RE: Limiting access to instances when using OS aut
Posted in 2015
Larry (Solaris 10, IDS 11.50.FC7) uses OS authentication and wanted certain users barred from one of two instances; currently all OS users can reach both. The answer: you can't revoke CONNECT from an individual while PUBLIC holds it — instead REVOKE CONNECT FROM PUBLIC and GRANT CONNECT to the specific user list in each database. Larry accepted this. Others suggested alternatives: REMOTE_SERVER_CFG (needs 11.70.xC4+) if using hosts.equiv, or a per-user sysdbopen procedure that raises an exception to block a few users.
Auto-generated by DrWatson from the posts below — may be imperfect; read the full thread.
Topics: General Discussion
We are using: Solaris 10 IDS 11.50.FC7 We use OS authentification when accessing database instances on our server. We have two instances. Is there any easy way to limit the access of a particular user to access one instance, but not have access to the other instance? Up to this point, any user with access could access both instances without any trouble. The situation has arisen where we need to limit the access for certain users. Any suggestions would be appreciated. Database authentification is currently not an option at this point. Larry Sorensen
Remove connect privileges from those users in the databases on the other server? Art Art S. Kagel, President and Principal Consultant ASK Database Management www.askdbmgt.com Blog: http://informix-myview.blogspot.com/ Disclaimer: Please keep in mind that my own opinions are my own opinions and do not reflect on the IIUG, nor any other organization with which I am associated either explicitly, implicitly, or by inference. Neither do those opinions reflect those of other individuals affiliated with any entity with which I am affiliated nor those of the entities themselves. On Thu, Jun 25, 2015 at 10:00 AM, LARRY SORENSEN <lsorensen25@msn.com> wrote: > We are using: > > Solaris 10 > IDS 11.50.FC7 > > We use OS authentification when accessing database instances on our > server. We > have two instances. Is there any easy way to limit the access of a > particular > user to access one instance, but not have access to the other instance? Up > to > this point, any user with access could access both instances without any > trouble. The situation has arisen where we need to limit the access for > certain users. Any suggestions would be appreciated. Database > authentification > is currently not an option at this point. > > Larry Sorensen > > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > --001a113f8d34f56a4505195afe24
Would I be correct in assuming the databases have connect to public?... On Thu, Jun 25, 2015 at 6:31 PM, Art Kagel <art.kagel@gmail.com> wrote: > Remove connect privileges from those users in the databases on the other > server? > > Art > > Art S. Kagel, President and Principal Consultant > ASK Database Management > www.askdbmgt.com > > Blog: http://informix-myview.blogspot.com/ > > Disclaimer: Please keep in mind that my own opinions are my own opinions > and do not reflect on the IIUG, nor any other organization with which I am > associated either explicitly, implicitly, or by inference. Neither do > those opinions reflect those of other individuals affiliated with any > entity with which I am affiliated nor those of the entities themselves. > > On Thu, Jun 25, 2015 at 10:00 AM, LARRY SORENSEN <lsorensen25@msn.com> > wrote: > > > We are using: > > > > Solaris 10 > > IDS 11.50.FC7 > > > > We use OS authentification when accessing database instances on our > > server. We > > have two instances. Is there any easy way to limit the access of a > > particular > > user to access one instance, but not have access to the other instance? > Up > > to > > this point, any user with access could access both instances without any > > trouble. The situation has arisen where we need to limit the access for > > certain users. Any suggestions would be appreciated. Database > > authentification > > is currently not an option at this point. > > > > Larry Sorensen > > > > > > > > > > ******************************************************************************* > > Forum Note: Use "Reply" to post a response in the discussion forum. > > > > > > --001a113f8d34f56a4505195afe24 > > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > -- Fernando Nunes Portugal http://informix-technology.blogspot.com My email works... but I don't check it frequently... --001a113d5b8847880805195b14b2
Yes. The databases have connect to Public. Can you grant connect to Public, and then remove connect privileges to a specific user? Larry > To: ids@iiug.org > From: domusonline@gmail.com > Subject: Re: Limiting access to instances when using OS.... [35319] > Date: Thu, 25 Jun 2015 13:37:40 -0400 > > Would I be correct in assuming the databases have connect to public?... > > On Thu, Jun 25, 2015 at 6:31 PM, Art Kagel <art.kagel@gmail.com> wrote: > > > Remove connect privileges from those users in the databases on the other > > server? > > > > Art > > > > Art S. Kagel, President and Principal Consultant > > ASK Database Management > > www.askdbmgt.com > > > > Blog: http://informix-myview.blogspot.com/ > > > > Disclaimer: Please keep in mind that my own opinions are my own opinions > > and do not reflect on the IIUG, nor any other organization with which I am > > associated either explicitly, implicitly, or by inference. Neither do > > those opinions reflect those of other individuals affiliated with any > > entity with which I am affiliated nor those of the entities themselves. > > > > On Thu, Jun 25, 2015 at 10:00 AM, LARRY SORENSEN <lsorensen25@msn.com> > > wrote: > > > > > We are using: > > > > > > Solaris 10 > > > IDS 11.50.FC7 > > > > > > We use OS authentification when accessing database instances on our > > > server. We > > > have two instances. Is there any easy way to limit the access of a > > > particular > > > user to access one instance, but not have access to the other instance? > > Up > > > to > > > this point, any user with access could access both instances without any > > > trouble. The situation has arisen where we need to limit the access for > > > certain users. Any suggestions would be appreciated. Database > > > authentification > > > is currently not an option at this point. > > > > > > Larry Sorensen > > > > > > > > > > > > > > > > > ******************************************************************************* > > > Forum Note: Use "Reply" to post a response in the discussion forum. > > > > > > > > > > --001a113f8d34f56a4505195afe24 > > > > > > > > > ******************************************************************************* > > Forum Note: Use "Reply" to post a response in the discussion forum. > > > > > > -- > Fernando Nunes > Portugal > > http://informix-technology.blogspot.com > My email works... but I don't check it frequently... > > --001a113d5b8847880805195b14b2 > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. >
No. > On 25 Jun 2015, at 19:34, LARRY SORENSEN <lsorensen25@msn.com> wrote: > > Yes. The databases have connect to Public. > > Can you grant connect to Public, and then remove connect privileges to a > specific user? > > Larry > >> To: ids@iiug.org >> From: domusonline@gmail.com >> Subject: Re: Limiting access to instances when using OS.... [35319] >> Date: Thu, 25 Jun 2015 13:37:40 -0400 >> >> Would I be correct in assuming the databases have connect to public?... >> >> On Thu, Jun 25, 2015 at 6:31 PM, Art Kagel <art.kagel@gmail.com> wrote: >> >>> Remove connect privileges from those users in the databases on the other >>> server? >>> >>> Art >>> >>> Art S. Kagel, President and Principal Consultant >>> ASK Database Management >>> www.askdbmgt.com >>> >>> Blog: http://informix-myview.blogspot.com/ >>> >>> Disclaimer: Please keep in mind that my own opinions are my own opinions >>> and do not reflect on the IIUG, nor any other organization with which I am >>> associated either explicitly, implicitly, or by inference. Neither do >>> those opinions reflect those of other individuals affiliated with any >>> entity with which I am affiliated nor those of the entities themselves. >>> >>> On Thu, Jun 25, 2015 at 10:00 AM, LARRY SORENSEN <lsorensen25@msn.com> >>> wrote: >>> >>>> We are using: >>>> >>>> Solaris 10 >>>> IDS 11.50.FC7 >>>> >>>> We use OS authentification when accessing database instances on our >>>> server. We >>>> have two instances. Is there any easy way to limit the access of a >>>> particular >>>> user to access one instance, but not have access to the other instance? >>> Up >>>> to >>>> this point, any user with access could access both instances without any >>>> trouble. The situation has arisen where we need to limit the access for >>>> certain users. Any suggestions would be appreciated. Database >>>> authentification >>>> is currently not an option at this point. >>>> >>>> Larry Sorensen >>>> >>>> >>>> >>>> >>> >>> >> > ******************************************************************************* >>>> Forum Note: Use "Reply" to post a response in the discussion forum. >>>> >>>> >>> >>> --001a113f8d34f56a4505195afe24 >>> >>> >>> >>> >> > ******************************************************************************* >>> Forum Note: Use "Reply" to post a response in the discussion forum. >>> >>> >> >> -- >> Fernando Nunes >> Portugal >> >> http://informix-technology.blogspot.com >> My email works... but I don't check it frequently... >> >> --001a113d5b8847880805195b14b2 >> >> >> > ******************************************************************************* >> Forum Note: Use "Reply" to post a response in the discussion forum. >> > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. >
No. Are you using hosts.equiv? -----Original Message----- From: "LARRY SORENSEN" <lsorensen25@msn.com> Sent: =E2=80=8E25/=E2=80=8E06/=E2=80=8E2015 19:35 To: "ids@iiug.org" <ids@iiug.org> Subject: RE: Limiting access to instances when using OS.... [35320] Yes. The databases have connect to Public.=20 Can you grant connect to Public, and then remove connect privileges to a=20 specific user?=20 Larry=20 > To: ids@iiug.org=20 > From: domusonline@gmail.com=20 > Subject: Re: Limiting access to instances when using OS.... [35319]=20 > Date: Thu, 25 Jun 2015 13:37:40 -0400=20 >=20 > Would I be correct in assuming the databases have connect to public?...=20 >=20 > On Thu, Jun 25, 2015 at 6:31 PM, Art Kagel <art.kagel@gmail.com> wrote:=20 >=20 > > Remove connect privileges from those users in the databases on the othe= r=20 > > server?=20 > >=20 > > Art=20 > >=20 > > Art S. Kagel, President and Principal Consultant=20 > > ASK Database Management=20 > > www.askdbmgt.com=20 > >=20 > > Blog: http://informix-myview.blogspot.com/=20 > >=20 > > Disclaimer: Please keep in mind that my own opinions are my own opinion= s=20 > > and do not reflect on the IIUG, nor any other organization with which I= am=20 > > associated either explicitly, implicitly, or by inference. Neither do=20 > > those opinions reflect those of other individuals affiliated with any=20 > > entity with which I am affiliated nor those of the entities themselves.= =20 > >=20 > > On Thu, Jun 25, 2015 at 10:00 AM, LARRY SORENSEN <lsorensen25@msn.com>= =20 > > wrote:=20 > >=20 > > > We are using:=20 > > >=20 > > > Solaris 10=20 > > > IDS 11.50.FC7=20 > > >=20 > > > We use OS authentification when accessing database instances on our=20 > > > server. We=20 > > > have two instances. Is there any easy way to limit the access of a=20 > > > particular=20 > > > user to access one instance, but not have access to the other instanc= e?=20 > > Up=20 > > > to=20 > > > this point, any user with access could access both instances without = any=20 > > > trouble. The situation has arisen where we need to limit the access f= or=20 > > > certain users. Any suggestions would be appreciated. Database=20 > > > authentification=20 > > > is currently not an option at this point.=20 > > >=20 > > > Larry Sorensen=20 > > >=20 > > >=20 > > >=20 > > >=20 > >=20 > >=20 >=20 ***************************************************************************= ****=20 > > > Forum Note: Use "Reply" to post a response in the discussion forum.=20 > > >=20 > > >=20 > >=20 > > --001a113f8d34f56a4505195afe24=20 > >=20 > >=20 > >=20 > >=20 >=20 ***************************************************************************= ****=20 > > Forum Note: Use "Reply" to post a response in the discussion forum.=20 > >=20 > >=20 >=20 > --=20 > Fernando Nunes=20 > Portugal=20 >=20 > http://informix-technology.blogspot.com=20 > My email works... but I don't check it frequently...=20 >=20 > --001a113d5b8847880805195b14b2=20 >=20 >=20 >=20 ***************************************************************************= ****=20 > Forum Note: Use "Reply" to post a response in the discussion forum.=20 >=20 ***************************************************************************= ****=20 Forum Note: Use "Reply" to post a response in the discussion forum.=20
NO!
REVOKE CONNECT FROM PUBLIC;
GRANT CONNECT TO <userlist>;
Art
Art S. Kagel, President and Principal Consultant
ASK Database Management
www.askdbmgt.com
Blog: http://informix-myview.blogspot.com/
Disclaimer: Please keep in mind that my own opinions are my own opinions
and do not reflect on the IIUG, nor any other organization with which I am
associated either explicitly, implicitly, or by inference. Neither do
those opinions reflect those of other individuals affiliated with any
entity with which I am affiliated nor those of the entities themselves.
On Thu, Jun 25, 2015 at 11:34 AM, LARRY SORENSEN <lsorensen25@msn.com>
wrote:
> Yes. The databases have connect to Public.
>
> Can you grant connect to Public, and then remove connect privileges to a
> specific user?
>
> Larry
>
> > To: ids@iiug.org
> > From: domusonline@gmail.com
> > Subject: Re: Limiting access to instances when using OS.... [35319]
> > Date: Thu, 25 Jun 2015 13:37:40 -0400
> >
> > Would I be correct in assuming the databases have connect to public?...
> >
> > On Thu, Jun 25, 2015 at 6:31 PM, Art Kagel <art.kagel@gmail.com> wrote:
> >
> > > Remove connect privileges from those users in the databases on the
> other
> > > server?
> > >
> > > Art
> > >
> > > Art S. Kagel, President and Principal Consultant
> > > ASK Database Management
> > > www.askdbmgt.com
> > >
> > > Blog: http://informix-myview.blogspot.com/
> > >
> > > Disclaimer: Please keep in mind that my own opinions are my own
> opinions
> > > and do not reflect on the IIUG, nor any other organization with which
> I am
> > > associated either explicitly, implicitly, or by inference. Neither do
> > > those opinions reflect those of other individuals affiliated with any
> > > entity with which I am affiliated nor those of the entities themselves.
> > >
> > > On Thu, Jun 25, 2015 at 10:00 AM, LARRY SORENSEN <lsorensen25@msn.com>
> > > wrote:
> > >
> > > > We are using:
> > > >
> > > > Solaris 10
> > > > IDS 11.50.FC7
> > > >
> > > > We use OS authentification when accessing database instances on our
> > > > server. We
> > > > have two instances. Is there any easy way to limit the access of a
> > > > particular
> > > > user to access one instance, but not have access to the other
> instance?
> > > Up
> > > > to
> > > > this point, any user with access could access both instances without
> any
> > > > trouble. The situation has arisen where we need to limit the access
> for
> > > > certain users. Any suggestions would be appreciated. Database
> > > > authentification
> > > > is currently not an option at this point.
> > > >
> > > > Larry Sorensen
> > > >
> > > >
> > > >
> > > >
> > >
> > >
> >
>
>
*******************************************************************************
> > > > Forum Note: Use "Reply" to post a response in the discussion forum.
> > > >
> > > >
> > >
> > > --001a113f8d34f56a4505195afe24
> > >
> > >
> > >
> > >
> >
>
>
*******************************************************************************
> > > Forum Note: Use "Reply" to post a response in the discussion forum.
> > >
> > >
> >
> > --
> > Fernando Nunes
> > Portugal
> >
> > http://informix-technology.blogspot.com
> > My email works... but I don't check it frequently...
> >
> > --001a113d5b8847880805195b14b2
> >
> >
> >
>
>
*******************************************************************************
> > Forum Note: Use "Reply" to post a response in the discussion forum.
> >
>
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
--001a1140289c7c47ec05195c3b55
Thank you all. I was hoping to not have to grant connect to each individual,
but I guess that is the way to go.
Thanks again.
> To: ids@iiug.org
> From: art.kagel@gmail.com
> Subject: Re: Limiting access to instances when using OS.... [35323]
> Date: Thu, 25 Jun 2015 15:00:14 -0400
>
> NO!
>
> REVOKE CONNECT FROM PUBLIC;
> GRANT CONNECT TO <userlist>;>
> Art
>
> Art S. Kagel, President and Principal Consultant
> ASK Database Management
> www.askdbmgt.com
>
> Blog: http://informix-myview.blogspot.com/
>
> Disclaimer: Please keep in mind that my own opinions are my own opinions
> and do not reflect on the IIUG, nor any other organization with which I am
> associated either explicitly, implicitly, or by inference. Neither do
> those opinions reflect those of other individuals affiliated with any
> entity with which I am affiliated nor those of the entities themselves.
>
> On Thu, Jun 25, 2015 at 11:34 AM, LARRY SORENSEN <lsorensen25@msn.com>
> wrote:
>
> > Yes. The databases have connect to Public.
> >
> > Can you grant connect to Public, and then remove connect privileges to a
> > specific user?
> >
> > Larry
> >
> > > To: ids@iiug.org
> > > From: domusonline@gmail.com
> > > Subject: Re: Limiting access to instances when using OS.... [35319]
> > > Date: Thu, 25 Jun 2015 13:37:40 -0400
> > >
> > > Would I be correct in assuming the databases have connect to public?...
> > >
> > > On Thu, Jun 25, 2015 at 6:31 PM, Art Kagel <art.kagel@gmail.com> wrote:
> > >
> > > > Remove connect privileges from those users in the databases on the
> > other
> > > > server?
> > > >
> > > > Art
> > > >
> > > > Art S. Kagel, President and Principal Consultant
> > > > ASK Database Management
> > > > www.askdbmgt.com
> > > >
> > > > Blog: http://informix-myview.blogspot.com/
> > > >
> > > > Disclaimer: Please keep in mind that my own opinions are my own
> > opinions
> > > > and do not reflect on the IIUG, nor any other organization with which
> > I am
> > > > associated either explicitly, implicitly, or by inference. Neither do
> > > > those opinions reflect those of other individuals affiliated with any
> > > > entity with which I am affiliated nor those of the entities themselves.
> > > >
> > > > On Thu, Jun 25, 2015 at 10:00 AM, LARRY SORENSEN <lsorensen25@msn.com>
> > > > wrote:
> > > >
> > > > > We are using:
> > > > >
> > > > > Solaris 10
> > > > > IDS 11.50.FC7
> > > > >
> > > > > We use OS authentification when accessing database instances on our
> > > > > server. We
> > > > > have two instances. Is there any easy way to limit the access of a
> > > > > particular
> > > > > user to access one instance, but not have access to the other
> > instance?
> > > > Up
> > > > > to
> > > > > this point, any user with access could access both instances without
> > any
> > > > > trouble. The situation has arisen where we need to limit the access
> > for
> > > > > certain users. Any suggestions would be appreciated. Database
> > > > > authentification
> > > > > is currently not an option at this point.
> > > > >
> > > > > Larry Sorensen
> > > > >
> > > > >
> > > > >
> > > > >
> > > >
> > > >
> > >
> >
> >
>
*******************************************************************************
> > > > > Forum Note: Use "Reply" to post a response in the discussion forum.
> > > > >
> > > > >
> > > >
> > > > --001a113f8d34f56a4505195afe24
> > > >
> > > >
> > > >
> > > >
> > >
> >
> >
>
*******************************************************************************
> > > > Forum Note: Use "Reply" to post a response in the discussion forum.
> > > >
> > > >
> > >
> > > --
> > > Fernando Nunes
> > > Portugal
> > >
> > > http://informix-technology.blogspot.com
> > > My email works... but I don't check it frequently...
> > >
> > > --001a113d5b8847880805195b14b2
> > >
> > >
> > >
> >
> >
>
*******************************************************************************
> > > Forum Note: Use "Reply" to post a response in the discussion forum.
> > >
> >
> >
> >
> >
>
*******************************************************************************
> > Forum Note: Use "Reply" to post a response in the discussion forum.
> >
> >
>
> --001a1140289c7c47ec05195c3b55
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
If you are using hosts.equiv and can upgrade one of the servers to 11.70.xC4 or
higher you could use onconfig parameter REMOTE_SERVER_CFG to limit connections.
Regards,
David.
> On 25 June 2015 at 20:40 LARRY SORENSEN <lsorensen25@msn.com> wrote:
>
>
> Thank you all. I was hoping to not have to grant connect to each individual,
> but I guess that is the way to go.
>
> Thanks again.
>
> > To: ids@iiug.org
> > From: art.kagel@gmail.com
> > Subject: Re: Limiting access to instances when using OS.... [35323]
> > Date: Thu, 25 Jun 2015 15:00:14 -0400
> >
> > NO!
> >
> > REVOKE CONNECT FROM PUBLIC;
> > GRANT CONNECT TO <userlist>;> >
> > Art
> >
> > Art S. Kagel, President and Principal Consultant
> > ASK Database Management
> > www.askdbmgt.com
> >
> > Blog: http://informix-myview.blogspot.com/
> >
> > Disclaimer: Please keep in mind that my own opinions are my own opinions
> > and do not reflect on the IIUG, nor any other organization with which I am
> > associated either explicitly, implicitly, or by inference. Neither do
> > those opinions reflect those of other individuals affiliated with any
> > entity with which I am affiliated nor those of the entities themselves.
> >
> > On Thu, Jun 25, 2015 at 11:34 AM, LARRY SORENSEN <lsorensen25@msn.com>
> > wrote:
> >
> > > Yes. The databases have connect to Public.
> > >
> > > Can you grant connect to Public, and then remove connect privileges to a
> > > specific user?
> > >
> > > Larry
> > >
> > > > To: ids@iiug.org
> > > > From: domusonline@gmail.com
> > > > Subject: Re: Limiting access to instances when using OS.... [35319]
> > > > Date: Thu, 25 Jun 2015 13:37:40 -0400
> > > >
> > > > Would I be correct in assuming the databases have connect to public?...
> > > >
> > > > On Thu, Jun 25, 2015 at 6:31 PM, Art Kagel <art.kagel@gmail.com> wrote:
> > > >
> > > > > Remove connect privileges from those users in the databases on the
> > > other
> > > > > server?
> > > > >
> > > > > Art
> > > > >
> > > > > Art S. Kagel, President and Principal Consultant
> > > > > ASK Database Management
> > > > > www.askdbmgt.com
> > > > >
> > > > > Blog: http://informix-myview.blogspot.com/
> > > > >
> > > > > Disclaimer: Please keep in mind that my own opinions are my own
> > > opinions
> > > > > and do not reflect on the IIUG, nor any other organization with which
> > > I am
> > > > > associated either explicitly, implicitly, or by inference. Neither do
> > > > > those opinions reflect those of other individuals affiliated with any
> > > > > entity with which I am affiliated nor those of the entities
> themselves.
> > > > >
> > > > > On Thu, Jun 25, 2015 at 10:00 AM, LARRY SORENSEN
<lsorensen25@msn.com>
> > > > > wrote:
> > > > >
> > > > > > We are using:
> > > > > >
> > > > > > Solaris 10
> > > > > > IDS 11.50.FC7
> > > > > >
> > > > > > We use OS authentification when accessing database instances on our
> > > > > > server. We
> > > > > > have two instances. Is there any easy way to limit the access of a
> > > > > > particular
> > > > > > user to access one instance, but not have access to the other
> > > instance?
> > > > > Up
> > > > > > to
> > > > > > this point, any user with access could access both instances
without
> > > any
> > > > > > trouble. The situation has arisen where we need to limit the access
> > > for
> > > > > > certain users. Any suggestions would be appreciated. Database
> > > > > > authentification
> > > > > > is currently not an option at this point.
> > > > > >
> > > > > > Larry Sorensen
> > > > > >
> > > > > >
> > > > > >
> > > > > >
> > > > >
> > > > >
> > > >
> > >
> > >
> >
>
*******************************************************************************
> > > > > > Forum Note: Use "Reply" to post a response in the discussion forum.
> > > > > >
> > > > > >
> > > > >
> > > > > --001a113f8d34f56a4505195afe24
> > > > >
> > > > >
> > > > >
> > > > >
> > > >
> > >
> > >
> >
>
*******************************************************************************
> > > > > Forum Note: Use "Reply" to post a response in the discussion forum.
> > > > >
> > > > >
> > > >
> > > > --
> > > > Fernando Nunes
> > > > Portugal
> > > >
> > > > http://informix-technology.blogspot.com
> > > > My email works... but I don't check it frequently...
> > > >
> > > > --001a113d5b8847880805195b14b2
> > > >
> > > >
> > > >
> > >
> > >
> >
>
*******************************************************************************
> > > > Forum Note: Use "Reply" to post a response in the discussion forum.
> > > >
> > >
> > >
> > >
> > >
> >
>
*******************************************************************************
> > > Forum Note: Use "Reply" to post a response in the discussion forum.
> > >
> > >
> >
> > --001a1140289c7c47ec05195c3b55
> >
> >
> >
>
*******************************************************************************
> > Forum Note: Use "Reply" to post a response in the discussion forum.
> >
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
There is the possibility of using the sysdbopen stored procedure .
If it were just one or two users, you could create a sysdbopen stored
procedure that would be owned by the users that you wish to exclude from
access and have that stored procedure raise an exception. The error would stop
the users from using the DB where you created the sysdbopen stored procedure.
This would not address the issue, where all who have UNIX/Linux access would
have access to the DB it would just limit certain users from access from
certain DB.
I would go the route of granting particular access to particular DB instead of
"blocking" a few users from a few DB, but it would be possible to do it
through the sysdbopen and block only a limited number of users.
George.
-----Original Message-----
From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of LARRY
SORENSEN
Sent: Thursday, June 25, 2015 1:40 PM
To: ids@iiug.org
Subject: RE: Limiting access to instances when using OS.... [35325]
Thank you all. I was hoping to not have to grant connect to each individual,
but I guess that is the way to go.
Thanks again.
> To: ids@iiug.org
> From: art.kagel@gmail.com
> Subject: Re: Limiting access to instances when using OS.... [35323]
> Date: Thu, 25 Jun 2015 15:00:14 -0400
>
> NO!
>
> REVOKE CONNECT FROM PUBLIC;
> GRANT CONNECT TO <userlist>;>
> Art
>
> Art S. Kagel, President and Principal Consultant ASK Database
> Management www.askdbmgt.com
>
> Blog: http://informix-myview.blogspot.com/
>
> Disclaimer: Please keep in mind that my own opinions are my own
> opinions and do not reflect on the IIUG, nor any other organization
> with which I am associated either explicitly, implicitly, or by
> inference. Neither do those opinions reflect those of other
> individuals affiliated with any entity with which I am affiliated nor those
of the entities themselves.
>
> On Thu, Jun 25, 2015 at 11:34 AM, LARRY SORENSEN <lsorensen25@msn.com>
> wrote:
>
> > Yes. The databases have connect to Public.
> >
> > Can you grant connect to Public, and then remove connect privileges
> > to a specific user?
> >
> > Larry
> >
> > > To: ids@iiug.org
> > > From: domusonline@gmail.com
> > > Subject: Re: Limiting access to instances when using OS....
> > > [35319]
> > > Date: Thu, 25 Jun 2015 13:37:40 -0400
> > >
> > > Would I be correct in assuming the databases have connect to public?...
> > >
> > > On Thu, Jun 25, 2015 at 6:31 PM, Art Kagel <art.kagel@gmail.com> wrote:
> > >
> > > > Remove connect privileges from those users in the databases on
> > > > the
> > other
> > > > server?
> > > >
> > > > Art
> > > >
> > > > Art S. Kagel, President and Principal Consultant ASK Database
> > > > Management www.askdbmgt.com
> > > >
> > > > Blog: http://informix-myview.blogspot.com/
> > > >
> > > > Disclaimer: Please keep in mind that my own opinions are my own
> > opinions
> > > > and do not reflect on the IIUG, nor any other organization with
> > > > which
> > I am
> > > > associated either explicitly, implicitly, or by inference.
> > > > Neither do those opinions reflect those of other individuals
> > > > affiliated with any entity with which I am affiliated nor those
> > > > of the entities
themselves.
> > > >
> > > > On Thu, Jun 25, 2015 at 10:00 AM, LARRY SORENSEN
> > > > <lsorensen25@msn.com>
> > > > wrote:
> > > >
> > > > > We are using:
> > > > >
> > > > > Solaris 10
> > > > > IDS 11.50.FC7
> > > > >
> > > > > We use OS authentification when accessing database instances
> > > > > on our server. We have two instances. Is there any easy way to
> > > > > limit the access of a particular user to access one instance,
> > > > > but not have access to the other
> > instance?
> > > > Up
> > > > > to
> > > > > this point, any user with access could access both instances without
> > any
> > > > > trouble. The situation has arisen where we need to limit the access
> > for
> > > > > certain users. Any suggestions would be appreciated. Database
> > > > > authentification
> > > > > is currently not an option at this point.
> > > > >
> > > > > Larry Sorensen
> > > > >
> > > > >
> > > > >
> > > > >
> > > >
> > > >
> > >
> >
> >
>
*******************************************************************************
> > > > > Forum Note: Use "Reply" to post a response in the discussion forum.
> > > > >
> > > > >
> > > >
> > > > --001a113f8d34f56a4505195afe24
> > > >
> > > >
> > > >
> > > >
> > >
> >
> >
>
*******************************************************************************
> > > > Forum Note: Use "Reply" to post a response in the discussion forum.
> > > >
> > > >
> > >
> > > --
> > > Fernando Nunes
> > > Portugal
> > >
> > > http://informix-technology.blogspot.com
> > > My email works... but I don't check it frequently...
> > >
> > > --001a113d5b8847880805195b14b2
> > >
> > >
> > >
> >
> >
>
*******************************************************************************
> > > Forum Note: Use "Reply" to post a response in the discussion forum.
> > >
> >
> >
> >
> >
>
*******************************************************************************
> > Forum Note: Use "Reply" to post a response in the discussion forum.
> >
> >
>
> --001a1140289c7c47ec05195c3b55
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
*******************************************************************************
Forum Note: Use "Reply" to post a response in the discussion forum.
This electronic message transmission contains information from the Company
that may be proprietary, confidential and/or privileged. The information is
intended only for the use of the individual(s) or entity named above. If you
are not the intended recipient, be aware that any disclosure, copying or
distribution or use of the contents of this information is prohibited. If you
have received this electronic transmission in error, please notify the sender
immediately by replying to the address listed in the "From:" field.
Yes. That's the way to go "period". However....
Depending on your schedule, if you're not comfortable doing it because
you're afraid of missing a user, you can activate auditing for a period of
time and capture the start session.
That's an easy way to get a list of users.
It's amazing the number os sites that still have connect to public, grant
all to public etc...
I believe this is mainly IBM's fault as we don't want to change the default
or at least turn NODEFDAC into a server side configuration.
Having said that, there's several things you can do...
1- Someone else already mentioned REMOTE_SERVER_CFG for trusted connections.
2- You can change the $INFORMIXDIR/dbssodir/seccfg file, to define a group
of users that CAN connect to the instance. No one else will be allowed. Not
sure about distributed queries... please check. Needs an instance restart
3- Use PAM and add a module that allows/denies the users in a certain
file...A module like pam_listfile can do it. This can be used for any
client using an API that supports PAM (all but OleDB to the best of my
knowledge)
Regards
On Thu, Jun 25, 2015 at 8:40 PM, LARRY SORENSEN <lsorensen25@msn.com> wrote:
> Thank you all. I was hoping to not have to grant connect to each
> individual,
> but I guess that is the way to go.
>
> Thanks again.
>
> > To: ids@iiug.org
> > From: art.kagel@gmail.com
> > Subject: Re: Limiting access to instances when using OS.... [35323]
> > Date: Thu, 25 Jun 2015 15:00:14 -0400
> >
> > NO!
> >
> > REVOKE CONNECT FROM PUBLIC;
> > GRANT CONNECT TO <userlist>;> >
> > Art
> >
> > Art S. Kagel, President and Principal Consultant
> > ASK Database Management
> > www.askdbmgt.com
> >
> > Blog: http://informix-myview.blogspot.com/
> >
> > Disclaimer: Please keep in mind that my own opinions are my own opinions
> > and do not reflect on the IIUG, nor any other organization with which I
> am
> > associated either explicitly, implicitly, or by inference. Neither do
> > those opinions reflect those of other individuals affiliated with any
> > entity with which I am affiliated nor those of the entities themselves.
> >
> > On Thu, Jun 25, 2015 at 11:34 AM, LARRY SORENSEN <lsorensen25@msn.com>
> > wrote:
> >
> > > Yes. The databases have connect to Public.
> > >
> > > Can you grant connect to Public, and then remove connect privileges to
> a
> > > specific user?
> > >
> > > Larry
> > >
> > > > To: ids@iiug.org
> > > > From: domusonline@gmail.com
> > > > Subject: Re: Limiting access to instances when using OS.... [35319]
> > > > Date: Thu, 25 Jun 2015 13:37:40 -0400
> > > >
> > > > Would I be correct in assuming the databases have connect to
> public?...
> > > >
> > > > On Thu, Jun 25, 2015 at 6:31 PM, Art Kagel <art.kagel@gmail.com>
> wrote:
> > > >
> > > > > Remove connect privileges from those users in the databases on the
> > > other
> > > > > server?
> > > > >
> > > > > Art
> > > > >
> > > > > Art S. Kagel, President and Principal Consultant
> > > > > ASK Database Management
> > > > > www.askdbmgt.com
> > > > >
> > > > > Blog: http://informix-myview.blogspot.com/
> > > > >
> > > > > Disclaimer: Please keep in mind that my own opinions are my own
> > > opinions
> > > > > and do not reflect on the IIUG, nor any other organization with
> which
> > > I am
> > > > > associated either explicitly, implicitly, or by inference. Neither
> do
> > > > > those opinions reflect those of other individuals affiliated with
> any
> > > > > entity with which I am affiliated nor those of the entities
> themselves.
> > > > >
> > > > > On Thu, Jun 25, 2015 at 10:00 AM, LARRY SORENSEN <
> lsorensen25@msn.com>
> > > > > wrote:
> > > > >
> > > > > > We are using:
> > > > > >
> > > > > > Solaris 10
> > > > > > IDS 11.50.FC7
> > > > > >
> > > > > > We use OS authentification when accessing database instances on
> our
> > > > > > server. We
> > > > > > have two instances. Is there any easy way to limit the access of
> a
> > > > > > particular
> > > > > > user to access one instance, but not have access to the other
> > > instance?
> > > > > Up
> > > > > > to
> > > > > > this point, any user with access could access both instances
> without
> > > any
> > > > > > trouble. The situation has arisen where we need to limit the
> access
> > > for
> > > > > > certain users. Any suggestions would be appreciated. Database
> > > > > > authentification
> > > > > > is currently not an option at this point.
> > > > > >
> > > > > > Larry Sorensen
> > > > > >
> > > > > >
> > > > > >
> > > > > >
> > > > >
> > > > >
> > > >
> > >
> > >
> >
>
>
*******************************************************************************
> > > > > > Forum Note: Use "Reply" to post a response in the discussion
> forum.
> > > > > >
> > > > > >
> > > > >
> > > > > --001a113f8d34f56a4505195afe24
> > > > >
> > > > >
> > > > >
> > > > >
> > > >
> > >
> > >
> >
>
>
*******************************************************************************
> > > > > Forum Note: Use "Reply" to post a response in the discussion forum.
> > > > >
> > > > >
> > > >
> > > > --
> > > > Fernando Nunes
> > > > Portugal
> > > >
> > > > http://informix-technology.blogspot.com
> > > > My email works... but I don't check it frequently...
> > > >
> > > > --001a113d5b8847880805195b14b2
> > > >
> > > >
> > > >
> > >
> > >
> >
>
>
*******************************************************************************
> > > > Forum Note: Use "Reply" to post a response in the discussion forum.
> > > >
> > >
> > >
> > >
> > >
> >
>
>
*******************************************************************************
> > > Forum Note: Use "Reply" to post a response in the discussion forum.
> > >
> > >
> >
> > --001a1140289c7c47ec05195c3b55
> >
> >
> >
>
>
*******************************************************************************
> > Forum Note: Use "Reply" to post a response in the discussion forum.
> >
>
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
--
Fernando Nunes
Portugal
http://informix-technology.blogspot.com
My email works... but I don't check it frequently...
--001a11408a52d719e105195f4e2f
Hello,
Sysdbopen/close SProcs should be the flexible way and allow you to set PDQ /
Lock / Isolation Level and many other parameters and log and trace if needed.
I use it to manage connections over 12 Onlines on the same server.
The Synonym access between Onlines still an access method that don't trigger
the sysdbopen/close SProcs, if you use it, you'll have to take care of them.
Regards,
Samuel
-----Message d'origine-----
De : ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] De la part de Fernando
Nunes
Envoyé : vendredi 26 juin 2015 00:40
À : ids@iiug.org
Objet : Re: Limiting access to instances when using OS.... [35329]
Yes. That's the way to go "period". However....
Depending on your schedule, if you're not comfortable doing it because you're
afraid of missing a user, you can activate auditing for a period of time and
capture the start session.
That's an easy way to get a list of users.
It's amazing the number os sites that still have connect to public, grant all
to public etc...
I believe this is mainly IBM's fault as we don't want to change the default or
at least turn NODEFDAC into a server side configuration.
Having said that, there's several things you can do...
1- Someone else already mentioned REMOTE_SERVER_CFG for trusted connections.
2- You can change the $INFORMIXDIR/dbssodir/seccfg file, to define a group of
users that CAN connect to the instance. No one else will be allowed. Not sure
about distributed queries... please check. Needs an instance restart
3- Use PAM and add a module that allows/denies the users in a certain file...A
module like pam_listfile can do it. This can be used for any client using an
API that supports PAM (all but OleDB to the best of my
knowledge)
Regards
On Thu, Jun 25, 2015 at 8:40 PM, LARRY SORENSEN <lsorensen25@msn.com> wrote:
> Thank you all. I was hoping to not have to grant connect to each
> individual, but I guess that is the way to go.
>
> Thanks again.
>
> > To: ids@iiug.org
> > From: art.kagel@gmail.com
> > Subject: Re: Limiting access to instances when using OS.... [35323]
> > Date: Thu, 25 Jun 2015 15:00:14 -0400
> >
> > NO!
> >
> > REVOKE CONNECT FROM PUBLIC;
> > GRANT CONNECT TO <userlist>;> >
> > Art
> >
> > Art S. Kagel, President and Principal Consultant ASK Database
> > Management www.askdbmgt.com
> >
> > Blog: http://informix-myview.blogspot.com/
> >
> > Disclaimer: Please keep in mind that my own opinions are my own
> > opinions and do not reflect on the IIUG, nor any other organization
> > with which I
> am
> > associated either explicitly, implicitly, or by inference. Neither
> > do those opinions reflect those of other individuals affiliated with
> > any entity with which I am affiliated nor those of the entities themselves.
> >
> > On Thu, Jun 25, 2015 at 11:34 AM, LARRY SORENSEN
> > <lsorensen25@msn.com>
> > wrote:
> >
> > > Yes. The databases have connect to Public.
> > >
> > > Can you grant connect to Public, and then remove connect
> > > privileges to
> a
> > > specific user?
> > >
> > > Larry
> > >
> > > > To: ids@iiug.org
> > > > From: domusonline@gmail.com
> > > > Subject: Re: Limiting access to instances when using OS....
> > > > [35319]
> > > > Date: Thu, 25 Jun 2015 13:37:40 -0400
> > > >
> > > > Would I be correct in assuming the databases have connect to
> public?...
> > > >
> > > > On Thu, Jun 25, 2015 at 6:31 PM, Art Kagel <art.kagel@gmail.com>
> wrote:
> > > >
> > > > > Remove connect privileges from those users in the databases on
> > > > > the
> > > other
> > > > > server?
> > > > >
> > > > > Art
> > > > >
> > > > > Art S. Kagel, President and Principal Consultant ASK Database
> > > > > Management www.askdbmgt.com
> > > > >
> > > > > Blog: http://informix-myview.blogspot.com/
> > > > >
> > > > > Disclaimer: Please keep in mind that my own opinions are my
> > > > > own
> > > opinions
> > > > > and do not reflect on the IIUG, nor any other organization
> > > > > with
> which
> > > I am
> > > > > associated either explicitly, implicitly, or by inference.
> > > > > Neither
> do
> > > > > those opinions reflect those of other individuals affiliated
> > > > > with
> any
> > > > > entity with which I am affiliated nor those of the entities
> themselves.
> > > > >
> > > > > On Thu, Jun 25, 2015 at 10:00 AM, LARRY SORENSEN <
> lsorensen25@msn.com>
> > > > > wrote:
> > > > >
> > > > > > We are using:
> > > > > >
> > > > > > Solaris 10
> > > > > > IDS 11.50.FC7
> > > > > >
> > > > > > We use OS authentification when accessing database instances
> > > > > > on
> our
> > > > > > server. We
> > > > > > have two instances. Is there any easy way to limit the
> > > > > > access of
> a
> > > > > > particular
> > > > > > user to access one instance, but not have access to the
> > > > > > other
> > > instance?
> > > > > Up
> > > > > > to
> > > > > > this point, any user with access could access both instances
> without
> > > any
> > > > > > trouble. The situation has arisen where we need to limit the
> access
> > > for
> > > > > > certain users. Any suggestions would be appreciated.
> > > > > > Database authentification is currently not an option at this
> > > > > > point.
> > > > > >
> > > > > > Larry Sorensen
> > > > > >
> > > > > >
> > > > > >
> > > > > >
> > > > >
> > > > >
> > > >
> > >
> > >
> >
>
>
*******************************************************************************
> > > > > > Forum Note: Use "Reply" to post a response in the discussion
> forum.
> > > > > >
> > > > > >
> > > > >
> > > > > --001a113f8d34f56a4505195afe24
> > > > >
> > > > >
> > > > >
> > > > >
> > > >
> > >
> > >
> >
>
>
*******************************************************************************
> > > > > Forum Note: Use "Reply" to post a response in the discussion forum.
> > > > >
> > > > >
> > > >
> > > > --
> > > > Fernando Nunes
> > > > Portugal
> > > >
> > > > http://informix-technology.blogspot.com
> > > > My email works... but I don't check it frequently...
> > > >
> > > > --001a113d5b8847880805195b14b2
> > > >
> > > >
> > > >
> > >
> > >
> >
>
>
*******************************************************************************
> > > > Forum Note: Use "Reply" to post a response in the discussion forum.
> > > >
> > >
> > >
> > >
> > >
> >
>
>
*******************************************************************************
> > > Forum Note: Use "Reply" to post a response in the discussion forum.
> > >
> > >
> >
> > --001a1140289c7c47ec05195c3b55
> >
> >
> >
>
>
*******************************************************************************
> > Forum Note: Use "Reply" to post a response in the discussion forum.
> >
>
>
>
>
*************************************