Setting up database permissions
When you have created the Oracle database that will be used for IBM® BigFix® Remote Control you will need to configure its permissions.
About this task
To configure the database permissions complete the following steps:
Procedure
- Run Oracle SQL*Plus.
- Windows® systems
-
For example: Click Start > Programs > Oracle-OraHomeName > Application Development > SQL Plus.
Alternatively, enter the following command at a command prompt.
sqlplusw
Log on using the database user name and password and click OK. See your database system administrator if you do not have this.For example:
Username - system
Password - dboracle
- Linux® systems
- Open a UNIX® or a Windows terminal and enter the
SQL*Plus command:
sqlplus username / password @connect_identifier
username and password are the database credentials required to connect to the database.
connect_identifier is the connection required for your specific database.
For example, @TRCDB as SYSDBA
@//servername:port/DatabaseSID as SYSDBA
servername is the server name or IP address of the system where your Oracle installation is located.
port is the port of the system where your Oracle installation is located.
DatabaseSID is the SID defined for the database you created.
- After SQL*Plus has started and connected to the database you can create the required users and grant permissions. There are two methods for creating users and granting permissions. Choose the appropriate method for creating the users.
- Create one user ID in Oracle which will also be used to log on to IBM BigFix Remote Control.
Create a single user. The user must be called Asset. This user ID is used by IBM BigFix Remote Control to create and log on to the database, and use the database.
Issue the following commands to create the user ASSET.
- connect SYS/PASSWORD@DATABASE AS SYSDBA;
where PASSWORD is the default Oracle user password.
and DATABASE is the database name that was defined when creating the database. For example, TRCBD.
- CREATE USER ASSET IDENTIFIED BY PASSWORD DEFAULT TABLESPACE
users TEMPORARY TABLESPACE temp; Note: PASSWORD can be changed to whatever you require, for the user ASSET.
- GRANT UNLIMITED TABLESPACE TO ASSET;
- GRANT CONNECT TO ASSET;
- GRANT CREATE INDEXTYPE TO ASSET;
- GRANT CREATE SEQUENCE TO ASSET;
- GRANT CREATE TABLE TO ASSET;
- GRANT CREATE TRIGGER TO ASSET;
- GRANT CREATE INDEXTYPE TO ASSET;
- GRANT CREATE PROCEDURE TO ASSET;
- GRANT CREATE VIEW TO ASSET;
- GRANT ANALYZE ANY TO ASSET;
- connect SYS/PASSWORD@DATABASE AS SYSDBA;
- Create a separate user ID to log on to IBM BigFix Remote Control
Create 2 users. User 1 must be called Asset. This user has no specific permissions and is used only as a schema name. User 2 is the main user and can be called anything you require. This user is used by IBM BigFix Remote Control to create and logon to the database, and use the database. Use the assistant tool to create user TRCDBU.
Complete the following steps to create the required permissions for user TRCDBU.
- GRANT UNLIMITED TABLESPACE TO ASSET;
- GRANT UNLIMITED TABLESPACE TO TRCDBU;
- GRANT ALTER ANY INDEX TO TRCDBU ;
- GRANT ALTER ANY INDEXTYPE TO TRCDBU ;
- GRANT ALTER ANY PROCEDURE TO TRCDBU ;
- GRANT ALTER ANY SEQUENCE TO TRCDBU ;
- GRANT ALTER ANY TABLE TO TRCDBU ;
- GRANT ALTER ANY TRIGGER TO TRCDBU ;
- GRANT COMMENT ANY TABLE TO TRCDBU ;
- GRANT CREATE ANY INDEX TO TRCDBU ;
- GRANT CREATE ANY INDEXTYPE TO TRCDBU ;
- GRANT CREATE ANY SEQUENCE TO TRCDBU ;
- GRANT CREATE ANY TABLE TO TRCDBU ;
- GRANT CREATE ANY TRIGGER TO TRCDBU ;
- GRANT CREATE INDEXTYPE TO TRCDBU ;
- GRANT CREATE PROCEDURE TO TRCDBU ;
- GRANT CREATE SEQUENCE TO TRCDBU ;
- GRANT CREATE TABLE TO TRCDBU ;
- GRANT CREATE TRIGGER TO TRCDBU ;
- GRANT CREATE VIEW TO TRCDBU ;
- GRANT DELETE ANY TABLE TO TRCDBU ;
- GRANT INSERT ANY TABLE TO TRCDBU;
- GRANT DROP ANY INDEX TO TRCDBU ;
- GRANT DROP ANY INDEXTYPE TO TRCDBU ;
- GRANT DROP ANY PROCEDURE TO TRCDBU ;
- GRANT DROP ANY SEQUENCE TO TRCDBU ;
- GRANT DROP ANY TABLE TO TRCDBU ;
- GRANT DROP ANY TRIGGER TO TRCDBU ;
- GRANT EXECUTE ANY INDEXTYPE TO TRCDBU ;
- GRANT EXECUTE ANY LIBRARY TO TRCDBU ;
- GRANT EXECUTE ANY TYPE TO TRCDBU ;
- GRANT SELECT ANY SEQUENCE TO TRCDBU ;
- GRANT SELECT ANY TABLE TO TRCDBU ;
- GRANT UNLIMITED TABLESPACE TO TRCDBU ;
- GRANT UPDATE ANY TABLE TO TRCDBU;
- GRANT ANALYZE ANY TO TRCDBU;