Re: [?] Assigning Informix as group/owner of apps?
Posted in 1994
> Subject: [?] Assigning Informix as group/owner of apps?
> Date: 9 Dec 1994 15:39:42 -0800
> Reply-To: cpilot@teleport.com (Richard Shannon)
> Organization: Teleport - Portland's Public Access (503) 220-1016
>
> Dear Net.Wisdom:
>
> I have two questions regarding Informix account usage in the unix
> environment.
>
> 1. Do you recommend using the Informix account to manage the database.
> ie. granting/revoking permissions, adding/dropping tables, dbload,
> etc.
No. Account/user informix should be reserved for installing software and,
in an OnLine environment, managing instances and dbspaces, and (optionally)
doing *initial* database creation.
>
> Would it be better to use a separate administrative account for this?
> Why?
Yes. The administrative account should be used for table creation, privilege
granting, etc. I usually use an account/user name of 'xxxxxdba' or 'dbaxxxxx'
where 'xxxxx' is the project name, abbreviated if necessary. If parts of
the database are logically owned by multiple departments, then you might want
to have 'dbamain', 'dbafinan', 'dbalegal', etc. Some folks prefer to leave
off the 'dba' from the names, and have the departmental DBA accounts be
'finance', 'legal', etc.
The DBA account(s) should NOT be the primary account of any particular user,
but should be used by any DBA qualified individual when "wearing the DBA hat".
This facilitates passing responsibility for DBA functions to new or replace-
ment staff. By doing this for ANSI mode databases, all programmers know the
correct owner name for all tables, views, etc., in the one DBA case, or the
owner shows logical relationships of tables, in the multi-department case.
This is much better than having some tables owned by 'smith', some by 'jones',
etc., with no particular reason except that those programmers created the
tables initially. By the way, how do you change permissions, etc., on a
table owned by 'smith' after Smith has left the company and his/her login
has been removed? The DBA could do "grant ... as smith". But since you must
have DBA privilege to do this, why not have the DBA own the tables directly?
>
> 2. What are the pros/cons/issues when using Informix as owner and group
> of all database applications and having all users being members of
> that group?
One of the major cons of having regular users in the informix group is that
it bypasses one part of the protections used by Informix for OnLine cooked
dbspaces or SE table files: Informix sets access to such files to 660,
with user and group ownership set to 'informix'. This effectively prevents
normal users from directly reading or writing the files containing the
database. This protection is gone if users are part of group informix.
I don't see any particular pros to having informix own anything other than
the system catalog tables. Some ownership issues were discussed under item
1. above.
>
> Thankyou in advance any and all comments!
>
> Todd Bernhardt
> Programmer
> Willamette Industries, Inc.
> cpilot@teleport.com
You're welcome. Happy holidays.
Regards,
Alan ___________________________
______________________| R. Alan Popiel |__________________________
\\ Internet: | Martin Marietta, SLS | /
\\ alan@den.mmc.com | P.O. Box 179, M/S 3810 | Std disclaimers apply. /
)Voice: | Denver, CO 80201-0179 USA | (
/ 303-977-9998 |___________________________| (But you knew that!) \\
/________________________) (____________________________\\