Help with Windows AD and SLES IDS
Posted in 2017
Topics: Platform-Specific Issues
Hello community, first post here and sorry I'm a newbie in this topic. I have a SLES-Server with IDS, windows server 2012 r2 with AD and some windows clients and a own domain. I've read the paper about http://www-1.ibm.com/support/docview.wss?rs=0&uid=swg21405613 I've some questions about this topic. In KDC setup for IDS they add an user INFORMIXSERVER, i'm not sure why? Is user informix not enough for informix? So I need user informix and users for my clients in AD? I've found some infos about setspn, sometimes '@' is used, sometimes domain/host. Im not sure which is the correct syntax? ty
Hello Stefan, I think you first should clarify whether AD should only be used as an LDAP service, providing user identities and credentials for e.g. your DB server host (which then don't need to exist there as locally defined users), or whether you'd also want to use AD's Kerberos single-sign-on (SSO) capabilities with Informix. Only for SSO the setspn business would apply: 'kerberized users' (AD user accounts) only are one half of Kerberos SSO authentication, the other half are 'kerberized services' those users would be authenticated to. Each such service needs to be be known to the KDC by a Service Principal Name (SPN) which is a special form of user account. You create an SPN for an Informix server (here: 'service') using the Informix server's DBSERVERNAME. Then you'd place a certificate (key) for this SPN into the service (DB server) host's key store. I think there are a number of reasons why user informix should be exempted from all this and rather exist as a good old local user on the DB host box - unless, of course, company policy dictates differently. HTH, Andreas From: "STEFAN CONSUL" <plew@gmx.de> To: ids@iiug.org Date: 10/18/2017 09:49 AM Subject: Help with Windows AD and SLES IDS [40084] Sent by: ids-bounces@iiug.org Hello community, first post here and sorry I'm a newbie in this topic. I have a SLES-Server with IDS, windows server 2012 r2 with AD and some windows clients and a own domain. I've read the paper about http://www-1.ibm.com/support/docview.wss?rs=0&uid=swg21405613 I've some questions about this topic. In KDC setup for IDS they add an user INFORMIXSERVER, i'm not sure why? Is user informix not enough for informix? So I need user informix and users for my clients in AD? I've found some infos about setspn, sometimes '@' is used, sometimes domain/host. Im not sure which is the correct syntax? ty ******************************************************************************* Forum Note: Use "Reply" to post a response in the discussion forum.
Hi Andreas, thank you for you help. The system should have a SSO-infrastructure. At the moment I have a domain with the SLES-Server and a testclient, I created a service prinicipal with setspn for the db like in the paper. with ktpass I generate a keytab file for the db-server. This works so far, so now I've to merge it with the krb5.keytab file. But I have no keytab file, I checked the yast kerberos client configuration and settings are right so far. Do I have to manually generate a keytab file for the sless or can I use the generated one without merge? I'm not sure if I understand this right. ty
Hi Stefan, haven't done this in a while but I think, if no /etc/krb5.keytab file existing yet, you can just put your key file from Windows ktpass utility as that file. Otherwise 'ktutil' OS utility would be your friend. HTH, Andreas From: "STEFAN CONSUL" <plew@gmx.de> To: ids@iiug.org Date: 10/19/2017 09:06 AM Subject: Re: Help with Windows AD and SLES IDS [40092] Sent by: ids-bounces@iiug.org Hi Andreas, thank you for you help. The system should have a SSO-infrastructure. At the moment I have a domain with the SLES-Server and a testclient, I created a service prinicipal with setspn for the db like in the paper. with ktpass I generate a keytab file for the db-server. This works so far, so now I've to merge it with the krb5.keytab file. But I have no keytab file, I checked the yast kerberos client configuration and settings are right so far. Do I have to manually generate a keytab file for the sless or can I use the generated one without merge? I'm not sure if I understand this right. ty ******************************************************************************* Forum Note: Use "Reply" to post a response in the discussion forum.