DB2 public許可權相關

fjzcau發表於2015-03-28
--檢視public擁有的表或檢視的許可權
db2 " select char(grantee,20) as grantee, char(tabname,40) as tabname,
  controlauth, alterauth, deleteauth , insertauth, selectauth, updateauth
from syscat.tabauth where grantee='PUBLIC' and tabname like '%AUTH%'
"
---------------------------------------------------------------
資料庫在 Restrict 模式下,授權使用者:test

db2 grant use of TABLESPACE USERSPACE1 to test
db2 grant IMPLICIT_SCHEMA ON DATABASE to test
db2 grant CREATETAB ON DATABASE to test
db2 grant dataaccess on DATABASE to test
db2 grant connect on database to test
db2 grant usage on workload sysdefaultuserworkload to user test


db2 revoke connect ,bindadd,createtab on database from public;

--restrictive 為 YES,不把相關許可權授予public
db2 get db cfg for testdb | grep -i restrict

--------------------------------------------------------------------------------------------------------
REVOKE BINDADD ON DATABASE FROM PUBLIC;
REVOKE CREATETAB ON DATABASE FROM PUBLIC;
REVOKE CONNECT ON DATABASE FROM PUBLIC;
REVOKE IMPLICIT_SCHEMA ON DATABASE FROM PUBLIC;
REVOKE USE OF TABLESPACE USERSPACE1 FROM PUBLIC;
REVOKE SELECT ON TABLE SYSCAT.COLAUTH FROM PUBLIC;
REVOKE SELECT ON TABLE SYSCAT.DBAUTH FROM PUBLIC;
REVOKE SELECT ON TABLE SYSCAT.INDEXAUTH FROM PUBLIC;
REVOKE SELECT ON TABLE SYSCAT.PACKAGEAUTH FROM PUBLIC;
REVOKE SELECT ON TABLE SYSCAT.PASSTHRUAUTH FROM PUBLIC;
REVOKE SELECT ON TABLE SYSCAT.ROUTINEAUTH FROM PUBLIC;
REVOKE SELECT ON TABLE SYSCAT.SCHEMAAUTH FROM PUBLIC;
REVOKE SELECT ON TABLE SYSCAT.SECURITYLABELACCESS FROM PUBLIC;
REVOKE SELECT ON TABLE SYSCAT.SECURITYPOLICYEXEMPTIONS FROM PUBLIC;
REVOKE SELECT ON TABLE SYSCAT.SEQUENCEAUTH FROM PUBLIC;
REVOKE SELECT ON TABLE SYSCAT.SURROGATEAUTHIDSFROM PUBLIC;
REVOKE SELECT ON TABLE SYSCAT.TABAUTH FROM PUBLIC;
REVOKE SELECT ON TABLE SYSCAT.TBSPACEAUTH FROM PUBLIC;
REVOKE SELECT ON TABLE SYSCAT.XSROBJECTAUTHFROM PUBLIC;
REVOKE SELECT ON TABLE SYSCAT.AUTHORIZATIONIDS FROM PUBLIC;
REVOKE SELECT ON TABLE SYSCAT.OBJECTOWNERS FROM PUBLIC;
REVOKE SELECT ON TABLE SYSCAT.PRIVILEGES FROM PUBLIC;
Grant DBADM ON DATABASE FROM USER jeff


來自 “ ITPUB部落格 ” ,連結:http://blog.itpub.net/22661144/viewspace-1477191/,如需轉載,請註明出處,否則將追究法律責任。

相關文章