Blocul de instalare/migrare Oracle 21c XE, terminat si validat pe VM 302. Kit de instalare (nou) scripts/build-client-kit.ps1 exporta CONTAFIN_ORACLE si FIRMANOUA de pe LXC 108 (PDB ROA2, nu ROA - ROA e productia ROA_CENTRAL), le aduce local prin cele trei hopuri container -> LXC -> host -> statie, le redenumeste la numele pe care le asteapta scripturile si le impacheteaza cu o copie a directorului roa-windows-setup. Citeste logul expdp si raporteaza cate firme are NOM_FIRME, ca sa nu plece din greseala datele unui client. roa-windows-setup/INSTALEAZA.cmd ruleaza pasii 01..08 fara "set /p", deci merge si prin SSH - RunAll.cmd nu poate fi rulat neinteractiv. Trateaza corect codul 5 de la pasul 03 si se opreste la prima eroare reala. Corectii 01-setup-database.ps1 nu mai scrie SQLNET.RECV_TIMEOUT / SEND_TIMEOUT in sqlnet.ora. Le hardcoda la 30 s, iar fisierul e citit si de impdp: in timpul unui import serverul poate lucra minute fara sa trimita un pachet, clientul murea cu ORA-12609 iar scriptul raporta esec pentru un import care se terminase cu bine pe server. Reprodus si reparat pe VM 302. 01-setup-database.ps1: Step 4c optional (-ResetSystemPassword) care curata EXPIRED(GRACE) pe SYSTEM in CDB root; ALTER PROFILE opreste expirarile viitoare dar nu reseteaza un cont deja intrat in gratie. uninstall-roa.sql: retry la DROP USER dupa KILL SESSION, plus un bloc final de verdict care numara ce a ramas si iese cu ORA-20900 daca baza nu e curata. Pana acum toate sectiunile prindeau exceptiile in WHEN OTHERS si scriptul tiparea "UNINSTALL COMPLETE" chiar si cand un user supravietuise, iar instalarea urmatoare dadea ORA-31684 in lant. 99-uninstall-roa.ps1 propaga codul de iesire. 08-post-install-config.ps1: Step 7b seteaza SMTP_OUT_SERVER si ACL-ul de retea pentru CONTAFIN_ORACLE. UTL_MAIL se instala si primea EXECUTE, adica destul cat sa compileze, dar nu si cat sa trimita. Privilegiul resolve nu accepta interval de porturi (ORA-24244), deci se acorda separat de connect. 07-verify-installation.ps1: sectiune noua care verifica prezenta lui FIRMANOUA.dmp in DMPDIR si o raporteaza ca eroare daca lipseste. Fara el, adaugarea unei firme noi pica in DBMS_DATAPUMP.ADD_FILE peste luni de la instalare, cand nimeni nu mai leaga eroarea de instalare. configure-profile.sql: antetul spune ca e unealta de remediere manuala, nu parte din flux; pas nou la final pentru CDB root. Documentatie README-ul roa-windows-setup descrie acum explicit cele doua scenarii - instalare pe curat si migrare - de unde se iau DMP-urile sablon, si capcana ORA-12609. Handoff-urile de sesiune au fost sterse; ce era durabil in ele a intrat in README-uri si in docs/diagnostic-spatiu-clienti.md. Validare pe VM 302: ciclu complet din kit, instalare pe curat, verificarea finala "[OK] All checks passed!". Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SzF1hf4aFS1tmJWpPMiwGp
151 lines
5.3 KiB
SQL
151 lines
5.3 KiB
SQL
-- ============================================================================
|
|
-- PASSWORD PROFILE CONFIGURATION
|
|
-- ============================================================================
|
|
-- Configures DEFAULT profile for no password expiration
|
|
-- CRITICAL for ROA application compatibility
|
|
--
|
|
-- This script disables all password restrictions to prevent:
|
|
-- - Password expiration issues during long-running installations
|
|
-- - Account lockouts from failed login attempts
|
|
-- - Password reuse restrictions
|
|
--
|
|
-- WARNING: This reduces security. For production environments, consider
|
|
-- creating a custom profile with appropriate settings.
|
|
--
|
|
-- ATENTIE - UNELTA DE REMEDIERE MANUALA, NU FACE PARTE DIN FLUXUL DE INSTALARE
|
|
-- ----------------------------------------------------------------------------
|
|
-- La o instalare normala NU rulezi scriptul asta: `01-setup-database.ps1` face
|
|
-- deja acelasi lucru automat, la Step 4 (in PDB) si Step 4b (in CDB root).
|
|
-- Foloseste-l doar cand `07-verify-installation.ps1` / `verify-objects.sql`
|
|
-- semnaleaza ca profilul DEFAULT are din nou limite de parola - de exemplu pe o
|
|
-- baza configurata inainte ca Step 4b sa existe, sau dupa un patch Oracle.
|
|
--
|
|
-- Usage:
|
|
-- sqlplus sys/<parola>@<host>:1521/XEPDB1 as sysdba @configure-profile.sql
|
|
--
|
|
-- Connect as: SYSDBA, pe PDB (XEPDB1), NU pe CDB root.
|
|
-- ============================================================================
|
|
|
|
SET ECHO OFF
|
|
SET FEEDBACK ON
|
|
SET SERVEROUTPUT ON
|
|
WHENEVER SQLERROR CONTINUE
|
|
|
|
PROMPT
|
|
PROMPT ========================================
|
|
PROMPT Configuring Password Profile
|
|
PROMPT ========================================
|
|
PROMPT
|
|
|
|
-- Show current profile settings
|
|
PROMPT Current DEFAULT profile settings:
|
|
SELECT resource_name, limit
|
|
FROM dba_profiles
|
|
WHERE profile = 'DEFAULT'
|
|
AND resource_type = 'PASSWORD'
|
|
ORDER BY resource_name;
|
|
|
|
PROMPT
|
|
PROMPT Modifying DEFAULT profile for ROA compatibility...
|
|
PROMPT
|
|
|
|
-- Disable password expiration
|
|
ALTER PROFILE DEFAULT LIMIT
|
|
PASSWORD_LIFE_TIME UNLIMITED
|
|
PASSWORD_REUSE_TIME UNLIMITED
|
|
PASSWORD_REUSE_MAX UNLIMITED
|
|
PASSWORD_VERIFY_FUNCTION NULL
|
|
PASSWORD_LOCK_TIME UNLIMITED
|
|
PASSWORD_GRACE_TIME UNLIMITED
|
|
FAILED_LOGIN_ATTEMPTS UNLIMITED;
|
|
|
|
PROMPT
|
|
PROMPT ========================================
|
|
PROMPT Profile Configuration Complete
|
|
PROMPT ========================================
|
|
PROMPT
|
|
|
|
-- Verify new settings
|
|
PROMPT New DEFAULT profile settings:
|
|
SELECT resource_name, limit
|
|
FROM dba_profiles
|
|
WHERE profile = 'DEFAULT'
|
|
AND resource_type = 'PASSWORD'
|
|
ORDER BY resource_name;
|
|
|
|
PROMPT
|
|
PROMPT WARNING: Password restrictions have been disabled.
|
|
PROMPT For production environments, consider creating a custom
|
|
PROMPT profile with appropriate security settings.
|
|
PROMPT
|
|
|
|
-- Unlock any locked accounts (optional)
|
|
PROMPT
|
|
PROMPT Unlocking ROA-related accounts if locked...
|
|
DECLARE
|
|
v_sql VARCHAR2(200);
|
|
BEGIN
|
|
FOR rec IN (SELECT username FROM dba_users
|
|
WHERE account_status LIKE '%LOCKED%'
|
|
AND username IN ('CONTAFIN_ORACLE', 'SYSTEM')) LOOP
|
|
v_sql := 'ALTER USER ' || rec.username || ' ACCOUNT UNLOCK';
|
|
EXECUTE IMMEDIATE v_sql;
|
|
DBMS_OUTPUT.PUT_LINE('Unlocked user: ' || rec.username);
|
|
END LOOP;
|
|
END;
|
|
/
|
|
|
|
-- Reset expired passwords (optional - requires manual password)
|
|
PROMPT
|
|
PROMPT If any accounts show EXPIRED status, reset their passwords:
|
|
SELECT username, account_status
|
|
FROM dba_users
|
|
WHERE username IN ('CONTAFIN_ORACLE', 'SYSTEM', 'SYS')
|
|
OR username LIKE 'FIRMA%'
|
|
OR username LIKE 'TEST%';
|
|
|
|
PROMPT
|
|
|
|
-- ============================================================================
|
|
-- ULTIMUL PAS: ACELASI PROFIL SI IN CDB ROOT
|
|
-- ============================================================================
|
|
-- ALTER PROFILE dintr-un PDB nu acopera CDB root: acolo DEFAULT ramane cu
|
|
-- PASSWORD_LIFE_TIME 180, deci SYSTEM din root expira la ~6 luni de la
|
|
-- instalare (ORA-28002, apoi ORA-28001) chiar daca in PDB totul e UNLIMITED.
|
|
--
|
|
-- DEFAULT din root e un profil LOCAL, deci clauza CONTAINER=ALL NU e valida
|
|
-- aici (ORA-65142). Se comuta containerul si se altereaza profilul de acolo.
|
|
--
|
|
-- Blocul e ULTIMUL din fisier intentionat: dupa ALTER SESSION SET CONTAINER
|
|
-- restul scriptului ar rula in root, nu in PDB.
|
|
-- Pe o baza non-CDB, ALTER SESSION esueaza inofensiv (WHENEVER SQLERROR
|
|
-- CONTINUE) si ALTER PROFILE se aplica pe singurul container existent.
|
|
PROMPT
|
|
PROMPT ========================================
|
|
PROMPT Applying the same profile in CDB root
|
|
PROMPT ========================================
|
|
PROMPT
|
|
|
|
ALTER SESSION SET CONTAINER = CDB$ROOT;
|
|
|
|
ALTER PROFILE DEFAULT LIMIT
|
|
PASSWORD_LIFE_TIME UNLIMITED
|
|
PASSWORD_GRACE_TIME UNLIMITED
|
|
PASSWORD_REUSE_TIME UNLIMITED
|
|
PASSWORD_REUSE_MAX UNLIMITED
|
|
FAILED_LOGIN_ATTEMPTS UNLIMITED
|
|
PASSWORD_LOCK_TIME UNLIMITED;
|
|
|
|
PROMPT
|
|
PROMPT Account status in CDB root:
|
|
SELECT username, account_status, expiry_date
|
|
FROM dba_users
|
|
WHERE username IN ('SYS', 'SYSTEM');
|
|
|
|
PROMPT
|
|
PROMPT NOTA: daca SYSTEM apare EXPIRED(GRACE), statusul NU se curata singur
|
|
PROMPT cand profilul devine UNLIMITED - cere o singura data:
|
|
PROMPT ALTER USER SYSTEM IDENTIFIED BY <parola>;
|
|
PROMPT (sau ruleaza 01-setup-database.ps1 -ResetSystemPassword)
|
|
PROMPT
|