Re: permissions
Posted in 1992
Jonathan Leffler writes (quoting Warren Saccente): > ********************************************************* > ** DBA privilege in Informix == ROOT privilege in Unix ** > ** You can't stop root! You can't stop DBAs!!! ** ^^^^^^^^^^^^^^^^^^^^^^ I'm tempted to get this bit stamped on my business cards ... ;-) > >(2) prevent the creator of a table/view from updating that table/view? > > No. The owner of a table may drop the table at any time. The owner of > a table may do anything with that table. If you don't want someone > fiddling with a table, they had better not own that table. Ah-ha ! Sort-of - how about a setuid-wrapper (make it setuid to informix, or a suitable DBA for your DB) that only runs one (or a small selection of) command(s) ? Things to remember are a) shell scripts that are setuid are drastically insecure, even if they're allowed on your machine. b) C-progs that need to run on a variety of Unix boxes tend to need a selection from setuid, setgid, setresuid, setresgid ... For a one-off, though, it should be dead easy. man setuid and go from there. > Yours, > Jonathan Leffler (johnl@obelix.informix.com) Thanks for all the info, hope this helps. Cheers - Tony. __________________________________________________________________________ Tony Heskett th@bnr.co.uk Voice: (+44) 279 429531 x 2637 BNR, London Road, Harlow, Essex, CM17 9NA Fax: (+44) 279 454187