Re: ODBC and Security
Posted in 1996
Hi, > Ray Kaminski said: > Some suggestions have been made as to granting and revoking access to > tables and columns. How do you deal with the situation where the 3rd party > application provides security at the value level? That is to say that a > particular user can only see rows in this table of the values meet certain > criteria (i.e. the salary is < $50000). Informix provides no means for > defining this type of security. It would also be nice if I-NET validated > the application that is connecting as well as the user. Informix does provide a means to do this, with views. You create a view where salary is <$50000, revoke all provileges on the base table and grant privileges to the view. Then no matter what application or ODBC driver the user is using, they can only see records where salary is <$50000. With Views and Roles, there are ways to implement better security on the server. > Until a greater level of security is provided at the server level I am not > sure there is a viable options for extremely security conscious > individuals. It is my understanding that the Openlink ODBC driver does > provide server based types of security but I am not familiar with this > driver. > Another option for the extremely security conscious is Online/Secure. There are trade-offs with security, and implementing a security conscious system does take more planning and work. There are also security issues with ODBC and client server that need to be resolved. Regards - Lester ############################################################################# # Lester Knutsen lester@access.digex.net # # Advanced DataTools Corporation Voice: 703-256-0267 # # Grant group privileges for Informix databases with DB Privileges # # Visit our Web page: http://www.access.digex.net/~lester # # Washington Area Informix User Group: http://www.access.digex.net/~waiug # #############################################################################