Table of Contents
iii
Overview ..............................................................................................................................................................1
System Wide Advice 2
Oracle TNS Listener Security...............................................................................................................................3
Hardening 3Network 3Authentication 4Authorization 5Audit 5
Oracle Database Security......................................................................................................................................7
Hardening 7Authentication 7Authorization 9Audit 10
Oracle Application Tier Security........................................................................................................................13
Hardening 13Authorization 15Audit 18
E-Business Suite Security...................................................................................................................................19
Hardening 19Network 20Authentication 21Authorization 24Audit 26Advanced Audit 28
Desktop Security.................................................................................................................................................31
Hardening 31
Operating Environment Security........................................................................................................................33
Hardening 33Network 34Authentication 35Authorization 36Maintenance 36
Extras for Experts...............................................................................................................................................39
Detect and Prevent Duplicate User Sessions 39Customize Password Validation 39Advanced Security/Networking Option (ASO/ANO) 39Configure Listener on a Non-Default
.dbc
Port 40Multi-Node Topology 40Hardening External Procedure (EXTPROC) Services 40
Appendix A: Security Setup Forms....................................................................................................................45Appendix B: Security Setup Forms That Accept SQL Statement......................................................................47Appendix C: Processes Used by E-Business Suite.............................................................................................49Appendix D: Ports Used by E-Business Suite....................................................................................................51Appendix E: Sample Linux Hardening of the Application Tier.........................................................................53Appendix F: References & More Resources......................................................................................................57