Allowing "mere mortals" to run onstat settings
Posted in 2005
Topics: Platform-Specific Issues
Informix 9.4FC6 on AIX 5.3...
I've had requests for mere mortals, (and a few automated monitoring
programs) to run onstat commands. I've been poking around the online
docs for a few hours and have found a reference to the DBSA group. The
DBSA group is set to informix by default. Is this a linux/aix group?
Is it possible to add other linux/aix groups to DBSA to give controlled
access to the onstat commands? If not, what is the most secure way to
do this?
TIA. Dave Thacker
On
10/25/05, Dave Thacker <dthacker@omnicorporate.com> wrote:
>
> Informix 9.4FC6 on AIX 5.3...
>
> I've had requests for mere mortals, (and a few automated monitoring
> programs) to run onstat commands. I've been poking around the online
> docs for a few hours and have found a reference to the DBSA group. The
> DBSA group is set to informix by default. Is this a linux/aix group?
> Is it possible to add other linux/aix groups to DBSA to give controlled
> access to the onstat commands? If not, what is the most secure way to
> do this?
The DBSA group is the group that owns $INFORMIXDIR/etc.
By default, that group is 'informix'. If you decide that group 'staff'
should own $INFORMXDIR/etc, then anybody who is in group 'staff' will be
able to administer your server. This is probably not a good idea - you want
a special group to be in charge.
This business of who can use 'onstat' is a nuisance. We're going to need a
better solution than the current one, which is to use the ONCONFIG variable
UNSECURE_ONSTAT to restore the status quo ante. Some people need to prevent
Joe Q Random from looking at other people's SQL statements; others do not
realize that they need to do so, and a few others actually do not really
need to do so.
--
Jonathan Leffler #include <disclaimer.h>
Email: jleffler@earthlink.net, jleffler@us.ibm.com
Guardian of DBD::Informix v2005.02 -- http://dbi.perl.org/
Jonathan is right; there needs to be a better way...
What I do is create "special manager scripts" for our managing customers
that write everything from logs to onstat output to temp files and let
them play via a captive user interface with appropriate traps to exit if
they get out of the program.
This allows unskilled and semiskilled managers to look, but not touch,
real files and commands. It also keeps the inquisitive at bay.
As to safeguarding each others SQLs, well, that is a management
decision. :)
Rob
-----Original Message-----
From: forum.subscriber@iiug.org [mailto:forum.subscriber@iiug.org] On
Behalf Of Jonathan Le....
Sent: Tuesday, October 25, 2005 8:41 PM
To: ids@iiug.org
Subject: Re: Allowing "mere mortals" to run onstat settings [5916]
On 10/25/05, Dave Thacker <dthacker@omnicorporate.com> wrote:
>
> Informix 9.4FC6 on AIX 5.3...
>
> I've had requests for mere mortals, (and a few automated monitoring
> programs) to run onstat commands. I've been poking around the online
> docs for a few hours and have found a reference to the DBSA group. The
> DBSA group is set to informix by default. Is this a linux/aix group?
> Is it possible to add other linux/aix groups to DBSA to give
controlled
> access to the onstat commands? If not, what is the most secure way to
> do this?
The DBSA group is the group that owns $INFORMIXDIR/etc.
By default, that group is 'informix'. If you decide that group 'staff'
should own $INFORMXDIR/etc, then anybody who is in group 'staff' will be
able to administer your server. This is probably not a good idea - you
want
a special group to be in charge.
This business of who can use 'onstat' is a nuisance. We're going to need
a
better solution than the current one, which is to use the ONCONFIG
variable
UNSECURE_ONSTAT to restore the status quo ante. Some people need to
prevent
Joe Q Random from looking at other people's SQL statements; others do
not
realize that they need to do so, and a few others actually do not really
need to do so.
--
Jonathan Leffler #include <disclaimer.h>
Email: jleffler@earthlink.net, jleffler@us.ibm.com
Guardian of DBD::Informix v2005.02 -- http://dbi.perl.org/