Re: Fixing Permissions Problem
Posted in 1995
>From: doug@catseye.pha.pa.us (Douglas R. Probst) >Date: 21 Nov 95 03:01:14 GMT >X-Informix-List-Id: <news.19085> > >In article <kcjDI664n.KCM@netcom.com>, Kate Juliff <kcj@netcom.com> wrote: >}I have transfered Informix SE and SQL to a new machine (I upgraded from a >}486 to Pentium.) and I can access my database just fine. However, even >}though I have granted permission to another user, he cannot access my >}database (he could before.). I think I have everything set up properlt >}but there must be something wrong somewhere. I don't want to reinstall >}after all the trouble I had with it the first time. As I can access the >}database and as everything other than the permissions problem is OK, I'd >}like to get around this. Any suggestions, > >Check the permissions on the .dbd .dat &.idx files (Unix perm.) >They must be 666 for everyone to have read and write permission. >I have been bit more than a few time with this. With all due respect, ".dbd" files apply to Informix 3.30 (pre-SQL) and are not relevant to the current discussion. The permissions on the ".dbs" directories for SE should be 770 (owned by the database creator, belonging to group informix), and the permissions on the ".dat" and ".idx" files within the directory should be 660 (owned by the table creator, belonging to group informix). Any other permissions, and specifically using 666 permission on the ".dat" and ".idx" files, leads to immense security problems -- anybody can destroy the database at any time without even having to use Informix to do it. You also need to ensure that group informix has at least execute permission on each directory leading to where the ".dbs" directory is. That typically means that those directories either have 751 or 755 or 771 or 775 permission -- the other's permssion needs to include 'x'. You typically do not want others to have write permission on those directories. The rules change if your database must also be accessed by a C-ISAM program; then you typically need 771 permissions on the ".dbs" directory and 666 permissions on the ".dat" and ".idx" files in it, and you still lose most of your security, and your files are vulnerable, but that was forced on you by the use of C-ISAM. Yours, Jonathan Leffler (johnl@informix.com) #include <disclaimer.h>