Pages

Thursday, May 2, 2019

EPM 11.1.2.4 Planning TLS 1.2 setup steps on AWS cloud environment



TLS protocol Parameters

olap.server.ssl.supportedProtocols=TLSv1.2

olap.server.ssl.supportedProtocols=TLSv1,TLSv1.1,TLSv1.2

-Dolap.server.ssl.supportedProtocols="TLSv1.2"

-Dweblogic.security.SSL.minimumProtocolVersion=TLSv1


JAVA_OPTIONS="${JAVA_OPTIONS} ${JAVA_PROPERTIES} -Djavax.net.ssl.keyStore=/cpapps/orepm/sslkeystore/keystore.jks -Djavax.net.ssl.keyStorePassword=xxxx -Djavax.net.ssl.trustStore=/cpapps/orepm/sslkeystore/keystore.jks -Djavax.net.ssl.CustomTrustStorePassphrase=xxx -Dwlw.iterativeDev=${iterativeDevFlag} -Dwlw.testConsole=${testConsoleFlag} -Dweblogic.security.SSL.minimumProtocolVersion=TLSv1.2 -Dwlw.logErrorsToConsole=${logErrorsToConsoleFlag}"



/cpapps/orplan/jdk1.7.0_131


ssl-versions="TLSv1.2"



- downloaded jdk1.7.0_131.tar.gz and unpacked to /cpapps/orplan/Oracle/Middleware

- copied /cpapps/orplan/Oracle/Middleware/jdk1.7.0_131/jre to /Oracle/Middleware/EPMSystem11R1/common/JRE/Sun/1.7.0

- updated below files.

/cpapps/orplan/Oracle/Middleware/EPMSystem11R1/common/config/11.1.2.0/setJavaRuntime.sh

/cpapps/orplan/Oracle/Middleware/user_projects/domains/EPMSystem/bin/setDomainEnv.sh



-XX:+UnlockCommercialFeatures

-XX:+UnlockCommercialFeatures -XX:-FlightRecorder



- modified essbase opmn configuration file under below location to update from jdk160_35 to jdk1.7.0_131

/cpapps/orplan/Oracle/Middleware/user_projects/planning/config/OPMN/opmn/opmn.xml



- update essbase.cfg with below cipherSuite SSLCIPHERSUITES SSL_RSA_WITH_AES_256_CBC_SHA





1 comment: