Enterprise User Security Authentication: Selection Criteria - Oracle Database B10772-01 Administrator's Manual

Database
Table of Contents

Advertisement

Introduction to Enterprise User Security
Table 11–1 Enterprise User Security Authentication: Selection Criteria
Password Authentication
Password-based authentication.
Provides centralized user and
password management.
Separate authentications required
for each database connection.
Retains users' current
authentication methods.
User identity can be used in
two-tier or multitier applications.
OracleAS Single Sign-On users and
enterprise users use the same stored
password.
Supports Oracle Release 7.3 and
later clients with an Oracle
Database 10g.
Supports current user database
links only if the connection between
databases is over SSL.
Can use third-party directories to
store users if synchronized with
Oracle Internet Directory.
1
If third-party directory is Microsoft Active Directory, then when user passwords change, they must be changed in both
Active Directory and in Oracle Internet Directory.
2
Must modify the Directory Integration Services agent to synchronize user PKCS #12 attributes.
3
If third-party directory is Microsoft Active Directory, then login to Windows gives you single sign-on login to databases.
However, you must modify the Directory Integration Services agent for other third-party directories to synchronize the
KrbPrincipalName attribute. This synchronization is automatic for Microsoft Active Directory.
11-10 Oracle Database Advanced Security Administrator's Guide
SSL Authentication
Provides strong authentication over
SSL.
Provides centralized user and PKI
credential/wallet management.
Supports
single sign-on (SSO)
using SSL.
Initial configuration maybe more
difficult because PKI credentials
must be generated for all users.
(Dependent on administrators' PKI
knowledge)
Compatible with either a two-tier or
multitier environment.
Supports Oracle8i and later clients
with an Oracle Database 10g.
Supports current user database
links.
Can use third-party directories to
store users if synchronized with
1
Oracle Internet Directory.
Kerberos Authentication
Provides strong authentication by
using Kerberos, version 5 tickets.
Provides centralized user and
Kerberos credential management.
Supports
single sign-on (SSO)
using Kerberos, version 5
encrypted tickets and
authenticators, and authentication
forwarding.
Initial configuration maybe more
difficult because Kerberos must be
installed and configured to
authenticate database users.
Compatible with either a two-tier
or multitier environment.
Supports Oracle Database 10g
clients and later with an Oracle
Database 10g.
Supports current user database
links only if the connection between
databases is over SSL.
Can use third-party directories to
store users if synchronized with
2
Oracle Internet Directory.
3

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the Oracle Database B10772-01 and is the answer not in the manual?

Subscribe to Our Youtube Channel

This manual is also suitable for:

Database advanced security 10g release 1

Table of Contents