<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	
	>
<channel>
	<title>
	Comments on: Oracle: Is it possible to setup a system that a client (specific IP address) can only connect to a specific DB-User?	</title>
	<atom:link href="https://www.dbi-services.com/blog/oracle-is-it-possible-to-setup-a-system-that-a-client-specific-ip-address-can-only-connect-to-a-specific-db-user/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.dbi-services.com/blog/oracle-is-it-possible-to-setup-a-system-that-a-client-specific-ip-address-can-only-connect-to-a-specific-db-user/</link>
	<description></description>
	<lastBuildDate>Thu, 08 Feb 2024 12:13:24 +0000</lastBuildDate>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	
	<item>
		<title>
		By: Clemens Bleile		</title>
		<link>https://www.dbi-services.com/blog/oracle-is-it-possible-to-setup-a-system-that-a-client-specific-ip-address-can-only-connect-to-a-specific-db-user/#comment-3115</link>

		<dc:creator><![CDATA[Clemens Bleile]]></dc:creator>
		<pubDate>Thu, 08 Feb 2024 12:13:24 +0000</pubDate>
		<guid isPermaLink="false">https://www.dbi-services.com/blog/?p=24630#comment-3115</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://www.dbi-services.com/blog/oracle-is-it-possible-to-setup-a-system-that-a-client-specific-ip-address-can-only-connect-to-a-specific-db-user/#comment-3110&quot;&gt;lakosm&lt;/a&gt;.

In your case I would create the application user as a &quot;no authentication&quot; user. See &lt;a href=&quot;https://oracle-base.com/articles/18c/schema-only-accounts-18c&quot; rel=&quot;nofollow ugc&quot;&gt;here&lt;/a&gt; for details. Then create a proxy user on the database which is allowed to be your application user. I.e. your application connects as follows:
username[application_user]/proxy_user_password@connect-string
E.g.
alter user cbleile1 no authentication;

sqlplus tdm1[cbleile1]/tdm1pwd@pdb1_cman

The application user does not need to have a failed connection profile anymore, because you always get an ORA-1017 when trying to connect even with the correct password. So to accidently connect to your application user you have to use that specific syntax for the proxy user and I doubt that it happens &quot;accidently&quot;.

Regards
Clemens]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://www.dbi-services.com/blog/oracle-is-it-possible-to-setup-a-system-that-a-client-specific-ip-address-can-only-connect-to-a-specific-db-user/#comment-3110">lakosm</a>.</p>
<p>In your case I would create the application user as a &#8220;no authentication&#8221; user. See <a href="https://oracle-base.com/articles/18c/schema-only-accounts-18c" rel="nofollow ugc">here</a> for details. Then create a proxy user on the database which is allowed to be your application user. I.e. your application connects as follows:<br />
username[application_user]/proxy_user_password@connect-string<br />
E.g.<br />
alter user cbleile1 no authentication;</p>
<p>sqlplus tdm1[cbleile1]/tdm1pwd@pdb1_cman</p>
<p>The application user does not need to have a failed connection profile anymore, because you always get an ORA-1017 when trying to connect even with the correct password. So to accidently connect to your application user you have to use that specific syntax for the proxy user and I doubt that it happens &#8220;accidently&#8221;.</p>
<p>Regards<br />
Clemens</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: lakosm		</title>
		<link>https://www.dbi-services.com/blog/oracle-is-it-possible-to-setup-a-system-that-a-client-specific-ip-address-can-only-connect-to-a-specific-db-user/#comment-3110</link>

		<dc:creator><![CDATA[lakosm]]></dc:creator>
		<pubDate>Mon, 05 Feb 2024 13:10:18 +0000</pubDate>
		<guid isPermaLink="false">https://www.dbi-services.com/blog/?p=24630#comment-3110</guid>

					<description><![CDATA[I understand your example. Only our needs are a little different. Each user has their own dedicated user. The dedicated users and the application user are in a common database. I want to prevent the dedicated user from accidentally trying to log in with the application user, since the application user&#039;s password is protected by a password profile. We can&#039;t take the failed login higher as you suggested, and it may happen that the dedicated user locks the application user after n attempts. I thought this could be solved with CMAN]]></description>
			<content:encoded><![CDATA[<p>I understand your example. Only our needs are a little different. Each user has their own dedicated user. The dedicated users and the application user are in a common database. I want to prevent the dedicated user from accidentally trying to log in with the application user, since the application user&#8217;s password is protected by a password profile. We can&#8217;t take the failed login higher as you suggested, and it may happen that the dedicated user locks the application user after n attempts. I thought this could be solved with CMAN</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Clemens Bleile		</title>
		<link>https://www.dbi-services.com/blog/oracle-is-it-possible-to-setup-a-system-that-a-client-specific-ip-address-can-only-connect-to-a-specific-db-user/#comment-3109</link>

		<dc:creator><![CDATA[Clemens Bleile]]></dc:creator>
		<pubDate>Mon, 05 Feb 2024 10:47:51 +0000</pubDate>
		<guid isPermaLink="false">https://www.dbi-services.com/blog/?p=24630#comment-3109</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://www.dbi-services.com/blog/oracle-is-it-possible-to-setup-a-system-that-a-client-specific-ip-address-can-only-connect-to-a-specific-db-user/#comment-3108&quot;&gt;lakosm&lt;/a&gt;.

You only need CMAN here (no AVDF), but we kind of use the behavior of TDM to meet our requirements. I.e. with CMAN you filter on client-ip and target service through rules. With TDM you get the additional possibility to define a link between a service and a db-user, because service pdb1 in the wallet has user tdm1 assigned only. And tdm1 got the proxy-user right to become &quot;only&quot; cbleile1 on the DB. The nice thing is that you still have to provide the password for cbleile1 when connecting, but you actually connect with the proxy-user tdm1, which has its password in the wallet. So TDM provides this link now between service (pdb1) and proxy-user (tdm1) and final user (cbleile1). As a client you need to know the password of cbleile1. A different client cannot connect to cbleile1, because it is not allowed to connect to service pdb1 (in CMAN) and hence cannot use the proxy-user tdm1. However, it can use service pdb1_2, which uses DB-service pdb1 in the wallet as well. So there&#039;s not need to create new services on the DB.]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://www.dbi-services.com/blog/oracle-is-it-possible-to-setup-a-system-that-a-client-specific-ip-address-can-only-connect-to-a-specific-db-user/#comment-3108">lakosm</a>.</p>
<p>You only need CMAN here (no AVDF), but we kind of use the behavior of TDM to meet our requirements. I.e. with CMAN you filter on client-ip and target service through rules. With TDM you get the additional possibility to define a link between a service and a db-user, because service pdb1 in the wallet has user tdm1 assigned only. And tdm1 got the proxy-user right to become &#8220;only&#8221; cbleile1 on the DB. The nice thing is that you still have to provide the password for cbleile1 when connecting, but you actually connect with the proxy-user tdm1, which has its password in the wallet. So TDM provides this link now between service (pdb1) and proxy-user (tdm1) and final user (cbleile1). As a client you need to know the password of cbleile1. A different client cannot connect to cbleile1, because it is not allowed to connect to service pdb1 (in CMAN) and hence cannot use the proxy-user tdm1. However, it can use service pdb1_2, which uses DB-service pdb1 in the wallet as well. So there&#8217;s not need to create new services on the DB.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: lakosm		</title>
		<link>https://www.dbi-services.com/blog/oracle-is-it-possible-to-setup-a-system-that-a-client-specific-ip-address-can-only-connect-to-a-specific-db-user/#comment-3108</link>

		<dc:creator><![CDATA[lakosm]]></dc:creator>
		<pubDate>Mon, 05 Feb 2024 07:57:12 +0000</pubDate>
		<guid isPermaLink="false">https://www.dbi-services.com/blog/?p=24630#comment-3108</guid>

					<description><![CDATA[Thanks, I&#039;ve tried what&#039;s in the MOS article, but it won&#039;t work for us. As for CMAN, my suggestion was that if a user does not have the &quot;connect through&quot; right to TDM, then CMAN will not allow him to access the database with any password. But according to them, there is no such option in CMAN. Then this functionality is only available in AVDF (e.g. Montoring /Blocking (proxy) mode)?]]></description>
			<content:encoded><![CDATA[<p>Thanks, I&#8217;ve tried what&#8217;s in the MOS article, but it won&#8217;t work for us. As for CMAN, my suggestion was that if a user does not have the &#8220;connect through&#8221; right to TDM, then CMAN will not allow him to access the database with any password. But according to them, there is no such option in CMAN. Then this functionality is only available in AVDF (e.g. Montoring /Blocking (proxy) mode)?</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Clemens Bleile		</title>
		<link>https://www.dbi-services.com/blog/oracle-is-it-possible-to-setup-a-system-that-a-client-specific-ip-address-can-only-connect-to-a-specific-db-user/#comment-3100</link>

		<dc:creator><![CDATA[Clemens Bleile]]></dc:creator>
		<pubDate>Fri, 02 Feb 2024 12:55:55 +0000</pubDate>
		<guid isPermaLink="false">https://www.dbi-services.com/blog/?p=24630#comment-3100</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://www.dbi-services.com/blog/oracle-is-it-possible-to-setup-a-system-that-a-client-specific-ip-address-can-only-connect-to-a-specific-db-user/#comment-3097&quot;&gt;lakosm&lt;/a&gt;.

Hi, yes, if you use a wrong password then your account gets locked after your defined 5 attempts. That behavior is actually difficult to change In my view you should allow more &quot;failed logon attempts&quot; and rely on the delays the failed attempt cause for the next failed attempt. The failed attempts should be audited of course. See also MOS Note &quot;High &#039;library cache lock&#039; Wait Time Due to Invalid Login Attempts (Doc ID 1309738.1)&quot; which might be interesting for you in this context.
Regards
Clemens]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://www.dbi-services.com/blog/oracle-is-it-possible-to-setup-a-system-that-a-client-specific-ip-address-can-only-connect-to-a-specific-db-user/#comment-3097">lakosm</a>.</p>
<p>Hi, yes, if you use a wrong password then your account gets locked after your defined 5 attempts. That behavior is actually difficult to change In my view you should allow more &#8220;failed logon attempts&#8221; and rely on the delays the failed attempt cause for the next failed attempt. The failed attempts should be audited of course. See also MOS Note &#8220;High &#8216;library cache lock&#8217; Wait Time Due to Invalid Login Attempts (Doc ID 1309738.1)&#8221; which might be interesting for you in this context.<br />
Regards<br />
Clemens</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: lakosm		</title>
		<link>https://www.dbi-services.com/blog/oracle-is-it-possible-to-setup-a-system-that-a-client-specific-ip-address-can-only-connect-to-a-specific-db-user/#comment-3097</link>

		<dc:creator><![CDATA[lakosm]]></dc:creator>
		<pubDate>Thu, 01 Feb 2024 14:00:16 +0000</pubDate>
		<guid isPermaLink="false">https://www.dbi-services.com/blog/?p=24630#comment-3097</guid>

					<description><![CDATA[Hi, our application db user is assigned to a (paasword) profile. In that profile a &quot;failed logon attempts&quot; parameter is set i.e. 5. In that case our other db users potentially can lock our app db user if they try to connect to the db app user using wrong password. We thouht CMAN will be a good tool to avoid it, but in your test:
&quot;sqlplus cbleile2/cbleile2@pdb1_cman
-&#062; ORA-28725. OK.&quot;
works when someone is trying with the correct password. Can we use CMAN to avoid our regular db user not to connect to our app db user even with wrong password?]]></description>
			<content:encoded><![CDATA[<p>Hi, our application db user is assigned to a (paasword) profile. In that profile a &#8220;failed logon attempts&#8221; parameter is set i.e. 5. In that case our other db users potentially can lock our app db user if they try to connect to the db app user using wrong password. We thouht CMAN will be a good tool to avoid it, but in your test:<br />
&#8220;sqlplus cbleile2/cbleile2@pdb1_cman<br />
-&gt; ORA-28725. OK.&#8221;<br />
works when someone is trying with the correct password. Can we use CMAN to avoid our regular db user not to connect to our app db user even with wrong password?</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Clemens Bleile		</title>
		<link>https://www.dbi-services.com/blog/oracle-is-it-possible-to-setup-a-system-that-a-client-specific-ip-address-can-only-connect-to-a-specific-db-user/#comment-3095</link>

		<dc:creator><![CDATA[Clemens Bleile]]></dc:creator>
		<pubDate>Mon, 29 Jan 2024 12:31:46 +0000</pubDate>
		<guid isPermaLink="false">https://www.dbi-services.com/blog/?p=24630#comment-3095</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://www.dbi-services.com/blog/oracle-is-it-possible-to-setup-a-system-that-a-client-specific-ip-address-can-only-connect-to-a-specific-db-user/#comment-3094&quot;&gt;lakosm&lt;/a&gt;.

Thanks for the info, you are correct, it has to be ncdb1 and (HOST = 19c-dg1). Those 2 typos have been corrected. Concerning &quot;pdb1_2 service must be running on the server&quot;: pdb1_2 is not a service running on the server, on the cman server it is an entry in the wallet, which tells it under what user it has to connect to the DB and in cman&#039;s tnsnames,ora telling it where to connect. I.e. the client 12cr2Client requests to connect to service pdb1_2. According the rule &quot;(src=12cr2Client)(dst=19c-dg1)(srv=pdb1_2)(act=accept)&quot; that is allowed. The CMAN checks its wallet for entry pdb1_2 which points to proxy user tdm2 on the DB and its tnsnames.ora with entry pdb1_2 with the connect string to the DB.
I.e. the service in the client tnsnames.ora is resolved on the cman-server as a combination of wallet entry pdb1_2 and tnsnames alias pdb1_2. On the db-server only service pdb1 is known.
Regards
Clemens]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://www.dbi-services.com/blog/oracle-is-it-possible-to-setup-a-system-that-a-client-specific-ip-address-can-only-connect-to-a-specific-db-user/#comment-3094">lakosm</a>.</p>
<p>Thanks for the info, you are correct, it has to be ncdb1 and (HOST = 19c-dg1). Those 2 typos have been corrected. Concerning &#8220;pdb1_2 service must be running on the server&#8221;: pdb1_2 is not a service running on the server, on the cman server it is an entry in the wallet, which tells it under what user it has to connect to the DB and in cman&#8217;s tnsnames,ora telling it where to connect. I.e. the client 12cr2Client requests to connect to service pdb1_2. According the rule &#8220;(src=12cr2Client)(dst=19c-dg1)(srv=pdb1_2)(act=accept)&#8221; that is allowed. The CMAN checks its wallet for entry pdb1_2 which points to proxy user tdm2 on the DB and its tnsnames.ora with entry pdb1_2 with the connect string to the DB.<br />
I.e. the service in the client tnsnames.ora is resolved on the cman-server as a combination of wallet entry pdb1_2 and tnsnames alias pdb1_2. On the db-server only service pdb1 is known.<br />
Regards<br />
Clemens</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: lakosm		</title>
		<link>https://www.dbi-services.com/blog/oracle-is-it-possible-to-setup-a-system-that-a-client-specific-ip-address-can-only-connect-to-a-specific-db-user/#comment-3094</link>

		<dc:creator><![CDATA[lakosm]]></dc:creator>
		<pubDate>Mon, 29 Jan 2024 11:34:33 +0000</pubDate>
		<guid isPermaLink="false">https://www.dbi-services.com/blog/?p=24630#comment-3094</guid>

					<description><![CDATA[hi, ty, but the correction you have made is still wrong: u wrote npdb1 but ncdb1 is the correct. In Test 2 I can see other strange things (i.e. pdb1_2 service must be running on the server and u didnt mention it). Maybe this host also not correct: (HOST = DB-dg1)
Anyway, ty the article, it is great!]]></description>
			<content:encoded><![CDATA[<p>hi, ty, but the correction you have made is still wrong: u wrote npdb1 but ncdb1 is the correct. In Test 2 I can see other strange things (i.e. pdb1_2 service must be running on the server and u didnt mention it). Maybe this host also not correct: (HOST = DB-dg1)<br />
Anyway, ty the article, it is great!</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Clemens Bleile		</title>
		<link>https://www.dbi-services.com/blog/oracle-is-it-possible-to-setup-a-system-that-a-client-specific-ip-address-can-only-connect-to-a-specific-db-user/#comment-3091</link>

		<dc:creator><![CDATA[Clemens Bleile]]></dc:creator>
		<pubDate>Mon, 29 Jan 2024 10:18:26 +0000</pubDate>
		<guid isPermaLink="false">https://www.dbi-services.com/blog/?p=24630#comment-3091</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://www.dbi-services.com/blog/oracle-is-it-possible-to-setup-a-system-that-a-client-specific-ip-address-can-only-connect-to-a-specific-db-user/#comment-3090&quot;&gt;lakosm&lt;/a&gt;.

Hi, that&#039;s correct. I adjusted the Blog accordingly.
Thanks and regards
Clemens]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://www.dbi-services.com/blog/oracle-is-it-possible-to-setup-a-system-that-a-client-specific-ip-address-can-only-connect-to-a-specific-db-user/#comment-3090">lakosm</a>.</p>
<p>Hi, that&#8217;s correct. I adjusted the Blog accordingly.<br />
Thanks and regards<br />
Clemens</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: lakosm		</title>
		<link>https://www.dbi-services.com/blog/oracle-is-it-possible-to-setup-a-system-that-a-client-specific-ip-address-can-only-connect-to-a-specific-db-user/#comment-3090</link>

		<dc:creator><![CDATA[lakosm]]></dc:creator>
		<pubDate>Mon, 29 Jan 2024 09:39:06 +0000</pubDate>
		<guid isPermaLink="false">https://www.dbi-services.com/blog/?p=24630#comment-3090</guid>

					<description><![CDATA[Hi, In the Client tnsnames.ora for the ncdb1_cman entry the service_name should be ncdb1 not pdb1. Am I right?]]></description>
			<content:encoded><![CDATA[<p>Hi, In the Client tnsnames.ora for the ncdb1_cman entry the service_name should be ncdb1 not pdb1. Am I right?</p>
]]></content:encoded>
		
			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/?utm_source=w3tc&utm_medium=footer_comment&utm_campaign=free_plugin

Page Caching using Disk: Enhanced 
Lazy Loading (feed)

Served from: www.dbi-services.com @ 2026-10-09 00:31:56 by W3 Total Cache
-->