Re: Complex security requirement: user + computer
Posted in 1997
In <01bc9098$2f1cb310$6f4684c6@pc-pmarks> "Paul Marks" <sessec01.pmarks@eds.com> writes: >My customer wishes to restrict access to data based not only upon which >user is logged in, but which client computer is logged into by the user. >For example, a user logged into a workstation deemed to be "in an unsecure >area" may not access any financial data (may only access certain Views). >Application-level security cannot be used since this must also apply to >third-party applications such as reporting tools. Simply restricting access >to the reporting tool itself is not a solution, since the tool may be >needed to access other, non-restricted data. If you're using ODBC for your connection, a product like OpenLink has this facility at the high level. ie it can accept or reject connections based on user and/or machine (and/or application etc). For the cases where the connection is OK, but you need to restrict the table level permissions, then normal Informix grants and the possible use of roles is something to check out. If this combination doesn't quite sort things out for you, but a product like OpenLink is acceptable (or useable) in your environment, then try splitting your databases in to subsets (I'll call them subdatabases) and configure Openlink to accept/reject access to each subdatabase (based on user/machine/application etc). Of course, this method has other drawbacks if it means redevelopment or if some of your client products cannot use more than one database at a time. -- Bryan Tonnet batonnet@phase4.com.au