Kerberos and Database control don't want to play

I've got a problem - it's been with Oracle support for over 2 weeks now and have had no reply.
Our infrastructure is 10.2.0.4 on Solaris. The requirement is having Kerberos enabled authentication for the database and management is via EM Database Control not Grid Control so each Database is managed individually and is self-contained.
Kerberos was installed and is working fine. You can get a ticket and login OK. What became obvious, however, that by enabling Kerberos, Database Control partially breaks. I know you can't have Kerberos EM accounts setup but that's not what we need to do.The agent just can not connect to the local database. I've done a bit of trouble-shooting and it's pretty obvious what the issue is but sorting it out is a bit of a problem.
Right, when you enable Kerberos, most of the settings are done in the sqlnet.ora file on the database server. The interesting setting here is the line :-
SQLNET.AUTHENTICATION_SERVICES= (BEQ,KERBEROS5)
Correct me if I'm right, but what this basically does is to say that any 'local' connections (eg sqlplus / as sysdba) just go in through the usual database/host group accounts (BEQ) whilst any other connections (sqlnet) go through Kerberos. This is where the problem looks as though it is. The EMAgent insists on using a full descriptor (host, port, sid etc..) and thus loops back through sqlnet and hits the Kerberos authentication brick wall and produces the standard Kerberos error :-
Thread-8 ERROR vpxoci: ORA-12638: Credential retrieval failed
vpxoci: Login 0xfdf08 failed, error=ORA-12638: Credential retrieval failed
TargetManager: Exception in computing dynamic properties of {db1.server1.acme.co.uk, oracle_database },SystemTablespaceNumber::ORA-12638: Credential retrieval failed
Thread-8 WARN vpxoci: OCI Error -- ErrorCode(12638): ORA-12638: Credential retrieval failed
The connect descriptor being used by the agent is :-
LOGIN = dbsnmp/<PW>@(DESCRIPTION=(ADDRESS=(PROTOCOL=TCP)(HOST=server1.acme.co.uk)(PORT=1521))(CONNECT_DATA=(SID=DB1)))
I've briefly edited the emoms.properties file to change the descriptor to IPC based and it still errors just the same. To duplicate this error we just created a normal database account "account1" identified internally and used these descriptors outside EM with sqlplus and it's just the same, so running :-
sqlplus account1/password@(DESCRIPTION=(ADDRESS=(PROTOCOL=TCP)(HOST=server1.acme.co.uk)(PORT=1521))(CONNECT_DATA=(SID=DB1)))
gives exactly the same credentials error and :-
# sqlplus account1/password
connects just fine. BTW, if you edit the original sqlnet.ora file and change (BEQ,KERBEROS5) to (BEQ) or even just remove the line, it all works fine but obviously disables Kerberos which isn't an option.
If someone has experienced this and knows a patch/fix or which configuration files to hand-edit I'd appreciate it.
Thks

user2664528 wrote:
Our infrastructure is 10.2.0.4 on Solaris. The requirement is having Kerberos enabled authentication for the database and management is via EM Database Control not Grid Control so each Database is managed individually and is self-contained.Sorry that I have no resolution to the larger problem. (I wonder whether a discussion in the Grid Control forum might be useful as the GC folk hide out there ... http://forums.oracle.com/forums/category.jspa?categoryID=70)
I am curious about the above statement since Grid Control does allow individual 'administrators' to be isolated to specific systems/configurations. That functionality is implemented using EE's Virtual Private Database capability and seems pretty solid to me.
What goes wrong when you use the isolation capability in Grid Control?

Similar Messages

  • There are certain albums and songs I don't want my children having access to in iTunes Match through their iPod and iPad.  Is there a way to control what songs are visible on different devices?

    There are certain albums and songs I don't want my children having access to in iTunes Match through their iPod and iPad.  Is there a way to control what songs are visible on different devices?

    No.

  • Want to use bluetooth speakers with volume control, don't want the iPad internal speaker sound, is this possible?

    want to use bluetooth speakers with volume control, don't want the sound at the iPad internal speakers, only on the external speakers.  is the possible? and how

    You can't downgrade the iOS.
    Take it to an Apple Store for evaluation.
    Make a Genius Bar Reservation
    http://www.apple.com/retail/geniusbar/
     Cheers, Tom

  • I recently downloaded Ios 7 and all the songs that i have purchased before but deleted off my itunes because i didn't want them showed up. I don't know how to delete them off my ipod and i really don't want them there

    I recently downloaded Ios 7 and all the songs that i have purchased before, but deleted off my itunes because i didn't want them, showed up. I don't know how to delete them off my ipod and i really don't want them there. Is there a way to get them off? The songs dont show up in my itunes on my computer, just on my ipod with a download button next to them. I don't want them there anymore because i don't like that kind of music anymore and i don't know how to get them to go away.

    There is a similar setting for Videos on that Settings screen, so if you leave that 'on' you may have similar happening in the Videos app

  • I've updated my phone and I've made a backup. but now it says I must enter my code to restore all my files and I haven't got this code. If I cancel the process or choose something else, all my stuff will be deleted, and I really don't want that.

    I've updated my phone and I've made a backup. but now it says I must enter my code to restore all my files and I haven't got this code. If I cancel the process or choose something else, all my stuff will be deleted, and I really don't want that.
    HELP ME PLEASE!!!

    If, for some reason, your backup got encrypted and you don't know the code, you'll have to set up your phone as new device and start all over again without the backup.
    Warning: If you encrypt an iPhone backup in iTunes and then forget your password, you will not be able to restore from backup and your data will be unrecoverable. If you forget the password, you can continue to back up and use the device, however you will not be able to restore the encrypted backup to any device without the password. You do not need to enter the password for your backup each time you back up or sync.
    If you cannot remember the password and want to start again, you must perform a full software restore and when iTunes prompts you to select the backup from which to restore, choose set up as a new device.
    If you can't get pass the lock screen, connect in recovery mode and restore the phone, you'll have the option to reset the lock secreen passcode.
    iOS: Unable to update or restore and iPhone and iPod touch: Wrong passcode results in red disabled screen
    If you cannot remember the passcode, you will need to restore your device using the computer with which you last synced it. This allows you to reset your passcode and resync the data from the device (or restore from a backup). If you restore on a different computer that was never synced with the device, you will be able to unlock the device for use and remove the passcode, but your data will not be present. Refer to Updating and restoring iPhone, iPad and iPod touch software.

  • Hi, I by accident bought a book in the IStore, but I could stop the download. So I didn´t receive the book yet. How can I cancel the purchase? I don´t want this book and so I don´t want to pay for it.

    Hi,
    I by accident bought a book in the IStore, but I stopped the download.
    So I didn´t receive the book yet.
    How can I cancel/reverse/countermand/recind the purchase?
    I don´t want this book and so I don´t want it and so I don´t want to pay for it.
    Thanks

    Hello cocoonfire,
    The best thing to do would be to contact iTunes Store support directly to see what can be done.
    How to report an issue with your iTunes Store, App Store, Mac App Store, or iBooks Store purchase
    http://support.apple.com/kb/ht1933
    To report an issue with your iTunes Store, App Store, Mac App Store, or iBooks Store purchase, follow these steps:
    Find the email receipt for your purchase.
    Click Report a Problem under the app that is having the issue.
    When prompted, enter the Apple ID and password you used to purchase the item, then click Report a Problem.
    Click Report a Problem next to the item you are having an issue with.
    From the Choose Problem dropdown menu, choose the appropriate issue.
    Follow the onscreen instructions and—if prompted—type a description of the problem into the text field.
    Click Submit to have your issue reviewed.
    Regards,
    Sterling

  • Are there ANY compatibility issues with Itunes 12.0.1 and Mavericks?  Don't want to download Yosemite.  Not hearing good things about it.

    Are there ANY compatibility issues with Itunes 12.0.1 and Mavericks?  Don't want to download Yosemite.  Not hearing good things about it.  I'm on Mavericks 10.9.5.

    one obstacle, quickly removed. thank you.
    nomenclature aside for a moment, 10.6.8 is correct but maybe more is necessary about the MacBook Pro: it is 'old': Identifier: 1.2, Intel Core Duo, 2.16 GHz, 1 Processor, L2 2 MB, RAM 2 GB.
    i hope that is enough to get an answer to this: is it unadvisable to update its OS; in other words, if i update to 10.9, will the machine be able to handle it, 'speedwise'?

  • I want to do a drag and drop but don't want it to be a test

    Hi,
    Any help would be greatly appreciated.
    I am using Captivate 7.
    I want to do a drag and drop but don't want it to be a test. This is for brain storming---not a test.
    None of the items to drag are correct or incorrect---they are just ideas. For example the 20 items could be different things you might put in your suitcase for vacation. There are no wrong answers---just your preference.
    There are 20 items to be dragged. There is only one drag target. All 20 items can go to that 1 drag target.
    I don't want the learner to have to drag all of the items to the target in order to finish. For example, the learner might leave 3 items out because the learner doesn't like those items. I want the learner to be able to hit submit (or any other button) at any time and go to the next slide immediately, not have to finish the drag and drop. Any ideas? 
    thanks!

    Also be aware that if you add a quiz to the project, that the drag and drop and quiz affect each other.
    In a way we have been cheated into thinking that is also a learning tool for repeated attempts. With a quiz in the project it does not work.
    I also tried it without the quiz. When learners now use it, the drag and drop will "hang" at times. EMBARRASING when a client phones you with a stuck learning session!!
    I have spent hours with the online Adobe dudes. It some or other "buG".
    "BUG" is IT code for "we designed something but did not test it well enough and now we pretend that it is some mysterious organic organism that is maliciously undermining our design"  

  • Hi ! Please my iphone is on the activation page and i can't do nothing, there is a sim card into but itune don't recognise it, and the phone don't want to activate. I tried everything, and before the reboot the iphone 3 was worked verry well. Please help

    Please my iphone is on the activation page and i can't do nothing, there is a sim card into but itune don't recognise it, and the phone don't want to activate. I tried everything, and before the reboot the iphone 3 was worked verry well. Please help me !

    Hello there, rebeccallouche.
    The following Knowledge Base article offers up some great steps and links to some additional information that is pertinent when having activation issues with your iPhone:
    iPhone: Troubleshooting activation issues
    http://support.apple.com/kb/ts3424
    Additionally, if the iPhone is not being recognized in iTunes this article will be useful as well:
    iOS: Device not recognized in iTunes for Windows
    http://support.apple.com/kb/ts1538
    Thanks for reaching out to Apple Support Communities.
    Cheers,
    Pedro.

  • I jailbreaked my iPhone 5 and now i don't want the jailbreak any more so i restored the iPhone without iTunes an now i don't wad then it turned itf off and now its stuck on the black screen with the loading sign. So please how can i turn my phone on again

    I jailbreaked my iPhone 5 and now i don't want the jailbreak any more so i restored the iphone without iTunes and then it turned it self off and now its stuck on the black screen with the loading sign. So please how can i turn my iPhone on again?

    I figured it out by pressing the home button and the off button but when i turn my phone on again it's not restored. And when i try to restore it with iTunes it has to update but i can't update my phone because it's jailbreaked but if i can't update it, it won't restore the phone.

  • I would like to download new Ps and Lr, but don't want to fwr involved with the cloud.  Is this possible?

    I need help.  I would like to download Ps CC and Lr, but don't want to get involved with the cloud, but would rather save on an external hard drive.  Is this possible?

    You can download the installers to your external drive.   However when you install them they will install Photoshop and LR on you boot drive. Adobe CC 2014 Direct Download Links: Creative Cloud 2014 Release | ProDesignTools

  • HT4461 How can I cancel a download once it starts? I started a download with software update and decided I don't want it. I can pause the download, but I want to cancel entirely

    I started to download from software update and decided I don't want the items after the download had begun. How can I cancel a download? I don't want to just pause it, I want it to GO AWAY. I don't want it to resume any time ever.

    Hello cranky71,
    Unrelated, for anyone curious.     The following link may help to solve your problem.
    Mac App Store: Buy, download, and install apps
    Regards.  71.

  • Want to use parental controls to prevent myself from being able to be on certain websites, but i can't do so on my account because i'm the administrator and parental controls don't work with the administrator. How can i do this?

    go on certain websites, but i can't use parental controls on my account because i'm the administrator. How do i prevent access to websites?

    Thanks for the reply, BUT --- i can't fool myself. I can make all the other accounts i want, but i'll still be able to get into the admin account and therefore have access to the websites i don't want to have access to. Is there a way to block websites from ALL accounts?

  • Need Help with logins for SQLPLUS and Database Control

    Hi,
    I am new to Oracle. I installed "Oracle 10g Standard Version" on Win XP Pro. I have two questions regarding logins:
    (1)     After installing the software I used “dbca” to create a General Purpose database. At the end of the database creation I clicked on the Password Management button and I entered the password for SYS, SYSTEM and SCOTT. Then at the DOS command prompt I typed “SQLPLUS” and I can login as SCOTT and system, but I cannot as login as sysdba or sysoper. I get invalid username/password; logon denied message.
    But I can type “SQLPLUS /NOLOG” and then issue command “connect /as sysdba” and connect successfully as sysdba. Any idea why I cannot login sysdba or sysoper?
    (2)     When I go to windows Start->All Programs->Oracle - OraDb10g_home1 and select “Database Control”. A browser windows open up Database Control page. I cannot start Listener nor Start up a Database Instance. No matter whether I try SYS, SYSDBA, SYSOPER or SCOTT I cannot login. Any idea what is going on here?
    At the SQLPLUS command prompt if I enter “select status from v$instance;” I get status as “OPEN”.
    I am lost in Oracle world as a typical newbie. Many thanks in advance for any advice or pointers.
    Thanks
    Joe

    (1) Yes I can login if I type "sqlplus / as sysdba". Does that mean "sysdba" doesn't have a password?
    (2) when I run "emctl status dbconsole", I get a message saying "Environment variable ORACLE_SID not defined. Please define it." Can someone tell me what should I do?
    Thanks
    Joe

  • Reinstall WinXP and Palm Desktop - Don't Want to Lose Data ??

    Hi - searched for this in the forum, but didn't find any answers to my particular situation.  Just need to make absolutely certain I don't lose anything.
    Had to perform a format/reinstall of XP in December.  All up-to-date with service packs, etc.
    Now need to reinstall all my Palm stuff.
    I have all the files from my pre-format stored in a massive hard drive backup on a separate drive.
    My Centro is up-to-date as of December right before re-install; I have added some additional contacts/appts in the Centro since then.
    I have added some other data in Outlook 2003.
    Now, after I install the Palm desktop:
    How would I perform my first hot-sync?
    How do I get all my programs etc. back?  They are on the Centro right now - I don't want to lose them.  Some don't need to sync with computer and some do.  I can't afford to lose the data in these programs.  Will syncing with the phone (overwriting the desktop) allow my programs to stay the way they are on the Centro right now?
    Do I need to do something with the backup I made?  Is it even useful?
    Thanks in advance, and let me know if I'm not making sense.
    Melody
    Post relates to: Centro (Sprint)

    Hello!
    Fresh reinstall of Windows and Palm Desktop?  If so then all you need to do is plug the cable into the phone and hit the black button.  Palm Desktop will prompt create new user, just hit yes and your all set!  The hotsync process auto does a handheld overwrite sync style for this inital process.  If you already created the username in Palm Desktop that is the same as the Centro and have not yet hotsynced, rename that user to whatever and then do that sync.

Maybe you are looking for