Re: Database security
Posted in 1991
Path: emory!swrinde!sdd.hp.com!hplabs!pyramid!infmx!aland From: aland@informix.com (Colonel Panic) Newsgroups: comp.databases.informix Message-ID: <1991Oct12.215926.9788@informix.com> Date: 12 Oct 91 21:59:26 GMT References: <503@rand.mel.cocam.oz.au> Sender: news@informix.com (Usenet News) Organization: International Brotherhood of Geeks, Local 619 In article <503@rand.mel.cocam.oz.au> shaneb@auzodt3.mel.cocam.oz.au (Shane Booth) writes: > > Does anyone know a way to allow users to run a 4GL application that inserts >and deletes from a database, but to disallow the users from altering the data >by running isql? The only good way to do this with current product is to make your 4GL application setuid to some "logical" user account (which the users cannot log into directly), then GRANT the insert/delete privileges only to that user. You must set both real and effective uid before spawning the engine (e.g. before the DATABASE statement). In System V, this means that the owner of the executable must be root; in BSD, it can be the target "logical" user or root. In Version 5.0 of the engines, you will be able to use a DBA stored procedure to accomplish the same need. >Here we run Informix-4GL version 4.00.UC1 for Sco Unix. If you have maintenance, I'd recommend upgrading to a newer version (e.g. 4.00.UH2). >Thanks for any help, >Shane Booth >shaneb@auzodt3.mel.cocam.oz.au -- Alan Denney aland@informix.com {pyramid|uunet}!infmx!aland "Love is like a snowmobile rushing across the frozen tundra. Suddenly, the snowmobile flips over pinning you underneath. At night, the Ice Weasels come." - Matt Groening, "Love is Hell"