Informix dbexport
Posted in 2000
Topics: Server Administration, Security, Permissions & Auditing, Migration, Import/Export & Data Conversion, Platform-Specific Issues
Hi all,
I have a very pecuiliar question on database export.
I am having a single user os(HP-UX) login 'tpssup' who is a DBA
privileged user doing all database related tasks like data archival and
entire database backup for day-to-day operation (daily) right now. Now
the requirement is i have to provide individual logins for each user
who should be able to do the above tasks as a normal user(having only
CONNECT privilege) with condition that they should have only select
privilege on database objects. This is with respect to security aspect.
I know that there is a file access mode bit called "set-user-ID" thru
which you can take the effective user id of the script as "tpssup"
dynamically and finish the above database admin task as a normal user
(having only CONNECT privilege).
I tried out the above by setting set-user-ID bit to "dbexport" informix
executable. But it is still giving error that
"User must be Informix or have DBA permission"
Individual login group name is different from Informix group but is
part of 'tpssup' user group.
Can i have any solution for this ?
I know, in ORACLE you can grant a role to normal user who can do full
export or import with out DBA privilege. Is there any role available
for dbexport or dbimport in INFORMIX ?
I have to take decision whether it is feasible or not ?
Any Kind of your early help is highly appreciated.
Regards,
Balasubramanian .M
Bangalore.
sbala@hclinsys.com
Sent via Deja.com http://www.deja.com/
Before you buy.
In a wrapper script change the value of LOGNAME to the owner of dbexport.
That in combination with having set the SUID bit for dbexport should let
the script run dbexport as that user. Dbexport is normally owned by user
informix which would allow it to work on ANY database, if you have chown'd
the file to tpssup it will only work for databases for which that user is
a DBA.
Art S. Kagel
muruganbalas@my-deja.com wrote:
>
> Hi all,
>
> I have a very pecuiliar question on database export.
>
> I am having a single user os(HP-UX) login 'tpssup' who is a DBA
> privileged user doing all database related tasks like data archival and
> entire database backup for day-to-day operation (daily) right now. Now
> the requirement is i have to provide individual logins for each user
> who should be able to do the above tasks as a normal user(having only
> CONNECT privilege) with condition that they should have only select
> privilege on database objects. This is with respect to security aspect.
>
> I know that there is a file access mode bit called "set-user-ID" thru
> which you can take the effective user id of the script as "tpssup"
> dynamically and finish the above database admin task as a normal user
> (having only CONNECT privilege).
>
> I tried out the above by setting set-user-ID bit to "dbexport" informix
> executable. But it is still giving error that
>
> "User must be Informix or have DBA permission"
>
> Individual login group name is different from Informix group but is
> part of 'tpssup' user group.
>
> Can i have any solution for this ?
>
> I know, in ORACLE you can grant a role to normal user who can do full
> export or import with out DBA privilege. Is there any role available
> for dbexport or dbimport in INFORMIX ?
>
> I have to take decision whether it is feasible or not ?
>
> Any Kind of your early help is highly appreciated.
>
> Regards,
>
> Balasubramanian .M
> Bangalore.
>
> sbala@hclinsys.com
>
> Sent via Deja.com http://www.deja.com/
> Before you buy.