At 05:29 PM 11/12/96 -0800, Troy wrote:
>Informix has special permissions that allow it to circumvent the
>sysusers table. Root is treated like any other user of the system.
>However, even root has access to informix (as an su). It is
>therefore not likely that you will find a way of fully restricting
>informix or root from any database.
There isn't any magic bullet for this problem. You have at least
two solutions, as any basic computer security course will tell you:
1. Secure the entire computer. Lock it in a cabinet, and give only
your trusted user the root and informix passwords. When he
needs some DBA or sysadmin work done, bring in that person
but supervise him. (You could just lock up the disks, too.)
2. Secure the vital data fields. Encrypt them and store them as
BLOBS. Only the chosen user(s) have the decryption key.
Then the DBA or sysadmin can see them all they want, they
just won't be able to make sense of the classified data.
Public Key Cryptography could allow end users to enter data
which would then be accessable only by the select user.
There are costs to both of these solutions, in the same way that
any security brings costs. Your best course of action is to find
out more about computer security by enrolling in a course, hiring
a security consultant, or buying some of the security books available.
It is a challenging and constantly changing field, and experts can
earn a good living there.
Enjoy,
Clem
______________________________________________________
Clem Akins (aka clema@informix.com)
Informix Software, Inc (Standard disclaimers apply)
International Technical Support
Last seen: Singapore, home of the Merlion