RE: rcmd: Connect all users from one server to ONE user in the other
Posted in 2004
Topics: Security, Permissions & Auditing
On Wed, 04 Aug 2004 18:31:04 -0400, Everett Mills wrote: And your security folk weren't beating at your door? It took weeks of negotiation and promises of my 5th born (stopped at 4 thank you) to get a 'test' account set up on production for test system monitor jobs to connect to the server (all production runs as a single userid through middleware). ;-) Art S. Kagel > Manuel & Art- > We use the su command to get around that (we have many users > that have on one unix server, but not on the other). It looks something > like this: > > su user_id -c "fglgo program.4gi" > > or > > su user_id -c "my_script.ksh" > > We have set up a dummy user id on both systems (here called "user_id") which > has all necessary database permissions, and has no password, so that anyone > can su to it. However, the .profile only exit in it, some that no one can > log in as it. Since we have our system set up so that no one gets a unix > prompt, we have deemed it to be a very small security risk. > > --EEM > > >> -----Original Message----- >> From: Art S. Kagel [mailto:kagel@bloomberg.net] Sent: Wednesday, August 04, >> 2004 12:57 PM To: informix-list@iiug.org Subject: Re: rcmd: Connect all >> users from one server to ONE user in > the >> other >> >> On Tue, 03 Aug 2004 19:18:37 -0400, Manuel Daponte wrote: >> >> > Hi, I have 2 boxes (SCO & RedHat) with Informix databases. In SCO I > have >> a >> > large database with +50 different users and a lot of information, > and in >> > RedHat I have a small database with only a couple of users accounts > for >> > admin purposes. >> > >> > I need, while connected to the SCO db, to execute remote queries to > the >> RH >> > db. The configuration for this is task is the same used for the r* >> commands >> > (rlogin, rmcd). I created the hosts.equiv entries and modified the >> Informix >> > config files, and if the user with wich I'm connected to SCO exists > in >> > Linux, everything works fine. The problem occurs when user exists in > SCO >> and >> > not in RH. >> > >> > Is there a way to "trust" all the users from another server WITHOUT >> creating >> > them in BOTH servers? For example, create a user in RH that will be > the >> > default user to execute the commands? >> >> No. IDS uses the OS's user validation services, so if the user is not >> known >> by the server's host machine he cannot get access to the databases on > that >> server. >> >> Art S. Kagel > > sending to informix-list
I bet you regret this in the long run. I am stuck in a shop where everything grew up around this practice and it would be too much trouble (=time) to change it now. But we are wishing we could just so we could implement roles and clean up some accidents that are just waiting to happen.
On Mon, 09 Aug 2004 09:29:05 -0400, sumGirl wrote: > I bet you regret this in the long run. I am stuck in a shop where everything > grew up around this practice and it would be too much trouble (=time) to > change it now. But we are wishing we could just so we could implement roles > and clean up some accidents that are just waiting to happen. The big problem is auditing. Either the audit records have to be written at a higher level or each table has to have a 'user' column that's always updated by the application so triggers can audit the changes by logging that column since the server does not know who it's dealing with. Art S. Kagel