dmwm / PHEDEX

CMS data-placement suite
8 stars 18 forks source link

Revoke delete privileges for site roles on t_xfer_replica table #897

Closed ericvaandering closed 10 years ago

ericvaandering commented 10 years ago

Original Savannah ticket 95710 reported by magini on Wed Jun 27 05:09:02 2012.

Hi,

currently, all site roles have full privileges on the t_xfer_replica table (delete, insert, select, update).

Delete privileges are no longer needed since PhEDEx 3.3, and should be revoked - all replica deletions from the t_xfer_replica table are now managed by the central FilePump agent.

Site roles still need update privileges (for the FileStager agent) and insert privileges (for the TMDBInject script, as long as we keep support for it).

Cheers Nicolo'

ericvaandering commented 10 years ago

Comment by wildish on Wed Jun 27 05:15:56 2012

is there any reason not to deprecate TMDBInject? We really don't need it any more, do we?

ericvaandering commented 10 years ago

Comment by magini on Tue Aug 21 09:59:49 2012

Delete privilege on t_xfer_replica was revoked from all sites with the password change on July 25th 2012:

http://cmssw.cvs.cern.ch/cgi-bin/cmssw.cgi/COMP/PHEDEX/Schema/OraclePrivs.sh?r1=1.29&r2=1.26&sortby=date

As you found out after the password change, TMDBInject is still needed by the relval machinery, which is still using it via ProdAgent.

Closing this item.

Cheers Nicolo'

ericvaandering commented 10 years ago

Closed by magini on Tue Aug 21 09:59:49 2012