最近denied比较频繁
告警日志频繁出现读取口令文件时,权限不足,检查相关trc文件
-
trace file /oracle/app/oracle/diag/rdbms/orcl/orcl1/trace/orcl1_ora_14549066.trc
-
oracle database 19c enterprise edition release 19.0.0.0.0 - production
-
version 19.9.0.0.0
-
build label: rdbms_19.9.0.0.0dbru_aix.ppc64_200930
-
oracle_home: /oracle/app/oracle/product/19.3.0/db_1
-
system name: aix
-
node name: db1
-
release: 1
-
version: 7
-
machine: 00fbdf014c00
-
instance name: orcl1
-
redo thread mounted by this instance: 1
-
oracle process number: 96
-
unix process pid: 14549066, image: oracle@db1 (tns v1-v3)
-
-
-
*** 2022-06-21t15:54:40.04417808:00
-
*** session id:(8.61294) 2022-06-21t15:54:40.04420508:00
-
*** client id:() 2022-06-21t15:54:40.04421208:00
-
*** service name:(sys$users) 2022-06-21t15:54:40.04421908:00
-
*** module name:(sqlplus@db1 (tns v1-v3)) 2022-06-21t15:54:40.04422708:00
-
*** action name:() 2022-06-21t15:54:40.04423408:00
-
*** client driver:() 2022-06-21t15:54:40.04424008:00
-
-
ora-17503: ksfdopn:2 failed to open file datadg/orcl/password/pwdorcl
-
ora-27300: os system dependent operation:open failed with status: 13
-
ora-27301: os failure message: permission denied
-
ora-27302: failure occurred at: sskgmsmr_7
-
ora-17503: ksfdopn:2 failed to open file datadg/orcl/password/pwdorcl
-
ora-27300: os system dependent operation:open failed with status: 13
-
ora-27301: os failure message: permission denied
-
ora-27302: failure occurred at: sskgmsmr_7
-
<error barrier> at 0xfffffffffff4140 placed kzia.c@2131
-
ora-01017: invalid username/password; logon denied
-
ora-17503: ksfdopn:2 failed to open file datadg/orcl/password/pwdorcl
-
ora-27300: os system dependent operation:open failed with status: 13
-
ora-27301: os failure message: permission denied
-
ora-27302: failure occurred at: sskgmsmr_7
似乎又是属组的问题,搜索mos
ora-17503/ora-27300/ora-27301/ora-27302 occurred if connected database via an os user who is not in "oinstall" group (doc id 2310640.1)
后来问题就消失,不再出现。
通过last|head 推测案发现场:
有个正经人,登录主机,配置监控,但是os用户权限没搞对,就导致登录数据库报错,后来可能是意识到问题,增加了oinstall组,解决了。
但是看了看 cat /etc/passwd 没有怀疑对象,未完...
阅读(1286) | 评论(0) | 转发(0) |