Mailing List
Home
Forum Home
Oracle List - by freelists.org
Oracle on SUSE Linux - Runing Oracle on SUSE Linux
Oracle database error code ...
www.freelists.org
Subjects
ORA 12540: TNS:internal limit restriction exceeded
ORA 12838 please : Is possible to append two times to the same table befo
ORA 12838 please : Is possible to append two times to the same table before
ora 04031
ora 12500 on windows
ORA 32004: obsolete and/or deprecated parameter(s) specified
ORA 01925: maximum of 30 enabled roles exceeded
ORA 01925: maximum of 30 enabled roles exceeded
ora 12500 on windows
ORA 01650, one idea
ORA 01650
ORA 4030
ORA 12838 please : Is possible to append two times to thesametable before do
ORA 12838 please : Is possible to append two times to thesame table before d
ORA 01536
ORA 03113 end of file on communication channel
ORA 32004: obsolete and/or deprecated parameter(s) specified
ORA 00600:
ORA 00020: maximum number of processes (%s) exceeded
ORA 01925: maximum of 30 enabled roles exceeded
ORA 3113 while creating a cluster database 9201 RAC on Linux with OCFS
ora 12500 on windows
ora 12500 on windows
ora 12500 on windows
ORA 01650, one idea
ora 12500 on windows
ora 12500 on windows
ora 12500 on windows
ORA 2000 Error Using DBMS STATS GATHER SCHEMA STATS
ORA 01650, one idea
ORA 01650, one idea
ORA 01650, one idea
ORA 01650
ORA 01650
Subject: ora 01031
ORA 4030
ORA 4030
ORA 06502: PL/SQL: numeric or value error: Bulk Bind: Truncated Bind
Subject: Re: ORA 01722 invalid number
 
Subject: Re: Auditing DBA privs

Subject: Re: Auditing DBA privs

2007-10-03       - By mkb

 Back
Steve,

I would start by looking at the database-stig-v7r2.pdf which is available for
download from iase.disa.mil/stigs/stig/database-stig-v7r2.pdf .  

Specifically, section 4 titled Database Auditing and B.14 Auditing in Oracle
should get you started.

This document outlines the Security Technical Implementation Guide (STIG)
process that many systems in federal agencies and the DOD have to go through
before a system can get accredited and be put on a live network.  The
recommendations in the database STIG should be sufficient to keep the IG off of
you backs.

In our setup, we have audit_sys_operations = true and set audit_trail=db.  I
don't have access to the system otherwise I would have attached a file listing
of the audit options that we have turned on (see section B.14 in the STIG guide
).

hth

--
mohammed



-- -- Original Message ----
From: "Smith, Steven K - MSHA" <Smith.Steven@(protected)>
To: oracle-l <oracle-l@(protected)>
Sent: Wednesday, October 3, 2007 11:15:18 AM
Subject: Auditing DBA privs


The Inspector General office is breathing down our necks here and is requesting
that we audit all activities performed by anyone with DBAish role privs.  We
are currently on version 9i and are currently using the ?soon to be
discontinued? DBA role.

At first glance, it appears that this would be simple.  I?ve started looking
into this and have found that ?audit DBA on session? isn?t going to do the
trick because of the limitations/bugs in the execution of that statement.  I
guess that auditing DBA really isn?t auditing everything that someone with the
DBA role does.  This is turning into the 300 lb gorilla.

Anyway ? I?m looking into setting up auditing for everything defined in the dba
_sys_privs view that is granted to DBA.  That should get a large majority of the
specific DBAish commands, but it will also get ?create sequence?, ?create view?
, etc.  Those are not DBA specific roles and those are not commands that can
only be executed by someone with DBA privileges.  HHmm?

Does anyone have experience in 9i auditing the commands of userids with DBA
role assigned to them?  Has anyone gone through this exercise before and is
willing to share their experiences and pitfalls?

I know that I?m potentially looking at a lot of data in the AUD$ table ?
managing it and reporting it is going to be a fun project in itself, but first
things first.

Thanks

Steve Smith
Desk: 303-231-5499
Fax: 303-231-5696


     __ ____ ____ ____ ____ ____ ____ ____ ____ ____ ____ ____ ____ ____ _____
__ ____ ___
Check out the hottest 2008 models today at Yahoo! Autos.
http://autos.yahoo.com/new_cars.html
<html><head><style type="text/css"><!-- DIV {margin:0px;} --></style></head>
<body><div style="font-family:times new roman, new york, times, serif;font-size
:12pt"><DIV style="FONT-SIZE: 12pt; FONT-FAMILY: times new roman, new york,
times, serif">Steve,</DIV>
<DIV style="FONT-SIZE: 12pt; FONT-FAMILY: times new roman, new york, times,
serif">&nbsp;</DIV>
<DIV style="FONT-SIZE: 12pt; FONT-FAMILY: times new roman, new york, times,
serif">I would start by looking at the database-stig-v7r2.pdf which is
available for download from <SPAN class=a><FONT size=2><FONT size=3>iase.disa
.mil/stigs/stig/database-stig-v7r2.pdf</FONT> .&nbsp; </FONT></SPAN></DIV>
<P><SPAN class=a><FONT size=2></FONT></SPAN>&nbsp;</P>
<P><SPAN class=a>Specifically, section 4 titled Database Auditing and B.14
Auditing in Oracle should get you started.</SPAN></P>
<P><SPAN class=a></SPAN>&nbsp;</P>
<P><SPAN class=a>This document outlines the Security Technical Implementation
Guide (STIG) process that many systems in federal agencies and the DOD have to
go through before a system can get accredited and be put on a live network.
&nbsp; The recommendations in the database STIG should be sufficient to keep the
IG off of you backs.</SPAN></P>
<P><SPAN class=a></SPAN>&nbsp;</P>
<P><SPAN class=a>In our setup, we have audit_sys_operations = true and set
audit_trail=db.&nbsp; I don't have access to the system otherwise I would have
attached a file listing of the audit options that we have turned on (see
section B.14 in the STIG guide).</SPAN></P>
<P><SPAN class=a></SPAN>&nbsp;</P>
<P><SPAN class=a>hth</SPAN></P>
<P><SPAN class=a></SPAN>&nbsp;</P>
<P><SPAN class=a>--</SPAN></P>
<P><SPAN class=a>mohammed</SPAN></P>
<DIV style="FONT-SIZE: 12pt; FONT-FAMILY: times new roman, new york, times,
serif"><BR><BR></DIV>
<DIV style="FONT-SIZE: 12pt; FONT-FAMILY: times new roman, new york, times,
serif">-- -- Original Message ----<BR>From: "Smith, Steven K - MSHA" &lt;Smith
.Steven@(protected)&gt;<BR>To: oracle-l &lt;oracle-l@(protected)&gt;<BR>Sent:
Wednesday, October 3, 2007 11:15:18 AM<BR>Subject: Auditing DBA privs<BR><BR>
<STYLE>
<!--
_filtered {font-family:"Book Antiqua";panose-1 (See http://ose-1.ora-code.com):2 4 6 2 5 3 5 3 3 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
  {margin:0in;margin-bottom:.0001pt;font-size:12.0pt;font-family:"Book Antiqua";}
a:link, span.MsoHyperlink
  {color:blue;text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
  {color:#606420;text-decoration:underline;}
span.EmailStyle17
  {font-family:Arial;color:windowtext;font-weight:normal;font-style:normal;text
-decoration:none none;}
_filtered {margin:1.0in 1.25in 1.0in 1.25in;}
div.Section1
  {}
-->
</STYLE>

<DIV class=Section1>
<P class=MsoNormal><FONT face=Arial><SPAN style="FONT-SIZE: 12pt; FONT-FAMILY:
Arial">The Inspector General office is breathing down our necks here and is
requesting that we audit all activities performed by anyone with DBAish role
privs.&nbsp; We are currently on version 9i and are currently using the ?soon
to be discontinued? DBA role.</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial><SPAN style="FONT-SIZE: 12pt; FONT-FAMILY:
Arial">&nbsp;</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial><SPAN style="FONT-SIZE: 12pt; FONT-FAMILY:
Arial">At first glance, it appears that this would be simple.&nbsp; I?ve
started looking into this and have found that ?audit DBA on session? isn?t
going to do the trick because of the limitations/bugs in the execution of that
statement.&nbsp; I guess that auditing DBA really isn?t auditing everything
that someone with the DBA role does.&nbsp; This is turning into the 300 lb
gorilla.</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial><SPAN style="FONT-SIZE: 12pt; FONT-FAMILY:
Arial">&nbsp;</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial><SPAN style="FONT-SIZE: 12pt; FONT-FAMILY:
Arial">Anyway ? I?m looking into setting up auditing for everything defined in
the dba_sys_privs view that is granted to DBA.&nbsp; That should get a large
majority of the specific DBAish commands, but it will also get ?create sequence
?, ?create view?, etc.&nbsp; Those are not DBA specific roles and those are not
commands that can only be executed by someone with DBA privileges.&nbsp; HHmm?<
/SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial><SPAN style="FONT-SIZE: 12pt; FONT-FAMILY:
Arial">&nbsp;</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial><SPAN style="FONT-SIZE: 12pt; FONT-FAMILY:
Arial">Does anyone have experience in 9i auditing the commands of userids with
DBA role assigned to them?&nbsp; Has anyone gone through this exercise before
and is willing to share their experiences and pitfalls?</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial><SPAN style="FONT-SIZE: 12pt; FONT-FAMILY:
Arial">&nbsp;</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial><SPAN style="FONT-SIZE: 12pt; FONT-FAMILY:
Arial">I know that I?m potentially looking at a lot of data in the AUD$ table ?
managing it and reporting it is going to be a fun project in itself, but first
things first.</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial><SPAN style="FONT-SIZE: 12pt; FONT-FAMILY:
Arial">&nbsp;</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial><SPAN style="FONT-SIZE: 12pt; FONT-FAMILY:
Arial">Thanks</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial><SPAN style="FONT-SIZE: 12pt; FONT-FAMILY:
Arial">&nbsp;</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial><SPAN style="FONT-SIZE: 12pt; FONT-FAMILY:
Arial">Steve Smith</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial><SPAN style="FONT-SIZE: 12pt; FONT-FAMILY:
Arial">Desk: 303-231-5499</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial><SPAN style="FONT-SIZE: 12pt; FONT-FAMILY:
Arial">Fax: 303-231-5696</SPAN></FONT></P>
<P class=MsoNormal><FONT face="Book Antiqua"><SPAN style="FONT-SIZE: 12pt">
&nbsp;</SPAN></FONT></P></DIV></DIV>
<DIV style="FONT-SIZE: 12pt; FONT-FAMILY: times new roman, new york, times,
serif"><BR></DIV></div><br>
     <hr size=1>Need a vacation? <a href="http://us.rd.yahoo.com/evt=48256/
*http://travel.yahoo.com/;_ylc
=X3oDMTFhN2hucjlpBF9TAzk3NDA3NTg5BHBvcwM1BHNlYwNncm91cHMEc2xrA2VtYWlsLW5jbQ--"
>Get great deals
to amazing places </a>on Yahoo! Travel. </body></html>