OracleSecurity & users
CMU step 2: export the AD root certificate
The database talks to AD over LDAPS, so its wallet must trust the certificate authority that issued the domain controllers' certificates. Export that root CA certificate in Base-64 and copy it to the database server. If an intermediate CA issued the DC certificates, export that one too.
Not yet verified. How scripts are tested
1# On a Windows machine that can reach the enterprise CA (often a DC), in PowerShell2# or a command prompt. If your PKI team runs the CA, ask them for the root CA3# certificate in Base-64 (.cer) instead.4 5# 1. Export the CA certificate (binary DER)6certutil -ca.cert C:\temp\ad_root_ca.cer7 8# 2. Convert it to Base-64 for orapki9certutil -encode C:\temp\ad_root_ca.cer C:\temp\ad_root_ca.txt10 11# 3. Check it's the right one: the Subject should be your root CA's name12certutil -dump C:\temp\ad_root_ca.txt13 14# 4. Copy ad_root_ca.txt to the database server, for example to /tmp (sftp or WinSCP).Run these on a Windows domain controller.
Part of these runbooks
More Oracle scripts: Security & users
- Accounts locked, expired or expiring soonApplication accounts that aren't OPEN, or whose passwords expire in the next 14 days. Catch service accounts before they break an application.
- Who has DBA, SYSDBA and powerful system privilegesNon-Oracle accounts and roles holding the DBA role or high-risk ANY privileges, then everyone in the password file. Worth reviewing every audit cycle.
- CMU step 1: prepare Active DirectoryDone once by an AD administrator before any database work: create the service account the database binds with, install Oracle's password filter on…
- CMU step 3: create the walletBuilds the auto-login wallet the database reads at login: the service account's user name, DN and password, plus the AD root certificate. With PDBs,…
- CMU step 4: create dsi.oraTells the database which domain controllers to use. Put it in the same folder as the wallet from step 3. Use fully qualified host names, and list at…
- CMU step 5: point each PDB at its wallet (CMU_WALLET)Creates a directory object for the wallet folder from step 3 and sets the CMU_WALLET database property in the PDB, so CMU reads that PDB's wallet and…