Thursday, July 30, 2026

Securing AI-Enabled Applications with Oracle Database 26ai

Artificial Intelligence (AI) is transforming enterprise applications by enabling intelligent search, automation, and data-driven decision making. As organizations integrate AI into their business processes, protecting the underlying data becomes more important than ever.

Oracle Database 26ai builds on Oracle's comprehensive security architecture, enabling organizations to secure both traditional database workloads and AI-enabled applications using proven Oracle Database security features. Rather than requiring a separate security framework, organizations can leverage existing capabilities such as Transparent Data Encryption (TDE), SQL Firewall, Unified Auditing, Database Vault, and least privilege administration to protect sensitive information.

Why AI Security Matters

AI applications often process valuable business information, including customer records, financial data, product documentation, and operational data. Without appropriate security controls, organizations may face risks such as:
  • Unauthorized access to sensitive data
  • SQL injection attacks
  • Stolen or compromised credentials
  • Insider threats
  • Data leakage
  • Regulatory compliance challenges
Protecting AI-enabled applications requires multiple layers of security rather than relying on a single security mechanism.

Oracle Database 26ai Security Approach

Oracle Database 26ai provides a layered security model that helps protect enterprise data throughout its lifecycle.

Transparent Data Encryption (TDE)

Transparent Data Encryption (TDE) protects sensitive information stored in Oracle Database by encrypting data at rest without requiring application changes.

Key benefits include:
  • Encryption of database data stored in encrypted tablespaces
  • Protection of backup data
  • Strong encryption algorithms such as AES-256
  • Integration with Oracle Key Vault for centralized key management
By enabling TDE, organizations can significantly reduce the risk of unauthorized access to stored data.

SQL Firewall

Applications often generate predictable SQL statements. Oracle SQL Firewall helps improve database security by allowing only approved SQL statements to execute.

Typical benefits include:
  • Helping protect applications from SQL injection attacks
  • Blocking unauthorized SQL statements
  • Reducing risks associated with compromised credentials
  • Providing centralized SQL validation
SQL Firewall complements existing application security controls by validating SQL at the database layer.

Unified Auditing

Monitoring database activity is an important part of every security strategy.

Unified Auditing simplifies audit management by storing audit records in a single repository and supports auditing of both successful and unsuccessful activities.

Common auditing scenarios include:
  • User logins
  • Administrative operations
  • Privilege usage
  • Object access
  • Security policy changes
A well-designed auditing strategy improves compliance reporting while providing valuable information during security investigations.

Database Vault

Database Vault helps organizations implement separation of duties and protect sensitive application data from unauthorized access, including privileged users.

Key capabilities include:
  • Realms
  • Command Rules
  • Rule Sets
  • Secure Application Roles
These controls provide additional protection beyond traditional privilege management.

Least Privilege Administration

One of the most effective security practices is granting users only the privileges required to perform their job functions.

Organizations should:
  • Review user privileges regularly
  • Avoid unnecessary system privileges
  • Remove unused accounts
  • Follow role-based access control whenever possible
Applying least privilege reduces the overall attack surface and minimizes the impact of compromised accounts.

Security Best Practices

When deploying AI-enabled applications on Oracle Database 26ai, consider the following recommendations:
  • Enable Transparent Data Encryption
  • Configure SQL Firewall for critical applications
  • Enable Unified Auditing
  • Protect sensitive data using Database Vault
  • Follow least privilege principles
  • Regularly review audit reports and security configurations
AI adoption continues to accelerate across enterprises, making database security more important than ever. Oracle Database 26ai enables organizations to secure AI-enabled applications by leveraging Oracle's mature security capabilities, including encryption, auditing, SQL Firewall, Database Vault, and least privilege administration.

A layered security approach not only helps protect sensitive information but also improves compliance, reduces operational risk, and strengthens overall database security.

Tuesday, July 28, 2026

Resolving Tableau Messaging Service (ActiveMQ) Startup Failure After Upgrading to Tableau Server 2025.3.6

After successfully upgrading our Tableau Server environment to version 2025.3.6, we encountered an issue where the Messaging Service (ActiveMQ) failed to start on two nodes in our multi-node deployment. This caused the affected nodes to remain in a degraded state, preventing the cluster from becoming fully operational

This article describes the symptoms we observed, the troubleshooting steps we performed, and the solution that successfully restored the Messaging Service.
Problem

 The log output below has been sanitized to remove environment-specific information, and repetitive log entries have been omitted for brevity.

C:\Tableau Server\data\tabsvc\services\activemqserver_<version>\status.cmd

Java class name: com.tableausoftware.activemq.ActiveMQApp
Method name: main
Arguments: status
"currentDeploymentState": "NONE",
"details": {
"message": "Connect to localhost:8099 [localhost/127.0.0.1,
localhost/0:0:0:0:0:0:0:1] failed:
Connection refused: connect"
},
"name": "activemqserver_0",
"processStatus": "DOWN",
"version": "<2025.3.x>"
Exit code: 4

Resolution

1. Go to:
C:\Tableau Server\data\tabsvc\services\activemqserver_<version>

2. Run:
disable.cmd

Expected (sanitized):
Connecting to JMX URL:
service:jmx:rmi:///jndi/rmi://localhost:1099/jmxrmi
INFO: Broker now available at:
service:jmx:rmi:///jndi/rmi://localhost:1099/jmxrmi
Exit code: 0

3. Rename:
C:\Tableau Server\data\tabsvc\services\activemqserver_0\kahadb

To:
kahadb.old

4. Run:
enable.cmd

Expected (sanitized):
Java class name: com.tableausoftware.activemq.ActiveMQApp
Method name: main
Arguments: enable
Exit code: 0

5. Restart Tableau Server:
tsm restart

All Tableau Servers came online without any warnings or issues

The embedded ActiveMQ broker stores its persistent message data in the KahaDB directory. If the message store becomes corrupted or incompatible during an upgrade, ActiveMQ may fail to start. Renaming the KahaDB folder causes Tableau to create a fresh message store during startup.

Best Practices
- Take a Tableau backup before making changes.
- Verify all nodes become Active after restart.
- Review ActiveMQ logs if the problem persists.
- Contact Tableau Support if the issue continues.

In this case, disabling the Messaging Service, renaming the KahaDB folder, re-enabling the service, and restarting Tableau Server successfully restored the Messaging Service and returned all nodes to a healthy state.

Thanks
https://oracleracexpert.com

Wednesday, July 22, 2026

Webinar: Oracle Database 26ai Security New Features

Join us for an exclusive technical session exploring the latest security enhancements in Oracle Database 26ai. Learn how Oracle helps secure modern enterprise and AI-enabled workloads using built-in security capabilities such as SQL Firewall, Transparent Data Encryption (TDE), Unified Auditing, Database Vault, Oracle Data Safe, and modern authentication mechanisms. This session includes practical demonstrations, best practices, and real-world implementation guidance for DBAs and architects.

Date & Time
July 31st 2026 | 8:00 AM – 9:00 AM Pacific Time (GMT-07:00 | San Francisco)

This session is ideal for:
  • Oracle DBAs
  • Database & Solution Architects
  • Security Professionals
  • Oracle Developers
  • Cloud Engineers
Topics covered in this webinar include:
  • Oracle Database 26ai Security Overview
  • AI Security and Protecting AI Workloads
  • SQL Firewall Architecture and Administration
  • Transparent Data Encryption (TDE)
  • Unified Auditing and Fine-Grained Auditing
  • Authentication using Microsoft Entra ID, IAM and Kerberos
  • Database Vault and Least Privilege Administration
  • Oracle Data Safe Security Assessment and Data Masking
  • Oracle Database 26ai Security Best Practices
  • Live Demonstration of Key Security Features
Key Takeaways
  • Understand the latest Oracle Database 26ai security enhancements.
  • Learn how to secure AI-enabled and enterprise database workloads.
  • Implement Oracle security best practices to reduce cyber risks.
  • Improve compliance using auditing, encryption, and least privilege.
  • Gain practical knowledge through real-world examples and demonstrations.

How to Register

Please send an email to: SatishbabuGunukula@gmail.com to register and receive webinar passcode details.

Click here to join the Meeting
Click here to download the Presentation

Saturday, May 30, 2026

How to Fix Oracle 26ai Installer Error INS-13001 on RHEL 9

While deploying the new Oracle AI Database 26ai on Red Hat Enterprise Linux 9.x (RHEL 9.x), I have come across a confusing scenario where the installation goes perfectly smoothly on SERVER1 but throws a frustrating error on a seemingly identical SERVER2.

WARNING: [May 18, 2026 1:26:22 PM] Verification of target environment returned with errors. WARNING: [May 18, 2026 1:26:22 PM] [WARNING] [INS-13001] Oracle Database is not supported on this operating system. Installer will not perform prerequisite checks on the system.
CAUSE: This operating system may not have been in the certified list at the time of the release of this software.
ACTION: Refer to My Oracle Support portal for the latest certification information for this operating system. Proceed with the installation if the operating system has been certified after the release of this software..


Checking /etc/redhat-release and /etc/os-release on both machines confirms they are both pristine, matching copies of RHEL 9.6. So why is one failing while the other succeeds?

[oracle@SERVER1]$cat /etc/redhat-release
Red Hat Enterprise Linux release 9.6 (Plow)

[oracle@SERVER1]$cat /etc/os-release
NAME="Red Hat Enterprise Linux"
VERSION="9.6 (Plow)"
ID="rhel"
ID_LIKE="fedora"
VERSION_ID="9.6"
PLATFORM_ID="platform:el9"
PRETTY_NAME="Red Hat Enterprise Linux 9.6 (Plow)"
ANSI_COLOR="0;31"
LOGO="fedora-logo-icon"
CPE_NAME="cpe:/o:redhat:enterprise_linux:9::baseos"
HOME_URL="https://www.redhat.com/"
DOCUMENTATION_URL="https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9"
...etc

[oracle@SERVER2]$cat /etc/redhat-release
Red Hat Enterprise Linux release 9.6 (Plow)

[oracle@SERVER2]$cat /etc/os-release
NAME="Red Hat Enterprise Linux"
VERSION="9.6 (Plow)"
ID="rhel"
ID_LIKE="fedora"
VERSION_ID="9.6"
PLATFORM_ID="platform:el9"
PRETTY_NAME="Red Hat Enterprise Linux 9.6 (Plow)"
ANSI_COLOR="0;31"
LOGO="fedora-logo-icon"
CPE_NAME="cpe:/o:redhat:enterprise_linux:9::baseos"
HOME_URL="https://www.redhat.com/"
DOCUMENTATION_URL="https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9"
...etc

We also did the research and found out that REHL9.6 is fully certified.

The answer usually isn't your OS version at all, it's OS security hardening policy. Here is why this happens and how to fix it in under two minutes.

The Secret Culprit: noexec on /tmp

During the initialization phase, the Oracle Universal Installer (OUI) extracts temporary architecture and OS-validation binaries into the system's /tmp directory and attempts to execute them.

On many production-hardened Linux servers, corporate security policies dictate that the /tmp partition must be mounted with the noexec flag. When the installer's background detection scripts get blocked from running, the OUI hits a generic failure and defaults to its catch-all warning: “OS not supported.”

How to Verify the Issue

Run the following command on both servers to check the mount permissions of your temporary directory:

$ mount | grep /tmp

If the failing server outputs noexec inside the configuration brackets, you have officially found the culprit.

The Solution: Redirect Oracle's Temp Directory or mount the /tmp with "exec"

You don’t need to ask your security team to compromise server hardening rules by remounting /tmp. Instead, you can simply instruct the Oracle installer to use a directory where the oracle user naturally has execution permission, such as their own home directory.

Log into your failing server as the oracle installation user, and run these commands in the terminal before launching the installer:

# 1. Create a dedicated temp directory in the oracle home folder

$ mkdir -p /home/oracle/oratmp


# 2. Redirect the installer's environment variables

$export TMP=/home/oracle/oratmp
$export TMPDIR=/home/oracle/oratmp

# 3. Launch the installer from this same terminal session

$./runInstaller

By changing these variables, the installer bypasses /tmp entirely, successfully reads your RHEL 9 configuration from /home/oracle/oratmp, and allows the setup to proceed seamlessly.

Thanks & Regards
https://oracleracexpet.com

Thursday, April 2, 2026

Beyond the Basics: Master Repeatable DDL in Oracle Database 23ai

The introduction of the IF [NOT] EXISTS clause in Oracle Database 23ai is more than a syntax update it’s a fundamental shift in how we approach Schema as Code.

In my recent exploration of this feature, I found that while the "Table" examples are the most common, the real power lies in how it simplifies the management of all schema objects. Let's dive deeper into some advanced examples and how they solve daily deployment hurdles.

1. Handling Supporting Objects: Indexes and Sequences

In any production environment, a table rarely exists in a vacuum. You usually have sequences for primary keys and indexes for performance. Before 23ai, if a migration script failed halfway through, you’d have to manually check which indexes were created and which weren't.

Now, you can ensure your entire environment is ready in a single, repeatable block:

-- Safely create a sequence for Employee IDs

SQL> CREATE SEQUENCE IF NOT EXISTS emp_seq START WITH 100 INCREMENT BY 1;

-- Safely create a performance index

SQL>CREATE INDEX IF NOT EXISTS idx_emp_name ON EMPLOYEE(EMP_NAME);

Why this matters: If your deployment tool (like Jenkins or GitLab CI/CD) retries a failed job, these statements won't cause the "Object already exists" error that usually stops a pipeline in its tracks.

2. Simplifying Application Logic: Synonyms

If you manage multi-tenant environments or applications that use synonyms to point to different schema versions, you know the struggle of "cleaning up" old pointers.

-- Ensure the public pointer exists without checking metadata

SQL> CREATE SYNONYM IF NOT EXISTS emp_public FOR HR_DATA.EMPLOYEE;

-- Or, if you are decommissioning a module:

SQL> DROP SYNONYM IF EXISTS old_emp_ref;

3. The "Gotcha" Deep Dive: Understanding Object vs. Attribute

As I mentioned in my recent Oracle Sprint, there is a subtle distinction to keep in mind: Object-level existence vs. Attribute-level existence.

Consider the ALTER TABLE command.
 
  • The Success: ALTER TABLE IF EXISTS employee ADD (department_id NUMBER); — This works perfectly because Oracle checks if the table "employee" exists.

  • The Failure: If you run that same command again, it will fail.

The Reason: Even though the table exists, the column "department_id" also now exists. The IF EXISTS clause doesn't currently look inside the table to see if the column is already there. For column-level idempotency, you still need to be strategic with your migration scripts.

4. Avoiding the Conflict: "REPLACE" vs. "IF NOT EXISTS"

This is a frequent point of confusion. You might be tempted to write: CREATE OR REPLACE VIEW IF NOT EXISTS emp_v AS SELECT...

Oracle will throw ORA-11541. * Use OR REPLACE when you want the object to be updated with new logic (common for Views, Procedures, and Functions).
Use IF NOT EXISTS when you want to ensure you don't overwrite something that is already there (common for Tables, Sequences, and Indexes).

Strategic Summary

The "Idempotent DDL" approach in 23ai removes the "fear of the second run." By incorporating these clauses into your standard SQL scripts, you:
  1. Reduce Boilerplate: No more 10-line PL/SQL blocks for a 1-line DDL.
  2. Increase Pipeline Uptime: Fewer "false positive" failures in CI/CD.
  3. Improve Readability: Your intent is clear to any developer reading the code.

Final Thought for the Community

As we move toward more automated, AI-driven database management, these small syntax changes are what make large-scale automation possible. Are you planning to refactor your legacy migration scripts to use these new clauses, or are you saving them for new projects only?

Let's discuss in the comments!

Thanks & Regards
https://oracleracexpert.com