DO6746-ORACLE11 - The Oracle listener.ora file should specify IP addresses rather than host names to identify hosts - '$ORACLE_HOME/network/admin/listener.ora HOST entroes do not use hostnames'

Information

The use of IP address in place of host names helps to protect against malicious corruption or spoofing of host names. Use of static IP addresses is considered more stable and reliable than use of hostnames or Fully Qualified Domain Names (FQDN).

Solution

Edit the listener.ora file and replace any HOST= [hostname or domain name] to use static IP addresses for the host.

The listener.ora file is by default located in the ORACLE_HOME/network/admin directory or the directory specified in the TNS_ADMIN environment variable for the listener service or process owner account.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Database_11g_Y21M10_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|III, Rule-ID|SV-24952r1_rule, STIG-ID|DO6746-ORACLE11, Vuln-ID|V-16031

Plugin: Unix

Control ID: 0ce4bbe969b15a93d0a1ff1aed432d58bc7e6d056f54370ca1441da473bd9459