user binary access
Posted in 2011
Topics: Server Administration, Security, Permissions & Auditing
Hi folks!
I need to use a new user to perform some administrative commands (onstat and
onmonitor) to get information about the engine state, but this user cannot
have access for some binaries (onmode, onspaces, onparams, onaudit, etc).
Does anybody have some tips to do that?
Thanks in advance,
Alberto.
Alberto,
What sort of information does your user need to find out? There may be ways.
> To: ids@iiug.org
> From: arfilho@orizonbrasil.com.br
> Subject: user binary access [25331]
> Date: Thu, 3 Nov 2011 09:43:39 -0400
>
> Hi folks!
>
> I need to use a new user to perform some administrative commands (onstat and
> onmonitor) to get information about the engine state, but this user cannot
> have access for some binaries (onmode, onspaces, onparams, onaudit, etc).
>
> Does anybody have some tips to do that?
>
> Thanks in advance,
> Alberto.
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
Hi Alberto,
Change the onconfig parameter UNSECURE_ONSTAT to 1, they will be allowed to
run onstat command, but not onmonitor I think this command is quite dangerous.
# UNSECURE_ONSTAT - Controls whether non-DBSA users are
# allowed to run all onstat commands.
# Acceptable values are:
# 1 Enabled
# 0 Disabled (Default)
Best regards,
Celso Cabral Coimbra
Administrador de Banco de Dados
ClearTech Ltda
"Trust at the heart of Communications"
Tel. (11) 3576-4509
-----Mensagem original-----
De: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] Em nome de ALBERTO
ROMEU PESSONIO FILHO
Enviada em: quinta-feira, 3 de novembro de 2011 11:44
Para: ids@iiug.org
Assunto: user binary access [25331]
Hi folks!
I need to use a new user to perform some administrative commands (onstat and
onmonitor) to get information about the engine state, but this user cannot
have access for some binaries (onmode, onspaces, onparams, onaudit, etc).
Does anybody have some tips to do that?
Thanks in advance,
Alberto.
*******************************************************************************
Forum Note: Use "Reply" to post a response in the discussion forum.
Any user who is a member of the DBSA group (group 'informix' on UNIX,
'admin-informix' on Windows) can run the restricted onstat commands and run
any utility in $INFORMIXDIR/bin that has group execute privileges enabled.
So, if you add this/these special user(s) to group informix and remove
group execute privilege from onparams, etc, that will do it. Please note
that onmonitor can perform many of the functions of onparams, onspaces, and
onmode so allowing this new user to use onmonitor may defeat the purpose of
restricting that user from access to these utilities!
Art
Art S. Kagel
Advanced DataTools (www.advancedatatools.com)
Blog: http://informix-myview.blogspot.com/
Disclaimer: Please keep in mind that my own opinions are my own opinions
and do not reflect on my employer, Advanced DataTools, the IIUG, nor any
other organization with which I am associated either explicitly,
implicitly, or by inference. Neither do those opinions reflect those of
other individuals affiliated with any entity with which I am affiliated nor
those of the entities themselves.
On Thu, Nov 3, 2011 at 9:43 AM, ALBERTO ROMEU PESSONIO FILHO <
arfilho@orizonbrasil.com.br> wrote:
> Hi folks!
>
> I need to use a new user to perform some administrative commands (onstat
> and
> onmonitor) to get information about the engine state, but this user cannot
> have access for some binaries (onmode, onspaces, onparams, onaudit, etc).
>
> Does anybody have some tips to do that?
>
> Thanks in advance,
> Alberto.
>
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
--e89a8f3ba85d3e21b204b0d55b01
Wrong approach, Celso. Setting UNSECURE_ONSTAT will open up the onstat
commands that display SQL and so may also display data that should be
secured to ALL USERS not just a specific new user. Also, setting this
ONCONFIG parameter will not open up onmonitor to this new user. See my
other response for the way to do this.
Art
Art S. Kagel
Advanced DataTools (www.advancedatatools.com)
Blog: http://informix-myview.blogspot.com/
Disclaimer: Please keep in mind that my own opinions are my own opinions
and do not reflect on my employer, Advanced DataTools, the IIUG, nor any
other organization with which I am associated either explicitly,
implicitly, or by inference. Neither do those opinions reflect those of
other individuals affiliated with any entity with which I am affiliated nor
those of the entities themselves.
On Thu, Nov 3, 2011 at 9:52 AM, Celso Cabral Coimbra <
ccoimbra@cleartech.com.br> wrote:
> Hi Alberto,
>
> Change the onconfig parameter UNSECURE_ONSTAT to 1, they will be allowed to
> run onstat command, but not onmonitor I think this command is quite
> dangerous.
> # UNSECURE_ONSTAT - Controls whether non-DBSA users are
> # allowed to run all onstat commands.
> # Acceptable values are:
> # 1 Enabled
> # 0 Disabled (Default)
>
> Best regards,
>
> Celso Cabral Coimbra
> Administrador de Banco de Dados
> ClearTech Ltda
> "Trust at the heart of Communications"
> Tel. (11) 3576-4509
>
> -----Mensagem original-----
> De: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] Em nome de ALBERTO
> ROMEU PESSONIO FILHO
> Enviada em: quinta-feira, 3 de novembro de 2011 11:44
> Para: ids@iiug.org
> Assunto: user binary access [25331]
>
> Hi folks!
>
> I need to use a new user to perform some administrative commands (onstat
> and
> onmonitor) to get information about the engine state, but this user cannot
> have access for some binaries (onmode, onspaces, onparams, onaudit, etc).
>
> Does anybody have some tips to do that?
>
> Thanks in advance,
> Alberto.
>
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
--14dae9340955f900da04b0d56649