Run "onmode" from another non-DBA user
Posted in 2007
A user wanted a non-informix, non-root account to run onmode from a script, getting "Must be a DBA to run this program"; SQL-level GRANT DBA didn't help, since onmode requires OS-level DBSA privilege. Suggested fix was sudo, e.g. a visudo entry allowing the user to run a specific wrapper script as user informix (NOPASSWD), rather than onmode itself, to limit which options can be used. The poster instead added the user to the informix OS group and it worked, but Jonathan Leffler warned this grants full DBSA power and should be undone in favour of sudo.
Auto-generated by DrWatson from the posts below — may be imperfect; read the full thread.
Topics: Server Administration, Security, Permissions & Auditing
We run a script from a non "informix" user. This script calls another
script in which it executes the "onmode" command.
We get the error "Must be a DBA to run this progam". We know that the user
that runs the parent script is not informix or root. But is there any way
that informix allows this particular user to be able to run the onmode
program in its child script?
We use "grant dba to 'user_id'" but still does not work.
Regards,
Long Nguyen
Hi,
You could setup sudo such that it will allow that user to run the onmode
command as user informix. This means you can restrict this user to onmode
and no other 'on' command.
Regards
---------------------------------------------------------------
********** _/ ********** David Logan
******* _/ ******* ITO Delivery Specialist - Database
***** _/ ***** Hewlett-Packard Australia Ltd
**** _/_/_/ _/_/_/ **** E-Mail: david.logan@hp.com
**** _/ _/ _/ _/ **** Desk: +61 8 8408 4273
**** _/ _/ _/_/_/ **** Mobile: +61 417 268 665
***** _/ ******
****** _/ ******** Postal: 148 Frome Street,
******** _/ ********** Adelaide SA 5001
Australia
i n v e n t
---------------------------------------------------------------
-----Original Message-----
From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of Long
Nguyen
Sent: Thursday, 25 January 2007 1:46 PM
To: ids@iiug.org
Subject: Run "onmode" from another non-DBA user [8301]
We run a script from a non "informix" user. This script calls another
script in which it executes the "onmode" command.
We get the error "Must be a DBA to run this progam". We know that the user
that runs the parent script is not informix or root. But is there any way
that informix allows this particular user to be able to run the onmode
program in its child script?
We use "grant dba to 'user_id'" but still does not work.
Regards,
Long Nguyen
****************************************************************************
***
Forum Note: Use "Reply" to post a response in the discussion forum.
I believe only user Informix or root can run onmode command. To be able to run
this command as another user, you can utilize "su" command, it should allow
you to do what you want.
----- Original Message ----
From: Long Nguyen <lnguyen@ruralco.com.au>
To: ids@iiug.org
Sent: Wednesday, January 24, 2007 10:16:21 PM
Subject: Run "onmode" from another non-DBA user [8301]
We run a script from a non "informix" user. This script calls another
script in which it executes the "onmode" command.
We get the error "Must be a DBA to run this progam". We know that the user
that runs the parent script is not informix or root. But is there any way
that informix allows this particular user to be able to run the onmode
program in its child script?
We use "grant dba to 'user_id'" but still does not work.
Regards,
Long Nguyen
*******************************************************************************
Forum Note: Use "Reply" to post a response in the discussion forum.
I meant "sudo"
----- Original Message ----
From: Kern Doe <kern_doe@yahoo.com>
To: ids@iiug.org
Sent: Wednesday, January 24, 2007 10:39:35 PM
Subject: Re: Run "onmode" from another non-DBA user [8303]
I believe only user Informix or root can run onmode command. To be able to run
this command as another user, you can utilize "su" command, it should allow
you to do what you want.
----- Original Message ----
From: Long Nguyen <lnguyen@ruralco.com.au>
To: ids@iiug.org
Sent: Wednesday, January 24, 2007 10:16:21 PM
Subject: Run "onmode" from another non-DBA user [8301]
We run a script from a non "informix" user. This script calls another
script in which it executes the "onmode" command.
We get the error "Must be a DBA to run this progam". We know that the user
that runs the parent script is not informix or root. But is there any way
that informix allows this particular user to be able to run the onmode
program in its child script?
We use "grant dba to 'user_id'" but still does not work.
Regards,
Long Nguyen
*******************************************************************************
Forum Note: Use "Reply" to post a response in the discussion forum.
*******************************************************************************
Forum Note: Use "Reply" to post a response in the discussion forum.
Thanks Sushil,
We add the user id to the informix column in /etc/group and it works no=
w.
Regards,
Long N
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
=
=20
"Sushil =
=20
Shirodkar" To: lnguyen@ruralc=
o.com.au =20
<sushilps@hotmail cc: =
=20
.com> Subject: RE: Run "onmod=
e" from another non-DBA user =20
[8301] =
=20
25/01/2007 02:40 =
=20
PM =
=20
=
=20
=
=20
I think the user should be in informix group.
Sushil..
>From: "Long Nguyen" <lnguyen@ruralco.com.au>
>Reply-To: ids@iiug.org
>To: ids@iiug.org
>Subject: Run "onmode" from another non-DBA user [8301]
>Date: Wed, 24 Jan 2007 22:16:21 -0500 (EST)
>Received: from perform.iiug.org ([216.177.38.211]) by
>bay0-mc7-f11.bay0.hotmail.com with Microsoft SMTPSVC(6.0.3790.2444); W=
ed,
>24 Jan 2007 19:26:53 -0800
>Received: by perform.iiug.org (Postfix, from userid 60001)id DB9629E88=
;
>Wed, 24 Jan 2007 22:16:29 -0500 (EST)
>Received: from perform.iiug.org (localhost [127.0.0.1])by perform.iiug=
.org
>(Postfix) with ESMTP id A4D959E73;Wed, 24 Jan 2007 22:16:23 -0500 (EST=
)
>Received: by perform.iiug.org (Postfix, from userid 60001)id BE30D9E72=
;
>Wed, 24 Jan 2007 22:16:21 -0500 (EST)
>X-Message-Info: LsUYwwHHNt1baq3FfHL2EusVISX5AIM2SraPoLmxwro=3D
>X-Original-To: ids@iiug.org
>Delivered-To: sig_user@iiug.org
>X-IIUG: ids@iiug.org
>X-BeenThere: ids@iiug.org
>X-Mailman-Version: 2.1.6
>Precedence: list
>List-Id: <ids.iiug.org>
>List-Unsubscribe:
><http://www.iiug.org/mailman/listinfo/ids>,<
mailto:ids-request@iiug.org?subject=3Dunsubscribe>
>List-Archive: <http://www.iiug.org/pipermail/ids>
>List-Post: <mailto:ids@iiug.org>
>List-Help: <mailto:ids-request@iiug.org?subject=3Dhelp>
>List-Subscribe:
><http://www.iiug.org/mailman/listinfo/ids>,<
mailto:ids-request@iiug.org?subject=3Dsubscribe>
>Errors-To: ids-bounces@iiug.org
>Return-Path: ids-bounces@iiug.org
>X-OriginalArrivalTime: 25 Jan 2007 03:26:53.0399 (UTC)
>FILETIME=3D[A8905E70:01C74030]
>
>We run a script from a non "informix" user. This script calls another
>script in which it executes the "onmode" command.
>We get the error "Must be a DBA to run this progam". We know that the =
user
>that runs the parent script is not informix or root. But is there any =
way
>that informix allows this particular user to be able to run the onmode=
>program in its child script?
>We use "grant dba to 'user_id'" but still does not work.
>Regards,
>Long Nguyen
>
>
>
***********************************************************************=
********
> Forum Note: Use "Reply" to post a response in the discussion forum.=
>
_________________________________________________________________
Get Hilary Duff's homepage with her photos, music, and more.
http://celebrities.live.com
=
Can you advise me of the syntax of sudo in giving a userid to authority to
run the command onmode like informix?
Thanks,
Long N
========================
"Kern Doe"
<kern_doe@yahoo.c To: ids@iiug.org
om> cc:
Sent by: Subject: Re: Run "onmode" from another non-DBA user
ids-bounces@iiug. [8304]
org
25/01/2007 02:41
PM
Please respond to
ids
I meant "sudo"
----- Original Message ----
From: Kern Doe <kern_doe@yahoo.com>
To: ids@iiug.org
Sent: Wednesday, January 24, 2007 10:39:35 PM
Subject: Re: Run "onmode" from another non-DBA user [8303]
I believe only user Informix or root can run onmode command. To be able to
run
this command as another user, you can utilize "su" command, it should allow
you to do what you want.
----- Original Message ----
From: Long Nguyen <lnguyen@ruralco.com.au>
To: ids@iiug.org
Sent: Wednesday, January 24, 2007 10:16:21 PM
Subject: Run "onmode" from another non-DBA user [8301]
We run a script from a non "informix" user. This script calls another
script in which it executes the "onmode" command.
We get the error "Must be a DBA to run this progam". We know that the user
that runs the parent script is not informix or root. But is there any way
that informix allows this particular user to be able to run the onmode
program in its child script?
We use "grant dba to 'user_id'" but still does not work.
Regards,
Long Nguyen
*******************************************************************************
Forum Note: Use "Reply" to post a response in the discussion forum.
*******************************************************************************
Forum Note: Use "Reply" to post a response in the discussion forum.
*******************************************************************************
Forum Note: Use "Reply" to post a response in the discussion forum.
This is an example that used to work for me in Sequent Dynix/ptx.
Requirement: visudo and make an entry as
useidwhatever hostnamewhatever = (informix) NOPASSWD:
/usr/informix/admin/scripts/whateverscript
in "whateverscript, perhaps, there is the "onmode" command which you'd like to
have, and it should work. I personally don't give anything like:
NOPASSWD: /informix/IDS940/bin/onmode
because the "whateveruser" can run a lot of undesirable "onmode" options.
Good luck.
----- Original Message ----
From: Long Nguyen <lnguyen@ruralco.com.au>
To: ids@iiug.org
Sent: Wednesday, January 24, 2007 11:27:35 PM
Subject: Re: Run "onmode" from another non-DBA user [8306]
Can you advise me of the syntax of sudo in giving a userid to authority to
run the command onmode like informix?
Thanks,
Long N
========================
"Kern Doe"
<kern_doe@yahoo.c To: ids@iiug.org
om> cc:
Sent by: Subject: Re: Run "onmode" from another non-DBA user
ids-bounces@iiug. [8304]
org
25/01/2007 02:41
PM
Please respond to
ids
I meant "sudo"
----- Original Message ----
From: Kern Doe <kern_doe@yahoo.com>
To: ids@iiug.org
Sent: Wednesday, January 24, 2007 10:39:35 PM
Subject: Re: Run "onmode" from another non-DBA user [8303]
I believe only user Informix or root can run onmode command. To be able to
run
this command as another user, you can utilize "su" command, it should allow
you to do what you want.
----- Original Message ----
From: Long Nguyen <lnguyen@ruralco.com.au>
To: ids@iiug.org
Sent: Wednesday, January 24, 2007 10:16:21 PM
Subject: Run "onmode" from another non-DBA user [8301]
We run a script from a non "informix" user. This script calls another
script in which it executes the "onmode" command.
We get the error "Must be a DBA to run this progam". We know that the user
that runs the parent script is not informix or root. But is there any way
that informix allows this particular user to be able to run the onmode
program in its child script?
We use "grant dba to 'user_id'" but still does not work.
Regards,
Long Nguyen
*******************************************************************************
Forum Note: Use "Reply" to post a response in the discussion forum.
*******************************************************************************
Forum Note: Use "Reply" to post a response in the discussion forum.
*******************************************************************************
Forum Note: Use "Reply" to post a response in the discussion forum.
*******************************************************************************
Forum Note: Use "Reply" to post a response in the discussion forum.
should be 2 separate lines...
useidwhatever hostnamewhatever = (informix)
NOPASSWD: /usr/informix/admin/scripts/whateverscript
----- Original Message ----
From: Kern Doe <kern_doe@yahoo.com>
To: ids@iiug.org
Sent: Thursday, January 25, 2007 4:30:00 PM
Subject: Re: Run "onmode" from another non-DBA user [8307]
This is an example that used to work for me in Sequent Dynix/ptx.
Requirement: visudo and make an entry as
useidwhatever hostnamewhatever = (informix) NOPASSWD:
/usr/informix/admin/scripts/whateverscript
in "whateverscript, perhaps, there is the "onmode" command which you'd like to
have, and it should work. I personally don't give anything like:
NOPASSWD: /informix/IDS940/bin/onmode
because the "whateveruser" can run a lot of undesirable "onmode" options.
Good luck.
----- Original Message ----
From: Long Nguyen <lnguyen@ruralco.com.au>
To: ids@iiug.org
Sent: Wednesday, January 24, 2007 11:27:35 PM
Subject: Re: Run "onmode" from another non-DBA user [8306]
Can you advise me of the syntax of sudo in giving a userid to authority to
run the command onmode like informix?
Thanks,
Long N
========================
"Kern Doe"
<kern_doe@yahoo.c To: ids@iiug.org
om> cc:
Sent by: Subject: Re: Run "onmode" from another non-DBA user
ids-bounces@iiug. [8304]
org
25/01/2007 02:41
PM
Please respond to
ids
I meant "sudo"
----- Original Message ----
From: Kern Doe <kern_doe@yahoo.com>
To: ids@iiug.org
Sent: Wednesday, January 24, 2007 10:39:35 PM
Subject: Re: Run "onmode" from another non-DBA user [8303]
I believe only user Informix or root can run onmode command. To be able to
run
this command as another user, you can utilize "su" command, it should allow
you to do what you want.
----- Original Message ----
From: Long Nguyen <lnguyen@ruralco.com.au>
To: ids@iiug.org
Sent: Wednesday, January 24, 2007 10:16:21 PM
Subject: Run "onmode" from another non-DBA user [8301]
We run a script from a non "informix" user. This script calls another
script in which it executes the "onmode" command.
We get the error "Must be a DBA to run this progam". We know that the user
that runs the parent script is not informix or root. But is there any way
that informix allows this particular user to be able to run the onmode
program in its child script?
We use "grant dba to 'user_id'" but still does not work.
Regards,
Long Nguyen
*******************************************************************************
Forum Note: Use "Reply" to post a response in the discussion forum.
*******************************************************************************
Forum Note: Use "Reply" to post a response in the discussion forum.
*******************************************************************************
Forum Note: Use "Reply" to post a response in the discussion forum.
*******************************************************************************
Forum Note: Use "Reply" to post a response in the discussion forum.
*******************************************************************************
Forum Note: Use "Reply" to post a response in the discussion forum.
On 1/24/07, Long Nguyen <lnguyen@ruralco.com.au> wrote: > We add the user id to the informix column in /etc/group and it works now. It doesn't matter what the problem was - this is the WRONG SOLUTION! Now this innocent user of yours is a fully-fledged DBSA in complete command of your Informix system. That was what you intended, wasn't it? If it wasn't, undo the 'fix'. > >We get the error "Must be a DBA to run this progam". The original error message should, and I believe does, say "Must be a DBSA to run this program". A DBSA who is a member of group informix has permission to trash your IDS instance by accident. They can run any program that user informix can (for almost all purposes). They can read any Informix device. They could accidentally copy stuff over your Informix chunks. In general, they can wreak havoc unintentionally. Please unassign the user from group informix. Please investigate sudo - it is almost certainly the answer you are looking for. And anyone else who has users other than informix and isn't completely aware of why it is a bad idea should start reworking their system now! -- Jonathan Leffler #include <disclaimer.h> Email: jleffler@earthlink.net, jleffler@us.ibm.com Guardian of DBD::Informix v2005.02 -- http://dbi.perl.org/ NB: Please do not use this email for correspondence - I don't read it every week, even.
Thank you Jonathan for reaffirming the solution and alarming the possible
damage. Yes, what's been done as a "fix" should be undone, "sudo" command
should be investigated and understood.
----- Original Message ----
From: Jonathan Leffler <jleffler.iiug@gmail.com>
To: ids@iiug.org
Sent: Tuesday, January 30, 2007 10:15:21 AM
Subject: Re: Run "onmode" from another non-DBA user [8321]
On 1/24/07, Long Nguyen <lnguyen@ruralco.com.au> wrote:
> We add the user id to the informix column in /etc/group and it works now.
It doesn't matter what the problem was - this is the WRONG SOLUTION!
Now this innocent user of yours is a fully-fledged DBSA in complete
command of your Informix system. That was what you intended, wasn't
it? If it wasn't, undo the 'fix'.
> >We get the error "Must be a DBA to run this progam".
The original error message should, and I believe does, say "Must be a
DBSA to run this program". A DBSA who is a member of group informix
has permission to trash your IDS instance by accident. They can run
any program that user informix can (for almost all purposes). They
can read any Informix device. They could accidentally copy stuff over
your Informix chunks. In general, they can wreak havoc
unintentionally.
Please unassign the user from group informix.
Please investigate sudo - it is almost certainly the answer you are looking
for.
And anyone else who has users other than informix and isn't completely
aware of why it is a bad idea should start reworking their system now!
--
Jonathan Leffler #include <disclaimer.h>
Email: jleffler@earthlink.net, jleffler@us.ibm.com
Guardian of DBD::Informix v2005.02 -- http://dbi.perl.org/
NB: Please do not use this email for correspondence - I don't read it
every week, even.
*******************************************************************************
Forum Note: Use "Reply" to post a response in the discussion forum.
Minor clarification below: On 1/30/07, Jonathan Leffler <jleffler.iiug@gmail.com> wrote: > > On 1/24/07, Long Nguyen <lnguyen@ruralco.com.au> wrote: > > We add the user id to the informix column in /etc/group and it works now. > > It doesn't matter what the problem was - this is the WRONG SOLUTION! > > Now this innocent user of yours is a fully-fledged DBSA in complete > command of your Informix system. That was what you intended, wasn't > it? If it wasn't, undo the 'fix'. > > > >We get the error "Must be a DBA to run this progam". > > The original error message should, and I believe does, say "Must be a > DBSA to run this program". A DBSA who is a member of group informix > has permission to trash your IDS instance by accident. They can run > any program that user informix can (for almost all purposes). They > can read any Informix device. They could accidentally copy stuff over > your Informix chunks. In general, they can wreak havoc > unintentionally. > > Please unassign the user from group informix. > > Please investigate sudo - it is almost certainly the answer you are looking > for. > > And anyone else who has users other than informix and isn't completely > aware of why it is a bad idea should start reworking their system now! That should be: Anyone else who has users other than user informix as a member of group informix and who isn't completely aware of why it is (in general) a bad idea should start reworking their system so the no-one except user informix is a member of group informix. Leaving until *now* is leaving it too late -- hurry up! As with most rules, there might be exceptions. But you have to be able to argue why it is safe in your environment. Most people can't. I can't devise a scenario where I'd regard it as safe or necessary. -- Jonathan Leffler #include <disclaimer.h> Email: jleffler@earthlink.net, jleffler@us.ibm.com Guardian of DBD::Informix v2005.02 -- http://dbi.perl.org/ NB: Please do not use this email for correspondence - I don't read it every week, even.