new OS authentication question

Hi guys,.

Firstly that it is a cross-post of confused about "identified on the outside" , the reason being that I had already marked this issue as 'answer' (before I came up with another question) and so a lot of people will probably look into it.

In any case, I was looking at the following link
[http://www.dba-oracle.com/t_windows_external_user_authentication.htm | http://www.dba-oracle.com/t_windows_external_user_authentication.htm]

Where it is said

-----------------------------------------------------------------------------------------------------------------------
CREATE USER OPS$ SCOTT IDENTIFIED BY TIGER;

Assuming that Scott has logged on to the operating system, Scott could enter SQLPlus with or without password:

sqlplus.
sqlplus scott/tiger

You can also create the user with the clause "identified externally:

CREATE USER OPS$ SCOTT IDENTIFIED EXTERNALLY.
-----------------------------------------------------------------------------------------------------------------------

Why Scott may enter without a password? We have not said that Scott is identified on the outside in the first example. Yes, we preceded the name of scott with OPS$, but only enough to tell Oracle that this user must be identified by the authentication of the os?

Thank you

Generally, it took "identified on the outside", but there is a documented exception: ops$. "+ If the OS_AUTHENT_PREFIX is set to OPS$ user can connect in a manner if created with a password." + »

SYS@orcl > show parameter os_authent_prefix
os_authent_prefix          string   ops$
SYS@orcl > create user ops$eorbegozo identified by oracle;
SYS@orcl > grant create session to ops$eorbegozo;

[eorbegozo@caliope ~]$ connect /
Connected to:
Oracle Database 10g Enterprise Edition Release 10.2.0.4.0 - Production
With the Partitioning, OLAP, Data Mining and Real Application Testing options
OPS$EORBEGOZO@orcl >

SYS@orcl > show parameter os_authent_prefix
os_authent_prefix          string   osuser$
SYS@orcl > create user osuser$eorbegozo identified by oracle;
SYS@orcl > grant create session to osuser$eorbegozo;

[eorbegozo@caliope ~]$ sqlplus /
ERROR:
ORA-01017: invalid username/password; logon denied

SYS@orcl > alter user osuser$eorbegozo identified externally;
User altered.

[eorbegozo@caliope ~]$ sqlplus /
Connected to:
Oracle Database 10g Enterprise Edition Release 10.2.0.4.0 - Production
With the Partitioning, OLAP, Data Mining and Real Application Testing options
OSUSER$EORBEGOZO@orcl >

You can read the Note: 18088.1 UNIX: OS authentication on the Oracle server for more info.

Enrique

Tags: Database

Similar Questions

  • Client VPN authentication question

    Hi friends,

    I recently started a new company, where the Cisco VPN Client is used by all remote Windows users. I'm not familiar with the customer. I see by our remote access policy that clients authenticate using PAP. This immediately caught my concern.

    My question is if this poses a threat to security? Even if the authentication is not encrypted, it is always the case in a 3DES IPSec tunnel, right? What is the best practice regarding using the VPN client and authentication?

    Thanks in advance!

    Equipment:

    Cisco VPN Client v5 (latest version) on Windows XP SP3

    Microsoft IAS (RADIUS) on W2K3 Server R2 x 64

    Router Cisco 3825

    IOS 12.4.24T Adv IP Services

    If I understand your customer VPN ends on 3825 router. the customer gets the name of username/password prompt after than phase 1 so it may not be clear.

    I hope this helps

    concerning

    -Syed

  • New record of question mark SSHD screnn

    My Seagate SSHD should fail, so I ordered a replacement.

    In the meantime I backed up with time machine on my external hard drive in my MacBook, and then I created a bootable USB key.

    This morning, I replaced the SSHD with a new one, but I get the white screen with a folder with an exclamation mark.

    It also happened that the laptop turns off unexpectedly. Could you help me please understand what is happening?

    Thanks yo!

    The question mark appears when the drive specified in the last

    System Preferences > startup drive...

    ... is not available. Your Mac can't find the boot drive, or the drive specified is not a bootable disk (does not contain Mac OS X).

    --------

    Start with the Alt/Option key, select your key USB Bootable and install on the new SSD.

    Long-term, make sure that you enable some version of TRIM, especially if your SSD is only 8 x the size of Mac OS X or smaller.

  • New user e260 - questions

    My new Sansa e260 is my first mp3 player, so I'm still on a steep learning curve!  Can someone help me with the following questions please?

    1. the Web of Sandisk site has lots of information about the e200 series, but I don't know if all this refers to my e260, or if it is a newer model that requires an update of the instructions.  Even my User Guide refers to the e200 rather than the e260.  It is safe for me to consider the e200 data as valid for my e260?

    2. my Quick Start Guide says that my e260 must be in MTP mode to be used with Windows Media Player (I use WMP 11).  But the instructions for switching between the MTP and MSC modes do not apply to my device.  For example, there is no "USB mode" option on my menu settings.  My drive seems to be recognized by WMP perectly fine.  Should I worry?

    3. How will I know if I should update the firmware?  It is classified in my unit version 03.01.11F.  If I should update this, where can I get the download?  As I said above, my model does not appear on the Web site.

    Thanks a lot for any advice on these topics.

    Once again, clu31355, thank you very much for this valuable information.  I think that you have answered all of my questions... and much more!

    Have a great Christmas.

    Penners

  • Windows 7 slow login / delay authentication question user wireless via ACS 5.8

    Just set up a new ACS 5.8 farm (only 2 servers) here and which I hope someone here can shed light on the difficulties.

    The new ACS server is set up to correctly authenticate administration network device and I am currently working on the definition of profiles for our wireless users authentication and business laptops.

    Being new to this version of ACS (we will migrate manually ACS 4) I followed an excellent example of this task described in a video on this site: http://www.labminutes.com/sec0044_ise_1_1_wireless_dot1x_machine_auth_peap

    I managed to have a Windows XP sp3 client authenticate properly, first with the authentication of the computer, then the authentication of users... and the domain logon process takes place in a short period of time< 1min="" and="" the="" user="" gets="" all="" their="" networked="" drives="" via="" the="" domain="" login="">

    However, I'm fighting to get our Windows 7 clients to authenticate properly.  It seems that the machine authentication does not work as expected (I can ping the laptop test from another machine on the network while the test machine is sitting at the login screen; and I see Authentication host recorded in the papers of authentication Radius ACS).  But, when a domain user logs in with his credentials, the connection process takes 4-5 minutes before an event to authenticate the user is entered in the register authentication Radius ACS, after which the login process completes, except that the domain logon script does not work and the user does not receive the drive mappings.

    Can someone point me in the right direction here?  I would be grateful any entry on this.

    Thanks in advance,

    John

    I had a similar problem with Wireless 802.1 x Win 7 clients unable to connect unless they had cached credentials of the AD.  Authenticate in the machine, but the user would take a lot of time if the Windows credentials have been cached.

    I could solve the problem by expanding the ACL of the air space used during the user authentication to include all DC in the environment.

  • RADIUS authentication question

    Hello world

    I'm learning the Radius Authentication. Here are my updated laboratory in place:

    R1 (107.107.107.10)-(107.107.107.4) - WIN2008 (RADIUS SERVER)

    Here is the config of RADIUS on the R1:

    AAA authentication login default local radius group

    RADIUS-server host 107.107.107.4 auth-port 1645 acct-port 1646
    key cisco RADIUS server

    I have a few questions:

    (1) above, I do not specify encryption on R1, R1 will use this as the default encryption?

    In the attached file, we see the password is encrypted, but there is no config on R1 to use particular encryption

    (2) we also see "authenticator", which is I think is R1 host name i.e encrypted with the shared secret. I'm wrong?

    Much appreciated and have a great weekend!

    Hello

    The Protocol Radius encrypts the password for the default user. I think that Radius uses MD5.

    The authenticator is a random string generated by the client and is used in the encryption of the password process.

    Thank you

    John

  • [^^ New here] Ask questions about the development of Blackberry GUI

    Hi everyone, im new here.

    (My English is not very good, but in any case I'll do my best to be understable).

    First of all, I'm going to introduce myself:

    My name is Díaz de Miguel (South America, Chile) and now I'm working with a team on what we called 'Santa Maria Mobile Challenge' here in my University (UTFSM, Universidad Tecnica Federico Santa Maria) and we have an app for phones mobile Blackberry... IM in charge of the User Interface of the application... so, here's my question:

    I conceive an idea of how it looks at the application (we are new to programming in java and J2ME for Blackberry), I designed in Photoshop, and with a few readings, I realize how can I do this on J2ME BB.

    In my research on J2ME and Clases de BB I think I can do this with HorizontalFieldManagers and VerticalFieldManagers... tie them a background image for each FieldManager (of course I have to divide my original and more image "images") and connect (or trigger) behaviour when he focused...

    The idea of this is to make each component of our application classes:

    IE: Where it says "task 1", which blocks will be a HorizontalFieldManager with 3 VerticalFieldManagers, one with the «!» Icon, the Second bearing the name of the task, in this example is "task 1", and the third will be the other information... and perhaps on the third HorizontalFieldManagers 2 more...)

    Well well... the idea of this post is to know if im on the right way to apply for ugly or there is a better way... I accept all the comments... I want to win this contest.

    Thank you!!

    Miguel Diaz

    ========================

    Reach:

    This is the Image:

    Hi and welcome to the development of BlackBerry,

    You are on the right track... It is difficult to design a beautiful blackberry app but you can do what you want with methods of painting FieldManagers und ...

    If you need help others let me know...

    Also if you need help doing some work im a blackberry developer contractor who is happy to help you any time...

    Concerning

    Paul Haenel

  • BlackBerry Smartphones New user's question. Attachment / broadcasting a connection

    So I a new user question that I didn't see it in the manual for the "BOLD".

    I know that you can attach the "BOLD" blackberry via bluetooth and using the usb cable.

    The question is can I just broadcast using the phone to create a wireless connection, can I use it with a laptop as the iphone?

    Thank you.

    chk these items:

    http://www.BlackBerry.com/BTSC/search.do?cmd=displayKC&docType=kc&externalId=KB05196&sliceId=SAL_Pub...

    http://www.BlackBerry.com/BTSC/search.do?cmd=displayKC&docType=kc&externalId=KB05178&sliceId=SAL_Pub...

  • AAA authentication question

    Here is the config, I have a switch:

    AAA authentication login default group Ganymede + local

    AAA authentication login vtylogin group Ganymede + local

    AAA authentication login conlogin group Ganymede + activate none

    the AAA authentication enable default Ganymede + activate

    Now, here are my questions:

    1. when I have my login of Ganymede console connection works, but when I type 'enable' and try to use my password to Active Directory, it does not work.  So I try the enable password, don't worry.  However if I change the 4th line "aaa authentication enable the Activate by default", I can now by using the enable password.

    2. my second question is when I SSH into the switch, I want only that it uses the RADIUS server and use only the database local when the Ganymede is not available.  However while Ganymede is available, I am still able to login using the local user account.  I guess that's by design?  Is there a way to prevent this if it isn't design?

    When you use the local user account to connect to the device, can you check if you can see the log in "past the authentication attempt" on the box of the CSA? If so, the same account could you please check your local ACS DB user to see that it was created by a fake?

  • Smartphones New blackBerry with questions

    This is my first post.  Yesterday bought a Curve 8530.  My first BlackBerry ever. Lovin' the phone.  Got 2 things I want to understand.

    (1) all my contacts are in Windows Contacts.  How can I synchronize my phone with Vista?

    (2) is it possible to change all the icons to and from the desktop computer?

    I'm sure I'll have 1 million questions soon, but these are 2 for now.

    Oh Yes.  Stayed up to play with the software that comes with the phone (Desktop Manager and Roxio) and just when I started to get the hang of it, got an update today all night and it was gone.  New software makes no sense to me and I don't know how or why I need to use it.  Any suggestions on what I'm supposed to do with this?

    Thanks for any help you can provide.

    One is enough... I'd go with DM 6

  • New ESX5 host - questions see SAN storage data and much more

    Just installed a new vSphere host 5 and added to a cluster with 2 x 3.5 host (in my vCenter Server 5)

    3 questions.

    1. I can't see LUN (on SAN datastore). Have zoned out my new HBA etc and still no joy. Tried the host that it recharges and rescan option etc. Any ideas?

    2 - my 3.5 hosts I was able to specify different default gateways for my Console and VMKernel Service (both on the same vswitch). I have the Service Console configured vmkernel. 10.16.5.x and 172.16.5.x (I know there is no Service Console in vSphere 5\ESXi) but on my ESX5 host I can't specify different gateways for VMKernel and network management. I'm afraid that vmotion etc will not work between 3.5 hosts and host 5, because although the VMkernels have addresses in the same range, they have not the same gateway. I have to add a local route on the host ESX 5? Or am I wrong configured somewhere?

    3 minor irritation. My local drive in my new server is showing that the data store. Can it be hidden or changed to not be visible in the data store? I want to only display my SAN data stores.

    Thank you very much

    Steve

    (1) sounds like a SAN configuration problem - you should be able to see the LUN masking and zoning is correct in the FC switch and storage array.

    (2) you could specify wear two ways because the vmkernel and the Service Console were different and supposed to be on different networks - you no longer have a gateway single vmkernel - traffic will work as long as they are on the same subnet - a gateway is used only when you exit the subnet

    (3) I do not think it is possible to hide the local data store - but I could be wrong

  • new to vmware - question

    Hi all, I'm new to VMWare and you want to ask a silly question. My project plans to use vmware on a single physical server running windows 2003 to implement multiple instances of servers windows 2003 virtual. My question is what do we need to have different IP address and host name for each server virtual windows? Or vmware manages to solve this problem itself? If so, how does this work?

    Thank you!

    lqin1983 wrote:

    guys, thanks for your reply... as you said, we need differernt IP addresses for each server, which makes it easy for us becase that means that we must go through a long process to the commission, the servers with the new ip address...

    If you had multiple physical servers, you will need to go through the same exact process. How many servers you plan giving each server an IP address is a big problem? VMWare removes just your need more physical servers, what you do with the guest computers is pretty much unchanged.

  • Totally new with noob questions

    OK so im totally new to developing with Flex. My company uses flex to create RIA that work to read and write with SalesForce CRM. I use the salesforce toolkit and have an understanding of how everything works great base. what im trying to do is take the data which are entered in a text box and who present for salesforce. Currently, the first name, name and phone number are in the code. have created text boxes, I don't know how to take the value that is entered in one and make that equal to the value of its corresponding field.

    like I said... total noob

    If you are in ActionScript. FirstName = firstName.text should be fine, but in MXML and sometimes in ActionScript, you may need this:

    VAC. FirstName = "{firstName.text}.

    If this post has answered your question or helped, please mark it as such.

  • All new phone lock question-restoration works not

    I just got a new phone and tried to erase the recovery mode because the device is picking up a random 6-digit and locking code. Unfortunately, it says that the device is not be restored. Is there anything else I can try?

    I do not understand what it means to 'clear the recovery mode '.  It could mean erase using recovery mode, or it may mean something quite opposite.

    In any case, try to use the procedure described in "Erase your device with the recovery mode" in the article of HT204306 you fixed above.  If this fails, contact Apple Support such as suggested in the "Get more help" section of this article.

  • new apple tv questioned

    We just bought the new apple tv 4; have an apple tv 2.  What I want to save data or do something special before plugging a new apple tv 4?  Thank you very much

    There is nothing to transfer the Apple TV 2 to the Apple TV 4 If that's what you mean. You'll need to no password you used, but it's a matter of just go in them rather than transfer them somehow.

Maybe you are looking for