permissions problem in IDS 7.31
Posted in 2003
Topics: Error Codes & Troubleshooting, Security, Permissions & Auditing, Versions, Editions & End-of-Life
ids@iiug.org
permissions problem in IDS 7.31
Firstly, I use dbschema to ascertain the access
levels on the table. Its last few lines appear
as:
grant select on "<user1>".<table1>
to "public" as "<user1>";
grant update on "<user1>".<table1>
to "public" as "<user1>";
grant insert on "<user1>".<table1>
to "public" as "<user1>";
grant delete on "<user1>".<table1>
to "public" as "<user1>";
grant index on "<user1>".<table1>
to "public" as "<user1>";
I want to revoke public access. Executing
revoke select on <table1> from public
as user informix results in:
580: Cannot revoke permission.
111: ISAM error: no record found.
Executing
revoke all on <table1> from public
results in the same dbschema output
as before.
Thanks.
Yousuf
-----Original Message-----
From: Mark D. Stock [mailto:mdstock@mydassolutions.com]
Sent: Wednesday, February 12, 2003 3:26 PM
To: ids@iiug.org
Subject: Re: permissions problem in IDS 7.31 [338]
what problem? You should be able to grant and revoke for non-existent
users if you are logged in as informix. If it is the only table with
that name in the database, then omit the username part as in:
REVOKE SELECT ON <table> FROM ...
Yousuf
wrote:
> ids@iiug.org
> permissions problem in IDS 7.31
> Firstly, I use dbschema to ascertain the access
> levels on the table. Its last few lines appear
> as:
>
> grant select on "<user1>".<table1>
> to "public" as "<user1>";
> grant update on "<user1>".<table1>
> to "public" as "<user1>";
> grant insert on "<user1>".<table1>
> to "public" as "<user1>";
> grant delete on "<user1>".<table1>
> to "public" as "<user1>";
> grant index on "<user1>".<table1>
> to "public" as "<user1>";
>
> I want to revoke public access. Executing
>
> revoke select on <table1> from public>
> as user informix results in:
>
> 580: Cannot revoke permission.
> 111: ISAM error: no record found.>
> Executing
>
> revoke all on <table1> from public>
> results in the same dbschema output
> as before.
Are you logged in as informix?
Is this a mode ANSI database?
Try this:
SELECT owner, tabname
FROM systables
WHERE tabname = "<table1>"
Do you have a single entry?
Try this:
SELECT a.grantor, a.grantee, t.tabname, a.tabauth
FROM systabauth a, systables t
WHERE a.tabid = t.tabid
AND a.tabname = "<table1>"
See any problems here?
Cheers,
--
Mark.
+----------------------------------------------------------+-----------+
| Mark D. Stock mailto:mdstock@MydasSolutions.com |//////// /|
| Mydas Solutions Ltd http://MydasSolutions.com |///// / //|
| +-----------------------------------+//// / ///|
| |We value your comments, which have |/// / ////|
| |been recorded and automatically |// / /////|
| |emailed back to us for our records.|/ ////////|
+----------------------+-----------------------------------+-----------+
set session authorization to "<user1>";
revoke all on <table1> from public;
You have to have DBA privs and <user1> has to have connect.
"Yousuf"
<yousuf@myrealbox To: ids@iiug.org
.com> cc:
Sent by: Subject: permissions problem in IDS 7.31 [339]
forum.subscriber@
iiug.org
02/12/2003 07:09
AM
ids@iiug.org
permissions problem in IDS 7.31
Firstly, I use dbschema to ascertain the access
levels on the table. Its last few lines appear
as:
grant select on "<user1>".<table1>
to "public" as "<user1>";
grant update on "<user1>".<table1>
to "public" as "<user1>";
grant insert on "<user1>".<table1>
to "public" as "<user1>";
grant delete on "<user1>".<table1>
to "public" as "<user1>";
grant index on "<user1>".<table1>
to "public" as "<user1>";
I want to revoke public access. Executing
revoke select on <table1> from public
as user informix results in:
580: Cannot revoke permission.
111: ISAM error: no record found.
Executing
revoke all on <table1> from public
results in the same dbschema output
as before.
Thanks.
Yousuf
-----Original Message-----
From: Mark D. Stock [mailto:mdstock@mydassolutions.com]
Sent: Wednesday, February 12, 2003 3:26 PM
To: ids@iiug.org
Subject: Re: permissions problem in IDS 7.31 [338]
what problem? You should be able to grant and revoke for non-existent
users if you are logged in as informix. If it is the only table with
that name in the database, then omit the username part as in:
REVOKE SELECT ON <table> FROM ...
------------------------------------------------------------------------
The information transmitted is intended only for the person or entity to
which it is addressed and may contain confidential and/or privileged
material. Any review, retransmission, dissemination or other use of, or
taking of any action in reliance upon, this information by persons or
entities other than the intended recipient is prohibited. If you received
this in error, please contact the sender and delete the material from any
computer.