Re: Security infrastructure plan

From: Sue Hoegemeier (Sue_H@nomail.please)
Date: 05/09/02


From: Sue Hoegemeier <Sue_H@nomail.please>
Date: Thu, 09 May 2002 12:17:47 -0600


Chris,
I'd Leave the system tables out of the whole thing. No one
needs access to those. Just allow the default public
privileges and that should be sufficient. Allowing users
other direct access to system tables is asking for problems.
Using a hierarchy of groups, roles that type of thing is
much easier to maintain and is the recommended approach in
MS documentations. Whatever you can manage through Windows
NT groups, use that. Use built in roles when you can and
then create your own to expand on what you need.
One thing though....If public is denied certain permissions
then you will effectively be denying to everyone other than
sysadmins. Deny take precedence and everyone is a member of
public. Only a sysadmin will bypass a deny. The rights and
privileges a user has is the sum all rights/privledges based
on their group membership, role membership and individual
account with deny taking precedence.
Don't forget to consider issues with the guest account if
you have it in the databases.
You may want to go over the security white paper for
whichever version of SQL Server you are running - it's a
very good resource:
For SQL 2000 -
http://www.microsoft.com/sql/techinfo/administration/2000/securityWP.asp
or for SQL 7 -
http://www.microsoft.com/sql/techinfo/administration/70/securityWP.asp

-Sue

On Thu, 9 May 2002 13:08:39 -0400, "Chris Beardsley"
<clb39@nospam-cornell.edu> wrote:

>The DB's on our local test Server currently has everyone in the public role.
>The public role has access to everything. This occurs to me to be a wide
>open security schema (or does not exist, whichever your preference).
>
>I was planning on making some more tiered access groups, then restricting
>public to select only. The results would look something like this:
>
>Full - all rights to select, insert, update, delete, and DRI - System table
>access
>Change - Rights to select, insert, update, and delete Denied DRI and system
>table access
>Public - Rights to select Denied Insert, Update, Delete and DRI and system
>table access
>Purgatory - Denied access to everything and system table access
>
>What am I missing with this user formula? What could I potentially break on
>the server (not App) if I implement this?
>
>Responses directly to this, or additional security information would be
>greatly appreciated.
>
>Chris
>



Relevant Pages

  • RE: Upgraded to Word 2003, now I cant open files
    ... Novell NetWare Network Privileges Required to Run Word ... Description of File System Directory and File Rights ...
    (microsoft.public.word.application.errors)
  • =?windows-1252?Q?Re=3A_=93Libertarians=2C=94=2F_vs_Corporate_Power?=
    ... result is that these collectivist entities with their government- ... bestowed privileges have taken over our economy, ... the defenders of individual rights. ... distinction between Big Brother and God! ...
    (alt.gathering.rainbow)
  • Re: turn off user account control
    ... Another possibility is that the developers might not be using the least privileges that their software needs and instead required Administrator privileges. ... what is requiring admin rights to run is old legacy COM solutions. ... One of the requirements of Vista compliant software is that it only needs Standard user rights to execute. ... But the bottom line is to make the application run with only requiring Standard user rights or least privilege, which most software developers bluntly disregard and everything runs with full-admin-rights when 9 times out of 10 it is not required. ...
    (microsoft.public.windows.vista.security)
  • Re: How to manage user access in FM7 and later
    ... > profiles and then use this groups to assign rights in FMP. ... > personal login system and a users file where a rights manager could ... > Take into account that the delegated rights manager knows nothing ... about everything you can do with homebuilt, individual privileges can be ...
    (comp.databases.filemaker)
  • What is the Anglobitch Thesis?
    ... the advance of women's 'rights' across the Anglosphere has not been ... accompanied by a corresponding reduction of their traditional privileges - ... men only with obligations and women aglow with rights plus privileges. ... Anglo-American media, ...
    (soc.men)