Still no luck with permissions
Posted in 1992
>Subject: Still no luck with permissions, and GRANT/REVOKE >X-Informix-List-Id: <newsgate.670> > >From: dvadura@plg.uwaterloo.ca (Dennis Vadura) >Newsgroups: comp.databases.informix >Message-ID: <1992Jan22.204806.11926@watmath.waterloo.edu> >Date: 22 Jan 92 20:48:06 GMT >Sender: news@watmath.waterloo.edu (News Owner) >Organization: Computer Science Dept., University of Waterloo >Originator: dvadura@plg.waterloo.edu > >Ok, perhaps someone can help me here. I am still stuck with correctly >setting up access perms for my database. I have a Sun IPX, with version >4.10.UC1 of the engine, and version 4.00.UH1 of the compiler. What I want >is to have several users access the database without having to set their >effective user id's to that of the owner of the database files. I thought >that the whole purpose of grant/revoke was to allow this to be the case. > >Suppose I have the following: > >MODE ANSI database in /u/database/live >DBPATH set to /u/database/live > >permissions on the directories are as follows: > > path: owner: perm: > /u/database/live informix 750 > /u/database informix 750 > /u root 755 And the group permissions? These are more important than the owner! permissions on /u are fine. The permissions on /u/database etc, should be as below. Use ls -lg if you're on a heathen system (BSD, SunOS, etc) to check your group ownership. File Owner Group Perms /u/database xyz pqr 751 /u/database/live xyz pqr 751 Or: File Owner Group Perms /u/database xyz informix 750 /u/database/live xyz informix 750 xyz and pqr can be anybody you like. The important part is that either the directories are in group informix or world has execute permission on the directories. The database is accessed by sqlexec. sqlexec runs with UID = user running it and EGID = informix. Unless you happen to own a directory somewhere in the path, the important thing is that GROUP informix must be able to access a file in the database directory, specifically /u/database/live/thingy.dbs/systables.* NB: no-one except user informix should be logged into group informix, or have group informix as one of their supplementary groups. It blows any security if they do! See also "Using Informix-SQL" by me for another explanation. It's published by Addison-Wesley. Ooops, sorry, that's a commercial. Jonathan Leffler (johnl@obelix)