Oracle FAQ Your Portal to the Oracle Knowledge Grid
HOME | ASK QUESTION | ADD INFO | SEARCH | E-MAIL US
 

Home -> Community -> Mailing Lists -> Oracle-L -> RE: password complexity -- implementing security changes

RE: password complexity -- implementing security changes

From: Baumgartel, Paul <paul.baumgartel_at_credit-suisse.com>
Date: Fri, 3 Mar 2006 15:38:29 -0500
Message-ID: <D97D1FAE0521BD44820B920EDAB3BBAC0A189F41@ENYC11P32005.corpny.csfb.com>


An Oracle password has the following rules: A password must begin with an alphabetic character. Passwords can contain only alphanumeric characters and the underscore (_), dollar sign ($), and pound sign (#).

So your @s, your /s, and your ^s are problematic from the get-go.

Paul Baumgartel
paul.baumgartel_at_credit-suisse.com
212.538.1143

-----Original Message-----
From: oracle-l-bounce_at_freelists.org
[mailto:oracle-l-bounce_at_freelists.org]On Behalf Of MARK BRINSMEAD Sent: Friday, March 03, 2006 3:22 PM
To: jkstill_at_gmail.com
Cc: venu_potluri_at_ml.com; rjamya_at_gmail.com; wbfergus_at_usgs.gov; oracle-l_at_freelists.org
Subject: Re: password complexity -- implementing security changes

Okay, so why is *that* a problem? After all, last time I checked, Oracle database passwords were case-insensitive anyway...

Special characters, on the other hand, *can* be a problem. I seem to recall even SQL*Plus giving me considerable grief with a password that contained "/" characters... No wait; it was a Pro*C application.

>
>
> One thing the verify_function cannot do is enforce upper or lower
> case.Try it, case doesn't matter.
>
> While on the subject, be careful with those special characters.
>
> Some applications do not like them.
>
> Net Backup for instance will not work if there is a @ or ^ in the
> passwordfor the account used to do backups.
>
>
>
> Jared Still
> Certifiable Oracle DBA and Part Time Perl Evangelist
>

--
http://www.freelists.org/webpage/oracle-l



==============================================================================
Please access the attached hyperlink for an important electronic communications disclaimer: 

http://www.credit-suisse.com/legal/en/disclaimer_email_ib.html
==============================================================================

--
http://www.freelists.org/webpage/oracle-l
Received on Fri Mar 03 2006 - 14:38:29 CST

Original text of this message

HOME | ASK QUESTION | ADD INFO | SEARCH | E-MAIL US