User Authentification
Posted in 2000
Topics: Server Administration, Platform-Specific Issues
Hello!
Informix Dynamic Server 2000, Linux version.
Is there a possibility to configure IDS so that a user identification is
required?
As far as I see by now, each unix user on the machine running IDS is
also allowed to connect to the database server.
So, if I happen to know a unix user's account I am able to access all
data he/she is allowed to access on the server. I would like to set up a
second barrier between the server and a successful 'dbaccess'.
(Actually I cannot imagine that there is no such possibility, but so far
I did not find any configuration option for that problem.)
Thank you for any hint.
Norbert
Norbert Heidbrink wrote:
>
> Hello!
>
> Informix Dynamic Server 2000, Linux version.
>
> Is there a possibility to configure IDS so that a user identification is
> required?
> As far as I see by now, each unix user on the machine running IDS is
> also allowed to connect to the database server.
> So, if I happen to know a unix user's account I am able to access all
> data he/she is allowed to access on the server. I would like to set up a
> second barrier between the server and a successful 'dbaccess'.
>
> (Actually I cannot imagine that there is no such possibility, but so far
> I did not find any configuration option for that problem.)
Informix relies strictly on host system security and has no login
protection of its own. Even the CONNECT TO ... USING ... uses the user's
system login and password. If someone has another user's login and
password he/she has access to everything ELSE that that user has access to.
Why are you not concerned about that over and above his Informix access?
Can you see that there is no difference? That user needs to change his/her
password and guard it better. Looks like if Informix did have another
security layer this user would be no more diligent about protecting THAT
password than his UNIX password!
This is a battle you cannot win. It very much reminds me of an old boss of
mine. We had a program that would delete data when run. All was fine until
some moron ran it with the wrong parameters and deleted needed records. My
boss (we did not know about pointy hairs back then) had the ultimate
solution! Prompt the user to verify that this was what he wanted to do,
make him press enter again. OK for a while then poof a different idiot
did the same thing and of course he was sure he wanted to delete those rows
so he pressed enter. Back comes the boss: "OK make then enter 'Y' and
press enter. Good for another month. New idiot, new data loss, same boss.
"Hmmm, can we make them reenter the key data? ..."
You see where this is going, right! Someone once said, "The problem with
making things fool proof is that fools are so devious!" So are those who
would avoid, circumvent, ignore, and crack security precautions. Give
someone access who needs it and that individual MUST safeguard the basic
security by safeguarding his/her password. PERIOD!
Art S. Kagel