Unable to Use EUSM Against Specific OUD Instance (Doc ID 1912789.1)

Last updated on JULY 02, 2017

Applies to:

Oracle Unified Directory - Version 11.1.2.2.0 and later
Information in this document applies to any platform.

Symptoms


EUSM commands fail on one node but work on the other node when attempting to setup mappings between Oracle 11.2.0.3.9 database and OUD 11.1.2.2.0 using EUSM.

OUD is running on a two-node cluster.

An example below of the error seen when attempting to list the existing mappings -

Exception in thread "main" java.lang.NullPointerException
at oracle.security.eus.esm.EUSRealmManager.checkRealmVersion(EUSRealmManager.java:474)
at oracle.security.eus.esm.EUSDomainManager.getDBSchemaMappings(EUSDomainManager.java:1010)
at oracle.security.eus.util.ESMdriver.listMappings(ESMdriver.java:400)
at oracle.security.eus.util.ESMdriver.main(ESMdriver.java:127)

This issue seems to be limited to EUSM commands run for the Oracle database.

The following search query works fine directly on the nodes.

ldapsearch -h bmioraids1 -p 6389 -D "cn=Directory Manager" -w ******** -b "cn=prdwh,cn=OracleContext,dc=example,dc=com" -s one-filter "(|(objectClass=orclDBEntryLevelMapping)(objectclass=orclDBSubtreeLevelMapping))" cn,orcldbdistinguishedname,orcldbnativeuser,objectclass

When the query is changed to use EUSM from the Oracle server to the OUD servers, the query fails 50% of the time.

eusm listMappings database_name="prdwh" realm_dn="dc=example,dc=com" ldap_host=ldap.example.com ldap_port=6389 ldap_user_dn="cn=directory manager" ldap_user_password="*********"

There is no orclversion listed in the ldapsearch output for the OUD instance that does not work -

[NG]
[oud@tea logs]$ ldapsearch -p 2389 -D "cn=Directory manager" -w dirmanager -b "dc=example,dc=com" -s base objectclass="*" orclversion
# extended LDIF
#
# LDAPv3
# base <dc=example,dc=com> with scope baseObject
# filter: objectclass=*
# requesting: orclversion
#

# example.com
dn: dc=example,dc=com
<==== there is NO orclVerision

But there is an orclversion listed from an ldapsearch on the OUD instance that is working.

Changes

 

Cause

Sign In with your My Oracle Support account

Don't have a My Oracle Support account? Click to get started

My Oracle Support provides customers with access to over a
Million Knowledge Articles and hundreds of Community platforms