Re: informix ownership
Posted in 1998
On Wed, 1 Jul 1998, Maria Wilson wrote:
> I was hoping to open up some discussion on the topic of root or
> informix "owning" the database instance. I was recently troubleshooting
> another Informix db server when I noticed that all the oninit processes
> and even the raw partitions were owned and grouped by root instead of
> informix. Would anyone care to share their experiences/opinions about
> this? We have alot of DBA/SA people here - so I seem to see alot of
> this. Comments?
A number of the Informix executables should be owned by root and are SUID
root. Traditionally, all the files in the Informix directory should belong
to group informix; some of the programs are also SGID informix. If the
SNMP daemons (snmpdm and snmpdp) are present, they are owned by root and
belong to group root and are both SUID and SGID. If the software is
installed correctly, then the database storage disks and files should be
owned by user informix and belong to group informix, and should be 660
permissions.
If the programs which should be SGID informix are installed SGID (group
ID!) root, then the disk chunks used by the databases should also belong to
group root. This is self-consistent, though hardly correct by any official
standard. The group ID of the SGID programs is what normally determines
whether the database disks can be accessed or not -- at the Unix
permissions level.
FWIW: there are several utilities in the IIUG archive (http://www.iiug.org)
which can diagnose incorrect permissions and which can fix any incorrect
permissions. See ckfl and utils_jl, for example.
Yours,
Jonathan Leffler (jleffler@informix.com) #include <witticism.h>
Guardian of DBD::Informix -- see http://www.perl.com/CPAN