Text box
Please note that the problems that i face may not be the same that exist on your environment so please test before applying the same steps i followed to solve the problem .
Wednesday, 8 August 2012
Install oracle grid control agent on Linux X86-64 bit
I will run the installer after modifying the response file as follows:
[oracle@SVCRMDEV01 agent]$ ./runInstaller -silent -responseFile /Oracle/product/stage/agsfw/linux_x64/response/additional_agent.rsp -invPtrLoc /Oracle/product/oraclehomes/oraInst.loc
Starting Oracle Universal Installer...
Checking Temp space: must be greater than 150 MB. Actual 30524 MB Passed
Checking swap space: must be greater than 150 MB. Actual 3867 MB Passed
Preparing to launch Oracle Universal Installer from /Oracle/product/stage/temp/OraInstall2012-08-07_11-04-39AM. Please wait ...[oracle@SVCRMDEV01 agent]$ *** Check for updates ***
*** Select Installation Type ***
*** Check Prerequisites ***
*** Specify Oracle Management Service Location ***
The specified Management Service on host csemp1.bss.etisalat.eg at port 1159 is unreachable. Check the connection details for the Management Service to ensure that you entered the value for the host name correctly
ERROR: Silent Install has failed. Please check the log files for more details.
[oracle@SVCRMDEV01 agent]$ cat /etc/hosts
# Do not remove the following line, or various programs
# that require network functionality will fail.
127.0.0.1 localhost.localdomain localhost
::1 localhost6.localdomain6 localhost6
10.195.90.11 SVCRMDEV01
[oracle@SVCRMDEV01 agent]$ cat /etc/hosts
# Do not remove the following line, or various programs
# that require network functionality will fail.
127.0.0.1 localhost.localdomain localhost
::1 localhost6.localdomain6 localhost6
10.195.90.11 SVCRMDEV01
[oracle@SVCRMDEV01 agent]$ cat /etc/hosts
# Do not remove the following line, or various programs
# that require network functionality will fail.
127.0.0.1 localhost.localdomain localhost
::1 localhost6.localdomain6 localhost6
10.195.90.11 SVCRMDEV01
[oracle@SVCRMDEV01 agent]$ cat /etc/hosts
# Do not remove the following line, or various programs
# that require network functionality will fail.
127.0.0.1 localhost.localdomain localhost
::1 localhost6.localdomain6 localhost6
10.195.90.11 SVCRMDEV01
10.195.2.239 csemp.bss.etisalat.eg csemp
10.195.2.72 csemp1.bss.etisalat.eg csemp1
[oracle@SVCRMDEV01 agent]$ ./runInstaller -silent -responseFile /Oracle/product/stage/agsfw/linux_x64/response/additional_agent.rsp -invPtrLoc /Oracle/product/oraclehomes/oraInst.loc
Starting Oracle Universal Installer...
Checking Temp space: must be greater than 150 MB. Actual 30318 MB Passed
Checking swap space: must be greater than 150 MB. Actual 5008 MB Passed
Preparing to launch Oracle Universal Installer from /Oracle/product/stage/temp/OraInstall2012-08-08_01-26-03PM. Please wait ...[oracle@SVCRMDEV01 agent]$ *** Check for updates ***
*** Select Installation Type ***
*** Check Prerequisites ***
*** Specify Oracle Management Service Location ***
*** Customize Ports ***
*** Review ***
-----------------------------------------------------------------------------
Summary
Global Settings
Source: /Oracle/product/stage/agsfw/linux_x64/agent//stage/../stage/products.xml
Oracle Home: /Oracle/product/agent11g (agent11g1)
Installation Type: Complete
Product Languages
English
Space Requirements
/Oracle/ Required 1.07GB (includes 34MB temporary) : Available 29.40GB
New Installations (58 products)
Oracle Management Agent 11.1.0.1.0
Agent Virtualization 11.1.0.1.0
Enterprise Manager Agent 11.1.0.1.0
Enterprise Manager Agent Core Files 11.1.0.1.0
Secure Socket Layer 11.1.0.7.0
Oracle Recovery Manager 11.1.0.7.0
Enterprise Manager Common Files 11.1.0.1.0
Enterprise Manager Common Core Files 11.1.0.1.0
Required Support Files 11.1.0.7.0
Oracle RAC Required Support Files-HAS 11.1.0.7.0
Oracle JDBC/THIN Interfaces 11.1.0.7.0
Oracle JDBC/OCI Instant Client 11.1.0.7.0
Oracle Globalization Support 11.1.0.7.0
Oracle Net Required Support Files 11.1.0.7.0
SSL Required Support Files for InstantClient 11.1.0.7.0
LDAP Required Support Files 11.1.0.7.0
Oracle Globalization Support 11.1.0.7.0
Perl Interpreter 5.10.0.0.1
Perl Modules 5.10.0.0.1
Expat libraries 2.0.1.0.1
XML Parser for Java 11.1.0.7.0
Precompiler Required Support Files 11.1.0.7.0
RDBMS Required Support Files 11.1.0.7.0
RDBMS Required Support Files for Instant Client 11.1.0.7.0
Parser Generator Required Support Files 11.1.0.7.0
Platform Required Support Files 11.1.0.7.0a
Patch for Oracle Process Management Notification 10.1.3.4.0
Oracle Process Management Notification 10.1.3.0.0
Agent Required Support Files 10.2.0.4.1
XDK Required Support Files 11.1.0.7.0
SQL*Plus Required Support Files 11.1.0.7.0
Secure Socket Layer 11.1.0.7.0
Oracle Core Required Support Files 11.1.0.7.0
Enterprise Manager Agent for Grid Control 11.1.0.1.0
Installation Common Files 11.1.0.7.0
Oracle Configuration Manager 10.3.2.1.0
Oracle Bali Share 11.1.1.2.0
Enterprise Manager Application Server Integrator Plugin -- Agent Support 11.1.0.2.0
Oracle Dynamic Monitoring Service Patch 10.1.2.3.0
Oracle Dynamic Monitoring Service 10.1.2.1.0
Enterprise Manager Application Server Plugin -- Agent Support 11.1.0.1.0
Enterprise Manager Application Server Plugin -- Common Support 11.1.0.1.0
Enterprise Manager Database Plugin -- Agent Support 11.1.0.1.0
Enterprise Manager Siebel Plugin -- Agent Support 11.1.0.1.0
Provisioning Advisor Framework Common Files For Agent and OMS 11.1.0.1.0
Common component for Virtualization 11.1.0.1.0
Oracle Notification Service (eONS) 11.2.0.1.0
Enterprise Manager Collaboration Suite Plugin -- Agent Support 11.1.0.1.0
Oracle Notification Service 10.1.3.0.0
Oracle Required Support Files 32 bit 11.1.0.7.0
OracleAS HTTP Client 11.1.1.2.0
OracleAS J2EE BULKOPS 11.0.0.0.0
Oracle Wallet Manager 11.1.0.7.0
Oracle Security Developer Tools 11.1.0.7.0
Oracle Universal Installer 11.1.0.8.0
Oracle One-Off Patch Installer 11.1.0.8.0
Installer SDK Component 11.1.0.8.0
Sun JDK 1.6.0.14.0
-----------------------------------------------------------------------------
Installation in progress
.................................................................Installation in progress
..................
Install successful
Linking in progress
Link successful
Setup in progress
.......
Setup successful
Warning: The following configuration scripts needs to be executed as the "root" user
/Oracle/product/agent11g/root.sh
To execute the configuration scripts:
1. Open a new terminal window
2. Login in as "root"
3. Run the scripts
Running Configuration assistant "Agent Oneoff Patch Application"
The ORACLE HOME is /Oracle/product/agent11gThe install isLocal is trueThe command is opatch apply -invPtrLoc /Oracle/product/agent11g/oraInst.loc -silent -local
Unjarring the oneoff 5336126.zip ...
/Oracle/product/agent11g/jdk/bin/jar xvf /Oracle/product/agent11g/install/oneoffs/111010/5336126.zip
created: 5336126/
created: 5336126/files/
created: 5336126/files/lib/
created: 5336126/files/lib/dms.jar/
created: 5336126/files/lib/dms.jar/oracle/
created: 5336126/files/lib/dms.jar/oracle/core/
created: 5336126/files/lib/dms.jar/oracle/core/ojdl/
inflated: 5336126/files/lib/dms.jar/oracle/core/ojdl/LogMessage$InstanceId.class
inflated: 5336126/files/lib/dms.jar/oracle/core/ojdl/LogMessage$MessageArgument.class
inflated: 5336126/files/lib/dms.jar/oracle/core/ojdl/LogMessage.class
inflated: 5336126/files/lib/dms.jar/oracle/core/ojdl/MessageType.class
created: 5336126/files/diagnostics/
created: 5336126/files/diagnostics/lib/
created: 5336126/files/diagnostics/lib/ojdl.jar/
created: 5336126/files/diagnostics/lib/ojdl.jar/oracle/
created: 5336126/files/diagnostics/lib/ojdl.jar/oracle/core/
created: 5336126/files/diagnostics/lib/ojdl.jar/oracle/core/ojdl/
inflated: 5336126/files/diagnostics/lib/ojdl.jar/oracle/core/ojdl/LogMessage$InstanceId.class
inflated: 5336126/files/diagnostics/lib/ojdl.jar/oracle/core/ojdl/LogMessage$MessageArgument.class
inflated: 5336126/files/diagnostics/lib/ojdl.jar/oracle/core/ojdl/LogMessage.class
inflated: 5336126/files/diagnostics/lib/ojdl.jar/oracle/core/ojdl/MessageType.class
inflated: 5336126/files/diagnostics/lib/ojdl.jar/oracle/core/ojdl/ODL11Formatter.class
created: 5336126/files/diagnostics/lib/ojdl.jar/oracle/core/ojdl/reader/
inflated: 5336126/files/diagnostics/lib/ojdl.jar/oracle/core/ojdl/reader/AccessLogReader.class
inflated: 5336126/files/diagnostics/lib/ojdl.jar/oracle/core/ojdl/reader/BaseTextLogReader.class
inflated: 5336126/files/diagnostics/lib/ojdl.jar/oracle/core/ojdl/reader/BufferedLogFileReader.class
inflated: 5336126/files/diagnostics/lib/ojdl.jar/oracle/core/ojdl/reader/BusStopLogReader.class
inflated: 5336126/files/diagnostics/lib/ojdl.jar/oracle/core/ojdl/reader/EOFParseException.class
inflated: 5336126/files/diagnostics/lib/ojdl.jar/oracle/core/ojdl/reader/FileSet.class
inflated: 5336126/files/diagnostics/lib/ojdl.jar/oracle/core/ojdl/reader/FileSetLogReader.class
inflated: 5336126/files/diagnostics/lib/ojdl.jar/oracle/core/ojdl/reader/LogContentHandler.class
inflated: 5336126/files/diagnostics/lib/ojdl.jar/oracle/core/ojdl/reader/LogFileReader.class
inflated: 5336126/files/diagnostics/lib/ojdl.jar/oracle/core/ojdl/reader/LogParser.class
inflated: 5336126/files/diagnostics/lib/ojdl.jar/oracle/core/ojdl/reader/LogReaderConstants.class
inflated: 5336126/files/diagnostics/lib/ojdl.jar/oracle/core/ojdl/reader/LogRecordImpl.class
inflated: 5336126/files/diagnostics/lib/ojdl.jar/oracle/core/ojdl/reader/MessageFormatFileSet.class
inflated: 5336126/files/diagnostics/lib/ojdl.jar/oracle/core/ojdl/reader/ODLTextLogReader.class
inflated: 5336126/files/diagnostics/lib/ojdl.jar/oracle/core/ojdl/reader/ODLTextLogReaderFactory.class
inflated: 5336126/files/diagnostics/lib/ojdl.jar/oracle/core/ojdl/reader/SAXParserDriver.class
inflated: 5336126/files/diagnostics/lib/ojdl.jar/oracle/core/ojdl/reader/SimpleTextLogReader.class
inflated: 5336126/files/diagnostics/lib/ojdl.jar/oracle/core/ojdl/reader/TextLogReader.class
inflated: 5336126/files/diagnostics/lib/ojdl.jar/oracle/core/ojdl/reader/UnformattedTextLogReader.class
inflated: 5336126/files/diagnostics/lib/ojdl.jar/oracle/core/ojdl/reader/WebCacheLogReader.class
inflated: 5336126/files/diagnostics/lib/ojdl.jar/oracle/core/ojdl/reader/XMLParser$CharBuf.class
inflated: 5336126/files/diagnostics/lib/ojdl.jar/oracle/core/ojdl/reader/XMLParser.class
inflated: 5336126/files/diagnostics/lib/ojdl.jar/oracle/core/ojdl/reader/oraclelog.dtd
created: 5336126/etc/
created: 5336126/etc/config/
inflated: 5336126/etc/config/inventory
inflated: 5336126/etc/config/actions
created: 5336126/etc/xml/
inflated: 5336126/etc/xml/GenericActions.xml
inflated: 5336126/etc/xml/ShiphomeDirectoryStructure.xml
inflated: 5336126/README.txt
Applying opatch for the oneoff 5336126 ...
/Oracle/product/agent11g/OPatch/opatch apply -invPtrLoc /Oracle/product/agent11g/oraInst.loc -silent -local -oh /Oracle/product/agent11g /Oracle/product/agent11g/install/oneoffs/111010/5336126
Invoking OPatch 11.1.0.8.0
Oracle Interim Patch Installer version 11.1.0.8.0
Copyright (c) 2009, Oracle Corporation. All rights reserved.
Oracle Home : /Oracle/product/agent11g
Central Inventory : /Oracle/product/oraclehomes/oraInventory
from : /Oracle/product/agent11g/oraInst.loc
OPatch version : 11.1.0.8.0
OUI version : 11.1.0.8.0
OUI location : /Oracle/product/agent11g/oui
Log file location : /Oracle/product/agent11g/cfgtoollogs/opatch/opatch2012-08-08_13-27-00PM.log
Patch history file: /Oracle/product/agent11g/cfgtoollogs/opatch/opatch_history.txt
ApplySession applying interim patch '5336126' to OH '/Oracle/product/agent11g'
Running prerequisite checks...
You selected -local option, hence OPatch will patch the local system only.
Backing up files and inventory (not for auto-rollback) for the Oracle Home
Backing up files affected by the patch '5336126' for restore. This might take a while...
Backing up files affected by the patch '5336126' for rollback. This might take a while...
Patching component oracle.dms, 10.1.2.3.0...
Updating jar file "/Oracle/product/agent11g/lib/dms.jar" with "/lib/dms.jar/oracle/core/ojdl/LogMessage$InstanceId.class"
Updating jar file "/Oracle/product/agent11g/lib/dms.jar" with "/lib/dms.jar/oracle/core/ojdl/LogMessage$MessageArgument.class"
Updating jar file "/Oracle/product/agent11g/lib/dms.jar" with "/lib/dms.jar/oracle/core/ojdl/LogMessage.class"
Updating jar file "/Oracle/product/agent11g/lib/dms.jar" with "/lib/dms.jar/oracle/core/ojdl/MessageType.class"
Updating jar file "/Oracle/product/agent11g/diagnostics/lib/ojdl.jar" with "/diagnostics/lib/ojdl.jar/oracle/core/ojdl/LogMessage$InstanceId.class"
Updating jar file "/Oracle/product/agent11g/diagnostics/lib/ojdl.jar" with "/diagnostics/lib/ojdl.jar/oracle/core/ojdl/LogMessage$MessageArgument.class"
Updating jar file "/Oracle/product/agent11g/diagnostics/lib/ojdl.jar" with "/diagnostics/lib/ojdl.jar/oracle/core/ojdl/LogMessage.class"
Updating jar file "/Oracle/product/agent11g/diagnostics/lib/ojdl.jar" with "/diagnostics/lib/ojdl.jar/oracle/core/ojdl/MessageType.class"
Updating jar file "/Oracle/product/agent11g/diagnostics/lib/ojdl.jar" with "/diagnostics/lib/ojdl.jar/oracle/core/ojdl/ODL11Formatter.class"
Updating jar file "/Oracle/product/agent11g/diagnostics/lib/ojdl.jar" with "/diagnostics/lib/ojdl.jar/oracle/core/ojdl/reader/AccessLogReader.class"
Updating jar file "/Oracle/product/agent11g/diagnostics/lib/ojdl.jar" with "/diagnostics/lib/ojdl.jar/oracle/core/ojdl/reader/BaseTextLogReader.class"
Updating jar file "/Oracle/product/agent11g/diagnostics/lib/ojdl.jar" with "/diagnostics/lib/ojdl.jar/oracle/core/ojdl/reader/BufferedLogFileReader.class"
Updating jar file "/Oracle/product/agent11g/diagnostics/lib/ojdl.jar" with "/diagnostics/lib/ojdl.jar/oracle/core/ojdl/reader/BusStopLogReader.class"
Updating jar file "/Oracle/product/agent11g/diagnostics/lib/ojdl.jar" with "/diagnostics/lib/ojdl.jar/oracle/core/ojdl/reader/EOFParseException.class"
Updating jar file "/Oracle/product/agent11g/diagnostics/lib/ojdl.jar" with "/diagnostics/lib/ojdl.jar/oracle/core/ojdl/reader/FileSet.class"
Updating jar file "/Oracle/product/agent11g/diagnostics/lib/ojdl.jar" with "/diagnostics/lib/ojdl.jar/oracle/core/ojdl/reader/FileSetLogReader.class"
Updating jar file "/Oracle/product/agent11g/diagnostics/lib/ojdl.jar" with "/diagnostics/lib/ojdl.jar/oracle/core/ojdl/reader/LogContentHandler.class"
Updating jar file "/Oracle/product/agent11g/diagnostics/lib/ojdl.jar" with "/diagnostics/lib/ojdl.jar/oracle/core/ojdl/reader/LogFileReader.class"
Updating jar file "/Oracle/product/agent11g/diagnostics/lib/ojdl.jar" with "/diagnostics/lib/ojdl.jar/oracle/core/ojdl/reader/LogParser.class"
Updating jar file "/Oracle/product/agent11g/diagnostics/lib/ojdl.jar" with "/diagnostics/lib/ojdl.jar/oracle/core/ojdl/reader/LogReaderConstants.class"
Updating jar file "/Oracle/product/agent11g/diagnostics/lib/ojdl.jar" with "/diagnostics/lib/ojdl.jar/oracle/core/ojdl/reader/LogRecordImpl.class"
Updating jar file "/Oracle/product/agent11g/diagnostics/lib/ojdl.jar" with "/diagnostics/lib/ojdl.jar/oracle/core/ojdl/reader/MessageFormatFileSet.class"
Updating jar file "/Oracle/product/agent11g/diagnostics/lib/ojdl.jar" with "/diagnostics/lib/ojdl.jar/oracle/core/ojdl/reader/ODLTextLogReader.class"
Updating jar file "/Oracle/product/agent11g/diagnostics/lib/ojdl.jar" with "/diagnostics/lib/ojdl.jar/oracle/core/ojdl/reader/ODLTextLogReaderFactory.class"
Updating jar file "/Oracle/product/agent11g/diagnostics/lib/ojdl.jar" with "/diagnostics/lib/ojdl.jar/oracle/core/ojdl/reader/SAXParserDriver.class"
Updating jar file "/Oracle/product/agent11g/diagnostics/lib/ojdl.jar" with "/diagnostics/lib/ojdl.jar/oracle/core/ojdl/reader/SimpleTextLogReader.class"
Updating jar file "/Oracle/product/agent11g/diagnostics/lib/ojdl.jar" with "/diagnostics/lib/ojdl.jar/oracle/core/ojdl/reader/TextLogReader.class"
Updating jar file "/Oracle/product/agent11g/diagnostics/lib/ojdl.jar" with "/diagnostics/lib/ojdl.jar/oracle/core/ojdl/reader/UnformattedTextLogReader.class"
Updating jar file "/Oracle/product/agent11g/diagnostics/lib/ojdl.jar" with "/diagnostics/lib/ojdl.jar/oracle/core/ojdl/reader/WebCacheLogReader.class"
Updating jar file "/Oracle/product/agent11g/diagnostics/lib/ojdl.jar" with "/diagnostics/lib/ojdl.jar/oracle/core/ojdl/reader/XMLParser$CharBuf.class"
Updating jar file "/Oracle/product/agent11g/diagnostics/lib/ojdl.jar" with "/diagnostics/lib/ojdl.jar/oracle/core/ojdl/reader/XMLParser.class"
Updating jar file "/Oracle/product/agent11g/diagnostics/lib/ojdl.jar" with "/diagnostics/lib/ojdl.jar/oracle/core/ojdl/reader/oraclelog.dtd"
ApplySession adding interim patch '5336126' to inventory
Verifying the update...
Inventory check OK: Patch ID 5336126 is registered in Oracle Home inventory with proper meta-data.
Files check OK: Files from Patch ID 5336126 are present in Oracle Home.
OPatch succeeded.
Unjarring the oneoff 7568506.zip ...
/Oracle/product/agent11g/jdk/bin/jar xvf /Oracle/product/agent11g/install/oneoffs/111010/7568506.zip
created: 7568506/
created: 7568506/files/
created: 7568506/files/lib/
created: 7568506/files/lib/dms.jar/
created: 7568506/files/lib/dms.jar/oracle/
created: 7568506/files/lib/dms.jar/oracle/dms/
created: 7568506/files/lib/dms.jar/oracle/dms/address/
inflated: 7568506/files/lib/dms.jar/oracle/dms/address/Optic.class
created: 7568506/files/lib/dms.jar/oracle/dms/collector/
inflated: 7568506/files/lib/dms.jar/oracle/dms/collector/Ajp13Connector.class
created: 7568506/etc/
created: 7568506/etc/config/
inflated: 7568506/etc/config/inventory
inflated: 7568506/etc/config/actions
created: 7568506/etc/xml/
inflated: 7568506/etc/xml/GenericActions.xml
inflated: 7568506/etc/xml/ShiphomeDirectoryStructure.xml
inflated: 7568506/README.txt
Applying opatch for the oneoff 7568506 ...
/Oracle/product/agent11g/OPatch/opatch apply -invPtrLoc /Oracle/product/agent11g/oraInst.loc -silent -local -oh /Oracle/product/agent11g /Oracle/product/agent11g/install/oneoffs/111010/7568506
Invoking OPatch 11.1.0.8.0
Oracle Interim Patch Installer version 11.1.0.8.0
Copyright (c) 2009, Oracle Corporation. All rights reserved.
Oracle Home : /Oracle/product/agent11g
Central Inventory : /Oracle/product/oraclehomes/oraInventory
from : /Oracle/product/agent11g/oraInst.loc
OPatch version : 11.1.0.8.0
OUI version : 11.1.0.8.0
OUI location : /Oracle/product/agent11g/oui
Log file location : /Oracle/product/agent11g/cfgtoollogs/opatch/opatch2012-08-08_13-27-04PM.log
Patch history file: /Oracle/product/agent11g/cfgtoollogs/opatch/opatch_history.txt
ApplySession applying interim patch '7568506' to OH '/Oracle/product/agent11g'
Running prerequisite checks...
You selected -local option, hence OPatch will patch the local system only.
Please shutdown Oracle instances running out of this ORACLE_HOME on the local system.
(Oracle Home = '/Oracle/product/agent11g')
Is the local system ready for patching? [y|n]
Y (auto-answered by -silent)
User Responded with: Y
Backing up files and inventory (not for auto-rollback) for the Oracle Home
Backing up files affected by the patch '7568506' for restore. This might take a while...
Backing up files affected by the patch '7568506' for rollback. This might take a while...
Patching component oracle.dms, 10.1.2.3.0...
Updating jar file "/Oracle/product/agent11g/lib/dms.jar" with "/lib/dms.jar/oracle/dms/address/Optic.class"
Updating jar file "/Oracle/product/agent11g/lib/dms.jar" with "/lib/dms.jar/oracle/dms/collector/Ajp13Connector.class"
ApplySession adding interim patch '7568506' to inventory
Verifying the update...
Inventory check OK: Patch ID 7568506 is registered in Oracle Home inventory with proper meta-data.
Files check OK: Files from Patch ID 7568506 are present in Oracle Home.
The local system has been patched and can be restarted.
OPatch succeeded.
Unjarring the oneoff 8685010.zip ...
/Oracle/product/agent11g/jdk/bin/jar xvf /Oracle/product/agent11g/install/oneoffs/111010/8685010.zip
y created: 8685010/
created: 8685010/files/
created: 8685010/files/opmn/
created: 8685010/files/opmn/lib/
created: 8685010/files/opmn/lib/optic.jar/
created: 8685010/files/opmn/lib/optic.jar/oracle/
created: 8685010/files/opmn/lib/optic.jar/oracle/ias/
created: 8685010/files/opmn/lib/optic.jar/oracle/ias/opmn/
created: 8685010/files/opmn/lib/optic.jar/oracle/ias/opmn/optic/
inflated: 8685010/files/opmn/lib/optic.jar/oracle/ias/opmn/optic/OpmnPhone.class
created: 8685010/etc/
created: 8685010/etc/config/
inflated: 8685010/etc/config/inventory
inflated: 8685010/etc/config/actions
created: 8685010/etc/xml/
inflated: 8685010/etc/xml/GenericActions.xml
inflated: 8685010/etc/xml/ShiphomeDirectoryStructure.xml
inflated: 8685010/README.txt
Applying opatch for the oneoff 8685010 ...
/Oracle/product/agent11g/OPatch/opatch apply -invPtrLoc /Oracle/product/agent11g/oraInst.loc -silent -local -oh /Oracle/product/agent11g /Oracle/product/agent11g/install/oneoffs/111010/8685010
Invoking OPatch 11.1.0.8.0
Oracle Interim Patch Installer version 11.1.0.8.0
Copyright (c) 2009, Oracle Corporation. All rights reserved.
Oracle Home : /Oracle/product/agent11g
Central Inventory : /Oracle/product/oraclehomes/oraInventory
from : /Oracle/product/agent11g/oraInst.loc
OPatch version : 11.1.0.8.0
OUI version : 11.1.0.8.0
OUI location : /Oracle/product/agent11g/oui
Log file location : /Oracle/product/agent11g/cfgtoollogs/opatch/opatch2012-08-08_13-27-11PM.log
Patch history file: /Oracle/product/agent11g/cfgtoollogs/opatch/opatch_history.txt
ApplySession applying interim patch '8685010' to OH '/Oracle/product/agent11g'
Running prerequisite checks...
You selected -local option, hence OPatch will patch the local system only.
Backing up files and inventory (not for auto-rollback) for the Oracle Home
Backing up files affected by the patch '8685010' for restore. This might take a while...
Backing up files affected by the patch '8685010' for rollback. This might take a while...
Patching component oracle.opmn, 10.1.3.4.0...
Updating jar file "/Oracle/product/agent11g/opmn/lib/optic.jar" with "/opmn/lib/optic.jar/oracle/ias/opmn/optic/OpmnPhone.class"
ApplySession adding interim patch '8685010' to inventory
Verifying the update...
Inventory check OK: Patch ID 8685010 is registered in Oracle Home inventory with proper meta-data.
Files check OK: Files from Patch ID 8685010 are present in Oracle Home.
OPatch succeeded.
Unjarring the oneoff 8240469.zip ...
/Oracle/product/agent11g/jdk/bin/jar xvf /Oracle/product/agent11g/install/oneoffs/111010/8240469.zip
created: 8240469/
created: 8240469/files/
created: 8240469/files/lib/
created: 8240469/files/lib/libclient11.a/
inflated: 8240469/files/lib/libclient11.a/kpuds.o
inflated: 8240469/files/lib/libclient11.a/kpudst.o
created: 8240469/files/lib32/
created: 8240469/files/lib32/libclient11.a/
inflated: 8240469/files/lib32/libclient11.a/kpuds.o
inflated: 8240469/files/lib32/libclient11.a/kpudst.o
created: 8240469/etc/
created: 8240469/etc/config/
inflated: 8240469/etc/config/inventory.xml
inflated: 8240469/etc/config/actions.xml
created: 8240469/etc/xml/
inflated: 8240469/etc/xml/GenericActions.xml
inflated: 8240469/etc/xml/ShiphomeDirectoryStructure.xml
inflated: 8240469/README.txt
Applying opatch for the oneoff 8240469 ...
/Oracle/product/agent11g/OPatch/opatch apply -invPtrLoc /Oracle/product/agent11g/oraInst.loc -silent -local -oh /Oracle/product/agent11g /Oracle/product/agent11g/install/oneoffs/111010/8240469
Invoking OPatch 11.1.0.8.0
Oracle Interim Patch Installer version 11.1.0.8.0
Copyright (c) 2009, Oracle Corporation. All rights reserved.
Oracle Home : /Oracle/product/agent11g
Central Inventory : /Oracle/product/oraclehomes/oraInventory
from : /Oracle/product/agent11g/oraInst.loc
OPatch version : 11.1.0.8.0
OUI version : 11.1.0.8.0
OUI location : /Oracle/product/agent11g/oui
Log file location : /Oracle/product/agent11g/cfgtoollogs/opatch/opatch2012-08-08_13-27-14PM.log
Patch history file: /Oracle/product/agent11g/cfgtoollogs/opatch/opatch_history.txt
ApplySession applying interim patch '8240469' to OH '/Oracle/product/agent11g'
Running prerequisite checks...
Patch 8240469: Optional component(s) missing : [ oracle.rdbms, 11.1.0.7.0 ] , [ oracle.rdbms.util, 11.1.0.7.0 ]
You selected -local option, hence OPatch will patch the local system only.
Please shutdown Oracle instances running out of this ORACLE_HOME on the local system.
(Oracle Home = '/Oracle/product/agent11g')
Is the local system ready for patching? [y|n]
Y (auto-answered by -silent)
User Responded with: Y
Backing up files and inventory (not for auto-rollback) for the Oracle Home
Backing up files affected by the patch '8240469' for restore. This might take a while...
yBacking up files affected by the patch '8240469' for rollback. This might take a while...
Patching component oracle.rdbms.rman, 11.1.0.7.0...
Patching component oracle.rdbms.rsf, 11.1.0.7.0...
Updating archive file "/Oracle/product/agent11g/lib/libclient11.a" with "lib/libclient11.a/kpuds.o"
Updating archive file "/Oracle/product/agent11g/lib/libclient11.a" with "lib/libclient11.a/kpudst.o"
Patching component oracle.rsf.hybrid, 11.1.0.7.0...
Updating archive file "/Oracle/product/agent11g/lib32/libclient11.a" with "lib32/libclient11.a/kpuds.o"
Updating archive file "/Oracle/product/agent11g/lib32/libclient11.a" with "lib32/libclient11.a/kpudst.o"
Running make for target irman
Running make for target client_sharedlib
ApplySession adding interim patch '8240469' to inventory
Verifying the update...
Inventory check OK: Patch ID 8240469 is registered in Oracle Home inventory with proper meta-data.
Files check OK: Files from Patch ID 8240469 are present in Oracle Home.
The local system has been patched and can be restarted.
OPatch succeeded.
Unjarring the oneoff 9676134.zip ...
/Oracle/product/agent11g/jdk/bin/jar xvf /Oracle/product/agent11g/install/oneoffs/111010/9676134.zip
created: 9676134/
created: 9676134/files/
created: 9676134/files/sysman/
created: 9676134/files/sysman/admin/
created: 9676134/files/sysman/admin/default_collection/
inflated: 9676134/files/sysman/admin/default_collection/database.xmlp
created: 9676134/files/sysman/admin/metadata/
inflated: 9676134/files/sysman/admin/metadata/oracle_database.xml
inflated: 9676134/files/sysman/admin/metadata/rac_database.xml
inflated: 9676134/README.txt
created: 9676134/etc/
created: 9676134/etc/xml/
inflated: 9676134/etc/xml/ShiphomeDirectoryStructure.xml
inflated: 9676134/etc/xml/GenericActions.xml
created: 9676134/etc/config/
inflated: 9676134/etc/config/actions.xml
inflated: 9676134/etc/config/inventory.xml
inflated: 9676134/etc/config/deploy.xml
Applying opatch for the oneoff 9676134 ...
/Oracle/product/agent11g/OPatch/opatch apply -invPtrLoc /Oracle/product/agent11g/oraInst.loc -silent -local -oh /Oracle/product/agent11g /Oracle/product/agent11g/install/oneoffs/111010/9676134
Invoking OPatch 11.1.0.8.0
Oracle Interim Patch Installer version 11.1.0.8.0
Copyright (c) 2009, Oracle Corporation. All rights reserved.
Oracle Home : /Oracle/product/agent11g
Central Inventory : /Oracle/product/oraclehomes/oraInventory
from : /Oracle/product/agent11g/oraInst.loc
OPatch version : 11.1.0.8.0
OUI version : 11.1.0.8.0
OUI location : /Oracle/product/agent11g/oui
Log file location : /Oracle/product/agent11g/cfgtoollogs/opatch/opatch2012-08-08_13-27-24PM.log
Patch history file: /Oracle/product/agent11g/cfgtoollogs/opatch/opatch_history.txt
ApplySession applying interim patch '9676134' to OH '/Oracle/product/agent11g'
Running prerequisite checks...
You selected -local option, hence OPatch will patch the local system only.
Backing up files and inventory (not for auto-rollback) for the Oracle Home
Backing up files affected by the patch '9676134' for restore. This might take a while...
Backing up files affected by the patch '9676134' for rollback. This might take a while...
Patching component oracle.sysman.top.agent, 11.1.0.1.0...
Copying file to "/Oracle/product/agent11g/sysman/admin/default_collection/database.xmlp"
Copying file to "/Oracle/product/agent11g/sysman/admin/metadata/oracle_database.xml"
Copying file to "/Oracle/product/agent11g/sysman/admin/metadata/rac_database.xml"
ApplySession adding interim patch '9676134' to inventory
Configuration assistant "Agent Oneoff Patch Application" Succeeded
Verifying the update...
Inventory check OK: Patch ID 9676134 is registered in Oracle Home inventory with proper meta-data.
Files check OK: Files from Patch ID 9676134 are present in Oracle Home.
OPatch succeeded.
Finished one-offs apply...
Deleting the files...
Finished deleting the above files...
Running Configuration assistant "Agent Configuration Assistant"
Performing free port detection on host=SVCRMDEV01
Securing the agent
Performing targets discovery and agent configuration
Starting the agent
Configuration assistant "Agent Configuration Assistant" Succeeded
AgentPlugIn:agent configuration finished with status = true
Running Configuration assistant "Agent Add-on Plug-in"
Configuration assistant "Agent Add-on Plug-in" Succeeded
Thursday, 5 July 2012
Sizing the Shared Pool
Resizing the shared pool
To size the shared pool we have only one parameter available to influence the library
cache size.The parameter name is "SHARED_POOL_SIZE".this parameter sizes the shared pool and then The dictionary cache takes some portion of the shared pool as determined by an internal algorithm.The calculations that have been used by the internal algorithm to determine the size of the shared pool
are based on many estimates about which objects were cached, the number of concurrent users,
and concurrent open cursors. These estimates can lead to wildly different values.
Oracle Support recommends using Automatic Shared Memory Management (ASMM). This is
enabled by setting the SGA_TARGET parameter to the value that the entire SGA will use. The
Memory Manager (MMAN) process adjusts the memory allocated to dynamic pools to obtain
the best performance within the memory allowed.
When the database is already in operation, the Shared Pool Advisor gives an indication of an
estimated optimal size. As with any estimate, check other indicators such as latch waits, hard
parses, and reloads for confirmation.
When there is no baseline, set the SHARED_POOL_SIZE to approximately 40% of the
available SGA.We can change this value after monitoring the performance and determine if we need more memory or decreasing the memory
The shared pool requires a certain amount of memory to even allow the instance to start. This
value varies with the packages that are invoked at startup, and that depends on the features and
options that are enabled. Enterprise Manager will invoke certain packages as soon as it starts.
Shared Pool Advisory
The STATISTICS_LEVEL initialization parameter controls the shared pool advisory. The
shared pool advisory statistics track the library cache’s use of shared pool memory and predict
the change in total instance-wide parse times for different sizes of the shared pool.
The below 2 views help you determine how much memory the library cache is using and how much does the library cache needs?.
SQL> select * from V$LIBRARY_CACHE_MEMORY;
LC_NAMESPACE LC_INUSE_MEMORY_OBJECTS LC_INUSE_MEMORY_SIZE LC_FREEABLE_MEMORY_OBJECTS LC_FREEABLE_MEMORY_SIZE
--------------- ----------------------- -------------------- -------------------------- -----------------------
BODY 0 0 34 2
CLUSTER 0 0 0 0
INDEX 0 0 0 0
JAVA DATA 0 0 0 0
JAVA RESOURCE 0 0 0 0
JAVA SOURCE 0 0 0 0
OBJECT 0 0 0 0
OTHER/SYSTEM 0 0 0 0
PIPE 0 0 0 0
SQL AREA 208 3 231 4
TABLE/PROCEDURE 0 0 391 3
TRIGGER 0 0 0 0
12 rows selected.
The V$LIBRARY_CACHE_MEMORY view displays information about memory allocated to
library cache memory objects in different namespaces. A memory object is an internal grouping
of memory for efficient management. A library cache object may consist of one or more
memory objects.
V$LIBRARY_CACHE_MEMORY, provide information to help
you determine how much memory the library cache is using, how much is currently pinned, how
much is on the shared pool’s LRU list, and how much time might be lost or gained by changing
the size of the shared pool. These statistics are reset if the STATISTICS_LEVEL parameter is
set to BASIC, or when the instance is restarted.
In order to estimate how much memory does the library cache needs?.
SQL> SELECT shared_pool_size_for_estimate AS
pool_size, estd_lc_size,
estd_lc_time_saved
FROM V$SHARED_POOL_ADVICE;
POOL_SIZE ESTD_LC_SIZE ESTD_LC_TIME_SAVED
---------- ------------ ------------------
132 8 86003
148 24 87333
164 40 88893
180 56 89500
196 72 90087
212 88 90518
228 104 90742
244 120 90911
260 136 91032
276 152 91118
10 rows selected.
The V$SHARED_POOL_ADVICE view should be the first tool to use when sizing the shared
pool. If the advisory indicates that a larger pool is not useful for the library cache memory
objects, you can drill down to see whether changing the SQL (to improve use of shared cursors)
or other activity (such as deferring DDL to off hours) improves performance.
The V$SHARED_POOL_ADVICE view displays information about the estimated time saved
during parsing using different shared pool sizes. The sizes range from 50% to 200%, in equal
intervals of the current shared pool size, and are not configurable. If rows in the
V$SHARED_POOL_ADVICE view have the same values of parse time savings (given in the
ESTD_LC_TIME_SAVED column), this indicates that there would be no additional hits on
those size ranges for library cache objects. However, if time saving values increase for larger
pool sizes, this indicates that it may help to increase the shared pool size.
The Statspack/AWR reports also present the shared pool advisory.
To size the shared pool we have only one parameter available to influence the library
cache size.The parameter name is "SHARED_POOL_SIZE".this parameter sizes the shared pool and then The dictionary cache takes some portion of the shared pool as determined by an internal algorithm.The calculations that have been used by the internal algorithm to determine the size of the shared pool
are based on many estimates about which objects were cached, the number of concurrent users,
and concurrent open cursors. These estimates can lead to wildly different values.
Oracle Support recommends using Automatic Shared Memory Management (ASMM). This is
enabled by setting the SGA_TARGET parameter to the value that the entire SGA will use. The
Memory Manager (MMAN) process adjusts the memory allocated to dynamic pools to obtain
the best performance within the memory allowed.
When the database is already in operation, the Shared Pool Advisor gives an indication of an
estimated optimal size. As with any estimate, check other indicators such as latch waits, hard
parses, and reloads for confirmation.
When there is no baseline, set the SHARED_POOL_SIZE to approximately 40% of the
available SGA.We can change this value after monitoring the performance and determine if we need more memory or decreasing the memory
The shared pool requires a certain amount of memory to even allow the instance to start. This
value varies with the packages that are invoked at startup, and that depends on the features and
options that are enabled. Enterprise Manager will invoke certain packages as soon as it starts.
Shared Pool Advisory
The STATISTICS_LEVEL initialization parameter controls the shared pool advisory. The
shared pool advisory statistics track the library cache’s use of shared pool memory and predict
the change in total instance-wide parse times for different sizes of the shared pool.
The below 2 views help you determine how much memory the library cache is using and how much does the library cache needs?.
SQL> select * from V$LIBRARY_CACHE_MEMORY;
LC_NAMESPACE LC_INUSE_MEMORY_OBJECTS LC_INUSE_MEMORY_SIZE LC_FREEABLE_MEMORY_OBJECTS LC_FREEABLE_MEMORY_SIZE
--------------- ----------------------- -------------------- -------------------------- -----------------------
BODY 0 0 34 2
CLUSTER 0 0 0 0
INDEX 0 0 0 0
JAVA DATA 0 0 0 0
JAVA RESOURCE 0 0 0 0
JAVA SOURCE 0 0 0 0
OBJECT 0 0 0 0
OTHER/SYSTEM 0 0 0 0
PIPE 0 0 0 0
SQL AREA 208 3 231 4
TABLE/PROCEDURE 0 0 391 3
TRIGGER 0 0 0 0
12 rows selected.
The V$LIBRARY_CACHE_MEMORY view displays information about memory allocated to
library cache memory objects in different namespaces. A memory object is an internal grouping
of memory for efficient management. A library cache object may consist of one or more
memory objects.
V$LIBRARY_CACHE_MEMORY, provide information to help
you determine how much memory the library cache is using, how much is currently pinned, how
much is on the shared pool’s LRU list, and how much time might be lost or gained by changing
the size of the shared pool. These statistics are reset if the STATISTICS_LEVEL parameter is
set to BASIC, or when the instance is restarted.
In order to estimate how much memory does the library cache needs?.
SQL> SELECT shared_pool_size_for_estimate AS
pool_size, estd_lc_size,
estd_lc_time_saved
FROM V$SHARED_POOL_ADVICE;
POOL_SIZE ESTD_LC_SIZE ESTD_LC_TIME_SAVED
---------- ------------ ------------------
132 8 86003
148 24 87333
164 40 88893
180 56 89500
196 72 90087
212 88 90518
228 104 90742
244 120 90911
260 136 91032
276 152 91118
10 rows selected.
The V$SHARED_POOL_ADVICE view should be the first tool to use when sizing the shared
pool. If the advisory indicates that a larger pool is not useful for the library cache memory
objects, you can drill down to see whether changing the SQL (to improve use of shared cursors)
or other activity (such as deferring DDL to off hours) improves performance.
The V$SHARED_POOL_ADVICE view displays information about the estimated time saved
during parsing using different shared pool sizes. The sizes range from 50% to 200%, in equal
intervals of the current shared pool size, and are not configurable. If rows in the
V$SHARED_POOL_ADVICE view have the same values of parse time savings (given in the
ESTD_LC_TIME_SAVED column), this indicates that there would be no additional hits on
those size ranges for library cache objects. However, if time saving values increase for larger
pool sizes, this indicates that it may help to increase the shared pool size.
The Statspack/AWR reports also present the shared pool advisory.
Tuesday, 3 July 2012
Attach and de-attach oracle home
To de-attach an oracle home:
To attach an oracle home:
Where node1 is the actual hostname.
/app/home/oracle/produInstaller -silent -attachHome -local -noClusterEnabled -invPtrLoc /app/home/oracle/oraInventory/oraInst.loc -ignorePreReq ORACLE_HOME=/app/home/oracle/product/agent10g ORACLE_HOME_NAME=agent1025g CLUSTER_NODES=node1Starting Oracle Universal Installer...Checking Temp space: must be greater than 150 MB. Actual 510 MB PassedChecking swap space: must be greater than 150 MB. Actual 120262 MB PassedPreparing to launch Oracle Universal Installer from /tmp/OraInstall2012-07-03_03-17-58PM. Please wait ...oracle@bscsstage01:/app/home/oracle/product/stage/solaris/agent [bscsdb1] >The inventory pointer is located at /app/home/oracle/oraInventory/oraInst.locThe inventory is located at /app/home/oracle/oraInventory'AttachHome' was successful.
To attach an oracle home:
/app/home/oracle/produInstaller -silent -attachHome -local -noClusterEnabled -invPtrLoc /app/home/oracle/oraInventory/oraInst.loc -ignorePreReq ORACLE_HOME=/app/home/oracle/product/agent10g ORACLE_HOME_NAME=agent1025g CLUSTER_NODES=node1
Where node1 is the actual hostname.
Thursday, 7 June 2012
Setting up Network ACLs in Oracle 11gr SMTP server
From Oracle 11g network packages like UTL_TCP, UTL_SMTP, UTL_MAIL, UTL_HTTP, and UTL_INADDR which can be used to access external network resources, are more restricted and secured. Oracle 11g introduced Fine-Grained Access to these packages by creating an Access Control List to use any external network resource through these packages. Before this any user who had an execute privilege on these packages was able to do anything to any network resource like web and local mail servers etc. But now a user needs a little more then just an execute privilege on the network packages.
Lets talk about using ACL in oracle 11g:
References:
http://www.oracleflash.com/36/Oracle-11g-Access-Control-List-for-External-Network-Services.html
http://oracledbajourney.blogspot.com/2012/09/ora-24247-network-access-denied-by.html
Lets talk about using ACL in oracle 11g:
$ sqlplus / as sysdba Connected to: Oracle Database 11g Enterprise Edition Release 11.2.0.1.0 - Production With the Partitioning, OLAP, Data Mining and Real Application Testing options select grantee , table_name , privilege from dba_tab_privs where table_name = 'UTL_HTTP' and grantee = 'PUBLIC'; GRANTEE TABLE_NAME PRIVILEGE ---------- -------------- ------------- PUBLIC UTL_HTTP EXECUTE -- By default access on UTL_HTTP is granted to PUBLIC. -- Revoke from public and grant to specific user who needs it. revoke execute on utl_http from public; grant execute on utl_http to scott; select grantee , table_name , privilege from dba_tab_privs where table_name = 'UTL_HTTP' and grantee in ('PUBLIC','SCOTT') GRANTEE TABLE_NAME PRIVILEGE ---------- -------------- ------------- SCOTT UTL_HTTP EXECUTE -- Now only SCOTT has execute rights on UTL_HTTP. SQL> conn scott/tiger Connected. create or replace procedure getTitle(pUrl VARCHAR2) is vResult CLOB; begin vResult := replace(UTL_HTTP.REQUEST(pUrl),chr(10),' '); vResult := regexp_replace(vResult,'.*.*','\1',1,1,'i'); dbms_output.put_line(vResult); end; / SQL> set serveroutput on SQL> execute getTitle('http://www.oracleflash.com'); BEGIN getTitle('http://www.oracleflash.com'); END; * ERROR at line 1: ORA-29273: HTTP request failed ORA-06512: at "SYS.UTL_HTTP", line 1722 ORA-24247: network access denied by access control list (ACL) ORA-06512: at "SCOTT.GETTITLE", line 5 ORA-06512: at line 1
As you may see that even in the presence of EXECUTE privilege, SCOTT is not able to access the web page using UTL_HTTP and has encountered an error "network access denied by access control list (ACL)". This literally means that the user is being denied access by the Access Control List.
How to configure Access Control List
We need to configure an Access Control List (ACL) and grant "connect" privilege on that ACL to user SCOTT. Then we need to assign host "www.oracleflash.com" to this ACL and any other host to which user SCOTT needs access.DBMS_NETWORK_ACL_ADMIN.CREATE_ACL()
creates a new Access Control List. Following are the parameters that it takes.acl
=> Name of the Access Control List. This is a XML file which will be created in /sys/acls directory by default.Description
=> Description of the ACL.Principal
=> Name of the user or role (case sensitive) to whom the permissions are being granted or denied.is_grant
=> TRUE or FALSE, whether to grant access or deny access.privilege
=> connect or resolve (lowercase always). Will the user be able to connect to the network resource or just could resolve the network address.start_date
=> Start date (optional) of the access to the user.end_date
=> End date (optional) of the access to the user.SQL> conn / as sysdba Connected. BEGIN DBMS_NETWORK_ACL_ADMIN.CREATE_ACL ( acl => 'oracleflash.xml', description => 'Permissions to access http://www.oracleflash.com', principal => 'SCOTT', is_grant => TRUE, privilege => 'connect'); COMMIT; END; / PL/SQL procedure successfully completed.
Add a privilege to Access Control List
First access to the ACL to any user is granted when the ACL is created with the CREATE_ACL procedure. If any other user or role needs permission on the ACL you may user the procedure ADD_PRIVILEGE.DBMS_NETWORK_ACL_ADMIN.ADD_PRIVILEGE()
Add access for more users or roles in an already existing ACL. It takes similar parameters as CREATE_ACL procedure except there is no description parameter and a new parameter position which is used in ADD_PRIVILEGE but not in CREATE_ACL.The position parameter decides the precedence of the rights for multiple users. For example we grant access to a role ORACLEFLASH at position 1, grant this role to user HR and deny access to user HR at position 2 in ACL. The user HR will still be able to use the network resource because he is granted access via role ORACLEFLASH which takes precedence in the ACL. When granting access to multiple roles and user set the precedence appropriately.create role oracleflash; -- A role is created. Now we grant connect to this role on our ACL. BEGIN DBMS_NETWORK_ACL_ADMIN.ADD_PRIVILEGE ( acl => 'oracleflash.xml', principal => 'ORACLEFLASH', is_grant => TRUE, privilege => 'connect', position => null); COMMIT; END; / PL/SQL procedure successfully completed.So far we have created an ACL and have granted connect access to user SCOTT and role ORACLEFLASH on this ACL. Now is the time to assign network hosts that this ACL can be used to access. In our case the host is "www.oracleflash.com".Assign a network host to Access Control List
DBMS_NETWORK_ACL_ADMIN.ASSIGN_ACL()
assigns a network host local or remote to an ACL. It takes the following parameters:acl
=> Name of the Access Control List.host
=> Name of the host.lower_port
=> Lower port (optional) from the range of ports allowed on this host.upper_port
=> Upper port (optional) from the range of ports allowed on this hostDefault for lower and upper port is null, which means all ports can be used on this host. And if you provide a port in lower_port and null in upper_port oracle assumes the upper_port=lower_port.BEGIN DBMS_NETWORK_ACL_ADMIN.ASSIGN_ACL ( acl => 'oracleflash.xml', host => '*.oracleflash.com'); COMMIT; END; / PL/SQL procedure successfully completed. BEGIN DBMS_NETWORK_ACL_ADMIN.ASSIGN_ACL ( acl => 'oracleflash.xml', host => '*.oracle.com'); COMMIT; END; / PL/SQL procedure successfully completed.NOTE: you may assign multiple hosts to one ACL, but you can't assign one host to multiple ACLs. If you do that then the previous assignment will be removed and new will become in effect.Host Assignments:
Host assignment can be done in many ways. For example if you assign a host to an ACL like www.oracleflash.com, the users can only access www.oracleflash.com. But if you assign a host like *.oracleflash.com, the users can assign any sub-domain on the oracleflash.com. And *.com will grant access to the whole web using .com domains. You need to be careful with this as you may be granting access to more servers then you should.DBMS_NETWORK_ACL_UTILITY.DOMAINS()
package contains functions to help determine possible matching domains. The DOMAINS table function returns all possible references against a host, that may be specified in ASSIGN_ACL procedure, in order of precedence.SQL> SELECT * FROM TABLE(DBMS_NETWORK_ACL_UTILITY.DOMAINS('www.oracleflash.com')); COLUMN_VALUE ------------------------------------ www.oracleflash.com *.oracleflash.com *.com * SQL> SELECT * FROM TABLE(DBMS_NETWORK_ACL_UTILITY.DOMAINS('192.168.0.132')); COLUMN_VALUE ------------------------------------ 192.168.0.132 192.168.0.* 192.168.* 192.* *The precedence here means that if you have assigned all these hosts to the ACLs then which host entry will take precedence on others. The above query returns results in order of precedence.We can verify the ACL's host assignment and privileges via two dictionary views, DBA_NETWORK_ACLS and DBA_NETWORK_ACL_PRIVILEGES.column acl format a30 column host format a20 column principal format a20 column privilege format a10 column is_grant format a8 set lines 1000 select acl , host , lower_port , upper_port from DBA_NETWORK_ACLS; ACL HOST LOWER_PORT UPPER_PORT ------------------------------ -------------------- ---------- ---------- /sys/acls/oracleflash.xml *.oracleflash.com /sys/acls/oracleflash.xml *.oracle.com select acl , principal , privilege , is_grant from DBA_NETWORK_ACL_PRIVILEGES; ACL PRINCIPAL PRIVILEGE IS_GRANT ------------------------------ -------------------- ---------- -------- /sys/acls/oracleflash.xml SCOTT connect true /sys/acls/oracleflash.xml ORACLEFLASH connect trueLets now see if the access is enabled or not.SQL> conn scott/tiger Connected. SQL> set serveroutput on SQL> execute getTitle('http://www.oracleflash.com'); OracleFlash.com: Oracle Articles, Tutorials, Step by Step Install Guides, Scripts. PL/SQL procedure successfully completed. SQL> execute getTitle('http://download.oracle.com/docs/cd/B28359_01/network.111/b28531/authorization.htm'); Configuring Privilege and Role Authorization PL/SQL procedure successfully completed.The user SCOTT is able to access both the oracleflash.com and oracle.com hosts. Lets see how the ACL grant to a role works.SQL> conn / as sysdba Connected. SQL> grant execute on utl_http to hr; Grant succeeded. SQL> conn hr/hr Connected. SQL> select substr(utl_http.request('http://www.oracleflash.com'),1,30) from dual; select substr(utl_http.request('http://www.oracleflash.com'),1,30) from dual * ERROR at line 1: ORA-29273: HTTP request failed ORA-06512: at "SYS.UTL_HTTP", line 1722 ORA-24247: network access denied by access control list (ACL) ORA-06512: at line 1Even after granting the EXECUTE privilege on UTL_HTTP to user HR, it is not able to access the host www.oracleflash.com. This is because the user HR has no access on the ACL we created for oracleflash.com. Now we will grant the role ORACLEFLASH to user HR, which has access on the ACL for oracleflash.com and see what happens.SQL> conn / as sysdba Connected. SQL> grant oracleflash to hr; Grant succeeded. SQL> conn hr/hr Connected. SQL> select substr(utl_http.request('http://www.oracleflash.com'),1,112) oracleflash 2 from dual; ORACLEFLASH -----------------------------------------------------------------------------------------This time the HR can access the web page as it has the role ORACLEFLASH, which has access on the ACL.Cleaning Up the Access Control List
Remove a host from Access Control List
Following procedure can be used to remove a host from the ACL.SQL> select acl , host , lower_port , upper_port from DBA_NETWORK_ACLS; ACL HOST LOWER_PORT UPPER_PORT ------------------------------ -------------------- ---------- ---------- /sys/acls/oracleflash.xml *.oracleflash.com /sys/acls/oracleflash.xml *.oracle.com BEGIN DBMS_NETWORK_ACL_ADMIN.unassign_acl ( acl => 'oracleflash.xml', host => '*.oracle.com'); COMMIT; END; / PL/SQL procedure successfully completed. SQL> select acl , host , lower_port , upper_port from DBA_NETWORK_ACLS; ACL HOST LOWER_PORT UPPER_PORT ------------------------------ -------------------- ---------- ---------- /sys/acls/oracleflash.xml *.oracleflash.comDelete a privilege from Access Control List
Following procedure can be used to delete a privilege from the ACL.SQL> select acl , principal , privilege , is_grant from DBA_NETWORK_ACL_PRIVILEGES; ACL PRINCIPAL PRIVILEGE IS_GRANT ------------------------------ -------------------- ---------- -------- /sys/acls/oracleflash.xml SCOTT connect true /sys/acls/oracleflash.xml ORACLEFLASH connect true BEGIN DBMS_NETWORK_ACL_ADMIN.delete_privilege ( acl => 'oracleflash.xml', principal => 'ORACLEFLASH', is_grant => TRUE, privilege => 'connect'); COMMIT; END; / PL/SQL procedure successfully completed. SQL> select acl , principal , privilege , is_grant from DBA_NETWORK_ACL_PRIVILEGES; ACL PRINCIPAL PRIVILEGE IS_GRANT ------------------------------ -------------------- ---------- -------- /sys/acls/oracleflash.xml SCOTT connect trueDrop an Access Control List
Following procedure can be used to drop the ACL.SQL> select acl , host , lower_port , upper_port from DBA_NETWORK_ACLS; ACL HOST LOWER_PORT UPPER_PORT ------------------------------ -------------------- ---------- ---------- /sys/acls/oracleflash.xml *.oracleflash.com BEGIN DBMS_NETWORK_ACL_ADMIN.DROP_ACL ( acl => 'oracleflash.xml'); COMMIT; END; / PL/SQL procedure successfully completed. SQL> select acl , host , lower_port , upper_port from DBA_NETWORK_ACLS; no rows selected
Creating ACL for SMTP server:
BEGINDBMS_NETWORK_ACL_ADMIN.UNASSIGN_ACL (acl => 'mailserver_acl.xml',host => 'CAINCCHX01.EG01.yahoo.net',lower_port => 25,upper_port => 25);END;/COMMIT;
BEGIN DBMS_NETWORK_ACL_ADMIN.drop_acl('mailserver_acl.xml'); END; / commit;
BEGINDBMS_NETWORK_ACL_ADMIN.create_acl(acl => 'mailserver_acl.xml',description => 'ACL that lets me talk to the my email server',principal => 'PPM_USER',is_grant => TRUE,privilege => 'connect');/
DBMS_NETWORK_ACL_ADMIN.assign_acl(acl => 'mailserver_acl.xml',HOST => 'CAINCCHX01.EG01.Yahoo.net',lower_port => 25,upper_port => 25);COMMIT;END;/
References:
http://www.oracleflash.com/36/Oracle-11g-Access-Control-List-for-External-Network-Services.html
http://oracledbajourney.blogspot.com/2012/09/ora-24247-network-access-denied-by.html
Subscribe to:
Posts (Atom)