Auditing an Oracle database for security issues is very important. PeteFinnigan.com provides all of the information and tools that you will need Click here for details of PeteFinnigan.com Limited's detailed Oracle database security audit service Click here for details of PeteFinnigan.com Limited's Oracle Security Training Courses
There are 36 visitors online    

Pete Finnigan's Oracle security weblog


Home » Archives » December 2006 » Oracle 11g will have SHA-1 hashed passwords and case sensitive passwords

[Previous entry: "Evading Oracle IDS and audit appliances"] [Next entry: "Integrigy have released a completely new version of their listener check tool"]

Oracle 11g will have SHA-1 hashed passwords and case sensitive passwords

December 21st, 2006 by Pete

Post to del.icio.us   Post to Furl   Digg!

I was made aware today by someone that the new release of Oracle, currently known as 11g or 11.1 will have case sensitive passwords and also the password algorithm has changed to SHA-1 instead of the old DES based hashing used.

It also seems that passwords hashed on 10gR2 and lower where the database has been upgraded to 11g will retain case insensitive passwords. This hints at the old DES based password algorithm still being available in 11g as well. I cannot confirm this as I am not a beta customer (indeed if I was I couldnt confirm it either!) and I am sure my source isn't either but they found out quite reliably so i am sure its correct.

This is good news that Oracle seem to be taking security very seriously in 11g.

December 2006
SMTWTFS
     12
3456789
10111213141516
17181920212223
24252627282930
31      

This is the weblog for Pete Finnigan. Pete works in the area of Oracle security and he specialises in auditing Oracle databases for security issues. This weblog is aimed squarely at those interested in the security of their Oracle databases.

Weblog Home
Weblog Archives

Oracle Security Step-by-Step (Version 2.0)

Home
Oracle Security Tools page
Oracle security papers
Oracle Security alerts

Web Development
SQL Server Security

RSS 1.0 FEED
RSS 2.0 FEED
Atom 0.3 FEED
Powered by gm-rss 2.0.0




View Pete Finnigan's profile on LinkedIn

Pete Finnigan

Create Your Badge



Valid XHTML 1.0!