Privilege error question
Posted in 2014
Topics: Security, Permissions & Auditing, Jobs, Consulting & Announcements
When running the following as informix:
grant sesessionauth on "public" to "informix";
I sometimes get:
8200: User (informix) does not have DBSECADM authority.
Why does this happen and how can I fix it. This is migrating a database
from one platform to another.
Art
Art S. Kagel, Principal Consultant
ASK Database Management
Blog: http://informix-myview.blogspot.com/
Disclaimer: Please keep in mind that my own opinions are my own opinions
and do not reflect on the IIUG, nor any other organization with which I am
associated either explicitly, implicitly, or by inference. Neither do
those opinions reflect those of other individuals affiliated with any
entity with which I am affiliated nor those of the entities themselves.
--001a11c3bd506325e00501a4430b
New installations will have that behavior. In place upgrades won't.
You need to grant the DBSECADM to Informix with a DBSA which can be
informix (!)
it's granted on an instance level... not at a database level, although you
must be connected to a database....
Regards
On Thu, Aug 28, 2014 at 12:51 AM, Art Kagel <art.kagel@gmail.com> wrote:
> When running the following as informix:
>
> grant sesessionauth on "public" to "informix";>
> I sometimes get:
>
> 8200: User (informix) does not have DBSECADM authority.>
> Why does this happen and how can I fix it. This is migrating a database
> from one platform to another.
>
> Art
>
> Art S. Kagel, Principal Consultant
> ASK Database Management
>
> Blog: http://informix-myview.blogspot.com/
>
> Disclaimer: Please keep in mind that my own opinions are my own opinions
> and do not reflect on the IIUG, nor any other organization with which I am
> associated either explicitly, implicitly, or by inference. Neither do
> those opinions reflect those of other individuals affiliated with any
> entity with which I am affiliated nor those of the entities themselves.
>
> --001a11c3bd506325e00501a4430b
>
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
--
Fernando Nunes
Portugal
http://informix-technology.blogspot.com
My email works... but I don't check it frequently...
--089e01537eba18c36e0501a4658f
Ahh, great! Thanks Fernando. Art --001a11345d66fa7e340501a47cd7
Yesterday I got the feeling I was missing something but I could not remember what... Not relevant to your situation, but because user informix cannot GRANT DBSESSIONAUTH TO informix; if you need to do it explicitly for informix, you need to create another DBSA (someone belonging to group informix by default), and then: As informix/some_user: GRANT DBSECADM TO some_user; As some_user: GRANT DBSESSIONAUTH TO informix; long live security rules! :) The reason why upgrades don't need this is for compatibility reasons. Before whichever version (11.10 I think) that introduced DBSECADM the informix user could do the GRANT SESSIONAUTH... so as we're so strick on not breaking compatibility even when it makes sense, during inplace upgrades from 11.10- to 11.10+ the privilege is automatically granted. Regards. On Thu, Aug 28, 2014 at 1:07 AM, Art Kagel <art.kagel@gmail.com> wrote: > Ahh, great! Thanks Fernando. > > Art > > --001a11345d66fa7e340501a47cd7 > > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > -- Fernando Nunes Portugal http://informix-technology.blogspot.com My email works... but I don't check it frequently... --089e01537eba1618c60501afbc4f