Re: ODBC and Security
Posted in 1996
"John H. Frantz" <john@rl.is> writes: > If the OpenLink > ODBC driver can control read/write permissions, then that may be a > good enough solution. But, does that stop anyone from using another > ODBC driver that's more open? If you have I-Star installed on your server, or you are running Informix On-Line 6.0 or later, then unfortunatley there are several ODBC drivers which could easily be obtained and installed by a savvy user to connect to the database with their usual permissions. OpenLink can only filter access made through its server based request broker. Most ODBC drivers go through I-NET on the PC to I-Star (pre-6.0) or direct to the engine (6.0 and later) on the server. > > I still think my original solution is most secure, which I'll repeat: > > Setup your users with read-only access to the database. Create one user > called "program" which has read/write access. Regardless of the user, > the central application connects to the database as user "program", > having the password hard coded. In this way, the central application > is the only client modifying data. Users can connect using ODBC or > anything else using their own id's to query and produce reports. Yours is a more secure approach, but is only possible if you have control over the main application (i.e. it's maintained in-house). I don't know if you can even do this kind of thing in Informix-4GL. (Is there a way to "re-login" to the server using 4GL?) It would be nice if Informix (and other RDBMS vendors) would extend their security mechanism to include such things as application id, remote system name, etc.