Solved

Secure Oracle Database link method

Posted on 2008-06-17
1
568 Views
Last Modified: 2013-12-19
I need the syntax for a Oracle Database link that offers the best security if a user needs to link to our database. We would like to be able to control the passwords and the user of the link shouldn't know the passwords of the link or  be able to get into our remote system if they ever got into our building and had access to our PC's
0
Comment
Question by:7Souls
1 Comment
 
LVL 73

Accepted Solution

by:
sdstuber earned 500 total points
ID: 21807395
it's not so much the link itself then as the user that will log into the database to use the link.
If they user can read sys.link$ then he/she can read the passwords.


Similarly, if the account on the remote system has extra privileges then don't let the user use that link at all.


the best way I know of is to create an unauthenticated link.


CREATE DATABASE LINK my_link  USING 'mydatabase';

this creates a private link, so it's only usable to the owner if the user you're interested in isn't the owner, then he/she can't use it.

if you want them to use it, then create it public, or create it under that user's schema.


With a database link like that,  you see it has no user or password.  In that case.  when you use the link  the current users' username and password are sent to the remote system.  So  the user logs in as themself and only as themself.   So they have only the permissions they have if they were to log in to the remote system directly.  If that's no permissions at all, then the link won't work for them.






0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
T-SQL Convert to PL/SQL 23 77
Encryption Decryption in Oracle 12 102
What is the version of ojdbc6.jar 2 37
grouping on time windows 6 41
Working with Network Access Control Lists in Oracle 11g (part 2) Part 1: http://www.e-e.com/A_8429.html Previously, I introduced the basics of network ACL's including how to create, delete and modify entries to allow and deny access.  For many…
I remember the day when someone asked me to create a user for an application developement. The user should be able to create views and materialized views and, so, I used the following syntax: (CODE) This way, I guessed, I would ensure that use…
This video shows how to copy a database user from one database to another user DBMS_METADATA.  It also shows how to copy a user's permissions and discusses password hash differences between Oracle 10g and 11g.
This video shows how to Export data from an Oracle database using the Datapump Export Utility.  The corresponding Datapump Import utility is also discussed and demonstrated.

929 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

8 Experts available now in Live!

Get 1:1 Help Now