Active Directory and Windows Security Integration with Oracle .ppt
《Active Directory and Windows Security Integration with Oracle .ppt》由会员分享,可在线阅读,更多相关《Active Directory and Windows Security Integration with Oracle .ppt(40页珍藏版)》请在麦多课文档分享上搜索。
1、,Active Directory and Windows Security Integration with Oracle Database,Alex Keh Principal Product Manager, Windows and .NET Oracle,Agenda,Database Registration and Name Resolution Single Sign-On Windows Native Authentication Kerberos Security for Web Applications on Windows Enterprise User Security
2、 and Virtual Directory,Database Registration and Name Resolution Overview,Store and resolve Net names through Active Directory Eliminate tnsnames.ora on clients Centralize configuration, reduce administration Authenticated connection to Active Directory (11g) Enhanced tools support for storing Net n
3、aming AD Users and Computers Oracle DB Configuration Assistant, Net Configuration Assistant and Net Manager,Database Registration and Name Resolution Active Directory support,DB Names and Connect Descriptors Repository,Database Registration and Name Resolution Configuration/Administration,Windows Ad
4、min,Active Directory,2 Register Schema with NetCA,Client Systems,5 - Configure Directory Naming and AD Usage with NetCA,1 Ensure Admin can modify Schema in AD,3 - Create Naming Context using NetCA,4 - Register DB in AD using DBCA or Net Manager,Database Registration and Name Resolution Run-time,1 Us
5、er signs on to Desktop,2 User issues Connect Request,DB Names and Connect Descriptors Repository,3 - Retrieves Connect Descriptor,4 - Connect to DB using Connect Descriptor,(Any Platform),Oracle DB,AD/KDC,Database Registration and Name Resolution Demo Environment,Windows XP SP2,Windows Server 2003 E
6、E SP1 (Domain Controller),Machine Name: xpclient.adnet.dev User: oracle Database Server: orcl,Machine Name: w2k3s.adnet.dev Domain: adnet.dev,Tools installed on Windows XP Support Tools (under Support directory on CD) - ADSI Edit is part of it Admin Tools (under i386 directory on CD) - AD users & co
7、mputers, etc (These are available on Windows 2003 media,),D E M O N S T R A T I O N,Database Registration and Name Resolution,Database Registration and Name Resolution Summary,Ensure that Administrator can modify Schema in Active Directory Register Schema using NetCA (one time for the entire AD fore
8、st) Create Naming Context using NetCA (once per domain or the entire forest depending on where you create it) Register Database in AD using DBCA or Net Manager Configure Directory Naming and Directory Usage (AD) using NetCA (on systems that want to use AD) on clients Set NAMES.LDAP_AUTHENTICATE_BIND
9、=Yes in SQLNET.ORA on all 11g client systems To support pre-11g clients Enable anonymous bind in AD Change ACLs for Oracle Naming Context and Database/Net Services objects to allow anonymous access,Please refer to the white paper Configuring Microsoft Active Directory for Net Naming for detailed inf
10、ormation,Agenda,Database Registration and Name Resolution Single Sign-On Windows Native Authentication Kerberos Security for Web Applications on Windows Enterprise User Security and Virtual Directory Q&A,Single Sign-On,Windows Native Authentication,Enabled by default and can work across systems Very
11、 easy to configure and use Windows user logon credentials used for database authentication Authentication protocol (Kerberos or NTLM) negotiated based on OS and Domain Controller Oracle Administration Assistant can be used to manage user authentication and role authorization Independent of Database
12、Registration and Name Resolution feature,Windows Native Authentication Use of Windows Groups,ORA_DBA: all members get SYSDBA privileges ORA_OPER: all members get SYSOPER privileges For any other Windows user, an external user needs to be created in Oracle DB create user “Salesfrank” identified exter
13、nally; Windows groups can be used to assign roles (if os_roles is true) create role sales identified externally; Corresponding Windows group for a database with SID orcl: ORA_orcl_sales_d if this should be a default role (If Oracle Administration Assistant is used, it makes appropriate changes in AD
14、 and Database),Windows Native Authentication,2 - User attempts to sign on to Oracle,1 - User signs on to desktop,4 - Identify as specific External User,5 Find Windows Group memberships (if os_roles is true),3 Negotiate security protocol and exchange security tokens,6 Assign roles based on DB roles o
15、r group memberships (based on os_roles),Oracle DB,AD/KDC,Windows Native Authentication Configuration,Set os_authent_prefix to “” in init.ora Ensure that sqlnet.authentication_services is set to NTS in sqlnet.ora (default set up) Set os_roles to true in init.ora if you want to use Windows Group Membe
16、rship for role authorization,D E M O N S T R A T I O N,Windows Native Authentication,Kerberos Authentication,Integrated with Microsoft Key Distribution Center (MSKDC) Supports heterogeneous systems A Windows client can connect to a non-Windows server and vice versa Uses External User mechanisms in D
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
2000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- ACTIVEDIRECTORYANDWINDOWSSECURITYINTEGRATIONWITHORACLEPPT

链接地址:http://www.mydoc123.com/p-378007.html