Security
Posted in 2000
Topics: Security, Permissions & Auditing
Hi There,
I wonder if anyone could help me with a little trouble
I'm having with Informix SQL 7.24UC7...
The SQL server I'm using is informix-se.
The database files are stored in a directory, files.dbs.
All these files are currently chmod 777.
I would like to change the permissions of these files
to chmod 755. The directory and files are owned by the
user "informix", and belong to the "informix" group.
The application program gets run by non-"informix" users,
and can access the database no problems if the permissions
on the files.dbs directory and all the files within are
set to 777. However, when I change the permissions to
755, I get a database error.
The database errors are:
329: Database not found, or no system permission13: Permission denied
Anyone any ideas?
TIA
Tom.
Tom Pearce wrote:
> Hi There,
>
> I wonder if anyone could help me with a little trouble
> I'm having with Informix SQL 7.24UC7...
>
> The SQL server I'm using is informix-se.
>
> The database files are stored in a directory, files.dbs.
> All these files are currently chmod 777.
> I would like to change the permissions of these files
> to chmod 755. The directory and files are owned by the
> user "informix", and belong to the "informix" group.
The proper permissions for all Informix data files and directories is
770.
SE, which you are apparently using, is more forgiving than IDS so 775
should work it you feel you need that, however, 770 should give you
the level of safety you want and still allow access to the database.
Art S. Kagel
>
>
> The application program gets run by non-"informix" users,
> and can access the database no problems if the permissions
> on the files.dbs directory and all the files within are
> set to 777. However, when I change the permissions to
> 755, I get a database error.
>
> The database errors are:
> 329: Database not found, or no system permission> 13: Permission denied
>
> Anyone any ideas?
>
> TIA
>
> Tom.
I don't know about OnLine cooked files, but to put a bit finer point on what Art said, in the case of SE, the files.dbs directory in your example should have permissions of 770, be owned by the user who created the database, and be assigned to group informix. The individual files should be permission 660 and be assigned to group informix. Each (.dat,.idx) pair file will probably be owned by the user who creates them. That's always the same user on our system, do I don't know if each file's owner will be the creating user or the "DBA" user who first created the database. As Art mentioned, having file permissions be --5 won't hurt database operations, but if the files.dbs directory permissions are also --5, every user on the system will be able to read your raw files and bypass Informix privileges. You definitely don't want --7 on anything. --7 on the files will allow users to write directly to them (assuming that the files.dbs permissions allow them to get to the files). --7 on files.dbs will allow others to add or remove entire files. I would check the owner, group and permissions on the installed Informix files, and maybe the permissions on all of the parent directories from files.dbs back to "/". As an aside, I noted that you want to change permission to 755. If you're trying to restrict access to the database, use Informix privileges. Check the manuals for info on that. Good luck, Walt. -- Walt Hultgren Manager, Information Technology Yerkes Research Center of Emory University Mailto:walt@rmy.emory.edu -- 404-727-0648