Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

QE-DEF-0288 (Unable to find the data source in the content store)

Status
Not open for further replies.

GBBach

IS-IT--Management
Jun 10, 2008
3
US
I'm trying to tighten down security in our Cognos 8.1 DEV environment and am getting this error when anyone OTHER THAN a system admin tries to run a report.

I've been all through security. My users are in Consumers role. Consumers is granted Read, Execute, Transverse on the package containing the reports. Consumers is also in the signon of the data source. (Have followed best practices - removed everyone and All Auth Users groups from all roles, etc.)

I'm probably missing something basic here (been looking at this too long) - any help would be greatly appreciated!
 
Have you tested that consumers signon? Successful?
Have you checked all the capabilities under tools?
It is best to have a test user so you can sign in and out and see the results in a testing environment first.
Narrow it down to one report, and one test user, and check the capabilities, roles, groups, and that they are successful in the signon for the data source.

CP [cook]
 
Thanks for responding. This is being done on a development environment.

The RR (report runner) account is a member of consumers role. Consumers have the following permissions:

Public Folder down to the report (RET - read, execute, transverse)
Connection & Signon(RWET) - don't think this is necessary
Cognos Viewer capability (ET)

They are also a member of the signon for the connection.

If I make consumers a member of sys admins or dir admins, then the RR user can run the report. As part of best practices, I removed Everyone and Auth users from all roles and just added Dir Admins.


 
Resolved:
In trying to tighten down security I removed the everyone group from all roles effectively shooting myself in the foot. The problem was that this removed traverse rights for all users from the cognos namespace. Thus to fix this I added authenticated users to the cognos namespace and gave it traverse rights.

An entity must have traverse rights on the root folder to navigate and read properties. In this case the only group that had traverse rights was dir admins (and of course by default system admins). This is why I could run the report as RR when I added consumers to either the dir admins or sys admins group. (RR is a member of Consumers).

 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top