OracleSecurity & users
CMU step 3: create the wallet
Builds the auto-login wallet the database reads at login: the service account's user name, DN and password, plus the AD root certificate. With PDBs, give each PDB a folder and point the PDB at it with CMU_WALLET in step 5. PDBs that use the same AD can share one folder. On RAC, the folder must exist on every node, or be on shared storage.
Not yet verified. How scripts are tested
1# On the database server as the oracle software owner.2 3# 1. Pick the wallet folder. With PDBs, use one folder per PDB (or one shared by4# PDBs on the same AD) and point the PDB at it with CMU_WALLET in step 5.5# On 19c, CMU_WALLET needs the CMU patch 31404487. Check it's applied:6$ORACLE_HOME/OPatch/opatch lspatches | grep 314044877# If it isn't listed, check My Oracle Support Doc ID 2462012.1 for your RU.8 9WALLET=/u01/app/oracle/cmu/<pdb_name>/wallet10 11# Without CMU_WALLET, the database uses sqlnet.ora's WALLET_LOCATION12# (plus /<pdb_guid> for a PDB) or, if that isn't set, the default:13# PDB: $ORACLE_BASE/admin/<db_unique_name>/<pdb_guid>/wallet14# non-CDB or root: $ORACLE_BASE/admin/<db_unique_name>/wallet15# (SELECT pdb_name, guid FROM dba_pdbs; from the root gives the GUID.)16 17mkdir -p $WALLET18 19# 2. Auto-login wallet. Prompts for a new wallet password: keep it in your vault.20orapki wallet create -wallet $WALLET -auto_login21 22# 3. The service account from step 1. Each command asks for the wallet password.23mkstore -wrl $WALLET -createEntry ORACLE.SECURITY.USERNAME oracle_cmu24mkstore -wrl $WALLET -createEntry ORACLE.SECURITY.DN "CN=oracle_cmu,OU=Service Accounts,DC=corp,DC=example,DC=com"25# No value on the next line: mkstore prompts for the service account password,26# which keeps it out of your shell history.27mkstore -wrl $WALLET -createEntry ORACLE.SECURITY.PASSWORD28 29# 4. Trust the AD root certificate from step 2 (add an intermediate CA the same way).30orapki wallet add -wallet $WALLET -cert /tmp/ad_root_ca.txt -trusted_cert31chmod 600 $WALLET/*32 33# 5. Check: three ORACLE.SECURITY entries, and your CA under Trusted Certificates.34orapki wallet display -wallet $WALLET35 36# 6. Check this server trusts the DC's LDAPS certificate.37# Expect: Verify return code: 0 (ok)38openssl s_client -connect <dc1.corp.example.com>:636 -CAfile /tmp/ad_root_ca.txt </dev/null 2>/dev/null | grep "Verify return code"Run these at the operating system prompt.
Helps with
Part of these runbooks
More Oracle scripts: Security & users
- Accounts locked, expired or expiring soonApplication accounts that aren't OPEN, or whose passwords expire in the next 14 days. Catch service accounts before they break an application.
- Who has DBA, SYSDBA and powerful system privilegesNon-Oracle accounts and roles holding the DBA role or high-risk ANY privileges, then everyone in the password file. Worth reviewing every audit cycle.
- CMU step 1: prepare Active DirectoryDone once by an AD administrator before any database work: create the service account the database binds with, install Oracle's password filter on…
- CMU step 2: export the AD root certificateThe database talks to AD over LDAPS, so its wallet must trust the certificate authority that issued the domain controllers' certificates. Export that…
- CMU step 4: create dsi.oraTells the database which domain controllers to use. Put it in the same folder as the wallet from step 3. Use fully qualified host names, and list at…
- CMU step 5: point each PDB at its wallet (CMU_WALLET)Creates a directory object for the wallet folder from step 3 and sets the CMU_WALLET database property in the PDB, so CMU reads that PDB's wallet and…