Re: Restricting ODBC access
Posted in 1998
Someone once mentioned making the role name a secret, i.e. the name of the role itself becomes a sort of password which would be built into the applications. Does this not work? Michael Segel wrote: > > Dave Otto wrote: > > > Easy if you are running 7.1+. Use ROLES. If there is no default role > > defined, then the first the application must do is execute the > > "set role..." statement. Unless the user has access to a SQL > > command AND knows the appropriate role to set, s/he will be > > locked out. > > Uhmm, no, not so easy. > You said it yourself. > If you know what role to set, voila! > > Straight client/server with Informix isn't a very good idea. > > 1) Must have UNIX id and passwd for each user, > (That's if you want to use Informix to authenticate the user.) > > 2) PC must become trusted by system. > Forget .rhosts. Biggest security nightmare. > That means hosts.equiv. > Hosts equiv is literally just that. ;-) > > 3) You now must manage PCs and Users which can become a nightmare. > (You're not going to trust every user from the PC right? And you aren't > going to let them store the access info on their PC right?) > > 4) Limitations in choice of connecting platforms. > VB? Delphi? VC++? whatever? Guess what? They be all Microsloft access > clients. > > Now if you have smart cards, or smart rings, and or consider biometrics, > then > you have a touch more security. > > But you may still want to consider 3 tier approach to a design. > Web based client, or Java based client, with an app server. > Then you only have to trust the app server. > Smart card auth still applicable. > > Informix works better in a three tier environment. > > Just a few wise words from the paranoid man from UNCLE! > > -Mikey -- ---------------------------------------------------------------------- John H. Frantz Power-4gl: Extending Informix-4gl john@rl.is http://www.rl.is/~john/pow4gl.html