Security Technology Center

オラクルは、幅広い製品やプロセス、およびテクノロジを通じてセキュアなインフラストラクチャを提供し、機密情報への未承認のアクセスを防ぎ、ユーザー管理のコストを削減し、プライバシ管理を容易にするサポートを行います。


 最新の Critical Patch Update Advisory を見る
 Oracle Software Security Assurance Blog を読む(US)

What's New

AuthnRequest Settings in OIF / SP
Damien Carru lists the various OIF/SP settings that affect how an AuthnRequest message is created in OIF in a Federation SSO flow.

Oracle Enterprise Manager Cloud Control authorization with Active Directory
Jeroen Gouma takes you step-by-step through the user authortization process in Oracle Enterprise Manager Cloud Control 12c.

Hands-On Mobile Workshops in the USA and Canada
Coming to your town! Workshops covering mobile security, development, and enterprise mobility. Work hands-on with Oracle MAF, Oracle SOA Suite, Oracle Mobile Security, and more.

Logging made easy in OAM 11g with this simple trick!
A-Team architect Tim Melander walks you step-by-step through a little-known but effective way to update the logging.xml file in Oracle Access Manager 11g

LDAP and Weblogic: Using ApacheDS as auth-provider
Martin Smeets offer suggestions on how LDAP connections can be debugged and shares an example how an ApacheDS can be used as an external authentication provider in Weblogic server.

Understanding OAM 11g ASDK Configuration and Cert Requirements
Oracle provides documentation on developing an Access Client for the OAM 11g ASDK, but getting it to work can be challenging when running the Access Servers in Simple or Cert Mode. Tim Melander's article describes the correct structure of the Access Client configuration including all the required files and code snippets to hopefully save you a lot of time.


ドキュメントおよびベスト・プラクティス

Critical Patch Updateの実装 (PDF)
Database Vault ベスト・プラクティス (PDF)
Oracle Security Overview
Oracle Database Security Guide
Oracle Application Server セキュリティ・ガイド
Oracle Identity Managementによる米国サーベンス・オクスリー(Sarbanes-Oxley, SOX)法への 対応 (PDF)

コミュニティ・コンテンツ

Learn Database Security Best Practices: Project Lockdown
How To Encrypt Data in Oracle Using PHP
Securing a .NET Application on the Oracle Database
Understanding Transparent Data Encryption
Database Security: Beyond the Password
Using VPD in an Oracle HTML DB Application
Encrypt Your Data Assets
Fine-Grained Auditing in Oracle Database 10g (3-part series)
Oracle 10g Virtual Private Database in Action
More Security Articles...