Setting UMASK to 077 for user Informix
Posted in 2008
Topics: General Discussion
I have a question, is there any issue if umask for user informix:is set to 077. This would be for either Informix 10 or 11. Thanks, Jeff Jeffrey J. Filippi Integrated Data Consulting, LLC 104 Cottonwood Dr. Streamwood, IL 60107 630-842-3608 630-497-1762 (Fax) jeff.filippi@itdataconsulting.com www.itdataconsulting.com IBM BUSINESS PARTNER
Post-install right? I don't see anything wrong with that. I have been wrong before, or as my wife says "Michael you are always wrong." But that is rarely associated with Informix stuff. Mike
On Tue, Jun 10, 2008 at 4:12 AM, Jeff Filippi
<jeff.filippi@itdataconsulting.com> wrote:
> I have a question, is there any issue if umask for user informix is set to
077.
>
> This would be for either Informix 10 or 11.
There would be some mostly minor issues to deal with, but it is
basically harmless.
The oninit program explicitly uses the umask() system call (quite a
lot), and the initial setting in the environment is immaterial to a
running instance, so there's no harm there.
For other operations, you'd need to think carefully. For example, if
you create a new (cooked) chunk with umask set to 077, then you'll
need to do 'chmod 660 new.chunk' after creating an empty file.
In general, it is not a bad idea to be restrictive setting the
informix umask. However, since only user informix belongs to group
informix (you don't have anyone else in group informix, do you?), the
setting of the group section of the umask is largely immaterial - I
usually use 007 (the James Bond setting), but it could be sensible to
use 017 or even 0117 so files are not created (group or other)
executable by default.
--
Jonathan Leffler #include <disclaimer.h>
Email: jleffler@earthlink.net, jleffler@us.ibm.com
Guardian of DBD::Informix v2008.0513 -- http://dbi.perl.org/
"Blessed are we who can laugh at ourselves, for we shall never cease
to be amused."
NB: Please do not use this email for correspondence.
I don't necessarily read it every week, even.