Corporation Network Router User Manual
viii
Task 1: Install Kerberos................................................................................................................ 6-2
Task 2: Configure a Service Principal for an Oracle Database Server................................... 6-2
Task 3: Extract a Service Table from Kerberos ......................................................................... 6-3
Task 4: Install an Oracle Database Server and an Oracle Client............................................ 6-4
Task 5: Install Oracle Net Services and Oracle Advanced Security...................................... 6-5
Task 6: Configure Oracle Net Services and Oracle Database................................................. 6-5
Task 7: Configure Kerberos Authentication............................................................................. 6-5
Task 8: Create a Kerberos User................................................................................................. 6-10
Task 9: Create an Externally Authenticated Oracle User...................................................... 6-10
Task 10: Get an Initial Ticket for the Kerberos/Oracle User................................................ 6-11
Utilities for the Kerberos Authentication Adapter .................................................................... 6-11
Obtaining the Initial Ticket with the okinit Utility................................................................ 6-11
Displaying Credentials with the oklist Utility........................................................................ 6-12
Removing Credentials from the Cache File with the okdstry Utility ................................. 6-13
Connecting to an Oracle Database Server Authenticated by Kerberos.............................. 6-13
Configuring Interoperability with a Windows 2000 Domain Controller KDC .................... 6-13
Task 1: Configuring an Oracle Kerberos Client to Interoperate with a Windows 2000
Domain Controller KDC 6-14
Task 2: Configuring a Windows 2000 Domain Controller KDC to Interoperate with an
Oracle Client 6-15
Task 3: Configuring an Oracle Database to Interoperate with a Windows 2000 Domain
Controller KDC........................................................................................................................... 6-17
Task 4: Getting an Initial Ticket for the Kerberos/Oracle User........................................... 6-17
Troubleshooting ................................................................................................................................ 6-18
7 Configuring Secure Sockets Layer Authentication
SSL and TLS in an Oracle Environment......................................................................................... 7-2
Difference between SSL and TLS................................................................................................ 7-2
About Using SSL........................................................................................................................... 7-3
How SSL Works in an Oracle Environment: The SSL Handshake........................................ 7-4
Public Key Infrastructure in an Oracle Environment.................................................................. 7-5
About Public Key Cryptography................................................................................................ 7-5
Public Key Infrastructure Components in an Oracle Environment...................................... 7-6
SSL Combined with Other Authentication Methods................................................................ 7-10
Architecture: Oracle Advanced Security and SSL ................................................................. 7-10