Re: Security in PC-Client/UNIX Server environment
Posted in 1995
On Apr 5, 11:51pm, Informix Sysadmin wrote: > Subject: Security in PC-Client/UNIX Server environment > > In our line of work, it is critical that we know WHO did WHAT to the > DATABASE when. Well, using the dumb terminal approach of UNIX, we have > that. But, I admit to being completely confused about the front-end on a > PC thing. If we use our PC app to determine who you are, can someone not > simply hack something onto a PC, and call themselves that? If we have to > determine who the user is at every update, then (it would appear) that we > will have to do that within the engine...no? Can anyone enlighten us on > this one? > > B. Brian, The PC user still has to have a legitimate account on the server just as they do on the dumb terminal. The PC provides this account and a password when logging on to the server so this login name can be used as your identifier to record who did what to the database in the same fashion as you did with the dumb terminal. The only difference is that you can store the password on the PC and have it automatically provided when the PC logs onto the server. This option does break your security and should be avoided as it allows anyone to use the PC and all you can tell is that the change came from a specific PC. There is, unfortunately, no automatic way of ensuring that all PC's have this option turned off. You have to use manual procedures to check on a regular basis that users have not configured the PC to do this. Cheers - Jim -- ----------------------------------------------------------------------------- Jim Gordon DHL Airways Inc. jgordon@us.dhl.com ----------------------------------------------------------------------------- My opinions are my own. They may vary with time but they remain mine!