Question about Project Lockdown

I've been reading through Arup Nanda's "Project Lockdown". I understand all of his rationals and procedures, but a few things leave me feeling a bit uneasy. Maybe it's just fear of the "unknown unknowns". In particular is the discussion on changing the unix access profiles for the oracle binaries. I have this uneasy feeling that if I were to implement those particular suggestions, it would end up biting me somewhere down the road.
Has anyone implemented all of the suggestions in this document? If so, what have been your experiences?

Arup Nanda_2 wrote:
Hi Ed,
Thanks Mark for pointing me out to this.
I have been using that for more than 8 or 9 years now, without any side effects. But as Emre Baransel reported that although he has been following that without any untoward effects, you should take every advise in the specific context of your environment. I have tried to put all caveats there; but there is no way for me to check all possible comobinations.
For instance, one of the advises is to remove executable permissions from extjob executable. If you are not using extrnal jobs from the database (99% of people don't), heeding that advise does nothing to your activities. But if you do external jobs, they are broken now. I have made that clear in the article; but I can't be sure if the reader will pay attention to that. But if you don't use external jobs, by changing the permissions you just closed a major vulnerability without applying the CPU patch, which may or may not close all the vulnerabilities.
Another is the case of nmb and nmo executables. If you are using Enterprise Manager to manage the O/S as well, then changing those executables will no longer allow you to do that. But if you don't do that particular activity (most don't), you again closed a major vulnerabillity without affecting your functionality.
For anyone who has ever authored anything, one thing is clear - the work is like broadcast, not point to point transmission. Even point-to-point. "If you explain something so clearly that no one can misunderstand, someone will".
It's not consulting which is situation specific. So, any work which is not prepared in context of a specific situation must be taken with that disclaimer - your mileage may vary. Understanding and testing is a must before committing the work.
Hope this helps.
ArupThanks for the response. Besides worrying about the "unknown unknowns" I also have a question about applying patches, especially the quarterly CPUs. Since, at some level, applying a patch is simply overlaying a specific file with a newer version, will this cause permissions to revert to default? Would we have to go through the process after applying a patch? I'll go back and re-read the original doc several more times to make sure I have a good grasp of what's going on here.

Similar Messages

  • Getting Started with CFBuilder - A Question About Project Settings

    Hello All,
    I'm just getting my feet wet with CFBuilder and giving it a spin after over a decade's worth of experience with Dreamweaver and I have a question about setting up my work environment.
    First of all, I have two computers that I mainly work from.  My home desktop computer, and a laptop for when I'm on the road.  I keep all of my web site project files syncronized between the two computers using Dropbox.
    I've noticed that when I create a new project in CFBuilder it stores a few files in my project root like ".project" and "settings.xml".  It looks like "settings.xml" stores information about which CFBuilder web server should be used for the project.  Unfortunately this messes things up for me a bit because on my desktop a web site project url might be:  http://desktop/myProject/ and on my laptop the project url could be http://laptop/myProject.
    The reason this isn't a problem in Dreamweaver is because dreamwevaer stores its configuration/preferences outside of my project folders so I can essentially define any testing server I want for both the desktop and laptop.
    Is there a way to configure CFBuilder to store project settings outside of the project folder?  Or does anyone have a suggestion for someone like me who syncronizes their project files from their laptop to their desktop?
    Thanks in advance for helping out a CFBuilder noob.

    I would recommend using a distributed version control system (DVCS) with a hosted service, such as using Git/Mercurial and Github/BitBucket/UnFuddle.  With Git, you can use a .ignore file to specify files/folders that you want to exclude from being stored in version control (I also exclude my CFBuilder project files from my repositories).  You would then sync your local Git repositories with your service of choice, and they would be accessible from any machine. 
    There are many advantages of using Git and a hosted service over just Dropbox:
    Each computer has a complete copy of the code repository, including all code changes over the history of your project.
    You store code modifications in "commits", or small entries in the DVCS.
    Commits can contain user-defined descriptions that help you identify what you did at each step of your development process
    You can roll back commits if you break something in your code.
    You can create "branches" of your code when you want to work on a specific feature of your application, and that branch is kept in isolation from other branches until you are ready to merge it back into the main production code branch.
    You can have public or private hosted repositories on the various services, enabling you to work with a team or participate in open-source development.
    There are Eclipse plugins available for CFBuilder that provide GUI tools for working with Git and hosted repositories (unless you are comfortable with using the command-line to do all your Git interactions).
    I don't think you can separate the project settings from the project in CFBuilder.

  • Question About Project File Location

    I was wondering how important is the project file location when it comes to performance?
    Currently, I store all of my adobe project files(AE, PRP, ENC) on my SSD along with my OS and applications.  
    Btw, I am familiar with the guidelines for disk usage, but cant seem to find anything that has covered this specific question.

    My C:\ is an SSD, and that is OS and programs only.  My D:\ is a fast WD 500 GB Raptor, and is reserved for Page file, My Documents. digital photos, and Video Projects.  E:\ and F:\ are both WD RE4 RAID0s, so all my drives are fast.
    I keep files which are frequently re-written, or replaced, off my SSD to avoid any risk of degradation due to repeated re-writing to the memory. 

  • Question about project manager on Flash CS4

    1 It seems that CS4 can not open flp, so how can I use CS4 to manager a project builded by CS3?
    2 if you choose a folder to found a new project in CS4, when you want to publish the whole project, you need to choose all the fla of that project...that will cost a lot of time if the project includes hundreds of files. But I didn't find out any quicker solution except check every fla by manpower. Is there any solution to publish a project faster?
    I am beginner of both CS3 and CS4, and thank you for anyone who can answer my questions.

    I'm planning on burning 1 master to a Taiyo Yuden White Inkjet Hub Printable 16X DVD-R disc.
    Make a disk image instead. It will be faster than a disc to disc copy.
    I have burnt tons of discs with the setting on "As fast as possible" with a 16x drive and discs. Never a problem. Some say that burning at a lower speed will increase reliability and decrease the chance of turning out a dud. Can't say that I have seen a difference.
    does it matter if I burn first and then print or should I print first and then burn?
    I would burn, check the disc and then print. If you do happen to get a bad batch, that's a lot of wasted time and ink if the discs don't work.

  • Question about project plan value and  availability control

    dear expert:
    I had built a project, and with CJ30, Allocated budget is 10000, in one of  WBS element.
    I created  a network and internal activities,
    when I  assiged a material component (Res + PR) and system can be saved even if the total plan cost value is crossing the budget value.(There is no PR created, now. )
    But, Budget checking is showing error message that budget is exceeded when I created any external service activity and crossing the budget value.(There is also no PR created, now. )
    My question is: what is the difference of the two plan value? Why one is relevant to the budget,and the other is not?
    Note:1) the tolerance limit with ++ (all activity groups), usage say 100% & action 3 (error) to the budget profile. The budget prifile is considered with only overall budget.
    2)In tables COSP, "value types" are all 01 (plan), but VRGNG field values ​​are different, components plan is: KPPE
    Service activities are: KPPP
    3)in CJ30 u2013 Extras>> Availability Control>> Analysis. I could see the following in red colour, these values system not considering into account.
    Entries in this color make no contribution to the assigned value!
    V: Value type not relevant ( Act./Plan/Stat.Act./Stat.Plan/Commt)
    D: Delivery
    S: Settlement to object with no budget control
    R: Revenue cost element
    C: Cost element is exempt cost element
    M: Minimum from actual + commitment and plan per order value update
    P: Plan value is not on apportioned order / network
    B: Plan Costing Single Position
    S: Funds Commitment in Balance
    Following is for material
    COSP 2011 01 8001110100     0000000200 KPPE D RMB             200,000.00  RMB   B
    Following is for service
    COSP 2011 01 8001110400  KPPP D RMB                                10.00  RMB
    regard
    mao jian

    Hi,
    Its not per item category. If  N or L sytem will check the budget if in your system if proper GL's are maintained in OBYC settings BSX and GBB > VBR nad cost elelemtns are created for them. for this you have to cosult with your MM / CO consultant.
    PS is highly inteergratd with CO and all values are updated per cost elements. If values are not updated in cost elements then budget chek wil not happen.
    In you case for material values may be updated in cost elements due to improper OBYC setting so budget check was not done.
    Chekc your OBYC setting and try to create material PR system will check for the budget.
    Check and confirm.
    regards,

  • Question about project "production"

    Once I complete a project I'm working on I'm planning on burning 1 master to a Taiyo Yuden White Inkjet Hub Printable 16X DVD-R disc. Once I burn the master I plan on using Toast to replicate all the discs to the same Taiyo Yuden media and then finally print the labels.
    My question is, can I burn this at 16x or does it run a risk of the disc not playing correctly? If so, what is the fastest speed I could use without running this risk?
    One last question, does it matter if I burn first and then print or should I print first and then burn?
    Thanks

    I'm planning on burning 1 master to a Taiyo Yuden White Inkjet Hub Printable 16X DVD-R disc.
    Make a disk image instead. It will be faster than a disc to disc copy.
    I have burnt tons of discs with the setting on "As fast as possible" with a 16x drive and discs. Never a problem. Some say that burning at a lower speed will increase reliability and decrease the chance of turning out a dud. Can't say that I have seen a difference.
    does it matter if I burn first and then print or should I print first and then burn?
    I would burn, check the disc and then print. If you do happen to get a bad batch, that's a lot of wasted time and ink if the discs don't work.

  • A simple question about Project

    Hello to everyone.
    I have too much picture in my Aperture library, and some of this picture are also in some project.
    Now i want delete this project for differene requirements, but obviously if i delete project,
    Aperture will delete all picture locate in library.
    This is a very big problem...
    I think can i export ma Project, delete it, and then reimporting image one by one, but in this case i will lost all adjustment, it's right?
    Anyone can help me?
    Many many thanks.
       michele.

    Michele,
    Don't worry about your English; it is better than my Italian.
    You have your organization backwards - "Projects" should be the smallest oganizational element, not the largest. In any case, no Project should hold more than 10,000 images.
    It is probably easiest if you think of Projects the way you would think of rolls of film, cards from your camera, or each day's photos. You can place these Projects inside of Folders which might be months, or years. Projects are the ONLY element that can actually contain images.
    In my particutlar case I use the following:
    Folders: Europe, Africa, North America, etc.
    Inside of these, Folders: UK, France, etc.
    Inside of these, Projects: London, Stonehenge, etc.
    Most of my Projects contain fewer than 100 images.
    To fix your problem, I would suggest that you create new, empty Projects that correspond to each day's shooting, or each trip you have taken, or some, similar event. Now move the images from your one big Project to the various smaller projects.
    Finally, you can group those Projects under Folders as needed.
    Albums are used to reference images, so they are useful for grouping all images of family members, cars, friends, regardless of where or when the original image was taken.
    I hope this is helpful.
    -- DiploStrat

  • Question about project management

    im a newbie of EBS. -_-, now learning PM, facing lots of question.
    can anyone provide the standard workflow and introduction for PM, example of implementing and configuring PM?
    how to define resource?
    thanks

    Hi,
    Can you please check whether you are assigned for project as resource and staffing manager. You need to check this authorisation at project defintion level.
    Please let us more on this if the problem is still there
    Pramod

  • A question about project settings..FCP 7

    I am using FCP 7 and I'm a little overwhelmed with the myriad of project settings options.
    I use a Canon T3i and film in full HD (1920x1080 i think).  All my footage I transcode in compressor to Apple ProRes 422 before importing to FCP projects.
    I installed another computer and reinstalled FCP 7 and lost my old templates and importing some footage, I get the red line indicating unrendered footage.
    Is there a standard setting that Compressor and FCP use to make it easy to just transcode, import, and edit?  I'd like all my projects to look the best possible in full HD and there's hundreds of preset project settings and I'm a little unfamiliar with all the options.
    Anyone have any quick tips, pointers, or thoughts?

    If you drop a clip into the timeline, it means the sequence settings don't match the clip settings.  Make a new sequence, add the clip. FCP should ask "do you want the sequence to match the clip settings?" Click YES. If you don't see that, you might need to trash your preferences...or it might be an older version that doesn't support ProRes formats (FCP 5.1 and earlier).
    Another way is to choose an EASY SETUP that matches your clip settings, and then make a new sequence.
    And your camera shoots 1920x1080p...not i.

  • Question about Project Duration

    I have an iMovie project that is 59:38:17, but after importing to iDVD it is now 62:27. I had the encoding set to "Best Performance" prior to the import. Will the project still look good now that it's over 60 minutes. Also, I was hoping to add a slideshow to the project.

    Best Performance works for 60 mins. or less of QT Playback. In practice it's slighlty less than 60 mins. if other items are added such as motion menus, slideshows, etc. all of which consume additional/available disc space.
    On the other hand I've see a post or two on this forum that claimed they were able to exceed the 60 min. mark by a few mins. and still maintain Best performance settings. Not sure exactly how they did it though...
    I personally try to stay under 57 mins. for Best Performance encoding...and maybe under 55 mins. or less if I plan to add a motion menu, slideshows, etc.
    Hope my reply is Helpful & clearly stated.

  • Question about dependent projects (and their libraries) in 11g-Oracle team?

    Hello everyone,
    I have a question about dependent projects. An example:
    In JDeveloper 10.1.3.x if you had for instance 2 projects (in a workspace): project 1 has one project library (for instance a log4j library) and project 2 is a very simple webapplication which is dependent on project 1. Project 2 has one class which makes use of log4j.
    This compiles fine, you can run project 2 in oc4j, and the libraries of project 1 (log4j) are added on the classpath and everything works fine. This is great for rapid testing as well as keeping management of libraries to a minimum (only one project where you would update a library e.g.)
    However in 11g this approach seems not to work at all anymore now that weblogic is used, not even when 'export library' is checked in project 1. The library is simply never exported at all - with a noclassdeffound error as result. Is this approach still possible (without having to define multiple deployment profiles), or is this a bug?
    Thanks!
    Martijn
    Edited by: MartijnR on Oct 27, 2008 7:57 AM

    Hi Ron,
    I've tried what you said, indeed in that .beabuild.txt when 'deploy by default' is checked it adds a line like: C:/JDeveloper/mywork/test2/lib/log4j-1.2.14.jar = test2-view-webapp/WEB-INF/lib/log4j-1.2.14.jar
    Which looks fine, except that /web-inf/lib/ is empty. I presume its a sort of mapping to say: Load it like it in WEB-INF/lib? This line is not there when the deploy by default is not checked.
    I modified the TestBean as follows (the method that references Log4j does it thru a Class.forName() now only):
    public String getHelloWorld() {
    try {
    Class clazz = Class.forName("org.apache.log4j.Logger");
    System.out.println(clazz.getName());
    catch(Exception e) {
    e.printStackTrace();
    return "Hello World";
    In both cases with or without line, it throws:
    java.lang.ClassNotFoundException: org.apache.log4j.Logger
         at weblogic.utils.classloaders.GenericClassLoader.findLocalClass(GenericClassLoader.java:283)
         at weblogic.utils.classloaders.GenericClassLoader.findClass(GenericClassLoader.java:256)
         at weblogic.utils.classloaders.ChangeAwareClassLoader.findClass(ChangeAwareClassLoader.java:54)
         at java.lang.ClassLoader.loadClass(ClassLoader.java:306)
         at java.lang.ClassLoader.loadClass(ClassLoader.java:251)
         at weblogic.utils.classloaders.GenericClassLoader.loadClass(GenericClassLoader.java:176)
         at weblogic.utils.classloaders.ChangeAwareClassLoader.loadClass(ChangeAwareClassLoader.java:42)
         at java.lang.ClassLoader.loadClassInternal(ClassLoader.java:319)
         at java.lang.Class.forName0(Native Method)
         at java.lang.Class.forName(Class.java:169)
         at nl.test.TestBean.getHelloWorld(TestBean.java:15)
    Secondly I added weblogic.xml with your suggested code, in the exploded war this results in a weblogic.xml which looks like:
    <?xml version = '1.0' encoding = 'windows-1252'?>
    <weblogic-web-app xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.bea.com/ns/weblogic/weblogic-web-app.xsd" xmlns="http://www.bea.com/ns/weblogic/weblogic-web-app">
    <container-descriptor>
    <prefer-web-inf-classes>true</prefer-web-inf-classes>
    </container-descriptor>
    <jsp-descriptor>
    <debug>true</debug>
    <working-dir>/C:/JDeveloper/mywork/test2/view/classes/.jsps</working-dir>
    <keepgenerated>true</keepgenerated>
    </jsp-descriptor>
    <library-ref>
    <library-name>jstl</library-name>
    <specification-version>1.2</specification-version>
    </library-ref>
    <library-ref>
    <library-name>jsf</library-name>
    <specification-version>1.2</specification-version>
    </library-ref>
    </weblogic-web-app>
    The only thing from me is that container-descriptor tag, the rest is added to it during the deployment. Unfortunately, it still produces the same error. :/ Any clue?

  • Question about subclips in a long project

    Hello all;
       I am editing a 1 hour long documentary in full HD with a lot of clips and so forth in it.  What I have been doing is for some segments creating a sequence in another project, rendering it and saving it as a H264 Full HD format, the same as the main project.  Then importing that rendered version into the main project instead of all the component parts.  This makes it harder if I want to change anything in that segment, but it cuts down on the load time of the main project, and seems to work OK.
      My question is - when I finally render the whole 1 hour project, will these included clips get degraded because they will be (I guess) rerendered?  Is there a better strategy for this?  Also, I'm doing the project in three 20 minute sections that I intend to simply run back to back in Encore when I'm done.  Is that likely to be a problem.
    Thanks in advance for any advice on this.
    Jim G.

    Hello again.
    I hope you don't mind if I ask you a follow up question about this issue of consolidating complex sequences into a rendered video file and then using that in a longer sequence.   On CS5 within the Export screen there is a button labeled, "Match Sequence Settings"  if I render a segment with that selected and import that into a longer sequence is that a problem too?  Or do I have to select something like AVI lossless?  Or should I avoid that as well? 
    Finally, for After Effects segments that I want to incorporate into Premier, I can use the Dynamic LInk thing, but it seems to mess with the color when I see it in Premiere.  Would it be OK to use the lossless renders from AE in the CS5 timeline?
    I apologize for pestering you with these questions.
    Thanks,  Jim Greeson

  • Question about elearning - OKP SAP Commercial Project Management

    Hi Gurus,
    i have a question about an e learning course which SAP offers-
    Course Name- OCPM10-
    OCPM10 - OKP SAP Commercial Project Management 1.0 | SAP Training and Certification Shop
    It's an e learning course for 20 hours, below are my questions-
    Since its an e-learning course, is it to be completed in a specified time (within 2-3 days) or we can have access to it throughout the year but duration of course is 20 hrs
    What kind of documentation is provided to me as part of this course.  

    1. C_TPLM22_05 - SAP Certified Solution Consultant PLM - Project Management with SAP ERP 2005   
    It includes SAP PLM 235 course material along with PLM 200, 210 220, 230,
    2. C_TPLM22_60 - SAP Certified Application Associate - Project Management with SAP ERP 6.0
    It is not including the PLM 235 course.
    This is the basic difference between  it.  IN Certification there are  6 -7 areas , in each of them you have to score more than 70 % , there many few multiple answer questions as well. Finally over score will come it should be higher than 70 %.  So, I ideally weight all the topics equally,
    With Regards
    Nitin P.

  • Question about the size of my project

    3.25 GB 20 or so tracks. a few plugins each a few software drums and synths. I getting overload warnings here and there. Not the I/O level the audio level. I look at the fear lilly Allen demo which has 50 tracks all sorts of plugins and a vid. 1.45 GB. I selected and deleted unused in audio bin and still the same. What am I missing. Logic Pro, IMAC 3.06 core 2 Duo 4 GB ram. Thanks Bill

    cowbell bill wrote:
    Still stumped, I've deleted all unused audio files, deleted all unused midi. Maybe a third of the project. I see nothing in the trash, Project size is still the same 3.25 GB. Bypassed all reverbs, And audio CPU level still maxing out in the red. What am I doing wrong. Thanks Bill
    When you speak about project size, do you mean the size of the project file itself? Or of the entire project folder?
    When you delete tracks or plugins from your project, you won't see anything in the trash, that is normal. Only when you delete an audio file from your disk +from within Logic+ you'll find that audio file in the trash.

  • Questions about using a PDF form online

    I have a client who wants to create an online version of a PDF form that they are currently using. I am currently trying to explain to them that this would be best done as an HTML web form, but I may not win this argument. I have only used PDFs for printed forms (either hand-written or using form fields) so I am not familiar with any problems that converting the form for use online would entail.
    When the 'Submit' button is pressed on the form, is there a way to redirect to another web page after the data is submitted? (i.e. does the PDF have access to it's outer 'environment'?)
    Are there any security issues submitting data using the PDF form as opposed to using a standard web form? (There may be sensitive data being submitted)
    I'm not sure how they plan to handle the data that is submitted, but there are several options in the submitForm parameters - I am assuming that using the HTML option would submit the data in the same format as a web form would. Am I correct here?
    Can the PDF be prevented from being downloaded or printed? This form should only be used to submit data to their server, not as a printed form.
    Are there any other 'gotchas' that I need to look out for? Does anyone have a recommendation for a site which contains any tutorials or guidelines for using PDF forms online?

    Thanks for the information.
    Yes, I agree that there is less reason for it to be a PDF form (Actually, no real reason other than the original form already exists in PDF), but I am unfortunately in the position that my input in this project is not necessarily being considered (my company is following direct -and inconsistent- directions from the client, and I have no contact with the client to ask questions about what their actual needs are). I have been told to give the client the 'Tomato' that they are asking for, even though they are describing an 'Apple'.
    The reason this form is not meant to be printed is that we have replaced the 'Signature' fields from the original form with checkboxes that the user must check to confirm they have 'signed' the document. If they are to print/fax/whatever the document, they should use the original form, not this one. And I am still trying to explain to them that this would be better served with an HTML web form, but I fear I am losing that battle.
    I have brought up the fact that it is not 100% guaranteed that Acrobat will be available in the browser, although I can only guess that it is less than likely that anyone will not have some sort of PDF viewer available to their browser.
    I will also mention that issues may arise if the file is not submitted from within the browser.

Maybe you are looking for