2.1.2 Ensure 'ACCEPT_MD5_CERTS' Is Configured Correctly

Information

The setting ACCEPT_MD5_CERTS specifies whether Oracle accepts certificates signed with the MD5 algorithm.

Note: See Additional Information regarding the deprecation of this setting.

Weak algorithms such as MD5 and SHA1 have known vulnerabilities that make them susceptible to attacks. Allowing their use can compromise data integrity and authentication, potentially exposing systems to risks. Transitioning to stronger algorithms, such as SHA-2, is recommended.

Solution

To remediate this recommendation, remove ACCEPT_MD5_CERTS from sqlnet.ora or set ACCEPT_MD5_CERTS to the value FALSE

In addition to listener.ora this parameter must also be set in sqlnet.ora

Impact:

Applications that use MD5-signed certificates must be updated to use certificates signed with a stronger, more secure algorithm such as SHA-2.

See Also

https://workbench.cisecurity.org/benchmarks/16474

Item Details

Category: ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-17(2), 800-53|IA-5, 800-53|IA-5(1), 800-53|SC-8, 800-53|SC-8(1), CSCv7|14.4

Plugin: Unix

Control ID: 0e4b3e8e9b0b65d77089328cff5c1bead0009e0f7cb44dca922b1fbeda67008e