Skip to main content

Job Role Separation (JRS) - RAC/Non-RAC environments


Job Role Separation (JRS) environment when deploying Oracle Grid Infrastructure is about having 2 different users for GI and DB installation.
In our scenario, we will have oracle for database installation and oraasm for Grid Infrastructure installation


Checklist for Job Role Separation (JRS) environment-


1. setuid bit - As root, change the file permissions of the oracle executable under the <Grid_Home>/bin and the <db_home>/bin,
to 6751
This is basically used on binaries when you would like OS user A to execute binary X which owned by user B preserving privileges of user B.

# cd <Grid_Home>/bin
# ls -l oracle
# chmod 6751 oracle
# ls -l oracle
-rwsr-s--x 1 grid oinstall 173515905 May 21 17:04 oracle

This is the setuid bit, and this must be set in order for users, other than "Grid" user to have it work.
(same applies to the db_home)
# cd <ORACLE_Home>/bin
# ls -l oracle
# chmod 6751 oracle
# ls -l oracle


2. Both users (oracle,oraasm) should be part of oinstall,asmdba,asmadmin groups.
We perform Grid Infrastructure installation first and when installing database, you will not be able to locate diskgroups.
This happens when oracle user is not secondary member of group which is assigned when configuring oracleasm.
In my scenario,
ls -ltr /dev/oracleasm/disks
total 0
brw-rw---- 1 oraasm asmadmin 253,  7 Aug 17 14:27 PLNDWSTG_DATA8

id oracle
uid=1006(oracle) gid=1013(oinstall) groups=1013(oinstall),1006(dbaplstg),1015(asmdba),1017(racdb)

id oraasm
uid=1002(oraasm) gid=1013(oinstall) groups=1013(oinstall),1002(asmadmin),1003(dbadvetl),1004(dbadvndw),1005(dbaplpub),1006(dbaplstg),1007(dbautpub),1008(dbautstg),1015(asmdba),1016(asmoper),1017(racdba)

We added asmadmin as secondary group to oracle user here.


3. Check for /etc/fstab to make sure grid home filesystem was mounted with option 'nosuid'

4. /etc/oracle/olr.loc must have correct GI home location.
This can occur during upgrades and we must make sure we have correct location under olr.loc for CRS_HOME and not old one.

5. Correct permissions for -
- GI_BASE
- GI_HOME

6. sqlnet.ora under GI_HOME should have below -
- DIAG_ADR_ENABLED=ON
- ORA_CLIENTTRACE_DIR to any valid directory that is having write permissions for oraasm in your GI_HOME
7. RDBMS_HOME/dbs/init.ora should only contain diskgroup name for db_create_online_log_dest_n.
To avoid below error, you can have init.ora parameter file checked to point to 'diskgroup name' and not complete path.


8. Both RDBMS_HOME/lib and GRID_HOME/lib must have correct permissions (755)


9. Check if CRS_HOME or ORA_CRS_HOME environments are set and make sure they are point to right GI_HOME. (typically during upgrades).

10. Last but not the least, we should check asm instance status using crsctl -
./crsct stat res -t


Reference notes -


ASM Diskgroup Can Not Be Shown When Creating Database With DBCA (Doc ID 1269734.1)
DBCA Does Not Display ASM Disk Groups In 11.2 (non-Windows environments) (Doc ID 1177483.1)
Remote Diagnostic Agent (RDA) - Getting Started (Doc ID 314422.1)
ORA-01261: Parameter Db_create_online_log_dest_1 Destination String Cannot Be Translated (Doc ID 2369000.1)




Comments

Popular posts from this blog

Logfile locations in EBS r12.1 and EBS r12.2

Startup/shutdown Apps tier services are started and stopped frequently and we must know logfiles when troubleshooting startup/shutdown issues. $INST_TOP/logs/appl/admin/log $INST_TOP/logs/appl/admin/log Apache OHS being part of opmn in r12.1 has continued in r12.2. Logfile locations for troubleshooting have been changed $INST_TOP/logs/ora/10.1.3/Apache/error_log[timestamp] $INST_TOP/logs/ora/10.1.3/opmn/HTTP_Server~1.log $IAS_ORACLE_HOME/instances/*/diagnostics/logs/OHS/*/*log*   OPMN Logfile locations for r12.1 and r12.2 have been changed $INST_TOP/logs/ora/10.1.3/opmn/opmn* $IAS_ORACLE_HOME/instances/*/diagnostics/logs/OPMN/opmn/* Oacore oacore in r12.1 is oc4j component and part of 10gAS. However, in r12.2, oacore is now a managed server for weblogic server $LOG_HOME/ora/10.1.3/j2ee/oacore/oacore*/ $LOG_HOME/ora/10.1.3/j2ee/oacore/oacore*/ $LOG_HOME/ora/10.1.3/opmn/oacore*/oacor...
Defragment workflow related tables in r12   References- 1.     How to Reorganize Workflow Tables? (Doc ID 388672.1) 2.     EBS Workflow (WF) Analyzer (Doc ID 1369938.1) Points to Remember –     Some workflow tables are associated to queues so that it is necessary to use the advance queuing instructions to reorganize them. For tables other than queue tables, please refer to different notes created by RDBMS team to reorganize tables. This activity depends on the RDBMS version.       Defragment tables in workflow r12 Verify tables are not associated to queues – SQL> select queue_table from dba_queue_tables   2   where queue_table like '%WF%'; QUEUE_TABLE ------------------------------ WF_CONTROL WF_DEFERRED WF_DEFERRED_TABLE_M WF_ERROR WF_IN WF_INBOUND_TABLE WF_JAVA_DEFERRED WF_JAVA_ERROR WF_JMS_IN WF_JMS_JMS_OUT WF_JMS_OUT WF_NOTIFICATION_IN WF...

Oracle EBS r12 migration to Solaris SPARC ** issues and solutions

Let me share a list of issues I faced when migrating a single node Oracle ebs r12.1.3 environment from Linux x86_64 to multinode Solaris SPARC machines. I have already shared ppt that was point of discussion before migration. Oracle ebs db platform migration Please note that below is set of issues and respective solutions while migration. I have not covered steps for migration in this post. I would also like to share list of references from metalink that were very handy during complete migration process. ·          Export/import process for 12.0 or 12.1 using 11gR1 or 11gR2 (Doc ID 741818.1) -           This document will be primarily used for database migration. ·          Application Tier Platform Migration with Oracle E-Business Suite Release 12 (Doc ID 438086.1) -           Apps tier will b...