Monday, May 22, 2023

Oracle Database Native Encryption

9:57 AM Posted by Dilli Raj Maharjan , No comments

    

     Encryption is the method to convert information into secret codes to protect from the bad guys. The real meaning of the information is hidden and the process of encrypting and decrypting data is called cryptography. The formulas used for cryptography are called encryption algorithms, or ciphers.

    Encryption plays a vital role in protecting information. It provides the following primary benefits.

  1. Confidentiality encodes the message's content.
  2. Authentication verifies the origin of a message.
  3. Integrity proves the contents of a message have remained the same since it was sent.
  4. Nonrepudiation prevents senders from denying they sent the encrypted message.

    Oracle database provides network encryption to protect data while traveling through the network. It offers native data network encryption and integrity to ensure that is secure from the bad guys. Oracle Native network encryption converts plaintext data into unintelligible ciphertext based on a key. In a symmetric cryptosystem, the same key is used both for encryption and decryption of the same data. Oracle Database provides the Advanced Encryption Standard (AES) symmetric cryptosystem for protecting the confidentiality of Oracle Net Services traffic.

    Oracle Database supports the Federal Information Processing Standard (FIPS) encryption algorithm, Advanced Encryption Standard (AES). AES is a highly supported algorithm all over the works. It defines three standard key lengths of 128-bit, 192-bit, and 256-bit.

    Encrypting network data provides data privacy so that unauthorized parties cannot view plaintext data as it passes over the network.

Oracle database native encryption is easy to deploy and follows the step-by-step guide to deploy it.

All configurations are done in the "sqlnet.ora" files on the client and server. 

Set the following parameters in the sqlnet.ora file of the server.

SQLNET.ENCRYPTION_SERVER
SQLNET.ENCRYPTION_TYPES_SERVER

Set the following parameters in the sqlnet.ora file of the client.

SQLNET.ENCRYPTION_CLIENT
SQLNET.ENCRYPTION_TYPES_CLIENT

Following are the acceptable values for SQLNET.ENCRYPTION_[SERVER|CLIENT]

  1. ACCEPTED: It is the most relaxed and default parameter if the parameter is not set. The client or server will allow both encrypted and non-encrypted connections. 
  2. REJECTED: It is the plain-text-only parameter and both client and server will refuse encrypted traffic.
  3. REQUESTED: It is a relaxed and somewhat secure way for encryption. The client or server will request encrypted traffic whenever possible but will accept non-encrypted traffic if encryption is not possible.
  4. REQUIRED: It is the highly restricted value for the parameter, the client or server will only accept encrypted traffic.


Set the following parameters in sqlnet.ora of the server to encrypt Oracle database network traffic using the AES256 algorithm. 

SQLNET.ENCRYPTION_SERVER=REQUIRED
SQLNET.ENCRYPTION_TYPES_SERVER=(AES256)

Set the following parameters in sqlnet.ora of the client to encrypt Oracle database network traffic using the AES256 algorithm. 

SQLNET.ENCRYPTION_CLIENT=REQUIRED
SQLNET.ENCRYPTION_TYPES_CLIENT=(AES256)

The above configuration will discard any unencrypted traffic. To get a lit bit of relaxed configuration we can use the following parameters in the sqlnet.ora file of the server. It will prefer a client to use an encrypted connection to the server but will accept a non-encrypted connection too.

SQLNET.ENCRYPTION_SERVER=REQUESTED
SQLNET.ENCRYPTION_TYPES_SERVER=(AES256)

It is highly advised to upgrade the Oracle database client version to support encryption. I have noticed a lot of incidents in the database due to clients not supporting the encryption. The output of the encrypted connection has been attached below. Executed command below to find if encryption is enabled while connecting to the database.

set line 1000
col NETWORK_SERVICE_BANNER for a100
select SID, SERIAL#,NETWORK_SERVICE_BANNER 
from V$SESSION_CONNECT_INFO 
where sid=(select sid from v$mystat where rownum=1);

# Unencrypted connection.


# Added parameters to the server side sqlnet.ora

# Added parameters to the client side sqlnet.ora

# Encrypted connections.


Wednesday, May 17, 2023

Decrypt Oracle Weblogic password.

7:02 PM Posted by Dilli Raj Maharjan No comments


    Oracle WebLogic Server is a Java EE application server currently developed by Oracle Corporation. Oracle acquired WebLogic Server when it purchased BEA Systems in 2008. It is a chance that we may forget the WebLogic admin username and password. Following is the step-by-step guide to recovering the WebLogic admin user and password.


1. Set oms environment variables.

. oraenv <<< oms 

2. Changed directory to the GCDomain/bin

cd  /u01/app/oracle/gc_inst/user_projects/domains/GCDomain/bin/

ls -alh






3. The WebLogic settings are in the setDomainEnv.sh script file(setDomainEnv.cmd for Windows and setDomainEnv.sh for Linux). Execute the command below to set WebLogic environment variables.

./setDomainEnv.sh

4. The username and password are stored in encrypted format in the file boot.properties below. Search the file with the name. There may be multiple boot.properties files, but the required one is inside the security directory.

find /u01 -iname boot.properties

Choose the one with the security/boot.properties as in the screenshot below.

/u01/app/oracle/gc_inst/user_projects/domains/GCDomain/servers/EMGC_ADMINSERVER/security/boot.properties


5. WebLogic Scripting Tool (WLST) is a command-line scripting interface system administrators and operators use to monitor and manage WebLogic Server instances and domains. Execute wlst.sh inside the oracle_common/common/bin directory.

${ORACLE_HOME}/oracle_common/common/bin/wlst.sh

Type the following command to fetch the password.

Once you execute the wlst.sh the prompt will be like below. 

wls:/offline>

6. Execute the command one at a time. Make sure you replace the location of the boot.properties noted in the earlier step.

from weblogic.security.internal import BootProperties

BootProperties.load("<boot.properties location>", false)

prop = BootProperties.getBootProperties()

print "username: " + prop.getOneClient()

print "password: " + prop.getTwoClient()

The password was recovered successfully.

Tuesday, April 4, 2023

How to find Oracle Enterprise Manager startup time.

7:24 PM Posted by Dilli Raj Maharjan No comments

 
    Oracle Enterprise Manager(OEM) is an on-premises solution for a comprehensive monitoring and management solution for Oracle products such as Oracle Database and Engineered Systems. A lot of plugins, monitoring Templates, thresholds, and other features make OEM a great tool for monitoring.

    Few days ago, I was asked to find the Oracle Management Service(OMS) startup time. I googled a lot and search for a better way to present the startup time for the OEM process. Finally, after 2 hours of searching I found the solution to find the startup time of the OEM.

    Following is the step-by-step process to find the startup time of the OMS startup time.

1. Click on Setup >> Manage Cloud Control >> Management Servers.



2. Click on the Management Servers >> Monitoring >> Status History.



3. The time value in the Up Since provides the time the OMS server has been started.




4. At the top left side, there is a drop-down menu to check the Overall Availability Duration. We have the option to check availability during the last 24 hours, last 7 days, last 31 days, and custom.







Thursday, March 16, 2023

How to change ASMSNMP user password in Oracle RAC Database.

8:22 PM Posted by Dilli Raj Maharjan , No comments


        The ASMSNMP user is an Oracle ASM user with privileges to monitor Oracle ASM instances. The ASMSNMP user password is required to configure monitoring. Following are the steps by step guides to change asmsnmp password if you forgot.

        The ASMSNMP user password is required while creating an Oracle RAC database. If you forgot, then you can follow the below steps to reset asmsnmp user password.

        Log in as grid user or export to  ORACLE ASM-HOME and SID as ASM instance if configured both grid and oracle in one user.

Method 1: Use alter user command.

        The command requires the SYSASM privilege to run. A user logged in as SYSDBA cannot change their password using this command.

Connecting to the ASM instance and executing an alter user
. oraenv <<< +ASM1
$ sqlplus / as sysasm

SQL> select * from v$pwfile_users;

USERNAME                        SYSDB  SYSOP  SYSAS
------------------------------  -----  -----  -----
SYS                             TRUE   TRUE   TRUE
ASMSNMP                         TRUE   FALSE  FALSE

SQL> ALTER USER asmsnmp IDENTIFIED BY <new_password>;

SQL> exit

Method 2: Using orapwusr command. 

The orapwusr attempts to update passwords on all nodes in a cluster. 

Connect as grid user, and export ASM instance variables.
. oraenv <<< +ASM1
$ asmcmd
ASMCMD> lspwusr
Username  sysdba  sysoper  sysasm
     SYS    TRUE     TRUE    TRUE
 ASMSNMP    TRUE    FALSE   FALSE

ASMCMD> lspwusr
Username  sysdba  sysoper  sysasm
     SYS    TRUE     TRUE    TRUE
 ASMSNMP    TRUE    FALSE   FALSE


The username is case-sensitive while using orapwusr command, use ASMSNMP in upper case.
ASMCMD> orapwusr
usage: orapwusr { { { --add | --modify [--password] }[--privilege {sysasm|sysdba|sysoper} ] } | --delete } user
help:  help orapwusr
ASMCMD> orapwusr --modify --password ASMSNMP
Enter password: *******




-- 12c and above.
[oracle@host19c +ASM1]$ asmcmd 
ASMCMD> lspwusr 
       Username sysdba sysoper sysasm  
            SYS   TRUE    TRUE   TRUE  
CRSUSER__ASM_001   TRUE   FALSE   TRUE  
        ASMSNMP   TRUE   FALSE  FALSE  
ASMCMD> help orapwusr 
usage: orapwusr {--add | --modify | --delete | --grant {sysasm|sysdba|sysoper} | --revoke {sysasm|sysdba|sysoper} } <user> 
 ASMCMD> orapwusr --modify ASMSNMP 
Enter password: ******** 
ASMCMD>