Single sign-on
Posted in 2011
Topics: Server Administration
We would like to implement the Single Sign-on login process to enforce security accessing Informix dbs? This is an attempt to secure data ( such as tax_id, SSNs) in certain tables from being read by everyone. This becomes specially difficult when our develpment environment gets restored with production data, as everyone currently has 'dba' privileges in Dev. Any advice on securing data by user id or a primer on using single sign-on is welcome. Current version: IDS 11.50.FC5, likely to move to 11.70 in development shortly. Thank you.
Single sign-on is available on IDS 11.50+ But your problem doesn't look like an authentication issue. If you don't have the proper privileges and you copy production data to development environment you're violating all the best practices... Single Sign-on will only make it easir to check that a user is who is telling the system. If after that you're allowing him to see all the data, it will not solve the main problem. You should have proper privileges, eventually consider LBAC (another security feature in 11.50), and you should not have production data in dev. environments. You must mask the data. There are other tools that can move production data to dev/test environments masking it during the process. IBM Optim is one of those tools, but naturally it costs money.... Regards. On Thu, Apr 7, 2011 at 6:17 PM, MURALI PAZHAYANNUR <pmurali@ftportfolios.com > wrote: > We would like to implement the Single Sign-on login process to enforce > security accessing Informix dbs? This is an attempt to secure data ( such > as > tax_id, SSNs) in certain tables from being read by everyone. This becomes > specially difficult when our develpment environment gets restored with > production data, as everyone currently has 'dba' privileges in Dev. Any > advice > on securing data by user id or a primer on using single sign-on is welcome. > Current version: IDS 11.50.FC5, likely to move to 11.70 in development > shortly. Thank you. > > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > -- Fernando Nunes Portugal http://informix-technology.blogspot.com My email works... but I don't check it frequently... --0015174a0bf47a9ac104a0581785
Hi Murali, SSO won't help limit the viewership. fortunately IDS has two options, one is far easier than the other, but requires that youare restricting table level objects. This method is refered to as Role Based ACcess, or RBAC for short. With default roles , first available in Version 10, You can restrict what tables a user can access by creating a role with access and then adding the role as a userid's default role. If you need Column Level access, you can use Informix's Label Based Access Control, LBAC for short. IMHO, if your company has the money and especially has multiple types of DB's, like SQL-SERVER, ORACLE, DB2, etc, then your best choice is IBM's Guardium product. As Fernando mentoned, what you really need is something to scrub your development/test data, because having SSN's attached to their real person's names is a violation of most if not all regulatory compliance laws. IBM OPTIM Data Privacy, is the product you would want to look at. -Mark Sent from my iPad On Apr 7, 2011, at 12:17 PM, MURALI PAZHAYANNUR <pmurali@ftportfolios.com> wrote: > We would like to implement the Single Sign-on login process to enforce > security accessing Informix dbs? This is an attempt to secure data ( such as > tax_id, SSNs) in certain tables from being read by everyone. This becomes > specially difficult when our develpment environment gets restored with > production data, as everyone currently has 'dba' privileges in Dev. Any advice > on securing data by user id or a primer on using single sign-on is welcome. > Current version: IDS 11.50.FC5, likely to move to 11.70 in development > shortly. Thank you. > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. >
Thank you, Mark and Fernando, for your advice. I will look into using RBAC. We do have a system of securing sensitive data by granting and revoking privileges by database and user or role. This is done in both production and development environments. We are trying to fine tune this and I was looking for advice. Please direct me to White papers or use cases or models using RBAC. Thank you once more.
At a previous employer, I would restore production data to QA / Dev but we made the db inaccessible until I had run a 'scrubber' utility to put random 16-digit numbers in the charge card field and randomize the other CC info, even if it added another 4 hours to the wait . Those were the rules. Bob ----- Original Message ----- From: "Mark Jamison" <majp51@me.com> To: ids@iiug.org Sent: Thursday, April 7, 2011 4:58:50 PM Subject: Re: Single sign-on [23369] Hi Murali, SSO won't help limit the viewership. fortunately IDS has two options, one is far easier than the other, but requires that youare restricting table level objects. This method is refered to as Role Based ACcess, or RBAC for short. With default roles , first available in Version 10, You can restrict what tables a user can access by creating a role with access and then adding the role as a userid's default role. If you need Column Level access, you can use Informix's Label Based Access Control, LBAC for short. IMHO, if your company has the money and especially has multiple types of DB's, like SQL-SERVER, ORACLE, DB2, etc, then your best choice is IBM's Guardium product. As Fernando mentoned, what you really need is something to scrub your development/test data, because having SSN's attached to their real person's names is a violation of most if not all regulatory compliance laws. IBM OPTIM Data Privacy, is the product you would want to look at. -Mark Sent from my iPad On Apr 7, 2011, at 12:17 PM, MURALI PAZHAYANNUR <pmurali@ftportfolios.com> wrote: > We would like to implement the Single Sign-on login process to enforce > security accessing Informix dbs? This is an attempt to secure data ( such as > tax_id, SSNs) in certain tables from being read by everyone. This becomes > specially difficult when our develpment environment gets restored with > production data, as everyone currently has 'dba' privileges in Dev. Any advice > on securing data by user id or a primer on using single sign-on is welcome. > Current version: IDS 11.50.FC5, likely to move to 11.70 in development > shortly. Thank you. > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. > ******************************************************************************* Forum Note: Use "Reply" to post a response in the discussion forum.