Oracle FAQ Your Portal to the Oracle Knowledge Grid
HOME | ASK QUESTION | ADD INFO | SEARCH | E-MAIL US
 

Home -> Community -> Usenet -> c.d.o.server -> Re: Verifying passwords have been changed in oracle

Re: Verifying passwords have been changed in oracle

From: Stephen Harris <sweh_at_spuddy.mew.co.uk>
Date: Fri, 08 Nov 2002 19:46:29 GMT
Message-ID: <s94hqa.s81.ln@spuddy.org>


Ed Stevens <spamdump_at_nospam.noway.nohow> wrote:
> How often do you have to audit to insure the sys and system passwords have been
> changed from the default? I would think this is something you'd have to check
> exactly once. And even if there were some fear that it might get set back to

Well, this is merely one test in a suite of tests. I'm building a compliance checker to ensure a build matches the security base line, and one of the baseline tests is that the password is not a default one. Other things will include ensuring SCOTT account doesn't exist, for example. Another would be permissions on the datafiles. And so on.

Initially the program will be executed on new builds to ensure they have been properly setup before going into production, but later there will be automated daily checks to verify nothing has broken.

-- 
                                 Stephen Harris
                              sweh_at_spuddy.mew.co.uk
      The truth is the truth, and opinion just opinion.  But what is what?
       My employer pays to ignore my opinions; you get to do it for free.
Received on Fri Nov 08 2002 - 13:46:29 CST

Original text of this message

HOME | ASK QUESTION | ADD INFO | SEARCH | E-MAIL US