<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Oracle 10.2 Migrations â€“ Account LOCKED(TIMED) and FAILED_LOGIN_ATTEMPTS</title>
	<atom:link href="http://www.pythian.com/news/284/oracle-102-migrations-%e2%80%93-account-lockedtimed-and-failed_login_attempts/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.pythian.com/news/284/oracle-102-migrations-%e2%80%93-account-lockedtimed-and-failed_login_attempts/</link>
	<description>News and views from Pythian DBAs</description>
	<lastBuildDate>Fri, 10 Feb 2012 13:01:25 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.4</generator>
	<item>
		<title>By: Laurent Schneider</title>
		<link>http://www.pythian.com/news/284/oracle-102-migrations-%e2%80%93-account-lockedtimed-and-failed_login_attempts/#comment-6494</link>
		<dc:creator>Laurent Schneider</dc:creator>
		<pubDate>Fri, 10 Nov 2006 09:16:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.pythian.com/blogs/284/oracle-102-migrations-%e2%80%93-account-lockedtimed-and-failed_login_attempts#comment-6494</guid>
		<description>yes, that&#039;s why I wrote that it is a bad practice to suppose the dbsnmp password is dbsnmp (well, the 10g agent works with 9i databases where it was default). So I guess the OEM team should update their security practices to be conform with the newest db releases !</description>
		<content:encoded><![CDATA[<p>yes, that&#8217;s why I wrote that it is a bad practice to suppose the dbsnmp password is dbsnmp (well, the 10g agent works with 9i databases where it was default). So I guess the OEM team should update their security practices to be conform with the newest db releases !</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alex Gorbachev</title>
		<link>http://www.pythian.com/news/284/oracle-102-migrations-%e2%80%93-account-lockedtimed-and-failed_login_attempts/#comment-6376</link>
		<dc:creator>Alex Gorbachev</dc:creator>
		<pubDate>Thu, 09 Nov 2006 13:36:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.pythian.com/blogs/284/oracle-102-migrations-%e2%80%93-account-lockedtimed-and-failed_login_attempts#comment-6376</guid>
		<description>Well, I don&#039;t recall that in 10g you have a default password, at least, in the installer. In fact, if I remember correctly, OUI does not allow setting it to DBSNMP manually (if I don&#039;t mistake it for something else).</description>
		<content:encoded><![CDATA[<p>Well, I don&#8217;t recall that in 10g you have a default password, at least, in the installer. In fact, if I remember correctly, OUI does not allow setting it to DBSNMP manually (if I don&#8217;t mistake it for something else).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Laurent Schneider</title>
		<link>http://www.pythian.com/news/284/oracle-102-migrations-%e2%80%93-account-lockedtimed-and-failed_login_attempts/#comment-6358</link>
		<dc:creator>Laurent Schneider</dc:creator>
		<pubDate>Thu, 09 Nov 2006 08:38:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.pythian.com/blogs/284/oracle-102-migrations-%e2%80%93-account-lockedtimed-and-failed_login_attempts#comment-6358</guid>
		<description>Alex, I could even say, it is a miserable strategy from Oracle to suppose the dbsnmp password could be dbsnmp, Oracle should not even allow this! as you install the agent, you should be forced to set the password for each target, the current approach &lt;i&gt;well, it is easier to set it to dbsnmp for auto-discovery&lt;/i&gt; is simply a huge security hole.

YMMV</description>
		<content:encoded><![CDATA[<p>Alex, I could even say, it is a miserable strategy from Oracle to suppose the dbsnmp password could be dbsnmp, Oracle should not even allow this! as you install the agent, you should be forced to set the password for each target, the current approach <i>well, it is easier to set it to dbsnmp for auto-discovery</i> is simply a huge security hole.</p>
<p>YMMV</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alex Gorbachev</title>
		<link>http://www.pythian.com/news/284/oracle-102-migrations-%e2%80%93-account-lockedtimed-and-failed_login_attempts/#comment-6293</link>
		<dc:creator>Alex Gorbachev</dc:creator>
		<pubDate>Wed, 08 Nov 2006 18:51:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.pythian.com/blogs/284/oracle-102-migrations-%e2%80%93-account-lockedtimed-and-failed_login_attempts#comment-6293</guid>
		<description>Laurent,
Good idea, Merci. But it should retry sooner or later anyway. Otherwise, it&#039;s a manual action.

Pete,
Thanks for your input. Fully agree with you and that why I mentioned reviewing security policies (or at least introduce some as there is often nothing to review). However, I believe that &lt;i&gt;migration projects should not include any additional tasks but bare minimum&lt;/i&gt;. Otherwise, it&#039;s too much troubles to troubleshoot what&#039;s going wrong during migration. What has more priority for the company - migration or security is another question. Often I see it&#039;s not in favor of security. :-(

Cheers guys.</description>
		<content:encoded><![CDATA[<p>Laurent,<br />
Good idea, Merci. But it should retry sooner or later anyway. Otherwise, it&#8217;s a manual action.</p>
<p>Pete,<br />
Thanks for your input. Fully agree with you and that why I mentioned reviewing security policies (or at least introduce some as there is often nothing to review). However, I believe that <i>migration projects should not include any additional tasks but bare minimum</i>. Otherwise, it&#8217;s too much troubles to troubleshoot what&#8217;s going wrong during migration. What has more priority for the company &#8211; migration or security is another question. Often I see it&#8217;s not in favor of security. :-(</p>
<p>Cheers guys.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pete Finnigan</title>
		<link>http://www.pythian.com/news/284/oracle-102-migrations-%e2%80%93-account-lockedtimed-and-failed_login_attempts/#comment-6272</link>
		<dc:creator>Pete Finnigan</dc:creator>
		<pubDate>Wed, 08 Nov 2006 12:07:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.pythian.com/blogs/284/oracle-102-migrations-%e2%80%93-account-lockedtimed-and-failed_login_attempts#comment-6272</guid>
		<description>Hi Alex,

I would not recommend setting it back to unlimited. In fact I disagree with Oracle&#039;s very conservative value of 10.  I would recommend creating different profiles for differnet groups of users, ie PROD accounts, DBA&#039;s, power users, users (if they connect directly), default accounts....

Each should have their own profile and differnt values. For instance failed_login_attempts should be much lower for accounts that are rarely directly accessed. Also the lock time for these should be much higher for the same reason. Even though Oracle have strengthened their default security position no one should rely on it. The security design should suit the application/ regulatory issues / internal policies always.

cheers

Pete</description>
		<content:encoded><![CDATA[<p>Hi Alex,</p>
<p>I would not recommend setting it back to unlimited. In fact I disagree with Oracle&#8217;s very conservative value of 10.  I would recommend creating different profiles for differnet groups of users, ie PROD accounts, DBA&#8217;s, power users, users (if they connect directly), default accounts&#8230;.</p>
<p>Each should have their own profile and differnt values. For instance failed_login_attempts should be much lower for accounts that are rarely directly accessed. Also the lock time for these should be much higher for the same reason. Even though Oracle have strengthened their default security position no one should rely on it. The security design should suit the application/ regulatory issues / internal policies always.</p>
<p>cheers</p>
<p>Pete</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Laurent Schneider</title>
		<link>http://www.pythian.com/news/284/oracle-102-migrations-%e2%80%93-account-lockedtimed-and-failed_login_attempts/#comment-6262</link>
		<dc:creator>Laurent Schneider</dc:creator>
		<pubDate>Wed, 08 Nov 2006 10:12:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.pythian.com/blogs/284/oracle-102-migrations-%e2%80%93-account-lockedtimed-and-failed_login_attempts#comment-6262</guid>
		<description>the fact that the OEM 10g agent is trying to log with DBSNMP/DBSNMP until the account is lock is a pity. After one  invalid password, Oracle should figure out we are NOT using the password DBSNMP for the account DBSNMP.</description>
		<content:encoded><![CDATA[<p>the fact that the OEM 10g agent is trying to log with DBSNMP/DBSNMP until the account is lock is a pity. After one  invalid password, Oracle should figure out we are NOT using the password DBSNMP for the account DBSNMP.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: vidya</title>
		<link>http://www.pythian.com/news/284/oracle-102-migrations-%e2%80%93-account-lockedtimed-and-failed_login_attempts/#comment-6209</link>
		<dc:creator>vidya</dc:creator>
		<pubDate>Tue, 07 Nov 2006 18:30:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.pythian.com/blogs/284/oracle-102-migrations-%e2%80%93-account-lockedtimed-and-failed_login_attempts#comment-6209</guid>
		<description>this is useful information - since I am on my way to a 10g Migration</description>
		<content:encoded><![CDATA[<p>this is useful information &#8211; since I am on my way to a 10g Migration</p>
]]></content:encoded>
	</item>
</channel>
</rss>

