Showing posts with label Solaris. Show all posts
Showing posts with label Solaris. Show all posts

Monday, April 14, 2014

Solaris 10 OS and Oracle Directory Server Enterprise Edition not affected by Heartbleed

We support Solaris 10 OS and Oracle Directory Server Enterprise Edition for a big customer here in Singapore. 

Both are not affected by Heartbleed security flaw.



Oracle Solaris 10 Sparc is not vulnerable to the SSL Heartbleed vulnerability.The latest patched default OpenSSL library in Solaris 10 is version 0.9.7d, which is not affected by the vulnerability. The Heartbleed vulnerability only affects OpenSSL version 1.0.1 to 1.0.1f.

Official response from Oracle Support with regard to Oracle Directory Server Enterprise Edition below:


ODSEE do not use OpenSSL. ODSEE uses NSS for the SSL libraries. You may want to refer to this link for more understanding on the topic: ODSEE 11.1.1.7.0 Administration Guide: http://docs.oracle.com/cd/E29127_01/doc.111170/e28972/ds-security.htm#bcaul


.

Monday, November 4, 2013

OS Patching and the Impact

I encountered a Priority 1 case in a customer site 2 weeks ago with an OpenSSO deployment for one of our government ministries. 


What really happened was the Single Sign-On infrastructure became unstable after a Solaris Patch Cluster was applied, especially during high-load.


No one realised the issue right after patching. There was even a round of internal testing conducted and the system was given the go-ahead by the administrator.

But on the 1st working day after the patching, the help-desk received numerous calls that authentication was "sometimes OK, sometimes not OK". They thought the farm of OpenSSO servers were restarting one at a time. But no one touched the OpenSSO servers at all.

We observed that CPU consumptions were on the high side and connection timeouts were often encountered.

I was consulted. As I was helping customers with tuning in another environment where our Solaris servers were recently patched and encountered poor performance, I thought it was a good bet to roll back the Solaris Patch Cluster.

As the fire was on the Production side, a decision was made to perform the roll-back on the servers in the Production environment first. That solved the issue!

Root cause? I'll let the Oracle experts tell us since they are paid to service us.

Once the fire was put off, we also subsequently roll-back the patch on our QAT environment and we were back in business.

Lesson learnt is OS Patching does have impact on the performance of the software that is installed on top of it. Do not ignore this fact. Load testing after patching will be ideal if time permits. (well, I would say no one does this 90% of the time. :> )

.




Friday, May 24, 2013

Solaris EOL Dates

Some of our customers are still running Solaris 10 (yes, a lot more have already migrated out to RHEL).



.


Sunday, November 28, 2010

Confusing Oracle/Sun Solaris OS Versioning

I'm always confused when I want to find out the exact release of the Solaris OS which I am working on.
If you do a "$ more /etc/release", you get something like below:



It's still very hard to relate 9/10 belongs to which release. I can relate more to U1, U2, etc... It's easier to track, at least for me.

Luckily, Wikipedia tracks it here.


  • Solaris 10 1/06 ("U1")
  • Solaris 10 6/06 ("U2")
  • Solaris 10 11/06 ("U3")
  • Solaris 10 8/07 ("U4")
  • Solaris 10 5/08 ("U5")
  • Solaris 10 10/08 ("U6")
  • Solaris 10 5/09 ("U7")
  • Solaris 10 10/09 ("U8")
  • Solaris 10 9/10 ("U9")

.