Leave a Comment:
14 comments
One problem I’m having with WNA configuration with OAM11g and EBIS is the encryption type. DES encryption is turned off by default in Windows 7 and Windows Server 2008 R2 and it is DES encryption that seems to be required for this type of setup on linux. We tried making all Win7 domain users use DES encryption but it caused them to be unable to change their passwords. So DES is definitely out for us. Not sure what else we can do…
ReplyHello Atul:
Can we configure webgate for IIS 5.O running in Windows 2000 machine. If so, can you please explain me how can it be done? Are there any webgate versions available?
Thanks,
Venkat
Hi Atul,
I have configured OID as default user store in OAM. With this I have to implement WNA. and I have mentioned OID as user store in the LDAP Authentication Module , Created the Kerberos Authentication Module named WNA_OID, and pointed WNA_OID module in KerberosSchemeOID with challenege Method as WNA. Now in an Application domain I have created a WNA policy which protectes the wnatest.html page and has KerberosSchemeOID.
OID, OAM and the wnatest.html pages are on same linux server whereas AD is on different Windows machine.
I have already verified the knit and klist command on the linux server (where OAM and OID are installed)and found authenticated.
There is a user present in both AD and OID with same password.
I have enabled WNA in IE of AD machine and while testing WNA , I found “An incorrect Username or Password was specified” error and when I have disbled WNA from IE and then it pops up for credentials . When I entered manually like username: abc.kjl, and password maually, it authenticates and allow to see the home page.
So it looks the credentails taken from desktop login are not working , while when maually passed the credential it works and get authenticated from OID.
Please suggest what should I do to make WNA happen automatically with WNA enabled in IE.
when checked the OAM log I found below error :
Please advice.
Thanks
ReplyI have checked the OAM log and found below error. Please suggest.
Thanks
Reply[2014-03-26T09:23:21.447-05:00] [oam_server1] [ERROR] [] [oracle.oam.proxy.oam] [tid: [ACTIVE].ExecuteThread: ‘1’ for queue: ‘weblogic.kernel.Default (self-tuning)’] [userId: ] [ecid:
9f3fcf5e6669ac10:452849f0:144feb12069:-8000-0000000000000012,1:21415] [APP: oam_server#11.1.2.0.0] Session invalid as returned by PBL_check_valid_session_response responseEvent fail for user
DnU=CN%3Dweblogic,cn%3Dusers,dc%3Daccenture,dc%3Dcom
[2014-03-26T09:27:05.014-05:00] [oam_server1] [ERROR] [] [oracle.oam.proxy.oam] [tid: [ACTIVE].ExecuteThread: ‘0’ for queue: ‘weblogic.kernel.Default (self-tuning)’] [userId: ] [ecid:
9f3fcf5e6669ac10:452849f0:144feb12069:-8000-0000000000000012,1:21746] [APP: oam_server#11.1.2.0.0] Session invalid as returned by PBL_check_valid_session_response responseEvent fail for user
DnU=CN%3Dweblogic,cn%3Dusers,dc%3Daccenture,dc%3Dcom
[2014-03-26T09:30:37.329-05:00] [oam_server1] [ERROR] [OAMSSA-20027] [oracle.oam.user.identity.provider] [tid: [ACTIVE].ExecuteThread: ‘0’ for queue: ‘weblogic.kernel.Default (self-tuning)’]
[userId: ] [ecid: 9f3fcf5e6669ac10:452849f0:144feb12069:-8000-000000000000004c,0] [APP: oam_server#11.1.2.0.0] Could not get user : Acc1234$$, idstore: OID, with exception:
oracle.security.idm.ObjectNotFoundException: No User found matching the criteria.
[2014-03-26T09:49:30.818-05:00] [oam_server1] [ERROR] [OAM-02010] [oracle.oam.controller] [tid: [ACTIVE].ExecuteThread: ‘1’ for queue: ‘weblogic.kernel.Default (self-tuning)’] [userId: ]
[ecid: 9f3fcf5e6669ac10:452849f0:144feb12069:-8000-0000000000000063,0] [APP: oam_server#11.1.2.0.0] User account is locked. Authentication failed.
[2014-03-26T10:42:00.802-05:00] [oam_server1] [ERROR] [] [oracle.oam.proxy.oam] [tid: [ACTIVE].ExecuteThread: ‘1’ for queue: ‘weblogic.kernel.Default (self-tuning)’] [userId: ] [ecid:
9f3fcf5e6669ac10:452849f0:144feb12069:-8000-0000000000000012,1:21912] [APP: oam_server#11.1.2.0.0] Session invalid as returned by PBL_check_valid_session_response responseEvent fail for user
DnU=CN%3Dweblogic,cn%3Dusers,dc%3Daccenture,dc%3Dcom
[2014-03-26T10:42:00.802-05:00] [oam_server1] [ERROR] [] [oracle.oam.proxy.oam] [tid: [ACTIVE].ExecuteThread: ‘0’ for queue: ‘weblogic.kernel.Default (self-tuning)’] [userId: ] [ecid:
9f3fcf5e6669ac10:452849f0:144feb12069:-8000-0000000000000012,1:21913] [APP: oam_server#11.1.2.0.0] Session invalid as returned by PBL_check_valid_session_response responseEvent fail for user
DnU=CN%3Dweblogic,cn%3Dusers,dc%3Daccenture,dc%3Dcom
[2014-03-26T11:14:19.339-05:00] [oam_server1] [ERROR] [] [oracle.oam.proxy.oam] [tid: [ACTIVE].ExecuteThread: ‘1’ for queue: ‘weblogic.kernel.Default (self-tuning)’] [userId: ] [ecid:
9f3fcf5e6669ac10:452849f0:144feb12069:-8000-0000000000000012,1:23913] [APP: oam_server#11.1.2.0.0] Session invalid as returned by PBL_check_valid_session_response responseEvent fail for user
DnU=cn%3Dweblogic,cn%3Dusers,dc%3Daccenture,dc%3Dcom
[2014-03-26T11:14:43.694-05:00] [oam_server1] [ERROR] [OAMSSA-20023] [oracle.oam.user.identity.provider] [tid: [ACTIVE].ExecuteThread: ‘1’ for queue: ‘weblogic.kernel.Default (self-tuning)’]
[userId: ] [ecid: 9f3fcf5e6669ac10:452849f0:144feb12069:-8000-00000000000000b6,0] [APP: oam_server#11.1.2.0.0] Authentication Failure for user : weblogic, for idstore OID with exception
invalid username/password with primary error message [LDAP: error code 49 – Invalid Credentials]
[2014-03-26T11:45:36.412-05:00] [oam_server1] [ERROR] [OAM-02010] [oracle.oam.controller] [tid: [ACTIVE].ExecuteThread: ‘0’ for queue: ‘weblogic.kernel.Default (self-tuning)’] [userId: ]
[ecid: 9f3fcf5e6669ac10:452849f0:144feb12069:-8000-00000000000000f3,0] [APP: oam_server#11.1.2.0.0] User account is locked. Authentication failed.
[2014-03-26T11:48:26.928-05:00] [oam_server1] [ERROR] [OAM-02010] [oracle.oam.controller] [tid: [ACTIVE].ExecuteThread: ‘0’ for queue: ‘weblogic.kernel.Default (self-tuning)’] [userId: ]
[ecid: 9f3fcf5e6669ac10:452849f0:144feb12069:-8000-000000000000010e,0] [APP: oam_server#11.1.2.0.0] User account is locked. Authentication failed.
ReplyHi Atul,
Any help on the above error which I am facing while doing WNA with OAM 11g R2 where OID is the Primary and System Store… please suggest.
I am struggling with this error.
Thanks,
Reply@USer1
Check if user is available in both OID & AD and account is not locked.
—–
Regards
Atul Kumar
Contact Us for Consulting Services
Thanks Atul for the reply.
Yes user is present in both OID & AD and is part of Administrator Group in both places.
Now I am getting only one error as mentioned below
[2014-03-27T10:45:01.395-05:00] [oam_server1] [ERROR] [OAM-02010] [oracle.oam.controller] [tid: [ACTIVE].ExecuteThread: ‘0’ for queue: ‘weblogic.kernel.Default (self-tuning)’] [userId: ] [ecid: 9f3fcf5e6669ac10:-2fdcd47:145035f6363:-8000-0000000000000108,0] [APP: oam_server#11.1.2.0.0] User account is locked. Authentication failed.
I was able to solve the below two errors by adding the OID authentication Provider in weblogic
9f3fcf5e6669ac10:452849f0:144feb12069:-8000-0000000000000012,1:23913] [APP: oam_server#11.1.2.0.0] Session invalid as returned by PBL_check_valid_session_response responseEvent fail for user DnU=cn%3Dweblogic,cn%3Dusers,dc%3Daccenture,dc%3Dcom
[2014-03-26T11:14:43.694-05:00] [oam_server1] [ERROR] [OAMSSA-20023][oracle.oam.user.identity.provider] [tid: [ACTIVE].ExecuteThread: ’1′ for queue: ‘weblogic.kernel.Default (self-tuning)’] [userId: ] [ecid:9f3fcf5e6669ac10:452849f0:144feb12069:-8000-00000000000000b6,0] [APP: oam_server#11.1.2.0.0] Authentication Failure for user : weblogic, for idstore OID with exception invalid username/password with primary error message [LDAP: error code 49 – Invalid Credentials]
Please guide
Thanks
ReplyHi. I wonder if you had any experience to reset EBS passwords after implementing SSO with WNA. Some of our users have “Both” as SSO Login type profile option and will be forced to change their EBS passwords time to time. Because user record is linked with SSO – Password is unchangeable. Could you please advise. Thanks
Reply[…] http://idm-world.blogspot.in/2013/09/configuring-oracle-access-manageroam.html http://www.ateam-oracle.com/part-2-how-to-configure-oam11g-wna-for-multiple-ad-forests/ http://onlineappsdba.com/index.php/2012/05/01/oam-11g-integration-with-microsoft-windows-active-dire… […]
Reply