data access control
Posted in 2010
Topics: Security, Permissions & Auditing
Folks, IDS11.10 UC2 AIX5.3 We granted READ permission on most of our tables to Public. So all valid users have the default read privileges. We are going to have an exception : An newly added user will be prevented from reading some tables that are granted to Public already. We do not want to revoke the Read permission from Public.( since (1)many processes are still accessing the data with this grant. (2) not want to mess up the current privileges assignment....). Can we control a user's read access to a table that has the READ permission to public? Thanks, Frank --000e0cd70a8446ac4904849b4b78
Could you create a role for that specific user and set it as the default for the user? -----Original Message----- From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of FRANK Sent: Monday, April 19, 2010 1:40 PM To: ids@iiug.org Subject: data access control [19739] Folks, IDS11.10 UC2 AIX5.3 We granted READ permission on most of our tables to Public. So all valid users have the default read privileges. We are going to have an exception : An newly added user will be prevented from reading some tables that are granted to Public already. We do not want to revoke the Read permission from Public.( since (1)many processes are still accessing the data with this grant. (2) not want to mess up the current privileges assignment....). Can we control a user's read access to a table that has the READ permission to public? Thanks, Frank --000e0cd70a8446ac4904849b4b78 ******************************************************************************* Forum Note: Use "Reply" to post a response in the discussion forum.
No, you cannot. The PUBLIC user's privileges apply to anyone who does not have explicitly more extensive privilege than public. In effect they act as a minimal privilege level rather than a default level. Instead, create a ROLE for everyone else, grant that role to everyone else, make that role the DEFAULT role for everyone else, grant all of the basic default privileges to this new role, then REVOKE all privileges from PUBLIC. Since it is likely that at some point you will have other users like this new underprivileged user, you should just create a ROLE for that category of users, grant the correct privileges to it, grant that role to this new user and make it his default ROLE. Now any new users just have to be added to the correct ROLE, granted the role and have it set as their default role. POOF! Best practices for any production systems? User PUBLIC does not have any privileges at all! Art Art S. Kagel Advanced DataTools (www.advancedatatools.com) IIUG Board of Directors (art@iiug.org) See you at the 2010 IIUG Informix Conference April 25-28, 2010 Overland Park (Kansas City), KS www.iiug.org/conf Disclaimer: Please keep in mind that my own opinions are my own opinions and do not reflect on my employer, Advanced DataTools, the IIUG, nor any other organization with which I am associated either explicitly, implicitly, or by inference. Neither do those opinions reflect those of other individuals affiliated with any entity with which I am affiliated nor those of the entities themselves. On Mon, Apr 19, 2010 at 2:40 PM, FRANK <yunyaoqu@gmail.com> wrote: > Folks, > > IDS11.10 UC2 > AIX5.3 > > We granted READ permission on most of our tables to Public. So all valid > users have the default read privileges. > > We are going to have an exception : An newly added user will be prevented > from reading some tables that are granted to Public already. > > We do not want to revoke the Read permission from Public.( since (1)many > processes are still accessing the data with this grant. (2) not want to > mess up the current privileges assignment....). > > Can we control a user's read access to a table that has the READ permission > to public? > > Thanks, > Frank > > --000e0cd70a8446ac4904849b4b78 > > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > --001636ed69dad4d9b104849b88f7
Maybe you could revoke all the public permissions, and then use the user.sysdbopen() feature, in order to specify the differences, or not??? Regards. Alexandre Marini Tecnologia da Informação - DBA msn: alexandre_marini@hotmail.com SEFAZ-MS / SGI-UIMP / Sistemas IBM-Informix See you at the 2010 IIUG Informix Conference April 25-28, 2010 Overland Park (Kansas City), KS www.iiug.org/conf <http://www.iiug.org> Art Kagel escreveu: > No, you cannot. The PUBLIC user's privileges apply to anyone who does not > have explicitly more extensive privilege than public. In effect they act as > a minimal privilege level rather than a default level. Instead, create a > ROLE for everyone else, grant that role to everyone else, make that role the > DEFAULT role for everyone else, grant all of the basic default privileges to > this new role, then REVOKE all privileges from PUBLIC. Since it is likely > that at some point you will have other users like this new underprivileged > user, you should just create a ROLE for that category of users, grant the > correct privileges to it, grant that role to this new user and make it his > default ROLE. Now any new users just have to be added to the correct ROLE, > granted the role and have it set as their default role. POOF! > > Best practices for any production systems? User PUBLIC does not have any > privileges at all! > > Art > > Art S. Kagel > Advanced DataTools (www.advancedatatools.com) > IIUG Board of Directors (art@iiug.org) > > See you at the 2010 IIUG Informix Conference > April 25-28, 2010 > Overland Park (Kansas City), KS > www.iiug.org/conf > > Disclaimer: Please keep in mind that my own opinions are my own opinions and > do not reflect on my employer, Advanced DataTools, the IIUG, nor any other > organization with which I am associated either explicitly, implicitly, or by > inference. Neither do those opinions reflect those of other individuals > affiliated with any entity with which I am affiliated nor those of the > entities themselves. > > On Mon, Apr 19, 2010 at 2:40 PM, FRANK <yunyaoqu@gmail.com> wrote: > > >> Folks, >> >> IDS11.10 UC2 >> AIX5.3 >> >> We granted READ permission on most of our tables to Public. So all valid >> users have the default read privileges. >> >> We are going to have an exception : An newly added user will be prevented >> from reading some tables that are granted to Public already. >> >> We do not want to revoke the Read permission from Public.( since (1)many >> processes are still accessing the data with this grant. (2) not want to >> mess up the current privileges assignment....). >> >> Can we control a user's read access to a table that has the READ permission >> to public? >> >> Thanks, >> Frank >> >> --000e0cd70a8446ac4904849b4b78 >> >> >> >> >> > ******************************************************************************* > >> Forum Note: Use "Reply" to post a response in the discussion forum. >> >> >> > > --001636ed69dad4d9b104849b88f7 > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > > >
Thanks, Art! Will see if we can plan it. Frank On Mon, Apr 19, 2010 at 2:57 PM, Art Kagel <art.kagel@gmail.com> wrote: > No, you cannot. The PUBLIC user's privileges apply to anyone who does not > have explicitly more extensive privilege than public. In effect they act as > a minimal privilege level rather than a default level. Instead, create a > ROLE for everyone else, grant that role to everyone else, make that role > the > DEFAULT role for everyone else, grant all of the basic default privileges > to > this new role, then REVOKE all privileges from PUBLIC. Since it is likely > that at some point you will have other users like this new underprivileged > user, you should just create a ROLE for that category of users, grant the > correct privileges to it, grant that role to this new user and make it his > default ROLE. Now any new users just have to be added to the correct ROLE, > granted the role and have it set as their default role. POOF! > > Best practices for any production systems? User PUBLIC does not have any > privileges at all! > > Art > > Art S. Kagel > Advanced DataTools (www.advancedatatools.com) > IIUG Board of Directors (art@iiug.org) > > See you at the 2010 IIUG Informix Conference > April 25-28, 2010 > Overland Park (Kansas City), KS > www.iiug.org/conf > > Disclaimer: Please keep in mind that my own opinions are my own opinions > and > do not reflect on my employer, Advanced DataTools, the IIUG, nor any other > organization with which I am associated either explicitly, implicitly, or > by > inference. Neither do those opinions reflect those of other individuals > affiliated with any entity with which I am affiliated nor those of the > entities themselves. > > On Mon, Apr 19, 2010 at 2:40 PM, FRANK <yunyaoqu@gmail.com> wrote: > > > Folks, > > > > IDS11.10 UC2 > > AIX5.3 > > > > We granted READ permission on most of our tables to Public. So all valid > > users have the default read privileges. > > > > We are going to have an exception : An newly added user will be prevented > > from reading some tables that are granted to Public already. > > > > We do not want to revoke the Read permission from Public.( since (1)many > > processes are still accessing the data with this grant. (2) not want to > > mess up the current privileges assignment....). > > > > Can we control a user's read access to a table that has the READ > permission > > to public? > > > > Thanks, > > Frank > > > > --000e0cd70a8446ac4904849b4b78 > > > > > > > > > > ******************************************************************************* > > Forum Note: Use "Reply" to post a response in the discussion forum. > > > > > > --001636ed69dad4d9b104849b88f7 > > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > --000e0cd183321bf47404849c775c