Parameters for sqlnet.ora Files

This chapter describes the sqlnet.ora file parameters.

Overview of Profile Configuration Files

Learn about profile configuration files.

The sqlnet.ora file is the Net Services profile configuration file. The sqlnet.ora file resides on clients and databases. You store and implement profiles using this file. You can also configure the database with access control parameters in the sqlnet.ora file. These parameters specify whether clients are allowed or denied access to a database based on the parameter settings.

The sqlnet.ora file enables you to:

Oracle Net searches for the sqlnet.ora file in the following locations and in the following order:

Note:

Profile Parameters in sqlnet.ora Files

These are the sqlnet.ora profile configuration parameters that you use to administer database clients and servers.

Note:

Starting with Oracle AI Database 26ai, the parameter ENCRYPTION_WALLET_LOCATION is desupported.

To store and retrieve the TDE wallet, use the WALLET_ROOT structure (introduced with Oracle Database 18c).

The WALLET_ROOT parameter is described in Oracle AI Database Transparent Data Encryption Guide.

ACCEPT_MD5_CERTS

The sqlnet.ora profile parameter ACCEPT_MD5_CERTS accepts MD5 signed certificates.

Purpose

To enable sqlnet to accept MD5 signed certificates. In addition to sqlnet.ora, you must also set this parameter in listener.ora.

Default

FALSE

Values

ACCEPT_SHA1_CERTS

Use the sqlnet.ora profile parameter ACCEPT_SHA1_CERTS to determine whether SQL Net accepts SHA1 signed certificates.

Purpose

To determine whether sqlnet accepts SHA1 signed certificates. In addition to setting this parameter in sqlnet.ora, you must also set this parameter in listener.ora.

The use of SHA-1 with DBMS_CRYPTO, SQLNET.CRYPTO_CHECKSUM_TYPES_CLIENT and SQLNET.CRYPTO_CHECKSUM_TYPES_SERVER is deprecated.

Using SHA-1 (Secure Hash Algorithm 1) with the parameters SQLNET.CRYPTO_CHECKSUM_TYPES_CLIENT and SQLNET.CRYPTO_CHECKSUM_TYPES_SERVER is deprecated in this release, and can be desupported in a future release. Using SHA-1 ciphers with DBMS_CRYPTO is also deprecated (HASH_SH1, HMAC_SH1). Instead of using SHA1, Oracle recommends that you start using a stronger SHA-2 cipher in place of the SHA-1 cipher.

Default

TRUE

Values

ALLOWED_WEAK_CERT_ALGORITHMS

Use the sqlnet.ora parameter ALLOWED_WEAK_CERT_ALGORITHMS to allow the use of deprecated certification algorithms as an exception.

Purpose

To allow the use of earlier weaker algorithms for backward compatibility. This is useful for environments that still require the use of certificates associated with deprecated algorithms, such as MD5 or SHA1 signed certificates.

Usage Notes

Starting in Oracle AI Database 26ai, the ALLOW_MD5_CERTS and ALLOW_SHA1_CERTS sqlnet.ora parameters are deprecated.

Instead of these parameters, use the ALLOWED_WEAK_CERT_ALGORITHMS sqlnet.ora parameter, which is new with Oracle AI Database 26ai.

If ALLOWED_WEAK_CERT_ALGORITHMS is set, then Oracle Database ignores ALLOW_MD5_CERTS and ALLOW_SHA1_CERTS. If ALLOWED_WEAK_CERT_ALGORITHMS is not set, then Oracle Database checks and uses the ALLOW_MD5_CERTS and ALLOW_SHA1_CERTS settings.

Values

MD5 | SHA1

Oracle Database allows you to use only those weak algorithms that you set here:

Ensure that you enclose the values in parenthesis. If you want to specify both MD5 and SHA1, then separate the values with a comma.

Default

SHA1

Examples

ALLOWED_WEAK_CERT_ALGORITHMS=(SHA1)
ALLOWED_WEAK_CERT_ALGORITHMS=(MD5,SHA1)

Related Topics

AZURE_DB_APP_ID_URI

Use the AZURE_DB_APP_ID_URI parameter to specify the application ID URI of the Oracle Database instance, registered with Microsoft Entra ID (previously called Microsoft Azure Active Directory).

Purpose

To specify the application ID URI that uniquely identifies your database instance in Entra ID.

This URI value is used to compose the authorization scope (permission) of your database token request during token-based authentication:

$Scope = "database_app_id_uri/scope"

For example:

$Scope = "https://application.example.com/123ab4cd-1a2b-1234-a12b-aa00123b2cd3/session:scope:connect"

Here, the app ID URI https://application.example.com/123ab4cd-1a2b-1234-a12b-aa00123b2cd3 is part of the scope.

Usage Notes

This parameter is mandatory. You must set it along with the TOKEN_AUTH parameter for the AZURE_INTERACTIVE, AZURE_SERVICE_PRINCIPAL, AZURE_MANAGED_IDENTITY, and AZURE_DEVICE_CODE authentication flows.

For the JDBC-thin clients, you can specify this parameter in the connect string, Easy Connect syntax, tnsnames.ora file, or properties. For the thick clients (OCI and Instant Client) and ODP.NET core and managed database clients, you can specify this parameter in the connect string, sqlnet.ora file, Easy Connect syntax, or tnsnames.ora file. The parameter value specified in the connect string takes precedence.

Default

None

Value

You can get the application ID URI value by logging in to the Azure portal. This is listed as the Application ID URI value on the App registrations - Overview page.

Note that this is the value that you specified while registering your Oracle Database instance with the Entra ID tenancy, as shown in Oracle AI Database Security Guide.

Examples

In the tnsnames.ora file:

net_service_name=
    (DESCRIPTION =
       (ADDRESS=(PROTOCOL=tcps)(HOST=sales-svr)(PORT=1521))
       (SECURITY=
          (TLS_SERVER_DN_MATCH=TRUE)
          (TLS_SERVER_CERT_DN="C=US,O=example,CN=OracleContext")
          (TOKEN_AUTH=AZURE_INTERACTIVE)
          (AZURE_DB_APP_ID_URI=https://application.example.com/123ab4cd-1a2b-1234-a12b-aa00123b2cd3))
       (CONNECT_DATA=(SERVICE_NAME=sales.us.example.com))
     )

In the sqlnet.ora file:

TLS_SERVER_DN_MATCH=TRUE
TOKEN_AUTH=AZURE_INTERACTIVE
AZURE_DB_APP_ID_URI=https://application.example.com/123ab4cd-1a2b-1234-a12b-aa00123b2cd3

In the Easy Connect string:

tcps:sales-svr:1521/sales.us.example.com?TOKEN_AUTH=AZURE_INTERACTIVE&AZURE_DB_APP_ID_URI=https://application.example.com/123ab4cd-1a2b-1234-a12b-aa00123b2cd3

In these examples, the CLIENT_ID, TENANT_ID, and REDIRECT_URI parameters are not specified. CLIENT_ID and TENANT_ID are required parameters when using the thick clients (OCI and Instant Client). These parameters are optional for the JDBC-thin and ODP.NET core and managed database clients, which can automatically get these values from the Azure SDK configuration.

Related Topics

BEQUEATH_DETACH

Use the sqlnet.ora parameter to enable and disable handling signals on Linux and UNIX systems.

Purpose

To enable or disable signal handling on Linux and UNIX systems

Default

no

Values

Example

BEQUEATH_DETACH=yes

CLIENT_CERTIFICATE

Use the CLIENT_CERTIFICATE parameter to specify the file system path to a client certificate that authenticates your database client application.

Purpose

File system path to a client certificate that authenticates your database client application in Microsoft Entra ID. A client certificate is the digital certificate of an Azure cloud resource, and the client uses this certificate as a credential to prove its identity when requesting an Entra ID access token. This is used for the AZURE_SERVICE_PRINCIPAL token-based authentication flow.

Note: Only the JDBC-thin clients and ODP.NET core and managed database clients (and not the thick clients, such as OCI and Instant Client) support certificate-based authentication.

Usage Notes

Default

None

Value

Full path (including a file name) to the Azure certificate file

Examples

In the tnsnames.ora file:

net_service_name=
    (DESCRIPTION =
       (ADDRESS=(PROTOCOL=tcps)(HOST=sales-svr)(PORT=1521))
       (SECURITY=
          (TLS_SERVER_DN_MATCH=TRUE)
          (TLS_SERVER_CERT_DN="C=US,O=example,CN=OracleContext")
          (TOKEN_AUTH=AZURE_SERVICE_PRINCIPAL)
          (AZURE_DB_APP_ID_URI=https://application.example.com/123ab4cd-1a2b-1234-a12b-aa00123b2cd3)
          (CLIENT_CERTIFICATE=ORACLE_HOME/.azure/certificates/my-app.pem))
       (CONNECT_DATA=(SERVICE_NAME=sales.us.example.com))
     )

In the Easy Connect string:

tcps:sales-svr:1521/sales.us.example.com?TOKEN_AUTH=AZURE_SERVICE_PRINCIPAL&AZURE_DB_APP_ID_URI=https://application.example.com/123ab4cd-1a2b-1234-a12b-aa00123b2cd3&CLIENT_CERTIFICATE=ORACLE_HOME/.azure/certificates/my-app.pem

In these examples, the CLIENT_ID and TENANT_ID parameters are not specified. These parameters are optional for the JDBC-thin and ODP.NET core and managed database clients, which can automatically get these values from the Azure SDK configuration.

Related Topics

CLIENT_ID

Use the CLIENT_ID parameter to specify the ID of the database client Microsoft Entra ID app registration.

Purpose

To specify the client ID assigned to your database client during Entra ID app registration. Note that this is not the client ID for the database server. This application is your database client that requests to get an access token for the user during Azure token-based authentication.

Usage Notes

You use this parameter along with the TOKEN_AUTH parameter for the AZURE_INTERACTIVE, AZURE_SERVICE_PRINCIPAL, AZURE_MANAGED_IDENTITY, and AZURE_DEVICE_CODE authentication flows, as follows:

Note that this parameter is mandatory for the OCI and Instant Clients. It is optional only when using the JDBC-thin clients and ODP.NET core and managed database clients.

For the JDBC-thin clients, you can specify this parameter in the connect string, Easy Connect syntax, tnsnames.ora file, or properties. For the thick clients (OCI and Instant Client) and ODP.NET core and managed database clients, you can specify this parameter in the connect string, sqlnet.ora file, Easy Connect syntax, or tnsnames.ora file. The parameter value specified in the connect string takes precedence.

Default

None

Value

You can get the client ID value by logging in to the Azure portal. This is listed as the Application (client) ID value on the App registrations - Overview page.

Examples

In the tnsnames.ora file:

net_service_name=
    (DESCRIPTION =
       (ADDRESS=(PROTOCOL=tcps)(HOST=sales-svr)(PORT=1521))
       (SECURITY=
          (TLS_SERVER_DN_MATCH=TRUE)
          (TLS_SERVER_CERT_DN="C=US,O=example,CN=OracleContext")
          (TOKEN_AUTH=AZURE_INTERACTIVE)
          (AZURE_DB_APP_ID_URI=https://application.example.com/123ab4cd-1a2b-1234-a12b-aa00123b2cd3)
          (CLIENT_ID=123ab4cd-1a2b-1234-a12b-aa00123b2cd3)
       (CONNECT_DATA=(SERVICE_NAME=sales.us.example.com))
     )

In the sqlnet.ora file:

TLS_SERVER_DN_MATCH=TRUE
TOKEN_AUTH=AZURE_INTERACTIVE
AZURE_DB_APP_ID_URI=https://application.example.com/123ab4cd-1a2b-1234-a12b-aa00123b2cd3
CLIENT_ID=123ab4cd-1a2b-1234-a12b-aa00123b2cd3

In the Easy Connect string:

tcps:sales-svr:1521/sales.us.example.com?TOKEN_AUTH=AZURE_INTERACTIVE&AZURE_DB_APP_ID_URI=https://application.example.com/123ab4cd-1a2b-1234-a12b-aa00123b2cd3&CLIENT_ID=123ab4cd-1a2b-1234-a12b-aa00123b2cd3

In these examples, the TENANT_ID and REDIRECT_URI parameters are not specified. TENANT_ID is required when using the thick clients (OCI and Instant Client). This parameter is optional for the JDBC-thin and ODP.NET core and managed database clients, which can automatically get this value from the Azure SDK configuration.

Related Topics

EXADIRECT_FLOW_CONTROL

The sqlnet.ora profile parameter EXADIRECT_FLOW_CONTROL enables or disables Exadirect flow control.

Purpose

To enable or disable Exadirect flow control.

Usage Notes

Set to on, the parameter enables Oracle Net to broadcast the available receive window to the sender. The sender limits the sends based on the receiver broadcast window.

Default

off

Example

EXADIRECT_FLOW_CONTROL=on

EXADIRECT_RECVPOLL

Use the sqlnet.ora parameter EXADIRECT_RECVPOLL to specify the amount of time that a receiver polls for incoming data.

Purpose

To specify the amount of time that a receiver polls for incoming data.

Usage Notes

You can set the parameter to a fixed value or set the parameter to AUTO to automatically tune the polling value.

Default

0

Example

EXADIRECT_RECVPOLL = 10

EXADIRECT_RECVPOLL = AUTO

DEFAULT_SDU_SIZE

Use the sqlnet.ora profile parameter to specify the session data unit size (SDU) for connections.

Purpose

To specify the SDU size, in bytes, for connections.

Usage Notes

Oracle recommends setting this parameter in both the client-side and server-side sqlnet.ora files to ensure that the same SDU size is used throughout a connection. When the configured values of client and database server do not match for a session, the lower of the two values is used.

You can override this parameter for a particular client connection by specifying the SDU parameter in the connect descriptor for a client.

Default

Value

512 to 2097152 bytes

Example 5-1 Example

DEFAULT_SDU_SIZE=4096

DISABLE_INTERRUPT

Use the sqlnet.ora profile parameter DISABLE_INTERRUPT to disable Oracle Net handling of a SIGINIT signal in client applications.

Purpose

To disable Oracle Net handling of a SIGINIT signal in client applications.

Usage Notes

Oracle Net installs a signal handler to catch a SIGINT signal. By default, the action on receipt of a SIGINIT signal is to cancel the current operation. If you set this parameter to TRUE, then you can override the default behavior and ignore Oracle Net handling of SIGINT signals.

For details on installing and uninstalling your own signal handlers in addition to Oracle Net, see Oracle AI Database Administrator’s Reference for Linux and UNIX-Based Operating Systems.

Default

FALSE

Example

DISABLE_INTERRUPT=TRUE

DISABLE_OOB

Use the sqlnet.ora profile parameter DISABLE_OOB to enable or disable Oracle Net to send or receive out-of-band break messages using urgent data from the underlying protocol.

Purpose

To enable or disable Oracle Net to send or receive out-of-band break messages using urgent data provided by the underlying protocol.

Usage Notes

Set to off, the parameter enables Oracle Net to send and receive break messages. Set to on, the parameter disables the ability to send and receive break messages. Once enabled, this feature applies to all protocols that the client uses.

Default

off

Example 5-2 Example

DISABLE_OOB=on

DISABLE_OOB_AUTO

Use the sqlnet.ora profile parameter DISABLE_OOB_AUTO to disable server path checks for out-of-band break messages at the time of the connection.

Purpose

To disable sqlnet.ora from checking for out-of-band (OOB) break messages in the server path at connection time.

Usage Notes

By default, the client determines if the server path supports out-of-band break messages at the time of establishing the connection. If DISABLE_OOB_AUTO is set to TRUE, then the client does not perform this check at connection time.

Default

FALSE

Example 5-3 Example

DISABLE_OOB_AUTO = TRUE

IPC.KEYPATH

Use the sqlnet.ora profile parameter IPC.KEYPATH to specify the destination directory where the internal file is created for UNIX domain sockets.

Purpose

To specify the destination directory where the internal file is created for UNIX domain sockets.

Usage Notes

This parameter applies only to Oracle Net usage of UNIX domain sockets and does not apply to other uses of UNIX domain sockets in Oracle Database, such as in Oracle Clusterware. If you use the IPC.KEYPATH parameter, then you should use the same value for IPC_KEYPATH on both the client and the listener on Oracle Database versions that are greater than Oracle Database 18c.

Default

The directory path is either /var/tmp/.oracle for Oracle Linux, Oracle Solaris or /tmp/.oracle for other UNIX variants.

Example

ipc.keypath=/home/oracleuser.

KERBEROS5_DELEGATION_MODE

Use the KERBEROS5_DELEGATION_MODE parameter to control whether the Kerberos Ticket Granting Ticket (TGT) is forwarded when authenticating to a remote server for enhanced security.

Purpose

To allow the client to control the forwarding of the TGT to the database server for enhanced security.

Usage Notes

Use this parameter in the SECURITY section of the tnsnames.ora file, or set it in the sqlnet.ora file.

Set this parameter to UNCONSTRAINED to enable forwarding of the client’s TGT. Once a service is granted unconstrained delegation privileges, it can use the user’s credentials to access any service on the network on behalf of the user.

Note:

If the client is on Windows and using MSLSA, Credential Guard blocks TGT forwarding by default. Setting the parameter to UNCONSTRAINED will not change this behavior, and the TGT will not be forwarded.

Set the parameter to CONSTRAINED to disable TGT forwarding to the database server and reduce the risks associated with delegation by limiting the services that can be accessed using a user’s credentials.

Note:

Values

Default

UNCONSTRAINED

Examples

Related Topics

KERBEROS5_PRINCIPAL

Use the KERBEROS5_PRINCIPAL parameter to set the Kerberos principal name associated with the Kerberos credentials cache (CC) file.

Purpose

When you configure Kerberos authentication for an Oracle Database client, you can specify multiple Kerberos principals with a single Oracle Database client.

This is an optional parameter. When specified, it is used to verify if the principal name in the credential cache (specified using KERBEROS5_CC_NAME) matches the parameter value.

Usage Notes

Use this parameter in the SECURITY section of the tnsnames.ora file, or set it in the sqlnet.ora file. Alternatively, you can set KERBEROS5_PRINCIPAL in the connect string along with the KERBEROS5_CC_NAME parameter to connect as a different Kerberos principal.

The parameter value specified in the connect string takes precedence over the value specified in the sqlnet.ora or tnsnames.ora file.

Each Kerberos principal must have a valid credential cache. Oracle Database checks KERBEROS5_PRINCIPAL against the value that is retrieved from the credential cache. If the two values do not match, then the user is not authenticated.

Examples

Note: The connection fails if the principal in the /tmp/krbuser1/krb.cc file does not contain the krbprinc1@example.com value.

Related Topics

MAX_CONDUITS

Use the sqlnet.ora parameter MAX_CONDUITS to specify the maximum number of conduits between the listener and the broker or dispatcher for handing off client connections.

Purpose

To set the maximum number of conduits created between the listener and the broker or dispatcher processes over which client connections are handed off.

Usage Notes

Setting a higher value enables multiple connections to be handed off in parallel, which is particularly useful during a logon storm when there is a spike in incoming connections.

Default

50

Example

MAX_CONDUITS=80

NAMES.DEFAULT_DOMAIN

Use the sqlnet.ora profile parameter NAMES.DEFAULT_DOMAIN to set the name of the domain in which clients most often look up names resolution requests.

Purpose

To set the domain from which the client most often looks up names resolution requests.

Usage Notes

When you set NAMES.DEFAULT_DOMAIN, the default domain name is automatically appended to any unqualified net service name or service name.

For example, if you set the default domain to www.example.com, then Oracle searches the connect string CONNECT scott@sales as www.example.com. If the connect string includes the domain extension, such as CONNECT scott@sales.www.example.com, then the domain is not appended to the string.

Default

None

Example

NAMES.DEFAULT_DOMAIN=example.com

NAMES.DIRECTORY_PATH

Use the sqlnet parameter NAMES.DIRECTORY_PATH to specify the order of the naming methods for client name resolution lookups.

Purpose

To specify the order of the naming methods for client name resolution lookups.

Default

NAMES.DIRECTORY_PATH=(tnsnames, ezconnect, ldap)

Values

The following table shows the NAMES.DIRECTORY_PATH values for the naming methods.

Naming Method Value Description
tnsnames (local naming method) Set to resolve a network service name through the tnsnames.ora file on the client.
ldap(directory naming method) Set to resolve a database service name, net service name, or network service alias through a directory server.
ezconnect or hostname (Easy Connect naming method) Select to enable clients to use a TCP/IP connect identifier that consists of a host name and optional port and service name.
nis (external naming method) Set to resolve service information through an existing Network Information Service (NIS).

Example

NAMES.DIRECTORY_PATH=(tnsnames)

NAMES.LDAP_AUTHENTICATE_BIND

Use the sqlnet parameter NAMES.LDAP_AUTHENTICATE_BIND to specify whether the LDAP naming adapter should authenticate using a specified wallet when it connects to the LDAP directory to resolve connect string names.

Purpose

To specify whether the LDAP naming adapter should attempt to authenticate using a specified wallet when it connects to the LDAP directory to resolve the service name in the connect string.

Usage Notes

When set to FALSE, the LDAP connection is established using an anonymous bind.

When set to TRUE, the LDAP connection is authenticated using an Oracle wallet. You must specify the wallet location using the WALLET_LOCATION parameter.

The parameter WALLET_LOCATION is deprecated for use with Oracle AI Database 26ai for the Oracle Database server. It is not deprecated for use with the Oracle Database client or listener.

For Oracle Database server, Oracle recommends that you use the WALLET_ROOT system parameter instead of using WALLET_LOCATION.

Values

TRUE | FALSE

Default

FALSE

Example

NAMES.LDAP_AUTHENTICATE_BIND=TRUE

NAMES.LDAP_AUTHENTICATE_BIND_METHOD

Use the sqlnet parameter NAMES.LDAP_AUTHENTICATE_BIND_METHOD to specify an authentication method for the client LDAP naming adapter.

Purpose

To specify the authentication method that the client LDAP naming adapter should use while connecting to the LDAP directory to resolve connect string names.

Usage Notes

The simple authentication method over LDAPS (LDAP over TLS connection) is supported.

You store the directory entry DN and password in an Oracle wallet. When the client connects to the LDAP server, it is authenticated using the credentials stored in this wallet. The wallet trust store must contain root certificates issued by the certificate authority of the LDAP server.

The LDAP naming adapter uses the oracle.ldap.client.dn and ` oracle.ldap.client.password` entries from the wallet for authenticating to the LDAP server. If these entries are not present, then the client attempts an anonymous authentication using TLS or LDAPS.

Values

Default

NONE

Example

NAMES.LDAP_AUTHENTICATE_BIND_METHOD=LDAPS_SIMPLE_AUTH

Related Topics

NAMES.LDAP_CONN_TIMEOUT

Use the sqlnet parameter NAMES.LDAP_CONN_TIMEOUT to specify the number of seconds that indicates that a non-blocking connect timeout to the LDAP server occurred.

Purpose

The parameter value -1 is for infinite timeout.

Default

15 seconds

Values

Values are in seconds. The range is -1 to the number of seconds that is acceptable for your environment. There is no upper limit.

To specify the number of seconds for a non-blocking connect timeout to the LDAP server.

Usage Notes

Example

names.ldap_conn_timeout = -1

NAMES.LDAP_PERSISTENT_SESSION

Use the sqlnet parameter NAMES.LDAP_PERSISTENT_SESSION to specify whether the LDAP naming adapter should leave the session with the LDAP server open after name lookups are complete.

Purpose

To specify whether the LDAP naming adapter should leave the session with the LDAP server open after a name lookup is complete.

Usage Notes

The parameter value is Boolean.

If you set the parameter to TRUE, then the connection to the LDAP server is left open after the name lookup is complete. The connection remains open for the duration of the process. If the connection is lost, then it is re-established as needed.

If you set the parameter to FALSE, then the LDAP connection is terminated as soon as the name lookup completes. Every subsequent look-up opens the connection, performs the look-up, and closes the connection. This option prevents LDAP from having a large number of clients connected to it at any one time.

Default

false

Example

NAMES.LDAP_PERSISTENT_SESSION=true

NAMES.NIS.META_MAP

Use the sqlnet parameter NAMES.NIS.META_MAP to specify the map file to use to map Network Information Service (NIS) attributes to an NIS mapname.

Purpose

To specify the map file to be used to map Network Information Service (NIS) attributes to an NIS mapname.

Default

sqlnet.maps

Example

NAMES.NIS.META_MAP=sqlnet.maps

OCI_COMPARTMENT

Use the OCI_COMPARTMENT parameter to specify Oracle Cloud Identifier (OCID) of the compartment that holds database instances for client connections.

Purpose

To define the scope of your database token request. This value instructs the database client to initiate a token request to databases within the specified compartment only. You use this parameter while configuring token-based authentication for Oracle Cloud Infrastructure (OCI) Identity and Access Management (IAM) users on OCI Database as a Service (DBaaS).

Usage Notes

The OCI_COMPARTMENT parameter is optional if you have not specified the OCI_DATABASE parameter. If you choose to set OCI_DATABASE, then you must also set OCI_COMPARTMENT to limit your token request to the specified database within that compartment.

If you do not set both the OCI_COMPARTMENT and OCI_DATABASE parameters, then the entire tenancy is the scope of your token request.

You can use this parameter along with the PASSWORD_AUTH and TOKEN_AUTH authentication settings:

Use this parameter under the SECURITY section of the tnsnames.ora file, sqlnet.ora file, Easy Connect syntax, or directly as part of the command-line connect string. The parameter value specified in the connect string takes precedence over the other specified values.

Default

None

Value

OCID for the IAM compartment to allow access for the database token. You can get the OCID value for your compartment from the Compartments information page in the OCI console.

The compartment OCID uses this syntax:

OCI_COMPARTMENT=compartment_OCID

For details on the syntax options, see Oracle Cloud IDs (OCIDs).

Examples

In the tnsnames.ora file:

net_service_name=
  (DESCRIPTION=
     (ADDRESS=(PROTOCOL=tcps)(HOST=salesserver1)(PORT=1522))
     (SECURITY=
        (TLS_SERVER_DN_MATCH=TRUE)
        (TLS_SERVER_CERT_DN="C=US,O=example,CN=OracleContext")
        (PASSWORD_AUTH=OCI_TOKEN)
        (OCI_IAM_URL=https://auth.us-region-
1.example.com/v1/actions/generateScopedAccessBearerToken)
        (OCI_TENANCY=ocid1.tenancy..12345)
        (OCI_COMPARTMENT=ocid1.compartment..12345)
        (OCI_DATABASE=ocid1.autonomousdatabase.oc1.12345))
     (CONNECT_DATA=(SERVICE_NAME=sales.us.example.com))
  )

In the sqlnet.ora file:

TLS_SERVER_DN_MATCH=TRUE
PASSWORD_AUTH=OCI_TOKEN
OCI_IAM_URL=https://auth.us-region-1.example.com/v1/actions/generateScopedAccessBearerToken
OCI_TENANCY=ocid1.tenancy..12345
OCI_COMPARTMENT=ocid1.compartment..12345
OCI_DATABASE=ocid1.autonomousdatabase.oc1.12345

In the Easy Connect syntax:

tcps:sales-svr:1521/sales.us.example.com?TOKEN_AUTH=OCI_INTERACTIVE&OCI_COMPARTMENT=ocid1.compartment..12345&OCI_DATABASE=ocid1.autonomousdatabase.oc1.12345

Related Topics

OCI_CONFIG_FILE

Use the OCI_CONFIG_FILE parameter to specify the directory location where the Oracle Cloud Infrastructure (OCI) configuration file is stored.

Purpose

To specify the directory location of the OCI configuration file. This file stores the client connection information for OCI Identity and Access Management (IAM) users as part of their profile. The SDK, CLI, and other OCI tools use this file to access the IAM user credentials during IAM token-based authentication.

Usage Notes

This is an optional parameter. If you do not set this parameter, then the database client gets the user’s profile from the default configuration file located at C:/user-profile/.oci/config. You can use this parameter to override the default configuration file location. In this case, the database client searches for the profile in the location specified by OCI_CONFIG_FILE.

You can use this parameter along with the TOKEN_AUTH parameter for the OCI_API_KEY and OCI_INTERACTIVE authentication flows:

For JDBC-thin clients, you can specify this parameter in the Easy Connect syntax or tnsnames.ora connect string. For ODP.NET Core classes and ODP.NET Managed Driver classes, you can specify this parameter in the sqlnet.ora file, Easy Connect syntax, or tnsnames.ora connect string. The parameter value specified in the connect string takes precedence.

Default

None

Value

Full path (including a file name) to the OCI configuration file

Examples

In the tnsnames.ora file:

net_service_name=
    (DESCRIPTION =
       (ADDRESS=(PROTOCOL=tcps)(HOST=sales-svr)(PORT=1521))
       (SECURITY=
          (TLS_SERVER_DN_MATCH=TRUE)
          (TLS_SERVER_CERT_DN="C=US,O=example,CN=OracleContext")
          (TOKEN_AUTH=OCI_INTERACTIVE)
          (OCI_CONFIG_FILE=/home/dbuser1/config))
       (CONNECT_DATA=(SERVICE_NAME=sales.us.example.com))
     )

In the sqlnet.ora file:

TLS_SERVER_DN_MATCH=TRUE
TOKEN_AUTH=OCI_INTERACTIVE
OCI_CONFIG_FILE=/home/dbuser1/config

In the Easy Connect string:

tcps:sales-svr:1521/sales.us.example.com?TOKEN_AUTH=OCI_INTERACTIVE&OCI_CONFIG_FILE=/home/dbuser1/config

In these examples, the optional OCI_PROFILE parameter is not specified. Thus, the client automatically gets the DEFAULT profile from the specified configuration file directory.

Related Topics

OCI_DATABASE

Use the OCI_DATABASE parameter to specify Oracle Cloud Identifier (OCID) of the database that you want to access for the client connection.

Purpose

To define the scope of your database token request. The database OCID value instructs the database client to initiate a token request to the specified database within your compartment. You use this parameter while configuring token-based authentication for Oracle Cloud Infrastructure (OCI) Identity and Access Management (IAM) users on OCI Database as a Service (DBaaS).

Usage Notes

This is an optional parameter. You can set this parameter to limit the access to only a particular database. If you set OCI_DATABASE, then you must also provide specific compartment identifier using the OCI_COMPARTMENT parameter.

You can use this parameter along with the PASSWORD_AUTH and TOKEN_AUTH authentication settings:

Specify this parameter under the SECURITY section of the tnsnames.ora file, sqlnet.ora file, Easy Connect syntax, or directly as part of the command-line connect string. The parameter value specified in the connect string takes precedence.

Default

None

Value

OCID of the database that you want to access for the client connection. You can get the OCID value for your database from the Database details page in the OCI console.

The database OCID uses this syntax:

OCI_DATABASE=database_OCID

For details on the syntax options, see Oracle Cloud IDs (OCIDs).

Examples

In the tnsnames.ora file:

net_service_name=
  (DESCRIPTION=
     (ADDRESS=(PROTOCOL=tcps)(HOST=salesserver1)(PORT=1522))
     (SECURITY=
        (TLS_SERVER_DN_MATCH=TRUE)
        (TLS_SERVER_CERT_DN="C=US,O=example,CN=OracleContext")
        (PASSWORD_AUTH=OCI_TOKEN)
        (OCI_IAM_URL=https://auth.us-region-1.example.com/v1/actions/generateScopedAccessBearerToken)
        (OCI_TENANCY=ocid1.tenancy..12345)
        (OCI_COMPARTMENT=ocid1.compartment..12345)
        (OCI_DATABASE=ocid1.autonomousdatabase.oc1.12345))
     (CONNECT_DATA=(SERVICE_NAME=sales.us.example.com))
  )

In the sqlnet.ora file:

TLS_SERVER_DN_MATCH=TRUE
PASSWORD_AUTH=OCI_TOKEN
OCI_IAM_URL=https://auth.us-region-1.example.com/v1/actions/generateScopedAccessBearerToken
OCI_TENANCY=ocid1.tenancy..12345
OCI_COMPARTMENT=ocid1.compartment..12345
OCI_DATABASE=ocid1.autonomousdatabase.oc1.12345

In the Easy Connect syntax:

tcps:sales-svr:1521/sales.us.example.com?TOKEN_AUTH=OCI_INTERACTIVE&OCI_COMPARTMENT=ocid1.compartment..12345&OCI_DATABASE=ocid1.autonomousdatabase.oc1.12345

Related Topics

OCI_IAM_URL

Use the OCI_IAM_URL parameter to specify an endpoint URL that the database client must connect with to get the database token for authenticating Oracle Cloud Infrastructure (OCI) Identity and Access Management (IAM) users on OCI Database as a Service (DBaaS).

Purpose

To specify the IAM URL for your REST API requests. The database client connects to this URL to retrieve the database token from IAM.

Usage Notes

You set the OCI_IAM_URL parameter along with the PASSWORD_AUTH and OCI_TENANCY parameters while configuring IAM token-based authentication (using the IAM user name and IAM database password to retrieve the database token). These parameters are mandatory.

With this configuration, the database client can only request an IAM database token using the IAM user name and IAM database password. The client cannot request an IAM database token for an API-key, delegation token, security token, resource principal, service principal, or instance principal.

You can also set the optional OCI_COMPARTMENT and OCI_DATABASE parameters to specify the scope of your token request.

Use this parameter under the SECURITY section of the tnsnames.ora file, sqlnet.ora file, or directly as part of the command-line connect string. The parameter value specified in the connect string takes precedence over the other specified values.

Default

None

Value

OCI IAM endpoint URL that the database client must connect with to get the database token. This URL is specific to your region and uses this syntax:

<authentication_regional_endpoint>/v1/actions/generateScopedAccessBearerToken

You can derive this value by replacing <authentication_regional_endpoint> with the API endpoint URL for your region. To obtain the appropriate API endpoint URL, see Identity and Access Management Data Plane API.

For example, if you want to use the URL as https://auth.us-region-1.example.com, then your OCI_IAM_URL value is:

https://auth.us-region-1.example.com/v1/actions/generateScopedAccessBearerToken

Examples

In the tnsnames.ora file:

net_service_name=
  (DESCRIPTION=
     (ADDRESS=(PROTOCOL=tcps)(HOST=salesserver1)(PORT=1522))
     (SECURITY=
        (TLS_SERVER_DN_MATCH=TRUE)
        (TLS_SERVER_CERT_DN="C=US,O=example,CN=OracleContext")
        (PASSWORD_AUTH=OCI_TOKEN)
        (OCI_IAM_URL=https://auth.us-region-1.example.com/v1/actions/generateScopedAccessBearerToken)
        (OCI_TENANCY=ocid1.tenancy..12345))
     (CONNECT_DATA=(SERVICE_NAME=sales.us.example.com))
  )

In the sqlnet.ora file:

TLS_SERVER_DN_MATCH=TRUE
PASSWORD_AUTH=OCI_TOKEN
OCI_IAM_URL=https://auth.us-region-1.example.com/v1/actions/generateScopedAccessBearerToken
OCI_TENANCY=ocid1.tenancy..12345

In these examples, the optional OCI_COMPARTMENT and OCI_DATABASE parameters are not specified and thus the entire tenancy is set as the scope of the token request.

Related Topics

OCI_PROFILE

Use the OCI_PROFILE parameter to specify the profile name for Oracle Cloud Infrastructure (OCI) Identity and Access Management (IAM) users.

Purpose

To specify the profile name for IAM users. This profile is the client connection information stored in the OCI configuration file, and is used during IAM token-based authentication.

Usage Notes

Values

Default

DEFAULT

Examples

In the tnsnames.ora file:

net_service_name=
    (DESCRIPTION =
       (ADDRESS=(PROTOCOL=tcps)(HOST=sales-svr)(PORT=1521))
       (SECURITY=
          (TLS_SERVER_DN_MATCH=TRUE)
          (TLS_SERVER_CERT_DN="C=US,O=example,CN=OracleContext")
          (TOKEN_AUTH=OCI_INTERACTIVE)
          (OCI_CONFIG_FILE=/home/dbuser1/config))
          (OCI_PROFILE=ADMIN_USER))
       (CONNECT_DATA=(SERVICE_NAME=sales.us.example.com))
     )

In the sqlnet.ora file:

TLS_SERVER_DN_MATCH=TRUE
TOKEN_AUTH=OCI_INTERACTIVE
OCI_CONFIG_FILE=/home/dbuser1/config
OCI_PROFILE=ADMIN_USER

In the Easy Connect string:

tcps:sales-svr:1521/sales.us.example.com?TOKEN_AUTH=OCI_INTERACTIVE&OCI_CONFIG_FILE=/home/dbuser1/config&OCI_PROFILE=ADMIN_USER

Related Topics

OCI_TENANCY

Use the OCI_TENANCY parameter to specify Oracle Cloud Identifier (OCID) of the user’s tenancy.

Purpose

To specify OCID of the user’s tenancy (root compartment).

Usage Notes

You set this parameter along with the mandatory PASSWORD_AUTH and OCI_IAM_URL parameters while configuring token-based authentication for Oracle Cloud Infrastructure (OCI) Identity and Access Management (IAM) users on OCI Database as a Service (DBaaS).

With this configuration, the database client can only request an IAM database token using the IAM user name and IAM database password. The client cannot request an IAM database token for an API-key, delegation token, security token, resource principal, service principal, or instance principal.

You can also set the optional OCI_COMPARTMENT and OCI_DATABASE parameters to specify the scope of your token request. If you do not set the OCI_COMPARTMENT and OCI_DATABASE parameter values, then the entire tenancy is the scope of your token request.

Use this parameter under the SECURITY section of the tnsnames.ora file, sqlnet.ora file, or directly as part of the command-line connect string. The parameter value specified in the connect string takes precedence over the other specified values.

Default

None

Value

OCID of the user’s tenancy. You can get the OCID value for your tenancy from the Tenancy information page in the OCI console.

The tenancy OCID uses this syntax:

OCI_TENANCY=tenancy_OCID

For details on the syntax options, see Oracle Cloud IDs (OCIDs).

Examples

In the tnsnames.ora file:

net_service_name=
  (DESCRIPTION=
     (ADDRESS=(PROTOCOL=tcps)(HOST=salesserver1)(PORT=1522))
     (SECURITY=
        (TLS_SERVER_DN_MATCH=TRUE)
        (TLS_SERVER_CERT_DN="C=US,O=example,CN=OracleContext")
        (PASSWORD_AUTH=OCI_TOKEN)
        (OCI_IAM_URL=https://auth.us-region-1.example.com/v1/actions/generateScopedAccessBearerToken)
        (OCI_TENANCY=ocid1.tenancy..12345))
     (CONNECT_DATA=(SERVICE_NAME=sales.us.example.com))
  )

In the sqlnet.ora file:

TLS_SERVER_DN_MATCH=TRUE
PASSWORD_AUTH=OCI_TOKEN
OCI_IAM_URL=https://auth.us-region-1.example.com/v1/actions/generateScopedAccessBearerToken
OCI_TENANCY=ocid1.tenancy..12345

In these examples, the optional OCI_COMPARTMENT and OCI_DATABASE parameters are not specified and thus the entire tenancy is set as the scope of the token request.

Related Topics

PASSWORD_AUTH

Use the PASSWORD_AUTH parameter to configure an authentication method for Oracle Cloud Infrastructure (OCI) Identity and Access Management (IAM) users on OCI Database as a Service (DBaaS). With this setting, client connections use the IAM user name and IAM database password for logging in users to the database.

Purpose

To configure either IAM database password verifier authentication or IAM token-based authentication, using the IAM user name and IAM database password for the access.

For password verifier authentication, the database server retrieves an IAM database password verifier from IAM. For token-based authentication, the database client requests a database token (db-token) from IAM.

Usage Notes

Note:

You can also use other IAM user credentials (such as API-key, security token, resource principal, service principal, instance principal, or delegation token) to get the db-token. This db-token is a proof-of-possession (PoP) token. In this case, you use a different parameter setting (TOKEN_AUTH=OCI_TOKEN).

Unlike the IAM database password that can only be used by the database client to retrieve the token, these credentials require an application or tool to retrieve the token. See TOKEN_AUTH.

Default

PASSWORD_VERIFIER

Values and Examples

Value Example

For IAM database password verifier authentication:

PASSWORD_AUTH=PASSWORD_VERIFIER

Note: Use of IAM user name and IAM database password with the IAM database password verifier is the default configuration, and you do not need to set any additional parameters for the client.

However, if PASSWORD_AUTH is set to OCI_TOKEN in the client-side sqlnet.ora file, then the client tries to connect with OCI IAM to retrieve a database token using the IAM user name and IAM database password. In this case, you can override this setting for a particular connection using PASSWORD_AUTH=PASSWORD_VERIFIER.

In the tnsnames.ora file:

net_service_name= (DESCRIPTION = (ADDRESS=(PROTOCOL=tcps)(HOST=sales-svr)(PORT=1521)) (SECURITY= (TLS_SERVER_DN_MATCH=TRUE) (TLS_SERVER_CERT_DN="C=US,O=example,CN=OracleContext") (PASSWORD_AUTH=PASSWORD_VERIFIER)) (CONNECT_DATA=(SERVICE_NAME=sales.us.example.com)) )  

In the sqlnet.ora file:

PASSWORD_AUTH=PASSWORD_VERIFIER

For IAM token-based authentication with the IAM user name and IAM database password:

PASSWORD_AUTH=OCI_TOKEN

Note: You must configure the TCPS protocol (PROTOCOL=tcps) and set the TLS_SERVER_DN_MATCH parameter to TRUE for token-based authentication.

In the tnsnames.ora file:

net_service_name= (DESCRIPTION= (ADDRESS=(PROTOCOL=tcps)(HOST=salesserver1)(PORT=1522)) (SECURITY= (TLS_SERVER_DN_MATCH=TRUE) (TLS_SERVER_CERT_DN="C=US,O=example,CN=OracleContext") (PASSWORD_AUTH=OCI_TOKEN) (OCI_IAM_URL=https://auth.us-region-1.example.com/v1/actions/generateScopedAccessBearerToken) (OCI_TENANCY=ocid1.tenancy..12345)) (CONNECT_DATA=(SERVICE_NAME=sales.us.example.com))  ) 

In the sqlnet.ora file:

TLS_SERVER_DN_MATCH=TRUE PASSWORD_AUTH=OCI_TOKEN OCI_IAM_URL=https://auth.us-region-1.example.com/v1/actions/generateScopedAccessBearerToken OCI_TENANCY=ocid1.tenancy..12345

In these examples, the optional OCI_COMPARTMENT and OCI_DATABASE parameters are not specified and thus the entire tenancy is set as the scope of the token request.

Related Topics

RECV_BUF_SIZE

Use the sqlnet parameter RECV_BUF_SIZE to specify buffer space limit for session receive operations.

Purpose

To specify the buffer space limit for receive operations of sessions.

Usage Notes

You can override this parameter for a particular client connection by specifying the RECV_BUF_SIZE parameter in the connect descriptor for a client.

This parameter is supported by the TCP/IP, TCP/IP with TLS, and SDP protocols.

Note: Additional protocols might support this parameter on certain operating systems. Refer to the operating system-specific documentation for additional information about additional protocols that support this parameter.

Default

The default value for this parameter is operating system specific. The default for Linux 2.6 operating system is 87380 bytes.

Example

RECV_BUF_SIZE=11784

Related Topics

REDIRECT_URI

Use the REDIRECT_URI parameter to specify the redirect URI, registered for your Microsoft Entra ID client application.

Purpose

To specify the redirect URI (or reply URL), registered for your Entra ID client application. This is used for the AZURE_INTERACTIVE token-based authentication flow. This URL obtains the authorization code from the Entra authentication endpoint and determines which port to use to receive the authorization code.

Usage Notes

This is an optional parameter. If you do not specify this parameter, then it uses the default value of http://localhost, which is the most common redirect URL.

Specify this parameter only if necessary for your use case. The authorization server redirects the user to your specified address only if you have registered the redirect URI for the client application in the Azure portal, as shown in Oracle AI Database Security Guide.

You can specify this parameter along with the TOKEN_AUTH=AZURE_INTERACTIVE setting in the connect string, Easy Connect syntax, or tnsnames.ora file. The parameter value specified in the connect string takes precedence.

Default

The default redirect URI for all clients is:

http://localhost

Value

You can get a redirect URI value by logging in to the Azure portal. All URI values are listed as Redirect URIs on the App registrations - Authentication page of your Entra ID service.

Note that this is the value that you specified while registering your database client application with Entra ID.

Examples

In the tnsnames.ora file:

net_service_name=
    (DESCRIPTION =
       (ADDRESS=(PROTOCOL=tcps)(HOST=sales-svr)(PORT=1521))
       (SECURITY=
          (TLS_SERVER_DN_MATCH=TRUE)
          (TLS_SERVER_CERT_DN="C=US,O=example,CN=OracleContext")
          (TOKEN_AUTH=AZURE_INTERACTIVE)
          (AZURE_DB_APP_ID_URI=https://application.example.com/123ab4cd-1a2b-1234-a12b-aa00123b2cd3)
          (REDIRECT_URI=http://localhost:1575))
       (CONNECT_DATA=(SERVICE_NAME=sales.us.example.com))
     )

In the Easy Connect string:

tcps:sales-svr:1521/sales.us.example.com?TOKEN_AUTH=AZURE_INTERACTIVE&AZURE_DB_APP_ID_URI=https://application.example.com/123ab4cd-1a2b-1234-a12b-aa00123b2cd3&REDIRECT_URI=http://localhost:1575

In these examples, the CLIENT_ID and TENANT_ID parameters are not specified. CLIENT_ID and TENANT_ID are required parameters when using the thick clients (OCI and Instant Client). These parameters are optional for the JDBC-thin and ODP.NET core and managed database clients, which can automatically get these values from the Azure SDK configuration.

Related Topics

SDP.PF_INET_SDP

Use the sqlnet parameter SDP.PF_INET_SDP to specify the protocol family or address family constant for the SDP protocol on your system.

Purpose

To specify the protocol family or address family constant for the SDP protocol on your system.

Default

27

Values

Any positive integer

Example

SDP.PF_INET_SDP=30

SEC_USER_AUDIT_ACTION_BANNER

Use the sqlnet parameter SEC_USER_AUDIT_ACTION_BANNER to specify a text file that contains the banner contents that warn users about user action auditing.

Purpose

To specify a text file containing the banner contents that warn users about possible user action auditing.

Usage Notes

You must specify the complete path of the text file in the sqlnet.ora file on the server. Oracle Call Interface (OCI) applications can use OCI features to retrieve this banner and display it to users.

Default

None

Values

Name of the file for which the database owner has read permissions.

Example

SEC_USER_AUDIT_ACTION_BANNER=/opt/oracle/admin/data/auditwarning.txt

SEC_USER_UNAUTHORIZED_ACCESS_BANNER

Use the sqlnet parameter SEC_USER_UNAUTHORIZED_ACCESS_BANNER to specify the file that contains the banner contents that warn users about unauthorized database access.

Purpose

To specify the name of a text file containing the banner contents that warn users about unauthorized access to the database.

Usage Notes

You must specify the complete path of the text file in the sqlnet.ora file on the server. OCI applications can use OCI features to retrieve this banner and display it to users.

Default

None

Values

Name of the banner file for which the database owner has read permissions.

Example

SEC_USER_UNAUTHORIZED_ACCESS_BANNER=/opt/oracle/admin/data/unauthwarning.txt

SEND_BUF_SIZE

Use the sqlnet parameter SEND_BUF_SIZE to specify the buffer space limit for session send operations.

Purpose

To specify the buffer space limit for send operations of sessions.

Usage Notes

You can override this parameter for a particular client connection by specifying the SEND_BUF_SIZE parameter in the connect descriptor for a client.

This parameter is supported by the TCP/IP, TCP/IP with TLS, and SDP protocols.

Note: Additional protocols might support this parameter on certain operating systems. Refer to the operating system-specific documentation for additional information about additional protocols that support this parameter.

Default

The default value for this parameter is operating system specific. The default for Linux 2.6 operating systems is 16 KB.

Example

SEND_BUF_SIZE=11784

Related Topics

SEPS_WALLET_LOCATION

Use the SEPS_WALLET_LOCATION parameter to specify the wallet location for secure external password store (SEPS) and to enable the use of specified wallet for authentication.

Purpose

To specify the directory path of the client-side oracle wallet and to configure the client to use secure external password store for authentication purposes. Setting this parameter causes all CONNECT /@db_connect_string statements to use the information in the SEPS wallet at the specified location to authenticate to databases.

Usage Notes

You can set SEPS_WALLET_LOCATION in the sqlnet.ora file to specify a common wallet location for all connections. You can also set it in the connect string or tnsnames.ora file to specify a different wallet location for a particular connection.

Use of SEPS_WALLET_LOCATION in the connect string or tnsnames.ora overrides the sqlnet.ora SEPS_WALLET_LOCATION setting for the specific tnsnames.ora service.

To disable authentication using SEPS, you must unset SEPS_WALLET_LOCATION parameter. You must also unset SQLNET.WALLET_OVERRIDE or set it to FALSE in sqlnet.ora file.

Note: If the SEPS_WALLET_LOCATION parameter is set, the SQLNET.WALLET_OVERRIDE parameter is ignored.

Default

None

Examples

If you created the wallet in $ORACLE_HOME/network/admin and your Oracle home is set to/private/ora_db, then you need to enter the following into your client sqlnet.ora file.

SEPS_WALLET_LOCATION=/private/ora_db/network/admin

You can also set this parameter under the SECURITY section of the tnsnames.ora or directly as part of the command-line connect string. The parameter value specified in the connect string take precedence over the other specified values.

net_service_name=
  (DESCRIPTION=
    (ADDRESS=(PROTOCOL=tcps)(HOST=sales-svr)(PORT=1521))
    (CONNECT_DATA=(SERVICE_NAME=sales.us.example.com))
    (SECURITY=(SEPS_WALLET_LOCATION=/private/ora_db/network/admin)))
  )

Related Topics

SQLNET.ALLOW_WEAK_CRYPTO

Use the sqlnet.ora compatibility parameter SQLNET.ALLOW_WEAK_CRYPTO to configure your client-side network connection by reviewing the specified encryption and crypto-checksum algorithms.

Purpose

To configure your client-side network connection by reviewing the encryption and crypto-checksum algorithms enabled on the client and server. This ensures that the connection does not encounter compatibility issues and your configuration uses supported strong algorithms.

Usage Notes

Values

Default Value

TRUE

Recommended Value

FALSE

Note: Before setting this parameter to FALSE, you must remove all deprecated algorithms listed in the server and client sqlnet.ora files.

Example

SQLNET.ALLOW_WEAK_CRYPTO = FALSE

Related Topics

SQLNET.ALLOW_WEAK_CRYPTO_CLIENTS

Use the sqlnet.ora compatibility parameter SQLNET.ALLOW_WEAK_CRYPTO_CLIENTS to configure your server-side network connection by reviewing the specified encryption and crypto-checksum algorithms.

Purpose

To configure your server-side network connection by reviewing the encryption and crypto-checksum algorithms enabled on the client and server. This ensures that the connection does not encounter compatibility issues and your configuration uses supported strong algorithms.

Usage Notes

Values

Default Value

TRUE

Recommended Value

FALSE

Note: Before setting this parameter to FALSE, you must remove all deprecated algorithms listed in the server and client sqlnet.ora files.

Example

SQLNET.ALLOW_WEAK_CRYPTO_CLIENTS = FALSE

Related Topics

SQLNET.ALLOWED_LOGON_VERSION_CLIENT

Use the sqlnet parameter SQLNET.ALLOWED_LOGON_VERSION_CLIENT to define minimum authentication protocols that servers acting as clients to other servers can use for connecting to Oracle Database instances.

Purpose

To set the minimum authentication protocol allowed for clients when a server is acting as a client, such as connecting over a database link, when connecting to Oracle Database instances.

Usage Notes

The term VERSION in the parameter name refers to the version of the authentication protocol, not the version of the Oracle Database release.

If the version does not meet or exceed the value defined by this parameter, then authentication fails with an ORA-28040: The database does not accept your client's authentication protocol; login denied error.

The database password verifier for Oracle Database 10g, 10G is no longer supported or available on Oracle AI Database 26ai. Refer to the database upgrade guide preinstallation chapters for information about how to identify the Oracle Database 10G database password verifiers, and how to update the database user to use the latest and most secure database password verifier cryptography.

Values

Default

12

Example

If an Oracle AI Database 26ai database hosts a database link to an Oracle Database 19g database, then set the SQLNET.ALLOWED_LOGON_VERSION_CLIENT parameter as follows for the database link connection to proceed:

SQLNET.ALLOWED_LOGON_VERSION_CLIENT=12

In this case, you cannot configure the more secure SQLNET.ALLOWED_LOGON_VERSION_CLIENT setting of 12a on the 26ai server hosting the database link because the account on the Oracle Database 19g database might not have its password changed and thus might only have the 11G verifier.

Related Topics

SQLNET.ALLOWED_LOGON_VERSION_SERVER

Use the sqlnet.ora parameter SQLNET.ALLOWED_LOGON_VERSION_SERVER to set the minimum authentication protocol that is permitted when connecting to Oracle Database instances.

Purpose

To set the minimum authentication protocol for connecting to Oracle Database instances.

Usage Notes

Values

Note:

Default

12

Example

SQLNET.ALLOWED_LOGON_VERSION_SERVER=12

Related Topics

SQLNET.AUTHENTICATION_SERVICES

Use the sqlnet.ora parameter SQLNET.AUTHENTICATION_SERVICES to enable one or more authentication services.

Purpose

To enable one or more authentication services. If you have installed authentication, then Oracle recommends that you set SQLNET.AUTHENTICATION_SERVICES to either NONE or to one of the listed authentication methods.

Usage Notes

Values

Authentication methods that are available with Oracle Net Services are:

Default

ALL

Note: When installing Oracle Database with Database Configuration Assistant (DBCA), you can set this parameter to NTS in the sqlnet.ora file.

Examples

When specifying multiple authentication services, you must enclose the values within parentheses as follows:

SQLNET.AUTHENTICATION_SERVICES=(BEQ,KERBEROS5)

If you want to specify only a single authentication service, then parentheses are not required:

SQLNET.AUTHENTICATION_SERVICES=KERBEROS5

Related Topics

SQLNET.BREAK_RESET_TIMEOUT

Use the sqlnet.ora parameter SQLNET.BREAK_RESET_TIMEOUT to specify the duration of time that a database client or server should wait for the completion of break/reset operation.

Purpose

To specify the time for a database client or server to wait for the break/reset operation to complete. If the break/reset operation does not complete in the specified time interval, then the connection is closed.

You can specify the time in hours, minutes, seconds, or milliseconds by using the hr, min, sec, or ms keyword respectively. If you do not specify a unit of measurement, then the default unit is sec.

Usage Notes

Setting this parameter ensures that the peer is not left waiting indefinitely for the completion of break/reset operation. If a peer does not receive response data within the specified BREAK_RESET_TIMEOUT interval, the connection will be closed. If you set the timeout interval, then set the value initially to a low value and adjust the value according to the system and network capacity.

Default

None

Minimum Value

1 ms

Allowed Range

Any number greater than the minimum value of 1 ms up to 4294967295 ms

Example

SQLNET.BREAK_RESET_TIMEOUT=5 min

Related Topics

SQLNET.CLIENT_REGISTRATION

Use the sqlnet.ora parameter SQLNET.CLIENT_REGISTRATION to set a unique identifier for the client computer.

Purpose

To set a unique identifier for the client computer.

Usage Notes

This identifier is passed to the listener with any connection request and is included in the audit trail. The identifier can be any alphanumeric string up to 128 characters long.

Default

None

Example

SQLNET.CLIENT_REGISTRATION=1432

SQLNET.CLOUD_USER

Use the sqlnet.ora parameter SQLNET.CLOUD_USER to specify a user name for web server HTTP basic authentication.

Purpose

To specify a user name for web server HTTP basic authentication.

Usage Notes

When you use a secure websocket protocol, the client uses this user as the user name for authentication. The password for this user should be stored in a wallet using mkstore commands.

Perform the following configuration steps to use HTTP basic authentication with secure websockets:

  1. Create a wallet using the orapki utility.

    orapki wallet create -wallet wallet_directory

    Example

    orapki wallet create -wallet /app/wallet

  2. Add a web server public certificate.

    orapki wallet -wallet wallet_directory -trusted_cert -cert web_server_public_certificate_in_pem_format

    Example

    orapki wallet -wallet /app/wallet -trusted_cert -cert server_cert.txt

  3. Add the web server user name to sqlnet.ora. This user name is only used for authenticating the web server. This is not a database user name. After web server authentication, the web server connects to the back-end database server and database authentication is completed.

    Example

    sqlnet.cloud_user = dbuser1

  4. Add a web server user password to the wallet.

    mkstore -wrl wallet_location -createEntry username password

    Example

    mkstore -wrl /app/wallet -createEntry dbuser1 Secretdb#

  5. Make the wallet automatically log in and protect this wallet directory using operating system file permissions or any other means. Do this so that only the database client can have read access to it. Refer to the operating system utilities for information about changing the file permissions.

    orapki wallet create -wallet wallet_directory -auto_login

    Example

    orapki wallet create -wallet /app/wallet -auto_login

    Note:

    Oracle has introduced a new auto-login wallet version (7) with Oracle AI Database 26ai. Version 6 of the Oracle local auto-login wallet is deprecated.

    You can update your local auto-login wallet by modifying it with orapki.

  6. Update the sqlnet.ora file with the wallet entry.

    Example

    wallet_location=(SOURCE=(METHOD=file)(METHOD_DATA=(DIRECTORY=/app/wallet)))

Note:

Default

None

Related Topics

SQLNET.COMPRESSION

Use the sqlnet.ora parameter SQLNET.COMPRESSION to enable or disable data compression.

Purpose

To enable or disable data compression. If both the server and client have this parameter set to ON, then compression is used for the connection.

Note: The SQLNET.COMPRESSION parameter applies to all database connections, except for Oracle Data Guard streaming redo and SecureFiles LOBs (Large Objects).

Default

off

Values

Example

SQLNET.COMPRESSION=on

SQLNET.COMPRESSION_ACCELERATION

Use the sqlnet.ora parameter SQLNET.COMPRESSION_ACCELERATION to specify the use of hardware accelerated version of compression using this parameter if it is available for that platform.

Purpose

To specify the use of hardware accelerated version of compression using this parameter if it is available for that platform.

Usage Notes

You can set this parameter in the Oracle Connection Manager alias description.

Default

on

Values

Example 5-4 Example

compression_acceleration = on

SQLNET.COMPRESSION_LEVELS

Use the sqlnet.ora parameter SQLNET.COMPRESSION_LEVELS to specify the compression level.

Purpose

To specify the compression level.

Usage Notes

The compression levels are used at the time of negotiation to verify which levels are used at both ends, and to select one level.

For Database Resident Connection Pooling (DRCP), only the compression level low is supported.

Default

low

Values

Example

SQLNET.COMPRESSION_LEVELS=(high)

SQLNET.COMPRESSION_THRESHOLD

Use the sqlnet.ora parameter SQLNET.COMPRESSION_THRESHOLD to specify the minimum data size for which compression is needed.

Purpose

To specify the minimum data size, in bytes, for which compression is needed.

Usage Notes

Compression is not to be performed if the size of the data you are sending is less than this value.

Default

1024 bytes

Example

SQLNET.COMPRESSION_THRESHOLD=1024

SQLNET.CRYPTO_CHECKSUM_CLIENT

Use the sqlnet.ora parameter SQLNET.CRYPTO_CHECKSUM_CLIENT to specify the desired data integrity behavior when this client or server acting as a client connects to a server.

Purpose

To specify the checksum behavior for the client. The behavior partially depends on the SQLNET.CRYPTO_CHECKSUM_SERVER setting at the other end of the connection.

Default

accepted

Values

Example

SQLNET.CRYPTO_CHECKSUM_CLIENT=accepted

SQLNET.CRYPTO_CHECKSUM_SERVER

Use the sqlnet.ora parameter SQLNET.CRYPTO_CHECKSUM_SERVER to specify the data integrity behavior when a client or another server acting as a client connects to this server.

Purpose

To specify the checksum behavior for the database. The behavior partially depends on the SQLNET.CRYPTO_CHECKSUM_CLIENT setting at the other end of the connection.

Default

accepted

Values

Example

SQLNET.CRYPTO_CHECKSUM_SERVER=accepted

SQLNET.CRYPTO_CHECKSUM_TYPES_CLIENT

Use the sqlnet.ora parameter SQLNET.CRYPTO_CHECKSUM_TYPES_CLIENT to specify a list of data integrity algorithms that this client or server acting as a client uses.

Purpose

To specify a list of crypto-checksum algorithms for the client to use.

This list is used to negotiate a mutually acceptable algorithm with the other end of the connection. If an algorithm that is not installed on this side is specified, the connection terminates with the ORA-12650: No common encryption or data integrity algorithm error error message.

Default

All available algorithms

Values

Example

SQLNET.CRYPTO_CHECKSUM_TYPES_CLIENT=(SHA256, MD5)

SQLNET.CRYPTO_CHECKSUM_TYPES_SERVER

Use the sqlnet.ora parameter SQLNET.CRYPTO_CHECKSUM_TYPES_SERVER to specify the data integrity algorithms that this server or client to another server uses, in order of intended use.

Purpose

To specify a list of crypto-checksum algorithms for the database to use.

This list is used to negotiate a mutually acceptable algorithm with the other end of the connection. Each algorithm is checked against the list of available client algorithm types until a match is found. If an algorithm is specified that is not installed on this side, the connection terminates with the ORA-12650: No common encryption or data integrity algorithm error error message.

Default

All available algorithms

Values

Example

SQLNET.CRYPTO_CHECKSUM_TYPES_SERVER=(SHA256, MD5)

SQLNET.DBFW_PUBLIC_KEY

Use the sqlnet.ora parameter SQLNET.DBFW_PUBLIC_KEY to provide Oracle Database Firewall public keys to the Advanced Security Option (ASO) by specifying the file that stores the public keys.

Purpose

To provide Oracle Database Firewall public keys to Advanced Security Option (ASO) by specifying the name of the file that stores the Oracle Database Firewall public keys.

Default

None

Values

Full path name of the operating system file that has the public keys

Example

SQLNET.DBFW_PUBLIC_KEY="/path_to_file/dbfw_public_key_file.txt"

See Also: “SQLNET.ENCRYPTION_TYPES_SERVER”

SQLNET.DOWN_HOSTS_TIMEOUT

Use the sqlnet.ora parameter SQLNET.DOWN_HOSTS_TIMEOUT to specify the amount of time in seconds that server hosts down state information remains in the client cache.

Purpose

To specify the amount of time in seconds that information about the down state of server hosts is kept in the client process cache.

Usage Notes

Clients discover the down state of server hosts when attempting connections. When a connection attempt fails, the information about the down state of the server host is added to the client process cache. Subsequent connection attempts by the same client process move the addresses of the down hosts to the end of the address list, thereby reducing the priority of down hosts. When the duration of time that is specified by the SQLNET.DOWN_HOSTS_TIMEOUT parameter has elapsed, the host is purged from the process cache and its priority in the address list is restored.

Default

600 seconds (10 minutes)

Values

Any positive integer

Example

SQLNET.DOWN_HOSTS_TIMEOUT=60

SQLNET.ENCRYPTION_CLIENT

Use the sqlnet.ora parameter SQLNET.ENCRYPTION_CLIENT to set the encryption behavior when this client or server acting as a client connects to a server.

Purpose

To enable encryption for clients. Setting the tnsnames.ora parameter IGNORE_ANO_ENCRYPTION_FOR_TCPS to TRUE disables SQLNET.ENCRYPTION_CLIENT.

The behavior of the client partially depends on the value set for SQLNET.ENCRYPTION_SERVER at the other end of the connection.

Default

accepted

Values

Example

SQLNET.ENCRYPTION_CLIENT=accepted

SQLNET.ENCRYPTION_SERVER

The sqlnet.ora parameter SQLNET.ENCRYPTION_SERVER specifies the encryption behavior when a client or a server acting as a client connects to this server.

Purpose

To enable encryption for the database. Setting SQLNET.IGNORE_ANO_ENCRYPTION_FOR_TCPS to FALSE disables SQLNET.ENCRYPTION_SERVER.

The behavior of the server partially depends on the SQLNET.ENCRYPTION_CLIENT setting at the other end of the connection.

Default

accepted

Values

Example

SQLNET.ENCRYPTION_SERVER=accepted

SQLNET.ENCRYPTION_TYPES_CLIENT

Use the sqlnet.ora parameter SQLNET.ENCRYPTION_TYPES_CLIENT to specify the encryption algorithms this client or the server acting as a client uses.

Purpose

This list is used to negotiate a mutually acceptable algorithm with the other end of the connection. If an algorithm that is not installed is specified on this side, the connection terminates with the ORA-12650: No common encryption or data integrity algorithm error message.

Usage Notes

Starting with Oracle Database 21c, older encryption and hashing algorithms are deprecated.

The deprecated algorithms for DBMS_CRYPTO and native network encryption include MD4, MD5, DES, 3DES, and RC4-related algorithms as well as 3DES for Transparent Data Encryption (TDE). Removing older, less secure cryptography algorithms prevents accidental use of these algorithms. To meet your security requirements, Oracle recommends that you use more modern cryptography algorithms, such as the Advanced Encryption Standard (AES).

As a consequence of this deprecation, Oracle recommends that you review your network encryption configuration to see if you have specified use of any of the deprecated algorithms. If any are found, then switch to using a more modern cipher, such as AES. Also, if you are currently using 3DES encryption for your TDE deployment, then you should plan to migrate to a more modern algorithm such as AES. For more information, refer to Oracle Database Security Guide

To transition your Oracle Database environment to use stronger algorithms, download and install the patch described in My Oracle Support note 2118136.2.

Default

All available algorithms

Values

Approved algorithms:

Deprecated algorithms:

Example

SQLNET.ENCRYPTION_TYPES_CLIENT=(AES256)

SQLNET.ENCRYPTION_TYPES_SERVER

Use the sqlnet.ora parameter SQLNET.ENCRYPTION_TYPES_SERVER to specify the encryption algorithms this server uses in the order of the intended use.

Purpose

This list is used to negotiate a mutually acceptable algorithm with the client end of the connection. Each algorithm is checked against the list of available client algorithm types until a match is found. If an algorithm that is not installed is specified on this side, the connection terminates with an ORA-12650: No common encryption or data integrity algorithm error message.

Default

All available algorithms

Values

Approved algorithms:

Deprecated algorithms:

Starting with Oracle Database 21c, older encryption and hashing algorithms are deprecated.

The deprecated algorithms for DBMS_CRYPTO and native network encryption include MD4, MD5, DES, 3DES, and RC4-related algorithms as well as 3DES for Transparent Data Encryption (TDE). Removing older, less secure cryptography algorithms prevents accidental use of these algorithms. To meet your security requirements, Oracle recommends that you use more modern cryptography algorithms, such as the Advanced Encryption Standard (AES).

As a consequence of this deprecation, Oracle recommends that you review your network encryption configuration to see if you have specified use of any of the deprecated algorithms. If any are found, then switch to using a more modern cipher, such as AES. Also, if you are currently using 3DES encryption for your TDE deployment, then you should plan to migrate to a more modern algorithm such as AES. For more information, refer to Oracle Database Security Guide

To transition your Oracle Database environment to use stronger algorithms, download and install the patch described in My Oracle Support note 2118136.2.

Example

SQLNET.ENCRYPTION_TYPES_SERVER=(AES256, AES192, ...)

SQLNET.EXPIRE_TIME

Use the sqlnet.ora parameter SQLNET.EXPIRE_TIME to specify how often, in minutes, to verify that client and server connections are alive.

Purpose

To specify time intervals, in minutes, for how often to verify that client and server connections are alive.

Usage Notes

Setting a value greater than 0 ensures that connections are not left open indefinitely due to an unusual client termination. If your environment supports TCP keepalive tuning, then Oracle Net Services automatically uses the enhanced detection model and tunes the TCP keepalive parameters.

If the verification check identifies a terminated connection or a connection that is no longer usable, then the check returns an error, causing the server process to exit.

The sqlnet.ora parameter SQLNET.EXPIRE_TIME is primarily intended for the database server, which typically handles multiple connections simultaneously.

You can also use this parameter for database clients to verify if the server connection is alive.

Limitations on using the terminated connection detection feature are:

Default

0

Minimum Value

0

Recommended Value

10

Example

SQLNET.EXPIRE_TIME=10

SQLNET.IGNORE_ANO_ENCRYPTION_FOR_TCPS

Use the sqlnet.ora parameter SQLNET.IGNORE_ANO_ENCRYPTION_FOR_TCPS to ignore the value that is set for the parameter SQLNET.ENCRYPTION_SERVER for TCPS connections. This disables ANO encryption on the TCPS listener.

Purpose

Use SQLNET.IGNORE_ANO_ENCRYPTION_FOR_TCPS on your server to ignore the value that is set for SQLNET.ENCRYPTION_SERVER for TCPS connections. Doing this disables ANO encryption on the TCPS listener.

Default

FALSE

Example 5-5 Example

SQLNET.IGNORE_ANO_ENCRYPTION_FOR_TCPS=TRUE

SQLNET.INBOUND_CONNECT_TIMEOUT

Use the sqlnet.ora parameter SQLNET.INBOUND_CONNECT_TIMEOUT to specify the amount of time that clients have to connect with the database and authenticate.

Purpose

Use the parameter SQLNET.INBOUND_CONNECT_TIMEOUT to specify the time limit in ms, sec, or min, within which a client must connect with the database and provide authentication information.

Usage Notes

If the client fails to connect and complete the authentication within the specified timeframe, then the database terminates the connection. In addition, the database logs the IP address of the client and writes an ORA-12170 error message to the database alert log file.

The client receives either an ORA-12547: TNS:lost contact or an ORA-12637: Packet receive failed error message.

The default value of SQLNET.INBOUND_CONNECT_TIMEOUT is appropriate for typical scenarios. However, if you need to set a different value, then Oracle recommends setting this parameter in combination with theINBOUND_CONNECT_TIMEOUT_listener_name parameter in the listener.ora file. When specifying the values for these parameters, note the following recommendations:

It accepts different timeouts with or without space between the value and the unit. If you do not set a unit of measurement for SQLNET.INBOUND_CONNECT_TIMEOUT, then the default unit is sec. For example, you can set INBOUND_CONNECT_TIMEOUT_listener_name to 2 seconds and set the SQLNET.INBOUND_CONNECT_TIMEOUT parameter to 3 seconds. If clients are unable to complete the connections within the specified time due to system or network delays that are normal for the particular environment, then increase the value for SQLNET.INBOUND_CONNECT_TIMEOUT as needed.

Default

60 seconds

Example

SQLNET.INBOUND_CONNECT_TIMEOUT=40sec

SQLNET.FALLBACK_AUTHENTICATION

Use the sqlnet.ora parameter SQLNET.FALLBACK_AUTHENTICATION to specify whether to attempt password-based authentication if Kerberos authentication fails.

Purpose

To specify whether to attempt to use password-based authentication if Kerberos authentication fails. This is relevant for direct connections as well as database link connections.

Default

FALSE

Example

SQLNET.FALLBACK_AUTHENTICATION=TRUE

See Also: Oracle Database Security Guide

SQLNET.KERBEROS5_CC_NAME

Use the sqlnet.ora parameter SQLNET.KERBEROS5_CC_NAME to specify the complete path name to the Kerberos credentials cache (CC) file.

Purpose

To specify the complete path name to the Kerberos CC file.

Usage Notes

Values and Examples

You can use the following formats to specify a value for SQLNET.KERBEROS5_CC_NAME:

Default

The default value is operating system-dependent, as follows:

Related Topics

SQLNET.KERBEROS5_CLOCKSKEW

Use the sqlnet.ora parameter SQLNET.KERBEROS5_CLOCKSKEW to specify how much time elapses before a Kerberos credential is considered out-of-date.

Purpose

To specify how many seconds elapse before a Kerberos credential is considered out-of-date.

Default

300

Example

SQLNET.KERBEROS5_CLOCKSKEW=1200

See Also: Oracle Database Security Guide

SQLNET.KERBEROS5_CONF

Use the sqlnet.ora parameter SQLNET.KERBEROS5_CONF to specify the path name to the Kerberos configuration file that contains the realm for the default Key Distribution Center (KDC) and that maps realms to KDC hosts.

Purpose

To specify the complete path name to the Kerberos configuration file that contains the realm for the default Key Distribution Center (KDC) and that also maps realms to KDC hosts.

Usage Notes

KDC maintains a list of user principals and is contacted through the kinit program for the user’s initial ticket.

If you configure the SQLNET.KERBEROS5_CONF parameter, then the Kerberos 5 configuration file krb.conf is fetched from the directory path specified in the parameter. Alternately, you can skip configuring the SQLNET.KERBEROS5_CONF altogether and still ensure the discovery of your configuration file by placing the krb.conf file in one of the default search locations so as to allow for an automatic discovery by Kerberos authentication service.

Note: If you choose to place the Kerberos configuration file in one of the default search paths, then it is optional to set the parameter value as AUTO_DISCOVER, as placing the krb.conf file in one of the default locations enables automatic discovery without having to set the AUTO_DISCOVER parameter.

Default

On Linux and UNIX operating systems, krb.conf is automatically searched in the below file paths in the specified order:

  1. $ORACLE_BASE/network/admin/krb.conf

  2. $ORACLE_BASE_HOME/network/admin/krb.conf

  3. $ORACLE_HOME/network/admin/krb.conf

  4. /etc/krb.conf

c:\krb5\krb.conf on Microsoft Windows operating systems

Values

Example

SQLNET.KERBEROS5_CONF=/krb5/krb.conf

See Also: Oracle Database Security Guide

SQLNET.KERBEROS5_CONF_LOCATION

Use the sqlnet.ora parameter SQLNET.KERBEROS5_CONF_LOCATION to specify the directory for the Kerberos configuration file. The SQLNET.KERBEROS5_CONF_LOCATION parameter also specifies that the file is created by the system and not by the client.

Purpose

To specify the directory for the Kerberos configuration file. The parameter also specifies that the file is created by the system, and not by the client.

Usage Notes

The configuration file uses DNS look-up to obtain the realm for the default KDC, and it maps realms to the KDC hosts. This option is supported for all operating systems that support this feature.

Default

/krb5 on Linux and UNIX operating systems

c:\krb5 on Microsoft Windows operating systems

Example

SQLNET.KERBEROS5_CONF_LOCATION=/krb5

SQLNET.KERBEROS5_KEYTAB

Use the sqlnet.ora parameter SQLNET.KERBEROS5_KEYTAB to specify the path name to the Kerberos principal or, secret, key mapping file that extracts keys and decrypts incoming authentication information.

Purpose

To specify the complete path name to the Kerberos principal or, secret, key mapping file that extracts keys and decrypts incoming authentication information.

Default

/etc/v5srvtab on Linux and UNIX operating systems

c:\krb5\v5srvtab on Microsoft Windows operating systems

Example

SQLNET.KERBEROS5_KEYTAB=/etc/v5srvtab

See Also: Oracle Database Security Guide

SQLNET.KERBEROS5_REALMS

Use the sqlnet.ora parameter SQLNET.KERBEROS5_REALMS to specify the complete path name to the Kerberos realm translation file that maps a host name or domain name to a realm.

Purpose

To specify the complete path name to the Kerberos realm translation file that maps a host name or domain name to a realm.

Default

/krb5/krb.realms on Linux and UNIX operating systems

c:\krb5\krb.realms on Microsoft Windows operating systems

Example

SQLNET.KERBEROS5_REALMS=/krb5/krb.realms

See Also: Oracle Database Security Guide

SQLNET.OUTBOUND_CONNECT_TIMEOUT

Use the sqlnet.ora parameter SQLNET.OUTBOUND_CONNECT_TIMEOUT to specify the amount of time, in milliseconds, seconds, or minutes, in which clients must establish Oracle Net connections to database instances.

Purpose

To specify the time in ms, sec, or min for clients to establish an Oracle Net connection to the database instance.

Usage Notes

If an Oracle Net connection is not established in the time specified, then the connection attempt is terminated. The client receives the following error:

ORA-12170: Cannot connect. Outbound connect timeout of time_interval for host_port or key. (CONNECTION_ID=ID_string).

The outbound connect timeout interval is a superset of the TCP connect timeout interval that specifies a limit on the time needed to establish a TCP connection. Additionally, the outbound connect timeout interval includes the time taken to be connected to an Oracle instance that is providing the service. It accepts different timeouts with or without space between the value and the unit.

Without this parameter, a client connection request to the database server may be blocked for the default TCP connect timeout duration (60 seconds) when the database server host system is unreachable. In this case, no unit is mentioned and the default unit is sec.

The outbound connect timeout interval is only applicable for TCP, TCP with TLS, and IPC transport connections.

This parameter is overridden by the CONNECT_TIMEOUT parameter in the address description.

Default

None

Example

SQLNET.OUTBOUND_CONNECT_TIMEOUT=50 sec

Related Topics

SQLNET.RADIUS_ALLOW_WEAK_CLIENTS

Use the client-side sqlnet.ora parameter SQLNET.RADIUS_ALLOW_WEAK_CLIENTS to control the transport protocol that the Oracle Database client must use for communicating with the Oracle Database server.

Purpose

To control the transport protocol that the Oracle Database client must use for communication between the database client and database server, if the database client wants to use RADIUS authentication.

The default value is FALSE so that database clients can connect to the database server (to use RADIUS authentication) only if the connecting protocol used is TCPS.

Usage Notes

Values

Default

FALSE

Example

SQLNET.RADIUS_ALLOW_WEAK_CLIENTS=FALSE

Related Topics

SQLNET.RADIUS_ALLOW_WEAK_PROTOCOL

Use the server-side sqlnet.ora parameter SQLNET.RADIUS_ALLOW_WEAK_PROTOCOL to allow weak Oracle Database clients to use RADIUS authentication.

Purpose

To allow weak Oracle Database clients, which use non-TCPS protocol for connecting to the Oracle Database server, to use RADIUS authentication.

The default value is FALSE so that only strong clients (using TCPS for connecting to the database server) can use RADIUS authentication.

Usage Notes

Values

Default

FALSE

Example

SQLNET.RADIUS_ALLOW_WEAK_PROTOCOL=FALSE

Related Topics

SQLNET.RADIUS_ALTERNATE

Use the sqlnet.ora parameter SQLNET.RADIUS_ALTERNATE to specify an alternate RADIUS server to be used when the primary server is unavailable.

Purpose

To specify the location of an alternate RADIUS server to be used for fault tolerance when the primary server is unavailable. The value can be either the IP address or host name of the server.

Usage Notes

Starting with Oracle AI Database 26ai, the older RADIUS API that is based on Request for Comments (RFC) 2138 is deprecated.

Oracle AI Database 26ai introduces an updated RADIUS API based on RFC 6613 and RFC 6614. Oracle recommends that you start planning on migrating to use the new RADIUS API as soon as possible. The new API is enabled by default. These parameters associated with the older RADIUS API are also deprecated: SQLNET.RADIUS_ALTERNATE, SQLNET.RADIUS_ALTERNATE_PORT, SQLNET.RADIUS_AUTHENTICATION, and SQLNET.RADIUS_AUTHENTICATION_PORT. Refer to the Radius API documentation for information on changing the default to use the older RADIUS API.

If your database server supports the updated RADIUS standards, then use the SQLNET.RADIUS_ALTERNATE_TLS_HOST parameter instead of the deprecated SQLNET.RADIUS_ALTERNATE parameter.

If you need to enable pre-release 23ai clients to connect RADIUS users using the older RADIUS standards (which are blocked by default), then you must set one or both of the SQLNET.RADIUS_ALLOW_WEAK_CLIENTS and SQLNET.RADIUS_ALLOW_WEAK_PROTOCOL parameters.

Syntax

SQLNET.RADIUS_ALTERNATE=(hostname_or_IP_address_of_alternate_RADIUS_server)

Default

None

Example

SQLNET.RADIUS_ALTERNATE=(radius-server2)

Related Topics

SQLNET.RADIUS_ALTERNATE_PORT

Use the sqlnet.ora parameter SQLNET.RADIUS_ALTERNATE_PORT to specify the listening port of an alternate RADIUS server.

Purpose

To specify the listening port of an alternate RADIUS server.

Usage Notes

Starting with Oracle AI Database 26ai, the older RADIUS API that is based on Request for Comments (RFC) 2138 is deprecated.

Oracle AI Database 26ai introduces an updated RADIUS API based on RFC 6613 and RFC 6614. Oracle recommends that you start planning on migrating to use the new RADIUS API as soon as possible. The new API is enabled by default. These parameters associated with the older RADIUS API are also deprecated: SQLNET.RADIUS_ALTERNATE, SQLNET.RADIUS_ALTERNATE_PORT, SQLNET.RADIUS_AUTHENTICATION, and SQLNET.RADIUS_AUTHENTICATION_PORT. Refer to the Radius API documentation for information on changing the default to use the older RADIUS API.

If your database server supports the updated RADIUS standards, then use the SQLNET.RADIUS_ALTERNATE_TLS_PORT parameter instead of the deprecated SQLNET.RADIUS_ALTERNATE_PORT parameter.

If you need to enable pre-release 23ai clients to connect RADIUS users using the older RADIUS standards (which are blocked by default), then you must set one or both of the SQLNET.RADIUS_ALLOW_WEAK_CLIENTS and SQLNET.RADIUS_ALLOW_WEAK_PROTOCOL parameters.

Syntax

SQLNET.RADIUS_ALTERNATE_PORT=(listening_port_of_alternate_RADIUS_server)

Default

1812

Example

SQLNET.RADIUS_ALTERNATE_PORT=(1667)

Related Topics

SQLNET.RADIUS_ALTERNATE_RETRIES

Use the sqlnet.ora parameter SQLNET.RADIUS_ALTERNATE_RETRIES to specify the number of times that the database resends messages to alternate RADIUS servers.

Purpose

To specify the number of times that the database server should resend messages to an alternate RADIUS server.

Default

3

Example

SQLNET.RADIUS_ALTERNATE_RETRIES=4

SQLNET.RADIUS_ALTERNATE_TIMEOUT

Use the sqlnet.ora parameter SQLNET.RADIUS_ALTERNATE_TIMEOUT to set the time for an alternate RADIUS server to wait for a response.

Purpose

To set the time, in seconds, for an alternate RADIUS server to wait for a response.

Syntax

SQLNET.RADIUS_ALTERNATE_TIMEOUT=time_in_seconds

Default

5

Example

SQLNET.RADIUS_ALTERNATE_TIMEOUT=5

Related Topics

SQLNET.RADIUS_ALTERNATE_TLS_HOST

Use the sqlnet.ora parameter SQLNET.RADIUS_ALTERNATE_TLS_HOST to specify the host name of an alternate RADIUS server to be used when the primary server is unavailable.

Purpose

To specify the host name of an alternate RADIUS server, which is used for fault tolerance when the primary server is unavailable.

Usage Notes

Use this parameter only if your RADIUS server implements RADIUS with TLS over TCP.

Syntax

SQLNET.RADIUS_ALTERNATE_TLS_HOST=(TLS_hostname_of_alternate_RADIUS_server)

Default

None

Example

SQLNET.RADIUS_ALTERNATE_TLS_HOST=(radius-server2)

Related Topics

SQLNET.RADIUS_ALTERNATE_TLS_PORT

Use the sqlnet.ora parameter SQLNET.RADIUS_ALTERNATE_TLS_PORT to specify the listening port of an alternate RADIUS server.

Purpose

To specify the listening port of an alternate RADIUS server. The default port is 2083. If the alternate server uses a different port, then specify that value.

Usage Notes

Use this parameter only if your RADIUS server implements RADIUS with TLS over TCP.

Syntax

SQLNET.RADIUS_ALTERNATE_TLS_PORT=(listening_TLS_port_of_alternate_RADIUS_server)

Default

2083

Example

SQLNET.RADIUS_ALTERNATE_TLS_PORT=(5530)

Related Topics

SQLNET.RADIUS_AUTHENTICATION

Use the sqlnet.ora parameter SQLNET.RADIUS_AUTHENTICATION to specify the location of a primary RADIUS server.

Purpose

To specify the location of a primary RADIUS server. The value can be either the IP address or host name of the server.

Usage Notes

Starting with Oracle AI Database 26ai, the older RADIUS API that is based on Request for Comments (RFC) 2138 is deprecated.

Oracle AI Database 26ai introduces an updated RADIUS API based on RFC 6613 and RFC 6614. Oracle recommends that you start planning on migrating to use the new RADIUS API as soon as possible. The new API is enabled by default. These parameters associated with the older RADIUS API are also deprecated: SQLNET.RADIUS_ALTERNATE, SQLNET.RADIUS_ALTERNATE_PORT, SQLNET.RADIUS_AUTHENTICATION, and SQLNET.RADIUS_AUTHENTICATION_PORT. Refer to the Radius API documentation for information on changing the default to use the older RADIUS API.

If your database server supports the updated RADIUS standards, then use the SQLNET.RADIUS_AUTHENTICATION_TLS_HOST parameter instead of the deprecated SQLNET.RADIUS_AUTHENTICATION parameter.

If you need to enable pre-release 23ai clients to connect RADIUS users using the older RADIUS standards (which are blocked by default), then you must set one or both of the SQLNET.RADIUS_ALLOW_WEAK_CLIENTS and SQLNET.RADIUS_ALLOW_WEAK_PROTOCOL parameters.

Syntax

SQLNET.RADIUS_AUTHENTICATION=(hostname_or_IP_address_of_primary_RADIUS_server)

Default

Local host

Example

SQLNET.RADIUS_AUTHENETICATION=(radius-server1)

Related Topics

SQLNET.RADIUS_AUTHENTICATION_INTERFACE

Use the sqlnet.ora parameter SQLNET.RADIUS_AUTHENTICATION_INTERFACE to specify the class that contains the user interface for interacting with users.

Purpose

To specify the class containing the user interface that is used to interact with the user.

Default

DefaultRadiusInterface

Example

SQLNET.RADIUS_AUTHENTICATION_INTERFACE=DefaultRadiusInterface

SQLNET.RADIUS_AUTHENTICATION_PORT

Use the sqlnet.ora parameter SQLNET.RADIUS_AUTHENTICATION_PORT to specify the listening port of a primary RADIUS server.

Purpose

To specify the listening port of a primary RADIUS server.

Usage Notes

Starting with Oracle AI Database 26ai, the older RADIUS API that is based on Request for Comments (RFC) 2138 is deprecated.

Oracle AI Database 26ai introduces an updated RADIUS API based on RFC 6613 and RFC 6614. Oracle recommends that you start planning on migrating to use the new RADIUS API as soon as possible. The new API is enabled by default. These parameters associated with the older RADIUS API are also deprecated: SQLNET.RADIUS_ALTERNATE, SQLNET.RADIUS_ALTERNATE_PORT, SQLNET.RADIUS_AUTHENTICATION, and SQLNET.RADIUS_AUTHENTICATION_PORT. Refer to the Radius API documentation for information on changing the default to use the older RADIUS API.

If your database server supports the updated RADIUS standards, then use the SQLNET.RADIUS_AUTHENTICATION_TLS_PORT parameter instead of the deprecated SQLNET.RADIUS_AUTHENTICATION_PORT parameter.

If you need to enable pre-release 23ai clients to connect RADIUS users using the older RADIUS standards (which are blocked by default), then you must set one or both of the SQLNET.RADIUS_ALLOW_WEAK_CLIENTS and SQLNET.RADIUS_ALLOW_WEAK_PROTOCOL parameters.

Syntax

SQLNET.RADIUS_AUTHENTICATION_PORT=(listening_port_of_primary_RADIUS_server)

Default

1645

Example

SQLNET.RADIUS_AUTHENTICATION_PORT=(1667)

Related Topics

SQLNET.RADIUS_AUTHENTICATION_RETRIES

Use the sqlnet.ora parameter SQLNET.RADIUS_AUTHENTICATION_RETRIES to specify the number of times the database should resend messages to a primary RADIUS server.

Purpose

To specify the number of times the database should resend messages to a primary RADIUS server.

Default

3

Example

SQLNET.RADIUS_AUTHENTICATION_RETRIES=4

SQLNET.RADIUS_AUTHENTICATION_TIMEOUT

Use the sqlnet.ora parameter SQLNET.RADIUS_AUTHENTICATION_TIMEOUT to specify the amount of time that the database should wait for a response from a primary RADIUS server.

Purpose

To specify the amount of time, in seconds, that the database should wait for a response from a primary RADIUS server.

Default

5

Example

SQLNET.RADIUS_AUTHENTICATION_TIMEOUT=10

SQLNET.RADIUS_AUTHENTICATION_TLS_HOST

Use the sqlnet.ora parameter SQLNET.RADIUS_AUTHENTICATION_TLS_HOST to specify the host name of a primary RADIUS server.

Purpose

To specify the host name of a primary RADIUS server. This value is mandatory. If you do not set this parameter, then authentication fails.

Usage Notes

Use this parameter only if your RADIUS server implements RADIUS with TLS over TCP.

Syntax

SQLNET.RADIUS_AUTHENTICATION_TLS_HOST=(TLS_hostname_of_primary_RADIUS_server)

Default

None

Example

SQLNET.RADIUS_AUTHENTICATION_TLS_HOST=(radius-server1)

Related Topics

SQLNET.RADIUS_AUTHENTICATION_TLS_PORT

Use the sqlnet.ora parameter SQLNET.RADIUS_AUTHENTICATION_TLS_PORT to specify the listening port of a primary RADIUS server.

Purpose

To specify the listening port of a primary RADIUS server. The default port is 2083. If the server uses a different port, then specify that value.

Usage Notes

Use this parameter only if your RADIUS server implements RADIUS with TLS over TCP.

Syntax

SQLNET.RADIUS_AUTHENTICATION_TLS_PORT=(listening_TLS_port_of_primary_RADIUS_server)

Default

2083

Example

SQLNET.RADIUS_AUTHENTICATION_TLS_PORT=(5530)

Related Topics

SQLNET.RADIUS_CHALLENGE_KEYWORD

Use the sqlnet.ora parameter SQLNET.RADIUS_CHALLENGE_KEYWORD to set the keyword for requesting a challenge from the RADIUS server.

Purpose

To set the keyword for requesting a challenge from the RADIUS server. By setting the challenge keyword, you let the user avoid using a password on the client to verify identity.

Syntax

SQLNET.RADIUS_CHALLENGE_KEYWORD=keyword

Default

challenge

Example

SQLNET.RADIUS_CHALLENGE_KEYWORD=challenge

Related Topics

SQLNET.RADIUS_CHALLENGE_RESPONSE

Use the sqlnet.ora parameter SQLNET.RADIUS_CHALLENGE_RESPONSE to enable or disable challenge responses.

Purpose

To turn the challenge responses on or off.

Default

off

Values

on | off

Example

SQLNET.RADIUS_CHALLENGE_RESPONSE=on

SQLNET.RADIUS_CLASSPATH

Use the sqlnet.ora parameter SQLNET.RADIUS_CLASSPATH to set the path for Java classes and JDK Java libraries.

Purpose

To set the path for Java classes for a graphical interface, and to set the path to JDK Java libraries.

If you use the challenge-response authentication mode, then RADIUS displays a Java-based graphical interface. This interface first requests a password and then additional information, for example, a dynamic password that the user obtains from a token card.

Syntax

SQLNET.RADIUS_CLASSPATH=path_to_GUI_Java_classes

Default

$ORACLE_HOME/jlib/netradius.jar:$ORACLE_HOME/JRE/lib/sparc/native_threads

Example

SQLNET.RADIUS_CLASSPATH=/jre1.1

Related Topics

SQLNET.RADIUS_SECRET

Use the sqlnet.ora parameter SQLNET.RADIUS_SECRET to specify the location of a RADIUS secret key.

Purpose

To specify the location of a RADIUS secret key.

Usage Notes

For RADIUS with TLS over TCP, the default value is radsec. This value is used if you do not set this parameter in the sqlnet.ora file.

There is no default value for RADIUS with UDP. You must configure this parameter with a directory path to the file containing secret key. For example:

ORACLE_HOME/network/security/radius.key

Example

SQLNET.RADIUS_SECRET=oracle/bin/admin/radiuskey

Related Topics

SQLNET.RADIUS_SEND_ACCOUNTING

Use the sqlnet.ora parameter SQLNET.RADIUS_SEND_ACCOUNTING to enable and disable accounting.

Purpose

To turn accounting ON and OFF. When you enable accounting, packets are sent to the active RADIUS server at the listening port number’s value plus one.

Default

OFF

Values

ON | OFF

Example

SQLNET.RADIUS_SEND_ACCOUNTING=ON

Related Topics

SQLNET.RADIUS_TRANSPORT_PROTOCOL

Use the server-side sqlnet.ora parameter SQLNET.RADIUS_TRANSPORT_PROTOCOL to control the transport protocol that the Oracle Database server must use for communicating with the RADIUS server.

Purpose

To specify mutual Transport Layer Security (mTLS), Transport Layer Security (TLS), or User Datagram Protocol (UDP) as the protocol for communication between the Oracle Database server (acting as the RADIUS client) and the RADIUS server.

Usage Notes

Values

MTLS | TLS | UDP

Default

MTLS

Example

SQLNET.RADIUS_TRANSPORT_PROTOCOL=MTLS

Related Topics

SQLNET.RECV_TIMEOUT

Use the sqlnet.ora parameter SQLNET.RECV_TIMEOUT to specify the duration of time that a database client or server should wait for data from a peer after establishing a connection.

Purpose

To specify the time for a database client or server to wait for data from the peer after establishing a connection. The peer must send data within the time interval that you specify.

You can specify the time in hours, minutes, seconds, or milliseconds by using the hr, min, sec, or ms keyword respectively. If you do not specify a unit of measurement, then the default unit is sec.

Usage Notes

Setting this parameter for clients ensures that receive operations are not left in a wait state indefinitely or for a long period due to an unusual termination of the server process or server busy state. If a client does not receive response data in the time specified, then the client logs ORA-12535: TNS:operation timed out and ORA-12609: TNS: Receive timeout occurred messages to the sqlnet.log file. If you set the value, then set the value initially to a low value and adjust the value according to the system and network capacity. If necessary, use this parameter with the SQLNET.SEND_TIMEOUT parameter.

You can also set this parameter on the server-side to specify the time, in ms, sec, or min, for a server to wait for client data after a connection is established. If a client does not send data in time specified, then the database server logs ORA-12535: TNS:operation timed out and ORA-12609: TNS: Receive timeout occurred messages to the sqlnet.log file. Without this parameter, the database server might continue to wait for data from clients that may be down or are experiencing problems. The server usually blocks input from the client and gets these timeouts frequently if you set it to a low value.

Default

None

Minimum Value

1 ms

Allowed Range

Any number greater than the minimum value of 1 ms up to 4294967295 ms.

Example

SQLNET.RECV_TIMEOUT=3 min

Related Topics

SQLNET.SEND_TIMEOUT

Use the sqlnet.ora parameter SQLNET.SEND_TIMEOUT to specify the duration of time in which a database must complete send operations to clients after establishing connections.

Purpose

To specify the time for a database to complete send operations to clients after establishing connections.

You can specify the time in hours, minutes, seconds, or milliseconds by using the hr, min, sec, or ms keyword respectively. If you do not specify a unit of measurement, then the default unit is sec.

Usage Notes

Setting this parameter is recommended for environments in which clients shut down occasionally or unusually.

If the database server cannot complete a send operation in the time specified, then it logs ORA-12608: TNS: Send timeout occurred messages to the sqlnet.log file. Without this parameter, the database server might continue to send responses to clients that are unable to receive data due to a downed computer or a busy state.

You can also set this parameter on the client-side to specify the duration of time in ms, sec, or min, in which client must complete send operations to the database server after connections are established. It accepts different timeouts with or without space between the value and the unit. If you do not specify a unit of measure, then the default unit is sec. Without this parameter, the client might continue to send requests to a database server that is saturated with requests. If you choose to set the value, then set the value initially to a low value and adjust the value according to system and network capacity.

If necessary, then use this parameter with the SQLNET.RECV_TIMEOUT parameter.

Default

None

Minimum Value

1 ms

Allowed Range

Any number greater than the minimum value of 1 ms up to 4294967295 ms.

Example

SQLNET.SEND_TIMEOUT=30 sec

Related Topics

SQLNET.URI

Use the sqlnet.ora parameter SQLNET.URI to specify a database client URI mapping on a web server.

Purpose

To specify a database client URI mapping on a web server.

Usage Notes

Use this parameter to customize a URI for mapping the database websocket requests that come into a web server to the back-end database server. Secure websocket handshaking requests are sent with this URI.

Default

/sqlnet

Example 5-6 Example

sqlnet.uri="/my_uri_prefix/database/"

SQLNET.USE_HTTPS_PROXY

Use the sqlnet.ora parameter SQLNET.USE_HTTPS_PROXY to enable forward HTTP proxy tunneling for client connections.

Purpose

To enable forward HTTP proxy tunneling for client connections.

Usage Notes

If set to on, then clients can tunnel secure connections over forward HTTP proxy using the HTTP CONNECT method. This helps access the public cloud database service because it eliminates the requirement to open an outbound port on a client-side firewall.

This parameter is applicable with Oracle Connection Manager on the server side.

Default

on

Example

SQLNET.USE_HTTPS_PROXY=on

SQLNET.WALLET_OVERRIDE

Use the sqlnet.ora parameter SQLNET.WALLET_OVERRIDE to determine whether a client should override strong authentication credentials with the password credential from the stored wallet.

Purpose

To determine whether a client should override strong authentication credentials with the password credential from the stored wallet to log in to a database.

Note: This is a client-side parameter. The SQLNET.WALLET_OVERRIDE=TRUE setting on the database server may break external procedures.

Usage Notes

Values

true | false

Example

SQLNET.WALLET_OVERRIDE=true

Related Topics

TLS_ALLOW_WEAK_DN_MATCH

Use the sqlnet.ora parameter TLS_ALLOW_WEAK_DN_MATCH to allow the earlier weaker distinguished name (DN) matching behavior during server-side certificate validation.

Purpose

The TLS_SERVER_DN_MATCH parameter controls the DN matching behavior. DN matching adds another client-side check on both the listener and server certificates to ensure that the certificates are the correct ones that the client expects.

Starting with Oracle AI Database 26ai, the DN matching behavior is enhanced for better security. You can use the TLS_ALLOW_WEAK_DN_MATCH parameter to revert to the earlier DN matching behavior, that is, checking only the server certificate and allowing a service name check for partial DN matching.

Usage Notes

Note: To bring Oracle parameters in accord with the actual encryption and authentication methods for network connections, Oracle is deprecating all connect parameters prefixed with SSL_ in favor of parameters prefixed with TLS_. During this deprecation period, if both TLS_ALLOW_WEAK_DN_MATCH and SSL_ALLOW_WEAK_DN_MATCH parameters are configured, then the SSL_ALLOW_WEAK_DN_MATCH parameter will be ignored.

This parameter, introduced with Oracle AI Database 26ai, provides you with a longer period of time to adjust to the new DN matching behavior of TLS_SERVER_DN_MATCH.

The TLS_ALLOW_WEAK_DN_MATCH parameter, though new to Oracle AI Database 26ai, is deprecated and will be removed in a future release. Oracle recommends that you get new certificates or change your DN matching strategy.

Values

Default

FALSE

Example

TLS_ALLOW_WEAK_DN_MATCH=FALSE

Related Topics

TLS_CERTIFICATE_ALIAS

Use the sqlnet.ora or tnsnames.ora parameter TLS_CERTIFICATE_ALIAS to specify the certificate alias to use in Transport Layer Security (TLS) connections.

Purpose

To specify the alias that you provided when storing the client or server certificate in an Oracle Database wallet.

When encrypting TLS connections, both the database client and database server need to provide a signed certificate. You can store this certificate in an Oracle Database wallet or Microsoft Certificate Store (MCS). If there is more than one certificate that can be used, the user or application settings can specify the particular certificate to connect with. This choice can be made manually by the user via graphical user interface (GUI) or automatically by the application using a thumbprint or alias name. A thumbprint or alias name can uniquely identify the certificate.

This parameter instructs the client or server to automatically select a particular certificate using the specified alias name. Thus, the user does not need to manually select the correct client certificate from the list available in a wallet.

Usage Notes

Note: To bring Oracle parameters in accord with the actual encryption and authentication methods for network connections, Oracle is deprecating all connect parameters prefixed with SSL_ in favor of parameters prefixed with TLS_. During this deprecation period, if bothTLS_CERTIFICATE_ALIAS and SSL_CERTIFICATE_ALIAS parameters are configured, then the SSL_CERTIFICATE_ALIAS parameter will be ignored.

Use this parameter in the tnsnames.ora file, sqlnet.ora file, or directly as part of the command-line connect string. The parameter values specified in the connect string take precedence over the other specified values.

orapki helps you manage certificates and wallets for Oracle Database. To get the alias name value, run the following command:

orapki wallet display -wallet <wallet directory> -pwd <wallet password> -complete

Value

Certificate alias name

Default

None

Examples

Related Topics

TLS_CERTIFICATE_THUMBPRINT

Use the sqlnet.ora or tnsnames.ora parameter TLS_CERTIFICATE_THUMBPRINT to specify the certificate thumbprint to use in Transport Layer Security (TLS) connections.

Purpose

To specify the thumbprint signature for an X509 certificate. These thumbprints are automatically generated for certificates.

When encrypting TLS connections, both the database client and database server need to provide a signed certificate. You can store this certificate in an Oracle Database wallet or Microsoft Certificate Store (MCS). If there is more than one certificate that can be used, the user or application settings can specify the particular certificate to connect with. This choice can be made manually by the user via graphical user interface (GUI) or automatically by the application using a thumbprint or alias name. A thumbprint or alias name can uniquely identify the certificate.

This parameter instructs the client or server to automatically select a particular certificate using the specified thumbprint. Thus, the user does not need to manually select the correct certificate from the list available in a certificate store.

Usage Notes

Note: To bring Oracle parameters in accord with the actual encryption and authentication methods for network connections, Oracle is deprecating all connect parameters prefixed with SSL_ in favor of parameters prefixed with TLS_. During this deprecation period, if both TLS_CERTIFICATE_THUMBPRINT and SSL_CERTIFICATE_THUMBPRINT parameters are configured, then the SSL_CERTIFICATE_THUMBPRINT parameter will be ignored.

Use this parameter in the tnsnames.ora file, sqlnet.ora file, or directly as part of the command-line connect string. The parameter values specified in the connect string take precedence over the other specified values.

You can specify both the SHA-1 and SHA-256 thumbprint information for the client certificate.

orapki helps you manage certificates and wallets for Oracle Database. To get the thumbprint value, run the following command:

orapki wallet display -wallet <wallet directory> -pwd <wallet password> -complete

Value

SHA-1 or SHA-256 thumbprint of the client certificate, in the <Algorithm>:<Hash> format

For example:

SHA1:1B:11:01:5A:B1:2C:20:B2:12:34:3E:04:7B:83:47:DE:70:2E:4E:11
SHA256:B3:8A:5B:1A:03:63:83:92:2B:5D:E1:53:61:EE:03:94:0A:56:B4:56:41:7E:41:24:41:9B:88:EB:C6:1E:11:23

or

SHA1:1B11015AB12C20B212343E047B8347DE702E4E11
SHA256:B38A5B1A036383922B5DE15361EE03940A56B456417E4124419B88EBC61E1123

Default

None

Examples

Related Topics

TLS_CERT_REVOCATION

Use the sqlnet.ora parameter TLS_CERT_REVOCATION to configure revocation checks for certificates.

Purpose

Note: To bring Oracle parameters in accord with the actual encryption and authentication methods for network connections, Oracle is deprecating all connect parameters prefixed with SSL_ in favor of parameters prefixed with TLS_. During this deprecation period, if both TLS_CERT_REVOCATION and SSL_CERT_REVOCATION parameters are configured, then the SSL_CERT_REVOCATION parameter will be ignored.

To configure a revocation check for a certificate.

See Also: Oracle Database Security Guide

Default

none

Values

Example

TLS_CERT_REVOCATION=required

TLS_CRL_FILE

Use the sqlnet.ora parameter TLS_CRL_FILE to specify the name of the file in which you assemble the certificate revocation list (CRL) for client authentication.

Purpose

To specify the name of the file where you can assemble the CRL for client authentication.

Usage Notes

Note: To bring Oracle parameters in accord with the actual encryption and authentication methods for network connections, Oracle is deprecating all connect parameters prefixed with SSL_ in favor of parameters prefixed with TLS_. During this deprecation period, if both TLS_CRL_FILE and SSL_CRL_FILE parameters are configured, then the SSL_CRL_FILE parameter will be ignored.

This file contains the PEM-encoded CRL files, in order of preference. You can use this file alternatively or in addition to the TLS_CRL_PATH parameter. This parameter is only valid if TLS_CERT_REVOCATION is set to either requested or required.

Syntax

TLS_CRL_FILE=certificate_revocation_list_filename

Default

None

Example

TLS_CRL_FILE=crl.txt

Related Topics

TLS_CRL_PATH

Use the sqlnet.ora parameter TLS_CRL_PATH to specify the destination directory of the certificate revocation list (CRL) for client authentication.

Purpose

To specify the directory path where CRLs are stored.

Usage Notes

Note: To bring Oracle parameters in accord with the actual encryption and authentication methods for network connections, Oracle is deprecating all connect parameters prefixed with SSL_ in favor of parameters prefixed with TLS_. During this deprecation period, if both TLS_CRL_PATH and SSL_CRL_PATH parameters are configured, then the SSL_CRL_PATH parameter will be ignored.

This parameter is only valid if you set TLS_CERT_REVOCATION to either requested or required.

Both DER-encoded (binary format) and PEM-encoded (BASE64) CRLs are supported.

If you want to store CRLs in a local file system directory, then you must use the orapki utility to rename CRLs in your file system so the system can locate them.

Syntax

TLS_CRL_PATH=certificate_revocation_list_path

Default

None

Example

TLS_CRL_PATH=/home/user1/crldir

Related Topics

TLS_CIPHER_SUITES

Use the TLS_CIPHER_SUITES parameter to control the combination of authentication, encryption, and data integrity algorithms used by Transport Layer Security (TLS).

Purpose

To control the combination of authentication, encryption, and data integrity algorithms used by TLS. By default, the strongest protocol and cipher are negotiated between the database client and server. Setting this parameter will override the default behavior. You must use this parameter only if you have internal security controls that dictate the usage of certain protocol versions.

Usage Notes

Note: To bring Oracle parameters in accord with the actual encryption and authentication methods for network connections, Oracle is deprecating all connect parameters prefixed with SSL_ in favor of parameters prefixed with TLS_. During this deprecation period, if both TLS_CIPHER_SUITES and SSL_CIPHER_SUITES parameters are configured, then the SSL_CIPHER_SUITES parameter will be ignored.

Starting with Oracle AI Database 26ai, the use of Transport Layer Security protocol versions 1.0 and 1.1 are desupported.

In most cases, this change will not have any impact, because the database client and server will negotiate the use of the most secure protocol and cipher algorithm. However, if TLS 1.0 or 1.1 has been specified, then you must either remove it to allow the database server and client to pick the most secure protocol, or you must specify either TLS 1.2, or TLS 1.3, or both, for the protocol. Oracle recommends using the latest, most secure protocol. That protocol is TLS 1.3, which is introduced with Oracle AI Database 26ai.

Enclose the TLS_CIPHER_SUITES parameter value in parentheses. Otherwise, the cipher suite setting does not parse correctly.

Default

None

Values

Approved ciphers compatible with TLS 1.3:

Approved ciphers compatible with TLS 1.2:

Deprecated ciphers compatible with TLS 1.2:

Examples

TLS_CIPHER_SUITES=(TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256)
TLS_CIPHER_SUITES=(TLS_AES_256_GCM_SHA384, TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256)

Related Topics

TLS_CLIENT_AUTHENTICATION

Use the TLS_CLIENT_AUTHENTICATION parameter to specify whether the database client is authenticated using Transport Layer Security (TLS).

Purpose

To enable client authentication in a TLS connection. The connection can be one-way or two-way (mutual TLS or mTLS).

Usage Notes

Note: To bring Oracle parameters in accord with the actual encryption and authentication methods for network connections, Oracle is deprecating all connect parameters prefixed with SSL_ in favor of parameters prefixed with TLS_. During this deprecation period, if both TLS_CLIENT_AUTHENTICATION and SSL_CLIENT_AUTHENTICATION parameters are configured, then the SSL_CLIENT_AUTHENTICATION parameter will be ignored.

When set to TRUE, a two-way TLS connection is initiated. Both the client and server (including the listener) authenticate each other. For example, if you set this parameter to TRUE in the server configuration (server-side sqlnet.ora), then the server attempts to authenticate the client. If you set it to TRUE in the listener configuration (listener.ora), then the listener attempts to authenticate the client.

When set to FALSE, only the client authenticates the server and listener as a one-way TLS connection. For example, if you set this parameter to FALSE in the server configuration, then the server does not authenticate the client. If you set it to FALSE in the listener configuration, then the listener does not authenticate the client.

When set to OPTIONAL, the server behaves as follows:

Ensure that this parameter setting is consistent for the server or listener (on one side) and the client (on the other). Otherwise, the connection may fail. For example, if you enable client authentication in the server or listener configuration, then you must enable it in the client configuration.

Default

TRUE

Values

Example

TLS_CLIENT_AUTHENTICATION=FALSE

Related Topics

TLS_DISABLE_WEAK_EC_CURVES

Use the TLS_DISABLE_WEAK_EC_CURVES parameter to disable the use of weak Elliptic Curve Cryptography (ECC) curves.

Purpose

To disable the use of weak ECC curves with key length less than 256 bits. You can set this parameter in the database server (sqlnet.ora), client (sqlnet.ora or tnsnames.ora connect string), or the listener (listener.ora).

Usage Notes

Note: TLS_DISABLE_WEAK_EC_CURVES is deprecated in favor of TLS_KEY_EXCHANGE_GROUPS parameter starting with Oracle AI Database 26ai. Elliptic Curve Cryptography (ECC) features in Oracle Net Services, such as those used for secure external password stores, have some curves disabled by default. Oracle and other major vendors disable weak elliptic curves by default to protect systems from known cryptographic vulnerabilities, and to enforce modern security standards. These older, weaker curves can be susceptible to a variety of attacks and may present security risks if used. Because Oracle no longer has ECC curves with key length less than 256 bit enabled, this parameter no longer serves a purpose, and will be removed in a future release. Oracle strongly recommends that you review your configurations to ensure that you follow security best practices.

Note: To bring Oracle parameters in accord with the actual encryption and authentication methods for network connections, Oracle is deprecating all connect parameters prefixed with SSL_ in favor of parameters prefixed with TLS_. During this deprecation period, if both TLS_DISABLE_WEAK_EC_CURVES and SSL_DISABLE_WEAK_EC_CURVES parameters are configured, then the SSL_DISABLE_WEAK_EC_CURVES parameter will be ignored.

By default, this parameter is set to FALSE to enable the use of all ECC curves. If you want to enable the use of only Oracle approved curves with ECC curve key size of 256 bits or higher, then set this parameter to TRUE.

When set to TRUE, you can use only the following ECC curves:

Values

Default

FALSE

Examples

Related Topics

TLS_ENABLE_WEAK_CIPHERS

Use the sqlnet.ora parameter TLS_ENABLE_WEAK_CIPHERS to enable the use of weak Transport Layer Security (TLS) cipher suites.

Purpose

To enable the use of weak TLS ciphers for backward compatibility. You can set this parameter on both the database server and client.

Usage Notes

Note: To bring Oracle parameters in accord with the actual encryption and authentication methods for network connections, Oracle is deprecating all connect parameters prefixed with SSL_ in favor of parameters prefixed with TLS_. During this deprecation period, if both TLS_ENABLE_WEAK_CIPHERS and SSL_ENABLE_WEAK_CIPHERS parameters are configured, then the SSL_ENABLE_WEAK_CIPHERS parameter will be ignored.

By default, this parameter is set to FALSE to block the use of weak ciphers. This simplifies the passing of compliance audits and improves the overall security of your database. If you want to enable the use of weak ciphers, then set this parameter to TRUE.

When set to FALSE, you can use only the following strong ciphers:

With the TLS_ENABLE_WEAK_CIPHERS=FALSE setting, if you try to use a weak cipher, then the following error messages appear:

Values

Default

FALSE

Example

TLS_ENABLE_WEAK_CIPHERS=FALSE

Related Topics

TLS_EXTENDED_KEY_USAGE

Use the sqlnet.ora parameter TLS_EXTENDED_KEY_USAGE to specify the purpose certificate keys.

Purpose

To specify the purpose of the key in a certificate.

Usage Notes

Note: To bring Oracle parameters in accord with the actual encryption and authentication methods for network connections, Oracle is deprecating all connect parameters prefixed with SSL_ in favor of parameters prefixed with TLS_. During this deprecation period, if both TLS_EXTENDED_KEY_USAGE and SSL_EXTENDED_KEY_USAGE parameters are configured, then the SSL_EXTENDED_KEY_USAGE parameter will be ignored.

When you specify this parameter, Oracle uses the certificate with the matching extended key.

Values

client authentication

Example

TLS_EXTENDED_KEY_USAGE="client authentication"

TLS_KEY_EXCHANGE_GROUPS

Use the TLS_KEY_EXCHANGE_GROUPS parameter to enable or disable post-quantum cryptographic (PQC) ML-KEM algorithms and classical Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) groups for TLS connections.

Purpose

To enable selection of classical or quantum-safe key exchange algorithms for TLS connections. You can set this parameter in the database server (sqlnet.ora), client (sqlnet.ora or tnsnames.ora connect string), or the listener (listener.ora).

Usage Notes

This parameter takes a combination of following values as a comma-separated list:

Values

A comma-separated list of one or more of the values below:

The order in which you specify the values in the TLS_KEY_EXCHANGE_GROUPS parameter is honored. If you set TLS_KEY_EXCHANGE_GROUPS to ml-kem,hybrid,ec, then ML-KEM groups are given the highest preference, followed by Hybrid and ECDHE groups.

The following table shows the results of TLS negotiations based on the TLS_KEY_EXCHANGE_GROUPS values from the DB26ai client and the DB26ai server.

Server-Side Value Client-Side Value Result
Not set Not set Hybrid
ec,ml-kem ec,ml-kem ECDHE
ec,ml-kem ml-kem ML-KEM
ml-kem ec,ml-kem ML-KEM
ml-kem ml-kem ML-KEM
ec ec ECDHE
ml-kem,hybrid ml-kem,hybrid ML-KEM
ml-kem,hybrid Not set Hybrid
Not set ml-kem,ec ML-KEM

Default

hybrid, ec, weak, and ml-kem are enabled by default, in that order.

If you do not explicitly set the TLS_KEY_EXCHANGE_GROUPS parameter, then by default, TLS connections are negotiated with Hybrid TLS groups (if both the server and client support Hybrid PQC). However, if either the server or client does not support Hybrid PQC, the TLS connections will fallback to ECDHE groups transparently.

Examples

Related Topics

TLS_SERVER_DN_MATCH

Use the TLS_SERVER_DN_MATCH parameter to enforce server-side certificate validation through distinguished name (DN) matching.

Purpose

To enforce server-side certificate validation through DN matching.

The purpose of adding this DN matching parameter for the client is to further improve security on a Transport Layer Security (TLS) connection. A TLS connection relies on the client to verify if the database server certificate is valid and signed by a trusted root certificate. The listener and server certificate DN matching adds another client-side check on the listener and server certificates to ensure that the certificates are the correct ones that the client expects.

Usage Notes

Note: To bring Oracle parameters in accord with the actual encryption and authentication methods for network connections, Oracle is deprecating all connect parameters prefixed with SSL_ in favor of parameters prefixed with TLS_. During this deprecation period, if bothTLS_SERVER_DN_MATCH and SSL_SERVER_DN_MATCH parameters are configured, then the SSL_SERVER_DN_MATCH parameter will be ignored.

Default

NO

Values

Note:

Oracle recommends setting TLS_SERVER_DN_MATCH=YES unless you have a compelling, well-understood business case that requires disabling it.

Below are the potential risks when TLS_SERVER_DN_MATCH=NO:

If host name matching must be disabled, ensure that robust alternative controls are in place:

Example

TLS_SERVER_DN_MATCH=YES

Related Topics

TLS_VERSION

Use the TLS_VERSION parameter to define valid Transport Layer Security (TLS) versions to be used for connections.

Purpose

To define the version of TLS that must run on the systems with which the database server communicates. By default, the database server and client negotiate the strongest security protocol. Oracle does not recommend modifying this parameter, unless your security requirements mandate the usage of certain protocol versions.

Usage Notes

Note: To bring Oracle parameters in accord with the actual encryption and authentication methods for network connections, Oracle is deprecating all connect parameters prefixed with SSL_ in favor of parameters prefixed with TLS_. During this deprecation period, if both TLS_VERSION and SSL_VERSION parameters are configured, then the SSL_VERSION parameter will be ignored.

Values

undetermined | TLSv1.2 | TLSv1.3

Default

undetermined

Syntax and Examples

Related Topics

TCP.ALLOWED_PROXIES

Use the sqlnet.ora parameter TCP.ALLOWED_PROXIES to specify a list of the Oracle Connection Manager (CMAN) addresses that can forward client IP address to the database server.

Purpose

To specify a list of the CMAN addresses (IP addresses or host names) that can forward client IP address to the database server.

Usage Notes

Use this parameter in the server-side sqlnet.ora file to list the allowed CMAN instances.

In addition to the TCP.ALLOWED_PROXIES parameter, you must set the ENABLE_IP_FORWARDING parameter in the cman.ora file to enable client address forwarding. CMAN will forward client address only if ENABLE_IP_FORWARDING is set to ON.

You can use the SYS_CONTEXT ('USERENV','IP_ADDRESS') function to query the forwarded client address details.

Default

None

Value

A comma-separated list of IP addresses or host names from which you want to allow client address forwarding.

Example

TCP.ALLOWED_PROXIES=(10.1.1.1/24,cmanhost1.example.com)

Related Topics

TCP.CONNECT_TIMEOUT

Use the sqlnet.ora parameter TCP.CONNECT_TIMEOUT to specify the amount of time in which a client must establish TCP connections to database servers.

Purpose

To specify the time in ms, sec, or min, for a client to establish a TCP connection (PROTOCOL=tcp in the TNS connect address) to the database server.

Usage Notes

If a TCP connection to the database is not established in the specified amount of time, then the connection attempt ends. The client receives the following error:

ORA-12170: Cannot connect. TCP connect timeout of time_interval for host_port or key. (CONNECTION_ID=ID_string).

The timeout applies to each IP address that resolves to a host name. It accepts different timeouts with or without space between the value and the unit. For example, if a host name resolves to an IPv6 and an IPv4 address, and if the host is not reachable through the network, then the connection request times out twice because there are two IP addresses. In this example, the default timeout setting of 60 causes a timeout in 120 seconds. If you do not specify a unit of measure, then the default unit is sec.

Default

60

Example

TCP.CONNECT_TIMEOUT=40 sec

TCP.EXCLUDED_NODES

Use the sqlnet.ora parameter TCP.EXCLUDED_NODES to specify which clients are denied access to the database.

Purpose

To specify which clients are denied access to the database.

Usage Notes

This parameter is only valid when you set the TCP.VALIDNODE_CHECKING parameter to yes.

You can use wildcards in this parameter for IPv4 addresses and CIDR notation for IPv4 and IPv6 addresses.

Syntax

TCP.EXCLUDED_NODES=(hostname | ip_address, hostname | ip_address, ...)

Example

TCP.EXCLUDED_NODES=(finance.us.example.com, mktg.us.example.com, 192.0.2.25,
 172.30.*, 2001:DB8:200C:417A/32)

TCP.INVITED_NODES

Use the sqlnet.ora parameter TCP.INVITED_NODES to specify which clients are allowed access to the database.

Purpose

To specify which clients are allowed access to the database. This list takes precedence over the TCP.EXCLUDED_NODES parameter if both lists are present.

Syntax

TCP.INVITED_NODES=(hostname | ip_address, hostname | ip_address, ...)

Usage Notes

Example

TCP.INVITED_NODES=(sales.us.example.com, hr.us.example.com, 192.0.*,
 2001:DB8:200C:433B/32)

TCP.NODELAY

Use the sqlnet.ora parameter TCP.NODELAY to preempt delays in buffer flushing within the TCP/IP protocol stack.

Purpose

To preempt delays in buffer flushing within the TCP/IP protocol stack.

Default

yes

Values

yes | no

Example

TCP.NODELAY=yes

TCP.QUEUESIZE

Use the sqlnet.ora parameter TCP.QUEUESIZE to configure the maximum length of queues for pending connections on TCP listening sockets.

Purpose

To configure the maximum length of the queue for pending connections on a TCP listening socket.

Default

System-defined maximum value. The defined maximum value for Linux is 128.

Values

Any integer value up to the system-defined maximum.

Examples

TCP.QUEUESIZE=100

TCP.VALIDNODE_CHECKING

Use the sqlnet.ora parameter TCP.VALIDNODE_CHECKING to enable and disable valid node checking for incoming connections.

Purpose

To enable and disable valid node checking for incoming connections.

Usage Notes

If you set this parameter to yes, then incoming connections are allowed only if the connections originate from a node that conforms to a list that you specified in the TCP.INVITED_NODES or TCP.EXCLUDED_NODES parameters.

The TCP.INVITED_NODES and TCP.EXCLUDED_NODES parameters are valid only when you set the TCP.VALIDNODE_CHECKING parameter to yes.

You must set this parameter and the dependent parameters, TCP.INVITED_NODES and TCP.EXCLUDED_NODES, in the sqlnet.ora file of the listener. This is important in Oracle RAC environments where listeners run from the Oracle Grid Infrastructure home. Setting the parameter in the database home does not have an effect in Oracle RAC environments. In such environments, you must include the address of all Single Client Access Name (SCANs), Virtual IPs (VIPs), local IP in the TCP.INVITED_NODES list.

In VLAN environments, the sqlnet.ora file present in the Oracle Grid Infrastructure homes should include all of the addresses of all of the VLANs. The VLANs perform the network segregation, whereas the values that are set for INVITED_NODES enables or restricts access to databases within the VLANs.

If multiple databases within the same VLAN require different INVITED_NODE lists, then you must configure separate listeners.

Default

no

Values

yes | no

Example

TCP.VALIDNODE_CHECKING=yes

TENANT_ID

Use the TENANT_ID parameter to specify the ID of your Microsoft Entra ID tenant.

Purpose

To specify the ID of the Entra ID tenant in which your Entra ID application is registered. This is the Azure tenancy ID that uniquely identifies your database instance in Entra ID.

Usage Notes

Default

None

Value

You can get the tenant ID value by logging in to the Azure portal. This is listed as Tenant ID on the Tenant Properties page.

Examples

In the tnsnames.ora file:

net_service_name=
    (DESCRIPTION =
       (ADDRESS=(PROTOCOL=tcps)(HOST=sales-svr)(PORT=1521))
       (SECURITY=
          (TLS_SERVER_DN_MATCH=TRUE)
          (TLS_SERVER_CERT_DN="C=US,O=example,CN=OracleContext")
          (TOKEN_AUTH=AZURE_INTERACTIVE)
          (AZURE_DB_APP_ID_URI=https://application.example.com/123ab4cd-1a2b-1234-a12b-aa00123b2cd3)
          (TENANT_ID=1a123ab1-a1b1-1a2b-a1b2-a12bcdab0123)
          (REDIRECT_URI=http://localhost:1575))
       (CONNECT_DATA=(SERVICE_NAME=sales.us.example.com))
     )

In the sqlnet.ora file:

TLS_SERVER_DN_MATCH=TRUE
TOKEN_AUTH=AZURE_INTERACTIVE
AZURE_DB_APP_ID_URI=https://application.example.com/123ab4cd-1a2b-1234-a12b-aa00123b2cd3
TENANT_ID=1a123ab1-a1b1-1a2b-a1b2-a12bcdab0123
REDIRECT_URI=http://localhost:1575

In the Easy Connect string:

tcps:sales-svr:1521/sales.us.example.com?TOKEN_AUTH=AZURE_INTERACTIVE&AZURE_DB_APP_ID_URI=https://application.example.com/123ab4cd-1a2b-1234-a12b-aa00123b2cd3&TENANT_ID=1a123ab1-a1b1-1a2b-a1b2-a12bcdab0123&REDIRECT_URI=http://localhost:1575

In these examples, the CLIENT_ID parameter is not specified. CLIENT_ID is required when using the thick clients (OCI and Instant Client). This parameter is optional for the JDBC-thin and ODP.NET core and managed database clients, which can automatically get this value from the Azure SDK configuration.

Related Topics

TNSPING.TRACE_DIRECTORY

Use the sqlnet.ora parameter TNSPING.TRACE_DIRECTORY to specify the destination directory for the TNSPING utility trace file, tnsping.trc.

Purpose

To specify the destination directory for the TNSPING utility trace file, tnsping.trc.

Default

The ORACLE_HOME/network/trace directory.

Example

TNSPING.TRACE_DIRECTORY=/oracle/traces

TNSPING.TRACE_LEVEL

Use the sqlnet.ora parameter TNSPING.TRACE_LEVEL to enable or disable TNSPING utility tracing at a specified level.

Purpose

To enable or diable TNSPING utility tracing at a specified level.

Default

off

Values

Example

TNSPING.TRACE_LEVEL=admin

TOKEN_AUTH

Use the TOKEN_AUTH parameter to configure token-based authentication for Oracle Cloud Infrastructure (OCI) Identity and Access Management (IAM) or Microsoft Azure users of Microsoft Entra ID (previously called Microsoft Azure Active Directory).

Purpose

Token-based access enforces strong authentication, which enables a more secure access to the database. IAM users can connect to OCI Database as a Service (DBaaS) databases, and Azure users can connect to Oracle Databases (cloud or on-premises).

With this setting, when a / (slash) login is used, the Oracle Database client either looks for a token file or directly gets the token using single-sign on (SSO) credentials.

Use this parameter under the SECURITY section of the tnsnames.ora file, sqlnet.ora file, or directly as part of the command-line connect string. The parameter value specified in the connect string takes precedence over the other specified values.

Usage Notes for IAM

Note:

You can also use another IAM credential, IAM database password, to request the db-token from IAM. This db-token is a bearer token and does not come with a private key. You can configure the database client to request this token using your IAM user name and IAM database password. An application cannot pass this type of db-token to the client. In this case, you use a different parameter setting (PASSWORD_AUTH=OCI_TOKEN).

Unlike the API-key, security token, resource principal, service principal, instance principal, and delegation token that require an application or tool to get a token, the IAM database password can only be used by the database client to retrieve the token. See PASSWORD_AUTH.

Default Setting for IAM

None

Table 2 Values and Examples for IAM

Value Example
TOKEN_AUTH=OCI_TOKEN

In the tnsnames.ora file:

net_service_name= (DESCRIPTION = (ADDRESS=(PROTOCOL=tcps)(HOST=sales-svr)(PORT=1521)) (SECURITY= (TLS_SERVER_DN_MATCH=TRUE) (TLS_SERVER_CERT_DN="C=US,O=example,CN=OracleContext") (TOKEN_AUTH=OCI_TOKEN)) (CONNECT_DATA=(SERVICE_NAME=sales.us.example.com)) ) 

In the sqlnet.ora file:

TLS_SERVER_DN_MATCH=TRUE TOKEN_AUTH=OCI_TOKEN

In these examples, the optional TOKEN_LOCATION parameter is not specified. Thus, the client automatically gets the db-token and private key from the default token location.

TOKEN_AUTH=OCI_INTERACTIVE

In the tnsnames.ora file:

net_service_name= (DESCRIPTION = (ADDRESS=(PROTOCOL=tcps)(HOST=sales-svr)(PORT=1521)) (SECURITY= (TLS_SERVER_DN_MATCH=TRUE) (TLS_SERVER_CERT_DN="C=US,O=example,CN=OracleContext") (TOKEN_AUTH=OCI_INTERACTIVE)) (CONNECT_DATA=(SERVICE_NAME=sales.us.example.com)) ) 

In the sqlnet.ora file:

TLS_SERVER_DN_MATCH=TRUE TOKEN_AUTH=OCI_INTERACTIVE

In these examples, the optional OCI_CONFIG and OCI_PROFILE parameters are not specified. Thus, the client automatically gets the DEFAULT profile from the default configuration file directory.

TOKEN_AUTH=OCI_API_KEY

In the tnsnames.ora file:

net_service_name= (DESCRIPTION = (ADDRESS=(PROTOCOL=tcps)(HOST=sales-svr)(PORT=1521)) (SECURITY= (TLS_SERVER_DN_MATCH=TRUE) (TLS_SERVER_CERT_DN="C=US,O=example,CN=OracleContext") (TOKEN_AUTH=OCI_API_KEY)) (CONNECT_DATA=(SERVICE_NAME=sales.us.example.com)) ) 

In the sqlnet.ora file:

TLS_SERVER_DN_MATCH=TRUE TOKEN_AUTH=OCI_API_KEY

In these examples, the optional OCI_CONFIG and OCI_PROFILE parameters are not specified. Thus, the client automatically gets the API-key value from the DEFAULT profile stored in the default configuration file directory.

TOKEN_AUTH=OCI_INSTANCE_PRINCIPAL

In the tnsnames.ora file:

net_service_name= (DESCRIPTION = (ADDRESS=(PROTOCOL=tcps)(HOST=sales-svr)(PORT=1521)) (SECURITY= (TLS_SERVER_DN_MATCH=TRUE) (TLS_SERVER_CERT_DN="C=US,O=example,CN=OracleContext") (TOKEN_AUTH=OCI_INSTANCE_PRINCIPAL)) (CONNECT_DATA=(SERVICE_NAME=sales.us.example.com)) ) 

In the sqlnet.ora file:

TLS_SERVER_DN_MATCH=TRUE TOKEN_AUTH=OCI_INSTANCE_PRINCIPAL

TOKEN_AUTH=OCI_DELEGATION_TOKEN

In the tnsnames.ora file:

net_service_name= (DESCRIPTION = (ADDRESS=(PROTOCOL=tcps)(HOST=sales-svr)(PORT=1521)) (SECURITY= (TLS_SERVER_DN_MATCH=TRUE) (TLS_SERVER_CERT_DN="C=US,O=example,CN=OracleContext") (TOKEN_AUTH=OCI_DELEGATION_TOKEN)) (CONNECT_DATA=(SERVICE_NAME=sales.us.example.com)) ) 

In the sqlnet.ora file:

TLS_SERVER_DN_MATCH=TRUE TOKEN_AUTH=OCI_DELEGATION_TOKEN

TOKEN_AUTH=OCI_RESOURCE_PRINCIPAL

In the tnsnames.ora file:

net_service_name= (DESCRIPTION = (ADDRESS=(PROTOCOL=tcps)(HOST=sales-svr)(PORT=1521)) (SECURITY= (TLS_SERVER_DN_MATCH=TRUE) (TLS_SERVER_CERT_DN="C=US,O=example,CN=OracleContext") (TOKEN_AUTH=OCI_RESOURCE_PRINCIPAL)) (CONNECT_DATA=(SERVICE_NAME=sales.us.example.com)) ) 

In the sqlnet.ora file:

TLS_SERVER_DN_MATCH=TRUE TOKEN_AUTH=OCI_RESOURCE_PRINCIPAL

Usage Notes for Entra ID

  1. Azure Service Principal with Client Secret Credentials: The driver checks if client ID and client secret are configured as parameters to the driver or as SDK environment variables. If both are configured, then the driver authenticates as a service principal using a client secret. Otherwise, the driver proceeds to the next step.

    1. Azure Service Principal with Client Certificate Credentials: The driver checks if client ID and client certificate are configured as parameters to the driver or SDK environment variables. If both are configured, then the driver authenticates as a service principal using a client certificate. Otherwise, the driver proceeds to the next step.

    2. Azure Username Credentials: The driver checks if client ID, username, and password are configured as parameters to the driver or SDK environment variables. If all are configured, then the driver authenticates as a service principal using the username and password. Otherwise, the driver proceeds to the next step.

    3. Azure Managed Identity: The driver checks if the MSI_ENDPOINT or IDENTITY_ENDPOINT environment variable is set. If either is set, then the driver authenticates as a managed identity using the configured endpoint. If neither is set, then the driver checks if the AZURE_TENANT_ID and AZURE_FEDERATED_TOKEN_FILE environment variables are set. If both are set, then the driver authenticates as a managed identity using the configured token file. If both are not set, then the driver requests an access token from the Azure Instance Metadata Service (IMDS) endpoint. If the request succeeds, then the driver authenticates as a managed identity. Otherwise, the driver proceeds to the next step.

    4. Visual Studio Credentials: For ODP.NET Core classes and ODP.NET Managed Driver classes, the driver additionally evaluates the Azure user through Visual Studio Credentials authentication flow. The driver checks if the TENANT_ID parameter or the AZURE_TENANT_ID environment variable is set and if the Azure user is logged in to Visual Studio. If both the checks succeed, then authentication with the Visual Studio credentials is used. Otherwise, the driver proceeds to the next step.

    5. The driver reports an error indicating that authentication is not possible using any of the authentication flows.

Default Setting for Entra ID

None

Table 3 Values and Examples for Entra ID

Value Example
TOKEN_AUTH=OAUTH

  • If the token file is named token, TOKEN_AUTH=OAUTH, and TOKEN_LOCATION="token_file_directory":

    In the tnsnames.ora file:
    net_service_name= (DESCRIPTION= (ADDRESS=(PROTOCOL=tcps)(HOST=salesserver1)(PORT=1522)) (SECURITY= (TLS_SERVER_DN_MATCH=TRUE) (TLS_SERVER_CERT_DN="C=US,O=example,CN=OracleContext") (TOKEN_AUTH=OAUTH) (TOKEN_LOCATION="/home/dbuser1/access-token")) (CONNECT_DATA=(SERVICE_NAME=sales.us.example.com)) ) 

In the sqlnet.ora file:

TLS_SERVER_DN_MATCH=TRUE TOKEN_AUTH=OAUTH  TOKEN_LOCATION="/home/dbuser1/access-token" 

In these examples, the token file name is token. Thus, only the directory path (/home/dbuser1/access-token) is specified. The client automatically looks for the token file in the specified path and gets the access token.

  • If the token file name is different from token, TOKEN_AUTH=OAUTH, and TOKEN_LOCATION="token_file_directory/token_filename":

    In the tnsnames.ora file:

    net_service_name= (DESCRIPTION= (ADDRESS=(PROTOCOL=tcps)(HOST=salesserver1)(PORT=1522)) (SECURITY= (TLS_SERVER_DN_MATCH=TRUE) (TLS_SERVER_CERT_DN="C=US,O=example,CN=OracleContext") (TOKEN_AUTH=OAUTH) (TOKEN_LOCATION="/home/dbuser1/access-token/mytoken")) (CONNECT_DATA=(SERVICE_NAME=sales.us.example.com)) ) 

    In the sqlnet.ora file:

    TLS_SERVER_DN_MATCH=TRUE TOKEN_AUTH=OAUTH  TOKEN_LOCATION="/home/dbuser1/access-token/mytoken" 

    In these examples, the token file name is mytoken. Thus, both the file name and directory path (/home/dbuser1/access-token) are specified. The client gets the access token from the mytoken file in the specified path.

  • TOKEN_AUTH=AZURE_INTERACTIVE

    In the tnsnames.ora file:

    net_service_name= (DESCRIPTION = (ADDRESS=(PROTOCOL=tcps)(HOST=sales-svr)(PORT=1521)) (SECURITY= (TLS_SERVER_DN_MATCH=TRUE) (TLS_SERVER_CERT_DN="C=US,O=example,CN=OracleContext") (TOKEN_AUTH=AZURE_INTERACTIVE) (AZURE_DB_APP_ID_URI=https://application.example.com/123ab4cd-1a2b-1234-a12b-aa00123b2cd3) (REDIRECT_URI=http://localhost:1575)) (CONNECT_DATA=(SERVICE_NAME=sales.us.example.com)) ) 

    In the sqlnet.ora file:

    TLS_SERVER_DN_MATCH=TRUE TOKEN_AUTH=AZURE_INTERACTIVE AZURE_DB_APP_ID_URI=https://application.example.com/123ab4cd-1a2b-1234-a12b-aa00123b2cd3 REDIRECT_URI=http://localhost:1575

    In these examples, the CLIENT_ID and TENANT_ID parameters are not specified. These parameters are optional for the JDBC-thin and ODP.NET core and managed database clients, which can automatically get these values from the Azure SDK configuration. The thick clients (OCI and Instant Client) must specify these parameters.

    TOKEN_AUTH=AZURE_SERVICE_PRINCIPAL

    In the tnsnames.ora file:

    net_service_name= (DESCRIPTION = (ADDRESS=(PROTOCOL=tcps)(HOST=sales-svr)(PORT=1521)) (SECURITY= (TLS_SERVER_DN_MATCH=TRUE) (TLS_SERVER_CERT_DN="C=US,O=example,CN=OracleContext") (TOKEN_AUTH=AZURE_SERVICE_PRINCIPAL) (AZURE_DB_APP_ID_URI=https://application.example.com/123ab4cd-1a2b-1234-a12b-aa00123b2cd3)) (CONNECT_DATA=(SERVICE_NAME=sales.us.example.com)) ) 

    In the sqlnet.ora file:

    TLS_SERVER_DN_MATCH=TRUE TOKEN_AUTH=AZURE_SERVICE_PRINCIPAL AZURE_DB_APP_ID_URI=https://application.example.com/123ab4cd-1a2b-1234-a12b-aa00123b2cd3

    In these examples, the CLIENT_ID, TENANT_ID, and CLIENT_CERTIFICATE parameters are not specified. CLIENT_ID and TENANT_ID are optional for the JDBC-thin and ODP.NET core and managed database clients, which can automatically get these values from the Azure SDK configuration. The thick clients (OCI and Instant Client) must specify these parameters.

    TOKEN_AUTH=AZURE_MANAGED_IDENTITY

    In the tnsnames.ora file:

    net_service_name= (DESCRIPTION = (ADDRESS=(PROTOCOL=tcps)(HOST=sales-svr)(PORT=1521)) (SECURITY= (TLS_SERVER_DN_MATCH=TRUE) (TLS_SERVER_CERT_DN="C=US,O=example,CN=OracleContext") (TOKEN_AUTH=AZURE_MANAGED_IDENTITY) (AZURE_DB_APP_ID_URI=https://application.example.com/123ab4cd-1a2b-1234-a12b-aa00123b2cd3)) (CONNECT_DATA=(SERVICE_NAME=sales.us.example.com)) ) 

    In the sqlnet.ora file:

    TLS_SERVER_DN_MATCH=TRUE TOKEN_AUTH=AZURE_MANAGED_IDENTITY AZURE_DB_APP_ID_URI=https://application.example.com/123ab4cd-1a2b-1234-a12b-aa00123b2cd3

    In these examples, the CLIENT_ID parameter is not specified. This parameter is optional for the JDBC-thin and ODP.NET core and managed database clients, which can automatically get this value from the Azure SDK configuration. The thick clients (OCI and Instant Client) must specify this parameter.

    TOKEN_AUTH=AZURE_DEVICE_CODE

    In the tnsnames.ora file:

    net_service_name= (DESCRIPTION = (ADDRESS=(PROTOCOL=tcps)(HOST=sales-svr)(PORT=1521)) (SECURITY= (TLS_SERVER_DN_MATCH=TRUE) (TLS_SERVER_CERT_DN="C=US,O=example,CN=OracleContext") (TOKEN_AUTH=AZURE_DEVICE_CODE) (AZURE_DB_APP_ID_URI=https://application.example.com/123ab4cd-1a2b-1234-a12b-aa00123b2cd3)) (CONNECT_DATA=(SERVICE_NAME=sales.us.example.com)) ) 

    In the sqlnet.ora file:

    TLS_SERVER_DN_MATCH=TRUE TOKEN_AUTH=AZURE_DEVICE_CODE AZURE_DB_APP_ID_URI=https://application.example.com/123ab4cd-1a2b-1234-a12b-aa00123b2cd3

    In these examples, the CLIENT_ID and TENANT_ID parameters are not specified. These parameters are optional for the JDBC-thin and ODP.NET core and managed database clients, which can automatically get these values from the Azure SDK configuration. The thick clients (OCI and Instant Client) must specify these parameters.

    Related Topics

    TOKEN_LOCATION

    Use the TOKEN_LOCATION parameter to specify the directory location where token file is stored for token-based authentication.

    Purpose

    To specify the token file directory location. You use this parameter while configuring token-based authentication for Oracle Cloud Infrastructure (OCI) Identity and Access Management (IAM) or Microsoft Azure users of Microsoft Entra ID. The database client gets the token from this location and sends it to the database server. For Entra ID, you can also specify the token file name along with the directory location.

    Use this parameter along with the TOKEN_AUTH parameter in the tnsnames.ora file, sqlnet.ora file, or directly as part of the command-line connect string. The parameter values specified in the connect string take precedence over the other specified values.

    Usage Notes for IAM

    The TOKEN_LOCATION parameter is optional for IAM token-based authentication. You can use this parameter along with the TOKEN_AUTH parameter to override the default directory where the db-token and private key are stored. This location is used by the database client to retrieve the db-token and private key.

    When an IAM user initiates a connection using /@connect_identifier (and TOKEN_AUTH is set to OCI_TOKEN), the database client retrieves the db-token and private key from either the default directory or the location specified by TOKEN_LOCATION. The client then signs the db-token using the private key and sends the db-token to the database server.

    Default Setting for IAM

    Values and Examples for IAM

    Value Example
    TOKEN_LOCATION="token_file_directory"

    In the tnsnames.ora file:

    net_service_name= (DESCRIPTION = (ADDRESS=(PROTOCOL=tcps)(HOST=sales-svr)(PORT=1521)) (SECURITY= (TLS_SERVER_DN_MATCH=TRUE) (TLS_SERVER_CERT_DN="C=US,O=example,CN=OracleContext") (TOKEN_AUTH=OCI_TOKEN) (TOKEN_LOCATION="/home/oracle/.oci/db-token")) (CONNECT_DATA=(SERVICE_NAME=sales.us.example.com)) ) 

    In the sqlnet.ora file:

    TLS_SERVER_DN_MATCH=TRUE TOKEN_AUTH=OCI_TOKEN TOKEN_LOCATION="/home/oracle/.oci/db-token"

    Usage Notes for Entra ID

    The TOKEN_LOCATION parameter is mandatory for Azure token-based authentication. You must use this parameter along with the TOKEN_AUTH parameter to specify the directory location where the Entra ID OAuth2 access token is stored. This location is used by the database client to get the access token.

    If your token file is named token, then specify only the directory path. If the token file name is different from token, then you must use the file name along with the directory path.

    When an Azure user initiates a connection using /@connect_identifier, the database client retrieves the access token from the location specified by TOKEN_LOCATION and sends the token to the database server.

    Default Setting for Entra ID

    None

    Values and Examples for Entra ID

    Value Example

    If the token file is named token:

    TOKEN_LOCATION="token_file_directory"

    In the tnsnames.ora file:

    net_service_name= (DESCRIPTION= (ADDRESS=(PROTOCOL=tcps)(HOST=salesserver1)(PORT=1522)) (SECURITY= (TLS_SERVER_DN_MATCH=TRUE) (TLS_SERVER_CERT_DN="C=US,O=example,CN=OracleContext") (TOKEN_AUTH=OAUTH)(TOKEN_LOCATION="/home/dbuser1/access-token")) (CONNECT_DATA=(SERVICE_NAME=sales.us.example.com)) ) 

    In the sqlnet.ora file:

    TLS_SERVER_DN_MATCH=TRUE TOKEN_AUTH=OAUTH  TOKEN_LOCATION="/home/dbuser1/access-token" 

    In these examples, the token file name is token. Thus, only the directory path (/home/dbuser1/access-token) is specified. The client automatically looks for the token file in the specified path and gets the access token.

    If the token file name is different from token:

    TOKEN_LOCATION="token_file_directory/token_filename"

    In the tnsnames.ora file:

    net_service_name= (DESCRIPTION= (ADDRESS=(PROTOCOL=tcps)(HOST=salesserver1)(PORT=1522)) (SECURITY= (TLS_SERVER_DN_MATCH=ON) (TLS_SERVER_CERT_DN="C=US,O=example,CN=OracleContext") (TOKEN_AUTH=OAUTH) (TOKEN_LOCATION="/home/dbuser1/access-token/mytoken")) (CONNECT_DATA=(SERVICE_NAME=sales.us.example.com)) ) 

    In the sqlnet.ora file:

    TLS_SERVER_DN_MATCH=TRUE TOKEN_AUTH=OAUTH  TOKEN_LOCATION="/home/dbuser1/access-token/mytoken" 

    In these examples, the token file name is mytoken. Thus, both the file name and directory path (/home/dbuser1/access-token) are specified. The client gets the access token from the mytoken file in the specified path.

    Related Topics

    USE_CMAN

    Use the sqlnet.ora parameter USE_CMAN to specify client routing to Oracle Connection Manager.

    Purpose

    To specify client routing to Oracle Connection Manager.

    Usage Notes

    When set to true, the parameter routes the client to a protocol address for Oracle Connection Manager.

    When set to false, the client picks one of the address lists at random and fails over to the other address list if the chosen ADDRESS_LIST fails. With USE_CMAN=true, the client always uses the first address list.

    If no Oracle Connection Manager addresses are available, then connections are routed through any available listener address.

    Default

    false

    Values

    true | false

    Example

    USE_CMAN=true

    USE_DEDICATED_SERVER

    Use the sqlnet.ora parameter USE_DEDICATED_SERVER to append (SERVER=dedicated) to the CONNECT_DATA section of the connect descriptor that the client uses.

    Purpose

    To append (SERVER=dedicated) to the CONNECT_DATA section of the connect descriptor used by the client.

    Usage Notes

    The value for this parameter overrides the current value of the SERVER parameter in the tnsnames.ora file.

    When set to on, the parameter USE_DEDICATED_SERVER automatically appends (SERVER=dedicated) to the connect data for a connect descriptor. This enables connections from this client use a dedicated server process, even if shared server is configured.

    Default

    off

    Values

    Example

    USE_DEDICATED_SERVER=on

    Related Topics

    USE_SNI

    Use the sqlnet.ora parameter USE_SNI to enable setting Server Name Indication (SNI) value using CONNECT_DATA parameters.

    Purpose

    To enable or disable setting of SNI value using CONNECT_DATA parameters for TLS connections.

    Usage Notes

    When USE_SNI is set and CONNECT_DATA in the connect string has any of the supported parameters for SNI, then those parameters are used to set the SNI value. This SNI value is then used by the listener to select the appropriate service handler for servicing the request without having to do a TLS handshake with the client. The supported CONNECT_DATA parameters for setting SNI include SERVICE_NAME, INSTANCE_NAME, SERVER and COLOCATION_TAG.

    When USE_SNI is set and CONNECT_DATA doesn’t include any of the supported parameters listed above, then SNI value will not be set and the listener will perform the usual TLS handshake with the client to fetch the connect request.

    Values

    Default Value

    OFF

    Example

    USE_SNI=ON

    Note: Support for SNI is available in all versions starting 23.7, but not in earlier versions.

    Related Topics

    WALLET_LOCATION

    Use the WALLET_LOCATION parameter to specify the location of Oracle wallets.

    Purpose

    To specify the directory path where you want to create and store an Oracle wallet. Wallets securely contain certificates, secrets, private keys, and trust points used by Oracle Database.

    Usage Notes

    Additional Parameters

    Use SOURCE to specify the type of storage and storage location for wallets, as follows:

    Syntax and Examples

    The syntax depends on the wallet as follows:

    Default

    None

    Related Topics

    ADR Diagnostic Parameters in sqlnet.ora

    Diagnostic data for critical errors is stored in the sqlnet.ora Automatic Diagnostic Repository (ADR).

    About ADR Diagnostic Parameters

    You can use Automatic Diagnostic Repository (ADR) diagnostic parameters when ADR is enabled, which is the default. Oracle ignores non-ADR parameters in the sqlnet.ora file when you enable ADR.

    Since Oracle Database 11g, Oracle Database includes an advanced fault diagnostic infrastructure to prevent, detect, diagnose, and resolve problems. The problems might be critical errors such as those that are caused by database code bugs, metadata corruption, or customer data corruption.

    When critical errors occur, they are assigned incident numbers. Diagnostic data for the errors, such as traces and dumps, are captured and tagged with the incident number. The data is then stored in ADR, which is a file-based repository outside the database.

    The following sqlnet.ora parameters are used when you enable ADR (when DIAG_ADR_ENABLED is set to on):

    ADR_BASE

    Use the sqlnet.ora parameter ADR_BASE to specify the base location of the ADR files.

    Purpose

    To specify the base directory in which Oracle stores tracing and logging incidents when ADR is enabled.

    Usage Notes

    This parameter is applicable only to clients. On the server side, the ADR base location is defined by the DIAGNOSTIC_DEST initialization parameter in the init.ora file. See DIAGNOSTIC_DEST in Oracle Database Reference.

    Default

    ORACLE_BASE or ORACLE_HOME/log (if ORACLE_BASE is not defined)

    Values

    Any valid directory path to a directory with write permission.

    Example

    ADR_BASE=/oracle/network/trace

    DIAG_ADR_ENABLED

    Use the sqlnet.ora parameter DIAG_ADR_ENABLED to enable and disable ADR tracing.

    Purpose

    To specify whether ADR tracing is enabled.

    Usage Notes

    If you set the DIAG_ADR_ENABLED parameter to OFF, then non-ADR file tracing is used.

    Default

    on

    Values

    on | off

    Example 5-7 Example

    DIAG_ADR_ENABLED=on

    ENABLE_CONCISE_LOGS

    Use the sqlnet.ora parameter ENABLE_CONCISE_LOGS to enable or disable the logging in a concise format.

    Purpose

    To control how you want to view error stack messages in Oracle Network logs (sqlnet.log files), either in a concise or long format.

    Usage Notes

    When set to TRUE, the logs are printed in a concise format. A concise format displays all the relevant information of a failure in a single line. This setting reduces the size of the log files and makes them easier to read.

    When set to FALSE, the logs are printed in a longer, detailed format. A long format displays the messages in multiple lines, with additional details such as Version information.

    Values

    TRUE | FALSE

    Default

    TRUE

    Example

    ENABLE_CONCISE_LOGS=TRUE

    Related Topics

    LOG_SUPPRESSED_COUNT

    Use the sqlnet.ora parameter LOG_SUPPRESSED_COUNT to control the suppression of a log message based on the number of occurrences.

    Purpose

    To suppress an Oracle Network log message based on the specified number of occurrences on the database server.

    You can suppress repeated or duplicate records so that they no longer appear in any log. This can save some disk space and allow ease of navigation through large amounts of data.

    Note: You can set this parameter only on the database server side.

    Usage Notes

    Value

    Number of times (starting from the first occurrence) after which you want logging to be suppressed

    Allowed Range

    Any number greater than the minimum value of 1 up to 4294967295

    Default

    50

    Example

    LOG_SUPPRESSED_COUNT=100

    Related Topics

    LOG_SUPPRESSED_TIME

    Use the sqlnet.ora parameter LOG_SUPPRESSED_TIME to control the suppression of a log message based on the time interval.

    Purpose

    To suppress an Oracle Network log message based on the specified time interval.

    You can suppress repeated or duplicate records so that they no longer appear in any log. This can save some disk space and allow ease of navigation through large amounts of data.

    Note: You can set this parameter only on the database server side.

    Usage Notes

    Value

    Time interval in seconds (starting from the first occurrence) after which you want logging to be suppressed

    Allowed Range

    Any number greater than the minimum value of 1 up to 4294967295

    Default

    10

    Example

    LOG_SUPPRESSED_TIME=20

    Related Topics

    TRACE_LEVEL_CLIENT

    Use the sqlnet.ora parameter TRACE_LEVEL_CLIENT to enable and disable client tracing at a specific level.

    Purpose

    To enable client tracing at a specified level or to disable it.

    Usage Notes

    This parameter is also applicable when non-ADR tracing is used.

    Default

    off or 0

    Values

    Example

    TRACE_LEVEL_CLIENT=user

    TRACE_LEVEL_SERVER

    Use the sqlnet.ora parameter TRACE_LEVEL_SERVER to enable and disable server tracing at a specific level.

    Purpose

    To turn server tracing on at a specified level or to turn it off.

    Usage Notes

    This parameter is also applicable when non-ADR tracing is used.

    Default

    off or 0

    Values

    Example

    TRACE_LEVEL_SERVER=admin

    TRACE_TIMESTAMP_CLIENT

    Use the sqlnet.ora parameter TRACE_TIMESTAMP_CLIENT to add time stamps to trace events in client trace files.

    Purpose

    To add a time stamp in the form of dd-mmm-yyyy hh:mm:ss:mil to every trace event in the client trace file, which has a default name of sqlnet.trc.

    Usage Notes

    This parameter is also applicable when non-ADR tracing is used.

    Default

    on

    Values

    on or true | off or false

    Example

    TRACE_TIMESTAMP_CLIENT=true

    TRACE_TIMESTAMP_SERVER

    Use the sqlnet.ora parameter TRACE_TIMESTAMP_CLIENT to add time stamps to trace events in database trace files.

    Purpose

    To add a time stamp in the form of dd-mmm-yyyy hh:mm:ss:mil to every trace event in the database server trace file, which has a default name of svr_pid.trc.

    Usage Notes

    This parameter is also applicable when non-ADR tracing is used.

    Default

    on

    Values

    on or true | off or false

    Example

    TRACE_TIMESTAMP_SERVER=true

    Non-ADR Diagnostic Parameters in sqlnet.ora Files

    Learn about sqlnet.ora parameters that you use when you disable ADR.

    This section lists the sqlnet.ora parameters that are used when you disable ADR.

    Note: The default value of DIAG_ADR_ENABLED is on. Therefore, the DIAG_ADR_ENABLED parameter must explicitly be set to off to use non-ADR tracing.

    LOG_DIRECTORY_CLIENT

    Use the sqlnet.ora non-ADR diagnostic parameter LOG_DIRECTORY_CLIENT to specify the destination directory for client log files.

    Purpose

    To specify the destination directory for the client log file. By default, the log file is created in the current working directory.

    Usage Notes

    Use this parameter when ADR is not enabled.

    Values

    Any valid directory path.

    Example

    LOG_DIRECTORY_CLIENT=/oracle/network/log

    LOG_DIRECTORY_SERVER

    Use the non-ADR diagnostic sqlnet.ora parameter LOG_DIRECTORY_SERVER to specify the destination directory for database log files.

    Purpose

    To specify the destination directory for database log files.

    Usage Notes

    Use this parameter when ADR is not enabled.

    Default

    ORACLE_HOME/network/trace

    Values

    Any valid directory path to a directory with write permission.

    Example

    LOG_DIRECTORY_SERVER=/oracle/network/trace

    LOG_FILE_CLIENT

    Use the non-ADR diagnostic sqlnet.ora parameter LOG_FILE_CLIENT to specify the name of log files for clients.

    Purpose

    To specify the name of the log file for the client.

    Usage Notes

    Use this parameter when ADR is not enabled.

    Default

    ORACLE_HOME/network/log/sqlnet.log

    Values

    The default value cannot be changed.

    LOG_FILE_SERVER

    Use the non-ADR diagnostic sqlnet.ora parameter LOG_FILE_SERVER to specify log file names for the database.

    Purpose

    To specify the name of the log file for the database.

    Usage Notes

    Use this parameter when ADR is not enabled.

    Default

    sqlnet.log

    Values

    Example

    LOG_FILE_SERVER=svr.log

    TRACE_DIRECTORY_CLIENT

    Use the non-ADR diagnostic sqlnet.ora parameter TRACE_DIRECTORY_CLIENT to specify the destination directory for client trace files.

    Purpose

    To specify the destination directory for the client trace file. By default, the trace file is created in the current working directory.

    Usage Notes

    Use this parameter when ADR is not enabled.

    Values

    Any valid directory path to a directory with write permission.

    Example

    TRACE_DIRECTORY_CLIENT=/oracle/traces

    TRACE_DIRECTORY_SERVER

    Use the non-ADR diagnostic sqlnet.ora parameter TRACE_DIRECTORY_SERVER to specify the destination directory for database trace files.

    Purpose

    To specify the destination directory for the database server trace file. Use this parameter when ADR is not enabled.

    Default

     ORACLE_HOME/network/trace

    Values

    Any valid directory path to a directory with write permission.

    Example

    TRACE_DIRECTORY_SERVER=/oracle/traces

    TRACE_FILE_CLIENT

    Use the non-ADR diagnostic sqlnet.ora parameter TRACE_FILE_CLIENT to specify the names of client trace files.

    Purpose

    To specify the name of a client trace file.

    Usage Notes

    Use this parameter when ADR is not enabled.

    Default

    ORACLE_HOME/network/trace/cli.trc

    Values

    Any valid file name.

    Example

    TRACE_FILE_CLIENT=clientsqlnet.trc

    TRACE_FILE_SERVER

    Use the non-ADR diagnostic sqlnet.ora parameter TRACE_FILE_SERVER to specify the destination directory for database trace output.

    Purpose

    To specify the destination directory for the database server trace output.

    Usage Notes

    Use this parameter when ADR is not enabled.

    Default

    ORACLE_HOME/network/trace/svr_pid.trc

    Values

    Any valid file name. The process identifier (pid) is appended to the name automatically.

    Example

    TRACE_FILE_SERVER=svrsqlnet.trc

    TRACE_FILEAGE_CLIENT

    Use the non-ADR diagnostic sqlnet.ora parameter TRACE_FILEAGE_CLIENT to specify the maximum age of client trace files in minutes.

    Purpose

    To specify the maximum age of client trace files in minutes.

    Usage Notes

    When the age limit is reached, the trace information is written to the next file. The number of files is specified with the TRACE_FILENO_CLIENT parameter. Use this parameter when ADR is not enabled.

    Default

    Unlimited

    This is the same as setting the parameter to 0.

    Example 5-8 Example

    TRACE_FILEAGE_CLIENT=60

    TRACE_FILEAGE_SERVER

    Use the non-ADR diagnostic sqlnet.ora parameter TRACE_FILEAGE_SERVER to specify the maximum age of database trace files in minutes.

    Purpose

    To specify the maximum age of database server trace files in minutes.

    Usage Notes

    When the age limit is reached, the trace information is written to the next file. The number of files is specified with the TRACE_FILENO_SERVER parameter. Use this parameter when ADR is not enabled.

    Default

    Unlimited

    This is the same as setting the parameter to 0.

    Example 5-9 Example

    TRACE_FILEAGE_SERVER=60

    TRACE_FILELEN_CLIENT

    Use the non-ADR diagnostic sqlnet.ora parameter TRACE_FILELEN_CLIENT to specify the size of client trace files in kilobytes.

    Purpose

    When the file grows to the specified size, Oracle writes the trace information to the next file. The number of files is specified with the TRACE_FILENO_CLIENT parameter. Use this parameter when ADR is not enabled.

    To specify the size of the client trace files in kilobytes (KB).

    Usage Notes

    Example

    TRACE_FILELEN_CLIENT=100

    TRACE_FILELEN_SERVER

    Use the non-ADR diagnostic sqlnet.ora parameter TRACE_FILELEN_SERVER to specify the size of database trace files in kilobytes.

    Purpose

    To specify the size of the database server trace files in kilobytes (KB).

    Usage Notes

    When the file grows to the specified size, Oracle writes the trace information to the next file. The number of files is specified with the TRACE_FILENO_SERVER parameter. Use this parameter when ADR is not enabled.

    Example

    TRACE_FILELEN_SERVER=100

    TRACE_FILENO_CLIENT

    Use the non-ADR diagnostic sqlnet.ora parameter TRACE_FILENO_CLIENT to specify the number of trace files for client tracing.

    Purpose

    To specify the number of trace files for client tracing.

    Usage Notes

    When this parameter is set with the TRACE_FILELEN_CLIENT parameter, trace files are used in a cyclical fashion. The first file is filled first, then the second file, and so on. When the last file has been filled, then the first file is re-used, and so on.

    When this parameter is set with theTRACE_FILEAGE_CLIENT parameter, trace files are cycled based on their age. The first file is used until the age limit is reached, then the second file is used, and so on. When the last file’s age limit is reached, the first file is re-used.

    When you set this parameter with both the TRACE_FILELEN_CLIENT and TRACE_FILEAGE_CLIENT parameters, trace files are replaced when either the size limit or the age limit is reached.

    The trace file names are distinguished from one another by their sequence numbers. For example, if the default trace file of sqlnet.trc is used, and this parameter is set to 3, then the trace files would be named sqlnet1.trc, sqlnet2.trc and sqlnet3.trc.

    In addition, trace events in the trace files are preceded by the sequence number of the file. Use this parameter when ADR is not enabled.

    Default

    None

    Example

    TRACE_FILENO_CLIENT=3

    TRACE_FILENO_SERVER

    Use the non-ADR diagnostic sqlnet.ora parameter TRACE_FILENO_SERVER to specify the number of trace files for database tracing.

    Purpose

    To specify the number of trace files for database server tracing.

    Usage Notes

    When you set this parameter with the TRACE_FILELEN_SERVER parameter, trace files are used in a cyclical fashion. The first file is filled first, then the second file, and so on. When the last file has been filled, then the first file is re-used.

    When you set this parameter with theTRACE_FILEAGE_SERVER parameter, trace files are cycled based on the age of the trace file. The first file is used until the age limit is reached, then the second file is used, and so on. When the last file’s age limit is reached, the first file is re-used.

    When this parameter is set with both the TRACE_FILELEN_SERVER and TRACE_FILEAGE_SERVER parameters, trace files are cycled when either the size limit or the age limit is reached.

    The trace file names are distinguished from one another by their sequence numbers. For example, if the default trace file of svr_pid.trc is used, and this parameter is set to 3, then the trace files would be named svr1_pid.trc, svr2_pid.trc and svr3_pid.trc.

    In addition, trace events in the trace files are preceded by the sequence number of the file. Use this parameter when ADR is not enabled.

    Default

    None

    Example

    TRACE_FILENO_SERVER=3

    TRACE_UNIQUE_CLIENT

    Use the non-ADR diagnostic sqlnet.ora parameter TRACE_UNIQUE_CLIENT to specify whether Oracle creates a unique trace file for each client trace session.

    Purpose

    To specify whether a unique trace file is created for each client trace session.

    Usage Notes

    When you set the value to on, a process identifier is appended to the name of each trace file, enabling several files to coexist. For example, trace files named sqlnetpid.trc are created if default trace file name sqlnet.trc is used. When you set the value to off, data from a new client trace session overwrites the existing file. Use this parameter when ADR is not enabled.

    Default

    on

    Values

    on or off

    Example

    TRACE_UNIQUE_CLIENT=on