




版權(quán)說明:本文檔由用戶提供并上傳,收益歸屬內(nèi)容提供方,若內(nèi)容存在侵權(quán),請(qǐng)進(jìn)行舉報(bào)或認(rèn)領(lǐng)
文檔簡介
1、Administering User SecurityObjectivesAfter completing this lesson, you should be able to:Create and manage database user accounts:Authenticate usersAssign default storage areas (tablespaces)Grant and revoke privilegesCreate and manage rolesCreate and manage profiles:Implement standard password secur
2、ity featuresControl resource usage by usersDatabase User AccountsEach database user account has:A unique usernameAn authentication methodA default tablespace A temporary tablespaceA user profileAn initial consumer groupAn account statusPredefined Accounts: SYS and SYSTEMSYS account:Is granted the DB
3、A roleHas all privileges with ADMIN OPTIONIs required for startup, shutdown, and some maintenance commandsOwns the data dictionaryOwns the Automatic Workload Repository (AWR)SYSTEM account is granted the DBA role. These accounts are not used for routine operations.Creating a UserSelect Server Users,
4、 and then click the Create button.Authenticating UsersPasswordExternalGlobal注:題52Administrator AuthenticationOperating system security:DBAs must have the OS privileges to create and delete files.Typical database users should not have the OS privileges to create or delete database files. Administrato
5、r security:For SYSDBA, SYSOPER, and SYSASM connections: DBA user by name is audited for password file and strong authentication methodsOS account name is audited for OS authenticationOS authentication takes precedence over password file authentication for privileged usersPassword file uses case-sens
6、itive passwordsUnlocking a User Account andResetting the PasswordSelect the user, select Unlock User, and click Go.注:題15PrivilegesThere are two types of user privileges:System: Enables users to perform particular actions in the databaseObject: Enables users to access and manipulate a specific object
7、System privilege: Create sessionHR_DBAObject privilege: Update employees注:題34System PrivilegesObject PrivilegesTo grant object privileges:Choose the object type.Select objects.Select privileges.Search and select objects.123GRANTREVOKERevoking System Privilegeswith ADMIN OPTIONREVOKE CREATE TABLE FRO
8、M jeff;UserPrivilegeObjectDBAJeffEmiJeffEmiDBA注:題32GRANTREVOKERevoking Object Privilegeswith GRANT OPTIONBobJeffEmiEmiJeffBobBenefits of Roles Easier privilege management Dynamic privilege management Selective availability of privilegesAssigning Privileges to Roles andAssigning Roles to UsersUsersPr
9、ivilegesRolesHR_CLERKHR_MGRJennyDavidRachelDeleteemployees.Selectemployees.Updateemployees.Insertemployees.CreateJob.Predefined RolesRolePrivileges IncludedCONNECTCREATE SESSIONRESOURCECREATE CLUSTER, CREATE INDEXTYPE, CREATE OPERATOR, CREATE PROCEDURE, CREATE SEQUENCE, CREATE TABLE, CREATE TRIGGER,
10、 CREATE TYPESCHEDULER_ ADMINCREATE ANY JOB, CREATE EXTERNAL JOB, CREATE JOB, EXECUTE ANY CLASS, EXECUTE ANY PROGRAM, MANAGE SCHEDULERDBAMost system privileges; several other roles. Do not grant to nonadministrators.SELECT_CATALOG_ROLENo system privileges; HS_ADMIN_ROLE and over 1,700 object privileg
11、es on the data dictionaryCreating a RoleSelect Server Roles. Click OK when finished.Add privileges and roles from the appropriate tab.Add privileges and roles from the appropriate tab.Add privileges and roles from the appropriate tab.CREATE ROLE secure_application_roleIDENTIFIED USING ;Secure RolesR
12、oles can be nondefault.Roles can be protected through authentication.Roles can also be secured programmatically.SET ROLE vacationdba;注:題77Assigning Roles to Users注:題21、72Profiles and UsersUsers are assigned only one profile at a time.Profiles:Control resource consumptionManage account status and pas
13、sword expirationNote: RESOURCE_LIMIT must be set to TRUE before profiles can impose resource limitations.Implementing Password Security FeaturesPassword historyAccount lockingPassword aging and expiration Password complexity verificationUserSetting up profilesNote: Do not use profiles that cause the
14、 SYS, SYSMAN, and DBSNMP passwords to expire and the accounts to be locked.Creating a Password ProfileSupplied Password Verification Function: VERIFY_FUNCTION_11GThe VERIFY_FUNCTION_11G function insures that the password is:At least eight charactersDifferent from the username, username with a number
15、, or username reversedDifferent from the database name or the database name with a numberA string with at least one alphabetic and one numeric characterDifferent from the previous password by at least three lettersTip: Use this function as a template to create your own customized password verificati
16、on.Assigning Quotas to UsersUsers who do not have the UNLIMITED TABLESPACE system privilege must be givena quota before they can create objects in a tablespace. Quotas can be:A specific value in megabytes or kilobytesUnlimitedSummaryIn this lesson, you should have learned how to:Create and manage database user accounts:Authenticate usersAssign default storage areas (tablespaces)Grant and revoke privilegesCreate and manage rolesCreate and manage profiles:Implement standard password security featuresControl resource usage by us
溫馨提示
- 1. 本站所有資源如無特殊說明,都需要本地電腦安裝OFFICE2007和PDF閱讀器。圖紙軟件為CAD,CAXA,PROE,UG,SolidWorks等.壓縮文件請(qǐng)下載最新的WinRAR軟件解壓。
- 2. 本站的文檔不包含任何第三方提供的附件圖紙等,如果需要附件,請(qǐng)聯(lián)系上傳者。文件的所有權(quán)益歸上傳用戶所有。
- 3. 本站RAR壓縮包中若帶圖紙,網(wǎng)頁內(nèi)容里面會(huì)有圖紙預(yù)覽,若沒有圖紙預(yù)覽就沒有圖紙。
- 4. 未經(jīng)權(quán)益所有人同意不得將文件中的內(nèi)容挪作商業(yè)或盈利用途。
- 5. 人人文庫網(wǎng)僅提供信息存儲(chǔ)空間,僅對(duì)用戶上傳內(nèi)容的表現(xiàn)方式做保護(hù)處理,對(duì)用戶上傳分享的文檔內(nèi)容本身不做任何修改或編輯,并不能對(duì)任何下載內(nèi)容負(fù)責(zé)。
- 6. 下載文件中如有侵權(quán)或不適當(dāng)內(nèi)容,請(qǐng)與我們聯(lián)系,我們立即糾正。
- 7. 本站不保證下載資源的準(zhǔn)確性、安全性和完整性, 同時(shí)也不承擔(dān)用戶因使用這些下載資源對(duì)自己和他人造成任何形式的傷害或損失。
最新文檔
- 山東省濰坊市壽光重點(diǎn)中學(xué)2024-2025學(xué)年初三中考適應(yīng)性模擬押題測試(一)生物試題含解析
- 江蘇省金陵中學(xué)2025屆高三三輪復(fù)習(xí)系列七出神入化7物理試題含解析
- 氣象科技研發(fā)與應(yīng)用合同2025
- 西藏林芝地區(qū)察隅縣2025年三年級(jí)數(shù)學(xué)第二學(xué)期期末教學(xué)質(zhì)量檢測模擬試題含解析
- 上海市寶山區(qū)2024-2025學(xué)年初三第二次中考模擬統(tǒng)一考試生物試題含解析
- 山東省棗莊嶧城區(qū)六校聯(lián)考2024-2025學(xué)年初三第二學(xué)期期末質(zhì)量抽測化學(xué)試題含解析
- 智慧農(nóng)業(yè)技術(shù)創(chuàng)新與推廣策略
- 戰(zhàn)略合作保密合同書:機(jī)密信息篇
- 零食銷售用工合同
- 混凝土采購合同范本
- 2024年03月湖南省韶山思政教育實(shí)踐中心2024年招考5名合同聘用制教師筆試近6年高頻考題難、易錯(cuò)點(diǎn)薈萃答案帶詳解附后
- 強(qiáng)制執(zhí)行股東分紅申請(qǐng)書
- 基于arima模型的我國房地產(chǎn)預(yù)測分析
- JGT366-2012 外墻保溫用錨栓
- 《界面圖標(biāo)設(shè)計(jì)》課件
- 2021阿里巴巴Java開發(fā)手冊(cè)1.4
- 鐵路局客運(yùn)段QC小組提高列車旅客滿意度成果匯報(bào)
- 14S501-1球墨鑄鐵單層井蓋及踏步施工
- 加強(qiáng)理解溝通-爭做陽光少年主題班會(huì)
- 草籽播種施工方案范本
- 無人機(jī)動(dòng)力系統(tǒng)課件PPT
評(píng)論
0/150
提交評(píng)論