Managing User Accounts and Access
A super user can manage user accounts and access.
About Oracle DBSecCentral Auditor Accounts and Passwords
Learn about Oracle DBSecCentral auditor user accounts and passwords.
There are three types of auditor accounts in Oracle Database Security Central:
-
Super Auditor:
-
Creates user accounts for super auditors and auditors
-
Has auditor access to all targets and target groups
-
Grants auditor access to targets or target groups to auditors
-
-
Auditor: Has access to specific targets or target groups granted by a super auditor
-
Readonly Auditor: Has readonly access to:
-
Target database details as granted to them by the Super Auditor
-
Audit trail details
-
Database Firewall monitoring points
-
Dashboard data on the Home page, including the ability to view chart data and add filters
-
User entitlement, target database, and target database group access details
-
All reports and report schedules. Compliance Reports and Generated Reports for specific target databases are only visible to the Readonly Auditor if they have been granted access to the target database by the Super Auditor
-
All alerts and alert details
-
Passwords for these accounts need not be unique; however, Oracle recommends that passwords:
-
Have at least one uppercase alphabetic, one alphabetic, one numeric, and one special character (plus sign, comma, period, or underscore).
-
Be between 8 and 30 characters long.
-
Be composed of the following characters:
-
Lowercase letters: a-z.
-
Uppercase letters: A-Z.
-
Digits: 0- 9.
-
Punctuation marks: comma (,), period (.), plus sign (+), colon(:), and underscore (_).
-
-
Not be the same as the user name.
-
Not be an Oracle reserved word.
-
Not be an obvious word (such as welcome, account, database, and user).
-
Not contain any repeating characters.
Creating Local Auditor Users
Learn how to create user accounts with auditor privileges.
Super auditors can create both super auditor and auditor user accounts.
To create an auditor account in Oracle Database Security Central:
-
Log in to the Oracle Database Security Central console as a super auditor.
-
Select Settings.
The Manage Auditors subtab on the main page is selected by default.
-
Select Add in the top, right corner.
-
In the Add Auditor dialog box, select Local DBSecCentral User.
-
For Local DBSecCentral User, enter the details to create a database auditor.
-
Enter the newly created Auditor Name.
-
Select the Auditor Type.
-
Enter the Password and Re-type Password.
Oracle Database Security Central does not accept user names with quotation marks, such as
"jsmith". -
Select Save.
Related Topics
Creating New SSO Users
To create new users for single sign-on (SSO) authentication, you enter the user name and the auditor type.
-
Log in to the Oracle Database Security Central console as a
super auditor. -
Select Settings.
-
On the Manage Auditors subtab, select Add.
-
In the dialog box, select Single Sign-On.
-
Enter the SSO user name.
Allowed characters include uppercase letters, lowercase letters, numbers, and symbols (@.-_!^~+%). The total length of the SSO user name can't exceed 127 characters.
Note: Though DBSecCentral accepts uppercase and lowercase letters, it will store the user name in only uppercase. Microsoft performs a case-insensitive comparison of the user names.
-
Select the auditor type, Auditor, Readonly Auditor, or Super Auditor.
-
Select Save.
Related Topics
Viewing the Status of Auditor User Accounts
Learn how to view the status of auditor user accounts.
As a super auditor, you can view the status of auditor accounts by clicking the Settings The Manage Auditors page lists all auditor and super auditor accounts, their status, and password expiry dates.
Managing User Access to Targets or Groups
Learn to manage user access to targets and target groups.
About Managing User Access
Learn about managing user access.
Super auditors have access to all targets and target groups, and can grant access to specific targets and groups to auditors.
You can control access to targets or groups in two ways:
-
Modify a target or group to grant or revoke access for one or more users.
-
Modify a user account to grant or revoke access to one or more targets or groups.
Controlling Access by User
Learn about controlling user access to targets.
To control which targets or groups are accessible by a user:
-
Log in to the Oracle Database Security Central console as a super auditor.
-
Select Settings. The Manage Auditors page displays existing users and the targets or groups to which they have access.
-
Select the name of the user account that you want to modify.
The Modify Auditor page appears.
-
In the Targets & Target Groups section:
-
Select the access rights to which you want to grant or revoke for this user. You can also search for the access rights in the field under Targets & Target Groups.
-
Choose the access rights in the Available column and move them to the Selected column, to grant access. Choose the access rights in the Selected column and move them to the Available column, to revoke access.
-
-
Select Save.
See Also: Logging in to the Oracle Database Security Central Console
Controlling Access by Target or Group
Learn about controlling access to targets or target groups.
To control which users have access to a target or group:
-
Log in to the Oracle Database Security Central console as a super auditor.
-
Select Targets.
-
Select Access Rights tab in the left navigation menu.
-
Select the name of the target or target group for which you want to redefine access rights.
The Modify Access dialog for the specific target or group appears. It lists the user access rights to the target or group. Super auditors have access by default.
-
In the Modify Access dialog, select the users for which you want to grant or revoke access to this target or group.
-
Select the users for which you want to grant or revoke access to the targets or groups. You can also search for the users in the field.
-
Choose the access rights in the Available column and move them to the Selected column, to grant access. Choose the access rights in the Selected column and move them to the Available column, to revoke access.
-
-
Select Save.
See Also: Logging in to the Oracle Database Security Central Console
Changing a User Account Type
Learn how to change auditor user account type.
You can change an auditor account type between Readonly Auditor, Auditor, and Super Auditor. If a user’s account type is changed from Auditor or Readonly Auditor to Super Auditor, that user will have access to all targets and target groups. A user can only be assigned one auditor account type at a time.
To change a user account type in Oracle Database Security Central:
-
Log in to the Oracle Database Security Central console as a super auditor.
-
Select Settings.
The Manage Auditors page appears by default, and displays existing users and the targets or groups to which they have access.
-
Select the name of the user account you want to change.
-
In the Modify Auditor dialog, against the Type field, select on the edit icon.
-
In the Type drop-down list, select the new auditor type.
-
If you changed the type from Super Auditor to Auditor or Readonly Auditor, grant or revoke access to any targets or groups as necessary for this user.
-
Select the targets or groups to which you want to grant or revoke access. You can also search for the targets or groups in the field under Targets & Target Groups.
-
Choose the targets and groups in the Available column and move them to the Selected column, to grant access. Choose the targets and groups in the Selected column and move them to the Available column, to revoke access.
-
-
Select Save.
See Also: Logging in to the Oracle Database Security Central Console
Changing the Auditor Password
Learn how to change the password of an auditor.
Auditors can change their own password. A Super Auditor can also change the password of other auditors. If a Super Auditor changes the password of another auditor, then the password automatically expires immediately after it is changed.
See Also: About Oracle DBSecCentral Auditor Accounts and Passwords
Changing Your Own Password
You can change your own password any time.
-
Log in to the Oracle Database Security Central console as an auditor.
-
In the upper right corner, to the right of your login name, select the menu icon.
-
Select Change Password from this menu.
-
In the Change Password window, enter the following fields:
-
Current Password
-
New Password
-
Re-enter New Password
-
-
Select Save.
Changing the Password of Another Auditor
Learn how to change the password of another auditor as a Super Auditor.
A Super Auditorcan change the passwords of other auditors. However, the password automatically expires immediately after it is changed by the Super Auditor. The auditor must follow the instructions in the topic Changing the Expired Password of an Auditor.
-
Log in to the Audit Vault Server as Super Auditor.
-
Select Settings. The Manage Auditors tab in left navigation menu is selected by default.
-
Under Manage Auditors, select the name of the auditor whose password you want to change.
-
In the Modify Auditor window, select Change Password.
-
In the Change Password window, enter the following fields:
-
New Password
-
Re-enter New Password
-
-
Select Save.
Changing the Expired Password of an Auditor
Your password might be expired if a Super Auditor changes your password, or if it passes the password expiry date. You need to follow these steps:
-
Log in to AVCLI with your auditor user name.
-
AVCLI prompts to enter the password. Enter the expired password.
The following message is displayed:
The password has expired. Enter the new password: -
Enter the new password of your choice. Follow the password requirements.
The following message is displayed:
Re-enter password: -
Re-enter the new password.
-
If the following message is displayed, then you have successfully logged in to AVCLI with the new password, and your account is active again:
Connected to: Oracle Audit Vault Server - Version : 20.x.0.0.0
Note: If your attempt to log in fails for 3 times or more, then your account gets locked. You need to unlock your account and retry the above mentioned steps.
See Also:
Deleting an Auditor Account
As a Super Auditor, you can delete any auditor account except the last Super Auditor.
-
Log in to the Oracle Database Security Central console as a Super Auditor.
-
Select Settings.
The Manage Auditors page appears by default, and displays existing users and the targets or groups to which they have access.
-
Select the users you want to delete, and then select Delete.
See Also: Logging in to the Oracle Database Security Central Console