Does the EM 12c agent install user *have* to be a member of the oinstall group?
Does the EM 12c agent install user have to be a member of the oinstall group in order to monitor Oracle Databases/RAC/GI?
For example, our Oracle Database homes are owned by "oracle:oinstall" and the central inventory "inst_group" is "oinstall".
If we create an EM agent install user such as "emagent:oinstall" then it can access the central inventory but this emagent user would also be able to modify any other group-writable files belonging to the oinstall group. This is problematic for us from a security perspective.
So I am asking if it is possible (and supported!) to create the EM agent install user with a totally different primary group (such as "emagent:emagent"), and thus have an EM agent user that is *not* a member of the oinstall group?