{"id":875,"date":"2006-01-25T12:00:00","date_gmt":"2006-01-25T12:00:00","guid":{"rendered":"http:\/\/orcldoug.com\/blog\/?p=875"},"modified":"2006-01-25T12:00:00","modified_gmt":"2006-01-25T12:00:00","slug":"application-security","status":"publish","type":"post","link":"http:\/\/orcldoug.com\/blog\/2006\/01\/25\/application-security\/","title":{"rendered":"Application Security"},"content":{"rendered":"<p>Some conversations are a recurring experience of DBA life.<\/p>\n<blockquote><p>DBA [to software vendor] &#8211; &#8216;So why does the application schema owner need to have the DBA role privilege?&#8217;<\/p>\n<p>Vendor &#8211; &#8216;The installation procedure requires it&#8217;<\/p>\n<p>DBA &#8211; &#8216;So can we revoke it after the installation?&#8217;<\/p>\n<p>Vendor &#8211; &#8216;It hasn&#8217;t been tested so we couldn&#8217;t support it&#8217;<\/p>\n<p>DBA &#8211; &#8216;Could you test it to prove that it works?&#8217;<\/p>\n<p>Vendor &#8211; &#8216;That would be a change request and we&#8217;ll need time.&#8217;<\/p><\/blockquote>\n<p>Closely followed by :-<\/p>\n<blockquote><p>DBA &#8211; &#8216;We like to lock application schema owner accounts&#8217;<\/p>\n<p>Vendor &#8211; &#8216;The application servers need to connect to that account&#8217;<\/p>\n<p>DBA &#8211; &#8216;Couldn&#8217;t we create a separate login account and grant the privileges that are actually needed to that? That way there&#8217;s no risk of anyone dropping or modifying the application objects, except when the schema owner account is unlocked briefly under change control&#8217;<\/p>\n<p>Vendor &#8211; &#8216;It hasn&#8217;t been tested so we couldn&#8217;t support it&#8217;<\/p>\n<p>DBA &#8211; &#8216;Could you test it to prove that it works?&#8217;<\/p>\n<p>Vendor &#8211; &#8216;That would be a change request&#8217;<\/p>\n<p>DBA &#8211; &#8216;How about if we implement it in one of our test environment and prove to you that it will work.&#8217;<\/p>\n<p>Vendor &#8211; &#8216;We haven&#8217;t tested it so we couldn&#8217;t support it&#8217;<\/p><\/blockquote>\n<p>You&#8217;re on your own, basically.<\/p>\n<p>Of course, a poor security model; database independent (for which read, lowest common denominator) code; cobbled-together data model,  etc. etc. are never used as show-stoppers for business applications. The people who purchase them like the front-end interface, the functionality and the neat salesman with the neat demo. However, a word for the software vendors out there &#8211; when these applications turn up on a DBA&#8217;s lap, we sigh, maybe chuckle a bit, and then wonder how we&#8217;re going to make the best of a bad job while you laugh your way to the bank. Maybe it would be worth employing someone who has moved beyond the stage of knowing that Oracle is a database so you can use JDBC or ODBC to access it? You could even just employ them for a month or two at the start of the application design and development. It would save so much pain later on. For you, for your customers and for DBAs &#128521;<\/p>\n<p>&#8230; and people wonder why DBAs get angry sometimes?<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Some conversations are a recurring experience of DBA life. DBA [to software vendor] &#8211; &#8216;So why does the application schema owner need to have the DBA role privilege?&#8217; Vendor &#8211; &#8216;The installation procedure requires it&#8217; DBA &#8211; &#8216;So can we revoke it after the installation?&#8217; Vendor &#8211; &#8216;It hasn&#8217;t been tested so we couldn&#8217;t support&hellip; <a class=\"more-link\" href=\"http:\/\/orcldoug.com\/blog\/2006\/01\/25\/application-security\/\">Continue reading <span class=\"screen-reader-text\">Application Security<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-875","post","type-post","status-publish","format-standard","hentry","category-uncategorized","entry"],"jetpack_featured_media_url":"","jetpack-related-posts":[{"id":1063,"url":"http:\/\/orcldoug.com\/blog\/2006\/08\/21\/10g-default-installation-and-ofa\/","url_meta":{"origin":875,"position":0},"title":"10g Default Installation and OFA","date":"August 21, 2006","format":false,"excerpt":"or ... 'what's that all about?!?!'Last year, I blogged about some of the variations on Optimal Flexible Architecture that I've seen on my travels. I'm gradually coming round to having the service group for clustered applications as the top directory level (e.g.\/myapp1\/oradata\/\/myapp1\/oraindex\/\/myapp2\/oradata\/\/myapp2\/oraindex\/but I'm still not convinced. If people ever failed\u2026","rel":"","context":"With 7 comments","img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":1044,"url":"http:\/\/orcldoug.com\/blog\/2006\/08\/04\/tracing-session-activity-over-a-remote-database-link\/","url_meta":{"origin":875,"position":1},"title":"Tracing session activity over a remote database link","date":"August 4, 2006","format":false,"excerpt":"Yesterday someone asked me how to trace a session that selects from a view in a remote database via a link. If they activated the trace on the local instance, they wouldn't see the bulk of the work which was happening on the remote instance - just a bunch of\u2026","rel":"","context":"With 2 comments","img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":1028,"url":"http:\/\/orcldoug.com\/blog\/2006\/07\/20\/whats-a-development-dba\/","url_meta":{"origin":875,"position":2},"title":"What&#8217;s a &#8216;Development DBA&#8217;?","date":"July 20, 2006","format":false,"excerpt":"I theory, this should be a much more straightforward, less contentious question than my previous - 'What's a Data Warehouse DBA?'A development DBA looks after the development (and test) databases. It truly is as simple as that, but depends on the nature of the project you're working on and the\u2026","rel":"","context":"With 2 comments","img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":1042,"url":"http:\/\/orcldoug.com\/blog\/2006\/08\/04\/log-buffer-4\/","url_meta":{"origin":875,"position":3},"title":"Log Buffer #4","date":"August 4, 2006","format":false,"excerpt":"Welcome to the fourth edition of Log Buffer.Maybe it's the summer holiday season and DBA-land is a little quiet, but navel-gazing seems popular this week. During a conference keynote speech by Ray Lane I attended earlier this year, he highlighted how much the software industry likes to talk about itself\u2026","rel":"","context":"With 7 comments","img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":1030,"url":"http:\/\/orcldoug.com\/blog\/2006\/07\/21\/monitoring-index-usage\/","url_meta":{"origin":875,"position":4},"title":"Monitoring Index Usage","date":"July 21, 2006","format":false,"excerpt":"A common requirement cropped up this week. A new Data Warehouse has just gone live and is still in the 'do we have the right indexes here' phase. In this case, the suspicion is that there are too many indexes in a specific schema and that a number of them\u2026","rel":"","context":"With 8 comments","img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":1011,"url":"http:\/\/orcldoug.com\/blog\/2006\/07\/04\/whats-a-data-warehouse-dba\/","url_meta":{"origin":875,"position":5},"title":"What&#8217;s a &#8216;Data Warehouse DBA&#8217;?","date":"July 4, 2006","format":false,"excerpt":"I've seen that question asked often in forums and mail groups. It's easy to understand why there's so much confusion because, for most DBAs, if you've seen one database, you've seen them all. Or rather, you haven't seen any of them. What I mean is that every database that lands\u2026","rel":"","context":"With 14 comments","img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]}],"_links":{"self":[{"href":"http:\/\/orcldoug.com\/blog\/wp-json\/wp\/v2\/posts\/875","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/orcldoug.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/orcldoug.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/orcldoug.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/orcldoug.com\/blog\/wp-json\/wp\/v2\/comments?post=875"}],"version-history":[{"count":0,"href":"http:\/\/orcldoug.com\/blog\/wp-json\/wp\/v2\/posts\/875\/revisions"}],"wp:attachment":[{"href":"http:\/\/orcldoug.com\/blog\/wp-json\/wp\/v2\/media?parent=875"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/orcldoug.com\/blog\/wp-json\/wp\/v2\/categories?post=875"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/orcldoug.com\/blog\/wp-json\/wp\/v2\/tags?post=875"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}