Limit Access through ODBC
Posted in 2013
Topics: Connectivity: ODBC / JDBC / .NET
Hi all I am currently using the IDS 11.5 and most of my user are connecting through ODBC from windows with a specific database ID. But we also have some developer/user who is using the operating system accounts to access the informix DB through ODBC. Currently we are using the SYSDBOPEN and SYSDBCLOSE Procedures to monitor who is comming through the ODBC using OS account. Now come the issue, assume we want to block them, ans currently we are using the mulpliating of the /etc/passwd to block/release them. Thus i would like to ask is there a better way rather than mulpliating of the /etc/passwd file ?? Thanks & Regards Thomas Ng
The sysdbopen() function should block the connection if it returns an error code, IB. Art Art S. Kagel, Principal Consultant Advanced DataTools (www.advancedatatools.com) Blog: http://informix-myview.blogspot.com/ Disclaimer: Please keep in mind that my own opinions are my own opinions and do not reflect on my employer, Advanced DataTools, the IIUG, nor any other organization with which I am associated either explicitly, implicitly, or by inference. Neither do those opinions reflect those of other individuals affiliated with any entity with which I am affiliated nor those of the entities themselves. On Tue, Oct 29, 2013 at 2:57 AM, THOMAS NG <thye666@hotmail.com> wrote: > Hi all > > I am currently using the IDS 11.5 and most of my user are connecting > through > ODBC from windows with a specific database ID. > > But we also have some developer/user who is using the operating system > accounts to access the informix DB through ODBC. > > Currently we are using the SYSDBOPEN and SYSDBCLOSE Procedures to monitor > who > is comming through the ODBC using OS account. > > Now come the issue, assume we want to block them, ans currently we are > using > the mulpliating of the /etc/passwd to block/release them. > > Thus i would like to ask is there a better way rather than mulpliating of > the > /etc/passwd file ?? > > Thanks & Regards > > Thomas Ng > > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > --089e011828308ffcf204e9fda271
I'm not sure what you mean by "mulpliating" the /etc/passwd file, but: 1- Users will only be able to connect if thy have the connect privilege. If you have that to public, remove it and grant only to the allowed users. 2- In sysdbopen you can "RAISE EXCEPTION ... -746, "Get out of here, you nasty OS user!" 3- You could use PAM... but I think it would be an overkill for that In 11.70 you may have some more options as you can create internal, non-OS users. And in theory you can have private installations that won't even allow OS accounts (because that requires root and those instances don't run as root) Regards On Tue, Oct 29, 2013 at 6:57 AM, THOMAS NG <thye666@hotmail.com> wrote: > Hi all > > I am currently using the IDS 11.5 and most of my user are connecting > through > ODBC from windows with a specific database ID. > > But we also have some developer/user who is using the operating system > accounts to access the informix DB through ODBC. > > Currently we are using the SYSDBOPEN and SYSDBCLOSE Procedures to monitor > who > is comming through the ODBC using OS account. > > Now come the issue, assume we want to block them, ans currently we are > using > the mulpliating of the /etc/passwd to block/release them. > > Thus i would like to ask is there a better way rather than mulpliating of > the > /etc/passwd file ?? > > Thanks & Regards > > Thomas Ng > > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > -- Fernando Nunes Portugal http://informix-technology.blogspot.com My email works... but I don't check it frequently... --20cf307f32463313f604e9ff2d74