Re: Access denied using a PERL CGI script
Posted in 2000
Topics: Server Administration, Security, Permissions & Auditing
On Mon, 10 Jul 2000 18:54:28 GMT, Jonathan Leffler
<jleffler@informix.com> wrote:
>Paul King wrote:
>> I was trying to get my "example" PERL script (which still works in a
>> shell environment) to behave as a CGI script with the added HTML tags
>> to see if I can at least generate a web page with a table of data. The
>> PERL script on its own generates a table with little trouble.
>>
>> At the moment, I am trying to trace an "Access denied" error to the
>> database. It is a stubborn error, that persists whether the ownership
>> of the file is root.root or informix.informix. Under STARTI dbaccess,
>> I see the database (testdb@telepath) as "public". The owner of the
>> process which runs netscape is "informix." If anyone has any ideas,
>> let me know.
>>
>> Just for the record, I am not using the CGI module in Perl. I am using
>> a much smaller "perl-cgi.pm" module that does just the basics.
>
>I am inferring from your message that your webserver runs as user
>informix?
>That's an odd choice, but should be OK.
Actually, the database was owned and created by user informix. The
owner of the process that runs the CGI scripts appears to be user
"nobody". I think that is the way it is supposed to be. I am a novice
at CGI stuff, but I verified that user nobody was running the scripts
by creating a CGI script that had a one-line output in perl, namely
system("whoami");
And when the script was run in Netscape, the user was "nobody".
>
>Can you connect to testdb@telepath as user informix? Without providing
>a username or password, that is?
Yes.
>I expect that something doesn't trust
>something else. One of the key points is to be absolutely sure that you
>know which user ID is being used by your CGI script. Verify it; don't
>rely
>on what you think it is.
Thanks for your help.
Paul King
Paul King wrote:
>
> On Mon, 10 Jul 2000 18:54:28 GMT, Jonathan Leffler
> <jleffler@informix.com> wrote:
>
> >Paul King wrote:
> >> I was trying to get my "example" PERL script (which still works in a
> >> shell environment) to behave as a CGI script with the added HTML tags
> >> to see if I can at least generate a web page with a table of data. The
> >> PERL script on its own generates a table with little trouble.
> >>
> >> At the moment, I am trying to trace an "Access denied" error to the
> >> database. It is a stubborn error, that persists whether the ownership
> >> of the file is root.root or informix.informix. Under STARTI dbaccess,
> >> I see the database (testdb@telepath) as "public". The owner of the
> >> process which runs netscape is "informix." If anyone has any ideas,
> >> let me know.
> >>
> >> Just for the record, I am not using the CGI module in Perl. I am using
> >> a much smaller "perl-cgi.pm" module that does just the basics.
> >
> >I am inferring from your message that your webserver runs as user
> >informix?
> >That's an odd choice, but should be OK.
>
> Actually, the database was owned and created by user informix. The
> owner of the process that runs the CGI scripts appears to be user
> "nobody". I think that is the way it is supposed to be. I am a novice
> at CGI stuff, but I verified that user nobody was running the scripts
> by creating a CGI script that had a one-line output in perl, namely
>
> system("whoami");
>
> And when the script was run in Netscape, the user was "nobody".
OK, then either the script must use a CONNECT statement and specify
that it wants to connect as user informix and include the necessary
password, or you need to set up the database so that 'nobody' can
access it (meaning the webserver user).
> >Can you connect to testdb@telepath as user informix? Without providing
> >a username or password, that is?
>
> Yes.
>
> >I expect that something doesn't trust
> >something else. One of the key points is to be absolutely sure that you
> >know which user ID is being used by your CGI script. Verify it; don't
> >rely on what you think it is.
>
> Thanks for your help.
I suspect that means you had deduced what I just said, but I'm making
sure the message is received.
99% of the time, problems with web servers and Informix are related to
environment, taking a rather large view of environment to include both
environment variables and properties such as the user who is actually
accessing the database.
--
Yours,
Jonathan Leffler (Jonathan.Leffler@Informix.com) #include <disclaimer.h>
Guardian of DBD::Informix v1.00.PC1 -- http://www.perl.com/CPAN
"I don't suffer from insanity; I enjoy every minute of it!"