1.74 O19C-00-015400

Information

When using command-line tools such as Oracle SQL*Plus, which can accept a plain-text password, users must use an alternative logon method that does not expose the password.

GROUP ID: V-270568
RULE ID: SV-270568r1136925

The DOD standard for authentication is DOD-approved public key infrastructure (PKI) certificates.

Normally, with PKI authentication, the interaction with the user for authentication will be handled by a software component separate from the database management system (DBMS), such as ActivIdentity ActivClient. However, in cases where the DBMS controls the interaction, this requirement applies.

To prevent the compromise of authentication information such as passwords and PINs during the authentication process, the feedback from the system must not provide any information that would allow an unauthorized user to compromise the authentication mechanism.

Obfuscation of user-provided authentication secrets when typed into the system is a method used in addressing this risk.

Displaying asterisks when a user types in a password or a smart card PIN is an example of obscuring feedback of authentication secrets.

This requires reviewing applications, which will involve collaboration with the application developers. It is recognized that in many cases, the database administrator (DBA) is organizationally separate from the application developers, and may have limited, if any, access to source code. Nevertheless, protections of this type are so important to the secure operation of databases that they must not be ignored. At a minimum, the DBA must attempt to obtain assurances from the development organization that this issue has been addressed and must document what has been discovered.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

For Oracle SQL*Plus, which cannot be configured not to accept a plain-text password, and any other essential tool with the same limitation:

- Document the need for it, who uses it, and any relevant mitigations, and obtain AO approval.
- Train all users of the tool in the importance of not using the plain-text password option and how to keep the password hidden.

Consider wrapping the startup command with a shell or wrapper and using an Oracle external password store.

Oracle provides the capability to provide for a secure external password facility. Use the Oracle mkstore to create a secure storage area for passwords for applications, batch jobs, and scripts to use or deploy a site-authorized facility to perform this function.

Check to verify what has been stored in the Oracle External Password Store.

To view all contents of a client wallet external password store, check specific credentials by viewing them. Listing the external password store contents provides information used to decide whether to add or delete credentials from the store. To list the contents of the external password store, enter the following command at the command line:

$ mkstore -wrl wallet_location -listCredential

For example:

$ mkstore -wrl c:\\oracle\\product\\19.0.0\\db_1\\wallets -listCredential

The wallet_location specifies the path to the directory where the wallet, whose external password store contents is to be viewed, is located. This command lists all of the credential database service names (aliases) and the corresponding username (schema) for that database. Passwords are not listed.

Configuring Clients to Use the External Password Store

If the client is already configured to use external authentication, such as Windows native authentication or Transport Layer Security (TLS), then Oracle Database uses that authentication method. The same credentials used for this type of authentication are typically also used to log on to the database.

For clients not using such authentication methods or wanting to override them for database authentication, set the SQLNET.WALLET_OVERRIDE parameter in sqlnet.ora to TRUE . The default value for SQLNET.WALLET_OVERRIDE is FALSE, allowing standard use of authentication credentials as before.

If wanting a client to use the secure external password store feature, perform the following configuration task:

- Create a wallet on the client by using the following syntax at the command line: orapki create -wallet wallet_location -auto_login_local
```
For example:
```
orapki wallet create -wallet c:\\oracle\\product\\19.0.0\\db_1\\wallets -auto_login_local
Enter password: password
```
The `wallet_location` is the path to the directory where the wallet is to be created and stored. This command creates an Oracle wallet with the autologon feature enabled at the location specified. The autologon feature enables the client to access the wallet contents without supplying a password.

The `mkstore` utility `-create` option uses password complexity verification.

2. Create database connection credentials in the wallet by using the following syntax at the command line:
```
mkstore -wrl wallet_location -createCredential db_connect_string username
Enter password: password
```
For example:
```
mkstore -wrl c:\\oracle\\product\\19.0.0\\db_1\\wallets -createCredential oracle system
Enter password: password
```
In this specification:

The wallet_location is the path to the directory where the wallet was created. The `db_connect_string` used in the `CONNECT /@db_connect_string` statement must be identical to the `db_connect_string` specified in the `-createCredential` command.

The `db_connect_string` is the TNS alias used to specify the database in the `tnsnames.ora` file or any service name used to identify the database on an Oracle network. By default, `tnsnames.ora` is located in the `$ORACLE_HOME/network/admin` directory on Unix systems and in `ORACLE_HOME\\network\\admin` on Windows.

The username is the database logon credential. When prompted, enter the password for this user.

3. In the client `sqlnet.ora` file, enter the `WALLET_LOCATION` parameter and set it to the directory location of the wallet created in Step 1. For example, if the wallet was created in `$ORACLE_HOME/network/admin` and the Oracle home is set to `/private/ora12`, enter the following into the client `sqlnet.ora` file:
```
WALLET_LOCATION =
(SOURCE =
(METHOD = FILE)
(METHOD_DATA =
(DIRECTORY = /private/ora19/network/admin)
)
)
```
4. In the client `sqlnet.ora` file, enter the `SQLNET.WALLET_OVERRIDE` parameter and set it to `TRUE` as follows:
```
SQLNET.WALLET_OVERRIDE = TRUE
```
This setting causes all `CONNECT /@db_connect_string` statements to use the information in the wallet at the specified location to authenticate to databases.

When external authentication is in use, an authenticated user with such a wallet can use the `CONNECT /@db_connect_string` syntax to access the previously specified databases without providing a username and password. However, if a user fails that external authentication, these connect statements also fail.

Below is a sample `sqlnet.ora` file with the `WALLET_LOCATION` and the `SQLNET.WALLET_OVERRIDE` parameters set as described in Steps 3 and 4.

Below is a sample `SQLNET.ORA` File with wallet parameters set.

WALLET_LOCATION =(SOURCE =(METHOD = FILE)(METHOD_DATA =(DIRECTORY = /private/ora19/network/admin)))SQLNET.WALLET_OVERRIDE = TRUESSL_CLIENT_AUTHENTICATION = FALSESSL_VERSION = 1.1 or 1.2

Note: This assumes that a single sqlnet.ora file, in the default location, is in use. Refer to the following link if using a nondefault configuration: https://docs.oracle.com/en/database/oracle/oracle-database/19/netrf/parameters-for-the-sqlnet.ora.html.

See Also

https://workbench.cisecurity.org/benchmarks/26166