Tuesday, September 9, 2014

How to apply OWSM security in Oracle SOA BPEL

Service we expose need to secured when it is consumed by the client out of the organization. We can apply OWSM security to access the service by providing the username/password.

There are two ways mentioned below to apply OWSM policy to SOA service.
  • Apply OWSM policy during design time using Jdeveloper
  • Apply OWSM policy from  em console
Good info from:
http://eelzinga.wordpress.com/2010/05/14/oracle-soa-suite-11g-resequence-messages-in-mediator/

Example for Mediator Resequencing

http://eelzinga.wordpress.com/2010/05/14/oracle-soa-suite-11g-resequence-messages-in-mediator/

In realtime we use the resequnce for Order fulfillment. Where order id is used as group id and unique id is used as sequence id.

Order fulfillment usually has many stages each stage is passed to end service in sequential order by using resequencing option in mediator. Eventhough the status update the Order fulfillment we receive from the client is random we make it sequential.

Oracle SOA Registry Quick Notes


  1. OER: Acts as the single source of truth for information surrounding SOA assets and their dependencies.

Ie., for reusing the service we can search the OER as single trusted repository and we can also see all the dependencies for that composite in OER


2. OSR: Oracle Service Registry provides a 'DNS'-like reference for SOA runtime infrastructure to dynamically discover and bind to deployed services and end points.

Below resouce provide the detail of how to install OSR and how to harvest the composite to OSR from JDeveloper.
http://biemond.blogspot.co.uk/2009/12/using-oracle-service-registry-in-soa.html

Monday, September 8, 2014

Oracle SOA Oneway SSL Client configuration


Source: http://theheat.dk/blog/?p=474
With little modification I have posted below one way ssl configuration for Oracle SOA for my reference.
Oneway SSL configuration: 
Requirment is to setup the MW client to call the secured server through SSL. One way SSL means client will make sure that it is calling the correct server ie., server identification is enforced in oneway ssl. Eg is acceing Bank Online Site from broswer, we make sure that we  are calling the exact Bank website instead of fradulent one.

What Happens When a Client Encounters SSL

  1. The client requests that the server identify itself.
  2. The server sends the client a copy of its SSL Certificate.
  3. The client checks whether it trusts the SSL Certificate. If so, it sends a message to the server.
  4. The server sends back a digitally signed acknowledgement to start an SSL encrypted session.
  5. Encrypted data is shared between the browser and the server and https appears.

You have to configure 3 things in Oracle SOA EM:
1. Djavax.net.ssl.trustStore
Djavax.net.ssl.trustStore must point to your truststore in setDomainEnv.sh.
For example:
-Djavax.net.ssl.trustStore=/u01/app/oracle/domains/my_domain/keystores/soa_trust.jks
I don’t know why this is necessary since we also set this in the next step but it does not work if you don’t.
2. Set Keystore location in the SOA SuiteStart the FMW Control EM and navigate to the SOA Suites Managed Server. Right click and select SOA Administration and then Common Properties.Choose “More SOA Infra Advanced Configuration Properties” at the bottom.Press the “KeystoreLocation” link.Input the path to the keystore and press Apply.3. Set Keystore password in the SOA SuiteNavigate to Weblogic Domain and select your SOA Suite Domain. Right click and select Security and then Credentials.Press Create Map and input SOA. It must be SOA to work.Press Create Key and input:
  • Map: SOA
  • Key: KeystorePassword
  • User Name: KeystorePassword
  • Password: Password for the soa_trust.jks keystore.
It must be KeystorePassword for both Key and User Name to work.
Additional Point:Create map with name SOA, into this map create key with name KeystorePassword, user KeystorePassword and the password of the keystore. Create a 2nd Key KeyPassword, user KeyPassword with password and the keystore password.
TestWhen you start the Managed Server the .out log file should look like this:
INFO: SSLSocketFactoryManagerImpl.getKeystoreLocation SOA Keystore location: /u01/app/oracle/domains/my_domain/keystores/soa_trust.jks
INFO: SSLSocketFactoryManagerImpl.getKeystorePassword Obtained valid keystore password
INFO: SSLSocketFactoryManagerImpl.getKeyPassword Obtained null or empty key password
We have only input the password for the keystore not the key so it is OK that it cannot find this.
If you have input something wrong it looks like this:
INFO: SSLSocketFactoryManagerImpl.getKeystoreLocation SOA Keystore location: /u01/app/oracle/domains/my_domain/keystores/soa_trust.jks
INFO: SSLSocketFactoryManagerImpl.getKeystorePassword Obtained null or empty keystore password
INFO: SSLSocketFactoryManagerImpl.getKeyPassword Obtained null or empty key password
INFO: SSLSocketFactoryManagerImpl.getSSLSocketFactory Could not obtain keystore location or password
You can find more information here. This is for Two-way SSL but the steps are the same.

Wednesday, September 3, 2014

Oracle SOA JMS Error Quue Handling

Requirment:
Message is queue need to be deleted after 7 days and need to be archived.

Solution:
We have a Oracle SOA service which pushes the messages to the JMS Queue. Requirment is this message need to be deleted and archived after 7 days

Steps followed:
  1.  Add a time to like for the JMS Queue(InQueue) in BPEL JMS Apadtor of the JMS producer composite
     2.       Define the New Error Queue (ErrQueue) in EM console. 

     3.      For InQueue Select “Redirect” as expiration policy and select the “Error Destination” as the queue which is created in step 2.

By this way if the JMS message is older than 7 days(Or any configurable days) in InQueue it can be redirected/logged to new ErrQueue



Like to highlight the different expiration policy available for us to choose from.

None - Same as the Discard policy; expired messages are simply removed from the destination.
Discard - Removes expired messages from the messaging system. The removal is not logged and the message is not redirected to another location. If no value is defined for a given destination (i.e., None), then expired messages are discarded.
Log - Removes expired messages from the system and writes an entry to the server log file indicating that the messages have been removed from the system. The actual information that is logged is defined by the Expiration Logging Policy.
Redirect - Moves expired messages from their current location to the Error Destination defined for the destination. The message retains its body, and all of its properties. The message also retains all of its header fields, but with the following exceptions:
·         The destination for the message becomes the error destination.
·         All property overrides associated with the error destination are applied to the redirected message.
·         If there is no Time-To-Live Override value for the error destination, then the message receives a new Expiration Time of zero (indicating that it will not expire again).



Tuesday, September 2, 2014

Oracle SOA Transform multiple sources to the target using XSD Transformer

Oracle SOA Transform multiple sources to the target using XSD Transformer


Middleware is mainly used to call multiple webservices and transform the result from the multiple services and return back the result to the client. This is easily achived using Oracle Bpel XSD transformation
First we need to call different targetted services and assign the return values to variable. These variable can be selected as sources.

Example: 
Billing Service Output is stored in "Receive_Billing_Variable"
Credit Check output is stored in "REceive_Credit_Check_Variable"

These two variable can be selected as source in "Edit Transformer" by selecting the "+" symbol of source

Oracle SOA BPEL Transaction Quick Chat

Oracle BPEL we can set the transaction explicitly. If transaction is defined then that set of events will be working as unit. If there is failure in any event then that unit will be rolled back.

If we didn’t define the transaction explicitly then all the event will be working as single unit.


The table below summarises the transaction status when performing different activities.

Activity

Transaction Status in BPEL Process

Transaction Status in Target Process or Adapter

ReceiveNew TransactionN/A
Receive with Property “transaction=participate”Use Existing Transaction from CallerN/A
Invoke Synchronous ProcessUse Existing TransactionNew Transaction
Invoke Synchronous Process with Partner Link Property “transaction=participate”Use Existing TransactionUse Existing BPEL Transaction
Invoke Synchronous Process with Partner Link Property “idempotent=false”New TransactionNew Transaction
Invoke Synchronous Process with Partner Link Property “nonBlockingInvoke=true”New TransactionNew Transaction
Invoke Asynchronous ProcessUse Existing TransactionNew Transaction
Invoke Asynchronous Process with Partner Link Property “transaction=participate”Use Existing TransactionNew Transaction
Invoke Synchronous Process with Partner Link Property “idempotent=false”New TransactionNew Transaction
Wait < a couple of secondsUse Existing TransactionN/A
Wait > a couple of secondsNew TransactionN/A
FlowUse Existing Transaction