Re: Restricting ODBC access
Posted in 1998
Jacob Salomon wrote: > [ DBA's nightmare with ODBC access ] > Can anyone come up with a way to prevent database access via ODBC? I > can't simply deny ODBC drivers to all PC users - there are other > databases to be accessed. Jake, I share your nightmare. We have the same setup: UNIX accounts which only access the database via an application are ok, but ODBC access with the UNIX privileges can wreak havoc on the database. Using ROLEs in 7.x may help, no option for us since we are still in 5.x. Using Openlink or another server-based ODBC engine is an option, since it allows you to administer ODBC access privileges centrally. However, this solution will only be secure if you can totally shut off Informix-Net or -Star (in 5.x). We cannot because we have our 4GL and ESQL/C applications on an application server that has to access the Online database server via I-Net. I don't know if it is possible to replace the native Informix network access via I-Net (which requires no change in the application, just an appropriate setting of DBPATH) with Openlink or similar. Even if an Openlink client were available for our UNIX platform (SINIX), I'm afraid I'd have to considerably change our application so it could make use of it. Regards, Richard -- +--------------------------+------------------------------------------+ | Dr. Richard Spitz | INTERNET: spitz@ana.med.uni-muenchen.de | | EDV-Gruppe Anaesthesie | Tel : +49-89-7095-3413 | | Klinikum Grosshadern | FAX : +49-89-7095-8886 | | 81366 Munich, Germany | GSM : +49-172-8933578 | +--------------------------+------------------------------------------+