LSNRCTL shows VALID_NODE_CHECKING_REGISTRATION [NULL] when actually ON
(Doc ID 2414537.1)
Last updated on MARCH 10, 2019
Applies to:Oracle Net Services - Version 126.96.36.199 and later
Information in this document applies to any platform.
With the 188.8.131.52 version of Oracle, the DEFAULT setting for VNCR (Valid Node Checking Registration) is ON.
However, when a check is done for the value of VNCR using lsnrctl, the value shows as "NULL"
Unfortunately, some 3rd party "security scanning" tools either check for the above line OR the value posted by the Listener Control check.
For example, the "Nexus scan" may fail with:
“110053 - Oracle TNS Listener VSNNUM Version Remote Information Disclosure”
This is not because the TNS Listener is not secure, because testing with an actual "remote registration attempt" fails.
It is because the line is missing from the listener.ora file (so there is no "ON" value which it is looking for).
The 3rd party tools can vary and are not specifically considered in this note.
To view full details, sign in with your My Oracle Support account.
Don't have a My Oracle Support account? Click to get started!
In this Document