Showing posts with label SSO-OID-OAM. Show all posts
Showing posts with label SSO-OID-OAM. Show all posts

Monday, 17 February 2014

Oracle Identity and Access Management

Recently, I conducted a training on Oracle Identity Management related products, just putting various topics I have covered under this.


  • Technical Insight on Oracle Access Manager, Oracle Internet Directory, Oracle Virtual Directory, WebGate, AccessGate and Windows Native Authentication. In this topic I mostly talked on the various implementation/Support experience, I have with IDM Products and lesson learned from each.
  • Installation and Implementation Steps for Identity Management Components.
  • Load Balancer in front of OAM and WebGate
  • Basic Performance Tuning on OAM, EAG, OID, HTTP WebTier, OVD
  • Proxy SSL Configuration for OAM, eBusiness, EAG Components
  • Integration of OAM with eBusiness Suite and WebCentre Content Management.
  • Provisioning of Identity Management with Fusion Apps
Keep Learning !!!!!

Monday, 10 February 2014

Enterprise Password Management/Self Service Password Management using Oracle Enterprise SSO

Enterprise Password Management/Self Service Password Management using Oracle Enterprise SSO

Recently I got chance to work on a Enterprise Password Management related activities using ESSO.

It should be broadly categorized as 
■ Application Password Change
■ Self-Service Windows Password Reset

I would be elaborating "Self-Service Windows Password Reset" in this section.

■ Self-Service Windows Password Reset

● Provides a fully integrated self-service Windows password reset solution for end-users, eliminating help desk calls and speeding the reset process. The user is challenged with a series of challenge questions which must be answered correctly in order for password reset to succeed.
● Challenge questions and acceptable answers, including the “weight” of each question, are administrator-configurable. 
● Self-service password reset functionality is accessed directly from the Windows logon dialog (integrated via GINA or credential provider link, depending on the OS version), and remotely via Web browser.

Questions and answers can be either specified by the administrator and stored directly within the ESSO-PR data store or retrieved dynamically via standard APIs from external systems, such as HR databases. Furthermore the ESSO PR Client can direct a user to the OIM KBA authentication engine to facilitate change password via that system. 

The weight of each question can be individually configured by the administrator using ESSO-PR’s confidence-based rating system so that one question can count more towards granting the user access than another. Correct answers add to the user’s quiz core, while incorrect answers subtract from it but not necessarily disqualify the user. Once the user correctly answers enough questions to pass the quiz, access to the account unlock and/or password reset functionality is granted. 

Required questions
Eliminator questions
Optional questions

The administrator can assign individual questions to specific users or groups using the ESSO-PR Administrative Console.

Architecture diagram is presented below for your reference:




Monday, 21 October 2013

Tuning of HTTP WebTier for Access Manager SSO Implementation

Tuning of HTTP WebTier for Access Manager SSO Implementation

. $HOME/webtierenv.sh
opmnctl status -l

. $HOME/webtierenv.sh
cd $MW_HOME/Oracle_WT1/instances/instance1/diagnostics/logs/OPMN/opmn
grep 'Process Unreachable' opmn.log

. $HOME/webtierenv.sh
cd $MW_HOME/Oracle_WT1/instances/instance1/diagnostics/logs/OHS/ohs1
grep 'still did not exit, sending a SIGKILL' ohs1.log

Make sure no latest OHS Restart has happened.

$MW_HOME/Oracle_WT1/instances/instance1/config/OHS/ohs1/httpd.conf
Look for mpm_worker_module and change MaxClients to 300, ThreadsPerChild to 50

There are multiple tuning recommedtation for HTTP WebTier in the following link, and should be carried out as recommended performance tuning activities:
http://docs.oracle.com/cd/E23943_01/core.1111/e10108/http.htm

Find the complete Fusion Middleware tuning guide at:
http://docs.oracle.com/cd/E23943_01/core.1111/e10108/toc.htm




You have encountered an unexpected PLSQL Error, Please contact System Administrator

You have encountered an unexpected PLSQL Error, Please contact System Administrator

Enable FND Debug using followin profile options:

FND: Debug Log Enabled Yes
FND: Debug Log Filename <empty>
FND: Debug Log Level STATEMENT
FND: Debug Log Mode Asynchronous with Cross-Tier Sequencing
FND: Debug Log Module %

2. Run the following SQL and and write down this number
SQL> select max(log_sequence) from fnd_log_messages;

3. Reproduce the issue and run the following SQL again to get the relevant information:
SQL> select * from fnd_log_messages where log_sequence > NUMBER_IDENTIFIED_BEFORE_IN_SQL_STATEMENT_AT_STEP_2 order by log_sequence;

Verify in the fnd_log_messages, you can see the following:

106500495|fnd.plsql.oid.fnd_ldap_wrapper.create_user: |ORA-31202: DBMS_LDAP: LDAP client/server error: Invalid credentials|
106500496|fnd.plsql.oid.fnd_ldap_wrapper.create_user: |l_err_code :FND_SSO_UNEXP_ERROR, l_tmp_str :ORA-31202: DBMS_LDAP: LDAP client/server error: Invalid credentials|
106500497|fnd.plsql.APP_EXCEPTION.RAISE_EXCEPTION.dict_auto_log|Unabled to call fnd_ldap_wrapper.create_user due to the following reason:
An unexpected error occurred. Please contact your System Administrator. (USER_NAME=SHARMAJ1)|

If this is the case, then during cloing, DBAs must have screwed up OID registration from your live system.

Do a fresh registration using txkrun.pl:
SQL> delete from fnd_user_preferences where user_name='#INTERNAL'
$FND_TOP/bin/txkrun.pl -script=SetSSOReg -registerinstance=yes
$FND_TOP/bin/txkrun.pl -script=SetSSOReg -registeroid=yes -provisiontype=3

Thursday, 17 October 2013

Set the DataSource Connection Continuity to avoid Admin/Managed Service Restart

Set the DataSource Connection Continuity to avoid Admin/Managed Service Restart

In a IDM domain, if AdminServer is started before the DB is up and running and subsequently DB is brought up, OPSS data source does not refresh and hence prevents access to application on Admin Server

Connection Creation Retry Frequency >>> This is needed if the Datasource will be down before the Admin server starts
Test Connections on Reserve >>> This is required if the datasource goes down after successful start

Navigation: WebLogic Console >>> Services >>> Data Sources >>> Click on the Data Sources >>> Connection Pool >>> Advanced

This should be done for OAM, OID and eBusiness AccessGate datasources.


Understanding "Managed Server Independence" in WebLogic Configuration

Understanding "Managed Server Independence" in WebLogic Configuration

"Managed Server Independence" specifies whether this Managed Server can be started when the Administration Server is unavailable.

Check that all managed servers have "Managed Server Independence" Enabled (by default it is)
Navigation: WebLogic Console >>> Environment >>> Servers >>> Click on the Name of the Managed Server >>> Configuration >>> Tuning >>> Advanced
Check if Managed Server Independence is Enabled

If you have "Managed Server Independence" Enabled on all managed servers, 
You can restart AdminServer without any problem (the managed servers will continue to work)

I did work for this for OAM Domain, IDM Domain, and eBusiness AccessGate Domain. So if any of the admin server is down, you eBusiness SSO Login would continue to work.

How to Configure OAM to Use Load Balancer URL

How to Configure OAM to Use Load Balancer URL

Navigation: OAM Console >>> System Configuration >>> Access Manager >>> Access Manager Settings

Put the Load Balancer details in this screen.

For me it was BigIP F5 iRule setup, make sure following is already in place and done by F5 Team:
https://mkktestLBR1.lbrdomain.local >>> Redirects to mkktestOAMserver1.unixdomain.local at 14100 port with SSL terminated at F5 Level




After Fusion/OID Installation /em URL is not Accessible

After Fusion/OID Installation /em URL is not Accessible

While trying to access http://mkktestOIDserver1.unixdomain.local:7001/em after installation, it is giving me following error:

Error 503--Service Unavailable 
From RFC 2068 Hypertext Transfer Protocol -- HTTP/1.1:
10.5.4 503 Service Unavailable
The server is currently unable to handle the request due to a temporary overloading or maintenance of the server. The implication is that this is a temporary condition which will be alleviated after some delay. If known, the length of the delay may be indicated in a Retry-After header. If no Retry-After is given, the client SHOULD handle the response as it would for a 500 response.

Note: The existence of the 503 status code does not imply that a server must use it when becoming overloaded. Some servers may wish to simply refuse the connection.

Locate targets.xml file and take a backup of the original file:
$DOMAIN_HOME/sysman/state/targets.xml

Immediately after 1st line of <Targets> add the following line:
<Target TYPE="oracle_ias_farm" NAME="Farm_IDMDomain" DISPLAY_NAME="Farm_IDMDomain">
<Property NAME="MachineName" VALUE="mkktestOIDserver1.unixdomain.local"/>
<Property NAME="Port" VALUE="7001"/>
<Property NAME="Protocol" VALUE="t3"/>
<Property NAME="isLocal" VALUE="true"/>
<Property NAME="serviceURL" VALUE="service:jmx:t3://mkktestOIDserver1.unixdomain.local:7001/jndi/weblogic.management.mbeanservers.domainruntime"/>
<Property NAME="WebLogicHome" VALUE="/opt/oracle/IDMLIVE_MW_HOME/WebLogic/wlserver_10.3"/>
<Property NAME="DomainHome" VALUE="/opt/oracle/IDMLIVE_MW_HOME/WebLogic/user_projects/domains/IDMDomain"/>

Restart Admin Server.

This resolved the issue.

Wednesday, 16 October 2013

How to Dump Provisioning and Synchronisation Profile from OID

How to Dump Provisioning and Synchronisation Profile from OID

How to Dump Provisioning Profile from OID

This would help you understand what are the Provisioning Profile exists in OID, configuration and status of all those.

ldapsearch -h mkktestserver1.unixdomain.local -p 3060 -D "cn=orcladmin" \
-w MalayFalsePass -L -s sub -b "cn=provisioning profiles,cn=changelog subscriber,cn=oracle internet directory" objectclass=*

Accordingly you can take a call on either enabling or disabling those, or changing the interval or troubleshooting purpose.
orclstatus: ENABLED
orclodipprovisioningappname: ebusl
orclodipprovisioningappname: ebsgold

How to Dump Synchronisation Profile from OID

manageSyncProfiles list -h mkktestserver1.unixdomain.local -p 7005 -D weblogic

Output of this would be something like:
Following are the registered profile(s):
ADtoOIDSynch >>> This is the synch profile that is in place.....

manageSyncProfiles get -h mkktestserver1.unixdomain.local -p 7005 -D weblogic -pf ADtoOIDSynch

Output of this would be something like(I have given only the important fields and removed the attribute part)

If these are configured in OID DIP Synch Profile AD to OID Synch should be issueless.

Profile ADtoOIDSynch details are :
odip.profile.condirfilter = searchfilter=(|(objectclass=group)(objectclass=organizationalUnit)(&(objectclass=user)(!(objectclass=computer))))
odip.profile.status = ENABLE

odip.profile.syncmode = IMPORT
odip.profile.version = 4.0
odip.profile.configfile = [INTERFACEDETAILS]
Reader: oracle.ldap.odip.gsi.ActiveChgReader
CheckAllEntries: false
SkipErrorToSyncNextChange: true
UpdateSearchCount: 100
SearchDeltaSize: 500

odip.profile.lastchgnum = 122685657
odip.profile.debuglevel = 0

You can Validate Synch Profile using following Command:

manageSyncProfiles validateProfile -h mkktestserver1.unixdomain.local -p 7005 -D weblogic -pf ADtoOIDSynch

Sample output for validateProfile
Map rules "orclodipattributemappingrules" have the following warnings:
Attribute rule "2" has warning: Source attribute 'cn' is optional for a required destination attribute 'cn'
Attribute rule "7" has warning: Source attribute 'samaccountname' is optional for a required destination attribute 'orclsamaccountname'
Attribute rule "22" has warning: Source attribute 'employeeid' is optional for a required destination attribute 'sn'
Attribute rule "25" has warning: Source attribute 'samaccountname' is optional for a required destination attribute 'orclsamaccountname'
Attribute rule "25" has warning: Source attribute 'userprincipalname' is optional for a required destination attribute 'orclsamaccountname'.

You can test Synch Profile using following Command:

You need to disable the profile temporarily to do this testProfile.
manageSyncProfiles testProfile -h mkktestserver1.unixdomain.local -p 7005 -D weblogic -pf ADtoOIDSynch

SynchronizationStatus : Synchronization Successful
SynchronizationErrors :
ECID : 39cb4812cad10e7e:-123fc09f:1401eaa2992:-8000-0000000000005981
View the related logs using the above ECID with the wlst command :
displaylogs(target=<ManagedServer_Name>, ecid='39cb4812cad10e7e:-123fc09f:1401eaa2992:-8000-0000000000005981')

Now this ECID you can look in wls_ods1-diagnostic.log, in my case it was warning only. This report that "SynchronizationStatus : Synchronization Successful", this means, synch is going okay...

In the wls_ods1-diagnostic.log, you can see this ECID in warning as reported in validateProfile.

Following Commands are also very useful to troubleshoot Synch Profile Issues:

ldapsearch -p 389 -h mkktestADserver1.addomain.local -D "AdtoOidSyncUser@vaa.vtg.local" -w "MalayFalsePass" -b "" -s base "objectclass=*" highestCommittedUSN
ldapsearch -h mkktestOIDserver1.unixdomain.local -p 3060 -D "cn=orcladmin" -w MalayFalsePass -b "" -s base "objectclass=*" lastchangenumber
ldapsearch -h mkktestOIDserver1.unixdomain.local -p 3060 -D "cn=orcladmin" -w MalayFalsePass \

-b "cn=subscriber profile,cn=changelog subscriber,cn=oracle internet directory" -s sub "objectclass=*"




Ad to OID Synch Issue

Ad to OID Synch Issue

By default, Microsoft Active Directory Connector retrieves changes to all objects in the container configured for synchronization. If you are interested in retrieving only a certain type of change, for example only changes to users and groups, then you should configure an LDAP search filter. This filter screens out changes that are not required when Microsoft Active Directory Connector queries Microsoft Active Directory. The filter is stored in the searchfilter attribute in the synchronization profile.

To troubleshout this kind of DIP issue enable TRACE:32 Logging for the following components:
oracle.dip.config
oracle.dip.mbean.prov
oracle.dip.mbean.sync
oracle.dip.util

You can achive this using enterprise manager console:
Navigation: http://mkktestserver1.unixdomain.local:7003/em >>> Click on wls_ods1 >>> Drop down WebLogic Server >>> Logs >>> Log Configuration

Monitor the managed server log to capture the issue.

Users are not getting synchronised from AD to OID.

Put a searchfilter in ADtoOIDSynch profile definition.
searchfilter=(|(objectclass=group)(objectclass=organizationalUnit)(&(objectclass=user)(!(objectclass=computer))))

In wls_ods1 log you would see a message like following after this change:
[2013-07-28T13:34:15.178+01:00] [wls_ods1] [NOTIFICATION] [DIP-10252] [oracle.dip] [tid: ADtoOIDSynch] [userId: <anonymous>] [ecid: 0000K0Uebzv03zD_R9c9yd1Hwpv2000002,0] [APP: DIP#11.1.1.2.0] Found Search Filter : ((|(objectclass=group)(objectclass=organizationalUnit)(&(objectclass=user)(!(objectclass=computer))))).

To verify if synchronisation is properly happening or not you can follow this link:
http://mkkoracleapps.blogspot.com/2013/07/how-to-check-ad-to-oid-synch-is.html















Sunday, 13 October 2013

Remove Dangling DNs from OID

Remove Dangling DNs from OID

. $HOME/oidenv.sh
oiddiag collect_all=true
cd $MW_HOME/asinst_1/diagnostics/logs/OID/tools

In this directory, a LDIF File with Dangling DNs entries would be created, run ldapmodify to delete these. This would delete the entries, and is a recommended steps to improve the OID Performance.

ldapmodify -h mkktestserver1.unixdomain.local -p 3060 -D cn=orcladmin -w MalayFalsePass -v -f oiddiag20130824212502_FixMembrAttr.ldif

Putting one sample entry from the LDIF File below:
dn: cn=gs_apps_essbase_live_businesuser,ou=groups,ou=united kingdom,cn=users,dc=mkkaddomain,dc=root,dc=local
changetype: modify
delete: uniquemember
uniquemember: cn=amit joggarish,ou=itadmin,ou=united kingdom,dc=mkkaddomain,dc=root,dc=local

>>> This means that the groups would be deleted from the user's unique member group. This is noted as Dangling DN as the same group doesnot exist in OID, but this has come from Microsoft AD.

Thursday, 10 October 2013

LDAP Maximum Number of Connection Issue

Notice the following error in OIDLDAPD Logs($MW_HOME/asinst_1/diagnostics/logs/OID/oid1)
[2013-07-27T17:13:04+01:00] [OID] [ERROR:8] [23144] [OIDLDAPD] [host: mkktestserver1] [pid: 6070] [tid: 2] ServerListener : Exceeding maximum number of connections allowed. Num Conns = 1024, Max Conns = 1024, Closing the connection.
[2013-07-27T17:13:04+01:00] [OID] [ERROR:8] [23144] [OIDLDAPD] [host: mkktestserver1] [pid: 6070] [tid: 2] ServerListener : Exceeding maximum number of connections allowed. Num Conns = 1024, Max Conns = 1024, Closing the connection.

Even I notices over a period of time connections are not getting closed:
$ netstat -an | grep 3131 | wc -l
590
$ netstat -an | grep 3131 | wc -l
590
$ netstat -an | grep 3131 | wc -l
590

The "Max numbers of Connections reached" / "Exceeding maximum number of connections allowed" error in OID indicates that the oidldapd process has reached the limit of TCP connections that the Operating System (OS) will allow it to open. 

Solution

1. OID /em >>>  Click on oid1 >>> Select Administration >>> Server Properties >>> Performance tab
4. Enter value for LDAP Idle Connection Timeout (minute) field, for this case I entered 10 minutes.
5. Click on Apply button







Enterprise Manager is not showing Proper Status of OID Components

Enterprise Manager is not showing Proper Status of OID Components

In /em console the status of OID components are showing down, specifically DIP and Admin server.

AdminServer-diagnostic.log shows following error:
[2013-07-26T19:18:58.183+01:00] [AdminServer] [ERROR] [J2EE JMX-46335] [] [tid: DmsThread-15] [userId: <anonymous>] [ecid: 0000K06ty6w03zD_R9c9yd1HvKaN000002,0] [APP: NonJ2EEManagement#11.1.1] MBean attribute access denied. [[
MBean: oracle.as.management.mbeans.register:type=opmnInfoCenter
Getter for attribute InstanceNames
Detail: Access denied. Required roles: Admin, Operator, Monitor, executing subject: principals=[] java.lang.SecurityException: Access denied. Required roles: Admin, Operator, Monitor, executing subject: principals=[]
at oracle.as.jmx.framework.wls.spi.security.WLSMBeanSecurityHelper.isInWlsGlobalSecurityRoles(WLSMBeanSecurityHelper.java:245)

Solution

1. Stop OID Admin and Managed Server

2. Edit $DOMAIN_HOME/config/fmwconfig/servers/AdminServer/dms_config.xml using following contents:

Old Value
 <dumpConfiguration>
 <dump intervalSeconds="10800" maxSizeMBytes="75" enabled="true"/>
 </dumpConfiguration>

New Value
 <dumpConfiguration>
 <dump intervalSeconds="10800" maxSizeMBytes="75" enabled="false"/>
 </dumpConfiguration>

3. Stop OID Admin and Managed Server

Also apply the patch mentioned in FM 11g Control Console Shows Webcache or other Opmn-Managed Target As DOWN But It Is UP. (Doc ID 1501246.1 )

Error In Fusion Middleware Control Console After Patchset 11.1.1.6 - JMX-46335 (Doc ID 1477246.1)
OBIEE 11g: Error: "[ERROR] [J2EE JMX-46335]...[APP: NonJ2EEManagement] MBean attribute access denied." after Upgrade from 11.1.1.5 To 11.1.1.6 (Doc ID 1439413.1)
FM 11g Control Console Shows Webcache or other Opmn-Managed Target As DOWN But It Is UP. (Doc ID 1501246.1 )

Remote Diagnostic Agent(RDA) Analysis for WebLogic Admin/Managed Server

Remote Diagnostic Agent(RDA) Analysis for WebLogic Admin/Managed Server

RDA is a powerful tool to gather various important information about the setup in place. In this post I am discussing RDA for WebLogic Server.

1. Set Environmental Variables related to the domain to be profiled, by running: 
cd $DOMAIN_HOME/bin
. ./setDomainEnv.sh

2. Configure RDA to profile WebLogic Server related files:
cd $MW_HOME/oracle_common/rda
./rda.sh -S -p WebLogicServer

This will configure the RDA to include the relevant data for WLS. It will open a text wizard, will ask you some general questions, and set the environment for running a collection with WLS data.

3. Run RDA (with no parameters) to trigger the actual collection
cd $MW_HOME/oracle_common/rda
./rda.sh 

4. You can check then the output, on a browser. In the OUTPUT folder, look for "<YOUR_PREFIX>_start.htm".

This is very useful info for Oracle also to work on Service Request.

JVM Heap Tuning for OID Managed Server/WebLogic Server

JVM Heap Tuning for OID Managed Server/WebLogic Server

This is applicable for any weblogic Admin and Managed Server.
In $DOMAIN_HOME/servers/wls_ods1/logs/wls_ods1.log you would notice an error like this and OID managed server would go to UNKNOW status.

####<Jul 26, 2013 5:57:00 AM BST> <Error> <Kernel> <mkktestserver1.unixdomain.local> <wls_ods1> <[STUCK] ExecuteThread: '5' for queue: 'weblogic.kernel.Default (self-tuning)'> <<WLS Kernel>> <> <39cb4812cad10e7e:-5dbeb3ba:14006f69c2f:-8000-0000000000005522> <1374814620626> <BEA-000802> <ExecuteRequest failed
java.lang.OutOfMemoryError: Java heap space.
java.lang.OutOfMemoryError: Java heap space
>

Solution

From nodemanager.properties I can observe that we are using start up scripts to bring up OID servers. From start up script I can see we are using a maximum of 1024M of heap which might not be sufficient.

JVM Heap is configured in the following file:
$DOMAIN_HOME/bin/setDomainEnv.sh

Go to the following line:
EXTRA_JAVA_PROPERTIES="${EXTRA_JAVA_PROPERTIES} -Didm.oracle.home=${IDM_ORACLE_HOME} -Xms512m -Xmx1024m -Xss512K -Djava.protocol.handler.pkgs=oracle.mds.net.protocol -Dweblogic.management.discover=false"
export EXTRA_JAVA_PROPERTIES

Since we are using a 64 bit JDK, it is well worth to try update memory settings to:
EXTRA_JAVA_PROPERTIES="${EXTRA_JAVA_PROPERTIES} -Didm.oracle.home=${IDM_ORACLE_HOME} -Xms2048m -Xmx2048m -Xss512K -Djava.protocol.handler.pkgs=oracle.mds.net.protocol -Dweblogic.management.discover=false"
export EXTRA_JAVA_PROPERTIES

Keep monitoring wls_ods1.log for Java Heap Space Issue.

applive IDMLIVE /opt/oracle/IDMLIVE_MW_HOME/WebLogic/user_projects/domains/IDMDomain/bin $ diff setDomainEnv.sh.43 setDomainEnv.sh
372c372
< EXTRA_JAVA_PROPERTIES="${EXTRA_JAVA_PROPERTIES} -Didm.oracle.home=${IDM_ORACLE_HOME} -Xms512m -Xmx1024m -Xss512K -Djava.protocol.handler.pkgs=oracle.mds.net.protocol -Dweblogic.management.discover=false"
---
> EXTRA_JAVA_PROPERTIES="${EXTRA_JAVA_PROPERTIES} -Didm.oracle.home=${IDM_ORACLE_HOME} -Xms2048m -Xmx2048m -Xss512K -Djava.protocol.handler.pkgs=oracle.mds.net.protocol -Dweblogic.management.discover=false"
applive IDMLIVE /opt/oracle/IDMLIVE_MW_HOME/WebLogic/user_projects/domains/IDMDomain/bin $

Upgrade OAM 11.1.2.0 to OAM 11.1.2.1

Upgrade OAM 11.1.2.0 to OAM 11.1.2.1

Recently I have upgraded OAM from 11.1.2.0 to 11.1.2.1.. Sharing the steps.. hope would be helpful.....

1. Stop OAM Admin and Managed Server

2. Download OAM R2PS1 from edelivery: https://edelivery.oracle.com/EPD/Download/get_form?egroup_aru_number=15364663. Just get the files V37472-01.zip (Parts 1 and 2 both)

3. Execute runInstaller >>> specify the existing 11.1.2.0 MW_HOME so it goes into upgrade mode. Follow the instruction in GUI.

4. Upgrade OAM Schema and any other products in the domain using PSA.

. $HOME/oamenv.sh
cd $ORACLE_HOME/bin
./psa
Follow the instruction in the GUI.

5. Start OAM Admin Server Only

. $HOME/oamenv.sh
echo $DOMAIN_HOME
nohup $DOMAIN_HOME/bin/startWebLogic.sh -Dweblogic.management.username=weblogic -Dweblogic.management.password=MalayFalsePass > $HOME/oamweblogic.log 2>&1 &

6. Update System Mbean Configuration

. $HOME/oamenv.sh
cd $ORACLE_HOME/common/bin
./wlst.sh

connect()
Please enter your username [weblogic] : weblogic
Please enter your password [welcome1] : MalayFalsePass
Please enter your server URL [t3://localhost:7001] : t3://mkktestserver1.unixdomain.local:7004

patchUpgrade('/opt/oracle/OAMDEV_MW_HOME/WebLogic/Oracle_IDM1')
copyMbeanXmlFiles('/opt/oracle/OAMDEV_MW_HOME/WebLogic/user_projects/domains/OAMDomain','/opt/oracle/OAMDEV_MW_HOME/WebLogic/Oracle_IDM1')

7. Stop OAM Admin Server using WebLogic Console

8. Apply BP01 on top of OAM 11.1.2.1 or the latest available bundle patch.

OAM Bundle Patch Release History (Doc ID 736372.1)

9. Apply OAM Thread/CPU Utilisation Patch 16971881 and other recommended patches.

10. Start OAM Admin and Managed Server

Start the Oracle WebLogic Administration Server for OAM:
. $HOME/oamenv.sh
echo $DOMAIN_HOME
nohup $DOMAIN_HOME/bin/startWebLogic.sh -Dweblogic.management.username=weblogic -Dweblogic.management.password=MalayFalsePass > $HOME/oamweblogic.log 2>&1 &

Start WebLogic Managed Server for OAM:
. $HOME/oamenv.sh
echo $DOMAIN_HOME
nohup $DOMAIN_HOME/bin/startManagedWebLogic.sh oam_server1 http://mkktestserver1.unixdomain.local:7004 \
-Dweblogic.management.username=weblogic -Dweblogic.management.password=MalayFalsePass \
-Dsun.security.krb5.debug=true -Dsun.security.spnego.debug=true -Dweblogic.system.StoreBootIdentity=true > $HOME/oammanaged.log 2>&1 &


How to Determine the Port used for ODSM

How to Determine the Port used for ODSM

Open $MW_HOME/user_projects/domains/IDMDomain/config/config.xml and look for the following content.

    <name>wls_ods1</name>
    <complete-message-timeout>480</complete-message-timeout>
    <idle-connection-timeout>480</idle-connection-timeout>
    <idle-periods-until-timeout>8</idle-periods-until-timeout>
    <dgc-idle-periods-until-timeout>9</dgc-idle-periods-until-timeout>
    <machine>mkktestserver1.unixdomain.local</machine>
    <listen-port>7006</listen-port>

ODSM URL: http://mkktestserver1.unixdomain.local:7706/odsm

Friday, 16 August 2013

Performance tuning on OID - Consolidated Details

Performance tuning on OID - Consolidated Details

OID_Perf_Reco_1: Set DSA config to skip referrals

This is applicable when there are no referrals setup in OID.

By default this capability IS ENABLED and severely impacts performance when large groups (>200K) or large number of nested groups are involved.

Definition: A referral is a special type of entry that when obtained in a search, it contains the location of the actual entry, which could be in another part of the directory tree or even in another ldap server altogether. Unless you have specifically set-up referrals you most likely do not have any.

Confirm, there is no "Referrals" in place in OID:
ldapsearch -h mkkoidserver1 -p XXXX -D "cn=orcladmin" -w "xxxxxxxxxxxxx" -s sub -b "" objectclass=referral

If this doesn't return any rows then, there are no referrals in place.

Set the value of orclskiprefinsql in DSA config, to 1. This would make DSA config to skip referrals.

ldapmodify -h mkkoidserver1 -p XXXX -D cn=orcladmin -w xxxxxxxxxxxxx << eof
dn: cn=dsaconfig,cn=configsets,cn=oracle internet directory
changetype: modify 
replace: orclskiprefinsql 
orclskiprefinsql: 1 
eof



OID_Perf_Reco_2: orclinmemfiltprocess is very expensive on Oracle Database

This attribute can help significantly with the performance of certain types of search operations. It has been identified to be particularly useful with OAM, as some of the searches OAM performs can be especially expensive in the database without the use of "orclinmemfiltprocess".

ldapmodify -h mkkoidserver1 -p XXXX -D "cn=orcladmin" -w "xxxxxxxxxxxxx" -v <EOF 
dn: cn=dsaconfig,cn=configsets,cn=oracle internet directory 
changetype: modify 
replace: orclinmemfiltprocess 
orclinmemfiltprocess:(|(!(obuseraccountcontrol=*))(obuseraccountcontrol=activated)) 
orclinmemfiltprocess:(|(obuseraccountcontrol=activated)(!(obuseraccountcontrol=*))) 
orclinmemfiltprocess:(obapp=groupservcenter)(!(obdynamicparticipantsset=*)) 
orclinmemfiltprocess:(objectclass=oblixworkflowinstance) 
orclinmemfiltprocess:(objectclass=inetorgperson) 
orclinmemfiltprocess:(objectclass=oblixorgperson) 
orclinmemfiltprocess:(objectclass=oblixworkflowstepinstance) 
EOF

For OID 11g it should come as default, cross check and apply, it it applicable for you.

OID_Perf_Reco_3: Run oidstats.sql Regularly as part of daily housekeeping/maintenance

Run oidstats.sql any-time large updates are made to the OID. For large Active Directories, where changes are very frequent, and AD to OID to synchronisation is enabled, this is a very good option to perform on regular basis.

. $HOME/oidenv.sh
cd $MW_HOME/Oracle_IDM1/ldap/admin
sqlplus ods/xxxxxxxxxxxxx@OIDDB
START oidstats.sql;

Remove Dangling DNs: http://mkkoracleapps.blogspot.co.uk/2013/10/remove-dangling-dns-from-oid.html

Sunday, 11 August 2013

Removing Configured WebLogic Server Domain

How to remove a domain from a WebLogic Server Installation... As it is just a domain deployment, no tool is required, just remove the appropriate content as given below.....

Make sure you are keeping a proper backup before performing the steps mentioned below:

1. Remove the domain directory $MW_HOME/user_projects/domains/<Domain_Name>
Here in this example I am removing: eag_domain, so issue the following command,

rm -rf $MW_HOME/user_projects/domains/eag_domain

2. Remove the line for eag_domain from domain-registry.xml file

$ cat domain-registry.xml
<?xml version="1.0" encoding="UTF-8"?>
<domain-registry xmlns="http://xmlns.oracle.com/weblogic/domain-registry">
  <domain location="/opt/oracle/OAMLIVE_MW_HOME/WebLogic/user_projects/domains/OAMDomain"/>
  <domain location="/opt/oracle/OAMLIVE_MW_HOME/WebLogic/user_projects/domains/eag_domain"/>


3. Remove the line for eag_domain from nodemanager.domains

cd $MW_HOME/wlserver_10.3/common/nodemanager

$ cat nodemanager.domains
#Domains and directories created by Configuration Wizard
#Fri Jul 12 11:44:27 BST 2013
eag_domain=/opt/oracle/OAMLIVE_MW_HOME/WebLogic/user_projects/domains/eag_domain
OAMDomain=/opt/oracle/OAMLIVE_MW_HOME/WebLogic/user_projects/domains/OAMDomain

Thursday, 8 August 2013

Using staticports.ini for Oracle HTTP Server during OAM/EBS Integration

Using staticports.ini for Oracle HTTP Server during OAM/EBS Integration

Instead of 7777 of HTTP Server port, we had a requirement for 7778... 

HTTP WebTier Version 11.1.1.6

Create a file staticports.ini before starting the installation, and choose manual port configuration:

[OPMN]
OPMN Local Port = 6706
OPMN Remote Port = 6707

[OHS]
OHS Port = 7778
OHS Proxy Port = 9998
OHS SSL Port = 4444

[WEBCACHE]
Web Cache Listen Port = 7790
Web Cache Admin Port = 7791
Web Cache Statistics Port = 7792
Web Cache Invalidation Port = 7793
Web Cache SSL Port = 7794

appdev WEBTIERDEV /export/home/appdev $ opmnctl status -l

Processes in Instance: instance1
---------------------------------+--------------------+---------+----------+------------+----------+-----------+------
ias-component                    | process-type       |     pid | status   |        uid |  memused |    uptime | ports
---------------------------------+--------------------+---------+----------+------------+----------+-----------+------
webcache1                        | WebCache-admin     |   11620 | Alive    | 1319634190 |    12896 |  90:03:21 | http_admin:7791
webcache1                        | WebCache           |   11619 | Alive    | 1319634189 |    35176 |  90:03:21 | http_stat:7792,http_invalidation:7793,https_listen:7794,http_listen:7790
ohs1                             | OHS                |   11618 | Alive    | 1319634188 |     4680 |  90:03:21 | https:9998,https:4444,http:7778

appdev WEBTIERDEV /export/home/appdev $