TLS 1.2, LDAPS and EPM 11.1.2.4

classic Classic list List threaded Threaded
2 messages Options
Reply | Threaded
Open this post in threaded view
|

TLS 1.2, LDAPS and EPM 11.1.2.4

TheMayor
Hi Erman,

Thank you for your detailed blog post on your setup in EPM 11.1.2.4

I had one question regarding the fact that you upgraded your JDK to 6_181. All the documentation that I've read online suggests that in order to use TLS 1.2, you need to have a minimum of Java 7 installed. Can you comment here on if version 6_181 is supported?

Thanks,
TheMayor
Reply | Threaded
Open this post in threaded view
|

Re: TLS 1.2, LDAPS and EPM 11.1.2.4

ErmanArslansOracleBlog
Administrator
Hi,

That action in the blog post was done specifically for a LDAP-based TLS communication (LDAPS), and the refence MOS note was the following ->

SSL Enabled Windows 2016 MSAD External Directory from Essbase Server. ERROR: JAVAX.NAMING.COMMUNICATIONEXCEPTION: SIMPLE BIND FAILED: LDAPSERVER.COM:636 [ROOT EXCEPTION IS JAVA.NET.SOCKETEXCEPTION: CONNECTION RESET (Doc ID 2482392.1)

The document above suggest both JDK 6_181 (or later) or JDK 1.7..

So in order to be in the safe side, JDK 1.7 may be choosen here.
However, in our case this kind of an upgrade didn't solve our issue. (as you may already saw it in the blog post)

One last thing, Hyperion 11.1.2.4 doesn't support the TLS directly ( I mean TLS for HTTPS communication). We put an OHS 11.1.1.9 in front of it and offload the TLS/SSL work to that OS to do the trick as documented in ->

Does EPM to Support TLS 1.2 Communication via OHS? (Doc ID 2179810.1)

This is ofcourse for enabling/terminating the TLS communication at OHS level.
But, if you want a full SSL implementation in your EPM, I mean if you want to have SSL traffic between your HTTP Servers and Weblogic Server as well, then you will some extra work.

So, in that case we need to talk about a proxy OHS (11.1.1.9) in front of the original OHS of EPM+ WLS patching (for supporting TLS 1.2 in weblogic level) + JDK upgrade here (again for supporting TLS 1.2 in code level), and it is like an experimental configuration as it is not documented for TLS 1.2 :)

That mean, if you want to have a full TLS 1.2 implementation in your EPM, then you need to do extra work and it seems risky to me.

Check this community discussion ->

Enabling Full SSL deployment of Oracle EPM 11.1.2.4 environment to support TLS 1.1/1.2

Link : https://community.oracle.com/thread/4283550


On Mon, 27 Jan 2020 at 22:47, TheMayor [via Erman Arslan's Oracle Forum] <[hidden email]> wrote:
Hi Erman,

Thank you for your detailed blog post on your setup in EPM 11.1.2.4

I had one question regarding the fact that you upgraded your JDK to 6_181. All the documentation that I've read online suggests that in order to use TLS 1.2, you need to have a minimum of Java 7 installed. Can you comment here on if version 6_181 is supported?

Thanks,
TheMayor


If you reply to this email, your message will be added to the discussion below:
http://erman-arslan-s-oracle-forum.2340467.n4.nabble.com/TLS-1-2-LDAPS-and-EPM-11-1-2-4-tp8039.html
To start a new topic under Middleware / Weblogic, email [hidden email]
To unsubscribe from Erman Arslan's Oracle Forum, click here.
NAML


--

Erman Arslan, MBA 

Director -Database & Systems



Oracle Certified Expert, Certified Exadata and Linux Administrator

Author,  Practical Oracle E-Business Suite

Blog:     ermanarslan.blogspot.com

Forum:  http://ermanarslan.blogspot.com/p/forum.html


Mobile: +905334132140