Return-Path: <oracle-l-bounce@freelists.org>
X-Original-To: oracle-l@orafaq.com
Delivered-To: oracle-l@orafaq.com
Received: from puck1183.startdedicated.com (localhost [127.0.0.1])
 by puck1183.startdedicated.com (Postfix) with ESMTP id C86761960639
 for <oracle-l@orafaq.com>; Thu,  7 Jul 2016 16:59:55 +0200 (CEST)
Received: from turing.freelists.org (turing.freelists.org [206.53.239.180])
 by puck1183.startdedicated.com (Postfix) with ESMTPS
 for <oracle-l@orafaq.com>; Thu,  7 Jul 2016 16:59:55 +0200 (CEST)
Received: from localhost (localhost [127.0.0.1])
 by turing.freelists.org (Avenir Technologies Mail Multiplex) with ESMTP id 644B724081;
 Thu,  7 Jul 2016 10:59:13 -0400 (EDT)
X-Virus-Scanned: Debian amavisd-new at turing.freelists.org
Received: from turing.freelists.org ([127.0.0.1])
 by localhost (turing.freelists.org [127.0.0.1]) (amavisd-new, port 10024)
 with ESMTP id HH1xuQovqQxh; Thu,  7 Jul 2016 10:59:13 -0400 (EDT)
Received: from turing.freelists.org (localhost [127.0.0.1])
 by turing.freelists.org (Avenir Technologies Mail Multiplex) with ESMTP id 7B1FD23B32;
 Thu,  7 Jul 2016 10:59:00 -0400 (EDT)
Received: with ECARTIS (v1.0.0; list oracle-l); Thu, 07 Jul 2016 10:57:38 -0400 (EDT)
Received: from localhost (localhost [127.0.0.1])
 by turing.freelists.org (Avenir Technologies Mail Multiplex) with ESMTP id 7F03C2175B
 for <oracle-l@freelists.org>; Thu,  7 Jul 2016 10:57:38 -0400 (EDT)
Received: from turing.freelists.org ([127.0.0.1])
 by localhost (turing.freelists.org [127.0.0.1]) (amavisd-new, port 10024)
 with ESMTP id zSmDNcOCGNl5 for <oracle-l@freelists.org>;
 Thu,  7 Jul 2016 10:57:38 -0400 (EDT)
Received: from mail-oi0-f45.google.com (mail-oi0-f45.google.com [209.85.218.45])
 (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits))
 (No client certificate requested)
 by turing.freelists.org (Avenir Technologies Mail Multiplex) with ESMTPS id 4F2D521732
 for <oracle-l@freelists.org>; Thu,  7 Jul 2016 10:57:38 -0400 (EDT)
Received: by mail-oi0-f45.google.com with SMTP id r2so26392577oih.2
        for <oracle-l@freelists.org>; Thu, 07 Jul 2016 07:57:38 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=1e100.net; s=20130820;
        h=x-gm-message-state:mime-version:in-reply-to:references:from:date
         :message-id:subject:to:cc;
        bh=ECNDxWoF80qsf6ySVDuRzav+TJm2Frt4GGgLi7go/CU=;
        b=CbYqoM815XY89EBx9LJTb78wf8by3tHOiV2Ji4d24OQEW5k74IEuo396SxGBdxW9dF
         ERjlaRDqNjqt6ja/PpS5zSzAsXOVAKUUByDewOUhFR6ZVT+xvYQoOf5I8q5QE8PUMPL0
         0k5QFqj+pK5fmQ9owPbXpYvJQaqboVGRdggzdb/gM3zMgd+2ePfo23/krMDm+oymXIrZ
         D8cqQIg4jzS21EzIsjjwt3z0WDZdUU2NZ0EIsvbD22gbcMlrlA8CnLRN/CiOntMTPXXZ
         9hRNZVhUqkwdBnyGOGBPBAUpbGy9RSR1PHRJ+rYU28G2b7Ku/FZqZVLWCqvbtsOSuZMk
         BbRQ==
X-Gm-Message-State: ALyK8tJYsTizXE9LX8VRoHzndAWTDktzHdgx2dcxzTiWBnMmoX9Wi7ftQXlmqnvCOWMrhVGD/jjKy9zvuGVe5A==
X-Received: by 10.157.8.49 with SMTP id 46mr425253oty.81.1467903457803; Thu,
 07 Jul 2016 07:57:37 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.182.241.6 with HTTP; Thu, 7 Jul 2016 07:57:37 -0700 (PDT)
In-Reply-To: <C1FB7BA65B13C542B2CB1CE5DB8F74AF4B5F8A54@NC2PWEX501.us.ad.lfg.com>
References: <577D96E8.60502@gmail.com> <CAC540oiLsoSZ+26yqv0ecmFq8P__4+NbGQUPjQgLqGqjZPkEGQ@mail.gmail.com>
 <577DA534.2090905@gmail.com> <CADo_RaP=DgVAr6SsqF8WX+JNsyyBHBCqY+_BtW6XoZT05Kd_Ww@mail.gmail.com>
 <016201d1d808$763be5f0$62b3b1d0$@comcast.net> <CAP79kiTUN+7bixhP30F0CMH90+RdeWtBE7BAWSUH8b3kOvDuLA@mail.gmail.com>
 <CADo_RaMmO1hTeKfD3DoTZuQKLKU5+sbJ11fwm8mHYMUEs5JQmA@mail.gmail.com>
 <TU4PR84MB020639612E0EC3826DE052F0CC3B0@TU4PR84MB0206.NAMPRD84.PROD.OUTLOOK.COM>
 <CAJvnOJYUx-597WkN7jxVtk2uBFwqr40VeH_YFP48caKnVBZCcg@mail.gmail.com> <C1FB7BA65B13C542B2CB1CE5DB8F74AF4B5F8A54@NC2PWEX501.us.ad.lfg.com>
From: Chris Taylor <christopherdtaylor1994@gmail.com>
Date: Thu, 7 Jul 2016 09:57:37 -0500
Message-ID: <CAP79kiQsE00mGCqM012iPqk+O=+=LrY-bO3RjtHQ0MtFsogNuQ@mail.gmail.com>
Subject: Re: Passwords in DBA_USERS (Oracle 12c)
To: "Deas, Scott" <Scott.Deas@lfg.com>
Cc: "andrew.kerber@gmail.com" <andrew.kerber@gmail.com>, "mark.powell2@hpe.com" <mark.powell2@hpe.com>, 
 "andy@oracledepot.com" <andy@oracledepot.com>, 
 "dimensional.dba@comcast.net" <dimensional.dba@comcast.net>, Mladen Gogala <gogala.mladen@gmail.com>, 
 oracle-l <oracle-l@freelists.org>
Content-Type: multipart/alternative; boundary=94eb2c0308542ac45305370ce81b
X-archive-position: 65476
X-ecartis-version: Ecartis v1.0.0
Sender: oracle-l-bounce@freelists.org
Errors-to: oracle-l-bounce@freelists.org
X-original-sender: christopherdtaylor1994@gmail.com
Precedence: normal
Reply-To: christopherdtaylor1994@gmail.com
List-help: <mailto:ecartis@freelists.org?Subject=help>
List-unsubscribe: <oracle-l-request@freelists.org?Subject=unsubscribe>
List-software: Ecartis version 1.0.0
List-Id: oracle-l <oracle-l.freelists.org>
X-List-ID: oracle-l <oracle-l.freelists.org>
List-subscribe: <oracle-l-request@freelists.org?Subject=subscribe>
List-owner: <mailto:mark.bobak@proquest.com>
List-post: <mailto:oracle-l@freelists.org>
List-archive: <http://www.freelists.org/archives/oracle-l>
X-list: oracle-l
--94eb2c0308542ac45305370ce81b
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

It appears the only problem with this approach is the DBA doesn't include
this ability automatically.  You still have to do the grant to the DBA to
allow the connect through - which requires a 3rd account to do the grant as
you can't grant privs to yourself.  It would be great if this was included
in the DBA role functionality to connect through any user.

After setting up the necessary grant, it is definitely easier to do it this
way but in the middle of an application deployment, this method is
cumbersome if the setup grants haven't been completed.

Thanks,
Chris


On Thu, Jul 7, 2016 at 9:44 AM, Deas, Scott <Scott.Deas@lfg.com> wrote:

> But you don=E2=80=99t need to know the user=E2=80=99s password or change =
it, you just
> proxy into the account.  We=E2=80=99ve been using it successfully here fo=
r years.
>
>
>
>
> http://www.oracle.com/technetwork/issue-archive/2013/13-mar/o23asktom-190=
6478.html
>
>
>
> Thanks,
> Scott
>
>
>
> *From:* oracle-l-bounce@freelists.org [mailto:
> oracle-l-bounce@freelists.org] *On Behalf Of *Andrew Kerber
> *Sent:* Thursday, July 07, 2016 10:27 AM
> *To:* mark.powell2@hpe.com
> *Cc:* Chris Taylor <christopherdtaylor1994@gmail.com>;
> andy@oracledepot.com; dimensional.dba@comcast.net; Mladen Gogala <
> gogala.mladen@gmail.com>; oracle-l <oracle-l@freelists.org>
> *Subject:* Re: Passwords in DBA_USERS (Oracle 12c)
>
>
>
> Yes.  Until programmers learn to include functionality that allows
> passwords to be changed easily on the mid tier, the DBA or designated
> security personnel must be able to change a password and take it back to
> what it was.
>
>
>
> On Thu, Jul 7, 2016 at 9:20 AM, Powell, Mark <mark.powell2@hpe.com> wrote=
:
>
> Andy, I will disagree that it is absurd for Oracle to allow a means for a
> 'privileged' user to be able to change another's users password hash
> because without such a method how would an existing user with their
> existing password be migrated to another database?
>
> ________________________________
> From: oracle-l-bounce@freelists.org <oracle-l-bounce@freelists.org> on
> behalf of Andy Klock <andy@oracledepot.com>
> Sent: Thursday, July 7, 2016 9:32:56 AM
> To: Chris Taylor
> Cc: dimensional.dba@comcast.net; Mladen Gogala; oracle-l
> Subject: Re: Passwords in DBA_USERS (Oracle 12c)
>
> All your points are valid Chris.  My absurdity comment is about the Oracl=
e
> software allowing someone to log into someone else's account and then res=
et
> the password back to its previous state. This is a gaping security hole
> that should be filled. Removing PASSWORD from DICTIONARY access was a ste=
p
> in the right direction. Those hashes shouldn't be considered unbreakable.
>
> Didn't meant to imply that the Mladen was doing anything wrong.
>
> On Thu, Jul 7, 2016 at 9:16 AM, Chris Taylor <
> christopherdtaylor1994@gmail.com<mailto:christopherdtaylor1994@gmail.com>=
>
> wrote:
> Having the password "somewhere" is important so I'm not sure if Andy is
> suggesting it's absurd to have it anywhere in the database or not.  But f=
or
> at least one case it's terribly important and that is supporting legacy
> applications.
>
> Sometimes you need to be able to login as an application schema to create
> an object such as a materialized view or database link that is either
> exceptionally difficult or impossible to do UNLESS you are logged in as t=
he
> schema owner.
> The DBA may not have access to the schema password but can preserve the
> password by looking at sys.user$ for the encrypted password, temporarily
> change it, create the object (db link or MV), then change the password ba=
ck
> without ever affecting the application (or briefly affecting the
> application at least).
>
> Thanks,
> Chris
>
>
> --
> http://www.freelists.org/webpage/oracle-l
>
>
>
>
> --
>
> Andrew W. Kerber
>
> 'If at first you dont succeed, dont take up skydiving.'
>
> Notice of Confidentiality: **This E-mail and any of its attachments may
> contain
> Lincoln National Corporation proprietary information, which is privileged=
,
> confidential,
> or subject to copyright belonging to the Lincoln National Corporation
> family of
> companies. This E-mail is intended solely for the use of the individual o=
r
> entity to
> which it is addressed. If you are not the intended recipient of this
> E-mail, you are
> hereby notified that any dissemination, distribution, copying, or action
> taken in
> relation to the contents of and attachments to this E-mail is strictly
> prohibited
> and may be unlawful. If you have received this E-mail in error, please
> notify the
> sender immediately and permanently delete the original and any copy of
> this E-mail
> and any printout. Thank You.**
>

--94eb2c0308542ac45305370ce81b
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div class=3D"gmail_default" style=3D"font-family:arial,he=
lvetica,sans-serif">It appears the only problem with this approach is the D=
BA doesn&#39;t include this ability automatically.=C2=A0 You still have to =
do the grant to the DBA to allow the connect through - which requires a 3rd=
 account to do the grant as you can&#39;t grant privs to yourself.=C2=A0 It=
 would be great if this was included in the DBA role functionality to conne=
ct through any user.</div><div class=3D"gmail_default" style=3D"font-family=
:arial,helvetica,sans-serif"><br></div><div class=3D"gmail_default" style=
=3D"font-family:arial,helvetica,sans-serif">After setting up the necessary =
grant, it is definitely easier to do it this way but in the middle of an ap=
plication deployment, this method is cumbersome if the setup grants haven&#=
39;t been completed.</div><div class=3D"gmail_default" style=3D"font-family=
:arial,helvetica,sans-serif"><br></div><div class=3D"gmail_default" style=
=3D"font-family:arial,helvetica,sans-serif">Thanks,</div><div class=3D"gmai=
l_default" style=3D"font-family:arial,helvetica,sans-serif">Chris</div><div=
 class=3D"gmail_default" style=3D"font-family:arial,helvetica,sans-serif"><=
br></div></div><div class=3D"gmail_extra"><br><div class=3D"gmail_quote">On=
 Thu, Jul 7, 2016 at 9:44 AM, Deas, Scott <span dir=3D"ltr">&lt;<a href=3D"=
mailto:Scott.Deas@lfg.com" target=3D"_blank">Scott.Deas@lfg.com</a>&gt;</sp=
an> wrote:<br><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;=
border-left:1px #ccc solid;padding-left:1ex">





<div lang=3D"EN-US" link=3D"blue" vlink=3D"purple">
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,sans-serif;color:#1f497d">But you don=E2=80=99t need to know th=
e user=E2=80=99s password or change it, you just proxy into the account.=C2=
=A0 We=E2=80=99ve been using it successfully here for years.<u></u><u></u><=
/span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,sans-serif;color:#1f497d"><u></u>=C2=A0<u></u></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,sans-serif;color:#1f497d"><a href=3D"http://www.oracle.com/tech=
network/issue-archive/2013/13-mar/o23asktom-1906478.html" target=3D"_blank"=
>http://www.oracle.com/technetwork/issue-archive/2013/13-mar/o23asktom-1906=
478.html</a><u></u><u></u></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,sans-serif;color:#1f497d"><u></u>=C2=A0<u></u></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,sans-serif;color:#1f497d">Thanks,<br>
Scott<u></u><u></u></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,sans-serif;color:#1f497d"><u></u>=C2=A0<u></u></span></p>
<p class=3D"MsoNormal"><b><span style=3D"font-size:11.0pt;font-family:&quot=
;Calibri&quot;,sans-serif">From:</span></b><span style=3D"font-size:11.0pt;=
font-family:&quot;Calibri&quot;,sans-serif"> <a href=3D"mailto:oracle-l-bou=
nce@freelists.org" target=3D"_blank">oracle-l-bounce@freelists.org</a> [mai=
lto:<a href=3D"mailto:oracle-l-bounce@freelists.org" target=3D"_blank">orac=
le-l-bounce@freelists.org</a>]
<b>On Behalf Of </b>Andrew Kerber<br>
<b>Sent:</b> Thursday, July 07, 2016 10:27 AM<br>
<b>To:</b> <a href=3D"mailto:mark.powell2@hpe.com" target=3D"_blank">mark.p=
owell2@hpe.com</a><br>
<b>Cc:</b> Chris Taylor &lt;<a href=3D"mailto:christopherdtaylor1994@gmail.=
com" target=3D"_blank">christopherdtaylor1994@gmail.com</a>&gt;; <a href=3D=
"mailto:andy@oracledepot.com" target=3D"_blank">andy@oracledepot.com</a>; <=
a href=3D"mailto:dimensional.dba@comcast.net" target=3D"_blank">dimensional=
.dba@comcast.net</a>; Mladen Gogala &lt;<a href=3D"mailto:gogala.mladen@gma=
il.com" target=3D"_blank">gogala.mladen@gmail.com</a>&gt;; oracle-l &lt;<a =
href=3D"mailto:oracle-l@freelists.org" target=3D"_blank">oracle-l@freelists=
.org</a>&gt;<br>
<b>Subject:</b> Re: Passwords in DBA_USERS (Oracle 12c)<u></u><u></u></span=
></p>
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
<div>
<p class=3D"MsoNormal">Yes.=C2=A0 Until programmers learn to include functi=
onality that allows passwords to be changed easily on the mid tier, the DBA=
 or designated security personnel must be able to change a password and tak=
e it back to what it was.<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
<div>
<p class=3D"MsoNormal">On Thu, Jul 7, 2016 at 9:20 AM, Powell, Mark &lt;<a =
href=3D"mailto:mark.powell2@hpe.com" target=3D"_blank">mark.powell2@hpe.com=
</a>&gt; wrote:<u></u><u></u></p>
<blockquote style=3D"border:none;border-left:solid #cccccc 1.0pt;padding:0i=
n 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in">
<p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt">Andy, I will disagree=
 that it is absurd for Oracle to allow a means for a &#39;privileged&#39; u=
ser to be able to change another&#39;s users password hash because without =
such a method how would an existing user with their
 existing password be migrated to another database?<br>
<br>
________________________________<br>
From: <a href=3D"mailto:oracle-l-bounce@freelists.org" target=3D"_blank">or=
acle-l-bounce@freelists.org</a> &lt;<a href=3D"mailto:oracle-l-bounce@freel=
ists.org" target=3D"_blank">oracle-l-bounce@freelists.org</a>&gt; on behalf=
 of Andy Klock &lt;<a href=3D"mailto:andy@oracledepot.com" target=3D"_blank=
">andy@oracledepot.com</a>&gt;<br>
Sent: Thursday, July 7, 2016 9:32:56 AM<br>
To: Chris Taylor<br>
Cc: <a href=3D"mailto:dimensional.dba@comcast.net" target=3D"_blank">dimens=
ional.dba@comcast.net</a>; Mladen Gogala; oracle-l<br>
Subject: Re: Passwords in DBA_USERS (Oracle 12c)<br>
<br>
All your points are valid Chris.=C2=A0 My absurdity comment is about the Or=
acle software allowing someone to log into someone else&#39;s account and t=
hen reset the password back to its previous state. This is a gaping securit=
y hole that should be filled. Removing PASSWORD
 from DICTIONARY access was a step in the right direction. Those hashes sho=
uldn&#39;t be considered unbreakable.<br>
<br>
Didn&#39;t meant to imply that the Mladen was doing anything wrong.<br>
<br>
On Thu, Jul 7, 2016 at 9:16 AM, Chris Taylor &lt;<a href=3D"mailto:christop=
herdtaylor1994@gmail.com" target=3D"_blank">christopherdtaylor1994@gmail.co=
m</a>&lt;mailto:<a href=3D"mailto:christopherdtaylor1994@gmail.com" target=
=3D"_blank">christopherdtaylor1994@gmail.com</a>&gt;&gt; wrote:<br>
Having the password &quot;somewhere&quot; is important so I&#39;m not sure =
if Andy is suggesting it&#39;s absurd to have it anywhere in the database o=
r not.=C2=A0 But for at least one case it&#39;s terribly important and that=
 is supporting legacy applications.<br>
<br>
Sometimes you need to be able to login as an application schema to create a=
n object such as a materialized view or database link that is either except=
ionally difficult or impossible to do UNLESS you are logged in as the schem=
a owner.<br>
The DBA may not have access to the schema password but can preserve the pas=
sword by looking at sys.user$ for the encrypted password, temporarily chang=
e it, create the object (db link or MV), then change the password back with=
out ever affecting the application
 (or briefly affecting the application at least).<br>
<br>
Thanks,<br>
Chris<br>
<br>
<br>
--<br>
<a href=3D"http://www.freelists.org/webpage/oracle-l" target=3D"_blank">htt=
p://www.freelists.org/webpage/oracle-l</a><br>
<br>
<u></u><u></u></p>
</blockquote>
</div>
<p class=3D"MsoNormal"><br>
<br clear=3D"all">
<br>
-- <u></u><u></u></p>
<div>
<p class=3D"MsoNormal">Andrew W. Kerber<br>
<br>
&#39;If at first you dont succeed, dont take up skydiving.&#39;<u></u><u></=
u></p>
</div>
</div>
</div>
<p></p>
<p></p>
<p>Notice of Confidentiality: **This E-mail and any of its attachments may =
contain <br>Lincoln National Corporation proprietary information, which is =
privileged, confidential,<br>or subject to copyright belonging to the Linco=
ln National Corporation family of <br>companies. This E-mail is intended so=
lely for the use of the individual or entity to <br>which it is addressed. =
If you are not the intended recipient of this E-mail, you are <br>hereby no=
tified that any dissemination, distribution, copying, or action taken in <b=
r>relation to the contents of and attachments to this E-mail is strictly pr=
ohibited <br>and may be unlawful. If you have received this E-mail in error=
, please notify the <br>sender immediately and permanently delete the origi=
nal and any copy of this E-mail <br>and any printout. Thank You.**</p></div=
>

</blockquote></div><br></div>

--94eb2c0308542ac45305370ce81b--
--
http://www.freelists.org/webpage/oracle-l


