Security :: Modify Profile To Use Old Password?
			Aug 23, 2010
				I have a database in which a user xxxx is assigned a password  'bbbbb'.I want to change the password to the one which was used before which was 'aaaaa'.But when I change the password it was saying "Password cannot be Reused".So I checked in user profile and found out that password_reuse_time=unlimited and password_reuse_max=5.
  So what I did was change the password 6 times to something else(Since it is 5) and then tried changing it to 'aaaaa' but still it is saying "Old password cannot be reused".
	
	View 3 Replies
  
    
	ADVERTISEMENT
    	
    	
        Dec 5, 2011
        I've created a password verification function (verify_pwd) in a schema which is not in SYS, but an equivalent of SYS. However, the problem arises when I'm trying to create a profie (MAIN_PROFILE) with the following attributes :
CREATE PROFILE MAIN_PROFILE LIMIT
PASSWORD_LIFE_TIME 90
PASSWORD_VERIFY_FUNCTION verify_pwd;
The above script is resulting in an error.
ORA-02376 : invalid or redundant resource...Can I create the function verify_pwd not in the schema SYS but instead in a schema equivalent to SYS?
	View 3 Replies
    View Related
  
    
	
    	
    	
        Jun 5, 2012
        I want to know what if any person don't know the password of SYS, can he create password file, becauase i dont know the password of sys users, generally login with '/ as sysdba', 
	View 4 Replies
    View Related
  
    
	
    	
    	
        Nov 16, 2010
        Lost Windows password? Forgot Windows password? Your PC was hacked? Therefore, it is a basic step for every Windows users to enhance the security of Windows password. In the networks, it is found that a number of user's passwords are easy to guess. Only the smallest groups are the most security conscious and select passwords that are mixed lowercase and uppercase letters, numbers and punctuation to create cryptic passwords. Adopting strong password is one of the most effective ways to ensure system security. Here are several methods for you to enhance the security of your passwords in Windows 7/2000/XP/Vista and so on. You'd better remember the methods below unless you want to reset Windows password from time to time.
1. Is random password a great password?
A common myth is that totally random passwords like Ht3&e#L%5d@$B are the best passwords. This is not true. While they may be strong passwords, they are usually difficult to remember, slow to type, and sometimes vulnerable to attacks against the password generating algorithm. It is easy to create passwords that are strong but much easier to remember by using a few simple techniques. For example, consider the password "Luck-73@Better?". This password utilizes uppercase and lowercase letters, two numbers, and three symbols. The password is 15 characters long and can be memorized with very little effort. Moreover, this password can be typed very fast. The portion"Luck" and "Better" alternate between left and right-handed keys on the keyboard, improving speed, decreasing typos, and decreasing the chances of someone being able to discover your password by watching you.
2. Create the long Windows password
Although a password may eventually be discovered through some means, it is possible to create a password that cannot be cracked in any reasonable time. If a password is long enough, it will take so long or require so much processing power to crack it. That is essentially the same as being unbreakable (at least for most hackers).
3. Create the Windows password constantly?
This may be good advice for some high-risk passwords, but it is not the best policy for every user. It is frustrating for a user to have to constantly think of and remember new passwords every 30 days. It may be better to focus on stronger passwords and better user awareness rather than limiting password age. A more realistic time for the common user may be 90-120 days.
4. Write down Windows password in a proper place
Sometimes it is necessary for some users losing and forgetting complex passwords easily to write down them somewhere proper. However, it is important to educate users on how to write down passwords properly. Obviously, a sticky note on the monitor is not a good idea, but storing passwords in a safe or even a locked cabinet may be sufficient.
5. 14 characters is the optimal password length
Each character that you add to your password increases the protection. Your passwords should be 8 or more characters in length; 14 characters or longer is the Optimal Password Length. Many systems also support use of the space bar in passwords, so you can create a phrase made of many words. It is not easier to forget and lose, as well as longer than a simple password, and harder to guess.
6. Try not to use the same Windows password for all accounts
Some users always make the same passwords for every account to make it easy to remember. In that case, when any one of them lost, your other information protected by that password will be in danger as well. It is serious to use different passwords for different systems and accounts.
7. Do not use some common words that other users maybe guess
Most of users prefer to use some common words to remember easily, for example, login name, birth date, driver's license, passport number, pets' name and other words contained their personal information someone knows. In that case, your Windows system will not be safe anymore. Moreover, do remember not to use some words spelled backwards, abbreviations, sequences or repeated characters and adjacent letters, such as, asdfgh, 123456, 888888, abcdef and so on.
You can smoothly use your Windows now because the strong and powerful Windows password is created successfully, Certainly, I believe that many users lost Windows password and forgot Windows password, then you need have to reset Windows password or recover Windows password. It is a big problem for plenty of Windows users that how to reset Windows password. how to recover Windows password and they are puzzled by resetting windows password, for instance, reset Windows 7 password, recover password Windows XP, remove Windows Vista password and other operating systems after they create the password with complex letters, numbers and symbols. However, it is unnecessary to worry and it is said that things will eventually sort themselves out. There are many ways to reset forgotten Windows password, including use windows password reset disk and windows password reset software, like  Super Windows Password Reset, a professional windows password reset software which could enable you to logon to Windows smoothly without reinstalling system. 
	View 1 Replies
    View Related
  
    
	
    	
    	
        Oct 18, 2011
        I am using 'Novell Sentinel Log Manager' to collect/fetch logs from my Oracle 11g R2.To enable auditing, first I did following:
login as sys, then
SQL> create user testuser identified by "testuser";
SQL> grant connect to testuser
SQL> grant dba to sharf
SQL> grant CREATE SESSION to testuser;
SQL> grant select on v_$session to testuser;
SQL> grant select on v_$version to testuser;
SQL> grant select on SYS.DBA_AUDIT_TRAIL to testuser;
SQL> grant select_catalog_role to testuser;
SQL> grant select any dictionary to testuser;
Now logon/logof of user 'testuser' are logged , as well as if testuser drops a table or creates a table, its also logged . but when 'testuser' insert a new record, this information does not logged ;( while I need to know exactly what was added SQL> insert into emp (empid, name, salary) values (10002, 'Ron', 6000)
likewise if 'testuser' modify/update an existing record it also does not logged.
SQL> update emp set salary=700 where empid=10001;
which sql statements I have to execute to start auditing 'insert' and 'update', so that I know what was added/inserted and exactly what was updated/ changed/modify by user 'testuser'.
	View 12 Replies
    View Related
  
    
	
    	
    	
        Aug 25, 2010
        I am trying to create a custom package that creates users as well as modify user information in OID using DBMS_LDAP package. I was able to create the package but I am stuck on specifying the orcladmin password for the procedure DBMS_LDAP.simple_bind_s(my_session,'orcladmin','orcladminpwd');
I need to get the orcladmin password dynamically. Is there a way to achieve this? 
We are planning to provide our application users the ability to add new users / modify their own OID information.
	View 2 Replies
    View Related
  
    
	
    	
    	
        Mar 7, 2012
        i have created a database on my pc and i have given a password at the time of installation , after the installation  it is accessed successfully by the given password , but i observed that when i gave anything in password then it is also accessed by it and i don't have any other database of this same name.
And when i access it through another system then it is accessed only by its original password not by any other password.
	View 7 Replies
    View Related
  
    
	
    	
    	
        Jun 2, 2011
        how to see password  of users in 11g
	View 11 Replies
    View Related
  
    
	
    	
    	
        Oct 25, 2011
        I'm working for a credit card company and on a security project.  We have oracle databases.  Currently the passwords have to be changed every so often for key accounts for security purposes. Any tool to automate the process?
Any way to automate password changes on many accounts where only some people would be able to get the new password once it was changed.
Also, these IDs/passwords are sometimes used by applications to connect to the database so .ini files or some type of connection file would need to be changed automatically also.
	View 2 Replies
    View Related
  
    
	
    	
    	
        Nov 11, 2011
        i am using a oracle server. And all my users password has been expired, is there any way to recover those users without failing my data.
	View 19 Replies
    View Related
  
    
	
    	
    	
        Feb 6, 2011
        I have following problem I have simple script in bash where I connect to db and launch simple select. 
username:$(value)@host...
Problem is that i want to hide the password or encrypt. currently as you can see Iam using  variable (value) where the password is keep. the problem is that, mentioned script is launched by many people which are using the same user (monitor). the variable is read from a file where user (monitor ) has access its in the same directory.
is there any way how to solve it ? 
for e.g. 
1. to put the file with password in another folder where the user (monitor) has no access to see the file.
2. to decrypt the password, but I have no clue how to do it .
	View 23 Replies
    View Related
  
    
	
    	
    	
        May 6, 2013
        We have a requirement that the password of users never expire. But the user is notified when the password has not been changed for a long time. For example: If the user has not changed his password in 100days, he is to be notified that the password is old and he should consider changing it.
Is this possible directly through the password policy configurations? Or will it have to be handled using a separate procedure?
	View 9 Replies
    View Related
  
    
	
    	
    	
        Oct 10, 2011
        While searching for password encryption I came across these statements.
1.Password Encryption While Connecting. This protection is always in force, by default. Passwords are always automatically and transparently encrypted during network (client/server and server/server) connections, using a modified DES (Data Encryption Standard) or 3DES algorithm, before sending them across the network. 
Confirm whether by default oracle encrypts the password before sending it to the database across the network even when the clear text password is used for connecting from a jdbc client.
	View 1 Replies
    View Related
  
    
	
    	
    	
        Oct 15, 2010
        Is it possible to track the password changes made by some user using the logminer with the archived logs?
	View 1 Replies
    View Related
  
    
	
    	
    	
        Aug 31, 2010
        We currently hardcode the password inside our Java application to make the connection with the Database,this makes the password to be visible to all users who can read the application code. How can we encrypt the database password so we don't have to hardcode it into the application?
	View 1 Replies
    View Related
  
    
	
    	
    	
        Jan 5, 2013
        What is happening here:
c:usersjohnhome>
c:usersjohnhome>orapwd file=%ORACLE_HOME%databasePWDorcl.ora password=oracle
c:usersjohnhome>sqlplus sys/garbage@orcl as sysdba
SQL*Plus: Release 11.2.0.3.0 Production on Sat Jan 5 18:25:06 2013
Copyright (c) 1982, 2011, Oracle.  All rights reserved.
Connected to:
Oracle Database 11g Enterprise Edition Release 11.2.0.3.0 - Production
With the Partitioning, Oracle Label Security, OLAP, Data Mining,
Oracle Database Vault and Real Application Testing options
orcl> sho user
USER is "SYS"
orcl> select sys_context('userenv','ip_address') from dual;
SYS_CONTEXT('USERENV','IP_ADDRESS')
---------------------------------------------------------------------------------------------------
127.0.0.1
orcl>Why can I get a sys login, when I am connecting through the listener and giving an incorrect password? The listening address is a loopback address, is Oracle clever enough to realize that I am in fact logged on to the server as a member of the OSDBA group? I didn't think that information was passed through SQL*Net.
	View 3 Replies
    View Related
  
    
	
    	
    	
        Jan 8, 2013
        where do I find a list or a description of allowed characters for a 10g password?
	View 8 Replies
    View Related
  
    
	
    	
    	
        Mar 17, 2013
        I see the following  in dba_users.
select username,account_status,EXPIRY_DATE from dba_users;
USERNAME   ACCOUNT_STATUS  EXPIRY_DATE
-------------------------------------------------
DEMO       EXPIRED(GRACE)  2013-03-20 10:52:48
My question here is what if we dont reset the password by 20th of March.Will we not be able to reset the password once the password is expired ?
	View 4 Replies
    View Related
  
    
	
    	
    	
        Jul 7, 2011
        I want to create oracle user with non expiring password or i want to create one oracle user and set the password as non expiring.
	View 9 Replies
    View Related
  
    
	
    	
    	
        Apr 24, 2011
        oracle version oracle 10gr2
os: windows 64
from [URL] How to I use secure external password in asp.dot net or c# dot net with reference to [URL]
I've created the wallet, but then how apply it in dot net context?
string connectionString = "Data Source=ARK2;User ID=scott; Password=tiger";
suppose I created a  secure db connect string, what should be user id and password?
Is it user id="" password=""
or user_id ="/" password=""
	View 2 Replies
    View Related
  
    
	
    	
    	
        Nov 28, 2011
        i create password file in oracle 10g now i want to Set the EXCLUSIVE to REMOTE_LOGIN_PASSWORD initialization parameter. so what should i do.
	View 5 Replies
    View Related
  
    
	
    	
    	
        Aug 27, 2012
        i forget my system password  and i can't login to my database,and its not letting me in as sys/manager as sysdba...how to generate new user and password....
	View 13 Replies
    View Related
  
    
	
    	
    	
        Nov 28, 2011
        I want to create password file in Oracle 10g, setp to create password file.
	View 5 Replies
    View Related
  
    
	
    	
    	
        Nov 10, 2010
        Is there a way to see who or when password was changed for SYS or SYSTEM account?
	View 4 Replies
    View Related
  
    
	
    	
    	
        Aug 29, 2013
        Our Audit Company has given us a recommendation:"Old DB Link encrypted Passwords: The password of the Oracle databases links are encrypted using DES (password starts with 05). This encryption methord is known and users can decrypt the passwords using a simple SQL query. Please recreate the database links to use the new encryption method (password starts with 06)."What does it mean and how can we perform this recommendation?
	View 2 Replies
    View Related
  
    
	
    	
    	
        Dec 14, 2011
        We have a production database on 11.2.0.2 version. The application user was prompted to change the password after his password expired.
USERID                         NTIMESTAMP#                                                                    ACTION# RETURNCODE
------------------------------ --------------------------------------------------------------------------- ---------- ----------
M500796                        13-DEC-11 06.11.06.065209 PM                                                       100      28001
After changing the password he is not able to logon. The aud$ table does not show any occurrence of 1017, therefore it is not a question of Invalid password.
LVV> show parameter  SEC_CASE_SENSITIVE_LOGON
NAME                                 TYPE        VALUE
------------------------------------ ----------- ------------------------------
sec_case_sensitive_logon             boolean     FALSE
	View 2 Replies
    View Related
  
    
	
    	
    	
        Aug 23, 2010
        We have enable the alter log for audit purpose so the password will be display in the log which is not security. I try to use "password" to change password but very user got the error below. 
SQL> password
Changing password for RUDEE
Old password:
New password:
Retype new password:
ERROR:
ORA-00604: error occurred at recursive SQL level 1
ORA-20014: -6502 ORA-06502: PL/SQL: numeric or value error
ORA-06512: at line 27
Password unchanged
	View 17 Replies
    View Related
  
    
	
    	
    	
        Apr 14, 2011
        I'm trying to hide the password for the batch programs that connect to the DB Server
as Cadot pointed out in 
[URL].........
Quote:
use secure external password store
with reference to 
[URL].........
when I create wallet, the system does not prompt me for password
C:>mkstore -wrl "C:ora102NETWORKADMIN" -create
when creating login credentials, again the system never prompts me for password
C:>mkstore -wrl "C:ora102NETWORKADMIN" -createCredential db10g scott tiger
here's my sqlnet.ora configurations
WALLET_LOCATION =
(SOURCE =
(METHOD = FILE)
(METHOD_DATA =
(DIRECTORY =C:ora102NETWORKADMIN)
 )
 )
SQLNET.WALLET_OVERRIDE = TRUE
SSL_CLIENT_AUTHENTICATION = FALSESSL_VERSION = 0
here's my tnsname.ora settings
DB10G =
(DESCRIPTION =
(ADDRESS_LIST =
(ADDRESS = (PROTOCOL = TCP)(HOST = localhost)(PORT = 1521))
)
(CONNECT_DATA =
(SERVER = DEDICATED)
(SERVICE_NAME = mike)
)
)
here's the outcome
C:Documents and SettingsAdministrator>sqlplus /@db10g
SQL*Plus: Release 10.2.0.4.0 - Production on Wed Apr 13 22:53:06 2011
Copyright (c) 1982, 2007, Oracle.  All Rights Reserved.
ERROR:
ORA-12534: TNS:operation not supported
Enter user-name:
so I Google around for the solution to the ORA-12534 error, one of the site, 
[URL].......
here's my lsnrctl services
Connecting to (ADDRESS=(PROTOCOL=tcp)(HOST=)(PORT=1521))
Services Summary...
Service "MIKEXDB" has 1 instance(s).
Instance "mike", status READY, has 1 handler(s) for this service...
Handler(s):
[code].....     
The command completed successfully
right now I think I will be a fool to think that the solution is to resolve the ERROR: ORA-12514: TNS:listener does not currently know of service requested in connect descriptor. so what is wrong with my setup, or is it some patch that I need to apply? 
	View 9 Replies
    View Related
  
    
	
    	
    	
        Jul 16, 2011
        When i try to change the user account password, i get following error.
alter user bala
identified by Ju4hlsd2;
ERROR at line 1:
ORA-20178: ORA-20176: ORA-28003: password verification for the specified password failed
ORA-20007: Password cannot consist of sequences of 3+ characters from the userid
how to set the password based on the error.
	View 5 Replies
    View Related
  
    
	
    	
    	
        Jul 2, 2011
        I am not able to login in the database with sys user. when i am trying with sqlplus "/as sysdba" it is showing
ERROR: ORA-01031: insufficient privileges.
& when i am trying with sqlplus sys as sysdba it is showing 
ERROR:ORA-01017: invalid username/password; logon denied.
I login with system user and changed the password of sys nd then tried login with sys but same result.
remote_login_passwordfile is set to NONE nd i am login through that user only by which i was always able to login.
	View 23 Replies
    View Related