Oracle 监听器密码设置方法(LISTENER)
监听器也有安全?Sure!在缺省的情况下,任意用户不需要使用任何密码即通过lsnrctl工具对OracleListener进行操作或关闭,从而造成任意新的会话都将无法建立连接。在Oracle9i中Oracle监听器允许任何一个人利用lsnrctl从远程发起对监听器的管理。也容易导致数据库受到损坏。
1.未设定密码情形下停止监听
[oracle@test~]$lsnrctlstoplistener_demo92-->停止监听,可以看出不需要任何密码即可停止 LSNRCTLforLinux:Version9.2.0.8.0-Productionon26-JUN-201108:22:26 Copyright(c)1991,2006,OracleCorporation.Allrightsreserved. Connectingto(DESCRIPTION=(ADDRESS=(PROTOCOL=TCP)(HOST=test)(PORT=1521))) Thecommandcompletedsuccessfully
2.重新启动监听并设置密码
[oracle@test~]$lsnrctl LSNRCTLforLinux:Version9.2.0.8.0-Productionon26-JUN-201108:24:09 Copyright(c)1991,2006,OracleCorporation.Allrightsreserved. WelcometoLSNRCTL,type"help"forinformation. LSNRCTL>setcurrent_listenerlistener_demo92-->设置当前监听器 CurrentListenerislistener_demo92 LSNRCTL>start-->启动过程也不需要任何密码,启动的详细信息省略 LSNRCTL>change_password-->使用change_password来设置密码 Oldpassword: Newpassword: Reenternewpassword: Connectingto(DESCRIPTION=(ADDRESS=(PROTOCOL=TCP)(HOST=test)(PORT=1521))) Passwordchangedforlistener_demo92 Thecommandcompletedsuccessfully LSNRCTL>save_config-->注意此处的save_config失败 Connectingto(DESCRIPTION=(ADDRESS=(PROTOCOL=TCP)(HOST=test)(PORT=1521))) TNS-01169:Thelistenerhasnotrecognizedthepassword LSNRCTL>setpassword-->输入新设定的密码验证 Password: Thecommandcompletedsuccessfully LSNRCTL>save_config-->再次save_config成功 Connectingto(DESCRIPTION=(ADDRESS=(PROTOCOL=TCP)(HOST=test)(PORT=1521))) Savedlistener_demo92configurationparameters. ListenerParameterFile/oracle/92/network/admin/listener.ora OldParameterFile/oracle/92/network/admin/listener.bak Thecommandcompletedsuccessfully -->增加密码之后可以看到listener.ora文件中有一条新增的记录,即密码选项(注:尽管使用了密码管理方式,仍然可以无需密码启动监听) [oracle@testadmin]$morelistener.ora #----ADDEDBYTNSLSNR26-JUN-201105:12:48--- PASSWORDS_listener_demo92= #--------------------------------------------
3.尝试未使用密码的情况下停止监听
[oracle@test~]$lsnrctlstoplistener_demo92 LSNRCTLforLinux:Version9.2.0.8.0-Productionon26-JUN-201106:09:51 Copyright(c)1991,2006,OracleCorporation.Allrightsreserved. Connectingto(DESCRIPTION=(ADDRESS=(PROTOCOL=TCP)(HOST=test)(PORT=1521))) TNS-01169:Thelistenerhasnotrecognizedthepassword-->收到错误信息,需要使用密码认证
4.使用密码来停止监听
[oracle@test~]$lsnrctl LSNRCTL>setcurrent_listenerlistener_demo92 CurrentListenerislistener_demo92 LSNRCTL>stop Connectingto(DESCRIPTION=(ADDRESS=(PROTOCOL=TCP)(HOST=test)(PORT=1521))) TNS-01169:Thelistenerhasnotrecognizedthepassword LSNRCTL>setpassword Password: Thecommandcompletedsuccessfully LSNRCTL>stop Connectingto(DESCRIPTION=(ADDRESS=(PROTOCOL=TCP)(HOST=test)(PORT=1521))) Thecommandcompletedsuccessfully LSNRCTL>status Connectingto(DESCRIPTION=(ADDRESS=(PROTOCOL=TCP)(HOST=test)(PORT=1521))) TNS-12541:TNS:nolistener TNS-12560:TNS:protocoladaptererror TNS-00511:Nolistener LinuxError:111:Connectionrefused Connectingto(DESCRIPTION=(ADDRESS=(PROTOCOL=IPC)(KEY=EXTPROC))) TNS-12541:TNS:nolistener TNS-12560:TNS:protocoladaptererror TNS-00511:Nolistener LinuxError:2:Nosuchfileordirectory
5.save_config失败的问题
-->在Oracle9i中,使用save_config命令将会失败 LSNRCTL>save_config Connectingto(DESCRIPTION=(ADDRESS=(PROTOCOL=TCP)(HOST=<hostname>)(PORT=<port>))) TNS-01169:Thelistenerhasnotrecognizedthepassword -->应该先使用setpassword之后再save_config,则保存配置成功。 LSNRCTL>setpassword Password:<thepasswordyouchose> Thecommandcompletedsuccessfully /*在Oracle10g中不会出现类似的问题,因为在10g中可以使用基于操作系统验证方式。listener将检测到如果用户属于dba组的成员, 将会被授予改变密码,保存配置以及停止监听等权限。*/
6.配置listener.ora中ADMIN_RESTRICTIONS参数
参数作用:
当在listener.ora文件中设置了ADMIN_RESTRICTIONS参数后,在监听器运行时,不允许执行任何管理命令,同时set命令将不可用
,不论是在服务器本地还是从远程执行都不行。此时对于监听的设置仅仅通过手工修改listener.ora文件,要使修改生效,只能
使用lsnrctlreload命令或lsnrctlstop/start命令重新载入一次监听器配置信息。
修改方法:
在listener.ora文件中手动加入下面这样一行
ADMIN_RESTRICTIONS_<监听器名>=ON
下面是其它网友的补充:
LSNRCTL>change_password
Oldpassword:
Newpassword:
Reenternewpassword:
Connectingto(DESCRIPTION=(ADDRESS=(PROTOCOL=TCP)(HOST=ecp-uc-db1)(PORT=1521)))
PasswordchangedforLISTENER
Thecommandcompletedsuccessfully
LSNRCTL>setpassword
Password:
Thecommandcompletedsuccessfully
LSNRCTL>save_config
Connectingto(DESCRIPTION=(ADDRESS=(PROTOCOL=TCP)(HOST=ecp-uc-db1)(PORT=1521)))
SavedLISTENERconfigurationparameters.
ListenerParameterFile/opt/oracle/product/10.2.0/db_1/network/admin/listener.ora
OldParameterFile/opt/oracle/product/10.2.0/db_1/network/admin/listener.bak
Thecommandcompletedsuccessfully
[oracle@ecp-uc-db1admin]$catlistener.ora
#—-ADDEDBYTNSLSNR10-JUN-201118:13:24—
PASSWORDS_LISTENER=6D7AA003392C436A
#——————————————–
note:10g数据库上需要上添加(重启监听)
LOCAL_OS_AUTHENTICATION_LISTENER=OFF
1、添加LOCAL_OS_AUTHENTICATION_LISTENER=OFF之前
SecurityON:PasswordorLocalOSAuthentication
2、添加LOCAL_OS_AUTHENTICATION_LISTENER=OFF之后
SecurityON:Password
LSNRCTL>status
Connectingto(DESCRIPTION=(ADDRESS=(PROTOCOL=TCP)(HOST=ecp-uc-db1)(PORT=1521)))
TNS-01169:Thelistenerhasnotrecognizedthepassword
LSNRCTL>stop
Connectingto(DESCRIPTION=(ADDRESS=(PROTOCOL=TCP)(HOST=ecp-uc-db1)(PORT=1521)))
TNS-01169:Thelistenerhasnotrecognizedthepassword
LSNRCTL>setpassword123456
Thecommandcompletedsuccessfully
LSNRCTL>status
Connectingto(DESCRIPTION=(ADDRESS=(PROTOCOL=TCP)(HOST=ecp-uc-db1)(PORT=1521)))
STATUSoftheLISTENER
————————
AliasLISTENER
VersionTNSLSNRforLinux:Version10.2.0.4.0–Production
StartDate10-JUN-201118:15:49
Uptime0days0hr.1min.16sec
TraceLeveloff
SecurityON:Password
SNMPOFF
ListenerParameterFile/opt/oracle/product/10.2.0/db_1/network/admin/listener.ora
ListenerLogFile/opt/oracle/product/10.2.0/db_1/network/log/listener.log
ListeningEndpointsSummary…
(DESCRIPTION=(ADDRESS=(PROTOCOL=tcp)(HOST=ECP-UC-DB1)(PORT=1521)))
(DESCRIPTION=(ADDRESS=(PROTOCOL=ipc)(KEY=EXTPROC0)))
ServicesSummary…
Service“PLSExtProc”has1instance(s).
Instance“PLSExtProc”,statusUNKNOWN,has1handler(s)forthisservice…
Service“ecp”has1instance(s).
Instance“ecp”,statusREADY,has1handler(s)forthisservice…
Service“ecpXDB”has1instance(s).
Instance“ecp”,statusREADY,has1handler(s)forthisservice…
Service“ecp_XPT”has1instance(s).
Instance“ecp”,statusREADY,has1handler(s)forthisservice…
Thecommandcompletedsuccessfully