Locking the system and sys accounts is viable; I do this on all the databases I manage. You can still / as sysdba when logged into the host and applying patches etc. What do you mean by changing? You're not suggesting creating a new user that will own all the objects that sys currently owns are you?




Reply With Quote