ODBC and Security
Posted in 1996
I recently set up a service on my database server to allow pc clients to access our finicial database. It lives in an on-line instance and the clients use Intersolve ODBC drivers to connect to it. It works well except for security. We use relaxed permissions on our data as the applications provide security tables which we maintain. What I would like to do is limit the access granted to users who access the data through the service port. The user is prompted for a user id and password when the connection is made, but once connected the user can do any sort of updates, inserts and/or deletes. My frist thought on this was to force the users to use a special UID for inqueries only. I could then grant read access to the tables for that UID, anyone running an application would use their reular UID. That limited UID could be set in the clients ODBC.INI file. Well any clever user would quickly learn to edit it and connect as themselves. Are there any options I could use on /usr/informix/lib/sqlexecd that may help? That is the process that listens to the port. Is the source for sqlexecd available? It would seem fairly simple to modify it to filter out UIDs and thus protect the database. I would like to give this capability to the users but am leary of the potential for data corruption. Any one out there addressed this issue yet? I am open to ideas or suggestions, please e-mail or post here. Thanks Mike Sullivan