Can IDS controle who allows to import or export?
Posted in 2000
Topics: Security, Permissions & Auditing, Versions, Editions & End-of-Life
Hi all, I would like to control number of users to import or export our informix databases. I don't know if I can do it with IDS 7.20UC2 or not? I see Informix is different with Oracle in this case. I hope I will receive some advises about it. Thanks in advance for any idea. HV
Do you mean you want to limit the number of concurrent connections to the server? You can do this with careful configuration of the NETTYPE parameters on a per-interface basis (ie number of shared memory users and number of ethernet users are independent). Art S. Kagel Huy Vu wrote: > > Hi all, > > I would like to control number of users to import or export our informix > databases. I don't know if I can do it with IDS 7.20UC2 or not? > > I see Informix is different with Oracle in this case. > > I hope I will receive some advises about it. > > Thanks in advance for any idea. > > HV
No, I would like to allow a specific users to import or export databases. Thanks again. H.V "Art S. Kagel" <kagel@bloomberg.net> wrote in message news:3885FC0C.6BB2FC13@bloomberg.net... > Do you mean you want to limit the number of concurrent connections to the > server? You can do this with careful configuration of the NETTYPE > parameters on a per-interface basis (ie number of shared memory users and > number of ethernet users are independent). > > Art S. Kagel > > Huy Vu wrote: > > > > Hi all, > > > > I would like to control number of users to import or export our informix > > databases. I don't know if I can do it with IDS 7.20UC2 or not? > > > > I see Informix is different with Oracle in this case. > > > > I hope I will receive some advises about it. > > > > Thanks in advance for any idea. > > > > HV
Export : Only "informix" or the creator of the database or a user who has the DBA privilege may perform exports. Import : Problematic. Informix does not provide clear-cut control over this. Any user who can connect to an Instance is allowed to create/import a database (something to do with "Open Systems", I guess). However, there are simple ways to ensure that you, as the DBA, are informed whenever an "unauthorized" database is created. For example, you could have a simple shell script which runs once a day to examine sysmaster:sysdatabases. It could be programmed to mail you if it finds "new" databases. Then, if you have a big enough stick... Rudy Huy Vu wrote: > Hi all, > > I would like to control number of users to import or export our informix > databases. I don't know if I can do it with IDS 7.20UC2 or not? > > I see Informix is different with Oracle in this case. > > I hope I will receive some advises about it. > > Thanks in advance for any idea. > > HV
Huy, I'd think that you could do this by restricting permissions on the databases. That said, remember that all an export really is is a select of every row in the table, along with the rows in the system catalog that describe the table. If you allow your users to select data from the table, I would think that you're allowing them to export that table. Likewise, if you're allowing them to insert into the table, you're permitting an import. I'm hard pressed to think of the business reason that you'd have for allowing a select, but not allowing an export; likewise for the import. If creating large files is the issue, then I'd restrict that permission at the O.S. level. HTH. -- Dan Michaelis Database Administrator dan@kax.com Sent via Deja.com http://www.deja.com/ Before you buy.