Active Users
Posted in 2006
An auditor asked for a system-generated list of Informix users with their permissions plus a list of administrators (IDS 9.40 on HP-UX). Replies explained there is no single report: database-level privileges come from each database's sysusers table (D/R/C types) and systabauth for table-level grants, while administrative rights are OS-based — user informix/root, members of the DBSA/informix group (role separation can designate a DBSA group), plus the permissions on $INFORMIXDIR/bin utilities and onconfig settings such as DBCREATE_PERMISSION. Suggestions included sudo for controlled onmode access. Resolution: compile the report from several queries and OS/file-permission checks.
Auto-generated by DrWatson from the posts below — may be imperfect; read the full thread.
Topics: Security, Permissions & Auditing, Versions, Editions & End-of-Life
Our auditors have asked that I provide the following: System generated listing of active Informix users (with their access permissions), as well as a system generated listing of Informix administrators. Is there such a listing? How do I generate such a listing? IDS 9.40.FC3 HPUX 11.11 Thanks, Chuck
On 15/12/06, CHUCK GILKER <cgilker@milbank.com> wrote:
>
> Our auditors have asked that I provide the following:
> System generated listing of active Informix users (with their access
> permissions), as well as a system generated listing of Informix
> administrators.
>
> Is there such a listing? How do I generate such a listing?
>
> IDS 9.40.FC3
> HPUX 11.11
>
> Thanks,
> Chuck
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
Chuck
SELECT * FROM sysuserswill show those users that have had specific permissions allocated to them.
usertype D is DBA, R is resource and C is connect. If a user is not
specified they inherit public's permission.
SELECT * FROM systabauthwill show table level permissions. Again, if a user is not named they
user public's permissions.
tabauth has 8 character positions:-
s = select
u = update
* = columne-level
i = insert
d = delete
x = create index
a = alter structure
r = references
Upper case means the user can give the permissions to other uers.
See also Inforix Guide to SQL - Reference
Keith
Can anyone listed as a DBA in the table sysusers run programs such as onmode?
If public is listed as a DBA in the table sysusers this means everyone not in
the table sysusers inherits DBA rights. Would have mean everyone is a DBA and
can run onmode? I know that is not the case, but am I confusing two different
issues? Who can run onmode? How can I get a list of users who can run onmode?
No. Only user informix or root can run onmode.
Art S. Kagel
----- Original Message -----
From: Chuck Gilker <ids@iiug.org>
At: 12/15 10:00:05
Can anyone listed as a DBA in the table sysusers run programs such as onmode?
If public is listed as a DBA in the table sysusers this means everyone not in
the table sysusers inherits DBA rights. Would have mean everyone is a DBA and
can run onmode? I know that is not the case, but am I confusing two different
issues? Who can run onmode? How can I get a list of users who can run onmode?
*******************************************************************************
Forum Note: Use "Reply" to post a response in the discussion forum.
CHUCK GILKER wrote:
> Can anyone listed as a DBA in the table sysusers run programs such as onmode?
> If public is listed as a DBA in the table sysusers this means everyone not in
> the table sysusers inherits DBA rights. Would have mean everyone is a DBA and
> can run onmode? I know that is not the case, but am I confusing two different
> issues? Who can run onmode? How can I get a list of users who can run onmode?
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
Well, let's see.
You could use the experimental method, and study the relation between user
types in sysusers and and onmode by creating fictitious users, granting them
DBA (important bit missing here) and then seeing if they can successfully run
onmode.
Or maybe - assuming that you are using any UNIX port - you could examine the
permissions of the onmode executable. Although not directly controlling who
can run onmode, that should give you a clue.
Or maybe you could open the administrator's reference, turn to the onmode page
and see who can run onmode straight from the horse's mouth.
I'll give you a hint. sysusers has a databasewide scope, onmode instancewide.
And no, it's not a good idea to grant DBA to public.
--
Ciao,
Marco
______________________________________________________________________________
Marco Greco /UK /IBM Standard disclaimers apply!
Structured Query Scripting Language http://www.4glworks.com/sqsl.htm
4glworks http://www.4glworks.com
Informix on Linux http://www.4glworks.com/ifmxlinux.htm
if the user is in the informix group (unix group) then that user will be able
to run onmode commands.
----- Original Message ----
From: CHUCK GILKER <cgilker@milbank.com>
To: ids@iiug.org
Sent: Friday, December 15, 2006 8:50:36 AM
Subject: Re: Active Users [8008]
Can anyone listed as a DBA in the table sysusers run programs such as onmode?
If public is listed as a DBA in the table sysusers this means everyone not in
the table sysusers inherits DBA rights. Would have mean everyone is a DBA and
can run onmode? I know that is not the case, but am I confusing two different
issues? Who can run onmode? How can I get a list of users who can run onmode?
*******************************************************************************
Forum Note: Use "Reply" to post a response in the discussion forum.
__________________________________________________
Do You Yahoo!?
Tired of spam? Yahoo! Mail has the best spam protection around
http://mail.yahoo.com
Actually, if you enable role separation, then everyone in the DBSA group can
run onmode.
----- Original Message ----
From: "ART KAGEL, BLOOMBERG/ 731 LEXIN" <kagel@bloomberg.net>
To: ids@iiug.org
Sent: Friday, December 15, 2006 9:00:41 AM
Subject: Re: Active Users [8009]
No. Only user informix or root can run onmode.
Art S. Kagel
----- Original Message -----
From: Chuck Gilker <ids@iiug.org>
At: 12/15 10:00:05
Can anyone listed as a DBA in the table sysusers run programs such as onmode?
If public is listed as a DBA in the table sysusers this means everyone not in
the table sysusers inherits DBA rights. Would have mean everyone is a DBA and
can run onmode? I know that is not the case, but am I confusing two different
issues? Who can run onmode? How can I get a list of users who can run onmode?
*******************************************************************************
Forum Note: Use "Reply" to post a response in the discussion forum.
*******************************************************************************
Forum Note: Use "Reply" to post a response in the discussion forum.
You can install the "sudo" command and configure it to a user "userA" to run
any command as informix
as "userA"
sudo -u informix onmode -"options"
in this way you can log whatever the "userA" runs as informix
Celso Coimbra
E-mail: ccoimbra@cleartech.com.br
-----Mensagem original-----
De: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org]Em nome de infx
dba
Enviada em: sexta-feira, 15 de dezembro de 2006 13:12
Para: ids@iiug.org
Assunto: Re: Active Users [8011]
if the user is in the informix group (unix group) then that user will be able
to run onmode commands.
----- Original Message ----
From: CHUCK GILKER <cgilker@milbank.com>
To: ids@iiug.org
Sent: Friday, December 15, 2006 8:50:36 AM
Subject: Re: Active Users [8008]
Can anyone listed as a DBA in the table sysusers run programs such as onmode?
If public is listed as a DBA in the table sysusers this means everyone not in
the table sysusers inherits DBA rights. Would have mean everyone is a DBA and
can run onmode? I know that is not the case, but am I confusing two different
issues? Who can run onmode? How can I get a list of users who can run onmode?
*******************************************************************************
Forum Note: Use "Reply" to post a response in the discussion forum.
__________________________________________________
Do You Yahoo!?
Tired of spam? Yahoo! Mail has the best spam protection around
http://mail.yahoo.com
*******************************************************************************
Forum Note: Use "Reply" to post a response in the discussion forum.
Allow me to elucidate.
Whenever you install an informix engine there is this line that we always seem
to hit no on.
"Do you want to enable role separation"
If you had said yes, you can specifiy a group which has DBSA privileges. In a
secure environment, this means you can now run informix as user "fred" so long
as fred is part of the group assigned DBSA privileges. And DBSA means you can
run every option of onmode, oninit, onstat, and oncheck.
You can still eanble role separation manually, but it's so much easier to just
reinstall.
If you have not enabled role separation, then only root and informix can run
everything, although people in the informix group can run most things.
----- Original Message ----
From: Mark Jamison <majp51@yahoo.com>
To: ids@iiug.org
Sent: Friday, December 15, 2006 9:57:27 AM
Subject: Re: Active Users [8012]
Actually, if you enable role separation, then everyone in the DBSA group can
run onmode.
----- Original Message ----
From: "ART KAGEL, BLOOMBERG/ 731 LEXIN" <kagel@bloomberg.net>
To: ids@iiug.org
Sent: Friday, December 15, 2006 9:00:41 AM
Subject: Re: Active Users [8009]
No. Only user informix or root can run onmode.
Art S. Kagel
----- Original Message -----
From: Chuck Gilker <ids@iiug.org>
At: 12/15 10:00:05
Can anyone listed as a DBA in the table sysusers run programs such as onmode?
If public is listed as a DBA in the table sysusers this means everyone not in
the table sysusers inherits DBA rights. Would have mean everyone is a DBA and
can run onmode? I know that is not the case, but am I confusing two different
issues? Who can run onmode? How can I get a list of users who can run onmode?
*******************************************************************************
Forum Note: Use "Reply" to post a response in the discussion forum.
*******************************************************************************
Forum Note: Use "Reply" to post a response in the discussion forum.
*******************************************************************************
Forum Note: Use "Reply" to post a response in the discussion forum.
Hi,
This is a more complex question than it might appear because there is no
precise definition of "Informix user" or "Informix Administrator". The
sysusers table in each database shows who can do what in or to that
database. But the question of who can use certain utlities (oncheck,
onmode, onspaces for example) is controlled by the permissions on those
executable files. So you have to check which users are in the groups that
are allowed to execute each utility. Next, the user informix has special
privileges, and in some cases those privileges extend to all users in the
group informix. Lastly, if you're using IDS 10, you'll have to show
what's configured in the onconfig file for the DBCREATE_PERMISSION
parameter. All of those things are necessary to show who's allowed to do
what to "Informix".
So I am not aware of any single report that will answer your auditors.
Depending on which OS you're using, you'll have to do things to show the
OS users and groups, you'll have to show the results of a query on the
sysmaster:sysdatabases table followed by a query on the sysusers table in
each of those databases, you'll have to show the results of onstat -c, and
you'll have to show the privileges for each of the executables in each
separate installation of IDS you have.
And, of course, if you have any privileges assigned to "public", then
anyone who can access the system can do those things. I hope that's not
the case.
Cheers,
Dick Snoke
IBM Software Group - ChannelWorks
dsnoke@us.ibm.com
(404) 487-1595
"CHUCK GILKER" <cgilker@milbank.com>
Sent by: ids-bounces@iiug.org
12/14/2006 08:27 PM
Please respond to
ids@iiug.org
To
ids@iiug.org
cc
Subject
Active Users [8004]
Our auditors have asked that I provide the following:
System generated listing of active Informix users (with their access
permissions), as well as a system generated listing of Informix
administrators.
Is there such a listing? How do I generate such a listing?
IDS 9.40.FC3
HPUX 11.11
Thanks,
Chuck
*******************************************************************************
Forum Note: Use "Reply" to post a response in the discussion forum.
> Chuck Gilker wrote:
> Can anyone listed as a DBA in the table sysusers run programs such as onmode?
> If public is listed as a DBA in the table sysusers this means everyone not in
> the table sysusers inherits DBA rights. Would have mean everyone is a DBA and
> can run onmode? I know that is not the case, but am I confusing two different
> issues? Who can run onmode? How can I get a list of users who can run onmode?
And ART KAGEL wrote:
> No. Only user informix or root can run onmode.
And Jonathan added:
And members of the DBSA group, which is group informix by default or
the group that owns $INFORMIXDIR/etc in detail (and it is configured
by registry on Windows). The group DBSA permission is sometimes a bit
spotty - some things may be refused that you wouldn't expect.
--
Jonathan Leffler #include <disclaimer.h>
Email: jleffler@earthlink.net, jleffler@us.ibm.com
Guardian of DBD::Informix v2005.02 -- http://dbi.perl.org/