Friday Nov 04, 2011

Suppress ADF version number in HTML pages


I was recently working with a partner that was undergoing a security hardening project with their ADF-based application. The issue was too much information was being returned by the ADF server in the HTML pages. Information that would be valuable to hackers or anyone profiling a system. Example of this information is here:








</body><!--Created by Oracle ADF (ADF Faces API -
11.1.1.4.0/ADF Faces Implementation - 11.1.1.4.0, RCF-revision: 39851 (branch:
faces-1003-11.1.1.4.0, plugins: 1.2.3), Trinidad-revision: 1051544 (branch:
1.2.12.3-branch, plugins: 1.2.10), build: adf-faces-rt_101221_0830, libNum:
0355 powered by JavaServer Faces API 1.2 Sun Sep 26 03:21:43 EDT 2010 
(1.2)), accessibility (mode:null, contrast:standard, size:medium),
skin:customSkin.desktop (CustomSkin)--></html>
















This is controlled by a parameter in web.xml


  <context-param>

    <description>Whether the 'Generated by...' comment at
the bottom of ADF Faces HTML pages should contain version number
information.</description>

   
<param-name>oracle.adf.view.rich.versionString.HIDDEN</param-name>

    <param-value>true</param-value>

  </context-param>





And viola! Special thanks to the ADF PM that hooked me up with the great information!


Chuck Speaks



http://twitter.com/ChuckAtOracle

Tuesday May 10, 2011

Oracle Fusion Middleware 11gR1 PS4 Released

The latest release of Oracle Fusion Middleware, to include WebLogic Server 10.3.5 is available for download here:

http://www.oracle.com/technetwork/middleware/fusion-middleware/downloads/index.html

For more information on this release please see Oracle Support article 1316076.1

****Note: This release of WebLogic fixes the multicast issue with servers configured for both IPv4 and IPv6 as posted in my previous blog.

Chuck Speaks
Oracle Platform Technology Solutions
http://twitter.com/ChuckAtOracle

Multicast Issues Anyone?

I spent enough time chasing this one down that I think it needs a blog entry.

The issue is this: There is a two-node WebLogic 10.3.4 cluster with an admin server and two managed servers (one on each physical machine). The O/S is RedHat running Unbreakable Kernel 2.6.32-100.0.19.el5. x86-64.

When trying to start the managed servers we received the following stack trace errors:

******************************

java.net.SocketException: Socket closed
at java.net.PlainDatagramSocketImpl.receive0(Native Method)
at java.net.PlainDatagramSocketImpl.receive(PlainDatagramSocketImpl.java:136)
at java.net.DatagramSocket.receive(DatagramSocket.java:725)
at weblogic.cluster.MulticastFragmentSocket.receive(MulticastFragmentSocket.java:239)
at weblogic.cluster.FragmentSocketWrapper.receive(FragmentSocketWrapper.java:98)
Truncated. see log file for complete stacktrace
>
java.net.SocketException: sendto failed: Invalid argument
at java.net.PlainDatagramSocketImpl.send(Native Method)
at java.net.DatagramSocket.send(DatagramSocket.java:625)
at weblogic.cluster.MulticastFragmentSocket.sendThrottled(MulticastFragmentSocket.java:206)
at weblogic.cluster.MulticastFragmentSocket.send(MulticastFragmentSocket.java:158)
at weblogic.cluster.FragmentSocketWrapper.send(FragmentSocketWrapper.java:91)
Truncated. see log file for complete stacktrace
********************

All the regular multicast test came back fine. The ultimate fix was to add the following to the startManagedServer.sh scripts for the MS's in JAVA_OPTIONS.

-Djava.net.preferIPv4Stack=true

After setting that everything started up just fine.

Hope this helps somebody out there.

Chuck Speaks
Oracle Platform Technology Services
http://twitter.com/ChuckatOracle

Tuesday Oct 28, 2008

Oracle Modernization Book Available

[Read More]

Friday Oct 24, 2008

Oracle Service Bus 10gR3 is PRODUCTION

[Read More]

Friday Oct 17, 2008

Oracle Service Bus 2-Day Training

[Read More]

Friday Jan 04, 2008

Oracle Fusion Middleware 11g Tech Preview

[Read More]
About

Chuck Speaks is a Senior Sales Consultant in the North American ISV/OEM Sales organization. A former member of Oracle Platform Technology Solutions (PTS), he is focused on the Oracle Fusion Middleware stack and database technologies as well as Fusion Applications architecture.

Search

Categories
Archives
« April 2014
SunMonTueWedThuFriSat
  
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
   
       
Today