版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领
文档简介
1、Administering User SecurityObjectivesAfter completing this lesson, you should be able to:Create and manage database user accounts:Authenticate usersAssign default storage areas (tablespaces)Grant and revoke privilegesCreate and manage rolesCreate and manage profiles:Implement standard password secur
2、ity featuresControl resource usage by usersDatabase User AccountsEach database user account has:A unique usernameAn authentication methodA default tablespace A temporary tablespaceA user profileAn initial consumer groupAn account statusPredefined Accounts: SYS and SYSTEMSYS account:Is granted the DB
3、A roleHas all privileges with ADMIN OPTIONIs required for startup, shutdown, and some maintenance commandsOwns the data dictionaryOwns the Automatic Workload Repository (AWR)SYSTEM account is granted the DBA role. These accounts are not used for routine operations.Creating a UserSelect Server Users,
4、 and then click the Create button.Authenticating UsersPasswordExternalGlobal注:题52Administrator AuthenticationOperating system security:DBAs must have the OS privileges to create and delete files.Typical database users should not have the OS privileges to create or delete database files. Administrato
5、r security:For SYSDBA, SYSOPER, and SYSASM connections: DBA user by name is audited for password file and strong authentication methodsOS account name is audited for OS authenticationOS authentication takes precedence over password file authentication for privileged usersPassword file uses case-sens
6、itive passwordsUnlocking a User Account andResetting the PasswordSelect the user, select Unlock User, and click Go.注:题15PrivilegesThere are two types of user privileges:System: Enables users to perform particular actions in the databaseObject: Enables users to access and manipulate a specific object
7、System privilege: Create sessionHR_DBAObject privilege: Update employees注:题34System PrivilegesObject PrivilegesTo grant object privileges:Choose the object type.Select objects.Select privileges.Search and select objects.123GRANTREVOKERevoking System Privilegeswith ADMIN OPTIONREVOKE CREATE TABLE FRO
8、M jeff;UserPrivilegeObjectDBAJeffEmiJeffEmiDBA注:题32GRANTREVOKERevoking Object Privilegeswith GRANT OPTIONBobJeffEmiEmiJeffBobBenefits of Roles Easier privilege management Dynamic privilege management Selective availability of privilegesAssigning Privileges to Roles andAssigning Roles to UsersUsersPr
9、ivilegesRolesHR_CLERKHR_MGRJennyDavidRachelDeleteemployees.Selectemployees.Updateemployees.Insertemployees.CreateJob.Predefined RolesRolePrivileges IncludedCONNECTCREATE SESSIONRESOURCECREATE CLUSTER, CREATE INDEXTYPE, CREATE OPERATOR, CREATE PROCEDURE, CREATE SEQUENCE, CREATE TABLE, CREATE TRIGGER,
10、 CREATE TYPESCHEDULER_ ADMINCREATE ANY JOB, CREATE EXTERNAL JOB, CREATE JOB, EXECUTE ANY CLASS, EXECUTE ANY PROGRAM, MANAGE SCHEDULERDBAMost system privileges; several other roles. Do not grant to nonadministrators.SELECT_CATALOG_ROLENo system privileges; HS_ADMIN_ROLE and over 1,700 object privileg
11、es on the data dictionaryCreating a RoleSelect Server Roles. Click OK when finished.Add privileges and roles from the appropriate tab.Add privileges and roles from the appropriate tab.Add privileges and roles from the appropriate tab.CREATE ROLE secure_application_roleIDENTIFIED USING ;Secure RolesR
12、oles can be nondefault.Roles can be protected through authentication.Roles can also be secured programmatically.SET ROLE vacationdba;注:题77Assigning Roles to Users注:题21、72Profiles and UsersUsers are assigned only one profile at a time.Profiles:Control resource consumptionManage account status and pas
13、sword expirationNote: RESOURCE_LIMIT must be set to TRUE before profiles can impose resource limitations.Implementing Password Security FeaturesPassword historyAccount lockingPassword aging and expiration Password complexity verificationUserSetting up profilesNote: Do not use profiles that cause the
14、 SYS, SYSMAN, and DBSNMP passwords to expire and the accounts to be locked.Creating a Password ProfileSupplied Password Verification Function: VERIFY_FUNCTION_11GThe VERIFY_FUNCTION_11G function insures that the password is:At least eight charactersDifferent from the username, username with a number
15、, or username reversedDifferent from the database name or the database name with a numberA string with at least one alphabetic and one numeric characterDifferent from the previous password by at least three lettersTip: Use this function as a template to create your own customized password verificati
16、on.Assigning Quotas to UsersUsers who do not have the UNLIMITED TABLESPACE system privilege must be givena quota before they can create objects in a tablespace. Quotas can be:A specific value in megabytes or kilobytesUnlimitedSummaryIn this lesson, you should have learned how to:Create and manage database user accounts:Authenticate usersAssign default storage areas (tablespaces)Grant and revoke privilegesCreate and manage rolesCreate and manage profiles:Implement standard password security featuresControl resource usage by us
温馨提示
- 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
- 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
- 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
- 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
- 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
- 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
- 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。
最新文档
- 2025山东核电有限公司高校毕业生招聘笔试历年常考点试题专练附带答案详解试卷3套
- 2025国泰租赁有限公司招聘笔试历年备考题库附带答案详解试卷3套
- 甘肃公务员考试考场试题及答案
- 2025四川九洲光电科技股份有限公司招聘软件工程师(前后端软件设计开发方向)测试笔试历年常考点试题专练附带答案详解试卷3套
- 混凝土搅拌站安全生产防控方案
- 2025中国能建中电工程天津院校园招聘笔试历年典型考点题库附带答案详解试卷3套
- 2025“才聚齐鲁成就未来”山东黄金集团校园招聘笔试历年典型考点题库附带答案详解试卷3套
- 主城区污水治理项目技术方案
- xx市污泥处置中心项目技术方案
- 2025年及未来5年中国专用自卸车市场竞争态势及行业投资潜力预测报告
- 【课件】2025年消防月主题培训全民消防生命至上安全用火用电
- 2025秋形势与政策课件-聚焦建设更高水平平安中国
- 【MOOC】国际名酒知识与品鉴-暨南大学 中国大学慕课MOOC答案
- 防火重点部位每日巡查表
- 新昌人民医院固定资产及设备全资源管理系统项目采购要素
- SB/T 11095-2014中药材仓库技术规范
- GB/T 3836.3-2021爆炸性环境第3部分:由增安型“e”保护的设备
- GB/T 1220-1992不锈钢棒
- 《中国近现代史纲要》第八章-中华人民共和国的成立与中国社会主义建设道路的探索
- 高中英语长难句语法解析与翻译
- 腹部体格检查-课件
评论
0/150
提交评论