Re: Increase Security
Posted in 1995
> Our database is Informix sql 3.2 running on SCO 3.2.2
> The database and all tables are currently set to "GRANT DBA to PUBLIC"
> and has been fine when adding new users especially as they are
> restricted by menu access to 4gl programs. I am currently opening up the
> systems to make use of mail and shell programs for all users, but I am
> concerned that the databases could be left open to meddling and
> corruption.
Anyone with DBA privileges can drop the database, and since public
has DBA privileges, anyone could accidently drop the database. All
it takes is to go into isql and type DDY.
> What is the best way to open the system, keep the flexibility for new
> user additions but maintain security for the database.
I would recommend that you revoke all privileges from public and
develope a set of scripts to manage your security. One way with
shell scripts is something like this:
## shell script to grant privileges
USER=$1 ## pass the user name as an argument
## Start dbaccess and grant privileges
dbaccess dbname - <<EOF
grant connect to $USER;
grant select, update, insert on tabname1 to $USER;
grant select, update, insert on tabname2 to $USER;
grant select, update, insert on tabname3 to $USER;
grant select, update, insert on tabname4 to $USER;-- etc ....
EOF
## End shell script to grant privileges
This way when you get a new user, all you have to do is
run a script with the users name as an argument. You could
also develope a 4GL program to do it.
If you would like to get a bit more advanced, we have a product,
DB Privileges that does all this for you and may cost less then
the time it would take for you to develope your own system. The
following is the description we have in the Informix InSync Catalog.
A 30 day 4GL RDS demo is available.
---------------------------------------------------------------
DB Privileges is an interface to Informix database privileges. It
allows a database administrator to quickly change user database,
table or column permissions on a data entry screen without any
programming. DB Privileges is easy enough for a non technical
security officer to maintain database privileges.
DB Privileges is the first product that allows a database
administrator to create and manage groups of users with common
Informix database permissions. Add a user to a group and the user
instantly inherits all the group database permissions. Remove a
user and all their privileges will be automatically revoked.
DB Privileges is available as Informix-4GL code that may be
customized to meet your specific requirements. An enterprise
version of DB Privileges is available that controls database
privileges across multiple database servers.
Regards - Lester
#############################################################################
# Lester Knutsen lester@access.digex.net #
# Advanced DataTools Corporation Voice: 703-256-0267 #
# Grant group privileges for Informix databases with DB Privileges #
# Visit our Web page: http://www.access.digex.net/~lester #
#############################################################################