Oracle Bi Solutions

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Wednesday, 27 February 2013

The boot identity may have been changed since the b oot identity file was created

Posted on 09:21 by Unknown

1) Boot.properties  :   key file to start the node manager/ weblogic 

weblogic.security.SecurityInitializationException: Authentication denied: Boot i
dentity not valid; The user name and/or password from the boot identity file (bo
ot.properties) is not valid. The boot identity may have been changed since the b
oot identity file was created. Please edit and update the boot identity file wit
h the proper values of username and password. The first time the updated boot id
entity file is used to start the server, these new values are encrypted.
entity file is used to start the server, these new values are encrypted.
        at weblogic.security.service.CommonSecurityServiceManagerDelegateImpl.do
BootAuthorization(CommonSecurityServiceManagerDelegateImpl.java:959)
        at weblogic.security.service.CommonSecurityServiceManagerDelegateImpl.in
itialize(CommonSecurityServiceManagerDelegateImpl.java:1050)
        at weblogic.security.service.SecurityServiceManager.initialize(SecurityS
erviceManager.java:873)
        at weblogic.security.SecurityService.start(SecurityService.java:141)
        at weblogic.t3.srvr.SubsystemRequest.run(SubsystemRequest.java:64)
        Truncated. see log file for complete stacktrace
Caused By: javax.security.auth.login.FailedLoginException: [Security:090304]Auth
entication Failed: User weblogic123 javax.security.auth.login.FailedLoginExcepti
on: [Security:090302]Authentication Failed: User weblogic123 denied
        at weblogic.security.providers.authentication.LDAPAtnLoginModuleImpl.log
in(LDAPAtnLoginModuleImpl.java:261)
        at com.bea.common.security.internal.service.LoginModuleWrapper$1.run(Log
inModuleWrapper.java:110)
        at java.security.AccessController.doPrivileged(Native Method)
        at com.bea.common.security.internal.service.LoginModuleWrapper.login(Log
inModuleWrapper.java:106)
        at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
        Truncated. see log file for complete stacktrace

If you read the bold text your problem/solution is clearly explained at the time of starting BI Services the credentials you entered will store in boot.properties file located at 

\middleware\user_projects\domains\bifoundation_domain\servers\AdminServer\security



when the credentials are wrong then it will throw above error message next time it wont ask again for the password because it already stored at boot.properties file so solution is to delete the file and start the BI Services again this time enter the right credentials without fail and the console should display below message
<Storing boot ide
ntity in the file: \middleware\user_projects\domains\bifoundation_domain\serve
rs\AdminServer\security\boot.properties>

Embedded LDAP Data : Default LDAP server

2)  Weblogic Server’s default security providers use an  embedded LDAP server to persist all security-related data. Each server stores this data locally,including all of the user,group,role,access control policy,and credential information.For each domain,the admin server acts as the master LDAP server and replicates new information to the embedded LDAP running on each of the managed servers.
All the data of the embedded LDAP server will store into a directory 
\middleware\user_projects\domains\bifoundation_domain\servers\AdminServer\data




Whenever a WebLogic Server is started, it places all of its internal files in a server instance-specific directory. By default, the server’s directory is located in the directory it was started from and has the same name as the server instance (for example,
user_projects/bifoundation_domain/AdminServer/data).
 Inside this server directory is an ldap sub directory where you will find the LDAP server’s files.  shows the full directory structure and description of the embedded LDAP server directory contents.

LDAP folder has below details

backup - Zipped backup files created once a day from the ldapfiles directory 
conf - Configuration files that are generated on the first server start
ldapfiles - LDAP server data files
log  - LDAP server log files
replicadata - Managed server replicated data

backup time can be manged from console 


If you ever encounter a problem where a managed server won’t start and you suspect that its LDAP data may be corrupt, you can either try to use one of the backup zip files from the backup directory to revert the contents of the ldap files directory or simply remove the entire ldap directory and let it be recreated when the managed server starts up and connects to the admin server

where ldap_bkp is backup file and ldap  - is newly created one when I start ' Start BI Services' - weblogic
\middleware\user_projects\domains\bifoundation_domain\servers\AdminServer\data\ldap\ldapfiles  has different files but below are key files to know 

EmbeddedLDAP.data - is the main data file where all the users, groups, roles, and policies are stored
EmbeddedLDAP.delete - contains information about deleted entries
EmbeddedLDAP.lok  - 
file is used to ensure access consistency to the LDAP information. In some cases, a Weblogic Server might shutdown without allowing the embedded LDAP server to unlock the data. If this hap-pens, the server will go into a loop, waiting for the file to be removed and printing out a warning message:

<Could not obtain an exclusive lock for directory: \middleware\user_projects\domains\bifoundation_domain\servers\AdminServer\data\ldap\ldapfiles Waiting for 10 seconds and then retrying in case existing Weblogic Server is still shutting down.>

Typically, deleting the EmbeddedLDAP.lok file will resolve this issue

3) Authentication Provider : Control Flag which wont allow you to login analytics 

Authentication Providers are used to derive  login credentials, certificate or custom headers, using some form of LDAP, or other identity store

When a user has configured their custom provider and changed the control flag to required for both the providers (custom and Default Authenticator) 

The Control Flag governs whether authentication from a provider is required. If 
multiple providers are present, then at least one of them must be set to REQUIRED(but not both) You can mess up your domain resulting in not being able to start your server 
anymore (if you use two Authentication Providers, define the Weblogic user in both 
of them and set one to REQUIRED resulting in not being able to access the domain 
anymore). In fact, you should always set the Default Authenticator to REQUIRED.
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in OBIEE | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Upper Function
    In Oracle/PLSQL, the  upper function  converts all letters in the specified string to uppercase. If there are characters in the string that ...
  • OBIEE 11g Hide/Show Sections based on Dashboard Prompt
    allow a user’s interaction to hide/show certain sections of a dashboard. In this particular case the user wanted to choose either ‘Quarterly...
  • [OBIEE11g] - OBIEE Dashboard for Informatica Metadata Reporting
    The metadata that Informatica Power Center 8 retains in its repository can be exposed via OBIEE reports and dashboards. This metadata includ...
  • [ODI] - Frequently Asked Questions (FAQ)
    Here is a list of FAQs about Oracle Data Integrator 1) What is Oracle Data Integrator (ODI)? 2) What is E-LT? 3) What components make up Ora...
  • OBIEE 11g not showing new dashboard in the drop down menu
    When creating New dashboard in  OBIEE 11g, I have faced with issue that dashboard name did not show up in drop down dashboard menu. 1. When ...
  • Data Modeling: Schema Generation Issue with ERwin Data Modeler 7.3
    We are using Computer Associate’s ERwin Data Modeler 7.3 for data modeling. In one of our engagements, we are pushing data model changes to ...
  • Installation Informatica Powercenter 9.1 on Oracle Enterprise Linux 5.6
    Ingredients: Program Version Filename Oracle Express 11G 11.2.0 oracle-xe-11.2.0-0.5.x86_64.rpm SQL Developer 3.0 sqldeveloper-3.0.04.34-1.n...
  • Informatica Powercenter Workflow Manager Repository Navigator docking float issue
    In case you’re also experiencing where your Repository Navigator is not dock or attached and it seems just floating within Workflow Manager ...
  • [OBIEE11g] - Creating Dashboard Traversing Through Graph
    The general requirement asked for by customers is that they want to Click on the Main Dashboard Page’s Graph and be transferred to the other...
  • OBIEE 11g - Query Limit
    Query limit and number of minutes a query can run per physical layer database connection, follow the below steps. > Login to Repository u...

Categories

  • BI Publisher
  • DAC
  • DataWarehouse
  • Hyperion
  • Informatica
  • OBIEE
  • ODI
  • Oracle Applications EBS 12.1.3
  • Oracle Database
  • PL/SQL
  • SQL
  • Unix/Linux

Blog Archive

  • ▼  2013 (500)
    • ►  November (8)
    • ►  October (1)
    • ►  July (4)
    • ►  June (9)
    • ►  May (15)
    • ►  April (24)
    • ►  March (43)
    • ▼  February (73)
      • Remember Username and Password in Obiee11g
      • Change Locale in OBIEE 11g
      • Change Password in BI Publisher 111.1.6.0
      • OBIEE 11g - Change the Date Format/ Evaluate Function
      • OBIEE 11g - Enabling Sorting order for more than 1...
      • OBIEE 11g - Changing the NodeManager and weblogic ...
      • OBIEE 11g - Description ID column
      • Fact and Dimension from single source Table
      • OBIEE 11g - Denormalizing physical tables in BMM l...
      • OBIEE 11g - ADF Integration
      • BUG:12930924 SAG: CANNOT DISPLAY MORE THAN 300 OBJ...
      • OBIEE 11g - Hide Apply and Reset button
      • OBIEE 11g Security - Creating Application Policies
      • OBIEE11g startup error - An instance of the interf...
      • OBIEE 11g - Partial Update using Condition in Answers
      • OBIEE 11g - custom Date format in Answers
      • The boot identity may have been changed since the ...
      • OBIEE 11g - weblogic admin account creation
      • Informatica PC Upgrade from 861 to 91 Installation...
      • Installation Informatica Powercenter 9.1 on Oracle...
      • How to Start oracel Database 11gR 2 manually on Linux
      • OBIEE 11g - Installation on OEL 5.8
      • OBIEE 11.1.1.6.5 and J Developer Integration on Li...
      • Oracle SQL Developer :Enter full path for java.exe
      • OBIEE 11g - Unable to get file lock , will retry i...
      • OBIEE 11g - Changing Presentation Services Port Nu...
      • OBIEE 11g - Changing the background color on hover...
      • OBIEE 11g - Date Format change based on Locale Set...
      • OBIEE 11g - Javascript and CSS locations
      • OBIEE 11g - Removing the Gray Header from Reports
      • OBIEE 11g - Refreshing a report Everytime
      • OBIEE 11g - Adding Bookmark Link in Dashboard
      • OBIEE 11g - Searching a Text in Page
      • OBIEE 11g - Remember Username and Password
      • OBIEE 11g - Removing/ Deleting Report Links in a Page
      • OBIEE11g - Export to Excel issue
      • OBIEE 11g - Right-click interactions in Dashboard ...
      • OBIEE11g - Right Function
      • OBIEE 11g - Set Default currency in Dashboard
      • OBIEE 11g - Hide BI Portal Name
      • OBIEE 11g - Export or Print Dashboard Page
      • OBIEE 11g - Ldap authentication is failing when us...
      • OBIEE 11g - Warning: "Upgrade is recommended to th...
      • OBIEE 11g - [OracleBIServerComponent] [ERROR:1] [...
      • OBIEE 11g - State: HY000. Code: 10058. [NQODBC] [S...
      • OBIEE 11g - List of System/Predefined Session Vari...
      • OBIEE 11g - Writeback Steps
      • [OBIPS] [ERROR:1] [] [saw.security.odbcuserpopulat...
      • [ERROR:1] [] [] [ecid: 18c5ef9f7c3aec02:-1a7b1b1:1...
      • OBIEE 11g - Important Path Directories
      • OBIEE 11g - OBI Server and Presentation Cache Mana...
      • How to login to OBIEE 11g - With User and Password...
      • OBIEE 11g - Direct Query from Database, bypassed C...
      • OBIEE 11g - Error Codes: OPR4ONWY:U9IM8TAC:OI2DL65P
      • OBIEE 11g - Deploying RPD without BI Presentation ...
      • OBIEE 11g - Dashboard Selective View from Report L...
      • OBIEE11g - RPD Deployment Considerations
      • OBIEE 11g - Starting / Stopping Domain Services in...
      • OBIEE 11g - SQL Conditional COUNT & SUM
      • OBIEE11g - Security Migration
      • OBIEE 11g - Performance Tuning
      • OBIEE 11g - User Guide for BI Mobile
      • OBIEE 11g - Active Directory Authenication
      • OBIEE 11g - Security Troubleshooting
      • DAC - Error "main" java.lang.NoClassDefFoundError...
      • DAC11g Starting issue (-server)
      • OBIEE 11.1.1.6.7 Opatch Apply from 11.1.1.6.0 to 1...
      • OBIEE 11.1.1.6.8 - bugs fixed
      • Informatica Powercenter Workflow Manager Repositor...
      • DAC - Restrict the number of years using Mcal Peri...
      • DAC - Global Currency Code Issue in dac
      • Hyperion Installation 11.1.2.1.0 on Linux 32 Bit
      • OBIEE 11g - Deploying RPD on Linux to Access the L...
    • ►  January (323)
Powered by Blogger.

About Me

Unknown
View my complete profile