Re: Instance LogIn Restriction

"James Titmas" <[email protected]> Mon, 18 Nov 2002 07:53:05 -0500
Newsgroups gmane.linux.suse.db2
Message-ID <[email protected]>
I have hundreds of users and I do not want to maintain them in this way.
There are only 3 that know the login identification for the db2 instance.
However, I still want to force them to login to their linux bash user acct
first.  This will aid in auditing purposes also; to keep track of who is
doing what.  If they login directly with the instance id there is no way to
know exactly who it is.  My AIX administrator mentioned looking into the
/etc/security/access.conf file usage but this appears to only be Apache
server related.



                                                                                                           
                      Klaus Thiele                                                                         
                      <[email protected]>          To:      "James Titmas" <[email protected]>,           
                                               [email protected]                                       
                      11/15/02 05:54           cc:                                                         
                      PM                       Subject: Re: [suse-ibm-db2] Instance LogIn Restriction      
                                                                                                           
                                                                                                           




Hi James,

you can create a client-instance for your users.
   /usr/IBMdb2/V7.1/instance/db2icrt -s client -u db2fenc1 joeblow
then 'joeblow' has it's own db2-environment (sqllib directory)
following 'joeblow' has to catalog a node and the database
  catalog tcpip node mynode remote thishostname server 50000
  remote_instance db2inst1 system thishostname
  catalog database dbname at node mynode
then 'joeblow' can connect (with the privileges the admin has granted to
   him)
   connect to dbname user .....

hope this helps
  klaus

Am Freitag, 15. November 2002 20:39 schrieb James Titmas:
> I want to restrict an instance account so that it cannot have direct
local
> log-ins of any kind.  The only way to get to it will be to 'su' to it
from
> a user account.  i.e.  Log in as joeblow then su to dbinst1.  Can anyone
> help?  I'm using SuSE Linux v7.0 on s/390.

--
Klaus Thiele - Personal & Informatik AG
mailto:[email protected]

 "Your mouse has moved.
  Windows must be restarted for the change to take effect."