Re: Revoking Permission
Posted in 2000
Topics: Security, Permissions & Auditing
mars1972@my-deja.com wrote: > > In article <89lthn$i32$1@nnrp1.deja.com>, > fsabile@my-deja.com wrote: > > I need help on permissions. Our system grants > > connect to public. I want public to have access > > to all the tables except for one problematic user. > > > > I tried revoke connect from username but because > > public has connect, the user can still access > > tables. I tried REVOKE ALL on tablename FROM > > username and still didn't work. > > > > Is there a way not to give a unix user access to > > my database even though public has connect grants? > > > > I would appreciate any help you can give me. > > Thank you in advance. > > > > Sent via Deja.com http://www.deja.com/ > > Before you buy. > > I believe you'd have to revoke permission from public and grant it to > everyone except that person. I could be wrong. Anybody else know of a > different way? You are not wrong. You will have to revoke permissions from public and then grant permissions to each user. You could grant permissions to a role, but then each user would need permissions on the role and would have to switch to that role before accessing tables. If you are working on UNIX it is fairly trivial to get a list of users from your /etc/passwd file and combine this with a list of tables from your systables table to write a script to do the grants for you. Cheers, -- Mark. +----------------------------------------------------------+-----------+ | Mark D. Stock mailto:mdstock@mydas.freeserve.co.uk |//////// /| | http://www.informix.com http://www.informixhandbook.com |///// / //| | http://www.iiug.org +-----------------------------------+//// / ///| | |What year 2000 bug? year 2000 bug? |/// / ////| | |year 2000 bug? year 2000 bug? year |// / /////| | |2000 bug? year 2000 bug? year 1900 |/ ////////| +----------------------+-----------------------------------+-----------+
If you're using UNIX, why not just delete the users account from /etc/passwd. Hey presto: -951 User username is not known on the database server. Only problem is if they need access to a second DB on the server. In article <89mqu2$hf6$1@news.xmission.com>, "Mark D. Stock" <mdstock@mydas.freeserve.co.uk> wrote: > > mars1972@my-deja.com wrote: > > > > In article <89lthn$i32$1@nnrp1.deja.com>, > > fsabile@my-deja.com wrote: > > > I need help on permissions. Our system grants > > > connect to public. I want public to have access > > > to all the tables except for one problematic user. > > > > > > I tried revoke connect from username but because > > > public has connect, the user can still access > > > tables. I tried REVOKE ALL on tablename FROM > > > username and still didn't work. > > > > > > Is there a way not to give a unix user access to > > > my database even though public has connect grants? > > > > > > I would appreciate any help you can give me. > > > Thank you in advance. > > > > > > Sent via Deja.com http://www.deja.com/ > > > Before you buy. > > > > I believe you'd have to revoke permission from public and grant it to > > everyone except that person. I could be wrong. Anybody else know of a > > different way? > > You are not wrong. You will have to revoke permissions from public and > then grant permissions to each user. You could grant permissions to a > role, but then each user would need permissions on the role and would > have to switch to that role before accessing tables. > > If you are working on UNIX it is fairly trivial to get a list of users > from your /etc/passwd file and combine this with a list of tables from > your systables table to write a script to do the grants for you. > > Cheers, > -- > Mark. > > +----------------------------------------------------------+-----------+ > | Mark D. Stock mailto:mdstock@mydas.freeserve.co.uk |//////// /| > | http://www.informix.com http://www.informixhandbook.com |///// / //| > | http://www.iiug.org +-----------------------------------+//// / ///| > | |What year 2000 bug? year 2000 bug? |/// / ////| > | |year 2000 bug? year 2000 bug? year |// / /////| > | |2000 bug? year 2000 bug? year 1900 |/ ////////| > +----------------------+-----------------------------------+-----------+ > Sent via Deja.com http://www.deja.com/ Before you buy.