Oracle Bi Solutions

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Tuesday, 12 February 2013

OBIEE 11g - Active Directory Authenication

Posted on 08:07 by Unknown

1. AUTHENTICATION WITH ACTIVE DIRECTORY
1.1 OVERVIEW
This document provides instructions for configuration Oracle BI 11g to authenticate against Active Directory.
With this configuration, the embedded Weblogic LDAP provider will still be the “primary” identity provider, so you don’t need to migrate the “BISystemUser” account or any other system/admin accounts to Active Directory.
The advantage of this is that Oracle BI will still be accessible and running even if the Active Directory server becomes unavailable on the network.
Active Directory will be configured as the “secondary” identity provider, so all you normal end user accounts can be mastered in here. It assumes that all user “groups” will also be stored in Active Directory. So both authentication and authorization of the end users will be handled by Active Directory.
Towards the end there is a section which shows you how to tune the authentication/authorisation processes – this is applicable for very large Active Directory tree structures.


1.2 SET WEBLOGIC LDAP TO “SUFFICIENT”
• Log on to the WebLogic Console as the weblogic adminsitrator account:
http://[BI SERVER]:7001/console


• Click on the “Providers” tab and then click on the “Lock and Edit” button:



1.3 CREATE NEW IDENTITY PROVIDER
• Navigate back to the “Providers” tab by clicking the link at the top of the page:




• Set the following “Name” and “Type” before hitting the “OK” button:
Name: ADAuthenticator
Type: ActiveDirectoryAuthenticator



• You should see you new Identity Provider listed, click on the “ADAuthenticator” link to do some further configuration:


• Set the “Control Flag” parameter to “SUFFICIENT” and then click the “Save” button



• Once saved, go to the “Provider Specific” tab:


• Set the Active Directory configuration parameters as follows:
Host: [AD Server Hostname or IP address]
Port: [AD port e.g. 389]
Principle: [DN for OBI service account, used for connecting to AD to authenticate]
e.g. CN=BIAdmin, OU=Users, DC=mycompany, DC=com
Credential: [password for OBI service account]
Confirm Credential: [password OBI service account]
User Base DN: [DN for the location of users within AD]
e.g. OU=Users, DC=mycompany, DC=com
All Users Filter: (&(sAMAccountName=*)(objectclass=user))
User From Name Filter: (&(sAMAccountName=%u)(objectclass=user))
User Name Attribute: sAMAccountName
Group Base DN: [DN for the location of groups within AD]
OU=Groups, DC=mycompany, DC=com



• Click the “Save” button


• Return back to the “Providers” tab (by clicking the link at the top) and then click the “Reorder” button:



• Move “ADAuthenticator” to the second in the list:


• Click on the “OK” button

• Now click “Activate Changes”



1.4 ENABLE “VIRTUALIZATION”

NOTE: This step is required to enable the use of multiple Identity Providers and also to ensure that users will still be able to log in to OBIEE even if the WebLogic “Admin Server” went down
• Log on to Enterprise Manager as the [BI ADMIN USER] account:

http://[BI SERVER]:7001/em



• Expand “WebLogic Domain”, right-mouse click on “bifoundation_domain” and then choose the following menu option:
Security > Security Provider Configuration




• In the middle of the screen, click the “Configure” button:




• Click the “Add” button to add the following 3 custom properties:
user.login.attr sAMAccountName
username.attr sAMAccountName
virtualize true






• Click the “OK” button at the top-right
• Observe the success message to confirm the parameters have been applied:






1.5 TUNING ACTIVE DIRECTORY FOR LARGE ORGANISATIONS (OPTIONAL)


If you have a very large Active Directory tree structure, then it might cause performance issues during the login process as it takes an extended period of time for authentication and authorisation to complete.
The settings documented in this section can significantly improve performance.
In one example (where users/groups were spread over 150 sub-trees in Active Directory) these settings reduced login times from 5-6 minutes down to just a few seconds.
• Log on to the WebLogic Console as the weblogic adminsitrator account:
http://[BI SERVER]:7001/console
• Navigate to the following screen “Security Realms > myRealm > Providers > Authentication” and click on the link for your “ADAuthentictor”:






• Click the “Lock and Edit” button
• Go to the “Provider Specific” tab and change the following parameters:
Use Token Groups For Group Membership Lookup: [Enable]
Cache Size: 3200





• Click the “Save” button
• Now go to the “Performance” tab of your authenticator and set the parameters as follows:
Max Group Hierarchies in Cache: 1000
Group Hierarchy Cache TTL: 600
Enable SID to Group Lookup Caching: [Enable]
Max SID TO Group Lookups In Cache: 5000




• Click the “Save” Button
• Click the “Activate Changes” button
NOTE: You will need to restart, this will be done in the next section


1.6 RESTART ORACLE BI
• The configuration is now complete, restart all Oracle BI Services:




Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in OBIEE | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Upper Function
    In Oracle/PLSQL, the  upper function  converts all letters in the specified string to uppercase. If there are characters in the string that ...
  • OBIEE 11g Hide/Show Sections based on Dashboard Prompt
    allow a user’s interaction to hide/show certain sections of a dashboard. In this particular case the user wanted to choose either ‘Quarterly...
  • [OBIEE11g] - OBIEE Dashboard for Informatica Metadata Reporting
    The metadata that Informatica Power Center 8 retains in its repository can be exposed via OBIEE reports and dashboards. This metadata includ...
  • [ODI] - Frequently Asked Questions (FAQ)
    Here is a list of FAQs about Oracle Data Integrator 1) What is Oracle Data Integrator (ODI)? 2) What is E-LT? 3) What components make up Ora...
  • OBIEE 11g not showing new dashboard in the drop down menu
    When creating New dashboard in  OBIEE 11g, I have faced with issue that dashboard name did not show up in drop down dashboard menu. 1. When ...
  • Data Modeling: Schema Generation Issue with ERwin Data Modeler 7.3
    We are using Computer Associate’s ERwin Data Modeler 7.3 for data modeling. In one of our engagements, we are pushing data model changes to ...
  • Installation Informatica Powercenter 9.1 on Oracle Enterprise Linux 5.6
    Ingredients: Program Version Filename Oracle Express 11G 11.2.0 oracle-xe-11.2.0-0.5.x86_64.rpm SQL Developer 3.0 sqldeveloper-3.0.04.34-1.n...
  • Informatica Powercenter Workflow Manager Repository Navigator docking float issue
    In case you’re also experiencing where your Repository Navigator is not dock or attached and it seems just floating within Workflow Manager ...
  • [OBIEE11g] - Creating Dashboard Traversing Through Graph
    The general requirement asked for by customers is that they want to Click on the Main Dashboard Page’s Graph and be transferred to the other...
  • OBIEE 11g - Query Limit
    Query limit and number of minutes a query can run per physical layer database connection, follow the below steps. > Login to Repository u...

Categories

  • BI Publisher
  • DAC
  • DataWarehouse
  • Hyperion
  • Informatica
  • OBIEE
  • ODI
  • Oracle Applications EBS 12.1.3
  • Oracle Database
  • PL/SQL
  • SQL
  • Unix/Linux

Blog Archive

  • ▼  2013 (500)
    • ►  November (8)
    • ►  October (1)
    • ►  July (4)
    • ►  June (9)
    • ►  May (15)
    • ►  April (24)
    • ►  March (43)
    • ▼  February (73)
      • Remember Username and Password in Obiee11g
      • Change Locale in OBIEE 11g
      • Change Password in BI Publisher 111.1.6.0
      • OBIEE 11g - Change the Date Format/ Evaluate Function
      • OBIEE 11g - Enabling Sorting order for more than 1...
      • OBIEE 11g - Changing the NodeManager and weblogic ...
      • OBIEE 11g - Description ID column
      • Fact and Dimension from single source Table
      • OBIEE 11g - Denormalizing physical tables in BMM l...
      • OBIEE 11g - ADF Integration
      • BUG:12930924 SAG: CANNOT DISPLAY MORE THAN 300 OBJ...
      • OBIEE 11g - Hide Apply and Reset button
      • OBIEE 11g Security - Creating Application Policies
      • OBIEE11g startup error - An instance of the interf...
      • OBIEE 11g - Partial Update using Condition in Answers
      • OBIEE 11g - custom Date format in Answers
      • The boot identity may have been changed since the ...
      • OBIEE 11g - weblogic admin account creation
      • Informatica PC Upgrade from 861 to 91 Installation...
      • Installation Informatica Powercenter 9.1 on Oracle...
      • How to Start oracel Database 11gR 2 manually on Linux
      • OBIEE 11g - Installation on OEL 5.8
      • OBIEE 11.1.1.6.5 and J Developer Integration on Li...
      • Oracle SQL Developer :Enter full path for java.exe
      • OBIEE 11g - Unable to get file lock , will retry i...
      • OBIEE 11g - Changing Presentation Services Port Nu...
      • OBIEE 11g - Changing the background color on hover...
      • OBIEE 11g - Date Format change based on Locale Set...
      • OBIEE 11g - Javascript and CSS locations
      • OBIEE 11g - Removing the Gray Header from Reports
      • OBIEE 11g - Refreshing a report Everytime
      • OBIEE 11g - Adding Bookmark Link in Dashboard
      • OBIEE 11g - Searching a Text in Page
      • OBIEE 11g - Remember Username and Password
      • OBIEE 11g - Removing/ Deleting Report Links in a Page
      • OBIEE11g - Export to Excel issue
      • OBIEE 11g - Right-click interactions in Dashboard ...
      • OBIEE11g - Right Function
      • OBIEE 11g - Set Default currency in Dashboard
      • OBIEE 11g - Hide BI Portal Name
      • OBIEE 11g - Export or Print Dashboard Page
      • OBIEE 11g - Ldap authentication is failing when us...
      • OBIEE 11g - Warning: "Upgrade is recommended to th...
      • OBIEE 11g - [OracleBIServerComponent] [ERROR:1] [...
      • OBIEE 11g - State: HY000. Code: 10058. [NQODBC] [S...
      • OBIEE 11g - List of System/Predefined Session Vari...
      • OBIEE 11g - Writeback Steps
      • [OBIPS] [ERROR:1] [] [saw.security.odbcuserpopulat...
      • [ERROR:1] [] [] [ecid: 18c5ef9f7c3aec02:-1a7b1b1:1...
      • OBIEE 11g - Important Path Directories
      • OBIEE 11g - OBI Server and Presentation Cache Mana...
      • How to login to OBIEE 11g - With User and Password...
      • OBIEE 11g - Direct Query from Database, bypassed C...
      • OBIEE 11g - Error Codes: OPR4ONWY:U9IM8TAC:OI2DL65P
      • OBIEE 11g - Deploying RPD without BI Presentation ...
      • OBIEE 11g - Dashboard Selective View from Report L...
      • OBIEE11g - RPD Deployment Considerations
      • OBIEE 11g - Starting / Stopping Domain Services in...
      • OBIEE 11g - SQL Conditional COUNT & SUM
      • OBIEE11g - Security Migration
      • OBIEE 11g - Performance Tuning
      • OBIEE 11g - User Guide for BI Mobile
      • OBIEE 11g - Active Directory Authenication
      • OBIEE 11g - Security Troubleshooting
      • DAC - Error "main" java.lang.NoClassDefFoundError...
      • DAC11g Starting issue (-server)
      • OBIEE 11.1.1.6.7 Opatch Apply from 11.1.1.6.0 to 1...
      • OBIEE 11.1.1.6.8 - bugs fixed
      • Informatica Powercenter Workflow Manager Repositor...
      • DAC - Restrict the number of years using Mcal Peri...
      • DAC - Global Currency Code Issue in dac
      • Hyperion Installation 11.1.2.1.0 on Linux 32 Bit
      • OBIEE 11g - Deploying RPD on Linux to Access the L...
    • ►  January (323)
Powered by Blogger.

About Me

Unknown
View my complete profile