ODBC, pointers please
Posted in 2001
Topics: Installation, Setup & Upgrades, Storage & Space Management, Connectivity: ODBC / JDBC / .NET, Connectivity: ESQL/C, 4GL & Embedded SQL, Server Administration, Security, Permissions & Auditing, Versions, Editions & End-of-Life
We are taking our first tentative steps from a vanilla UNIX-IDS-4GL environment to using ODBC with, initially, VB. I'd like to know how to handle security, my problem is this, all of my users access our Unix server with a user id and password as you'd expect! The database permissions/privileges are pretty much wide open, these being controlled at the application level, as is to a great extent referential integrity. Now if I install the ODBC drivers from the client SDK onto a PC, I can use Microsoft query to access the server directly, bypassing the applications! All I need is my user id and password for the server. Short of implementing some sort of three tier system I.e. DB Server--> Apps server--> Client. how do I control this? We're on HPUX 10.20 IDS 7.30.UC7 ODBC 3.31 32 bit -- Tony Flaherty Snr. A/P, Informix DBA, HpUx Admin, Gimmi a broom! MFS Ltd.
Depends. Do you want the users to have read only access to the database? If so, it depends (again) on the ODBC driver. You can set up some that use connection brokers so that the users only have read only access. Another way to do it is to double encrypt the user's passwords. When the user enters their password, the application can encrypt it before it sends it to the server. The user's password on the UNIX box isn't what the user thinks it is. For example: User's password (that s/he enters into the app): hello Program encrypts it (we'll use a simple example): idmmp (increment letters by one) Program passes to the ODBC driver user's password on UNIX: idmmp That way, when the user attempts to use the ODBC driver to access the database through something other than your application, they won't know the password. (They think their password is hello on UNIX, but it's really idmmp). Of course, this means that the user will only be able to change their password through your application as well because the same encryption must be used both times. In article <941vth$2ro$1@hermes.mfs.misys.co.uk>, "Tony Flaherty" <aef@mfs.misys.co.uk> wrote: > We are taking our first tentative steps from a vanilla UNIX-IDS-4GL > environment to using ODBC with, initially, VB. > > I'd like to know how to handle security, my problem is this, all of my users > access our Unix server with a user id and password as you'd expect! The > database permissions/privileges are pretty much wide open, these being > controlled at the application level, as is to a great extent referential > integrity. > > Now if I install the ODBC drivers from the client SDK onto a PC, I can use > Microsoft query to access the server directly, bypassing the applications! > All I need is my user id and password for the server. Short of implementing > some sort of three tier system I.e. DB Server--> Apps server--> Client. how > do I control this? > > We're on > HPUX 10.20 > IDS 7.30.UC7 > ODBC 3.31 32 bit > > -- > Tony Flaherty > Snr. A/P, Informix DBA, HpUx Admin, Gimmi a broom! > MFS Ltd. > > -- # unrm / ksh: unrm: not found # man cpio Sent via Deja.com http://www.deja.com/