OracleSecurity & users
CMU step 6: turn on directory access
Switches the database to Active Directory for global users. In a CDB, run it in each PDB that uses CMU, not in the root: setting it in the root only applies to the root. The commented section covers AD users who connect AS SYSDBA or with another admin privilege: Oracle's 19c guide also requires a 12.2-format password file and REMOTE_LOGIN_PASSWORDFILE = EXCLUSIVE.
Not yet verified. How scripts are tested
1-- In a CDB, run this in the PDB, not the root:2-- ALTER SESSION SET CONTAINER = <pdb_name>;3SHOW CON_NAME4SHOW PARAMETER ldap_directory5 6-- Reads the wallet and dsi.ora now. Run it again any time you change either.7ALTER SYSTEM SET LDAP_DIRECTORY_ACCESS = 'PASSWORD' SCOPE = BOTH;8 9-- Optional: AD users who connect AS SYSDBA, SYSOPER, SYSBACKUP and so on.10-- With CMU_WALLET (step 5) these logins only work while the database is open,11-- so keep a local SYSDBA login for startup and recovery.12--13-- a) Password file in 12.2 format. At the OS prompt (path from srvctl config14-- database on RAC); new 19c databases usually have it already:15-- orapwd describe file=$ORACLE_HOME/dbs/orapw<ORACLE_SID>16-- If it's older, migrate it, keeping existing entries:17-- orapwd file=$ORACLE_HOME/dbs/orapw<ORACLE_SID>.new input_file=$ORACLE_HOME/dbs/orapw<ORACLE_SID> format=12.218--19-- b) In the PDB:20-- ALTER SYSTEM SET LDAP_DIRECTORY_SYSAUTH = YES SCOPE = SPFILE;21--22-- c) In the CDB root (usually already EXCLUSIVE; check with SHOW PARAMETER):23-- ALTER SYSTEM SET REMOTE_LOGIN_PASSWORDFILE = EXCLUSIVE SCOPE = SPFILE;24--25-- d) Restart the instance (srvctl on RAC). Grant the admin privilege itself in step 7.26 27SHOW PARAMETER ldap_directorySave it as ora-cmu-params.sql and run it with SQL> @ora-cmu-params.
Helps with
Part of these runbooks
More Oracle scripts: Security & users
- Accounts locked, expired or expiring soonApplication accounts that aren't OPEN, or whose passwords expire in the next 14 days. Catch service accounts before they break an application.
- Who has DBA, SYSDBA and powerful system privilegesNon-Oracle accounts and roles holding the DBA role or high-risk ANY privileges, then everyone in the password file. Worth reviewing every audit cycle.
- CMU step 1: prepare Active DirectoryDone once by an AD administrator before any database work: create the service account the database binds with, install Oracle's password filter on…
- CMU step 2: export the AD root certificateThe database talks to AD over LDAPS, so its wallet must trust the certificate authority that issued the domain controllers' certificates. Export that…
- CMU step 3: create the walletBuilds the auto-login wallet the database reads at login: the service account's user name, DN and password, plus the AD root certificate. With PDBs,…
- CMU step 4: create dsi.oraTells the database which domain controllers to use. Put it in the same folder as the wallet from step 3. Use fully qualified host names, and list at…