>Date: Mon, 13 Feb 1995 15:17:11 -0800 (PST)
>From: Informix Sysadmin <informix@asl3.asl-labs.bc.ca>
>X-Informix-List-Id: <list.5553>
>
>[...]
>
>On that note....is there a way to stop users from being able to kill an
>SQLTURBO process that has THEIR name on it? It sort of leaves our
>DATABASE hanging out in the wind if someone gets a little trigger happy
>with the KILL statement :(
Succinctly, No. It is a basic premise of Unix security that a user should
be able to send signals to their own processes. Even if the signals are
not sensible. Even if the signal is SIGKILL and the process should not be
sent SIGKILL signals.
If you are going to evade the problem, you have two choices.
(1) You can upgrade to 6.00 or above, where the one-engine-per-application
regime is replaced by server processes that are owned by user informix,
and are therefore immune to signals from unauthorised (non-root,
non-informix) users.
(2) You can develop an elaborate scheme which arranges that when a user
runs the engine, the actual UID used in the database is different from
the one used by regular Unix. Walt Hultgren (walt@rmy.emory.edu)
presented a paper on such a scheme -- you could contact him (or the
archives, no doubt) for the information. There are also variants of
that scheme which jigger the engine rather than the application, but
the basic idea remains the same. The downside of this is the nightmare
of maintaining two (or more) UIDs per actual user.
Yours,
Jonathan Leffler (johnl@informix.com) #include <disclaimer.h>