Wednesday, June 29, 2016

Oracle Identity Manager SQL Queries


SQL Query  to check Account Status

select usr.usr_login,usr.usr_key,ost.ost_status,obj.obj_name,oiu.obi_key
from OST INNER JOIN (OBJ INNER JOIN (OBI INNER JOIN (USR INNER JOIN OIU on oiu.usr_key = usr.usr_key)
on obi.obi_key = oiu.obi_key)
on obj.obj_key = obi.obj_key)
on ost.ost_key = oiu.ost_key
where usr.usr_login = 'XXXXX';

Checks the Policy Evaluation Queue

SELECT USR.USR_KEY,
USR.USR_LOGIN,
USR.USR_STATUS,
USER_PROVISIONING_ATTRS.POLICY_EVAL_NEEDED ,
USER_PROVISIONING_ATTRS.POLICY_EVAL_IN_PROGRESS
FROM USER_PROVISIONING_ATTRS USER_PROVISIONING_ATTRS ,
USR USR
WHERE USER_PROVISIONING_ATTRS.USR_KEY = USR.USR_KEY
AND USER_PROVISIONING_ATTRS.POLICY_EVAL_NEEDED =1
AND USER_PROVISIONING_ATTRS.POLICY_EVAL_IN_PROGRESS != 1

AND USR_STATUS NOT IN ('Deleted','Disabled','Rejected','Disabled Until Start Date');

Query to find Audit Records

select * from upa_fields where upa_usr_key in (select upa_usr_key from upa_usr where usr_key ='XXXXX') order by update_date;


Thanks to Vasanth for Sharing these queries ,

user weblogic soft locked

Fix:
Stop all the servers including Adminserver.
Connect with OIM Schema to the database in my case it was PROD_OIM query usr table and you can find the USR_LAST_NAME (WEBLOGIC) is locked.

Manually
update the column like update PROD_OIM.usr set USR_LOCKED=0 where USR_LAST_NAME='WEBLOGIC'
update DEV1_OIM.usr set  USR_LOGIN_ATTEMPTS_CTR=0 where USR_LAST_NAME='WEBLOGIC'
update DEV1_OIM.usr set USR_LOCKED_ON = null where USR_LAST_NAME='WEBLOGIC'

And restart Admin server.

OIM Authenticator [user weblogic soft locked]


AdminServer-diagnostic.log:[2016-06-28T17:23:49.695+10:00] [AdminServer] [ERROR] [] [OIM Authenticator] [tid: [ACTIVE].ExecuteThread: '0' for queue: 'weblogic.kernel.Default (self-tuning)'] [userId: ] [ecid: 97d01cde0ab00d89:-10597b02:1555023c94a:-8000-00000000000114f2,0] [APP: consoleapp] User weblogic soft locked
AdminServer-diagnostic.log:[2016-06-29T21:01:18.339+10:00] [AdminServer] [ERROR] [] [OIM Authenticator] [tid: [STANDBY].ExecuteThread: '403' for queue: 'weblogic.kernel.Default (self-tuning)'] [userId: ] [ecid: 97d01cde0ab00d89:-10597b02:1555023c94a:-8000-0000000000012ac8,0] [APP: consoleapp] User weblogic soft locked
AdminServer-diagnostic.log:[2016-06-29T21:05:39.810+10:00] [AdminServer] [ERROR] [] [OIM Authenticator] [tid: [STANDBY].ExecuteThread: '404' for queue: 'weblogic.kernel.Default (self-tuning)'] [userId: ] [ecid: 97d01cde0ab00d89:-10597b02:1555023c94a:-8000-0000000000012aca,0] [APP: consoleapp] User weblogic soft locked
AdminServer-diagnostic.log:[2016-06-29T21:06:02.016+10:00] [AdminServer] [ERROR] [] [OIM Authenticator] [tid: [STANDBY].ExecuteThread: '400' for queue: 'weblogic.kernel.Default (self-tuning)'] [userId: ] [ecid: 97d01cde0ab00d89:-10597b02:1555023c94a:-8000-0000000000012acc,0] [APP: consoleapp] User weblogic soft locked
AdminServer-diagnostic.log:[2016-06-29T21:12:08.892+10:00] [AdminServer] [ERROR] [] [OIM Authenticator] [tid: [STANDBY].ExecuteThread: '405' for queue: 'weblogic.kernel.Default (self-tuning)'] [userId: ] [ecid: 97d01cde0ab00d89:-10597b02:1555023c94a:-8000-0000000000012ace,0] [APP: consoleapp] User weblogic soft locked

Delete Lines containing specific keyword or multiple keywords using Notepad ++


Goto the search menu Ctrl+F and there to the "Mark" tab. 

Check "Bookmarkline" (if there is no "Mark" tab update to the current version).

Then just enter your search term and click "Mark All"

All line containing the search term are bookmarked.

Now go to the Menu "Search -> Bookmark -> Remove Bookmarked lines"
Done.

Friday, August 21, 2015

FED-10107: Federation does not exist: cannot complete the requested operation

Identity Provider Initiated SSO was failing with the below error ,

Error:[2015-08-21T21:41:10.579+10:00] [wls_oif1] [ERROR] [FED-10107] [oracle.security.fed.eventhandler.profiles.idp.sso.v20.AuthnRequestEventHandler] [tid: [ACTIVE].ExecuteThread: '1' for queue: 'weblogic.kernel.Default (self-tuning)'] [userId: ] [ecid: 0057T2yXfUlAtHWVLyyGOA0003DH000j6^,0:3] [APP: OIF#11.1.1.2.0] [URI: /fed/user/authnoam] Federation does not exist: cannot complete the requested operation

Product: Oracle Identity Federation

The problem is specific to Persistent Name ID Format.


Solutions:

In the case of Persistent Name ID Format,always perform a SP-initiated SSO and also make sure the SP sets AllowCreate=true in the SAML AuthnRequest sent to Oracle Identity Federation,This will create a federation record for the User,and thereafter IDP-initiated SSO Works


Monday, July 27, 2015

Oracle Identity Manager Version

How to find OIM Version
===================

Login to DB as OIM schema user and execute the below sql statement. Check the screenshot below.

select xsd_value from xsd where xsd_code='XL_BUILD_NUMBER';


Wednesday, April 16, 2014

Siteminder custom login page – how to post to FCC

With Siteminder, it is possible to use a custom login page for HTML forms authentication (other than the default login.fcc). This custom login page can be a .html file, .asp file, .jsp, file, etc. In order to properly authenticate users, this custom page will need to perform a POST to the .fcc. Here are the basic steps to get this to work:
* In the System tab of the Siteminder admin UI, right-click on Authentication Schemes and select Create Authentication Scheme
* For Authentication Scheme Type, select HTML Form template
* Enter the fully qualified name of the web server hosting your login page
* For Target, enter the relative path to your custom page. By default, this will be set to “/siteminderagent/forms/login.fcc”. As an example, you may want to set it to “/mycustompages/login.asp”
* In your custom login page (“/mycustompages/login.asp”), make sure the form posts to the login.fcc. The example below assumes you are using the default login.fcc located in the forms directory:
*
o form id=”myform” name=”myform” method=”POST” action=”/siteminderagent/forms/login.fcc
* Also, your custom login page must contain the following parameters (which Siteminder expects to be present on the POST request to the .fcc):
*
o input type=text name=”USER”>
o type=password name=”PASSWORD”>
o input type=hidden name=target value=””> [note: in this example, we are parsing the target from the query string. you could also hardcode it]
o
* Assuming your Web Agent has been properly configured, when users now attempt to access Realms protected using this new Authentication Scheme, they will be redirected to your custom login page.
* After entering their credentials and submitting the form, the POST to the FCC will take place which will authenticate the user and redirect them to the original protected target.
More Here
Courtesy:http://www.ssohelp.com/notes/Siteminder_custom_login_page_-_how_to_post_to_FCC