MSAMM
Back to course

Oracle Apps DBA: Keeping E-Business Suite Alive · Module 15 · Security, credentials and audit

The credential in the context file

Lesson 154 of 184 · 3 min · Free preview

Passwords in configuration files, in scripts, in shell history and IN YOUR OWN TERMINAL SCROLLBACK. Where they end up, and how to stop putting them there. The APPS password is the most valuable credential in an EBS estate, and the estate leaks it in about six places by default. CONFIGURATION FILES ARE THE FIRST AND THE ONE PEOPLE KNOW ABOUT. Credentials appear in generated configuration, and those files are readable by more accounts than anybody assumes. Check the permissions on your own estate rather than trusting the defaults — a world-readable configuration file is Lesson 9's second finding. SCRIPTS ARE THE SECOND AND THE WORST, BECAUSE THEY GET COPIED. A password in a shell script is a password in every backup of that file system, in every clone, in every copy somebody took to a laptop, and possibly in a source repository. Module 12 Lesson 2 of the OIC course

This lesson is free

Watch the full lesson, with its written notes, without an account. It is one of the free lessons this course opens with.

Watch the full lesson

Get the free lessons by email

We will email you a link to every free lesson in this course. No account needed, and one message only.

In this module: Module 15 · Security, credentials and audit

  1. 1What you are actually holding
  2. 2The default accounts
  3. 3The credential in the context fileFree preview
  4. 4Changing the passwords that matter
  5. 5Least privilege for a DBA team
  6. 6Auditing: what to record and what it costs
  7. 7Encryption, in transit and at rest
  8. 8Network exposure
  9. 9What breaks: four security findings
  10. 10Lab briefing · Audit an estate you did not build