Prev | Current Page 466 | Next

Richard Niemiec

"Oracle Database 10g Performance Tuning Tips & Techniques"


CAUTION
As of Oracle Database 11g, database passwords are case sensitive.
To disable case sensitivity, set the SEC_CASE_SENSITIVE_LOGON
intitialization parameter to FALSE.
The system initialization parameter REMOTE_LOGIN_PASSWORDFILE controls how the
password file is used for the database instance. It has three possible values: NONE, SHARED,
and EXCLUSIVE.
If the value is NONE, then Oracle ignores any password file that exists. Any privileged users
must be authenticated by other means, such as by operating system authentication, which is
discussed in the next section.
With a value of SHARED, multiple databases can share the same password file, but only the
SYS user is authenticated with the password file, and the password for SYS cannot be changed.
As a result, this method is not the most secure, but it does allow a DBA to maintain more than
one database with a single SYS account.
Chapter 9: Database Security and Auditing 283
TIP
If a shared password file must be used, ensure that the password for
SYS is at least eight characters long and includes a combination of
upper- and lowercase alphabetic, numeric, and special characters to
fend off a brute-force attack.
A value of EXCLUSIVE binds the password file to only one database, and other database user
accounts can exist in the password file. As soon as the password file is created, use this value to
maximize the security of SYSDBA or SYSOPER connections.
The dynamic performance view V$PWFILE_USERS lists all the database users who have either
SYSDBA or SYSOPER privileges, as shown here:
SQL> select * from v$pwfile_users;
USERNAME SYSDB SYSOP SYSAS
------------------------------ ----- ----- -----
SYS TRUE TRUE FALSE
RJB TRUE FALSE FALSE
Operating System Authentication
If a DBA chooses to implement operating system authentication, a database user is automatically
connected to the database when they use the following SQL*Plus syntax:
SQL> sqlplus /
This method is similar to how an administrator connects to the database, without the as sysdba or
as sysoper clause.


Pages:
454 455 456 457 458 459 460 461 462 463 464 465 466 467 468 469 470 471 472 473 474 475 476 477 478
odzyskiwanie danych www.poznan.tomoje.eu/node/3762 usługi ślusarskie w poznaniu tania bieżnia magnetyczna samochody