Re: Is there some free way to encrypt Oracle network data in Windows

  • From: Steve Farmer <hts@xxxxxxxxxx>
  • To: bdbafh@xxxxxxxxx, Paula_Stankus@xxxxxxxxxxxxxxx
  • Date: Tue, 30 Aug 2005 19:43:21 +0100

Hi

Seems I was looking at an older version of oracle which included the encryption :(

Still ssl tunneling should work ...

Regards
Steve
At 2:22 PM -0400 30/8/05, Paul Drake wrote:
On 8/30/05, <mailto:Paula_Stankus@xxxxxxxxxxxxxxx>Paula_Stankus@xxxxxxxxxxxxxxx <<mailto:Paula_Stankus@xxxxxxxxxxxxxxx>Paula_Stankus@xxxxxxxxxxxxxxx> wrote:

I believe it requires the Advanced Security Option which I heard last
was $10K per cpu - just to encrypt the data between the database server
and the app on the network.



Paula,

There is alot more to "encryption" than just applying a key to a packet's payload to create cyphertext. Rather than have this get ugly, I'd suggest that you actually read up on this.

<http://download-west.oracle.com/docs/cd/B14117_01/network.101/b10772/toc.htm>http://download-west.oracle.com/docs/cd/B14117_01/network.101/b10772/toc.htm

There are concepts such as "authentication", "user rights", "data integrity", "key management" that need to be addressed as well as interoperability with vendors offerings.

I'm sure that an auditor would have a field day with a roll-your-own solution if the security of the data was truly important. I've worked around this in the past with a cross-over cable between app server and database server (network not reachable except via either host) and by putting the web/app/database server software on the same host and running everything on lo - neither of which scale particularly well.

hth.

Paul



-----Original Message-----
From: <mailto:oracle-l-bounce@xxxxxxxxxxxxx> oracle-l-bounce@xxxxxxxxxxxxx
[mailto:<mailto:oracle-l-bounce@xxxxxxxxxxxxx>oracle-l-bounce@xxxxxxxxxxxxx] On Behalf Of Steve Farmer
Sent: Tuesday, August 30, 2005 11:13 AM
To: <mailto:oracle-l@xxxxxxxxxxxxx> oracle-l@xxxxxxxxxxxxx
Subject: RE: Is there some free way to encrypt Oracle network data in
Windows


Hi

SqlNet supports encryption

Regards
Steve
I think that you can set that at listener level. Not sure.

Regards
GBA

-----Mensaje original-----
De: <mailto:oracle-l-bounce@xxxxxxxxxxxxx>oracle-l-bounce@xxxxxxxxxxxxx
[mailto:<mailto:oracle-l-bounce@xxxxxxxxxxxxx> oracle-l-bounce@xxxxxxxxxxxxx] En nombre de Juan Carlos Reyes
Pacheco Enviado el: Martes, 30 de Agosto de 2005 09:20
Para: <mailto:oracle-l@xxxxxxxxxxxxx>oracle-l@xxxxxxxxxxxxx
Asunto: Is there some free way to encrypt Oracle network data in
Windows


Hi, please
Is there some free way to encrypt Oracle network data transmission in
Windows?
For example to avoid some person capture network data and found the
role passwords.

Thank you
--
Oracle Certified Profesional 9i 10g
Orace Certified Professional Developer 6i

8 years of experience in Oracle 7,8i,9i,10g and developer 6i
--

<//www.freelists.org/webpage/oracle-l>//www.freelists.org/webpage/oracle-l


-- <//www.freelists.org/webpage/oracle-l>//www.freelists.org/webpage/oracle-l


--
-------------------------------------------------
Nearly all men can stand adversity, but if you want to test a man's
character, give him power.
-Abraham Lincoln, U.S. president (1809-1865) Support free speech; visit
<http://www.efa.org.au/>http://www.efa.org.au/

Heads Together Software Pty Ltd <http://www.hts.com.au>http://www.hts.com.au
Email: <mailto:hts@xxxxxxxxxx>hts@xxxxxxxxxx      Tel: +44 7985 602 102
--
<//www.freelists.org/webpage/oracle-l>//www.freelists.org/webpage/oracle-l


-- BEGIN-ANTISPAM-VOTING-LINKS ------------------------------------------------------ Teach CanIt if this mail (ID 42895320) is spam: Spam: <https://dohsmsi01.doh.state.fl.us/canit/b.php?c=s&i=42895320&m=15dce5060>https://dohsmsi01.doh.state.fl.us/canit/b.php?c=s&i=42895320&m=15dce5060 342 Not spam: <https://dohsmsi01.doh.state.fl.us/canit/b.php?c=n&i=42895320&m=15dce5060>https://dohsmsi01.doh.state.fl.us/canit/b.php?c=n&i=42895320&m=15dce5060 342 Forget vote: <https://dohsmsi01.doh.state.fl.us/canit/b.php?c=f&i=42895320&m=15dce5060>https://dohsmsi01.doh.state.fl.us/canit/b.php?c=f&i=42895320&m=15dce5060 342 ------------------------------------------------------ END-ANTISPAM-VOTING-LINKS

--
<//www.freelists.org/webpage/oracle-l>//www.freelists.org/webpage/oracle-l




-- #/etc/init.d/init.cssd stop # f=ma, divide by 1, convert to moles.


--
-------------------------------------------------
Nearly all men can stand adversity, but if you want to test a man's character, give him power.
-Abraham Lincoln, U.S. president (1809-1865)
Support free speech; visit http://www.efa.org.au/


Heads Together Software Pty Ltd http://www.hts.com.au Email: hts@xxxxxxxxxx Tel: +44 7985 602 102

Other related posts: