cancel
Showing results for 
Search instead for 
Did you mean: 

Cannot log into DTR with Active Directory User

Former Member
0 Kudos

Greetings,

I have set up and installed JDI correctly. I can log into /devinf, the cbs, cms and sld systems with no problem using both Administrator and my JDI.Administrator that I assigned to an Active Directory user. I can log into the DTR using a user from the database (i.e. Administrator), however, when trying to access the DTR with an Active Directory user, I get the following message:

500 Internal Server Error

SAP J2EE Engine/6.40

Application error occurred during the request procession.

Details: Error [javax.servlet.ServletException: Group found, but unique name "businessUnit.all.guests" is not unique!], with root cause [com.tssap.dtr.server.deltav.InternalServerException: Group found, but unique name "businessUnit.all.guests" is not unique!]. The ID of this error is

Exception id: [0012798F81680042000000090000165C0003FE9AA3C0B86B].

This group exists in multiple domainshowever, this has not caused us any issues to date with our portal and other pieces of SAP WASit's only this DTR error.

Any help is greatly appreciated.

Thanks,

Marty

Accepted Solutions (1)

Accepted Solutions (1)

Former Member
0 Kudos

Hello Marty,

To use your iNo. for DTR login, please set your password at

Create a user in NWDI using userstore link.

Use this password to login to DTR with you iNo.

Hope this helps.

Regards,

Rahul

Message was edited by: Rahul Tongia

MartyMcCormick
Product and Topic Expert
Product and Topic Expert
0 Kudos

Hi Rahul,

Thanks for your response. I'm not having issues with my iNo, but rather, this is an entirely different Active Directory instance with users/ groups for the portal / JDI.

Any other suggestions?

Thanks,

Marty

former_member183805
Active Participant
0 Kudos

Hi Marty,

In the document available at the link enclosed below, there is a part that explains how to configure DTR so that it always uses "Unique-IDs".

http://help.sap.com/saphelp_nw04/helpdata/en/20/f4a94076b63713e10000000a155106/frameset.htm

It is mentioned that this is valid for LDAP, but the information is applicable for Active Directory as well.

Regards,

Manohar

MartyMcCormick
Product and Topic Expert
Product and Topic Expert
0 Kudos

Thanks for the answer Manoharlooks to be exactly what I need. Howeverit didnt work:( I changed the file by creating a new client, browsing to the repository.properties file, making the change, checking in the activity and then restarting the server.

When I open a web browser to the following url: /dtr/ws/system/config/active/registry/repository.properties , I can see the om.tssap.dtr.server.deltav.security.um.useGroupUniqueId=yes

BUT i still get the same error:(

Am I doing something wrong?

Thanks,

Marty

Former Member
0 Kudos

Hello Marty,

Please change the value to:

com.tssap.dtr.server.deltav.security.um.useGroupUniqueID=<b>true</b>

instead of

com.tssap.dtr.server.deltav.security.um.useGroupUniqueID=<b><i>yes</i></b>.

In addition, please edit your ACL files and replace the group names with their corresponding LDAP unique identifiers.

(The documentation mentioned before also indicates the structure of the unique identifiers)

Regards,

Girish

MartyMcCormick
Product and Topic Expert
Product and Topic Expert
0 Kudos

Thanks for your reply. I switched it to true in both spots (edited on the file system on the portal server as well) and restarted with no luck.

I'm not maintaining permissions in the DTR so I don't have any entries in those XML files. By default the DTR is wide open, correct?

Any other suggestions?

Thanks,

Marty

Former Member
0 Kudos

Can you please browse to

/dtr/ws/system/config/active/registry/repository.properties

and check if the property name/value is casewise exactly:

com.tssap.dtr.server.deltav.security.um.useGroupUniqueID=true

I see from your previous post that the 'D' in useGroupUniqueID is in lower case for you.

MartyMcCormick
Product and Topic Expert
Product and Topic Expert
0 Kudos

Hi Girish,

Thanks for the reply. I just had a typo in my above post. In my repository.properties at the top I have:

com.tssap.dtr.server.deltav.security.um.useGroupUniqueID=true

I have opened an OSS message as well...

Thanks,

Marty

former_member183805
Active Participant
0 Kudos

Update: Note 876889 has been released to address this issue.

Symptom: When using an LDAP user store with DTR, access to DTR may fail with an "Internal Server Error".

MartyMcCormick
Product and Topic Expert
Product and Topic Expert
0 Kudos

Hi Manohar,

I actually worked an OSS Message with support and they delivered the ear file to me earlier this week. Guess that was a driver in this patch and Note;)

Thanks for following up.

Marty

Answers (0)