Skip to content

Common Oracle Software Licensing Issues – Part II

The technical half of the Oracle compliance problem: proving actual usage, indirect access through non-Oracle applications, the hard and soft partitioning rules that turn a virtualisation saving into an audit finding, and assembling the Oracle Server Worksheet.

Part I covered the paperwork: tailored agreements that drift, cores mistaken for processors, obsolete metrics, duplicate named users and options that are enabled by default. This part covers the technical half — tracking usage, indirect access, virtualisation and the Oracle Server Worksheet.

Tracking usage

Being able to track how your installed Oracle software is actually used is central to staying compliant. That runs from knowing how many named users are genuinely using a database, through to measuring against the right metric for each licence you hold, across everything you own rather than the systems you happen to have looked at.

Detailed usage data does two jobs.

The first is defensive. At audit, it lets you show Oracle that you understand how their software is being used in your organisation, and it gives you the ground to challenge false positives — measurement scripts do produce them, and without your own evidence you have no basis on which to argue.

The second is financial, and it is the one that pays for the work. Usage data shows you which named users are not using the software. Somebody who has left, or changed role, or was provisioned for a project that ended, is still consuming a licence. Re-harvesting those licences means you buy fewer next time.

In CerteroX SAM, usage metering is file-based, with first-used and last-used tracking per title and a percentage-used figure over a rolling ninety-day window. Terminal Server and RDS remote usage is tracked per device, so users who reach the software through a published desktop are not invisible. Where a device genuinely should not consume a licence — development, training, MSDN, second use — the Exclude From Licensing workflow removes it from the calculation and records why, which is a defensible answer rather than an unexplained gap.

Indirect access

Indirect access is one of the most common routes to unintended non-compliance, and it is not obvious from inside the Oracle environment at all.

For Oracle licensing, indirect access is where a non-Oracle application reaches an Oracle database or Oracle data, typically through a single shared service account. The application has one connection. Behind it may sit hundreds of people.

In many cases those people need valid Named User Plus licences for the organisation to be compliant. The single account does not cover them. You need to be able to identify where indirect access exists and manage it deliberately, because the alternative is discovering it during a true-up or an audit, at which point the shortfall is retrospective and the negotiating position is poor.

Virtualisation

Virtualisation is an effective way to cut infrastructure cost, and it is the single most expensive place Oracle licensing goes wrong. The reason is that Oracle’s definition of what counts as virtualisation is much narrower than the industry’s.

Oracle’s position is built around partitioning, and states that there are “several hardware and software virtualization technologies available that deliver partitioning”. In Oracle’s terms there are two kinds: hard and soft.

Soft partitioning

Soft partitioning divides the operating system using OS resource managers. Oracle explicitly states that soft partitioning “is not permitted as a means to determine or limit the number of software licenses required for any given server or cluster of servers”.

In practice: if you run VMware on a cluster and Oracle runs on any machine in that cluster, Oracle’s position is that every machine in the cluster requires licensing — not only the host the software is installed on.

That is expensive, and it eliminates the virtualisation saving several times over. We have seen organisations make exactly this mistake, and it is almost always found during an audit, when it becomes a large true-up.

Hard partitioning

Hard partitioning is where a single server is physically separated into distinct smaller systems, each behaving as an independent, self-contained server.

Oracle has specifically identified the technologies it recognises for licensing purposes:

  • Physical Domains — also known as PDomains, Dynamic Domains or Dynamic System Domains
  • Solaris Zones — also known as Solaris containers; capped zones and containers only
  • IBM LPAR — plus DLPAR with AIX 5.2
  • IBM micro-partitions — capped partitions only
  • vPAR
  • nPAR
  • Integrity Virtual Machine — capped partitions only
  • Secure Resource Partitions — capped partitions only
  • Fujitsu PPAR

Oracle VM Server can also be used, but the rules governing it are precise and should be investigated in full before implementation rather than after.

This list is Oracle’s, published in its partitioning policy, and Oracle revises it. Check the current version against your own hardware before you rely on any entry above — including this one.

Given all of that, it is no surprise that virtualisation is one of the leading reasons Oracle customers become non-compliant. The technical fix is to know, at all times, which hosts sit in which cluster and which of them can run Oracle. CerteroX ITAM inventories VMware, Hyper-V, Citrix XenServer, IBM HMC, Oracle VM, Red Hat oVirt and Nutanix with the host-to-guest relationship intact, and CerteroX SAM applies processor type, core factor and licence pool hosting rights on top of it, so the licensable footprint of a cluster is calculated rather than estimated.

The Oracle Server Worksheet

The Oracle Server Worksheet is the return you have to assemble. It sets out:

  • which Oracle products you have installed
  • what licence metric applies to each
  • the infrastructure the licences are assigned to

The worksheet goes to Oracle’s licensing team — Global Licensing and Advisory Services, formerly License Management Services — who compare it against what you have bought and identify any shortfall.

Assembling it manually is slow and error-prone, and the effort scales with how untidy the Oracle footprint is. That matters beyond the inconvenience: you need accurate, current data or you will be negotiating from a weak position about a shortfall you cannot independently verify.

The way to shorten it is continuous automated discovery and inventory of the Oracle footprint, with usage measured alongside it, so the worksheet is drawn from a live position rather than reconstructed from memory under time pressure.

What the Oracle engine in CerteroX SAM covers specifically: options and packs with the supporting evidence and an override where use is justified; processor types and core factors; licence pools with hosting rights and geographic rules; cover-down logic for Enterprise Edition; uncapped quantity handling for unlimited licence agreements; and E-Business Suite responsibilities.

One point worth knowing about the data itself. Certero is a verified third-party tool vendor with Oracle License Management Services, which means Oracle’s audit team can accept data from Certero during an official audit, as an alternative to installing Oracle’s own measurement tools. That is a narrower statement than it is sometimes made to sound — it does not remove Oracle from the process — but it does mean the measurement you run for your own management is the same measurement that can go into the engagement, rather than a rehearsal for one.

If you are working through an Oracle position and want to compare notes, get in touch.

Related reading

Other posts covering the same ground.

  • Device-based licensing and access control

    Locking an application down at user level does not make you compliant with a per-device licence. In a Citrix or RDS environment, one user with access can cost you a licence for every device in the organisation.

    • ITAM
    • SAM
    • Governance
    4 min
  • Gartner Myth Buster – Part 1

    A third-party summary of a vendor can be wrong, and it stays wrong for as long as people read it. The case for checking a vendor's facts at source — and the current, sourced record for Certero.

    • ITAM
    • SAM
    • Governance
    7 min
  • The role of good data in software audits

    An audit is won or lost on the quality of your inventory long before the letter arrives. Six ways data goes wrong, and what it takes to have the answer already in hand.

    • ITAM
    • SAM
    • Governance
    8 min
From reading to evidence

Put the hardest claim here
to a technical person.

Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.

No gated download at the end of it.