denrepo

OracleSecurity & users

CMU step 6: turn on directory access

Switches the database to Active Directory for global users. In a CDB, run it in each PDB that uses CMU, not in the root: setting it in the root only applies to the root. The commented section covers AD users who connect AS SYSDBA or with another admin privilege: Oracle's 19c guide also requires a 12.2-format password file and REMOTE_LOGIN_PASSWORDFILE = EXCLUSIVE.

Changes data19c

Not yet verified. How scripts are tested

This script changes the database. Check the names and values before you run it.
ora-cmu-params.sql
1-- In a CDB, run this in the PDB, not the root:2-- ALTER SESSION SET CONTAINER = <pdb_name>;3SHOW CON_NAME4SHOW PARAMETER ldap_directory5 6-- Reads the wallet and dsi.ora now. Run it again any time you change either.7ALTER SYSTEM SET LDAP_DIRECTORY_ACCESS = 'PASSWORD' SCOPE = BOTH;8 9-- Optional: AD users who connect AS SYSDBA, SYSOPER, SYSBACKUP and so on.10-- With CMU_WALLET (step 5) these logins only work while the database is open,11-- so keep a local SYSDBA login for startup and recovery.12--13-- a) Password file in 12.2 format. At the OS prompt (path from srvctl config14--    database on RAC); new 19c databases usually have it already:15--      orapwd describe file=$ORACLE_HOME/dbs/orapw<ORACLE_SID>16--    If it's older, migrate it, keeping existing entries:17--      orapwd file=$ORACLE_HOME/dbs/orapw<ORACLE_SID>.new input_file=$ORACLE_HOME/dbs/orapw<ORACLE_SID> format=12.218--19-- b) In the PDB:20-- ALTER SYSTEM SET LDAP_DIRECTORY_SYSAUTH = YES SCOPE = SPFILE;21--22-- c) In the CDB root (usually already EXCLUSIVE; check with SHOW PARAMETER):23-- ALTER SYSTEM SET REMOTE_LOGIN_PASSWORDFILE = EXCLUSIVE SCOPE = SPFILE;24--25-- d) Restart the instance (srvctl on RAC). Grant the admin privilege itself in step 7.26 27SHOW PARAMETER ldap_directory

Save it as ora-cmu-params.sql and run it with SQL> @ora-cmu-params.

Open in denrepo

Helps with

Part of these runbooks

More Oracle scripts: Security & users