Disable SELinux

How to Disable SELinux

You've setup a new system, or installed something new on your Linux system and its not working. You get the feeling that SELinux is the cause of the problem. This page was written to help.

Overview

SELinux has two major components on your system. There's the kernel mechanism which is enforcing a bunch of access rules which apply to processes and files. And secondly, there's file labels : every file on your system has extra labels attached to it which tie-in with those access rules. Run ls -Z and you'll see what I mean.

Should you really disable SELinux?

Be aware that by disabling SELinux you will be removing a security mechanism on your system. Think about this carefully, and if your system is on the Internet and accessed by the public, then think about it some more. Joshua Brindle (an SELinux developer) has comments on disabling SELinux here, which states clearly that applications should be fixed to work with SELinux, rather than disabling the OS security mechanism.
You need to decide if you want to disable SELinux temporarily to test the problem, or permanently switch it off. It may also be a better option to make changes to the policy to permit the operations that are being blocked - but this requires knowledge of writing policies and may be a steep learning curve for some people. For the operating system as a whole, there is two kinds of disabling:
  • Permissive - switch the SELinux kernel into a mode where every operation is allowed. Operations that would be denied are allowed and a message is logged identifying that it would be denied. The mechanism that defines labels for files which are being created/changed is still active.
  • Disabled - SELinux is completely switched off in the kernel. This allows all operations to be permitted, and also disables the process which decides what to label files & processes with.
Disabling SELinux could lead to problems if you want to re-enable it again later. When the system runs with file labelling disable it will create files with no label - which could cause problems if the system is booted into Enforcement mode. A full re-labelling of the file system will be necessary.

Temporarily switch off enforcement

You can switch the system into permissive mode with the following command:
echo 0 >/selinux/enforce
You'll need to be logged in as root, and in the sysadm_r role:
newrole -r sysadm_r
To switch back into enforcing mode:
echo 1 >/selinux/enforce
In Fedora Core and RedHat Enterprise Linux you can use the setenforce command with a 0 or 1 option to set permissive or enforcing mode, its just a slightly easier command than the above. To check what mode the system is in,
cat /selinux/enforce
which will print a "0" or "1" for permissive or enforcing - probably printed at the beginning of the line of the command prompt.

Permanently Permissive

The above will switch off enforcement temporarily - until you reboot the system. If you want the system to always start in permissive mode, then here is how you do it. In Fedora Core and RedHat Enterprise, edit /etc/selinux/config and you will see some lines like this:

# This file controls the state of SELinux on the system.
# SELINUX= can take one of these three values:
# enforcing - SELinux security policy is enforced.
# permissive - SELinux prints warnings instead of enforcing.
# disabled - No SELinux policy is loaded.
SELINUX=enforcing
# SELINUXTYPE= can take one of these two values:
# targeted - Only targeted network daemons are protected.
# strict - Full SELinux protection.
SELINUXTYPE=targeted
... just change SELINUX=enforcing to SELINUX=permissive, and you're done. Reboot if you want to prove it. For the other Linuxes which don't have the /etc/selinux/config file, you just need to edit the kernel boot line, usually in /boot/grub/grub.conf if you're using the GRUB boot loader. On the kernel line, add enforcing=0 at the end. For example,

title SE-Linux Test System
 root (hd0,0)
 kernel /boot/vmlinuz-2.4.20-selinux-2003040709 ro root=/dev/hda1 nousb enforcing=0
 #initrd /boot/initrd-2.4.20-selinux-2003040709.img

Fully Disabling SELinux

Fully disabling SELinux goes one step further than just switching into permissive mode. Disabling will completely disable all SELinux functions including file and process labelling. In Fedora Core and RedHat Enterprise, edit /etc/selinux/config and change the SELINUX line to SELINUX=disabled:

# This file controls the state of SELinux on the system.
# SELINUX= can take one of these three values:
# enforcing - SELinux security policy is enforced.
# permissive - SELinux prints warnings instead of enforcing.
# disabled - No SELinux policy is loaded.
SELINUX=disabled
# SELINUXTYPE= can take one of these two values:
# targeted - Only targeted network daemons are protected.
# strict - Full SELinux protection.
SELINUXTYPE=targeted
... and then reboot the system. For the other Linuxes which don't have the /etc/selinux/config file, you just need to edit the kernel boot line, usually in /boot/grub/grub.conf, if you're using the GRUB boot loader. On the kernel line, add selinux=0 at the end. For example,

title SE-Linux Test System
        root (hd0,0)
        kernel /boot/vmlinuz-2.4.20-selinux-2003040709 ro root=/dev/hda1 nousb selinux=0
        #initrd /boot/initrd-2.4.20-selinux-2003040709.img
You will have to reboot to disable SELinux, you just can't do it while the system is running.

Re-Enabling SELinux

If you've disabled SELinux as in the section above, and you want to enable it again then you've got a bit of work to do. The problem will be that files created or changed when SELinux was disabled won't have the correct file labels on them - if you just reboot in enforcing mode then a lot of stuff won't work properly. What you need to do is to enable SELinux by editing /etc/selinux/config (for Fedora/RedHat) or by adding selinux=1 to the kernel boot line, then boot into permissive mode, then relabel everything, and then reboot into (or simply switch to) enforcing mode.
After booting into permissive mode, run fixfiles relabel
Alternatively, in Fedora and RedHat Enterprise Linux you can run touch /.autorelabel and reboot or put autorelabel on the boot command line - in both cases the file system gets a full relabel early in the boot process. Note that this can take quite some time for systems with a large number of files.
After relabelling the filesystem, you can switch to enforcing mode (see above) and your system should be fully enforcing again.

ADSTRTAL.sh returns error : TIMED OUT( 100000 ): INTERRUPTED EXCEPTION

Oracle Applications Technology Stack - Version 12.0.6 to 12.1.3 [Release 12.0 to 12.1]
Information in this document applies to any platform..


 Goal

When starting Application Server 10g services with EBusiness Suite Release 12, if the server is heavily loaded you may sometimes receive a timeout message from one or more startup scripts called by adstrtal.sh:-
  adoacorectl.sh
  adformsctl.sh
  adoafmctl.sh

This note describes how you can increase the default timeout values for the startup scripts, which may prevent this issue from occurring.

Fix

The OC4J containers (JVMs) with AS10g are given a certain amount of time to startup.  If the time taken to startup the process is longer than this value, you will see an error returned by the startup script.
NOTE : despite the error being thrown, the process may actually startup correctly.  You can use the following command to check the status of the processes:-
     $ADMIN_SCRIPTS_HOME/adopmnctl.sh status
The error seen for a timeout will normally be similar to that shown below:-
****************************************************
        Executing service control script:
        /oracle/VIS/inst/apps/VIS_myhost/admin/scripts/adoafmctl.sh start
        script returned:
****************************************************
        ERROR : Timed out( 100000 ): Interrupted Exception
        You are running adoafmctl.sh version 120.6.12000000.2
        Starting OPMN managed OAFM OC4J instance  ...
****************************************************
The timeout value is defined in the $ORA_CONFIG_HOME/10.1.3/opmn/conf/opmn.xml file   There are three entries to be concerned about, one for each of the managed OC4J containers (oacore, forms and oafm).  The entry is shown below the appropriate "process-type id=" section and looks like shown below by default:-
<start timeout="600" retry="2"/>
Modifying the timeout value from "600" to "1800" may resolve the timeout error
For example you may see entry similar to shown below for the "oacore" JVM group (lines omitted for brevity)
    <process-type id="oacore" module-id="OC4J" status="enabled" working-dir="$ORACLE_HOME/j2ee/home">
      <module-data>
       ...............
       ...............
      </module-data>
      <start timeout="600" retry="2"/>
      <stop timeout="120"/>
      <restart timeout="720" retry="2"/>
       ...............
       ...............
These default timeout values cannot be changed using Autoconfig variables, so any change needs to be implemented using the "Configuration Customizations" section in Note 387859.1 : Using AutoConfig to Manage System Configurations in Oracle Applications Release 12
If you are running into this issue and want to change the timeout as described in this note, these are the recommended steps:
If your problem is occurring in a TEST environment
1.  Shutdown all AS10g services
2.  Manually edit the opmn.xml file as described above
3.  Restart AS10g services to confirm the timeout message is no longer seen
4.  Implement this new timeout value by modifying the AutoConfig template for opmn.xml
Filename "opmn_xml_1013.tmp" located in $FND_TOP/admin/template
5.  Run AutoConfig to regenerate the configuration files with your changes
6.  Check the changes have taken effect in the opmn.xml file correctly
7.  Restart AS10g services and confirm the timeout message no longer appears
If your problem is occurring in a PRODUCTION environment
1.  Shutdown all AS10g services on a TEST environment
2.  Modify the AutoConfig template for opmn.xml for your TEST environment
3.  Run AutoConfig on TEST environment to regenerate the configuration files with your changes
4.  Check the files in TEST environment to be sure the change has taken effect as expected
5.  Restart AS10g Service on TEST environment and ensure the services all startup correctly
6.  Promote this change to your PROD instance

Note: You may see adoacorectl.sh or other OPMN managed scripts fail with message "exiting with status 150"

This may indicate that the script has not started/stopped within the timeout defined for the service control infrastructure

"s_oacoretimeout" is an AutoConfig variable whose value is used internally by the service control infrastructure to determine how much time it should wait before giving up on a script that starts/stops a service.
The above error likely indicates this OACore timeout has been hit. The default is 100 seconds, but can be increased if necessary.
The variables for the OPMN managed processes are:
s_oacoretimeout
s_formstimeout
s_oafmtimeout

For further information on debugging service startup issues see Note 743518.1 "Starting up AS10g services in an EBusiness Suite Release 12 environment"
For additional reading you can review section "3 Starting and Stopping" in the Oracle Application Server Administrator's Guide 10g Release 3 (10.1.3)
 

How To change the Port Pool in the E-Business Suite


Applies to:

Oracle Applications Technology Stack - Version 11.5.9 to 12.1.3 [Release 11.5 to 12.1]
Information in this document applies to any platform.

ACTION Plan:-


1. Review Note 216664.1 - 'FAQ: Cloning Oracle Applications Release 11i'
  • See Question 21: What is the port pool? What if I want to give a specific value to a Server Port?
2. Run adpreclone.pl:
  • Set the Applications Environment by sourcing $APPL_TOP/APPSORA.env
  • "cd" to $OAD_TOP/admin/scripts
  • Execute "perl adpreclone.pl appsTier"
3. Run adcfgclone.pl:
  • Stop all oracle services for Applications by running "adstpall.sh".
  • "cd to "$OAD_TOP/clone/bin
  • Execute "perl adcfgclone.pl appsTier"
  • Enter new port pool number when prompted
If it is required to change the Port Pool or port on the database tier, please follow Note 338003.1 - 'How to change the hostname and/or port of the Database Tier using AutoConfig'.

If you want to change some Ports individually, then use OAM to update the Contextfile and after you have stored your modified values, execute Autoconfig.
 

How to change the hostname of an Applications Tier using AutoConfig


Applies to:

Oracle Applications Technology Stack - Version: 11.5.10.2 to 11.5.10.2 - Release: 11.5.10 to 11.5.10
Information in this document applies to any platform.



Solution

The following method can be used to successfully change an Applications Tier hostname using AutoConfig.
1. Deregister the current Applications server (Required)
As the Applications hostname will be changed, the current Applications server node needs to be de-registered.
To deregister the current Applications server node, run the following command as the owner of the Oracle Applications file system and current database instance:
perl $AD_TOP/bin/adgentns.pl appspass=<APPSpwd> contextfile=<CONTEXT> -removeserver
If you already changed the information of your existing AutoConfig Context file and have not done the above step, then you can manually update the Net Services Topology Model using the following syntax: 
Locate the System Name:
The System name is the database name
Verify with sql query:
select DB_NAME from FND_DATABASES;
Locate the server name corresponding to the tier in question:
Query on the Applications tier:
select NAME, SERVER_TYPE from FND_APP_SERVERS, FND_NODES  where FND_APP_SERVERS.NODE_ID = FND_NODES.NODE_ID and SERVER_TYPE='APPS' and FND_NODES.NODE_NAME=upper('hostname');
Run the following PL/SQL block:
begin FND_NET_SERVICES.remove_server('<SYSTEM_NAME'>, '<SERVER_NAME>'); end; / commit; /
 2. Update the AutoConfig Context files (conditional)
If the Context file values have already been changed previously and you had to manually remove the Tier server, then you can skip this step
Create a new context file using the following syntax:-
cd $APPL_TOP/admin perl $AD_TOP/bin/adclonectx.pl contextfile=$CONTEXT_FILE
This will create a new Context file of the format <SID>_<new hostname>.xml in the current working directory 
3. Shutdown the Applications Tier Services (Required)
Shutdown the Middle Tier services using the script under the following location:-
 
$COMMON_TOP/admin/scripts/<old SID_hostname>/adstpall.sh apps <appspasswd>
4. Change the machine hostname (Required)
Change the hostname at O/S level at this stage
If you use /etc/hosts ensure you remember to update the entries.
Linux Red Hat Platforms Only:
  • Verify that the /etc/hosts file contains entries that are similar to the following:
127.0.0.1 localhost.localdomain <ip_address> <node_name>.<domain_name>

  • Verify that the /etc/sysconfig/network file contains an entry that is similar to the following:
HOSTNAME=<node_name>.<domain_name>
  • Check to see if the /etc/sysconfig/networking/profiles/default/network file exists. If it does, remove it.
  • If you changed any files in the previous steps, reboot the system.
5. Reseed the Net Services Topology Model (Required)

The Net Services Topology Model is automatically updated by running AutoConfig :-

Run AutoConfig on the Applications tier node using the following syntax:-
cd <AD_TOP>/bin
./adconfig.sh contextfile=<full path to new Context file> appspass=<appspasswd>
 
6. Start the Applications Tier Services
Rerun APPSORA.env to set the new Application environment
Start the Applications Tier Services using the script from the new directory:-
$COMMON_TOP/admin/scripts/<SID_<new hostname>/adstrtal.sh apps <appspasswd>
7. Finishing Tasks
 

R12 - Logon is not working

Applies to:

Oracle Applications Manager - Version 12.0.0 to 12.0.4 [Release 12]
Information in this document applies to any platform.

Symptoms

After the clone of an E-Business Suite Instance Release 12.0.4, the logon was not working as expected on the target Instance.
Launching the logon URL
http://<hostname>.<domain>:<Port>
 is redirected to
http://host.domain:port/OA_HTML/AppsLocalLogin.jsp

Result :

Nothing happens - no Homepage screen is presented, neither an error message is brought up.


Note 422419.1- 'How To Enable and Collect Debug for HTTP, OC4J and OPMN in R12' references the steps to get debug details. After enabling the debug, following failures have been identified in the logfile "$LOG_HOME/ora/10.1.3/j2ee/oacore/oacore_default_group_1/application.log" :
...

javax.servlet.ServletException: oracle.classloader.util.AnnotatedClassNotFoundException:

Missing class: _OA
Dependent class: oracle.jsp.runtimev2.JspPageInfo
Loader: oc4j:10.1.3
Code-Source: <physical Path to ORACLE_HOME>/10.1.3/j2ee/home/lib/ojsp.jar
Configuration: <code-source> in META-INF/boot.xml in
<physical Path to ORACLE_HOME>/10.1.3/j2ee/home/oc4j.jar

This load was initiated at oacore.web.html.jsp15997082:0.0.0 using the loadClass() method.

The missing class is not available from any code-source or loader in the system.
at oracle.jsp.runtimev2.JspPageTable.service(JspPageTable.java:387)
at oracle.jsp.runtimev2.JspServlet.internalService(JspServlet.java:478)
at oracle.jsp.runtimev2.JspServlet.service(JspServlet.java:401)
at javax.servlet.http.HttpServlet.service(HttpServlet.java:856)
at com.evermind[Oracle Containers for J2EE 10g (10.1.3.0.0)
].server.http.ResourceFilterChain.doFilter(ResourceFilterChain.java:64)
at oracle.apps.jtf.base.session.ReleaseResFilter.doFilter(ReleaseResFilter.java:26)
at com.evermind[Oracle Containers for J2EE 10g (10.1.3.0.0)
].server.http.EvermindFilterChain.doFilter(EvermindFilterChain.java:15)
at oracle.apps.fnd.security.AppsServletFilter.doFilter(AppsServletFilter.java:318)
at com.evermind[Oracle Containers for J2EE 10g (10.1.3.0.0)
].server.http.ServletRequestDispatcher.invoke(ServletRequestDispatcher.java:627)
at com.evermind[Oracle Containers for J2EE 10g (10.1.3.0.0)
].server.http.ServletRequestDispatcher.forwardInternal(ServletRequestDispatcher.java:376)
at com.evermind[Oracle Containers for J2EE 10g (10.1.3.0.0)
].server.http.HttpRequestHandler.doProcessRequest(HttpRequestHandler.java:870)
at com.evermind[Oracle Containers for J2EE 10g (10.1.3.0.0)
].server.http.HttpRequestHandler.processRequest(HttpRequestHandler.java:451)
at com.evermind[Oracle Containers for J2EE 10g (10.1.3.0.0)
].server.http.AJPRequestHandler.run(AJPRequestHandler.java:299)
at com.evermind[Oracle Containers for J2EE 10g (10.1.3.0.0)
].server.http.AJPRequestHandler.run(AJPRequestHandler.java:187)
at oracle.oc4j.network.ServerSocketReadHandler$SafeRunnable.run(ServerSocketReadHandler.java:260)
at oracle.oc4j.network.ServerSocketAcceptHandler.procClientSocket(ServerSocketAcceptHandler.java:230)
at oracle.oc4j.network.ServerSocketAcceptHandler.access$800(ServerSocketAcceptHandler.java:33)
at oracle.oc4j.network.ServerSocketAcceptHandler$AcceptHandlerHorse.run(ServerSocketAcceptHandler.java:831)
at com.evermind[Oracle Containers for J2EE 10g (10.1.3.0.0)].util.ReleasableResourcePooledExecutor$MyWorker.run(ReleasableResourcePooledExecutor.java:303)
at java.lang.Thread.run(Thread.java:595)

...

If you are running into the same issue after a Fresh Install or Release 12.0.x, please check the post-Installation checks logfile for the error :
...
ERROR
RW-50016: Error: - {0} was not created
...

Cause

The cause has been identified as JSP- or Class-File corruption under the $COMMON_TOP/_pages.

The corruption could be a result of a wrong CLASSPATH Setting in the Environment, as the System itself was not able to access the Classes.

Solution

To implement the solution, please execute the following steps :
1. Open a new Shell and source the APPS User Environment

2. Change into the $FND_TOP Patch directory
cd $FND_TOP/patch/115/bin
3. Compile the JSP files using following command :
perl ojspCompile.pl --compile --flush -p 2
4. Initiate the execution of Autoconfig on the DB- and the APPS_Tier(s)

5. Start the APPS-Tier(s) Services again and re-test the logon


R12 Rapidwiz Postinstall Steps Http, Login page, Virtual directory, JSP, Help Page Fails


Applies to:

Oracle Application Install - Version 12.0.1 and later    Linux x86

Symptoms


Following post install checks failed:

HTTP
Login page
Virtual Directory
JSP
Help Page

and following errors are seen in installation log files ($INST_TOP/logs/xxxxxxxx.log)

HTTP
-----

checking URL = http://<hostname>:<port>

RW-50015: Error: - HTTP Listener is not responding. The service might not have started on the port yet. Please check the service and use the retry button.


Help Page
----------

checking URL = http://<hostname>:<port>/OA_HTML/help

RW-50015: Error: - Help Page is not responding. The service might not have started on the port yet. Please check the service and use the retry button.


Virtual Directory
------------------

RW-50015: Error: - Http Server Virtual Directories is not responding. The service might not have started on the port yet. Please check the service and use the retry button.


JSP
----

checking URL = http://<hostname>:<port>/OA_HTML/jtfTestCookie.jsp

RW-50015: Error: - JSP is not responding. The service might not have started on the port yet. Please check the service and use the retry button.


Login Page
-----------

RW-50015: Error: - Login Page is not responding. The service might not have started on the port yet. Please check the service and use the retry button.
RW-10001: Rapidinstall wizard has detected that your configuration has errors. You must resolve these issues before continuing.

Http_server is shown as Down.

Cause

The cause of this problem has been identified and verified in an unpublished Bug 5682462.
The root cause for all the failures was that Apache (http) didn't start up because of not having latest RPMS as per install documents

After the install, when trying to start up the http server, this happens:
$./adapcctl.sh start
.
You are running adapcctl.sh version 120.6
.
Starting OPMN managed Oracle HTTP Server (OHS) instance ...
.
adapcctl.sh: exiting with status 204
.
adapcctl.sh: check the logfile
$INST_TOP/apps/CONTEXT_NAME/logs/appl/admin/log/adapcctl.txt for more information.

Solution

Action Plan-


Red Hat Enterprise Linux  RPM one by one--

glibc-2.3.4-2.25
glibc-common-2.3.4-2.25
binutils-2.15.92.0.2-21
compat-libstdc++-296-2.96-132.7.2
gcc-3.4.6-3
gcc-c++-3.4.6-3
libgcc-3.4.6-3
libstdc++-3.4.6-3
libstdc++-devel-3.4.6-3
openmotif21-2.1.30-11.RHEL4.6
pdksh-5.2.14-30.3
setarch-1.6-1
make-3.80-6.EL4
gnome-libs-1.4.1.2.90-44.1
sysstat-5.0.5-11.rhel4
compat-db-4.1.25-9
control-center-2.8.0-12.rhel4.5
xscreensaver-4.18-5.rhel4.11

Then rerun the rapidwiz


Temporary Action Plan

Remove the parameter -DSSL in the ohs_start() function as follows:
.
$/<?>ora/10.1.3/Apache/Apache/bin/apachectl:

$ diff apachectl.original apachectl.hacked

129c129,130
> eval ohs_start -DSSL "$args"
---
> # eval ohs_start -DSSL "$args"
> eval ohs_start "$args"

Restart Issue.

RW-50015



R12 Installation Post Steps: Apache Fails: RW-50015 Cannot Load Libphp4.So, Unresolved Symbols

Applies to:

Oracle Applications Manager - Version: 12.0.4 and later   [Release: 12 and later ]
HP-UX PA-RISC (64-bit)


Solution

To implement the solution, please execute the following steps:

1) check if the symbolic link ldflags in the $IAS_ORACLE_HOME/lib32 is pointing to an existing library
if it is not the case, please change it in order to points to $IAS_ORACLE_HOME/lib
ldflags -> ../lib/ldflags
and recreate the libclntsh file by running the genclntsh in $IAS_ORACLE_HOME/bin.

2) relink the 10.1.3 home as follow

a. Set the env for 10.1.3 home using
$INST_TOP/ora/10.1.3/$CONTEXT_NAME.env
echo $ORACLE_HOME
b. Relink Binaries under 10.1.3 home using
a. cd 10.1.3_HOME/appsutil/clone
b. run adlnkweboh.sh
c. check the logfile under 10.1.3_HOME/install/make_$DATE.log
d. check 10.1.3_HOME/lib32/libclntsh.sl.10.1has new timestamp and created correctly

3) restart apache and retest the issue

ERROR 1396 (HY000): Operation ALTER USER failed for 'Mysql'@'%'

 This MySQL error — ERROR 1396 (HY000): Operation ALTER USER failed for 'Mysql'@'%' — means that MySQL cannot find the user ...