Total Pageviews

Wednesday, October 11, 2017

Oracle 12C database abnormal shutdown solution


If Anytime Oracle Database goes down abnormally, due to machine failure or server reboot, most of the times objects gets into "INVALID" state.


command to check the status
select object_name,status from dba_objects where status='INVALID';

if you see a lot of INVALID objects run the following command after login to SQL

../../dbhome/rdbms/admin

run following utility to recompile these objects

SQL>@utlrp.sql




Monday, July 24, 2017

OAM command to dump all url from OAM server



This command should dump the URIs from the existing OAM server. Just change the path and the application domain.


OAM_REG_HOME=<MW_HOME>middleware/Oracle_IDM1/oam/server/rreg

./bin/oamreg.sh agentValidate <application_domain>

Saturday, June 10, 2017

OAAM 11gr1ps2 enabling logging and exporting configuration



Enable trace in OAAM Server
- Log in to Fusion Middleware Control console (hostname:7001/em)
- On the left pane go to Farm_IAMDomain -> WebLogic Domain -> IAMDomain -> oaam_server_server1 (you might have different domain name or server names).
- From the top of the right pane, under oaam_server_server1, select WebLogic server -> Logs -> Log Configuration.
- Go to Log Levels tab, expand the Root logger -> Oracle node and change the level for oracle.oaam to TRACE:32.


Exporting OAAM properties.
To export OAAM properties -> go to oaam_admin console -> Properties -> leave the Search fiels empty -> run Search -> click on Row in the left corner of the properties table to select all -> Actions -> export selecte

Wednesday, March 29, 2017

OAM export policies error Traceback (innermost last): File "", line 1, in ? NameError: exportPolicy


wls:/oam_domain/serverConfig> exportPolicy(PathTempOAMPolicyFile='/tmp/pre_upgrade_oam.xml')
Traceback (innermost last):
  File "<console>", line 1, in ?
NameError: exportPolicy
wls:/oam_domain/serverConfig> exportPolicy('/tmp/policy_export.xml')
Traceback (innermost last):
  File "<console>", line 1, in ?
NameError: exportPolicy
wls:/oam_domain/serverConfig> exit()


Solution:

you are running wlst.sh command from wrong place. it should be run from $ORACLE_HOME/common/bin/wlst.sh

find where is ORACLE_HOME/common/bin

and run 
wlst.sh

wls:/oam_domain/serverConfig> exportPolicy('/tmp/policy_export.xml')
Successfully exported policies. Check log file for details.

if you got below error use  command without path

wls:/oam_domain/serverConfig> exportPolicy(PathTempOAMPolicyFile='/tmp/pre_upgrade_oam.xml')
Traceback (innermost last):
  File "<console>", line 1, in ?
TypeError: exportPolicy() got an unexpected keyword argument 'PathTempOAMPolicyFile'


use command without PathTempOAMPolicyFile


wls:/oam_domain/serverConfig> exportPolicy('/tmp/policy_export.xml')







Saturday, February 4, 2017

difference between 10g webgate and 11g webgate

from oracle

Here is 11g features:
  • Oracle Universal Installer for platform. Generic for all platforms
  • Host-based cookie
  • Individual WebGate OAMAuthnCookie_ making it more secure
  • A per agent key, and server key, are used. Agent key is stored in wallet file and Server key is stored in Credential store
  • One per-agent secret key shared between 11g WebGate and OAM Server One OAM Server key
  • OAM 11g supports cross-network-domain single sign-on out of the box. Oracle recommends you use Oracle Identity Federation for this situation.
  • Capability to act as a detached credential collector
  • Webgate Authorization Caching
  • Diagnostic page to tune parameters
  • Has separate install and configuration option. Hence, single install and multiple instance configuration is supported.
And 10g:

  • InstallShield and One installer per platform
  • Domain-based cookie
  • ObSSOCookie (one for all 10g Webgates)
  • Global shared secret stored in the directory server only (not accessible to WebGate)
  • There is just one global shared secret key per OAM deployment which is used by all the WebGates
  • OAM 10g provides a proprietary multiple network domain SSO capability that predates Oracle Identity Federation. Complex configuration is required.
  • One Web server configuration supported per WebGate. Need to have multiple WebGates for multiple instances.

configuring e-Auth Mode at OIF thru WLST



Configuring for eAuth Mode

You can configure the Oracle Identity Federation server to comply with the eAuth specifications. Most of the configuration is performed through Fusion Middleware Control, but the specifications require the presence of two attributes in the SSO assertion that can only be configured through the MBeans/WLST scripts:

the us:gov:e-authentication:basic:specVer attribute containing the version of the eAuth specifications supported by this server

the us:gov:e-authentication:basic:Sid attribute containing the session identifier of the user performing the single sign-on

To configure Oracle Identity Federation to set those two attributes (for a specific provider) and to set the value of the eAuth version, enter the WLST script environment for Oracle Identity Federation instance, and set the following properties if needed:

Set the eauthmodeenabled boolean property for the remote provider to true to enable the eAuth mode:

setFederationProperty(REMOTE_PROVIDER_ID,
'eauthmodeenabled', 'true', 'boolean')
##
## replace REMOTE_PROVIDER_ID with the identifier of the remote provider
Set the eauthversion string property from the idpglobal group to the value the Oracle Identity Federation server should use (2.0 for example):

setConfigProperty('idpglobal', 'eauthversion', '2.0', 'string')


Sunday, January 22, 2017

OIF updating self signed certificate 2048 bit using orapki

OIF require creating PKCS#12 wallet creation. below is the command to create wallet



1. Creating a PKCS#12 Wallet
To create an Oracle PKCS#12 wallet (ewallet.p12), use the following command:

orapki wallet create -wallet wallet_location [-pwd password]


To create an auto login wallet (cwallet.sso) that is associated with a PKCS#12 wallet (ewallet.p12), use the following command:

orapki wallet create -wallet wallet_location -auto_login [-pwd password]

This command creates a wallet with auto login enabled (cwallet.sso) and associates it with a PKCS#12 wallet (ewallet.p12). The command prompts you to enter the password for the PKCS#12 wallet, if no password has been specified at the command line

2. Adding self signed certificate to Wallet

./orapki wallet add -wallet /tmp/wallet dn "cn=Orasystemsusa certificate" keysize 2048 self_signed validity 1825 pwd Password1

validity 1825 is number of days certificate will be valid.


3. Once you have wallet with self-signed certificate you can upload it by following

Upload the new wallet.

Log in to Fusion Middleware Control and navigate to the Oracle Identity Federation instance.

Navigate to Administration, then Security and Trust.

In the Wallets tab, click Update.

Check the Update checkbox for the wallet you want to update.

Select the keystore type, wallet location, password, and alias. (i uploaded ewallet file)

Click OK.