On release 11g and onwards, you need to create an ASM user and grant the SYSASM role. The purpose of the SYSASM role is to provide a level of separation between the RDBMS & ASM credentials.
The SYSASM role, which has full capability on the ASM instance, is authenticated through the OSASM user group, similar to the SYSDBA roles, which is authenticated through OSDBA.
1) The following example shows how to connect as SYSASM and configure a new user for SYSASM role:
+ASM:oracle> export ORACLE_SID=+ASM
+ASM:oracle>sqlplus "/as sysasm"
SQL*Plus: Release 11.1.0.6.0 - Production on Thu Oct 1 15:44:00 2009
Copyright (c) 1982, 2007, Oracle. All rights reserved.
Connected to:
Oracle Database 11g Enterprise Edition Release 11.1.0.6.0 - Production
With the Partitioning, OLAP, Data Mining and Real Application Testing options
SQL> create user ASMUSER identified by oracle;
User created.
SQL> grant SYSASM, SYSOPER to ASMUSER;
Grant succeeded.
SQL> exit
2) Then connect as ASMUSER:
+ASM:oracle> export ORACLE_SID=+ASM
+ASM:oracle>sqlplus "ASMUSER/oracle as sysasm"
SQL*Plus: Release 11.1.0.6.0 - Production on Thu Oct 1 15:45:26 2009
Copyright (c) 1982, 2007, Oracle. All rights reserved.
Connected to:
Oracle Database 11g Enterprise Edition Release 11.1.0.6.0 - Production
With the Partitioning, OLAP, Data Mining and Real Application Testing options
SQL> select * from v$pwfile_users;
USERNAME SYSDBA SYSOPE SYSASM
------------------------------ ------ ------ ------
SYS TRUE TRUE TRUE
ASMUSER FALSE TRUE TRUE