IDS 9.40.uc4 'onstat -g sql'
Posted in 2004
Topics: Installation, Setup & Upgrades, Stored Procedures & SPL, Server Administration, Versions, Editions & End-of-Life
Hi all...
I just installed the above release...once my development team started
banging on it they quickly noticed they could no longer do an 'onstat -g
sql xxx' ... command comes back and tells them they bust be a dba...I
contacted IBM support and they verified that this is how the command should
now behave...also told me they had a bunch of "feature" request to put it
back. They made the change for security reasons...there work around was to
write a SPL to get the data out of the sysmaster tables...which of course
can be done easily enough...Here's my question though...has anyone come up
with a work around the security...my developers want to see it the way it
"used" to be...
Thanks for any help!
Peter Logan
Senior DBA
Spartan Stores, INC.
850 76th. Street SW
Byron Center MI 49315
--0__=09BBE5A9DFDA26EE8f9e8a93df938690918c09BBE5A9DFDA26EE
Content-type: multipart/alternative;
Boundary="1__=09BBE5A9DFDA26EE8f9e8a93df938690918c09BBE5A9DFDA26EE"
--1__=09BBE5A9DFDA26EE8f9e8a93df938690918c09BBE5A9DFDA26EE
Content-type: text/plain; charset=US-ASCII
Content-transfer-encoding: quoted-printable
Sigh.....
When we added the code to display the host variables instead of '?' a l=
ot
of customers considered it to be a security violation because anyone co=
uld
see what the actual data was that was being used to populate the table.=
(I
could see what your salary was set to. ) So we felt that we needed to
tighten up the display of the onstat -g sql just a bit.
I fully agree, however, the only thing that needed to be restricted was=
the
display of the host variables, not the entire onstat -g sql output.
And yes - it is foolish to lock down onstat when the same information c=
an
be obtained from sysmaster.
M.P.
=
"Peter_Logan...." =
<Peter_Logan@spar =
tanstores.com> =
To
Sent by: ids@iiug.org =
forum.subscriber@ =
cc
iiug.org =
Subj=
ect
IDS 9.40.uc4 'onstat -g sql' [35=
78]
10/27/2004 07:08 =
AM =
=
=
=
=
Hi all...
I just installed the above release...once my development team started
banging on it they quickly noticed they could no longer do an 'onstat -=
g
sql xxx' ... command comes back and tells them they bust be a dba...I
contacted IBM support and they verified that this is how the command sh=
ould
now behave...also told me they had a bunch of "feature" request to put =
it
back. They made the change for security reasons...there work around wa=
s to
write a SPL to get the data out of the sysmaster tables...which of cour=
se
can be done easily enough...Here's my question though...has anyone come=
up
with a work around the security...my developers want to see it the way =
it
"used" to be...
Thanks for any help!
Peter Logan
Senior DBA
Spartan Stores, INC.
850 76th. Street SW
Byron Center MI 49315
=
--1__=09BBE5A9DFDA26EE8f9e8a93df938690918c09BBE5A9DFDA26EE
Content-type: text/html; charset=US-ASCII
Content-Disposition: inline
Content-transfer-encoding: quoted-printable
<html><body>
<p>Sigh.....<br>
<br>
When we added the code to display the host variables instead of '?' a l=
ot of customers considered it to be a security violation because anyone=
could see what the actual data was that was being used to populate the=
table. (I could see what your salary was set to. ) So we felt that w=
e needed to tighten up the display of the onstat -g sql just a bit.<br>=
<br>
I fully agree, however, the only thing that needed to be restricted was=
the display of the host variables, not the entire onstat -g sql output=
.<br>
<br>
And yes - it is foolish to lock down onstat when the same information c=
an be obtained from sysmaster.<br>
<br>
<br>
M.P. <br>
<br>
<img src=3D"cid:10__=3D09BBE5A9DFDA26EE8f9e8a93df938@us.ibm.com" width=3D=
"16" height=3D"16" alt=3D"Inactive hide details for "Peter_Logan..=
.." <Peter_Logan@spartanstores.com>">"Peter_Logan....&q=
uot; <Peter_Logan@spartanstores.com><br>
<br>
<br>
<table width=3D"100%" border=3D"0" cellspacing=3D"0" cellpadding=3D"0">=
<tr valign=3D"top"><td style=3D"background-image:url(cid:20__=3D09BBE5A=
9DFDA26EE8f9e8a93df938@us.ibm.com); background-repeat: no-repeat; " wid=
th=3D"40%">
<ul>
<ul>
<ul>
<ul><b><font size=3D"2">"Peter_Logan...." <Peter_Logan@spa=
rtanstores.com></font></b><font size=3D"2"> </font><br>
<font size=3D"2">Sent by: forum.subscriber@iiug.org</font>
<p><font size=3D"2">10/27/2004 07:08 AM</font></ul>
</ul>
</ul>
</ul>
</td><td width=3D"60%">
<table width=3D"100%" border=3D"0" cellspacing=3D"0" cellpadding=3D"0">=
<tr valign=3D"top"><td width=3D"1%" valign=3D"middle"><img src=3D"cid:3=
0__=3D09BBE5A9DFDA26EE8f9e8a93df938@us.ibm.com" border=3D"0" height=3D"=
1" width=3D"58" alt=3D""><br>
<div align=3D"right"><font size=3D"2">To</font></div></td><td width=3D"=
100%"><img src=3D"cid:30__=3D09BBE5A9DFDA26EE8f9e8a93df938@us.ibm.com" =
border=3D"0" height=3D"1" width=3D"1" alt=3D""><br>
<font size=3D"2">ids@iiug.org</font></td></tr>
<tr valign=3D"top"><td width=3D"1%" valign=3D"middle"><img src=3D"cid:3=
0__=3D09BBE5A9DFDA26EE8f9e8a93df938@us.ibm.com" border=3D"0" height=3D"=
1" width=3D"58" alt=3D""><br>
<div align=3D"right"><font size=3D"2">cc</font></div></td><td width=3D"=
100%"><img src=3D"cid:30__=3D09BBE5A9DFDA26EE8f9e8a93df938@us.ibm.com" =
border=3D"0" height=3D"1" width=3D"1" alt=3D""><br>
</td></tr>
<tr valign=3D"top"><td width=3D"1%" valign=3D"middle"><img src=3D"cid:3=
0__=3D09BBE5A9DFDA26EE8f9e8a93df938@us.ibm.com" border=3D"0" height=3D"=
1" width=3D"58" alt=3D""><br>
<div align=3D"right"><font size=3D"2">Subject</font></div></td><td widt=
h=3D"100%"><img src=3D"cid:30__=3D09BBE5A9DFDA26EE8f9e8a93df938@us.ibm.=
com" border=3D"0" height=3D"1" width=3D"1" alt=3D""><br>
<font size=3D"2">IDS 9.40.uc4 'onstat -g sql' [3578]</font></td></tr>
</table>
<table border=3D"0" cellspacing=3D"0" cellpadding=3D"0">
<tr valign=3D"top"><td width=3D"58"><img src=3D"cid:30__=3D09BBE5A9DFDA=
26EE8f9e8a93df938@us.ibm.com" border=3D"0" height=3D"1" width=3D"1" alt=
=3D""></td><td width=3D"336"><img src=3D"cid:30__=3D09BBE5A9DFDA26EE8f9=
e8a93df938@us.ibm.com" border=3D"0" height=3D"1" width=3D"1" alt=3D""><=
/td></tr>
</table>
</td></tr>
</table>
<br>
<tt><br>
<br>
<br>
<br>
Hi all...<br>
<br>
I just installed the above release...once my development team started<b=
r>
banging on it they quickly noticed they could no longer do an 'onstat -=
g<br>
sql xxx' ... command comes back and tells them they bust be a dba...I<b=
r>
contacted IBM support and they verified that this is how the command sh=
ould<br>
now behave...also told me they had a bunch of "feature" reque=
st to put it<br>
back. They made the change for security reasons...there work arou=
nd was to<br>
write a SPL to get the data out of the sysmaster tables...which of cour=
se<br>
can be done easily enough...Here's my questio
Related threads
- Posting from the Informix-list
- Migrating from IDS 9.40.UC6 to 11.50.UC3
- Ip for a network session
- questions onstat -g