IDS 11.70 : enabling role separation after install
Posted in 2014
Hello I would like to know whether role separation can be freely enabled/disabled after having installed the binaries on a UNIX (AIX in my case) server (and after having created my database) ? I found two contradictory webpages on the IDS 11.70 infocenter, so where is the right information ? Thanks in advance Fabrice ======== http://pic.dhe.ibm.com/infocenter/idshelp/v117/topic/com.ibm.sec.doc/ids_da_004. htm IBM® Informix® 11.70 Role separation When you install a database server instance, you implement role separation by setting the INF_ROLE_SEP environment variable to a non-zero integer value. Role separation enforces separating administrative tasks by people who run and audit the database server. If INF_ROLE_SEP is not set, then user informix can perform all administrative tasks. You cannot switch on role separation by resetting the environment after the server instance has been installed without role separation, and you cannot selectively implement role separation on only some of the databases of the same database server. For more information about the INF_ROLE_SEP environment variable, see the IBM Informix Guide to SQL: Reference. For more information about role separation, see Using role separation. ========== http://pic.dhe.ibm.com/infocenter/idshelp/v117/topic/com.ibm.sec.doc/ids_au_052. htm?resultof=%22%61%61%6f%64%69%72%22%20 On Windows, role separation is configured only during installation. On UNIX, you normally configure role separation during installation, but you can also configure it after the installation is complete or after the database server is configured. The OSA who installs the software enforces role separation, and decides which users (Windows) or groups (UNIX) are the DBSSO and AAO. On UNIX, the group that owns $INFORMIXDIR/aaodir is the AAO group; the group that owns $INFORMIXDIR/dbssodir is the DBSSO group. By default, group informix is the DBSSO, AAO, and DBSA group.