{"id":8710,"date":"2016-12-09T09:16:47","date_gmt":"2016-12-09T14:16:47","guid":{"rendered":"https:\/\/pitss.org\/us\/?p=8710"},"modified":"2018-05-23T19:01:22","modified_gmt":"2018-05-23T23:01:22","slug":"secure-reports-showjobs-end-users","status":"publish","type":"post","link":"https:\/\/pitss.org\/us\/2016\/12\/09\/secure-reports-showjobs-end-users\/","title":{"rendered":"How to Secure Reports Showjobs from End Users"},"content":{"rendered":"<p>[et_pb_section fb_built=&#8221;1&#8243; admin_label=&#8221;section&#8221; _builder_version=&#8221;3.0.51&#8243; custom_padding=&#8221;0px||50px|&#8221;][et_pb_row custom_padding=&#8221;0px|||&#8221; admin_label=&#8221;Row&#8221; _builder_version=&#8221;3.0.51&#8243; background_size=&#8221;initial&#8221; background_position=&#8221;top_left&#8221; background_repeat=&#8221;repeat&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;3.0.47&#8243; parallax=&#8221;off&#8221; parallax_method=&#8221;on&#8221;][et_pb_text admin_label=&#8221;Text&#8221; _builder_version=&#8221;3.0.106&#8243; custom_margin=&#8221;||30px|&#8221;]<\/p>\n<p>By default, if you were to access the showjobs page of yourReports 11g or 12c environment, any user is able to view the page and open up the reports even if they contain confidential information. There is a way you can configure the showjobs to wh ere only specific users can access this page or any of the Reports admin pages.<\/p>\n<p>[\/et_pb_text][et_pb_divider color=&#8221;#e2e2e2&#8243; divider_position=&#8221;center&#8221; disabled_on=&#8221;on|on|off&#8221; admin_label=&#8221;Divider&#8221; _builder_version=&#8221;3.2&#8243; custom_css_main_element=&#8221;margin-bottom:30px !important;&#8221;][\/et_pb_divider][et_pb_text admin_label=&#8221;Text&#8221; _builder_version=&#8221;3.0.51&#8243; custom_margin=&#8221;||30px|&#8221;]<\/p>\n<h3><strong>What you&#8217;ll learn in this article:<\/strong><\/h3>\n<p><strong style=\"font-size: 16px; padding-right: 5px; background-color: #ffffff; color: #abd25e;\">\u2713<\/strong>\u00a0Steps that work for 12c and 11g with screenshots<\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row custom_padding=&#8221;40px|40px|30px|40px&#8221; background_position_1=&#8221;top_left&#8221; background_repeat_1=&#8221;no-repeat&#8221; admin_label=&#8221;Row&#8221; _builder_version=&#8221;3.0.51&#8243; background_color=&#8221;#006bb3&#8243;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;3.0.47&#8243; parallax=&#8221;off&#8221; parallax_method=&#8221;on&#8221; background_position=&#8221;top_left&#8221; background_repeat=&#8221;no-repeat&#8221;][et_pb_text admin_label=&#8221;Text&#8221; _builder_version=&#8221;3.0.106&#8243; background_color=&#8221;#006bb3&#8243; background_layout=&#8221;dark&#8221;]<\/p>\n<h2 style=\"font-size: 30px! important;\"><strong>Fill out the form below to access this blog post.<\/strong><\/h2>\n<p>[\/et_pb_text][et_pb_code admin_label=&#8221;Code&#8221; module_class=&#8221;white-text&#8221; _builder_version=&#8221;3.3.1&#8243;][ninja_form id=42][\/et_pb_code][\/et_pb_column][\/et_pb_row][et_pb_row custom_padding=&#8221;0px||0px|&#8221; custom_margin=&#8221;30px||0px|&#8221; background_position_1=&#8221;top_left&#8221; background_repeat_1=&#8221;no-repeat&#8221; admin_label=&#8221;Row&#8221; _builder_version=&#8221;3.0.51&#8243;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;3.0.47&#8243; parallax=&#8221;off&#8221; parallax_method=&#8221;on&#8221; background_position=&#8221;top_left&#8221; background_repeat=&#8221;no-repeat&#8221;][et_pb_cta title=&#8221;Avoid the Shadow App Mayhem&#8221; button_url=&#8221;https:\/\/pitss.org\/avoid-the-shadow-app-mayhem-transform-your-legacy-applications\/&#8221; url_new_window=&#8221;on&#8221; button_text=&#8221;LEARN MORE ABOUT SHADOW APPS&#8221; admin_label=&#8221;Call To Action&#8221; _builder_version=&#8221;3.3.1&#8243; background_color=&#8221;#222222&#8243; custom_button=&#8221;on&#8221; button_font=&#8221;Abel|||on|&#8221; text_orientation=&#8221;left&#8221; custom_padding=&#8221;45px|50px|45px|50px&#8221; border_style=&#8221;solid&#8221;]Is your IT team always chasing down shadow applications? You can keep your users happy by modernizing your legacy systems. Give users the tools to be more productive, all while updating and securing your internal systems.[\/et_pb_cta][\/et_pb_column][\/et_pb_row][\/et_pb_section]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>By default, if you were to access the showjobs page of yourReports 11g or 12c environment, any user is able to view the page and open up the reports even if they contain confidential information. There is a way you can configure the showjobs to wh ere only specific users can access this page or [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"on","_et_pb_old_content":"By default, if you were to access the showjobs page of your Oracle Reports 11g or 12c environment, any user is able to view the page and open up the reports even if they contain confidential information. There is a way you can configure the showjobs to where only specific users can access this page or any of the Reports admin pages (steps written for 12c but they will also work for 11g):\r\n<ol>\r\n \t<li>Open up rwservlet.properties (make a backup first) located in $DOMAIN_HOME\/config\/fmwconfig\/servers\/WLS_REPORTS\/applications\/reports_12.2.1\/configuration.<\/li>\r\n \t<li>Locate the line <strong><webcommandaccess>L2<\/webcommandaccess><\/strong>. Change <strong>L2<\/strong> to <strong>L1<\/strong>.\r\n<ol>\r\n \t<li>L1 will only permit end users to use the non-admin rwservlet commands <strong>GETJOBID, KILLJOBID, SHOWAUTH, and SHOWJOBID<\/strong>.<\/li>\r\n \t<li><a href=\"https:\/\/pitss.org\/us\/wp-content\/uploads\/sites\/4\/2016\/12\/rwservlet.properties.png\"><img class=\"alignnone size-full wp-image-8711\" src=\"https:\/\/pitss.org\/us\/wp-content\/uploads\/sites\/4\/2016\/12\/rwservlet.properties.png\" alt=\"rwservlet.properties\" width=\"867\" height=\"163\" \/><\/a><\/li>\r\n<\/ol>\r\n<\/li>\r\n \t<li>Save and close the file.<\/li>\r\n \t<li>Open up rwserver.conf (make a backup first) located in $DOMAIN_HOME\/config\/fmwconfig\/components\/ReportsServerComponent\/$rptsvr.<\/li>\r\n \t<li>Near the bottom of the file, look for the line <strong><queue maxQueueSize=\u201d1000\u201d\/><\/strong>. Immediately after this line, add the following line:\r\n<ul>\r\n \t<li><identifier encrypted=\u201dno\u201d>username\/password<\/identifier><\/li>\r\n \t<li><strong>NOTE: After you restart WLS_REPORTS and rep_server1, the credentials will be encrypted. Also, you may create any username\/password combination you like. It does not need to be what is configured in weblogic or in the database.<\/strong><\/li>\r\n \t<li><a href=\"https:\/\/pitss.org\/us\/wp-content\/uploads\/sites\/4\/2016\/12\/rwserver.conf-update.png\"><img class=\"alignnone size-full wp-image-8712\" src=\"https:\/\/pitss.org\/us\/wp-content\/uploads\/sites\/4\/2016\/12\/rwserver.conf-update.png\" alt=\"rwserver.conf update\" width=\"854\" height=\"679\" \/><\/a><\/li>\r\n<\/ul>\r\n<\/li>\r\n<\/ol>\r\n<ol start=\"6\">\r\n \t<li>Save and close the file.<\/li>\r\n \t<li>Restart both WLS_REPORTS and the standalone reports server.<\/li>\r\n \t<li>Try to access showjobs normally. You should be presented with the following error:\r\n<ul>\r\n \t<li>REP-52262: Diagnostic output is disabled<\/li>\r\n \t<li><a href=\"https:\/\/pitss.org\/us\/wp-content\/uploads\/sites\/4\/2016\/12\/REP-52262.png\"><img class=\"alignnone size-full wp-image-8713\" src=\"https:\/\/pitss.org\/us\/wp-content\/uploads\/sites\/4\/2016\/12\/REP-52262.png\" alt=\"REP-52262\" width=\"554\" height=\"463\" \/><\/a><\/li>\r\n<\/ul>\r\n<\/li>\r\n<\/ol>\r\n<ol start=\"9\">\r\n \t<li>Now, add \u201c?authId=username\/password\u201d to the end of the URL. Notice how the showjobs page appears.\r\n<ul>\r\n \t<li><a href=\"https:\/\/pitss.org\/us\/wp-content\/uploads\/sites\/4\/2016\/12\/showjobs-working.png\"><img class=\"alignnone size-full wp-image-8714\" src=\"https:\/\/pitss.org\/us\/wp-content\/uploads\/sites\/4\/2016\/12\/showjobs-working.png\" alt=\"showjobs working\" width=\"662\" height=\"469\" \/><\/a><\/li>\r\n<\/ul>\r\n<\/li>\r\n<\/ol>\r\n<ol start=\"10\">\r\n \t<li>If you were to reopen rwserver.conf, notice how the credentials are encrypted:\r\n<ul>\r\n \t<li><a href=\"https:\/\/pitss.org\/us\/wp-content\/uploads\/sites\/4\/2016\/12\/rwserver.conf-encrypted.png\"><img class=\"alignnone size-full wp-image-8715\" src=\"https:\/\/pitss.org\/us\/wp-content\/uploads\/sites\/4\/2016\/12\/rwserver.conf-encrypted.png\" alt=\"rwserver.conf encrypted\" width=\"835\" height=\"484\" \/><\/a><\/li>\r\n<\/ul>\r\n<\/li>\r\n<\/ol>\r\nSource: Oracle Support document <strong><span id=\"kmPgTpl:sd_r1:0:dv_rDoc:0:ol22\" class=\"p_AFHoverTarget xq\">1242614.1<\/span><\/strong> (Steps in the Oracle Support document are written for 11g)","_et_gb_content_width":"","footnotes":""},"categories":[4,36],"tags":[11,16,89,41,25,37],"class_list":["post-8710","post","type-post","status-publish","format-standard","hentry","category-install-config","category-reports","tag-11g","tag-11gr2","tag-12c","tag-configuration","tag-customer-support-request","tag-reports"],"_links":{"self":[{"href":"https:\/\/pitss.org\/us\/wp-json\/wp\/v2\/posts\/8710","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pitss.org\/us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pitss.org\/us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pitss.org\/us\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/pitss.org\/us\/wp-json\/wp\/v2\/comments?post=8710"}],"version-history":[{"count":13,"href":"https:\/\/pitss.org\/us\/wp-json\/wp\/v2\/posts\/8710\/revisions"}],"predecessor-version":[{"id":11397,"href":"https:\/\/pitss.org\/us\/wp-json\/wp\/v2\/posts\/8710\/revisions\/11397"}],"wp:attachment":[{"href":"https:\/\/pitss.org\/us\/wp-json\/wp\/v2\/media?parent=8710"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pitss.org\/us\/wp-json\/wp\/v2\/categories?post=8710"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pitss.org\/us\/wp-json\/wp\/v2\/tags?post=8710"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}