RE: password iin dba_users - Oracle 11

From: Ian Cary <ian.cary_at_ons.gsi.gov.uk>
Date: Thu, 22 Jan 2009 09:51:51 +0000
Message-ID: <OF018E775F.A7C0DECC-ON80257546.0035DC01-80257546.00362FFA_at_ons.gsi.gov.uk>



This is just a guess but perhaps the old style password hash is also used to support databases where password case sensitivity has been turned off using;

   alter system set sec_case_sensitive_logon=false

It wouldn't seem unreasonable for Oracle to detect that this parameter is set and just re-use the old code.

Cheers,

Ian

|---------+------------------------------>

| | John.Hallas_at_morriso|
| | nsplc.co.uk |
| | Sent by: |
| | oracle-l-bounce_at_fre|
| | elists.org |
| | |
| | |
| | 21/01/2009 13:48 |
| | Please respond to |
| | John.Hallas |
| | |
|---------+------------------------------> >--------------------------------------------------------------------------------------------------------------| | | | To: jkstill_at_gmail.com, Ian Cary/ONS_at_ONS | | cc: legedoos_at_gmail.com, oracle-l_at_freelists.org, oracle-l-bounce_at_freelists.org | | Subject: RE: password iin dba_users - Oracle 11 | >--------------------------------------------------------------------------------------------------------------|

Jared,
I understood that the old style password hash was there to support a database which has been migrated from 10g to 11g and converted to use the new case sensitive passwords.
As an ex 10g user changes his password or has an alter user command run against him he changes from the old hash to the new hash (which also includes case sensitivity) which is the reason why there is room to accommodate both hash versions.

I think I need to spend a bit of time researching this one, although currently we have no 10g to 11g migration plans, just new 11g builds.

John

It didn't work on 11g, simply due to the fact that the password hash is no longer
available in DBA_USERS.

It is however available in sys.user$ as Ian pointed out.

As referenced in Pete's blog, the old style password hash is still there, presumably for non-11g clients, though I haven't made any attempt to verify that.



Wm Morrison Supermarkets Plc is registered in England with number 358949. The registered office of the company is situated at Gain Lane, Bradford, West Yorkshire BD3 7DL. This email and any attachments are intended for the addressee(s) only and may be confidential.

If you are not the intended recipient, please inform the sender by replying to the email that you have received in error and then destroy the email. If you are not the intended recipient, you must not use, disclose, copy or rely on the email or its attachments in any way.

Wm Morrison Supermarkets PLC accepts no liability or responsibility for anything said in the email or its attachments and gives no warranty as to accuracy. It is the policy of Wm Morrison Supermarkets PLC not to enter into any contractual or other obligations by email.

Although we have taken steps to ensure the email and its attachments are virus-free, we cannot guarantee this or accept any responsibility, and it is the responsibility of recipients to carry out their own virus checks.


This email was received from the INTERNET and scanned by the Government Secure Intranet anti-virus service supplied by Cable&Wireless in partnership with MessageLabs. (CCTM Certificate Number 2007/11/0032.) In case of problems, please call your organisation’s IT Helpdesk. Communications via the GSi may be automatically logged, monitored and/or recorded for legal purposes.

For the latest data on the economy and society consult National Statistics at http://www.statistics.gov.uk


Please Note: Incoming and outgoing email messages are routinely monitored for compliance with our policy on the use of electronic communications


Legal Disclaimer : Any views expressed by the sender of this message are not necessarily those of the Office for National Statistics


The original of this email was scanned for viruses by the Government Secure Intranet virus scanning service supplied by Cable&Wireless in partnership with MessageLabs. (CCTM Certificate Number 2007/11/0032.) On leaving the GSi this email was certified virus free. Communications via the GSi may be automatically logged, monitored and/or recorded for legal purposes. i0zX+n{+i^ Received on Thu Jan 22 2009 - 03:51:51 CST

Original text of this message