Rovoke insert permission but still can insert
Posted in 2017
Poster revoked DBA, RESOURCE and INSERT privileges on table tmp_rosas from user 'rafael', yet the user could still insert rows; PUBLIC only had connect privilege. Responders asked for 'dbschema -d db -t table -p all' output and whether the user had other/default roles (he said a role existed but was dropped). The thread then diverted into getting dbschema to run on Windows: fixing INFORMIXSERVER, INFORMIXDIR (use the Start Menu/.cmd Informix command window) and finally DB_LOCALE, found via sysmaster:sysdbslocale. No resolution to the original privilege problem is recorded.
Auto-generated by DrWatson from the posts below — may be imperfect; read the full thread.
Topics: Server Administration, Security, Permissions & Auditing
I have issued these commands:
revoke dba from rafael;
revoke resource from rafael;
revoke all on tmp_rosas from rafael;
grant select on tmp_rosas to rafael;
grant insert on tmp_rosas to rafael;
revoke insert on tmp_rosas from rafael;
But the user rafael is be ing able to insert records in the table. The publi
group has connect privilegies but I can't revoke them.
Show us a "dbschema -d yourdatabase -t tmp_rosas -p all"
Regards
On Tue, Sep 19, 2017 at 12:23 PM, RAFAEL ALTUNGY <raltungy@decimas.es>
wrote:
> I have issued these commands:
>
> revoke dba from rafael;
> revoke resource from rafael;
> revoke all on tmp_rosas from rafael;
> grant select on tmp_rosas to rafael;
> grant insert on tmp_rosas to rafael;
> revoke insert on tmp_rosas from rafael;>
> But the user rafael is be ing able to insert records in the table. The
> publi
> group has connect privilegies but I can't revoke them.
>
>
> ************************************************************
> *******************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
--
Fernando Nunes
Portugal
http://informix-technology.blogspot.com
My email works... but I don't check it frequently...
Does the user have other roles defined or a default role defined?
Regards,
David.
> On 19 September 2017 at 12:23 RAFAEL ALTUNGY <raltungy@decimas.es> wrote:
>
>
> I have issued these commands:
>
> revoke dba from rafael;
> revoke resource from rafael;
> revoke all on tmp_rosas from rafael;
> grant select on tmp_rosas to rafael;
> grant insert on tmp_rosas to rafael;
> revoke insert on tmp_rosas from rafael;>
> But the user rafael is be ing able to insert records in the table. The publi
> group has connect privilegies but I can't revoke them.
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
I've definied a role but I have dropped it before issuing the commands.
I can't run the dbschema command. It says it couldn't initialize security
subsystem.
INFORMIXSERVER env var set to DBSERVERNAME value (rather than any of
DBSERVERALIASES) ?
From: "RAFAEL ALTUNGY" <raltungy@decimas.es>
To: ids@iiug.org
Date: 09/19/2017 01:43 PM
Subject: Re: Rovoke insert permission but still can insert [39913]
Sent by: ids-bounces@iiug.org
I can't run the dbschema command. It says it couldn't initialize security
subsystem.
*******************************************************************************
Forum Note: Use "Reply" to post a response in the discussion forum.
I have created the env varieble and now it says "-23101 Unable to load locale categories."
Are you sure you're doing this in a properly defined Informix environment? Command prompt with environment from %informixdir%\\\\<db_server_name>.cmd ? -23101 typically means: INFORMIXDIR env var not set (properly). From: "RAFAEL ALTUNGY" <raltungy@decimas.es> To: ids@iiug.org Date: 09/19/2017 02:45 PM Subject: Re: Rovoke insert permission but still can insert [39918] Sent by: ids-bounces@iiug.org I have created the env varieble and now it says "-23101 Unable to load locale categories." ******************************************************************************* Forum Note: Use "Reply" to post a response in the discussion forum.
I am doing it at the command line in the server directly in the directory C:\\\\Program Files\\\\IBM\\\\IBM Informix Dynamic Server\\\\11.50\\\\bin
So you need to have INFORMIXDIR set, probably should be:
set INFORMIXDIR=C:\\\\Program Files\\\\IBM\\\\IBM Informix Dynamic Server\\\\11.50
From: "RAFAEL ALTUNGY" <raltungy@decimas.es>
To: ids@iiug.org
Date: 09/19/2017 03:17 PM
Subject: Re: Rovoke insert permission but still can insert [39920]
Sent by: ids-bounces@iiug.org
I am doing it at the command line in the server directly in the directory
C:\\\\Program Files\\\\IBM\\\\IBM Informix Dynamic Server\\\\11.50\\\\bin
*******************************************************************************
Forum Note: Use "Reply" to post a response in the discussion forum.
Created env variable and same error.
Pls. use Start Menu -> IBM Informix 11.50 -> <your_server> for opening a command window with proper environment settings. Or execute said .cmd file in INFORMIXDIR. From: "RAFAEL ALTUNGY" <raltungy@decimas.es> To: ids@iiug.org Date: 09/19/2017 03:42 PM Subject: Re: Rovoke insert permission but still can insert [39924] Sent by: ids-bounces@iiug.org Created env variable and same error. ******************************************************************************* Forum Note: Use "Reply" to post a response in the discussion forum.
Now the rror is -23197 - Database locale information mismatch.
SELECT * FROM sysmaster:sysdbslocale
Check the dbs_collate for the database you're interested in... e.g.en_US.819
and then set:
set DB_LOCALE=en_US.819
(change the locale to what you've found of course...)
On Tue, Sep 19, 2017 at 2:52 PM, RAFAEL ALTUNGY <raltungy@decimas.es> wrote:
> Now the rror is -23197 - Database locale information mismatch.
>
>
> ************************************************************
> *******************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
--
Fernando Nunes
Portugal
http://informix-technology.blogspot.com
My email works... but I don't check it frequently...
Cool, that is progress!
Looks like your database got created from elsewhere (using different
environment), using a specific DB_LOCALE setting defining, among other
things, the database's code set.
Following query might help finding that setting, then set
DB_LOCALE=<that_locale> should allow you access to your database.
echo select dbs_collate from sysdbslocale where dbs_dbsname =
"<your_database>" | dbaccess sysmaster
From: "RAFAEL ALTUNGY" <raltungy@decimas.es>
To: ids@iiug.org
Date: 09/19/2017 03:52 PM
Subject: Re: Rovoke insert permission but still can insert [39929]
Sent by: ids-bounces@iiug.org
Now the rror is -23197 - Database locale information mismatch.
*******************************************************************************
Forum Note: Use "Reply" to post a response in the discussion forum.
Were you be able to run dbschema before? when was the last time? Something
must have been changed!
Anyway, try to see if you can validate of your Informix folders and files,
follow the information below:
http://www-01.ibm.com/support/docview.wss?uid=swg21383261
Script (file_check.sh) to check permission and ownerships of Informix products:
http://www-1.ibm.com/support/docview.wss?fdoc=imids&rs=630&uid=swg21113385
Let's go GreenThis email contains 100% recycled electrons.
From: RAFAEL ALTUNGY <raltungy@decimas.es>
To: ids@iiug.org
Sent: Tuesday, September 19, 2017 9:42 AM
Subject: Re: Rovoke insert permission but still can insert [39924]
Created env variable and same error.
*******************************************************************************
Forum Note: Use "Reply" to post a response in the discussion forum.