RE: Priviliged access through ODBC
Posted in 2000
Openlink ODBC drivers have extra security build in {Read only, log in from allowed hosts} on all the users privileges. You can also let all ODBC access log in with a trusted openlink user. This is the closest you are going to get. {www.openlinksw.com} The only other way is to implement a tcp port wrapper, or some other type of middle ware or firewall where you can restrict queries. -----Original Message----- From: Henk van der Geld [SMTP:henk.van.der.geld@centric.nl] Sent: Thursday, June 08, 2000 5:23 PM To: informix-list@iiug.org Subject: Priviliged access through ODBC Hi, We are deploying an information system where we use 4GL application programs that access an Informix database. What we have done so far is that we defined all table priviliges for all users. As far as a user accesses the database through the application program there is no risk of having unwanted manipulation of the data. But when it comes to usage of ODBC, eg through use of MS-Access, then things change. Now the same user can do anything with the data that he/she wants. So this is a big risk. This situation gives a lot of tension. We can't define more table priviliges, because then the application programs don't work anymore. So what we are looking for is a possibility to define the required table priviliges for the case that a person access the database through ODBC. Does anybody know of the possibilities that are available. Any advice/help/tip will be appreciated. regards, Henk