Re: Privileged Tasks
Posted in 2009
Topics: Server Administration
> Jonathan Leffler wrote > Sent: Saturday, February 28, 2009 6:14 PM > Connect permission is granted to the database by a DBA - that should > generally not be user informix (or user root). > > Table permissions can be granted by the table owner or a DBA - again, > that should not normally be user informix. > Nearly all the databases here are owned by informix just as the tables. What's wrong with it? Thanks to you and the others for your help. Reinhard
On Mar 1, 11:15 pm, "Habichtsberg, Reinhard" <RHabichtsb...@arz- emmendingen.de> wrote: > > Jonathan Leffler wrote > > Sent: Saturday, February 28, 2009 6:14 PM > > Connect permission is granted to the database by a DBA - that should > > generally not be user informix (or user root). > > > Table permissions can be granted by the table owner or a DBA - again, > > that should not normally be user informix. > > Nearly all the databases here are owned by informix just as the tables. > What's wrong with it? It mixes separable duties. Whether that matters depends mainly on the size of the organization. For larger organizations, it often does; for smaller ones, it may be irrelevant because there simply aren't enough people to separate the different duties. User informix should be used to administer IDS - if you aren't using role separation. However, administering IDS is different from administering a database within an IDS instance, so that should be done by a separate administrative user. However, if the same person is going to do both jobs, maybe it doesn't matter after all. Also, user informix is typically a shared account; it is harder to track who did what with such accounts. Hence avoid using shared accounts when you need auditability; hence, use role separation. But again, if it is all one person, then maybe it doesn't matter. I also think of user informix as similar to user root; I do as little as possible as root, because it is dangerous, and I do as little as possible as informix, because it can be dangerous. I usually don't know the informix password on my machine - someone else controls it (but I do use root privilege instead, sometimes, so it isn't completely clean). Yours, Jonathan Leffler