LSNRCTL shows VALID_NODE_CHECKING_REGISTRATION [NULL] when actually ON
(Doc ID 2414537.1)
Last updated on FEBRUARY 03, 2019
Applies to:Oracle Net Services - Version 18.104.22.168 and later
Information in this document applies to any platform.
With the 22.214.171.124 version of Oracle, the DEFAULT setting for VNCR (Valid Node Checking Registration) is ON.
However, when a check is done for the value of VNCR using lsnrctl, the value shows as "NULL"
Unfortunately, some 3rd party "security scanning" tools either check for the above line OR the value posted by the Listener Control check.
For example, the "Nexus scan" may fail with:
“110053 - Oracle TNS Listener VSNNUM Version Remote Information Disclosure”
This is not because the TNS Listener is not secure, because testing with a remote registration attempt fails.
It is because the line is missing from the listener.ora file OR there is no "ON" value.
The 3rd party tools can vary and are not specifically considered in this note.
Of primary importance is that this appears to be a defect, based on why the lsnrctl data is showing NULL.
To view full details, sign in with your My Oracle Support account.
Don't have a My Oracle Support account? Click to get started!
In this Document