Wednesday, 13 March 2013

Planning 11.1.2.2.300+ change homepage default view

There is a new property available from 11.1.2.2.300 to change the default homepage view when you first log into Planning.

The default for a user is the Task List view:


The default view can be changed at application level from Task List to be either Forms or Approvals.


To change the view go to Administration > Application > Properties


Add a new property name called HOME_PAGE and to set the default view to forms add a property value of “Forms”

Restart the planning web application server.


If a user then logs in it should display the default view of Forms.


If you want to change the default view to “Approvals” then just add that as the property value and restart.

The application default view should then be Approvals and if you want to set it back to Task List then delete the property or update the value to “TaskList” and restart.

11.1.2.2 Online help or not

This is one of those blogs that has been in the back of my mind for ages and I have never been sure whether to write up, maybe because it is about online help and that is enough to send anybody to sleep.

From 11.1.2.2 the way help is delivered has changed and to be honest I know it is all over the documentation but I think through my own ignorance I pretty much ignored the following statement.

“Online Help content for EPM System products is served from a central Oracle download location, which reduces the download and installation time for EPM System. You can also install and configure online Help to run locally.”

I hardly use the help that is accessed through the various products and I tend to go directly to the EPM documentation library which has everything all under one roof.

In my experience the majority of deployments have used OHS as the web server so there are no problems in using the online though if you are unlucky enough to use IIS then the following information is important:

“Online Help served from the central Oracle download location not supported if you are using IIS as your Web server.”

Another reason for installing the help locally might be external internet access is restricted or you might find it useful to have it to hand on say a personal or training VM image, you could even install the help locally and leave it dormant so if it is required at some point it can be enabled.

Before installing the help locally let us just have a quick look at how the online help functions using OHS, if we take EAS for example:


Selecting “Online Help” opens a browser window and redirects to the Oracle documentation web site.

The redirection to the Oracle web site is controlled by including the mod_rewrite module in OHS and using the RewriteRule directive.

If you take a look in
<MIDDLEWARE_HOME>\user_projects\<instancename>\ohs\config\OHS\ohs_component you will see the OHS (apache) configuration file httpd.conf


If you open the configuration file there will be a line that has the following Include directive.


The include directive basically means that the contents of the epm_online_help.conf file are also read in when the main OHS configuration file is accessed.


The epm_online_help.conf file contains all the rules for the online help and uses the RewriteRule directive to redirect the requested help URLs to the corresponding location on the Oracle documentation site.

The EAS rule has the syntax to match all requests from /epmstatic/eas/docs/ and apply a permanent redirect (R=301) to the oracle URL, the L parameter means that it is the last rule so need to carry on trying to match.

When you click “Online Help” in the EAS console the originating URL is
http://<webserver>:<port>/epmstatic/eas/docs/en/eas/help/welcome.html

which is matched by the rule and creates a new URL on the fly:

http://www.oracle.com/pls/topic/lookup?ctx=epm921&id=/eas/docs/ + en/eas/help/welcome.html

So the redirect URL becomes
http://www.oracle.com/pls/topic/lookup?ctx=epm921&id=/eas/docs/en/eas/help/welcome.html


You will notice that is not the final URL as it is then redirected again internally on the Oracle site to the correct documentation location.

Another example of this functionality in action is the Reporting and Analysis help accessed within Workspace.


The rule defined in the configuration file is:

RewriteRule ^/epmstatic/reporting_analysis/docs/(.*) http://www.oracle.com/pls/topic/lookup?ctx=epm921&id=/reporting_analysis/docs/$1 [R=301,L]

If you run a fiddler session while accessing the help you will be able view the redirection happening.


The original request is made against
http://<httpserver>:19000/epmstatic/reporting_analysis/docs/en/raf/webuser/launch.html

which is matched by the rewrite rule and the engine creates a new URL based on the logic
http://www.oracle.com/pls/topic/lookup?ctx=epm921&id=/reporting_analysis/docs/ + en/raf/webuser/launch.html

so the redirect URL becomes
http://www.oracle.com/pls/topic/lookup?ctx=epm921&id=/reporting_analysis/docs/en/raf/webuser/launch.html


This is then redirected by Oracle to the relevant location on the documentation site.

Anyway say you don’t want to use the online help and need to install and configure the help to run locally, well you would think there might be an option in the installer and the files would be available with the rest of the EPM files in the Oracle Software Delivery Cloud but no the help can be downloaded as a zip file from http://download.oracle.com/docs/cds/epm11122.zip , I am not sure if this file is kept up to date with any changes to help documentation.

Going back to the statement in the documentation ““reduces the download and installation time for EPM System”, it took me only a few minutes to download and extract the 540MB zip file so I am wouldn’t really say it reduced the time by a noticeable amount but I understand this can depend on network connection.

To install if very simple first open the zip file


Extract the epmstatic folder to <MIDDLEWARE_HOME>\EPMSystem11R1\common on the HTTP server to merge the help documentation into the existing epmstatic directory.

Now the documentation is in place the online help will need to be disabled and this can be achieved by editing the OHS configuration file httpd.conf in
<MIDDLEWARE_HOME>\user_projects\<instancename>\ohs\config\OHS\ohs_component


Comment out the line which has the include directive to the EPM online help configuration file and then restart the services.


Accessing the help documentation should now be via the files stored on the HTTP server.

Problems starting the OPMN Essbase windows service after changing the Log On account

Back with another quick blog that was inspired from a post on the OTN forum, the poster raised an issue when changing the account to manage the OPMN windows service.

The issue relates to starting the Essbase OPMN service but I believe it is valid for any of the 11.1.2.x EPM OPMN services.

After the initial configuration of Essbase an OPMN windows service will be created and set to be controlled by the Local System account.


Say you change the Log On account for the service to different account to the one that configured Essbase,  the issue will not occur if it is the user that configured Essbase which I will explain why shortly.


Attempting to start the service should now fail with the standard timeout message.


The first place to look if any OPMN type issues occur for Essbase is logs located at
<MIDDLEWARE_HOME>\user_projects\<instancename>\diagnostics\logs\OPMN\opmn

As the OPMN process did not start then the log to check first is opmn.log and it should reveal the following information:

[opmn] [ERROR:1] [] [ons-secure] Failed to open wallet (file:E:\Oracle\Middleware\user_projects\essbase\config\OPMN\opmn\wallet) [default password] (28759)

When OPMN starts it attempts to access the Oracle wallet file cwallet.sso in the above location and fails, so why does it fail well if you check the security properties of the file you will see.
 

The only accounts that have access to the file are the SYSTEM user and the user that originally configured Essbase which in my case is FUSION so the user that I configured to start the OPMN service will not have access to the file which ends up causing the failure.
 

The simple solution is to add the account with read permissions to the wallet file.

[opmn] [NOTIFICATION:1] [90] [ons-internal] ONS server initiated
[opmn] [TRACE:1] [522] [pm-internal] PM state directory exists: E:\Oracle\Middleware\user_projects\epmsystem1\config\OPMN\opmn\states
[opmn] [NOTIFICATION:1] [675] [pm-internal] OPMN server ready. Request handling enabled
[opmn] [NOTIFICATION:1] [667] [pm-requests] Request 2 Started. Command: /start
[opmn] [NOTIFICATION:1] [662] [pm-process] Starting Process: Essbase1~EssbaseAgent~AGENT~1 (528287129:0)
[opmn] [NOTIFICATION:1] [665] [pm-process] Process Alive: Essbase1~EssbaseAgent~AGENT~1 (528287129:2768)
[opmn] [NOTIFICATION:1] [668] [pm-requests] Request 2 Completed. Command: /start

The OPMN service should now start without any problems.

Thursday, 28 February 2013

Financial Reporting Studio firewall fun

Another quick blog from me, I was recently working on an 11.1.2.2 windows environment build with a customer who had a strict policy to enable the windows firewall between servers and the users accessing the system, I have never really had much dealings with firewalls as I have been lucky enough to work with internal networks which have been firewall free.

I had no issues with the server to server communication and the users were mainly accessing the system through the web using OHS on port 19000 and the Excel addin (it still lives on), these also proved to be no problem on the firewall front.

There were a number of power users who were also report building with the Financial Reporting Studio, now Financial Reporting has never been a friend of mine and it is has been designed to give me grief.

If you have ever configured a firewall for Financial Reporting Studio then this will probably be no interest for you and you can have a nice cup of tea and devote your time to a different blog :)

I stupidly though that by now in the 11.1.2.2 world that the FR studio will just go through the http server port 19000 and all will be good but no it still seems it living with its looks in prehistoric times.

Anyway, port 19000 was already opened to allow inbound traffic to the web server.


Ok, time to log into the Financial Reporting Studio on a client machine.


Now if you have never seen the above message before you have never used FR Studio, it basically means some sort of problem exists and you are going to have to spend time trying to work it out what because there seems to have been no investment in all these years FR studio has existed in error trapping and messaging.

I have lost count of the amount of times I have seen this message be posted on forums and if you search for the message in Oracle Support you will be inundated with articles.

A quick look at the “Oracle Enterprise Performance Management System Communication Flows” spreadsheet reveals the following:


So the Studio does not just communicate directly with the HTTP server and also requires the RMI default ports of 8205-8209 opening.


The RMI ports are added to the firewall rules so time to try again.


The login was successful so case closed; come on this is FR studio we are talking about life is not so simple…
Opening a report produced:


The communication flow document did not highlight any additional ports for the Studio use but obviously it does use some.

A Wireshark trace highlighted:


 The FR Studio was communicating on a dynamic port.


I referred to the ports section of “Oracle Enterprise Performance Management System Installation Start Here” and it contained more information than the flows spreadsheet by specifying that FR also uses an ADM server with dynamic ports which can be configured in a propertiesd file.

I always incorrectly thought the ADM communication was internal but apparently not though why does it need to be dynamic?
 

Just when you think that most of the properties have been moved to the Shared Services registry you find out there are more file based ones out there.

As you can see there is commented out parameter ADM_RMI_SERVER which must mean that it takes the default value or 0 and a dynamic port range.


I set the port to a value close to the other RMI service port range and restarted the Financial Reporting web app.


 The new port was added to the inbound firewall rules.

 

Opening financial Reports was successful and there were no other notable problems, now I know there is an article in Oracle Support on a similar topic but personally I find that trying to solve the issue first proves to be much more satisfying than being handed something on a plate.

One more thing if you do see the following error popup when you log into Financial Reporting Studio:


It might be down to the version of the Studio, in my case I was running 11.1.2.2 Studio and Financial Reporting had been patched to 11.1.2.300 so it is always good to make sure the versions are exactly in sync, this can simply be achieved by downloading Studio from Workspace.

Changing the EAS web console heap size

Recently I was asked about a heap size issue with the 11.1.2.1 EAS web console, now I have never seen the following error before and probably won’t again as business rules slowly merge into calculation manager.


The reason I had probably not seen it before is because I don’t think I have had to deal with many rules that are 2MB in size and trying to save the rule in EAS would generate the error.

Anyway I was not going to even attempt to get into the reason why the rule was so big and just increase the maximum java heap size for the console.

If this was the standard EAS console then increasing the heap size is straight forward and just requires an edit to:

<drive>:\Oracle\Middleware\EPMSystem11R1\products\Essbase\eas\console\bin\admincon.bat


Update the –Xmx value from the default 256MB and restart the console and that’s it.

Increasing the maximum JVM size for the web console does not seem as simple though I am hoping somebody comes along and tells me I am idiot and provides a simpler solution.

If you start the web console you can see the min and max size being passed into Java


The default heap sizes are min 32MB and max 256MB.

I originally thought I could override the settings through the Java control panel


This did not seem to make any difference and the clients Java control panel was locked down so it wouldn’t have been that simple to get it implemented if it did work.

When starting up the EAS web console it reads a jnlp (Java Network Launching Protocol) file to set the parameters passed into the Java application so the file must exist somewhere in the EAS web application.


I found an easconsole.jnlp file sat in the easconsole.war file which is deployed with the EAS web app server.


I updated the file to increase the value held in the max-heap-size parameter, deleted the EAS web application server tmp folder and restarted the web application.

Still no joy the jnlp file that was being delivered still had the default settings, surely that is the file that is being used…Well maybe it was in previous versions but it is not being used in 11.1.2.1

I should have just left it there but it would play on my mind if I didn’t find the right file.

After searching some more I found another easconsole.jnlp


This file was hidden away within a java archive file webstart_server.jar within the EAS console web application.

I updated the file to increase the max to 1024MB, cleared the EAS web app tmp directory and browser cache then started the web app up again.


Success, this time the file I updated was the one being used by the web application.

It worth mentioning that hacking the files in a web app does work but if you patch EAS server it could wipe out any configuration settings and they would need to be applied again.

Now I am sure there is an easier solution and in the end the option taken was to use the standard EAS console with the simple method to increase JVM.

I will probably never have to do that again but at least I have written it down in case. :)

Tuesday, 22 January 2013

EPM 11.1.2.2 configurator – host unreachable

I was recently working on an 11.1.2.2 Windows 2008R2 environment build and was hit with the following error in the configurator:


The error didn’t occur at first as I was able to successfully configure a number of products but when I started up the configurator again it started to warn that the database server was unreachable, at first I was hit with an anxious feeling that I had messed up but I was sure I had configured correctly and I knew the database server was definitely accessible. 


After clicking “OK” to the warning all the correct component configuration was displayed so there were no problems connecting to the database.

I did keep on ignoring the error message as there were no signs of problems with configuration and I put it down to a possible firewall issue with the database server but the back of my mind I did want to know the answer.

I recently stumbled up the following information:

“EPM System Configurator tests whether this address is reachable. A best effort is made to reach the host, but firewalls and server configuration may block requests, resulting in an unreachable status even though some specific ports may be accessible. The Java call typically uses an ICMP ECHO REQUEST if the privilege can be obtained; otherwise, it will try to establish a TCP connection on port 7 (Echo) of the destination host.

You can ignore the warning and continue, or you can open up port 7 and the warning will no longer be displayed.”


I thought I would have a look at confirming the information was correct and enabled the firewall on a 11.1.2.2 VM environment, starting up the configurator generated the same warning message.


 
 

I did enable ICMP in the inbound firewall rules on the database server and was able to ping it but unfortunately it did not resolve the issue for me in the configurator.


I ran a Wireshark trace when opening the configurator and you can clearly see the echo request of port 7 to the database server.


I then added a new firewall inbound rule on the database server firewall to allow all connections on TCP port 7.

I ended up rebooting everything just to be sure, started up the configurator and success the warning message was no more.

So if you do get hit by the warning don’t panic as it may just a firewall causing the pain.