Subject Re: [ib-support] About SYSDBA
Author Scott Taylor
At 02:16 AM 19/07/2002, you wrote:
>t seems that I can delete the user SYSDBA just like any other, by editing
>isc4.gdb directly, through IBConsole, using the security service like with
>the IBX.

Of course you can. As a paranoid SysAdmin that would be the first thing to
do before putting a live DB on the Internet. At least rename SYSDBA.

> once this is done there is no way to access the server as an
>administrator, and if SYSDBA is the only user there is no way to access the
>server at all.

That's fairly obvious. A quick reinstall will fix your lost admin account.

>Is it normal to be able to delete SYSDBA that easily, and how
>could I prevent this from happening.

Change the password from the default is a good start. You have to have the
rights to remove accounts; don't give them to just anyone. Basic,
sensible, security practices come into play here.

>My second question is related to the
>first, can I have nmore than one administrator user and how can I identify
>it let's say in the isc4.gdb? I've noticed it's userID value is null while
>it's 0, by default, for all the others is that right?

Go to IBPhoenix.com and find the file OpGuide.pdf (I think that's where I
found it), there is a pretty strait forward piece in there about database
security. Save me from reiterating the whole thing here. ;)

Scott.