Академический Документы
Профессиональный Документы
Культура Документы
About Me
Enter password:
Add self-signed certificate
orapki wallet add -wallet $ORACLE_HOME/owm/wallets/root -dn 'CN=root' -keysize 2048 -self_signed -
validity 365
Oracle PKI Tool : Version 11.2.0.1.0 - Production
Copyright (c) 2004, 2009, Oracle and/or its affiliates. All rights reserved.
Enter password:
Import root certificate into database wallet
orapki wallet add -wallet $ORACLE_HOME/owm/wallets/db -trusted_cert -cert
$ORACLE_HOME/owm/wallets/root/root.cer -pwd Welcome1
Oracle PKI Tool : Version 11.2.0.1.0 - Production
Copyright (c) 2004, 2009, Oracle and/or its affiliates. All rights reserved.
-----END CERTIFICATE-
cat $ORACLE_HOME/owm/wallets/db/dbcert.req
-----BEGIN NEW CERTIFICATE REQUEST-----
MIIBfDCB5gIBADA9MRUwEwYKCZImiZPyLGQBGRYFbG9jYWwxFjAUBgoJkiaJk/IsZAEZFgZvcmFj
bGUxDDAKBgNVBAMTA2RiMTCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAqNY8AZQTx7HUlxST
3lBM6coj1z5QPjlMAN50tx8xa8fyLtHPGWF5gMpn2ZcbUwJrH0ZlqpahxGX6jtehmK6RRJ6/AuYQ
CPvgox5sUtXdSVgdDolsyighLdI70/1wC/PsIMF/0kvcrGvXMcvMKVf1PMS2aVUiCF8MnQmN6r2X
lWsCAwEAAaAAMA0GCSqGSIb3DQEBBAUAA4GBACnIa6jIYfO3QLDBAGTJzKAxiNp8PUS/LgznDqq1
ceJ3tYKszHJoouKaY2cz8fOT8opizYk4yTtxVkg3mPS0L5SwwXUQIarnELDBjku1m68wg7VJBAuy
I6UZkezbU0Hvhqm93YFXrcQS/VJnt+tZILzFyX9BMU2IhGxSfWlVaEek
-----END NEW CERTIFICATE REQUEST-----
Demonstration
Enter password:
• Sqlnet.ora file:
SSL_VERSION = 3.0
SSL_CLIENT_AUTHENTICATION = TRUE
WALLET_LOCATION =
(SOURCE =
(METHOD = FILE)
(METHOD_DATA =
(DIRECTORY =
/u01/app/oracle/product/11.2.0/db_1/owm/wallets/db)
)
)
ADR_BASE = /u01/app/oracle
• Listener.ora
SID_LIST_LISTENER =
(SID_LIST =
(SID_DESC =
(GLOBAL_DBNAME = ORCL.ORACLE.LOCAL)
(ORACLE_HOME = /u01/app/oracle/product/11.2.0/db_1)
(SID_NAME = orcl)
)
)
SSL_CLIENT_AUTHENTICATION = true
WALLET_LOCATION =
(SOURCE =
(METHOD = FILE)
(METHOD_DATA =
(DIRECTORY = /u01/app/oracle/product/11.2.0/db_1/owm/wallets/db)
)
)
LISTENER =
(DESCRIPTION =
(ADDRESS = (PROTOCOL = TCPS)(HOST = host1.oracle.local)(PORT = 2484))
)
ADR_BASE_LISTENER = /u01/app/oracle
• Configure netmgr for client side
• Sqlnet.ora
SSL_VERSION = 3.0
SSL_CLIENT_AUTHENTICATION =TRUE
SSL_SERVER_DN_MATCH = YES
WALLET_LOCATION =
(SOURCE =
(METHOD = FILE)
(METHOD_DATA =
(DIRECTORY =
/u01/app/oracle/product/11.2.0/db_1/owm/wallets/user)
)
)
ADR_BASE = /u01/app/oracle
• Tnsnames.ora
ORCL =
(DESCRIPTION =
(ADDRESS_LIST =
(ADDRESS = (PROTOCOL = TCPS)(HOST =
host1.oracle.local)(PORT = 2484))
)
(CONNECT_DATA =
(SERVICE_NAME = ORCL.oracle.local)
)
)
• Restart the listener
$lsnrctl stop
$lsnrctl start
$sqlplus /@orcl
SQL*Plus: Release 11.2.0.1.0 Production on Tue Apr 23 23:14:15 2013
Copyright (c) 1982, 2009, Oracle. All rights reserved.
Connected to:
Oracle Database 11g Enterprise Edition Release 11.2.0.1.0 – Production
With the Partitioning, OLAP, Data Mining and Real Application Testing
options
Questions?