Re: dbaccess Permissions
Posted in 1995
At 11:50 AM 5/23/95, Cathy Kipp wrote:
}Folks,
}
}I know it is not generally considered a good idea to change Unix file
}permissions on Informix files, but I do have a problem I think this change
}would help me with anyway, or maybe you all have a better solution.
}
}Problem: User A has been granted a wide variety of permissions to Informix
} tables and databases because the user runs applications which
} require these permissions. However, if User A were to become a
} more advanced user, he/she could easily execute dbaccess from the
} Unix command line and create all sorts of havoc by inserting,
} updating, and deleting data which I really don't want them touching
} except through an application program. (This is becoming as issue
} since users now have access to Unix where before they were confined
} to menus.)
}
}Potential Solutions:
}
}1) Change dbaccess permissions from: -rwxr-xr-x informix informix
} to: -rwxr-x--- informix infmx_user
Cathy -
I've done this exact thing, since I do not want anyone other then INFORMIX
to use dbaccess, for the same reasons you've stated. I have not encountered
any problems with doing this.
Jon
}
} where the group infmx_user includes only the half dozen people who have
} any business executing this program. At the moment this is my preferred
} solution. Are there any problems with this scenario I am missing?
}
}2) Write a set of stored procedures which are executed as dba to grant
} and revoke privileges every time a user enters or exits a program.
} I really don't think this is a very efficient thing to do and I would
} prefer to avoid it.
}
}3) Any other brilliant solutions any of you have come up with and may be
} using?
}
}Thanks for any comments and/or ideas.
}
}Regards,
}
}- Cathy
}
}---------------------------------------------------------------------------
-----
}Cathy Kipp e-mail: ckipp@vth1.vth.colostate.edu Phone: (970)
491-1294
}Colorado State University Veterinary Teaching Hospital Fax: (970)
491-1205
}
}
==================================================================
Jon Vemo Internet: jvemo@cyberspace.com
Bothell, WA USA
------------------------------------------------------------------
Watch out for road-kill on the information superhighway....SPLAT!!
==================================================================