Batch deletion of user privileges?
Posted in 2003
Topics: Security, Permissions & Auditing
Hi Informixers, we are presently removing some dozens of user accounts from our Unix system (regular "housekeeping"). Since most of these accounts have access privileges in one or more of our Informix databases, I am looking for an easy way to remove these privileges. Rather than having to issue hundreds of "revoke all on <tablename> from <user>" and "revoke connect from <user>", is there a more effective way to do this? I'm thinking of "delete from systabauth where grantee in ("user1", "user2", ...) and "delete from sysusers where username in ..."). Is this safe and does it achieve the desired effect? I don't expect this to be officially supported, but that's fine with me as long as it does what it's supposed to do, without any undesirable side effects. Regards, Richard -- +-------------------------------+---------------------------------------+ | Dr. med Richard Spitz | Mail: spitz@ana.med.uni-muenchen.de | | Klinik f'r Anaesthesiologie | Tel : +49-89-7095-6110 | | Klinikum der Univ. M'nchen | FAX : +49-89-7095-6420 | | 81366 M'nchen, Germany | GSM : +49-172-8933578 | +-------------------------------+---------------------------------------+
Using system tables may do the trick. In order to avoid this kind of work in the future, use roles instead. Assign privileges to roles and then roles to users or vice versa - depends how you look on that. Gorazd "Richard Spitz" <Richard.Spitz@ana.med.uni-muenchen.de> wrote in message news:hnrtlvgtfb9a644v9f1fk7rn3aq7glq32u@4ax.com... > Hi Informixers, > > we are presently removing some dozens of user accounts from our > Unix system (regular "housekeeping"). Since most of these accounts > have access privileges in one or more of our Informix databases, I > am looking for an easy way to remove these privileges. > > Rather than having to issue hundreds of "revoke all on <tablename> > from <user>" and "revoke connect from <user>", is there a more > effective way to do this? > > I'm thinking of "delete from systabauth where grantee in ("user1", > "user2", ...) and "delete from sysusers where username in ..."). > Is this safe and does it achieve the desired effect? > > I don't expect this to be officially supported, but that's fine > with me as long as it does what it's supposed to do, without > any undesirable side effects. > > Regards, Richard > > -- > +-------------------------------+---------------------------------------+ > | Dr. med Richard Spitz | Mail: spitz@ana.med.uni-muenchen.de | > | Klinik f'r Anaesthesiologie | Tel : +49-89-7095-6110 | > | Klinikum der Univ. M'nchen | FAX : +49-89-7095-6420 | > | 81366 M'nchen, Germany | GSM : +49-172-8933578 | > +-------------------------------+---------------------------------------+