Vault to Oracle set up rules to restrict the user and the type of application that can connect

Oracle 11 g 2 (11.2.0.4.3)

RHEL 6

Hi all

We are experiencing a few problems to configure the following condition:

Users A, B, and C will not be able to connect via SQLPLUS.

So I took note of the political examples on how to Set Up database Vault (Doc ID 972477.1() -section restrict access to the database (sqlplus) unwanted tools:

However, it doesn't evaluate the rule in the rule set correctly. The rule set is as follows:

DVF. F$ MODULE! = ' SQL * MORE AND DVF. F$ SESSION_USER NOT IN ("USERA", "USERB", "USERC")

This rule allows all users to connect except those defined in the rule. And it applies also to the developer SQL (and all other connections). If I change to be 'IN' he also allows users in the list, but no one else. In addition, somewhere I think it evaluates it as "OR" rather than "AND". What I want to do is:

IF user IN ("USERA", "USERB", "USERC") AND SYS_CONTEXT ('USERENV', 'MODULE') = ' SQL * MORE

SO, do not allow the user to connect.

Note: The factor (MODULE) has been created by me and her expression is SYS_CONTEXT('USERENV','MODULE')

Any help on this would be greatly appreciated.

I tested these rules and they work:

(1) ((upper (sys_context ('userenv', 'module')) like '%%') and (not in sys_context ('userenv', 'session_user') ('A', 'B'))) or ((upper (sys_context ('userenv', 'module')) like ' % %') and DEVELOPER (not in sys_context ('userenv', 'session_user') ('A', 'B'))))

(2) ((upper (sys_context ('userenv', 'module')) not like ' %PLUS%')) or ((upper (sys_context ('userenv', 'module')) not like ' % DEVELOPER %'))))))

I'm blocking users A and B to connect from SQL * more and SQL Developer

-set the rule defined for all THE TRUE evaluation

Tags: Database

Similar Questions

  • restrict the types of files that can be downloaded

    I refer to the Configuration Guide for Oracle E-Business Suite Release 12. I have a question on the recommendation * restrict the types of files that can be downloaded *. I'm not really a functional E-Business Suite user, more looking at it from a perspective of risk analysis.

    A few questions if you will allow me:

    May I ask if anyone of you in your E-Business Suite facilities restrict the types of files that can be downloaded? If yes which?
    What is the risk by limiting only not the files that can be downloaded? What can happen? What's the risk major?
    And also, specific to the financial modules of EBS, what types of files "load" users? Can you give us some examples?
    Can do you more harm than good by limiting certain types of files allowed for download?
    And also where exactly can you check what restrictions in terms of file type and size are currently defined? And how to navigate EBS to see what's next?

    Published by: user599292 on March 20, 2013 02:54

    Please see these documents.

    Mechanism of Security Configuration in the function of attachments in Oracle E-Business Suite [ID 1357849.1]
    Configuration Guide for Oracle E-Business Suite Release 12 [403537.1 ID]
    Error: This file Type is not allowed. Please choose another file. [1428248.1 ID]
    New Configuration of the security translates into "this file Type is not allowed" error downloading jar CX [1432305.1 ID]

    Thank you
    Hussein

  • Select a type of user account (for example, standard user, restricted user, and other types) on computer XP pro?

    Hello.

    I have a question about how to select the type of user account for each user account.

    I read that if I type 'control userpasswords2' term, it will bring up a window of hidden user accounts.  In this window, select a name of the user account and click property, click on membership group and it will show all the type of account you can purchase (including the standard user, restricted user, the other who has many other types)

    Here is the link I read

    http://www.exnol.com/globally-control-and-change-all-users-passwords-in-Windows

    Let's say my computer is XP pro and it is in the home (not domain joined ) working group. Am I able to set these types of accounts to my user account using 'control userpasswords2' just as I explained above?

    I was wondering because I read in the microsoft help article or somewhere that it indicates that the computer must be on the field to be able to choose the type of account by using this process, I explained, and one account type you can choose where your computer is located in the Working Group's account admin or limited using the control panel then click on accounts of users... but other said it should not be on the field... I got confused.

    I would like to try it myself, but I don't have XP pro computer with me right now, I'd appreciate it really if someone could help me with the answer.

    Hi greenyy,

    If you are the administrator of the machine Windows XP Professional, you can use the command 'control userpasswords2' and access the list of user accounts and change the type of account.

    You need not necessarily be on a domain, however, it may not work for some types of user accounts on a working group.

    A test, you can try to change the type of account for user accounts & check if it works.

    Reference: To change the type of user account 

    Hope the helps of information. Please post back and we do know.

    Concerning
    Joel S
    Microsoft Answers Support Engineer
    Visit our Microsoft answers feedback Forum and let us know what you think.

  • I was setting up my NEW email in Hotmail and has been BLOCKED! I can't communicate with anyone and get this resolved - someone here who can solve this problem?

    I was setting up my NEW email in Hotmail and has been BLOCKED! I can't communicate with anyone and get this resolved - someone here who can solve this problem? It must be the WORST email service I've EVER had! WHI is here to do something about it?

    How much do you pay for this service?

    In all cases, to submit all queries Hotmail on the forum right here:

    Windows Live Solution Center
    http://windowslivehelp.com/

  • Print an e-mail, how do you restrict the number of pages that only 1 4?

    I'm going to print an email, and it maybe 11 pages and I want just the first page.  It says on the bottom 1 of 11 but will display all 11 pages.  How do you restrict it just the page or pages you want.

    This seems to be the limitation of the charm/devices/printer mechanism.  If it's the printer drivers or not I don't know.  On the machine, as I sit the connected printer to Dell, the XPS print driver or the OneNote driver offers an option to choose the pages to print.  By clicking on "additional settings", you get all sorts of options such as duplex printing, but no page selection.

    Hope that gets sorted soon!

  • Office 2010 does not display in the list of programs that can be set as the default value in Windows 7

    I have Office 2010 Home and Student installed on my Pavilion p6367 c - b, which is under W7 Home Premium.

    If I open Word or Excel and then use the open function to open a file, the file opens without any problem.  However, when I try to open a document or a spreadsheet by clicking on it directly (for example, in windows Explorer or a shortcut to this file), I get a message that says: there is no program associated with this file type and "create an association in the default program control panel.

    Unfortunately, when I go on this Panel, Office is not shown as one of the programs that I choose and I see nothing to add.  I know I must be missing something but...

    I hope someone can help me!

    Thank you.

    Hi, once again, Rick:

    I played a bit with change the types of files on a Vista computer, I was working on that. I thought I had to use WinZip to open a file that had no association.

    When I went to the list of available programs that is given to me, WinZip was not an option to choose. If it sounds the same problem you are having. You access the list to select an Office application to open a file and it is not among the list of available programs.

    I thought it was weird, so I played a little bit more. If you go on the left side of the box, you should have options to look for other places, so I went to computer > CProgam files and then I scrolled down and found in WinZip. Then, I open the WinZip program menu and select the executable file to open the file.  It worked (well, he gave me WinZip as default program to open the file, but the file does not open. It must have been corrupted or something).

    Then, give that a try. I am now back on the XP computer and do not have access to the specifics. But the procedure for file association for Vista is the same as W7. I write from memory of what I did last night.

    Paul

  • Restrict the application of Digital Signatures

    Hello

    I am trying to determine what options are available natively in Acrobat to restrict the type of certificate that is used to apply a digital signature.  AFAIK, Acrobat, default, seems to allow the use of a certificate that has the extension 'Digital Signature'  This has the potential to create big problems in a regulated environment.

    In my organization, our users receive multiple certificates for different applications.  For example, a user can have a certificate for VPN, one for SMIME email access and, finally, one that is specifically for the application of electronic signatures.  There is a more rigorous selection process for obtaining a certificate of electronic signature, and it also invites for a password every time that the private key is available.  Each type of certificate has a separate certification authority.

    We have configured the identities approved each user in Acrobat by deploying a file of address book for them.  We have only our CA electronic signature as a CA approved in Acrobat (with some other universally approved authorities).  The result is that, when a signature that has been applied by using any other AC, Acrobat does not check the signature.  It's good, but it isn't enough since the dynamic images that come with Acrobat digital signatures do not appear on the documents printed or flattened.

    Basically, I am trying to determine if there is a way to configure Acrobat (in native, out-of-the-box mode) such that it will only request digital signatures using certificates that are issued by an authority that is defined as a trusted identity.

    If anyone has encountered this before?

    Hi Mike,.

    You should apply the starting value for each signature field that you want to restrict. The starting value becomes part of the properties of the signature field.

    You can use the JavaScript debugger included in Acrobat. To select bring him the Advanced > Document Processing > JavaScript debugger menu item (providing you use Acrobat Pro v9).

    Here is an example of code that you can apply where you need a specific issuer and the use of the key:

    var f = this.getField ("Signature1");
    caCert var = security.importFromFile ("Certificate", "/ C/Documents and Settings / / My Documents/myCA.cer");

    f.signatureSetSeedValue({)
    certspec: {}
    Issuer: [caCert],
    keyUsage: [0x7FFFFFF7], //Insure the certificate has value KeyUsage nonrepudiation
    flags: 0 x 34 / / 2 requires transmitter + 32 requires the use of keys
    },
    });

    Let me know if you are looking to apply a different condition.

    Steve

  • rules design and sets of rules

    Hello

    My requirement is to provide sets of rules to our database development team. To save sets of rules in a centralized directory and configure maker data as follows the rule of this directory may be an option. How can I fix this with Data Modeler? I am able to create and save sets of rules. But where are these sets of rules located on my system? And how should I configure Data Modeler for read sets of rules somewhere else? It is possible at all? Help, please.

    Data Modeler 4.1.0.19

    Hello

    You can find these files in the directory indicated by the 'Types of system default directory' preference. The file you are looking for is called dr_custom_scripts.xml.

    Joop

  • Dialin VPN - a way to restrict specific users?

    I have a Cisco router with a dial fairly simple VPDN with updated user names in place in the router config itself (no external RADIUS server) so that MS-Windows people can use OS VPN - built - in client to connect to the top and access servers on my local network.

    Is it possible to restrict a connection (via ACL or otherwise) when a specific username connects?

    for example: If someone connects with user name "thomas", I want to restrict their access to a specific server IP on my LAN

    Is this possible?

    Hi Thomas

    The answer is simply no. but there are alternative means.

    Cisco devices do not have the ACL on users. You must buy CS ACS and integrate with your device.

    http://www.Cisco.com/en/us/products/sw/secursw/ps2086/index.html

    Another option, install RADIUS on the winows server, manually set the IP address of the user in the tab call user properties in Active Directory, and then apply ACLs on this address ip, or you can assign a name for this IP etc.

    Or you can create tunnel-group by user and assign pools of IP that contains only 1 IP, name this IP and write ACL, if you don't have too many users who connect through VPDN.

    Concerning

  • Dynamic action to set the value of the point of Application

    Hello
    I want to display a form button that sets a value of the point of Application. Can someone please help and guide how to proceed?

    The requirement is, the user will receive a report, they can change a record and a button will allow him to SET the record for the session. When it accesses a different page within the application, they will see that the data relevant to the record that is DEFINED.

    Thanks in advance
    Aali

    Hi, Estelle,.

    You can use the dynamic action 'Code from PL/SQL Execute' to fix your application. For example, your code might look like

    begin
        :G_DISPLAY_MODE := :P1_DISPLAY_MODE;
    end;
    

    Page items to submit: P1_DISPLAY_MODE

    P1_DISPLAY_MODE would be the element on your current page where you select the desired value.

    Hope that you give something to play with.

    Concerning
    Patrick
    -----------
    My Blog: http://www.inside-oracle-apex.com
    APEX Plug-Ins: http://apex.oracle.com/plugins
    Twitter: http://www.twitter.com/patrickwolf

  • Y a you it the restriction when the type of file stored on the cloud?

    Hello
    Having problems paying UTI cloud of my space on the, I wonder if there are restrictions when the type of file format
    organization unit to the size of files that can be stored on the cloud?

    Some will upload and go! Can you inform me if the system is not at the point or if it's just me
    who have this kind of problems?

    Thanks and regards.

    There are intermittent problems with the download of large files. We aware and are working on fixing it.

    -Dave

  • How to restrict the Subscriber to display its own feed?

    How to pass the opponent UserID to Subscriber?

    private function displayExistingStreams (): void
    {var publishers: Object = _streamManager.getStreamsOfType (StreamManager.CAMERA_STREAM);}
    status_txt. Text = "displayExistingStreams";
    for (var publisherID:String in editors) {}
    If (publisherID! = _userManager.myUserID) {}
    setUpSubscriber (publisherID);
    }
    }

    }
    protected function setUpSubscriber(p_publisherID:String):void {}

    currentSubscriber = new WebcamSubscriber();
    currentSubscriber.displayUserBars = true;
    currentSubscriber.connectSession = cSession;
    currentSubscriber.subscribe ();

    publisherIDs used to restrict the list of editors that this Subscriber needs to show videos for.
    currentSubscriber.publisherIDs = [p_publisherID];

    }

    Hello

    You will need to loop on userManager.userCollection user ID and get all user ID and all codes except yourself the webcamSubscriber.publisherIDs value. And you need to update this whenever the user enters or leaves the room (listening to UserEvent.USER_CREATE and UserEvent.USER_REMOVE in UserManager, if you want to dynamically maintain this list publisherIDs)

    I answered this in other forum posts earlier.

    Hope this helps

    Thank you

    Hironmay Basu

  • Set a default value in the target?

    Hi experts,

    How can I set a default value in the target data store that I'll use in the interface?

    Hello

    Open your store of target data column, click the Description tab and the default value is .

    Then in the interface, select this column and go to run on the TARGET.

    Implementing tab say, odiRef.getColDefaultValue)

    Thank you
    G

  • Can we have another condition to the rule set (business rules)

    can we have condition ifElse in the set of rules?


    Thank you

    There is no IfElse in the rule set.

    If you require an If else, write 2 different rules:
    (1) with the positive test condition.
    (2) with the negative test condition.

    Oracle Business Rules follow Pattern Matching, Rete algorithm, not mistake for a procedural language built IfElse.

    --
    Mark recognition appropriate as useful or appropriate response, if your problem is resolved.

  • How to convert a set of rules to update a rule update shared?

    I created a set of update rules in the Tools section of the E10 data, but it does not appear in the list of rules to update shared and so I am unable to use it in the stages of treatment for my forms (even if I can still use it in programs).  Anyone know how I can convert my update rule set in the Tools section of data in a rule to update shared without having to recreate?

    Thank you very much.

    Just to clarify this was always so even when she was just E9. Rules update form could never be used in the program generator and updated program rules Builder could never be used in forms. Several times I was caught swearing on my screen because of this, especially when I was brand new to Eloqua and has just completed the construction of a massive update rule in the WRONG section.

    Here is some information on why they were different and are always different.

    In a program, you have a contact into step - the update will unfold on the contact which is the step at a time. If you look at a program generator update rule it doesn't let you not specify criteria for 'research', example of email address because he knows that it will be applied to, the person in the step at the present time.

    A form update rule has a criterion of "research", usually the email address. A person submits a form, they give you their email address, the update rule needs to know what field should we use to make a match in the entire database to find out who it should be updated. You can also not use same email address, you can use other unique identifiers or a combination of different areas.

    In my view, there are a few other differences with the two types of update rules, I think you can make some types of joint and date stamping in one where the other you can't, I don't remember the exact details but I think that there are a few minor differences.

    In this context, it does not mean always, they must be different, it would be amazing if you could use the same update rule in the program as well as the forms generator or at least copy a rule to update the forms in the format program generator, as a kind of conversion, where a person made a mistake not that it never happens.

    An Eloqua - One Love - an update rule

    Omar.

Maybe you are looking for

  • After uninstalling shockwave player because of a malfunction, Firefox opens not all sites so I can recharge the flash drive

    Flash player was not working.Starting process of re - install.Uninstalled former player as suggested.Now unable to open all sites, so can not download the new player.How can I get firefox back online when it will not open sites? I have

  • Installing the driver on the Qosmio G20

    I have a G20 machine (bought from the Japan) and I want to install my copy of XP pro. XP Setup works well until the end, then I start to install the driver and the software as suggested by Toshiba: acoustic silencer V1.00.005Ahelp V1.02.00_TINASSIST_

  • Table with numeric columns and string

    Hello everyone. I am a new labviewer, so I have 2 questions fundamental. 1. I found this basic timer loop, which I need to get inside my structure of the event. How to wire this loop with my writing and reading? 2. I need to wire my digital indicator

  • How to create different types of analog inputs without using the DAQ assistant?

    Hi all I would like to create multiple entries multiple analog channels of type... I mean I want to have the voltage of 5 and 2 channels of temperature... However, I am not using the DAQ assistant. I use "create channel" vi. Can anyone suggest me ple

  • My screen is black.

    After turning on my computer, my screen is black and when I click on the Start button to connect to the internet, it changes its original color. What could be the cause of this problem.  Thank you very much, Mr. Moore