Troubleshooting Enterprise User Security
Enterprise User Security Configuration Tasks and Troubleshooting
12-31
2.
Check that there is a value for the attribute
krbprincipalname
in the
user entry. If there is no value, then use Oracle Internet Directory
Self-Service Console to enter one.
3.
Use Enterprise Security Manager to check that the user search base
containing this user is listed in the realm Oracle Context that you are using.
4.
Check that the ACL on the user search base attribute allows read and search
access to the
krbprincipalname
attributes by the
verifierServices
group. This is set properly by default, but may have been altered.
ORA-28293: No matched Kerberos principal found in any user entry.
Action:
Check the following:
1.
Check that a user entry exists in Oracle Internet Directory for your user.
2.
Use Enterprise Security Manager or
ldapsearch
to check that a user
search base containing this user is listed in the identity management realm
that you are using.
3.
Check that the user entry in the directory contains the correct Kerberos
principal name by using the following steps:
–
Use Enterprise Security Manager Console to find the Kerberos principal
name attribute that is configured for the directory in your realm, and
–
Check that the correct Kerberos principal name appears in that attribute
in the user's directory entry.
4.
If you have an exclusive schema for the global user in the database, check
that the DN in the database matches the DN of the user entry in Oracle
Internet Directory.
ORA-28300: No permission to read user entry in LDAP directory service
Action:
Check that the database wallet contains the correct credentials for the
database-to-directory connection. The wallet DN should be the DN of the
database in Oracle Internet Directory. To retrieve the credentials, perform the
following steps:
1.
Use the
mkstore
command line utility to retrieve the database password
for the wallet by using the following syntax:
mkstore -wrl <database wallet location> -viewEntry
ORACLE.SECURITY.PASSWORD -viewEntry ORACLE.SECURITY.DN
Содержание Database Advanced Security 10g Release 1
Страница 17: ...xvii ...
Страница 20: ...xx ...
Страница 24: ...xxiv ...
Страница 42: ...xlii ...
Страница 44: ......
Страница 62: ...Oracle Advanced Security Restrictions 1 18 Oracle Database Advanced Security Administrator s Guide ...
Страница 100: ...Duties of an Enterprise User Security Administrator DBA 2 38 Oracle Database Advanced Security Administrator s Guide ...
Страница 102: ......
Страница 116: ...How To Configure Data Encryption and Integrity 3 14 Oracle Database Advanced Security Administrator s Guide ...
Страница 124: ......
Страница 148: ...RSA ACE Server Configuration Checklist 5 24 Oracle Database Advanced Security Administrator s Guide ...
Страница 246: ...Managing Certificates 8 28 Oracle Database Advanced Security Administrator s Guide ...
Страница 254: ...Configuring Oracle Database for External Authentication 9 8 Oracle Database Advanced Security Administrator s Guide ...
Страница 284: ......
Страница 350: ...Troubleshooting Enterprise User Security 12 38 Oracle Database Advanced Security Administrator s Guide ...
Страница 384: ......
Страница 394: ...Data Encryption and Integrity Parameters A 10 Oracle Database Advanced Security Administrator s Guide ...
Страница 414: ...Physical Security D 6 Oracle Database Advanced Security Administrator s Guide ...
Страница 518: ...Index 10 ...