设置 Oracle 监听器密码(LISTENER)

--==================================
-- 设置 Oracle 监听器密码(LISTENER)
--==================================


    监听器也有安全?Sure!在缺省的情况下,任意用户不需要使用任何密码即通过lsnrctl 工具对Oracle Listener进行操作或关闭,从
而造成任意新的会话都将无法建立连接。在Oracle 9i 中Oracle监听器允许任何一个人利用lsnrctl从远程发起对监听器的管理。也容易导致数
据库受到损坏。

1. 未设定密码情形下停止监听       
  1. [oracle@test ~]$ lsnrctl stop listener_demo92   -->停止监听,可以看出不需要任何密码即可停止  
  2.                                                                                              
  3. LSNRCTL for Linux: Version 9.2.0.8.0 - Production on 26-JUN-2011 08:22:26                    
  4.                                                                                              
  5. Copyright (c) 1991, 2006, Oracle Corporation.  All rights reserved.                          
  6.                                                                                              
  7. Connecting to (DESCRIPTION=(ADDRESS=(PROTOCOL=TCP)(HOST=test)(PORT=1521)))                   
  8. The command completed successfully                                                           
[oracle@test ~]$ lsnrctl stop listener_demo92   -->停止监听,可以看出不需要任何密码即可停止 
                                                                                            
LSNRCTL for Linux: Version 9.2.0.8.0 - Production on 26-JUN-2011 08:22:26                   
                                                                                            
Copyright (c) 1991, 2006, Oracle Corporation.  All rights reserved.                         
                                                                                            
Connecting to (DESCRIPTION=(ADDRESS=(PROTOCOL=TCP)(HOST=test)(PORT=1521)))                  
The command completed successfully                                                          
2. 重新启动监听并设置密码
  1. [oracle@test ~]$ lsnrctl                                                                                                   
  2.                                                                                                                            
  3. LSNRCTL for Linux: Version 9.2.0.8.0 - Production on 26-JUN-2011 08:24:09                                                  
  4. Copyright (c) 1991, 2006, Oracle Corporation.  All rights reserved.                                                        
  5.                                                                                                                            
  6. Welcome to LSNRCTL, type "help" for information.                                                                             
  7. LSNRCTL> set current_listener listener_demo92  -->设置当前监听器                                                           
  8. Current Listener is listener_demo92                                                                                        
  9. LSNRCTL> start             -->启动过程也不需要任何密码,启动的详细信息省略                                                  
  10. LSNRCTL> change_password   -->使用change_password来设置密码                                                                
  11. Old password:                                                                                                              
  12. New password:                                                                                                              
  13. Reenter new password:                                                                                                      
  14. Connecting to (DESCRIPTION=(ADDRESS=(PROTOCOL=TCP)(HOST=test)(PORT=1521)))                                                 
  15. Password changed for listener_demo92                                                                                       
  16. The command completed successfully                                                                                         
  17. LSNRCTL> save_config        -->注意此处的save_config失败                                                                   
  18. Connecting to (DESCRIPTION=(ADDRESS=(PROTOCOL=TCP)(HOST=test)(PORT=1521)))                                                 
  19. TNS-01169: The listener has not recognized the password                                                                    
  20. LSNRCTL> set password       -->输入新设定的密码验证                                                                        
  21. Password:                                                                                                                  
  22. The command completed successfully                                                                                         
  23. LSNRCTL> save_config       -->再次save_config成功                                                                          
  24. Connecting to (DESCRIPTION=(ADDRESS=(PROTOCOL=TCP)(HOST=test)(PORT=1521)))                                                 
  25. Saved listener_demo92 configuration parameters.                                                                            
  26. Listener Parameter File   /oracle/92/network/admin/listener.ora                                                            
  27. Old Parameter File   /oracle/92/network/admin/listener.bak                                                                 
  28. The command completed successfully                                                                                         
  29.                                                                                                                            
  30. -->增加密码之后可以看到listener.ora文件中有一条新增的记录,即密码选项(注:尽管使用了密码管理方式,仍然可以无需密码启动监听) 
  31. [oracle@test admin]$ more listener.ora                                                                                     
  32.     #----ADDED BY TNSLSNR 26-JUN-2011 05:12:48---                                                                            
  33.     PASSWORDS_listener_demo92 =                                                                                              
  34.     #--------------------------------------------                                                                            
[oracle@test ~]$ lsnrctl                                                                                                  
                                                                                                                          
LSNRCTL for Linux: Version 9.2.0.8.0 - Production on 26-JUN-2011 08:24:09                                                 
Copyright (c) 1991, 2006, Oracle Corporation.  All rights reserved.                                                       
                                                                                                                          
Welcome to LSNRCTL, type "help" for information.	                                                                        
LSNRCTL> set current_listener listener_demo92  -->设置当前监听器                                                          
Current Listener is listener_demo92                                                                                       
LSNRCTL> start             -->启动过程也不需要任何密码,启动的详细信息省略                                                 
LSNRCTL> change_password   -->使用change_password来设置密码                                                               
Old password:                                                                                                             
New password:                                                                                                             
Reenter new password:                                                                                                     
Connecting to (DESCRIPTION=(ADDRESS=(PROTOCOL=TCP)(HOST=test)(PORT=1521)))                                                
Password changed for listener_demo92                                                                                      
The command completed successfully                                                                                        
LSNRCTL> save_config        -->注意此处的save_config失败                                                                  
Connecting to (DESCRIPTION=(ADDRESS=(PROTOCOL=TCP)(HOST=test)(PORT=1521)))                                                
TNS-01169: The listener has not recognized the password                                                                   
LSNRCTL> set password       -->输入新设定的密码验证                                                                       
Password:                                                                                                                 
The command completed successfully                                                                                        
LSNRCTL> save_config       -->再次save_config成功                                                                         
Connecting to (DESCRIPTION=(ADDRESS=(PROTOCOL=TCP)(HOST=test)(PORT=1521)))                                                
Saved listener_demo92 configuration parameters.                                                                           
Listener Parameter File   /oracle/92/network/admin/listener.ora                                                           
Old Parameter File   /oracle/92/network/admin/listener.bak                                                                
The command completed successfully                                                                                        
                                                                                                                          
-->增加密码之后可以看到listener.ora文件中有一条新增的记录,即密码选项(注:尽管使用了密码管理方式,仍然可以无需密码启动监听)
[oracle@test admin]$ more listener.ora                                                                                    
	#----ADDED BY TNSLSNR 26-JUN-2011 05:12:48---                                                                           
	PASSWORDS_listener_demo92 =                                                                                             
	#--------------------------------------------                                                                           
3. 尝试未使用密码的情况下停止监听 
  1. [oracle@test ~]$ lsnrctl stop listener_demo92                                                
  2. LSNRCTL for Linux: Version 9.2.0.8.0 - Production on 26-JUN-2011 06:09:51                    
  3. Copyright (c) 1991, 2006, Oracle Corporation.  All rights reserved.                          
  4.                                                                                              
  5. Connecting to (DESCRIPTION=(ADDRESS=(PROTOCOL=TCP)(HOST=test)(PORT=1521)))                   
  6. TNS-01169: The listener has not recognized the password    -->收到错误信息,需要使用密码认证 
[oracle@test ~]$ lsnrctl stop listener_demo92                                               
LSNRCTL for Linux: Version 9.2.0.8.0 - Production on 26-JUN-2011 06:09:51                   
Copyright (c) 1991, 2006, Oracle Corporation.  All rights reserved.                         
                                                                                            
Connecting to (DESCRIPTION=(ADDRESS=(PROTOCOL=TCP)(HOST=test)(PORT=1521)))                  
TNS-01169: The listener has not recognized the password    -->收到错误信息,需要使用密码认证
4. 使用密码来停止监听  
  1. [oracle@test ~]$ lsnrctl                                                        
  2. LSNRCTL> set current_listener listener_demo92                                   
  3. Current Listener is listener_demo92                                             
  4. LSNRCTL> stop                                                                   
  5. Connecting to (DESCRIPTION=(ADDRESS=(PROTOCOL=TCP)(HOST=test)(PORT=1521)))      
  6. TNS-01169: The listener has not recognized the password                         
  7. LSNRCTL> set password                                                           
  8. Password:                                                                       
  9. The command completed successfully                                              
  10. LSNRCTL> stop                                                                   
  11. Connecting to (DESCRIPTION=(ADDRESS=(PROTOCOL=TCP)(HOST=test)(PORT=1521)))      
  12. The command completed successfully                                              
  13. LSNRCTL> status                                                                 
  14. Connecting to (DESCRIPTION=(ADDRESS=(PROTOCOL=TCP)(HOST=test)(PORT=1521)))      
  15. TNS-12541: TNS:no listener                                                      
  16. TNS-12560: TNS:protocol adapter error                                          
  17.   TNS-00511: No listener                                                        
  18.    Linux Error: 111: Connection refused                                         
  19. Connecting to (DESCRIPTION=(ADDRESS=(PROTOCOL=IPC)(KEY=EXTPROC)))               
  20. TNS-12541: TNS:no listener                                                      
  21. TNS-12560: TNS:protocol adapter error                                          
  22.   TNS-00511: No listener                                                        
  23.    Linux Error: 2: No such file or directory                                      
[oracle@test ~]$ lsnrctl                                                       
LSNRCTL> set current_listener listener_demo92                                  
Current Listener is listener_demo92                                            
LSNRCTL> stop                                                                  
Connecting to (DESCRIPTION=(ADDRESS=(PROTOCOL=TCP)(HOST=test)(PORT=1521)))     
TNS-01169: The listener has not recognized the password                        
LSNRCTL> set password                                                          
Password:                                                                      
The command completed successfully                                             
LSNRCTL> stop                                                                  
Connecting to (DESCRIPTION=(ADDRESS=(PROTOCOL=TCP)(HOST=test)(PORT=1521)))     
The command completed successfully                                             
LSNRCTL> status                                                                
Connecting to (DESCRIPTION=(ADDRESS=(PROTOCOL=TCP)(HOST=test)(PORT=1521)))     
TNS-12541: TNS:no listener                                                     
 TNS-12560: TNS:protocol adapter error                                         
  TNS-00511: No listener                                                       
   Linux Error: 111: Connection refused                                        
Connecting to (DESCRIPTION=(ADDRESS=(PROTOCOL=IPC)(KEY=EXTPROC)))              
TNS-12541: TNS:no listener                                                     
 TNS-12560: TNS:protocol adapter error                                         
  TNS-00511: No listener                                                       
   Linux Error: 2: No such file or directory	                                 
5. save_config失败的问题   
  1. -->在 Oracle 9i中,使用save_config命令将会失败                                                                          
  2.     LSNRCTL> save_config                                                                                                  
  3.     Connecting to (DESCRIPTION=(ADDRESS=(PROTOCOL=TCP)(HOST=<hostname>)(PORT=<port>)))                                    
  4.     TNS-01169: The listener has not recognized the password                                                               
  5.                                                                                                                         
  6. -->应该先使用set password之后再save_config,则保存配置成功。                                                            
  7.     LSNRCTL> set password                                                                                                 
  8.     Password: <the password you chose>                                                                                    
  9.     The command completed successfully                                                                                    
  10.                                                                                                                           
  11. /*在Oracle 10g 中不会出现类似的问题,因为在10g中可以使用基于操作系统验证方式。listener将检测到如果用户属于dba组的成员, 
  12. 将会被授予改变密码,保存配置以及停止监听等权限。 */                                                                     
-->在 Oracle 9i中,使用save_config命令将会失败                                                                         
	LSNRCTL> save_config                                                                                                 
	Connecting to (DESCRIPTION=(ADDRESS=(PROTOCOL=TCP)(HOST=<hostname>)(PORT=<port>)))                                   
	TNS-01169: The listener has not recognized the password	                                                             
                                                                                                                       
-->应该先使用set password之后再save_config,则保存配置成功。                                                           
	LSNRCTL> set password                                                                                                
	Password: <the password you chose>                                                                                   
	The command completed successfully                                                                                   
	                                                                                                                     
/*在Oracle 10g 中不会出现类似的问题,因为在10g中可以使用基于操作系统验证方式。listener将检测到如果用户属于dba组的成员,
将会被授予改变密码,保存配置以及停止监听等权限。 */                                                                    
6.  配置listener.ora中ADMIN_RESTRICTIONS参数
    参数作用:
        当在listener.ora文件中设置了ADMIN_RESTRICTIONS参数后,在监听器运行时,不允许执行任何管理命令,同时set命令将不可用
        ,不论是在服务器本地还是从远程执行都不行。此时对于监听的设置仅仅通过手工修改listener.ora文件,要使修改生效,只能
        使用lsnrctl reload命令或lsnrctl stop/start命令重新载入一次监听器配置信息。
    修改方法:
        在listener.ora文件中手动加入下面这样一行

            ADMIN_RESTRICTIONS_<监听器名> = ON

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值