Installing IDS 10 without 'informix' user present
Posted in 2008
Tom asked whether IDS 10 could be installed on Solaris without creating an OS user named 'informix', using another user in the informix group instead. The consensus: no — on UNIX the informix user is hard-coded as the server administrator/owner and must exist; only on Windows (10.00.TC5+) can the local system account substitute for it, though ER with UNIX machines then breaks. Tom found the server could be coaxed into running as another user only after installing/initialising as informix, and concluded they would simply create the informix user. Others warned against adding extra users to the informix group, suggesting DBSA role separation and group ownership of $INFORMIXDIR instead.
Auto-generated by DrWatson from the posts below — may be imperfect; read the full thread.
Topics: Installation, Setup & Upgrades
Hi, Is it possible to install IDS10 without the 'informix' user on the system? The group 'informix' exists and has a user as a member - is there any way to tell the install to use this other username in place of 'informix' when creating directories/permissions? I haven't been able to find this referenced in any documentation. Thanks
On 10/04/2008, TOM W <twillia@gmail.com> wrote: > Hi, > Is it possible to install IDS10 without the 'informix' user on the system? The > group 'informix' exists and has a user as a member - is there any way to tell > the install to use this other username in place of 'informix' when creating > directories/permissions? > > I haven't been able to find this referenced in any documentation. > > Thanks > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > See you at the IIUG Informix 2008 Conference > The Power Conference for Informix Professionals > April 27 - 30, 2008 Marriott Overland Park (Kansas City), Kansas > http://www.iiug.org/conf > Registration Now Open!! > Tom No. The Informix User is not only just used as the 'owner' of the file/directories but is also embeddd in the code as the only user (beside root) to be able to configure and run the engine and to manage the engine environment such as adding space, logs etc. It must exist on both Unix and Windoze. Keith
Thanks for the quick reply Keith. That's kind of what I was thinking. I'm up against some fairly tight restrictions here; is it possible to create the informix user, complete the IDS install, then grand dba rights to another username, chown dbspaces, binaries and directories and then remove the informix user? Cheers, Tom
Ignore my last post, I'm being an idiot. Thanks Keith.
On 10/04/2008, TOM W <twillia@gmail.com> wrote: > Thanks for the quick reply Keith. That's kind of what I was thinking. > > I'm up against some fairly tight restrictions here; is it possible to create > the informix user, complete the IDS install, then grand dba rights to another > username, chown dbspaces, binaries and directories and then remove the > informix user? > > Cheers, > Tom > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > See you at the IIUG Informix 2008 Conference > The Power Conference for Informix Professionals > April 27 - 30, 2008 Marriott Overland Park (Kansas City), Kansas > http://www.iiug.org/conf > Registration Now Open!! > Tom DBA (Database Administrator) rights can be granted to anyone DSA (Database SERVER Administor) rights are not a grantable option, however the installation guide seems to indicate that any user in group informix has DSA rights, however there are dire warnings not to do this and further warnings about the consequences. Why are you so restricted. Someone has to have the authority to manage and run the Server and it is best this is the informix user as designed. Keith
As far as I know Windows is currently the only platform where you have the option to install and run IDS without creating an informix user, which probably doesn't help you right? Guy ----- Original Message ---- From: TOM W <twillia@gmail.com> To: ids@iiug.org Sent: Wednesday, April 9, 2008 11:49:05 PM Subject: Installing IDS 10 without 'informix' user present [11812] Hi, Is it possible to install IDS10 without the 'informix' user on the system? The group 'informix' exists and has a user as a member - is there any way to tell the install to use this other username in place of 'informix' when creating directories/permissions? I haven't been able to find this referenced in any documentation. Thanks ******************************************************************************* Forum Note: Use "Reply" to post a response in the discussion forum. See you at the IIUG Informix 2008 Conference The Power Conference for Informix Professionals April 27 - 30, 2008 Marriott Overland Park (Kansas City), Kansas http://www.iiug.org/conf Registration Now Open!! __________________________________________________ Do You Yahoo!? Tired of spam? Yahoo! Mail has the best spam protection around http://mail.yahoo.com
> It must exist on both Unix and Windoze. On Windoze IDS 10.00.TC5 and higher the local system user can be internally converted to an "informix" user, allowing IDS installations to run with no informix user on the machine. The only caveat is ER sync between UNIX and Windows machines would not be expected to work with no informix user on the Windows machine. Guy ----- Original Message ---- From: Keith Simmons <smiley73@googlemail.com> To: ids@iiug.org Sent: Thursday, April 10, 2008 1:04:32 AM Subject: Re: Installing IDS 10 without 'informix' user .... [11814] On 10/04/2008, TOM W <twillia@gmail.com> wrote: > Hi, > Is it possible to install IDS10 without the 'informix' user on the system? The > group 'informix' exists and has a user as a member - is there any way to tell > the install to use this other username in place of 'informix' when creating > directories/permissions? > > I haven't been able to find this referenced in any documentation. > > Thanks > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > See you at the IIUG Informix 2008 Conference > The Power Conference for Informix Professionals > April 27 - 30, 2008 Marriott Overland Park (Kansas City), Kansas > http://www.iiug.org/conf > Registration Now Open!! > Tom No. The Informix User is not only just used as the 'owner' of the file/directories but is also embeddd in the code as the only user (beside root) to be able to configure and run the engine and to manage the engine environment such as adding space, logs etc. It must exist on both Unix and Windoze. Keith ******************************************************************************* Forum Note: Use "Reply" to post a response in the discussion forum. See you at the IIUG Informix 2008 Conference The Power Conference for Informix Professionals April 27 - 30, 2008 Marriott Overland Park (Kansas City), Kansas http://www.iiug.org/conf Registration Now Open!! __________________________________________________ Do You Yahoo!? Tired of spam? Yahoo! Mail has the best spam protection around http://mail.yahoo.com
Right, this is a Solaris box. I spent most of today playing around with various configurations, it seems you *can* get it to run as a user other than informix on Solaris, with a lot of messing around, but only if it's already been installed/initialised as 'informix'. Never mind, they'll just have to create an 'informix' user.
On Thu, Apr 10, 2008 at 5:45 AM, Keith Simmons <smiley73@googlemail.com> wrote: > On 10/04/2008, TOM W <twillia@gmail.com> wrote: > > Thanks for the quick reply Keith. That's kind of what I was thinking. > > > > I'm up against some fairly tight restrictions here; is it possible to create > > the informix user, complete the IDS install, then grand dba rights to another > > username, chown dbspaces, binaries and directories and then remove the > > informix user? > Tom > > DBA (Database Administrator) rights can be granted to anyone DSA > (Database SERVER Administor) rights are not a grantable option, > however the installation guide seems to indicate that any user in > group informix has DSA rights, however there are dire warnings not to > do this and further warnings about the consequences. > Why are you so restricted. Someone has to have the authority to manage > and run the Server and it is best this is the informix user as > designed. Do not add other users to group informix. Those users will be able to trash any portion of the informix system by accident - which is undesirable. It's also a good reason for not using the informix user account any more than minimally necessary, which is a lot less necessary than most people think. [I essentially don't login as informix on my machine - I don't know the informix password and don't care what it is, but I can cheat around that when I need to. I occasionally run a program or script as user informix (mainly to start up or shut down one of my IDS instances), and I use a SUID informix, SGID informix program to create chunk (cooked) files for me: onchunk - of my own devising. With those exceptions, I don't have a need to be user informix. And generally, where I do use user informix, it's because I've been too lazy to set up DBSA role separation.] Do set the group of $INFORMIXDIR to the (small, trusted) group who should administer the server. ...for the rest, see my other email response... -- Jonathan Leffler #include <disclaimer.h> Email: jleffler@earthlink.net, jleffler@us.ibm.com Guardian of DBD::Informix v2008.0229 -- http://dbi.perl.org/ "Blessed are we who can laugh at ourselves, for we shall never cease to be amused." NB: Please do not use this email for correspondence. I don't necessarily read it every week, even.