restricting creation of databases
Posted in 2003
Topics: General Discussion
Hello folks, I'm trying to find out if there is a way to restrict database creation via sql for users with connect and resource access. Basically, I'm supposed to be supporting an application that uses Informix and have to manually restore to another system. What I'm finding is that one particular user has learned how to create new databases outside the scope of the application and they are causing my restores to fail on my backup system since those tables are not part of the backup system when I do my restores. Any help in figuring out how to restrict either creation of databases in sql, creation of databases in general, or how to restrict what users can do in sql (isql) would be really great. Thanks in advance. I will summarize for the list. Javier Zayas System Administrator Claremont University Consortium javier.zayas@cuc.claremont.edu <mailto:javier.zayas@cuc.claremont.edu> http://www.cuc.claremont.edu <http://www.cuc.claremont.edu> (909)607-3143
You cannot restrict people from creating a database, except by restricting then from getting to the tools that allow creation of a database. What are you using for backup / restore? MW > -----Original Message----- > From: forum.subscriber@iiug.org [mailto:forum.subscriber@iiug.org]On > Behalf Of Javier Zayas > Sent: Thursday, 11 September 2003 11:10 a.m. > To: ids@iiug.org > Subject: restricting creation of databases [1824] > > > Hello folks, > > I'm trying to find out if there is a way to restrict database > creation via > sql for users with connect and resource access. Basically, > I'm supposed to > be supporting an application that uses Informix and have to > manually restore > to another system. What I'm finding is that one particular > user has learned > how to create new databases outside the scope of the > application and they > are causing my restores to fail on my backup system since > those tables are > not part of the backup system when I do my restores. Any help > in figuring > out how to restrict either creation of databases in sql, creation of > databases in general, or how to restrict what users can do in > sql (isql) > would be really great. Thanks in advance. I will summarize > for the list. > > Javier Zayas > System Administrator > Claremont University Consortium > javier.zayas@cuc.claremont.edu <mailto:javier.zayas@cuc.claremont.edu> http://www.cuc.claremont.edu <http://www.cuc.claremont.edu> (909)607-3143
If you are on 9.30 there's an ONCONFIG parameter DBCREATE_PERMISSION where you can specify which users can create databases. HTH Thanx much, Rajib Sarkar Advisory Software Engineer (RAS) IBM Data Management Group Ph : (602)-217-2100 Fax: (602)-217-2100 T/L : 667-2100 As long as you derive inner help and comfort from anything, keep it -- Mahatma Gandhi "Javier Zayas " <javier_zayas@cuc.cla To: ids@iiug.org remont.edu> cc: Sent by: Subject: restricting creation of databases [1824] forum.subscriber@iiug .org 09/10/2003 04:09 PM Hello folks, I'm trying to find out if there is a way to restrict database creation via sql for users with connect and resource access. Basically, I'm supposed to be supporting an application that uses Informix and have to manually restore to another system. What I'm finding is that one particular user has learned how to create new databases outside the scope of the application and they are causing my restores to fail on my backup system since those tables are not part of the backup system when I do my restores. Any help in figuring out how to restrict either creation of databases in sql, creation of databases in general, or how to restrict what users can do in sql (isql) would be really great. Thanks in advance. I will summarize for the list. Javier Zayas System Administrator Claremont University Consortium javier.zayas@cuc.claremont.edu <mailto:javier.zayas@cuc.claremont.edu> http://www.cuc.claremont.edu <http://www.cuc.claremont.edu> (909)607-3143
I know that 9.30 has this option as I've been able to search the archives and find that as a solution. However, when I try to use the same syntax in 7.3.1.UC4 it doesn't seem to do anything. Does anyone know if 7.x versions of IDS have this parameter available or if there is a similar parameter available for me to set. TIA Javier Zayas System Administrator x73143 -----Original Message----- From: Rajib Sarkar [mailto:rsarkar@us.ibm.com] Sent: Thursday, September 11, 2003 8:21 AM To: Javier Zayas Cc: forum.subscriber@iiug.org; ids@iiug.org Subject: Re: restricting creation of databases [1824] If you are on 9.30 there's an ONCONFIG parameter DBCREATE_PERMISSION where you can specify which users can create databases. HTH Thanx much, Rajib Sarkar Advisory Software Engineer (RAS) IBM Data Management Group Ph : (602)-217-2100 Fax: (602)-217-2100 T/L : 667-2100 As long as you derive inner help and comfort from anything, keep it -- Mahatma Gandhi "Javier Zayas " <javier_zayas@cuc.cla To: ids@iiug.org remont.edu> cc: Sent by: Subject: restricting creation of databases [1824] forum.subscriber@iiug .org 09/10/2003 04:09 PM Hello folks, I'm trying to find out if there is a way to restrict database creation via sql for users with connect and resource access. Basically, I'm supposed to be supporting an application that uses Informix and have to manually restore to another system. What I'm finding is that one particular user has learned how to create new databases outside the scope of the application and they are causing my restores to fail on my backup system since those tables are not part of the backup system when I do my restores. Any help in figuring out how to restrict either creation of databases in sql, creation of databases in general, or how to restrict what users can do in sql (isql) would be really great. Thanks in advance. I will summarize for the list. Javier Zayas System Administrator Claremont University Consortium javier.zayas@cuc.claremont.edu <mailto:javier.zayas@cuc.claremont.edu> http://www.cuc.claremont.edu <http://www.cuc.claremont.edu> (909)607-3143
Rajib's right; it is a comma separated list of user names:
DBCREATE_PERMISSION me,you,him,her,anon
Now JOE cannot create databases, only me, you, him, her and anon can do so.
Also applies to 9.40, of course. (I don't think it is in 7.31, but you can
try looking for DBCREATE_PERMISSION in the oninit binary; if you find it,
try it; if not, it probably won't work.)
--
Jonathan Leffler (jleffler@us.ibm.com)
STSM, Informix Database Engineering, IBM Data Management
4100 Bohannon Drive, Menlo Park, CA 94025
Tel: +1 650-926-6921 Tie-Line: 630-6921
"I don't suffer from insanity; I enjoy every minute of it!"
|---------+---------------------------->
| | Rajib |
| | Sarkar/Phoenix/IB|
| | M@IBMUS |
| | Sent by: |
| | forum.subscriber@|
| | iiug.org |
| | |
| | |
| | 09/11/2003 08:24 |
| | AM |
|---------+---------------------------->
>-------------------------------------------------------------------------------
--------------------------------------------------------------|
| |
| To: ids@iiug.org |
| cc: |
| Subject: Re: restricting creation of databases [1831] |
>-------------------------------------------------------------------------------
--------------------------------------------------------------|
If you are on 9.30 there's an ONCONFIG parameter DBCREATE_PERMISSION where
you can specify which users can create databases.
HTH
Thanx much,
Rajib Sarkar
Advisory Software Engineer (RAS)
IBM Data Management Group
Ph : (602)-217-2100
Fax: (602)-217-2100
T/L : 667-2100
As long as you derive inner help and comfort from anything, keep it --
Mahatma Gandhi
"Javier Zayas "
<javier_zayas@cuc.cla To: ids@iiug.org
remont.edu> cc:
Sent by: Subject: restricting
creation of databases [1824]
forum.subscriber@iiug
.org
09/10/2003 04:09 PM
Hello folks,
I'm trying to find out if there is a way to restrict database creation via
sql for users with connect and resource access. Basically, I'm supposed to
be supporting an application that uses Informix and have to manually
restore
to another system. What I'm finding is that one particular user has learned
how to create new databases outside the scope of the application and they
are causing my restores to fail on my backup system since those tables are
not part of the backup system when I do my restores. Any help in figuring
out how to restrict either creation of databases in sql, creation of
databases in general, or how to restrict what users can do in sql (isql)
would be really great. Thanks in advance. I will summarize for the list.
Javier Zayas
System Administrator
Claremont University Consortium
javier.zayas@cuc.claremont.edu <mailto:javier.zayas@cuc.claremont.edu>
http://www.cuc.claremont.edu <http://www.cuc.claremont.edu>
(909)607-3143