4 Replies Latest reply: Apr 21, 2014 7:41 AM by Stevan-Oracle RSS

    Siebel 8.1.1.10 and Web SSO & SDK

    1285169

      Hi,

       

      I have problem with setup SSO auth on Siebel 8.1.1.10.

       

      When connect to OM i have error in log:

       

      5:16 2014-04-16 16:55:16 +0400 00000005 001 003f 0001 09 FINSObjMgr_enu 33554451 10624 7612 D:\ses\siebsrvr\log\SCCObjMgr_enu_0032_33554451.log 8.1.1.10 SIA [23021] ENU

       

       

      GenericLog GenericError 1 00000004534e0b1c:0 2014-04-16 16:55:16 (secmgr.cpp (2608) err=4587621 sys=0) SBL-SEC-00101: An error occurred loading the Siebel authentication subsystem configuration parameters from the configuration store. Please contact your system administrator to check parameter (null).

       

       

      ObjMgrSessionLog Error 1 00000004534e0b1c:0 2014-04-16 16:55:16 (physmod.cpp (9382)) SBL-DAT-00561: An error occurred loading the Siebel authentication subsystem configuration from the configuration store. More specifically, <?>

      Please contact your system administrator for assistance.

       

       

      ObjMgrSessionLog Error 1 00000004534e0b1c:0 2014-04-16 16:55:16 (model.cpp (5978)) SBL-DAT-00561: An error occurred loading the Siebel authentication subsystem configuration from the configuration store. More specifically, <?>

      Please contact your system administrator for assistance.

       

      ObjMgrCTLog Error 1 00000004534e0b1c:0 2014-04-16 16:55:16 (ctxtmgr.cpp (4567)) SBL-SVC-00208: Please login first.

       

       

       

      Setting eapps.cfg

      [include]

      eapps_sia.cfg

      eapps_fins.cfg

      eapps_sis.cfg

       

       

      [swe]

      Language      = ENU

      Log           = errors

      LogDirectory  = d:\sweapp\log

      ClientRootDir = d:\sweapp

      SessionMonitor  = False

      AllowStats      = true

      LogSegmentSize  = 0

      LogMaxSegments  = 0

      DisableNagle    = False

      SeedFile        = seedfile.bin

      IntegratedDomainAuth = TRUE

      SingleSignOn = TRUE

       

       

      [ConnMgmt]

      EnableVirtualHosts = false

      VirtualHostsFile   = d:\sweapp\admin\lbconfig.cfg

      CertFileName       = $(CertFileName)

      CACertFileName     = $(CaCertFileName)

      KeyFileName        = $(KeyFileName)

      KeyFilePassword    = $(KeyFilePassword)

      PeerAuth           = $(PeerAuth)

      PeerCertValidation = $(PeerCertValidation)

       

       

      [defaults]

      EncryptedPassword = FALSE

      AnonUserName  = GUESTCST

      AnonPassword  = ************

      StatsPage     = _stats.swe

      HTTPPort      = 80

      HTTPSPort     = 443

      EnableFQDN          = False

      FQDN                =

      TrustToken          =

      DoCompression       = true

      GuestSessionTimeout = 300

      SessionTimeout      = 3600

       

      [/fins_rus]

      AnonUserName = GUESTCST

      AnonPassword = GUESTCST

      SingleSignon = TRUE

      TrustToken = WIATrust

      UserSpecSource = Server

      UserSpec = REMOTE_USER

      ProtectedVirtualDirectory = /fins_rus

      ConnectString = siebel.TCPIP.None.None://DS-SBLAPP06T:2321/SBA81/FINSObjMgr_enu/

      WebPublicRootDir = d:\sweapp\public\rus

      WebUpdatePassword = support

       

      ---------------------------

      And in fins.cfg i adding string

       

      [InfraSecMgr]

      SecAdptName = WIA

      SecAdptMode = CUSTOM

       

       

      [WIA]

      SecAdptDllName = /ses/siebsrvr/bin/wia.dll

      dbUsername = SADMIN

      dbPassword = ********

      SingleSignOn = TRUE

      TrustToken = WIATrust

       

       

      Please, help....

        • 1. Re: Siebel 8.1.1.10 and Web SSO & SDK
          Stevan-Oracle

          If you are just trying to do Windows Integrated Authentication with IIS as your SSO system, you should not need to use the custom WIA security adapter.  The standard ADSISecAdpt and LDAPSecAdpt in Siebel 8 can handle this natively.  So unless you have made other customizations to the WIA custom security adapter to accommodate other requirements, I would suggest trying to use either the standard LDAPSecAdpt or the standard ADSISecAdpt (assuming your servers are on Windows the ADSISecAdpt is easier to set up in this case).

           

          Also -- although unrelated to this specific issue -- two observations from the information you provided.

           

          1.  The SingleSignOn parameter should not be in the [SWE] section of your eapps file.  It goes in either the [defaults] section or the section for the specific virtual URL.

           

          2.  The DoCompression parameter is somewhat flaky and can result in unpredictable behaviors especially if SSO and/or SSL are involved.  I generally recommend people to set this to false.

           

          Hope this helps.

           

          Stevan - Oracle

          • 2. Re: Siebel 8.1.1.10 and Web SSO & SDK
            1285169

            Stevan. thank's for reply

             

            In fins.cfg i need set this:

             

            [InfraSecMgr]

            SecAdptName = ADSISecAdpt

            SecAdptMode = ADSI

             

            and delete strings -->?

             

            [WIA]

            SecAdptDllName = /ses/siebsrvr/bin/wia.dll

            dbUsername = SADMIN

            dbPassword = ********

            SingleSignOn = TRUE

            TrustToken = WIATrust

            • 3. Re: Siebel 8.1.1.10 and Web SSO & SDK
              Prameela -Oracle

              Hi,

               

              No need to set these parameters at fins.cfg level, from Siebel version 8.x onwards you need to set these values for NamedSubsystem and OM parameter level.

               

              Details have been provided in Siebel Security Book Shelf Guid

               

              https://docs.oracle.com/cd/E14004_01/books/Secur/Secur_SecAdaptAuth23.html#wp1598728e

               

              Hope this helps.

               

              Thanks,

              Prameela

              • 4. Re: Siebel 8.1.1.10 and Web SSO & SDK
                Stevan-Oracle

                As Prameela pointed out in Siebel 8.x you do not need to set these in the .cfg file UNLESS you are using a mobile or dedicated client.  They are set as parameters now from within the UI for the standard thin web client.

                 

                Best regards,

                Stevan - Oracle