LSNRCTL shows VALID_NODE_CHECKING_REGISTRATION [NULL] when actually ON
Last updated on JUNE 22, 2018
Applies to:Oracle Net Services - Version 22.214.171.124 and later
Information in this document applies to any platform.
With the 126.96.36.199 version of Oracle, the DEFAULT setting for VNCR (Valid Node Checking Registration) is ON.
However, when a check is done for the value of VNCR using lsnrctl, the value shows as "NULL"
Unfortunately, some 3rd party "security scanning" tools either check for the above line OR the value posted by the Listener Control check.
For example, the "Nexus scan" may fail with:
“110053 - Oracle TNS Listener VSNNUM Version Remote Information Disclosure”
This is not because the TNS Listener is not secure, because testing with a remote registration attempt fails.
It is because the line is missing from the listener.ora file OR there is no "ON" value.
The 3rd party tools can vary and are not specifically considered in this note.
Of primary importance is that this appears to be a defect, based on why the lsnrctl data is showing NULL.
Sign In with your My Oracle Support account
Don't have a My Oracle Support account? Click to get started
My Oracle Support provides customers with access to over a
Million Knowledge Articles and hundreds of Community platforms