標籤:資料庫安全 oracle 管理員 密碼 作業系統
一、Oracle身份認證方法
Oracle身分識別驗證主要有如下幾種方式:
-
作業系統認證
-
口令檔案認證
-
資料庫密碼認證
-
外部身分識別驗證
-
網路身分識別驗證
其中,作業系統認證和口令檔案針對管理員賬戶;外部身分識別驗證類似於作業系統認證。
1、作業系統認證
作業系統使用者添加到DBA組之後,可以直接用connect / as sysdba串連。如:
[[email protected] ~]# useradd scott[[email protected] ~]# su scott[[email protected] ~]$ export ORACLE_SID=orcl[[email protected] ~]$ export ORACLE_BASE=/app/oracle[[email protected] ~]$ export ORACLE_HOME=$ORACLE_BASE/product/11.2.0/db_1[[email protected] ~]$ export PATH=$PATH:$ORACLE_HOME/bin[[email protected] ~]$ export LANG=en_US.UTF-8[[email protected] ~]$ alias sqlplus=‘rlwrap sqlplus‘;[[email protected] ~]$ alias rman=‘rlwrap rman‘;[[email protected] ~]$ sqlplus /nolog
SQL> conn /as sysdbaERROR:ORA-01031: insufficient privileges
#另一視窗中執行
[[email protected] ~]# usermod -a -G dba scott[[email protected] ~]# grep scott /etc/groupdba:x:500:oracle,scott
#此時再執行
SQL> conn /as sysdbaConnected.
是否啟用作業系統驗證,由sqlnet.ora中的SQLNET.AUTHENTICATION_SERVICES參數控制,它具有如下三個值:
當sqlnet.authentication_services=none時,只能使用密碼串連。
SQL> conn /as sysdbaERROR:ORA-01031: insufficient privilegesSQL> conn sys/asd as sysdbaConnected.
當sqlnet.authentication_services=all時,允許作業系統認證。
SQL> conn /as sysdbaConnected.
sqlnet.authentication_services=nts時,linux系統下不能使用作業系統認證。
2、口令檔案的管理
[讀書筆記]密碼檔案總結。
3、資料庫密碼認證
簡而言之就是:conn user/[email protected]服務名
4、外部身分識別驗證
建立使用者時使用externally參數。
5、網路身分識別驗證
一個用於管理身份的新興標準時使用 LDAP 伺服器。Oracle Internet Directory(OID) 就是 Oracle 符合 LDAP 標準的一個產品,全域使用者就是在 LDAP 目錄中定義的使用者。[暫時還未接觸到,目前可以忽略,建立使用者時使用globally參數]
二、使用者管理
2.1建立使用者
create user user_name
[identified by password |externally| globally] #資料庫認證方式,資料庫認證、作業系統認證
[default collation collation_name]#很少用到
[default tablespace tablespace_name]
[[locla] temporary tablespace tablespace_name|tablespace group name]
[quota size_clause|unlimited on tablespace_name]
[profile profile_name] #概要檔案,只做瞭解,oracle建議使用 Database Resource Manager
[password expire]#密碼立即失效
[account lock|unlock]
[enable editions]#應該是版本控制
[container=current|all]#CDB和PDB中使用
2.2修改使用者
alter user 開頭,後面的語句基本與create user相同。
2.3 刪除使用者
DROP USER user_name [ CASCADE ] ;
2.4 許可權管理
oracle許可權的分配與回收
1)許可權分配官方文檔:
http://docs.oracle.com/cd/E11882_01/server.112/e41084/statements_9013.htm#SQLRF01603
2)許可權回收官方文檔:
http://docs.oracle.com/cd/E11882_01/server.112/e41084/statements_9020.htm#SQLRF01609
三、角色管理
3.1 角色的建立
create role role_name;
3.2 許可權分配
grant role to user/role;
3.3 角色刪除
drop role;
3.4 系統預定義的角色
connect:11.2中只有create session 的許可權;
resource:具有建立資料對象和過程對象的許可權,還包括unlimited tablespace的許可權;
dba:處了啟動和關閉資料庫外幾乎所有許可權
select_catalog_role:只有查看資料字典的許可權,但沒有系統許可權或針對使用者資料的許可權。
scheduler_admin:擁有用於管理調度服務的發送器作業所需的系統許可權。
四、設定檔
ORACLE 設定檔
五、審計
【讀書筆記】Database Audit
本文出自 “三國冷笑話” 部落格,請務必保留此出處http://myhwj.blog.51cto.com/9763975/1888728
資料庫安全管理