Thursday, January 12, 2023

Maximo Prorate or Allocate Service Costs (Landed or Freight Cost) on POLINES in PO

What are Service Costs ? 

Service Cost includes Landed Cost, Freight Cost, Storage Cost, Managerial Personnel Cost, Advertisement Expenses, Customs Duty, Insurance Cost, Clearing Charges, Ground Maintenance, Plant Security Services etc. 

Why allocation of Service Cost is required ?

Allocation splits the standard service cost across stock tracked items on purchase order. We can allocate landed cost to PO line items even after the PO is invoiced. But, the POLINE item should not be consumed or shipped from the storeroom.

If we purchase an item in Inventory storeroom, unit cost is the cost price of the item. But there are other costs associated with purchasing items such as shipping cost etc.,  

Landed costs are a way to distribute these extraneous costs as they allow us to record the total cost of inventory per unit. It records the accurate profit reporting. 

How Services are represented in Maximo ?

Maximo enables the user to allocate or distribute the standard service cost on PO or Invoice approval.

Service Items are created in Service Items application. Services can be requested from internal or external vendors. When they are requested from Internal Vendor, we can record actual costs on Work orders without creating a PR. They are not linked to an Asset, it often include labor, tools and materials billed as single unit.

Service Item can be associated with vendors to restrict the access. 

Steps to prorate or allocate service cost on PO application

An Organization level MAXVAR variable INVOICEMGT is used to choose which application is used to prorate service cost. By default, the value is 1 where Invoice application is used for prorating. If you want to use it for PO application, set the value to 0 using below sql script.

UPDATE MAXVARS SET VARVALUE = 0 WHERE VARNAME = 'INVOICEMGT' AND ORGID = 'XXX';

Restart of server is required to reflect the changes in Maximo system

Create a PO with 3 POLINES each of quantity as 1: 
1. Item 1001 of unit cost 10
2. Item 1002 of unit cost 15
3. Standard Service Cleaning of unit cost 30 with Prorate Service ? checkbox selected



When you approve this PO, the cost of the standard service line will be distributed to all other POLINES. 
 
Calculation of prorated cost on polines
Prorate Factor = TotalProrateCostOfAllStandardServiceLines / TotalMaterialCostOfAllLines
                          =  30 / (10+15) = 1.2

TotalMaterialCostOfAllLines - i) must include only POLINES of type ITEM; 
ii) Exclude POLINES of direct issue items, services & materials and 
iii) Maxvar PRSPECIALDIRECT value should be set to 0. 

PRSPECIALDIRECT - specifies whether standard service costs are to be charged only to 'Direct Issue' line items in invoice. 

Prorate Cost  = Unit Cost * Prorate Factor
Loaded Cost = Unit Cost + Prorate Cost 

After PO Approval , the distribution of cost will be like


Item 1001 - Unit Cost= 10; Prorate Cost= 10 * 1.2 = 12; Loaded Cost= 10+12 = 22


Item 1002 - Unit Cost= 15; Prorate Cost= 15 * 1.2 = 18; Loaded Cost= 15+18 = 33


Standard Service - Unit Cost = 30 ; Prorate Cost = -30 (negative);  Loaded Cost = 0 (distributed to all item lines ) 

Friday, December 2, 2022

Data Load of Job Plan Records via Maximo Integration Framework (MIF)

MIF data loading in format of csv for Job plans require a sequence of data loads to complete a ACTIVE job plan. 

A Job Plan consists of child objects like Job Plan Tasks, Job Labor, Job Materials, Job Services and Job Tools.

Create separate Enterprise Services for Job plan, Job Plan + Job Task, Job Plan + Job Material, Job Plan + Job Labor and Job Plan + Job Service. 

A Job Plan has different statuses, and we are not allowed to modify Job Plan after it is in ACTIVE status. So, we need to follow a sequence of data load to create a single Job Plan with its related child records.

Job Plan (DRAFT status) -> Job Tasks -> Job Labor -> Job Material -> Job Service -> Job Tool -> Job Plan (ACTIVE) -> Previous Revision Job plan (REVISED)

Use External system application to load these csv files.

Job Plan 

ORGID,SITEID,JPNUM,DESCRIPTION,STATUS,TEMPLATETYPE,JPDURATION,PLUSCREVNUM,PRIORITY,INTERRUPTIBLE
EAGLENA,BEDFORD,16353456,Circuit Breaker Plan,DRAFT,MAINTENANCE,0.75,1,1,1

Job Plan + Job Task

ORGID$SITEID$JPNUM$PLUSCREVNUM$JPTASK$DESCRIPTION_id$DESCRIPTION_LD$HASLD$TASKSEQUENCE$TASKDURATION$PLUSCJPREVNUM$PREDECESSORTASKS
EAGLENA$BEDFORD$16353456$1$10$"Locomotive gear"$"a) Consign the equipment in accordance with the LOTO procedure; 
b) Consign adjacent equipment;"$$1$0

Delimiter for loading Job task data should be dollar sign ($), because we often have comma (,) in long description in the JOBTASK, so in order to differentiate the delimiter and actual content, we use $ instead of comma (,).



Job Plan + Job Labor

ORGID,SITEID,JPNUM,PLUSCREVNUM,JPTASK,CRAFT,QUANTITY,LABORHRS,VENDOR
EAGLENA,BEDFORD,16353456,1,MECH,2,1.5,

Job Plan + Job Material

ORGID,SITEID,JPNUM,PLUSCREVNUM,JPTASK,ITEMSETID,ITEMNUM,ITEMQTY,DIRECTREQ,LOCATION,STORELOCSITE
EAGLENA,BEDFORD,16353456,1,10,ITEMSETID,1120002028,1,0,LABSTORE,BEDFORD

Job Plan 

ORGID,SITEID,JPNUM,DESCRIPTION,STATUS,TEMPLATETYPE,JPDURATION,PLUSCREVNUM,PRIORITY,INTERRUPTIBLE
EAGLENA,BEDFORD,16353456,Circuit Breaker Plan,ACTIVE,MAINTENANCE,0.75,1,1,1

Maximo don't change the status of previous revision of Job plan automatically. We need to load the Job plan data to manually change the previous revision to REVISED status.

Job Plan - Previous Version

ORGID,SITEID,JPNUM,DESCRIPTION,STATUS,TEMPLATETYPE,JPDURATION,PLUSCREVNUM,PRIORITY,INTERRUPTIBLE
EAGLENA,BEDFORD,16353456,Circuit Breaker Plan,REVISED,MAINTENANCE,0.75,0,1,1

Tuesday, November 1, 2022

Configuring Websphere 7 for SAML SSO to authenticate Users in Maximo

This post details on how to configure Websphere 7.x version for SAML SSO to authenticate users in Maximo application

What is SAML ? 
  • Security Assertion Markup Language (SAML) is a standard for logging users into applications based on their sessions in another context
  • Most organizations already know the identity of users because they are logged in to their Active Directory domain or intranet, So they use this information to login into Maximo
  • SAML SSO works by transferring the user’s identity from one place (the identity provider) to another (the service provider)
  • When the user accesses the Maximo URL, the application identifies the user's origin, then redirects the user back to the Identity provider for authentication 
  • The user either has an existing active browser session with the identity provider or establishes one by logging into the identity provider 
  • The identity provider (AWS or Azure) builds the authentication response in the form of an XML-document containing the user’s username or email address, signs it using an X.509 certificate, and posts this information to the service provider
  • The service provider (Maximo) retrieves the authentication response and validates it using the certification and metadata
  • The identity of the user is established and the user is provided with Maximo access
 Steps to be followed:
1. Login to the operating system where WebSphere is installed
2. Install the default SAML ACS (Assertion Consumer Service) servlet supplied with WebSphere
  • If using Windows, open a command prompt
  • Navigate to WAS application bin directory (/opt/IBM/WebSphere/AppServer/bin on Linux/Unix or C:\Program Files\IBM\WebSphere\AppServer\bin on Windows)
  • We can install SAML ACS to a cluster or single-server. Please run the following command:    

Operating System

Command

Windows

wsadmin.bat -lang jython -f installSamlACS.py install clusterName 

(or)

wsadmin.bat -lang jython -f installSamlACS.py install nodeName serverName 

Linux/Unix

./wsadmin.sh -lang jython -f installSamlACS.py install clusterName

(or) 

./wsadmin.sh -lang jython -f installSamlACS.py install nodeName serverName

                where clusterName is the name of your WebSphere cluster ; nodeName and serverName are your node and server values respectively

  • If you are using a web server such as IBM HTTP Server in front of your application be sure that the newly installed EAR is targeted to the web server
    •  Login to the WebSphere Admin Console
    •  Using the left-hand menu go to Applications and then WebSphere enterprise  applications
    •  Click the link for WebSphereSamlSP
    •  Under Modules click Manage Modules
    • Confirm that both the cluster and the web server are assigned to the module

             If changes were required, generate and propagate the plugin configuration
    • Using the left hand side menu, go to Servers, then Server Types and click Web Servers
    • Click the checkbox next to your web server and click Generate Plug-in from the toolbar menu
    • Click the checkbox next to your web server and click Propagate Plug-in from the toolbar menu
    • Restart the web server
3. Create a new Security Domain 
  • Using the left-hand menu, select Security then Security Domains
  • Click New
  • Provide a name and description for security domain
  • Click OK
4. Confirm that Application Security is enabled
  • From the list of Security Domains, click the new domain you created 
  • Check the value next to Application Security. If the value is Enabled then you can continue on to step 5
  • Expand the Application Security section and select Customize for this domain
  • Enable the Enable application security checkbox and click Apply



5.  Configure a new Trust Association Interceptor

  • From the list of Security Domains, click the new domain you created
  • Expand the Trust Association section and select the Customize for this domain option
  • Click to enable the Enable trust association checkbox and click Apply
  • Click the Interceptors link under Trust Association
  • Click New
  • For the Interceptor class name enter com.ibm.ws.security.web.saml.ACSTrustAssociationInterceptor
  • Under Custom Properties enter the property name sso_1.sp.acsUrl with a value of your ACS URL 
  • Click New to add an additional property
  • Enter the name sso_1.sp.EntityID and provide a value for the SP entity ID and click OK


6.  Save settings and synchronize nodes

7.  Export SAML SP metadata

  • Navigate to the WAS application bin directory (/opt/IBM/WebSphere/AppServer/bin on Linux/Unix or C:\Program Files\IBM\WebSphere\AppServer\bin on Windows)
  • Launch the wsadmin tool

Operating System

Command

Windows

wsadmin.bat -lang jython

Linux/Unix

./wsadmin.sh -lang jython

  • Execute the following command 
AdminTask.exportSAMLSpMetadata('-spMetadataFileName sp_metadata.xml -ssoId 1 -securityDomainName DOMAINNAME')
    • DOMAINNAME --> should be the same name which is created on Step 3  
    • By default, metadatafile will be stored in this path "/opt/IBM/WebSphere/AppServer/profiles/ctgDmgr01"  
8. Share the Service Provider metadata to your IdP (Identity Provider like AWS or Azure Active Directory) with the following information:
  • Target URL of the application
  • IdP will provide its signing certificate inside the metadata file or request it separately and import it manually later
  • Please validate the certificate in the signature KeyInfo element of the assertion from IdP provider
9. After you received your IdP's sp_metadata.xml, ClientMaximo.cer and entityDescription file - Import them 
  • Launch the wsadmin tool using step 7
  • Execute the following commands
      • AdminTask.importSAMLIdpMetadata('-idpMetadataFileName idp_metadata.xml -signingCertAlias MyCertAlias -securityDomainName DOMAINNAME')
      • AdminConfig.save()
If the idp_metadata.xml file is not in the same path as the wsadmin tool, then you will need to specify the full path to the file.

The value for signingCertAlias can be any string; it will be used to identify the signing certificate in the WebSphere Trust Store so just choose a suitable name that is not already in the store (see Security > SSL certificate and key management > Key stores and certificates > CellDefaultTrustStore > Signer certificates for a list of keys already in the store)

DOMAINNAME - should be the same name which is created on Step 3
  • Exit the wsadmin tool and return to the WebSphere Admin Console
10. Verify TAI custom properties
  • Using the left hand menu, select Security and then Security Domains
  • Click the link to your security domain
  • Expand the Trust Association section and click the Interceptors link
  • Click com.ibm.ws.security.web.saml.ACSTrustAssociationInterceptor
 The following fields may be defined: 

Property

Value

sso_1.sp.acsUrl

value set in Step 5 - https://hostname/samlsps

sso_1.sp.EntityID

value set in Step 5 - https://hostname/

sso_1.sp.targetURL

https://hostname/maximo/webclient/login/login.jsp

sso_1.idp_1.certAlias

name of the certificate alias you provided in point 9

sso_1.idp_1.entityID

entity ID of the IdP which is provided in the IdP metadata file and will be automatically populated

sso_1.idp_1.singleSignOnUrl

URL endpoint for IdP authentication (automatically populated from metadata)

 
                  

sso_1.sp.filter – this is an optional property. We can filter out servers that can be exempted from using SSO. Usually, we enable SSO only for UI server, and filter out MIF/CRON/REPORT servers.

If you do not see the sso_1.idp_1.certAlias property then a certificate was not provided with the metadata file. We will need to obtain the certificate from the IdP and add it to WebSphere manually by going to Security > SSL certificate and key management > Key stores and certificates > CellDefaultTrustStore > Signer certificates and clicking Add.
 
Once imported, you will need to add a custom property to Trust Association Interceptor TAI   - sso_1.idp_1.certAlias and assign it the value of the new certificate alias you created

11. Finalize Security Domain setup
    • Using the left-hand menu select Security and then Security Domains
    • Expand User Realm, click the Customize for this domain radio button
    • Click Apply at the bottom of the screen and save changes
    • Go back to the Security Domain, expand User Realm (it should already be set to Customize) and click Configure... 
    • If you are not taken to the Trusted authentication realms - inbound page automatically then click the associated link in the lower right part of the screen (under Related Items)
    • Click the Add External Realm... button in the toolbar
    • Enter the value of the sso_1.idp_1.entityID from point 10 and click OK
    • Click Apply and save changes and return to the security domain configuration screen by following steps 
    • Click the Custom Properties link at the bottom of the screen
    • Add the following two properties:

Property

Value

com.ibm.websphere.security.DeferTAItoSSO

com.ibm.ws.security.web.saml.ACSTrustAssociationInterceptor

com.ibm.websphere.security.InvokeTAIbeforeSSO

com.ibm.ws.security.web.saml.ACSTrustAssociationInterceptor


    • Click OK and save changes
12. Assign security domain to servers or clusters
    • Assign server/cluster where WebSphereSamlSP.ear was deployed in point 2
    • Proceed to the security domain configuration screen as described in point 11
    • Under the heading Assigned Scopes expand the tree starting at Cell
    • Locate the server(s) or cluster(s) where you would like to enable SSO and click each one to enable it. If you are not using clusters then your servers will appear under the Nodes section. If your servers are in clusters then you must look under the Clusters section
    • Enable all appropriate servers click the OK button at the bottom of the page and save your changes

13. Restart application servers and web server to pick up configuration changes
14. Test SSO using the login URL provided by your IdP

Debugging
  • To debug issues with SAML, we need to enable trace logging on the server where the SAML ACS servlet has been installed
  • By default, WebSphere provides no feedback in the standard logs for most SSO issues 
  • If you are troubleshooting SAML in a cluster where multiple servers are running it’s recommended you stop all but one server to simplify diagnosing your problem
  • To enable trace logging for the server where the ACS servlet is installed, login to the WebSphere Admin Console and do the following
    • Using the left-hand menu select Servers then Server Types then WebSphere application servers

    • Locate the server where you installed the ACS servlet in point 2 of the Step-by-step guide and click it

    • Under Troubleshooting on the right side click Diagnostic trace service


    • Under Additional Properties click Change Log Detail Levels

    • Add the following log levels, separating each with a colon :  com.ibm.ws.security.*=all: com.ibm.wsspi.wssecurity.*=all: com.ibm.ws.wssecurity.saml.*=all:

    • Click OK and save your changes
    • Restart the server where you have enabled trace logging
    • Now test your SSO flow again and view the trace.log file in the log folder of your server for errors
    • The messages will generally give some indication of where the problem lies but you may need to find a proper person to escalate to if you cannot determine the problem 

Saturday, October 1, 2022

Maximo varcharmultiplier batch file for upgrade or configdb process

What is varcharmultiplier ? 

  • varcharmultiplier is Out of the Box Maximo batch file.
  • It is used to increase the database column length by Maximo column length (MAXATTRIBUTE.LENGTH) multiplied by the input provided in -m parameter
  • This multiplier value will be stored in MAXVARS table for VARNAME = VARCHARMULTIPLE
  • It's applicable only for DB2 and Microsoft SQL Server databases because Oracle by default has VARCHAR(2) as the multiplier
Why varcharmultiplier is used ?

  • for translation process after upgrade of database, so that import of translated data in form of xliff files are loaded into Maximo without any truncation errors
  • to modify any column length of a table which has double-byte (Chinese, Korean, German etc) language description, without "data too long" error in description column during the insert process from XXBASETABLE to converted BASETABLE.
    •  for example, if you increase the decimal points of a column in WORKORDER table, Maximo will take backup of existing WORKORDER table into a new table XXWORKORDER , then it will modify the table definition of WORKORDER. Maximo will run the insert statements from XXWORKORDER to revised WORKORDER table. If the description column has any special characters, then we might get an error like "data too long to insert" on description column. varcharmultiplier is used to resolve the error by increasing the database length than Maximo UI column length.  

How to execute ? 
  •  This batch file is located in the Maximo Installed path: <WindowsDrive>\IBM\SMP\maximo\tools\maximo\varcharmultiplier.bat (Windows)  or /opt/IBM/SMP/maximo/tools/maximo/varcharmultiplier.sh (linux)
  • Stop the Servers
  • Navigate to this path and run varcharmultiplier.bat -m<Positive Number>. For example, varcharmultiplier -m2
  • Start the Servers
  • The log for the execution will be stored in the folder <WindowsDrive>\IBM\SMP\maximo\tools\maximo\log\VarcharMultiplierYYYYMMDDHHmmss.log or <Linux>/opt/IBM/SMP/maximo/tools/maximo/log/VarcharMultiplierYYYYMMDDHHmmss.log
  • In case, if you encounter any errors on the database while altering the column length, please check the string_units [SYSTEM or CODEUNITS32] configuration parameter setting.

Courtesy: Madhavan https://www.linkedin.com/in/madhavan-s-872b346/

Reference: https://www.ibm.com/support/pages/tdtoolkit-truncate-error-import-microsoft-sql-server-db2-double-byte-languages


Wednesday, September 14, 2022

Maximo SQL query to retrieve Active Users of a group or from a specific server

Information about the number of users logging in a specific JVM is required for sizing the infrastructure capability of a JVM. 

One such example is to get the users logging into Maximo from Anywhere solution. Client can decide on the number of the user licenses needed for Mobile Add-on. 

Administrator can come up with JVM size with the number of concurrent users connecting to this server where Maximo Anywhere Users are connecting to. 

This data can be retrieved using a SQL query from a specific JVM. This query will list the successful login of users into a dedicated JVM with their last login date.

SELECT DISTINCT

    b.userid,     b.defsite,     c.displayname,     b.status,

    MAX (trunc(d.attemptdate)) AS lastlogin

FROM

    maximo.groupuser       a,     maximo.maxuser         b,

    maximo.person          c,     maximo.logintracking   d

WHERE

    a.groupname LIKE 'ANYWHERE_TECHNICIAN%'

    AND a.userid = b.userid

    AND b.defsite IN (  'XX01', 'YY01' )

    AND c.personid = b.personid

    AND b.status = 'ACTIVE'

    AND a.userid = d.userid

    AND d.servername = 'MXServer_AW01'

    AND d.attemptresult = 'LOGIN'

GROUP BY

    b.userid,     b.defsite,     c.displayname,     b.status

ORDER BY

    b.defsite,     b.userid

Friday, August 19, 2022

Trigger publish channel without event listener using automation script

The transactions from Maximo is passed to external system using Publish Channel component. 




The records can be initiated to Publish Channel using 2 ways: by an event or export from database.

  • Frequently occurring scenario is the record will be triggered by an event, Publish Channel would pick up them and transfer it to external system after processing all rules. 
  • There are a few other scenarios where in we need to resend the outbound data by export option without any user event on the object. These configuration will have "Event Listener ? " flag disabled.



Business Cases for Export:
1. The data sent from Maximo didn't reach external system due to internal data error. So, we need to resend the same transaction again to external system
2. Middleware outage or intermittent technical glitch requires resending of same record

For example, re-send Inventory Issue Transactions from Maximo to external system. MATUSETRANS object in Maximo holds the Inventory Issues transactions. 





We need to create a ACTION automation script, Sig Option, Button and Security Access for Resend operation by following this link - https://www.maximoscripting.com/use-a-button-to-launch-an-action-script/

Code to resend inventory issue - iface/invokePublishChannelfromScript.py

References - https://maximodeploy.blogspot.com/2020/05/invokecall-publish-channel.html


Friday, July 22, 2022

MIF Data Loading with non-English characters in Description without invalid characters or ? question mark in UI

When we receive data from clients to load them into Maximo, they might contain description with non-English characters. Non-English description are characters from languages like French, German, Portuguese etc., 

What we generally do is create a csv file for Enterprise Service with the content from file (.xls or .xlsx) gathered from client in Excel Application. If we load them into Maximo External System, we might end up with question marks or invalid characters in description field. 



Non-English description won't belong to ASCII character set. These characters in description would be removed in csv file if you save csv file by standard file format without encoding.

In order to retain the non-English (non-ASCII) characters in Maximo description field, we need to save the csv file with UTF-8 (Unicode Transformation Format - 8 bit) encoding.

Steps to follow for saving the file in UTF-8 format:
  • Open the .csv file in plain notepad application
  • Click on File -> Save As ; On the window that is opened, Choose Encoding = UTF-8