Part I covered the paperwork: tailored agreements that drift, cores mistaken for
processors, obsolete metrics, duplicate named users and options that are enabled
by default. This part covers the technical half — tracking usage, indirect
access, virtualisation and the Oracle Server Worksheet.
Tracking usage
Being able to track how your installed Oracle software is actually used is
central to staying compliant. That runs from knowing how many named users are
genuinely using a database, through to measuring against the right metric for
each licence you hold, across everything you own rather than the systems you
happen to have looked at.
Detailed usage data does two jobs.
The first is defensive. At audit, it lets you show Oracle that you understand how
their software is being used in your organisation, and it gives you the ground to
challenge false positives — measurement scripts do produce them, and without your
own evidence you have no basis on which to argue.
The second is financial, and it is the one that pays for the work. Usage data
shows you which named users are not using the software. Somebody who has left,
or changed role, or was provisioned for a project that ended, is still consuming
a licence. Re-harvesting those licences means you buy fewer next time.
In CerteroX SAM, usage metering is file-based, with first-used and last-used
tracking per title and a percentage-used figure over a rolling ninety-day window.
Terminal Server and RDS remote usage is tracked per device, so users who reach
the software through a published desktop are not invisible. Where a device
genuinely should not consume a licence — development, training, MSDN, second use —
the Exclude From Licensing workflow removes it from the calculation and records
why, which is a defensible answer rather than an unexplained gap.
Indirect access
Indirect access is one of the most common routes to unintended non-compliance,
and it is not obvious from inside the Oracle environment at all.
For Oracle licensing, indirect access is where a non-Oracle application reaches
an Oracle database or Oracle data, typically through a single shared service
account. The application has one connection. Behind it may sit hundreds of
people.
In many cases those people need valid Named User Plus licences for the
organisation to be compliant. The single account does not cover them. You need
to be able to identify where indirect access exists and manage it deliberately,
because the alternative is discovering it during a true-up or an audit, at which
point the shortfall is retrospective and the negotiating position is poor.
Virtualisation
Virtualisation is an effective way to cut infrastructure cost, and it is the
single most expensive place Oracle licensing goes wrong. The reason is that
Oracle’s definition of what counts as virtualisation is much narrower than the
industry’s.
Oracle’s position is built around partitioning, and states that there are
“several hardware and software virtualization technologies available that deliver
partitioning”. In Oracle’s terms there are two kinds: hard and soft.
Soft partitioning
Soft partitioning divides the operating system using OS resource managers. Oracle
explicitly states that soft partitioning “is not permitted as a means to determine
or limit the number of software licenses required for any given server or cluster
of servers”.
In practice: if you run VMware on a cluster and Oracle runs on any machine in
that cluster, Oracle’s position is that every machine in the cluster requires
licensing — not only the host the software is installed on.
That is expensive, and it eliminates the virtualisation saving several times
over. We have seen organisations make exactly this mistake, and it is almost
always found during an audit, when it becomes a large true-up.
Hard partitioning
Hard partitioning is where a single server is physically separated into distinct
smaller systems, each behaving as an independent, self-contained server.
Oracle has specifically identified the technologies it recognises for licensing
purposes:
- Physical Domains — also known as PDomains, Dynamic Domains or Dynamic System Domains
- Solaris Zones — also known as Solaris containers; capped zones and containers only
- IBM LPAR — plus DLPAR with AIX 5.2
- IBM micro-partitions — capped partitions only
- vPAR
- nPAR
- Integrity Virtual Machine — capped partitions only
- Secure Resource Partitions — capped partitions only
- Fujitsu PPAR
Oracle VM Server can also be used, but the rules governing it are precise and
should be investigated in full before implementation rather than after.
This list is Oracle’s, published in its partitioning policy, and Oracle revises
it. Check the current version against your own hardware before you rely on any
entry above — including this one.
Given all of that, it is no surprise that virtualisation is one of the leading
reasons Oracle customers become non-compliant. The technical fix is to know, at
all times, which hosts sit in which cluster and which of them can run Oracle.
CerteroX ITAM inventories VMware, Hyper-V, Citrix XenServer, IBM HMC, Oracle VM,
Red Hat oVirt and Nutanix with the host-to-guest relationship intact, and
CerteroX SAM applies processor type, core factor and licence pool hosting rights
on top of it, so the licensable footprint of a cluster is calculated rather than
estimated.
The Oracle Server Worksheet
The Oracle Server Worksheet is the return you have to assemble. It sets out:
- which Oracle products you have installed
- what licence metric applies to each
- the infrastructure the licences are assigned to
The worksheet goes to Oracle’s licensing team — Global Licensing and Advisory
Services, formerly License Management Services — who compare it against what you
have bought and identify any shortfall.
Assembling it manually is slow and error-prone, and the effort scales with how
untidy the Oracle footprint is. That matters beyond the inconvenience: you need
accurate, current data or you will be negotiating from a weak position about a
shortfall you cannot independently verify.
The way to shorten it is continuous automated discovery and inventory of the
Oracle footprint, with usage measured alongside it, so the worksheet is drawn
from a live position rather than reconstructed from memory under time pressure.
What the Oracle engine in CerteroX SAM covers specifically: options and packs
with the supporting evidence and an override where use is justified; processor
types and core factors; licence pools with hosting rights and geographic rules;
cover-down logic for Enterprise Edition; uncapped quantity handling for unlimited
licence agreements; and E-Business Suite responsibilities.
One point worth knowing about the data itself. Certero is a verified third-party
tool vendor with Oracle License Management Services, which means Oracle’s audit
team can accept data from Certero during an official audit, as an alternative to
installing Oracle’s own measurement tools. That is a narrower statement than it
is sometimes made to sound — it does not remove Oracle from the process — but it
does mean the measurement you run for your own management is the same
measurement that can go into the engagement, rather than a rehearsal for one.
If you are working through an Oracle position and want to compare notes, get in
touch.