文档介绍:DBA never sleep-DBA,永不眠
Focus on Oracle Database, GodenGate and Unix
Using Class of Secure Transport (COST) to Restrict Instance Registration in
Oracle RAC (Doc ID 13408
分类: Oracle 11g RAC 2013-11-04 12:24 128人阅读评论(0) 收藏举报
Class of Secure TranCOSTwalletOracle DatabaseInstance Registratio
Applies to:
Services - Version to [Release to ]
Information in this document applies to any platform.
Goal
To demonstrate how the COST parameter "SECURE_REGISTER_ = " is used to te ri_nnsatmaence
registration with listeners in RAC environments. With COST restrictions in place only local and 
authorized instances having appropriate credentials will be allowed to register. These instructions
can be used to address the issues published in Oracle Security Alert CVE-2012-1675 by using COST to
restrict connections to only those instances having appropriate credentials.
About COST
The class of secure transports (COST) parameters specify a list of transports that are considered
secure for administration and registration of a particular listener. The COST parameters identify
which transports are considered secure for that installation and whether the administration of a
listener requires secure transports. COST will not affect client connections utilizing other
protocols. For more details and for information about other available COST parameters please see the
Administrators Guide work Reference.
Oracle versions that support COST
Although not documented in the Oracle work Administrator Guide COST parameters and
functionality are supported as of .
Solution
Topics in this section: 
1) Oracle RAC - Securing registration with Scan listeners
2) Oracle RAC - Securing ASM and Database registration with the Local (node) listener.
3) Oracle RAC versions prior to ( - ) 
 
1) Oracle RAC - Securing registration with Scan listeners
This example environment is a two node RAC clus