Privileged Tasks
Posted in 2009
Topics: General Discussion
Hi all
I'm looking for a list of administrative tasks which _have_ to be done by
user inforrmix or by the superuser root on Unix. I searched the manuals of
9.4, 10 and 11 but couldn't find much helpfull.
Example:
Task Must be done Must be done Any valid user
by informix by root is privileged
oncheck X
onstat -g ses XQuery sysmaster X
etc.
Where could such a list be found?
TIA, Reinhard.
Hello Reinhard, Installing Informix tools (i.e. 4GL, ISQL, debugger), engine, and "network" (Client SDK) have to be installed by root and informix (but it leans more on the root side). Granting connects and permissions to databases and tables have to be done by informix. And LBAC is new which I have not yet used but I will hazard a guess that is done by informix, too. -L.S.
LIGHT SCANS wrote:
> Hello Reinhard,
>
> Installing Informix tools (i.e. 4GL, ISQL, debugger), engine, and
> "network" (Client SDK) have to be installed by root and informix (but
> it leans more on the root side). Granting connects and permissions to
> databases and tables have to be done by informix. And LBAC is new
> which I have not yet used but I will hazard a guess that is done by
> informix, too.
>
> -L.S.
I had answered this in the IIUG mailing list. To quote me:
"The text below seems a little garbled....
Anyway, I don't think you have that list anywhere, and the problem may be a bit
more complex... To give you some examples:
1- oncheck probably has to be run as a user belonging to group informix. Ir
reads the chunks and these are informix:informix 660
2- root is only required for installation unless I'm missing something
3- onstat options that allow you to see queries must be run by a DBSA (more on
this later). But you can overcome this by defining UNSECURE_ONSTAT 1 on your
onconfig
4- Query on sysmaster will depend on your settings when you create it. If you
have NODEFDAC defined, it will not give any privileges to public. Otherwise,
most of the sysmaster pseudo-tables will be selectable by anyone
DBSA (DataBase System Administrators) are a group of users that can do almos
any kind of administration activities. You define the group of DBSA by changing
the group ownership of your $INFORMIXDIR/etc.
The users belonging to this group will be able to run onstat (all options),
start and stop the instance, running onspaces etc. Note the following:
- Although a DBSA can run onspaces, your chunks will have to be owned by
informix:informix (660) so, informix user intervention may be required
- To start the instance you have to change the permissions of
$INFORMIXDIR/bin/oninit (chmod o+x $INFORMIXDIR/bin/oninit). This is not a
security issue because oninit will check that the user is authorized to run it
(either root, informix or a DBSA)
- To run onbar you must belong to group "bargroup"
I probably missed some points...
You can check the docs for role separation.
Most of this (if not all) applies to all versions.
"
In addition, I have to contradict you:
1- Granting connects and permissions on tables is done with any database DBA.
Note that the database owner is the first DBA. And that in recent versions you
define who can create databases through ONCONFIG parameter. So if you set it up
correctly, any DBSA (besides informix and root) can define who can create
databases and consequently who can be database owners/DBA, and consequently who
can grant database and table privileges
2- For using LBAC you need to have DBSECADM privilege which is given by a DBSA
Regards.
--
Fernando Nunes
Portugal
http://informix-technology.blogspot.com
My email works... but I don't check it frequently...
On Feb 27, 3:17 pm, LIGHT SCANS <light_sc...@yahoo.com> wrote:
> Installing Informix tools (i.e. 4GL, ISQL, debugger), engine, and
> "network" (Client SDK) have to be installed by root and informix (but
> it leans more on the root side). Granting connects and permissions to
> databases and tables have to be done by informix. And LBAC is new
> which I have not yet used but I will hazard a guess that is done by
> informix, too.
Installation needs root privileges. Once installation is done, root
privilege is seldom needed, except when setting up a new raw chunk -
those are normally owned by root until root hands the ownership over
to informix, and that has to be done by root.
Connect permission is granted to the database by a DBA - that should
generally not be user informix (or user root).
Table permissions can be granted by the table owner or a DBA - again,
that should not normally be user informix.
LBAC permissions have to be given by someone with DBSECADM
privileges. User informix (or any other DBSA, database system
administrator) will grant that privilege; user informix cannot
exericise that privilege on their own (it requires collusion between
two users).
(I saw Fernando's message too - it looked good. 'oncheck' should be
SGID informix so any DBSA should be able to run it.)
-=JL=-
Related threads
- Posting from the Informix-list
- Migrating from IDS 9.40.UC6 to 11.50.UC3
- Ip for a network session
- questions onstat -g