Wednesday, September 4, 2024

Authentication enhancements in Oracle 23c

Oracle 23c offers longer passwords improved security in authentication now supports up to 1024 bytes

• Oracle Data pump Export and import support longer encryption passwords up to 2024 bytes long
• Oracle Call interface (OCI) and Oracle C++ Call interface support up to 1024 bytes long password for user authentication.
• JDBC think driver support up to 1024 characters for password
• Oracle Database (including Autonomous) and clients supports password up to 1024 bytes

You can login into Oracle Database using Microsoft Azure Active Directory single sing-on OAuth2 access token. Multicloud feature integrates Oracle Database and Azure AD and you can perform this integration on

• Oracle 19.16 and later (Back ported) but not for Oracle 21c.
• Oracle Autonomous Database on Dedicated/Shared Exadata Infrastructure
• Oracle Exadata Clod Service
• Oracle Base Database Service

You can map AD users to Oracle Database schema and roles and also you can login ODP.NET can login into Oracle Database Using Microsoft Azure Active Directory. The UTL_HTTP support SHA-256/512 and XDB HTTP supports SHA512, authentication and updated Kerberos Library support.

The password length helps accommodating Oracle Identity Access management (IAM) and Identity Cloud service (IDCS) and helps enabling uniform password rules.

Oracle 23c offers many Improvements in Kerberos security and MIT Kerberos version 1.20.1 supports cross domain, windows credential guard and multiple principals.

KERBEROS5_CC_NAME and KERBEROS5_PRINCIPAL can be specified in tnsnames.ora and the values must match for user authentication.

kuser =
(DESCRIPTION=(ADDRESS=(PROTOCOL=tcp)(HOST=orahost)(PORT=1521)) (CONNECT_DATA=(SERVICE_NAME=ORCL))
(SECURITY=(KERBEROS5_CC_NAME = /tmp/kuser/krb.cc) (KERBEROS5_PRINCIPAL = kprinc)))

Kerberos parameters can be specified in Sqlnet.ora file but note that some parameters you can set at server level, and some are at client level and few you can set on both.

You can set below parameters on both client and server

SQLNET.AUTHENTICATION_SERVICES=(KERBEROS5)
SQLNET.AUTHENTICATION_KERBEROS5_SERVICE=oracle
SQLNET.KERBEROS5_CONF=<Kerberos_configfile_path >
SQLNET.KERBEROS5_CONF_MIT=(TRUE)
SQLNET.FALLBACK_AUTHENTICATION=FALSE
SQLNET.KERBEROS5_CLOCKSKEW=1200

The below parameter is not required on the server, but in case if your client in Microsoft Windows then you may want to consider setting OSMSFT:// or MSLSA
SQLNET.KERBEROS5_CC_NAME= <Kerberos_CC_name_withpath>

This setting is not usually required for the client or the server.
SQLNET.KERBEROS5_REALMS=<Kerberos_realms_path >
Only set this parameter on the server
SQLNET.KERBEROS5_KEYTAB=<Kerberos_keytab_path > 

Thanks & Regards,
https://oracleracexpert.com

8 comments:

  1. Oracle 23c has introduced impressive authentication enhancements designed to improve security and streamline user access. These updates make it easier for businesses to manage sensitive data while reinforcing robust access control mechanisms. With multi-factor authentication and advanced security protocols, Oracle 23c strengthens data protection against unauthorized access. For companies in fields like digital manufacturing or even PVC Patch Maker industries, these enhancements offer peace of mind knowing their critical data is secure. Oracle's focus on authentication advancements is a welcome addition for organizations prioritizing both innovation and data protection in today’s digital landscape.

    ReplyDelete
  2. Oracle 23c brings exciting authentication enhancements, strengthening database security and user management. For businesses seeking precision and quality in digitizing services, check out Hot Digitizing – your go-to for embroidery digitizing excellence!

    ReplyDelete
  3. Sprunki is a creative and interactive music-making game that has exploded in popularity across social media platforms.

    ReplyDelete
  4. Reminds me, back in my college days, I once locked myself out of a system because I fat-fingered a password reset; it was a nightmare sorting that out. Now that Slither io moment made me understand the need to memorize passwords.

    ReplyDelete
  5. 외출이 번거로운 날에도 편안한 시간을 보내고 싶다면 이런 형태의 서비스가 실용적일 것 같아요. 평택출장마사지 원하는 장소에서 이용할 수 있어 이동 시간을 아낄 수 있다는 점이 돋보입니다. 일정이 촘촘한 분들에게도 활용도가 높아 보입니다.

    ReplyDelete
  6. 상품권 거래는 편리함도 중요하지만 정확한 정보 확인이 기본이라는 점에 공감합니다. 상품권매입 관련 서비스를 이용하기 전에는 업체가 공개한 수수료와 지급 기준을 확인하고 개인정보 제공 범위까지 살펴보는 것이 안전한 거래에 도움이 되겠네요.

    ReplyDelete
  7. 외부로 이동하기 어려운 날에도 편하게 관리 시간을 마련할 수 있다는 점이 인상적입니다. 개인 일정에 맞춰 시간을 조정하기 쉽고 휴식 공간을 직접 선택할 수 있다는 점도 편리하네요. 수원출장마사지 효율적인 시간 활용을 원하는 분들에게 적합해 보입니다.

    ReplyDelete
  8. 활동량이 많은 날이나 장시간 업무로 몸이 지친 날 편안하게 쉬는 시간이 중요하다고 느낍니다. 출장마사지 익숙한 공간에서 받을 수 있어 심리적으로도 편안하고, 이동 부담을 줄이면서 휴식 시간을 효율적으로 활용할 수 있다는 장점이 있습니다.

    ReplyDelete