Question about creation of roles from the scratch
Posted in 2011
Topics: Security, Permissions & Auditing, Platform-Specific Issues
Hello all, I have a situacion at work with mi IDS. I'm running 11.50 FC8 on an AIX 5.3. Ok, i have about 1000 users and 1300 tables. I'm trying to group the users in groups (sorry for redundancy) in order to prepare role separation. But, i'm not sure if i have one, two, three, N different combination of permissions. I'm writting by now an exe windows program but i think its inefficient. Can anyone give me at least a clue? Very best regards, Leonardo Santagostini
Hi Leonardo.
In most common cases, you´ll only need one or two groups (DBSSO,
DBSA....) in role separation,
and all your specific database roles (separated in groups, like you
said) are made through simple database roles, really.
Maybe you don´t even need role separation feature itself.
Check some links, and make sure if it´s what you´ll need ok?
(Role separation):
http://publib.boulder.ibm.com/infocenter/idshelp/v115/index.jsp?tab=search&searc
hWord=role+separation
(Roles):
http://publib.boulder.ibm.com/infocenter/idshelp/v115/topic/com.ibm.ddi.doc/ids_
ddi_270.htm?resultof=%22%72%6f%6c%65%73%22%20%22%72%6f%6c%22%20
If you have just a need to separate tables and permissions into specific
usergroups, I would suggest you to:
1) take one user, of each group, as a source for permissions
2) list that user permission, and put it into a unique role name
3) after that, you can revoke the same users specific permissions, and
grant them to your new role
(do that for all similar group permissions you have).
There is a very good utility on IIUG called dup-auth.sh - it´s very
simple to use it.
If you have Server Studio software installed, it has even a "duplicate
permission" feature - much easier for you.
Hope this helps.
Regards.
Em 17/10/2011 17:02, Leonardo Santagostini escreveu:
> Hello all,
>
> I have a situacion at work with mi IDS.
>
> I'm running 11.50 FC8 on an AIX 5.3.
>
> Ok, i have about 1000 users and 1300 tables.
>
> I'm trying to group the users in groups (sorry for redundancy) in
> order to prepare role separation.
>
> But, i'm not sure if i have one, two, three, N different combination
> of permissions.
>
> I'm writting by now an exe windows program but i think its inefficient.
>
> Can anyone give me at least a clue?
>
> Very best regards,
> Leonardo Santagostini
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
--
Alexandre Marini
Tecnologia da Informação - DBA
SEFAZ-MS / SGI-UGSR / Sistemas IBM-Informix
<Cert-Info-Mgmt_color.jpg>
IBM Certified System Administrator - Informix Dynamic Server V10 / V11 /
V11.70
IBM Information Management Informix Technical Professional v3
Hello Alex,
I need de second option. I need to separate tables and permissions into
specific usergroups,
So i will try doing the things you suggested.
Thanks,
Regards,
Leonardo Santagostini
El 18 de octubre de 2011 08:57, Alexandre Marini
<amarini@fazenda.ms.gov.br>escribió:
> Hi Leonardo.
> In most common cases, you´ll only need one or two groups (DBSSO, DBSA....)
> in role separation,
> and all your specific database roles (separated in groups, like you said)
> are made through simple database roles, really.
> Maybe you don´t even need role separation feature itself.
>
> Check some links, and make sure if it´s what you´ll need ok?
> (Role separation):
>
>
http://publib.boulder.ibm.com/infocenter/idshelp/v115/index.jsp?tab=search&searc
hWord=role+separation
> (Roles):
>
>
http://publib.boulder.ibm.com/infocenter/idshelp/v115/topic/com.ibm.ddi.doc/ids_
ddi_270.htm?resultof=%22%72%6f%6c%65%73%22%20%22%72%6f%6c%22%20
>
> If you have just a need to separate tables and permissions into specific
> usergroups, I would suggest you to:
> 1) take one user, of each group, as a source for permissions
> 2) list that user permission, and put it into a unique role name
> 3) after that, you can revoke the same users specific permissions, and
> grant them to your new role
> (do that for all similar group permissions you have).>
> There is a very good utility on IIUG called dup-auth.sh - it´s very simple
> to use it.
> If you have Server Studio software installed, it has even a "duplicate
> permission" feature - much easier for you.
>
> Hope this helps.
> Regards.
>
> Em 17/10/2011 17:02, Leonardo Santagostini escreveu:
>
> Hello all,
>
> I have a situacion at work with mi IDS.
>
> I'm running 11.50 FC8 on an AIX 5.3.
>
> Ok, i have about 1000 users and 1300 tables.
>
> I'm trying to group the users in groups (sorry for redundancy) in
> order to prepare role separation.
>
> But, i'm not sure if i have one, two, three, N different combination
> of permissions.
>
> I'm writting by now an exe windows program but i think its inefficient.
>
> Can anyone give me at least a clue?
>
> Very best regards,
> Leonardo Santagostini
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
>
>
>
> --
>
> Alexandre Marini
>
> Tecnologia da Informação - DBA
>
> SEFAZ-MS / SGI-UGSR / Sistemas IBM-Informix
>
> <http://Cert-Info-Mgmt_color.jpg>****
>
> IBM Certified System Administrator - Informix Dynamic Server V10 / V11 /
> V11.70****
>
> IBM Information Management Informix Technical Professional v3****
>
> ** **
>
--00248c0eee5047e3f604af947242