Thursday, October 18, 2007
It does not run Oracle
But it is capable of running Linux, and -according to the specsheet- MS Windows XP. I doubt that, with just 256MB on board, but hey - it uses no more than 5 Watts peak, 3 Watts average!
Thursday, October 04, 2007
Tweep-tweep-tweep
Something like that would have been heard, coming from an object, circling the earth, just like an artificial moon.
The space age was born, today, fifty years ago, with the launch of the sputnik.
And it's animal's day, of course.
The space age was born, today, fifty years ago, with the launch of the sputnik.
And it's animal's day, of course.
Tuesday, September 18, 2007
WNA and Firefox
Where IE supports Windows Native Authentication sort of 'Out of the Box', Firefox does not. Here's how to enable Windows Native Authentication (WNA) in forefox:
- type 'about:config' in the address bar
- navigate to the entry 'network.negotiate-auth.trusted-uris' (tip: set the search filter to "network.negotiate"
- enter the domains you want WNA to act upon, e.g. "home.local".
Multiple domains are to be separated by commas; e.g. "home.local,home.networked" - earlier releases indicate that a leading dot is required (e.g. ".home.local" instaed of "home.local")
- type 'about:config' in the address bar
- navigate to the entry 'network.negotiate-auth.trusted-uris' (tip: set the search filter to "network.negotiate"
- enter the domains you want WNA to act upon, e.g. "home.local".
Multiple domains are to be separated by commas; e.g. "home.local,home.networked" - earlier releases indicate that a leading dot is required (e.g. ".home.local" instaed of "home.local")
Wednesday, September 12, 2007
ldapbindssl
Trying to get password synchronisation from Active Directory to Oracle internet Directory (OID) to work. The password filter is a bit hard to find ("CD 1 of the Application Server"), actually it is in de utils directory of this download.
Looks great, upto the part where I try ldapbindssl.
The first attempt resulted in
D:\>ldapbindssl -h idmhost -p 1636 -D cn=orcladmin -w welcome1
Connecting server in SSL Mode
Checking if SSL is enabled
SSL not enabled.
SSL being enabled...
Binding ...
Ldap bindERROR
System Error Code: 997
LDAP Error Code: 52
Error Message: Server Unavailable
I realized, idmhost was not enough, and changed that to the fully qualified name. This changed the error codes returned:
D:\>ldapbindssl -h idmhost.home.local -p 1636 -D cn=orcladmin -w welcome1
Connecting server in SSL Mode
Checking if SSL is enabled
SSL not enabled.
SSL being enabled...
Binding ...
Ldap bindERROR
System Error Code: 1396
LDAP Error Code: 52
Error Message: Server Unavailable
Not very helpful at all. Searching the internet resulted in just one reference.
However, the System Error Codes are actually Microsoft error codes. So, the 1396 error actually means
And - there is a note on that one (and a bug...): Mealink note 430907.1.
Unfortunately, the note just explains you made a mistake in the Subject of your certificate, there is no example of how it should look. Created a new certicificate (self-signed) with the subject cn=idmhost.home.local. Imported that, but now the error is:
D:\>ldapbindssl -h idmhost.home.local -p 1636 -D cn=orcladmin -w welcome1
Connecting server in SSL Mode
Checking if SSL is enabled
SSL not enabled.
SSL being enabled...
Binding ...
Ldap bindERROR
System Error Code: 1790
LDAP Error Code: 52
And error 1790 means ERROR_TRUST_FAILURE (Network logon failed)
Still have to figure that one out...
Edit: Apparently, someone picked this up - just read the note again, and it now says:
Edit: Managed to get things working, this is the condensed how-to:
On the OID server:
- Create the wallet:
orapki wallet create -wallet ./ -auto_login
- Add the request:
orapki wallet add -wallet ./ -dn "cn=idmhost.home.local" -keysize 1024
- you can now export the request, and have it sent to a CA:
orapki wallet export -wallet ./ -dn "cn=idmhost.home.local" -request ./idmhost.req
- or, simply sign the request:
orapki wallet add -wallet ./ -dn "cn=idmhost.home.local" -keysize 1024 -self_signed -validity 3650
- Now, export the self-signed certificate:
orapki wallet export -wallet ./ -dn "cn=idmhost.home.local" -cert ./idmhost.cert
Get this certificate over to the MS Windows machine (I used cut-n-paste, and saved in a cer-file), and use the certificate wizard (click on the .cer file).
After that, the test went OK:
D:\>ldapbindssl -h idmhost.home.local -p 1636 -D cn=orcladmin -w welcome1
Connecting server in SSL Mode
Checking if SSL is enabled
SSL not enabled.
SSL being enabled...
Binding ...
Bind Successful
Looks great, upto the part where I try ldapbindssl.
The first attempt resulted in
D:\>ldapbindssl -h idmhost -p 1636 -D cn=orcladmin -w welcome1
Connecting server in SSL Mode
Checking if SSL is enabled
SSL not enabled.
SSL being enabled...
Binding ...
Ldap bindERROR
System Error Code: 997
LDAP Error Code: 52
Error Message: Server Unavailable
I realized, idmhost was not enough, and changed that to the fully qualified name. This changed the error codes returned:
D:\>ldapbindssl -h idmhost.home.local -p 1636 -D cn=orcladmin -w welcome1
Connecting server in SSL Mode
Checking if SSL is enabled
SSL not enabled.
SSL being enabled...
Binding ...
Ldap bindERROR
System Error Code: 1396
LDAP Error Code: 52
Error Message: Server Unavailable
Not very helpful at all. Searching the internet resulted in just one reference.
However, the System Error Codes are actually Microsoft error codes. So, the 1396 error actually means
ERROR_WRONG_TARGET_NAME (Logon Failure: The target account name is incorrect.)
And - there is a note on that one (and a bug...): Mealink note 430907.1.
Unfortunately, the note just explains you made a mistake in the Subject of your certificate, there is no example of how it should look. Created a new certicificate (self-signed) with the subject cn=idmhost.home.local. Imported that, but now the error is:
D:\>ldapbindssl -h idmhost.home.local -p 1636 -D cn=orcladmin -w welcome1
Connecting server in SSL Mode
Checking if SSL is enabled
SSL not enabled.
SSL being enabled...
Binding ...
Ldap bindERROR
System Error Code: 1790
LDAP Error Code: 52
And error 1790 means ERROR_TRUST_FAILURE (Network logon failed)
Still have to figure that one out...
Edit: Apparently, someone picked this up - just read the note again, and it now says:
For Example, if the OID server hostname is "oid.oracle.com" then the SUBJECT attribute of the server certificate must also be "oid.oracle.com".
Edit: Managed to get things working, this is the condensed how-to:
On the OID server:
- Create the wallet:
orapki wallet create -wallet ./ -auto_login
- Add the request:
orapki wallet add -wallet ./ -dn "cn=idmhost.home.local" -keysize 1024
- you can now export the request, and have it sent to a CA:
orapki wallet export -wallet ./ -dn "cn=idmhost.home.local" -request ./idmhost.req
- or, simply sign the request:
orapki wallet add -wallet ./ -dn "cn=idmhost.home.local" -keysize 1024 -self_signed -validity 3650
- Now, export the self-signed certificate:
orapki wallet export -wallet ./ -dn "cn=idmhost.home.local" -cert ./idmhost.cert
Get this certificate over to the MS Windows machine (I used cut-n-paste, and saved in a cer-file), and use the certificate wizard (click on the .cer file).
After that, the test went OK:
D:\>ldapbindssl -h idmhost.home.local -p 1636 -D cn=orcladmin -w welcome1
Connecting server in SSL Mode
Checking if SSL is enabled
SSL not enabled.
SSL being enabled...
Binding ...
Bind Successful
Thursday, August 30, 2007
Remove a realm
Playing around with OID and Application Server Hosting, I created some realms. Quite easy to add one, but there's no delete, drop or remove realm option.
So: how to drop a realm, without painstakingly going through the ODM (Oracle Directory Manager) screens, that do not support a cascaded delete?
Appears to be quite simple:
login on the machine your OID runs on, and:
opmnctl stopall
./bulkdelete.sh -connect [tns_alias] \
-base "dc=test2,dc=home,dc=local"
The base is the actual realm you want to drop.
So: how to drop a realm, without painstakingly going through the ODM (Oracle Directory Manager) screens, that do not support a cascaded delete?
Appears to be quite simple:
login on the machine your OID runs on, and:
opmnctl stopall
./bulkdelete.sh -connect [tns_alias] \
-base "dc=test2,dc=home,dc=local"
The base is the actual realm you want to drop.
How to unlock orcladmin
Proving the point that using 'cn=orcladmin' or 'orcladmin' when starting Oracle Internet Directory (OID) Manager (ODM), is actually the same account, I managed to "prove" the point just once too often, resulting in a "your account is locked" error.
So, the question raises: how to unlock you superuser account orcladmin?
Very simple:
login on the Application Server where your OID runs, and:
$ORACLE_HOME/bin/oidpasswd connect=[tns_alias] unlock_su_acct=true
You will be asked to provide the ODS password - which happens to be the same as the ias_admin password, specified at install time. Which happens to be the password for orcladmin, too, unless you changed it.
So, the question raises: how to unlock you superuser account orcladmin?
Very simple:
login on the Application Server where your OID runs, and:
$ORACLE_HOME/bin/oidpasswd connect=[tns_alias] unlock_su_acct=true
You will be asked to provide the ODS password - which happens to be the same as the ias_admin password, specified at install time. Which happens to be the password for orcladmin, too, unless you changed it.
Tuesday, August 28, 2007
Passwords: store them in a Wallet!
Working on OID and database registrations, I found the wallet created by the DBCA does not need to be signed. Basically - it's empty!
Well, not quite; although the oracle Wallet Manager, owm, only shows "there's something", details can be retrieved using mkstore:
oracle10@infra mkstore -wrl /oracle/infra/admin/dev/wallet -list
Enter password:
Oracle Secret Store entries:
ORACLE.SECURITY.DN
ORACLE.SECURITY.PASSWORD
oracle10@infra mkstore -wrl /oracle/infra/admin/dev/wallet -viewEntry ORACLE.SECURITY.DN
Enter password:
ORACLE.SECURITY.DN = cn=infra,cn=OracleContext,dc=home,dc=local
oracle10@infra mkstore -wrl /oracle/infra/admin/dev/wallet -viewEntry ORACLE.SECURITY.PASSWORD
Enter password:
ORACLE.SECURITY.PASSWORD = RJT01YL5
oracle10@infra
The password you need to provide, is the password you specified for the wallet at the time you registered the database.
So, if you ever want to know the password of database registration, this is how. Works for 10.2 databases, should work for 10.1 (as 10.1 also knows mkstore), does not work for 9.2 or lower.
Another great option of mkstore (and the reason I found this...) is to store credentials for a database - great for securing database links and batch processes.
More on that in the security manual, here, and an example.
Well, not quite; although the oracle Wallet Manager, owm, only shows "there's something", details can be retrieved using mkstore:
oracle10@infra mkstore -wrl /oracle/infra/admin/dev/wallet -list
Enter password:
Oracle Secret Store entries:
ORACLE.SECURITY.DN
ORACLE.SECURITY.PASSWORD
oracle10@infra mkstore -wrl /oracle/infra/admin/dev/wallet -viewEntry ORACLE.SECURITY.DN
Enter password:
ORACLE.SECURITY.DN = cn=infra,cn=OracleContext,dc=home,dc=local
oracle10@infra mkstore -wrl /oracle/infra/admin/dev/wallet -viewEntry ORACLE.SECURITY.PASSWORD
Enter password:
ORACLE.SECURITY.PASSWORD = RJT01YL5
oracle10@infra
The password you need to provide, is the password you specified for the wallet at the time you registered the database.
So, if you ever want to know the password of database registration, this is how. Works for 10.2 databases, should work for 10.1 (as 10.1 also knows mkstore), does not work for 9.2 or lower.
Another great option of mkstore (and the reason I found this...) is to store credentials for a database - great for securing database links and batch processes.
More on that in the security manual, here, and an example.
Subscribe to:
Posts (Atom)
