Configuring RADIUS Authentication
RADIUS is a client/server security protocol widely used to enable remote authentication and access.
-
About Configuring RADIUS Authentication
Oracle AI Database supports the RADIUS standard for user authentication. -
RADIUS Components
RADIUS has a set of authentication components that enable you to manage configuration settings. -
RADIUS Authentication Modes
The RADIUS server can authenticate users using technologies such as FIDO and text message authentication codes. In addition, Oracle Database supports synchronous and challenge-response (async) authentication modes. -
RADIUS Parameters
Oracle provides a set of RADIUS-specific parameters. -
Enabling RADIUS Authentication, Authorization, and Accounting
You can enable RADIUS authentication, authorization, and accounting from the command line. -
Using RADIUS to Log in to a Database
You can use RADIUS to log into a database by using either synchronous authentication mode or challenge-response mode. -
Integrating Authentication Devices Using RADIUS
The RADIUS challenge-response user interface further enhances authentication in a RADIUS configuration.
About Configuring RADIUS Authentication
Oracle AI Database supports the RADIUS standard for user authentication.
Note: Starting with Oracle AI Database 26ai, the older RADIUS API that is based on Request for Comments (RFC) 2138 is deprecated.Oracle AI Database 26ai introduces an updated RADIUS API based on RFC 6613 and RFC
- Oracle recommends that you start planning on migrating to use the new RADIUS API as soon as possible. The new API is enabled by default. These parameters associated with the older RADIUS API are also deprecated:
SQLNET.RADIUS_ALTERNATE,SQLNET.RADIUS_ALTERNATE_PORT,SQLNET.RADIUS_AUTHENTICATION, andSQLNET.RADIUS_AUTHENTICATION_PORT. Refer to the Radius API documentation for information on changing the default to use the older RADIUS API.
RADIUS is frequently used for multi-factor authentication (MFA) when it is used to access an Oracle AI Database. The specific MFA technologies (such as smart cards or biometric cards) depend on the RADIUS server. The database server and client support asynchronous and synchronous challenges for MFA.
The Oracle AI Database RADIUS implementation uses the TLS/TCPS standards that are described in RFC 6013 and 6014 and is enabled by default by the Oracle AI Database. If you want to use the older implementation (before Oracle AI Database 26ai) using an older RADIUS standard, then you must enable one or both of the SQLNET.RADIUS_ALLOW_WEAK_CLIENTS and SQLNET.RADIUS_ALLOW_WEAK_PROTOCOL parameters to use the older RADIUS implementation.
From an end user’s perspective, the entire authentication process is transparent. When the user seeks access to an Oracle AI Database server, the Oracle AI Database server, acting as the RADIUS client, notifies the RADIUS server. The RADIUS server then:
-
Looks up the user’s security information
-
Passes authentication and authorization information between the appropriate authentication server or servers and the Oracle AI Database server
-
Grants the user access to the Oracle AI Database server
-
Logs session information, including when, how often, and for how long the user was connected to the Oracle AI Database server
Note:
Oracle AI Database does not support RADIUS authentication over database links.
To configure Oracle AI Database to use RADIUS, you will modify parameters in the
sqlnet.orafile. The settings insqlnet.oraapply to all pluggable databases (PDBs).
Figure 26-1 illustrates the Oracle AI Database-RADIUS environment.
Figure 1: RADIUS in an Oracle Environment

Description of the illustration asoag003.png
The Oracle AI Database server acts as the RADIUS client, passing information between the Oracle client and the RADIUS server. Similarly, the RADIUS server passes information between the Oracle AI Databasee server and the appropriate authentication servers.
A RADIUS server vendor is often the authentication server vendor as well. In this case authentication can be processed on the RADIUS server.
Related Topics