Reparing SMPATCH DB

From Tom
Jump to: navigation, search

This documentation can be redistributed and/or modified under the terms of the GNU General Public License as published by the Free Software Foundation; either version 2, or (at your option) any later version.

Unless required by applicable law, this documentation is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details.

This documentation should not be used as a replacement for a valid Oracle service contract and/or an Oracle service engagement. Failure to follow Oracle guidelines for installation and/or maintenance could result in service/warranty issues with Oracle.

Use of this documentation is at your own risk!

--Tom Stevenson (talk) 17:11, 26 May 2015 (EDT)


First read Oracle document: https://support.oracle.com/CSP/main/article?cmd=show&type=NOT&doctype=PROBLEM&id=1288579.1

The following is based on the information from the above URL from May 9, 2011.

Download and unzip "new cert for smpatch 26/04/2011 (2.84 KB)" (link found in above document).  
This file is used in the "keytool" command below (the "-file" option.).  
A copy of this file can be located at "/wsu/cit/ecs/global/smpatch/verisign-chain-ca-2048bit.crt".

Execute the following commands:

smpatch set patchpro.patch.source=https://getupdates1.sun.com/

For the following two commands, "keytool" will prompt for a "keystore" password. Enter: 'changeit'

cd /wsu/cit/ecs/global/smpatch
keytool -import -trustcacerts -alias oracle.com -file verisign-chain-ca-2048bit.crt -keystore /usr/lib/patch/cacerts
keytool -list -v -alias oracle.com -keystore /usr/lib/patch/cacerts

You should get the following output from the "keytool -list" command above:

[root@bantapp2 ~]# keytool -list -v -alias oracle.com -keystore /usr/lib/patch/cacerts

Enter keystore password:  changeit
Alias name: oracle.com
Creation date: May 9, 2011
Entry type: trustedCertEntry

Owner: CN=VeriSign Class 3 International Server CA - G3, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US
Issuer: CN=VeriSign Class 3 Public Primary Certification Authority - G5, OU="(c) 2006 VeriSign, Inc. - For authorized use only", OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US
Serial number: 641be820ce020813f32d4d2d95d67e67
Valid from: Sun Feb 07 19:00:00 EST 2010 until: Fri Feb 07 18:59:59 EST 2020
Certificate fingerprints:
         MD5:  BA:B0:65:B4:3B:9C:E8:40:30:21:7D:C5:C6:CD:3F:EB
         SHA1: B1:8D:9D:19:56:69:BA:0F:78:29:51:75:66:C2:5F:42:2A:27:71:04

Re-register the server after updating the key above.

smpatch set patchpro.patch.source=https://getupdates.oracle.com/
sconadm register -c
smpatch analyze

--Tom Stevenson 14:22, 3 February 2012 (EST)

Help contents:

Reading: Go | Search | URL | Namespace | Page name | Section | Link | Backlinks | Piped link | Interwiki link | Redirect | Variable | Category | Special page
Tracking changes: Recent | (enhanced) | Related | Watching pages | Page history | Diff | User contributions | Edit summary | Minor edit | Patrolled edit
Logging in and preferences: Logging in | Preferences | User style
Editing: Overview | Wikitext | New page | List | Images/files | Image page | Special characters | Formula | Table | EasyTimeline | Inputbox | Template | (p. 2) | Renaming (moving) a page | Editing shortcuts | Talk page | Testing | Export | Import | rlc |