denrepo

OracleSecurity & users

CMU step 3: create the wallet

Builds the auto-login wallet the database reads at login: the service account's user name, DN and password, plus the AD root certificate. With PDBs, give each PDB a folder and point the PDB at it with CMU_WALLET in step 5. PDBs that use the same AD can share one folder. On RAC, the folder must exist on every node, or be on shared storage.

Changes data19cOS prompt

Not yet verified. How scripts are tested

This changes files or settings on the server. Check the names and values before you run it.
ora-cmu-wallet.sh
1# On the database server as the oracle software owner.2 3# 1. Pick the wallet folder. With PDBs, use one folder per PDB (or one shared by4#    PDBs on the same AD) and point the PDB at it with CMU_WALLET in step 5.5#    On 19c, CMU_WALLET needs the CMU patch 31404487. Check it's applied:6$ORACLE_HOME/OPatch/opatch lspatches | grep 314044877#    If it isn't listed, check My Oracle Support Doc ID 2462012.1 for your RU.8 9WALLET=/u01/app/oracle/cmu/<pdb_name>/wallet10 11#    Without CMU_WALLET, the database uses sqlnet.ora's WALLET_LOCATION12#    (plus /<pdb_guid> for a PDB) or, if that isn't set, the default:13#      PDB:              $ORACLE_BASE/admin/<db_unique_name>/<pdb_guid>/wallet14#      non-CDB or root:  $ORACLE_BASE/admin/<db_unique_name>/wallet15#    (SELECT pdb_name, guid FROM dba_pdbs; from the root gives the GUID.)16 17mkdir -p $WALLET18 19# 2. Auto-login wallet. Prompts for a new wallet password: keep it in your vault.20orapki wallet create -wallet $WALLET -auto_login21 22# 3. The service account from step 1. Each command asks for the wallet password.23mkstore -wrl $WALLET -createEntry ORACLE.SECURITY.USERNAME oracle_cmu24mkstore -wrl $WALLET -createEntry ORACLE.SECURITY.DN "CN=oracle_cmu,OU=Service Accounts,DC=corp,DC=example,DC=com"25#    No value on the next line: mkstore prompts for the service account password,26#    which keeps it out of your shell history.27mkstore -wrl $WALLET -createEntry ORACLE.SECURITY.PASSWORD28 29# 4. Trust the AD root certificate from step 2 (add an intermediate CA the same way).30orapki wallet add -wallet $WALLET -cert /tmp/ad_root_ca.txt -trusted_cert31chmod 600 $WALLET/*32 33# 5. Check: three ORACLE.SECURITY entries, and your CA under Trusted Certificates.34orapki wallet display -wallet $WALLET35 36# 6. Check this server trusts the DC's LDAPS certificate.37#    Expect: Verify return code: 0 (ok)38openssl s_client -connect <dc1.corp.example.com>:636 -CAfile /tmp/ad_root_ca.txt </dev/null 2>/dev/null | grep "Verify return code"

Run these at the operating system prompt.

Open in denrepo

Helps with

Part of these runbooks

More Oracle scripts: Security & users