Skip to main content

Oracle 11g (FGA) Access Control List

After got API for sending SMS and developed packages we tried to send URL, but we faced below known error.

SQL> select alarmsender.pkg_sms_sender.send_sms('Ulfet','99450???????','test') from dual;  
 ORA-29273: HTTP request failed  
 ORA-06512: at "SYS.UTL_HTTP", line 1722  
 ORA-24247: network access denied by access control list (ACL)  
 ORA-06512: at line 1  

Starting Oracle 11g Oracle introduce FGA (Fine Grained Access) for using UTTL_HTTP, UTL_MAIL etc packages.

After reading Oracle notes, we need to create ACL and then assgin it.

Let`s check our db registery.

SQL> set linesize 400  
 SQL> col comp_name format a40  
 SQL> select comp_name, status from dba_registry;  
 COMP_NAME   STATUS  
 ---------------------------------------- --------------------------------------------  
 OWB   VALID  
 Oracle Application Express  VALID  
 Oracle Enterprise Manager  VALID  
 OLAP Catalog   VALID  
 Spatial   VALID  
 Oracle Multimedia  VALID  
 Oracle XML Database  VALID  
 Oracle Text   VALID  
 Oracle Expression Filter  VALID  
 Oracle Rules Manager  VALID  
 Oracle Workspace Manager  VALID  
 COMP_NAME   STATUS  
 ---------------------------------------- --------------------------------------------  
 Oracle Database Catalog Views  VALID  
 Oracle Database Packages and Types VALID  
 JServer JAVA Virtual Machine  VALID  
 Oracle XDK   VALID  
 Oracle Database Java Packages  VALID  
 OLAP Analytic Workspace  VALID  
 Oracle OLAP API   VALID  
 18 rows selected.  


--Creating new ACL

SQL> BEGIN  
   DBMS_NETWORK_ACL_ADMIN.CREATE_ACL (  
   acl     => 'smssend_nowsms.xml', --acl  
   description => 'Permissions to access http://10.10.9.15', --needed host  
   principal  => 'ALARMSENDER', --my user  
   is_grant   => TRUE,  
   privilege  => 'connect');  
   COMMIT;  
 EN 2  3  4  5  6  7  8  9 D;  
 / 10  
 PL/SQL procedure successfully completed.  
 SQL>


--Assign it

 SQL> BEGIN  
   DBMS_NETWORK_ACL_ADMIN.ASSIGN_ACL (  
   acl     => 'smssend_nowsms.xml',         
   host     => '10.10.9.15',  
   lower_port  => 8084,  
   upper_port  => 8084);   
   COMMIT;  
 END;  
 / 

PL/SQL procedure successfully completed.

SQL>

--Checking using select statement

SQL> SELECT * FROM TABLE(DBMS_NETWORK_ACL_UTILITY.DOMAINS('10.10.9.15'));  
 COLUMN_VALUE  
 10.10.9.15  
 10.10.9.*  
 10.10.*  
 10.*  
 *  


SQL> select acl , host , lower_port , upper_port from dba_network_acls;  
 ACL,HOST,LOWER_PORT,UPPER_PORT  
 /sys/acls/smssend_nowsms.xml,10.10.9.15,8084,8084  

SQL> select acl , principal , privilege , is_grant from dba_network_acl_privileges;  
 ACL,PRINCIPAL,PRIVILEGE,IS_GRANT  
 /sys/acls/smssend_nowsms.xml,ALARMSENDER,connect,true  



--Now try again
SQL> select alarmsender.pkg_sms_sender.send_sms('Ulfet','99450???????','test') from dual;
works fine!

Comments

Post a Comment

Popular posts from this blog

Fix ORA-01139: RESETLOGS option only valid after an incomplete database recovery

While shutting down my TEST database process was hanged. Then I had to use shutdown abort. But when I wanted to start database it did not open. SQL> select name from v$database; NAME --------- TEST SQL> shut abort; ORACLE instance shut down. SQL> startup mount ORACLE instance started. Total System Global Area 6597406720 bytes Fixed Size 2265664 bytes Variable Size 3204451776 bytes Database Buffers 3372220416 bytes Redo Buffers 18468864 bytes Database mounted. SQL> alter database open; alter database open * ERROR at line 1: ORA-03113: end-of-file on communication channel Process ID: 6552 Session ID: 191 Serial number: 3  What`s wrong?  SQL> alter database open resetlogs; ERROR:    ORA-03114: not connected to ORACLE    SQL> exit Disconnected from Oracle Database 11g Enterprise Edition Release 11.2.0.4.0 - 64bit Pr...

Fix: ORA-13639: The current operation was interrupted because it timed out.

Sometimes SQL Tuning Advisor interrupts cause time limit took more than defined. You have to analyze it or increase value. Here you can see increasing of value. Example result of sql select                  execution_name, advisor_name,                  to_char(execution_start,'dd-mon-yy hh:mi:ss') execution_start,                  to_char(execution_end,'dd-mon-yy hh:mi:ss') execution_end, status,error_message from dba_advisor_executions where task_name = 'SYS_AUTO_SQL_TUNING_TASK' order by execution_start; Check value of TIME_LIMIT`s parameter : SQL> column parameter_value for A35 SQL> select parameter_name, parameter_value from dba_advisor_parameters where task_name = 'SYS_AUTO_SQL_TUNING_TASK' and parameter_name in ('TIME_LIMIT', 'DEFAULT_EXECUTION_TYP...

How to fix ORA-26040: Data block was loaded using the NOLOGGING option

Today I faced with new ORA error. After solving I want to share this experience with yours. So, today 5`th datafile of my database was corrupted (/u01/app/oracle/oradata/ulfet_db/example01.dbf). After recover via RMAN I saw strange error. RMAN> recover datafile 5 block 443; Starting recover at 24-MAR-13 using channel ORA_DISK_1 channel ORA_DISK_1: restoring block(s) channel ORA_DISK_1: specifying block(s) to restore from backup set restoring blocks of datafile 00005 channel ORA_DISK_1: reading from backup piece /u01/app/oracle/flash_recovery_area/ULFET_DB/backupset/2013_03_24/o1_mf_nnndf_TAG20130324T223233_8nykp220_.bkp channel ORA_DISK_1: piece handle=/u01/app/oracle/flash_recovery_area/ULFET_DB/backupset/2013_03_24/o1_mf_nnndf_TAG20130324T223233_8nykp220_.bkp tag=TAG20130324T223233 channel ORA_DISK_1: restored block(s) from backup piece 1 channel ORA_DISK_1: block restore complete, elapsed time: 00:00:03 starting media recovery media recovery complete, elapsed ti...