|
POST
|
Thanks for your reply. Unfortunately, we did not configure any store and they are currently configured as built-in: Thanks
... View more
07-09-2020
09:33 PM
|
0
|
7
|
5059
|
|
POST
|
Is it an unsupported worklow ? I can provide full script and data to reproduce the issue if anyone interested
... View more
07-08-2020
11:33 AM
|
0
|
0
|
966
|
|
POST
|
Hello, In fact it has nothing to do with the old accounts nor the upgrade as I am able to reproduce the issue on brand new 10.8 environment. I was misguided because group membership is correctly computed at account initialization but not afterward so the test was different. Following your recommandation, I enabled logging to debug mode and created to 2 groups 'TEST-SAML' and 'TEST-SAML2' configured as member of the organization group 'gis-esriportal' and tried to log in with an account not initialized on ArcGIS Enterprise and member of the group 'gis-esriportal': As you can see the user 'foobar' is correctly added to the groups 'TEST-SAML' and 'TEST-SAML2' as it is a member of 'gis-esriportal'. Then, I created a third group 'TEST-SAML3' configured membership to the very same enterprise group 'gis-esriportal'. If I try to log in once again with the test account (after signing out, clearing cookie and incognito mode), the following is logged: So it seems like it does test for membership but according to ArcGIS Enterprise, it is not member of 'gis-esriportal' group. Then I delete the account on 'ArcGIS Enterprise' and tried to log in again: User is added to 'TEST-SAML3' group this time. Any idea what could be the issue ? Thanks
... View more
07-08-2020
12:14 AM
|
0
|
12
|
5059
|
|
POST
|
Thanks for your quick reply Jonathan Quinn ! It is much appreciated
... View more
07-07-2020
01:44 PM
|
0
|
0
|
3364
|
|
POST
|
Thanks for your reply Jeff Smith. I am still investigating and I found out why it was working on one deployment and not the other: it was because I tested with a newly created account ! I deleted an account on production as it was only a 'viewer' and did not have any item, asked him to login again, and after initial login it worked ! User could access the group he could not see before because his account had been created again in Portal. It means that group membership is computed at account creation but not computed for new groups. Does that help to identify the possible issue ? BTW, I don't think it is BUG-000121049 as I am member of that of the group in the SAML response and creator of the group. Thanks !
... View more
07-07-2020
11:09 AM
|
0
|
14
|
6592
|
|
POST
|
Many thanks Jonathan Quinn for your detailed reply ! Just wondering, is it possible to register more than 2 "Portal for ArcGIS" ? Thanks
... View more
07-07-2020
09:41 AM
|
0
|
2
|
3364
|
|
POST
|
OK, so I run additional tests on our UAT environment on 10.8 and it's working fine... but not in production with the very same SAML configuration on Portal. The only difference I could think of about those 2 environments is that the production was upgraded from 10.7.1 while the UAT while in the meantime reconfigured from scratch... On production, I removed SAML configuration and configured it again just like on UAT environment: same results, still not working
... View more
07-03-2020
09:14 AM
|
0
|
0
|
6592
|
|
POST
|
Hello, We just discovered the same issue on ArcGIS Enterprise 10.8 ! When configuring a group viewable and joinable by only "Members of an Enterprise Group", users can't see them even when they are in the group. It used to work ! The funny thing is that they can see old groups created with older version of Portal for ArcGIS that are configured the exact same way !!! I decoded the reply from SAML when logging in: And of course when trying to access webmap from that group, I get 403 error. This is a big issue for us !!
... View more
07-03-2020
08:11 AM
|
0
|
19
|
6593
|
|
POST
|
Just wanted to add that I read the following thread that could seems similar: PORTAL HA But the requirement would be to have HA deployment for one network and HA deployment for the other one (ie: we do not want one network to fall back on the other network when portal is down). So it implies 4 "Portal for ArcGIS" basically. But nowhere it is mention that you can multiply "Portal for ArcGIS" component just like you can with "ArcGIS Server". Thanks !
... View more
07-03-2020
07:04 AM
|
0
|
0
|
3364
|
|
POST
|
Hello, I am wondering if it is possible to have an activ-activ deployment of "Portal for ArcGIS" component in a HA deployment ? The requirement from the security team is the following: "ArcGIS Enterprise" should be accessible from 2 differents networks and hit different servers. One network should be able to hit a "Portal for ArcGIS" component opened to the outside world and another network should be able to hit the same "Arcgis Enterprise" (same maps, config, ...) but hosted on different dedicated server thanks to networking configuration. While I think it could be possible with "ArcGIS Server" component as they can all be "activ" in the deployment, I am under the impression that it is not possible with "Portal for ArcGIS" component as there is one activ and one passiv: "If you stop the Portal for ArcGIS service or the primary machine becomes unavailable (for example, if the hard drive fails), the portal will failover to the standby" (from documentation). Did I miss anything ? Any suggestion regarding this requirement ? Thanks ! /cc Jonathan Quinn
... View more
07-03-2020
06:46 AM
|
0
|
5
|
3455
|
|
POST
|
No, credentials are not embedded. They are prompted when opening the map in Collector. Just wanted to add that we recently upgraded from SDE Oracle 10.3.1 to 10.8, might be related ?
... View more
07-02-2020
10:23 AM
|
0
|
1
|
1524
|
|
POST
|
Thanks for your reply Doug Morgenthaler ! - The affected table is part of a feature layer from SDE 10.8 (Oracle) published to an ArcGIS Server 10.8 with token based security - Mobile plateform is IOS (not tested on android)
... View more
07-01-2020
01:37 PM
|
0
|
3
|
1524
|
|
POST
|
Hello, I am facing a very similar issue as described on this thread: Anyone else having a problem with downloading offline maps all of a sudden? I have been able to download 2 webmaps for years and today out of the blue it is no longer working. On Collector "Classic", I have the following error displayed: « Table MYTABLE not found » and the map is not dowloaded. On Collector, I can download the map, but the layer using this table has a red exclamation mark and the following error is displayed: "Domain: com.esri.arcgis.runtime.error Code: 20 Description: No data" No changes have been made to "MYTABLE" feature class and monitoring the requests with Fildder, I was able to download the runtime geodatabase generated by the ArcGIS Server containing this table, convert it to a regular file geodatabase, and to open in ArcMap: the table does exist and does contain features. Any idea what could the issue ? Thanks for your help !
... View more
07-01-2020
10:52 AM
|
0
|
5
|
1730
|
|
POST
|
Hello, I would like to reference in my ArcGIS Enterprise A a secured service from another ArcGIS Enterprise B configured with SAML authentification (to another IDP than my ArcGIS Enterprise A). When trying to add this layer on my ArcGIS Enterprise A, it detects that the service is secured and prompt me for a username and password. The problem is that I have access to this other ArcGIS Enterprise B with an account from this IDP and not a built-in ArcGIS account. How I am supposed to do ? What I had in mind was not to store the credentials, register my ArcGIS Enterprise as an "OAuth client" on that ArcGIS Enterprise B, and I was hopping that when adding this layer in my mapViewer it would then show their "autorize" popup as my ArcGIS Enterprise A has been registered on their ArcGIS Enterprise B. Is that a non supported workflow ? If not, any workaround ? Thanks !
... View more
07-01-2020
12:18 AM
|
0
|
2
|
1414
|
| Title | Kudos | Posted |
|---|---|---|
| 1 | Friday | |
| 2 | 2 weeks ago | |
| 4 | 3 weeks ago | |
| 1 | a month ago | |
| 2 | a month ago |