From oracle-l-bounce@freelists.org Mon Apr 11 12:31:16 2005 Return-Path: Received: from air891.startdedicated.com (root@localhost) by orafaq.com (8.12.10/8.12.10) with ESMTP id j3BHVGOW002316 for ; Mon, 11 Apr 2005 12:31:16 -0500 X-ClientAddr: 206.53.239.180 Received: from turing.freelists.org (freelists-180.iquest.net [206.53.239.180]) by air891.startdedicated.com (8.12.10/8.12.10) with ESMTP id j3BHVFem002312 for ; Mon, 11 Apr 2005 12:31:16 -0500 Received: from localhost (localhost [127.0.0.1]) by turing.freelists.org (Avenir Technologies Mail Multiplex) with ESMTP id D379193F92; Mon, 11 Apr 2005 11:29:06 -0500 (EST) Received: from turing.freelists.org ([127.0.0.1]) by localhost (turing [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 28506-06; Mon, 11 Apr 2005 11:29:06 -0500 (EST) Received: from turing (localhost [127.0.0.1]) by turing.freelists.org (Avenir Technologies Mail Multiplex) with ESMTP id 5AA1093E4E; Mon, 11 Apr 2005 11:29:06 -0500 (EST) X-MimeOLE: Produced By Microsoft Exchange V6.5.7226.0 Content-class: urn:content-classes:message MIME-Version: 1.0 Content-type: text/plain Subject: RE: Security audit of Oracle databases Date: Mon, 11 Apr 2005 12:27:14 -0400 Message-ID: X-MS-Has-Attach: X-MS-TNEF-Correlator: Thread-Topic: Security audit of Oracle databases Thread-Index: AcU+qPbFBFbuC1/PS+awXO/yvmjpDgAClG7g From: To: , Cc: X-OriginalArrivalTime: 11 Apr 2005 16:27:15.0086 (UTC) FILETIME=[524E52E0:01C53EB3] X-CanItPRO-Stream: default X-Spam-Score: undef - spam-scanning disabled X-Scanned-By: CanIt (www . roaringpenguin . com) on 167.78.2.22 Content-Transfer-Encoding: 8bit X-archive-position: 18302 X-ecartis-version: Ecartis v1.0.0 Sender: oracle-l-bounce@freelists.org Errors-To: oracle-l-bounce@freelists.org X-original-sender: Paula_Stankus@doh.state.fl.us Precedence: normal Reply-To: Paula_Stankus@doh.state.fl.us X-list: oracle-l X-Virus-Scanned: by amavisd-new-20030616-p9 (Debian) at avenirtech.net X-Spam-Checker-Version: SpamAssassin 2.60 (1.212-2003-09-23-exp) on air891.startdedicated.com X-Spam-Status: No, hits=0.4 required=5.0 tests=AWL,NO_REAL_NAME autolearn=no version=2.60 X-Spam-Level: Why not come up with an algoritm instead of writing them down? ________________________________ From: Jared Still [mailto:jkstill@gmail.com] Sent: Monday, April 11, 2005 11:13 AM To: stephenbooth.uk@gmail.com Cc: Stankus, Paula G; oracle-l@freelists.org Subject: Re: Security audit of Oracle databases On 4/11/05, stephen booth wrote: All important passwords should be recorded and stored somewhere safe (a piece of paper in an offsite secure location (e.g. where you keep your disaster recovery backups). BTW, of those 5 examples of why a DBA I will disagree with storing passwords on paper. It is extremely cumbersome and quite unworkable. We tried it, it doesn't work. There are a few commercial password safes available, some appear quite good, and allow limited access and auditing of password usage. -- Jared Still Certifiable Oracle DBA and Part Time Perl Evangelist ________________________________ Teach CanIt if this mail (ID 29303289) is spam: Spam Not spam Forget previous vote -- http://www.freelists.org/webpage/oracle-l