Sunday, May 25, 2014

SSL - Secure Socket Layer

Introduction to SSL
SSL (Secure Sockets Layer) is protocol used for establishing secured connection over the internet between a client and a server.  Oracle WebLogic Server Supports SSL 3.0. Configuring SSL is an optional. You can avoid SSL in development environments, Oracle recommends to use SSL configurations for production environments.

SSL can be configured in two ways

  • One-Way SSL
  • Two-Way SSL

One-Way SSL
In One-Way SSL the server must present its certificate to the client, but vice versa is not required.
One-Way SSL is common on the Internet and used in B2C applications. B2C stands for Business to Customer. It refers to the transactions between businesses and their customers. Example: Amazon online bookstore.

Two-Way SSL
In this the server presents its certificate to the client and the client presents its certificate to the server.
It is used in B2B applications. B2B stands for Business to Business. It refers transactions between businesses such as between a manufacturer and a wholesaler, or between a wholesaler and a retailer.

Private Keys, Digital Certificates, and Trusted Certificate Authorities

SSL uses public key encryption technology for authentication. Private keys, digital certificates, and trusted certificate authorities establish and verify server identity.

Public-key cryptography require two separate keys, one of which is private and one of which is public. These two keys are mathematically linked. Public-key cryptography is also known as asymmetric cryptography as it uses two different keys.

Public Key
Public key is known to every one and it is used to

  • Encrypt plaintext (or)
  • Verify the digital signature of a certificate

Private Key
Private key is a secret key which is known to owner or server only and it is used to

  • Decrypt the cipher text or encrypted text
  • Create a digital signature
The public key is used to encrypt plaintext or to verify a digital signature; whereas the private key is used to decrypt ciphertext or to create a digital signature.

With public key encryption, a public key and a private key are generated for a server. The keys are related such that data encrypted with the public key can only be decrypted using the corresponding private key and vice versa.

Digital Certificate
It is also known as public key certificate is an electronic document which uses a digital signature to bind a public key with an identity. The identity could be anything. For example it could be represent a user, a device, a service or even a few lines of code.  The public key is embedded into a digital certificate with additional information describing the owner of the public key, such as name, street address, and e-mail address. A private key and digital certificate provide identity for the server.


The certificate authority (CA) takes the responsible to issue the certificates. The data embedded in a digital certificate is verified by a certificate authority and digitally signed with the certificate authority's digital certificate. Well-know certificate authorities include Verisign and Entrust.net. The trusted certificate authority (CA) certificate establishes trust for a certificate.

Trusted Certificate Authorities
The certificate authority (CA) takes the responsible to issue the certificates. The data embedded in a digital certificate is verified by a certificate authority and digitally signed with the certificate authority's digital certificate. Well-know certificate authorities include Verisign and Entrust.net. The trusted certificate authority (CA) certificate establishes trust for a certificate.

There are multiple CAs and they will be organized hierarchically. The top level would be the Root CA, which have a certificate signed by itself. All subordinate Certificate Authorities certificate should be requested to and signed by the root CA. Clients send the certificate signing request (CSR) to some subordinate CAs. They will sign the certificate with their private key and issue the following certificates.

  • Root Certificate
  • Chain Certificate
  • Server Signed Certificate


Root Certificate
A certificate authority can issue multiple certificates in the form of a tree structure. A root certificate is the top-most certificate of the tree, the private key of which is used to "sign" other certificates.

Chain Certificate
It is an intermediate certificate which forms the chain of trust. All certificates immediately below the root certificate inherit the trustworthiness of the root certificate. It is also known as L1C or Intermeidate Certificate. It provides the chain of trust between the signed certficate, the signing CA and one of the root CAs.

How to check which one is Root Certificate, Chain Certificate or Server Signed Certificate?
Every certificate includes the fields "Issued To" and "Issued By".
Server signed certificate includes the fields "Issued To" be the host name or domain name and "Issued By" will be Intermediate CA.
On the other hand an intermediate CA certificate will show different information in these two fields like "Issued To" be the intermediate CA and "Issued By" will be the Root CA or another Intermediate CA
On the other hand the Root CA certificate contains both "Issued To" and "Issued By" will be the same CA.


SSL Certificate Types

Regular SSL Certificates: The regular certificates can be installed on one domain.
Wildard SSL Certificates: If you want to have encrypted secure connection over several subdomains on a on a single domain name you need Wildcard SSL Certificates.
EV SSL Cerificates: The EV SSL certificate are issued to firms and companies which are legally presented. These certificates are used to build additional confidence in the company‘s customers

SSL Hand Shake
It enables the client and server to agree on the version of the SSL protocol to use,type of cryptographic algorithms to select, authenticate each other by exchanging and validating digital certificates.


Steps involved in the SSL handshake are as below:

  • The ssl handshake starts from the client with  "client hello" message that lists cryptographic information (the SSL version and the CipherSuites supported by the client.). The message also contains a random byte string that is used in subsequent computations. 
  • The server responds with a "server hello" message that contains the CipherSuite chosen by the server from the list provided by the SSL client, the session ID and another random byte string. The SSL server also sends its digital certificate. If the server requires a digital certificate for client authentication, the server sends a "client certificate request" 
  • The client verifies the digital signature on the SSL server's digital certificate and checks that the CipherSuite chosen by the server is acceptable.
  • The client sends the random byte string (pre-master secret) that enables both the client and the server to compute the secret key to be used for encrypting subsequent message data. The random byte string itself is encrypted with the server's public key.
  • If the server sent a "client certificate request", the SSL client sends a random byte string encrypted with the client's private key, together with the client's digital certificate
  • The client sends the server a "finished" message, which is encrypted with the secret key, indicating that the client part of the handshake is complete.
  • The server sends the SSL client a "finished" message, which is encrypted with the secret key, indicating that the server part of the handshake is complete.

Once handshake is done, creation of a SSL session between the client and the server, allowing the end-points to exchange application data securely, using the negotiated parameters for encryption and decryption.

Note:
The SSL  handshake involves compute-intensive public-key cryptography, adding significant delay to the connection establishment process.

Wednesday, May 21, 2014

Native Memory usage by PMAP command


Native Memory is an area which is usually used by the JVM for it’s internal operations and to execute the JNI codes. The JVM Uses Native Memory for Code Optimization and for loading the classes and libraries along with the intermediate code generation.

The Size of the Native Memory depends on the Architecture of the Operating System and the amount of memory which is already commited to the Java Heap. Native memory is an Process Area where the


  • JNI codes gets loaded or 
  • JVM Libraries gets loaded or 
  • Native Performance packs or
  • Proxy Modules gets loaded.


Some times you can see your java process is consuming more memory than you specified in your application (Startup scripts, Xmx) and your Unix or Linux box is running out of memory. Then you restart the process, and the same thing happens again after couple of weeks. If this type of things happened repeatedly, then your system is suffering from a potential memory leak.

You can use below commands to get the native memory consumption by a process.

  • pmap command on Solaris & Linux
  • svmon command on AIX


The native heap also known as C-Heap is storing objects such as MMAP file, other JVM and third party native code objects.

So if you start debugging why is the process consuming more memory than you allocated? Is it a bug or something else happening? First of all, part of it can definitely be the indication of native code leaking memory. And in most of the cases it is completely normal behaviour of the JVM.

PMAP
The pmap command reports the memory map of a process or processes. You can use below options for pmap.

       -x   extended     Show the extended format.
       -d   device         Show the device format.


$ pmap 8096
8096:   /u01/app/oracle/product/fmw/jrockit-jdk1.6.0_37-R28.2.5-4.1.0/bin/java -jrockit -Xms4096m -Xmx4096m -Dweblogic.log.RedirectStdoutToServerLogEnabled=true -server -XX:+UseStringCache -Djrockit.oomdiagnostics=true -Dweblogic.Name=apptest_soa1 -Djava.security.policy=/u01/app/oracle/product/fmw/wlserver_10.3/server/lib/weblogic.polic
0000000000400000     76K r-x--  /u01/app/oracle/product/fmw/jrockit-jdk1.6.0_37-R28.2.5-4.1.0/bin/java
0000000000612000      4K rw---  /u01/app/oracle/product/fmw/jrockit-jdk1.6.0_37-R28.2.5-4.1.0/bin/java
0000000002434000 341820K rw---    [ anon ]
0000000040066000      8K rwx--    [ anon ]
0000000044a06000     12K rw---    [ anon ]
00000000fe180000 4225536K rw---    [ anon ]
0000003992800000    112K r-x--  /lib64/ld-2.5.so
0000003992a1c000      4K r----  /lib64/ld-2.5.so
0000003993400000    520K r-x--  /lib64/libm-2.5.so
0000003993482000   2044K -----  /lib64/libm-2.5.so
0000003993681000      4K r----  /lib64/libm-2.5.so
0000003993682000      4K rw---  /lib64/libm-2.5.so
0000003993c00000      8K r-x--  /lib64/libdl-2.5.so
0000003994000000     88K r-x--  /lib64/libpthread-2.5.so
0000003994a08000      4K rw---  /lib64/librt-2.5.so
0000003996216000      8K rw---    [ anon ]
0000003997800000     68K r-x--  /lib64/libresolv-2.5.so
0000003997811000   2048K -----  /lib64/libresolv-2.5.so
0000003997a11000      4K r----  /lib64/libresolv-2.5.so
0000003997a12000      4K rw---  /lib64/libresolv-2.5.so
0000003997a13000      8K rw---    [ anon ]
000000399b000000     52K r-x--  /lib64/libgcc_s-4.1.2-20080825.so.1
000000399b00d000   2048K -----  /lib64/libgcc_s-4.1.2-20080825.so.1
000000399b20d000      4K rw---  /lib64/libgcc_s-4.1.2-20080825.so.1
00007f50309b4000     64K rw---    [ anon ]
00007f5030a44000  35472K rw---    [ anon ]
00007f5032cf8000     16K r-x--  /lib64/libnss_dns-2.5.so
00007f5032cfc000   2044K -----  /lib64/libnss_dns-2.5.so
.............
.............trimmed
.............
00007fffa0c0a000     80K rwx--    [ stack ]
00007fffa0c1e000     28K rw---    [ anon ]
00007fffa0c72000      4K r-x--    [ anon ]
ffffffffff600000      4K r-x--    [ anon ]
 total          6891548K

$pmap -x 8096
8096:   /u01/app/oracle/product/fmw/jrockit-jdk1.6.0_37-R28.2.5-4.1.0/bin/java -jrockit -Xms4096m -Xmx4096m -Dweblogic.log.RedirectStdoutToServerLogEnabled=true -server -XX:+UseStringCache -Djrockit.oomdiagnostics=true -Dweblogic.Name=apptest_soa1 -Djava.security.policy=/u01/app/oracle/product/fmw/wlserver_10.3/server/lib/weblogic.polic
Address           Kbytes     RSS   Dirty Mode   Mapping
0000000000400000      76      36       0 r-x--  java
0000000000612000       4       4       4 rw---  java
0000000002434000  341820  336172  336172 rw---    [ anon ]
000000399b000000      52      16       0 r-x--  libgcc_s-4.1.2-20080825.so.1
000000399b00d000    2048       0       0 -----  libgcc_s-4.1.2-20080825.so.1
000000399b20d000       4       4       4 rw---  libgcc_s-4.1.2-20080825.so.1
00007f50309b4000      64      64      64 rw---    [ anon ]
00007f5030a44000   35472   35472   35472 rw---    [ anon ]
00007f5032cf8000      16      16       0 r-x--  libnss_dns-2.5.so
00007f5032cfc000    2044       0       0 -----  libnss_dns-2.5.so
00007f5032efb000       4       4       4 r----  libnss_dns-2.5.so
000007f5035059000    1020       0       0 -----  librmi.so
00007f5035158000       4       4       4 rw---  librmi.so
00007f5035159000    3328    3328    3328 rw---    [ anon ]
00007f5035499000    1028      36       0 rw-s-  WLS_DIAGNOSTICS000000.DAT
00007f503559a000   34560   34560   34560 rw---    [ anon ]
00007f5037790000    5632    5632    5632 rw---    [ anon ]
..............
..............
..............
00007f5037d10000     396     172       0 r-x--  libMapUpgradeMgr.so
00007f50b8f62000     188     184     184 rw---  libjvm.so
00007f50b8f91000     696     684     684 rw---    [ anon ]
00007f50b904e000       8       8       8 rw---    [ anon ]
00007fffa0c0a000      80      32      32 rwx--    [ stack ]
00007fffa0c1e000      28      28      28 rw---    [ anon ]
00007fffa0c72000       4       4       0 r-x--    [ anon ]
ffffffffff600000       4       0       0 r-x--    [ anon ]
----------------  ------  ------  ------
total kB         6891548 5531992 5515296

$ pmap -d 8096
8096:   /u01/app/oracle/product/fmw/jrockit-jdk1.6.0_37-R28.2.5-4.1.0/bin/java -jrockit -Xms4096m -Xmx4096m -Dweblogic.log.RedirectStdoutToServerLogEnabled=true -server -XX:+UseStringCache -Djrockit.oomdiagnostics=true -Dweblogic.Name=apptest_soa1 -Djava.security.policy=/u01/app/oracle/product/fmw/wlserver_10.3/server/lib/weblogic.policy
Address           Kbytes Mode  Offset           Device    Mapping
0000000000400000      76 r-x-- 0000000000000000 000:00015 java
0000000000612000       4 rw--- 0000000000012000 000:00015 java
0000000002434000  341820 rw--- 0000000000000000 000:00000   [ anon ]

00007f5035058000       4 r-x-- 0000000000000000 000:00015 librmi.so
00007f5035059000    1020 ----- 0000000000001000 000:00015 librmi.so
00007f5035158000       4 rw--- 0000000000000000 000:00015 librmi.so
00007f5035159000    3328 rw--- 0000000000000000 000:00000   [ anon ]
00007f5035499000    1028 rw-s- 0000000000000000 000:00017 WLS_DIAGNOSTICS000000.DAT
00007f503559a000   34560 rw--- 0000000000000000 000:00000   [ anon ]
00007f5037790000    5632 rw--- 0000000000000000 000:00000   [ anon ]
00007f5037d10000     396 r-x-- 0000000000000000 000:00015 libMapUpgradeMgr.so
00007f5037d73000    1024 ----- 0000000000063000 000:00015 libMapUpgradeMgr.so
00007f5037e73000      56 rw--- 0000000000063000 000:00015 libMapUpgradeMgr.so
00007f5037e81000    1136 r-x-- 0000000000000000 000:00015 libXOM.so
...................
...................
...................

00007fffa0c1e000      28 rw--- 0000000000000000 000:00000   [ anon ]
00007fffa0c72000       4 r-x-- 0000000000000000 000:00000   [ anon ]
ffffffffff600000       4 r-x-- 0000000000000000 000:00000   [ anon ]
mapped: 6891548K    writeable/private: 5624952K    shared: 1300K

$ pmap -d 8096 | grep mapped
mapped: 6891548K    writeable/private: 5624952K    shared: 1300K


$ pmap -d 8096 | grep mapped | awk '{print $4}'
5624904K

The above commands gives the exact memory (private memory)  usage 5624904K (~5.36GB) a particular Java process even though the max heap size of the java process is 4GB.

If you want to know which process is consuming more native memory, write a script to get list of  all processes in the box and get the memory usage of each process by  above pmap command.

Gather the memory usage details on hourly basis or daily basis by putting this script in cronjob.
If the memory usage for a particular process is keep on increasing, it will indicate the native memory leak



     

Why is my Java process is taking more memory than the max heap (Xmx) size


Some times you can see your java process is consuming more memory than you specified in your application (Startup scripts, Xmx). This blog entry will give a short description of why the jvm process is consuming more memory.

Use the below command to get the your application java process id.

Example:
ps -ef | grep "java" | awk '{print $2}'
8096

$ ps aux | grep 8096
oracle 8096  5.5 22.4 6891548 5531984 ?     Sl   May10 573:10 /u01/app/oracle/product/fmw/jrockit-jdk1.6.0_37-R28.2.5-4.1.0/bin/java -jrockit -Xms4096m -Xmx4096m -Dweblogic.log.RedirectStdoutToServerLogEnabled=true -server -XX:+UseStringCache -Djrockit.oomdiagnostics=true -Dweblogic.Name=apptest_soa1 -Djava.security.policy=/u01/app/oracle/product/fmw/wlserver_10.3/server/lib/weblogic.polic

From the above stats, the actual size of physical memory (RAM) used by the java process (pid: 8096) (known as resident memory of the process) is 5531984KB (~5.27GB) even though the max heap size of the java process is 4GB.


Even by using top command, you will get the similar statistics.

$ top -p 8096
top - 15:16:28 up 234 days, 19:20,  2 users,  load average: 0.00, 0.00, 0.00
Tasks:   1 total,   0 running,   1 sleeping,   0 stopped,   0 zombie
Cpu(s):  0.0%us,  0.2%sy,  0.0%ni, 99.7%id,  0.0%wa,  0.0%hi,  0.0%si,  0.0%st
Mem:  24638424k total, 13084140k used, 11554284k free,   496232k buffers
Swap: 12578852k total,        0k used, 12578852k free,  5588616k cached

PID USER      PR  NI  VIRT  RES  SHR S %CPU %MEM    TIME+  COMMAND                                                                                                                                                          
8096 oracle  20   0 6730m 5.3g  16m S  1.7 22.5 572:25.40 java      

RES  which stand for Resident Set Size is the portion of a process's memory that is held in RAM.
VSZ which stand for Virtual Set Size is the portion of a process's virtual memory. And also you can observe that the memory utilization (RES) is 5.3GB which is more than your max heap 4GB.


The -Xmx switch which you have used during your start-up scripts is limiting the memory consumed by your application heap. Besides heap memory, you java application process uses other part of the memory. You are already aware of different Memory Spaces available as part of the Java Process.

Java Process Memory= Max Heap Memory + Max PermGeneration  Memory + Native Memory

Total memory utilization of the JVM process consist of more things than just the Java heap. The jvm process uses more memory for various reasons. Below are few examples:
  • JNI Code
  • JIT Optimization
  • Loaded libraries (including jar and class files)
  • Thread Stacks
  • Garbage Collection etc.,


Tuesday, May 20, 2014

Applying WebLogic Server Patches using BSU utility

BSU Stands for Bea Smart Update.  This utility is used to apply the WebLogic Server Patches.

Applying Patch Set Updates (PSUs)

The patch set updates (PSUs) come with a "README.txt" file that explains how to apply the patches. You must follow the the patch instructions before applying the WebLogic patches. The instructions looks similar as below:

Create cache_dir under $MW_HOME/utils/bsu if it doesn't exist. Unzip and Copy the WebLogic Server Patches under the above directory as below:

    $ mkdir -p $MW_HOME/utils/bsu/cache_dir
    $ cd $MW_HOME/utils/bsu/cache_dir
    $ unzip /tmp/p16199510_1036_Generic.zip

This zip file contains the patch jar (ex:ABCD.jar) file and patch catalog xml file. The encoded patch catalog, patch-catalog.xml, contains metadata about a patch and the patch dependencies and conflicts.

Apply the patch

    $ cd $MW_HOME/utils/bsu
    $ ./bsu.sh -install -patch_download_dir=$MW_HOME/utils/bsu/cache_dir -patchlist=ABCD -prod_dir=$WLS_HOME

If you get conflicts, you may have to remove previous patches, before attempting to apply the patch again.

    $ cd $MW_HOME/utils/bsu
    $ ./bsu.sh -remove -patchlist=XYZ1 -prod_dir=$WLS_HOME

    $ ./bsu.sh -install -patch_download_dir=$MW_HOME/utils/bsu/cache_dir -patchlist=ABCD -prod_dir=$WLS_HOME

After the patch is successfully applied, you can view the applied patches by using the below command

$ cd /u01/app/oracle/product/fmw/utils/bsu/
$ ./bsu.sh -prod_dir=/u01/app/oracle/product/fmw/wlserver_10.3 -view -status=applied
ProductName:       WebLogic Server
ProductVersion:    10.3 MP6
Components:        WebLogic Server/Core Application Server,WebLogic Server/Admi
                   nistration Console,WebLogic Server/Configuration Wizard and
                   Upgrade Framework,WebLogic Server/Web 2.0 HTTP Pub-Sub Serve
                   r,WebLogic Server/WebLogic SCA,WebLogic Server/WebLogic JDBC
                    Drivers,WebLogic Server/Third Party JDBC Drivers,WebLogic S
                   erver/WebLogic Server Clients,WebLogic Server/WebLogic Web S
                   erver Plugins,WebLogic Server/UDDI and Xquery Support,WebLog
                   ic Server/Evaluation Database,WebLogic Server/Workshop Code
                   Completion Support
BEAHome:           /u01/app/oracle/product/fmw
ProductHome:       /u01/app/oracle/product/fmw/wlserver_10.3
PatchSystemDir:    /u01/app/oracle/product/fmw/utils/bsu
PatchDir:          /u01/app/oracle/product/fmw/patch_wls1036
Profile:           Default
DownloadDir:       /u01/app/oracle/product/fmw/utils/bsu/cache_dir
JavaVersion:       1.6.0_29
JavaVendor:        Sun

After applying the patches, Restart the WebLogic Servers including Admin Server.

Applying a Single WebLogic Patch

$ ./bsu.sh -prod_dir=/u01/app/oracle/product/fmw/wlserver_10.3 -patchlist=RFP7  -verbose -install -log=RFP7_bsu.log
Checking for conflicts..
No conflict(s) detected

Starting installation of Patch ID: RFP7
Installing /u01/app/oracle/product/fmw/utils/bsu/cache_dir/RFP7.jar
Extracting /u01/app/oracle/product/fmw/patch_wls1036/patch_jars/BUG16199510_1036.jar
Updating /u01/app/oracle/product/fmw/patch_wls1036/profiles/default/sys_manifest_classpath/weblogic_patch.jar
Old manifest value: Class-Path=../../../patch_jars/BUG14390070_1036.jar ../../../patch_jars/BUG16362974_1036.jar ../../../patch_jars/BUG14763317_1036.jar ../../../patch_jars/BUG14182177_1036.jar ../../../patch_jars/BUG13572968_ons.jar ../../../patch_jars/BUG14742729_1036.jar ../../../patch_jars/BUG14482558_1036.jar ../../../patch_jars/BUG16358443_103603.jar ../../../patch_jars/BUG15917028_1036.jar ../../../patch_jars/BUG16250408_1036.jar ../../../patch_jars/BUG16180221_1036.jar ../../../patch_jars/BUG14390065_1036.jar ../../../patch_jars/BUG16582503_1036.jar ../../../patch_jars/BUG16741136_103603.jar ../../../patch_jars/BUG14261891_1036.jar ../../../patch_jars/BUG15865825_1036.jar ../../../patch_jars/BUG14809365_1036.jar ../../../patch_jars/BUG16104758_1036.jar ../../../patch_jars/BUG16810704_1036.jar ../../../patch_jars/BUG14736139_1036.jar ../../../patch_jars/com.bea.core.stax2_2.0.0.0_3-0-3.jar ../../../patch_jars/BUG14595754_1036.jar ../../../patch_jars/BUG14702608_1036.jar
New manifest value: Class-Path=../../../patch_jars/BUG16199510_1036.jar ../../../patch_jars/BUG14390070_1036.jar ../../../patch_jars/BUG16362974_1036.jar ../../../patch_jars/BUG14763317_1036.jar ../../../patch_jars/BUG14182177_1036.jar ../../../patch_jars/BUG13572968_ons.jar ../../../patch_jars/BUG14742729_1036.jar ../../../patch_jars/BUG14482558_1036.jar ../../../patch_jars/BUG16358443_103603.jar ../../../patch_jars/BUG15917028_1036.jar ../../../patch_jars/BUG16250408_1036.jar ../../../patch_jars/BUG16180221_1036.jar ../../../patch_jars/BUG14390065_1036.jar ../../../patch_jars/BUG16582503_1036.jar ../../../patch_jars/BUG16741136_103603.jar ../../../patch_jars/BUG14261891_1036.jar ../../../patch_jars/BUG15865825_1036.jar ../../../patch_jars/BUG14809365_1036.jar ../../../patch_jars/BUG16104758_1036.jar ../../../patch_jars/BUG16810704_1036.jar ../../../patch_jars/BUG14736139_1036.jar ../../../patch_jars/com.bea.core.stax2_2.0.0.0_3-0-3.jar ../../../patch_jars/BUG14595754_1036.jar ../../../patch_jars/BUG14702608_1036.jar
Result: Success

Applying a Multiple WebLogic Patches
You can apply all WebLogic patches at a time by using below command.

$ ./bsu.sh -prod_dir=/u01/app/oracle/product/fmw/wlserver_10.3 -patchlist=TWDG,QKPF,F6G7 -verbose -install -log=patches_bsu.log
Checking for conflicts......
No conflict(s) detected

Starting installation of Patch ID: TWDG
Installing /u01/app/oracle/product/fmw/utils/bsu/cache_dir/TWDG.jar
Extracting /u01/app/oracle/product/fmw/patch_wls1036/patch_jars/BUG14742729_1036.jar
Updating /u01/app/oracle/product/fmw/patch_wls1036/profiles/default/sys_manifest_classpath/weblogic_patch.jar
Old manifest value: Class-Path=../../../patch_jars/BUG14182177_1036.jar ../../../patch_jars/BUG14763317_1036.jar ../../../patch_jars/BUG16362974_1036.jar ../../../patch_jars/BUG16741136_103603.jar ../../../patch_jars/BUG15917028_1036.jar ../../../patch_jars/BUG14809365_1036.jar ../../../patch_jars/BUG14736139_1036.jar ../../../patch_jars/com.bea.core.stax2_2.0.0.0_3-0-3.jar ../../../patch_jars/BUG15865825_1036.jar ../../../patch_jars/BUG16199510_1036.jar
New manifest value: Class-Path=../../../patch_jars/BUG14742729_1036.jar ../../../patch_jars/BUG14182177_1036.jar ../../../patch_jars/BUG14763317_1036.jar ../../../patch_jars/BUG16362974_1036.jar ../../../patch_jars/BUG16741136_103603.jar ../../../patch_jars/BUG15917028_1036.jar ../../../patch_jars/BUG14809365_1036.jar ../../../patch_jars/BUG14736139_1036.jar ../../../patch_jars/com.bea.core.stax2_2.0.0.0_3-0-3.jar ../../../patch_jars/BUG15865825_1036.jar ../../../patch_jars/BUG16199510_1036.jar
Result: Success

Starting installation of Patch ID: QKPF
Installing /u01/app/oracle/product/fmw/utils/bsu/cache_dir/QKPF.jar
Extracting /u01/app/oracle/product/fmw/patch_wls1036/patch_jars/BUG14390065_1036.jar
Updating /u01/app/oracle/product/fmw/patch_wls1036/profiles/default/sys_manifest_classpath/weblogic_patch.jar
Old manifest value: Class-Path=../../../patch_jars/BUG14742729_1036.jar ../../../patch_jars/BUG14182177_1036.jar ../../../patch_jars/BUG14763317_1036.jar ../../../patch_jars/BUG16362974_1036.jar ../../../patch_jars/BUG16741136_103603.jar ../../../patch_jars/BUG15917028_1036.jar ../../../patch_jars/BUG14809365_1036.jar ../../../patch_jars/BUG14736139_1036.jar ../../../patch_jars/com.bea.core.stax2_2.0.0.0_3-0-3.jar ../../../patch_jars/BUG15865825_1036.jar ../../../patch_jars/BUG16199510_1036.jar
New manifest value: Class-Path=../../../patch_jars/BUG14390065_1036.jar ../../../patch_jars/BUG14742729_1036.jar ../../../patch_jars/BUG14182177_1036.jar ../../../patch_jars/BUG14763317_1036.jar ../../../patch_jars/BUG16362974_1036.jar ../../../patch_jars/BUG16741136_103603.jar ../../../patch_jars/BUG15917028_1036.jar ../../../patch_jars/BUG14809365_1036.jar ../../../patch_jars/BUG14736139_1036.jar ../../../patch_jars/com.bea.core.stax2_2.0.0.0_3-0-3.jar ../../../patch_jars/BUG15865825_1036.jar ../../../patch_jars/BUG16199510_1036.jar
Result: Success

Starting installation of Patch ID: F6G7
Installing /u01/app/oracle/product/fmw/utils/bsu/cache_dir/F6G7.jar
Extracting /u01/app/oracle/product/fmw/patch_wls1036/patch_jars/BUG14261891_1036.jar
Updating /u01/app/oracle/product/fmw/patch_wls1036/profiles/default/sys_manifest_classpath/weblogic_patch.jar
Old manifest value: Class-Path=../../../patch_jars/BUG14390065_1036.jar ../../../patch_jars/BUG14742729_1036.jar ../../../patch_jars/BUG14182177_1036.jar ../../../patch_jars/BUG14763317_1036.jar ../../../patch_jars/BUG16362974_1036.jar ../../../patch_jars/BUG16741136_103603.jar ../../../patch_jars/BUG15917028_1036.jar ../../../patch_jars/BUG14809365_1036.jar ../../../patch_jars/BUG14736139_1036.jar ../../../patch_jars/com.bea.core.stax2_2.0.0.0_3-0-3.jar ../../../patch_jars/BUG15865825_1036.jar ../../../patch_jars/BUG16199510_1036.jar
New manifest value: Class-Path=../../../patch_jars/BUG14261891_1036.jar ../../../patch_jars/BUG14390065_1036.jar ../../../patch_jars/BUG14742729_1036.jar ../../../patch_jars/BUG14182177_1036.jar ../../../patch_jars/BUG14763317_1036.jar ../../../patch_jars/BUG16362974_1036.jar ../../../patch_jars/BUG16741136_103603.jar ../../../patch_jars/BUG15917028_1036.jar ../../../patch_jars/BUG14809365_1036.jar ../../../patch_jars/BUG14736139_1036.jar ../../../patch_jars/com.bea.core.stax2_2.0.0.0_3-0-3.jar ../../../patch_jars/BUG15865825_1036.jar ../../../patch_jars/BUG16199510_1036.jar
Result: Success


$./bsu.sh -prod_dir=/u01/app/oracle/product/fmw/wlserver_10.3 -view -status=applied
ProductName:       WebLogic Server
ProductVersion:    10.3 MP6
Components:        WebLogic Server/Core Application Server,WebLogic Server/Admi
                   nistration Console,WebLogic Server/Configuration Wizard and
                   Upgrade Framework,WebLogic Server/Web 2.0 HTTP Pub-Sub Serve
                   r,WebLogic Server/WebLogic JDBC Drivers,WebLogic Server/Thir
                   d Party JDBC Drivers,WebLogic Server/WebLogic Server Clients
                   ,WebLogic Server/WebLogic Web Server Plugins,WebLogic Server
                   /UDDI and Xquery Support,WebLogic Server/Workshop Code Compl
                   etion Support
BEAHome:           /u01/app/oracle/product/fmw
ProductHome:       /u01/app/oracle/product/fmw/wlserver_10.3
PatchSystemDir:    /u01/app/oracle/product/fmw/utils/bsu
PatchDir:          /u01/app/oracle/product/fmw/patch_wls1036
Profile:           Default
DownloadDir:       /u01/app/oracle/product/fmw/utils/bsu/cache_dir
JavaVersion:       1.6.0_29
JavaVendor:        Sun


Patch ID:          TWDG (14742729)
Patch ID:          QKPF (14390065,13652966)
Patch ID:          F6G7 (14261891)

Note:
After applying the WebLogic Server Patches, Rstart all WebLogic Server Instances in the domain.

Thursday, May 15, 2014

bsu.sh failed with a Null Pointer Exception


Problem
The bsu utility is not able to locate weblogic product installations directory. Due to this, while running bsu.sh in WebLogic Server 10.3.6, it failed with a Null Pointer Exception.


Error Message
$ ./bsu.sh -view -prod_dir=/u01/app/oracle/product/fmw/wlserver_10.3 -status=applied
Exception in thread "Thread-0" java.lang.NullPointerExceptionnull

        at com.bea.plateng.patch.PatchTargetHelper.loadPatchProfiles(PatchTargetHelper.java:447)
        at com.bea.plateng.patch.PatchTarget.<init>(PatchTarget.java:268)
        at com.bea.plateng.patch.PatchTargetFactory.create(PatchTargetFactory.java:30)
        at com.bea.plateng.patch.ProductAliasTarget.constructPatchTargetList(ProductAliasTarget.java:88)
        at com.bea.plateng.patch.ProductAliasTarget.<init>(ProductAliasTarget.java:46)
        at com.bea.plateng.patch.ProductAliasTargetHelper.getProdAliasTargetList(ProductAliasTargetHelper.java:55)
        at com.bea.plateng.patch.ProductAliasTargetHelper.getAllHomeToProdAliasesTargetMap(ProductAliasTargetHelper.java:32)
        at com.bea.plateng.patch.ProductAliasTargetHelper.checkProfilesInProductAliases(ProductAliasTargetHelper.java:133)
        at com.bea.plateng.patch.Patch$1.run(Patch.java:376)
        at java.lang.Thread.run(Thread.java:662)

$ ./bsu.sh -report
java.lang.NullPointerException
Exception in thread "Thread-0" java.lang.NullPointerException
        at java.io.File.<init>(File.java:222)
        at com.bea.plateng.patch.PatchBundleTarget.getItFromWeblogicServerProperties(PatchBundleTarget.java:378)
        at com.bea.plateng.patch.PatchBundleTarget.<init>(PatchBundleTarget.java:306)
        at com.bea.plateng.patch.PatchTargetFactory.create(PatchTargetFactory.java:39)
        at com.bea.plateng.patch.ProductAliasTarget.constructPatchTargetList(ProductAliasTarget.java:69)
        at com.bea.plateng.patch.ProductAliasTarget.<init>(ProductAliasTarget.java:46)
        at com.bea.plateng.patch.ProductAliasTargetHelper.getProdAliasTargetList(ProductAliasTargetHelper.java:55)
        at com.bea.plateng.patch.ProductAliasTargetHelper.getAllHomeToProdAliasesTargetMap(ProductAliasTargetHelper.java:32)
        at com.bea.plateng.patch.ProductAliasTargetHelper.checkProfilesInProductAliases(ProductAliasTargetHelper.java:133)
        at com.bea.plateng.patch.Patch$1.run(Patch.java:376)
        at java.lang.Thread.run(Thread.java:662)

Cause
  • When there is an invalid weblogic product installation directory path present in the beahomelist file.
  • If the  beahomelist file is corrupted

Solution
If the bsu.sh throws the NullPointerException then perform the following steps:

  1. Rename the existing beahomelist.  Create a new beahomelist with just one entry of the current weblogic product installation directory path that is being used and try to run the bsu.sh
  2. If it fails, rename the beahomelist and launch the bsu in gui mode. You will get  Error prompt as "Unable to locate any supported product installations. Click OK to locate a BEA Home with valid target installations". See the below screenshot for the same.
 



Then click OK, and in the next prompt choose the BEA Home directory. Then it will create a new beahomelist file. Now run the bsu.sh to apply, view or remove the WebLogic patches

In Windows the beahomelist file is present under the ${SystemDrive}\bea folder
Ex: c:\bea

For Linux and UNIX - the beahomelist file is located under the ${HOME}/bea folder.
Ex:/home/<app user id>/bea

$ cat beahomelist
/u01/app/oracle/product/fmw

Once the above work around is done verify by executing the below command to ensure bsu.sh is working fine

$ cd /u01/app/oracle/product/fmw/utils/bsu/
$ ./bsu.sh -prod_dir=/u01/app/oracle/product/fmw/wlserver_10.3 -view -status=applied
ProductName:       WebLogic Server
ProductVersion:    10.3 MP6
Components:        WebLogic Server/Core Application Server,WebLogic Server/Admi
                   nistration Console,WebLogic Server/Configuration Wizard and
                   Upgrade Framework,WebLogic Server/Web 2.0 HTTP Pub-Sub Serve
                   r,WebLogic Server/WebLogic SCA,WebLogic Server/WebLogic JDBC
                    Drivers,WebLogic Server/Third Party JDBC Drivers,WebLogic S
                   erver/WebLogic Server Clients,WebLogic Server/WebLogic Web S
                   erver Plugins,WebLogic Server/UDDI and Xquery Support,WebLog
                   ic Server/Evaluation Database,WebLogic Server/Workshop Code
                   Completion Support
BEAHome:           /u01/app/oracle/product/fmw
ProductHome:       /u01/app/oracle/product/fmw/wlserver_10.3
PatchSystemDir:    /u01/app/oracle/product/fmw/utils/bsu
PatchDir:          /u01/app/oracle/product/fmw/patch_wls1036
Profile:           Default
DownloadDir:       /u01/app/oracle/product/fmw/utils/bsu/cache_dir
JavaVersion:       1.6.0_29
JavaVendor:        Sun