dbaccess Permissions
Posted in 1995
Folks,
I know it is not generally considered a good idea to change Unix file
permissions on Informix files, but I do have a problem I think this change
would help me with anyway, or maybe you all have a better solution.
Problem: User A has been granted a wide variety of permissions to Informix
tables and databases because the user runs applications which
require these permissions. However, if User A were to become a
more advanced user, he/she could easily execute dbaccess from the
Unix command line and create all sorts of havoc by inserting,
updating, and deleting data which I really don't want them touching
except through an application program. (This is becoming as issue
since users now have access to Unix where before they were confined
to menus.)
Potential Solutions:
1) Change dbaccess permissions from: -rwxr-xr-x informix informix
to: -rwxr-x--- informix infmx_user
where the group infmx_user includes only the half dozen people who have
any business executing this program. At the moment this is my preferred
solution. Are there any problems with this scenario I am missing?
2) Write a set of stored procedures which are executed as dba to grant
and revoke privileges every time a user enters or exits a program.
I really don't think this is a very efficient thing to do and I would
prefer to avoid it.
3) Any other brilliant solutions any of you have come up with and may be
using?
Thanks for any comments and/or ideas.
Regards,
- Cathy
--------------------------------------------------------------------------------
Cathy Kipp e-mail: ckipp@vth1.vth.colostate.edu Phone: (970) 491-1294
Colorado State University Veterinary Teaching Hospital Fax: (970) 491-1205