OracleSecurity & users
CMU step 5: point each PDB at its wallet (CMU_WALLET)
Creates a directory object for the wallet folder from step 3 and sets the CMU_WALLET database property in the PDB, so CMU reads that PDB's wallet and dsi.ora from there. Run it in every PDB that uses CMU. On 19c it needs the CMU patch 31404487. One catch: because the directory object lives inside the database, AD users can't log in AS SYSDBA to start a database that's down; keep a local SYSDBA login for that.
Not yet verified. How scripts are tested
1-- In each PDB that uses CMU (not the root):2ALTER SESSION SET CONTAINER = <pdb_name>;3 4-- The folder from step 3. PDBs on the same AD can point at one shared folder.5CREATE OR REPLACE DIRECTORY cmu_wallet_dir AS '/u01/app/oracle/cmu/<pdb_name>/wallet';6 7-- The property takes the directory object's name in upper case.8ALTER DATABASE PROPERTY SET CMU_WALLET = 'CMU_WALLET_DIR';9 10-- If the PDB was created with PATH_PREFIX, use a path relative to it instead:11-- CREATE OR REPLACE DIRECTORY cmu_wallet_dir AS 'cmu/wallet';12 13-- Check: the property and the folder it points at14SELECT p.property_value AS cmu_wallet, d.directory_path15FROM database_properties p16LEFT JOIN dba_directories d ON d.directory_name = p.property_value17WHERE p.property_name = 'CMU_WALLET';Save it as ora-cmu-wallet-prop.sql and run it with SQL> @ora-cmu-wallet-prop.
Helps with
Part of these runbooks
More Oracle scripts: Security & users
- Accounts locked, expired or expiring soonApplication accounts that aren't OPEN, or whose passwords expire in the next 14 days. Catch service accounts before they break an application.
- Who has DBA, SYSDBA and powerful system privilegesNon-Oracle accounts and roles holding the DBA role or high-risk ANY privileges, then everyone in the password file. Worth reviewing every audit cycle.
- CMU step 1: prepare Active DirectoryDone once by an AD administrator before any database work: create the service account the database binds with, install Oracle's password filter on…
- CMU step 2: export the AD root certificateThe database talks to AD over LDAPS, so its wallet must trust the certificate authority that issued the domain controllers' certificates. Export that…
- CMU step 3: create the walletBuilds the auto-login wallet the database reads at login: the service account's user name, DN and password, plus the AD root certificate. With PDBs,…
- CMU step 4: create dsi.oraTells the database which domain controllers to use. Put it in the same folder as the wallet from step 3. Use fully qualified host names, and list at…