用户手册目录Contents3About Hyperion Security11Security Components11User Authentication11Authentication Components11Security API12Native Directory12User Directories12User Authentication Scenarios12Single Sign-on Directly to Hyperion Products12Single Sign-on from External Systems13Provisioning (Role-Based Authorization)14Roles15Global Roles16Predefined Roles17Aggregated Roles17Users17Groups17Setting Up Authentication19Setting Up Direct Authentication to Hyperion Products19Creating Users on the User Directory19Creating Groups20Migrating Users and Groups to Shared Services Security20Installing and Deploying Shared Services20Identifying User Directories to Shared Services20Setting Up SSO with SAP Enterprise Portal21Nested SAP Groups22Inheritance Policy for Nested Groups23Deployment Locations23Prerequisites23Setting Up SSO from SiteMinder25Special Considerations26Configuring the SiteMinder Policy Server27Configuring the SiteMinder Web Agent27Enabling SiteMinder Authentication in Shared Services27Other Procedures28Using NTLM to Support SSO28NTLM with UNIX Application Environments29Support for Multiple NTLM Domains29User Management Console33Launching User Management Console33Overview of User Management Console34Navigating in User Management Console34Searching for Users, Groups, Roles, and Delegated Lists34Configuring User Directories37Operations Related to User Directory Configuration37Using the Unique Identity Attribute to Handle Inter-OU Moves in LDAP-Enabled User Directories38Planning the Migration to the Unique Identity Attribute38Back Up Native Directory and Hyperion Product Repositories39Migration Sequence39Behavior During Migration39Important Considerations When Using the Unique Identity Attribute39Configuring Oracle Internet Directory, MSAD, and Other LDAP-Enabled User Directories40Configuring an SAP Provider46Configuring an NTLM User Directory49Configuring Relational Databases as User Directories50Testing User Directory Connections53Editing User Directory Settings53Deleting User Directory Configurations54Managing User Directory Search Order54Adding a User Directory to the Search Order55Changing the Search Order56Removing a Search Order Assignment56Setting Global Parameters57Overriding Cache Refresh Interval for MSAD and other LDAP-Enabled User Directories58Setting Timeout to Resolve SAP Keystore File59Connection Pooling59Using Special Characters61Working with Applications and Projects65Overview65Working with Projects65Creating Projects66Modifying Project Properties67Deleting Projects67Managing Applications67Assigning Access Permissions to Applications68Moving Applications69Copying Provisioning Information Across Applications69Deleting an Application69Delegated User Management71About Delegated User Management71Hierarchy of Administrators71Shared Services Administrators71Delegated Administrators72Enabling Delegated User Management Mode72Creating Delegated Administrators72Planning Steps73User Accounts for Delegated Administrators73Create a Delegation Plan73Provisioning Delegated Administrators73Creating Delegated Lists73Modifying Delegated Lists75Deleting Delegated Lists77Viewing Delegated Reports77Managing Native Directory79About Native Directory79Installation Location79Default Users and Groups80Starting Native Directory80Starting Native Directory in Normal Mode80Starting Native Directory in Debug Mode80Stopping Native Directory81Managing Native Directory Users81Creating Users81Modifying User Accounts82Deactivating User Accounts83Activating Inactive User Accounts84Deleting User Accounts84Managing Native Directory Groups84Creating Groups85Modifying Groups86Deleting Groups88Managing Roles88Creating Aggregated Roles89Modifying Aggregated Roles90Deleting Aggregated Roles90Changing Native Directory root User Password91Backing Up the Native Directory Database91Best Practices91Hot Backup92Cold Backup92Synchronizing Native Directory Database with the Shared Services Repository93Recovering Native Directory Data93Setting Up Native Directory for High Availability and Failover94Out of the Box Deployment94Cold Standby Deployment96Hot Standby Deployment98Migrating Native Directory99Managing Provisioning101Provisioning Users and Groups101Deprovisioning Users and Groups102Generating Provisioning Reports102Importing and Exporting Native Directory Data103Overview104Use Scenarios105Move Provisioning Data Across Environments105Manage Users and Groups in Native Directory105Bulk Provision Users and Groups105Installing the Import/Export Utility106Before Starting Import/Export Operations106Sample importexport.properties File106Sequence of Operations107Preparing the Property File107Product Codes111Considerations for Setting Filters112Prerequisites for Running Import/Export Utility from a Remote Host113Running the Utility113Import File format114XML File Format114CSV File Format118Using the Update Native Directory Utility to Clean Stale Native Directory Data125About the Update Native Directory Utility125Installing the Update Native Directory Utility126Running the Update Native Directory Utility126Update Native Directory Utility Options127Update Native Directory Utility Log Files128Product-Specific Updates128Essbase129Planning129Financial Management130Reporting and Analysis131Strategic Finance132Troubleshooting133Shared Services Log Files133User Directory Error Codes134Troubleshooting Tools and Utilities134CSSSpy134WebDAV Browser134Hyperion Product Roles135Shared Services Roles135Essbase Roles137Reporting and Analysis Roles137Financial Management Roles139Planning Roles141Business Rules Roles142Business Modeling Roles143Strategic Finance Roles143Transaction Manager Roles144Performance Scorecard Roles144Strategic Finance Roles144Data Integration Management Roles145Essbase Provider Services Roles145Shared Services Roles and Permitted Tasks147Essbase User Provisioning149Launching User Management Console from Essbase149Essbase Projects, Applications, and Databases in Shared Services150Essbase Users and Groups in Shared Services151Assigning Database Calculation and Filter Access151Setting Application Access Type153Synchronizing Security Information Between Shared Services and Essbase154Migrating Essbase Users to Shared Services Security155Backing Up Security Information155Reporting and Analysis User Provisioning157Launching User Management Console from Workspace157Reporting and Analysis Roles157Reporting and Analysis Role Hierarchy157Content Manager Branch158Scheduler Manager Branch159Sample Role Combinations159Financial Management User Provisioning161Assigning Users and Groups to Financial Management Applications161Assigning User Access to Security Classes162Setting Up E-mail Alerting163Process Management Alerting164Intercompany Transaction Alerting165Running Security Reports for Financial Management Applications165Migrating Financial Management Users to Shared Services Security166Planning User Provisioning167Launching User Management Console From Planning167Returning to Planning From User Management Console167Updating Users and Groups in Planning168Migrating User and Group Identities168Deprovisioning or Deleting Users and Groups168Updating Users With a Utility169Roles in Planning170Write Access to Data in Essbase170Roles Between Planning and Business Rules170Access Permissions Between Planning and Essbase170About Connection Types and Planning171Migrating Users to Shared Services171Business Rules User Provisioning173About Business Rules Security173Launching User Management Console174Business Rules User Roles174Migrating Business Rules Users to Shared Services Security175Performance Scorecard User Provisioning177Launching User Management Console from Performance Scorecard177Managing Permissions in Performance Scorecard178Creating and Provisioning Users and Groups over Shared Services178Access Permissions179Before You Begin179Creating a New User or Group Using Shared Services179Assign Performance Scorecard Properties Individually180Assign Bulk Properties in Performance Scorecard181Migrating Performance Scorecard Users and Groups to Shared Services Security182Business Modeling Roles and Tasks189Administrator189Builder190End User190Essbase Provider Services User Provisioning191Provisioning the Administrator Role in Shared Services191Migrating Analytic Provider Services Users to Shared Services192Data Integration Management User Provisioning193Authentication Methods193Data Integration Management User Roles194Glossary195Index199文件大小: 4.2 MB页数: 206Language: English打开用户手册