Sunday, 20 May 2018

Stop Application using wsadmin script



Below Script Helps you to Stop Application.

Run below script from Deployment Manager Bin
$pwd
/opt/IBM/WebSphere/AppServer/profiles/Dmgr01/bin
$./wsadmin -f /tmp/StopApp.py DefaultApp gbr_testserver1

Note :Here DefaultApp is Application Name , gbr_testserver1 is server Name

give file name as StopApp.py 
=========================================================================

import sys
from time import sleep

def stopAppOnServer(appName, serverName):
   appready = AdminApp.isAppReady(appName)
   print appready
   if appready == 'false':
                sleep(40)
                appready = AdminApp.isAppReady(appName)
                print appready
   else:
                print "stoping the application "+appName+" on "+serverName+" "
                appManager = AdminControl.queryNames("type=ApplicationManager,process="+ serverName +",*")
                if appManager == "":
                        print "Please make sure whether Application Server is up and running before stoping the applicaiton "   
                AdminControl.invoke(appManager, 'stopApplication', appName)
                appstate = AdminControl.completeObjectName("type=Application,name="+appName+",*")
                if appstate == "":
                        print ""+ appName +" stopped "

# ----------------------------------------------------------------------------------------------------------------------------
# This function verifies whether Application is already Available to Stop or not.
# -----------------------------------------------------------------------------------------------------------------------------
def appexist():
   print " checking for the "+appName+" applicaiton whether it is Available to Stop or not"
   apps = AdminApp.list().split(lineSeparator)
   for applist in apps:
    if applist == appName:
        print "Application is availabe to stop"
        AdminConfig.save()
    else:
        print " ------------------------------------------------"
        print " "+appName+" doesn't exists now so it will not be stopped  "


#----------------------------------------------------------------------------------------
#Main codes start here....
# ----------------------------------------------------------------------------------------
if (len(sys.argv) !=2):
        print " Please enter correct arguments "
        print " ex: StopApp.py sample server1"
else:
        appName = sys.argv[0]
        serverName = sys.argv[1]
        print "Application Name : " +appName
        print "Server Name : " +serverName
        appexist()
        stopAppOnServer(appName, serverName)



Output of Above script will be as follows
=========================================================================

./wsadmin.sh -f /tmp/StopApp.py DefaultApp gbr_testserver1
WASX7209I: Connected to process "dmgr" on node localhostCellManager01 using SOAP connector;  The type of process is: DeploymentManager
WASX7303I: The following options are passed to the scripting environment and are available as arguments that are stored in the argv variable: "[DefaultApp, gbr_testserver1]"
Application Name : DefaultApp
Server Name : gbr_testserver1
 checking for the DefaultApp applicaiton whether it is Available to Stop or not
Application is availabe to stop
ADMA5071I: Distribution status check started for application DefaultApp.
WebSphere:cell=localhostCell01,node=localhostNode01,distribution=true,expansion=notprocessing
ADMA5011I: The cleanup of the temp directory for application DefaultApp is complete.
ADMA5072I: Distribution status check completed for application DefaultApp.
true
stoping the application DefaultApp on gbr_testserver1
DefaultApp stopped


Start Application using wsadmin script

Below Script Helps you to Start Application.

Run below script from Deployment Manager Bin
$pwd
/opt/IBM/WebSphere/AppServer/profiles/Dmgr01/bin
$./wsadmin -f /tmp/StartApp.py DefaultApp gbr_testserver1

Note :Here DefaultApp is Application Name , gbr_testserver1 is server Name

give file name as StartApp.py 
=========================================================================
import sys
from time import sleep

def startAppOnServer(appName, serverName):
   appready = AdminApp.isAppReady(appName)
   print appready
   if appready == 'false':
                sleep(40)
                appready = AdminApp.isAppReady(appName)
                print appready
   else:
                print "starting the application "+appName+" on "+serverName+" "
                appManager = AdminControl.queryNames("type=ApplicationManager,process="+ serverName +",*")
                if appManager == "":
                        print "Please make sure whether Application Server is up and running before starting the applicaiton "
                        AdminControl.invoke(appManager, 'startApplication', appName)
                appstate = AdminControl.completeObjectName("type=Application,name="+appName+",*")
                if appstate != "":
                        print ""+ appName +" started "

# ----------------------------------------------------------------------------------------------------------------------------
# This function verifies whether Application is Available to Start or not.
# -----------------------------------------------------------------------------------------------------------------------------
def appexist():
   print " checking for the "+appName+" applicaiton whether it is Available to Start or not"
   apps = AdminApp.list().split(lineSeparator)
   for applist in apps:
    if applist == appName:
        print "Application is availabe to start"
        AdminConfig.save()
    else:
        print " ------------------------------------------------"
        print " "+appName+" doesn't exists to Start Application"


#----------------------------------------------------------------------------------------
#Main codes start here....
# ----------------------------------------------------------------------------------------
if (len(sys.argv) !=2):
        print " Please enter correct arguments "
        print " ex: StartApp.py sample server1"
else:
        appName = sys.argv[0]
        serverName = sys.argv[1]
        print "Application Name : " +appName
        print "Server Name : " +serverName
        appexist()
        startAppOnServer(appName, serverName)




output of Above Script will be as follows
=========================================================================

$./wsadmin.sh -f /tmp/StartApp.py DefaultApp gbr_testserver1
WASX7209I: Connected to process "dmgr" on node localhostCellManager01 using SOAP connector;  The type of process is: DeploymentManager
WASX7303I: The following options are passed to the scripting environment and are available as arguments that are stored in the argv variable: "[DefaultApp, gbr_testserver1]"
Application Name : DefaultApp
Server Name : gbr_testserver1
 checking for the DefaultApp applicaiton whether it is Available to Start or not
Application is availabe to start
ADMA5071I: Distribution status check started for application DefaultApp.
WebSphere:cell=localhostCell01,node=localhostNode01,distribution=true,expansion=notprocessing
ADMA5011I: The cleanup of the temp directory for application DefaultApp is complete.
ADMA5072I: Distribution status check completed for application DefaultApp.
true
starting the application DefaultApp on gbr_testserver1
DefaultApp started

Sunday, 8 April 2018

creating dmgr profile using silent mode



creating dmgr Profile

/tmp$ cat > dmgr_creation_response_File_txt
create
profileName=qat_dm
templatePath=/data/was855_qat/WebSphere/AppServer/profileTemplates/management
profilePath=/data/was855_qat/WebSphere/qat_dm
nodeName=node0151_qat_dm
dmgrHost=dmgrhost0150.machine.group
cellName=qat_cell
enableAdminSecurity=true
startingPort=30001
adminUserName=wasadm
adminPassword=wasadm
cellID=qat
omitAction=defaultAppDeployAndConfig



bin$ ./manageprofiles.sh -response /tmp/dmgr_creation_response_File_txt

if Appserver Got Deleted then restoring it

if Appserver gor deleted accidentally then

copy some Appserver directory to deleted Appserver location

then check

$   grep cell_name setupCmdLine.sh 

$ perl -p -i -e  's/oldcellname/newcellname/g'  setupCmdLine.sh



now after running above command it will replace all copied cell name with deleted cell name.
 here old cell name is copied other cell name  and new cell name is deleted cell name.


now check again check with below you will get all cell name with deleted cell name

$   grep cell_name setupCmdLine.sh 


Note: Ensure Perl is available on server before going for above



Generating Session cookie with TimeStamp

Application servers > server_name. Under Web Container Settings, click Web container transport chains > chain_name > HTTP Inbound Channel > Custom Properties > New

v0CookieDateRFC1123compat = true

Note: v0CookieDateRFC1123compat = false     by default.

By default, the value for the V0 Set-Cookie header Expires attribute is specified in the two digit year format. Set the v0CookieDateRFC1123compat property to true if you need to use the older RFC1123, which requires a four digit year format value for the V0 Set-Cookie Expires attribute.

Sunday, 2 April 2017

Creating Certificate Signing Request(CSR) using OpenSSL Commands

[root@jboss SSL_Prac]# pwd
/tmp/SSL_Prac
[root@jboss SSL_Prac]# openssl req -new -newkey rsa:2048 -nodes -keyout Privatekey.pem -out Certreq.pem
Generating a 2048 bit RSA private key
...............................................................................................+++
.................+++
writing new private key to 'Privatekey.pem'
-----
You are about to be asked to enter information that will be incorporated
into your certificate request.
What you are about to enter is what is called a Distinguished Name or a DN.
There are quite a few fields but you can leave some blank
For some fields there will be a default value,
If you enter '.', the field will be left blank.
-----
Country Name (2 letter code) [GB]:US
State or Province Name (full name) [Berkshire]:NJ
Locality Name (eg, city) [Newbury]:WEEH
Organization Name (eg, company) [My Company Ltd]:gbr soft tech ltd
Organizational Unit Name (eg, section) []:*.gbr.com
Common Name (eg, your name or your server's hostname) []:gbr.soft.com
Email Address []:gbrtech@abcdef.com

Please enter the following 'extra' attributes
to be sent with your certificate request
A challenge password []:wasadmin
An optional company name []:gbr soft tech ltd
[root@jboss SSL_Prac]#
Note:    - nodes    is an optional parameter NOT to encrypt the private key. This is useful when your web server starts automatically, say at boot time. If your private key is encrypted, you would be required to enter a password everytime your web server restarted. You could also omit this option to create an encrypted key and then later remove the encryption from the key.
The Above Command will give you Two Files 1.certificate Sigining Request 2. Private Key of The Certificate Like Below.
[root@jboss SSL_Prac]# ls
Certreq.pem  Privatekey.pem
[root@jboss SSL_Prac]#
[root@jboss SSL_Prac]# cat Certreq.pem
-----BEGIN CERTIFICATE REQUEST-----
MIIDEzCCAfsCAQAwgZIxCzAJBgNVBAYTAklOMQswCQYDVQQIEwJUUzEMMAoGA1UE
BxMDSFlEMRowGAYDVQQKExFnYnIgc29mdCB0ZWNoIGx0ZDESMBAGA1UECwwJKi5n
YnIuY29tMRUwEwYDVQQDEwxnYnIuc29mdC5jb20xITAfBgkqhkiG9w0BCQEWEmdi
cnRlY2hAYWJjZGVmLmNvbTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEB
AMqD3YGptEr4ECIY0CM8kSxY2TyzQKwCyAVU41GpjV6pQN/sbqzEVvNI7RuIJJdD
LTdGPfFr58p3k2IzC6g/bNSDjzNok9BKUsEzm4rOV9q96+W1SnC1XpQtnp/1SNRI
6ht+AnSdlsa8tUXAA6A5EGYI5HHithfGyjuf/rSvN7wNqyu16awS/4KbJnCQWN0Y
CgXlWJqVJquD/I0lVNgfvfQoM27qGkI2Kjy+dsRkS8LCYLTCbv2wJGqA4lq0WVDd
NfH+SQOPc1TTPE9CkkPm+38kIHkpUo83ZA0EB5o5pwGtamdDnW2kX3TFNaY4t/Of
PWsV5ZIA7/qiaR2dXQKyR88CAwEAAaA7MBcGCSqGSIb3DQEJBzEKEwh3YXNhZG1p
bjAgBgkqhkiG9w0BCQIxExMRZ2JyIHNvZnQgdGVjaCBsdGQwDQYJKoZIhvcNAQEF
BQADggEBAI3bTi4z02koCw997EFYU3OI7Wj8l4T+YTIfqmID9SmPfts25FnOwUEZ
IO7E6DrttqPQmXVYOpq8wY2B4P/kMXZsN38K+Zm32USn6EkJib4vjcHS2qkph7tv
M8FhfAYdGvs/3JF6u4F9fPvyPcHgW4w3nI6dNpbzqzCYYvxDvgpgbyiOPMGL0q0o
MTmFPjTRaWpRBb51QEzw/DnWba9jGXV7YprcPNhAhVZsJaO6JXlB9aI5GgitH+6N
e6AxkvxJvgkj+77lA7FM3nwSba/J8AtYysTg2dyeNSsvBWeeSuu10koe4kyeCupc
Bpjwm5aNkdhZV/569brjB2fAvHI4MCY=
-----END CERTIFICATE REQUEST-----
[root@jboss SSL_Prac]# cat Privatekey.pem
-----BEGIN RSA PRIVATE KEY-----
MIIEpAIBAAKCAQEAyoPdgam0SvgQIhjQIzyRLFjZPLNArALIBVTjUamNXqlA3+xu
rMRW80jtG4gkl0MtN0Y98WvnyneTYjMLqD9s1IOPM2iT0EpSwTObis5X2r3r5bVK
cLVelC2en/VI1EjqG34CdJ2Wxry1RcADoDkQZgjkceK2F8bKO5/+tK83vA2rK7Xp
rBL/gpsmcJBY3RgKBeVYmpUmq4P8jSVU2B+99CgzbuoaQjYqPL52xGRLwsJgtMJu
/bAkaoDiWrRZUN018f5JA49zVNM8T0KSQ+b7fyQgeSlSjzdkDQQHmjmnAa1qZ0Od
baRfdMU1pji38589axXlkgDv+qJpHZ1dArJHzwIDAQABAoIBAANEJzFtLEQ9Rf1W
yxyWYH0HndFVzsg3b0Ruvw/VHTuWnT4/UPWmYQShe3mDM5vg8HzAvEUFiYKBdTYT
Pq/i/f1bddbNa/zjBfypuWt+snoLsB9PUjkJI9Jd/f30dc0+s8/ns2BwHjtsVbwf
Qa+22+XZZN3VWzx870wQ44nEfbChvG2X2+UhRrHY4ZTKqsLGcHg5dkOF0rz/PjB/
LUNofuxvXyHJvz8nlOhGf7BZchd0hQb0MmGKrxDqm3avMji/DIq79q5wCRlH7JK1
j+lDa2Yau9DFGUVAG9WJzjTktMxiPUI1cPGEjYr/xoJr5PbVbgl3YlP2uWVaxg1A
44iSOeECgYEA+fDSeTcoVQcTlS7DrzfIE4T1PTSWVv9PcpRe/Qw7fyR2LU5c5eST
ckIYgBWSjGPnlDlns8sKxrghB/Nxig5jZnsHvkEfvFfozdXY8INo3LxMdYFKSZ/9
/vAFWt208TdFnmi8GPsD3RUeKJjZfzT4SdjUhhS6PIqlw9ygudEw0BECgYEAz2y2
B9TIzRYnEfEWo/faMmhAJ8EKIZP9g/rdpto9SvAT+byN7DcrDzQxO/zGA++KB/J1
xqTyPJzl7+NY30IrBvrWOrzvOLpOfk5E6P/eHHRW1uz+RKwLW4LN0Ct2+stdeBYY
UCTDIOCqUYuzK31oAxjQUVuZM8ga0kuoZ76Fed8CgYAkjf0qb0+9x9AsZG+IQ99G
Q47eib9nL+X9uwd9ePmGqd2C2NAra1fJQTN2IDGTyNTIz/CD0jFcSPfDwu4bI+mT
xnCmeb3bfPv2hs04t+9xQTTphqRHyleKnq4Z0Q0yrkPHXEgOW0AAaKNFir1cpnGd
01GZ3pQyYJDH6Y+0PY0nEQKBgQDEoCvqPoZfCyncMysgIfqgH/z48mAVNoFyk+N7
oJPLrstwyJHMovtZfUNStypKXs78+5UzyfarCJxbi6sacFHzWuKraaBnqQxxZOaj
7LDzTkFnmd7q4CAgDl3lgN5XnWIsTN2dU0v5pZ8uj/w3NLjdfq8zAF65HG54fSnV
tmA3BwKBgQCjxS2Zdgs8GT+HoFCWmDaxggUZNf5laf2y1uwWfOiIOC24GLWj4Eub
SLQN/GnNOjAJbuJpuMQUawfit7VqPbFHcL2AHr1Lt0bs1jCm9jgfStFSvqLN3WlH
/DBs8r2XiA0DLz6yA9xkSe+yKDt8Ty09JaDz/+2QpQBcB6rJjlrcYA==
-----END RSA PRIVATE KEY-----
[root@jboss SSL_Prac]#
To Check the Created CSR
[root@jboss SSL_Prac]#  openssl req -text -noout -verify -in Certreq.pem
Certificate Request:
    Data:
        Version: 0 (0x0)
        Subject: C=US, ST=NJ, L=WEEH, O=gbr soft tech ltd, OU=*.gbr.com, CN=gbr.soft.com/emailAddress=gbrtech@abcdef.com
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
            RSA Public Key: (2048 bit)
                Modulus (2048 bit):
                    00:ca:83:dd:81:a9:b4:4a:f8:10:22:18:d0:23:3c:
                    91:2c:58:d9:3c:b3:40:ac:02:c8:05:54:e3:51:a9:
                    8d:5e:a9:40:df:ec:6e:ac:c4:56:f3:48:ed:1b:88:
                    24:97:43:2d:37:46:3d:f1:6b:e7:ca:77:93:62:33:
                    0b:a8:3f:6c:d4:83:8f:33:68:93:d0:4a:52:c1:33:
                    9b:8a:ce:57:da:bd:eb:e5:b5:4a:70:b5:5e:94:2d:
                    9e:9f:f5:48:d4:48:ea:1b:7e:02:74:9d:96:c6:bc:
                    b5:45:c0:03:a0:39:10:66:08:e4:71:e2:b6:17:c6:
                    ca:3b:9f:fe:b4:af:37:bc:0d:ab:2b:b5:e9:ac:12:
                    ff:82:9b:26:70:90:58:dd:18:0a:05:e5:58:9a:95:
                    26:ab:83:fc:8d:25:54:d8:1f:bd:f4:28:33:6e:ea:
                    1a:42:36:2a:3c:be:76:c4:64:4b:c2:c2:60:b4:c2:
                    6e:fd:b0:24:6a:80:e2:5a:b4:59:50:dd:35:f1:fe:
                    49:03:8f:73:54:d3:3c:4f:42:92:43:e6:fb:7f:24:
                    20:79:29:52:8f:37:64:0d:04:07:9a:39:a7:01:ad:
                    6a:67:43:9d:6d:a4:5f:74:c5:35:a6:38:b7:f3:9f:
                    3d:6b:15:e5:92:00:ef:fa:a2:69:1d:9d:5d:02:b2:
                    47:cf
                Exponent: 65537 (0x10001)
        Attributes:
            challengePassword        :wasadmin
            unstructuredName         :gbr soft tech ltd
    Signature Algorithm: sha1WithRSAEncryption
        8d:db:4e:2e:33:d3:69:28:0b:0f:7d:ec:41:58:53:73:88:ed:
        68:fc:97:84:fe:61:32:1f:aa:62:03:f5:29:8f:7e:db:36:e4:
        59:ce:c1:41:19:20:ee:c4:e8:3a:ed:b6:a3:d0:99:75:58:3a:
        9a:bc:c1:8d:81:e0:ff:e4:31:76:6c:37:7f:0a:f9:99:b7:d9:
        44:a7:e8:49:09:89:be:2f:8d:c1:d2:da:a9:29:87:bb:6f:33:
        c1:61:7c:06:1d:1a:fb:3f:dc:91:7a:bb:81:7d:7c:fb:f2:3d:
        c1:e0:5b:8c:37:9c:8e:9d:36:96:f3:ab:30:98:62:fc:43:be:
        0a:60:6f:28:8e:3c:c1:8b:d2:ad:28:31:39:85:3e:34:d1:69:
        6a:51:05:be:75:40:4c:f0:fc:39:d6:6d:af:63:19:75:7b:62:
        9a:dc:3c:d8:40:85:56:6c:25:a3:ba:25:79:41:f5:a2:39:1a:
        08:ad:1f:ee:8d:7b:a0:31:92:fc:49:be:09:23:fb:be:e5:03:
        b1:4c:de:7c:12:6d:af:c9:f0:0b:58:ca:c4:e0:d9:dc:9e:35:
        2b:2f:05:67:9e:4a:eb:b5:d2:4a:1e:e2:4c:9e:0a:ea:5c:06:
        98:f0:9b:96:8d:91:d8:59:57:fe:7a:f5:ba:e3:07:67:c0:bc:
        72:38:30:26
[root@jboss SSL_Prac]#
To Check the Created Private Key:
[root@jboss SSL_Prac]#  openssl rsa -in Privatekey.pem -check
RSA key ok
writing RSA key
-----BEGIN RSA PRIVATE KEY-----
MIIEpAIBAAKCAQEAyoPdgam0SvgQIhjQIzyRLFjZPLNArALIBVTjUamNXqlA3+xu
rMRW80jtG4gkl0MtN0Y98WvnyneTYjMLqD9s1IOPM2iT0EpSwTObis5X2r3r5bVK
cLVelC2en/VI1EjqG34CdJ2Wxry1RcADoDkQZgjkceK2F8bKO5/+tK83vA2rK7Xp
rBL/gpsmcJBY3RgKBeVYmpUmq4P8jSVU2B+99CgzbuoaQjYqPL52xGRLwsJgtMJu
/bAkaoDiWrRZUN018f5JA49zVNM8T0KSQ+b7fyQgeSlSjzdkDQQHmjmnAa1qZ0Od
baRfdMU1pji38589axXlkgDv+qJpHZ1dArJHzwIDAQABAoIBAANEJzFtLEQ9Rf1W
yxyWYH0HndFVzsg3b0Ruvw/VHTuWnT4/UPWmYQShe3mDM5vg8HzAvEUFiYKBdTYT
Pq/i/f1bddbNa/zjBfypuWt+snoLsB9PUjkJI9Jd/f30dc0+s8/ns2BwHjtsVbwf
Qa+22+XZZN3VWzx870wQ44nEfbChvG2X2+UhRrHY4ZTKqsLGcHg5dkOF0rz/PjB/
LUNofuxvXyHJvz8nlOhGf7BZchd0hQb0MmGKrxDqm3avMji/DIq79q5wCRlH7JK1
j+lDa2Yau9DFGUVAG9WJzjTktMxiPUI1cPGEjYr/xoJr5PbVbgl3YlP2uWVaxg1A
44iSOeECgYEA+fDSeTcoVQcTlS7DrzfIE4T1PTSWVv9PcpRe/Qw7fyR2LU5c5eST
ckIYgBWSjGPnlDlns8sKxrghB/Nxig5jZnsHvkEfvFfozdXY8INo3LxMdYFKSZ/9
/vAFWt208TdFnmi8GPsD3RUeKJjZfzT4SdjUhhS6PIqlw9ygudEw0BECgYEAz2y2
B9TIzRYnEfEWo/faMmhAJ8EKIZP9g/rdpto9SvAT+byN7DcrDzQxO/zGA++KB/J1
xqTyPJzl7+NY30IrBvrWOrzvOLpOfk5E6P/eHHRW1uz+RKwLW4LN0Ct2+stdeBYY
UCTDIOCqUYuzK31oAxjQUVuZM8ga0kuoZ76Fed8CgYAkjf0qb0+9x9AsZG+IQ99G
Q47eib9nL+X9uwd9ePmGqd2C2NAra1fJQTN2IDGTyNTIz/CD0jFcSPfDwu4bI+mT
xnCmeb3bfPv2hs04t+9xQTTphqRHyleKnq4Z0Q0yrkPHXEgOW0AAaKNFir1cpnGd
01GZ3pQyYJDH6Y+0PY0nEQKBgQDEoCvqPoZfCyncMysgIfqgH/z48mAVNoFyk+N7
oJPLrstwyJHMovtZfUNStypKXs78+5UzyfarCJxbi6sacFHzWuKraaBnqQxxZOaj
7LDzTkFnmd7q4CAgDl3lgN5XnWIsTN2dU0v5pZ8uj/w3NLjdfq8zAF65HG54fSnV
tmA3BwKBgQCjxS2Zdgs8GT+HoFCWmDaxggUZNf5laf2y1uwWfOiIOC24GLWj4Eub
SLQN/GnNOjAJbuJpuMQUawfit7VqPbFHcL2AHr1Lt0bs1jCm9jgfStFSvqLN3WlH
/DBs8r2XiA0DLz6yA9xkSe+yKDt8Ty09JaDz/+2QpQBcB6rJjlrcYA==
-----END RSA PRIVATE KEY-----
[root@jboss SSL_Prac]#


Creating CSR from Existing PrivateKey
[root@jboss CSR_Created]# openssl req -out NewCSRfromPrivateKey.csr -key Privatekey.pem -new
You are about to be asked to enter information that will be incorporated
into your certificate request.
What you are about to enter is what is called a Distinguished Name or a DN.
There are quite a few fields but you can leave some blank
For some fields there will be a default value,
If you enter '.', the field will be left blank.
-----
Country Name (2 letter code) [GB]:
State or Province Name (full name) [Berkshire]:
Locality Name (eg, city) [Newbury]:
Organization Name (eg, company) [My Company Ltd]:
Organizational Unit Name (eg, section) []:
Common Name (eg, your name or your server's hostname) []:
Email Address []:

Please enter the following 'extra' attributes
to be sent with your certificate request
A challenge password []:
An optional company name []:
[root@jboss CSR_Created]#

Creating Private Key from Existing CSR
[root@jboss CSR_Created]# openssl req -out Certreq.pem  -pubkey -new -newkey  rsa:2048 -keyout NewPrivateKey.key
Generating a 2048 bit RSA private key
.....................................................+++
.....................................................+++
writing new private key to 'NewPrivateKey.key'
Enter PEM pass phrase:
Verifying - Enter PEM pass phrase:
-----
You are about to be asked to enter information that will be incorporated
into your certificate request.
What you are about to enter is what is called a Distinguished Name or a DN.
There are quite a few fields but you can leave some blank
For some fields there will be a default value,
If you enter '.', the field will be left blank.
-----
Country Name (2 letter code) [GB]:
State or Province Name (full name) [Berkshire]:
Locality Name (eg, city) [Newbury]:
Organization Name (eg, company) [My Company Ltd]:
Organizational Unit Name (eg, section) []:
Common Name (eg, your name or your server's hostname) []:
Email Address []:

Please enter the following 'extra' attributes
to be sent with your certificate request
A challenge password []:
An optional company name []:
[root@jboss CSR_Created]#
Remove a passphrase from a private key
[root@jboss CSR_Created]# openssl rsa -in Privatekey.pem -out removedpwdnewPrivateKey.pem
writing RSA key
[root@jboss CSR_Created]#

[root@jboss CSR_Created]# cat PrivateKey.key
-----BEGIN RSA PRIVATE KEY-----
Proc-Type: 4,ENCRYPTED
DEK-Info: DES-EDE3-CBC,FDCAB9D75EFF7CA2

tIRGJSna3U526ghaA30u9UUI3AM+lRwFW6dx3+VaSYcEIkqy4kN1Li1WwO2G0HjW
LlvjIq62ebu6WLRVN7ac9OQQkv/C/AC4/cD6L7/j6Tkf2NQjkEiH4gPrDw2Uc5iK
Drdbfk7rMKXriFNLVKmBo9zdlLjGpvKCPX5WhMs2gby6KAqm4vBXNRAwBpTsh0hj
M0NeV1IojkiBwSv6Cx7YnLrFMUj0gJ2iGBP7Odc/r1Jal5SS7BxFIu3Q3mzzUaJG
6lvBiqhkEzdYRyhs8B8YMnCITXgKBVKk2eqU6kmExacH9e9iCpYDmxp2MkO6grVY
p0X8jFCyzWh7YsOAscE0O6uKAhJPKNoRhfmtBQ+J9E4afPdeBZmutUALpIzYXuXY
wUJh1FdVirKxNSzKzeBrl1Lm5c3hpCzSArltR0g27FIFJXP5eKWwF/rgatD/iK8T
LSp3r9BtuUSWi76BaWiovI1FuamRNhKT+AamBakOZ+iyDyenTvIQAa+mYK7PrlY5
1qKi52sTtE5NWgC+UJmJ1WipAzB0c9FA8ljRsirEiZZnidT+UbM0aC6Bc754AxSk
FZ71X/KXgTy6eCMxgoJJM+mJ23y46prlYzzV+tYrhOodvxUuQNj2by0kaBED7rSu
YrQ35YFr5xSY3x8b98cP2ZQU8n0DRYIERqy86F+mDCLJUdAaM7TuWyw6fqO8n2WJ
KrUclyvz3cOulnIbL/BNEVn+o7pA59mS0QZ/rRVDDAl+/mHrW1SqyBrGacGMcMeq
vCnwl3IVb9L6C6Mllt0XlSgHAEUwfxWg/0W5LLso0zHFA1wHmXA0QkgJtW1sa4QV
gH5NRBEwcMR7rT9SJlVX9GZNuEvfxVEwFliHzgyzVcJFLnW/AB94JbI+ogWeJuMX
BVUpBTWsjqSaXDHd0Z34jrfFmazHbQsgGoR/Lvy0BXDPV2KjU0KyvJNTvhxm233D
h2ZNc2/gBkkMduDFaCriThomLuD5IQ2KSzz2t/Zl+rWJnLzwaICXRyczbs4yHB2d
R3X0KZuLi6PdvkNC0FJMYSed5dYj+vDs29HX35SPOgmkFRSfPVej55UUGD+rNcvh
DYnIuuQtv7ISnPKY7GcLxvcc7C49RTkTySgjzAqPR+UDOB1xqgOCqUds7bRrxAqG
rN83xbZ4kdyT8AJuXJzaVXohl+XZpPJ6TRKDZuW4QzzhJtb8UQGNRZ1OcNZ7oN+K
KfvKFGl7kmj/llLzzkY06THkzwk5F8L+i6ve+l4P3ZbPQwbBpid72PSD5LlF7b9F
2o5YCPnwGDkvmPj2mZZ7En0EvSkM+yL4GoSPG0tGkpdxcgpZR/LG9rfPVpgQWiN4
wqJPiEGOHLe6SIPjamr0MRnAceurBYRoBWhTXQQyW+G2Vm+w65xnzguXKFrxSbdb
jKbthfwoT+IB7UGWHZjsllVUv/o6tSxalqwjTPHE1Bn1/tOf5hNDPQFo/tPsKPNQ
GefmqJXD9kD9HFw2QwTHiAmluiHXCkNAMeDc/2sjj3bEeIHKUqMuts8v+N3laqvb
SVH18xpQv97rnMnYaqE5hfoIKQzo/LncZJP4saW4nZVjY7Pez/uFtg==
-----END RSA PRIVATE KEY-----
[root@jboss CSR_Created]# 
[root@jboss CSR_Created]# 
[root@jboss CSR_Created]# cat removedpwdnewPrivateKey.pem
-----BEGIN RSA PRIVATE KEY-----
MIIEpAIBAAKCAQEAyoPdgam0SvgQIhjQIzyRLFjZPLNArALIBVTjUamNXqlA3+xu
rMRW80jtG4gkl0MtN0Y98WvnyneTYjMLqD9s1IOPM2iT0EpSwTObis5X2r3r5bVK
cLVelC2en/VI1EjqG34CdJ2Wxry1RcADoDkQZgjkceK2F8bKO5/+tK83vA2rK7Xp
rBL/gpsmcJBY3RgKBeVYmpUmq4P8jSVU2B+99CgzbuoaQjYqPL52xGRLwsJgtMJu
/bAkaoDiWrRZUN018f5JA49zVNM8T0KSQ+b7fyQgeSlSjzdkDQQHmjmnAa1qZ0Od
baRfdMU1pji38589axXlkgDv+qJpHZ1dArJHzwIDAQABAoIBAANEJzFtLEQ9Rf1W
yxyWYH0HndFVzsg3b0Ruvw/VHTuWnT4/UPWmYQShe3mDM5vg8HzAvEUFiYKBdTYT
Pq/i/f1bddbNa/zjBfypuWt+snoLsB9PUjkJI9Jd/f30dc0+s8/ns2BwHjtsVbwf
Qa+22+XZZN3VWzx870wQ44nEfbChvG2X2+UhRrHY4ZTKqsLGcHg5dkOF0rz/PjB/
LUNofuxvXyHJvz8nlOhGf7BZchd0hQb0MmGKrxDqm3avMji/DIq79q5wCRlH7JK1
j+lDa2Yau9DFGUVAG9WJzjTktMxiPUI1cPGEjYr/xoJr5PbVbgl3YlP2uWVaxg1A
44iSOeECgYEA+fDSeTcoVQcTlS7DrzfIE4T1PTSWVv9PcpRe/Qw7fyR2LU5c5eST
ckIYgBWSjGPnlDlns8sKxrghB/Nxig5jZnsHvkEfvFfozdXY8INo3LxMdYFKSZ/9
/vAFWt208TdFnmi8GPsD3RUeKJjZfzT4SdjUhhS6PIqlw9ygudEw0BECgYEAz2y2
B9TIzRYnEfEWo/faMmhAJ8EKIZP9g/rdpto9SvAT+byN7DcrDzQxO/zGA++KB/J1
xqTyPJzl7+NY30IrBvrWOrzvOLpOfk5E6P/eHHRW1uz+RKwLW4LN0Ct2+stdeBYY
UCTDIOCqUYuzK31oAxjQUVuZM8ga0kuoZ76Fed8CgYAkjf0qb0+9x9AsZG+IQ99G
Q47eib9nL+X9uwd9ePmGqd2C2NAra1fJQTN2IDGTyNTIz/CD0jFcSPfDwu4bI+mT
xnCmeb3bfPv2hs04t+9xQTTphqRHyleKnq4Z0Q0yrkPHXEgOW0AAaKNFir1cpnGd
01GZ3pQyYJDH6Y+0PY0nEQKBgQDEoCvqPoZfCyncMysgIfqgH/z48mAVNoFyk+N7
oJPLrstwyJHMovtZfUNStypKXs78+5UzyfarCJxbi6sacFHzWuKraaBnqQxxZOaj
7LDzTkFnmd7q4CAgDl3lgN5XnWIsTN2dU0v5pZ8uj/w3NLjdfq8zAF65HG54fSnV
tmA3BwKBgQCjxS2Zdgs8GT+HoFCWmDaxggUZNf5laf2y1uwWfOiIOC24GLWj4Eub
SLQN/GnNOjAJbuJpuMQUawfit7VqPbFHcL2AHr1Lt0bs1jCm9jgfStFSvqLN3WlH
/DBs8r2XiA0DLz6yA9xkSe+yKDt8Ty09JaDz/+2QpQBcB6rJjlrcYA==
-----END RSA PRIVATE KEY-----
[root@jboss CSR_Created]#

Error : (20014)Internal error: Error retrieving pid file (null) remove it before continuing if it is corrupted.

Error :
(20014)Internal error: Error retrieving pid file (null)
remove it before continuing if it is corrupted.

If you are seeing the Above error while stopping the IHS server , please check the IHS  Server Pid,if IHS pid file is Empty, then kill the IHS Instances and remove th IHS pid file and Restart IHS server will fix the issue.

one critical error i came across with similar error but above resolution was not working for fixing.
for fixing the issue we have restarted all the IHS servers under that issue facing IHS server , after restart of IHS serves, all IHS servers under that cell are started normally and stopping Normally.

Sunday, 19 March 2017

application is not accesible with " A WebGroup/Virtual Host to handle / has not been defined " error in SystemOut logs

Even Virtual host port is defined in virtual host and Virtual host is properly mapped to the application still getting

 A WebGroup/Virtual Host to handle / has not been defined " error in SystemOut logs and application is not accessible.

then Stop Node and JVM. take backup of ear's under applications

C:\Program Files\IBM\WebSphere\AppServer\profiles\AppSrv01Sec\config\cells\was85user-PCCell01\applications path

and remove the application ear that is throwing error and which is not accessible from above mentioned location now Synchronize the Node then Start Node and Start JVM.

Note: Don't Remove any configurations in Deployment Manager.

Note : use valid path If you are using Linux Machines.

getting permission Related Error on /tmp even if /tmp is having 777 permissions


In most of the Environments /tmp will have sticky applied to it . if you give 777 also it will not work and gives permission issue because /tmp will be owned by unix user (root) if you want to provide access like creater of file or directory should have all privileges you should apply sticky on that directory.

below command applies sticky on /tmp

chmod 777 /tmp

chmod o+t /tmp


How to Stop SystemOut.logand SystemErr.log rotation even server is running state



If Get Requirement like to OFF or to stop SystemOut.log or SystemErr.log log rotation,please follow below steps


To stop Application Related logs Dumping in Server log

Step1 : uncheck Show application print statements like in screen shot

 Logging and tracing > server1 > JVM Logs



Step 2: off the Tracing in Server in below location.below is for runtime if you want you can use same for configuration time also but it require server restart.

Logging and tracing > server1 > Diagnostic trace service > Change log detail levels




Monday, 30 May 2016

after deployment the code changes are not reflecting in one node out of two nodes in cluster

to fix this you need to restart Node agent  then after try to sync Node even if still changes are not reflecting then copy installed application from installedApps from successfully installed node to unsuccessfully deployed node.

ensure to sync and restart dmgr ,node and jvm and check code changes are reflecting


if above does not work then check cus and blas available in cell level  in  unsuccessful node  are as same as working application code in fine and  working node.and then restart dmgr , nodeagent, JVM.

unstash the file and get password

#!/usr/bin/perl
use strict;
die "Usage: $0 <stash file>n" if $#ARGV != 0;
my $file=$ARGV[0];
open(F,$file) || die "Can't open $file: $!";
my $stash;
read F,$stash,1024;
my @unstash=map { $_^0xf5 } unpack("C*",$stash);
foreach my $c (@unstash) {
 last if $c eq 0;
 printf "%c",$c;
}
printf " ";



Unstashing steps:

Step 1: copy the above script into a perl script file (ex: unstash.pl  or py)

Step 2: run the file as ./unstash.pl filename.sth (ex: ./unstash.pl  filea.sth)

you will get the password after unstashing

Sunday, 3 April 2016

Disabling the Directory Browsing in WebServer

In most of the Web servers Directory browsing is enabled by default.

to secure the code from Directory Browsing we need to disable the Directory Browsing using the below steps.

Before directory Browsing Disabled

Alias "/test/" "/testMachine/folder1/"

Directory "/testMachine/folder1/">
Options Indexes MultiViews
AllowOverride None
Order allow,deny
Allow from all
</Directory>

In Web Server httpd.conf find the above lines and replace Indexes with --Indexes.after making the changes code in httpd.conf file looks like below

After directory Browsing Disabled

Alias "/test/" "/testMachine/folder1/"

Directory "/testMachine/folder1/">
Options -Indexes MultiViews
AllowOverride None
Order allow,deny
Allow from all
</Directory>

Ensure you have restarted webservers to reflect the changes. before verifying clear browser cookies.

Note: in Few Apache based websevers even we can remove the word Indexes will also gives the same directory disabled behaviour.
to reflect the Directory browsing use correct webserver conf file and correct application accessible directory as mentioned above if you have mulplte applications configured in your webservers.

Sunday, 27 March 2016

ClassNotFound Exception after installation of application | application url is giving 404 exception and giving classNotFound in logs

1.check the parent class first class loader policy is set.

2. make sure all required shared libraries is mapped to application.

3. check all the jar files are available at shared library location.

4. verify class path is set for the application is there is any.




Wednesday, 23 March 2016

disk space full alerts on /tmp which is 1GB size and there are no file available or all files available are taking less than 10MB on /tmp.

To free up the space on /tmp we have used below command to identify which process are taking space on /tmp. and restarted the process will free up the space on /tmp.

$lsof|grep -i wasadm|grep -i deleted


the above command lists all the open files and unmapped process using /tmp space and running with wasadm user.

after creating the datasource test connection is successful but when application is accessed that time it is giving error from newly creating server(WAS8.5) and it is not giving any error when accessible from the old server(WAS6.1).

issue is caused due to Microsoft SQL server went to read only mode, after Microsoft SQL server restart everything was working fine.

Tuesday, 22 March 2016

Application is not able to access from web seal servers and they were working fine from direct URL's.

issue is with web seal log file reached to 2GB so it stopped the responding .to resolve this we have renamed the log file and restarted the web seal server then application is able to access from the web seal servers as log rotation is made.

Webseal log Rotation

The websead msg log is not controlled from within the webseal conf file, but instead, via the routing file.
--------------------------------------------
The contents of the msg__webseald.log file come from webseal's STDERR, as controlled in the /opt/pdweb/etc/routing file
 FATAL:STDERR:-
ERROR:STDERR:-
WARNING:STDERR:-

The routing file can be modified to redirect these messages to a file, and the log file management can be configured at the same time.
 For example.
FATAL:UTF8FILE.10.10000:/var/pdweb/log/msg__webseald.log
ERROR:UTF8FILE.10.10000:/var/pdweb/log/msg__webseald.log
WARNING:UTF8FILE.10.10000:/var/pdweb/log/msg__webseald.log


Note:log file will be rotated after 10000 entries in any of file Fatal or error or warning log file .and max historical files are 10

In one of the application giving the SSLHandshake error after clicking on one of the tab's in application even all certificates are available in server.

after discussing with application team we understand that after clicking on that tab it will go to other application in other jvm (reporting application residing server)in the same host and generate the report. so we have used the retrieve from port option with reporting server certificate name to get the other report generating server certificate and restarted the error giving server to resolve the error. if reporting server is residing in other host  then we need to add reporting application root and intermediate cert in truststore of error giving application and restart the server is other way to resolve this type of issue .

Monday, 21 March 2016

hostname not found and SSLHandshake error

we have renewed VeriSign web server certificate from our end informed to application team for checkout the application ,during checkout it went successful without any issue. we were not sure to which other applications the current application is interacting with. later when people soft servers are bounce after 3months from people soft team, people soft  were seeing sslhandshake error(related to our vip name) from people soft team end along with host not found exception in logs. to solving this we have give verisign intermediate cert (class G4) to them to add intermediate cert  in their server, after adding cert in people soft server and restarting peoplesoft servers the sslhandshake error is fixed.to resolve the host not found we have reached DNS team to resolve from DNC team end, for temporary fix we have added our vip name in host aliases in /etc/resolve.conf and restarted networkmanager service .

webserver is not starting or not stoping and just giving unable to start webserver or unable to stop webserver

when i tried to grep process using ps command some of the web server process are running with root id and pid is generated with root .for solving this issue i have killed all running instances of that particular web server and changed the pid running user and group to correct id and group and started web server started.

grepping the process

in Linux:

$ps -ef|grep -i <webserver_name> | grep -i <webserver_port>

in Solaries

$/usr/ucb/ps -auxwww|grep -i <webserver_name> | grep -i <webserver_port>

killing process:

$kill -9 <pid>