Seguridad
Posted in 2004
Topics: General Discussion
Saludos: Quisiera que me orienten respecto a la seguridad que se podria implementar para el servidor de base de datos. La idea de tener politicas de seguridad en un servidor de base de datos, no quiere decir que seamos el cuello de botella para los sistemas y aplicaciones que se encuentran en ella.. eso lo tengo claro. Pero mi interez es poder conocer la mejor y la mas optima politica de seguridad que me permita asegurar el servidor de base de datos asi como asegurar la alta disponibilidad de los sistemas y aplicaciones. Muchas gracias por su orientacion _________________________________________________________________ Consigue aqu' las mejores y mas recientes ofertas de trabajo en Am'rica Latina y USA: http://latam.msn.com/empleos/ sending to informix-list sending to informix-list
in4mix peru wrote: > Saludos: This news group (and the mailing list) operates primarily in English. > Quisiera que me orienten respecto a la seguridad que se podria > implementar para el servidor de base de datos. The BabelFish says: Greetings: It wanted that they orient to me with respect to the security that podria to implement itself for the database server. > La idea de tener politicas de seguridad en un servidor de base de datos, > no quiere decir que seamos el cuello de botella para los sistemas y > aplicaciones que se encuentran en ella.. eso lo tengo claro. Pero mi interez > es poder conocer la mejor y la mas optima politica de seguridad que me > permita asegurar el servidor de base de datos asi como asegurar la alta > disponibilidad de los sistemas y aplicaciones. The idea to have politicas of security in a database server, does not mean that we are the neck of bottle for the systems and applications that are in her. that I know it clearly. But my interez is to be able to know the best and but optimal politica security that allows me to assure the database server asi like assuring the high availability the systems and applications. > Muchas gracias por su orientacion Thank you very much by his orientacion. OK, translating the translation, I think that means, roughly: <JL-Translation-1> I need to find out about the security that the IDS product implements in the database server. Having security policies in the database server does not mean that they are the bottleneck for the applications and systems stored in the database server - that I understand. But I need to know the best and optimal security policies that allow me to ensure that the server will be available - for high availability systems and applications. </JL-Translation-1> Or, re-translating my first translation and simplifying grossly: <JL-Translation-2> How do I set up my IDS database server so that it will be always available? What security considerations are there? </JL-Translation-2> And there is no single, simple answer to that. It depends on a lot of details - such as how many machines you have, of what types, and what are the application requirements for failover, and what's the acceptable downtime, and so on. Without a lot more background information (in English if at all possible), then there is very little we can do to help you. You could consider HDR - it requires two substantially identical machines. You could consider ER. You could consider dual-ported disks. You could consider ... lots of different things. As to security, disable the programs which you don't use - remove the execute permissions on (SUID or SGID) programs from IDS which you are sure you don't use. There's a script, ibmifmx_security.sh to help do that. If you don't use SNMP, for example, remove the execute permission on the SNMP binaries. -- Jonathan Leffler #include <disclaimer.h> Email: jleffler@earthlink.net, jleffler@us.ibm.com Guardian of DBD::Informix v2003.04 -- http://dbi.perl.org/