Why I need older version of Chrome browser? The latest is the best, right ?
Starting from version 45 the NPAPI is permanently disabled, and as a result I cannot use Chrome to launch the Oracle Form anymore.
Here I show you how to download previous version of Chrome browser, from the OFFICIAL source, not from randomly file download sites which probably contain virus and showing pictures not good in the office.
The key word is -- CHROMIUM, not CHROME
(1) Goto Wiki page http://en.wikipedia.org/wiki/Google_Chrome_release_history to find out which version or platform you want to download. Find out the BUILD number, e.g. for version 41 it should be 41.0.2272. Look for the latest build for this version from here. Build 41.0.2272.76 is the last stable build for version 41. If you don't know, just add "dot zero", i.e. 41.0.2272.0
(2) Goto Google Chromium Version Tracking page https://omahaproxy.appspot.com to find out the branch base position of the version you need. Put your build version into the "Position Lookup" box, and it will give you the "Base Position" number. For build 41.0.2272.76, the number is 310958.
(3) Goto Chromium Continuous Build Storage page http://commondatastorage.googleapis.com/chromium-browser-continuous/index.html
Select Platform, and search (or use Filter at the top) the Position Number you obtained from (2).
(4) Download the mini_installer.exe. This is the one you need.
To launch Oracle Form for Oracle EBS 11i or R12, you need a free extension called "User-Agent Switcher", offered by www.esolutions.se. When you need to launch a Form, simply switch the User Agent to "Safari on Mac", and it should able to solve the infamous "Registry.dat file not found" issue.
Finally, why use Chromium? Because it does not force you to update to latest version. Even you are able to download previous version of Chrome Browser, after installation has done it will automatically upgrade itself to the latest version. And it is so hard to disable the update, just like a very persistent virus that no simple way to get rid of.
Showing posts with label EBS. Show all posts
Showing posts with label EBS. Show all posts
Thursday, November 12, 2015
Wednesday, July 29, 2015
Using GoDaddy Certificate to Sign Your Oracle EBS Jar Files
GoDaddy provide the cheapest Jar-signing certificate that they also give different bargain / discount off the shelf price actively ( I get their discount spam mail everyday). However if you ask their support about how to do the jar signing, they are absolute clueless. Okay. That's why their price is low.
Here are the steps of signing the jar files:
(1) Download KeyStore Explorer (KSE), install, and make sure it runs well. You will use this excellent software throughout the steps
(2) Before creating you private key, check the $APPL_TOP/admin/adsign.txt file. It should look like
[sid]_[hostname] 1 CUST
Use KSE to open the $APPL_TOP/admin/adkeystore.dat. The keystore password is "puneet". This is the default keystore password used by Oracle. Every time you open/modify this keystore file, you need this password to continue.
Here are the steps of signing the jar files:
(1) Download KeyStore Explorer (KSE), install, and make sure it runs well. You will use this excellent software throughout the steps
(2) Before creating you private key, check the $APPL_TOP/admin/adsign.txt file. It should look like
[sid]_[hostname] 1 CUST
Use KSE to open the $APPL_TOP/admin/adkeystore.dat. The keystore password is "puneet". This is the default keystore password used by Oracle. Every time you open/modify this keystore file, you need this password to continue.
(3) Generate the private key pair
Oracle told you the command is "adjkey -initialize -keysize
2048 -alias mycompany"
But you can run this instead:
keytool -keystore adkeystore.dat -genkey -alias mycompany -keyalg RSA -keysize 2048
- You're supposed to use your company name for mycompany. Use lower case characters for alias name.
- Use "myxuan" for certificate password. Oracle uses this default password for certificates.
Enter keystore password: puneet
What is your first and last name?
[Unknown]:
What is the name of your organizational unit?
[Unknown]: Happy Valley
What is the name of your organization?
[Unknown]: Happy Valley
What is the name of your City or Locality?
[Unknown]: Toronto
What is the name of your State or Province?
[Unknown]: Ontario
What is the two-letter country code for this unit?
[Unknown]: CA
Is CN=Unknown, OU=Happy Valley, O=Happy Valley, L=Toronto, ST=Ontario, C=CA correct?
[no]: Yes
Enter key password for myxuan
(RETURN if same as keystore password):
Re-enter new password: myxuan
Use KSE to open the adkeystore.dat file, you will see the new entry you just created:
(3) Generate CSR
keytool -sigalg
SHA256withRSA -certreq -keystore adkeystore.dat -file mycompany.csr -alias mycompany
Enter keystore password: puneet
Enter key password for myxuan
A new file mycompany.csr is created. You can use KSE to open up this CSR file to see the details.
(4) Paid money to GoDaddy (through web site, or you can call / email their salesrep, if you have corporate account or you need quotation / paper work / invoice / bargain / discount etc). Finally they will give you a ZIP file. It contains one file with SPC extension.
(5) Add signed certificate to keystore
keytool -keystore adkeystore.dat -import -trustcacerts -alias mycompany -file godaddy.spc
Enter keystore password: puneet
Enter key password for myxuan
Certificate reply was installed in keystore
Use KSE to open adkeystore.dat again. This time you will see the signed certificate and it's chain:
(6) Optional: In KSE, delete the default private key with alias [SID]_[hostname]. Change the alias name of the GoDaddy-signed certificate if needed.
(7) Put this alias name (mycompany or whatever you have) to adsign.txt
mycompany 1 CUST
(8) Run adadmin to force regenerate all jar file.
(9) Bounce Apache and Form Servers. BINGO.
Tuesday, April 7, 2015
How to Enable PL/SQL gateway (MOD_PLSQL) in Oracle EBS R12.2
Oracle disabled mod_plsql support by default in EBS R12.1, and much to my surprise that Oracle still put mod_plsql stuff in EBS 12.2. Again it is not enabled by default, but making it work is not a difficult task at all.
All the changes mentioned below is in fs1, but it could be fs2 depends on which one is your running instance.
(1) Stop or start the Apache by adapachl.sh script. No need to stop the Weblogic since this functionality is provided by Apache Mod.
(2) Identify the running oracle_apache.conf file under directory
$IAS_ORACLE_HOME/instances/EBS_web_[SID]_OHS1/config/OHS/EBS_web_[SID]
Add a line at the end of this file:
include ${ORACLE_INSTANCE}/config/${COMPONENT_TYPE}/${COMPONENT_NAME}/plsql.conf
The variables specified in config file will be resolved during runtime. So no need to put the actual path in there.
(3) The file plsql.conf mentioned in this line is not exist (under the same directory of oracle_apache_conf just modified). Make a copy of this file from directory
$ORACLE_HOME/Apache/modplsql/conf
Modify the lines similar as follows:
#Window
LoadModule plsql_module "${ORACLE_HOME}/ohs/modules/mod_plsql.dll"
#Linux/Unix
LoadModule plsql_module "${ORACLE_HOME}/ohs/modules/modplsql.so"
# Turn on logging for debug only!!
PlsqlLogEnable on
PlsqlLogDirectory ${ORACLE_INSTANCE}/diagnostics/logs/${COMPONENT_TYPE}/${COMPONENT_NAME}
<Location /pls/[SID] >
All the changes mentioned below is in fs1, but it could be fs2 depends on which one is your running instance.
(1) Stop or start the Apache by adapachl.sh script. No need to stop the Weblogic since this functionality is provided by Apache Mod.
(2) Identify the running oracle_apache.conf file under directory
$IAS_ORACLE_HOME/instances/EBS_web_[SID]_OHS1/config/OHS/EBS_web_[SID]
Add a line at the end of this file:
include ${ORACLE_INSTANCE}/config/${COMPONENT_TYPE}/${COMPONENT_NAME}/plsql.conf
The variables specified in config file will be resolved during runtime. So no need to put the actual path in there.
(3) The file plsql.conf mentioned in this line is not exist (under the same directory of oracle_apache_conf just modified). Make a copy of this file from directory
$ORACLE_HOME/Apache/modplsql/conf
Modify the lines similar as follows:
#Window
LoadModule plsql_module "${ORACLE_HOME}/ohs/modules/mod_plsql.dll"
#Linux/Unix
LoadModule plsql_module "${ORACLE_HOME}/ohs/modules/modplsql.so"
# Turn on logging for debug only!!
PlsqlLogEnable on
PlsqlLogDirectory ${ORACLE_INSTANCE}/diagnostics/logs/${COMPONENT_TYPE}/${COMPONENT_NAME}
include "${ORACLE_INSTANCE}/config/${COMPONENT_TYPE}/${COMPONENT_NAME}/mod_plsql/dads.conf"
include "${ORACLE_INSTANCE}/config/${COMPONENT_TYPE}/${COMPONENT_NAME}/mod_plsql/cache.conf"
(4) The file dads.conf does exist but the content is empty. So add the mod_plsql location for your instance
<Location /pls/[SID] >
SetHandler pls_handler
Order deny,allow
Allow from all
AllowOverride None
PlsqlDatabaseUsername apps
PlsqlDatabasePassword apps
PlsqlDatabaseConnectString localhost:1521:[SID] ServiceNameFormat
PlsqlAuthenticationMode Basic
PlsqlNLSLanguage AMERICAN_AMERICA.AL32UTF8
PlsqlRequestValidationFunction XX_MOD_PLSQL_CHECK
PlsqlErrorStyle DebugStyle
<Location >
(5) The rest of the setup will be identical to R12.1
http://symplik.blogspot.com/2013/10/how-to-enable-plsql-gateway-in-r12.html
http://symplik.blogspot.com/2013/10/how-to-enable-plsql-gateway-in-r12.html
Tuesday, December 9, 2014
How to Enable PL/SQL gateway (MOD_PLSQL) in Oracle EBS R12.1
If your company is planning to upgrade you 11i instance to R12.1, then please be aware that the PL/SQL gateway (mod_plsql) is no longer available by default in R12.1. However, it doesn't mean that it cannot be activated again. Oracle highly recommends you use other programs to replace it by APEX, OA Framework, or ADF, but if your company has invested huge amount of time and effect in PL/SQL gateway code, and the code is working very well, then you could keep the code and let it run, similar in 11i environment.
Here are the steps:
Create the following directories:
$INST_TOP/ora/10.1.3/Apache/modplsql/cache
$INST_TOP/ora/10.1.3/Apache/modplsql/conf
$INST_TOP/ora/10.1.3/Apache/modplsql/logs
Create file $INST_TOP/ora/10.1.3/Apache/modplsql/conf/plsql.conf, with content similar the following. Substitute the environment variables and values in [] for your environment.
# load required module (Windows)
LoadModule plsql_module %IAS_ORACLE_HOME%/bin/modplsql.dll
# load required module (*nix)
LoadModule plsql_module $IAS_ORACLE_HOME/Apache/modplsql/bin/modplsql.so
#Directives specify for modplsql
PlsqlLogEnable on
PlsqlLogDirectory $INST_TOP/ora/10.1.3/Apache/modplsql/logs
PlsqlCacheEnable On
PlsqlCacheDirectory $INST_TOP/ora/10.1.3/Apache/modplsql/cache
PlsqlCacheTotalSize 20971520
PlsqlCacheMaxSize 1048576
PlsqlCacheMaxAge 30
PlsqlCacheCleanupTime Everyday 00:00
<Location /pls/[SID] >
SetHandler pls_handler
Order deny,allow
Allow from all
AllowOverride None
PlsqlDatabaseUsername apps
PlsqlDatabasePassword @BSvYt+H8Fv3C4YjspMEOP9k=
PlsqlDatabaseConnectString [DB Server]:[Port]:[SID] ServiceNameFormat
PlsqlAuthenticationMode Basic
PlsqlNLSLanguage AMERICAN_AMERICA.AL32UTF8
PlsqlRequestValidationFunction XX_MOD_PLSQL_CHECK
PlsqlErrorStyle DebugStyle
</Location>
You can use $IAS_ORACLE_HOME/Apache/modplsql/conf/dadobf to generate the obfuscated password.
Syntax: dadobf [password]
For other possible parameters, you can check out this link
http://docs.oracle.com/cd/E23943_01/web.1111/e10144/under_mods.htm
Open $INST_TOP/ora/10.1.3/Apache/Apache/conf/oracle_apache.conf, search and take out the comment of this line:
include "$INST_TOP/ora/10.1.3/Apache/modplsql/conf/plsql.conf"
The above change is not permanent. If one run autoconfig, this config file will be re-generated, hence the changes will be reverted. So you need to make the changes in the template files as well.
Generate a template report:
$AD_TOP/bin/adtmplreport.sh contextfile=$CONTEXT_FILE
Read the log output, search for TARGET FILE: ...oracle_apache_conf
and then you can find out the template file:
$FND_TOP/admin/template/oracle_apache_conf_1013.tmp
Open this template file and take out the comment of line line include ...plsql.conf
Under System Administrator Responsibility -> Security -> Web PL/SQL (FNDSCPLS form)
Even though Oracle told you this Form is obsolete, this form will still used for to control which function/procedure/package to be able called in Web PL/SQL gateway.
First of all, you must enable the root function which invoke the PL/SQL gateway code ORACLESSWA
As specified in the Apache directive PlsqlRequestValidationFunction, a security function is needed to limit the usage of PL/SQL gatway code:
CREATE OR REPLACE function APPS.XX_MOD_PLSQL_CHECK(procedure_name varchar2) return boolean is
var_result varchar2(1);
begin
var_result := FND_WEB_CONFIG.CHECK_ENABLED(procedure_name);
if var_result='Y' then
return true;
else
return false;
end if;
end;
/
Form Function for PL/SQL gateway code must have a type of "SSWA plsql function"*, or "SSWA plsql function that opens a new window (Kiosk Mode)" and the HTML Call is the Stored Procedure name.
*In R12.2, the type "SSWA plsql function" is obsoleted.
Here are the steps:
Create the following directories:
$INST_TOP/ora/10.1.3/Apache/modplsql/cache
$INST_TOP/ora/10.1.3/Apache/modplsql/conf
$INST_TOP/ora/10.1.3/Apache/modplsql/logs
Create file $INST_TOP/ora/10.1.3/Apache/modplsql/conf/plsql.conf, with content similar the following. Substitute the environment variables and values in [] for your environment.
# load required module (Windows)
LoadModule plsql_module %IAS_ORACLE_HOME%/bin/modplsql.dll
# load required module (*nix)
LoadModule plsql_module $IAS_ORACLE_HOME/Apache/modplsql/bin/modplsql.so
#Directives specify for modplsql
PlsqlLogEnable on
PlsqlLogDirectory $INST_TOP/ora/10.1.3/Apache/modplsql/logs
PlsqlCacheEnable On
PlsqlCacheDirectory $INST_TOP/ora/10.1.3/Apache/modplsql/cache
PlsqlCacheTotalSize 20971520
PlsqlCacheMaxSize 1048576
PlsqlCacheMaxAge 30
PlsqlCacheCleanupTime Everyday 00:00
<Location /pls/[SID] >
SetHandler pls_handler
Order deny,allow
Allow from all
AllowOverride None
PlsqlDatabaseUsername apps
PlsqlDatabasePassword @BSvYt+H8Fv3C4YjspMEOP9k=
PlsqlDatabaseConnectString [DB Server]:[Port]:[SID] ServiceNameFormat
PlsqlAuthenticationMode Basic
PlsqlNLSLanguage AMERICAN_AMERICA.AL32UTF8
PlsqlRequestValidationFunction XX_MOD_PLSQL_CHECK
PlsqlErrorStyle DebugStyle
</Location>
You can use $IAS_ORACLE_HOME/Apache/modplsql/conf/dadobf to generate the obfuscated password.
Syntax: dadobf [password]
These folders and files will be gone when you do the cloning that all the files in INST_TOP directory will be re-generated. So make sure you copy these folders and files to the clone instance after running adcfgclone.
For other possible parameters, you can check out this link
http://docs.oracle.com/cd/E23943_01/web.1111/e10144/under_mods.htm
Open $INST_TOP/ora/10.1.3/Apache/Apache/conf/oracle_apache.conf, search and take out the comment of this line:
include "$INST_TOP/ora/10.1.3/Apache/modplsql/conf/plsql.conf"
The above change is not permanent. If one run autoconfig, this config file will be re-generated, hence the changes will be reverted. So you need to make the changes in the template files as well.
Generate a template report:
$AD_TOP/bin/adtmplreport.sh contextfile=$CONTEXT_FILE
Read the log output, search for TARGET FILE: ...oracle_apache_conf
and then you can find out the template file:
$FND_TOP/admin/template/oracle_apache_conf_1013.tmp
Open this template file and take out the comment of line line include ...plsql.conf
Under System Administrator Responsibility -> Security -> Web PL/SQL (FNDSCPLS form)
Even though Oracle told you this Form is obsolete, this form will still used for to control which function/procedure/package to be able called in Web PL/SQL gateway.
First of all, you must enable the root function which invoke the PL/SQL gateway code ORACLESSWA
As specified in the Apache directive PlsqlRequestValidationFunction, a security function is needed to limit the usage of PL/SQL gatway code:
CREATE OR REPLACE function APPS.XX_MOD_PLSQL_CHECK(procedure_name varchar2) return boolean is
var_result varchar2(1);
begin
var_result := FND_WEB_CONFIG.CHECK_ENABLED(procedure_name);
if var_result='Y' then
return true;
else
return false;
end if;
end;
/
Form Function for PL/SQL gateway code must have a type of "SSWA plsql function"*, or "SSWA plsql function that opens a new window (Kiosk Mode)" and the HTML Call is the Stored Procedure name.
Tuesday, January 14, 2014
Wednesday, December 18, 2013
Concurrent Program Business Event Hook - How to Get It Work Properly
Since R12 concurrent program can invoke business processes during different phases of program execution. I'd done similar customization in version 11.5 and now this is a out-of-the-box feature. The problem about this feature is that:
How can I invoke it? And more importantly, how can I invoke specific logic for a given concurrent program only?
(1) First and foremost, set the value of the mysterious Profile Option "Concurrent: Business Intelligence Integration Enable" to "Yes". (Can anyone from Oracle tell me why it is called this name?)
(2) Check one or more of the business events for a given concurrent program.
(3) Do a lookup for the Even Name
(4) Administrator Workflow => Business Events => Do a search of this even name
(7) When this concurrent program is executed and it reaches certain status/phase, it will call the associated business event, and trigger to start the event subscription (it can be deferred if the phase value is higher than 99). In our case it will run the PL/SQL Rule function (must be a function inside a package). Here is how this function looks like:
Possible parameters you can get from P_EVENT:
REQUEST_ID
REQUESTED_BY
PROGRAM_APPLICATION_ID
CONCURRENT_PROGRAM_ID
STATUS
COMPLETION_TEXT
TIME_STAMP (in form of DDMMYY HHMISS)
In addition, you can retrieve info for this Workflow Event Type through standard methods, e.g. getEventKey, getEventName, getEventData, etc.
Basically having the REQUEST ID is good enough to query up all different kinds of parameters associated with this request.
Event subscription is a generic mechanism, so every concurrent program which has certain business event active will trigger the subscription to start. So MAKE SURE you have implement highly-restrained conditions and very specific logic in the Rule Function so that the code is executed for desired situation only.
Okay. Here is another mystery: where is the info of concurrent program business event stored?
Answer: Table FND_CONC_PROG_ONSITE_INFO, column BUSINESS_EVENT_MAP
It is a 50 character column with Y or N in there, and only the first 8 characters are relevant to the business event setting for a given concurrent_program_id.
Business Event Position relative to the character column position:
1 4 7
2 5 8
3 6
How can I invoke it? And more importantly, how can I invoke specific logic for a given concurrent program only?
(1) First and foremost, set the value of the mysterious Profile Option "Concurrent: Business Intelligence Integration Enable" to "Yes". (Can anyone from Oracle tell me why it is called this name?)
(2) Check one or more of the business events for a given concurrent program.
Concurrent Program
Business Event
|
Event Definition Name
|
Program Completed
|
oracle.apps.fnd.concurrent.program.completed
|
Request Completed
|
oracle.apps.fnd.concurrent.request.completed
|
Request On Hold
|
oracle.apps.fnd.concurrent.request.on_hold
|
Post Processing Ended
|
oracle.apps.fnd.concurrent.request.postprocessing_ended
|
Post Processing Started
|
oracle.apps.fnd.concurrent.request.postprocessing_started
|
Request Resumed
|
oracle.apps.fnd.concurrent.request.resumed
|
Request Running
|
oracle.apps.fnd.concurrent.request.running
|
Request Submitted
|
oracle.apps.fnd.concurrent.request.submitted
|
(4) Administrator Workflow => Business Events => Do a search of this even name
(5) Click "Subscription", then "Create Subscription". Create a Custom Action Type
(6) Set the PL/SQL Rule Function (see below for sample code for this function). Save the settings for this subscription.
![]() |
FUNCTION REQUEST_COMPLETED_FUNC (
p_subscription_guid IN RAW,
p_event IN OUT WF_EVENT_T) RETURN VARCHAR2 IS
var_programName VARCHAR2(100);
var_appShortName VARCHAR2(30);
var_respKey VARCHAR2(100);
var_userName VARCHAR2(30);
num_concRequestID NUMBER;
BEGIN
num_concRequestID := p_event.getValueForParameter('REQUEST_ID');
select fcp.concurrent_program_name
, fa.application_short_name
, fr.responsibility_key
, fu.user_name
into var_programName
, var_appShortName
, var_respKey
, var_userName
from fnd_concurrent_requests fcr
, fnd_concurrent_programs fcp
, fnd_application fa
, fnd_responsibility fr
, fnd_user fu
where fcr.request_id = num_concRequestID
and fcr.concurrent_program_id = fcp.concurrent_program_id
and fcr.program_application_id = fa.application_id
and fcr.responsibility_id = fr.responsibility_id
and fcr.requested_by = fu.user_id;
IF var_programName = 'XXX' and
var_appShortName = 'YY' and
var_respKey = 'ZZZ' and
var_userName = 'TTT' then
/* Put your program/responsibility/user-specific logic in here */
END IF;
END;
Possible parameters you can get from P_EVENT:
REQUEST_ID
REQUESTED_BY
PROGRAM_APPLICATION_ID
CONCURRENT_PROGRAM_ID
STATUS
COMPLETION_TEXT
TIME_STAMP (in form of DDMMYY HHMISS)
In addition, you can retrieve info for this Workflow Event Type through standard methods, e.g. getEventKey, getEventName, getEventData, etc.
Basically having the REQUEST ID is good enough to query up all different kinds of parameters associated with this request.
Event subscription is a generic mechanism, so every concurrent program which has certain business event active will trigger the subscription to start. So MAKE SURE you have implement highly-restrained conditions and very specific logic in the Rule Function so that the code is executed for desired situation only.
Okay. Here is another mystery: where is the info of concurrent program business event stored?
Answer: Table FND_CONC_PROG_ONSITE_INFO, column BUSINESS_EVENT_MAP
It is a 50 character column with Y or N in there, and only the first 8 characters are relevant to the business event setting for a given concurrent_program_id.
Business Event Position relative to the character column position:
1 4 7
2 5 8
3 6
So, if you have Request Submitted and Request Completed checked, the column value becomes:
YNNNNNNYNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN
Genius, isn't it?
YNNNNNNYNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN
Genius, isn't it?
Labels:
EBS
Thursday, December 5, 2013
WebADI Finally Works with 64bit Office Now
As mentioned in Steven Chan Blog, after years of waiting (just a couple of year actually), Oracle finally releases Patch 16399718: SUPPORT WEB ADI WITH MICROSOFT OFFICE 2010 64-BIT VERSION. I'd tested this patch under my R12.1.3 environment, and as promised, it works!
However, it's after 2 hours of debugging and swearing.
The problem is that when any WebADI template is downloaded and opened, the embedded browser inside Excel shows the error:
java.lang.NoSuchMethodError: oracle.apps.bne.utilities.oa.BneDFFStructure.setValType(Ljava/lang/String;)V
After reverse engineering a couple of the Java classes, and searching related patches in Metalink, I found out the class BneDFFStructure is too old that I need to apply patch 14209751 to update the version of this class from
BneDFFStructure.java 120.1.12010000.2 2009/08/03 16:23:37
to
BneDFFStructure.java 120.1.12010000.4 2012/11/30 19:32:09
After the patching (along with 17322095 for Windows 8 fix), I am able to start the WebADI template under Windows 8 and Excel 2013 64-bit. Oh my god, finally my users can do their job and will not bother me to upload stuff for them again!
However, it's after 2 hours of debugging and swearing.
The problem is that when any WebADI template is downloaded and opened, the embedded browser inside Excel shows the error:
java.lang.NoSuchMethodError: oracle.apps.bne.utilities.oa.BneDFFStructure.setValType(Ljava/lang/String;)V
After reverse engineering a couple of the Java classes, and searching related patches in Metalink, I found out the class BneDFFStructure is too old that I need to apply patch 14209751 to update the version of this class from
BneDFFStructure.java 120.1.12010000.2 2009/08/03 16:23:37
to
BneDFFStructure.java 120.1.12010000.4 2012/11/30 19:32:09
After the patching (along with 17322095 for Windows 8 fix), I am able to start the WebADI template under Windows 8 and Excel 2013 64-bit. Oh my god, finally my users can do their job and will not bother me to upload stuff for them again!
Sunday, November 3, 2013
Get Rid of Applet Security Warning when Using Self-Signed Certificate in EBS (Part III)
In Part II I'd provided the solution for all the possible warning message and you will see if you uses a self-signed certificate for Applet Jar signing. In this blog I discuss how to do mass deployment of such solution to hundred of employees in you company.
The ultimate solution is to add your in-house CA root certificate to User Signer CA, and add the certificate for jar signing to User Trusted Certificate. The relationship between added certificate and physical file is shown below.
Assumption:
In the client machine --
In-house CA Certificate File = C:\certs\cacert.pem (this is the same file as C:\OpenSSL\CA\private\cacert.pem)
Certificate for jar signing = C:\cert\adkeystore.der (this is the same file as in $APPL_TOP/admin)
The JRE is installed using all default installation settings, and no extra tweaking has been done on top of it.
(1) Set a local variable for keystore location:
set KEYSTORE_LOC=%USERPROFILE%\AppData\LocalLow\Sun\Java\Deploymenr\security
(2) Add in-house CA Certificate to User Signer CA:
keytool -import -alias symplik_ca -file C:\certs\cacert.pem -file -keystore %KEYSTORE_LOC%\trusted.cacerts -storepass "" -noprompt
(3) Add certificate for jar-signing to User Trusted Certificate:
keytool -import -alias ebs12appltop -file C:\certs\adkeystore.der-file -keystore %KEYSTORE_LOC%\trusted.certs -storepass "" -noprompt
Show whether it is really added:
keytool -list -keystore %KEYSTORE_LOC%\trusted.certs -storepass ""
ebs12appltop, Nov 1, 2013, trustedCertEntry,
Certificate fingerprint (SHA1): 6B:28:5C:28:A6:D1:5A:32:EE:E7:47:37:DB:B1:EB:BB:8C:4D:46:AD
(4) Turn off the certificate revocation check, and launch the form, and accept the warning.
Do a list of certificate of the keystore trusted.certs and you will find the original alias has changed:
keytool -list -keystore %KEYSTORE_LOC%\trusted.certs -storepass ""
deploymentusercert$tsflag$loc=http//papaya.symplik.com:8020java.util.random@19b0d0, Nov 1, 2013, trustedCertEntry,
Certificate fingerprint (SHA1): 6B:28:5C:28:A6:D1:5A:32:EE:E7:47:37:DB:B1:EB:BB:8C:4D:46:AD
Turn the certificate revocation check in Java Control Panel on again.
So, the key to make the User-Trusted Certificate not being checked for revocation is to use a connect ALIAS NAME, in a format of:
deploymentusercert$tsflag$loc=[url]:[port]
I found out the last part (java.util.random@xxxx) is not really needed.
What it means is that instead of using an arbitrary alias name in step (3), you need to to use a proper alias name to import this certificate:
keytool -import -alias "deploymentusercert$tsflag$loc=http//papaya.symplik.com:8020"
-keystore %KEYSTORE_LOC%\trusted.certs -storepass "" noprompt
So, to do the mass deployment of self-signed certificate to client machines, you can:
- Replace the files trusted.cacerts and trusted.certs in employees desktop, as you prepared in step (2) and (4), or
- Prepare a batch file to run the keytool commands, which fetch the certificate files from somewhere from the corporate LAN. This method will able to preserve any certificates added in client JRE before this deployment.
The ultimate solution is to add your in-house CA root certificate to User Signer CA, and add the certificate for jar signing to User Trusted Certificate. The relationship between added certificate and physical file is shown below.
Assumption:
In the client machine --
In-house CA Certificate File = C:\certs\cacert.pem (this is the same file as C:\OpenSSL\CA\private\cacert.pem)
Certificate for jar signing = C:\cert\adkeystore.der (this is the same file as in $APPL_TOP/admin)
The JRE is installed using all default installation settings, and no extra tweaking has been done on top of it.
(1) Set a local variable for keystore location:
set KEYSTORE_LOC=%USERPROFILE%\AppData\LocalLow\Sun\Java\Deploymenr\security
(2) Add in-house CA Certificate to User Signer CA:
keytool -import -alias symplik_ca -file C:\certs\cacert.pem -file -keystore %KEYSTORE_LOC%\trusted.cacerts -storepass "" -noprompt
(3) Add certificate for jar-signing to User Trusted Certificate:
keytool -import -alias ebs12appltop -file C:\certs\adkeystore.der-file -keystore %KEYSTORE_LOC%\trusted.certs -storepass "" -noprompt
Show whether it is really added:
keytool -list -keystore %KEYSTORE_LOC%\trusted.certs -storepass ""
ebs12appltop, Nov 1, 2013, trustedCertEntry,
Certificate fingerprint (SHA1): 6B:28:5C:28:A6:D1:5A:32:EE:E7:47:37:DB:B1:EB:BB:8C:4D:46:AD
(4) Turn off the certificate revocation check, and launch the form, and accept the warning.
Do a list of certificate of the keystore trusted.certs and you will find the original alias has changed:
keytool -list -keystore %KEYSTORE_LOC%\trusted.certs -storepass ""
deploymentusercert$tsflag$loc=http//papaya.symplik.com:8020java.util.random@19b0d0, Nov 1, 2013, trustedCertEntry,
Certificate fingerprint (SHA1): 6B:28:5C:28:A6:D1:5A:32:EE:E7:47:37:DB:B1:EB:BB:8C:4D:46:AD
Turn the certificate revocation check in Java Control Panel on again.
So, the key to make the User-Trusted Certificate not being checked for revocation is to use a connect ALIAS NAME, in a format of:
deploymentusercert$tsflag$loc=[url]:[port]
I found out the last part (java.util.random@xxxx) is not really needed.
What it means is that instead of using an arbitrary alias name in step (3), you need to to use a proper alias name to import this certificate:
keytool -import -alias "deploymentusercert$tsflag$loc=http//papaya.symplik.com:8020"
-keystore %KEYSTORE_LOC%\trusted.certs -storepass "" noprompt
So, to do the mass deployment of self-signed certificate to client machines, you can:
- Replace the files trusted.cacerts and trusted.certs in employees desktop, as you prepared in step (2) and (4), or
- Prepare a batch file to run the keytool commands, which fetch the certificate files from somewhere from the corporate LAN. This method will able to preserve any certificates added in client JRE before this deployment.
Saturday, November 2, 2013
Get Rid of Applet Security Warning when Using Self-Signed Certificate in EBS (Part II)
If your EBS 11i or R12 environment does not have patch 17309237 applied, you will see this warning when you start any Forms:
Reason: JAR file manifest does not contain the Permission attribute.
You check the box of "I accept the risk..." and click Run, you could see the error "FRM-92095: Oracle JInitiator version too low. Please install version 1.1.8.2 or higher"
Reason: You need to patch your IAS to version 10.1.2.3 (through patch 5983622), and patch 14825718 for numerous bug fixes -- which requires OPatch 1.0.0.0.63 or higher, and OUI must be 10.1.
So you probably need to apply 6640838 (to Oracle Home 10.1.2) which upgrade OUI to 10.1, and then unzip patch 6880880_10100_[OS].zip to this Oracle Home directory.
A quick workaround is to change the java.vendor system property value back to it's original owner: Sun Microsystems Inc. This property value has changed to "Oracle Corporation" since JRE 7.
To achieve this change, you can open the Java Control Panel -> Java -> View -> User Tab
Add a Runtime Parameter: -Djava.vendor="Sun Microsystems Inc."
Or even simpler way is to add a system variable JAVA_TOOL_OPTIONS and the value is
-Djava.vendor="Sun Microsystems Inc."
After you'd apply the patch 17309237 and using self-signed certificate, you will see another warning:
Reason: UNKNOWN Publisher, i.e. The JRE does not know the CA which signed these JAR files.
You can continue to work if you check the "I accept..." box, but this warning will show up EVERY TIME when you start the form.
Start the Form again you will see the warning but the content is slightly different:
Reason: The Publisher is recognized, but the JRE cannot find out whether this certificate has been revoked or not (through Certificate Revocation list CRL or Online Certificate Status Protocol OCSP).
Again,. you can continue to work if you check the "I accept..." box, but this warning will show up EVERY TIME when you start the form.
Change the JRE setting to stop checking certificate revocation
Start the Form again, and finally you get a "one-click-away-everything-done' warning:
After the Form is opened successfully, you can go back to the Java control panel, and you will see that this certificate has been added to Trust Certificate. It is done automatically when you check the "Do not show this again..." warning message dialog box.
Finally, you can set the Certificate Revocation security settings back to the originally values:
If you open the Form again, no more warning will be shown even you set the checking back. Hurray !!
Get Rid of Applet Security Warning when Using Self-Signed Certificate in EBS (Part I)
Since the outbreak of Java Applet security issue around January 2013, this fiasco ended in October that Oracle finally provided a stable and acceptable JRE version (according to those Mozilla developers) to make those security experts feel happy, and now it is Java SE 7u45.
In short, the changes make the Java Applet more difficult to run malicious code by giving never-ending stop signs and warnings if the Jar files are not properly signed. In light of these changes, Oracle released the long-waiting patch 17191279 to resolve this issue, as mentioned in Metalink doc 1591073.1 "Enhanced Jar Signing for Oracle E-Business Suite".
If your company is willing to pay the ransom to Verisign, Thawte or other Certificate Authorities, those security warning will be gone smoothly. However, if you plan to use self-signed certificate, please follow this blog and I'll go through a step-by-step approach to settle this, without paying a dime to these CAs.
All the steps are tested in the environment of Oracle EBS R12.1.x under Windows OS. If you're using Unix/Linux environment, the steps are essentially the same. These steps can also be applied to 11i environment.
Part I - Apply patch 17191279
This patch requires you to run the adgrants.sql script (follows the readme file in the patch) before patching. If you encounter error in one of the AD worker and the process hangs in the middle, you can:
- open SQL*Plus, connect as APPS, run the SQL
create context AD_JAR using AD_JAR;
You can check the content of this certificate file by
Copy file CA certificate to APPL_TOP (if different locations), and add this CA certificate to keystore:
C:\OpenSSL\CA>c:\oracle\apps\tech_st\10.1.3\appsutil\jdk\jre\bin\keytool.exe ^
Double check whether this key alias has been added:
(7.1) Copy client certificate adkeystore.csr to OpenSSL directory C:\OpenSSL\CA
(7.2) Do the signing
if you got error:
In short, the changes make the Java Applet more difficult to run malicious code by giving never-ending stop signs and warnings if the Jar files are not properly signed. In light of these changes, Oracle released the long-waiting patch 17191279 to resolve this issue, as mentioned in Metalink doc 1591073.1 "Enhanced Jar Signing for Oracle E-Business Suite".
If your company is willing to pay the ransom to Verisign, Thawte or other Certificate Authorities, those security warning will be gone smoothly. However, if you plan to use self-signed certificate, please follow this blog and I'll go through a step-by-step approach to settle this, without paying a dime to these CAs.
All the steps are tested in the environment of Oracle EBS R12.1.x under Windows OS. If you're using Unix/Linux environment, the steps are essentially the same. These steps can also be applied to 11i environment.
Part I - Apply patch 17191279
This patch requires you to run the adgrants.sql script (follows the readme file in the patch) before patching. If you encounter error in one of the AD worker and the process hangs in the middle, you can:
- open SQL*Plus, connect as APPS, run the SQL
create context AD_JAR using AD_JAR;
- run adctrl to restart the failed worker.
Part II - Setup your own CA
(1) Download OpenSSL 0.9.8h for Windows from Sourceforge, and unzip it under C:\OpenSSL. Even though it is independent of Oracle EBS stuff, I recommend that you put it in APPLTOP server.
(2) Open a Command Prompt
C:\> cd OpenSSL
C:\OpenSSL> mkdir CA
C:\OpenSSL> copy share\openssl.cnf CA\openssl.conf
C:\OpenSSL> cd CA
C:\OpenSSL> mkdir certs
C:\OpenSSL> mkdir crl
C:\OpenSSL> mkdir newcerts
C:\OpenSSL> mkdir private
C:\OpenSSL\CA>set PATH=C:\OpenSSL\bin;%PATH%
C:\OpenSSL\CA>set OPENSSL_CONF=c:\OpenSSL\CA\openssl.conf
C:\OpenSSL\CA>echo off
echo >index.txt
echo 01>serial
echo on
C:\OpenSSL\CA>
DO NOT close this command prompt....
(3) Edit C:\OpenSSL\CA\openssl.conf
Change the dir property to what we set in our environment
[ CA_default ]
dir = ./demoCA # Where everything is kept
certs = $dir/certs # Where the issued certs are kept
[ CA_default ]
dir = C:\\OpenSSL\\CA # Where everything is kept
certs = $dir/certs # Where the issued certs are kept
Change the policy to allow signing all certificates
# For the CA policy
[ policy_match ]
countryName = match
stateOrProvinceName = match
organizationName = match
organizationalUnitName = optional
commonName = supplied
emailAddress = optional
# For the CA policy
[ policy_match ]
countryName = optional
stateOrProvinceName = optional
organizationName = optional
organizationalUnitName = optional
commonName = optional
emailAddress = optional
Go back to the command prompt in step (2)...
(4) Create your own Certificate Authority
C:\OpenSSL\CA>openssl genrsa -des3 -out private\cakey.pem 4096
Loading 'screen' into random state - done
Generating RSA private key, 4096 bit long modulus
.............................................................++
.............................................++
e is 65537 (0x10001)
Enter pass phrase for server.key: (password)
Verifying - Enter pass phrase for server.key: (password)
C:\OpenSSL\CA>openssl req -new -x509 -days 3650 -key private\cakey.pem -out cacert.pem -config openssl.conf
Enter pass phrase for cakey.pem:
Loading 'screen' into random state - done
You are about to be asked to enter information that will be incorporated
into your certificate request.
What you are about to enter is what is called a Distinguished Name or a DN.
There are quite a few fields but you can leave some blank
For some fields there will be a default value,
If you enter '.', the field will be left blank.
-----
Country Name (2 letter code) []:CA
State or Province Name (full name) []:Ontario
Locality Name (eg, city) []:Toronto
Organization Name (eg, company) []:SYMPLiK Technologies
Organizational Unit Name (eg, section) []:Information Technology
Common Name (eg, your websiteÆs domain name) []: SYMPLiK Certificate Authority
Email Address []:
You can check the content of this certificate file by
C:\OpenSSL\CA>openssl x509 -noout -text -in cacert.pem
(5) Add CA certificate to JRE in APPL_TOP
First, find out where is the JRE datastore located in APPL_TOP:
echo $OA_JRE_TOP\lib\security\cacerts
c:\oracle\apps\tech_st\10.1.3\appsutil\jdk\jre\lib\security\cacerts
Copy file CA certificate to APPL_TOP (if different locations), and add this CA certificate to keystore:
C:\OpenSSL\CA>c:\oracle\apps\tech_st\10.1.3\appsutil\jdk\jre\bin\keytool.exe ^
-import -alias symplik -file cacert.pem -trustcacerts -v -keystore ^
c:\oracle\apps\tech_st\10.1.3\appsutil\jdk\jre\lib\security\cacerts
Enter keystore password: (changeit)
Owner: OU=Information Technology, O=SYMPLiK Technologies, L=Toronto ST=Ontario, C=CA
Issuer: OU=Information Technology O=SYMPLiK Technologies, L=v, ST=Ontario, C=CA
Serial number: c7d2e988a015eb6a
Valid from: Wed Oct 30 11:02:26 CST 2013 until: Sat Oct 28 11:02:26 CST 2023
Certificate fingerprints:
MD5: AF:26:AE:7A:9D:68:89:06:E8:90:30:6E:EE:6A:EC:62
SHA1: 22:66:25:B1:AA:1C:C7:EA:01:BF:4C:EB:F6:04:80:BE:0D:6A:1B:86
Signature algorithm name: SHA1withRSA
Version: 1
Trust this certificate? [no]: yes
Certificate was added to keystore
[Storing c:\oracle\apps\tech_st\10.1.3\appsutil\jdk\jre\lib\security\cacerts]
Double check whether this key alias has been added:
C:\OpenSSL\CA>c:\oracle\apps\tech_st\10.1.3\appsutil\jdk\jre\bin\keytool.exe \
-list -keystore \
c:\oracle\apps\tech_st\10.1.3\appsutil\jdk\jre\lib\security\cacerts
....
symplik, Oct 30, 2013, trustedCertEntry,
Certificate fingerprint (MD5): AF:26:AE:7A:9D:68:89:06:E8:90:30:6E:EE:6A:EC:62
....
(6) Open another command prompt which has set the APPL_TOP environment.
(6.1) Initialize the keystore
C:> cd %APPL_TOP%\admin
C:\oracle\apps\apps_st\appl\admin>adjkey -initialize -keysize 4096
Copyright (c) 2002 Oracle Corporation
Redwood Shores, California, USA
AD Java Key Generation
Version 12.0.0
NOTE: You may not use this utility for custom development
unless you have written permission from Oracle Corporation.
Reading product information from file...
Reading language and territory information from file...
Reading language information from applUS.txt ...
Enter the APPS username: apps
Enter the APPS password:
Successfully created javaVersionFile.
adjkey will now create a signing entity for you.
Enter the Name of your Company (used for both CN and
ORGANIZATION NAME) [CN/ORGANIZATION NAME] : SYMPLiK Technologies
Enter the department or group that will use the certificate [ORGANIZATION UNIT] : Finance
Enter the full name of the city where your organization's
head office is located [LOCALITY] : Toronto
Enter the full name of the State, Province or County where
your organization's head office is located [STATE] : Ontario
Enter the two-letter ISO abbreviation for your country
(for example, US for the United States) [COUNTRY] : CA
Enter keystore password: Re-enter new password: Enter key password for
(RETURN if same as keystore password): Re-enter new password:
keytool -genkey -alias VCPDEMO_papaya -keyalg RSA -keysize 4096 -keystore c:\oracle\apps\apps_st\appl\admin\adkeystore.dat -validity 14600 -dname " CN=SYMPLiK Technologies, OU=Finance, O=SYMPLiK Technologies, L=Toronto, S=Ontario, C=CA"
The above Java program completed successfully.
Your digital signature has been created successfully and
imported into the keystore database. This signature
will now be used to sign Applications JAR files whenever
they are patched.
IMPORTANT: If you have multiple web servers, you must copy
files to each of the remaining web servers on your site.
See the documentation reference for more information.
adjkey is complete.
(6.2) Generate client certificate
C:\oracle\apps\apps_st\appl\admin>adjkey -certreq -file adkeystore.csr
Copyright (c) 2002 Oracle Corporation
Redwood Shores, California, USA
AD Java Key Generation
Version 12.0.0
NOTE: You may not use this utility for custom development
unless you have written permission from Oracle Corporation.
Reading product information from file...
Reading language and territory information from file...
Reading language information from applUS.txt ...
Enter the APPS username: apps
Enter the APPS password:
Successfully created javaVersionFile.
Enter keystore password: Enter key password for
keytool -certreq -file adkeystore.csr -keystore c:\oracle\apps\apps_st\appl\admin\adkeystore.dat -alias VCPDEMO_papaya
The above Java program completed successfully.
adjkey is complete.
(7) Sign the client certificate by your CA
(7.1) Copy client certificate adkeystore.csr to OpenSSL directory C:\OpenSSL\CA
(7.2) Do the signing
C:\OpenSSL\CA>openssl ca -in adkeystore.csr -out adkeystore.crt
Using configuration from c:\OpenSSL\CA\openssl.conf
Loading 'screen' into random state - done
Enter pass phrase for C:\OpenSSL\CA\private\cakey.pem:
Check that the request matches the signature
Signature ok
The Subject's Distinguished Name is as follows
countryName :PRINTABLE:'CA'
stateOrProvinceName :PRINTABLE:'Ontario'
localityName :PRINTABLE:'Toronto'
organizationName :PRINTABLE:'SYMPLiK Technologies'
organizationalUnitName:PRINTABLE:'FINANCE'
commonName :PRINTABLE:'SYMPLiK Technologies'
Certificate is to be certified until Oct 28 03:21:06 2023 GMT (3650 days)
Sign the certificate? [y/n]:y
1 out of 1 certificate requests certified, commit? [y/n]y
Write out database with 1 new entries
Data Base Updated
if you got error:
failed to update database TXT_DB error number 2
It's because the same /C/ST/O/OU/CN combination exists.
Change the 'unique_subject = no' in openssl.conf
remove index.attr and rerun
(7.3) Convert the signed certificate to DER format
C:\OpenSSL\CA>openssl x509 -outform der -in adkeystore.crt -out adkeystore.der
(7.4) Copy DER-formatted certificate to %APPL_TOP%\admin directory
(8) Add the DER-formatted certificate to keystore
C:\oracle\apps\apps_st\appl\admin>adjkey -import -file adkeystore.der -trustcacerts
Copyright (c) 2002 Oracle Corporation
Redwood Shores, California, USA
AD Java Key Generation
Version 12.0.0
NOTE: You may not use this utility for custom development
unless you have written permission from Oracle Corporation.
Reading product information from file...
Reading language and territory information from file...
Reading language information from applUS.txt ...
Enter the APPS username: apps
Enter the APPS password:
Successfully created javaVersionFile.
Enter keystore password: Enter key password for Certificate reply was installed in keystore
keytool -import -file adkeystore.der -trustcacerts -keystore c:\oracle\apps\apps_st\appl\admin\adkeystore.dat -alias VCPDEMO_papaya
The above Java program completed successfully.
adjkey is complete.
(9) Run adadmin and force regenerate all JAR files (R12: 1 > 4 > yes / 11i: 1 > 5 > yes)
Subscribe to:
Posts
(
Atom
)








+-+%5BUntitled-1%5D.png)










