Go to main content

Securing Users and Processes in Oracle® Solaris 11.3

Exit Print View

Updated: September 2018
 
 

What's New in Rights in Oracle Solaris 11.3

    This section highlights information for existing customers about important new features in user rights, also called role-based access control (RBAC) and new features in process rights, also called privileges.

  • The dax_access privilege enables data analytics acceleration on the DAX co-processors on SPARC M7 servers and SPARC T7-Series systems for Oracle Database 12c. A database given this privilege can offload parts of query processing to the hardware.

  • You can generate a password hash for a user and use the passwd -p command to assign it. This functionality is useful for automated installation (AI) and scripting. For more information, see the pwhash(1) and passwd(1) man pages.

  • Oracle Solaris provides the pam_otp_auth PAM module for processing one-time passwords (OTP). OTPs provide a second authentication step before login. The package that installs the module also installs two PAM stacks in the /etc/security/pam_policy directory. For more information, see Task Map: Using OTP in Oracle Solaris in Managing Kerberos and Other Authentication Services in Oracle Solaris 11.3.

  • Oracle Solaris provides the pam_pkcs11 PAM module for managing smart card authentication. Smart cards enable users to log in only if they 1) possess a smart card that is recognized by the login server and 2) can supply the correct PIN. For more information, see Chapter 7, Using Smart Cards for Multifactor Authentication in Oracle Solaris in Managing Kerberos and Other Authentication Services in Oracle Solaris 11.3.