Re: DBSECADM question with Label-Based Access Control (v11)
Posted in 2007
> > However, in my testing with v11, I was able (as user informix) to
> grant DBSECADM to informix.
Which version were you testing? There was a problem in a beta version of IDS 11.10 where informix could grant dbsecadm to itself.
Guy
----- Original Message ----
From: The Durster <seandurity@gmail.com>
To: informix-list@iiug.org
Sent: Tuesday, October 2, 2007 7:35:47 AM
Subject: DBSECADM question with Label-Based Access Control (v11)
IDS 11.10.FC1 on HP-UX 11.23
>From the SQL Reference Guide for v11 under "Granting the Database
Security Administrator Role":
"You cannot grant DBSECADM to a role or to yourself."
>From Carlton Doe's book on IDS 11: "User informix does not have the
DBSECADM role by default and cannot grant the role to user
informix" (pg. 26)
However, in my testing with v11, I was able (as user informix) to
grant DBSECADM to informix. Then, with the informix user ID, I wasable to create policies, labels, and such. Is this a bug in the code
or the documentation? It does seem to violate the role separation
principle that the new role presumes to provide. Note: if I revoke
DBSECADM from informix, then informix cannot create labels or
policies...as expected.
_______________________________________________
Informix-list mailing list
Informix-list@iiug.org
http://www.iiug.org/mailman/listinfo/informix-list
____________________________________________________________________________________
Moody friends. Drama queens. Your life? Nope! - their life, your story. Play Sims Stories at Yahoo! Games.
http://sims.yahoo.com/