Re: Informix-NET and trusted host access
Posted in 1993
>Date: Wed, 24 Mar 93 07:51:18 CST >From: uunet!mulga.awadi.com.AU!lwaugh (Lionel Waugh) >Subject: Informix-NET and trusted host access >X-Informix-List-Id: <list.2041> >I am surprised that nobody seemed interested to comment on my previous posting. > Perhaps nobody is using Informix-NET ? > Perhaps nobody is worried about losing network security ? > Perhaps 'I am not doing it right' ? Perhaps I didn't notice it... >I would like some indication (even if you disagree with me), as to whether >the current requirement of Informix-NET having trusted host access between >Workstation and Database server is unreasonable? I think it is reasonable, but then I would, wouldn't I, given who I work for. The problem is: if you don't have trusted status, how are you going to provide the user ID and password for network access? What about if a query in the application suddenly refers to a remote database, possibly via a synonym and you weren't even aware that the table was in another database? If you want a secure system, you don't have network access. You can, of course, require indiviuals (including informix) to have .rhosts entries instead of using hosts.equiv. Or, put another way, how would you make the system secure without compromising the ease of use? Give me a counter-proposal. Yours, Jonathan Leffler (johnl@obelix.informix.com) #include <disclaimer.h>