Re: Suggestion reg. encryption ??
Hi Craig, yes that is the one. cheers Pete In article <[EMAIL PROTECTED]>, Craig Munday <[EMAIL PROTECTED]> writes >Pete, > >Which paper of Aarons are you referring to? Is the paper entitled >"Encryption of data at rest"? > >Regards, >Craig Munday. > > > >At 05:29 AM 29/09/2003 -0800, you wrote: >>Hi Jp >> >>On the specific issue of encryption your main concern will be hiding the >>encryption key from any prying eyes. There is a couple of links to >>papers on my site about encryption in Oracle http://www.petefinnigan.com >>/orasec.htm especially the link to Aarons paper which discusses the key >>hiding issue. I also wrote a paper for iDefense.com earlier this year >>about encrypting data in Oracle databases. It was slightly high level as >>it was aimed at what the possibilities and tools available are. It is >>not in the public domain so i cannot send out copies but if you email >>them you might be able to get a copy from them. >> >>hope this helps a bit >> >>kind regards >> >>Pete >>-- >>Pete Finnigan >>email:[EMAIL PROTECTED] >>Web site: http://www.petefinnigan.com - Oracle security audit specialists >>Book:Oracle security step-by-step Guide - see http://store.sans.org for >>details. >> >>-- >>Please see the official ORACLE-L FAQ: http://www.orafaq.net >>-- >>Author: Pete Finnigan >> INET: [EMAIL PROTECTED] >> >>Fat City Network Services-- 858-538-5051 http://www.fatcity.com >>San Diego, California-- Mailing list and web hosting services >>- >>To REMOVE yourself from this mailing list, send an E-Mail message >>to: [EMAIL PROTECTED] (note EXACT spelling of 'ListGuru') and in >>the message BODY, include a line containing: UNSUB ORACLE-L >>(or the name of mailing list you want to be removed from). You may >>also send the HELP command for other information (like subscribing). > > >-- >Please see the official ORACLE-L FAQ: http://www.orafaq.net -- Pete Finnigan email:[EMAIL PROTECTED] Web site: http://www.petefinnigan.com - Oracle security audit specialists Book:Oracle security step-by-step Guide - see http://store.sans.org for details. -- Please see the official ORACLE-L FAQ: http://www.orafaq.net -- Author: Pete Finnigan INET: [EMAIL PROTECTED] Fat City Network Services-- 858-538-5051 http://www.fatcity.com San Diego, California-- Mailing list and web hosting services - To REMOVE yourself from this mailing list, send an E-Mail message to: [EMAIL PROTECTED] (note EXACT spelling of 'ListGuru') and in the message BODY, include a line containing: UNSUB ORACLE-L (or the name of mailing list you want to be removed from). You may also send the HELP command for other information (like subscribing).
Re: Suggestion reg. encryption ??
Hi Jp, No its not the paper you mention from iDefense but the one you got is not too bad. My paper was called "Encrypting data in the Oracle database" - as i say if you email them you may be able to get it. kind regards Pete In article <[EMAIL PROTECTED]>, Prem Khanna J <[EMAIL PROTECTED]> writes >Hi Pete, > >Thanx a lot. > >http://www.petefinnigan.com/orasec.htm > >This URL of yours has a lot related to encryption. >As u said,i received "Best Practices for Securing Oracle" >from iDefense.com.Is this the paper u mentioned about ? > -- Pete Finnigan email:[EMAIL PROTECTED] Web site: http://www.petefinnigan.com - Oracle security audit specialists Book:Oracle security step-by-step Guide - see http://store.sans.org for details. -- Please see the official ORACLE-L FAQ: http://www.orafaq.net -- Author: Pete Finnigan INET: [EMAIL PROTECTED] Fat City Network Services-- 858-538-5051 http://www.fatcity.com San Diego, California-- Mailing list and web hosting services - To REMOVE yourself from this mailing list, send an E-Mail message to: [EMAIL PROTECTED] (note EXACT spelling of 'ListGuru') and in the message BODY, include a line containing: UNSUB ORACLE-L (or the name of mailing list you want to be removed from). You may also send the HELP command for other information (like subscribing).
Re: Suggestion reg. encryption ??
Pete, Which paper of Aarons are you referring to? Is the paper entitled "Encryption of data at rest"? Regards, Craig Munday. At 05:29 AM 29/09/2003 -0800, you wrote: Hi Jp On the specific issue of encryption your main concern will be hiding the encryption key from any prying eyes. There is a couple of links to papers on my site about encryption in Oracle http://www.petefinnigan.com /orasec.htm especially the link to Aarons paper which discusses the key hiding issue. I also wrote a paper for iDefense.com earlier this year about encrypting data in Oracle databases. It was slightly high level as it was aimed at what the possibilities and tools available are. It is not in the public domain so i cannot send out copies but if you email them you might be able to get a copy from them. hope this helps a bit kind regards Pete -- Pete Finnigan email:[EMAIL PROTECTED] Web site: http://www.petefinnigan.com - Oracle security audit specialists Book:Oracle security step-by-step Guide - see http://store.sans.org for details. -- Please see the official ORACLE-L FAQ: http://www.orafaq.net -- Author: Pete Finnigan INET: [EMAIL PROTECTED] Fat City Network Services-- 858-538-5051 http://www.fatcity.com San Diego, California-- Mailing list and web hosting services - To REMOVE yourself from this mailing list, send an E-Mail message to: [EMAIL PROTECTED] (note EXACT spelling of 'ListGuru') and in the message BODY, include a line containing: UNSUB ORACLE-L (or the name of mailing list you want to be removed from). You may also send the HELP command for other information (like subscribing). -- Please see the official ORACLE-L FAQ: http://www.orafaq.net -- Author: Craig Munday INET: [EMAIL PROTECTED] Fat City Network Services-- 858-538-5051 http://www.fatcity.com San Diego, California-- Mailing list and web hosting services - To REMOVE yourself from this mailing list, send an E-Mail message to: [EMAIL PROTECTED] (note EXACT spelling of 'ListGuru') and in the message BODY, include a line containing: UNSUB ORACLE-L (or the name of mailing list you want to be removed from). You may also send the HELP command for other information (like subscribing).
Re: Suggestion reg. encryption ??
Hi Pete, Thanx a lot. http://www.petefinnigan.com/orasec.htm This URL of yours has a lot related to encryption. As u said,i received "Best Practices for Securing Oracle" from iDefense.com.Is this the paper u mentioned about ? Hi Craig, thanx a lot for your wonderful reply (and for your precious time spent to explain me). u have given me surplus info'. i need to look into the resources u had given me. HSM would be the last option and many many thanx for letting me know that. Hi Ranganath, ton of thanx for your pretty example. i am not able to reach http://www.protegrity.com/. can u ? hope it's down. thanx for your prompt reply..as u always do :) Regards, Jp. -- Please see the official ORACLE-L FAQ: http://www.orafaq.net -- Author: Prem Khanna J INET: [EMAIL PROTECTED] Fat City Network Services-- 858-538-5051 http://www.fatcity.com San Diego, California-- Mailing list and web hosting services - To REMOVE yourself from this mailing list, send an E-Mail message to: [EMAIL PROTECTED] (note EXACT spelling of 'ListGuru') and in the message BODY, include a line containing: UNSUB ORACLE-L (or the name of mailing list you want to be removed from). You may also send the HELP command for other information (like subscribing).
Re: Suggestion reg. encryption ??
Hi, For your reference, have a look at http://www.cybcon.com/~jkstill/util/encryption/encryption.html there is some good information from Jared, and a PL/SQL implementation of the Blowfish algorithm that I donated. In answer to your first question: 1) Security being the priority , which would be the way to go & why ? I'm not a big fan of the dbms_obfuscation_toolkit in its current form. Although it gives you an implementation of the DES and Triple DES algorithms it suffers from the following: 1) It seems to only provide Electronic Code Book encryption, if you want Cipher Block Chaining you need to implement this yourself; 2) The encryption is performed in the server's memory with both the key and data in the clear at some point; and even more serious 3) It does not provide for any key management. The absence of key management is quite a draw back and in my opinion makes the dbms_obfuscation_toolkit (and my PL/SQL Blowfish package for that matter) next to useless as a tool for improving data security. The Oracle documentation talks a little about key management and offers some naive suggestions for filling the gap. In my opinion here is some of what the documentation missed: 1) The encryption key(s) should be stored within a tamper resistant and tamper evident device fitted with movement detectors (ie. the key is erased if movement is detected). 2) No one person should know the entire key. Typically encryption keys are randomly generated and exported in their component form (2+ components) that are then given to separate component holders. 3) There should be functions available so that derived keys are never exposed in the clear outside of a secure device. 4) The PL/SQL suggestion within the Oracle documentation would seem to make it difficult to roll the key when it needs to be changed. Also literal values do not get obfuscated by the wrap command so I didn't really understand how wrap was to provide any protection. Could someone explain this to me? 5) Storing the clear keys in the database means that not only does your database security need to be reviewed but most likely your security procedures around your on-site and off-site backups now need to be strengthened. Most companies seem to have third parties storing off-site backups - it is probably not a good idea to hand a backup tape to someone that contains both keys and the data that the keys protect. Regarding Java, the Java Cryptographic Extensions API will give you an interface to a key store and encryption algorithms. It is up to the merits of a particular JCE implementation that you have to examine, some implementations are secure, some are not. In answer to your second question: 2. How is it normally done ? From reading this list, my guess is that some people have implemented encryption using the dbms_obfuscation_toolkit. Some people have asked me if they could use the Blowfish package I donated to Jared's site. Some people have used the Java Cryptographic Provider provided by SUN within their application. And from my own experiences I know others have implemented their own cryptographic code in Java/C++/etc. If you are serious about security being your priority then I would suggest that you make use of one of a number of Hardware Security Modules (HSM) available on the market. They have a bit of a learning curve to them but they are the only way to go for any serious endeavor. Forget about dbms_obfuscation_toolkit. I've worked with a couple of devices and have provided a brief description of them below. 1) Thales RG7100 HSM (RG8000 now available) . The device can connect to your host system via a number of interfaces (ethernet included). This device provides key management functions and stores one master key (called the LMK) in its secure memory. All other keys (ie. your key to encrypt the credit card numbers) are stored external (ie. in a file or database) to the device encrypted under the LMK such that they can only be decrypted within the secure memory of the device (ie. the keys are never exposed in the clear). This device would be useful if you wanted to share a single device between a number of hosts that needed to perform encrypts/decrypts on credit card numbers. Alternatively, it is quite easy to conceive an application that multiplexes encrypt/decrypt requests to a pool of HSMs if one HSM is not fast enough for your needs. Although the device is fast, crypto can still take a bit of time. 2) Eracom CSA8000. This device is a card that you insert into a PCI slot and has a Java Cryptographic Extensions API. Like the Thales HSM, this device also has a tamper detector protecting its secure memory. Unlike the Thales HSM this device has approximately 1MB of memory for key storage and has no LMK - you store your actual encryption key inside the secure memory of the board - not externally. The device provides key management functionality. I think Eracom also make a card that will do SSL too. 3) I heard that IBM make
Re: Suggestion reg. encryption ??
Hi Jp On the specific issue of encryption your main concern will be hiding the encryption key from any prying eyes. There is a couple of links to papers on my site about encryption in Oracle http://www.petefinnigan.com /orasec.htm especially the link to Aarons paper which discusses the key hiding issue. I also wrote a paper for iDefense.com earlier this year about encrypting data in Oracle databases. It was slightly high level as it was aimed at what the possibilities and tools available are. It is not in the public domain so i cannot send out copies but if you email them you might be able to get a copy from them. hope this helps a bit kind regards Pete -- Pete Finnigan email:[EMAIL PROTECTED] Web site: http://www.petefinnigan.com - Oracle security audit specialists Book:Oracle security step-by-step Guide - see http://store.sans.org for details. -- Please see the official ORACLE-L FAQ: http://www.orafaq.net -- Author: Pete Finnigan INET: [EMAIL PROTECTED] Fat City Network Services-- 858-538-5051 http://www.fatcity.com San Diego, California-- Mailing list and web hosting services - To REMOVE yourself from this mailing list, send an E-Mail message to: [EMAIL PROTECTED] (note EXACT spelling of 'ListGuru') and in the message BODY, include a line containing: UNSUB ORACLE-L (or the name of mailing list you want to be removed from). You may also send the HELP command for other information (like subscribing).
RE: suggestion
Title: RE: suggestion
this is the format instancename_ora_ospid.trc
perhaps this might help ...
SELECT c.VALUE || '/' || LOWER(INSTANCE) || '_ora_' ||
LTRIM(TO_CHAR(a.spid,'fm999')) || '.trc'
FROM v$process a, v$session b, v$parameter c, v$thread c
WHERE a.addr = b.paddr
AND b.audsid = USERENV('sessionid')
AND c.NAME = 'user_dump_dest'
/
Raj
Rajendra dot Jamadagni at nospamespn dot com
All Views expressed in this email are strictly personal.
QOTD: Any clod can have facts, having an opinion is an art !
-Original Message-
From: Norris, Gregory T [ITS] [mailto:[EMAIL PROTECTED]]
Sent: Wednesday, September 24, 2003 10:15 AM
To: Multiple recipients of list ORACLE-L
Subject: RE: suggestion
How did you go about determining the tracefile name within the trigger? I don't think I've ever seen an example for this...
-Original Message-
Sent: Wednesday, September 24, 2003 8:05 AM
To: Multiple recipients of list ORACLE-L
hmmm... here is what I did ...
change user_dump_dest to a file system which has lots of space, 100G in our case
modify a logon trigger and for a certain group of people (based on a role) "execute dbms_support.start_trace";
Create a logoff trigger that raises a alert user_logoff and sends a trace file string (actual name of the trace file).
I had a SQR report running on both sides of RAC waiting to respond to this alert.
As soon as this alert came, it waited 1 second and then went to system and verified that it owned the trace file (based on the instance) and then gzipped it and based on the date moved to a directory.
When we got tired of collecting trace files, we stopped the process. All of this is fairly easy to do, it took me about an hour to put this all together.
If you just want sql text, you may want to use "dbms_support.start_trace(false,true)" .. it will avoid wait events listing but will give you bind variables.
Raj
Rajendra dot Jamadagni at nospamespn dot com
All Views expressed in this email are strictly personal.
QOTD: Any clod can have facts, having an opinion is an art !
-Original Message-
Sent: Tuesday, September 23, 2003 9:10 PM
To: Multiple recipients of list ORACLE-L
Actually, you can capture SQLs relatively inexpensively by using FGA - simply add the "audit_condition => '1=1'" when adding a policy to each table.
For OLTP, this wouldn't make much sense. For ad-hoc (DSS), what you are going to do with all those captured SQLs is another story.
- Original Message -
To: Multiple recipients of list ORACLE-L
Sent: Wednesday, September 24, 2003 11:09 AM
For statistics, logon & logoff triggers + v$mystat + autonomous transactions.
If you want to capture all sql, it will be hard & very resource hungry, you either enable trace for given session (which slows stuff down enormously) or poll v$sql or v$open_cursor frequently. This isn't a good idea either. You might want to look at fine grained auditing if you want to track which data is viewed by anybody.
Tanel.
- Original Message -
To: Multiple recipients of list ORACLE-L
Sent: Wednesday, September 24, 2003 1:39 AM
hi
there is a requirement for capturing sqls and cpu consumed by any session logging into the database . this info should be stored in the database.
can you please give me suggestions as to how i do this?
thanks
sai
--
Please see the official ORACLE-L FAQ: http://www.orafaq.net
--
Author: Norris, Gregory T [ITS]
INET: [EMAIL PROTECTED]
Fat City Network Services -- 858-538-5051 http://www.fatcity.com
San Diego, California -- Mailing list and web hosting services
-
To REMOVE yourself from this mailing list, send an E-Mail message
to: [EMAIL PROTECTED] (note EXACT spelling of 'ListGuru') and in
the message BODY, include a line containing: UNSUB ORACLE-L
(or the name of mailing list you want to be removed from). You may
also send the HELP command for other information (like subscribing).
This e-mail
message is confidential, intended only for the named recipient(s) above and may
contain information that is privileged, attorney work product or exempt from
disclosure under applicable law. If you have received this message in error, or are
not the named recipient(s), please immediately notify corporate MIS at (860) 766-2000
and delete this e-mail message from your computer, Thank
you.*2
RE: suggestion
How did you go about determining the tracefile name within the trigger? I don't think I've ever seen an example for this... -Original Message- Sent: Wednesday, September 24, 2003 8:05 AM To: Multiple recipients of list ORACLE-L hmmm... here is what I did ... change user_dump_dest to a file system which has lots of space, 100G in our case modify a logon trigger and for a certain group of people (based on a role) "execute dbms_support.start_trace"; Create a logoff trigger that raises a alert user_logoff and sends a trace file string (actual name of the trace file). I had a SQR report running on both sides of RAC waiting to respond to this alert. As soon as this alert came, it waited 1 second and then went to system and verified that it owned the trace file (based on the instance) and then gzipped it and based on the date moved to a directory. When we got tired of collecting trace files, we stopped the process. All of this is fairly easy to do, it took me about an hour to put this all together. If you just want sql text, you may want to use "dbms_support.start_trace(false,true)" .. it will avoid wait events listing but will give you bind variables. Raj Rajendra dot Jamadagni at nospamespn dot com All Views expressed in this email are strictly personal. QOTD: Any clod can have facts, having an opinion is an art ! -Original Message- Sent: Tuesday, September 23, 2003 9:10 PM To: Multiple recipients of list ORACLE-L Actually, you can capture SQLs relatively inexpensively by using FGA - simply add the "audit_condition => '1=1'" when adding a policy to each table. For OLTP, this wouldn't make much sense. For ad-hoc (DSS), what you are going to do with all those captured SQLs is another story. - Original Message - To: Multiple recipients of list ORACLE-L Sent: Wednesday, September 24, 2003 11:09 AM For statistics, logon & logoff triggers + v$mystat + autonomous transactions. If you want to capture all sql, it will be hard & very resource hungry, you either enable trace for given session (which slows stuff down enormously) or poll v$sql or v$open_cursor frequently. This isn't a good idea either. You might want to look at fine grained auditing if you want to track which data is viewed by anybody. Tanel. - Original Message - To: Multiple recipients of list ORACLE-L Sent: Wednesday, September 24, 2003 1:39 AM hi there is a requirement for capturing sqls and cpu consumed by any session logging into the database . this info should be stored in the database. can you please give me suggestions as to how i do this? thanks sai -- Please see the official ORACLE-L FAQ: http://www.orafaq.net -- Author: Norris, Gregory T [ITS] INET: [EMAIL PROTECTED] Fat City Network Services-- 858-538-5051 http://www.fatcity.com San Diego, California-- Mailing list and web hosting services - To REMOVE yourself from this mailing list, send an E-Mail message to: [EMAIL PROTECTED] (note EXACT spelling of 'ListGuru') and in the message BODY, include a line containing: UNSUB ORACLE-L (or the name of mailing list you want to be removed from). You may also send the HELP command for other information (like subscribing).
RE: suggestion
hmmm... here is what I did ... change user_dump_dest to a file system which has lots of space, 100G in our case modify a logon trigger and for a certain group of people (based on a role) "execute dbms_support.start_trace"; Create a logoff trigger that raises a alert user_logoff and sends a trace file string (actual name of the trace file). I had a SQR report running on both sides of RAC waiting to respond to this alert. As soon as this alert came, it waited 1 second and then went to system and verified that it owned the trace file (based on the instance) and then gzipped it and based on the date moved to a directory. When we got tired of collecting trace files, we stopped the process. All of this is fairly easy to do, it took me about an hour to put this all together. If you just want sql text, you may want to use "dbms_support.start_trace(false,true)" .. it will avoid wait events listing but will give you bind variables. Raj Rajendra dot Jamadagni at nospamespn dot com All Views expressed in this email are strictly personal. QOTD: Any clod can have facts, having an opinion is an art ! -Original Message-From: Binley Lim [mailto:[EMAIL PROTECTED]Sent: Tuesday, September 23, 2003 9:10 PMTo: Multiple recipients of list ORACLE-LSubject: Re: suggestion Actually, you can capture SQLs relatively inexpensively by using FGA - simply add the "audit_condition => '1=1'" when adding a policy to each table. For OLTP, this wouldn't make much sense. For ad-hoc (DSS), what you are going to do with all those captured SQLs is another story. - Original Message - From: Tanel Poder To: Multiple recipients of list ORACLE-L Sent: Wednesday, September 24, 2003 11:09 AM Subject: Re: suggestion For statistics, logon & logoff triggers + v$mystat + autonomous transactions. If you want to capture all sql, it will be hard & very resource hungry, you either enable trace for given session (which slows stuff down enormously) or poll v$sql or v$open_cursor frequently. This isn't a good idea either. You might want to look at fine grained auditing if you want to track which data is viewed by anybody. Tanel. - Original Message - From: Sai Selvaganesan To: Multiple recipients of list ORACLE-L Sent: Wednesday, September 24, 2003 1:39 AM Subject: suggestion hi there is a requirement for capturing sqls and cpu consumed by any session logging into the database . this info should be stored in the database. can you please give me suggestions as to how i do this? thanks sai This e-mail message is confidential, intended only for the named recipient(s) above and may contain information that is privileged, attorney work product or exempt from disclosure under applicable law. If you have received this message in error, or are not the named recipient(s), please immediately notify corporate MIS at (860) 766-2000 and delete this e-mail message from your computer, Thank you.*2
Re: suggestion
Actually, you can capture SQLs relatively inexpensively by using FGA - simply add the "audit_condition => '1=1'" when adding a policy to each table. For OLTP, this wouldn't make much sense. For ad-hoc (DSS), what you are going to do with all those captured SQLs is another story. - Original Message - From: Tanel Poder To: Multiple recipients of list ORACLE-L Sent: Wednesday, September 24, 2003 11:09 AM Subject: Re: suggestion For statistics, logon & logoff triggers + v$mystat + autonomous transactions. If you want to capture all sql, it will be hard & very resource hungry, you either enable trace for given session (which slows stuff down enormously) or poll v$sql or v$open_cursor frequently. This isn't a good idea either. You might want to look at fine grained auditing if you want to track which data is viewed by anybody. Tanel. - Original Message - From: Sai Selvaganesan To: Multiple recipients of list ORACLE-L Sent: Wednesday, September 24, 2003 1:39 AM Subject: suggestion hi there is a requirement for capturing sqls and cpu consumed by any session logging into the database . this info should be stored in the database. can you please give me suggestions as to how i do this? thanks sai
Re: suggestion
For statistics, logon & logoff triggers + v$mystat + autonomous transactions. If you want to capture all sql, it will be hard & very resource hungry, you either enable trace for given session (which slows stuff down enormously) or poll v$sql or v$open_cursor frequently. This isn't a good idea either. You might want to look at fine grained auditing if you want to track which data is viewed by anybody. Tanel. - Original Message - From: Sai Selvaganesan To: Multiple recipients of list ORACLE-L Sent: Wednesday, September 24, 2003 1:39 AM Subject: suggestion hi there is a requirement for capturing sqls and cpu consumed by any session logging into the database . this info should be stored in the database. can you please give me suggestions as to how i do this? thanks sai
RE: suggestion w/c platforms to choose from...
Grace - Well if they want to build all you mentioned in-house, > order taking , purchase order and accounting module,hr then I wouldn't worry too much about server sizing because it'll take them forever to get all that done. Well, I just couldn't avoid tossing that remark in, please excuse it. Dennis Williams DBA, 40%OCP Lifetouch, Inc. [EMAIL PROTECTED] -Original Message- Sent: Wednesday, November 06, 2002 6:34 PM To: Multiple recipients of list ORACLE-L this will be build in-house... - Original Message - To: "Multiple recipients of list ORACLE-L" <[EMAIL PROTECTED]> Sent: Wednesday, November 06, 2002 11:56 PM > Grace - Amen to Yechiel's first rule. At the VERY least, warn your > management that they need to consider a second system for the datamart. This > way, if it works terribly, you don't look dumb. >My experience is mainly Unix, so 200 OLTP users on an NT box sounds iffy > from a throughput point of view. I would tend to go with a small 4-CPU > Solaris server, especially if this is a critical application. From what I've > heard, and I will defer to list members that have more experience here, 200 > ERP users are near the upper limit of Windows-based systems, and if you > ended up undersizing the system or you add users faster than expected, you > might run out of headroom. A lot would depend on what your site's experience > base is. If you are used to maintaining high-availability NT systems, then > that might work well for you. >If you care to mention which ERP system you will be using for the order > taking, PO, HR, GL, etc., you may garner advice specific to that system. > Many of us support ERP systems of different stripes and it is possible that > different ERP systems behave better on some platforms. > > Dennis Williams > DBA, 40%OCP > Lifetouch, Inc. > [EMAIL PROTECTED] > > > -Original Message- > Sent: Wednesday, November 06, 2002 6:49 AM > To: Multiple recipients of list ORACLE-L > > > First rule: Do not mix OLTP and datamart. > Datamart access is very heavy and complex SQL's that will impact your OLTP > system. > > I think that an NT with 2-4 CPUs and a lot of memory will do (a not so > educated guess). > Controller with a lot of cache memory and fast disks (15,000 rpm). > > Yechiel Adar > Mehish > - Original Message - > To: Multiple recipients of list ORACLE-L <[EMAIL PROTECTED]> > Sent: Wednesday, November 06, 2002 3:48 AM > > > > database will be used for oltp and data mart > > # of users -- 200 > > very critical, since order taking , purchase order and accounting > module,hr > > will run on it.. > > > > - Original Message - > > To: "Multiple recipients of list ORACLE-L" <[EMAIL PROTECTED]> > > Sent: Tuesday, November 05, 2002 9:03 PM > > > > > > > As a rule buy the biggest, meanest, fault tolerance, with gigabytes of > > > memory and terabytes of disk storage that you can buy. > > > > > > If you will provide more data about: > > > > > > 1) The size of the database > > > 2) How many users > > > 3) How critical is the system > > > 4) The use of the system - data warehouse, OLTP etc > > > > > > then you will probably get a more specified answer. > > > > > > Yechiel Adar > > > Mehish > > > - Original Message - > > > To: Multiple recipients of list ORACLE-L <[EMAIL PROTECTED]> > > > Sent: Tuesday, November 05, 2002 2:13 PM > > > > > > > > > > hi, > > > > can anyone suggestion w/c platform should i used to run oracle? wat > are > > > the > > > > things to consider in choosing platform? > > > > > > > > thanks > > > > > > > > Best regards, > > > > Grace Lim > > > > MIS Department > > > > Suy Sing Comm'l Corp. > > > > T- (632)-2474134 > > > > F- (632)-2474160 > > > > > > > > -- > > > > Please see the official ORACLE-L FAQ: http://www.orafaq.com > > > > -- > > > > Author: grace > > > > INET: [EMAIL PROTECTED] > > > > > > > > Fat City Network Services-- 858-538-5051 http://www.fatcity.com > > > > San Diego, California-- Mailing list and web hosting services > > > > - > > > > To REMOVE yourself from this mailing list, send an E-Mail message > > > > to: [EMAIL PROTECTED] (note EXACT spelling of 'ListGuru') and in > > > > the message BODY, include a line containing: UNSUB ORACLE-L > > > > (or the name of mailing list you want to be removed from). You may > > > > also send the HELP command for other information (like subscribing). > > > > > > -- > > > Please see the official ORACLE-L FAQ: http://www.orafaq.com > > > -- > > > Author: Yechiel Adar > > > INET: [EMAIL PROTECTED] > > > > > > Fat City Network Services-- 858-538-5051 http://www.fatcity.com > > > San Diego, California-- Mailing list and web hosting services > > > - > > > To REMOVE yourself from this mailing list, send an E-Mail message > > > to: [EMAIL PROTECTED] (note EXACT spelling of 'ListGuru') and in > > >
Re: suggestion w/c platforms to choose from...
this will be build in-house... - Original Message - To: "Multiple recipients of list ORACLE-L" <[EMAIL PROTECTED]> Sent: Wednesday, November 06, 2002 11:56 PM > Grace - Amen to Yechiel's first rule. At the VERY least, warn your > management that they need to consider a second system for the datamart. This > way, if it works terribly, you don't look dumb. >My experience is mainly Unix, so 200 OLTP users on an NT box sounds iffy > from a throughput point of view. I would tend to go with a small 4-CPU > Solaris server, especially if this is a critical application. From what I've > heard, and I will defer to list members that have more experience here, 200 > ERP users are near the upper limit of Windows-based systems, and if you > ended up undersizing the system or you add users faster than expected, you > might run out of headroom. A lot would depend on what your site's experience > base is. If you are used to maintaining high-availability NT systems, then > that might work well for you. >If you care to mention which ERP system you will be using for the order > taking, PO, HR, GL, etc., you may garner advice specific to that system. > Many of us support ERP systems of different stripes and it is possible that > different ERP systems behave better on some platforms. > > Dennis Williams > DBA, 40%OCP > Lifetouch, Inc. > [EMAIL PROTECTED] > > > -Original Message- > Sent: Wednesday, November 06, 2002 6:49 AM > To: Multiple recipients of list ORACLE-L > > > First rule: Do not mix OLTP and datamart. > Datamart access is very heavy and complex SQL's that will impact your OLTP > system. > > I think that an NT with 2-4 CPUs and a lot of memory will do (a not so > educated guess). > Controller with a lot of cache memory and fast disks (15,000 rpm). > > Yechiel Adar > Mehish > - Original Message - > To: Multiple recipients of list ORACLE-L <[EMAIL PROTECTED]> > Sent: Wednesday, November 06, 2002 3:48 AM > > > > database will be used for oltp and data mart > > # of users -- 200 > > very critical, since order taking , purchase order and accounting > module,hr > > will run on it.. > > > > - Original Message - > > To: "Multiple recipients of list ORACLE-L" <[EMAIL PROTECTED]> > > Sent: Tuesday, November 05, 2002 9:03 PM > > > > > > > As a rule buy the biggest, meanest, fault tolerance, with gigabytes of > > > memory and terabytes of disk storage that you can buy. > > > > > > If you will provide more data about: > > > > > > 1) The size of the database > > > 2) How many users > > > 3) How critical is the system > > > 4) The use of the system - data warehouse, OLTP etc > > > > > > then you will probably get a more specified answer. > > > > > > Yechiel Adar > > > Mehish > > > - Original Message - > > > To: Multiple recipients of list ORACLE-L <[EMAIL PROTECTED]> > > > Sent: Tuesday, November 05, 2002 2:13 PM > > > > > > > > > > hi, > > > > can anyone suggestion w/c platform should i used to run oracle? wat > are > > > the > > > > things to consider in choosing platform? > > > > > > > > thanks > > > > > > > > Best regards, > > > > Grace Lim > > > > MIS Department > > > > Suy Sing Comm'l Corp. > > > > T- (632)-2474134 > > > > F- (632)-2474160 > > > > > > > > -- > > > > Please see the official ORACLE-L FAQ: http://www.orafaq.com > > > > -- > > > > Author: grace > > > > INET: [EMAIL PROTECTED] > > > > > > > > Fat City Network Services-- 858-538-5051 http://www.fatcity.com > > > > San Diego, California-- Mailing list and web hosting services > > > > - > > > > To REMOVE yourself from this mailing list, send an E-Mail message > > > > to: [EMAIL PROTECTED] (note EXACT spelling of 'ListGuru') and in > > > > the message BODY, include a line containing: UNSUB ORACLE-L > > > > (or the name of mailing list you want to be removed from). You may > > > > also send the HELP command for other information (like subscribing). > > > > > > -- > > > Please see the official ORACLE-L FAQ: http://www.orafaq.com > > > -- > > > Author: Yechiel Adar > > > INET: [EMAIL PROTECTED] > > > > > > Fat City Network Services-- 858-538-5051 http://www.fatcity.com > > > San Diego, California-- Mailing list and web hosting services > > > - > > > To REMOVE yourself from this mailing list, send an E-Mail message > > > to: [EMAIL PROTECTED] (note EXACT spelling of 'ListGuru') and in > > > the message BODY, include a line containing: UNSUB ORACLE-L > > > (or the name of mailing list you want to be removed from). You may > > > also send the HELP command for other information (like subscribing). > > > > -- > > Please see the official ORACLE-L FAQ: http://www.orafaq.com > > -- > > Author: grace > > INET: [EMAIL PROTECTED] > > > > Fat City Network Services-- 858-538-5051 http://www.fatcity.com > > San Diego, California-- Mailing list and web hosti
RE: suggestion w/c platforms to choose from...
Grace - Amen to Yechiel's first rule. At the VERY least, warn your management that they need to consider a second system for the datamart. This way, if it works terribly, you don't look dumb. My experience is mainly Unix, so 200 OLTP users on an NT box sounds iffy from a throughput point of view. I would tend to go with a small 4-CPU Solaris server, especially if this is a critical application. From what I've heard, and I will defer to list members that have more experience here, 200 ERP users are near the upper limit of Windows-based systems, and if you ended up undersizing the system or you add users faster than expected, you might run out of headroom. A lot would depend on what your site's experience base is. If you are used to maintaining high-availability NT systems, then that might work well for you. If you care to mention which ERP system you will be using for the order taking, PO, HR, GL, etc., you may garner advice specific to that system. Many of us support ERP systems of different stripes and it is possible that different ERP systems behave better on some platforms. Dennis Williams DBA, 40%OCP Lifetouch, Inc. [EMAIL PROTECTED] -Original Message- Sent: Wednesday, November 06, 2002 6:49 AM To: Multiple recipients of list ORACLE-L First rule: Do not mix OLTP and datamart. Datamart access is very heavy and complex SQL's that will impact your OLTP system. I think that an NT with 2-4 CPUs and a lot of memory will do (a not so educated guess). Controller with a lot of cache memory and fast disks (15,000 rpm). Yechiel Adar Mehish - Original Message - To: Multiple recipients of list ORACLE-L <[EMAIL PROTECTED]> Sent: Wednesday, November 06, 2002 3:48 AM > database will be used for oltp and data mart > # of users -- 200 > very critical, since order taking , purchase order and accounting module,hr > will run on it.. > > - Original Message - > To: "Multiple recipients of list ORACLE-L" <[EMAIL PROTECTED]> > Sent: Tuesday, November 05, 2002 9:03 PM > > > > As a rule buy the biggest, meanest, fault tolerance, with gigabytes of > > memory and terabytes of disk storage that you can buy. > > > > If you will provide more data about: > > > > 1) The size of the database > > 2) How many users > > 3) How critical is the system > > 4) The use of the system - data warehouse, OLTP etc > > > > then you will probably get a more specified answer. > > > > Yechiel Adar > > Mehish > > - Original Message - > > To: Multiple recipients of list ORACLE-L <[EMAIL PROTECTED]> > > Sent: Tuesday, November 05, 2002 2:13 PM > > > > > > > hi, > > > can anyone suggestion w/c platform should i used to run oracle? wat are > > the > > > things to consider in choosing platform? > > > > > > thanks > > > > > > Best regards, > > > Grace Lim > > > MIS Department > > > Suy Sing Comm'l Corp. > > > T- (632)-2474134 > > > F- (632)-2474160 > > > > > > -- > > > Please see the official ORACLE-L FAQ: http://www.orafaq.com > > > -- > > > Author: grace > > > INET: [EMAIL PROTECTED] > > > > > > Fat City Network Services-- 858-538-5051 http://www.fatcity.com > > > San Diego, California-- Mailing list and web hosting services > > > - > > > To REMOVE yourself from this mailing list, send an E-Mail message > > > to: [EMAIL PROTECTED] (note EXACT spelling of 'ListGuru') and in > > > the message BODY, include a line containing: UNSUB ORACLE-L > > > (or the name of mailing list you want to be removed from). You may > > > also send the HELP command for other information (like subscribing). > > > > -- > > Please see the official ORACLE-L FAQ: http://www.orafaq.com > > -- > > Author: Yechiel Adar > > INET: [EMAIL PROTECTED] > > > > Fat City Network Services-- 858-538-5051 http://www.fatcity.com > > San Diego, California-- Mailing list and web hosting services > > - > > To REMOVE yourself from this mailing list, send an E-Mail message > > to: [EMAIL PROTECTED] (note EXACT spelling of 'ListGuru') and in > > the message BODY, include a line containing: UNSUB ORACLE-L > > (or the name of mailing list you want to be removed from). You may > > also send the HELP command for other information (like subscribing). > > -- > Please see the official ORACLE-L FAQ: http://www.orafaq.com > -- > Author: grace > INET: [EMAIL PROTECTED] > > Fat City Network Services-- 858-538-5051 http://www.fatcity.com > San Diego, California-- Mailing list and web hosting services > - > To REMOVE yourself from this mailing list, send an E-Mail message > to: [EMAIL PROTECTED] (note EXACT spelling of 'ListGuru') and in > the message BODY, include a line containing: UNSUB ORACLE-L > (or the name of mailing list you want to be removed from). You may > also send the HELP command for other information (like sub
Re: suggestion w/c platforms to choose from...
First rule: Do not mix OLTP and datamart. Datamart access is very heavy and complex SQL's that will impact your OLTP system. I think that an NT with 2-4 CPUs and a lot of memory will do (a not so educated guess). Controller with a lot of cache memory and fast disks (15,000 rpm). Yechiel Adar Mehish - Original Message - To: Multiple recipients of list ORACLE-L <[EMAIL PROTECTED]> Sent: Wednesday, November 06, 2002 3:48 AM > database will be used for oltp and data mart > # of users -- 200 > very critical, since order taking , purchase order and accounting module,hr > will run on it.. > > - Original Message - > To: "Multiple recipients of list ORACLE-L" <[EMAIL PROTECTED]> > Sent: Tuesday, November 05, 2002 9:03 PM > > > > As a rule buy the biggest, meanest, fault tolerance, with gigabytes of > > memory and terabytes of disk storage that you can buy. > > > > If you will provide more data about: > > > > 1) The size of the database > > 2) How many users > > 3) How critical is the system > > 4) The use of the system - data warehouse, OLTP etc > > > > then you will probably get a more specified answer. > > > > Yechiel Adar > > Mehish > > - Original Message - > > To: Multiple recipients of list ORACLE-L <[EMAIL PROTECTED]> > > Sent: Tuesday, November 05, 2002 2:13 PM > > > > > > > hi, > > > can anyone suggestion w/c platform should i used to run oracle? wat are > > the > > > things to consider in choosing platform? > > > > > > thanks > > > > > > Best regards, > > > Grace Lim > > > MIS Department > > > Suy Sing Comm'l Corp. > > > T- (632)-2474134 > > > F- (632)-2474160 > > > > > > -- > > > Please see the official ORACLE-L FAQ: http://www.orafaq.com > > > -- > > > Author: grace > > > INET: [EMAIL PROTECTED] > > > > > > Fat City Network Services-- 858-538-5051 http://www.fatcity.com > > > San Diego, California-- Mailing list and web hosting services > > > - > > > To REMOVE yourself from this mailing list, send an E-Mail message > > > to: [EMAIL PROTECTED] (note EXACT spelling of 'ListGuru') and in > > > the message BODY, include a line containing: UNSUB ORACLE-L > > > (or the name of mailing list you want to be removed from). You may > > > also send the HELP command for other information (like subscribing). > > > > -- > > Please see the official ORACLE-L FAQ: http://www.orafaq.com > > -- > > Author: Yechiel Adar > > INET: [EMAIL PROTECTED] > > > > Fat City Network Services-- 858-538-5051 http://www.fatcity.com > > San Diego, California-- Mailing list and web hosting services > > - > > To REMOVE yourself from this mailing list, send an E-Mail message > > to: [EMAIL PROTECTED] (note EXACT spelling of 'ListGuru') and in > > the message BODY, include a line containing: UNSUB ORACLE-L > > (or the name of mailing list you want to be removed from). You may > > also send the HELP command for other information (like subscribing). > > -- > Please see the official ORACLE-L FAQ: http://www.orafaq.com > -- > Author: grace > INET: [EMAIL PROTECTED] > > Fat City Network Services-- 858-538-5051 http://www.fatcity.com > San Diego, California-- Mailing list and web hosting services > - > To REMOVE yourself from this mailing list, send an E-Mail message > to: [EMAIL PROTECTED] (note EXACT spelling of 'ListGuru') and in > the message BODY, include a line containing: UNSUB ORACLE-L > (or the name of mailing list you want to be removed from). You may > also send the HELP command for other information (like subscribing). -- Please see the official ORACLE-L FAQ: http://www.orafaq.com -- Author: Yechiel Adar INET: [EMAIL PROTECTED] Fat City Network Services-- 858-538-5051 http://www.fatcity.com San Diego, California-- Mailing list and web hosting services - To REMOVE yourself from this mailing list, send an E-Mail message to: [EMAIL PROTECTED] (note EXACT spelling of 'ListGuru') and in the message BODY, include a line containing: UNSUB ORACLE-L (or the name of mailing list you want to be removed from). You may also send the HELP command for other information (like subscribing).
Re: suggestion w/c platforms to choose from...
database will be used for oltp and data mart # of users -- 200 very critical, since order taking , purchase order and accounting module,hr will run on it.. - Original Message - To: "Multiple recipients of list ORACLE-L" <[EMAIL PROTECTED]> Sent: Tuesday, November 05, 2002 9:03 PM > As a rule buy the biggest, meanest, fault tolerance, with gigabytes of > memory and terabytes of disk storage that you can buy. > > If you will provide more data about: > > 1) The size of the database > 2) How many users > 3) How critical is the system > 4) The use of the system - data warehouse, OLTP etc > > then you will probably get a more specified answer. > > Yechiel Adar > Mehish > - Original Message - > To: Multiple recipients of list ORACLE-L <[EMAIL PROTECTED]> > Sent: Tuesday, November 05, 2002 2:13 PM > > > > hi, > > can anyone suggestion w/c platform should i used to run oracle? wat are > the > > things to consider in choosing platform? > > > > thanks > > > > Best regards, > > Grace Lim > > MIS Department > > Suy Sing Comm'l Corp. > > T- (632)-2474134 > > F- (632)-2474160 > > > > -- > > Please see the official ORACLE-L FAQ: http://www.orafaq.com > > -- > > Author: grace > > INET: [EMAIL PROTECTED] > > > > Fat City Network Services-- 858-538-5051 http://www.fatcity.com > > San Diego, California-- Mailing list and web hosting services > > - > > To REMOVE yourself from this mailing list, send an E-Mail message > > to: [EMAIL PROTECTED] (note EXACT spelling of 'ListGuru') and in > > the message BODY, include a line containing: UNSUB ORACLE-L > > (or the name of mailing list you want to be removed from). You may > > also send the HELP command for other information (like subscribing). > > -- > Please see the official ORACLE-L FAQ: http://www.orafaq.com > -- > Author: Yechiel Adar > INET: [EMAIL PROTECTED] > > Fat City Network Services-- 858-538-5051 http://www.fatcity.com > San Diego, California-- Mailing list and web hosting services > - > To REMOVE yourself from this mailing list, send an E-Mail message > to: [EMAIL PROTECTED] (note EXACT spelling of 'ListGuru') and in > the message BODY, include a line containing: UNSUB ORACLE-L > (or the name of mailing list you want to be removed from). You may > also send the HELP command for other information (like subscribing). -- Please see the official ORACLE-L FAQ: http://www.orafaq.com -- Author: grace INET: [EMAIL PROTECTED] Fat City Network Services-- 858-538-5051 http://www.fatcity.com San Diego, California-- Mailing list and web hosting services - To REMOVE yourself from this mailing list, send an E-Mail message to: [EMAIL PROTECTED] (note EXACT spelling of 'ListGuru') and in the message BODY, include a line containing: UNSUB ORACLE-L (or the name of mailing list you want to be removed from). You may also send the HELP command for other information (like subscribing).
Re: suggestion w/c platforms to choose from...
How about a 400 CPU nCube running Oracle 9i RAC? If they still support nCube that is. ( Larry owns nCube ) Seriously though, does your app maintain HR data for 500 people, or is it a 20TB Data Warehouse? These apps may require different HW configurations. Jared "grace" <[EMAIL PROTECTED]> Sent by: [EMAIL PROTECTED] 11/05/2002 04:13 AM Please respond to ORACLE-L To: Multiple recipients of list ORACLE-L <[EMAIL PROTECTED]> cc: Subject:suggestion w/c platforms to choose from... hi, can anyone suggestion w/c platform should i used to run oracle? wat are the things to consider in choosing platform? thanks Best regards, Grace Lim MIS Department Suy Sing Comm'l Corp. T- (632)-2474134 F- (632)-2474160 -- Please see the official ORACLE-L FAQ: http://www.orafaq.com -- Author: grace INET: [EMAIL PROTECTED] Fat City Network Services-- 858-538-5051 http://www.fatcity.com San Diego, California-- Mailing list and web hosting services - To REMOVE yourself from this mailing list, send an E-Mail message to: [EMAIL PROTECTED] (note EXACT spelling of 'ListGuru') and in the message BODY, include a line containing: UNSUB ORACLE-L (or the name of mailing list you want to be removed from). You may also send the HELP command for other information (like subscribing). -- Please see the official ORACLE-L FAQ: http://www.orafaq.com -- Author: INET: [EMAIL PROTECTED] Fat City Network Services-- 858-538-5051 http://www.fatcity.com San Diego, California-- Mailing list and web hosting services - To REMOVE yourself from this mailing list, send an E-Mail message to: [EMAIL PROTECTED] (note EXACT spelling of 'ListGuru') and in the message BODY, include a line containing: UNSUB ORACLE-L (or the name of mailing list you want to be removed from). You may also send the HELP command for other information (like subscribing).
RE: suggestion w/c platforms to choose from...
How about considering what OS skills your systems admins already have? Do they have experience with HP/UX, or Solaris, or NT/2000 type systems etc.? How big is the database? How many users will it have? What will the database be used for? How much money do you have to spend? Mark -Original Message- Sent: 05 November 2002 12:14 To: Multiple recipients of list ORACLE-L hi, can anyone suggestion w/c platform should i used to run oracle? wat are the things to consider in choosing platform? thanks Best regards, Grace Lim MIS Department Suy Sing Comm'l Corp. T- (632)-2474134 F- (632)-2474160 -- Please see the official ORACLE-L FAQ: http://www.orafaq.com -- Author: grace INET: [EMAIL PROTECTED] Fat City Network Services-- 858-538-5051 http://www.fatcity.com San Diego, California-- Mailing list and web hosting services - To REMOVE yourself from this mailing list, send an E-Mail message to: [EMAIL PROTECTED] (note EXACT spelling of 'ListGuru') and in the message BODY, include a line containing: UNSUB ORACLE-L (or the name of mailing list you want to be removed from). You may also send the HELP command for other information (like subscribing). -- Please see the official ORACLE-L FAQ: http://www.orafaq.com -- Author: Mark Leith INET: [EMAIL PROTECTED] Fat City Network Services-- 858-538-5051 http://www.fatcity.com San Diego, California-- Mailing list and web hosting services - To REMOVE yourself from this mailing list, send an E-Mail message to: [EMAIL PROTECTED] (note EXACT spelling of 'ListGuru') and in the message BODY, include a line containing: UNSUB ORACLE-L (or the name of mailing list you want to be removed from). You may also send the HELP command for other information (like subscribing).
Re: suggestion w/c platforms to choose from...
As a rule buy the biggest, meanest, fault tolerance, with gigabytes of memory and terabytes of disk storage that you can buy. If you will provide more data about: 1) The size of the database 2) How many users 3) How critical is the system 4) The use of the system - data warehouse, OLTP etc then you will probably get a more specified answer. Yechiel Adar Mehish - Original Message - To: Multiple recipients of list ORACLE-L <[EMAIL PROTECTED]> Sent: Tuesday, November 05, 2002 2:13 PM > hi, > can anyone suggestion w/c platform should i used to run oracle? wat are the > things to consider in choosing platform? > > thanks > > Best regards, > Grace Lim > MIS Department > Suy Sing Comm'l Corp. > T- (632)-2474134 > F- (632)-2474160 > > -- > Please see the official ORACLE-L FAQ: http://www.orafaq.com > -- > Author: grace > INET: [EMAIL PROTECTED] > > Fat City Network Services-- 858-538-5051 http://www.fatcity.com > San Diego, California-- Mailing list and web hosting services > - > To REMOVE yourself from this mailing list, send an E-Mail message > to: [EMAIL PROTECTED] (note EXACT spelling of 'ListGuru') and in > the message BODY, include a line containing: UNSUB ORACLE-L > (or the name of mailing list you want to be removed from). You may > also send the HELP command for other information (like subscribing). -- Please see the official ORACLE-L FAQ: http://www.orafaq.com -- Author: Yechiel Adar INET: [EMAIL PROTECTED] Fat City Network Services-- 858-538-5051 http://www.fatcity.com San Diego, California-- Mailing list and web hosting services - To REMOVE yourself from this mailing list, send an E-Mail message to: [EMAIL PROTECTED] (note EXACT spelling of 'ListGuru') and in the message BODY, include a line containing: UNSUB ORACLE-L (or the name of mailing list you want to be removed from). You may also send the HELP command for other information (like subscribing).
