Table level privilege QUESTION.
Posted in 2017
Topics: Security, Permissions & Auditing
IDS 11.70.UC2TL on Linux. A database and all its objects owned by an ID that is NOT Informix, the question is:What is the best way to do to allow Informix having all the powers necessary to manage all table level privileges on this database.For example, for Informix to be able to grant access or revoke access from someone.Thanks in advance for any inputs.Kern -- Let's go GreenThis email contains 100% recycled electrons.
grant dba to informix ?
Marcus Haarmann
Von: "Kern Doe" <kern_doe@yahoo.com>
An: "ids" <ids@iiug.org>
Gesendet: Dienstag, 20. Juni 2017 18:48:56
Betreff: Table level privilege QUESTION. [39405]
IDS 11.70.UC2TL on Linux.
A database and all its objects owned by an ID that is NOT Informix, the
question is:What is the best way to do to allow Informix having all the powers
necessary to manage all table level privileges on this database.For example,
for Informix to be able to grant access or revoke access from someone.Thanks
in advance for any inputs.Kern --
Let's go GreenThis email contains 100% recycled electrons.
*******************************************************************************
Forum Note: Use "Reply" to post a response in the discussion forum.
Thanks for your reply but that doesn't work for me. Try it yourself:
1) as some ID (root?), create the demo database
2) as Informix, pick one table and revoke select from public.
> On Jun 20, 2017, at 4:13 PM, Marcus Haarmann <marcus.haarmann@midoco.de>
wrote:
>
> grant dba to informix ?>
> Marcus Haarmann
>
> Von: "Kern Doe" <kern_doe@yahoo.com>
> An: "ids" <ids@iiug.org>
> Gesendet: Dienstag, 20. Juni 2017 18:48:56
> Betreff: Table level privilege QUESTION. [39405]
>
> IDS 11.70.UC2TL on Linux.
> A database and all its objects owned by an ID that is NOT Informix, the
> question is:What is the best way to do to allow Informix having all the
powers
> necessary to manage all table level privileges on this database.For example,
> for Informix to be able to grant access or revoke access from someone.Thanks
> in advance for any inputs.Kern --
>
> Let's go GreenThis email contains 100% recycled electrons.
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
From the manual:
Without the AS clause, the user who executes the REVOKE statement must be the
grantor of the privilege that is being revoked. The DBA or the owner of the
object
can use the AS clause to specify another user (who must be the grantor of the
privilege) as the revoker of the privileges.
So, as informix you can:
REVOKE SELECT ON randomtable FROM PUBLIC AS randomtableowner;