-- ============================================================================ -- PASSWORD PROFILE CONFIGURATION -- ============================================================================ -- Configures DEFAULT profile for no password expiration -- CRITICAL for ROA application compatibility -- -- This script disables all password restrictions to prevent: -- - Password expiration issues during long-running installations -- - Account lockouts from failed login attempts -- - Password reuse restrictions -- -- WARNING: This reduces security. For production environments, consider -- creating a custom profile with appropriate settings. -- -- ATENTIE - UNELTA DE REMEDIERE MANUALA, NU FACE PARTE DIN FLUXUL DE INSTALARE -- ---------------------------------------------------------------------------- -- La o instalare normala NU rulezi scriptul asta: `01-setup-database.ps1` face -- deja acelasi lucru automat, la Step 4 (in PDB) si Step 4b (in CDB root). -- Foloseste-l doar cand `07-verify-installation.ps1` / `verify-objects.sql` -- semnaleaza ca profilul DEFAULT are din nou limite de parola - de exemplu pe o -- baza configurata inainte ca Step 4b sa existe, sau dupa un patch Oracle. -- -- Usage: -- sqlplus sys/@:1521/XEPDB1 as sysdba @configure-profile.sql -- -- Connect as: SYSDBA, pe PDB (XEPDB1), NU pe CDB root. -- ============================================================================ SET ECHO OFF SET FEEDBACK ON SET SERVEROUTPUT ON WHENEVER SQLERROR CONTINUE PROMPT PROMPT ======================================== PROMPT Configuring Password Profile PROMPT ======================================== PROMPT -- Show current profile settings PROMPT Current DEFAULT profile settings: SELECT resource_name, limit FROM dba_profiles WHERE profile = 'DEFAULT' AND resource_type = 'PASSWORD' ORDER BY resource_name; PROMPT PROMPT Modifying DEFAULT profile for ROA compatibility... PROMPT -- Disable password expiration ALTER PROFILE DEFAULT LIMIT PASSWORD_LIFE_TIME UNLIMITED PASSWORD_REUSE_TIME UNLIMITED PASSWORD_REUSE_MAX UNLIMITED PASSWORD_VERIFY_FUNCTION NULL PASSWORD_LOCK_TIME UNLIMITED PASSWORD_GRACE_TIME UNLIMITED FAILED_LOGIN_ATTEMPTS UNLIMITED; PROMPT PROMPT ======================================== PROMPT Profile Configuration Complete PROMPT ======================================== PROMPT -- Verify new settings PROMPT New DEFAULT profile settings: SELECT resource_name, limit FROM dba_profiles WHERE profile = 'DEFAULT' AND resource_type = 'PASSWORD' ORDER BY resource_name; PROMPT PROMPT WARNING: Password restrictions have been disabled. PROMPT For production environments, consider creating a custom PROMPT profile with appropriate security settings. PROMPT -- Unlock any locked accounts (optional) PROMPT PROMPT Unlocking ROA-related accounts if locked... DECLARE v_sql VARCHAR2(200); BEGIN FOR rec IN (SELECT username FROM dba_users WHERE account_status LIKE '%LOCKED%' AND username IN ('CONTAFIN_ORACLE', 'SYSTEM')) LOOP v_sql := 'ALTER USER ' || rec.username || ' ACCOUNT UNLOCK'; EXECUTE IMMEDIATE v_sql; DBMS_OUTPUT.PUT_LINE('Unlocked user: ' || rec.username); END LOOP; END; / -- Reset expired passwords (optional - requires manual password) PROMPT PROMPT If any accounts show EXPIRED status, reset their passwords: SELECT username, account_status FROM dba_users WHERE username IN ('CONTAFIN_ORACLE', 'SYSTEM', 'SYS') OR username LIKE 'FIRMA%' OR username LIKE 'TEST%'; PROMPT -- ============================================================================ -- ULTIMUL PAS: ACELASI PROFIL SI IN CDB ROOT -- ============================================================================ -- ALTER PROFILE dintr-un PDB nu acopera CDB root: acolo DEFAULT ramane cu -- PASSWORD_LIFE_TIME 180, deci SYSTEM din root expira la ~6 luni de la -- instalare (ORA-28002, apoi ORA-28001) chiar daca in PDB totul e UNLIMITED. -- -- DEFAULT din root e un profil LOCAL, deci clauza CONTAINER=ALL NU e valida -- aici (ORA-65142). Se comuta containerul si se altereaza profilul de acolo. -- -- Blocul e ULTIMUL din fisier intentionat: dupa ALTER SESSION SET CONTAINER -- restul scriptului ar rula in root, nu in PDB. -- Pe o baza non-CDB, ALTER SESSION esueaza inofensiv (WHENEVER SQLERROR -- CONTINUE) si ALTER PROFILE se aplica pe singurul container existent. PROMPT PROMPT ======================================== PROMPT Applying the same profile in CDB root PROMPT ======================================== PROMPT ALTER SESSION SET CONTAINER = CDB$ROOT; ALTER PROFILE DEFAULT LIMIT PASSWORD_LIFE_TIME UNLIMITED PASSWORD_GRACE_TIME UNLIMITED PASSWORD_REUSE_TIME UNLIMITED PASSWORD_REUSE_MAX UNLIMITED FAILED_LOGIN_ATTEMPTS UNLIMITED PASSWORD_LOCK_TIME UNLIMITED; PROMPT PROMPT Account status in CDB root: SELECT username, account_status, expiry_date FROM dba_users WHERE username IN ('SYS', 'SYSTEM'); PROMPT PROMPT NOTA: daca SYSTEM apare EXPIRED(GRACE), statusul NU se curata singur PROMPT cand profilul devine UNLIMITED - cere o singura data: PROMPT ALTER USER SYSTEM IDENTIFIED BY ; PROMPT (sau ruleaza 01-setup-database.ps1 -ResetSystemPassword) PROMPT