Consultation of Privileges
Posted in 2004
Topics: General Discussion
A consultation of Privileges:
When the instance is created, by default it is initialized with the tables
of the system: to sysmaster and sysutils.... these are created with the
following privileges:
select *from sysmasterinformix D
public C
select *from sysutilsinformix D
public C
root D
The question is: IN THESE DATA BASES, I CAN ELIMINATE THE CONNECT PRIVILEGE
GROUP PUBLIC WITHOUT IT HAS IMPACT FOR THE EXISTING APPLICATIONS?
Thanks
_________________________________________________________________
Las mejores tiendas, los precios mas bajos, entregas en todo el mundo,
YupiMSN Compras: http://latam.msn.com/compras/
sending to informix-list
Dooku Maul wrote:
> A consultation of Privileges:
> When the instance is created, by default it is initialized with the tables
> of the system: to sysmaster and sysutils.... these are created with the
> following privileges:
> select *from sysmaster> informix D
> public C
>
> select *from sysutils> informix D
> public C
> root D
>
> The question is: IN THESE DATA BASES, I CAN ELIMINATE THE CONNECT PRIVILEGE
> GROUP PUBLIC WITHOUT IT HAS IMPACT FOR THE EXISTING APPLICATIONS?
You should be able to remove public access to the sysmaster and
sysutils databases without breaking anything that doesn't use them.
I'm not sure it is recommended - though there are some advantages to
doing so. And you may be surprised by the collection of things that
use sysmaster (in particular) and therefore break. SysUtils is
basically for ON-Bar, so that is more readily contained.
So, don't take this as complete permission to go ahead and do it.
However, you should not break things so badly that, if necessary, you
can re-grant connect permission to public and get back to where you were.
--
Jonathan Leffler #include <disclaimer.h>
Email: jleffler@earthlink.net, jleffler@us.ibm.com
Guardian of DBD::Informix v2003.04 -- http://dbi.perl.org/