RE: InformixClient for Wins+Delphi+ODBC and DB security
Posted in 2000
Have been there with security. What people forget is that your user runs both WIN+UNIX apps with full read/write. Load ODBC and all security down the drain. AFAIK There are only 2 options. Tune you Delphi app to connect via ODBC, but use Openlink drivers. They have lots of security build in, like from what app/user/ip/os/readonly connections are allowed. No informix client needed on client computer. Trail copy at www.openlinksw.com Delphi_app<->OpenlinkODBC+TCP<->Unix_server/Informix Look at infspy iiug. A TCP wrapper/gateway. Some C coding needed on your side. App/Any_OS...<->Unix/Infspy_TCP<->Unix/Informix_TCP You will have to ask your net guys not to route original INF_TCP_port, but allow SPY_TCP_port. Hope it helps -----Original Message----- From: Nebojsa Sevo [mailto:mips@zg.tel.hr] Sent: Friday, 20 October, 2000 3:07 PM To: informix-list@iiug.org Subject: InformixClient for Wins+Delphi+ODBC and DB security I have a client with our old legacy application with UNIX users working on terminal emulations. All database security is in application logic. Now we developed new Win application using Delphi5 for management reporting and GUI presentation of database data ("read only" application). I installed and configured Informix CLI and Delphi BDE and everything is working OK. My problems is: How can I prevent PC users to install ODBC driver, connect to DB using their UNIX user names and passwords (they use them to run application) and use some tool (MS query for example) in which they can write and execute SQL statements DELETE, UPDATE or INSERT? Users must have table level privileges to do that SQLs because they are doing that in application. I just don't want that they can do that outside the application from PC client. If that isn't possible, can I log all connections coming from those clients and executing "destructive" SQLs. UNIX platform is AIX 4.3.3 and Informix is 7.31.UC6. Thanks