Tasks requiring ROOT for RAC DBA

Our team of networking and Applications through some growth headaches. We try to solve the permissions that should be in a RAC DBA. Our RAC DBA is responsible for the Oracle Clusterware, Oracle automatic storage
Management software and Oracle's RDBMS. The operating system, the server and the storage subsystem are the responsibility of the system administrator. We have the following environment:

Production and Test (CARS)
Oracle Enterprise Linux 5 2 update
Oracle Clusterware 11.2.0.2 - grid Infrastructure
Oracle ASM 11.2.0.2
Oracle Database 11.2.0.2 EA

Development (Single Instance)
Oracle Enterprise Linux 5 2 update
Oracle ASM 11.2.0.2 - grid Infrastructure
Oracle Database 11.2.0.2 EA


The RAC DBA, I identified areas requiring a ROOT of RAC and single Instance DB; However, I understand maybe more:

diagcollection.pl
-diagnostic tool for Oracle Clusterware, which may be requested by the Oracle Support
ocrconfig
-to fix the ocr configuration problem (add, replace and delete requires root)
srvctl change
-root required to change ip address
tar
-TAR Grid Infrastructure Directory structure preserving files with superuser
cluvfy
-cluvfy solve this scripts need to run as ROOT
-Some commands cluvfy under 11 GR 1 material only would go well for - post cfs check as ROOT in our last facility
Libraries of ASM
-ROOT required to install and configure the ASM library
fdisk - l
-It allows to see the attached disks that is relevant when the ASM disks are not mounted
/ etc/sysconfig/oracleasm
-oracleasm loading configuration file
/ usr/sbin/oracleasm
-to put at the disposal of the ASMLIB disks (scandisks etc..)
/ usr/sbin/asmtool
-due to the bug asm configuration tool
ASM cluster file system
-Some commands require ROOT (mounting etc..)
-acfsutil
var
-loading errors and oracleasm ohas could be connected here
cvuqdisk
-must be loaded to install new
root.sh
-script required for installation, updates and patches
oraInstRoot.sh
-required to run install script
rootupgrade.sh
-upgrade script
roothas.pl
-upgrade script
ocrcheck
-check the alteration of ocr
-check damaged portion requires ROOT
-Local registry of oracle
Grid infrastructure
-.runInstaller of the grid Infrastructure
-includes upgrades
ASM (asmca) Setup Wizard
-configuration of asm starts
-Bishop of flight for asm disks
ocrconfig
-configuration of ocr tool
-import of ocr
-export of ocr
-Local registry of oracle
ocrdump
-allows you to check the Save ocr file
-Local registry of oracle
opatch
-fixed grid control requires ROOT
crsctl
-Start and stop Oracle Clusterware, Oracle ASM, and database/Instance
-Restore disk to vote
-restore the ocr
-set log for debugging dynamic
-check periodically install
srvctl
-change applications (e.g. ip address change.)
-Add filesystem (acfs)


What other RAC DBA must have ROOT access to?

AllYourDataBase wrote:

In other words, you must either trust your DBA to not be malicious / inept and accept the fact that they have root access, or not give them sudo and form your system administrators to manage the grid infrastructure.

Agree.

On all databases, that I never managed, even in the era of mainframe, was my sysadmin/root access in order to exercise my DBA functions. Often service waiting too for sysadmin is not available. Similarly, the sysadmin also often held in a DBA when I'm on vacation or unavailable.

It is a partnership - both parties have the same goals and objectives. A stable and robust and functional environment.

Set up the walls between these parties on behalf of the so-called security policy? My point is that will be invariable cause more problems than what it addresses. And I've seen it in other departments - where a minor problem takes several days to resolve due to the wall (and distrust) between sysadmin and s/n, regardless of the amount of paperwork needed to get real results as the responsibility and accountability are ignored by both parties.

Tags: Database

Similar Questions

  • When it is run Sysprep and Capture task requires user name and password and won't restart

    MDT 2012

    I have a Windows 7 reference image.  I should be able to start on this OS, map a drive to the scripts directory and run litetouch and select my task "sysprep and capture.  When I run that he just ask a local username and pass and don't restart or ask where I want to put my image.

    I also run sysprep manually and PXE-started and ran the task but same result.  A few dialogs that require local administrators and passowrd but never a location to copy the image from.

    When I created the sysprep and capture task, she prays for a picture that is strange.  why he poses for a picture when the sysprep and capture task is intended to create an image.

    Your question is the best answer in the IT Pro Forum: http://social.technet.microsoft.com/Forums/en-US/w7itproinstall/threads

    J W Stuart: http://www.pagestart.com

  • connect by query, element need root for each line

    Hello

    I'm working on a hierarchical query using connection by front. Each node in the tree has two properties, a type and a sequence.

    The table that contains the hierarchy has 4 fields:
    element_type_from
    element_sequence_from
    element_type_to
    element_sequence_to

    Each child has a parent, a parent can have several childeren. For a map, the element_type_to and element_sequence_to fields are zero.

    To generate a tree, you can run:
    select element_type_to
    ,      element_sequence_to
    from   element_hierarchy
    start with element_type_from = [root_element_type]
           and element_sequence_from = [root_element_sequence]
    connect by prior element_type_to = element_type_from
           and prior element_sequence_to = element_sequence_from
    That works well... but... not only don't want child elements, I would like to return the sequence of element root for each child (in our table is a type of root element is always the same). There are several root elements and I want to create a list containing all the trees and each node in the tree must have its roots as well.

    There is the possibility to use sys_connect_by_path. This returns the root, but also the full path to the current child. It also returns a varchar2, requiring to be substr-ed and to_number-ed to get the sequence... not nice.

    warning, extremely ugly (but functional) code:
    select element_type_to
    ,      element_sequence_to
    ,      to_number(substr(sys_connect_by_path(element_sequence_from ,','),2,instr(sys_connect_by_path(element_sequence_from ,',') ||',',',',2)-2)) root_sequence
    from   element_hierarchy
    start with element_type_from = [root_element_type]
           and element_sequence_from = ( select [root_element_sequence] from all_root_elements )
    connect by prior element_type_to = element_type_from
           and prior element_sequence_to = element_sequence_from
    There must be something simple I'm missing here! Can you help me?

    Edit: Oops, the database version is 10.2.0.4.0

    CONNECT_BY_ROOT maybe?

  • I have to download updates certificates root for my XP laptop?

    I have to download updates certificates root for my XP laptop?

    Yes, you should.  Read the description of the update and it becomes clear why you should do it.

  • WINDOWS cannot OPEN THE FILE D:\Sources\Install.wim REQUIERED. Make sure that all required files for installation aare available and restart the installation. Error code: 0x8007000D,.

    IM TRYING to re - INSTALL WINDOWS VISTA ON MY T-6321 to the front door, BUT WHEN I INSERT THE DISC, AND INSTALL, a MESSAGE APPEARS SAYING: WINDOWS cannot OPEN THE FILE D:\Sources\Install.wim REQUIERED. Make sure that all required files for installation aare available and restart the installation. Error code: 0x8007000D, SHOULD ALL BE ON THE DISCALREADY?

    Hi JRCLNSIN100,

     

    Welcome to Microsoft Answers Forums.

    We would like to get some more information from you to help solve your problem. You better, please answer the following questions.

    ·         What is the disk you use to reinstall?

    ·         Is this a recovery or reinstalling the disc you are using?

    ·         When exactly do you get this error message?

    ·         What is the edition of Windows Vista, you try to install?

    ·         How old is the drive that you are using?

    ·         How are you starting the installation process?

    After researching the error 0x8007000D code is essentially due to file corruption and a problem with the drive itself.

    First check if you have scratches or dust on the disc and clean the surface and try again.

    To check if the disk is wrong, you will need to copy the contents of the DVD to the hard drive and try to install using that.

    To perform a flat installation of Windows Vista, follow these steps.

    Note The hard disk must have at least 3 GB of free space on the disk for the Windows Vista installation files. The hard disk must have at least 15 GB of additional disk space to install Windows Vista. For more information about system requirements for Windows Vista, see the Microsoft Web site at the following address:

    http://www.Microsoft.com/Windows/products/windowsvista/editions/SystemRequirements.mspx

    1. Insert the Windows Vista installation disc.
    2. Start Windows Explorer.
    3. In Windows Explorer, click to select the drive for the Windows Vista installation disc.
    4. On the Edit menu, click select all.
    5. On the Edit menu, click copy.
    6. Click to select the hard disk you want to contain the flat installation files.
    7. On the file menu, point to new, click the folder, type Windows Vista Setupand then press ENTER.
    8. Double-click the Windows Vista Setup program, and then click Paste on the Edit menu.
    9. Double-click Setup.exe, and then follow the instructions that appear.

    See the link below for more information on flat installation.

    How to perform a flat installation of Windows Vista

    http://support.Microsoft.com/kb/928902

    This problem can also occur if the firmware of the DVD drive is defective or obsolete.

    If the step above does not resolve the question suggests that you install the latest drivers for the DVD player on the computer.

    For more information please visit the link below.

    Error message when you try to install Windows Vista by using the DVD drive on the computer: "Windows cannot install required files".

    http://support.Microsoft.com/kb/930984

    Hope this information is useful.

    Let me know if it worked.

    All the best!

    Thanks and greetings

    Halima S - Microsoft technical support.

    Visit our Microsoft answers feedback Forum and let us know what you think.

  • VG202 and the VG204 requires licenses for CME?

    Hello

    VG202 and the VG204 requires licenses for CME?

    Reference number?

    Thank you

    Hello

    You men user license, the registration as EPSC ports? If so, let's say that Yes.

    When one of the FXS ports as SCCP that you use an instance of user, or one of the available ephone register, so if you're wondering if adding to the CMF as SCCP FXS ports, Yes, it will decrese the amount of phones that you have available to the general public.

    On the other hand, if you use the VG20X with h.323 or SIP to the CMF it will not use the ephone instances, so you shouldn't worry about this.

    --
    Jorge Armijo

    Do not forget to rate helpful responses and identify useful or correct answers.

  • lsnrctl reload for RAC

    Hi all

    I had a problem when using db CARS. I tried to get the status of the listener after I reload it. And I get the error

    [oracle@aie-45-215 ~] $ lsnrctl reload LISTENER

    LSNRCTL for Linux: Version 11.2.0.4.0 - Production June 1, 2015 19:33:57

    Copyright (c) 1991, 2013, Oracle.  All rights reserved.

    Connection to (ADDRESS = (PROTOCOL = tcp)(HOST=) (PORT = 1521))

    The command completed successfully

    [oracle@aie-45-215 ~] $ lsnrctl status

    LSNRCTL for Linux: Version 11.2.0.4.0 - Production June 1, 2015 19:29:16

    Copyright (c) 1991, 2013, Oracle.  All rights reserved.

    Connection to (ADDRESS = (PROTOCOL = tcp)(HOST=) (PORT = 1521))

    AMT-12541: TNS:no listener

    AMT-12560: TNS:protocol adapter error

    AMT-00511: no listener

    Linux error: 111: connection refused

    If I stop and restart the listener, then it works again.

    [oracle@aie-45-215 ~] srvctl stop listener $

    [oracle@aie-45-215 ~] $ srvctl start listener

    [oracle@aie-45-215 ~] $ lsnrctl status

    LSNRCTL for Linux: Version 11.2.0.4.0 - Production June 1, 2015 19:34:39

    Copyright (c) 1991, 2013, Oracle.  All rights reserved.

    Connection to (ADDRESS = (PROTOCOL = tcp)(HOST=) (PORT = 1521))

    STATUS of the LISTENER

    ------------------------

    Alias LISTENER

    Version TNSLSNR for Linux: Version 11.2.0.4.0 - Production

    Beginning June 1, 2015 19:34:33

    Uptime 0 days 0 h 0 min 6 sec

    Draw level off

    Security ON: OS Local Authentication

    SNMP OFF

    Parameter Listener of the /u01/app/11.2.0/grid/network/admin/listener.ora file

    The listener log file /U01/app/Oracle/diag/tnslsnr/AIE-45-215/listener/alert/log.XML

    Summary of endpoints listening...

    (DESCRIPTION = (ADDRESS = (PROTOCOL = ipc) (KEY = LISTENER)))

    (DESCRIPTION = (ADDRESS = (PROTOCOL = tcp)(HOST=10.80.45.215) (PORT = 1521)))

    (DESCRIPTION = (ADDRESS = (PROTOCOL = tcp)(HOST=10.80.45.225) (PORT = 1521)))

    Summary of services...

    "Rone" service has 1 instance (s).

    'Rone1' instance, State LOAN, has 1 operation for this service...

    Service 'roneXDB' has 1 instance (s).

    'Rone1' instance, State LOAN, has 1 operation for this service...

    The command completed successfully

    Here's what the listener.ora

    [oracle@aie-45-215 ~] $ cat /u01/app/11.2.0/grid/network/admin/listener.ora

    Listener = (Description = (ADDRESS_LIST = (Address = (Protocol = IPC) (Key = Listener))) # line added by Agent

    LISTENER_SCAN1 = (Description = (ADDRESS_LIST = (Address = (Protocol = IPC) (Key = LISTENER_SCAN1))) # line added by Agent

    ENABLE_GLOBAL_DYNAMIC_ENDPOINT_LISTENER_SCAN1 = ON # line added by Agent

    ENABLE_GLOBAL_DYNAMIC_ENDPOINT_LISTENER = ON # line added by Agent

    So "lsnrctl reload" should not used for RAC environment or I used by mistake?

    Liz

    Node VIP and public IP address of the node, the two IP will be exist for the listener node. Check the status of the listener without changing anything. You will see the listener with both the PPE

    $GRID_HOME/bin/lsnrctl State AUDITOR

  • Retrieve the tasks and events for a Virtual Machine

    Hello everyone.

    This question may seem trivial to some people here, but I cannot make it work: I would like to use VCO to retrieve the tasks and events for a specific virtual machine (IN parameter). Can someone help me to do?

    Best regards

    As I said, it must create a collector by using the createCollectorForTasks method in VcTaskManager.

    The parameter of this method is an instance of VcTaskFilterSpec, in which specify you the object to filter (in your case, the reference entity VM)

    You will get a VcTaskHistoryCollector which can only be traversed by using the methods readNextTasks and readPreviousTasks.

    // Get TaskManager service
    var sdktm = vm.sdkConnection.taskManager;
    
    // Create FilterSpec containing vm reference to filter
    var filter = new VcTaskFilterSpec();
    var spec = new VcTaskFilterSpecByEntity();
    spec.entity = vm.reference;
    spec.recursion = VcTaskFilterSpecRecursionOption.self;
    filter.entity = spec;
    
    // Create collector
    var collector = sdktm.createCollectorForTasks(filter);
    collector.resetCollector();
    
    // Browse all pages returned by collector (10 entries per page)
    var taskPage;
    while ((taskPage = collector.readPreviousTasks(10)) != null)
    {
        for each (var task in taskPage)
        {
            System.log("Task: " + task.name + " -> " + task.startTime);
        }
    }
    
  • 'Require SSL for client connections and Administrator display.

    Whence him 'require SSL for client connections and Administrator display' option under Display Configuration > global settings go into View 5.1? I don't see this because I do not have the right license or move it elsewhere?

    According to the documentation of view 5.0 (http://pubs.vmware.com/view-50/index.jsp?topic=/com.vmware.view.installation.doc/GUID-5706AA18-795A-4575-96EF-98CA3E19228C.html), the option should always be there.

    Thank you!

    In the login server access configuration display: > servers > server connection > edit one of the servers, and you should see the optoins

  • Initiation of a process task requiring entries using API

    Friends,

    I'd do it to trigger a process of IOM outside task. I got the key of millet and key process instance.

    But this task requires certain mandatory entries. Can you please let me know how to get these entries to the method

    provIntf.addProcessTaskInstance(mil,key,processinstancekey);

    tcFormInstanceOperationsIntf API to set the value of the process form with the help of the key of the Process Instance. And then you can call the addProcessTaskInstance method

  • Distribution of tasks between developers for my project ADF

    Dear all

    I installed the team productivity Center to manage subversion and distribute tasks among developers for my adf project, I managed to finish the subversion.

    But how do Team Center contains a facility to distribute tasks to the my developers, I think I need a JIRA repository to manage this problem, if yes kindly made me know how referential JIRA, otherwise let me know how to configure this installation in the center of the team's productivity.

    Thank you

    Hello

    information on how to set up JIRA can come from site is:

    http://www.atlassian.com/software/JIRA/

    He has an installation of the first time users guide: http://confluence.atlassian.com/display/JIRA043/Installing+JIRA+Standalone

    Note that PTC has no JIRA ships with a license for this.

    For all other documents, see the Web of PTC site: http://www.oracle.com/technetwork/developer-tools/tpc/overview/index.html

    Frank

  • Upgradation OS for RAC

    Hi guys... How is everything...

    I have the node CCR on Windows2003R2 Itaniam. I need to know is there any procedure for upgradation OS for RAC... I mean I'm going to the bottom of the Cluster & when the OS database places a gradation.

    Hello

    you need not stop the entire base.
    Upgrades of the OS can be in upgradeable mode (so one node after another), you must stop the instance and the clusterstack on the node, you perform the upgrade.

    Policies to support Oracle to launch of the CARS with different versions of an operating system within a period of 24 hours.
    In other words: after completing the upgrade of the first node you have 24 hours to what your other nodes must be at the same level of the new OS.

    Concerning

    Sebastian

  • What are the best free tools for Oracle DBA development?

    Hi, I have been for years production dba. I am familiar with a complete cycle of the installation of the database, configure, backup recovery, etc.

    Now my role will change soon for development dba. I have no problem to create instances. Then in the data modeling, data standardization, etc., what kind of tools I can use?

    Good suggestions, or documents that you can provide?

    Thanks in advance.

    Oracle SQL Developer Data Modeler and Oracle JDeveloper can be used for data modeling. Both of these tools are free. You can try and make your idea - they are free.
    We will be happy to receive your comments on Data Modeler.

    Philippe

  • ASM vs RAID for RAC 11 GR 2 environment

    Hello!
    We plan to install 11 GR 2 CARS with two-node Cluster on LINUX in our environment.
    Operating system: OEL 5.4
    In our material, we got two dell servers with 16 GB of RAM on each side more on SAN we have only 8 (173 GB) disk left for RAC Cluster configuration. I create the database (LIVE/UAT) on this Cluster Setup. Currently our Production DB dimensions are 6 GB and I assumed that for 5 years, that he's not going beyond 100 GB coming and I keep size UAT 15 GB difficulty without modification. So, how do get you the best performance from ASM using my all resources.

    My question:
    (1) who is the best solution for the ASM and RAID in our storage environment?
    (2) disc how do I create a group for the two databases (UAT/LIVE)?
    (3) records how much should I allocate in each group of disks with RAID Option or if all this suggests for LUNS, how to create LUNS on the disk I got?
    (4) I know oracle recommends two DATA DISK group & FRA is there any suggestion of CRS, REDO and TEMP FILE?
    Thank you for your Assintance.

    Nadège.

    My first question was: which RAID Option (0,1,5,0+1) I choose with ASM?

    Well, it does not matter for the DSO. At least in your configuration with 8 disks.
    RAID0is not an option - forget about it. RAID1 (or combined with more than two discs and a RAID0 superimposed making it a RAID 1 + 0) could be an option for the writing intensive databases. RAID5 is more for intensive reading due the RAID5 write hole but offers a capacity of 'more' at the expense of slower writing speed.

    I have recommended to the stick with RAID1 (mirroring two disks) and exporting to ASM rather than create a big RAID1 + 0 on all of your discs and exporting as a big Chuck of ASM storage for the management of. If you want to add storage lateron your perfect according to the recommendations of the Oracles have LUNS of equal size in ASM with two mirrored drives. If you create it large RAID 1 + 0 and lateron add two drives you have a 600 GB size logic unit number and a 170 GB size... it's a big shift.

    But if I create TWO group of disk then, is it advisable to provide two data bases (UAT/LIVE). ?

    Normally, there is a separation between UAT and P on the storage and the server level. In your case, it might be 'ok' to do everything in the same disk group. It depends especially of what database puts the load on the disk subsystem.

    --
    Ronny Egner
    My Blog: http://blog.ronnyegner-consulting.de

  • Study for the DBA Oracle 9i Oracle 11g Vs

    Hi evreybody, I would like to ask you about some...
    I start studying for Oracle DBA Jr in to run them, we see Oracle 9i and in my house, I would like to install a few Db Oracle por get practice and don't really know if installing Oracle 9i or you recommend me to install Oracle 11 g, I don't really know the difrence so I ask you to give me some advice on. Ahhh another question. I think that its really better equipped to use Oracle Unix platafor, like Solaris or something like Red Hat. I will be very thanksfull you can advise me about it too.
    Ahh, which by the way is maybe better to get some VmWare Oracle por practice without the real software?

    Marco,

    Well, I started with version 8 and I can say that the old version was much better for learning than current ones. But today, 10 / 11g (and same 9i) have tons of goodies added to them. I guess that, much has been said by colleagues on 9i memebers so I won't again. But I'd take the first of 10g OCP examz, then do the upgrade to 11g with a review. This is based on what the first, he'll give you certifications on both versions. Now, this isn't really a revolutionary right, but still, it's very nice to have certifications on several tracks. Second and most relevant oneis that 11g is, if not completely, for the most part uses 10g as its base to the ground. It would be a better understanding approach, the mechanisms put in place in 10g and than to see their improvements and additions added to 11g. In the past, I can say that the new curricula of functionality are always a bit better as the track completes on the end of learning too, you will get a lot of info. But I understand that time, cost, these factors all come between so think of these as well as any other, decide on your track. One solution is to start from 10 and than go to 11g.

    Just my 2 cents.

    HTH
    Aman...

Maybe you are looking for