Re: How to connect as different user using dbaccess ?
Posted in 2005
rkusenet wrote: > "Jonathan Leffler" <jleffler@earthlink.net> wrote >>Alexey Sonkin wrote: >> >>>The problem is that is a very bad idea to pass the password in a >>>command line. Any user who has access to that machine is able to >>>get this password by simply issuing 'ps -ef' >> >>With all of that, I agree. The feature is there - I don't >>particularly recommend its use. The code in SQLCMD does attempt to >>zap the password argument - empirically, this has no effect on >>Solaris, and probably not on other platforms either. > > Jonathan, > > I remember going thru this with you when I was developing infotable, the tool > which prints out the schema of a database in a very readable format. I rejected > accepting user name and password as a command line option for the same reason > mentioned above. I finally setteled for the following option: > > (a) set an environment variable INFOTPASS to point out to a file. > (b) that file contains connect information in the format dbname|user name|password > (c) set unix permission 600 to that file for security. > > infotable will read from this file before connecting. IMO it is quite secured as long > as the password file's permission is not set incorrectly. > > Perhaps you can implement same approach for sqlcmd. The next version of SQLCMD - probably 77.0x - will support this with the environment variable SQLCMDPASSWORDS (not INFOTPASS). I'm meditating on whether - and how - to integrate this into all connect statements; it is already operational for the command line connections in SQLCMD. I also expect to make available to UPDBLOB et al. I sent Ravi a pre-release (77.00) shortly before he announced his retirement from c.d.i. I have not heard back from him since then, probably for the obvious reasons. -- Jonathan Leffler #include <disclaimer.h> Email: jleffler@earthlink.net, jleffler@us.ibm.com Guardian of DBD::Informix v2003.04 -- http://dbi.perl.org/