Thursday, July 29, 2021

Forum is back online ! -- Erman Arslan's Oracle Forum --

We're back online! Thanks Nabble for the support. We are on a different Nabble server now. But nothing is changed in your perspective :) 
You can access the forum directly from the blog as before.. 
Just by clicking the "Erman Arslan's Oracle Forum is available now. Click here to ask a question. " link in the homepage of this blog or by using the direct url : http://ermanarslan.blogspot.com/p/forum.html

We will continue where we left off. Actually it was a few hours break but just saying :)

Planned Outgage ! -- Erman Arslan's Oracle Forum --

We have an outgage due to a planned operation that is currently being performed by our forum host (Nabble).

Our forum is being migrated to its new host at the moment.

Erman Arslan's Oracle Forum will be available soon. Thanks for your understanding and patience...

Note that, due to the short vacation, the questions piled up a bit. I will answer them all, once our forum will be reachable again.

    

Friday, July 9, 2021

Erman Arslan's Oracle Forum / Jun 1 2021 - July 7 2021 - "Questions and Answers Series"

Question: How much time do you spend/lose?

Answer: Well, how much time I gain? :) 

Remember, you can ask questions and get remote support using my forum.
Just click on the link named "Erman Arslan's Oracle Forum is available now.
Click here to ask a question", which is available on the main page of Erman Arslan's Oracle Blog 
-- or just use the direct link:


Come on, let's see what we've been up to in Jun + in the beginning of July 2021.
Do not forget to read the blog posts too :)

Backup testing failed using data protector tool by satish

ERROR in ADOP PREPARE PHASE by neldyan14

Oracle OAS 5.5 integration with Oracle OAM by Zaheer

Error opening oat page for specific user in r12 by satish

XML materialized view by Roshan

Dynamic footer on RTF template of word by Huy Nguyen

Oracle Apex 20.1 LDAP authentication with Windows Active Directory by Zaheer

Creating materialized view based on OEBS editionables by ANIETO

DB Cloning failing in EBS R12.1.3 after upgrading Database to 19c by soumya

Global database name cannot be left blank by big

oracle cloud 13c by Arsalan

Autoconfig delet profile option by big

How to Implement Signon Password Custom Profile Option R12.2 by satish

ODA- Database migration between 2 ODA Boxes and 19C upgrade for EBS by mmanavat

Changing domain name in r12.2 multinode by satish

forms-c4ws by big

How Can I Restrict Applications Users To Be Signed In Only Once At Any Time Doc ID 375403.1

Connection is long by big

Is Oracle Certification easy to pass? by Tasmina

Restrict user to a single session r12.2.5 by satish

Oracle RAC and PCP in R12.2 by mi_singh@hotmail.com

How do I set db_unique_name properly in CDB.env file? by SriCheb

Data access from one dB to other by satish

Security report r12.2 by satish

Test mail for workflowmailer by big

Concurrent manager for Alert Notification by big

golden gate index issue by Roshan

Dblink from oracle to PostgreSQL-compilation error by satish

pluggable database could not open by Arsalan

Switching EBS Application from primary to Secondary Database by Tabrez

Recoverability Roadmaps & Remediation Options - Oracle, Systems, Apps Technology, Virtualization and Engineered Systems

In this post, I want to share my thoughtson Recoverability, actually my approach that I use in Recoverability Assessments.. Actually, these types of assessments are comprehensive, they even include DR solutions, trainings, recovery processes and the continuous availability.

I start with the readiness.. Readiness in 3 different areas : People, Process and Technology. I review and rank the readiness for key areas that are enablers for availability, resiliency and recoverability by assessing current IT capabilities of the customer.

Once I generate the readiness documents, I do my analysis, determine the gaps and then present my recommendations. I support the customer in execution as well.. ( if they need me there..)

So it is pretty straight forward, but still requires lots of efforts :)

The assesments starts with the information gathering. I just gather the detailed information and do my analysis for a number of attributes in the following areas;  

Operational Staff, Response Plans, Recovery Testing, Program Maintenance, Business Expectations, Production & DR Facilities, Application Infrastructure, Data Restoration and Recovery Network.

During this first phase, we usually meet with the customers. I write down the people, process, and techonology findings. Then, we popuplate tool based discovery reports ( DB , Server, SAN healtchecks, Server grabs & logs etc..)

In the second phase, I create a recommendation list.  Next, I do the remediation roadmap, finalize the recoverability assessment document and lasty I give the final recoverability assessment repsentation (an executive presentation actually)

While analyzing the people and process findings, I check to see if there any any gaps in the following areas; business expectations, production & DR facilities, Application Infra, Data Restoration, Recovery network , Operational Staff, Reponse plan, Recovery Testing, Program maintanence and etc..

Following is an example of the GAPs that may be found in the Recovery network ;

No formal DR program
DR requirements unknown
Lack of formal documented policies or processes

Following is another example of the GAPs that may be found in Data Restoration area;

Lack of service levels with the business
No formal tiering structure
Recovery RTOs / RPOs have not been defined
Lack of recovery expectations

These are big gaps :) and they are here just to give you some examples, but I guess you understand  the scope of the work already..

In the technology analysis phase, I analyze the following layers through the following critieria;

Presenation layer, Login/application, Database, Compute, Storage, Network  --> Production HA, DR, Backup, Archiving.

Some examples for the technology findings in this phase;

A single point of failure (SPOF) exists which would cause a complete outage for the application.
Server configuration is not aligned with the intended high-availability design (cluster is misconfigured).

Well, after the findings, I create a recommendation matrix, and summarize these recommendations..
I analyze the recommendation from the implementation effort and business impact perspectives and then create a matrix to show the risk level / business impact and implementation effort  of each recommendations.


Business Impact goes low to high when you go upwards in the y axis, effort goes high to low when you go right in the x axis.. So,  action items/recommendations in the top right quadrant are given high implementation priority, due to low effort & high impact. So you get the idea..

As for the redmediation options, I give the as-is Architecture, then propose target solutions by considering/analayzing the gaps. There may be more than one solution proposed as part of the Gap Analysis against Recoverability Business Requirements .

Finally I create thre recoverabiliy roadmap and that's it :)

In the recoverability roadmap, I start with the areas of opportunities and build a 18 Months plan. (maybe further) . I list the actions that should be done in near term, in 6-12 Months and in 12-18 Months to reach the target state where we usually have the following;

Increased ROI
Standardized Environment
Ensured Recoverability 
Recoverability and continuous availability services aligned with the business needs
Operational Excellence
Organizational stability
Culture of Ensured availability & DR Services.

That's end of this post. I hope you find it useful.
If you need any advice or consultancy, feel free to contact me.

Thursday, July 8, 2021

OVM Manager / Weblogic -- CVE-2019-2725 / deserialization - remote code execution vulnerability

Here is a filtered information for OVM customers, who are complaining about CVE-2019-2725, which is a deserialization vulnerability, a remote code execution vulnerability that is remotely exploitable without authentication.

I guess everyone already knows that OVM uses Weblogic in the backend. Actually this post is for all the ones who use certain versions of Weblogic..  Weblogic 10.3.6 and 12.1.3. 

The solution is simple for the ones who have extended support contract because these Weblogic releases are currently in extended support. This is the reality for both OVM Manager and Weblogic customers.

So, you just apply the latest PSU, or a PSU which fixes the issue and the overlay patch if there is any 
and that's it.. You are done .. (for instanc :e Apr 2019 PSU 12.1.3.0.190416 Patch 29204657 + Overlay Patch 29694149 on 12.1.3.0.190416 for CVE-2019-2725)

OVM Manager customer can also apply the PSU and overlays.. Although Weblogic is bundled with OVM Manager, it is supported to get latest security updates, to the latest minor updates. I mean you can apply PSUs to the Weblogic of OVM Manager..

The questions arises for the ones who don't have extended support for Weblogic. That is if they don't have extended support contract, they won't be able to download any WLS patches for those specific releases.. 

This means  no PSU, no CPU, no overlay...

In this case, they have 2 options.. 

1) They may upgrade their OVM manager to version 3.4.7, which is bundled with Weblogic 12.1.3.0.210119 -- January 2021 Patch Set Update (PSU) for WebLogic Server 12.1.3.0.

2) They may implement the following workaround (but this must be tested, I mean it must be ensured that OVM Manager will not lose any functionalities after these actions);

Delete the wls9_async_response.war & wls-wsat.war packages from Weblogic and restart the OVM Manager+ Weblogic
Disable access to“/_async/*” and “/wls-wsat/” URLs on weblogic.
Test well..
-- you may even implement this access restriction on the firewall level.

MOS References:

Upgrading products bundled with Oracle VM Manager (Doc ID 2195205.1)
Security Alert CVE-2019-2725 Patch Availability Document for Oracle WebLogic Server (Doc ID 2535708.1)

Tuesday, June 29, 2021

Weblogic -- BI Publisher 12.2.1.3 -- Error running config.sh - java.lang.IllegalArgumentException: ONS configuration failed / oracle.ons.NoServersAvailable: Subscription time out

I want to share a solution for a problem that was recently encountered  in one of our client environments.

The problem was on config.sh.. That is, config.sh was encountering ONS errors.. This was a fresh install and it wasn't expected to be that challenging.

Anyways there were multiple errors recorded in the flow.. 

The first one was ;

oracle.ons.NoServersAvailable: Subscription time out -> 

 java.lang.IllegalArgumentException: ONS configuration failed

BARMedataPlugin related errors were following it;

problem encountered when cleaning up SI using plugin: 

oracle.bi.servicelcm.metadata.BARMetadataPlugin[[java.lang.NullPointerException at sun.nio.fs.UnixFileSystem.getPath(UnixFileSystem.java:272)

UnixFileSystem.getPath and UnixFileSystem.java were foundational. I checked their source code.. But! these were the results actually.

So the config.sh encountered a problem related with the ONS and then it understood that it has failed but continued and tried to clean the mess but can't find the mess / a specific file that it expected to be present in the filesystem.. Probably.. So that error in UnixFileSystem.java was a result of that. 

I like interpreting the logs this way :) They tell me the story  when I read them correctly :) They also give me the execution flow, so that I can guess the internal parts of the execution.

Anyways, I was already familiar with that ONS problem, so I revisited one my earlier posts ->  https://ermanarslan.blogspot.com/2017/09/problem-installing-oracle-fusion.html

I tried that workround documented in that post.. (After all It saved my day earlier..)

The workaround for this was, to supply an argument in the config_internal.sh. (config.sh indirectly executes config_internal.sh) -> oracle.jdbc.fanEnabled=false

However; suprisingly this time it didn't work.. config.sh was still getting those ONS errors in the next runs.

So this time I implemented a fix and here I 'am writing this blog post for it..

The fix was a patch actually..

Patch 26045997: ENABLING DRIVER FAN WITHOUT RUNNING ONS DAEMONS CAUSES CONNECT REQUEST ERROR

So, we applied it to the WLS and then run config.sh without a problem..

Ofcourse these things are based on the DB layer configuration and if that ONS configuration was compatible with the expectations of config.sh, we wouldn't get any errors in the first place.. 

Continuing the life without ONS configuration have some disadvantages, but as far as I see, in most of the clients they are acceptable.. So that patch is the key to save the day :)

Stay tuned..

Wednesday, June 23, 2021

GTECH -- Summer School 2021 -- Oracle Database & Cloud & Big Data & EBS - Training For Newly Graduates!

Favorite days for my trainer mode :) a quick but efficient training for new engineers who are interested in our subjects. Summer School 2021-- Oracle Database & Cloud & Big Data & EBS - Training For Newly Graduates!


Once in a year, we as GTech provide training for newly graduated engineers.

In this training, we teach Sql, PL/SQL, Oracle Database & Cloud, EBS, OBIEE, BigData, ETL and more.

This year was the fourth time, that I was the lecturer for "Database and Cloud".

See the following blog posts for 2020, 2019 and 2018 Summer Schools ->

https://ermanarslan.blogspot.com/2020/08/gtech-summer-school-2020-oracle.html
https://ermanarslan.blogspot.com/2019/07/gtech-summer-school-2019-oracle.html
https://ermanarslan.blogspot.com/2018/07/summer-school-introduction-to-oracle.html

As usual, the students of the class were so curios about databases and actually Oracle in general..

I tried to shed a light on the important topics like Oracle Database Server Architecture, Oracle Database Process Architecture, background processes, High availability configurations, Cloud Computing (Oracle Cloud Infrastructure + Google Cloud Platform /GCP) , Big Data, NoSQL databases and so on..

The list of topics covered in the training was as follows;
  • Introduction to RDBMS
  • Introduction to Oracle
  • Architecture (Oracle)
  • Installation (Oracle) & workshop
  • DBA role & DBA tools
  • Cloud Computing
  • Big Data & NoSQL
  • APPS DBA role & EBS System Administration (EBS 12.2)

Monday, June 14, 2021

Speaking at Google-IDC Webinar / Database Modernization -- Google Cloud, Oracle BMS, Cloud SQL , Spanner and more

Speaking at the event, IDC - Google. My topic will be about Database Modernization.
I will explain running Oracle Databases on GCP - Bare Metal, Cloud SQL(Postgresql, MS SQL and MYSQL) and some Google specific database solutions like Spanner.
I will give the motivation and the need for database modernization and will look to the process of obtaining a modern database environment and put some light on the benefits of it.
The event is in Turkey and the presetation will be in Turkish. If you want to join, we will happy to see you among us in the event. Stay tuned!

Registration Link:
--Webinar'a kayıt olmak isteyen arkadaşlar için kayıt linkini aşağıda paylaşıyorum:

Monday, May 31, 2021

Erman Arslan's Oracle Forum -- May 2021 - "Questions and Answers Series"

Question: How much time do you spend/lose?

Answer: Well, how much time I gain? :) 

Remember, you can ask questions and get remote support using my forum.
Just click on the link named "Erman Arslan's Oracle Forum is available now.
Click here to ask a question", which is available on the main page of Erman Arslan's Oracle Blog 
-- or just use the direct link:


Come on, let's see what we've been up to in May .
Do not forget to read the blog posts too :)


May 2021 Issues:

·     logminer read rate downstream DB by Roshan

·        Upgrade Java Version on Oracle APPS R 12.0 by Brian Hogantara

·        logminer read rate by Roshan

·        open files by Roshan

·        How do I set db_unique_name properly in CDB.env file? by SriCheb

·        Concurrent manager for Alert Notification by big

·        Creating materialized view based on OEBS editionables by ANIETO

·        Oracle datbase is generating lot and lot of .trc and .trm files by Mohammed Hamed

·        EBS Database performance degraded after upgrade to 19c by soumya

·        Failure of server APACHE bridge by big

·        vmstat by Roshan

·        Dblink from Linux to windows by satish

·        Order of modules during conversion by Kalyana Chakravarthy

·        Bursting program errors by Sri

·        Migration of EBS R12.2.4 from Redhat 6 to Redhat 7 by Tabrez

·        shared NFS performance issue by Roshan

·        rapidwiz failed during installation 12.2 on 2 node rac environment. by raiq1

·        regarding forms by shafi

·        Adstpall.sh is exiting with status 3 by Mohammed Hamed

·        runcluvfy failed continuously by raiq1

·        Rac to Rac Cloning by dbaappadmin

·        Oracle indexes --in Turkish by sami çelik

·        Re: R12.2.4 Failed to execute FMW pre-requisite check by abdul

·        Replication/ updation of Patch on eBS by Zaheer

·        R12.2.4 Failed to execute FMW pre-requisite check by abdul

·        shareplex by Roshan

·        Monitor MV by Roshan

·        configuring psqlodbc-13.00.0000 in RHEL7 64bit by satish

·        OHS 12.2.1.4 config issue by Zaheer

·        DBlink from oracle to postgresql -DG4ODBC by satish

·        SQL Monitoring Report - Estimated Rows by DBAS

·        Dblink from oracle to PostgreSQL by satish

·        Long running concurrent programs - in Turkish by serdar

Sunday, May 30, 2021

Exadata X8M-2 & PCA X8-2 -- Part 2 Installation / Exadata X8M-2 installation (Imaging, install.sh steps, insights, notes and so on)

Let's take a look at Exadata X8M-2 installation process.. Actually, It is a standard procedure that we follow for installing all the Exadata versions.. 

This time we have ROCE and PMEM inside the machine (in addition to the standard Exadata hardware), but these components don't make any difference while imaging the machine.. We just be sure that they are working properly after the imaging and before installing the GRID & RDBMS software..

In this post, I will give you an overview about the process, some clues and some experiences real life..

Let's start with the installation method; 

Well... The installation/imaging is done remotely due to pandemic.

Basically, we need a shell that allows remote copy-paste for during installation process.

Shared Shell does that job ->  https://www.oracle.com/support/shared-shell.html

Only the java must be installed on the client computer that runs the shell.

The installations are done from a NFS share. So, we put all the required installation files into the NFS share and make the installation by using them..

The installation process is similar to the method that we follow for installing the earlier versions of Exadata.

We connect to the ILOM interfaces of the nodes using SSH.

We first install the CELL nodes, then the DB nodes.. Actually it doesn't matter which node we start with , but we prefer installing the CELL nodes first.. 

The steps for imaging/re-imaging is similar both for DB and CELL nodes.. We just use different ISO images..

Before the imaging, we need to have the NFS shares be accessable from the ILOMs of the Exadata nodes. This is caused of the configuration we do, we basically tell ILOMs to reach the NFS and boot from there.

So, we connect the first CELL using ILOM through SSH and we start the /SP/console. (start /SP/console)

We check the current image version of the CELL using imageinfo.

We set the ISO using the set server_URI command. (set server_URI=nfs://nfs_ip/directory/cellblabla.iso) 

Note that, we mustunzip the cell image zip file before that.

Then, we use "set /SP/services/kvms/host_storage_device/ mode=remote", and tlater set the boot device to cdrom. (set boot_device=cdrom)

We reboot/hard reset.. the node ->  "reset /SYS"  and then we run the command "start /SP/console" (to follow the boot process) -- The node boots itself using the new iso placed in the NFS.. So reimaging starts taking place here..

We watch the first boot of the first cell node we are imaging and see if there are any problems or not.. If everything works as expected, we repeat the same process for all the remaining CELL nodes in parallel..

When the boot process is completed, we check the image version with the imageinfo command and expect to see the image version we used for the installation/imaging/reimaging process.

Once we complete reimaging the CELL nodes, we use the same installation method for the DB nodes.. Remember, only the ISO image is different for the DB nodes. ( so we set the correct Image using the set server_URI)

Once the imaging is completed, we expect to see that all the interfaces are up & running. The interfaces with re prefix (re*) are ROCE interfaces.. eth0,bondeth0, re1, re2.. all of the must be up.

Note that, in our case, in one of the CELL nodes, the ROCE interfaces were not present.. We reimaged that CELL multiple times but this didn't solve the issue. 

We even check the system by following the MOS Note: Verify RoCE Cabling on Oracle Exadata Database Machine X8M-2 and X8M-8 Servers (Doc ID 2587717.1), but no fix.. 

That CELL node couldn't see the ROCE interfaces at all.. So we made a dummy replacement.(reseat the cards and cables) , rebooted the machine and it worked! Of course we created an SR and ordered the new ROCE interfaces, but this move saved the day and we could at least proceed with the software installation.

One important note; in these kinds of issues that we identify during the installation, any issues like hardware issues , ILOM alerts, blinking Service led and so on, we create a SR to Oracle Support and solve the issue by following that SR.

Note that, we had Service led blinking in one of the Cell nodes as well.. This time for PMEM.. Well,.. We did that dummy replacement trick and reseated the failing card.  It worked for this issue too :) Again, we still ordered the new parts...

We also had a LACP issue in the DB nodes.. The LACP client interfaces were up but not pingable .. We investigated the issue in the Linux side but everyting seemed okay.. Then the customer corrected the configuration in the switch side and LACP interfaces started working properly.. So, if you encounter problems with the LACP - (for the client interfaces), make the customer check the switch configuration and cabling in the first place! :)

Link Aggregation Control Protocol (LACP) on Exadata (Doc ID 2198475.1)

We continue with the software installation; (GRID, Database and all that) 

We put the files listed in OEDA output into the nfs share. ( or into a local directory on the first database node) Note that, we don't put the ISO images that we used for the imaging process into the NFS share.

Before starting the software installation, we check all the nodes and ensure that, their network interfaces are up, their dates are correct and sync, their gateways are correct and pingable.. (we do all the environment checks including nslookup actually...) We also check the passwordless ssh connectivity between the nodes ( for root)

Then, we run the install.sh Example:install.sh -cf OEDA_xml-s1 ... In order to run this command, the OEDA itself should be there in the node as well.. Ofcourse OEDA xml too should be there.

Note that, we need to use the same version of OEDA, which we used to create the OEDA xml. If we use a different version of OEDA during the software installation, we may get errors while performing the install steps. So, if we use a newer version of OEDA for the installation, then we need to rebuild our OEDA xml using that newer version of OEDA.. ( We open the newer OEDA, we import the OEDA xml and we save it.. This way, we get our OEDA xml generated with our new version ODEA)

Note that, one of the steps of install.sh updates the environment as 1/8 rack. (if we are performing a 1/8 installation). Install.sh uses OEDA xml as input. So in this step, install.sh decrease the cores and it implements the Capacity on Demand if we choosed that in OEDA. For instance, it decreases the core count of the second db node to 8 and reboot that node.. Then , it decrease the core count of first db node and reboot the node.. After the reboot, we continue with the next step of install.sh.

So we complete all the steps (that we find necessary to be implemented.. For instance ,we don't execute the step named Resecure Machine in some of the installations, as very tight security becomes a problem in some customer sites.) and finish the software installation.. 

Once the installation is completed, exachk is executed and lastly we get our installation report.. 

That 's it.. After completing the steps in install.sh, we get ourselves an up&running, ready Exadata X82-M..

You can check my previous Exadata installation-related blog posts about this install.sh process but it is mostly straight forward..

Next post in this series (Part3) will be about on PCA configuration.. I mean configuring the virtual environment in PCA. Stay tuned ! Happy weekend.