managing users
Posted in 1999
Topics: Security, Permissions & Auditing
Question. How do people usually manage user ids for a database application. Say I have an OLTP system that has hundreds of "user accounts" that may be used to connect and do various types of work. Seems that I have two basic alternatives: 1) Create a UNIX login/passwd for each and every user and let them use that to identify themselves to the database. The database could grant various permissions based these user names 2) Let them all use a common uid/password for purposes of database connections, and have an application specific table of user names and passwords that is managed by the application to control access and keep records. I am curious as to how other people have approached this problem in other applications. Have you used option 1, 2 or some other? What were the benefits and drawbacks you experienced? For various reasons, I am drawn to option #2. I'd be happy to discuss why in future posts, if anybody cares to go over this topic... Thanks. Also - is there a better newsgroup for a general question such as this? There isn't anything Informix specific about this question, just that I'm using IUS to build this application... ============================================================ Roger S. Reynolds email: rsr@rogerware.com rsr@softix.com Web: http://www.rogerware.com
Another alternative is to use proxy account(s) for actual system access and manage user accounts and passwords at the application or business logic level. Roger S Reynolds wrote in message <6aou2.177$s%4.620@news6.ispnews.com>... >Question. > >How do people usually manage user ids for a database application. >Say I have an OLTP system that has hundreds of "user accounts" that may >be used to connect and do various types of work. >Seems that I have two basic alternatives: >1) Create a UNIX login/passwd for each and every user and let them use > that to identify themselves to the database. > The database could grant various permissions based these user names >2) Let them all use a common uid/password for purposes of database >connections, > and have an application specific table of user names and passwords that > is managed by the application to control access and keep records. > >I am curious as to how other people have approached this problem in other >applications. Have you used option 1, 2 or some other? >What were the benefits and drawbacks you experienced? > >For various reasons, I am drawn to option #2. I'd be happy to discuss why >in future posts, if anybody cares to go over this topic... > >Thanks. > >Also - is there a better newsgroup for a general question such as this? >There isn't anything Informix specific about this question, just that I'm >using >IUS to build this application... > >============================================================ >Roger S. Reynolds >email: rsr@rogerware.com rsr@softix.com > Web: http://www.rogerware.com > > >