Re: Database security
Posted in 1991
Path: emory!swrinde!zaphod.mps.ohio-state.edu!hobbes.physics.uiowa.edu!ns-mx!umaxc.weeg.uiowa.edu!durrell From: durrell@umaxc.weeg.uiowa.edu (Cyberpixie) Newsgroups: comp.databases.informix Message-ID: <8566@ns-mx.uiowa.edu> Date: 10 Oct 91 23:55:59 GMT References: <6170@jethro.Corp.Sun.COM> Sender: news@ns-mx.uiowa.edu Organization: Tragically Hip Road Trip In article <6170@jethro.Corp.Sun.COM> myro@srfrogs.Corp.Sun.COM writes: >What _may_ work is to turn on the setuid bit on for 4gl code. >If the theory holds up, then all changes made to the database >will be made by one user, which may ruin other parts of your >database security. For example it will be next to impossible to track >who made what changes, and it will make any individual permissions useless. A hack that's probably not worth the trouble: run the 4gl app from a shell script wrapper, and let the wrapper create a temp file with the user name in it before running the setuid 4gl code. It's simple enough to check the file for the user name in the initialization segment of the program; then add a column to keep the user name in. This is somewhat bad, since it increases the size of the database; however, you can get individual permissions and tracking this way. -- Bryant Durrell durrell@umaxc.weeg.uiowa.edu ------------------------------------------------------------------------------ Life is just like high school, but with better production values.