Re: Permissions on Informix raw devices.
Posted in 1994
>Date: Fri, 22 Jul 94 00:00 STZ (Some Time Zone) >From: <name deleted to protect the guilty> >To: johnl@informix.com >Subject: Re: Permissions on Informix raw devices. > >In comp.databases.informix, Jonathan Leffler (johnl@informix.com) writes: >>[...] the block device should be owned by user informix, belong to group >>informix, and should have 000 permissions. There is no cause to access >>the block device at all. The raw character device should be owned by >>user informix, belong to group informix, and should have 660 permissions. > >Hmm, >I never thought about that. >Of course all customers are members of group informix. They WHAT!!!!!!!! SHRIEK! YOU CAN'T DO THAT! YOU MUST NOT DO THAT! Pause, for a deep breath, and to give me time to scrape myself off the ceiling... 1... 2... 3... 4... 5... 6... 7... 8... 9... 10! ........................................................................... Let's start at the beginning: Informix software needs to be installed on a machine which has a user called informix and a group called informix. The UID and GID do not matter, but the UID should be distinct from every other UID, and the GID should be distinct from every other GID, and the login group for user informix is conventionally informix, but this is not mandatory. No other user on the system should belong to group informix. That means root shouldn't belong to group informix. That means that no DBA should belong to group informix. That means that no ordinary user should belong to group informix. Especially not any ordinary user! If you are running Informix-SE, no-one even needs to be able to login as informix. There is no administration task under SE that requires informix privileges. If you need god-like powers, you can allow your normal system administrators (and if you can't trust them, you may as well just set all permissions to 777 everywhere!) to do the job as root. This means that user informix should have a dummy password. If you are running Informix-OnLine, then certain tasks can only be done by user informix, and therefore you need to set user informix as a bona fide user with a regular password. This login needs to be protected every bit as vigilantly as the root password is. In fact, if the only people who will need to work as informix are also people who work as root, you can still keep the informix password as a dummy, as root can become informix without being asked for a password. The tasks which require you to be informix rather than root are doing archives etc through the TbMonitor/OnMonitor user interface program. The command line utilities such as tbtape can be run by informix or root, I believe (though I haven't checked). The Informix software installation process is run by root and sets the permissions correctly on the installed software. Changing the permissions is apt to lead to problems -- don't do it unless you are sure you know what you are doing. When an SE database is created, the permissions are set correctly. When tables are created in an SE database, the permissions are set correctly. Again, do not change them unless you are certain you know what you are doing. I've never had to change the permissions on an SE database except when someone else has fouled things up. I have occasionally changed the owner of the files when someone unexpected got to own a file. But that only happens if you are too casual with your RESOURCE or DBA privileges. When an OnLine system is set up, you need to be careful to ensure that the privileges on the devices (and the (optionally symbolic) links to the devices) are correctly set up. As I said in my original email, the block devices should be owned by informix and belong to group informix and should have 000 permissions. This marks the devices as being used by an OnLine system, and ensures that no-one except root can damage the OnLine system using the block device. The raw devices should be owned by informix and belong to group informix and should have 660 permission. No more, no less. The directory or directories holding the devices should not be modifiable except by root. If you deviate from these standard guidelines, you forfeit security of your database. If you don't know why, read up on Unix system security and learn about what it means to have the Informix engines (SE and pre-6.00 OnLine) running SGID informix. They are started SUID root, but this privilege is turned off shortly after start up, and the real and effective UIDs revert to the real UID of the process starting the Engine. If you don't understand what I just said, don't worry. You don't have to understand it to do the job right -- just follow the guidelines I stated. BUT don't go changing the permissions on anything either -- you aren't qualified! >So even with 660 permissions any user (maybe after he was fired) will be >able to destroy the complete database. All these "grant options" seem to >be a large joke. Only if you do it all wrong! >Wouldn't an sqlturbo with something like setuid "ionline" be more secure? That's what user informix and group informix are for. See above... When you set the system up correctly, it is very secure. When you blow the system security, you can blow it thoroughly. Yours in desparation, Jonathan Leffler (johnl@informix.com) #include <disclaimer.h>