Assigning Informix as group/owner of apps?
Posted in 1994
In Message-Id: <3capru$9ln@kelly.teleport.com>
cpilot@teleport.com (Richard Shannon) writes:
> [...]
> 1. Do you recommend using the Informix account to manage the database.
> ie. granting/revoking permissions, adding/dropping tables, dbload,
> etc.
>
> Would it be better to use a separate administrative account for this?
> Why?
>
> 2. What are the pros/cons/issues when using Informix as owner and group
> of all database applications and having all users being members of
> that group?
> [...]
We use the informix account ONLY for dba tasks, and not for all of those.
You should have an informix account and informix group, both of these
distinct from all other accounts. No one but user informix in group
informix. If you're using SE, then informix doesn't even have to have
a password, as you can do all you need to from the root account. In
OnLine, informix has to do some things from the command line.
We have an "application" account which own all the non-system tables.
It sets permissions on those tables, owns all the source, data, and
executable directories and code. This keeps separate the functions of
the data administrator and the engine administrator. We have a distinct
dba function (and a person to do it.) Even if you don't yet, you
can benefit from planning to be big if you EVER MIGHT get big.
There are grave security issues at stake when you start deviating from
these guidelines. Having users in the informix group gives them the
power to do things inside the INFORMIXDIR that you don't want. There
are no pros worth the risks of having all users members of group informix.
We wrote a set of scripts which handle the tasks of setting, showing,
revoking permissions for a list of tables for a given user. They are
just loops which echo "revoke all on table tabname for user username"
(or whatever) to isql. You can also manually diddle the systabauth
table (as informix) to get user permissions set, but that's pretty manly.
Good luck,
__________________________________________________________________
| Clem Akins Standard Disclaimers Apply |
|Reynolds Metals Co, Alloys Plant "Climb High, Cave Deep!" |
| Muscle Shoals, Alabama USA cwakins@leia.alloys.rmc.com |
|________________________________________________________________|