DBSECADM question with Label-Based Access Control (v11)
Posted in 2007
Topics: Security, Permissions & Auditing, Platform-Specific Issues, Jobs, Consulting & Announcements
IDS 11.10.FC1 on HP-UX 11.23
>From the SQL Reference Guide for v11 under "Granting the Database
Security Administrator Role":
"You cannot grant DBSECADM to a role or to yourself."
>From Carlton Doe's book on IDS 11: "User informix does not have the
DBSECADM role by default and cannot grant the role to user
informix" (pg. 26)
However, in my testing with v11, I was able (as user informix) to
grant DBSECADM to informix. Then, with the informix user ID, I wasable to create policies, labels, and such. Is this a bug in the code
or the documentation? It does seem to violate the role separation
principle that the new role presumes to provide. Note: if I revoke
DBSECADM from informix, then informix cannot create labels or
policies...as expected.
The Durster wrote:
> IDS 11.10.FC1 on HP-UX 11.23
>
>>From the SQL Reference Guide for v11 under "Granting the Database
> Security Administrator Role":
> "You cannot grant DBSECADM to a role or to yourself."
>
>>From Carlton Doe's book on IDS 11: "User informix does not have the
> DBSECADM role by default and cannot grant the role to user
> informix" (pg. 26)
>
> However, in my testing with v11, I was able (as user informix) to
> grant DBSECADM to informix. Then, with the informix user ID, I was> able to create policies, labels, and such. Is this a bug in the code
> or the documentation? It does seem to violate the role separation
> principle that the new role presumes to provide. Note: if I revoke
> DBSECADM from informix, then informix cannot create labels or
> policies...as expected.
>
Your first quote is from the Security Guide and not from the SQL Reference but
that's a minor point.
I think there is an error in the documentation. I haven't test it but the
DBSECADM is a role that can only be granted by a DBSA as the same chapter says.
informix is by default one DBSA. Remember that DBSA are members of the group
owning $INFORMIXDIR/etc which by default is "informix" to which the "informix"
user belongs. The contradiction appear to be in the phrase "You cannot grant
DBSECAM to a role or to yourself"... Assuming you can be Informix, that you can
grant the role to yourself...I haven't checked Carlton's book, but it is certainly a good exercise to look
there for a way to grant the role to a user... I'd say informix is the only
user who can grant it (unless you configure role separation).
So, in short, I'd say your experiences are correct and there are some glitches
in the docs...
Regards.
--
Fernando Nunes
Portugal
http://informix-technology.blogspot.com
My email works... but I don't check it frequently...