ISM - run backups as a user other than root?
Posted in 2010
Malc asked how to run Informix Storage Manager (ISM) backups as user informix instead of root, since his sysadmins won't allow new root cron/at jobs; running as informix gives "savegrp: You are not authorized to run this command" and no bootstrap file is created. Replies suggested sudo (with a NOPASSWD entry in sudoers so no password is hardcoded), setuid, or wrapping/renaming the binary so the internal savegrp call goes through sudo, plus checking ism_show -admins and adding informix@hostname as an ISM admin. Malc said informix was already an admin and it still failed; no working resolution is recorded.
Auto-generated by DrWatson from the posts below — may be imperfect; read the full thread.
Topics: Triggers, Constraints & Referential Integrity, Logging & Checkpoints
One more thing ((c) 2010). It is a TOTAL pain in that with ISM you have to be root to run the backup commands. The root user round here is under tighter security than a very nervous camel's backside in a very powerful sandstorm. They are really NOT happy about adding anything to root cron or 'at' or into their imprenetrable schedule, and database backups don't register much if at all on their 'things we want/need/have to do' radar. Is there any way at all of allowing the informix user to run the backup commands without ISM triggering the "07/27/10 10:15:41 savegrp: You are not authorized to run this command" error? It basically means that no bootstrap file can be created if user informix runs the backups (whether database ot logical log) Ta
"Malc" <iiug@perrior.net> wrote in message news:1cb6c095-0543-4031-9c82-d8d5d5f5bbd2@b5g2000vbl.googlegroups.com... > One more thing ((c) 2010). > > It is a TOTAL pain in that with ISM you have to be root to run the > backup commands. > The root user round here is under tighter security than a very nervous > camel's backside in a very powerful sandstorm. They are really NOT > happy about adding anything to root cron or 'at' or into their > imprenetrable schedule, and database backups don't register much if at > all on their 'things we want/need/have to do' radar. > Is there any way at all of allowing the informix user to run the > backup commands without ISM triggering the "07/27/10 10:15:41 savegrp: > You are not authorized to run this command" error? It basically means > that no bootstrap file can be created if user informix runs the > backups (whether database ot logical log) sudo?
On Jul 27, 4:02 pm, "Neil Truby" <neil.tr...@ardenta.com> wrote: > "Malc" <i...@perrior.net> wrote in message > > news:1cb6c095-0543-4031-9c82-d8d5d5f5bbd2@b5g2000vbl.googlegroups.com... > > > One more thing ((c) 2010). > > > It is a TOTAL pain in that with ISM you have to be root to run the > > backup commands. > > The root user round here is under tighter security than a very nervous > > camel's backside in a very powerful sandstorm. They are really NOT > > happy about adding anything to root cron or 'at' or into their > > imprenetrable schedule, and database backups don't register much if at > > all on their 'things we want/need/have to do' radar. > > Is there any way at all of allowing the informix user to run the > > backup commands without ISM triggering the "07/27/10 10:15:41 savegrp: > > You are not authorized to run this command" error? It basically means > > that no bootstrap file can be created if user informix runs the > > backups (whether database ot logical log) > > sudo? Needs to be non-interactive and we don't want to hardcode passwords anywhere...
On 27/07/2010 16:02, Neil Truby wrote: > > sudo? suid? -- This message has been scanned for viruses and dangerous content by OpenProtect(http://www.openprotect.com), and is believed to be clean.
> From: neil.truby@ardenta.com > Subject: Re: ISM - run backups as a user other than root? > Date: Tue, 27 Jul 2010 16:02:37 +0100 > To: informix-list@iiug.org > > "Malc" <iiug@perrior.net> wrote in message > news:1cb6c095-0543-4031-9c82-d8d5d5f5bbd2@b5g2000vbl.googlegroups.com... > > One more thing ((c) 2010). > > > > It is a TOTAL pain in that with ISM you have to be root to run the > > backup commands. > > The root user round here is under tighter security than a very nervous > > camel's backside in a very powerful sandstorm. They are really NOT > > happy about adding anything to root cron or 'at' or into their > > imprenetrable schedule, and database backups don't register much if at > > all on their 'things we want/need/have to do' radar. > > Is there any way at all of allowing the informix user to run the > > backup commands without ISM triggering the "07/27/10 10:15:41 savegrp: > > You are not authorized to run this command" error? It basically means > > that no bootstrap file can be created if user informix runs the > > backups (whether database ot logical log) > > sudo? > Sudo works. We do that here with people who have to do some simple maintenance work. The only word of caution is to be careful how you log their sessions because it can really kill performance if you have an i/o bottleneck. _________________________________________________________________ The New Busy is not the old busy. Search, chat and e-mail from your inbox. http://www.windowslive.com/campaign/thenewbusy?ocid=PID28326::T:WLMTAGL:ON:WL:en-US:WM_HMP:042010_3
On 27/07/2010 16:08, Malc wrote: >> >> sudo? man sudoers no passwords required -- This message has been scanned for viruses and dangerous content by OpenProtect(http://www.openprotect.com), and is believed to be clean.
On Jul 27, 4:18 pm, Clive Eisen <cl...@serendipita.com> wrote: > On 27/07/2010 16:08, Malc wrote: > > > > >> sudo? > > man sudoers > > no passwords required > Ah promising - set up an alias and assign the command string to that alias with NOPASSWD set... Hmm - looks like the call to 'savegrp' is made from within the legato executable; experimentation is in order then!
On 27/07/2010 16:50, Malc wrote: > On Jul 27, 4:18 pm, Clive Eisen<cl...@serendipita.com> wrote: >> On 27/07/2010 16:08, Malc wrote: >> >> >> >>>> sudo? >> >> man sudoers >> >> no passwords required >> > Ah promising - set up an alias and assign the command string to that > alias with NOPASSWD set... > Hmm - looks like the call to 'savegrp' is made from within the legato > executable; experimentation is in order then! Hmnn Well that means you will have to run legato sudo As you still need to 'type' sudo savegrp to make it happen even with sudoers Other thoughts 1) suid 2) use sudoers and binary edit the legato binary to get it to call say Savegrp 2a) where Legato is a script that execs sudo savegrp $@ or 2b) If your sysadmins don't like a script you can write a bit of C that does the same -- This message has been scanned for viruses and dangerous content by OpenProtect(http://www.openprotect.com), and is believed to be clean.
On 27 July, 10:23, Malc <i...@perrior.net> wrote: > One more thing ((c) 2010). > > It is a TOTAL pain in that with ISM you have to be root to run the > backup commands. > The root user round here is under tighter security than a very nervous > camel's backside in a very powerful sandstorm. They are really NOT > happy about adding anything to root cron or 'at' or into their > imprenetrable schedule, and database backups don't register much if at > all on their 'things we want/need/have to do' radar. > Is there any way at all of allowing the informix user to run the > backup commands without ISM triggering the "07/27/10 10:15:41 savegrp: > You are not authorized to run this command" error? It basically means > that no bootstrap file can be created if user informix runs the > backups (whether database ot logical log) > > Ta informix should be able to run backups fine including savegrp. Run ism_show -admins and check that informxi@hostname is configure as an admin for the ISM server other use ism_add -admins informix@hostname
On Jul 29, 7:56 pm, "da...@smooth1.co.uk" <da...@smooth1.co.uk> wrote: > > informix should be able to run backups fine including savegrp. > > Run > > ism_show -admins > > and check that informxi@hostname is configure as an admin for the ISM > server other use > > ism_add -admins informix@hostname Yup informix is in the admins list, first thing we checked, still no dice!