RE: os authenticated accounts
Date: Tue, 4 Mar 2008 14:02:30 -0500
I have always preferred to set the os_authent_prefix='' rather than OPS$. I am not sure if trying to limit the node access is practical since I do not think the node checking can be associated to usernames in the sqlnet layer. You might need to resort to checking the IP for any OS authenticated accounts in an after logon database event trigger.
- Mark D Powell -- Phone (313) 592-5148
[mailto:oracle-l-bounce_at_freelists.org] On Behalf Of QuijadaReina, Julio C
Sent: Tuesday, March 04, 2008 9:52 AM
To: 'mdemenko_at_gmail.com'; joe_dba_at_hotmail.com Cc: oracle-l_at_freelists.org
Subject: RE: os authenticated accounts
Yes, it is possible.
The following parameters on your database init.ora relating to this are (if my memory serves me correctly):
Create the account you will use on your Linux box. Then create the externally identified account on your database. From your Linux client you should be able to connect by issuing 'sqlplus /' after setting the client environment.
A word of caution: anyone knowing your database tnsnames and the name of the account could potentially connect to your database. That sounds pretty bad! You might want to look into tcp.validnode_checking and tcp.invited_nodes pars on your server's sqlnet.ora and/or have the OS firewall setting that opens the listener port only to your linux client.
[mailto:oracle-l-bounce_at_freelists.org] On Behalf Of Maxim Demenko Sent: Tuesday, March 04, 2008 1:05 AM
Subject: Re: os authenticated accounts
Joe Smith schrieb:
> Is it possible to use OS authenticated accounts ( i.e. identified
> externally ) between two servers?
> I have a linux box with with an oracle client install and an aix
> server with EE installed.
> The external account was originally on the aix server. We want to
> move the 3rd party app and the account to a linux box.
> -- Shed those extra pounds with MSN and The Biggest Loser! Learn more.
You may look on the external users identified by ssl certificates (if you are on 10g onwards).
Not sure about additional licensing costs (i.e. whether it is part of ASO or not).
-- http://www.freelists.org/webpage/oracle-l -- http://www.freelists.org/webpage/oracle-l -- http://www.freelists.org/webpage/oracle-lReceived on Tue Mar 04 2008 - 13:02:30 CST