RE: restricting database creation
Posted in 2003
Topics: Storage & Space Management, Server Administration, Versions, Editions & End-of-Life
Hi folks, I just want to add a few things to try to give a bit more clarity to my problem so I will try to diagram it in steps. 1) User JOE only has connect permissions to application tables/database. 2) User JOE can run SQL statements. 3) User JOE runs statement "create database <dbname> on <dbspace> with <whatever_logging>; 4) User JOE now is a DBA for his database that he has created. This is a production environment and I do not want to go around trying to figure out who is running wild and just creating new databases for their own pleasure/use outside the scope of what the server is designed for. So, with that said, we are running IDS 7.3.1.UC4 and I am trying to figure out how I can restrict it so that only certain users can actually create any databases on the system. I have heard of a DBCREATE_PERMISSIONS configuration parameter, but I don't know what the syntax for it is and i've been trying to play with a few different variations of what seems logical with no success. Any help with this problem would be greatly appreciated. Javier Zayas System Administrator Claremont University Consortium javier.zayas@cuc.claremont.edu <mailto:javier.zayas@cuc.claremont.edu> http://www.cuc.claremont.edu <http://www.cuc.claremont.edu> (909)607-3143
Javier, So, you have a user who is jeopardising the integrity of a production environment by unauthorised activities. Seems like something needs to be done to curb their activities. sysmaster:sysdatabases has an 'owner' column that may be useful to find out who has created the additional database/s. or change the permissions on the offending database/s and see who moans. It's a caring/sharing sort of day... Andy. In message <200309110041.h8B0f7Q7005797@ace.iiug.org>, Javier Zayas <javier_zayas@cuc.claremont.edu> writes >Hi folks, > >I just want to add a few things to try to give a bit more clarity to my >problem so I will try to diagram it in steps. > >1) User JOE only has connect permissions to application >tables/database. >2) User JOE can run SQL statements. >3) User JOE runs statement "create database <dbname> on <dbspace> with ><whatever_logging>; >4) User JOE now is a DBA for his database that he has created. > >This is a production environment and I do not want to go around trying to >figure out who is running wild and just creating new databases for their own >pleasure/use outside the scope of what the server is designed for. So, with >that said, we are running IDS 7.3.1.UC4 and I am trying to figure out how I >can restrict it so that only certain users can actually create any databases >on the system. I have heard of a DBCREATE_PERMISSIONS configuration >parameter, but I don't know what the syntax for it is and i've been trying >to play with a few different variations of what seems logical with no >success. Any help with this problem would be greatly appreciated. > >Javier Zayas >System Administrator >Claremont University Consortium >javier.zayas@cuc.claremont.edu <mailto:javier.zayas@cuc.claremont.edu> >http://www.cuc.claremont.edu <http://www.cuc.claremont.edu> >(909)607-3143 > > > -- Andrew Lennard andy@kontron.demon.co.uk