Subject Re: [firebird-support] Firebird init script
Author The Wogster
Rick Debay wrote:
>> What's to fix?
>
> Let me rephrase. Has the change mentioned in the comment been
> implemented? The init script is WORLD readable, so anyone can find the
> SYSDBA password if they are allowed to log on to the server, even as a
> n00b guest.
>
>>> Shouldn't anyone belonging to the firebird group be allowed to
> stop/start the server?
>> Heaven forbid.
>
> Why is it (from Pavel Cisar's comment) the intention that only root can
> restart firebird? There is a firebird user, and a firebird group. I
> would expect that the firebird user, or a member of the firebird group,
> be allowed to have operator privileges. I'm not talking about someone
> who can log on to the database, but a user on the box who belongs to the
> group that the install script created.
>

Starting or stopping the database server, should be difficult, root
needs the ability, because it needs to be able to stop the server during
a machine shutdown or restart. If just anyone can stop the server, then
some idiot is going to shut it down, when the world is trying to use it.

W