Search the web
Sign In
New User? Sign Up
psftdba · PeopleSoft DBA Forum

Group Information

  • Members: 899
  • Category: PeopleSoft
  • Founded: Nov 3, 2002
  • Language: English
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Hear how Yahoo! Groups has changed the lives of others. Take me there.

Messages

  Messages Help
Advanced
PSADMIN role considered...harmful?   Message List  
Reply Message #3527 of 4784 |
After taking a look at the privileges granted to SYSADM via the
delivered PSADMIN role, I'm wondering if anyone has trimmed any of the
seemingly unnecessary ones from their installation. For example, I
don't see why SYSADM should have access to create a tablespace or drop
a user. And I'm a bit disturbed to see IMP_FULL_DATABASE after
reading this article (though it sounds like the issue discussed may
have been fixed in the July08 security patch):

http://blog.tanelpoder.com/2007/11/10/oracle-security-all-your-dbas-are-sysdbas-\
and-can-have-full-os-access/


Comments in the psroles.sql script, which creates PSADMIN, say in
part, "These are the minimum privileges required to run PeopleSoft
applications." But then, this wouldn't be the first statement
PeopleSoft has made that wasn't entirely true. So is there anyone out
there who has tried locking down PSADMIN a bit?

--James




Tue Jan 6, 2009 5:43 pm

stoneandkobi
Offline Offline
Send Email Send Email

Message #3527 of 4784 |
Expand Messages Author Sort by Date

After taking a look at the privileges granted to SYSADM via the delivered PSADMIN role, I'm wondering if anyone has trimmed any of the seemingly unnecessary...
James Blanding
stoneandkobi Offline Send Email
Jan 6, 2009
5:43 pm

By coincidence, I was having exactly this discussion on a customer site earlier today. I've just read Tanel's blog entry - Ouch! You can trim the PSADMIN role...
David Kurtz
davidkurtz Offline Send Email
Jan 6, 2009
6:25 pm

James, All dba's and security admins will question the need for the privileges given to SYSADM via the PSADMIN role. We had 2 ways to approach it. First one...
shajivps Offline Send Email Jan 9, 2009
9:46 am
Advanced

Copyright © 2010 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines NEW - Help