Announcements

Oracle training based on real-time expertise as per industry standards. Upcoming batch details are here.

View batch schedule

Free Oracle mock interview. Register using the link.

Register

#DBAchallenge: submit your questions.

Ask questions
Swipe for more →
Browse by Topic
Latest Posts
    Showing posts with label Linux. Show all posts
    Showing posts with label Linux. Show all posts

    Saturday, September 26, 2026

    How to Enable SSH Root Login on Oracle Enterprise Linux 9 (OEL9)

    How to Enable SSH Root Login on Oracle Enterprise Linux 9 (OEL9)

     

    While setting up an Oracle Enterprise Linux 9 (OEL9) server, I encountered an issue where I was unable to connect to the server remotely using the root user over SSH.

    Interestingly, SSH access using a normal user worked without any issues.

     

    This post explains the troubleshooting steps I followed and how I enabled SSH root login.

     

    1. SSH Connection Using the Root User

    I initially tried connecting to the OEL9 server from my Mac using the root account:

     

    mallikarjunramadurg@APAC-FR2WVTDXR4 ~ % ssh root@192.168.1.101

    root@192.168.1.101's password:

    Permission denied, please try again.

    root@192.168.1.101's password:

     

    Even though I was entering the correct root password, the SSH connection was rejected with:

    Permission denied, please try again.

     

    2. SSH Connection Using a Normal User

    To verify whether the SSH service itself was working, I tried connecting using the mallik user.

     

    mallikarjunramadurg@APAC-FR2WVTDXR4 ~ % ssh mallik@192.168.1.101

    mallik@192.168.1.101's password:

    [mallik@ora96 ~]#

     

    The connection worked successfully.

    This confirmed that:

    The server was reachable over the network.

    The SSH service was running.

    Password authentication was working for the mallik user.

    The issue was specifically related to SSH access for the root user.

     

    3. Testing Root SSH Login From the Server

    I then logged in using the mallik account and tried connecting to the same server using SSH as root:

     

    [mallik@ora96 ~]$ ssh root@192.168.1.101

    root@192.168.1.101's password:

    Permission denied, please try again.

    root@192.168.1.101's password:

     

    This produced the same result.

    However, after entering the password, I was able to access the root shell through the server's local console via virtual box direct server access.

     

    [root@ora96 ~]#

     

    4. Verify Root Access Through the Console

    To make sure the root account and password were working correctly, I logged into the server directly using the Web Console / VirtualBox console with the root account.

     

    The root login worked successfully.

    This helped narrow down the problem to SSH configuration rather than the root password itself.

     

    5. Check the SSH Configuration

    Next, I checked the SSH configuration files for the following parameters:

     

    PermitRootLogin

    PasswordAuthentication

     

    I used:

     

    [root@ora96 sshd_config.d]# grep -iE 'permitrootlogin|passwordauthentication' /etc/ssh/sshd_config /etc/ssh/sshd_config.d/*.conf 2>/dev/null

     

    The output showed:

    /etc/ssh/sshd_config:#PermitRootLogin prohibit-password

    /etc/ssh/sshd_config:#PasswordAuthentication yes

    /etc/ssh/sshd_config:# PasswordAuthentication. Depending on your PAM configuration,

    /etc/ssh/sshd_config:# the setting of "PermitRootLogin without-password".

    /etc/ssh/sshd_config:# PAM authentication, then enable PasswordAuthentication

     

     

    The important setting here is:

    #PermitRootLogin prohibit-password

    The PermitRootLogin setting controls whether the root account is allowed to log in through SSH.

     

    In my case, SSH root login using a password was not enabled.

     

    6. Enable SSH Root Login

    I then modified the SSH configuration to explicitly allow root login and password authentication.

     

    [root@ora96 sshd_config.d]# sed -i 's/^#PermitRootLogin prohibit-password/PermitRootLogin yes/' /etc/ssh/sshd_config

    [root@ora96 sshd_config.d]# sed -i 's/^#PasswordAuthentication yes/PasswordAuthentication yes/' /etc/ssh/sshd_config

     

    After modifying the configuration, I restarted the SSH service:

     

    [root@ora96 sshd_config.d]# systemctl restart sshd

     

    The SSH service restarted successfully.

     

    7. Test SSH Root Login From the Mac

    I then tested the connection again from my Mac.

     

    mallikarjunramadurg@APAC-FR2WVTDXR4 ~ % ssh root@192.168.1.101

    root@192.168.1.101's password:

    [root@ora96 ~]#

     

    The root SSH login was now successful.

     

    8. Test Root SSH Login From the Server

    I also verified the configuration from the mallik user session:

     

    [mallik@ora96 ~]$ ssh root@192.168.1.101

    root@192.168.1.101's password:

    [root@ora96 ~]#

     

    This also worked successfully.

     

    Conclusion

    The issue was not related to the root password or the SSH service itself. The problem was caused by the SSH server configuration preventing password-based root login.

     

    The key configuration changes were:

    PermitRootLogin yes

    PasswordAuthentication yes

     

    After updating the SSH configuration and restarting sshd, I was able to successfully connect to the OEL9 server using the root account over SSH.

     

    Important Security Note

    Enabling direct SSH access for the root user with password authentication can increase the security risk of a server, particularly if SSH is exposed to untrusted networks or the internet.

     

    For production environments, it is generally preferable to:

    Use a regular administrative account.

     

    Grant administrative privileges through sudo.

    Use SSH keys instead of passwords.

    Restrict SSH access using firewall/network controls.

    Disable direct root SSH login when it is not required.

     

    For a lab or test environment, however, enabling root SSH access can be useful when direct root access is specifically required.

     

    🌱 Vismo Technologies – Learn • Practice • Grow

    #VismoTechnologies #OracleRAC #Oracle19c #OracleDBA #RACTraining #OracleTraining #DatabaseTraining #OnlineTraining #LiveClasses #OracleCareers #OracleWorld #LearnPracticeGrow

     


    Tuesday, September 8, 2026

    LV-VG-PV Creating and mounting NFS mount point on Linux Vs Widows

    LV-VG-PV Creating and mounting NFS mount point on Linux Vs Widows

    ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
    Raw partition = fixed slice of one physical disk, filesystem sits directly on it.

    /data  →  /dev/sdb1  →  disk sdb

    The partition's start and end are literal sector numbers on that one disk. To grow it, the free sectors must sit immediately after it on the same disk. Nothing about a partition can reference a second disk.

    LVM inserts an abstraction layer between the disks and the filesystem:

    /data  →  lv_data      (Logical Volume  — what you mount/format)
                 ↑
              vg_data      (Volume Group    — a pool of space)
               ↑     ↑
             sdb1   sdc    (Physical Volumes — the actual disks)

    Three concepts:

    PV (physical volume) — a disk or partition handed over to LVM (pvcreate)
    VG (volume group) — one pool built from one or more PVs (vgcreate)
    LV (logical volume) — a virtual block device carved out of the pool (lvcreate), which is what you mkfs and mount


    1. Confirm the disk


    [root@jump_oel79 ~]# cd /dev/
    [root@jump_oel79 dev]# ll sd*
    brw-rw----. 1 root disk 8,  0 May 20 14:39 sda
    brw-rw----. 1 root disk 8,  1 May 20 14:39 sda1
    brw-rw----. 1 root disk 8,  2 May 20 14:39 sda2
    brw-rw----. 1 root disk 8, 16 Sep  3 21:31 sdb
    [root@jump_oel79 dev]# df -h
    Filesystem           Size  Used Avail Use% Mounted on
    devtmpfs             5.7G     0  5.7G   0% /dev
    tmpfs                5.8G     0  5.8G   0% /dev/shm
    tmpfs                5.8G  162M  5.6G   3% /run
    tmpfs                5.8G     0  5.8G   0% /sys/fs/cgroup
    /dev/mapper/ol-root   79G   68G   12G  86% /
    /dev/sda1           1014M  327M  688M  33% /boot
    tmpfs                1.2G   40K  1.2G   1% /run/user/0

    [root@jump_oel79 dev]# lsblk /dev/sdb
    NAME MAJ:MIN RM  SIZE RO TYPE MOUNTPOINT
    sdb    8:16   0 1000G  0 disk
    [root@jump_oel79 dev]# fdisk -l /dev/sdb

    Disk /dev/sdb: 1073.7 GB, 1073741824000 bytes, 2097152000 sectors
    Units = sectors of 1 * 512 = 512 bytes
    Sector size (logical/physical): 512 bytes / 512 bytes
    I/O size (minimum/optimal): 512 bytes / 512 bytes

    2. Partition (GPT)


    [root@jump_oel79 dev]# parted -s /dev/sdb mklabel gpt
    [root@jump_oel79 dev]# parted -s -a optimal /dev/sdb mkpart primary xfs 0% 100%
    [root@jump_oel79 dev]# partprobe /dev/sdb
    [root@jump_oel79 dev]# lsblk /dev/sdb
    NAME   MAJ:MIN RM  SIZE RO TYPE MOUNTPOINT
    sdb      8:16   0 1000G  0 disk
    └─sdb1   8:17   0 1000G  0 part
    [root@jump_oel79 dev]#

    3. Filesystem


    [root@jump_oel79 dev]# mkfs.xfs /dev/sdb1
    meta-data=/dev/sdb1              isize=256    agcount=4, agsize=65535872 blks
             =                       sectsz=512   attr=2, projid32bit=1
             =                       crc=0        finobt=0, sparse=0, rmapbt=0
             =                       reflink=0
    data     =                       bsize=4096   blocks=262143488, imaxpct=25
             =                       sunit=0      swidth=0 blks
    naming   =version 2              bsize=4096   ascii-ci=0, ftype=1
    log      =internal log           bsize=4096   blocks=127999, version=2
             =                       sectsz=512   sunit=0 blks, lazy-count=1
    realtime =none                   extsz=4096   blocks=0, rtextents=0
    [root@jump_oel79 dev]#

    4. Mount point + mount


    [root@jump_oel79 dev]# mkdir -p /data
    [root@jump_oel79 dev]# mount /dev/sdb1 /data
    [root@jump_oel79 dev]# df -hT /data
    Filesystem     Type  Size  Used Avail Use% Mounted on
    /dev/sdb1      xfs  1000G   33M 1000G   1% /data
    [root@jump_oel79 dev]# blkid /dev/sdb1
    /dev/sdb1: UUID="b1da372b-579e-49e8-b38a-7da12157b067" TYPE="xfs" PARTLABEL="primary" PARTUUID="03f0b9c5-ec44-4b98-9554-102fdb5f36eb"
    [root@jump_oel79 dev]#

    5. Make it persistent


    [root@jump_oel79 dev]# echo 'UUID=b1da372b-579e-49e8-b38a-7da12157b067 /data xfs defaults 0 0' >> /etc/fstab
    [root@jump_oel79 dev]# mount -a
    [root@jump_oel79 dev]# df -h
    Filesystem           Size  Used Avail Use% Mounted on
    devtmpfs             5.7G     0  5.7G   0% /dev
    tmpfs                5.8G     0  5.8G   0% /dev/shm
    tmpfs                5.8G  162M  5.6G   3% /run
    tmpfs                5.8G     0  5.8G   0% /sys/fs/cgroup
    /dev/mapper/ol-root   79G   68G   12G  86% /
    /dev/sda1           1014M  327M  688M  33% /boot
    tmpfs                1.2G   40K  1.2G   1% /run/user/0
    /dev/sdb1           1000G   33M 1000G   1% /data
    [root@jump_oel79 dev]#


    If you'd rather use LVM (lets you grow /data later by adding disks):

    pvcreate /dev/sdb
    vgcreate vg_data /dev/sdb
    lvcreate -l 100%FREE -n lv_data vg_data
    mkfs.xfs /dev/vg_data/lv_data
    mkdir -p /data
    echo '/dev/vg_data/lv_data /data xfs defaults 0 0' >> /etc/fstab
    mount -a

    [root@jump_oel79 dev]# df -h
    Filesystem           Size  Used Avail Use% Mounted on
    devtmpfs             5.7G     0  5.7G   0% /dev
    tmpfs                5.8G     0  5.8G   0% /dev/shm
    tmpfs                5.8G  162M  5.6G   3% /run
    tmpfs                5.8G     0  5.8G   0% /sys/fs/cgroup
    /dev/mapper/ol-root   79G   68G   12G  86% /
    /dev/sda1           1014M  327M  688M  33% /boot
    tmpfs                1.2G   40K  1.2G   1% /run/user/0
    /dev/sdb1           1000G   33M 1000G   1% /data
    [root@jump_oel79 dev]#


    If you have already mounted the /dev/sdb disk format it with a filesystem, created a mount point and we need to mount with LVM
    then for that. If you haven't put data on /data mount point yet, switch now to LVM so that you can dynamically increase this /data mount point later

    umount /data
    sed -i '\|/data|d' /etc/fstab        # remove the line you just added
    wipefs -a /dev/sdb1

    pvcreate /dev/sdb1
    vgcreate vg_data /dev/sdb1
    lvcreate -l 100%FREE -n lv_data vg_data
    mkfs.xfs /dev/vg_data/lv_data
    echo '/dev/vg_data/lv_data /data xfs defaults 0 0' >> /etc/fstab
    mount -a
    df -hT /data


    [root@jump_oel79 dev]# umount /data
    [root@jump_oel79 dev]# sed -i '\|/data|d' /etc/fstab
    [root@jump_oel79 dev]# wipefs -a /dev/sdb1
    /dev/sdb1: 4 bytes were erased at offset 0x00000000 (xfs): 58 46 53 42
    [root@jump_oel79 dev]#
    [root@jump_oel79 dev]# pvcreate /dev/sdb1
      Physical volume "/dev/sdb1" successfully created.
    [root@jump_oel79 dev]# vgcreate vg_data /dev/sdb1
      Volume group "vg_data" successfully created
    [root@jump_oel79 dev]# lvcreate -l 100%FREE -n lv_data vg_data
      Logical volume "lv_data" created.
    [root@jump_oel79 dev]# mkfs.xfs /dev/vg_data/lv_data
    meta-data=/dev/vg_data/lv_data   isize=256    agcount=4, agsize=65535744 blks
             =                       sectsz=512   attr=2, projid32bit=1
             =                       crc=0        finobt=0, sparse=0, rmapbt=0
             =                       reflink=0
    data     =                       bsize=4096   blocks=262142976, imaxpct=25
             =                       sunit=0      swidth=0 blks
    naming   =version 2              bsize=4096   ascii-ci=0, ftype=1
    log      =internal log           bsize=4096   blocks=127999, version=2
             =                       sectsz=512   sunit=0 blks, lazy-count=1
    realtime =none                   extsz=4096   blocks=0, rtextents=0
    [root@jump_oel79 dev]# echo '/dev/vg_data/lv_data /data xfs defaults 0 0' >> /etc/fstab
    [root@jump_oel79 dev]# mount -a
    [root@jump_oel79 dev]# df -hT /data
    Filesystem                  Type  Size  Used Avail Use% Mounted on
    /dev/mapper/vg_data-lv_data xfs  1000G   33M 1000G   1% /data
    [root@jump_oel79 dev]#


    Later, adding /dev/sdc (1000G) becomes:

    pvcreate /dev/sdc
    vgextend vg_data /dev/sdc
    lvextend -l +100%FREE /dev/vg_data/lv_data
    xfs_growfs /data                     # online, no unmount needed

    /data goes to ~2TB with no downtime.





    Your LVM mount /data is ready — you just need to export it.

    1. Install and enable NFS server


    yum install -y nfs-utils
    systemctl enable --now nfs-server rpcbind

    2. Add the export


    bash
    echo '/data 10.0.0.0/8(rw,sync,no_root_squash,no_subtree_check)' >> /etc/exports

    Replace 10.0.0.0/8 with your client subnet or a specific IP. Use * only in a trusted lab. Drop no_root_squash unless clients genuinely need root write access — it's a security hole.
    echo '/data *(rw,sync,no_subtree_check)' >> /etc/exports

    3. Apply and verify


    exportfs -rav
    exportfs -v
    showmount -e localhost

    4. Firewall (if firewalld is running)


    firewall-cmd --permanent --add-service={nfs,rpc-bind,mountd}
    firewall-cmd --reload

    5. SELinux (only if enforcing and clients need write)


    setsebool -P nfs_export_all_rw 1

    6. Mount from a client


    mkdir -p /mnt/data
    mount -t nfs jump_oel79:/data /mnt/data
    # persist:
    echo 'jump_oel79:/data /mnt/data nfs defaults,_netdev 0 0' >> /etc/fstab


    [root@jump_oel79 dev]# yum install -y nfs-utils
    Loaded plugins: langpacks, ulninfo
    Package 1:nfs-utils-1.3.0-0.68.0.1.el7.2.x86_64 already installed and latest version
    Nothing to do
    [root@jump_oel79 dev]# systemctl enable --now nfs-server rpcbind
    Created symlink from /etc/systemd/system/multi-user.target.wants/nfs-server.service to /usr/lib/systemd/system/nfs-server.service.
    [root@jump_oel79 dev]#
    [root@jump_oel79 dev]# echo '/data *(rw,sync,no_subtree_check)' >> /etc/exports
    [root@jump_oel79 dev]#
    [root@jump_oel79 dev]# exportfs -rav
    exporting *:/data
    [root@jump_oel79 dev]# exportfs -v
    /data             <world>(sync,wdelay,hide,no_subtree_check,sec=sys,rw,secure,root_squash,no_all_squash)
    [root@jump_oel79 dev]# showmount -e localhost
    Export list for localhost:
    /data *
    [root@jump_oel79 dev]# firewall-cmd --permanent --add-service={nfs,rpc-bind,mountd}
    success
    [root@jump_oel79 dev]# firewall-cmd --reload
    success
    [root@jump_oel79 dev]# setsebool -P nfs_export_all_rw 1
    [root@jump_oel79 dev]# hostname
    jump_oel79.localdomain.com
    [root@jump_oel79 dev]#

    [root@jump_oel810 ~]# hostname
    jump_oel810.localdomain.com
    [root@jump_oel810 ~]#
    [root@jump_oel810 ~]# mkdir -p /mnt/data
    [root@jump_oel810 ~]# mount -t nfs 10.26.3.61:/data /mnt/data
    [root@jump_oel810 ~]# echo '10.26.3.61:/data /mnt/data nfs defaults,_netdev 0 0' >> /etc/fstab
    [root@jump_oel810 ~]# df -h
    Filesystem           Size  Used Avail Use% Mounted on
    devtmpfs             5.7G     0  5.7G   0% /dev
    tmpfs                5.7G     0  5.7G   0% /dev/shm
    tmpfs                5.7G  9.2M  5.7G   1% /run
    tmpfs                5.7G     0  5.7G   0% /sys/fs/cgroup
    /dev/mapper/ol-root   56G   11G   45G  19% /
    /dev/sda2           1014M  659M  356M  65% /boot
    /dev/sda1            599M  6.0M  593M   1% /boot/efi
    tmpfs                1.2G   12K  1.2G   1% /run/user/42
    tmpfs                1.2G     0  1.2G   0% /run/user/0
    10.26.3.61:/data    1000G   33M 1000G   1% /mnt/data
    [root@jump_oel810 ~]#


    Saturday, April 18, 2026

    Oracle DBA Tools and What is NFS Share? What is samba Share?

    Oracle DBA Tools and What is NFS Share? What is samba Share?

    putty / MobaXterm -> terminal software to connect remotely to you Linux VMs/Physical server  
    RDP -> terminal software to connect remotely to you Windows VMs/Physical server  
    winscp -> Transfer the file between windows and Linux
    scp/ftp/sftp -> Transfer the file between linux and Linux
    NFS Share / NFS mount -> shared mount point / drive between Linux
    SMB Share -> shared mount point / drive between Windows 
    Samba Share -> shared mount point / drive between Windows & Linux 

    Regards,
    Mallikarjun / Vismo Technologies
    WhatsApp: +91 9880616848 / +91 9036478079
    Cell: +91 9880616848 / +91 9036478079
    Email: mallikarjun.ramadurg@gmail.com / vismotechnologies@gmail.com

    Wednesday, June 18, 2025

    -bash: oraenv: No such file or directory

    -bash: oraenv: No such file or directory


    What Are Root.sh And OrainstRoot.sh Scripts In A Standalone RDBMS Installation? (Doc ID 1493121.1)

    Issue:

    Unable to run oraenv to set oracle environmental variable 

    Error Message:

    [oracle@oraclelab1 ~]$ . oraenv
    -bash: oraenv: No such file or directory

    Cause:

    /usr/local/bin/oraenv environmental executable file might have got corrupted or root.sh script has not ran as part of Oracle Home installation

    Fix:

    recreate or rebuild /usr/local/bin/oraenv environmental executable file by running root.sh script as root user

    Error Logs and commands output:

    1. Check the database instance status and oracle owner

    [root@oraclelab1 ~]# ps -ef|grep smon
    root     18125 17601  0 23:48 pts/1    00:00:00 grep --color=auto smon
    oracle   28764     1  0 May01 ?        00:00:31 ora_smon_MALLIK
    [root@oraclelab1 ~]#
    [root@oraclelab1 ~]# su - oracle
    Last login: Mon Jun 16 23:33:49 IST 2025 on pts/1
    [oracle@oraclelab1 ~]$

    2. When we are trying the set the oracle environmental variable by running .oraenv it is failing with error message oraenv: No such file or directory

    /usr/local/bin/oraenv environmental executable file might have got corrupted or root.sh script has not ran as part of Oracle Home installation

    [oracle@oraclelab1 ~]$ . oraenv
    -bash: oraenv: No such file or directory
    [oracle@oraclelab1 ~]$
    [oracle@oraclelab1 ~]$ which oraenv
    /usr/bin/which: no oraenv in (/usr/local/bin:/bin:/usr/bin:/usr/local/sbin:/usr/sbin)
    [oracle@oraclelab1 ~]$ env |grep ORA
    [oracle@oraclelab1 ~]$

    3. recreate or rebuild /usr/local/bin/oraenv environmental executable file by running root.sh script as root user

    [root@oraclelab1 ~]# cat /etc/oratab
    #
    # This file is used by ORACLE utilities.  It is created by root.sh
    # and updated by either Database Configuration Assistant while creating
    # a database or ASM Configuration Assistant while creating ASM instance.

    # A colon, ':', is used as the field terminator.  A new line terminates
    # the entry.  Lines beginning with a pound sign, '#', are comments.
    #
    # Entries are of the form:
    #   $ORACLE_SID:$ORACLE_HOME:<N|Y>:
    #
    # The first and second fields are the system identifier and home
    # directory of the database respectively.  The third field indicates
    # to the dbstart utility that the database should , "Y", or should not,
    # "N", be brought up at system boot time.
    #
    # Multiple entries with the same $ORACLE_SID are not allowed.
    #
    MALLIK:/u01/app/oracle/product/19.0.0.0/dbhome_1:N
    [root@oraclelab1 ~]#
    [root@oraclelab1 ~]# /u01/app/oracle/product/19.0.0.0/dbhome_1/root.sh
    Performing root user operation.

    The following environment variables are set as:
        ORACLE_OWNER= oracle
        ORACLE_HOME=  /u01/app/oracle/product/19.0.0.0/dbhome_1

    Enter the full pathname of the local bin directory: [/usr/local/bin]:
    The contents of "dbhome" have not changed. No need to overwrite.
       Copying oraenv to /usr/local/bin ...
    The contents of "coraenv" have not changed. No need to overwrite.

    Entries will be added to the /etc/oratab file as needed by
    Database Configuration Assistant when a database is created
    Finished running generic part of root script.
    Now product-specific root actions will be performed.
    Oracle Trace File Analyzer (TFA - Standalone Mode) is available at :
        /u01/app/oracle/product/19.0.0.0/dbhome_1/bin/tfactl

    Note :
    1. tfactl will use TFA Service if that service is running and user has been granted access
    2. tfactl will configure TFA Standalone Mode only if user has no access to TFA Service or TFA is not installed

    [root@oraclelab1 ~]#

    4. Now try to set the oracle environmental variable by running .oraenv which worked fine without any issue. 

    [root@oraclelab1 ~]# su - oracle
    Last login: Mon Jun 16 23:48:35 IST 2025 on pts/1
    [oracle@oraclelab1 ~]$
    [oracle@oraclelab1 ~]$ . oraenv
    ORACLE_SID = [oracle] ? MALLIK
    The Oracle base has been set to /u01/app/oracle
    [oracle@oraclelab1 ~]$
    [oracle@oraclelab1 ~]$ env |grep ORA
    ORACLE_SID=MALLIK
    ORACLE_BASE=/u01/app/oracle
    ORACLE_HOME=/u01/app/oracle/product/19.0.0.0/dbhome_1
    [oracle@oraclelab1 ~]$
    [oracle@oraclelab1 ~]$ which oraenv
    /usr/local/bin/oraenv
    [oracle@oraclelab1 ~]$
    [oracle@oraclelab1 ~]$ sqlplus / as sysdba

    SQL*Plus: Release 19.0.0.0.0 - Production on Mon Jun 16 23:49:48 2025
    Version 19.3.0.0.0

    Copyright (c) 1982, 2019, Oracle.  All rights reserved.

    Connected to:
    Oracle Database 19c Enterprise Edition Release 19.0.0.0.0 - Production
    Version 19.3.0.0.0

    SQL> select instance_name, status from v$instance;

    INSTANCE_NAME    STATUS
    ---------------- ------------
    MALLIK           OPEN

    SQL> exit
    Disconnected from Oracle Database 19c Enterprise Edition Release 19.0.0.0.0 - Production
    Version 19.3.0.0.0
    [oracle@oraclelab1 ~]$


    Wednesday, May 26, 2021

    What is SSL/TSL and How to generate Self-Signed SSL Certificate?

    What is an SSL certificate?

    SSL - Secure Sockets Layer

    TSL - Transport Layer Security

     

    SSL certificates are what enable websites to move from HTTP to HTTPS

    -        Which is more secure.

    -        An SSL certificate is a data file hosted in a website's origin server.

    -        SSL certificates make SSL/TLS encryption possible.

    -        they contain the website's public key and the website's identity, along with related information.

     

    Devices attempting to communicate with the origin server will reference this file to obtain the public key and verify the server's identity. The private key is kept secret and secure.

     

    Here is the full history of SSL and TLS releases:

    SSL 1.0 – never publicly released due to security issues.

    SSL 2.0 – released in 1995. Deprecated in 2011. Has known security issues.

    SSL 3.0 – released in 1996. Deprecated in 2015. Has known security issues.

    TLS 1.0 – released in 1999 as an upgrade to SSL 3.0. Planned deprecation in 2020.

    TLS 1.1 – released in 2006. Planned deprecation in 2020.

    TLS 1.2 – released in 2008.

    TLS 1.3 – released in 2018.

     

    What is SSL?

    SSL is commonly called as TLS, is a protocol for encrypting Internet traffic and verifying server identity. Any website with an HTTPS web address uses SSL/TLS.

    See What is SSL? and What is TLS? to learn more.

     

    What information does an SSL certificate contain?

    SSL certificates include:

     

    A. The domain name that the certificate was issued for

    B. Which person, organization, or device it was issued to

    C. Which certificate authority issued it

    D. The certificate authority's digital signature

    E. Associated subdomains

    F. Issue date of the certificate

    G. Expiration date of the certificate

    H. The public key (the private key is kept secret)

     

    The public and private keys used for SSL are essentially long strings of characters used for encrypting and decrypting data. Data encrypted with the public key can only be decrypted with the private key, and vice versa.

     

    Why do websites need an SSL certificate?

    A website needs an SSL certificate in order to keep user data secure, verify ownership of the website, prevent attackers to hack site.

     

    Encryption: SSL/TLS encryption is possible because of the public-private key pairing that SSL certificates facilitate. Clients (such as web browsers) get the public key necessary to open a TLS connection from a server's SSL certificate.

     

    Authentication: SSL certificates verify that a client is talking to the correct server that actually owns the domain. This helps prevent domain spoofing and other kinds of attacks.

     

    HTTPS: Most crucially for businesses, an SSL certificate is necessary for an HTTPS web address. HTTPS is the secure form of HTTP, and HTTPS websites are websites that have their traffic encrypted by SSL/TLS.

     

    User data are secure in transit most browsers have started tagging HTTP sites as "not secure"

     

    How does a website obtain an SSL certificate?

    For an SSL certificate to be valid, domains need to obtain it from a certificate authority (CA).

    A CA is an outside organization, a trusted third party, that generates and gives out SSL certificates.

     

    The CA will also digitally sign the certificate with their own private key, allowing client devices to verify it.

    Most, but not all, CAs will charge a fee for issuing an SSL certificate.

     

    Once the certificate is issued, it needs to be installed and activated on the website's origin server. Web hosting services can usually handle this for website operators. Once it's activated on the origin server, the website will be able to load over HTTPS and all traffic to and from the website will be encrypted and secure.

     

    What is a self-signed SSL certificate?

    Technically, anyone can create their own SSL certificate by generating a public-private key pairing and including all the information mentioned above. Such certificates are called self-signed certificates because the digital signature used, instead of being from a CA, would be the website's own private key.

     

    But with self-signed certificates, there's no outside authority to verify that the origin server is who it claims to be. Browsers don't consider self-signed certificates trustworthy and may still mark sites with one as "not secure," despite the https:// URL. They may also terminate the connection altogether, blocking the website from loading.

     

    Self-signed certificates can have the same level of encryption as the trusted CA-signed SSL certificate

     

    Typically, the self-signed certificates are used for testing purposes or internal usage. You should not use a self-signed certificate in production systems that are exposed to the Internet.

     

    Is it possible to get a free SSL certificate?

    There are few vendors provide free SSL certificate but very cautious before signing up and generating the SSL certificate.

    Better to go with paid service with enterprise provider for SSL certificate.

     

    Creating a Self-Signed SSL Certificate

    Prerequisites

    The OpenSSL toolkit is required to generate a self-signed certificate.
    To check whether the openssl package is installed on your Linux system, open your terminal, type openssl version

     

    [root@node1 dbs]# openssl version

    OpenSSL 1.0.2k-fips  26 Jan 2017

    [root@node1 dbs]#

     

    If the openssl package is not installed on your system, you can install it with your distribution’s package manager:

     

    #yum install openssl

     

    Creating Self-Signed SSL Certificate

    To create a new Self-Signed SSL Certificate, use the openssl req command:

     

    openssl req -newkey rsa:4096 \

                -x509 \

                -sha256 \

                -days 365 \

                -nodes \

                -out example.crt \

                -keyout example.key

     

    Let’s breakdown the command and understand what each option means:

    -newkey rsa:4096 --- Creates a new certificate request and 4096 bit RSA key (The default is 2048 bits)

    -x509 --- Creates a X.509 Certificate.

    -sha256 --- Use 265-bit SHA (Secure Hash Algorithm).

    -days 365 --- The number of days to certify the certificate for 365 days.

    -nodes --- Creates a key without a passphrase.

    -out example.crt --- Specifies the filename to write the newly created certificate to. (You can specify any file name)

    -keyout example.key --- Specifies the filename to write the newly created private key to. (You can specify any file name)

     

    Once you hit Enter, the command will generate the private key and ask you a series of questions. The information you provided is used to generate the certificate.

     

    [root@node1 ~]# mkdir Certs

    [root@node1 ~]# cd Certs/

    [root@node1 Certs]# pwd

    /root/Certs

    [root@node1 Certs]# ls -ltrh

    total 0

    [root@node1 Certs]# openssl req -newkey rsa:4096 \

    >             -x509 \

    >             -sha256 \

    >             -days 365 \

    >             -nodes \

    >             -out example.crt \

    >             -keyout example.key

    Generating a 4096 bit RSA private key

    ............................................++

    ......................................................................++

    writing new private key to 'example.key'

    -----

    You are about to be asked to enter information that will be incorporated

    into your certificate request.

    What you are about to enter is what is called a Distinguished Name or a DN.

    There are quite a few fields but you can leave some blank

    For some fields there will be a default value,

    If you enter '.', the field will be left blank.

    -----

    Country Name (2 letter code) [XX]:

     

    Enter the information requested and press Enter.

     

    Country Name (2 letter code) [XX]:IN

    State or Province Name (full name) []:Karnataka

    Locality Name (eg, city) [Default City]:Bangalore

    Organization Name (eg, company) [Default Company Ltd]:Mallik

    Organizational Unit Name (eg, section) []:IT

    Common Name (eg, your name or your server's hostname) []:mallik.com

    Email Address []:mallik@gmail.com

     

    The certificate and private key will be created at the specified location. Use the ls command to verify that the files were created:

     

    [root@node1 Certs]# ls -ltrh

    total 8.0K

    -rw-r--r-- 1 root root 3.2K May 26 01:24 example.key

    -rw-r--r-- 1 root root 2.1K May 26 01:24 example.crt

    [root@node1 Certs]#

     

    That’s it! You have generated a new self-signed SSL certificate.

    It is always a good idea to back up your new certificate and key to external storage.

     

    Creating Self-Signed SSL Certificate without Prompt

    If you want to generate a self-signed SSL certificate without being prompted for any question use the -subj option and specify all the subject information:

     

    openssl req -newkey rsa:4096 \

                -x509 \

                -sha256 \

                -days 3650 \

                -nodes \

                -out example.crt \

                -keyout example.key \

                -subj "/C=IN/ST=Karnataka/L=Bangalore/O=Mallik/OU=IT/CN=mallik.com"

     

    [root@node1 Certs]# pwd

    /root/Certs

    [root@node1 Certs]# ls -ltrh

    total 0

    [root@node1 Certs]# openssl req -newkey rsa:4096 \

    >             -x509 \

    >             -sha256 \

    >             -days 3650 \

    >             -nodes \

    >             -out example.crt \

    >             -keyout example.key \

    >             -subj "/C=IN/ST=Karnataka/L=Bangalore/O=Mallik/OU=IT/CN=mallik.com"

    Generating a 4096 bit RSA private key

    ................................................++

    .................................................................................................++

    writing new private key to 'example.key'

    -----

    [root@node1 Certs]# ls -ltrh

    total 8.0K

    -rw-r--r-- 1 root root 3.2K May 26 01:30 example.key

    -rw-r--r-- 1 root root 2.0K May 26 01:30 example.crt

    [root@node1 Certs]#

     

    The fields, specified in -subj line are listed below:

     

    C= --- Country name. The two-letter ISO abbreviation.

    ST= --- State or Province name.

    L= --- Locality Name. The name of the city where you are located.

    O= --- The full name of your organization.

    OU= --- Organizational Unit.

    CN= --- The fully qualified domain name.

     

    Conclusion

    We have shown you how to generate a self-signed SSL certificate using the openssl tool. Now that you have the certificate, you can configure your application to use it.

    Feel free to leave a comment if you have any questions.

     

    How to verify the SSL certificates?

    You can verify the certificate using keycdn site

    https://tools.keycdn.com/ssl

     

    [root@node1 Certs]# pwd

    /root/Certs

    [root@node1 Certs]#

     

    [root@node1 Certs]# cat example.key

    -----BEGIN PRIVATE KEY-----

    MIIJQgIBADANBgkqhkiG9w0BAQEFAASCCSwwggkoAgEAAoICAQChyzr6xUMfIOxM

    Bigm0M4/BWzWbl/S2d63Ctm/ZMZoPPIo8GTPs+vhZqD33XGm7ktkwQv5IqadybXY

    dmlKSgl73SS0ccWR14teZVhGolGJFCFZFKTZ8E3hfcvMWU/yP2s8WQ4YNuy06NVq

    rwCxNvWTk1s5gXiqpTj1wrSz+jUrHe7I0OLRIfuJYUzCU9ZLsdRwyd4jPWN2oTH3

    5evXDqe/4cGBhXrbcikT4wkR/mGy8V4ywJSil2ZDUBiNEyVuQaUiw8IpUdcXz6pN

    o+85r+z7GRBtJ86JCGAotIBhEvtt2X48JKRI44Jp50EEz1fYPp+6XdDPApomPpxt

    PDndFgiF8Trw3+S74QZZzdoGS7CFYT+4hVVu0ver9zD/D1Eaaqs4W2+I6MnVIqXf

    eef6Y4YQDD1iXnPzvWOEEZ8PRWB9lRO9Wt9852UGF3TZALfXcyyX2eudbS4Xa5rY

    9nnIzZhCKrxp4QdEAF6JZcPiD9tNW1t6b3KjHDQkPfsq4V4aW7NYJkQXLCQMgFZ0

    Uyu5Tas/vGpLomDm34kVhRM53gJi4/LHJyTynIKV0ANW5gNV6q+sgH1erI95IkWe

    grxcpj9U28/IX0lDVp3sPThpmKp6oqv5ofC1aI9Pq8C254KNQbz64Vp7baXBAM95

    jWyY4H1RPEsSqM65GqZE41Ytsn5sfwIDAQABAoICACdBZQ0FIZUC6vJDKCjKzs/R

    pCee3hcNj5D/y/c5Hz6ZUvQF55/RerDUsseQ7gtfk+FdSWdoNd7g2wMrL767mfN4

    o3g4hoQtNP5xPmrc5UWKIdE4Rgsu1+aXHAR3wwL2yjD5Noc/hE0clPNuhI960zi8

    Lw0T0dAtiFVwqWFlmtLcT1xf+jhds2cQuYwIxVzWR8IZ6JDKS0C0Oah5G7CxOJhA

    0S940GdAGqFdm4zHGLNPBtjviuCsNT6tx1crRxCqUsPNlWVrGvIHC74MwXVQrwH5

    gdfKKb1rz9DwgpmK/oAXnh4/kbCxqqnBVzAwkpLAFwcjzg78BaSz2kZSr4Np3iUm

    sMf/oXRooEjn4oWgyQ1LEaP4eLW8aXZz5V1hpXjHtl6c4afEIeBiTSbP0OAVo1wS

    aP6p6WpZvJPxiugQmgeKpAyO8Rry8rAOHeRN50APQxM/SeB6kfuOPMNCpB6BkXD+

    NYz/+E8YwFauD8ug35fDFFCA564Pp231Vua4wBLOwOXaqTw0yPo9dQFiaVygUmDJ

    5m5k8eRmsWNZbkGzbMlk2mu+4zAfoURU4RiIj1uSk1xtF5PoOiPBQZBSp1XpesXe

    m06SWPU5LnyphiAX+mwk5WZwl0PxaD67gsVfjbLQZuxo2Dc2EY6KW/aqlOxyNbUx

    ycTKJpLno9ei5PWIUodhAoIBAQDMtk25s26vKdjzsDDDvanExAP/dSwLhmKYGVXS

    3nuf9Assc5hHCU9iRs0wY0mlCOYS3+Z//3cb4jkIRz0nNoIf1MRvHeZRgoDOgN8P

    dcXo29Qgz8jB4neHRxyr3YZO7OtpSJYUisbUyuhUlnAtFolJUOy8Umvz5KgwfP11

    ohKUTS7zvVRIc9Wcm9Cqy/D0u7GCrI5JYXEWuU2M+ONBzJqZVAaxmqcWB37SxIou

    Rbaz+XxmAU1Q3uAzdxTEqmXmruh2YmZQn97Y7hXwvZI5Y+FLLGW7/p3a1bno/rBK

    EvpW6oOeMmkPyvO6Qw7hHJk6RlB1Mnc9AhtJiaoeLIYEFikRAoIBAQDKVENRUO/I

    kyUZBokVypuIaHcqXvYkl3ohpKQVhW8R0zue78IbfKudaRVlGhzQA6YS2Yvbfc3m

    OChfQMW+wZLtsZ1QctjFKL9DSW0jcqAkd5avxNknWgP+6yT2819VkVx153/tb+4f

    yOVW0Ro6jmdC7z069JHn1vgWfqzvdwCZ7CHUskfbFpNLW7wO2i/4Oa0qHvoBRDdK

    2gUR8vj+/U7PQHJa3T11CeTeaFy7/iWlhsIm4ZusUOKtxnqa9mBIxSj/QZr1eS5c

    n3dgD3aIA/4vRdKv1vCAT5lWvMuay1oVgaYZj6fhEf9lITFdo+jNQQKvgsI482po

    Rm1LAV3spbyPAoIBAQCPxHBtvJA9QDx3WAPHVEoIQEk2fUnDhktz2kcl4s4blb7L

    JxuIuAciU+sC0pgD6W37T3eH6RfzYzr+j1lpUqSsSjbyeqMoF2jynhsJtoKZeNlP

    ed3aHHwpa029fcQ3Zbgmpq2QG65r/1yPG2AIqk0cSlMYJyJdlPZxpzYyCPLXaCVT

    VGH+yCr644r2iGfe2Hpf9WOwMVjExrqqCJlBurnQeOyCisRRek4dI56PxLH9T3eI

    A94Sr5PxUO4q+Ci8i5YCnjSQ5tYQr5SFD/3DhFvS+YkxMC4YZAU+lq+kNhPOOsDY

    tzqFttjYtQOcIQOTo5IZ3KlVFUeoq5/ntQkhkZahAoIBAHsC8g6tW6uhsqtdatkh

    3p/3i4PqSlKC+hEcTVp8TsQSniwKbwRRLvG8IvLeBmh932mUdFCVUyrGN915vwA0

    JoV3OELiIGL2XBqnuMAVf8HMJ4Rj9PbU5psFEetGmk6m2wUgI4oTRD504OKArSau

    z59FXv/KFC9VZm4exDuvKWFrzEHJxqAwQItPka2iAAo13s8+GBfPBqLunKiGBdbZ

    4SFmeGBAJI5U3p5N6xus7+yMWtxSzFfesYKfqokug+maXUub8n+OFp7foS95F0Ko

    0tCg7fBUiNIqEvtGO6+4NOPgeEEQMyxGyfUNUjsxXWf1P5G/uR/w9l/Bec9hXF51

    gYcCggEANiSeVHpCZSN78v0YTe/QE3wH3TtJtlvPuTpa0RD4ZSjV0KGWECcbT0G+

    LXJai6tcIack9RPLJwmkXglC6YEPPpraZnSwJS3zkt0wwK9PJ5purm46qUxdmFZo

    sepNfDvQJ1v3bWg4c0AfFP5bHrBRWwu8LcDrYgo+ZdPEdTWXJFqdvHVdtW/Szbc9

    uP46IENTpBx97CwfshJgvp8tXq5CRCkyxXPTqvW+y0sicDUJEvMVE3TSkLWGEkL4

    JvtRrJ29TDw1loKmf3uUo/AejUpX076xCx/znSbuC4QuSL0d1Zn5sxHngI/QfNE+

    eUnqCTMDXkVzefAniD559uI4d6Ef5w==

    -----END PRIVATE KEY-----

    [root@node1 Certs]# cat example.crt

    -----BEGIN CERTIFICATE-----

    MIIFozCCA4ugAwIBAgIJALNK4s6wRd+BMA0GCSqGSIb3DQEBCwUAMGgxCzAJBgNV

    BAYTAklOMRIwEAYDVQQIDAlLYXJuYXRha2ExEjAQBgNVBAcMCUJhbmdhbG9yZTEP

    MA0GA1UECgwGTWFsbGlrMQswCQYDVQQLDAJJVDETMBEGA1UEAwwKbWFsbGlrLmNv

    bTAeFw0yMTA1MjUyMDAwMjdaFw0zMTA1MjMyMDAwMjdaMGgxCzAJBgNVBAYTAklO

    MRIwEAYDVQQIDAlLYXJuYXRha2ExEjAQBgNVBAcMCUJhbmdhbG9yZTEPMA0GA1UE

    CgwGTWFsbGlrMQswCQYDVQQLDAJJVDETMBEGA1UEAwwKbWFsbGlrLmNvbTCCAiIw

    DQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBAKHLOvrFQx8g7EwGKCbQzj8FbNZu

    X9LZ3rcK2b9kxmg88ijwZM+z6+FmoPfdcabuS2TBC/kipp3Jtdh2aUpKCXvdJLRx

    xZHXi15lWEaiUYkUIVkUpNnwTeF9y8xZT/I/azxZDhg27LTo1WqvALE29ZOTWzmB

    eKqlOPXCtLP6NSsd7sjQ4tEh+4lhTMJT1kux1HDJ3iM9Y3ahMffl69cOp7/hwYGF

    ettyKRPjCRH+YbLxXjLAlKKXZkNQGI0TJW5BpSLDwilR1xfPqk2j7zmv7PsZEG0n

    zokIYCi0gGES+23ZfjwkpEjjgmnnQQTPV9g+n7pd0M8CmiY+nG08Od0WCIXxOvDf

    5LvhBlnN2gZLsIVhP7iFVW7S96v3MP8PURpqqzhbb4joydUipd955/pjhhAMPWJe

    c/O9Y4QRnw9FYH2VE71a33znZQYXdNkAt9dzLJfZ651tLhdrmtj2ecjNmEIqvGnh

    B0QAXollw+IP201bW3pvcqMcNCQ9+yrhXhpbs1gmRBcsJAyAVnRTK7lNqz+8akui

    YObfiRWFEzneAmLj8scnJPKcgpXQA1bmA1Xqr6yAfV6sj3kiRZ6CvFymP1Tbz8hf

    SUNWnew9OGmYqnqiq/mh8LVoj0+rwLbngo1BvPrhWnttpcEAz3mNbJjgfVE8SxKo

    zrkapkTjVi2yfmx/AgMBAAGjUDBOMB0GA1UdDgQWBBQsKcacavJRZkeUNNKduye/

    v3KR+TAfBgNVHSMEGDAWgBQsKcacavJRZkeUNNKduye/v3KR+TAMBgNVHRMEBTAD

    AQH/MA0GCSqGSIb3DQEBCwUAA4ICAQBwLVman86V0LNmA01As8Ku2FrPlSs707Jo

    6FBh9Ft2krwGv+RfXoruSVQ62pJMGczotvyRdQ/ctlyghQnmVXeJrENNV/bjV5QM

    OPx4P49slUv6aP8+1rLzogmeYPuLnq+ZcncUVRBZ2oZHw8M51LRCHSUG+mCHbfk8

    VCacI+eU/AgDG+wqVjSzWFJbzZptvsHX1lD3bbg8MswY8x1qUAIKFgpgr3y8GwGO

    BWyXemKyDPrjNIKYVYKI5iSErLWWOzEJJPzvjrj30O4DYmAlTfR1RY2D/+di7sAU

    o4sjl+1TG5YFyaoGv06YE+qRXTuPI3XGAPb13K+IEo1wZ8Zl3P98wtBKcz66ZERq

    mqpX/aNoe+f0P89FpWW1Ju+QhOny7ueu5GviKbvquN+g4GITuM3XV6K5GeMMzSK9

    8XZnJpnGPz3/8gcFKM6o7FoAhEjpCkiPhLZ0oJU1eN2VdyKpr27bLQUcFAbgkSPu

    U3ACsQ7mxtUNl2FmXPJuBoAq6l51ubsGHHGaRHvdEK8guNBBLhxi4P7ftYmPBqMP

    YP9da1Kn8EzBo/sJkgdjCCzH1WHzp8xdExXeJPYqCfGHQx2BUkvFX8y5V0ZfMzDG

    5eHsyuSwM1+dnged+mbgDbxrEkDjY/P2zxPtYmEqS/nvnsPzIyu/rp8qiB+6MZs9

    nvOTrbKQ/w==

    -----END CERTIFICATE-----

    [root@node1 Certs]#


    URL: https://tools.keycdn.com/ssl


    Validate of example.key file:

    Validation of example.crt file:


    Regards,

    Mallik


    🌟 Proud to be an Oracle ACE Pro! 🚀

    🌟 Proud to be an Oracle ACE Pro! 🚀 I’m excited to share my official Oracle ACE Profile with the Oracle community. 👨‍💻 Mallikarjun ...