Must be a DBSA to run this program
Posted in 2009
Topics: Server Administration
Hello
We need to perform some administrative activity like "onmode -sky ,oninit" for
this purpose we are using following configuration parameter, but we are unable
to perform these activities and got error "Must be a DBSA to run this program".
ADMIN_USER_MODE_WITH_DBSA 1
ADMIN_MODE_USERS mabrar
Can we perform these activities with the user who is not a member of Informix
group?
ADMIN_USER_MODE_WITH_DBSA## Controls who can connect to IDS in administration mode. Acceptable values
are:
## 1 DBSAs, users specified by ADMIN_MODE_USERS, and the user Informix
## 0 Only the user informix (Default)
ADMIN_MODE_USERS## Specifies the user names, separated by commas, who can connect to IDS in
administration mode, in addition to the user Informix
Thanks
The user must belong to the group that owns the directory $INFORMIXDIR/etc
I have detailed info about role separation here:
http://informix-technology.blogspot.com/2008/02/compliance-role-separation-and-a
udit.html
The manual to check is the "trusted facility" or "security guide" in latest
releases.
Regards.
On Tue, Apr 7, 2009 at 12:53 PM, OMER KHAN <oskhan@i2cinc.com> wrote:
> Hello
>
> We need to perform some administrative activity like "onmode -sky ,oninit"
> for
> this purpose we are using following configuration parameter, but we are
> unable
> to perform these activities and got error "Must be a DBSA to run this
> program".
>
> ADMIN_USER_MODE_WITH_DBSA 1
> ADMIN_MODE_USERS mabrar>
> Can we perform these activities with the user who is not a member of
> Informix
> group?
>
> ADMIN_USER_MODE_WITH_DBSA> ## Controls who can connect to IDS in administration mode. Acceptable
> values
> are:
> ## 1 DBSAs, users specified by ADMIN_MODE_USERS, and the user Informix
> ## 0 Only the user informix (Default)
> ADMIN_MODE_USERS> ## Specifies the user names, separated by commas, who can connect to IDS in
> administration mode, in addition to the user Informix
>
> Thanks
>
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
--
Fernando Nunes
Portugal
http://informix-technology.blogspot.com
My email works... but I don't check it frequently...
--001636c5a82f5513ba0466f6cd63
On Tue, Apr 7, 2009 at 04:53, OMER KHAN <oskhan@i2cinc.com> wrote:
> We need to perform some administrative activity like "onmode -sky ,oninit"
for
> this purpose we are using following configuration parameter, but we are
unable
> to perform these activities and got error "Must be a DBSA to run this
> program".
>
> ADMIN_USER_MODE_WITH_DBSA 1
> ADMIN_MODE_USERS mabrar>
> Can we perform these activities with the user who is not a member of Informix
> group?
>
> ADMIN_USER_MODE_WITH_DBSA> ## Controls who can connect to IDS in administration mode. Acceptable values
> are:
> ## 1 DBSAs, users specified by ADMIN_MODE_USERS, and the user Informix
> ## 0 Only the user informix (Default)
> ADMIN_MODE_USERS> ## Specifies the user names, separated by commas, who can connect to IDS in
> administration mode, in addition to the user Informix
The DBSA group is determined by the group that owns $INFORMIXDIR/etc.
By default, that group is group informix, so the default DBSA group is
group informix. If you are using a Unix-like system, then you can
change the group that owns the directory to a suitably restricted
alternative group, and then the members of that alternative group who
are listed in the ADMIN_MODE_USERS parameter will be able to
administer IDS in administrative mode. Note that this means you can
have two classes of DBSA - those who can connect in administrative
mode and those who can't. However, the distinction is fragile; the
second class can change things so that they can connect after all.
If you want these users to be able to start IDS, then you need to
modify the permissions on $INFORMIXDIR/bin/oninit with 'chmod o+x'
(add execute permission for others). This is safe; IDS checks whether
you are a DBSA before going very far at all (and definitely before
doing any damage - or even file accesses). This is about the only
time I'm going to suggest you relax the permissions on files under
$INFORMIXDIR - make the most of it.
--
Jonathan Leffler #include <disclaimer.h>
Email: jleffler@earthlink.net, jleffler@us.ibm.com
Guardian of DBD::Informix v2008.0513 -- http://dbi.perl.org/
"Blessed are we who can laugh at ourselves, for we shall never cease
to be amused."
NB: Please do not use this email for correspondence.
I don't necessarily read it every week, even.
Robert Benchley - "A dog teaches a boy fidelity, perseverance,
and to turn around three times before lying down." -
http://www.brainyquote.com/quotes/authors/r/robert_benchley.html