|
Walter,
Unfortunately, there is no way. You can prevent
root from connecting as sysdba by removing the dba group from root userid; but
hey, root can "root" it again; he is root, remember, omnipotent.
Even if that is successful, he can connect
to any dba account, such as "oracle" using "su -" and then connect as
sysdba. Worse, they can connect to _any_ dba user, not necessarily "oracle", and
your audit logs will show as if coming from that user.
Therefore the issue is serious than it sounds like
and you should approach at from the manegerial level. Take dba group out if
the root userid and establish ground rules that dba group is never allowed to
any user without the DBA's request. If they continue to do "su - oracle", make
them aware that this operation is imporsonation, and may be deemed illegal. They
will listen to that word!
HTH.
Arup
|
- RE: How to keep "root" out? Guang Mei
- Re: How to keep "root" out? Peter . McLarty
- RE: How to keep "root" out? Vergara, Michael (TEM)
- How to keep "root" out? Walter K
- RE: How to keep "root" out? Goulet, Dick
- RE: How to keep "root" out? Mark Leith
- RE: How to keep "root" out? DENNIS WILLIAMS
- RE: How to keep "root" out? Brian McGraw
- RE: How to keep "root" out? Mark Leith
- Re: How to keep "root" out? Jonathan Gennick
- RE: How to keep "root" out? Arup Nanda
- RE: How to keep "root" out? Mladen Gogala
- RE: How to keep "root" out? Jamadagni, Rajendra
- RE: How to keep "root" out? Freeman Robert - IL
- RE: How to keep "root" out? Saira Somani-Mendelin
- Re: How to keep "root" out? Tanel Poder
- Re: How to keep "root" out? Tanel Poder
- RE: How to keep "root" out? Denny Koovakattu
- Re: How to keep "root" out? Denny Koovakattu
- RE: How to keep "root" out? Freeman Robert - IL
- RE: How to keep "root" out? Goulet, Dick
