onstat -g sql
Posted in 2006
A site running IDS 10 wanted a user with DBA rights on a database (but not in the informix group) to run "onstat -g sql" to see running SQL. Answer: since 9.40xC4 those onstat options (-sql, -ses, -stm, -ssc) are restricted to DBSA users (user informix/group informix, i.e. the group owning $INFORMIXDIR/etc); setting the ONCONFIG parameter UNSECURE_ONSTAT to 1 re-opens them, but to everyone, not selectively per-database. A suggested SECURESTATG parameter was shown to be a documentation error (it doesn't exist), and Leffler/Greco warned that changing SUID/SGID permissions on onstat won't work, since onstat also checks real UID/GID for DBSA membership.
Auto-generated by DrWatson from the posts below — may be imperfect; read the full thread.
Topics: Server Administration
problem :
We have a user who has dba rights on his database.(Informix version 10)
He can execute the "onstat -u" command to see which users are active.
Now he's asking to have have the possibility to do "onstat -g sql" to see more
detailed what the users are doing.
This we can not allow (adding the user to informix-group) because of security.
Is there an another way to collect this kind of information via an
sql-statement on sysmaster tables ?
Kind regards,
Nadine
In v10 there is the onconfig parameter ...
UNSECURE_ONSTAT
If you set that to something other than 0 ... ie. 1, then onstat -g sql
will work the way it did prior to v9.40fc4 ... be aware that that will
open back up the onstat to all users ...
PDL
"NADINE DIEL...." <nadine.dieltjens@eds.com>
Sent by: ids-bounces@iiug.org
04/25/2006 11:31 AM
Please respond to
ids@iiug.org
To
ids@iiug.org
cc
Subject
onstat -g sql [6589]
problem :
We have a user who has dba rights on his database.(Informix version 10)
He can execute the "onstat -u" command to see which users are active.
Now he's asking to have have the possibility to do "onstat -g sql" to see
more
detailed what the users are doing.
This we can not allow (adding the user to informix-group) because of
security.
Is there an another way to collect this kind of information via an
sql-statement on sysmaster tables ?
Kind regards,
Nadine
*******************************************************************************
Forum Note: Use "Reply" to post a response in the discussion forum.
Hi ,
Also there is another configuration parameter SECURESTATG.
Set it to 0 so that all DBAs can run onstat commands to view running SQL
statements.
Regards,
Sobha
"NADINE DIEL...." <nadine.dieltjens@eds.com>
Sent by: ids-bounces@iiug.org
04/25/2006 09:01 PM
Please respond to
ids@iiug.org
To
ids@iiug.org
cc
Subject
onstat -g sql [6589]
problem :
We have a user who has dba rights on his database.(Informix version 10)
He can execute the "onstat -u" command to see which users are active.
Now he's asking to have have the possibility to do "onstat -g sql" to see
more
detailed what the users are doing.
This we can not allow (adding the user to informix-group) because of
security.
Is there an another way to collect this kind of information via an
sql-statement on sysmaster tables ?
Kind regards,
Nadine
*******************************************************************************
Forum Note: Use "Reply" to post a response in the discussion forum.
On 4/25/06, Sobha Rani .... <scheruku@in.ibm.com> wrote:
> Also there is another configuration parameter SECURESTATG.
> Set it to 0 so that all DBAs can run onstat commands to view running SQL
> statements.
Actually, no; the correct spelling of SECURESTAG is UNSECURE_ONSTAT.
And the reference to DBA should be DBSA - meaning (by default) user
informix and members of group informix. You can change the DBSA group
by changing the group that owns $INFORMIXDIR/etc - but do not do that
casually.
I just finished approving a doc note correction for that...
> "NADINE DIEL...." <nadine.dieltjens@eds.com>
>
> We have a user who has dba rights on his database.(Informix version 10)
> He can execute the "onstat -u" command to see which users are active.
> Now he's asking to have have the possibility to do "onstat -g sql" to see
> more detailed what the users are doing.
> This we can not allow (adding the user to informix-group) because of
> security.
> Is there an another way to collect this kind of information via an
> sql-statement on sysmaster tables ?
--
Jonathan Leffler #include <disclaimer.h>
Email: jleffler@earthlink.net, jleffler@us.ibm.com
Guardian of DBD::Informix v2005.02 -- http://dbi.perl.org/
Ask your unix administrater.
He can be constructive with the unix access rights 'sticky bit'.
-----Original Message-----
From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org]
Sent: 25 April 2006 17:31
To: ids@iiug.org
Subject: onstat -g sql [6589]
problem :
We have a user who has dba rights on his database.(Informix version 10)
He can execute the "onstat -u" command to see which users are active.
Now he's asking to have have the possibility to do "onstat -g sql" to see
more
detailed what the users are doing.
This we can not allow (adding the user to informix-group) because of
security.
Is there an another way to collect this kind of information via an
sql-statement on sysmaster tables ?
Kind regards,
Nadine
****************************************************************************
***
Forum Note: Use "Reply" to post a response in the discussion forum.
*****DISCLAIMER*****
Dit bericht en alle bijhorende zijn uitsluitend bestemd voor de geadresseerde
en
vertrouwelijk. Indien dit bericht niet voor U bestemd is, gelieve dit dan te
vernietigen en
de verzender te verwittigen. Openbaring, vermenigvuldiging, verspreiding en
verstrekking aan
derden is niet toegestaan, tenzij anders vermeld. Aangezien internet de
integriteit van dit
bericht niet kan verzekeren, kan de Dienst Vreemdelingenzaken niet
verantwoordelijk gesteld
worden indien dit bericht gewijzigd is.
Bezoek onze website: http://www.dofi.fgov.be
----------------------------------------
*****DISCLAIMER*****
Ce message et toutes les pieces jointes sont etablis a l'intention exclusive
de ses
destinataires et sont confidentiels. Si vous recevez ce message par erreur,
merci de le
detruire et d'en avertir l'expediteur. Toute utilisation de ce message non
conforme a sa
destination, toute diffusion ou toute publication, totale ou partielle, est
interdite, sauf
autorisation expresse. L'internet ne permettant pas d'assurer l'integrite de
ce message,
l'Office des Etrangers decline toute responsabilite au titre de ce message,
dans l'hypothese
ou il aurait ete modifie.
Visitez notre site web: http://www.dofi.fgov.be
Support Inf.... wrote:
> Ask your unix administrater.
> He can be constructive with the unix access rights 'sticky bit'.
I think you installed incorrectly your product, and are suggesting a very
slippery path anyway
>
> -----Original Message-----
> From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org]
> Sent: 25 April 2006 17:31
> To: ids@iiug.org
> Subject: onstat -g sql [6589]
>
> problem :
>
> We have a user who has dba rights on his database.(Informix version 10)
> He can execute the "onstat -u" command to see which users are active.
> Now he's asking to have have the possibility to do "onstat -g sql" to see
> more
> detailed what the users are doing.
> This we can not allow (adding the user to informix-group) because of
> security.
> Is there an another way to collect this kind of information via an
> sql-statement on sysmaster tables ?
>
> Kind regards,
>
> Nadine
>
--
Ciao,
Marco
______________________________________________________________________________
Marco Greco /UK /IBM Standard disclaimers apply!
Structured Query Scripting Language http://www.4glworks.com/sqsl.htm
4glworks http://www.4glworks.com
Informix on Linux http://www.4glworks.com/ifmxlinux.htm
Jonathan
Actually the manual has both documented.
Please explain how these work. I have tried the SECURESTATG and as
indicated by the manual this should allow users that have DBA to run
onstat. However this is not the case. I have tried with both set and
SECURESTATG has no effect if UNSECURE_ONSTAT is set. It would be nice=
to
let the users that have DBA on a database be able to view the onstat -g=
[sql stm ses ssc] on sessions that are using that database. It looks =
like
that is what they tried to do.
The following is from the 10.00.XC4 manuals.
1-70 IBM Informix Dynamic Server Administrator's Reference
SECURESTATG
onconfig.std value 1
possible values
0 =3D All database administrators can run onstat
commands to view running SQL statements.
1 =3D Users with GRANT DBA access to a database
cannot run onstat commands to view running SQL
statements.
takes effect When the database server is shut down and
restarted
refer to IBM Informix Administrator's Guide
The onstat commands that show the SQL statement text that is executing =
on a
session are normally restricted to DBA users. To remove this restrictio=
n,
set the
UNSECURE_ONSTAT configuration parameter to 1. Onstat commands that show=
SQL statements include the onstat -ses, onstat -stm, onstat -ssc, and
onstat -sql.
IBM Informix Dynamic Server Getting Started Guide
Chapter 2. Using New Features in Dynamic Server 2-7
UNSECURE_ONSTAT Configuration ParameterThe onstat commands that show SQL statement text being executed by a
session
are normally restricted to DBA users. This restriction can be removed b=
y
setting the
UNSECURE_ONSTAT configuration parameter to 1. For example, the onstat -=
ses,
onstat -stm, onstat -ssc, and onstat -sql commands show SQL statement t=
ext.onconfig.std value
not set
possible values 1
takes effect when the database server is shut down and restarted
=
=20
"Jonathan Le...." =
=20
<jleffler.iiug@gm =
=20
ail.com> =
To=20
Sent by: ids@iiug.org =
=20
ids-bounces@iiug. =
cc=20
org =
=20
Subj=
ect=20
Re: onstat -g sql [6600] =
=20
04/27/2006 06:16 =
=20
AM =
=20
=
=20
=
=20
Please respond to =
=20
ids@iiug.org =
=20
=
=20
=
=20
On 4/25/06, Sobha Rani .... <scheruku@in.ibm.com> wrote:
> Also there is another configuration parameter SECURESTATG.
> Set it to 0 so that all DBAs can run onstat commands to view running =
SQL
> statements.
Actually, no; the correct spelling of SECURESTAG is UNSECURE_ONSTAT.
And the reference to DBA should be DBSA - meaning (by default) user
informix and members of group informix. You can change the DBSA group
by changing the group that owns $INFORMIXDIR/etc - but do not do that
casually.
I just finished approving a doc note correction for that...
> "NADINE DIEL...." <nadine.dieltjens@eds.com>
>
> We have a user who has dba rights on his database.(Informix version 1=
0)
> He can execute the "onstat -u" command to see which users are active.=
> Now he's asking to have have the possibility to do "onstat -g sql" to=
see
> more detailed what the users are doing.
> This we can not allow (adding the user to informix-group) because of
> security.
> Is there an another way to collect this kind of information via an
> sql-statement on sysmaster tables ?
--
Jonathan Leffler #include <disclaimer.h>
Email: jleffler@earthlink.net, jleffler@us.ibm.com
Guardian of DBD::Informix v2005.02 -- http://dbi.perl.org/
***********************************************************************=
********
Forum Note: Use "Reply" to post a response in the discussion forum.
=
>Support Inf.... wrote:
>> Ask your unix administrater.
>> He can be constructive with the unix access rights 'sticky bit'.
>I think you installed incorrectly your product, and are suggesting a very
>slippery path anyway
I do not say : change the way the product is installed.
I just suggested to be constructive, add something like
-r-xr-s--- informix users_group onstat2 --> /usr/informix/bin/onstat
>
> -----Original Message-----
> From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org]
> Sent: 25 April 2006 17:31
> To: ids@iiug.org
> Subject: onstat -g sql [6589]
>
> problem :
>
> We have a user who has dba rights on his database.(Informix version 10)
> He can execute the "onstat -u" command to see which users are active.
> Now he's asking to have have the possibility to do "onstat -g sql" to see
> more
> detailed what the users are doing.
> This we can not allow (adding the user to informix-group) because of
> security.
> Is there an another way to collect this kind of information via an
> sql-statement on sysmaster tables ?
>
> Kind regards,
>
> Nadine
>
--
Ciao,
Marco
____________________________________________________________________________
__
Marco Greco /UK /IBM Standard disclaimers apply!
Structured Query Scripting Language http://www.4glworks.com/sqsl.htm
4glworks http://www.4glworks.com
Informix on Linux http://www.4glworks.com/ifmxlinux.htm
****************************************************************************
***
Forum Note: Use "Reply" to post a response in the discussion forum.
*****DISCLAIMER*****
Dit bericht en alle bijhorende zijn uitsluitend bestemd voor de geadresseerde
en
vertrouwelijk. Indien dit bericht niet voor U bestemd is, gelieve dit dan te
vernietigen en
de verzender te verwittigen. Openbaring, vermenigvuldiging, verspreiding en
verstrekking aan
derden is niet toegestaan, tenzij anders vermeld. Aangezien internet de
integriteit van dit
bericht niet kan verzekeren, kan de Dienst Vreemdelingenzaken niet
verantwoordelijk gesteld
worden indien dit bericht gewijzigd is.
Bezoek onze website: http://www.dofi.fgov.be
----------------------------------------
*****DISCLAIMER*****
Ce message et toutes les pieces jointes sont etablis a l'intention exclusive
de ses
destinataires et sont confidentiels. Si vous recevez ce message par erreur,
merci de le
detruire et d'en avertir l'expediteur. Toute utilisation de ce message non
conforme a sa
destination, toute diffusion ou toute publication, totale ou partielle, est
interdite, sauf
autorisation expresse. L'internet ne permettant pas d'assurer l'integrite de
ce message,
l'Office des Etrangers decline toute responsabilite au titre de ce message,
dans l'hypothese
ou il aurait ete modifie.
Visitez notre site web: http://www.dofi.fgov.be
On 4/27/06, Support Inf.... <supinformix@dofi.fgov.be> wrote:
>
> >Support Inf.... wrote:
> >> Ask your unix administrater.
> >> He can be constructive with the unix access rights 'sticky bit'.
>
> >I think you installed incorrectly your product, and are suggesting a very
> >slippery path anyway
>
> I do not say : change the way the product is installed.
> I just suggested to be constructive, add something like
> -r-xr-s--- informix users_group onstat2 --> /usr/informix/bin/onstat
>
The permissions need to be SGID informix (or maybe SUID informix) to
connect to shared memory. What is suggested here won't help for sure
- be extremely careful modifying permissions on IDS utilities. I do
occasionally suggest you can make minor changes, but it is rather
seldom and usually much smaller than changing the group - unless you
are simply disabling the command.
> >
> > -----Original Message-----
> > From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org]
> > Sent: 25 April 2006 17:31
> > To: ids@iiug.org
> > Subject: onstat -g sql [6589]
> >
> > problem :
> >
> > We have a user who has dba rights on his database.(Informix version 10)
> > He can execute the "onstat -u" command to see which users are active.
> > Now he's asking to have have the possibility to do "onstat -g sql" to see
> > more
> > detailed what the users are doing.
> > This we can not allow (adding the user to informix-group) because of
> > security.
> > Is there an another way to collect this kind of information via an
> > sql-statement on sysmaster tables ?
--
Jonathan Leffler #include <disclaimer.h>
Email: jleffler@earthlink.net, jleffler@us.ibm.com
Guardian of DBD::Informix v2005.02 -- http://dbi.perl.org/
Support Inf.... wrote:
>>Support Inf.... wrote:
>>
>>>Ask your unix administrater.
>>>He can be constructive with the unix access rights 'sticky bit'.
>>
>
>>I think you installed incorrectly your product, and are suggesting a very
>>slippery path anyway
>
>
> I do not say : change the way the product is installed.
> I just suggested to be constructive, add something like
> -r-xr-s--- informix users_group onstat2 --> /usr/informix/bin/onstat
correct ownership & permissions for onstat:
marco@dolcetto:~$ cd $INFORMIXDIR/bin
marco@dolcetto:/usr4/products/9.40.UC4W4/bin$ ls -l onstat
-rwxr-sr-x 1 informix informix 7335668 Jul 1 2004 onstat
marco@dolcetto:/usr4/products/9.40.UC4W4/bin$
hence, if you feel the need to add the set groupid bit to onstat (which will
not actually solve the issue at hand), then you have installed the product
incorrectly. Or rephrased, your onstat doesn't have the correct pemissions,
and I would be very much surprised to learn that it manages to connect to
shared memory, unless your oninit permissions are wrong too...
<PEDANTIC>
BTW, if you RTFM (chmod (2)) you'll discover that the sticky bit is something
else, plus you seem to imply that you are (sym)linking files - which will
actually not give you different ownership and permissions
</PEDANTIC>
>
>
>>-----Original Message-----
>>From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org]
>>Sent: 25 April 2006 17:31
>>To: ids@iiug.org
>>Subject: onstat -g sql [6589]
>>
>>problem :
>>
>>We have a user who has dba rights on his database.(Informix version 10)
>>He can execute the "onstat -u" command to see which users are active.
>>Now he's asking to have have the possibility to do "onstat -g sql" to see
>>more
>>detailed what the users are doing.
>>This we can not allow (adding the user to informix-group) because of
>>security.
>>Is there an another way to collect this kind of information via an
>>sql-statement on sysmaster tables ?
>>
>>Kind regards,
>>
>>Nadine
>>
>
>
--
Ciao,
Marco
______________________________________________________________________________
Marco Greco /UK /IBM Standard disclaimers apply!
Structured Query Scripting Language http://www.4glworks.com/sqsl.htm
4glworks http://www.4glworks.com
Informix on Linux http://www.4glworks.com/ifmxlinux.htm
On 4/27/06, Marco Greco <marco@4glworks.com> wrote:
> Support Inf.... wrote:
> >>Support Inf.... wrote:
> >>>Ask your unix administrater.
> >>>He can be constructive with the unix access rights 'sticky bit'.
> >
> >>I think you installed incorrectly your product, and are suggesting a very
> >>slippery path anyway
> >
> > I do not say : change the way the product is installed.
> > I just suggested to be constructive, add something like
> > -r-xr-s--- informix users_group onstat2 --> /usr/informix/bin/onstat
>
> correct ownership & permissions for onstat:
>
> marco@dolcetto:~$ cd $INFORMIXDIR/bin
> marco@dolcetto:/usr4/products/9.40.UC4W4/bin$ ls -l onstat
> -rwxr-sr-x 1 informix informix 7335668 Jul 1 2004 onstat
> marco@dolcetto:/usr4/products/9.40.UC4W4/bin$
>
> hence, if you feel the need to add the set groupid bit to onstat (which will
> not actually solve the issue at hand), then you have installed the product
> incorrectly. Or rephrased, your onstat doesn't have the correct pemissions,
> and I would be very much surprised to learn that it manages to connect to
> shared memory, unless your oninit permissions are wrong too...
>
> <PEDANTIC>
> BTW, if you RTFM (chmod (2)) you'll discover that the sticky bit is something
> else, plus you seem to imply that you are (sym)linking files - which will
> actually not give you different ownership and permissions
> </PEDANTIC>
Over and above what Marco just said, and I said in my previous
response, changing the group from informix won't help. Although Unix
will let the users run the command, and if you made it SUID informix,
it would probably be able to connect to the shared memory, it also do
another check - to ensure that the user is recorded in the system
databases (password file, group file) as a member of the DBSA group.
If the real UID and real GID(s) do not match, you will not be allowed
to run the program - onstat will say something along the lines of
'must be a DBSA to run this program'.
> >>-----Original Message-----
> >>From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org]
> >>Sent: 25 April 2006 17:31
> >>To: ids@iiug.org
> >>Subject: onstat -g sql [6589]
> >>
> >>problem :
> >>
> >>We have a user who has dba rights on his database.(Informix version 10)
> >>He can execute the "onstat -u" command to see which users are active.
> >>Now he's asking to have have the possibility to do "onstat -g sql" to see
> >>more
> >>detailed what the users are doing.
> >>This we can not allow (adding the user to informix-group) because of
> >>security.
> >>Is there an another way to collect this kind of information via an
> >>sql-statement on sysmaster tables ?
> >>
> >>Kind regards,
> >>
> >>Nadine
> >>
> >
> >
>
> --
> Ciao,
> Marco
>
______________________________________________________________________________
> Marco Greco /UK /IBM Standard disclaimers apply!
>
> Structured Query Scripting Language http://www.4glworks.com/sqsl.htm
> 4glworks http://www.4glworks.com
> Informix on Linux http://www.4glworks.com/ifmxlinux.htm
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
--
Jonathan Leffler #include <disclaimer.h>
Email: jleffler@earthlink.net, jleffler@us.ibm.com
Guardian of DBD::Informix v2005.02 -- http://dbi.perl.org/
On 4/27/06, kernoal.ste.... <kernoal.stephens@autozone.com> wrote:
>
> Jonathan
>
> Actually the manual has both documented.
The reference to SECURESTATG is bogus - the parameter does not exist in IDS.
Try: strings $INFORMIXDIR/bin/oninit | egrep 'SECURESTATG|UNSECURE_ONSTAT'
> Please explain how these work. I have tried the SECURESTATG and as
> indicated by the manual this should allow users that have DBA to run
> onstat. However this is not the case. I have tried with both set and
> SECURESTATG has no effect if UNSECURE_ONSTAT is set. It would be nice
> to let the users that have DBA on a database be able to view the onstat -g
> [sql stm ses ssc] on sessions that are using that database. It looks
> like that is what they tried to do.
That is not readily manageable - it certainly isn't what is done.
> The following is from the 10.00.XC4 manuals.
>
> 1-70 IBM Informix Dynamic Server Administrator's Reference
>
> SECURESTATG
I know about that section - it is wrong.
> IBM Informix Dynamic Server Getting Started Guide
> Chapter 2. Using New Features in Dynamic Server 2-7
>
> UNSECURE_ONSTAT Configuration Parameter> The onstat commands that show SQL statement text being executed by a
> session
> are normally restricted to DBA users.
I was not aware of that section - and it is marginally wrong too.
'DBA users' should be DBSA users.
> On 4/25/06, Sobha Rani .... <scheruku@in.ibm.com> wrote:
> > Also there is another configuration parameter SECURESTATG.
> > Set it to 0 so that all DBAs can run onstat commands to view running
> > SQL statements.
>
> Actually, no; the correct spelling of SECURESTAG is UNSECURE_ONSTAT.
>
> And the reference to DBA should be DBSA - meaning (by default) user
> informix and members of group informix. You can change the DBSA group
> by changing the group that owns $INFORMIXDIR/etc - but do not do that
> casually.
>
> I just finished approving a doc note correction for that...
>
> > "NADINE DIEL...." <nadine.dieltjens@eds.com>
> >
> > We have a user who has dba rights on his database.(Informix version 10)
> > He can execute the "onstat -u" command to see which users are active.
> > Now he's asking to have have the possibility to do "onstat -g sql" to see
> > more detailed what the users are doing.
> > This we can not allow (adding the user to informix-group) because of
> > security.
> > Is there an another way to collect this kind of information via an
> > sql-statement on sysmaster tables ?
--
Jonathan Leffler #include <disclaimer.h>
Email: jleffler@earthlink.net, jleffler@us.ibm.com
Guardian of DBD::Informix v2005.02 -- http://dbi.perl.org/
Jonathan,
I did the strings $INFORMIXDIR/bin/oninit | egrep
'SECURESTATG|UNSECURE_ONSTAT'
none of the words showed up. I know UNSECURE_ONSTAT works I have tested
that one.
Why is it not listed as part of the strings output?
Is SECURESTATG part of a future release?
Here is my version information
oninit -versionProgram Name: oninit
Build Version: 10.00.FC4
Build Number: N204
Build Host: ibm6c1b
Build OS: AIX 5.2
Build Date: Fri Nov 18 23:51:41 CST 2005
GLS Version: glslib-4.00.FC7
onstat -versionProgram Name: onstat
Build Version: 10.00.FC4
Build Number: N204
Build Host: ibm6c1b
Build OS: AIX 5.2
Build Date: Fri Nov 18 23:54:46 CST 2005
GLS Version: glslib-4.00.FC7
"Jonathan Le...."
<jleffler.iiug@gm
ail.com> To
Sent by: ids@iiug.org
ids-bounces@iiug. cc
org
Subject
Re: onstat -g sql [6610]
04/27/2006 11:04
AM
Please respond to
ids@iiug.org
On 4/27/06, kernoal.ste.... <kernoal.stephens@autozone.com> wrote:
>
> Jonathan
>
> Actually the manual has both documented.
The reference to SECURESTATG is bogus - the parameter does not exist in
IDS.
Try: strings $INFORMIXDIR/bin/oninit | egrep 'SECURESTATG|UNSECURE_ONSTAT'
> Please explain how these work. I have tried the SECURESTATG and as
> indicated by the manual this should allow users that have DBA to run
> onstat. However this is not the case. I have tried with both set and
> SECURESTATG has no effect if UNSECURE_ONSTAT is set. It would be nice
> to let the users that have DBA on a database be able to view the onstat
-g
> [sql stm ses ssc] on sessions that are using that database. It looks
> like that is what they tried to do.
That is not readily manageable - it certainly isn't what is done.
> The following is from the 10.00.XC4 manuals.
>
> 1-70 IBM Informix Dynamic Server Administrator's Reference
>
> SECURESTATG
I know about that section - it is wrong.
> IBM Informix Dynamic Server Getting Started Guide
> Chapter 2. Using New Features in Dynamic Server 2-7
>
> UNSECURE_ONSTAT Configuration Parameter> The onstat commands that show SQL statement text being executed by a
> session
> are normally restricted to DBA users.
I was not aware of that section - and it is marginally wrong too.
'DBA users' should be DBSA users.
> On 4/25/06, Sobha Rani .... <scheruku@in.ibm.com> wrote:
> > Also there is another configuration parameter SECURESTATG.
> > Set it to 0 so that all DBAs can run onstat commands to view running
> > SQL statements.
>
> Actually, no; the correct spelling of SECURESTAG is UNSECURE_ONSTAT.
>
> And the reference to DBA should be DBSA - meaning (by default) user
> informix and members of group informix. You can change the DBSA group
> by changing the group that owns $INFORMIXDIR/etc - but do not do that
> casually.
>
> I just finished approving a doc note correction for that...
>
> > "NADINE DIEL...." <nadine.dieltjens@eds.com>
> >
> > We have a user who has dba rights on his database.(Informix version 10)
> > He can execute the "onstat -u" command to see which users are active.
> > Now he's asking to have have the possibility to do "onstat -g sql" to
see
> > more detailed what the users are doing.
> > This we can not allow (adding the user to informix-group) because of
> > security.
> > Is there an another way to collect this kind of information via an
> > sql-statement on sysmaster tables ?
--
Jonathan Leffler #include <disclaimer.h>
Email: jleffler@earthlink.net, jleffler@us.ibm.com
Guardian of DBD::Informix v2005.02 -- http://dbi.perl.org/
*******************************************************************************
Forum Note: Use "Reply" to post a response in the discussion forum.
Try, strings -a oninit | egrep 'SECURESTATG|UNSECURE_ONSTAT'
Thanks
Jena...
=
"kernoal.ste...." =
<kernoal.stephens =
@autozone.com> =
To
Sent by: ids@iiug.org =
ids-bounces@iiug. =
cc
org =
Subj=
ect
Re: onstat -g sql [6611] =
04/27/2006 11:46 =
AM =
=
=
Please respond to =
ids@iiug.org =
=
=
Jonathan,
I did the strings $INFORMIXDIR/bin/oninit | egrep
'SECURESTATG|UNSECURE_ONSTAT'
none of the words showed up. I know UNSECURE_ONSTAT works I have tested=
that one.
Why is it not listed as part of the strings output?
Is SECURESTATG part of a future release?
Here is my version information
oninit -versionProgram Name: oninit
Build Version: 10.00.FC4
Build Number: N204
Build Host: ibm6c1b
Build OS: AIX 5.2
Build Date: Fri Nov 18 23:51:41 CST 2005
GLS Version: glslib-4.00.FC7
onstat -versionProgram Name: onstat
Build Version: 10.00.FC4
Build Number: N204
Build Host: ibm6c1b
Build OS: AIX 5.2
Build Date: Fri Nov 18 23:54:46 CST 2005
GLS Version: glslib-4.00.FC7
"Jonathan Le...."
<jleffler.iiug@gm
ail.com> To
Sent by: ids@iiug.org
ids-bounces@iiug. cc
org
Subject
Re: onstat -g sql [6610]
04/27/2006 11:04
AM
Please respond to
ids@iiug.org
On 4/27/06, kernoal.ste.... <kernoal.stephens@autozone.com> wrote:
>
> Jonathan
>
> Actually the manual has both documented.
The reference to SECURESTATG is bogus - the parameter does not exist in=
IDS.
Try: strings $INFORMIXDIR/bin/oninit | egrep 'SECURESTATG|UNSECURE_ONST=
AT'
> Please explain how these work. I have tried the SECURESTATG and as
> indicated by the manual this should allow users that have DBA to run
> onstat. However this is not the case. I have tried with both set and
> SECURESTATG has no effect if UNSECURE_ONSTAT is set. It would be nice=
> to let the users that have DBA on a database be able to view the onst=
at
-g
> [sql stm ses ssc] on sessions that are using that database. It looks
> like that is what they tried to do.
That is not readily manageable - it certainly isn't what is done.
> The following is from the 10.00.XC4 manuals.
>
> 1-70 IBM Informix Dynamic Server Administrator's Reference
>
> SECURESTATG
I know about that section - it is wrong.
> IBM Informix Dynamic Server Getting Started Guide
> Chapter 2. Using New Features in Dynamic Server 2-7
>
> UNSECURE_ONSTAT Configuration Parameter> The onstat commands that show SQL statement text being executed by a
> session
> are normally restricted to DBA users.
I was not aware of that section - and it is marginally wrong too.
'DBA users' should be DBSA users.
> On 4/25/06, Sobha Rani .... <scheruku@in.ibm.com> wrote:
> > Also there is another configuration parameter SECURESTATG.
> > Set it to 0 so that all DBAs can run onstat commands to view runnin=
g
> > SQL statements.
>
> Actually, no; the correct spelling of SECURESTAG is UNSECURE_ONSTAT.
>
> And the reference to DBA should be DBSA - meaning (by default) user
> informix and members of group informix. You can change the DBSA group=
> by changing the group that owns $INFORMIXDIR/etc - but do not do that=
> casually.
>
> I just finished approving a doc note correction for that...
>
> > "NADINE DIEL...." <nadine.dieltjens@eds.com>
> >
> > We have a user who has dba rights on his database.(Informix version=
10)
> > He can execute the "onstat -u" command to see which users are activ=
e.
> > Now he's asking to have have the possibility to do "onstat -g sql" =
to
see
> > more detailed what the users are doing.
> > This we can not allow (adding the user to informix-group) because o=
f
> > security.
> > Is there an another way to collect this kind of information via an
> > sql-statement on sysmaster tables ?
--
Jonathan Leffler #include <disclaimer.h>
Email: jleffler@earthlink.net, jleffler@us.ibm.com
Guardian of DBD::Informix v2005.02 -- http://dbi.perl.org/
***********************************************************************=
********
Forum Note: Use "Reply" to post a response in the discussion forum.
***********************************************************************=
********
Forum Note: Use "Reply" to post a response in the discussion forum.
=