CERN Accelerating science

All Oracle database authentication change

 
Description: 

Due to an urgent security issue, we have to change the authentication method for all Oracle databases. This change is expected to be completely transparent, please contact Oracle.Support@cern.ch if you observe any change. All database services managed by IT-DB will receive the change.

Reason for this intervention: 

The change is required because of the serious vulnerability in some versions of the Oracle logon protocol which enables a brute force attack on passwords (Oracle vulnerability CVE-2012-3137; see http://cern.ch/go/7XlV and http://cern.ch/go/7Kgf for press reports). 

Effective from date: 
Wednesday, September 26, 2012 - 10:00
End date: 
Wednesday, September 26, 2012 - 12:00
Service Element Affected: 
Database Replication Services
DB & App Platform for Accelerators
DB & App Platform for AIS
DB & App Platform for EDMS
DB & Application Platform Service for Projects & Experiments
Impact on service: 
Intervention should be transparent
Posted by: 
IT-DB
Unit responsible for resolution: 
IT Department