Re: ODBC and Security
Posted in 1996
> bw000001@pixie.co.za ("Billy Wheeler") writes: > > It would be nice if Informix (and other RDBMS vendors) would extend their > > security mechanism to include such things as application id, remote system > > name, etc. > > It would have been nice if the ODBC standard had catered for such > things. Unfortunately, M*cr*s*ft don't seem to think about real-world > issues much - gets in the way of the bank balance... :) You should place the blame where the blame is due. ODBC is coordinated with the Call Level Interface originally specified by the SQL Access Group (I think they where called) and is now (or is soon to be) an ANSI standard. Roger Sipple (the founder of Informix) where (and possibly is) heavily involved in this work. Informix ought to take the lead in doing something with ODBC (or now the ANSI SQL/CLI or what it is called) to make it usable. The issues are also a little more difficult than others have been saying. 1. We are *not* in a position where we can accept that all updates are done via I4GL programs. The users demand GUI programs also for updates. For John Frantz and many others who have said that I4GL is adequate: Adequate doesn't count here, we are after excelense. That can in many situations *not* be achievd with a character based interface. 2. We may be able to use NewEra programs. However than the users gets I-Net on their PCs and installation of ODBC is almost a nobrainer. 3. We do want to be able to use ODBC to write programs with full access and update rights to the database. We are not alone. This is what *must* be solved, and solved to its full extent. All of the rest of the discussion is interesting and fine, but it is beside the point. Informix is also generally in a bad need to supply full security like we have with I4GL under Unix also when using ODBC. If this isn't a heavy market demand right now it will become so very soon. Anybody know what users do who have MS SQLserver running on Windows NT? Do they accept the crasy situation that any user can do anyting to the database or is there some good solution? What about other databases? OpenLink may have a workable solution if we can turn off the option for users of installing another ODBC driver. I am looking into this solution, but my first incarnation of trying to install their driver wasn't successfull, and my time for experiments in this area is very limited. Nils.Myklebust@ccmail.telemax.no NM-data AS, Toyenbekken 21, Oslo, Norway My opinions are those of my company