How To Configure Data Encryption and Integrity
Configuring Network Data Encryption and Integrity for Oracle Servers and Clients
3-5
Oracle Advanced Security key management function changes the session key with
every session.
Authentication Key Fold-in
The purpose of Authentication Key Fold-in is to defeat a possible third party attack
(historically called the man-in-the-middle attack) on the Diffie-Hellman key
negotiation. It strengthens the session key significantly by combining a shared
secret, known only to the client and the server, with the original session key
negotiated by Diffie-Hellman.
The client and the server begin communicating using the session key generated by
Diffie-Hellman. When the client authenticates to the server, they establish a shared
secret that is only known to both parties. Oracle Advanced Security combines the
shared secret and the Diffie-Hellman session key to generate a stronger session key
designed to defeat a man-in-the-middle attack.
How To Configure Data Encryption and Integrity
This section describes how to configure Oracle Advanced Security native Oracle
Net Services encryption and integrity, and presumes the prior installation of Oracle
Net Services.
The network or security administrator sets up the encryption and integrity
configuration parameters. The profile on client and server systems using data
encryption and integrity (
sqlnet.ora file
) must contain some or all of the
parameters listed in this section, under the following topics:
■
About Activating Encryption and Integrity
■
About Negotiating Encryption and Integrity
■
Setting the Encryption Seed (Optional)
■
Configuring Encryption and Integrity Parameters Using Oracle Net Manager
Note:
The authentication key fold-in function is an imbedded
feature of Oracle Advanced Security and requires no configuration
by the system or network administrator.
See Also:
Chapter 7, "Configuring Secure Sockets Layer
Authentication"
, to configure the SSL feature for encryption,
integrity, and authentication
Summary of Contents for Database Advanced Security 10g Release 1
Page 17: ...xvii ...
Page 20: ...xx ...
Page 24: ...xxiv ...
Page 42: ...xlii ...
Page 44: ......
Page 102: ......
Page 124: ......
Page 246: ...Managing Certificates 8 28 Oracle Database Advanced Security Administrator s Guide ...
Page 284: ......
Page 384: ......
Page 414: ...Physical Security D 6 Oracle Database Advanced Security Administrator s Guide ...
Page 518: ...Index 10 ...