REVOKE problem (again)
Posted in 2000
Topics: Server Administration, Security, Permissions & Auditing
Is there any way for DBA to revoke privileges granted by another user?
INFORMIX DBA can grant privileges to one user/role from another:
GRANT something ON object TO user AS grantor
but he cannot revoke privileges he granted this manner. Statement
REVOKE something ON object FROM user AS grantor
gives a syntax error. Of course I can perform
DELETE FROM systabauth WHERE ...
but I'm afraid that such method is unsafe.
Any help would be appreciated.
Leonid
-------------
To INFORMIX: why GRANT is unrevertable?
I ran into this problem too.
Although I have found you can GRANT permissions
as another user (the "AS grantor" clause).
Informix does not have the ability to REVOKE as
another user (no "AS grantor" clause).
I believe you must be connect to the database as that
user that you specificied in the grant statement to revoke
the permission.
"Leonid Belov" <white@science-ltd.ru> wrote in message
news:39F8222F.2102F744@science-ltd.ru...
> Is there any way for DBA to revoke privileges granted by another user?
> INFORMIX DBA can grant privileges to one user/role from another:
>
> GRANT something ON object TO user AS grantor>
> but he cannot revoke privileges he granted this manner. Statement
>
> REVOKE something ON object FROM user AS grantor>
> gives a syntax error. Of course I can perform
>
> DELETE FROM systabauth WHERE ...>
> but I'm afraid that such method is unsafe.
>
> Any help would be appreciated.
>
> Leonid
>
> -------------
> To INFORMIX: why GRANT is unrevertable?
Steve Waggoner wrote: > > I ran into this problem too. > > Although I have found you can GRANT permissions > as another user (the "AS grantor" clause). > > Informix does not have the ability to REVOKE as > another user (no "AS grantor" clause). > > I believe you must be connect to the database as that > user that you specificied in the grant statement to revoke > the permission. DBA must know user's password to REVOKE such a way - but he not need password to GRANT... So we can decide that DBA hasn't full control over permissions. He can grant privileges but he can't revoke ones he granted before. All other operations are revertable - CREATE-DROP, ADD CONSTRAINT-DROP CONSTRAINT etc. Why GRANT not? > > "Leonid Belov" <white@science-ltd.ru> wrote in message > news:39F8222F.2102F744@science-ltd.ru... > > Is there any way for DBA to revoke privileges granted by another user?