<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Privileges for Oracle roles does not work in Data Management Questions</title>
    <link>https://community.esri.com/t5/data-management-questions/privileges-for-oracle-roles-does-not-work/m-p/49710#M2781</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;&lt;BR /&gt;EDIT: I've just re-read a few things in this thread.&amp;nbsp; You said that the user can see the data if permissions are given to the user directly rather than just to the role.&amp;nbsp; In that case, please check to see if the role in question for that user account is set to be a DEFAULT role in Oracle.&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Thank you very much, William. You were exactly right about the default roles.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Ivan&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 23 Dec 2013 07:51:02 GMT</pubDate>
    <dc:creator>IvanGnevanov</dc:creator>
    <dc:date>2013-12-23T07:51:02Z</dc:date>
    <item>
      <title>Privileges for Oracle roles does not work</title>
      <link>https://community.esri.com/t5/data-management-questions/privileges-for-oracle-roles-does-not-work/m-p/49702#M2773</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hello!&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I have an issue: there are oracle users and roles, created for managing access to the data.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I gave the privileges on the ArcSDE feature datasets to the oracle roles, but the users in that roles still do not have access to the data.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;[ATTACH=CONFIG]28836[/ATTACH]&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The configuration is: ArcGIS Desktop 10.1 -&amp;gt; ArcSDE 9.3.1 -&amp;gt; Oracle 9i&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Any ideas? &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Ivan&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 03 Nov 2013 11:57:21 GMT</pubDate>
      <guid>https://community.esri.com/t5/data-management-questions/privileges-for-oracle-roles-does-not-work/m-p/49702#M2773</guid>
      <dc:creator>IvanGnevanov</dc:creator>
      <dc:date>2013-11-03T11:57:21Z</dc:date>
    </item>
    <item>
      <title>Re: Privileges for Oracle roles does not work</title>
      <link>https://community.esri.com/t5/data-management-questions/privileges-for-oracle-roles-does-not-work/m-p/49703#M2774</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;It's been most of decade since I last used Oracle 9i, but I've never had any difficulty&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; using roles to manage access in Oracle.&amp;nbsp; How exactly are you going about assigning&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;permissions?&amp;nbsp; What geometry storage are you using?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;You should know that Oracle retired 9iR2 long ago, and ArcGIS 9.3.1 rolls off into&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Retired status soon, so you'll be working without a net soon.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;- V&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Nov 2013 00:12:14 GMT</pubDate>
      <guid>https://community.esri.com/t5/data-management-questions/privileges-for-oracle-roles-does-not-work/m-p/49703#M2774</guid>
      <dc:creator>VinceAngelo</dc:creator>
      <dc:date>2013-11-04T00:12:14Z</dc:date>
    </item>
    <item>
      <title>Re: Privileges for Oracle roles does not work</title>
      <link>https://community.esri.com/t5/data-management-questions/privileges-for-oracle-roles-does-not-work/m-p/49704#M2775</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Vince,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;There has been created oracle roles for different data access (for example, read-only access). SELECT ANY TABLE system privilege has been granted to the roles. The roles has been granted to different oracle users.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Then I used ArcCatalog to apply a privileges on feature datasets to that roles (for example, SELECT only).&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;The users in the roles do not have any access to the data unless I give the privileges to the user directly.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Maybe it is neccesary to give more base privileges to the roles, not only to the data itself?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Yes, that is the old software configuration and it is planned to move to contemporary releases in the near future.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Ivan&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Nov 2013 02:26:58 GMT</pubDate>
      <guid>https://community.esri.com/t5/data-management-questions/privileges-for-oracle-roles-does-not-work/m-p/49704#M2775</guid>
      <dc:creator>IvanGnevanov</dc:creator>
      <dc:date>2013-11-05T02:26:58Z</dc:date>
    </item>
    <item>
      <title>Re: Privileges for Oracle roles does not work</title>
      <link>https://community.esri.com/t5/data-management-questions/privileges-for-oracle-roles-does-not-work/m-p/49705#M2776</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;SELECT ANY TABLE access is a dangerous trap.&amp;nbsp; Don't go anywhere near it.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The proper way to grant access has three tiers:&lt;/SPAN&gt;&lt;BR /&gt;&lt;UL&gt;&lt;BR /&gt;&lt;LI&gt;Tables&lt;/LI&gt;&lt;BR /&gt;&lt;LI&gt;Roles&lt;/LI&gt;&lt;BR /&gt;&lt;LI&gt;Users&lt;/LI&gt;&lt;BR /&gt;&lt;/UL&gt;&lt;SPAN&gt;You should explicitly grant role access to the tables (feature classes) using Desktop,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; and explicitly grant user access to roles using SQL.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;- V&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Nov 2013 04:26:53 GMT</pubDate>
      <guid>https://community.esri.com/t5/data-management-questions/privileges-for-oracle-roles-does-not-work/m-p/49705#M2776</guid>
      <dc:creator>VinceAngelo</dc:creator>
      <dc:date>2013-11-05T04:26:53Z</dc:date>
    </item>
    <item>
      <title>Re: Privileges for Oracle roles does not work</title>
      <link>https://community.esri.com/t5/data-management-questions/privileges-for-oracle-roles-does-not-work/m-p/49706#M2777</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Vince,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Ok, SELECT ANY TABLE is a bad idea, but it was implemented after a fault to give access using roles.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;You should explicitly grant role access to the tables (feature classes) using Desktop,&lt;BR /&gt; and explicitly grant user access to roles using SQL.&lt;BR /&gt;&lt;BR /&gt;&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;It is all done exactly as you say. The role access to tables is done using ArcCatalog, user access to roles in made using SQL.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Ivan&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Nov 2013 05:02:27 GMT</pubDate>
      <guid>https://community.esri.com/t5/data-management-questions/privileges-for-oracle-roles-does-not-work/m-p/49706#M2777</guid>
      <dc:creator>IvanGnevanov</dc:creator>
      <dc:date>2013-11-05T05:02:27Z</dc:date>
    </item>
    <item>
      <title>Re: Privileges for Oracle roles does not work</title>
      <link>https://community.esri.com/t5/data-management-questions/privileges-for-oracle-roles-does-not-work/m-p/49707#M2778</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;You'll need to give an example of a set of permission maps that doesn't work &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;as expected before we can help you.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;- V&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Nov 2013 11:03:47 GMT</pubDate>
      <guid>https://community.esri.com/t5/data-management-questions/privileges-for-oracle-roles-does-not-work/m-p/49707#M2778</guid>
      <dc:creator>VinceAngelo</dc:creator>
      <dc:date>2013-11-05T11:03:47Z</dc:date>
    </item>
    <item>
      <title>Re: Privileges for Oracle roles does not work</title>
      <link>https://community.esri.com/t5/data-management-questions/privileges-for-oracle-roles-does-not-work/m-p/49708#M2779</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Vince,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Here are the scripts for the role GEOPH_SURF and a user ABRAMOVA_MI. &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;------------------------&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;DROP ROLE GEOPH_SURF;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;CREATE ROLE GEOPH_SURF NOT IDENTIFIED;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;GRANT DELETE, INSERT, SELECT, UPDATE ON GEOPHYSICS.MINELEASE_T TO GEOPH_SURF;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;GRANT DELETE, INSERT, SELECT, UPDATE ON GEOPHYSICS.S165_IDX$ TO GEOPH_SURF;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;GRANT GEOPH_SURF TO SYS WITH ADMIN OPTION;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;GRANT GEOPH_SURF TO ABRAMOVA_MI;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;----------------------------------&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;DROP USER ABRAMOVA_MI CASCADE;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;CREATE USER ABRAMOVA_MI&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; IDENTIFIED BY VALUES '*'&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; DEFAULT TABLESPACE USERS&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; TEMPORARY TABLESPACE TEMP&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; PROFILE DEFAULT&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; ACCOUNT UNLOCK;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; -- 3 Roles for ABRAMOVA_MI &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; GRANT CONNECT TO ABRAMOVA_MI;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; GRANT GEOPH_SURF TO ABRAMOVA_MI;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; GRANT RESOURCE TO ABRAMOVA_MI;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; ALTER USER ABRAMOVA_MI DEFAULT ROLE CONNECT, RESOURCE;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; -- 1 System Privilege for ABRAMOVA_MI &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; GRANT UNLIMITED TABLESPACE TO ABRAMOVA_MI;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;--------------------------------------&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The privileges for a feature dataset with a single feature class in a Desktop are:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;[ATTACH=CONFIG]28887[/ATTACH]&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;In this case the user does not see the feature class, unless I give explicit rights:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;[ATTACH=CONFIG]28888[/ATTACH]&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Ivan&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Nov 2013 04:33:36 GMT</pubDate>
      <guid>https://community.esri.com/t5/data-management-questions/privileges-for-oracle-roles-does-not-work/m-p/49708#M2779</guid>
      <dc:creator>IvanGnevanov</dc:creator>
      <dc:date>2013-11-06T04:33:36Z</dc:date>
    </item>
    <item>
      <title>Re: Privileges for Oracle roles does not work</title>
      <link>https://community.esri.com/t5/data-management-questions/privileges-for-oracle-roles-does-not-work/m-p/49709#M2780</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I'm not convinced that all of the permissions have been assigned correctly; mainly with the F, S, D, and A tables that correspond to your base table.&amp;nbsp; I see from you original screenshot that the object class in question is versioned as a State ID is referenced in the error.&amp;nbsp; This is why it's critical to use the ArcGIS Desktop tools when granting and revoking permissions to roles for given object classes... because doing so in Oracle can cause issues if you don't do it for all of the right tables involved.&amp;nbsp; &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;You will need to find out which F, S, D, and A tables correspond to your feature class's base table and grant the same permissions to those as you did with the base table.&amp;nbsp; Once you commit your permission SQL statements from within Oracle, close and re-open ArcGIS Desktop and try connecting again with a user from the role that was just given permissions.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;EDIT: I've just re-read a few things in this thread.&amp;nbsp; You said that the user can see the data if permissions are given to the user directly rather than just to the role.&amp;nbsp; In that case, please check to see if the role in question for that user account is set to be a DEFAULT role in Oracle.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 14 Dec 2013 03:15:15 GMT</pubDate>
      <guid>https://community.esri.com/t5/data-management-questions/privileges-for-oracle-roles-does-not-work/m-p/49709#M2780</guid>
      <dc:creator>WilliamCraft</dc:creator>
      <dc:date>2013-12-14T03:15:15Z</dc:date>
    </item>
    <item>
      <title>Re: Privileges for Oracle roles does not work</title>
      <link>https://community.esri.com/t5/data-management-questions/privileges-for-oracle-roles-does-not-work/m-p/49710#M2781</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;&lt;BR /&gt;EDIT: I've just re-read a few things in this thread.&amp;nbsp; You said that the user can see the data if permissions are given to the user directly rather than just to the role.&amp;nbsp; In that case, please check to see if the role in question for that user account is set to be a DEFAULT role in Oracle.&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Thank you very much, William. You were exactly right about the default roles.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Ivan&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Dec 2013 07:51:02 GMT</pubDate>
      <guid>https://community.esri.com/t5/data-management-questions/privileges-for-oracle-roles-does-not-work/m-p/49710#M2781</guid>
      <dc:creator>IvanGnevanov</dc:creator>
      <dc:date>2013-12-23T07:51:02Z</dc:date>
    </item>
    <item>
      <title>Re: Privileges for Oracle roles does not work</title>
      <link>https://community.esri.com/t5/data-management-questions/privileges-for-oracle-roles-does-not-work/m-p/49711#M2782</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;Thank you very much, William. You were exactly right about the default roles.&lt;BR /&gt;&lt;BR /&gt;Ivan&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I'm glad it worked out for you.&amp;nbsp; Please mark the correct answer using the green check so others with the same challenges can identify the solution.&amp;nbsp; Have a great day!&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Dec 2013 13:54:47 GMT</pubDate>
      <guid>https://community.esri.com/t5/data-management-questions/privileges-for-oracle-roles-does-not-work/m-p/49711#M2782</guid>
      <dc:creator>WilliamCraft</dc:creator>
      <dc:date>2013-12-23T13:54:47Z</dc:date>
    </item>
  </channel>
</rss>

