Re: ODBC and Security
Posted in 1996
Setnet fix should apply here: see prior email from me and my partners in crime, besure to check orginal posting by David Chan and subc@lmis.jcdc.doleta.gov (one of my partners in crime "SMILE"). I only included heading from my regular some say to much replies: Date: Tue, 28 May 96 19:19 BST-1 From: David Chan <dwc@cix.compulink.co.uk> To: cherylk@prod1.jcdc.doleta.gov Cc: dwc@cix.compulink.co.uk Subject: multiple connects Date: Wed, 29 May 1996 23:33:42 -0500 (CDT) From: Cheryl Kendricks <cherylk@prod1.jcdc.doleta.gov> To: subuc@lmis.jcdc.doleta.gov Cc: informix-list@rmy.emory.edu Subject: Re: Set501.exe( for multiple connects ) Date: Thu, 30 May 1996 18:05:43 -0500 (CDT) From: Cheryl Kendricks <cherylk@prod1.jcdc.doleta.gov> To: Tim Schaefer <tschaefe@encore.com> Cc: informix-list@rmy.emory.edu Subject: Re: getting login name in 4GL to save bandwidth..... CLK that Database Administrator - DOL Job Corps San Marcos, Texas ------------------------------------------------------------------------ On 12 Mar 1996, Irwin Goldstein wrote: } "John H. Frantz" <john@rl.is> writes: } } > If the OpenLink } > ODBC driver can control read/write permissions, then that may be a } > good enough solution. But, does that stop anyone from using another } > ODBC driver that's more open? } } If you have I-Star installed on your server, or you are running Informix } On-Line 6.0 or later, then unfortunatley there are several ODBC drivers } which could easily be obtained and installed by a savvy user to connect } to the database with their usual permissions. OpenLink can only filter } access made through its server based request broker. Most ODBC drivers } go through I-NET on the PC to I-Star (pre-6.0) or direct to the engine } (6.0 and later) on the server. } } > } > I still think my original solution is most secure, which I'll repeat: } > } > Setup your users with read-only access to the database. Create one user } > called "program" which has read/write access. Regardless of the user, } > the central application connects to the database as user "program", } > having the password hard coded. In this way, the central application } > is the only client modifying data. Users can connect using ODBC or } > anything else using their own id's to query and produce reports. } } Yours is a more secure approach, but is only possible if you have control } over the main application (i.e. it's maintained in-house). I don't know } if you can even do this kind of thing in Informix-4GL. (Is there a way } to "re-login" to the server using 4GL?) } } It would be nice if Informix (and other RDBMS vendors) would extend their } security mechanism to include such things as application id, remote system } name, etc. }