DBMS_LDAP with encrypted passwords (SHA)

Guys,

We have a Server LDAP (Sun) that holds our passwords in an encrypted format (SHA).

DBMS_LDAP can be used to authenticate through clear text of the Nations Unies/PW to the LDAP server that encrypted passwords?

Any help with this really appreciated.

Thanks in advance.

Hello

Yes absolutely, if you try to authenticate with the password in clear text, the LDAP server's hash and compare it with the stored value (if you think about it, it's the only way that you can really work if it worked if you spent in the password hashed out the place that would be a huge vulnerability for all who knew the value hashed - that is, they could authenticate without knowing the original password).

John.
--------------------------------------------
Blog: http://jes.blogs.shellprompt.net
Work: http://www.apex-evangelists.com
Author of Pro Application Express: http://tinyurl.com/3gu7cd
AWARDS: Don't forget to mark correct or useful posts on the forum, not only for my answers, but for everyone!

Tags: Database

Similar Questions

  • call sqlldr with encrypted password

    Hello

    I was wondering if there is a way to open a sql * session of the charger from the command line without the password hardcoded.

    It's basically a scenario where a script should trigger the sqlldr session directly after that it writes the file to disk.

    PS external tables are not an option unfortunately.

    Thank you!

    Hi Rustydud

    A simple solution is to set up a user identified externally (see [CREATE USER... IDENTIFIED externally|file:///C:/oradocs/B19306_01/server.102/b14200/statements_8003.htm#i2065278], then give this user INSERT privilege on the table. Then only, your script must contain:

    sqlldr / file =...

    Another approach is to store your password in a protected file (for example ~/.dbpasswd), and then to direct in the sqlldr command (works on * nix; typed memory so excuse all vomiting):

    dbpasswd=`cat ~/.dbpasswd`
    sqlldr file=x log=y <
    

    (The .dbpasswd file must have 400 permissions so that only you can read it, even better, put in a single directory that you can read).

    STILL, the document (between ps.) (Some utilities clean their own lines of command to remove the user/user name parameter, so it may be not necessary these days).

    If you are really paranoid, you can store an encrypted password and decrypt when you assign it to $dbpasswd. But if you can decipher, everyone can so who knows the mechanism to decrypt...

    Hope that helps

    Nigel cordially

  • Why can't encrypt a PDF document with a password? The options are visible in Adobe Acrobat Pro XI, but disabled so I can't use them

    Why can't encrypt a PDF document with a password? The options are visible in Adobe Acrobat Pro XI, but disabled so I can't use them

    It was because my document is open read-only. When I corrected that I could apply the password.

  • What is the difference between "Normal password" vs "Encrypted password" in connection SSL/TSL?

    I thought that SSL/TSL implies a secure connection.
    What it means to use "Normal password" vs "Encrypted password" in "Authentication method" when you use "connection security: SSL/TSL. One of the servers I use only accepts "Normal password", however, Thunderbird does not have the warning "server does not use encryption.

    Use of SSL or TLS means that your login and password, at least, are encrypted. There is no need to manually select the encryption.

    As said, some service providers Internet supported the option of password encrypted in itself; When they care to do it correctly, they offer TLS/SSL. Passwords encrypted, when used, are usually offered instead of SSL or TLS. I think a weakness is that only the password is encrypted, so only with SSL/TLS, your username, your password and potentially all of your message is encrypted.

    https://en.Wikipedia.org/wiki/Transport_Layer_Security

    The key is that you can use to offer the provider ISP or mail. If they offer encryption, use it; If they do not, seek a better supplier. The server configuration governs what settings and options are in use. You cannot choose to use a feature that has not been enabled on the server of its operators.

  • iTunes backup encrypted - password forgotten

    I started to do encrypted backups from my iPhone to my computer in iTunes, but I forgot the password.

    I don't want to erase my phone completely and start all over again.

    Is it possible to "throw" the current encrypted backup and start an encrypted backup 'new' with a password that I won't lose this time?

    I don't want to just save the backup to that one costed upwards I can never access.

    Thanks, Flyguy

    (PS - Yes, setting a password and then do not store a safe place is a really stupid thing to do)

    If you are lucky to have the password in the keychain, then proceed as follows. http://osxdaily.com/2013/06/26/recover-lost-encrypted-backup-password-iOS/

  • Authentication Radius Cisco with Windows NAP with encrypted authentication

    I need authentication radius configuration for Cisco IOS devices for device management. My radius server is on Windows 2008 R2.

    Can I implement this with encrypted authentication? In the attached diagram, can what protocol I use for encrypted authentication?

    According to some sites, we need activate authentication in clear text. All those put in place secure as MSCHAP authentication?

    Hello

    You activate the text authentication (PAP) clear. Don't forget Ray sends the username in clear but encrypts the password. You can confirm this take a wireshark capture. You will also get the RADIUS encryption using a key to Ray long and complex.

    If you want to encrypt the user name and password, then you would use GANYMEDE

    Thank you

    John

  • Cannot get 12.4SE to use the encrypted password for ODBC

    Hello

    We run gendata/genprint on the Linux platform and move from 11.5 to 12.4SE. The MRL is in a database of DB2 installed on MVS (and connect via ODBC). We installed the 12.4SE on the server, the engines and copied the entire folder structure, including our ISP * files, our installation of 11.5 - didn't change at all. If I run the motors with an unencrypted password, it works fine. The problem I'm running is when I run with a password encrypted in the ODBC DBHandler (that is what we have in our configuration 11.5), I get a lot of mistakes (the first letter is actually absent from these messages, I'm not myself truncating):

    Error in main(): unable to RunGenData(). See the errors file for more messages.

    Warning in RPDefDisplayProc(): display user procedure has not been defined.

    arningCountSIFileNamecratch/home/dmkr/documaker/rel124/rps100/rplib/unix /... /c/rperr.cSILineNumber099

    rrorCountSIFileNamecratch/home/dmkr/documaker/rel124/rps100/rplib/unix /... /c/rperr.cSILineNumber115

    lapsedTimeSIFileNamecratch/home/dmkr/documaker/rel124/rps100/rplib/unix /... /c/rperr.cSILineNumber193

    enData Completed-

    When I go to the ERRFILE.dat, I see:

    Transaction error report - system timestamp: Mon oct 19 12:36:33 2015
    DM12041: Error: error library FAP: Transaction: <>, area: ODBC error >
    Code1: <-30082 >, code2: < 4294937214 >
    message: 08001-30082 [unixODBC] [IBM] [CLI driver] security SQL30082N treatment failed with reason "3' ("PASSWORD MISSING").  SQLSTATE = 08001 >.
    DM12041: Error: error library FAP: Transaction: <>, area: < LBYInitializeLoaders() >
    Code1: < 0 >, code2: < 0 >
    message: failed to initialize the library < FJ§ > >.
    DM15066: Error RunGenData: could not LBYInitializeLoaders().   The system is configured to use the library, but the library could not be initialized.  Verify that the library is properly specified in the INI file and is accessible.

    == > Number of warning: 0
    == > Error number: 3

    When I look to the top of DM15066, I see:

    Explanation
    The call to LBYInitializeLoaders failed in function (GenTrn.c, GenData.c or GenPrint/PrintEnv.c). The usual reason that LBYInitializeLoaders do not is that the library is stored in a DBMS (DB2, Oracle or SQL Server) and the DBMS or database in the DBMS is not accessible.

    Programmer's response
    Check that the DBMS or database in the DBMS used by the MRL is running. If this isn't the case, please re - initialize the DBMS or database in the DBMS.

    Anyone has an idea why my installation 12.4SE dislikes the encrypted passwords?

    Thank you

    Gregg

    I hope that I am not striking myself, but I think I have it working now. I started a support ticket about not being not able to get the cryrun utility to work on Linux, and when I hit the stage 2 ("solutions"), one of the proposed solutions talked about this specific question. He explained that specifying a folder deflib allow the utility Cryruw32.exe to place a file 'Omar', and that you then this odek file in your deflib when you try to run the documaker engine. I read the release notes, pointing to the "reference help utilities" for more information, but there is NOTHING in this guide for the Cryrun utility which mentions the file "odek".

    Anywho, I made a generic file deflib, run the utility, FTP'd the file down to the deflib of my application on the Linux server, copied the encrypted password new/different in fsiuser.ini, and voila, it ran!

    For those interested, it was Doc ID 2006951.1

    Thanks for your help.

  • MAXL - Backup Script Essbase for lack of encrypted password

    I went through the steps of...

    1. creation of public/private keys

    2. password encryption

    3. pass these components in the backup script Essbase

    From the kick-off of the EssbaseBackup.bat, it fails to connect with the username password / encrypted.

    If I remove the encrypted password and instead, encode the password, it connects fine and generates the backup file Essbase.

    Anyone of you people seen this behavior before?  All good pointers trying to solve this problem?

    Appreciate any feedback.

    Error.JPG

    It would have been useful to see your script too, but looks like you are missing $key in your statement at the opening session.

    It should be something like:

    login administrator $key 23958236592475923472398969868968756 ON HYPERION;

    I'm assuming you use you're maxl script with the parameter-d and the provision of key private after him.

  • com.sleepycat.db.Database.verify (), does not not with encrypted db. bug?

    Hello

    I have a berkeley database file encrypted with a password (in fact, there are two databases into the same physical file). The version of the api from Berkeley that I use is the 5.3.21:

    Data bases work very well, and I can read all the data (in the two databases)...

    However, if I try to check the database with the method, com.sleepycat.db.Database.verify (), I get the following error...

    Encrypted checksum BDB0196: no encryption key specified
    Page 0 BDB0522: corrupt metadata page
    Encrypted checksum BDB0196: no encryption key specified
    BDB3016 C:\cneDir\env-cipher/inforep.db: pgin failed for page 0

    Even if being databaseConfig with my password in the configuration... This is the code I use:
        private static void doVerify(String args[], String symmetricKey) {
            DatabaseConfig dbConfig;
            VerifyConfig verifyConfig;
            String filename;
            String dbName;
            boolean result;
    
            filename = args[0] + "/" + args[1];
            dbName   = args[2];
    
            dbConfig = new DatabaseConfig();
            dbConfig.setEncrypted(symmetricKey);
            System.out.println("Is encrypted: " + dbConfig.getEncrypted());
            dbConfig.setChecksum(true);
    
            verifyConfig = new VerifyConfig();
            verifyConfig.setNoOrderCheck(false);
    
            try {
                result = Database.verify(filename, dbName, System.out, verifyConfig, dbConfig);
                System.out.println("Everything is OK? " + result);
            } catch (Exception ex) {
                System.out.println("D OH!");
                ex.printStackTrace();
            }
    It forced me to take the source code of the Java APIs to see what happens...
    Atfer looking at the source code of the API, it seems to me that the com.sleepycat.db.Database.verify () method, never sets the password at any time of his execution... So I take the source code and change the method to set my password (hard):
        public static boolean verify(final String fileName,
                                     final String databaseName,
                                     final java.io.PrintStream dumpStream,
                                     VerifyConfig verifyConfig,
                                     DatabaseConfig dbConfig)
            throws DatabaseException, java.io.FileNotFoundException {
    
            final Db db = DatabaseConfig.checkNull(dbConfig).createDatabase(null);
            //db.set_flags(DbConstants.DB_ENCRYPT);
            db.set_encrypt("1234", DbConstants.DB_ENCRYPT_AES);   //Here, 1234 is my password
            return db.verify(fileName, databaseName, dumpStream,
                             VerifyConfig.checkNull(verifyConfig).getFlags());
        }
    Atfer this change, the com.sleepycat.db.Database.verify () method returns true and throws no exceptions. So, I guess this could be a bug, right?

    Hi Carlos,

    This is a bug and the fix will be included in the next release (6.0). Thank you for reporting this issue.

    Kind regards
    -Jin

  • Anyone know how to solve my problem? I can't import my photos from Iphone to computer. Sign says: Photos in the camera cannot be imported because the IPhone is locked with a password or read. My phone is unlocked. I've tried everything

    Anyone know how to solve my problem? I can't import my photos from Iphone to computer. Sign says: Photos in the camera cannot be imported because the IPhone is locked with a password or read. My phone is unlocked. I tried everything, every single idea. Without success! Any other idea?

    For example, you specify that the device does not display the lock screen, correct? Do you use Touch IDS? If so, try to put your finger on the device to see if it's what he wants.

    See you soon,.

    GB

  • Photos in the camera roll on 'iPhone' cannot be imported because the iPhone is locked with a password or read

    6 + put iPhone updated to 10.0.0.2 and now get the error, the pictures on the Filmstrip on "iPhone" cannot be imported because the iPhone is locked with a password or read. You must enter your password on the iPhone to view and import them.

    Working solutions proposed so far. Guess I'll have to wait for the correction of a bug to Apple...

    iPhoto 11 (9.2.3); OS X 10.6.8

    On the alert to "trust this computer" on your iPhone, iPad or iPod touch - Apple Support

    LN

  • "iPhone is disabled, connect to iTunes" AND "iTunes can not connect to the iPhone because it is locked with a password" error message on the phone and the computer! Help!

    So I recently had my password wrong too many times and my iPhone 4S locked out telling me "iPhone is disabled; Connect to iTunes'. And so I connected to iTunes and decided to restore my phone. I finished the process of restoration of the configuration of my phone, but ultimately, it was not even let me in the phone! Once AGAIN he said "iPhone is disabled; " Connect " to iTunes '. However, this time, this message appeared just when I turned on my phone with a black background. I didn't scan the screen for the error message is displayed (and there was no time to be shown). When I tried to connect to iTunes again as he asked, now it says "iTunes can not connect to the iPhone because it is locked with a password".

    So now, he said "iPhone is disabled; ' Connect to iTunes' on my iPhone 4S and ''iTunes can't connect to the iPhone because it is locked with a password ' on my computer. WHAT should I do?

    As described in step 2 of "Erase your device with iTunes" in this article, you will need to use the Recovery Mode.

    Recovery mode is described in this article as well.  You may try to go into recovery mode more than once to succeed.

    If you have forgotten the password for your iPhone, iPad or iPod touch, or your device is disabled - Apple supports

  • I NEED HELP Please im having a problem to forget my password and when I plug it it says its locked with a password he try to put the itunes thing but

    NEED HELP Please im having a problem to forget my password and when I plug it it says its locked with a password he tried to put the itunes thing but it says enter password I put in what I rember, then said lokced for five minutes help me pls

    Without knowing the password for your iPhone, there is no way to unlock it, bring even you to the Genius Bar. If you continue to enter the wrong password, you will be locked out of your iPhone, and your data will be unaccessable.

  • How I find myself with two passwords to iCloud for the same account?

    How I find myself with two passwords to iCloud for the same account?

    For security reasons, I only use iCloud for Contacts and "find my iPhone".

    Several months ago Apple forced me to change my password to iCloud.  So I did this.   In the last months, I used successfully the new password to 10 or 12 times when asked without problem.

    However, I received a notification of a software update for my Apple Watch. I did the update without problem. However, after completing the update my iPhone asked me to connect to my iCloud account. When I did this, she rejected my password. I made 4 attempts typing very slowly and with care for you sure I did it right.

    Then, operating under a hunch, I decided to enter my old password to iCloud. It worked?  I'm confused about this, any ideas would be appreciated.

    I had a similar problem last year. I had to call Apple. Contact is a bottom of this page.

  • MacBook pro locked with a password of the firmware, Help!

    I have a macbook pro, end 2011, which is locked with a password of the firmware, and I do not know. Are their any of you know how powerful hardware hacks, and no one knows a way of hacking the firmware lock? I tried to avoide paying someone to fix my machine and unlock the firmware, then I tried a lot of material tweeks likely to pass the lock of the firmware and unlock my computer. Please help and thanks in advance for all this you find to do it yourself Tech who would rather their firmware password reset themselves. Thank you.

    See this article:

    http://osxdaily.com/2015/01/28/forgot-Mac-firmware-password-what-now/

Maybe you are looking for

  • Is there a compatible adapter for the A40?

    I use a satellite pro A40 (2.6 model GHz DVD-ROM) and my power brick just died. I had a quick glance at the section options and accessories on this site and found that there are no adapters for the A40. Is this true? are there any adapters CA / CC fo

  • My 8.5 table look-up does not work at 8.6.

    Hi, I recently updated my labview 8.5 to 8.6, but my model has a few tables of choice that does not work in the new version, so my model does not work as well. the proporty of choice to the 8.6 table does not include preview and it displays a table i

  • connect laptop to TV with HDMI

    I have a laptop HP Pavilion g7Windows 7 Home Premium 64-bit Service Pack 1Intel (R) Core (TM) i5 - 2450 M CPU @ 2.50 GHzGraphics unit 1:AMD Radeon HD series 7400MGraphics unit 2:Intel(r) HD Graphics 3000All the pilot has been updated weekenden -.My p

  • I'm unable to receive e-mails with my my sisters UK free-serve account Hotmail account.

    My sister's in the United Kingdom uses freeserve.   For a month, I was unable to get her e-mail, but she gets mines.   Why is Hotmail blocking that server and when are they going to fix the problem? original title: Hotmail emails from freeserve

  • HP Officejet Pro 8610: IMPOSSIBLE to PRINT GMAIL WITH NEWLY INSTALLED HP OFFICEJET PRO 8610 wireless

    All documents from my computer of fine print using the 8610 wireless. However, if I try to print any GMAILs, nothing happens.  I checked I have the selected 8610 as default printer and the printer has the correct documents ready, but nothing happens.