Oracle FAQ Your Portal to the Oracle Knowledge Grid
HOME | ASK QUESTION | ADD INFO | SEARCH | E-MAIL US
 

Home -> Community -> Usenet -> c.d.o.server -> Re: OK to revoke privileges from SYS or DBA?

Re: OK to revoke privileges from SYS or DBA?

From: hpuxrac <johnbhurley_at_sbcglobal.net>
Date: 6 Dec 2004 14:36:43 -0800
Message-ID: <1102372603.822048.265640@z14g2000cwz.googlegroups.com>


DA Morgan wrote:

snip

> I'd drop the DBA role completely as that is what Oracle advises. It
> exists, like CONNECT and RESOURCE solely for demonstration purposes
> just as does SCOTT/TIGER.

I disagree. Securing access to oracle provided roles is one thing, recommending dropping the roles is another thing altogether.

I for one have never heard anyone from oracle advising the DBA role should be dropped. I don't think that I would consider dropping connect or resource role either.

Where does this recommendation come from exactly?

Is this something someone has done on a production system and why? What were the ramifications?

This advice seems to me to be somewhat seat of the pants and highly questionable. Willing to have it proven otherwise of course.

John

> --
> Daniel A. Morgan
> University of Washington
> damorgan_at_x.washington.edu
> (replace 'x' with 'u' to respond)
Received on Mon Dec 06 2004 - 16:36:43 CST

Original text of this message

HOME | ASK QUESTION | ADD INFO | SEARCH | E-MAIL US