DO6748-ORACLE11 - Case sensitivity for passwords should be enabled - 'sec_case_sensitive_logon = true'

Information

Enablement of password case sensitivity allows Oracle password complexity to meet DoD password requirements. Password complexity decreases the likelihood of successful password attacks by malicious users.

Solution

Enable case sensitive passwords.

From SQL*Plus:

alter system set sec_case_sensitive_logon = TRUE scope = both;

The above SQL*Plus command will set the parameter to take effect immediately and permanently at next system startup.

NOTE: Password and account requirements have changed for DoD since the STIG requirement listed in the table for this check was published.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Database_11g_Y21M10_STIG.zip

Item Details

References: CAT|II, Rule-ID|SV-60351r1_rule, STIG-ID|DO6748-ORACLE11, Vuln-ID|V-16033

Plugin: OracleDB

Control ID: 3b69d3732de1f0e5d250a060add21c99651d5f3d48a299cdc83f3d9da6c172f1