Monday, November 2, 2015

Set up SSL in OAM 11.1.2.3 (11gR2 PS3), When integrating with 12.2



1. Demo Certificates

The below messages in your Web logic Log indicates that your web logic domain holds a risk.
Whilst you do not want SSL communication for your web services or applications. The internal (administrative) processes in your Weblogic domain still relies on the default demotrust and with this everyone can access your domain




2. Generate the identity java keystore

keytool -genkey -keysize 2048 -keyalg RSA -alias hostname -keystore hostname_identity.jks

Subject:   CN=host.domain.com,OU=OraFinHR,O=Becker,L=SF,ST=CA,C=US




3. Generate signing request

keytool -certreq -alias hostname -file certnew.csr -keystore hostname_identity.jks


4. Certificate Authority (CA)

Certificate Authority to sign your certificate requests (the .CSR files you generated).
You can create your own CA and self-sign them, Shall use an external Internet CA provider,
Since this becomes expensive and time prone when you need such an external provider to sign every SSL enabled server in your landscape.
The best situation for us would be if the current organization already has an internal CA provider,  especially when the rootCA is trusted by the servers and machines in your landscape.

5. Convert .p7b file to Readable Format#
$ openssl pkcs7 -print_certs -in certnew.p7b -out cert_chain.cer

6. Importing the CA response
Import the certificates in your keystore, starting with the rootCA, then the intermediateCA, then the specific server alias

keytool -importcert -trustcacerts -alias rootca -file ca.crt -keystore hostname_identity.jks
keytool -importcert -alias intermediateca -file initca.crt -keystore hostname_identity.jks
keytool -importcert -alias server01 -file certnew.cer -keystore hostname_identity.jks

keytool -importcert -trustcacerts -alias rootca -file ca.crt -keystore hostname_trust.jks
keytool -importcert -alias intermediateca -file initca.crt -keystore hostname_trust.jks


7. Change Settings in Weblogic Server

NB: Make sure you take a back up of config.xml, before you proceed to Enable SSL.
Location: $MW_HOME/user_projects/domains/<DOMAIN>/config/config.xml
By Preserving this at any point you can roll back changes, and resume services with the old settings.

Login into the Weblogic Console
Go to Domain Structure > IDMDomain >>Environment >> Servers
Make sure SSL Listen Port should be checked.


Click on Keystores Tab & Click on Keystores::Change >> Select “Custom Identity and Custom Trust”
Custom Identity Keystore <Give full keystore path>
Custom Identity Keystore Type <JKS>
Custom Identity Keystore Passphrase <anything>
Same for Custom Trust Keystore: You can give keystore path or CACERTS path.

Click on SSL tab >
Private Key Alias > Give the alias name what you given while you generating keystore file and PassPhrase.

Click Save.
Goto Change Centre >> Activate Changes.
Restart the Admin Server. The Admin log should like below.
NB: Also make sure "JSSE" check box is checked, Under SSL> Advanced tab.

NB: Repeat these steps for intended Managed Servers

Verify your URL:
https://host.domain:sslport/console


8. Change the OAM protocol

NB: Make sure you take a back up of oam-config.xml, before you proceed to Enable Protocol.
Location: $MW_HOME/user_projects/domains/<DOMAIN>/config/fmwconfig/oam-config.xml

By Preserving this at any point you can roll back changes, and resume services with the old settings.

After Enable SSL, Change in (11gR2 PS3 OAM). Login into the "oamconsole" and change the Protocol to SSL

Goto Access Manager Settings > Change OAM Server Port to SSL Port & OAM Server Protocol to “https”


Restart the OAM Managed Server

Login into the EBS and Test whether your URL is redirecting to the oam SSL url.

Cheers!! 
Srikanth

Friday, October 30, 2015

HOW TO ENABLE SSL for OID



The following is an example of a default config set:

cn=configset, cn=osdldapd, cn=subconfigsubentry
cn=configset
objectclass=top
objectclass=orclConfigSet
objectclass=orclLDAPSubConfig
orclsslauthentication=32  (This can be 0, 32, or 64.)
orclsslenable=2
orclsslport=3060
orclserverprocs=1

Where:
for orclsslauthentication:
    0  - is mode 1 in SSL ODM client (No Authentication)
            + no authentication or confidentiality mode.
            + no server wallet or client wallet needed.
            + Diffie Hellman algorithms will be used.

    32 - is mode 2 in SSL ODM client (Server Authentication)
            + server authentication only
            + complete server wallet needed (private key, certificate, the
              signer certificate, and trustpoints)
            + client wallet needed (Client wallet only needs to have trustpoints
              so as to be able to verify the server certificates.
            + RSA algorithms will be used.

    64 - is mode 3 in SSL ODM client (Client and Server Authentication)

            + this SSL mode will requires server and client authentication.
            + complete server wallet needed (server private key, server
              certificate, trustpoints, etc...)
       + complete client wallet on ODM side (client private key, client
              certificate, trustpoints, etc..)
            + RSA algorithms will be used.


Notes:

1. The SSL mode must be consistent between the client and server.
2. If the server is setup with server mode (2), clients can use either mode 1
   or mode 2 (No Authentication or Server Authentication)
3. If the server is setup with mode 3 (Client and Server Authentication),
   clients can ONLY use mode 3 (SSL Client and Server Authentication).
4. If the server is setup with mode 1 (No Authentication) then the client can
   ONLY use mode 1 (No Authentication)


Security >> Wallet



Either Create a Self Signed or Import a existing wallet.



Click Oracle Internet Directory > Administration > Server Properties

Click on Change SSL Settings


From SSL Authentication Select from “No Authentication”  >> “Server Authentication”  or “Mutual Authentication”


-      Select ciphers (it is recommended to select ciphers based on enterprise security requirements)
-       Restart OID using opmnctl stopall; opmnctl startall






OID OAM Env Issues on HP-UX


Issue Description or Issue Log#

$$ORACLE_HOME/bin/ldapsearch -h hostname -p 3060 \
> -D "cn=orcladmin" -w pwd -b \
> "cn=Provisioning Profiles, cn=Changelog Subscriber, cn=Oracle Internet Directory" \
> -s sub "objectclass=*" > profile.ldif
/usr/lib/hpux64/dld.so: Unsatisfied code symbol 'nzcrltlfc_temp_ldap_fetch_crl' in load module '/u01/oracle/mw/Oracle_IDM1/bin/ldapsearch'.
/usr/lib/hpux64/dld.so: Unsatisfied code symbol 'nzcrltliu_temp_ldap_is_url' in load module '/u01/oracle/mw/Oracle_IDM1/bin/ldapsearch'.
/usr/lib/hpux64/dld.so: Unsatisfied code symbol 'nzcrltlfc_temp_ldap_fetch_crldp' in load module '/u01/oracle/mw/Oracle_IDM1/bin/ldapsearch'.
Killed

Fix# Make sure env is pointing to IDM /OID
export SHLIB_PATH=/u01/oracle/mw/Oracle_IDM1/lib
$unset LD_LIBRARY_PATH

Check for any other env is pointing to any other Oracle Homes Except IDM/OID


Same for other ldap utilities like 
ldapadd       ldapbind      ldapdelete    ldapmodify    ldapsearch
ldapaddmt     ldapcompare   ldapmoddn     ldapmodifymt

Syntax#

ldapsearch -h hostname-p 3081 -D cn=orcladmin -w pwd -b "" -s sub -L "cn=oid1" orclnonsslport > modifyport.ldif
ldapmodify -h hostname -p 3081 -D cn=orcladmin -w pwd -f modifyport.ldif

How To Change LDAP Port OID

Oracle Internet Directory - Version 11.1.1.7.0 and later

1.   Issue a ldapsearch like the following:


ldapsearch -h hostname -p 3060 -D cn=orcladmin -w %pwd -b "" -s sub -L "cn=oid1" orclnonsslport > modifyport.ldif


2- Open the modifyport.ldif with vi and you should see the following:


dn: cn=oid1, cn=odsldapd,cn=subconfigsubentry

orclnonsslport: 3060

3-  Modify this file so it looks like the following

(setting the non-sslport to 3070)

dn: cn=oid1, cn=odsldapd,cn=subconfigsubentry

changetype: modify
replace: orclnonsslport
orclnonsslport: 3070

4- Run ldapmodify on the file modifyport.ldif

example:
ldapmodify -h hostname -p 3060 -D cn=orcladmin -w pwd -f modifyport.ldif

Output like#
modifying entry cn=oid1,cn=osdldapd,cn=subconfigsubentry


5- Stop OID 

opmnctl stopproc ias-component=oid1

6- Restart OID

opmnctl startproc ias-component=oid1

6- test a ldapbind on the new port

ldapbind -h hostname -p 3070
bind successful

For LDAP Options
https://docs.oracle.com/cd/E22289_01/html/821-1279/ldapmodify.html

Thursday, October 22, 2015

Enhanced Features of EBS 12.2.5

Enhanced new Application DBA features of Oracle E-Business Suite Release 12.2.5 

Script to Automate Changing Oracle WebLogic Server Administration User Password (Conditional to be on patch set level R12.AD.C.Delta.7 and R12.TXK.C.Delta.7 )
  • The procedure used to change the Oracle WebLogic Server Administration User Password has been simplified and largely automated by the introduction of a new utility that performs what were previously manual steps.

    You can set the Oracle WebLogic Server Administration User password to a non-default value during Oracle E-Business Suite installation. if you need to change the password at a later time, you can do so on the run file system by shutting down all application tier services except the Admin Server, then running the new
    $FND_TOP/patch/115/bin/txkUpdateEBSDomain.pl script with the -action=updateAdminPassword option.
Support for Middle Tier EBS Technology Checker
  • The new middle tier checker (MT-ETCC) technology script complements the original ETCC database checker script (now called DB-ETCC). The scripts report respectively on any missing middle tier and database tier bugfixes and patches that are required for Release 12.2.
Simplified Procedure for Changing WLS Data Source
  • Changing the APPS schema password in the WLS Data Source with FNDCPASS or AFPASSWD has now been simplified and partially automated. The required sequence of actions on the run file system of the primary node includes shutting down the application tier services; starting AdminServer with the adadminsrvctl.sh script; running thetxkManageDBConnectionPool.pl script and choosing the 'updateDSPassword' option; and finally restarting the application tier services. Reference: Chapter 6, Basic DBA Tasks, Oracle E-Business Suite Maintenance Guide.
Improved Delete Node and Delete Managed Server APIs
  • The improvements include addition of more validations.
Mandatory Definitions of Context Variables
  • Definition of the following is mandatory in the pairs file used for standard clone and for addition of nodes:
    • s_webentryurlprotocol
    • s_webentryhost
    • s_webentrydomain
    • s_active_webport
Various Fixes for Oracle Database 12c
  • These include cleanup of existing integrations following run of Rapid Clone.
Automatic Execution of ETCC on Database Tier After Cloning
  • This now takes place automatically, instead of as a manual step after database tier cloning.
 Various adop Enhancements and Fixes
  • These include enhancemente to validations, logging and security.
3.1 Enhanced adop user interface
Category
Description
Parameters
Changed UI
The UI of the adop utility has been significantly enhanced, to display more selective information on the console. Messages, prompts and other elements have also been extensively refined to increase the ease of use of the various patching commands.
Dependent on operation


3.2 New adop monitoring and validation features
Category
Description
Parameters
New features
Progress of an online patching cycle can be followed by running the new Online Patching Monitoring utility (adopmon). This utility can be used to follow the overall progress of a patching cycle, as well as identifying the various individual adop actions being taken.

$ adopmon

Before you start a new patching cycle by running the prepare phase, you can optionally check your system's readiness by running adop with the 'validate' option. If you do this while a patching cycle is in progress, validation will take place for the cutover phase.
$ adop -validate


3.3 Support for new EBS Installation Central Inventory
Category
Description
Parameters
New feature
Support for an instance-specific EBS Installation Central Inventory has been introduced as an option for the application tier on UNIX platforms. The inventory is identified by <s_base>/oraInventory/oraInst.loc. This feature is useful where multiple Oracle E-Business Suite installations exist on the same host, helping to avoid issues when fs_clone is run simultaneously on different instances.

To use the EBS Installation Central Inventory, all application tier Oracle Homes registered in the global inventory for the instance must be migrated to the new inventory.
Not applicable

To use the EBS Installation Central Inventory, all application tier Oracle Homes registered in the global inventory for the instance must be migrated to the new inventory. This is done by running the following steps on the primary application tier node:


1.    Source the run edition file system.
2.    Edit the context file and set the value of the context variable s_ebs_central_inventory to 'true'.
3.    Run AutoConfig.
4.    Run the following command:
$ perl <FND_TOP>/patch/115/bin/txkMigrateInventory.pl -contextfile=<CONTEXT_FILE>
Ensure that all application tier Oracle Homes have been migrated to the EBS Installation Central Inventory.
Repeat all the above steps on any non-shared nodes and shared master nodes (for example, in a hybrid setup). For all shared slave nodes, perform Steps 1 to 3 (only) on each node.

Once the inventory is migrated, any subsequently added nodes will be automatically configured to use the EBS Installation Central Inventory, and any new target instance cloned from this instance will automatically be configured to use it.
3.4 Oracle WebLogic Server performance improvements
Category
Description
Parameters
New options
  • A new -DserverType=wlx start argument for managed servers reduces their memory footprint, by preventing startup of the Enterprise JavaBeans (EJB), Java EE Connector Architecture (JCA), and Java Message Service (JMS) services.
-DserverType=wlx

  • To reduce oacore startup time, the Portlet Producer libraries are no longer deployed to the EBS domain. A new context variable, s_deploy_portlet, has been introduced to cater for cases where portlet-related configuration is required, such as in instances needing Webcenter integration.
s_deploy_portlet
New mode
The default value of s_forms-c4wsstatus is now set to 'Disabled'.Thus, the formsc4-ws servers are no longer started during a 'start all' operation.
s_forms-c4wsstatus
Several related enhancements have been made to Oracle WebLogic Server:
  • A new -DserverType=wlx start argument for managed servers reduces their memory footprint, by preventing startup of the Enterprise JavaBeans (EJB), Java EE Connector Architecture (JCA), and Java Message Service (JMS) services.
  • The default value of s_forms-c4wsstatus is now set to 'Disabled'.Thus, the formsc4-ws servers are no longer started during a 'start all' operation.
  • To reduce oacore startup time, the Portlet Producer libraries are no longer deployed to the EBS domain. A new context variable, s_deploy_portlet, has been introduced to cater for cases where portlet-related configuration is required, such as in instances needing Webcenter integration.


3.5 New 'dualfs' option in standard cloning
Category
Description
Parameters
New option
A new 'dualfs' option is available when performing a standard clone, as well as while adding a new node. With the 'dualfs' option, both the run and patch file systems are cloned and configured in a single operation.
dualfs


Doc ID 2050998.1

Saturday, September 19, 2015

What is ORACLE RAC IP & VIRTUAL IP or VIP

What is ORACLE RAC IP & VIRTUAL IP or VIP
Public IP:  The public IP address is for the server.  This is the same as any server IP address, a unique address with exists in /etc/hosts.
Private IP: Oracle RCA requires "private IP" addresses to manage the CRS, the clusterware heartbeat process and the cache fusion layer.
Virtual IP:  Oracle uses a Virtual IP (VIP) for database access.  The VIP must be on the same subnet as the public IP address.  The VIP is used for RAC failover (TAF).


In previous terms of RAC, We have one Public IP & One Private IP.

Public IP is for the rest of the world. In Normal case we use a protocol called Stateful protocol for Ex. TCP/IP (its like acknowledges)
Private communication between Node to Node should be very fast, In general we use a protocol called State less Protocol. For example UDP.

UDP like a SEND & FORGET.

In tnsnames. Ora

Node1 / Host1 Public IP
Node2 / Host2 Public IP.

Basically these hosts or node names be resolved by the clients.

When ever a client requires to establish a connection It looks for the first resolvable IP in Network file and establishes a connection.
The traditional setup before 10gR2, which uses a TCP/Ip protocol to get connected the client to the node.

TCP/IP basically is a state full protocal and should have a certain number of re-tries or time out required, before the client recognizes that node gone down.
Suppose if the time out we set is 600s, the client keep tries to establish a connection. After 600 seconds the client will get an error infor something like below.

Can not resolve the hostname or tns lost contact.

Then only client will fail over to the next available node.
==========

Since this is unacceptable for certain kind of high transaction environments.

So the Oracle comes with a better solution introduced a concept called a VIP.

VIP, A Virtual IP is nothing but another IP which runs on same interface eth0 as your Public IP.

This VIP is available on all nodes like your each node individual. Your listener is aware of both Public IP & vip.

It listens to public IP & VIP. Incase of a fail over the vip of Node-1 shifted to Node# 2.

The trouble is as soon as the VIP shifted to Node# 2, it changes the mac address which is appended of each VIP of the network interfaces.

When you start eth0 vip on Node#1 eth0 of node#1 address will be appended to vip1
When vip1 switches to node2 the mac address of vip1 going to be mac address of the interface card of Node#2, which means a new mac address is initiaed.

This changed mac address is immediately going to ask node#2, something is called re-arg, re-arg is protocol address resolution protocol
It means the node#2 immediately broad cast the new mac address to the all connected client.

All connected clients when they get the notification that the new vip have new mac address, they immediately Marked as invalid all connected sessions.

They imm’ly connected to vip on the other node, but the listener running on other node will not listen to VIP1,
It only listen to the PublicIP and VIP2. Once the vip1 is discarded by the listener running on Node#2, The client
Reads the second VIP address from tnsnames and connects to VIP#2.

THIS WHOLE THING COMPLETED IN 20 secs time


WEBLOGIC Frequently Asked Questions faq

Memory leak is when objects are not romved from the heap even when they are not required.
OUT OF MEMORY?
a) Insufficient heap size, not able to match the extra load.
b) Objects licing too long, like HTTP Sessions.
c) Memory leak in application code.
d) Full GC not happening due to JVM Bug.
Trail & Error
Gather memory data by enabling GC verbose.
If its due to Http Session, timing out http session after certain interval might help.
Look into the code for jdbc connection handling.
Optimizing the heap size according to the load.
Stuck threads are JVM threads that have been running for more than a certain configurable time (default 600 seconds)
Garbage collection is the JVM’s process of freeing up unused Java objects in the Java heap.The Java heap is where the objects of a Java program live. It is a repository for live objects, dead objects, and free memory. When an object can no longer be reached from any pointer in the running program, it is considered “garbage” and ready for collection.
The JVM heap size determines how often and how long the VM spends collecting garbage. An acceptable rate for garbage collection is application-specific and should be adjusted after analyzing the actual time and frequency of garbage collections. 
A domain is the basic administration unit for WebLogic Server. It consists of one or more WebLogic Server instances, and logically related resources and services that are managed, collectively, as one unit.
Administration Server  A domain always includes one WebLogic Server instance that is configured as an Administration Server. The Administration Server provides a central point for managing the domain and providing access to the WebLogic Server administration tools. These tools include, but are not limited to, the following:
WebLogic Server Administration Console—graphical user interface to the Administration Server
WebLogic Server Node Manager—Java program enabling you to start, shut down, restart, and monitor remote WebLogic Server instances
Managed Servers  All other WebLogic Server instances in a domain are called Managed Servers. Managed Servers host application components and resources, which are also deployed and managed as part of the domain. In a domain with only a single WebLogic Server instance, that one server functions as both the Administration Server and Managed Server.