Bug? Role Separation ... informix can't access...
Posted in 2008
Topics: Server Administration, Security, Permissions & Auditing
IDS 11.10 UC1de
Linux - OpenSuSE 10.2
This is not a big problem, I already got a simple work around, but the situation don't sense for me...
If anyone have a explanation for this...
I don't found anything on the manuals....
I had configured a database with full role separation :
USER / GROUP
- ix_aao / ix_aao
configured at group of $INFORMIXDIR/aaodir
- ix_dbsa / ix_dbsa
configured at group of $INFORMIXDIR/etc
- ix_dbsso / ix_dbsso
configured at group of $INFORMIXDIR/dbssodir
- * / ix_user
configured in file $INFORMIXDIR/dbssodir/seccfg
All works fine, except with user informix.
It is the unique user what can not open a session . If need execute any command on sysadmin I can't. But just add informix to "ix_user" and works...
My question, if ix_aao , ix_dbsa and ix_dbsso can access , why informix don't ???
Look the commands bellow, executed with super user (root) :
codsrv222:~ # id ix_dbsa
uid=1007(ix_dbsa) gid=1007(ix_dbsa) groups=1007(ix_dbsa)
codsrv222:~ # id ix_dbsso
uid=1005(ix_dbsso) gid=1005(ix_dbsso) groups=1005(ix_dbsso),16(dialout),33(video)
codsrv222:~ # id ix_aao
uid=1006(ix_aao) gid=1004(ix_aao) groups=1004(ix_aao),16(dialout),33(video)
codsrv222:~ # id cmartins
uid=1004(cmartins) gid=1006(ix_user) groups=1006(ix_user),16(dialout),33(video)
codsrv222:~ # id informix
uid=1000(informix) gid=1000(informix) groups=1000(informix)
codsrv222:~ #
codsrv222:~ #
codsrv222:~ # su - cmartins -c " echo \\"select * from sysdual\\" |dbaccess sysmaster"
Database selected.
dummy
X
1 row(s) retrieved.
Database closed.
codsrv222:~ #
codsrv222:~ # su - ix_aao -c " echo \\"select * from sysdual\\" |dbaccess sysmaster"
Database selected.
dummy
X
1 row(s) retrieved.
Database closed.
codsrv222:~ # su - ix_dbsso -c "echo \\"select * from sysdual\\" |dbaccess sysmaster"
Database selected.
dummy
X
1 row(s) retrieved.
Database closed.
codsrv222:~ # su - informix -c "echo \\"select * from sysdual\\" |dbaccess sysmaster"
25571: Cannot create a user thread.
Interrupted system call
codsrv222:~ #
codsrv222:~ # usermod -G ix_user informix
codsrv222:~ # id informix
uid=1000(informix) gid=1000(informix) groups=1000(informix),1006(ix_user)
codsrv222:~ #
codsrv222:~ # su - informix -c ". ./ids11.sh; echo \\"select * from sysdual\\" |dbaccess sysmaster"
Database selected.
dummy
X
1 row(s) retrieved.
Database closed.
codsrv222:~ #
Abra sua conta no Yahoo! Mail, o único sem limite de espaço para armazenamento!
http://br.mail.yahoo.com/
Cesar Inacio Martins wrote:
> IDS 11.10 UC1de
> Linux - OpenSuSE 10.2
>
> This is not a big problem, I already got a simple work around, but the
> situation don't sense for me...
> If anyone have a explanation for this...
> I don't found anything on the manuals....
> I had configured a database with full role separation :
>
> USER / GROUP
> - ix_aao / ix_aao
> configured at group of $INFORMIXDIR/aaodir
> - ix_dbsa / ix_dbsa
> configured at group of $INFORMIXDIR/etc
> - ix_dbsso / ix_dbsso
> configured at group of $INFORMIXDIR/dbssodir
> - * / ix_user
> configured in file $INFORMIXDIR/dbssodir/seccfg
>
> All works fine, except with user informix.
> It is the unique user what can not open a session . If need execute any
> command on sysadmin I can't. But just add informix to "ix_user" and
> works...
> My question, if ix_aao , ix_dbsa and ix_dbsso can access , why informix
> don't ???
It's mainly a (more or less known) bug. The only question is 'should
the AAO, DBSA and DBSSO also need to be in the users group, or should
informix be allowed in without being in the users group'? The most
likely fix is to let informix in like the AAO et al are let in. I
forget whether there's a bug for this in the system - I suspect so, but
I'm not sure.
I'm not clear from your diagram whether you have set the owners on the
'role-determining' directories to something other than informix. I
don't advise that - it is apt to lead to problems.
> Look the commands bellow, executed with super user (root) :
>
> codsrv222:~ # id ix_dbsa
> uid=1007(ix_dbsa) gid=1007(ix_dbsa) groups=1007(ix_dbsa)
> codsrv222:~ # id ix_dbsso
> uid=1005(ix_dbsso) gid=1005(ix_dbsso)
> groups=1005(ix_dbsso),16(dialout),33(video)
> codsrv222:~ # id ix_aao
> uid=1006(ix_aao) gid=1004(ix_aao) groups=1004(ix_aao),16(dialout),33(video)
> codsrv222:~ # id cmartins
> uid=1004(cmartins) gid=1006(ix_user)
> groups=1006(ix_user),16(dialout),33(video)
> codsrv222:~ # id informix
> uid=1000(informix) gid=1000(informix) groups=1000(informix)
> codsrv222:~ #
> codsrv222:~ #
> codsrv222:~ # su - cmartins -c " echo \\"select * from sysdual\\"
> |dbaccess sysmaster"
> Database selected.
>
> dummy
>
> X
>
> 1 row(s) retrieved.
>
> Database closed.
> codsrv222:~ #
> codsrv222:~ # su - ix_aao -c " echo \\"select * from sysdual\\" |dbaccess
> sysmaster"
> Database selected.
>
> dummy
>
> X
>
> 1 row(s) retrieved.
>
> Database closed.
> codsrv222:~ # su - ix_dbsso -c "echo \\"select * from sysdual\\"
> |dbaccess sysmaster"
> Database selected.
>
> dummy
>
> X
>
> 1 row(s) retrieved.
>
> Database closed.
> codsrv222:~ # su - informix -c "echo \\"select * from sysdual\\"
> |dbaccess sysmaster"
> 25571: Cannot create a user thread.>
> Interrupted system call
> codsrv222:~ #
> codsrv222:~ # usermod -G ix_user informix
> codsrv222:~ # id informix
> uid=1000(informix) gid=1000(informix) groups=1000(informix),1006(ix_user)
> codsrv222:~ #
> codsrv222:~ # su - informix -c ". ./ids11.sh; echo \\"select * from
> sysdual\\" |dbaccess sysmaster"
> Database selected.
>
> dummy
>
> X
>
> 1 row(s) retrieved.
>
> Database closed.
> codsrv222:~ #
--
Jonathan Leffler #include <disclaimer.h>
Email: jleffler@earthlink.net, jleffler@us.ibm.com
Guardian of DBD::Informix v2008.0229 -- http://dbi.perl.org/
publictimestamp.org/ptb/PTB-3261 tiger2 2008-05-17 03:00:03
6CAF6B5330213B6ED5BD79DD23E13E46C38719535D36B1F9