Re: Increase Security
Posted in 1995
In article <ian.goddard.33.0015B6E5@geo2.poptel.org.uk>, ian.goddard@geo2.poptel.org.uk (Ian Goddard) writes: >In article <46jsgo$rcm@cssun.mathcs.emory.edu> johnl@informix.com (Jonathan Leffler) writes: >>From: johnl@informix.com (Jonathan Leffler) >>Subject: Re: Increase Security >>Date: 24 Oct 1995 19:23:04 -0400 > >......... > >>The fundamental problem with any security system in SQL-based systems is >>that if UserA needs UPDATE privilege on TableB when using ProgramC, it is >>nearly impossible to prevent that user from updating TableB via DB-Access >>or ISQL as well. DBA-privileged stored procedures almost work -- but what >>happens if the user crashes the program which arranged for the privileges >>to be granted? Answer -- the privileges stay granted. The only possible >>exception might be if the database has transactions and the privileges are >>granted within an uncomitted transaction, but then do the privileges take >>effect for some other process; I doubt it. I don't have a solution for >>this problem. There is at least 1 way to fix this problem. Keek your own security based on the program that is being run rather table permissions. It is very easy to do and much more managable than Informix's grant/revoke. If you need more information, I can send it to you. >......... > >It seems to me that we need the client/server protocols to enable a client >*program* to identify itself in a manner which will be proof against tampering >(as far as this is possible) and will let the server check the client against >an approved list. As a by-product this would also enable the server lock out >incorrect versions of the clients. Whilst it's easy to define the >requirement, however, it's less easy to see how it might be met. Anyone got >any ideas? > Again, this can be done using the same thing. All you have to do is to make the program switch into another user once the first user is authenticated. I think newera can do this. Also, Informix 7.1 or 7.2 has a role future. I think it should do what you want. -- Dari Shirazi | Internet: dshirazi@uhl.uiowa.edu The University of Iowa - Hygienic Lab | Voice: (319) 335-4500 Oakdale Research Campus, OH-E5B | Fax: (319) 335-4555 Iowa City, IA 52242 |