Creating Database Control Administrative Users

来源:互联网 发布:javaweb博客系统源码 编辑:程序博客网 时间:2024/05/16 09:52

Creating Database Control Administrative Users

When you log in to Oracle Enterprise Manager Database Control (Database Control) using the SYS, SYSTEM, or SYSMAN user accounts, you are logging in as the Database Control super user. These are the only accounts that are automatically granted the roles and privileges required to administer Database Control itself. Examples of Database Control administration tasks include the following:
当你用SYS、SYSTEM或者SYSMAN用户登录oracle企事业管理数据库控制台的时候,这是以数据库控制台的超级用户登录的。只有这些用户自动有访问数据库控制台的权限。数据库控制台管理任务包含如下方面:

  • Creating other Database Control administrators
    创建其它数据库控制台管理员

  • Configuring e-mail and other notification methods
    配置e-mail或者其它通知方式

    See "Setting Up Direct Alert Notification".
    参见 "Setting Up Direct Alert Notification"

  • Setting alert thresholds for database metrics, such as tablespace space usage percentage exceeded or SQL response time exceeded
    为数据库设置一些警告项,如表空间使用百分比或者sql的响应时间

    See "Managing Alerts".
    参见 "Managing Alerts"

  • Selecting database policies to apply, so that Database Control can show alerts if a policy is violated. (An example policy is "A nonsystem user cannot use the SYSTEM or SYSAUX tablespace as its default tablespace.")
    为数据库选择一个策略,以便让数据库控制台在违反策略的时候显示警告(如:非系统用户不能用SYSTEM或者SYSAUX表空间用做默认表空间。)

  • Defining blackouts, which are time periods in which database monitoring is suspended so that maintenance operations do not skew monitoring data or generate needless alerts.
    定义中断,数据库监控器被挂起的时间内,保证主程序监控数据准确并且不产生多余的警告。

    See "Defining Blackout Periods".

You can create Database Control administrative users who have enough privileges to administer Database Control itself, but lack the high-level database administration privileges of the SYS and SYSTEM users. This enables you to assign the minimum privileges required for other Database Control administrators to do their jobs, which is a best practice for database security. You can also create a Database Control administrative account for yourself, thus avoiding logging in as SYS or SYSTEM until you must perform database administration tasks.
可以创建有足够权限管理数据库控制台的管理用户,但是不能有SYS和SYSTEM用户这样高的级别。这使得你把最少的权限分配给其它的数据库控制台管理员来工作,这是最好的数据库安全实现。你可以为自己创建一个数据库控制台管理账户,在不需要执行数据库管理任务时避免用SYS或者SYSTEM登录。

Using the following procedure, you can assign Database Control administrative privileges to an existing database user or create a new Database Control administrative user. When you create a new Database Control administrative user, a user account is created for that user for the database. You must then decide which system privileges, object privileges, or roles to grant the user, if any, to perform database administration tasks.
用下面的过程你可以为一个已有的数据库用户分配数据库控制台管理权限或者创建一个新的数据库控制台管理用户。当你创建一个新的数据库控制台管理用户时,在数据库会创建此用户的账户。要执行数据库管理任务需要定下来给这个用户赋哪些权限。

To create a Database Control administrative user:
创建一个数据库控制台管理用户:

  1. On any Database Control page, at the top of the page, click Setup.
    在任何一个数据库控制台页面上方,点击Setup

    The Enterprise Manager Configuration page appears, showing the Overview of Setup page.
    弹出企业管理配置页,显示总览的创建页面。

  2. In the left navigation bar, click Administrators.
    在左边的导航条中,点击Administrators

    The Administrators page appears.
    弹出管理页面。


    Description of the illustration em_admin_create.gif
  3. Click Create.
    点击 Create

    The Create Administrator: Properties page appears.


    Description of the illustration em_admin_create_properties.gif
  4. In the Name field, enter a new user name, or click the flashlight icon next to the field and select an existing database user.
    在Name栏输入一个新的用户名,或者点击文本框旁边的手电图标,在数据库中查找已有的用户。

  5. In the Password and Confirm Password fields, enter a user password.
    PasswordConfirm Password栏输入密码。

    If you are creating a new user, assign a password. If you are selecting an existing user, enter any text in the password fields. The text is ignored, and the password for the user is not changed.
    如果你创建一个新的用户,请分配一个密码。如果选择了一个已有的用户,随便在密码栏输入。里面的内容会被忽略,这个用户的密码不会改变。

  6. Enter one or more e-mail addresses for this administrator only if you plan to set up e-mail notifications for the database.
    如果你想为数据库创建邮件通知,输入一个或多个电子邮件地址。

    See "Setting Up Direct Alert Notification" for more information.
    参见 "Setting Up Direct Alert Notification"

  7. Click Review to view a page that summarizes the information that you entered.
    点击Review查看你刚才输入的汇总。

  8. Click Finish to create the new administrative user.
    点击Finish创建一个新的管理员用户。

    The Administrators page appears, showing the new administrator in the list.
    出现管理员页面,新建的用户出会列出来。