Thursday, August 13, 2015

Oracle VM Server for SPARC or LDoms 3.2

Abstract:

Virtualization under Solaris comes in different flavor. Logical Domains (LDom's) or Oracle VM for SPARC (OVM for SPARC) enables different OS's to be hosted on newer hardware without expensive electrical partitioning using ASIC's. Oracle has released LDom or OVM for SPARC 3.2.

Oracle Documentation:

[http] Overall Documentation Home
[http] What's New?
[http] 3.2 Release Notes
[http] 3.2.0.1 Supplemental Release Notes
[http] Installation Guide
[http] Administration Guide
[http] Security Guide
[http] Reference Manuals

Conclusions:

Oracle Logical Domains or Oracle VM for SPARC composes a very reasonable platform for hosting various Solaris Server instances. Solaris 11 bundles the latest version of OVM Server, simplifying a physical environment and providing additional flexibility to reduce planned downtime on current modern hardware.

Monday, August 10, 2015

Solaris 11.3 Beta Released!

Abstract:

Oracle has released Solaris 11.3 Beta. The networking sub-system has been greatly improved, for Solaris to operate as a sophisticated service provider for firmware based hypervisor such as LDom or Oracle VM for SPARC. SPARC Solaris 11.3 is the only serious hypervisor Control Domain from Oracle which supports features like VXLAN and ZFS.

Documentation

[http] What's New?
[http] System Requirements
[http] Frequently Asked Questions
[http] Release Notes
[http] Information Library

Media

[http] Installation from CD/DVD or USB

System Controller: Lights Out Management

 

Abstract:

A System Controller (SC) is a thin facility to gain some level of access to a server chassis during the time an operating system is not booted. Sun Microsystems released various Lights Out Management (LOM) interfaces on their various server SC Cards. After the purchase of Sun by Oracle, the use continued such server features. The following lists the various LOM interface types on the Sun/Oracle system SC's.

LOM Table for System Controllers

The following table lists the various types of systems according to their lights out management system controllers.
TypeSystem Model
LOM
LOMSUN Netra X1
LOMSUN Netra T1400/1405
LOMSUN Netra T1 AC200
LOMSUN Netra T1 DC200
LOMSUN Fire V100
LOMSUN Fire V120
LOMSUN Netra 20
LOMSUN Netra 1280
LOMSUN Netra 1290
LOMSUN Fire V1280
LOMSUN Fire V2900
ALOM
ALOMSun Fire V125
ALOMSun Fire V210
ALOMSun Fire V215
ALOMSun Fire V240
ALOMSun Fire V245
ALOMSun Fire V250
ALOMSun Fire V440
ALOMSun Fire V445
ALOMSun Fire T1000
ALOMSun Fire T2000
ALOMSun SPARC Enterprise T1000
ALOMSun SPARC Enterprise T2000
ALOMSun Netra T2000
ALOMSun Blade T6300
ELOM
ELOMSun Fire X2100
ELOMSun Fire X2200
ELOMSun Blade X6250
ELOMSun Blade X6450
RSC
RSCSun Enterprise 250
RSCSun Fire 280R
RSCSun Fire V480
RSCSun Fire V880
RSCSun Fire V490
RSCSun Fire V890
XSCF
XSCFSun Enterprise M3000
XSCFSun Enterprise M4000
XSCFSun Enterprise M5000
XSCFSun Enterprise M8000
XSCFSun Enterprise M9000
ILOM
ILOMSun Fire X4100
ILOMSun Fire X4170
ILOMSun Fire X4200
ILOMSun Fire X4270
ILOMSun Fire X4470
ILOMSun Fire X4500
ILOMSun Fire X4600
ILOMSun Fire X4800
ILOMSun Blade 6000
ILOMSun Blade X6220
ILOMSun Blade X6220
ILOMSun Blade X6270
ILOMSun Blade X6275
ILOMSun Blade X6440
ILOMSun Blade 8000
ILOMSun Netra X4200
ILOMSun SPARC Enterprise T5140
ILOMSun SPARC Enterprise T5240
ILOMSun SPARC Enterprise T5440
ILOMSun SPARC Enterprise T5120
ILOMSun SPARC Enterprise T5220
ILOMSun Blade T6320
ILOMSun Blade T6340
ILOMSPARC T3-1
ILOMSPARC T3-2
ILOMSPARC T3-4
ILOMSPARC T4-1
ILOMSPARC T4-2
ILOMSPARC T4-4
ILOMSPARC T5-1
ILOMSPARC T5-2
ILOMSPARC T5-4
ILOMSPARC T5-8



Saturday, April 4, 2015

Tab Update: OpenSXCE May 2014 Distribution

Abstract: 

Sun Microsystems created OpenSolaris on May 8 in 2008 as an Open Sourced version of it's enterprise and managed services grade Solaris operating system. In 2010, Sun was acquired by Oracle, OpenSolaris project was closed, Community based OpenIndiana was born, and the Oracle Solaris Express binary release program was officially re-instantiated. Independent maintainer Martin Bochnig produced his own Intel and SPARC release of MartUX in 2006, produced the first (and last) SPARC release of OpenIndiana in 2012, and later forked (and maintaining) his own SVR4 package based SPARC and Intel distributions called OpenSXCE. The most current OpenSXCE release is now 2015.05... perhaps the first OpenSolaris based SPARC distribution which offers USB boot support!

[OpenSXCE  by Martin Bochnig]

OpenSXCE

Introduction:

OpenSXCE 2014.05 is an enterprise-class OpenSolaris based server and desktop oriented distribution. Options include: Live-DVD, Live-USB, Virtual Box, LDOM - with local or remote SVR4 package network repository options. Both SPARC and Intel continue to be made available. This may be the FIRST USB Bootable OpenSolaris based release in history! Many congratulations to for maintaining platform-independent OpenSolaris releases, originally promised by the Illumos community.

2014.05 Release

[http] Main Web Site with Downloads
[txt] 2015.04 Release Notes
[http] 2014.05 x86/x64 Live DVD
[http] 2014.05 x86/x64 Live USB
[http] 2015.05 x86/x64 Virtual Box
[http] 2015.05 x86/x64 SVR4 Repository
[http] 2014.05 SPARC Live DVD
[http] 2014.05 SPARC Live USB
[http] 2015.05 SPARC LDOM
[http] 2015.05 SPARC SVR4 Repository[email] Maintainer - Martin Bochnig

Tuesday, March 31, 2015

Security: 2015q1 Concerns

Viruses, Worms, Vulnerabilities and Spyware concerns during and just prior 2015 Q1.

  • [2015-03-07] Litecoin-mining code found in BitTorrent app, freeloaders hit the roof
    "μTorrent users are furious after discovering their favorite file-sharing app is quietly bundled with a Litecoin mining program. The alt-coin miner is developed by distributed computing biz Epic Scale, and is bundled in some installations of μTorrent, which is a Windows BitTorrent client. Some peeps are really annoyed that Epic's code is running in the background while they illegally pirate torrent movies and Adobe Creative Suite Linux ISOs, and say they didn't ask for it to be installed."

  • [2015-03-06] FREAKing HELL: All Windows versions vulnerable to SSL snoop
    "Microsoft has confirmed that its implementation of SSL/TLS in all versions of Windows is vulnerable to the FREAK encryption-downgrade attack. This means if you're using the firm's Windows operating system, an attacker on your network can potentially force Internet Explorer and other software using the Windows Secure Channel component to deploy weak encryption over the web. Intercepted HTTPS connections can be easily cracked, revealing sensitive details such as login cookies and banking information, but only if the website or service at the other end is still supporting 1990s-era cryptography (and millions of sites still are)."

  • [2015-03-05] Broadband routers: SOHOpeless and vendors don't care
    "Home and small business router security is terrible. Exploits emerge with depressing regularity, exposing millions of users to criminal activities. Many of the holes are so simple as to be embarrassing. Hard-coded credentials are so common in small home and office routers, comparatively to other tech kit, that only those with tin-foil hats bother to suggest the flaws are deliberate."
  • [2015-03-05] Obama criticises China's mandatory backdoor tech import rules
    "US prez Barack ‪Obama has criticised China's new tech rules‬, urging the country to reverse the policy if it wants a business-as-usual situation with the US to continue. As previously reported, proposed new regulations from the Chinese government would require technology firms to create backdoors and provide source code to the Chinese government before technology sales within China would be authorised. China is also asking that tech companies adopt Chinese encryption algorithms and disclose elements of their intellectual property."
  • [2015-03-05] Sales up at NSA SIM hack scandal biz Gemalto
    "Sales at the world's biggest SIM card maker, Gemalto, which was last month revealed to have been hacked by the NSA and GCHQ, rose by five per cent to €2.5bn (£1.8bn) in 2014. Following the hack, the company's share price fell by $470m last month. In February, it was revealed that the NSA and Britain's GCHQ had hacked the company to harvest the encryption keys, according to documents leaked by former NSA sysadmin, whistleblower Edward Snowden."

  • [2015-02-24] SSL-busting adware: US cyber-plod open fire on Comodo's PrivDog
    "Essentially, Comodo's firewall and antivirus package Internet Security 2014, installs a tool called PrivDog by default. Some versions of this tool intercept encrypted HTTPS traffic to force ads into webpages. PrivDog, like the Lenovo-embarrassing Superfish, does this using a man-in-the-middle attack: it installs a custom root CA certificate on the Windows PC, and then intercepts connections to websites. Web browsers are fooled into thinking they are talking to legit websites, such as online banks and secure webmail, when in fact they are being tampered with by PrivDog so it can inject adverts. If that's not bad enough, PrivDog turns invalid HTTPS certificates on the web into valid ones: an attacker on your network can point your computer at an evil password-stealing website dressed up as your online bank, and you'd be none the wiser thanks to PrivDog."
  • [2015-02-23] Psst, hackers. Just go for the known vulnerabilities
    "Every one of the top ten vulnerabilities exploited in 2014 took advantage of code written years or even decades ago, according to HP, which recorded an increase in the level of mobile malware detected. “Many of the biggest security risks are issues we’ve known about for decades, leaving organisations unnecessarily exposed,” said Art Gilliland, senior vice president and general manager, Enterprise Security Products, HP. “We can’t lose sight of defending against these known vulnerabilities by entrusting security to the next silver bullet technology; rather, organisations must employ fundamental security tactics to address known vulnerabilities and in turn, eliminate significant amounts of risk," he added."

[Chinese Virus Image, courtesy WatchChinaTimes.com]
  • [2015-02-20] So long, Lenovo, and no thanks for all the super-creepy Superfish
    "Chinese PC maker Lenovo has published instructions on how to scrape off the Superfish adware it installed on its laptops – but still bizarrely insists it has done nothing wrong. That's despite rating the severity of the deliberate infection as "high" on its own website. Well played, Lenonope. Superfish was bundled on new Lenovo Windows laptops with a root CA certificate so it could intercept even HTTPS-protected websites visited by the user and inject ads into the pages. Removing the Superfish badware will leave behind the root certificate – allowing miscreants to lure Lenovo owners to websites masquerading as online banks, webmail and other legit sites, and steal passwords in man-in-the-middle attacks."

  • [2015-02-15] Mozilla's Flash-killer 'Shumway' appears in Firefox nightlies
    "Open source SWF player promises alternative to Adobe's endless security horror. In November 2012 the Mozilla Foundation announced “Project Shumway”, an effort to create a “web-native runtime implementation of the SWF file format.” Two-and-a-bit years, and a colossal number of Flash bugs later, Shumway has achieved an important milestone by appearing in a Firefox nightly, a step that suggests it's getting closer to inclusion in the browser. Shumway's been available as a plugin for some time, and appears entirely capable of handling the SWF files."

  • [2015-01-29] What do China, FBI and UK have in common? All three want backdoors...
    "The Chinese government wants backdoors added to all technology imported into the Middle Kingdom as well as all its source code handed over. Suppliers of hardware and software must also submit to invasive audits, the New York Times reports. The new requirements, detailed in a 22-page document approved late last year, are ostensibly intended to strengthen the cybersecurity of critical Chinese industries. Ironically, backdoors are slammed by computer security experts because the access points are ideal for hackers to exploit as well as g-men."
     
  • [2015-01-15] Console hacker DDoS bot runs on lame home routers
    "Console DDoSers Lizard Squad are using insecure home routers for a paid service that floods target networks, researchers say. The service crawls the web looking for home and commercial routers secured using lousy default credentials that could easily be brute-forced and then added to its growing botnet. Researchers close to a police investigation into Lizard Squad shared details of the attacks with cybercrime reporter Brian Krebs. The attacks used what was described as a 'crude' spin-off of a Linux trojan identified in November that would spread from one router to another, and potentially to embedded devices that accept inbound telnet connections. High-capacity university routers were also compromised in the botnet which according to the service boasted having run 17,439 DDoS attacks or boots at the time of writing."
  • [2014-12-14] CoolReaper pre-installed malware creates backdoor on Chinese Androids
    "Security researchers have discovered a backdoor in Android devices sold by Coolpad, a Chinese smartphone manufacturer. The “CoolReaper” vuln has exposed over 10 million users to potential malicious activity. Palo Alto Networks reckons the malware was “installed and maintained by Coolpad despite objections from customers”. It's common for device manufacturers to install software on top of Google’s Android mobile operating system to provide additional functionality or to customise Android devices. Some mobile carriers install applications that gather data on device performance. But CoolReaper operates well beyond the collection of basic usage data, acting as a true backdoor into Coolpad devices - according to Palo Alto.CoolReaper has been identified on 24 phone models sold by Coolpad."

  • [2014-11-24] Regin: The super-spyware the security industry has been silent about
    "A public autopsy of sophisticated intelligence-gathering spyware Regin is causing waves today in the computer security world... On Sunday, Symantec published a detailed dissection of the Regin malware, and it looks to be one of the most advanced pieces of spyware code yet found. The software targets Windows PCs, and a zero-day vulnerability said to be in Yahoo! Messenger, before burrowing into the kernel layer. It hides itself in own private area on hard disks, has its own virtual filesystem, and encrypts and morphs itself multiple times to evade detection. It uses a toolkit of payloads to eavesdrop on the administration of mobile phone masts, intercept network traffic, pore over emails, and so on... Kaspersky's report on Regin today shows it has the ability to infiltrate GSM phone networks. The malware can receive commands over a cell network, which is unusual."




Thursday, March 19, 2015

Oracle: Next Generation of Engineered Systems


[Graphic courtesy Oracle Data Center Kickoff]

Oracle's Next Generation Engineered Systems

Abstract:

Larry Ellison: Executive Chairman of the Board and CTO introduces Oracle's 5th Generation of Oracle Engineered Systems. Provide the Highest Performance systems and Lowest Service Price at the core. Oracle effectively targets Cisco UCS, HP, EMC.

Summary of Major Announcements

Oracle Virtual Compute Appliance X5

Converged compute and srorage; Runs all datacenter applications. High Performance and Lowest Purchase Price... Combines compute servers, networking, and storage servers in the same box... highly available and fully redundant Compute Infrastructure: Scalable from 2-25 nodes; Linux, Solaris, and Windows; Network Infrastructure: High speed, low latency, fully configured fabric, integrates to existing Ethernet & Storage Networks Management Infrastructure: Redundant management servers; virtual assembly builder with templates included Half Price Oracle List to Cisco Discount; almost a third price

Oracle Storage Appliance X5

Twice as fast, half as much
  1. Extreme Flash Storage Server
  2. High Capacity Storage Server
12.8 TB PCIe Flash or 6.4 TB PCIe Flash with 48 TB SAS Disks

Oracle Database Appliance X5

2x Servers: 2x18 cores; 8x32 GB (256GB DIMM); 2x Infninband; 4x 10 Gbit Ethernet Storage: 4x 200 GB Flash for Redo Logs; 4x 400 GB Flash for ODA Accelerators; 16x 4TB Hard Drive (Data + Temp Tables + Archive Logs)

Zero Data Loss Recovery Appliance

Fully automated, point in time recovery, no data loss, thousands of databases Backup and log to another rack, another data center, or to Oracle Public Cloud

Big Data Appliance

Oracle Big Data SQL joins: Hadoop, NoSQL, and Oracle RDBMS

Exalogic Elastic Cloud X5-2

Private Cloud for Applications & Middleware Portability to Oracle Cloud Compute: 2x 18 cores, 256 GB RAM/node, 800 GB Flash/node Network: 40 Gbit InfiniBand internal; 10Gb or 1Gb Ethernet external Storage: 80 TB Disk; 256GB Storgage DRAM

Exadata Database Machine X5

Workloads: Warehousing, OLTP, Database as a Service, In-Memory Database Flash Disks replaced High-Performance Disks because Flash Capacity Increase and Price drop! Elastic Configurations: 2x DB and 3x Storage Servers... Full Rack... Multi-Rack Optimize for: In-Memory Max DRAM; OLTP Equal DB & Flash; Warehouse High Capacity Storage and Compute

Oracle SuperCluster

Two SPARC Options:
  1. SuperCluster T5-8
  2. SuperCluster M6-32
Same Storage Server and Software as Exadata X5

Data Center of the Future with Public Cloud

Options Include: - Logging Backups to the Cloud - Cloud as Backup Datacenter - Test and Development in Cloud with Production Local - Production in Cloud with Test and Development Local

The Deep Dive Sessions

The following Deep Dive sessions are for both newly announced hardware as well as for some existing software noted at the bottom of this section. Written summaries provided can assist in helping select which videos to watch.
Oracle SuperCluster

Oracle Largest, Most Advanced, and Most Secure Appliance

  • Exadata Storage Grid
  • Firmware based Hypervisor (vs re-purposed Linux OS as Hypervisor)
  • Cloud Tenant Self Service Portal
  • Rule Based Access Control Metering and Limiting by Account for customer's self service 
  • IO Domain Recipes (i.e. Small, Medium, Large selections) 
  • Templates on top of Recipe (Pre-configured Recipe with OS Patches and Application)
  • Extreme Tenant Isolation through Zone, Network Paths, and Disks
  • Automated Compliance Validation of isolation
Oracle Exadata X5-2

Exadata X5-2: Extreme Flash and Elastic Configurations

Oracle Exalogic X5

Oracle Exalogic X5-2 and Exalogic Elastic Cloud Software 12c

Engineered system designed to run the mid-tier components
  • Oracle Applications 
  • Java Applications 
  • Fusion Middleware 
Exabus Technology, shared with Exadata, which reduced latency between servers. Platform as a Service (Software made available in a cloud) and Infrastructure as a Service deployed on the customer premise.
Virtual Compute Appliance

Oracle Virtual Compute Appliance: Simplify IT and Save Money

Goals:
  • Simplify Deployment
  • Reduce Cost
Pre-built system which is ready to use in a Data Center with a minimal number of steps
  • Compute Capability: 2 - 25 nodes
  • Software defined network with Dual Redundant InfiniBand
  • Ethernet and FibreChannel external connectivity
  • Active-Passive Management Server
  • ZFS Storage Appliance with Redundant Controllers
Self-Service
  1. Provisioning of VM's, Storage, and Network
  2. Policy Driven
  3. Metering and Chargeback
  4. RESTful Infrastructure as a Service (IaaS) interface
Oracle Enterprise Manager drives IaaS
  • Fault Detection
  • Incident Management
  • Lifecycle Managment
  • Change Managment
  • Search & Compare of VM's
  • Apply Patches
  • Gold Templates
  • Compliance reporting
All software is bundled (Linux, Solaris, OEM 12c, Oracle VM, Orchestration, Oracle Virtual Networking, Oracle Trusted Partitioning)
Oracle Database Appliance

Oracle Database Appliance X5-2

Provides everything to deploy a high availability database & application
  • Wizards for simplified deployment
  • Patch Automation (Firmware, OS, Database, Storage, etc.)
  • Oracle High Availability Software Stack (Real Application Cluster or RAC)
  • Affordable with Capacity on Demand
  • Oracle Multitenant Option bundled License
  • In-Memory Database Option bundled License
  • OS and Virtualization Licenses
Refreshed hardware, higher consolidation density Oracle Enterprise Manager Plug-In for Monitoring and Management with Analytics across Appliances Same software stack as Exadata for affordable Test and Development
Oracle FS1 Flash Storage System

Oracle FS1 Flash Storage System 

Summary of Features
  • 2 - 16 Highly Available Nodes
  • Petabytes of Flash
  • 2M 50/50 Read/Write IOPS
  • 80 GB/sec or 5 TB/minute Data Movement
Designed to leverage Flash, not existing Hard Disk solutions. Supports both Flash and Disk, Designed for Flash with Economies of Disk
Oracle Big Data Appliance X5-2

Big Data Appliance

Solves problems surrounding:
  • Performance
    Optimized Hardware
  • Time
    30% Quicker to Deploy
  • Cost
    21% Less Expensive to Purchase
  • Integration
    Data Transparently into the Infrastructure
Oracle Big Data SQL for simple insertion Oracle Enterprise Manager Compatibility
Oracle for Enterprise Big Data

The Move to Big Data

Oracle Linux

Oracle: A Complete, Independent Linux Vendor

Nothing significantly new, basic key points:
  • Oracle Linux Premier Support included with Oracle Hardware
  • Stand-Alone Oracle Linux Premier Support offered for other servers 
  • MyOracleSupport Integrated 
  • Oracle KSplice Bundled (on-line patches, immediately active)
  • Oracle Enterprise Manager included for Patching and Management 
  • Oracle Clusterware Bundled 
  • Oracle Backport Lifetime Sustaining Support (no bug fixes, new hardware support) 
  • Oracle OpenStack bundled 
  • Red Hat Binary Compatibility
Delivery on DVD with pure Red Hat or Oracle Unbreakable Linux Kernel. OS Features
  • Oracle Unbreakable Kernel option for newer Oracle Engineered Systems.
  • DTrace Integration from Solaris for Oracle Linux
  • Isolation features: Linux Containers (LXC) similar to Solaris Zones; Docker (for Application)
  • Free to download, use, distribute, update; Pay for production system
  • Oracle VM Templates
Differentiation: DTrace and KSplice

Friday, March 13, 2015

New Tab: Packaging Resources!

[Solaris Logo, formerly from Sun Microsystems, now Oracle]

Announcement:
Network Management has just released the new Packaging Tab for Solaris Community!



Packaging resources for Solaris

[http] - SunFreeware (migrating to UNIXPackages)
[http] - UNIXPackages (commercial)
[http] - OpenCSW
[http] - Solaris Multimedia
[http] - iBiblio Solaris Package Archive
[http] - Solaris 11 Packages from Oracle (commercial)

Package/Configuration Management Resources for CPE

OpenACS [Home|Source] Config Mgmt for TR069 Protocol