1753902 Members
9557 Online
108810 Solutions
New Discussion юеВ

Oracle/Security

 
Dwyane Everts_1
Honored Contributor

Oracle/Security

All,

Let me begin this thread by qualifying...this thread pertains to OS security and network security; hence, I placed it under "HP-UX General."

I'm looking for your experiences with Oracle 9i RAC (DB) and 11ias (apps). We are new to Oracle, and I'm trying to install this software as securely as possible. Problem is, Oracle seems to require access to "r-commands" (rcp, remsh, etc.) and NFS to run properly. I would prefer to use scp and ssh, and eliminate NFS. These are obviously unsecure services.

I know this is not an easy question to answer due to limited forum space, but I'm looking for your experiences and possibly a "best practices" approach.

How can Oracle call itself "unbreakable" when it requires such backend services to be running?

Thanks in advance....
Dwyane
4 REPLIES 4
Sanjay_6
Honored Contributor

Re: Oracle/Security

Hi,

I'm not sure about this, but i have not seen any oracle requirement saying that rcp/remsh must be allowed. Also NFS server is not a prerequisite. It is required if you want to mount the oracle installation CD using pfs_mount. There is a workaround for pfs_mount (you can use the regulat mount command / need some patches for rock-ridge support)

Most of our system running oracle databases have "r" commands disabled and no NFS enabled. We enable NFS client on as and when basis.

Hope this helps.

Regds
Dwyane Everts_1
Honored Contributor

Re: Oracle/Security

Sanjay,

Perhaps that explains the NFS requirement. We are currently installing the software. And when the installs are complete, maybe we can go back and turn things off.

Dwyane
Sanjay_6
Honored Contributor

Re: Oracle/Security

hi,

For future purpose, add these patches to your system for mount command to support rock-ridge extention,

for 11.11

1.) PHCO_25841 -> s700_800 11.11 Add Rock Ridge extension to mount_cdfs(1M)
2.) PHKL_26269 -> s700_800 11.11 Rock Ridge extension for ISO-9660
3.) PHKL_32035 -> s700_800 11.11 Rock Ridge extension for ISO-9660

Here is a product from hp to secure / lockdown your system from security point of view,

http://software.hp.com/portal/swdepot/displayProductInfo.do?productNumber=B6849AA

hope this helps.

regds
Steven E. Protter
Exalted Contributor

Re: Oracle/Security

Oracle does not require access to the r protocols. The intructions say to use pfs_mount which is outdated and causes all kinds of errors, including the conlusion that nfs and r protocols need to be sued.

You need X to install these products.

I'm attaching a cd mount script that works for oracle that will eliminate the need for pfs_mount.

It works for all oracle Rock ridge cd's.

SEP
Steven E Protter
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com