dbschema's output mixed with LBAC definition
Posted in 2008
Topics: Security, Permissions & Auditing, Platform-Specific Issues, Internationalization & Character Sets, Versions, Editions & End-of-Life
Just curious, the output of "dbschema" is added with LBAC's info(see below)
Can it be controlled?
Build Version: 11.10.UC2
Build Number: N158
Build Host: vach
Build OS: AIX 5.3
Build Date: Thu Oct 25 22:56:40 CDT 2007
GLS Version: glslib-4.50.UC2
Thanks,
Frank
informix@dolly $ dbschema -d noaa -t datatype_families
DBSCHEMA Schema Utility INFORMIX-SQL Version 11.10.UC2
Copyright IBM Corporation 1996, 2006 All rights reserved
Software Serial Number AAA#B000000
create security label component level
array ['top', 'sec', 'con', 'pub'];
create security label component levels
array ['high', 'medium', 'low'];
create security label component compartments
set {'president', 'hr', 'sales', 'tech'};
create security label component groups
tree ('company' root,
'hardware' under 'company',
'storage' under 'hardware',
'disk' under 'hardware',
'software' under 'company');
create security policy company
components level
with idslbacrules restrict not authorized write security label;
create security policy mypolicy
components levels, compartments, groups
with idslbacrules restrict not authorized write security label;
create security label company.director
component level 'con';
create security label mypolicy.hr
component levels 'high',
component compartments 'hr';
grant security label mypolicy.hr to fqu for all access;
grant security label company.director to fqu for read access;
{ TABLE "informix".datatype_families row size = 1244 number of columns = 8
index
size = 15 }
create table "informix".datatype_families
(
datatype_family char(10) not null ,
datafam_desc char(100) not null ,
datafam_long_desc char(1024),
url_id integer,
datafam_access_url char(100),
searchable char(1),
subscript_allowed char(1),
max_sum_hits integer,
primary key (datatype_family) constraint
"informix".datatype_families_pk
);
revoke all on "informix".datatype_families from "public" as "informix";
If your database has LBAC objects then dbschema will show it.. there is=
not
way to control that.
Manoj
=
"FRANK" =
<yunyaoqu@gmail.c =
om> =
To
Sent by: ids@iiug.org =
ids-bounces@iiug. =
cc
org =
Subj=
ect
dbschema's output mixed with LBA=
C
04/28/2008 12:31 definition [11918] =
PM =
=
=
Please respond to =
ids@iiug.org =
=
=
Just curious, the output of "dbschema" is added with LBAC's info(see be=
low)
Can it be controlled?
Build Version: 11.10.UC2
Build Number: N158
Build Host: vach
Build OS: AIX 5.3
Build Date: Thu Oct 25 22:56:40 CDT 2007
GLS Version: glslib-4.50.UC2
Thanks,
Frank
informix@dolly $ dbschema -d noaa -t datatype_families
DBSCHEMA Schema Utility INFORMIX-SQL Version 11.10.UC2
Copyright IBM Corporation 1996, 2006 All rights reserved
Software Serial Number AAA#B000000
create security label component level
array ['top', 'sec', 'con', 'pub'];
create security label component levels
array ['high', 'medium', 'low'];
create security label component compartments
set {'president', 'hr', 'sales', 'tech'};
create security label component groups
tree ('company' root,
'hardware' under 'company',
'storage' under 'hardware',
'disk' under 'hardware',
'software' under 'company');
create security policy company
components level
with idslbacrules restrict not authorized write security label;
create security policy mypolicy
components levels, compartments, groups
with idslbacrules restrict not authorized write security label;
create security label company.director
component level 'con';
create security label mypolicy.hr
component levels 'high',
component compartments 'hr';
grant security label mypolicy.hr to fqu for all access;
grant security label company.director to fqu for read access;
{ TABLE "informix".datatype_families row size =3D 1244 number of column=
s =3D 8
index
size =3D 15 }
create table "informix".datatype_families
(
datatype_family char(10) not null ,
datafam_desc char(100) not null ,
datafam_long_desc char(1024),
url_id integer,
datafam_access_url char(100),
searchable char(1),
subscript_allowed char(1),
max_sum_hits integer,
primary key (datatype_family) constraint
"informix".datatype_families_pk
);
revoke all on "informix".datatype_families from "public" as "informix";=
***********************************************************************=
********
Forum Note: Use "Reply" to post a response in the discussion forum.
See you at the IIUG Informix 2008 Conference
The Power Conference for Informix Professionals
April 27 - 30, 2008 Marriott Overland Park (Kansas City), Kansas
http://www.iiug.org/conf
Registration Now Open!!
=