Upgrading Oracle HTTP Server for Release 11i

The Oracle HTTP Server (OHS) 1.0.2.2 is based on Apache with Oracle mods, and serves as the web listener for the E-Business Suite Release 11i.  I suspect that one our best kept techstack secrets is that Oracle HTTP Server used in Apps 11i can -- and should -- be upgraded to the latest version available. 


11i Architecture:

We periodically release new versions of OHS to address performance, stability, and security issues.  These new versions are released in "rollup" patches and are certified with a minimum level of the ATG Family pack.  These rollup patches also include fixes for the Database Client, Mod_Plsql, and WebCache.

The latest patch available is Rollup 5, which can be downloaded via patch 4393827.  This patch can be used with TXK (FND) AUTOCONFIG TEMPLATE ROLLUP PATCH K (July 2005) Patch 4104924 and higher.  This rollup contains a large number of important fixes, too many fixes to list here comprehensively.  Here's an excerpt from the README:
  • 4393898 - SECURITY BUGS FIXED IN
    CPUJUL2005
  • 4199473 - SECURITY BUGS FIXED IN CPUAPR2005
  • 4049349 - SECURITY BUGS FIXED IN CPUJAN2005
  • 3811838 - SECURITY BUGS FIXED IN ALERT 68

  • 2169002 - HTTP 1.1 SUPPORT IN MOD_PROXY
  • 3267065 - SSL FAILS WITH SSLPROTOCOL WHEN ROLLUP4 APPLIED
  • 3351007 - ENABLING ROTATE LOGS INTERMITANTLY DELAYS SHUTDOWN
  • 3501964 - ALLOW EVENT.OCCURRED() TO NOT BE CALLED FROM SESSION.GETVALUE() IN
    APACHEJSERV
  • 3698788 - PROXY_HTTP.C CHANGES FOR SITEMINDER REVERSE PROXY SOLUTION
  • 3840903 - APPS:URL'S REWRITTEN WITH REWRITE NOT WORKING  ON NT (SAME RULES
    WORK ON UNIX)
  • 3477543 - SCRIPT_NAME AND PATH_INFO CANNOT HANDLE 0X5C IN THE URL

  • 3197147   - JVM CRASHES ON AN E-BIZ 11.5.9 ENVIRONMENT CONFIGURED TO
    USE SSL

  • 3889519   - UPLOAD IN SSL DOES NOT WORK WITH IE AFTER SECALERT 68 OR
    DB PATCH 9015
  • 2363247   - UNNECESSARY BITMAP PATH GENERATION AND BITMAP MEM
    ALLOCATION
  • 2379325   - WRONG COST CALCULATED AT KPRCDT
  • 2410612   - CONVENTIONAL EXPORT HAS WRONG DATA ON IMPORT
  • 2528524   - CLEAR TEXT PASSWORDS IN TRACE FILE
This patch is highly recommended for all E-Business Suite Release 11i customers.  Judging from the download statistics for this patch, it's likely that you don't have the latest release in your environment.  Given the inclusion of security-related fixes in this patch, I'd urge you to schedule an upgrade to this version at your earliest convenience.

For more details about Oracle HTTP Server rollup certifications with the E-Business Suite, see:
Related

Comments:

Are there any tricks to see if 4393827 has been applied to an instance? I see that it is not applied via adpatch.

Posted by Chris Bittakis on March 16, 2007 at 02:07 PM PDT #

Hi, Chris,No tricks from me, unfortunately.  If the Patch History in Oracle Application Manager doesn't list that patch as having been applied, chances are good that it hasn't been applied.Regards,Steven 

Posted by Steven Chan on March 19, 2007 at 05:07 AM PDT #

Post a Comment:
  • HTML Syntax: NOT allowed
About

Search

Categories
Archives
« April 2014
SunMonTueWedThuFriSat
  
1
4
5
6
7
8
9
10
11
12
13
14
19
20
21
23
24
25
26
27
28
29
30
   
       
Today