Restricting "Create Database"
Posted in 2000
Topics: Storage & Space Management, Security, Permissions & Auditing, Versions, Editions & End-of-Life
I feel like a bona-fide idiot posting this question, but can't find an answer anywhere. We're running IDS 7.3x(blah, blah, whatever) on Solaris 2.5.1. Here's the problem I have. On our development instance we developers often create databases in the rootdbs. We try to keep it pretty clean so that some idiot loading 1 million rows of data without adequate space won't cripple the engine. That means we have to import databases out of the dbspace almost daily. Keeping in mind that we typically allow public connect and select access on most databases in this instance, how can I restrict anyone from creating a database, or limit them to a default database (somewhat like Oracle does with a default user database setting in their profile)? I know that I can use UNIX "group" privileges to control access to the instance and objects, but in this case that won't help. Is role based security the answer? Any help is appreciated. Respond here or to mcwillij@fdhc.state.fl.us Thanks, Jake Sent via Deja.com http://www.deja.com/ Before you buy.
revoke dba, and resource privileges from everybody .
have the dba create the database ( in somedbspace other than rootdbs...)have the dba grant connect,resource,select etc...
to that new database to everybody.
have at it.
mcwillij@my-deja.com wrote:
> I feel like a bona-fide idiot posting this question, but can't find an
> answer anywhere. We're running IDS 7.3x(blah, blah, whatever) on
> Solaris 2.5.1. Here's the problem I have. On our development instance
> we developers often create databases in the rootdbs. We try to keep it
> pretty clean so that some idiot loading 1 million rows of data without
> adequate space won't cripple the engine. That means we have to import
> databases out of the dbspace almost daily.
>
> Keeping in mind that we typically allow public connect and select
> access on most databases in this instance, how can I restrict anyone
> from creating a database, or limit them to a default database (somewhat
> like Oracle does with a default user database setting in their profile)?
> I know that I can use UNIX "group" privileges to control access to the
> instance and objects, but in this case that won't help. Is role based
> security the answer?
>
> Any help is appreciated. Respond here or to mcwillij@fdhc.state.fl.us
>
> Thanks,
>
> Jake
>
> Sent via Deja.com http://www.deja.com/
> Before you buy.