![Oracle英文版培訓(xùn)課件之Grid Control:les05Securing Grid Control_第1頁](http://file4.renrendoc.com/view/a8055d85fe3b7cab047e658c45b5ac4e/a8055d85fe3b7cab047e658c45b5ac4e1.gif)
![Oracle英文版培訓(xùn)課件之Grid Control:les05Securing Grid Control_第2頁](http://file4.renrendoc.com/view/a8055d85fe3b7cab047e658c45b5ac4e/a8055d85fe3b7cab047e658c45b5ac4e2.gif)
![Oracle英文版培訓(xùn)課件之Grid Control:les05Securing Grid Control_第3頁](http://file4.renrendoc.com/view/a8055d85fe3b7cab047e658c45b5ac4e/a8055d85fe3b7cab047e658c45b5ac4e3.gif)
![Oracle英文版培訓(xùn)課件之Grid Control:les05Securing Grid Control_第4頁](http://file4.renrendoc.com/view/a8055d85fe3b7cab047e658c45b5ac4e/a8055d85fe3b7cab047e658c45b5ac4e4.gif)
![Oracle英文版培訓(xùn)課件之Grid Control:les05Securing Grid Control_第5頁](http://file4.renrendoc.com/view/a8055d85fe3b7cab047e658c45b5ac4e/a8055d85fe3b7cab047e658c45b5ac4e5.gif)
版權(quán)說明:本文檔由用戶提供并上傳,收益歸屬內(nèi)容提供方,若內(nèi)容存在侵權(quán),請(qǐng)進(jìn)行舉報(bào)或認(rèn)領(lǐng)
文檔簡介
SecuringGridControlObjectivesAftercompletingthislesson,youshouldbeableto:DescribethesecurityoptionsavailableforOracleManagementServiceandOracleManagementAgentConfigureGridControlforusewithproxyserversandthroughfirewallsAuthenticateGridControladministratorsusingSingleSign-OnConfigureGridControlforusewithEnterpriseUserSecurityGridControlSecurityGridControlsecurityhastwoprimarygoals:EnsuringsecuretransferofdatabetweenGridControlcomponentsDenyingunauthorizedusersaccesstoGridControlmonitoringdataandadministrativecontrolsSecuringGridControlEnterpriseManagerFrameworkSecurityprovidessafeandsecurecommunicationbetweentheGridControlcomponentsthrough:WorkingwithsecurityfeaturesofOracleHTTPServerImplementingHTTPSandPublicKeyInfrastructure(PKI)componentsforcommunicationsbetweenOracleManagementService(OMS)andOracleManagementAgentsUsingOracleAdvancedSecurityforcommunicationsbetweenOMSandtheManagementRepositoryGridControlSecurityFrameworkGridControlSecurityFrameworkprovidessecure(encrypted)communicationbetweenGridControlcomponents:Agent<->OMSOMS<->RepositoryOHSWebCacheOC4JEMOMSEncryptedchannelEncryptedchannelVerifythatOracleManagementAgentsAreSecureManagingAgentRegistrationPasswordsUseGridControlto:ChangeagentregistrationpasswordsCreateorremoveadditionalregistrationpasswordsRefusingNonsecureUploadsConfigureOMStorefuseunencrypteduploads.StopallOMSservices.ConfigureOMStorefuseuploadsviaHTTP.StartallOMSservices.$emctlsecurelockSecuringOMS–RepositoryCommunicationTosecurecommunicationbetweentheOMSandrepository,enabletheOracleAdvancedSecurityOption(ASO)for:RepositoryOMSAgentmonitoringtherepositorydatabaseEnablingASOfortheRepositoryModifyORACLE_HOME/network/admin/sqlnet.ora
torequestencryption:SQLNET.ENCRYPTION_SERVERSQLNET.CRYPTO_SEEDOMRSQLNET.ENCRYPTION_SERVER=REQUESTEDSQLNET.CRYPTO_SEED="abcdefg123456789"EnablingASOforEachOMSASOfortheOMSisconfiguredthroughentriesinOMS_HOME/sysman/config/perties.StopandrestarttheOMStoimplementthenewparameters.oracle.sysman.emRep.dbConn.enableEncryption=TRUE.encryption_types_client=(DES40C).encryption_client=REQUESTEDEnablingASOfortheAgentCreateAGENT_HOME/network/admin/sqlnet.ora
asatextfilewiththefollowingentry:SQLNET.CRYPTO_SEEDSQLNET.CRYPTO_SEED="abcdefg123456789"SecuringApplicationServerControlStand-aloneApplicationServerControlconsolemayalsobeconfiguredforsecureoperation:Stopthestand-aloneconsole:emctlstopiasconsoleSecurethestand-aloneconsole:emctlsecureemStartthestand-aloneconsole:emctlstartiasconsoleEnablingEnterpriseManagerSecurityFrameworkToenableEnterpriseManagerSecurityFramework,thecomponentsmustbeconfiguredinaspecificorder:SecuretheOMS(donebydefaultinGridControlR2).ForeachOracleManagementAgent,stopit,secureit,andrestartit:
emctlstopagent
emctlsecureagent
emctlstartagentWhenallagentsaresecure,locktheOMS:
emctl
securelockConfiguringEnterpriseManagerforFirewallsBeforeconfiguringyourfirewall,considerthefollowing:ItshouldbethelastphaseoftheEnterpriseManagerdeployment.Forexistingfirewalls,opendefaultEnterpriseManagercommunicationportsuntiltheinstallationandconfigurationprocessesarecomplete.IfenablingEnterpriseManagerFrameworkSecurity,donotsecuretheagentsuntilyouconfirmthatHTTPandHTTPStrafficbetweentheagentandManagementRepositoryworks.AfterconfirmingthattheOMSandOracleManagementAgentscancommunicate,completethetransitionintosecuremodeandchangefirewallconfigurationasnecessary.FirewallConfigurationforGridControlComponentsFirewallsbetweenthebrowserandtheGridControlconsoleOracleManagementAgentprotectedbyafirewallManagementServiceprotectedbyafirewallFirewallsbetweentheManagementServiceandtheManagementRepositoryFirewallsbetweenGridControlandamanageddatabasetargetFirewallsusedwithmultipleManagementServicesFirewallstoallowICMPandUDPtrafficforbeaconsFirewallswhenmanagingOracleApplicationServerConfiguringtheAgentforProxyCommunicationToconfiguretheagentsothatitcommunicatesviaaproxyserver,performthefollowingsteps:StoptheOracleManagementAgent.AddproxyinformationtoAGENT_HOME/sysman/config/perties:REPOSITORY_PROXYHOSTREPOSITORY_PROXYPORTStarttheOracleManagementAgent.ProxyserverConfiguringtheOMSforProxyCommunicationToconfiguretheOMSsothatitcommunicatesviaaproxyserver,performthefollowingsteps:StoptheOMS.AddproxyinformationtoOMS_HOME/sysman/config/perties.StarttheOMS.OHSWebCacheOC4JEMOMSProxyserverAuthenticatingGridControlAdministratorsGridControladministratorsare:AuthenticatedasrepositorydatabaseusersCreatedandmanagedthroughtheGridControlconsoleIfdesired,administratorsmaybecreated,managed,andauthenticatedviaOracleSingleSign-On.OracleSingleSign-OnSingleSign-On(SSO)isacomponentofOracleApplicationServerthatenablesuserstologintoWebapplicationsbyusingasingleusernameandpassword.ConfiguringGridControltouseSingleSign-Onisatwo-stepprocess:ConfiguretheOMStouseSSO.AddGridControlusers.ConfiguringtheOMSforSSOToconfiguretheOMStouseSSO,performthefollowingsteps:StoptheOMS.ReconfiguretheOMStouseSSO.StarttheOMS.emctlconfigsso -–host<SSOServer> -–port<SSODBListenerPort> -–sid<SSODBSID> -–pass<DBpasswordfororasso> -–das<URLforOIDDASserver>OHSWebCacheOC4JEMOMSEnterpriseUserSecurityWithEnterpriseUserSecurity,databaseusersareauthenticatedthroughacentralizeddirectory.Insteadofstoringmanagementcredentialsforeachtargetdatabase,theOMSmaybeconfiguredtou
溫馨提示
- 1. 本站所有資源如無特殊說明,都需要本地電腦安裝OFFICE2007和PDF閱讀器。圖紙軟件為CAD,CAXA,PROE,UG,SolidWorks等.壓縮文件請(qǐng)下載最新的WinRAR軟件解壓。
- 2. 本站的文檔不包含任何第三方提供的附件圖紙等,如果需要附件,請(qǐng)聯(lián)系上傳者。文件的所有權(quán)益歸上傳用戶所有。
- 3. 本站RAR壓縮包中若帶圖紙,網(wǎng)頁內(nèi)容里面會(huì)有圖紙預(yù)覽,若沒有圖紙預(yù)覽就沒有圖紙。
- 4. 未經(jīng)權(quán)益所有人同意不得將文件中的內(nèi)容挪作商業(yè)或盈利用途。
- 5. 人人文庫網(wǎng)僅提供信息存儲(chǔ)空間,僅對(duì)用戶上傳內(nèi)容的表現(xiàn)方式做保護(hù)處理,對(duì)用戶上傳分享的文檔內(nèi)容本身不做任何修改或編輯,并不能對(duì)任何下載內(nèi)容負(fù)責(zé)。
- 6. 下載文件中如有侵權(quán)或不適當(dāng)內(nèi)容,請(qǐng)與我們聯(lián)系,我們立即糾正。
- 7. 本站不保證下載資源的準(zhǔn)確性、安全性和完整性, 同時(shí)也不承擔(dān)用戶因使用這些下載資源對(duì)自己和他人造成任何形式的傷害或損失。
最新文檔
- 《13潔凈的水域》說課稿-2023-2024學(xué)年科學(xué)六年級(jí)下冊(cè)蘇教版
- Unit 2 Months of a Year Lesson Three(說課稿)-2024-2025學(xué)年重大版英語六年級(jí)上冊(cè)
- Unit 6 Chores Lesson 4 Let's spell(說課稿)-2024-2025學(xué)年人教新起點(diǎn)版英語五年級(jí)上冊(cè)001
- 2025水泥磚銷售合同范文
- 2024年七年級(jí)數(shù)學(xué)下冊(cè) 第10章 一元一次不等式和一元一次不等式組10.4一元一次不等式的應(yīng)用說課稿(新版)冀教版
- 中型臭氧設(shè)備購買合同范例
- 8 安全地玩(說課稿)-部編版道德與法治二年級(jí)下冊(cè)
- 農(nóng)業(yè)設(shè)備供貨合同范例
- 冷庫設(shè)備購銷合同范例
- 個(gè)人借還款合同范例
- 大學(xué)生創(chuàng)新創(chuàng)業(yè)教程PPT全套完整教學(xué)課件
- 小學(xué)科學(xué)項(xiàng)目化作業(yè)的設(shè)計(jì)與實(shí)施研究
- 2023年考研考博-考博英語-西安建筑科技大學(xué)考試歷年真題摘選含答案解析
- 2020年中考生物試卷及答案
- 反接制動(dòng)控制線路電路圖及工作原理
- MCNP-5A程序使用說明書
- java基礎(chǔ)知識(shí)大全
- SMM英國建筑工程標(biāo)準(zhǔn)計(jì)量規(guī)則中文 全套
- GB 18030-2022信息技術(shù)中文編碼字符集
- SB/T 10977-2013倉儲(chǔ)作業(yè)規(guī)范
- 弘揚(yáng)中華傳統(tǒng)文化課件
評(píng)論
0/150
提交評(píng)論