Posts

How to Secure our Oracle Databases

How Secure can we make our Oracle Databases?? This is a routine question that runs in minds of most database administrators.   HOW SECURE ARE OUR DATABASES. CAN WE MAKE IT ANYMORE SECURE . I am writing this post to share my experience and knowledge on securing databases. I personally follow below tips to secure my databases:  1. Make sure we only grant access to those users that really need to access database. 2. Remove all the unnecessary grants/privileges from users/roles. 3. Frequently audit database users Failed Logins in order to verify who is trying to login and their actions. 4. If a user is requesting elevated privileges, make sure you talk to them and understand their requirements. 5. Grant no more access than what needed. 6. At times users might need access temporarily. Make sure these temporary access are revoked after tasks are completed. 7. Define a fine boundary on who can access what?? 8. Use User profiles / Audit to ensure all activities are tracked. 9....

java.lang.SecurityException: The jurisdiction policy files are not signed by a trusted signer

I was trying to Install OID (Oracle Identity Manager) and I got this error : Problem:         at oracle.as.install.engine.modules.configuration.standard.StandardConfigActionManager.start(StandardConfigActionManager.java:186)         at oracle.as.install.engine.modules.configuration.boot.ConfigurationExtension.kickstart(ConfigurationExtension.java:81)         at oracle.as.install.engine.modules.configuration.ConfigurationModule.run(ConfigurationModule.java:86)         at java.lang.Thread.run(Thread.java:745) Caused by: java.lang.SecurityException: Can not initialize cryptographic mechanism         at javax.crypto.JceSecurity.<clinit>(JceSecurity.java:88)         ... 31 more Caused by: java.lang.SecurityException: The jurisdiction policy files are not signed by a trusted sig...

bash: /bin/install/.oui: No such file or directory

 Problem: [oracle@linux5 database]$ . runInstaller bash: /bin/install/.oui: No such file or directory [oracle@linux5 database]$ uname -a Linux linux5 3.8.13-16.2.1.el6uek.x86_64 #1 SMP Thu Nov 7 17:01:44 PST 2013 x86_64 x86_64 x86_64 GNU/Linux Solution: [oracle@linux5 database]$ ./runInstaller Starting Oracle Universal Installer... Checking Temp space: must be greater than 120 MB.   Actual 20461 MB    Passed Checking swap space: must be greater than 150 MB.   Actual 4031 MB    Passed Checking monitor: must be configured to display at least 256 colors.    Actual 16777216    Passed Preparing to launch Oracle Universal Installer from /tmp/OraInstall2016-11-22_09-46-02AM. Please wait ...[oracle@linux5 database]$

uninstall java on linux

If you are not sure of what the dependent packages that might be blocking java then you can also use yum remove jdk* This will also take care of dependent rpms . [root@linux06 usr]# yum remove jdk1.8.0_111-1.8.0_111-fcs.i586 Loaded plugins: refresh-packagekit, security Setting up Remove Process Resolving Dependencies --> Running transaction check ---> Package jdk1.8.0_111.i586 2000:1.8.0_111-fcs will be erased --> Processing Dependency: java for package: jna-3.2.4-2.el6.x86_64 --> Running transaction check ---> Package jna.x86_64 0:3.2.4-2.el6 will be erased --> Finished Dependency Resolution Dependencies Resolved ======================================================================================================================  Package           Arch        Version                 Repository ...

Is it safe to move/recreate alertlog while the database is up and running

 Is it safe to move/recreate alertlog while the database is up and running?? It is totally safe to "mv" or rename it while we are running. Since chopping part of it out would be lengthly process, there is a good chance we would write to it while you are editing it so I would not advise trying to "chop" part off -- just mv the whole thing and we'll start anew in another file. If you want to keep the last N lines "online", after you mv the file, tail the last 100 lines to "alert_also.log" or something before you archive off the rest. [oracle@Linux03 trace]$ ls -ll alert_* -rw-r-----. 1 oracle oracle    488012 Nov 14 10:23 alert_orcl.log I will rename the existing alertlog file to something   [oracle@Linux03 trace]$ mv alert_orcl.log alert_orcl_Pre_14Nov2016.log [oracle@Linux03 trace]$ ls -ll alert_* -rw-r-----. 1 oracle oracle 488012 Nov 14 15:42 alert_orcl_Pre_14Nov2016.log [oracle@Linux03 trace]$ ls -ll alert_* Now lets create some activity ...

Directory permissions granted to a user in database

Querying directory permissions granted to a user SELECT grantee, table_name directory_name, LISTAGG(privilege, ',') WITHIN GROUP (ORDER BY grantee)   FROM dba_tab_privs  WHERE table_name =' DPUMP' group by GRANTEE,TABLE_NAME; SAMPLE output: GRANTEE              DIRECTORY_NAME                 GRANTS             -------------------- ------------------------------ -------------------- SCOTT                  DPUMP                       READ,WRITE          TIGER              ...

Failed to auto-stop Oracle Net Listener using ORACLE_HOME/bin/tnslsnr

Usage : we can use dbshut script file in $ORACLE_HOME/bin to shutdown  database & listener.  [oracle@Linux03 bin]$ ps -ef|grep pmon oracle   20693     1  0 10:57 ?        00:00:00 ora_pmon_ orcl oracle   21133 19211  0 11:01 pts/0    00:00:00 grep pmon [oracle@Linux03 bin]$ dbshut Processing Database instance "orcl": log file /u01/app/oracle/product/12.1.0.2/db_1/shutdown.log [oracle@Linux03 bin]$ ps -ef|grep pmon oracle   21287 19211  0 11:09 pts/0    00:00:00 grep pmon [oracle@Linux03 bin]$ Error : Failed to auto-stop Oracle Net Listener using ORACLE_HOME/bin/tnslsnr [oracle@Linux03 bin]$ dbshut Failed to auto-stop Oracle Net Listener using ORACLE_HOME/bin/tnslsnr  Solution (same as above): edit dbshut script and change From : ORACLE_HOME_LISTNER=$1   To : ORACLE_HOME_LISTNER=$ORACLE_HOME Note :   One pre-req for this script...