The Developer Portal and internal users

Hello

I have configured on our ISE to use AD-users as sponsors. And it works perfectly.

but I also try to set up an internal user to the portal of the sponsor.

I've configured almost the same so I don't understand why the LSE reports:
Authentication of the sponsor has failed: not found for the user Sponsorgroup

My identity store is a sequence of the my and internal users and I can see from the log it looks like the right place:

Identity store:

Internal users

My condition is that the internal user, must be a member of the group identity: sponsorAllAccount

my home group:

Group membership:

SponsorAllAccount

and then get a group created promoter, this grop of sponsor which is allocated to the State, works very well for det AD-users.

Evaluate the politics of identity

5435 sponsor authentication failed

any suggestions why?    I now use the lastes 1.1.1 version.

BR

Tuva

Yes,

For your internal groups use the condition of group identity preconfigured on the left.

I don't know why there is an option on the left, he has not worked for me either in the authorization policies.

Thank you

Sent by Cisco Support technique iPad App

Tags: Cisco Security

Similar Questions

  • Separate authentication for external and internal users?

    Hello

    Asked me to come with a CEP for a client who wants a new system APEX is accessible to internal and external users. The client security team want to have two separate copies of the request for the APEX and both copies of the auditor of the APEX on separate databases on two separate servers from Weblogic to support different security requirements for both internal and external users. I don't think that is necessary as APEX should be able to impose conditions depending on what type of user is connected, by questioning the cookie passed in which could contain a flag to say whether the user is internally and externally. In addition, CAE can be used to further restrict external access.

    The middleware for the customer solution is managed by a third party, who have made the following recommendations:

    The domestic channel requires SSO to configure on WebLogic while the outside lane. Internal users must be validated on Active Directory, with RSA Authentication Manager used for external users. We cannot set up a listener APEX instance to use and not to use SINGLE sign-on at the same time. Two applications are necessary.

    Now, I understand from my understanding limited the listener of the APEX, it is possible to implement different rules depending on the type of user to access. However, might just as well not be managed from Magnatune APEX? We could write a custom authentication procedure that verifies again road and the SSO user authentication cookie or otherwise, as required.

    So my question is this: can it really be necessary to implement two versions of an APEX application, with two distinct on different servers APEX headphones, to meet the security requirements of separate here? Ultimately at the end of the day if that's what the customer wants, we have to build it, but I'm looking to reassure them via a CEP that won't be necessary. I think that the seller of hardware/middleware recommend that the client just because they do not know available in APEX itself custom authentication options.

    Please forgive any simplifications or the lack of details in the above - I'm more a developer APEX as a person of the infrastructure and a bit of a 'newbie' where the listener APEX is concerned. All advice gratefully appreciated!

    Graham.

    Hi Graham,

    It's a matter of people paranoid how and to what extent they trust their own infrastructure. Things could be easier than to split the environments, but I don't know if I just depends on the cookie because cookie can be easily rigged. But I think that the following architecture would be safe:
    1 internal users connect APEX listener somehow security team requires, come to APEX and maybe be identified using the internal IP address (range). To simulate the INVESTIGATION period should be difficult for external users.
    2. external users connect APEX listener through a defined gateway, preferably a proxy. All future requests through this gateway would be considered external users.
    You may add additional logic to the proxy, for example use something like 'mod_headers' in Apache HTTPD to add a page header to requests, so that you may identify as external users.
    You could, of course, also put it the other Tower and allow internal users to use some proxy to enforce certain rules of IP based address, or perhaps a few additional references as authentication for access to the proxy (which again could be transparent user in AD-configuration, at least if you stick with IE).

    You can easily implement the separation in your custom authentication process. But this architecture also allows some other compromise: even if someone does not trust your application logic to handle two types of application successfully, you can also use the proxy to enforce the specific call for an application id. Certainly you don't need to duplicate the infrastructure...
    Most of the companies already have a proxy for external users, for example to activate SSL and to hide other internal resources, for load balancing,... so I think you just need to put some configuration of the existing infrastructure and end up needing no component additional. Even if there is no proxy and yet, it would be an element of very light weight, easy to handle.

    So far, all this has nothing to do with the earpiece of the APEX. It's 'just' a web front-end for the instance of the APEX in the database. I wouldn't put a logic of network security in this service, but the split things upward front. The APEX listener can be patched to add some logic, but which was not supported.

    I think that this would work and should be sufficient for most of the safety requirements.
    If my picture was not painted understandable, let me know.

    -Udo

  • Download reports on applications in the Developer Portal

    Hi all

    In the Developer Portal, when I download a report on my app, it shows me a graph of downloads in the dates, I said. Is there a way to generate the number of downlaods in the specified date or is the only way to add each day one at a time?

    I would like to know how many people have downloaded my app, the v1 and v2.

    Thank you


  • Hello. I have the DVD of Lightroom 5.7.1 version. He just started is behaving badly and I've deleted and reinstalled the product. When I'm in the 'development' module, I get random stains of color in my images. This only happens in the develop module and

    Hello. I have the DVD of Lightroom 5.7.1 version. He just started is behaving badly and I've deleted and reinstalled the product. When I'm in the 'development' module, I get random stains of color in my images. This only occurs in the develop module and no where else. It also does not reach any other software or area on my pc. I also changed the cable and the same triesd another monitor. Anyone have any ideas? Thank you.

    Are patches of red and blue color?

    If so, you probably have warnings of cutting of light/shadow enabled. Press J to hide them.

    You can also activate their power by clicking on the arrows up left and right of the histogram.

    Salient facts cut medium red, medium blue clipped shadows.

  • When you use the brush in the development module and I have a lot less brushes to create an image, the program hangs up to what I sometimes have to use windows to complete the task.  I have ICC Intel i7 3.4 and 16 GB of RAM to operate Windows 7.  Why hang

    When you use the brush in the development module and I have a lot less brushes to create an image, the program hangs up to what I sometimes have to use windows to complete the task.  I have ICC Intel i7 3.4 and 16 GB of RAM to operate Windows 7.  Why hang up LR

    Doing a lot of brushing up on an image using Lightroom is known to have this problem. The first thing to try is to turn off the graphics acceleration (go to Preferences/Performance tab and then uncheck the box here). IF this does not help, then you can consider doing your brush in Photoshop Elements or Photoshop, instead of brushing in Lightroom.

  • I lost my 'Base' Panel in the develop module, and can not find a way to get it back. My right panel will of the histogram to the right in the tone curve Panel.  My basic Panel should be below the histogram.  Any ideas how to get it back.  I don't even hav

    I lost my 'Base' Panel in the develop module, and can not find a way to get it back. My right panel will of the histogram to the right in the tone curve Panel.  My basic Panel should be below the histogram.  Any ideas how to get it back.  I even uninstalled my lightroom and reinstalled with the same problem.  Help!

    Right-click on or near one of the other headers and a pop-up will appear and you will be able to select the base to the display panel.

  • Use the connection to the server externally and internally for PCoIP?

    Another great video, very well explained. Just a question, it is not possible to use a connection to the server for both internal and external users PCoIP? You must use servers to separate connection, one at gateway PCoIP to external users and other to PCoIP direct links?

    You could, but internal users would cross the bridge PCOIP.   I' always found lve easier just have a broker for external users.

  • Error Client Services for NetWare has disabled the Welcome screen and fast user, any change by changing the account settings

    Original title: "Client Services for NetWare."

    When I try to change my account settings, I get this message "client for NetWare has disabled the display of welcome and Fast User Switching.

    To restore these features, you must uninstall Client Services for Netware ".»

    I checked and the customer service is not installed on this computer.

    He puts this message up no matter what I try.

    What can I do to remove this problem?

    Hello

    Were there any changes made to the computer before the show?

    Please follow the steps in the link.

    Error message when you try to turn on welcome screen or Fast User Switching

    http://support.Microsoft.com/kb/315347

  • Two days ago, I was working in the develop module and all of a sudden the primary develop metrics box (temp, tint, exposure, contrast, etc) simply disappeared. I've tried everything I know to do to restore this critical area including close LR one

    In the development of Lightroom 5 module the main pane of corrections disappeared.  Any suggestions on how to get it back? I have an iMac.

    Make a right-click or Cmd-click on one of the other headers as tone curve Panel and make sure that there is a check mark in Basic on the shortcut menu that appears.

  • The new update to aurora made the Developer Edition and I deleted all my favorites,

    and Yes, I know now that I was able to save them, I know that there must be ways to get back them?

    See:

    There are several themes available via the buttons on the palette to customize.

  • References: Different Aspect in the development system and Run Time System

    I noticed a difference the appearance of references in system development and run time system.  He seems to have no effect in the executable version, but, out of curiosity, anyone has an explanation?

    Development system

    Run time system

    Jean-Marc

    TST wrote:

    When LabVIEW generates an executable file, it deletes the parts which are not necessary the screw (like the comics, or FPs of screws that will not open). I guess that's an extension of the one where the icon is not copied on. Another option is that RTE simply lack the code necessary to display this specific to this.

    In any case, I would say that this is a bug, even if it is minor.

    I don't think it's a bug, the summary of references to a CTL file, which is not present in the RTE, I think that LabVIEW disconnected from the reference shape the typedef and saves only the required properties.

    Tone

  • In Lightroom CC my dehaze cursor keeps disappearing. To retrieve for each image, I have to go in the calibration Panel in the develop Module and set it to 2012 (ongoing). Then he wrks. But only for images. I have to go through this process forever

    In Lightroom CC on a Mac, I have to go to the camera Calibration Panel in the module development for each image and change the drop-down list of effects to read 2012 (current) in order to make my cursor active, or usable dehaze. But I can't make the change for 2012 (current) 'sticky '. It is up to 2013 and my cursor dehire becomes ineligible for the next image every time. Someone at - it a solution? Thank you!

    Problem solved by the first installation of L 6.0, and then upgrade to 6.3 LR

    ~ Rohit

  • Discovers the connection Broker (the same external and internal DNS) URL

    I am trying to determine if its possible to connect internal broker who resolves internal view.compay.com (10.1.1.10) and say a security server located in the DMZ that resolves itself into view.company com (199.10.10.10).  Is it possible to keep this view.company.com for both?  At the moment we just solve internally to desktops.company.com, but I am trying to determine how it would be possible to use the same in both.

    You can have the will of the URL to the same name.    We have our internal DNS pointing to the name company.view.com and then from outside company.view.com resolves to our security server.

  • ISE according to the time portal comments

    G ' Day all,

    Could anyone advise if it is possible to extend or change the time profile of a guest account that has already been created? I'm trying to understand the use of time within the portal of Sponsor profiles. Imagine that a guest user has an account that gives them access to 2 weeks, by the end of the 2 weeks that the user requires another week of access.

    Of what I see as the time ISE profile page in the Developer Portal and config, is the user would have to wait before the expiry of the existing account and have a new account created or a new account must be created to grant additional access and the existing account could be deleted, I'm looking just for clarification if an extension of time for guest accounts is possible before the end of the account.

    Currently using ISE 1.1.3

    Thanks to the advanced guys.

    James.

    Hello

    Yes, I have increased the TAC issue and they notified me that the current version of ISE does not support guest accounts online updates, as the time profile sets the expiration date and then is not editable after that.

    Thank you

    Dave

  • How do I add a user to the partner portal

    How can I add a user on our partner portal?

    Add the person you want to add to the partner portal as a user at one of the sites in your partner portal. Contact the BC (by chat or ticket) and let them know that you want to add user X to your partner portal, give them the email of the user and the site they are currently a user. BC will then add them.

Maybe you are looking for

  • can I have new paragraphs or lists in a cell in numbers?

    I know it's a spreadsheet software, but only occasionally, I have cells that I want to make a large amount of text I would like to divide, if it is not ideally lists, then at least start a new line. I don't see how though.

  • Pavilion 500-160ev: CPU fan control

    Hello.im trying to figure out how to increase the number of turns of my cpu (pwm) fan in my Desktop hp Pavilion 500-160ev. I tried to do it in the BIOS, but there is no such option. Also I updated my BIOS but I can't find anywhere where to change the

  • LabVIEW crashing whenever I try to execute / compile an FPGA VI

    I have a project of RT using a cRIO-9012 / 9112 and every time that I hit on the FPGA VI, the compilation process starts but immediately blocked LabVIEW.  The FPGA code is simple - just a development which is basically copied from the VI example OR f

  • How can I find and repair a corrupted registry key

    How can I find and repair a corrupted registry key

  • Model number 15 laptop computer d051sa...

    OK I posted a few days ago on my PC laptop battery not charging I think now question not fixed wrong and lose the problem more info about contection between cord and laptop power in decision let no., I think that question need she will review by some