Informix as DBA (was Table Privilege Losses)
Posted in 1993
>From: uunet!lexmark.com!CJSENFT >Subject: Re: Table Privilege Losses >Date: 13 Apr 93 15:17:16 GMT >X-Informix-List-Id: <news.3032> >I just figured out my own problem this morning...we have >granted privileges while under userids other than informix >and then when the granting userids are modified, their >grantees privileges are lost. Hopefully granting everyone's >privileges under the informix userid will solve our problem. I'd like to comment on the administrative set-up you have (rather than on the details of how/why you lost privileges). It would appear that you are using the informix login as a principal DBA for your database. I would suggest that this is not necessarily a good idea. There are some differences between OnLine and SE in that OnLine has a number of administration programs which can only be run by user informix, whereas I can't think of any like that for SE. In general, the informix login name should only be used for operations which require informix privileges. On an SE system, informix can have no password so no-one ever operates as informix. With OnLine, informix needs to be a bona fide user, complete with password, and the login needs to be as carefully protected as the root password because it can do as much damage to your databases as root can. The informix group, incidentally, should only contain the user informix. No other user (at all) needs to belong to group informix. Anybody with group informix privileges can bypass all the built-in security of the database and access any data in the database. (It won't be easy, but it can be done.) You should have a separate database administrator login; separate from root, informix and your ordinary users. This login should also be carefully protected, for the same sorts of reasons as root and informix are. This login should be responsible for creating the database, and should generally own all the tables (and indexes and constraints and ...). I think that this user should, in general, be responsible for granting and revoking all privileges on the tables. (Other people may disagree with this, but it certainly simplifies the controls if only one user can gives access privileges.) This probably seems unduly fussy; in some ways, perhaps it is. But amongst other reasons, it gives a better separation of the duties. User informix is responsible for looking after OnLine systems as a whole, and the OnLine system may contain multiple independent databases. These different databases may need to be administered by different people, and maybe the user who administers database A (payroll) should not be allowed to administer database B (sales order processing), and vice versa. If you use OnLine-Secure, then these roles are forcibly separated. Yours, Jonathan Leffler (johnl@obelix.informix.com) #include <disclaimer.h>