下面从系统层、数据库层、运维层三个维度,系统说明 Linux 上 Informix 的安全加固方法,偏实战、可落地。
informix),禁止 root 运行usermod -s /bin/bash informix
usermod -s /sbin/nologin informix
chown -R informix:informix /opt/informix
chmod -R 750 /opt/informix
chmod 600 /opt/informix/etc/sqlhosts
sqlhosts,不使用信任连接(trusted)firewall-cmd --add-port=1526/tcp --permanent
firewall-cmd --reload
DROP USER informix;
(仅授权用户保留)DBA 权限给应用账号CREATE ROLE app_role;
GRANT SELECT, INSERT ON tab1 TO app_role;
GRANT app_role TO appuser;
onaudit -C start
编辑 onconfig:
ALLOW_NEWLINE = 0
SECURITY = 1
ontape / onbar 备份❌ 禁止使用:
trust 类型连接✅ 推荐:
[ ] 非 root 运行
[ ] 端口受防火墙限制
[ ] sqlhosts 权限 600
[ ] 无 trust 连接
[ ] 审计已开启
[ ] 定期备份
[ ] 权限最小化
如果你愿意,我可以:
你可以告诉我你的 Informix 版本和使用场景。