Posts

Showing posts with the label 12c

APEX, SERT, and EPG

APEX, SERT, and EPG Application Express, Security Evaluation and Recommendation Tool, and the Embedded PL/SQL Gateway My organisation has only just started seriously working with APEX and have recently launched our first internal production app (that was a challenge... I was told that this app needed to be in production in 2 days and nobody had bothered to check with me what was needed to make this happen).  I've learned a lot about APEX in the past few weeks and I've got a lot more to go. I recently came across SERT ( https://github.com/OraOpenSource/apex-sert ) and it sounds like a really nifty tool.  Today I found some time to try it out and see if our dev team might find it useful.  I decided to install it in our dev database.  This uses the EPG rather than ORDS. The install didn't go so well.  The first install failed near the end because I think I used a lowercase 'y' for a response somewhere and it got confused, bombing out with an ORA-06502...

Logon triggers

I've wanted to do this for a long time, but now a migration project to both a new data centre, and a new version of Oracle means I have opportunity to do it and hopefully, do it right. The current database design is not perfect.  There is one application user which is used by apps, users, support and development teams.  At the moment, there is no way to separate traffic, prevent connections from people to the wrong place or from unexpected places, or to do resource limiting.  I can't do any sensible auditing. This changes as of the migration to 12c.  I have defined 7 different services, which will all have different sets of expected users.  After logon triggers will be set up so that all connections to the controlled services have the connection source IP and database username checked.  If either isn't appropriate for the service, the connection attempt is logged and the connection terminated. CREATE OR REPLACE TRIGGER SYSTEM.check_service_appropriate...

OEM12C & wsm-pm

I find OEM incredibly hard to work with.  Not while it's running as it's actually a nice product from a user perspective, but keeping it working always seems like a huge hassle. This is partly because my knowledge of Weblogic is minimal, and partly because the documentation doesn't really explain where one thing starts and the other ends.  When I'm configuring something, am I configuring Weblogic, or am I configuring OEM?  It's not always clear. So, we come to today's issue. The target:  /EMGC_GCDomain/GCDomain/EMGC_ADMINSERVER/wsm-pm  was showing as down after a restart of the OMS.  I tried starting it from within OEM, which complained because it's not possible to control Weblogic through OEM, which makes sense. I logged in to the Weblogic console, and navigated to GCDomain->Deployments, located wsm-pm in the list, went to the Targets tab and EMGC_AdminServer wasn't in the list of targets!  Sounds like a s imple fix, then.  Click Lo...

OEM Cloud Control 12c: Discovering new Oracle Homes

A thing that I repeatedly forget is how to do this.  I'm writing it down in the vague hope that I'll remember next time. Take running database, already monitored by OEM 12c.  Install new version of Oracle Home using OUI.  Try to use OEM 12c to upgrade database, but find that OEM doesn't know about the new home. How do you add the new home?  "Add target" menu doesn't work.  Where is it? Instructions are here:  https://docs.oracle.com/cd/E24628_01/doc.121/e24473/discovery.htm#EMADM13141 The secret is to create a new job, of the "Discover Promote Oracle Home Target" type.  Add in the path to the Oracle Home, let the job run, and voila.  Your new Oracle Home is now available.