Question on DBSA, Informix ID, and User IDs.
Posted in 2011
Topics: Installation, Setup & Upgrades, Server Administration
We have: =20 IDS 11.5, 10, 9.4, 9.2, 8.31, and 7.30 OS AIX, SUN, HP, MP-RAS, and etc. =20 Has anyone instituted an LDAP user ID login to a db_admin group of dba IDs and then say that group be granted DBSA. =20 Is it possible and how to be able to perform database DDL modifications without being the informix ID? Sure we could probably login as the DBA of the database. =20 We want to only use the informix ID for installs, instance builds and maintenance, and informix environment establishment. But after that the informix ID is not necessary to perform DDL maintenance. =20 Any discussion thoughts on this subject would be appreciated. =20 Thanks, ******************************************************************* Ernie Knox IT Database Administrator Specialist Sears Holdings - BU: I & T Group 3333 Beverly Rd., B4-266A Hoffman Estates, IL. 60179 Office: (847) 286-5735 Email: Ernest.Knox@searshc.com Blackberry: 2244650553@messaging.sprintpcs.com <mailto:2244650553@messaging.sprintpcs.com>=20 Page via Skytel: 2244650553@sprint.skytel.com <mailto:2244650553@sprint.skytel.com>=20 Informix or MySQL Primary: 9110210@skytel.com <mailto:9110210@skytel.com>=20 Informix or MySQL Secondary: 7276872@skytel.com <mailto:7276872@skytel.com>=20 =20 " Yes we can make a Change! " " It's always a great day to watch Sports - GO LIONS, TIGERS, and BEARS! " " Lets not forget - GO Pistons and Red Wings! " GSU ******************************************************************* =20 This message, including any attachments, is the property of Sears Holdings = Corporation and/or one of its subsidiaries. It is confidential and may cont= ain proprietary or legally privileged information. If you are not the inten= ded recipient, please delete it without reading the contents. Thank you.
I've found a bit difficult to understand your questions. if the answer doesn't match your needs please say so. On Mon, Mar 28, 2011 at 7:53 PM, Knox, Ernest <Ernest.Knox@searshc.com>wrote: > We have: > > =20 > > IDS 11.5, 10, 9.4, 9.2, 8.31, and 7.30 > > My answers apply to 11.5, 10 and mostly if not all to 9.4 (assuming a later fixpack). Never done this on 9.2 but it should work. Never worked with 8.x. 7.30 is too old. I'm afraid somethings may have changed... Needless to say you need to consider upgrading if you're using any of these versions except 11.5. > OS AIX, SUN, HP, MP-RAS, and etc. > > And maybe some of your OSes too... > Has anyone instituted an LDAP user ID login to a db_admin group of dba > IDs and then say that group be granted DBSA. > It should work as long as the system is configured to get user/group info from the LDAP. If the OS is happy with is, so should be Informix. > Is it possible and how to be able to perform database DDL modifications > without being the informix ID? Sure we could probably login as the DBA > of the database. > > Yes. Any user can be granted DBA. And depending on the DML you want, maybe just ownership of the objects and/or RESOURCE privilege will be enough > We want to only use the informix ID for installs, instance builds and > maintenance, and informix environment establishment. But after that the > informix ID is not necessary to perform DDL maintenance. > This is just a refinement of the above. A DBSA can manage the instance and a DBA can run DML. Note that DBSA != DBA (but you can grant DBA to your DBSAs) > Any discussion thoughts on this subject would be appreciated. > > My 2 cents... If you still have doubts, please explain them. Regards. -- Fernando Nunes Portugal http://informix-technology.blogspot.com My email works... but I don't check it frequently... --0015174bf1988654ab049f913511
We're trying to limit the use of the informix ID to only certain install and build functions. After that we want to perform database maintain from a generic DBA ID, but do we still know who that person is and what they are doing? How would a generic DBA ID be much different from the informix ID for the actual informix DBA? If we LDAP as ourselves and sudo to informix, you would know that multiple people are logged on as informix and who they are. If we LDAP as ourselves and sudo to a generic ID, you would know that multiple people are logged on as that generic ID and who they are. You would have to maybe change the password every 90 days or so, but do you really get the security of not using the informix ID? Just brainstorming. Thanks, ******************************************************************* Ernie Knox IT Database Administrator Specialist Sears Holdings - BU: I & T Group 3333 Beverly Rd., B4-266A Hoffman Estates, IL. 60179 Office: (847) 286-5735 Email: Ernest.Knox@searshc.com Blackberry: 2244650553@messaging.sprintpcs.com Page via Skytel: 2244650553@sprint.skytel.com Informix or MySQL Primary: 9110210@skytel.com Informix or MySQL Secondary: 7276872@skytel.com " Yes we can make a Change! " " It's always a great day to watch Sports - GO LIONS, TIGERS, and BEARS! " " Lets not forget - GO Pistons and Red Wings! " GSU ******************************************************************* -----Original Message----- From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of Fernando Nunes Sent: Monday, March 28, 2011 4:59 PM To: ids@iiug.org Subject: Re: Question on DBSA, Informix ID, and User IDs. [23218] I've found a bit difficult to understand your questions. if the answer doesn't match your needs please say so. On Mon, Mar 28, 2011 at 7:53 PM, Knox, Ernest <Ernest.Knox@searshc.com>wrote: > We have: > > =20 > > IDS 11.5, 10, 9.4, 9.2, 8.31, and 7.30 > > My answers apply to 11.5, 10 and mostly if not all to 9.4 (assuming a later fixpack). Never done this on 9.2 but it should work. Never worked with 8.x. 7.30 is too old. I'm afraid somethings may have changed... Needless to say you need to consider upgrading if you're using any of these versions except 11.5. > OS AIX, SUN, HP, MP-RAS, and etc. > > And maybe some of your OSes too... > Has anyone instituted an LDAP user ID login to a db_admin group of dba > IDs and then say that group be granted DBSA. > It should work as long as the system is configured to get user/group info from the LDAP. If the OS is happy with is, so should be Informix. > Is it possible and how to be able to perform database DDL modifications > without being the informix ID? Sure we could probably login as the DBA > of the database. > > Yes. Any user can be granted DBA. And depending on the DML you want, maybe just ownership of the objects and/or RESOURCE privilege will be enough > We want to only use the informix ID for installs, instance builds and > maintenance, and informix environment establishment. But after that the > informix ID is not necessary to perform DDL maintenance. > This is just a refinement of the above. A DBSA can manage the instance and a DBA can run DML. Note that DBSA != DBA (but you can grant DBA to your DBSAs) > Any discussion thoughts on this subject would be appreciated. > > My 2 cents... If you still have doubts, please explain them. Regards. -- Fernando Nunes Portugal http://informix-technology.blogspot.com My email works... but I don't check it frequently... --0015174bf1988654ab049f913511 ************************************************************************ ******* Forum Note: Use "Reply" to post a response in the discussion forum.
I believe you should look into individual users for DBA and DBSA and possibly consider the use of the auditing facility. But again, doing so in such old versions can be tricky. I've used it extensively since v7.31 without major issues. On Mon, Mar 28, 2011 at 10:14 PM, Knox, Ernest <Ernest.Knox@searshc.com>wrote: > We're trying to limit the use of the informix ID to only certain install > and build functions. After that we want to perform database maintain > from a generic DBA ID, but do we still know who that person is and what > they are doing? > If you want to take accountability seriously, you'll want proper role separation and individual users. > How would a generic DBA ID be much different from the informix ID for > the actual informix DBA? > It wouldn't in my opinion. Eventually it can have less privileges than informix. This would be the major advantages of that approach. > If we LDAP as ourselves and sudo to informix, you would know that > multiple people are logged on as informix and who they are. > > If we LDAP as ourselves and sudo to a generic ID, you would know that > multiple people are logged on as that generic ID and who they are. You > would have to maybe change the password every 90 days or so, but do you > really get the security of not using the informix ID? > > Just brainstorming. > > Sorry for the self publicity, but you may want to take a look here: http://informix-technology.blogspot.com/2008/02/compliance-role-separation-and-a udit.html Also a reading of the security guide would be helpful Regards -- Fernando Nunes Portugal http://informix-technology.blogspot.com My email works... but I don't check it frequently... --001636d348660c4380049f938c28