- Load OWSM schema in the target database by running irca script.
- Go to ORACLE_HOME/owsm/config/coreman directory, and put new database details in the following properties
- monitor.repository.* in monitor-config-installer.properties
- monitor.repository.* in collector-config-installer.properties
- Obfuscate the passwords in the above mentioned files using wsmadmin tool
ORACLE_HOME/owsm/bin/wsmadmin encodePasswords ORACLE_HOME/owsm/config/coreman/monitor-config-installer.properties monitor.repository.password - Redeploy the monitor application by running
ORACLE_HOME/owsm/bin/wsmadmin deploy monitor
Monday, June 9, 2008
How To - 10.1.3 OWSM: Changing database location for monitoring data
Labels: howto, owsm 10.1.3.1
How To - 10.1.3 OWSM: Changing database location for Log policy step
Anyways, if you want to relocate your SOAP message logging to another database, then follow these steps.
- Load OWSM schema in the target database by running irca script.
- Login to OWSM Control, go to Policy Management, and click on Edit button for the gateway or agent where you have the Log policy step.
- Modify cfluent.messagelog.db.* properties, click the save button, and finally click the commit link.
Labels: howto, owsm 10.1.3.1
Tuesday, June 3, 2008
FAQ - OWSM 10.1.3 : Does OWSM support FCF with Oracle RAC database?
OWSM supports connections to Oracle RAC database (which is typically used in HA situations) using the multi node syntax for entering jdbc url viz. host1:port^host2:port. But, it doesn't support fast connection failover (FCF) yet.
Note: OWSM uses its own connection pooling mechanism to connect to the database instead of using the application server connection pool.
Labels: faq, owsm 10.1.3.1
Wednesday, May 14, 2008
How To - 10.1.3 OWSM: Pass SAML token to the service after verification
The "Verify SAML token" policy step when executed removes the SAML token xml from the request message. This is inline with ws-security processing.
But, sometimes you may require the SAML token to be passed to the web service after it's verified by OWSM. This can be achieved by
Writing a custom policy step, and placing it immediately after the "Verify SAML token" step in the policy request pipeline. The custom step needs to extract the SAML token xml from message context and put it back into the request payload.
public IResult execute(IMessageContext ctx) throws Fault {
...
MessageContext context = (MessageContext) ctx;
ArrayList samlTokensList = context.getProperty("SAML_ASSERTIONS");
String samlToken = samlTokensList.get(0);
// now you can add this xml to either the SOAP body or a header element.
...
}
Labels: howto, owsm 10.1.3.1
Sunday, April 13, 2008
My session in RSA 2008 conference at San Francisco
I co-presented a session with Marc Chanliau on "Java and Web Services Security in Action" under the SOA track in RSA 2008 conference held at Moscone Center in San Francisco. Inspite of the session being at 8am on Wed morning, we got a full room of audience. Thanks to everyone who attended.
The presentation can be downloaded from here.
Labels: conference
Replay of Thomas Kurian's keynote at RSA conference 2008 in San Francisco
Thomas Kurian delivered keynote at RSA conference 2008 in San Francisco. He highlighted that customers are looking for holistic approach towards security especially in the 3 areas - Data Protection, Identity and Access Management, and Controls Enforcement. He was later joined by John Stewart, Chief Security Officer, Cisco Systems, who addressed how Cisco is using Oracle solutions to secure major portions of it's business.
See replay of the keynote here.
Labels: conference, Oracle
Friday, April 4, 2008
How To - 10.1.3 OWSM: Configure gateway to talk to failover enabled web services
It's a common use case to provide fail over for your web services. If OWSM Gateway is protecting such webservices then one of the following methods can be used for such configuration.
Method 1: Gateway -> Load Balancer (LBR) -> Web Services
This is the most commonly used approach of using a hardware load balancer between gateway and the web services. When performing service registration in the gateway, enter the load balancer endpoint.
Method 2: Gateway -> Oracle HTTP Server (OHS) -> Oracle Web Services
Here OHS acts as a software load balancer.
Method 3: Gateway -> Web Services
Gateway also has a built in mechanism to perform failover on the webservices by passing in bunch of failover urls. You can configure it at the time of service registration (page 2) or later on by editing service details, and clicking "Modify Protocol Parameters".
There are 3 relevant properties that need to be set.
- FailoverURLs - List of comma separated web service urls. Gateway communicates with the web service endpoint in the order listed.
- Attempts - Number of failed attempts before which Gateway tries to contact next url from the FailoverURLs list. The default value is 5, but you change it to 1 if you want to failover to next web service after first failed attempt.
- RetryInterval - Gateway waits for this interval (ms) before retrying the same url based on the number of attempts set.
Labels: howto, owsm 10.1.3.1





