user can still connect after CONNECT privilege get revoked
Posted in 2005
Topics: Security, Permissions & Auditing
Hi, I have revoked the connect privilege from a user. The user is not admin. Still, the user can connect to the database. How to revoke the CONNECT privilege indeed from a user? How to check a user can't connect (e.g. catalog table or user setup) without letting the user try to connect? Thanks, Lan
lanegroups@go.com wrote:
> I have revoked the connect privilege from a user. The user is not
> admin. Still, the user can connect to the database.
>
> How to revoke the CONNECT privilege indeed from a user?
> How to check a user can't connect (e.g. catalog table or user setup)
> without letting the user try to connect?
Can PUBLIC connect? If so, anyone can.
SELECT * FROM informix.sysusers;
--
Jonathan Leffler #include <disclaimer.h>
Email: jleffler@earthlink.net, jleffler@us.ibm.com
Guardian of DBD::Informix v2005.01 -- http://dbi.perl.org/
CONNECT is revoked from PUBLIC as well:
U2 issed the following:
revoke CONNECT FROM U1;
REVOKE CONNECT FROM PUBLIC ;
U1 can still connect after that.
SELECT * FROM informix.sysusers;
username usertype priority password
-------------------------------- -------- -------- ----------------
informix D 9
U1 R 5
U2 D 5
Does the usertype for U1 has problem or anything else missing?
Thanks.
lanegroups@go.com wrote:
> CONNECT is revoked from PUBLIC as well:
> U2 issed the following:
> revoke CONNECT FROM U1;
> REVOKE CONNECT FROM PUBLIC ;>
> U1 can still connect after that.
>
> SELECT * FROM informix.sysusers;>
> username usertype priority password
> -------------------------------- -------- -------- ----------------
> informix D 9
> U1 R 5
> U2 D 5
>
> Does the usertype for U1 has problem or anything else missing?
U1 has resource (R); you have to do:
REVOKE RESOURCE FROM U1;-- U1 now only has CONNECT (C)
REVOKE CONNECT FROM U1;-- Now U1 only has PUBLIC privileges
-- And, since public doesn't have any, neither does U1.
--
Jonathan Leffler #include <disclaimer.h>
Email: jleffler@earthlink.net, jleffler@us.ibm.com
Guardian of DBD::Informix v2005.01 -- http://dbi.perl.org/