Re: Question on Access Privileges
Posted in 1993
>From: uunet!iti.gov.sg!cmlow (Low Chee Meng) >Subject: Question on Access Privilleges >Date: Thu, 24 Jun 1993 04:26:27 GMT >X-Informix-List-Id: <news.3630> >I have 2 questions with regards to the granting of access privileges >to various tables in an Informix (OnLine) database running on Unix. >1) Can I grant permissions to a group of users (based on the Unix 'group') >in one shot rather than to each individual user separately? In this way, >I do not need to modify the table privileges whenever I add or remove a >user account from the Unix group concerned. No. >2) If I have an ESQL/C program that has the SET_UID bit set, will whoever >that runs this program have the same access privileges as me? In other >words, does Informix check the REAL user-id or the EFFECTIVE user-id when >checking for access violations? It could use either, but the two user IDs are always the same. Both Informix-OnLine and Informix-SE are themselves SUID root, SGID informix programs. When the engine is run, these setXid privileges effectively lose the SUID-ness (and SGID-ness) of the program which runs the engine. The application real and effective IDs are not changed, of course, because they are a separate process from the engine process. The root privileges are used briefly to set ulimit to infinity (or near enough), and then the effective UID is reset to the real UID. The group informix privileges are retained and are the normal source of access rights on the database tables. Hence, no-one except user informix should belong to group informix. Yours, Jonathan Leffler (johnl@obelix.informix.com) #include <disclaimer.h>