Tuesday, May 6, 2014

Oracle Access Manager (OAM) 11.1.2.2.0 and Oracle Unified Directory (OUD) 11.1.2.2.0 Integration

Oracle Access Manager (OAM) 11.1.2.2.0 and Oracle Unified Directory (OUD) 11.1.2.2.0 and WebLogic 10.3.6 Integration


OAM and WebLogic installed on svrtst02
OUD and WebLogic installed on svrtst03

Assumptions:  WebLogic 10.3.6 domain has been created on both svrtst02 and svrtst03 and extended for OAM.

Good idea to backup the configuration or server home before proceeding.

Install OUD on svrtst03 in $MW_HOME.

So, svrtst02 has the following installed:
oracle_common
Oracle_IDM1
Oracle_OAMWebGate1
Oracle_WT1
coherence_3.7
user_projects
wlserver_10.3

And, svrtst03 has the following installed:
oracle_common
Oracle_OUD1
Oracle_WT
user_projects
wlserver_10.3

Run oud-setup on svrtst03 either in GUI mode or CLI.  End result being that the following command is executed to create an LDAP directory store:

./oud-setup \
          --cli \
          --baseDN dc=acme,dc=com \
          --addBaseEntry \
          --ldapPort 1389 \
          --adminConnectorPort 4444 \
          --rootUserDN cn=Directory\ Manager \
          --rootUserPasswordFile ****** \
          --doNotStart \
          --ldapsPort 1636 \
          --useJavaKeystore /certs/svrtst03.isedlab.org.jks \
          --keyStorePasswordFile ****** \
          --certNickname svrtst03.isedlab.org\ u.s.\ government\ id \
          --serverTuning autotune \
          --importTuning autotune \
          --no-prompt \
          --noPropertiesFile


The LDAP directory instance is created in $MW_HOME/asinst_1/OUD.
export OUD_HOME=$MW_HOME/asinst_1/OUD

Start the instance as follows:
cd $OUD_HOME/bin
./start-ds

The default listening port is 1389, the SSL port is on 1636 and the management port is on 4444.

The instance can be managed from here:
http://svrtst03:7001/odsm

Create a scripts directory in $OUD_HOME/scripts

Quick check to make sure that everything is up and running, from the CLI:
cd $OUD_HOME/bin
./ldapsearch -h localhost -p 1389 -D "cn=directory manager" -w passw0rd -b "dc=acme,dc=com" "(objectclass=*)"

dn: dc=acme,dc=com
dc: acme
objectClass: domain
objectClass: top



Configuring OUD for OAM


The following links are useful:
http://docs.oracle.com/cd/E27559_01/install.1112/e27301/preconfigoud.htm

http://uberether.com/2012/configuring-oracle-unified-directory-as-an-identity-store-for-access-manager-11gr2-11-1-2/


From the Oracle documentation:
"Before you can use your LDAP directory as an Identity store, you must preconfigure it. The procedure in this section enables you to preconfigure Oracle Unified Directory (OUD) for using Oracle Unified Directory (OUD) as your LDAP Identity store."

Create the following file in $MW_HOME/asinst_1/OUD/scripts:
OUDContainers.ldif

dn:cn=oracleAccounts,dc=acme,dc=com
cn:oracleAccounts
objectClass:top
objectClass:orclContainer

dn:cn=Users,cn=oracleAccounts,dc=acme,dc=com
cn:Users
objectClass:top
objectClass:orclContainer

dn:cn=Groups,cn=oracleAccounts,dc=acme,dc=com
cn:Groups
objectClass:top
objectClass:orclContainer

dn:cn=Reserve,cn=oracleAccounts,dc=acme,dc=com
cn:Reserve
objectClass:top
objectClass:orclContainer


Next, import the OUD server:
cd $OUD_HOME/bin
./stop-ds
./import-ldif --backendID userRoot --append --ldifFile $OUD_HOME/scripts/OUDContainers.ldif
./start-ds 


Configure OIM proxy users and acis to communicate with OUD after installing OUD. Create the OIM Admin User, Group and the ACIs.

vi $OUD_HOME/scripts/oudadmin.ldif

dn: cn=systemids,dc=acme,dc=com
changetype: add
objectclass: orclContainer
objectclass: top
cn: systemids

dn: cn=oimAdminUser,cn=systemids,dc=acme,dc=com
changetype: add
objectclass: top
objectclass: person
objectclass: organizationalPerson
objectclass: inetorgperson
mail: oimAdminUser
givenname: oimAdminUser
sn: oimAdminUser
cn: oimAdminUser
uid: oimAdminUser
userPassword: passw0rd

dn: cn=oimAdminGroup,cn=systemids,dc=acme,dc=com
changetype: add
objectclass: groupOfUniqueNames
objectclass: top
cn: oimAdminGroup
description: OIM administrator role
uniquemember: cn=oimAdminUser,cn=systemids,dc=acme,dc=com

dn: cn=oracleAccounts,dc=acme,dc=com
changetype: modify
add: aci
aci: (target = "ldap:///cn=oracleAccounts,dc=acme,dc=com")(targetattr =
 "*")(version 3.0; acl "Allow OIMAdminGroup add, read and write access to
 all attributes"; allow (add, read, search, compare,write, delete, import,export)
 (groupdn = "ldap:///cn=oimAdminGroup,cn=systemids,dc=acme,dc=com");)

dn: cn=oimAdminUser,cn=systemids,dc=acme,dc=com
changetype: modify
add: ds-privilege-name
ds-privilege-name: password-reset


Run the following command to load the above LDIF file:

./ldapmodify --hostname localhost --port 1389 --bindDN "cn=Directory Manager" \
--bindPassword passw0rd --defaultAdd --filename $OUD_HOME/scripts/oudadmin.ldif


Create a weblogic account

vi $OUD_HOME/scripts/weblogic.ldif

dn: cn=weblogic,cn=systemids,dc=acme,dc=com
changetype: add
objectclass: top
objectclass: person
objectclass: organizationalPerson
objectclass: inetorgperson
mail: weblogic
givenname: weblogic
sn: weblogic
cn: weblogic
uid: weblogic
userPassword: passw0rd


And add it to the LDAP:

./ldapmodify --hostname localhost --port 1389 --bindDN "cn=Directory Manager" \
--bindPassword passw0rd --defaultAdd --filename $OUD_HOME/scripts/weblogic.ldif


Add weblogic account to the oimAdminGroup

vi $OUD_HOME/scripts/weblogicGroup.ldif

dn: cn=oimAdminGroup,cn=systemids,dc=acme,dc=com
changetype: modify
add: uniquemember
uniquemember: cn=weblogic,cn=systemids,dc=acme,dc=com


And add it to the LDAP:

./ldapmodify --hostname localhost --port 1389 --bindDN "cn=Directory Manager" \
--bindPassword passw0rd --defaultAdd --filename ../scripts/weblogicGroup.ldif



Add the global-aci to changelog node in OUD (I think this is only necessary if you setup replication.  See the documentation listed above for more information).

cd $OUD_HOME/bin

./dsconfig ->
2. Authentication and Authorization ->
2. Access Control Handler ->
1. View and edit the Access Control Handler ->
2. global-aci ->
2. Add one or more values ->

(target="ldap:///cn=changelog")(targetattr="*")(version 3.0; acl "External changelog access"; allow(read,search,compare,add,write,delete,export) groupdn="ldap:///cn=oimAdminGroup,cn=systemids,dc=acme,dc=com";)

Delete this one:
(target="ldap:///cn=changelog")(targetattr="*")(version 3.0; acl "External changelog access"; deny (all) userdn="ldap:///anyone";)

q from dsconfig

Start OAM...
Configuration -> User Identity Stores


From OAM ID Stores, click Create



Store Name: OUD
Store Type: OUD: Oracle Unified Directory
Location: 10.10.107.49:1389
Login ID Attribute: uid
User Password Attribute: userPassword
User Search Base: dc=acme,dc=com
User Filter Object Class: inetOrgPerson
Group Search Base: dc=acme,dc=com

Test the connection and if successful, click Apply:



Change the Default Store to OUD:


And click Apply

Change the System Store to OUD click the green plus sign to add users:


Click Search and add the selected users:


Then click Apply:





Click OK and enter a valid administrator username and password to validate the system administrator account:




Click Validate.  This can error "Group oimAdminGroup is already a member" can be ignored.

Now configure the IDMDomainAgent to use the new OUD store:

Launch Pad -> Access Manager -> Authentication Modules



Click Search, then select LDAP.  Change User Identity Store to OUD and click Apply:



Sign out and then sign back in.  The new new credential store is in use now.

One way to confirm is to check the OUD access logs on svrtst03.

cd $OUD_HOME/logs

Do a tail -f access and logon to Oracle Access Manager.  Typical output is shown below from the access log:

[06/May/2014:10:33:56 -0400] SEARCH REQ conn=11517 op=23 msgID=24 base="dc=acme,dc=com" scope=sub filter="(&(objectclass=inetOrgPerson)(uid=weblogic))" attrs="uid,wirelessacctnumber,postalcode,manager,street,orclguid,obresponsetries,dateofbirth,uniquename,defaultgroup,telephonenumber,obresponsetimeout,orgunit,timezone,employeenumber,obYetToBeAnsweredChallenge,initials,activestartdate,description,maidenname,localityname,gender,objectclass,sn,oblastloginattemptdate,fax,middlename,homeaddress,country,obpasswordhistory,cn,oblastsuccessfullogin,oblastfailedlogin,preferredlanguage,pobox,mobile,hiredate,uiaccessmode,oblastresponseattemptdate,department,state,givenname,lastname,org,employeetype,title,obfirstlogin,name,obpasswordcreationdate,homephone,pager,mail,activeenddate,oblockouttime,obAnsweredChallenges,loginid,firstname,obpasswordexpmail,obpasswordchangeflag,postaladdress,obuseraccountcontrol,telephone,displayname,oblogintrycount"
[06/May/2014:10:33:56 -0400] SEARCH RES conn=11517 op=23 msgID=24 result=0 nentries=1 etime=3
[06/May/2014:10:33:56 -0400] BIND REQ conn=11526 op=3 msgID=4 type=SIMPLE dn="cn=weblogic,cn=systemids,dc=acme,dc=com"
[06/May/2014:10:33:56 -0400] BIND RES conn=11526 op=3 msgID=4 result=0 authDN="cn=weblogic,cn=systemids,dc=acme,dc=com" etime=2
[06/May/2014:10:33:56 -0400] SEARCH REQ conn=11517 op=24 msgID=25 base="cn=weblogic,cn=systemids,dc=acme,dc=com" scope=base filter="(objectclass=inetOrgPerson)" attrs="uid,wirelessacctnumber,postalcode,manager,street,orclguid,obresponsetries,dateofbirth,uniquename,defaultgroup,telephonenumber,obresponsetimeout,orgunit,timezone,employeenumber,obYetToBeAnsweredChallenge,initials,activestartdate,description,maidenname,localityname,gender,objectclass,sn,oblastloginattemptdate,fax,middlename,homeaddress,country,obpasswordhistory,cn,oblastsuccessfullogin,oblastfailedlogin,preferredlanguage,pobox,mobile,hiredate,uiaccessmode,oblastresponseattemptdate,department,state,givenname,lastname,org,employeetype,title,obfirstlogin,name,obpasswordcreationdate,homephone,pager,mail,activeenddate,oblockouttime,obAnsweredChallenges,loginid,firstname,obpasswordexpmail,obpasswordchangeflag,postaladdress,obuseraccountcontrol,telephone,displayname,oblogintrycount"
[06/May/2014:10:33:56 -0400] SEARCH RES conn=11517 op=24 msgID=25 result=0 nentries=1 etime=2
[06/May/2014:10:33:56 -0400] SEARCH REQ conn=11529 op=35 msgID=36 base="dc=acme,dc=com" scope=sub filter="(&(objectclass=inetOrgPerson)(uid=weblogic))" attrs="uid,wirelessacctnumber,postalcode,manager,street,orclguid,obresponsetries,dateofbirth,uniquename,defaultgroup,telephonenumber,obresponsetimeout,orgunit,timezone,employeenumber,obYetToBeAnsweredChallenge,initials,activestartdate,description,maidenname,localityname,gender,objectclass,sn,oblastloginattemptdate,fax,middlename,homeaddress,country,obpasswordhistory,cn,oblastsuccessfullogin,oblastfailedlogin,preferredlanguage,pobox,mobile,hiredate,uiaccessmode,oblastresponseattemptdate,department,state,givenname,lastname,org,employeetype,title,obfirstlogin,name,obpasswordcreationdate,homephone,pager,mail,activeenddate,oblockouttime,obAnsweredChallenges,loginid,firstname,obpasswordexpmail,obpasswordchangeflag,postaladdress,obuseraccountcontrol,telephone,displayname,oblogintrycount"
[06/May/2014:10:33:56 -0400] SEARCH RES conn=11529 op=35 msgID=36 result=0 nentries=1 etime=3
[06/May/2014:10:33:56 -0400] SEARCH REQ conn=11529 op=36 msgID=37 base="dc=acme,dc=com" scope=sub filter="(&(objectclass=groupofuniquenames)(uniquemember=cn=weblogic,cn=systemids,dc=acme,dc=com))" attrs="orgunit,mail,cn,description,name,orclguid,rolecategory,org,objectclass,displayname"
[06/May/2014:10:33:56 -0400] SEARCH RES conn=11529 op=36 msgID=37 result=0 nentries=1 etime=2
[06/May/2014:10:33:56 -0400] SEARCH REQ conn=11529 op=37 msgID=38 base="dc=acme,dc=com" scope=sub filter="(&(objectclass=groupofuniquenames)(uniquemember=cn=oimAdminGroup,cn=systemids,dc=acme,dc=com))" attrs="orgunit,mail,cn,description,name,orclguid,rolecategory,org,objectclass,displayname"
[06/May/2014:10:33:56 -0400] SEARCH RES conn=11529 op=37 msgID=38 result=0 nentries=0 etime=1
[06/May/2014:10:33:56 -0400] SEARCH REQ conn=11529 op=38 msgID=39 base="dc=acme,dc=com" scope=sub filter="(&(objectclass=inetOrgPerson)(uid=weblogic))" attrs="uid,wirelessacctnumber,postalcode,manager,street,orclguid,obresponsetries,dateofbirth,uniquename,defaultgroup,telephonenumber,obresponsetimeout,orgunit,timezone,employeenumber,obYetToBeAnsweredChallenge,initials,activestartdate,description,maidenname,localityname,gender,objectclass,sn,oblastloginattemptdate,fax,middlename,homeaddress,country,obpasswordhistory,cn,oblastsuccessfullogin,oblastfailedlogin,preferredlanguage,pobox,mobile,hiredate,uiaccessmode,oblastresponseattemptdate,department,state,givenname,lastname,org,employeetype,title,obfirstlogin,name,obpasswordcreationdate,homephone,pager,mail,activeenddate,oblockouttime,obAnsweredChallenges,loginid,firstname,obpasswordexpmail,obpasswordchangeflag,postaladdress,obuseraccountcontrol,telephone,displayname,oblogintrycount"
[06/May/2014:10:33:56 -0400] SEARCH RES conn=11529 op=38 msgID=39 result=0 nentries=1 etime=3
[06/May/2014:10:33:56 -0400] SEARCH REQ conn=11529 op=39 msgID=40 base="cn=weblogic,cn=systemids,dc=acme,dc=com" scope=base filter="(objectclass=inetOrgPerson)" attrs="uid,wirelessacctnumber,postalcode,manager,street,orclguid,obresponsetries,dateofbirth,uniquename,defaultgroup,telephonenumber,obresponsetimeout,orgunit,timezone,employeenumber,obYetToBeAnsweredChallenge,initials,activestartdate,description,maidenname,localityname,gender,objectclass,sn,oblastloginattemptdate,fax,middlename,homeaddress,country,obpasswordhistory,cn,oblastsuccessfullogin,oblastfailedlogin,preferredlanguage,pobox,mobile,hiredate,uiaccessmode,oblastresponseattemptdate,department,state,givenname,lastname,org,employeetype,title,obfirstlogin,name,obpasswordcreationdate,homephone,pager,mail,activeenddate,oblockouttime,obAnsweredChallenges,loginid,firstname,obpasswordexpmail,obpasswordchangeflag,postaladdress,obuseraccountcontrol,telephone,displayname,oblogintrycount"
[06/May/2014:10:33:56 -0400] SEARCH RES conn=11529 op=39 msgID=40 result=0 nentries=1 etime=1
[06/May/2014:10:33:57 -0400] SEARCH REQ conn=11529 op=40 msgID=41 base="dc=acme,dc=com" scope=sub filter="(&(objectclass=inetOrgPerson)(uid=weblogic))" attrs="uid,wirelessacctnumber,postalcode,manager,street,orclguid,obresponsetries,dateofbirth,uniquename,defaultgroup,telephonenumber,obresponsetimeout,orgunit,timezone,employeenumber,obYetToBeAnsweredChallenge,initials,activestartdate,description,maidenname,localityname,gender,objectclass,sn,oblastloginattemptdate,fax,middlename,homeaddress,country,obpasswordhistory,cn,oblastsuccessfullogin,oblastfailedlogin,preferredlanguage,pobox,mobile,hiredate,uiaccessmode,oblastresponseattemptdate,department,state,givenname,lastname,org,employeetype,title,obfirstlogin,name,obpasswordcreationdate,homephone,pager,mail,activeenddate,oblockouttime,obAnsweredChallenges,loginid,firstname,obpasswordexpmail,obpasswordchangeflag,postaladdress,obuseraccountcontrol,telephone,displayname,oblogintrycount"
[06/May/2014:10:33:57 -0400] SEARCH RES conn=11529 op=40 msgID=41 result=0 nentries=1 etime=3
[06/May/2014:10:33:57 -0400] SEARCH REQ conn=11529 op=41 msgID=42 base="dc=acme,dc=com" scope=sub filter="(&(objectclass=groupofuniquenames)(uniquemember=cn=weblogic,cn=systemids,dc=acme,dc=com))" attrs="orgunit,mail,cn,description,name,orclguid,rolecategory,org,objectclass,displayname"
[06/May/2014:10:33:57 -0400] SEARCH RES conn=11529 op=41 msgID=42 result=0 nentries=1 etime=1
[06/May/2014:10:33:57 -0400] SEARCH REQ conn=11529 op=42 msgID=43 base="dc=acme,dc=com" scope=sub filter="(&(objectclass=groupofuniquenames)(uniquemember=cn=oimAdminGroup,cn=systemids,dc=acme,dc=com))" attrs="orgunit,mail,cn,description,name,orclguid,rolecategory,org,objectclass,displayname"
[06/May/2014:10:33:57 -0400] SEARCH RES conn=11529 op=42 msgID=43 result=0 nentries=0 etime=2
[06/May/2014:10:34:02 -0400] CONNECT conn=11544 from=10.10.107.89:44839 to=10.10.107.49:1389 protocol=LDAP
[06/May/2014:10:34:02 -0400] DISCONNECT conn=11544 reason="Client Disconnect"


WebLogic Integration

On svrtst02, login to WebLogic.

Security Realms -> my realm -> Providers

From Authentication Providers, click New



Select LDAP Authenticator for Type and click OK.

From Authenticator Providers, click on OUD_LDAP:



 Under the Common tab, change Control Flag to SUFFICIENT:



 Click on the Provider Specific tab and enter the relevant information for the new provider:



Click Save to complete.

 

Saturday, April 26, 2014

Unable to Start Oracle Unified Directory

 

On RHEL 5.6, installed Oracle Unified Directory 11.1.2.2.0 from ofm_oud_generic_11.1.2.2.0_disk1_1of1.zip.

After installation into $MW_HOME/Oracle_OUD1 and configuration don't start the directory server as the directories $MW_HOME/Oracle_OUD1/logs and $MW_HOME/Oracle_OUD1/locks are not created by the oud-setup program.  Create these manually before starting the directory server.  If the directory server is started by oud-setup, then you are unable to stop using the stop-ds command because there is no server.pid file (stop-ds looks for this in the locks directory).  I ended up de-installing/re-installing when this first happened.

When trying to start using start-ds, the following error message is thrown:

severity=SEVERE_ERROR msgID=2359728 msg=The LDAP connection handler defined in configuration entry cn=LDAP Connection Handler,cn=Connection Handlers,cn=config was unable to bind to 0.0.0.0:389:  IOException(Address already in use)

Solution

cd $MW_HOME/Oracle_OUD1/config
cp -p config.ldif config.ldif.bak
vi config.ldif
Change this:
ds-cfg-listen-port: 389
to
ds-cfg-listen-port: 1389

Then issue start command.

Thanks to a anonymous reader for sharing the correct location as to where the true stop/start commands are:

cd $MW_HOME/asinst_1/OUD/bin

and issue the start command from there.

Wednesday, April 23, 2014

Installing OpenLDAP 2.4.39 on RHEL 5.6

Note: Very high level instructions.  Should work with OpenLDAP 2.4.38 (has been tested) as well and RHEL 5.10.  Possibly other versions also.

My directory structure is as follows:
software install location - /opt
schema file location - /usr/local/etc/
slapd.conf file location - /usr/local/etc/openldap/
database file location - /var/openldap/openldap-data/
certs location -  /usr/local/etc/openldap

Install Berkely DB

Download db-6.0.30.tar.gz and untar in /opt
cd /opt
tar xvf db-6.0.30.tar.gz
cd db-6.0.30/build_unix
../dist/configure --enable-cxx --prefix=/usr/local/BerkeleyDB.6.0
make
make install

Do this step so that libs can be found without having to go through creating messy links:
cd /etc/ld.so.conf.d
vi berkely_db.conf
/usr/lib

/sbin/ldconfig

Install OpenSSL

Download openssl-1.0.1g.tar.gz and untar in /opt
cd /opt
tar xvf openssl-1.0.1g.tar.gz
export CPPFLAGS="-I/usr/local/BerkeleyDB.6.0/include"
export LDFLAGS="-L/usr/local/BerkeleyDB.6.0/lib"
cd  openssl-1.0.1g
./config shared
make
make test
make install

Install Cyrus-SASL

Download cyrus-sasl-2.1.26.tar.gz and untar in /opt
cd /opt
tar xvf cyrus-sasl-2.1.26.tar.gz
cd db-6.0.20/
export CPPFLAGS="-I/usr/local/BerkeleyDB.6.0/include"
export LDFLAGS="-L/usr/local/BerkeleyDB.6.0/lib -L/usr/local/ssl/lib"
./configure --with-openssl=/usr/local/ssl --libdir=/usr/local/lib64
make
make install

After the install, note the following message:
********************************************************
* WARNING:
* Plugins are being installed into /usr/local/lib/sasl2,
* but the library will look for them in /usr/lib/sasl2.
* You need to make sure that the plugins will eventually
* be in /usr/lib/sasl2 -- the easiest way is to make a
* symbolic link from /usr/lib/sasl2 to /usr/local/lib/sasl2,
* but this may not be appropriate for your site, so this
* installation procedure won't do it for you.
*
* If you don't want to do this for some reason, you can
* set the location where the library will look for plugins
* by setting the environment variable SASL_PATH to the path
* the library should use.
********************************************************
I set the SASL_PATH environment variable in the .bash_profile file as follows:
SASL_PATH=/usr/local/lib/sasl2
export SASL_PATH


Install OpenLDAP

Download OpenLDAP openldap-2.4.39.tar.gz
cd /opt
tar xvf openldap-2.4.39.tar.gz
cd openldap-2.4.39
export CPPFLAGS="-I/usr/local/BerkeleyDB.6.0/include -I/usr/local/ssl/include"
export LDFLAGS="-L/usr/local/BerkeleyDB.6.0/lib -L/usr/local/ssl/lib"
./configure --with-tls --with-cyrus-sasl --sysconfdir=/usr/local --bindir=/usr/local --libdir=/usr/local/lib64
make depend
make
make test
make install


Copy Schema Files

mkdir /usr/local/etc
cp -rfp /opt/openldap-2.4.39/servers/slapd/schema /usr/local/etc/.

Copy slapd.conf

mkdir /usr/local/etc/openldap/
cp -rfp /opt/openldap-2.4.39/servers/slapd/slapd.conf  /usr/local/etc/openldap/

Generate  the Encrypted Admintrator LDAP Password

This can be entered into the slapd.conf file so that OpenLDAP can be started without user interaction:
/opt/openldap-2.4.39/servers/slapd/slappasswd -s password
{SSHA}O4iHZ1yg+f4ynVg1rrUjYMki2F6jTp7O

Copy this value and paste it into the /usr/local/etc/openldap/slapd.conf file:
rootpw          {SSHA}O4iHZ1yg+f4ynVg1rrUjYMki2F6jTp7O

The slapd.conf file may end up looking like this:
include         /usr/local/etc/schema/core.schema
include         /usr/local/etc/schema/cosine.schema
include         /usr/local/etc/schema/inetorgperson.schema

pidfile         /var/openldap/run/slapd.pid
argsfile        /var/openldap/run/slapd.args

#######################################################################
# BDB database definitions
#######################################################################

database        bdb
suffix          "dc=my-domain,dc=com"
rootdn          "cn=Manager,dc=my-domain,dc=com"
# Cleartext passwords, especially for the rootdn, should
# be avoid.  See slappasswd(8) and slapd.conf(5) for details.
# Use of strong authentication encouraged.
rootpw          {SSHA}O4iHZ1yg+f4ynVg1rrUjYMki2F6jTp7O
# The database directory MUST exist prior to running slapd AND
# should only be accessible by the slapd and slap tools.
# Mode 700 recommended.
directory       /var/openldap/openldap-data/my-domain
# Indices to maintain
index   objectClass     eq
index   cn              eq
index   uid             eq


Starting OpenLDAP Services

cd /usr/local/etc/openldap/slapd.conf
nohup /opt/openldap-2.4.39/servers/slapd/slapd -f /usr/local/etc/openldap/slapd.conf -d 1 &

View status of the OpenLDAP server:
tail -f nohup.out

Stoping OpenLDAP Services

kill -INT `cat /var/openldap/run/slapd.pid`

Enabling SSL

Request a server certificate from your RA or CA.

Place the issuing CA certificate file here:
TLSCACertificateFile    /usr/local/etc/openldap/cacert.pem

The signed server certificate file here:
TLSCertificateFile      /usr/local/etc/openldap/servercrt.pem

And the private key file (only readable by the process that starts the OpenLDAP server) here:
TLSCertificateKeyFile   /usr/local/etc/openldap/serverkey.pem

Monday, October 22, 2012

PuTTY X11 proxy: wrong authorisation protocol attempted Error: Can't open display: localhost:X.Y

This site helped with the solution:

http://froebe.net/blog/2008/11/14/getting-xlib-putty-x11-proxy-wrong-authentication-protocol-attempted-i-have-the-answer/

This site helped with configuring Xming:

http://www.math.umn.edu/systems_guide/putty_xwin32.html

Here's what I did (this assumes you have Xming installed and configured):

After installing Xming on a Windows box, I installed PuTTY.  I configured my PuTTY session for X11 forwarding as follows:

1. Start PuTTY

2. Enter a name or IP address in the Host Name (or IP address) box and for Connection type, select SSH

3. Save the session

4. In the Category section, expand Connection then SSH, then X11

5. On the Options controlling SSH X11 forwarding screen, check Enable X11 forwarding and MIT-Magic-Cookie-1

6. From the Category section on the left, click Session and then click Save in the Basic options for Your PuTTY session section

7. Start an Xming session, followed by an SSH session from PuTTY

8. From your newly opened SSH session, type xclock

9. An xwindow clock will appear on your Windows server

10. Now su - oracle

11. Attempt the same by typing xclock and you'll see an error such as this:
PuTTY X11 proxy: wrong authorisation protocol attempted Error: Can't open display: localhost:11.0

12. Open another PuTTY session and type the following:
# xauth list
localhost.localdomain/unix:0  MIT-MAGIC-COOKIE-1  1425043ba52e4f50f597c83d434baf82

13. In your oracle session, type the following:
$ xauth add localhost:0  MIT-MAGIC-COOKIE-1  1425043ba52e4f50f597c83d434baf82

14. Export your display to your Windows box:
$ export DISPLAY=192.168.10.120
$ export DISPLAY=localhost:10.0
Thanks for the correction to Anonymous posted January 25, 2013.

15. Run xclock, and you should see the clock on your Windows box
Running yum install <package_name> gives "The requested URL returned error: 404"

On a recently created CentOS 6.2 x64 VM, I tried to install some packages such as compat-libstdc++-33.x86_64 but when I ran the command:

# yum install compat-libstdc++-33.x86_64

I got the following errors:

...
...
http://mirror.atlanticmetro.net/centos/6.2/extras/x86_64/repodata/repomd.xml: [Errno 14] PYCURL ERROR 22 - "The requested URL returned error: 404"
Trying other mirror.
http://mirror.clarkson.edu/centos/6.2/extras/x86_64/repodata/repomd.xml: [Errno 14] PYCURL ERROR 22 - "The requested URL returned error: 404"
Trying other mirror.
http://mirror.cs.vt.edu/pub/CentOS/6.2/extras/x86_64/repodata/repomd.xml: [Errno 14] PYCURL ERROR 22 - "The requested URL returned error: 404"
Trying other mirror.
...
...
Trying other mirror.
http://pubmirrors.reflected.net/centos/6.2/os/x86_64/Packages/elfutils-libelf-devel-0.152-1.el6.x86_64.rpm: [Errno 14] PYCURL ERROR 22 - "The requested URL returned error: 404"
Trying other mirror.


Error Downloading Packages:
  elfutils-libelf-devel-0.152-1.el6.x86_64: failure: Packages/elfutils-libelf-devel-0.152-1.el6.x86_64.rpm from base: [Errno 256] No more mirrors to try.

To resolve the issue, I ran the following command:

# yum clean all
Loaded plugins: fastestmirror, presto, refresh-packagekit
Cleaning repos: base extras updates
Cleaning up Everything
Cleaning up list of fastest mirrors
0 delta-package files removed, by presto
 
I was then able to install the required package:

# yum install compat-libstdc++-33.x86_64
Loaded plugins: fastestmirror, presto, refresh-packagekit
Determining fastest mirrors
 * base: mirror.flhsi.com
 * extras: mirrors.loosefoot.com
 * updates: mirror.nwresd.org
base                                                     | 3.7 kB     00:00
base/primary_db                                          | 4.5 MB     00:00
extras                                                   | 3.5 kB     00:00
extras/primary_db                                        | 8.9 kB     00:00
updates                                                  | 3.5 kB     00:00
updates/primary_db                                       | 3.4 MB     00:09
Setting up Install Process
Resolving Dependencies
--> Running transaction check
---> Package compat-libstdc++-33.x86_64 0:3.2.3-69.el6 will be installed
--> Finished Dependency Resolution

Dependencies Resolved

================================================================================
 Package                    Arch          Version             Repository   Size
================================================================================
Installing:
 compat-libstdc++-33        x86_64        3.2.3-69.el6        base        183 k

Transaction Summary
================================================================================
Install       1 Package(s)

Total download size: 183 k
Installed size: 806 k
Is this ok [y/N]: y
Downloading Packages:
Setting up and reading Presto delta metadata
Processing delta metadata
Package(s) data still to download: 183 k
compat-libstdc++-33-3.2.3-69.el6.x86_64.rpm              | 183 kB     00:00
Running rpm_check_debug
Running Transaction Test
Transaction Test Succeeded
Running Transaction
  Installing : compat-libstdc++-33-3.2.3-69.el6.x86_64                      1/1

Installed:
  compat-libstdc++-33.x86_64 0:3.2.3-69.el6

Complete!

Friday, October 5, 2012

Automated Process to Apply Oracle PSU for Multiple Instances (Oracle 10g)

Assumes that there is more than one instance of an Oracle database in a Streams environment.

Assumes that a patch is to be applied along with a PSU.

Assumes that the listeners have been stopped.

Assumes that all relevant patches have been copied to $ORACLE_HOME/patches.

Should also work for 11g environments.

The operator is asked to run the script in the following order:


Apply the Patch (e.g. Patch ID 11724977)
1. Shutdown all database instances 
   $ sh patch_it.sh shutdown

2. Apply the patch 
   $ sh patch_it.sh patch_apply

3. Start up the database instances 
   $ sh patch_it.sh startup 


Apply the PSU 
1. Stop streams (note that for this case, the PSU does not require that the instances be shutdown). 
   $ sh patch_it.sh stop_streams 

2. Apply PSU
   $ sh patch_it.sh psu_apply 

3. Start streams 
   $ sh patch_it.sh start_streams 

Post-Installation Procedure
1. Check that the patch has been installed (this verifies that patch 11724977 has been applied) 
   $ sh patch_it.sh patch_check 

Back-out Procedure
1. Shutdown all database instances 
   $ sh patch_it.sh shutdown



2. Rollback the patch (Patch ID 11724977) 
   $ sh patch_it.sh patch_rollback

3. Start up all instances 
   $ sh patch_it.sh startup

4. Stop streams 
   $ sh patch_it.sh stop_streams

5. Rollback the PSU 
   $ sh patch_it.sh psu_rollback 


patch_it.sh Shell Script

#!/bin/bash

# Shuts down all streams processes
function stop_streams {
   echo
   echo "Shutting Down Streams"
   echo
   for NAME in $NAME_LIST
   do
      export ORACLE_SID=$NAME
      sqlplus '/ as sysdba' @stop_streams.sql << EOD
EOD
   done
}
# Starts up all streams processes
function start_streams {
   echo
   echo "Start Up Streams"
   echo
   for NAME in $NAME_LIST
   do
      export ORACLE_SID=$NAME
      sqlplus '/ as sysdba' @start_streams.sql << EOD
EOD
   done
}

# Shuts down all databases
function shutdown {
   echo
   echo "Shutdown databases"
   echo


   for NAME in $NAME_LIST
   do
      export ORACLE_SID=$NAME
      sqlplus '/ as sysdba' << EOD
      shutdown immediate
EOD
      done

   echo
   echo "All databases have been shutdown"
   echo
}

# Starts up all databases
function startup {
   echo
   echo "Startup databases"
   echo

   for NAME in $NAME_LIST
   do
      export ORACLE_SID=$NAME
      sqlplus '/ as sysdba' << EOD
      startup
EOD
   done

   echo
   echo "All databases have been started"
   echo
}

# Starts up all databases in UPGRADE mode
function startup_upgrade {
   echo
   echo "Startup databases - upgrade"
   echo

   for NAME in $NAME_LIST
   do
      export ORACLE_SID=$NAME
      sqlplus '/ as sysdba' << EOD
      startup upgrade
      spool patch_$NAME.log
      @?/rdbms/admin/catupgrd.sql
      spool off
EOD
   done

   echo
   echo "All databases have been started in upgrade mode"
   echo
}

# Run utlrp
function run_utlrp {
   echo
   echo "Running utlrp..."
   echo

   for NAME in $NAME_LIST
   do
      export ORACLE_SID=$NAME
      sqlplus '/ as sysdba' << EOD
      shutdown immediate
EOD
   done

   for NAME in $NAME_LIST
   do
      export ORACLE_SID=$NAME
      sqlplus '/ as sysdba' << EOD
      startup
      @?/rdbms/admin/utlrp.sql
EOD
   done

   echo
   echo "All databases have been upgraded"
   echo

}

# Check database registy
function check_db_registry {
   echo
   echo "Checking database registry..."
   echo

   for NAME in $NAME_LIST
   do
      export ORACLE_SID=$NAME
      sqlplus '/ as sysdba' << EOD
      @rmOCM.sql
      SELECT COMP_NAME, VERSION, STATUS FROM SYS.DBA_REGISTRY;
EOD
   done

}

# Checks opatch functionality
function patch_check {
   echo "Checking OPatch Functionality"

   cd $ORACLE_HOME/patches
   $OPATCH prereq CheckConflictAgainstOHWithDetail -jre $ORACLE_HOME/$JRE -phBaseDir ./$PATCH_ID -invPtrLoc $ORACLE_HOME/oraInst.loc || { echo "opatch check failed"; exit 1; }
}

# Applies patch
function patch_apply {
   echo "Applying Patch $PATCH_ID"
   cd $ORACLE_HOME/patches/$PATCH_ID
   $OPATCH apply -jre $ORACLE_HOME/$JRE -invPtrLoc $ORACLE_HOME/oraInst.loc || { echo "opatch apply $PATCH_ID failed"; exit 1; }
}

# Applies psu_apply
function psu_apply {
   for NAME in $NAME_LIST
   do
      export ORACLE_SID=$NAME
      sqlplus '/ as sysdba' << EOD
      @?/rdbms/admin/catbundle.sql psu apply
EOD
   done
}

# Rolls back patch
function patch_rollback {
   echo "Rolling back patch"
   cd $ORACLE_HOME/patches/$PATCH_ID
   $OPATCH rollback -id $PATCH_ID -jre $ORACLE_HOME/$JRE -invPtrLoc $ORACLE_HOME/oraInst.loc || { echo "opatch rollback $PATCH_ID failed"; exit 1; }
     
}

# Rollback psu_apply
function psu_rollback {
   for NAME in $NAME_LIST
   do
      export ORACLE_SID=$NAME
      NAME=`echo $NAME | tr '[:lower:]' '[:upper:]'`
      sqlplus '/ as sysdba' << EOD
      @?/rdbms/admin/catbundle_PSU_${NAME}_ROLLBACK.sql

EOD
   done
}

function downgrade_db {
   cp -rfp $ORACLE_HOME/rdbms/admin/catrelod.sql .
   cp -rfp $ORACLE_HOME/network/admin .
   for NAME in $NAME_LIST
   do
      export ORACLE_SID=$NAME
      sqlplus '/ as sysdba' <<EOD
      startup downgrade
      SPOOL downgrade_$NAME.out
      @?/rdbms/admin/catdwgrd.sql
      SPOOL OFF
      SHUTDOWN IMMEDIATE
EOD
   done
}

function downgrade_cat {
   cp -rfp catrelod.sql $ORACLE_HOME/rdbms/admin/
   cp -rfp admin $ORACLE_HOME/network/
   for NAME in $NAME_LIST
   do
      export ORACLE_SID=$NAME
      sqlplus '/ as sysdba' <<EOD
      startup downgrade
      SPOOL catrelod_$NAME.out
      @?/rdbms/admin/catrelod.sql
      SPOOL OFF
      SHUTDOWN IMMEDIATE
EOD
   done
}

##########################
# main                   #
##########################

# Must NOT be run as root
if [ "$(id -n -u)" != "oracle" ]
then
   echo "This script must be run as oracle" 1>&2
   exit 1
fi

ORACLE_HOME=/opt/app/oracle/product/10.2.0/db_1
OPATCH=$ORACLE_HOME/patches/OPatch/opatch
JRE=`ls -l $ORACLE_HOME|grep jre1|awk -F" " '{ print $9 }'`
#
# Change to relevant Patch ID
#
PATCH_ID=11724962
HOSTNAME=`hostname -f | awk -F . '{print $1}'`
# Hostname is in the form of servername-1a.<domain_name>/servername-2a.<domain_name>
# etc...  Matching on 1, we can determine if we are on servername-1 or servername-4
match="1"

if [[ "$HOSTNAME" =~ "${match}" ]]; then
     NAME_LIST="dbwhrs01 dbprod01 dbweb01"
     export NAME_LIST
  else
     NAME_LIST="dbwhrs02 dbprod02 dbweb02"
     export NAME_LIST
fi

case "$1" in
'startup')
   startup
;;
'startup_upgrade')
   startup_upgrade
;;
'run_utlrp')
   run_utlrp
;;
'check_db_registry')
   check_db_registry
;;
'shutdown')
   shutdown
;;
'patch_check')
   patch_check
;;
'patch_apply')
   patch_apply
;;
'psu_apply')
   psu_apply
;;
'patch_rollback')
   patch_rollback
;;
'psu_rollback')
   psu_rollback
;;
'start_streams')
   start_streams
;;
'stop_streams')
   stop_streams
;;
'downgrade_db')
   downgrade_db
;;
'downgrade_cat')
   downgrade_cat
;;
*)
   echo "Usage: $0 [startup|shutdown|patch_check|patch_apply|psu_apply|startup_upgrade|run_utlrp|check_db_registry|stop_streams|start_streams|patch_rollback|psu_rollback|downgrade_db|downgrade_cat]"
esac

stop_streams.sql Script
set serveroutput on size 1000000
declare

v_apply_name varchar2(100) := '';
v_capture_name varchar2(100) := '';
v_propagation_name varchar2(100) := '';

begin

   select apply_name into v_apply_name from dba_apply;
   select capture_name into v_capture_name from dba_capture;
   select propagation_name into v_propagation_name from dba_propagation;

   begin
      DBMS_APPLY_ADM.STOP_APPLY(apply_name => v_apply_name);
   exception
   when others then
      null;
   end;

   begin
      DBMS_CAPTURE_ADM.STOP_CAPTURE(capture_name => v_capture_name);
   exception
   when others then
      null;
   end;

   begin
      DBMS_PROPAGATION_ADM.STOP_PROPAGATION(v_propagation_name);
   exception
   when others then
      null;
   end;
end;
/

start_streams.sql Script
set serveroutput on size 1000000
declare

v_apply_name varchar2(100) := '';
v_capture_name varchar2(100) := '';
v_propagation_name varchar2(100) := '';

begin

   select apply_name into v_apply_name from dba_apply;
   select capture_name into v_capture_name from dba_capture;
   select propagation_name into v_propagation_name from dba_propagation;

   begin
      DBMS_APPLY_ADM.START_APPLY( apply_name => v_apply_name);
   exception
   when others then
      null;
   end;

   begin
      DBMS_CAPTURE_ADM.START_CAPTURE(capture_name => v_capture_name);
   exception
   when others then
      null;
   end;

   begin
      DBMS_PROPAGATION_ADM.START_PROPAGATION(v_propagation_name);
   exception
   when others then
      null;
   end;
end;
/
rmOCM.sql Script
Our site does not allow OCM component to be installed, hence it needs to be removed.

-- remove old dba jobs, if exists
DECLARE
job_num NUMBER;
CURSOR job_cursor is
    SELECT job
    FROM dba_jobs
    WHERE schema_user = 'ORACLE_OCM'
    AND (what like 'ORACLE_OCM.MGMT_CONFIG.%'
     OR what like 'ORACLE_OCM.MGMT_DB_LL_METRICS.%');
BEGIN
   FOR r in job_cursor LOOP
     sys.DBMS_IJOB.REMOVE(r.job);
     COMMIT;
   END LOOP;
   EXCEPTION
     WHEN OTHERS THEN
       -- ignore any exception
       null;
END;
/

#Rem stop the job
BEGIN
   BEGIN
     -- call to stop the job
     ORACLE_OCM.MGMT_CONFIG.stop_job;  
   EXCEPTION
     WHEN OTHERS THEN
       -- ignore any exception
       null;
  END;
END;
/

-- disable jobs

exec dbms_scheduler.disable('ORACLE_OCM.MGMT_STATS_CONFIG_JOB');
exec dbms_scheduler.disable('ORACLE_OCM.MGMT_CONFIG_JOB');

-- drop user ORACLE_OCM

drop user ORACLE_OCM cascade;

Thursday, October 4, 2012

My first PostgreSQL stored function...

Goal
------
Have the following table:
ld_operatingsystem

        Column        |            Type             | Modifiers
----------------------+-----------------------------+-----------
 computer_idn         | numeric                     |
 operating_system_idn | numeric                     |
 ostype               | character varying(255)      |
 version              | character varying(255)      |
 laststartuptime      | timestamp without time zone |
 facility_id          | numeric                     |
 suitename            | character varying(255)      |

I need to update the suitename column so that it is composed of the concatenation of the ostype and version columns.

Start a psql session and paste the function:

create or replace function u_ld_tbl() returns void as $$

declare

   userRecord record;

begin

   for userRecord IN
      select computer_idn, operating_system_idn, ostype, version from ld_operatingsystem
   loop
      update ld_operatingsystem
      set suitename = userRecord.ostype||' '||userRecord.version
      where computer_idn = userRecord.computer_idn
      and operating_system_idn = userRecord.operating_system_idn;

      raise notice 'Updated %, % ', userRecord.computer_idn, userRecord.operating_system_idn;
   end loop;

   return;
end;

$$ language plpgsql;

The function can be invoked from psql as follows:

select u_ld_tbl();
NOTICE:  Updated 31, 19
NOTICE:  Updated 1, 1
NOTICE:  Updated 4, 7
...
...
...
NOTICE:  Updated 53, 37
NOTICE:  Updated 54, 38
NOTICE:  Updated 55, 39
 u_ld_tbl
----------

(1 row)