User FUSION_APPS_PROV_PATCH_APPID denied

Error:

weblogic.security.SecurityInitializationException: Authentication denied: Boot identity not valid; The user name and/or password from the boot identity file (boot.properties) is not valid. The boot identity may have been changed since the boot identity file was created. Please edit and update the boot identity file with the proper values of username and password. The first time the updated boot identity file is used to start the server, these new values are encrypted.
at weblogic.security.service.CommonSecurityServiceManagerDelegateImpl.doBootAuthorization(CommonSecurityServiceManagerDelegateImpl.java:960)
at weblogic.security.service.CommonSecurityServiceManagerDelegateImpl.initialize(CommonSecurityServiceManagerDelegateImpl.java:1054)
at weblogic.security.service.SecurityServiceManager.initialize(SecurityServiceManager.java:873)
at weblogic.security.SecurityService.start(SecurityService.java:141)
at weblogic.t3.srvr.SubsystemRequest.run(SubsystemRequest.java:64)
at weblogic.work.ExecuteThread.execute(ExecuteThread.java:256)
at weblogic.work.ExecuteThread.run(ExecuteThread.java:221)
Caused By: javax.security.auth.login.FailedLoginException: [Security:090304]Authentication Failed: User FUSION_APPS_PROV_PATCH_APPID javax.security.auth.login.FailedLoginException: [Security:090302]Authentication Failed: User FUSION_APPS_PROV_PATCH_APPID denied
at weblogic.security.providers.authentication.LDAPAtnLoginModuleImpl.login(LDAPAtnLoginModuleImpl.java:261)

Solution:

  1. Set ORACLE_HOME to IDM_HOME on IDM Node

[oracle@appsdbatraining app]$ export ORACLE_HOME=/u01/idm/products/app/idm
[oracle@appsdbatraining app]$ export PATH=$ORACLE_HOME/bin:$PATH

2.  Run the following command on IDM Node

[oracle@appsdbatraining app]$ ldapsearch -h idm.appsdbatraining.com-p 3060 -D “cn=orcladmin” -w Oracle123 -s base -b “orclCSFKey=basic.credentials,cn=oracle.wsm.security,cn=CredentialStore,cn=IDMDomain,cn=JPSContext,cn=jpsroot” objectclass=* orclcsfname orclcsfpassword
orclCSFKey=basic.credentials,cn=oracle.wsm.security,cn=CredentialStore,cn=IDMDomain,cn=JPSContext,cn=jpsroot
orclcsfname=weblogic
orclcsfpassword=Oracle123

3. Modify password in IDStore through ODSM.

Navigate to the user entry: dc=com -> dc=mycompany -> cn=Users -> cn=AppIdUsers -> cn=FUSION_APPS_PROV_PATCH_APPID

Change the password to which you retrived in 2nd step Oracle123

4. Modify password in FA Domains boot.properties

[oracle@appsdbatraining app]$ cd /u01/fusion/fusionapps/wlserver_10.3/server/bin/

[oracle@appsdbatraining app]$ . ./setWLSEnv.sh

[oracle@appsdbatraining app]$ cd /u01/fusion/instance/domains/appsdbatraining/

[oracle@appsdbatraining app]$ java weblogic.security.Encrypt Oracle123

{AES}XZAS8mwYQuDuPVjiyajskm0sdkHx4gnNU6Galrqj2Y4=

[oracle@appsdbatraining app]$ vi CommonDomain/servers/AdminServer/security/boot.properties

Insert encrypted password in all domains AdminServer/security/boot.properties files as shown below:

#password={AES}wnzmpsjUR3H5RMajhWU8RJy5eNG4MG00jgZ/pqceQtE\=
password={AES}XZAS8mwYQuDuPVjiyajskm0sdkHx4gnNU6Galrqj2Y4=
username={AES}Ia2BYn47gX7sn1MUq2USFf3VZJ7HevMh1dWwQidneGlfiTC9xokN69seQVm6ogxz

Nagulu Polagani

"We are all apprentices in a craft where no one ever becomes a master."