Re: Security and the ODBC
Posted in 1997
Irwin Goldstein wrote: > I have frequently encountered the problem where a client wants to grant > users access to an application database through MS-Access (or other Windows > based query/report tool). Of course the way to do this is with ODBC. > However, the users normal Unix log in which they use to access the > application allows complete read/write access to the database. Normally > this is OK because the application handles security and proper maintenance > of referential integrity, etc. However, this level of access within > MS-Access is quite dangerous since the user could alter and even delete > data at will without regard to the controls normally enforced by the > application. > > The best solution I have found to this dilemna to date is to use the > OpenLink Multi-Tier ODBC driver instead of Informix-CLI or other "single > tier" driver. Is this really a solution? We have several UNIX servers running Online/STAR 5.07. We cannot disable I-STAR since we need it for distributed database access with Informix frontend tools (like 4GL, ESQL/C). Any user could install any single-tier ODBC driver like CLI or Intersolv on his own PC and connect to the server with his UNIX login and password. This has been causing me considerable head- ache, but I haven't found a good solution for it. Installing OPENLINK or similar multi-tier ODBC solutions would only help if I could throw out I-STAR altogether. But I have to keep it since I need it for Informix's own networking. Replacing that with ODBC or similar solutions would require rewriting dozens of programs. Has anybody found a solution for this? Regards, Richard -- +--------------------------+------------------------------------------+ | Dr. Richard Spitz | INTERNET: spitz@ana.med.uni-muenchen.de | | EDV-Gruppe Anaesthesie | Tel : +49-89-7095-3413 | | Klinikum Grosshadern | FAX : +49-89-7095-8886 | | 81366 Munich, Germany | | +--------------------------+------------------------------------------+