Long story short is its a problem of AD delivers a Weblogic - I nettoieriez it in the original source (i.e. AD), then delete all multiple connections, so the same ad.

  • 11.1.2.4 Hyperion integration with OBIEE 11.1.1.9.0

    Hi all

    We do the POC on integrating OBIEE 11.1.1.9.0 Hyperion 11.2.4 space via SSO.

    The documentation says:

    They should use storage of common identity for the standards body to work. I installed OBIEE home separate middleware and Hyperion Planning in separate middleware, identity storage is different for the two products.

    The integration will work? anyone tried this?

    If not, in the case if we want that it is on the same identity (embedded weblogic ldap) store should install us hyperion and obiee on same middleware House? Is supported the installation of Hyperion and OBIEE on same middleware House?

    I advanced and tried integration and recorded the obiee with hyperion workspace, Navigate-> administer->

    I see OBIEE links but they are not functional and the links read like

    ${/ Analytics, space for work/resources /? / global.js, answers},.

    ${/ Analytics, space for work/resources /? / global.js, dashboards},.

    ${/ Analytics, space for work/resources /? / global.js, offer},.

    ${/ Analytics, space for work/resources /? / global.js, Publisher}

    Anyone can throw some light on this.

    Thank you

    Anthony

    You will need to use a common external directory and configuration that is supported by OBIEE and EMP for example MSAD

    Take a look at the support matrix to see which directories are supported.

  • Inconsistency version OBIEE and customer

    I installed Obiee 11 g(11.1.1.7 version) and client (11.1.1.7.140715 version). When I try to extract data from a flat file and create a SPR and try to deploy my services facilitator and Planner Java go down.why?

    On your connection in the bottom right screen, you should see a link: any product

    Which version is running on the server?

    If you have installed the tools to your customers from the homescreen in OBIEE, so you don't have a version conflict.

    If no conflict, then you have to connect to your Enterprise Manager and search logs the reasons why your host of java and the Planner are declining.

    In addition, if the error occurs on deployment - make sure your SPR passes control of consistency (CTRL + K).

Maybe you are looking for