OBIEE 11 g of UNIQUE authentication data-level security

Hello

I have implemented SSO in OBIEE 11 g and integrated successfully with Oracle EBS R12. Now, I want to set up security level of data for users of EBS.
Can help me please key it.


Thank you.

This EBS SSO are that you have set up. ? Is it with cookie based ICX. ? If Yes, then

Please see the security first guide: http://docs.oracle.com/cd/E20490_01/bia.7963/e19042.pdf

Did you create block initialization custom to fill the 'GROUP' - variable. You can also choose to fill the "ROLES" - variable with the key responsibility. This variable corresponds directly to Application roles in the Enterprise Manager.

Make sure that the name of responsibility for BSE is the same that the role of the Application, you are assiging in EM. You could beverlasting responsibilities in EBS to match existing roles (seeds) or you create new roles in OBI Apps to match your current responsibilities.

Please check if useful.

Thank you
SVS

Tags: Business Intelligence

Similar Questions

  • BI Publisher data level / security at the level of the line

    I would like to know how we can give data level or line level of security defined in BI 11g Publisher.  If you have any best practice document/link, please provide.

    Don't know if you have already activated

    http://www.Oracle.com/technetwork/middleware/bi-Publisher/overview/WP-Oracle-BIP-row-level-security-132091.PDF

  • OBIEE 11 g (data-level security) session variable

    Hello
    Use OBIEE 11.1.1.6

    I would like to apply security to the level of data for a particular column as the year.
    Ex:
    I have 2 users A and B.
    If a user has connection I want to display the values of the year: 2006,2007,2008
    If a user B connection I want to display the values of the year: 2009,2010,2011


    Can u share docs or referral link pls.

    Thank you

    Hello

    Go to Manage > identity > double click the required user > click the permission button > click the data filters >, select the column required.

    year column here > then set the year filter = 2006,07,08.

    to another user that the same follow-up steps, then set the year filter = 2009,10,11.

    for example, when the user login that it cannot see the data restricted.

    Please check if useful/correct.

    Thank you

    Laeticia

    Published by: 934322 on February 22, 2013 02:52

  • Data level security group does not

    I'm testing the security level of data at the level of the group.

    Here's what I did

    1. went to security-> groups-> Permissions-> filters
    2 the name added to the fact table on which I want to filter.
    3 choose 'enable '.
    4. in the filter column, I added a filter on a column in the dimension. (I don't use any session variable in the filter)

    When I create a query responses with the column of the dimension (that I used in the filter) and of the fact table where I set the filter, the filter is not applied.
    Did I miss something in the creation of filters?

    Thanks in advance.

    Rama.

    Hello

    If the user is a member of two defined by the user and group administrator without filter apply to them because the group administrator will take precedence and no filter can be applied to Administrator.Even if you ooen administrator group, you will see this tab permission is disabled for the administrator group.

    I hope this helps.

    Kind regards
    Sandeep

  • How can it be implemented 'line-level-security' in BI Publisher 11 g (11.1.1.7.1)?

    Hello:

    I'm new with Bi Publisher and I'm looking for a way in to the row-level security in BI Publisher (BEEP) with a data model based on a SQL directly.

    We did some research and we have not found many so far... just this article http://www.Oracle.com/technetwork/middleware/bi-Publisher/overview/WP-Oracle-BIP-row-level-security-132091.PDF

    which is a pretty old document showing how do with VPD (virtual private data bases).

    We do not want to go through this... approach for reporting bi publisher, it would be quite expensive to maintain and works only for Oracle databases.

    What we check is if there is something simple... like to read a variable somehow (get that variable to a SQL in the comic book... Similarly we in RPD) and allows to filter the SQL in the data model.

    A simple example is a segregation by country, for example. I want the United States users get the information for that country only and so on.

    Have you faced the same problem... We have seen that 11.1.1.7.1 has a lot of improvements... is probably something now in this version that allow what we are looking for.

    All comments will be welcome!

    Thank you very much!

    Matias

    Would you be able to maintain an external table to have a Manager and country level mapping. If yes you can combine this with the above query and fix things?

  • Explain to me how a multi-level security strategy can be deployed domain LAN-to-WAN and the LAN domain to the domain of the workstation with the use of internal firewalls.

    Explain to me how a multi-level security strategy can be deployed domain LAN-to-WAN and the LAN domain to the domain of the workstation with the use of internal firewalls.

    Hello

    Your Windows XP question is more complex than what is generally answered in the Microsoft Answers forums. It is better suited for the IT Pro TechNet public. Please ask your question in the following forum.
    http://social.technet.Microsoft.com/forums/en-us/itproxpsp/threads

  • Users of the NON-OBI row-level security

    Hello

    I have a simple report:

    ID of seller Sales
    Salesperson1$ 200
    Salesperson2$ 100
    ...
    Salesperson100$ 80

    I need to send the report by e-mail to each of the commercial filtered by it s own ID, so Salesperson1 will receive its own information:

    ID of seller Sales
    Salesperson1$ 200

    Sellers are NON-OBI users, so I can't configure the row-level security, I would send all reports for the Admin user.

    How can I do this without having to replicate the report a hundred times and by creating an agent for each report?

    Thanks in advance,

    Concerning

    It would be N agents and then gave it the context - in your case the seller - to analysis through filter criteria. "Customize content delivery' giving the followingn XML when you look in the catalogue:

    
    
    
    
    
    
    
    
  • Rendering of the elements in a JSP page only to users authenticated on adf-security

    Greetings

    This is a simple question?

    I need to display a link only if I'm with a user authenticated on adf security. could someone provide me with the EL that I have to set the RENDER in my JSP

    Thank you

    Try something like:
    ADFContext.getCurrent () .getSecurityContext () .isAuthenticated)

    Therefore, EL must be:

    adfContext.securityContext.authenticated

    You should be able to use the EL generator.

    Vincent

  • OBIEE 11.1.1.7... Security siteminder as authentication provider

    Hello

    What to select in the list for 'Type' to create the authentication provider, if our authentication provider Siteminder

    We are 11.1.1.7 OBIEE and authenticator by default works fine and environrment TR upa and race


    Thank you

    Check the Doc ID 1287479.1

    If brand aid

  • OBIEE 101341 & password for ldap authentication

    Hello

    We strive to implement LDAP authentication for our users to obiee using ADSI option. The users passwords are encrypted to the LDAP server. Support for OBIEE LDAP authentication mechanism - only clears passwords to verify the credentials of the user?


    We tried once in the past to set the LDAP authentication, when we were on 782 Analytics Siebel and Oracle said encrypted passwords don't are not supported for LDAP authentication in this version od Siebel Analytics 782. Now that we have upgraded to OBIEE 101341, we want to try again and see. Any body let me know if the OBIEE LDAP authentication mechanism supports passwords encrypted in the clear.

    Thank you

    BI Server uses passwords in clear text in the LDAP authentication. Make sure that your LDAP servers are set up to allow this. No support for encrypted password. Hope this helps

  • Column on OBIEE report-level security.

    Hello
    I have a requirement in my project where some users must be restricted to show only some of the columns and others need to display all available columns.
    I know that users can be restricted by data (IE lines of the report), but I have never tried on columns.
    Please suggest if we succeed in OBIEE and how?
    Thank you
    Swami

    Read this:

    http://www.biconsultinggroup.com/knowledgebase.asp?CategoryID=198&SubCategoryID=369

  • Synchronize the analog continuous entry and continuous analog output using the unique PCI6024E data acquisition card

    Hello

    I want to generate the continuous signal and at the same time I want to read that signal that I generate using a single card DAQ. I want to generate signal and the received signal is synchronized and in phase.

    I looked at several samples on the sync, but it quiet confusing. One using the same clock of entry while the other use a trigger to start. I use the PCI-6024E DAQ card.

    Can someone help me in this regard?

    In two of these screenshots, the task to HAVE started first (that's what you want, because it is the task of the slave).

    Typically for AO, you can simply write a unique period of your waveform, and then regenerate again and again.  Your waveform would be preset before the task starts.  If you need to update the waveform on the fly according to enter programming during execution of the task, you would disable the regeneration.  In addition, if the wave form is such that it cannot be easily represented by a predefined buffer (for example, it is a strange frequency which is not a same ditch at the bottom of the sample clock), then non-regeneration is the way to go.

    Best regards

  • All available UNIQUE authentication mechanism between WebCenter portal and WebCenter Sites - 11.1.1.8.0?

    Hello

    Can someone let me know if there is any solution SSO already existing (as OID/OAM?) to integrate WebCenter portal and WebCenter Sites.

    All links to literature references will be greatly useful.

    Thank you

    Jean Claude

    Hello.

    Integration of Oracle Access Manager with Oracle WebCenter Sites - 11g Release 1 (11.1.1.8.0)

    It explains how to set up Sites to use OAM classes to set the same Cookies------authentication process.

    It should be enough to have Sites and the portal under the same SSO solution.

    Kind regards.

  • vCenter does not start after the upgrade from 5.1 5.1 U1b (UNIQUE authentication failed)

    Hello

    We have upgrade to vCenter Server (build 880146) 5.1.0a to vCenter Server 5.1. U1b and now vcenter service does not start

    This is the log:

    2013 10-21 T 10: 58:40.221 + 02:00 [02800 info '[OSP]'] [UserDirectorySso] GetUserInfo (Administrators, true)

    2013 10-21 T 10: 58:40.221 + 02:00 [02800 info "[OSP] [SsoAdminFacadeImpl]"] [GetDomains]

    2013 10-21 T 10: 58:40.252 + 02:00 [02800 info "[OSP] [SsoAdminFacadeImpl]"] [LazyInitAdmin] initialization

    2013 10-21 T 10: 58:40.252 + 02:00 [02800 info "[OSP] [SsoAdminFacadeImpl]"] [InitSsoAdminServices]

    2013 10-21 T 10: 58:40.252 + 02:00 [02800 info "[OSP] [SsoAdminFacadeImpl]"] [CreateAdminSsoServiceContent] try to connect to the administration of the SSO server.

    2013 10-21 T 10: 58:40.330 + 02:00 [02800 info "[OSP] [SsoAdminFacadeImpl]"] [InitSsoAdminServices] successfully.

    2013 10-21 T 10: 58:40.330 + 02:00 [02800 info "[OSP] [SsoAdminFacadeImpl]"] [LoginToAdmin]

    2013 10-21 T 10: 58:40.330 + 02:00 [02800 info "[OSP] [SsoAdminFacadeImpl]"] [CheckTokenValidity]

    2013 10-21 T 10: 58:40.330 + 02:00 [02800 info "[OSP] [SsoAdminFacadeImpl]"] [CheckTokenValidity] refreshing SSO token...

    2013 10-21 T 10: 58:40.330 + 02:00 [02800 info "[OSP] [SsoAdminFacadeImpl]"] [RefreshSsoToken]

    2013 10-21 T 10: 58:40.408 + 02:00 [02800 error "[OSP] [SsoAdminFacadeImpl]"] AcquireToken [RefreshSsoToken] exception: failed authentication: authentication failed

    2013 10-21 T 10: 58:40.408 + 02:00 [02800 info '[OSP]'] [UserDirectorySso] GetUserInfo NormalizationException: RemoteGetDomainNames RuntimeServiceFault exception: sso.fault.RuntimeServiceFault

    2013 10-21 T 10: 58:40.408 + 02:00 [02800 error '[OSP]'] [UserDirectorySso] NormalizeUserName AuthException: allow exceptions

    2013 10-21 T 10: 58:40.408 + 02:00 [02800 error '[OSP]'] [UserDirectorySso] GetDefaultPrincipal AuthException: allow exceptions

    2013 10-21 T 10: 58:40.408 + 02:00 [02800 info '[OSP]'] GetDefaultPrincipal(, true) [UserDirectorySso]

    2013 10-21 T 10: 58:40.408 + 02:00 [02800 info '[OSP]'] GetUserInfo(, true) [UserDirectorySso]

    2013 10-21 T 10: 58:40.408 + 02:00 [02800 info "[OSP] [SsoAdminFacadeImpl]"] [GetDomains]

    2013 10-21 T 10: 58:40.408 + 02:00 [02800 info "[OSP] [SsoAdminFacadeImpl]"] [LazyInitAdmin] initialization

    2013 10-21 T 10: 58:40.408 + 02:00 [02800 info "[OSP] [SsoAdminFacadeImpl]"] [InitSsoAdminServices]

    2013 10-21 T 10: 58:40.408 + 02:00 [02800 info "[OSP] [SsoAdminFacadeImpl]"] [CreateAdminSsoServiceContent] try to connect to the administration of the SSO server.

    2013 10-21 T 10: 58:40.439 + 02:00 [02800 info "[OSP] [SsoAdminFacadeImpl]"] [InitSsoAdminServices] successfully.

    2013 10-21 T 10: 58:40.439 + 02:00 [02800 info "[OSP] [SsoAdminFacadeImpl]"] [LoginToAdmin]

    2013 10-21 T 10: 58:40.439 + 02:00 [02800 info "[OSP] [SsoAdminFacadeImpl]"] [CheckTokenValidity]

    2013 10-21 T 10: 58:40.439 + 02:00 [02800 info "[OSP] [SsoAdminFacadeImpl]"] [CheckTokenValidity] refreshing SSO token...

    2013 10-21 T 10: 58:40.439 + 02:00 [02800 info "[OSP] [SsoAdminFacadeImpl]"] [RefreshSsoToken]

    2013 10-21 T 10: 58:40.502 + 02:00 [02800 error "[OSP] [SsoAdminFacadeImpl]"] AcquireToken [RefreshSsoToken] exception: failed authentication: authentication failed

    2013 10-21 T 10: 58:40.502 + 02:00 [02800 info '[OSP]'] [UserDirectorySso] GetUserInfo NormalizationException: RemoteGetDomainNames RuntimeServiceFault exception: sso.fault.RuntimeServiceFault

    2013 10-21 T 10: 58:40.502 + 02:00 [02800 error '[OSP]'] [UserDirectorySso] NormalizeUserName AuthException: allow exceptions

    2013 10-21 T 10: 58:40.502 + 02:00 [02800 info '[OSP]'] GetUserInfo(, true) [UserDirectorySso]

    2013 10-21 T 10: 58:40.502 + 02:00 [02800 info "[OSP] [SsoAdminFacadeImpl]"] [GetDomains]

    2013 10-21 T 10: 58:40.502 + 02:00 [02800 info "[OSP] [SsoAdminFacadeImpl]"] [LazyInitAdmin] initialization

    2013 10-21 T 10: 58:40.502 + 02:00 [02800 info "[OSP] [SsoAdminFacadeImpl]"] [InitSsoAdminServices]

    2013 10-21 T 10: 58:40.502 + 02:00 [02800 info "[OSP] [SsoAdminFacadeImpl]"] [CreateAdminSsoServiceContent] try to connect to the administration of the SSO server.

    2013 10-21 T 10: 58:40.533 + 02:00 [02800 info "[OSP] [SsoAdminFacadeImpl]"] [InitSsoAdminServices] successfully.

    2013 10-21 T 10: 58:40.533 + 02:00 [02800 info "[OSP] [SsoAdminFacadeImpl]"] [LoginToAdmin]

    2013 10-21 T 10: 58:40.533 + 02:00 [02800 info "[OSP] [SsoAdminFacadeImpl]"] [CheckTokenValidity]

    2013 10-21 T 10: 58:40.533 + 02:00 [02800 info "[OSP] [SsoAdminFacadeImpl]"] [CheckTokenValidity] refreshing SSO token...

    2013 10-21 T 10: 58:40.533 + 02:00 [02800 info "[OSP] [SsoAdminFacadeImpl]"] [RefreshSsoToken]

    2013 10-21 T 10: 58:40.595 + 02:00 [02800 error "[OSP] [SsoAdminFacadeImpl]"] AcquireToken [RefreshSsoToken] exception: failed authentication: authentication failed

    2013 10-21 T 10: 58:40.595 + 02:00 [02800 info '[OSP]'] [UserDirectorySso] GetUserInfo NormalizationException: RemoteGetDomainNames RuntimeServiceFault exception: sso.fault.RuntimeServiceFault

    2013 10-21 T 10: 58:40.595 + 02:00 [error 02800 "Default"] cannot add the default permission: user not found

    2013 10-21 T 10: 58:40.595 + 02:00 [error 02800 "Default"] cannot start allow - system has no access rule

    2013 10-21 T 10: 58:40.595 + 02:00 [error 02800 'Default'] [Auth] initialization failed: < class Vmacore::Authorize:AuthException(Authorize_Exception) >

    2013 10-21 T 10: 58:40.595 + 02:00 [02800 error 'authvpxdAuthorize'] could not initialize security

    2013 10-21 T 10: 58:40.595 + 02:00 [02800 WARNING "VpxProfiler"] ServerApp::Start [TotalTime] took ms 27456

    2013 10-21 T 10: 58:40.595 + 02:00 [02800 info 'Default'] judgment of VMware VirtualCenter.

    Hello

    VMware support solve my problem:

    We have seen two issues after the update.

    First of all, there is no user of the solution for the virtual center when I checked the application users with SSO to the webclient service administration page.

    Solve us this problem of repointing Virtual Centre to the next according to the kb SSO instance;

    http://KB.VMware.com/kb/2033620

    1. repoint.cmd configure vc - search server https://vcenter.com:7444/lookupservice/sdk - password "laquesea" - openssl-path of the user "admin@System-Domain"-"C:\Program Files\VMware\Infrastructure\Inventory Service\bin."

    After that, the modules in the vpxd.cfg solution was not properly updated and an operation manual.

    C:\ProgramData\VMware\VMware VirtualCenter\SSL\sso.crt

    vCenterServer_251703

    C:\ProgramData\VMware\VMware VirtualCenter\SSL\sso.key

    Above is the corrected version having replaced "null" with the correct path to the files of certificate and key.

    This allowed vcenter service start successfully.

  • Sorting the query according to the unique field data type.

    Hello

    I have a varchar data from the field in a table which cointains 'NumAriques' and 'Alphanumaric '. I need to sort the query using this field.
    While data are numAriques should sort as numAriques else data out as varchar.

    Is it posible in oracle. If so, please help me to get it.

    Hello

    I would do something like this:

    [11.2] Scott @ My11g > !cat t.sql
    with t(n) as (
         select ' 123' from dual
         union all select '123CAD' from dual
         union all select '123TAD' from dual
         union all select '123' from dual
         union all select '1234         ' from dual
         union all select '11111' from dual
         union all select 'zzrytarz' from dual
    )
    ------ end of sample data ------
    select
         n
         -- uncomment 2 following line to ease understanding :
         --,case when regexp_like(trim(n),'^\d+$') then 1 else 2 end
         --,case when regexp_like(trim(n),'^\d+$') then to_char(to_number(n),'fm00000000000000000000') else n end
    from t
    order by
         case when regexp_like(trim(n),'^\d+$') then 1 else 2 end
         ,case when regexp_like(trim(n),'^\d+$') then to_char(to_number(n),'fm00000000000000000000') else n end
    /
    
    [11.2] Scott @ My11g > @t
    
    N
    -------------
     123
    123
    1234
    11111
    123CAD
    123TAD
    zzrytarz
    
    7 rows selected.
    

Maybe you are looking for